HNHacker News
TopNewBestAskShowJobs

xSwag

1,512 karma · joined December 22, 2011

▲

I like breaking into things

submissionscomments
xSwag··on Laura Poitras: ‘Facebook is a gift to intelligence agencies’
Isn't Thiel a billionaire? I don't understand why he would do so much to promote a £9.99 book.
xSwag··on Try new Power8 CPU for free on RunAbove cloud: 176 threads!
Brilliant, I can finally implement one of my bandwidth intensive ideas! Thanks Steven!
xSwag··on Try new Power8 CPU for free on RunAbove cloud: 176 threads!
I've just read their main website. Out bandwidth at $0.01 per GB? Has anybody tried this? Looks too good to be true.
xSwag··on A scanner for SIP proxies vulnerable to Shellshock
IMO there should be some sort of header like

    x-whitehat: autopatch
which gives white-hats the opportunity to patch your system without exploiting. The why I see it, a malicious person is going to exploit your server anyway. This way white-hats could patch your system and not be prosecuted. With this, someone who discovered the patch could scan the internet, look for servers that say "yes, please patch me" and deploy a quick patch and nothing else.
xSwag··on Show HN: Deploy your websites from Dropbox
Why a $1 plan? What if that user asks for support, would you value 15 or 30 mins of your time at $1?
xSwag··on Two Countries, Two Vastly Different Phone Bills
> The all-you-can-eat is capped (small print) at a "fair usage" of 25 Gb/month.

I can tell you that this is wrong, I've personally had months where I've used 100GB+ of data over 3G and had no problems (this is on a £15 top-up). I don't know if they throttle or not, I've never really noticed it.

> Tethering is disabled while roaming overseas on "feel at home", but not prevented at home.

I didn't get my handset from Three but I've been able to tether in Paris and used at least 2GB when I was there.

xSwag··on Show HN: Encrypted pastebin with Bitcoin ad network
$5 per 1k US visitors? How do you do that?
xSwag··on NSA's BIOS Backdoor a.k.a. God Mode Malware
Why is this website not banned yet? They're very well known plagiarists.

http://attrition.org/errata/charlatan/infosec_institute/

xSwag··on Inside the Dark, Lucrative World of Consumer Debt Collection
1. Get loan

2. Don't pay it back

3. Ask debt collector friend to buy debt

4. Pay him off

Why would this not work?

xSwag··on Show HN: Vulnerability scans for WordPress. No installation or code required.
StartSSL has an issue with Apple computers. I'll be getting a better SSL cert once I get more customers and revenue.
xSwag··on Show HN: Vulnerability scans for WordPress. No installation or code required.
Hi, thanks for the feedback. I've asked for credit card details to prevent the abuse of this service since you can scan any website.

However, I'm currently in the process of working with the Google Analytics API to provide free scans for verified websites where the user can prove ownership -- this should roll out in about a week or so. Would you like me to drop you a PM when I release this feature?

xSwag··on Show HN: Vulnerability scans for WordPress. No installation or code required.
Sorry about that, server got knocked offline. Should be back soon.
xSwag··on Show HN: Vulnerability scans for WordPress. No installation or code required.
Hi everyone, this is the MVP I have been working on. It's almost 5am in the UK right now and I just wanted to launch as soon as possible and stop procrastinating (and waiting for my A-level results). It's funded entirely by my Google bug bounties, so thank you Google. I have not done any design stuff for it yet -- the site is very bare bones but functional.

Current solutions to vulnerability scanning such as WPscan are good but not user-friendly -- which is what I believe what WordPress users want. I've already got my first 5 customers prior to launch that wanted this product which I think is a good start, hopefully there is a market for this stuff.

I would love to hear any sort of feedback.

xSwag··on Dr. Dre, Jimmy Iovine Would Both Join Apple in Beats Deal
Anybody else more interested in when Dr.Dre is going to release Detox? I'd love to hear him rap about multi-billion deal
xSwag··on All the Western companies you’d have to combine to get something like Alibaba
So who's buying the IPO? Seems much better investment than SV companies with little or no profit.

