HNHacker News
TopNewBestAskShowJobs

samlanning

22 karma · joined October 31, 2013

submissionscomments
samlanning··on I quit my job to work full time on my open source project
Yes it does, both path and timestamp.

You can even filter to commands for your current directory by just pressing Ctrl+R a few times

samlanning··on Coverity Scan Update
Go support is currently in development, so very likely :)

As for the other languages there, there are no plans currently on the roadmap for 2019 to add any of them. However if this is something that particularly interests you, we'd encourage you to apply for a job and note that you'd like to add support for a particular language :)

samlanning··on Coverity Scan Update
Systemd and tesseract-ocr both use it for example:

https://github.com/tesseract-ocr/tesseract https://github.com/systemd/systemd

systemd have also written their own QL query: https://github.com/systemd/systemd/blob/master/.lgtm/cpp-que... https://lgtm.com/projects/g/systemd/systemd/alerts/?mode=tre...

(full disclosure, I also work at Semmle)

samlanning··on Preventing Disaster from Potential Security Bugs like Heartbleed
I have updated the article to add some clarifications in response to the comments posted here.
samlanning··on Preventing Disaster from Potential Security Bugs like Heartbleed
Hi Peter,

The point of the article was more saying that revoking certs is not sufficient, and we need better procedures in place to prevent disaster when problems of this nature occur.

samlanning··on Preventing Disaster from Potential Security Bugs like Heartbleed
Yes of course.

However by far the worst part of it is the private key leakage. With that, all the other stuff it sees in memory that is sensitive is probably being transmitted over the wire anyway. Which means that is can be MITM'd. Granted that is a lot more work than just examining memory...

If you plug that hole with a system like this, a website owner could just expire sessions and require people to log in again. In addition, the sessions for the past 2 years wont be at risk, only the active sessions used that day.

In short, short-lived certificates will dramatically reduce the damage, not prevent all damage.

EDIT: Sorry I realised that you were just adding to the list of consequences to this bug, not arguing the mitigations I mention would be useless! =)