Live data from Hacker News

Viewing profile — Dyaz17

Dyaz17

HN member
Joined
Wed, Dec 02, 2015, 2:06 AM UTC
HN karma
32
Public activity
29 items

About Dyaz17

No profile information was provided.

Recent public activity

  1. comment
    Comment #26029152

    This is just awesome... Congrats on the launch. This product seems to protect really well websites that include many third party JavaScript. On the other hand ,if you are one of th…

  2. comment
    Comment #24748857

    Regarding the security aspect, I created GuardScript to help catch malicious 3rd party (or 1st party) javascript changes: https://www.guardscript.com/ . You should use if you own a…

  3. comment
  4. comment
    Comment #23832012

    You can login to your instances from the admin console according to this : https://cloud.google.com/compute/docs/instances/connecting-t... So Google has a way to login to your inst…

  5. comment
    Comment #23831749

    What is the attack Vector that this solution prevent ? Am I missing something obvious ? Will it prevent Google from being able to have a Root access to the VM? From my understandin…

  6. comment
    Comment #22045964

    Great job. Here is what I propose to make it more secure and prevent you from being able to read anyone diary... I propose that each day a link/token is sent to your email. The lin…

  7. comment
    Comment #21565563

    You can also use https://www.guardscript.com that does this for free and send you a diff in your email.

  8. story
  9. comment
    Comment #20464153

    Nice product! And thank you for making it opensource. Any particular reason why you chose Ruby? A little plug : I have developed https://www.guardscript.com . It is a service that …

  10. story
  11. story
  12. comment
  13. comment
    Comment #20271541

    You are right, for now all the analysis should be done by the owner of the script. I'll think about adding a runbook...

  14. comment
    Comment #20271532

    Thank you, I have corrected it

  15. comment
    Comment #20271527

    Thanks for the suggestion.

  16. comment
    Comment #20271526

    No it does not include the headers. Only the js file downloaded.

  17. comment
    Comment #20271520

    For now, Guardscript Goal is for the different SaaS services to use it, not for the individual website owners to use it to monitor the JS of SaaS services.

  18. comment
    Comment #20271497

    You are right. SRI is the best solution and I mention it in the FAQ. Unfortunately, it can't always be implemented. See my previous comment : Well many companies that offer you a s…

  19. comment
  20. comment
    Comment #20271486

    Thanks for the suggestion

  21. comment
    Comment #20271483

    Thank you! I have changed it.

  22. comment
    Comment #20271482

    Well many companies that offer you a service don't include the Subresource integrity Tag. Check for instance Stripe : " rel="nofollow">https://js.stripe.com/v3"> or Facebook : " re…

  23. comment
    Comment #20265158

    Hey HN! I created GuardScript because in my previous company we started to include more and more third-party Javascript from SaaS services on our homepage, and this created securit…

  24. story
  25. comment