Live data from Hacker News

Viewing profile — 0xcrypto

0xcrypto

HN member
Joined
Sat, Nov 19, 2016, 7:05 AM UTC
HN karma
113
Public activity
24 items

About 0xcrypto

security researcher, architectures fanatic. Blog: https://eval.blog

[ my public key: https://keybase.io/0xcrypto; my proof: https://keybase.io/0xcrypto/sigs/Ea8rxkjY9bGIdBrz6W7qc6F2rV5mNlm3oj_w9skQqtA ]

Recent public activity

  1. story
  2. comment
    Comment #48901817

    A question, how are you or anyone else doing this is registering bundle identifiers without opening xcode?

  3. story
  4. story
  5. comment
    Comment #46843549

    Fewer CVEs do not necessarily mean safety.

  6. story
  7. story
  8. comment
    Comment #39897834

    My only concern with such articles is the use of "god" and "religion" which only gives the majority of humanity a reason to pray more and kill anyone who disagrees. Conscious or no…

  9. comment
    Comment #39748082

    Agree with this. I tried to create objective C files in xcode 15.2 many times, spent days thinking I must have messed up somewhere and finally I found this https://forums.developer…

  10. story
  11. comment
    Comment #37982695

    You are right that redirect_uri must match the exact registered redirect_uri. But some providers allow query parameters. For Microsoft, it was possible in 2020 when I reported the …

  12. comment
    Comment #37981681

    Well mistakes happen. One thing that is still not explained is that I contacted Hackerone many times in the timespan of 3 years but they couldn't get in contact with you either. Al…

  13. comment
    Comment #37977527

    Author of the blog post here. Yes, I agree that it wasn't Hackerone's fault and they tried their best to help. As for the violation of agreement with hackerone, I have read the pol…

  14. comment
    Comment #37977035

    Oh yes, that sounds better. I am changing the title now. Updated to "Stealing OAuth tokens of connected Microsoft accounts via open redirect in Harvest App"

  15. comment
    Comment #37976843

    Hi, author of the blog post here. Yes I understand your concern and I tried keeping Microsoft's name out of the title but couldn't think of anything else. Since the vulnerability o…

  16. story
  17. story
  18. story
  19. story
  20. story
  21. story
  22. comment
    Comment #15946629

    Looks pretty neat.

  23. story
  24. story