HNHacker News
TopNewBestAskShowJobs

wepple

3,233 karma · joined May 8, 2013

Security engineer. Strong opinions loosely held.
submissionscomments
wepple··on Google says it won't follow Amazon's lead with a return-to-office mandate
That’s hybrid, not full RTO
wepple··on Eliminating Memory Safety Vulnerabilities at the Source
We love it. Can move on to the other two hundred problems to work on.

Including where CNE will go next; logic and web bugs.

wepple··on Eliminating Memory Safety Vulnerabilities at the Source
Or an alternative approach: only compile the subset of features you explicitly need.

Obviously there’s a ton of variance in how practical this is any place, but it’s less common than it should be.

wepple··on Caroline Ellison sentenced to 2 years in prison
Nit: have orgies
wepple··on Caroline Ellison sentenced to 2 years in prison
> I wouldn’t serve 30 days in jail for a billion dollars.

You’d rather spend 50 years _totally free_ in your cubicle?

wepple··on Twitter/X will let people you've blocked see your posts
There does seem to be an exception for public outlets.

I clicked a link to NYPDs twitter and didn’t have to AuthN. Makes sense too; every org who wanted their content to be fully available to anyone would leave if twitter mandated login

(Although they still use Facebook)

wepple··on 'I Don't Want to Die.' He needed mental health care. He found a ghost network
The former, yes, but they’re far more expensive. The latter, kind-of. You have to have regular check-ins, dependent on the type of medication
wepple··on FTC: Vast Surveillance of Users by Social Media and Video Streaming Companies
Very aware of that. That to me seemed like a targeted attack by a tracked APT group. What I’m referring to above is that the more vanilla attacks (ex: popular online mattress store gets popped) actually have national security implications, despite seeming like just an inconvenience
wepple··on FTC: Vast Surveillance of Users by Social Media and Video Streaming Companies
I forgot where I saw this, but the US govt recently announced that they see mass PII theft as a legitimate national security issue.

It’s not just that you or I will be inconvenienced with a bit more fraud or email spam, but rather that large nation state adversaries having huge volumes of data on the whole population can be a significant strategic advantage

And so far we typically see email+password+ssn be the worst data leaked; I expect attackers will put in more effort to get better data where possible. Images, messages, gps locations, etc

wepple··on Show HN: Meet.hn – Meet the Hacker News community in your city
So, what do you do once you’re on the map and so are other people?
wepple··on Microsoft hosts a security summit but no press, public allowed
I have a strong standing dislike for Microsoft, but I’ve gotta agree here.

It sounds like they’re having a summit with partners and… those are typically never open to the public, so um?

Are we going to start renaming meetings to “conferences” and then complaining they’re all closed-doors?

El Reg is a clickbait rag, but this isn’t fun snark like they often do - it’s just dumb.

wepple··on Why Login Security Sucks
Sorry, when I said OTP I mean the recovery code OTP. They’re often 16 hex, so 16^16
wepple··on Why Login Security Sucks
> It is unclear why generating a one-time password for the user is bad but if we call the password a "recovery code" it is suddenly sufficient.

The OTP is usually very long, highly randomized (you don’t get to choose Summer2024!), and designed to be stored offline somewhere as a break glass. Passwords typically follow none of those rules.

wepple··on Why Login Security Sucks
This looks like any other public key crypto authentication (U2F) but more complex and less universally adopted?

How is this better than OIDC?

wepple··on The Yubikey Is the Digital Seatbelt We Need
TOTP is trivially phishable.

Code security is orthogonal to end-user authentication methods.

So, wrong on every count.

wepple··on The Yubikey Is the Digital Seatbelt We Need
Not a hot take at all, for anyone who has worked with securing code.

SWEs simply aren’t trained to deeply examine code and the side effects of it being pressured by skilled attackers.

2+ LGTMs reduces the change of a security issue making its way in, but no amount of expensive “more eyes” will eradicate bugs.

wepple··on Eating the Birds of America: Audubon's Culinary Reviews of America's Birds
I’m curious too. Perhaps they mean getting others to do all the scouting to near guarantee a successful hunt?