I wonder how it will affect YHOO -- Probably worth buying Jan 2015 $40 calls since Yahoo owns 24% stake, maybe even short AMZN on day of IPO.

xSwag··on Ask HN: Do you have a Ph.D? Is it useful? Was it worth it?
Counterpoint: Most quant jobs require a Phd in a STEM subject.
xSwag··on Poll: Is your startup or side project profitable?
I built a security scanner that scans WordPress installations for threats (plugin vulns, outdated installs, theme vulns, xss, sqli etc) without any installation or code knowledge required. I posted it on Reddit and got a few sign ups, after that I just got bored and I'm not sure what to do next. I'm thinking about partnering with WordPress tutorial websites and give them a recurring revenue cut or something. I really wish I was better at marketing products. Maybe I should just sell it or something. Any WordPress related websites with good amount of traffic please contact me if you're interested in partnering.
xSwag··on Verizon Using Recent Net Neutrality Victory to Wage War Against Netflix?
Yes let's arm ourselves with pitchforks based on an anecdotal experience of a stranger on the internet.
xSwag··on OpenSSL site defacement involving hypervisor hack rattles nerves
No.

Simple logic: The defacement was amature at best. If the group has a 0-day in a hypervisor they would have gone to multiple hosting companies and multiple attacks would have taken place, there are many more targets that are worth much more than openSSL.

Most likely, the administration panel of the hosting company was comprimised through malware/phishing. Seriously, if a group like this had a 0-day in hypervisor then they would be doing much much more damage.

xSwag··on Find Friends Abuse
There is an easier way to solve this issue: Bug Bounty.

It worked for Google, it worked for Facebook and its working for Yahoo! Infact, it worked so well for Google that they recently increased the rewards. A venture-backed startup like Snapchat that stores private pictures (even temporarily) should have no trouble paying out $5k a few times for vulnerabities.

xSwag··on Skype blog hacked
This blog is not hosted by the Skype but on WordPress VIP. This means that, most likely, the blog was not broken into using a software exploit of any sort since the security on VIP blogs is professional. Knowing that this is the Syrian Army, this attack was most likely done using phished credentials.

If they had any sort of system access they would have defaced the entire subdomain or the main site. So most likely, this is nothing to worry about. Your account data most likely still in safe hands.

xSwag··on DigitalOcean leaks customer data between VMs
TL;DR: In the DigitalOcean web panel you can check the "scrub data" checkbox when destroying a VM. When using the API this option is not ticked. This can lead to other customers being able to retrieve your data.

The author thinks that this is a security issue because this option should be enabled by default. However, (I assume) it's not in Digital Oceans interest to do full disk scrub because it reduces the lifespan of their SSD.

If a user forgets to log out of Facebook on a public computer, is it Facebook's responsibility? Similarly, if a user does not correctly delete data on a budget host, is it the hosts fault?

xSwag··on Ask HN: Plans for side projects in 2014?
I'm working on a freemium SaaS which provides security for WordPress based websites. It remotely scans for vulnerabilites in your wordpress website the same way an attacker would and notifies you. Zero programming knowledge required. No installation required.

I need more money for the servers so I'm currently waiting for my Google bug bounty to come through (it's been over 6 weeks!) so I can fund a security startup with security money from Google.

xSwag··on Show HN: First ever made Vine web client
Vine in the domain name is the fastest way to get a C&D letter.
xSwag··on A Warning: Do not turn in illegal files you found to the police.
Yes, most likely the password used a common word or something else similar susceptible to being brute-forced.
xSwag··on Bitcoin Crashing
He sold at $300, I bet he regrets that decision.

https://twitter.com/kevinrose/status/398865551730036736

xSwag··on [dead]
I assume most people on HN don't know whats going on so I'll chip in what I know:

The admin, allegedly this Thomas guy, ran off with 17k BTC which is worth around $15M right now. Nobody is able to transfer their bitcoin out of sheep either. Everybody is pissed off so people are attacking his server and trying to "dox" the person. Here is the address where the money has gone:

https://blockchain.info/address/1Cwb33nqn4S2uDsXwhNrUNy7FPdi...

If anybody is interested, check out the sheep subreddit, lot's more information on the issue there.

xSwag··on Ask HN: How do I stay "on" all the time?

    >smoking weed
    >wondering why you can't stay mentally on 
https://scholar.google.co.uk/scholar?q=cannabis+depression
xSwag··on Ph.D. 2.0: Rethinking the Ph.D. Application
I'm almost certain that a Ph.D. in the UK takes 3-4 years max. Why does it take so much longer in USA?
xSwag··on Tidbit: Client-Side Bitcoin Mining
For what time duration?
Page 1 of 6Next →