3,233 karma · joined May 8, 2013
Including where CNE will go next; logic and web bugs.
Obviously there’s a ton of variance in how practical this is any place, but it’s less common than it should be.
You’d rather spend 50 years _totally free_ in your cubicle?
I clicked a link to NYPDs twitter and didn’t have to AuthN. Makes sense too; every org who wanted their content to be fully available to anyone would leave if twitter mandated login
(Although they still use Facebook)
It’s not just that you or I will be inconvenienced with a bit more fraud or email spam, but rather that large nation state adversaries having huge volumes of data on the whole population can be a significant strategic advantage
And so far we typically see email+password+ssn be the worst data leaked; I expect attackers will put in more effort to get better data where possible. Images, messages, gps locations, etc
It sounds like they’re having a summit with partners and… those are typically never open to the public, so um?
Are we going to start renaming meetings to “conferences” and then complaining they’re all closed-doors?
El Reg is a clickbait rag, but this isn’t fun snark like they often do - it’s just dumb.
The OTP is usually very long, highly randomized (you don’t get to choose Summer2024!), and designed to be stored offline somewhere as a break glass. Passwords typically follow none of those rules.
How is this better than OIDC?
Code security is orthogonal to end-user authentication methods.
So, wrong on every count.
SWEs simply aren’t trained to deeply examine code and the side effects of it being pressured by skilled attackers.
2+ LGTMs reduces the change of a security issue making its way in, but no amount of expensive “more eyes” will eradicate bugs.
I spend a ton of time in the woods reading sign and just generally being aware & learning. Ton of hours and boot leather burned, I don’t think that works for the “pay to win” crowd
Not to mention, hunting is actually very difficult (contrary to a lot of belief). You end up spending a phenomenal amount of time learning about animals, their habitat, and behavior. There ends up being deep admiration.
Not all hunters of course, some are dipshits. But such is true for any group of people.
One would hope that there is clear evidence to support a claim that they’re well aware what they’re profiting off and aren’t aggressively shutting it down.
To use Reddit as an example: in the early days it was the Wild West, and there were some absolutely legally gray subreddits. They eventually booted those, and more recently even seem to ban subreddits just because The Verge wrote an article about how people say bad things there.
The typical HTML page these days is horrifically bloated, and whilst it’s machine parsable, it’s often complicated to actually understand what’s what. It’s random nested divs and unified everything. All the way down.
But I do wonder if adding context to existing HTML might be better than a whole other JSON blob that’ll get out of sync fast.
The piracy discussion is also hugely fascinating; I’m sure a good portion of HN remember Napster and friends, and the endless discussions had about that. We don’t seem to talk about it a lot.
You may not need to jump to the next best thing every 3 years, but as certain constructs are proven weak, you’ll need to start migrating systems and data off of them to modern equivalents.
The theatrics and drama of it is a silly distraction, but the fundamental questions seem worth following and discussing.
I’m not German; what an odd thing to comment.
A similar but different class of issues common to web stacks is when you have proxies and multiple layers of HTTP “things”, especially when they parse data differently (eg: nginx fronting Apache)
But you’re also paying them to make sure the serious bugs absolutely do get to you, and if researchers give up, you’re not getting the value you need.
I suspect the problem is that the type of folks who are prepared to do front-line triage which is most commonly large volumes of nonsense and a few mediocre bugs, are early career security folks who can’t easily spot a really serious P0 and a researcher who clearly knows what they’re talking about.
I’m convinced it’s largely designed to keep people from going full disclosure rather than actually getting bugs fixed.