I spend a ton of time in the woods reading sign and just generally being aware & learning. Ton of hours and boot leather burned, I don’t think that works for the “pay to win” crowd

wepple··on Eating the Birds of America: Audubon's Culinary Reviews of America's Birds
Whilst hunting might involve the killing & taking of an animal, it 100% relies on there being a healthy population to begin with.

Not to mention, hunting is actually very difficult (contrary to a lot of belief). You end up spending a phenomenal amount of time learning about animals, their habitat, and behavior. There ends up being deep admiration.

Not all hunters of course, some are dipshits. But such is true for any group of people.

wepple··on Eating the Birds of America: Audubon's Culinary Reviews of America's Birds
I recall reading about this in “The Scavengers Guide to Haute Cuisine”. In it. Steven Rinella creates a feast from Escoffier’s classic book. Excellent read.
wepple··on Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn
I believe both cases come down to how much effort the leaders put into identifying and purging the bad activities on their platforms.

One would hope that there is clear evidence to support a claim that they’re well aware what they’re profiting off and aren’t aggressively shutting it down.

To use Reddit as an example: in the early days it was the Wild West, and there were some absolutely legally gray subreddits. They eventually booted those, and more recently even seem to ban subreddits just because The Verge wrote an article about how people say bad things there.

wepple··on The semantic web is now widely adopted
I think that’s what we’re doing today, and it’s a phenomenal mess.

The typical HTML page these days is horrifically bloated, and whilst it’s machine parsable, it’s often complicated to actually understand what’s what. It’s random nested divs and unified everything. All the way down.

But I do wonder if adding context to existing HTML might be better than a whole other JSON blob that’ll get out of sync fast.

wepple··on Cryptographic Right Answers: Post Quantum Edition
Yeah, very very important point
wepple··on Kim Dotcom's extradition to the U.S. given green light by New Zealand
I bet that too is a ton of what drives interest, the platform angle was just the primary thing that came to mind now that that’s more the world I think about

The piracy discussion is also hugely fascinating; I’m sure a good portion of HN remember Napster and friends, and the endless discussions had about that. We don’t seem to talk about it a lot.

wepple··on Cryptographic Right Answers: Post Quantum Edition
Perhaps the meta-message here is that you absolutely have to design for cryptographic agility.

You may not need to jump to the next best thing every 3 years, but as certain constructs are proven weak, you’ll need to start migrating systems and data off of them to modern equivalents.

wepple··on Kim Dotcom's extradition to the U.S. given green light by New Zealand
There’s a substantial ongoing debate about how much responsibility a platform as for what users do on that platform. Nearly everyone in tech is affected by that.

The theatrics and drama of it is a silly distraction, but the fundamental questions seem worth following and discussing.

I’m not German; what an odd thing to comment.

wepple··on Kim Dotcom's extradition to the U.S. given green light by New Zealand
I do not categorize him as “small folk like us”
wepple··on Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server
“Carefully” is very load bearing.

A similar but different class of issues common to web stacks is when you have proxies and multiple layers of HTTP “things”, especially when they parse data differently (eg: nginx fronting Apache)

wepple··on Airbnb shares drop 12% as company flags weakening US demand
No surprises, they’re late stage enshittification.
wepple··on Coinbase awarded a $500k bug bounty
Oh yeah, I’d absolutely not want to have a raw unfiltered inbound bug bounty and be first line of triage, so paying H1 or Bugcrowd is the way to go.

But you’re also paying them to make sure the serious bugs absolutely do get to you, and if researchers give up, you’re not getting the value you need.

I suspect the problem is that the type of folks who are prepared to do front-line triage which is most commonly large volumes of nonsense and a few mediocre bugs, are early career security folks who can’t easily spot a really serious P0 and a researcher who clearly knows what they’re talking about.

wepple··on Coinbase awarded a $500k bug bounty
Bugcrowd is no different. The folks doing Triage often don’t comprehend even simple security issues.

I’m convinced it’s largely designed to keep people from going full disclosure rather than actually getting bugs fixed.

← PreviousPage 5 of 34Next →