Live data from Hacker News

Viewing profile — Herrera

Herrera

HN member
Joined
Fri, Dec 11, 2015, 9:03 PM UTC
HN karma
56
Public activity
22 items

About Herrera

Security researcher studying Computer Science at Federal University of Santa Catarina (UFSC).

Recent public activity

  1. story
  2. comment
    Comment #43235954

    Yeah, https://xsleaks.dev tracks most of the known ways to leak cross-origin data.

  3. story
  4. story
  5. comment
    Comment #22049835

    Bleichenbacher'06 never dies.

  6. story
  7. story
  8. comment
    Comment #17863321

    Interesting... I reported a variation of this issue to Google back in 2015 and they said they weren't "concerned about the premise of the attack in the bug description. You can alw…

  9. story
  10. comment
    Comment #13405990

    I was playing with picture-in-picture attacks on Chrome some time ago and even proposed a way for mitigation, but it was dismissed. Here's the PoC I did: https://www.youtube.com/wa…

  11. story
  12. story
  13. story
  14. comment
    Comment #12261791

    Really? That is strange, because there is ways this could be exploited... Can you link them to me?

  15. comment
    Comment #12119040

    A somewhat related topic: A few months ago Google fixed a vulnerability on the inline installation. It was possible to start a install on the attacker's website and then redirect t…

  16. comment
    Comment #10913051

    If you keep your left mouse button pressed you can cheat too.

  17. story
  18. comment
    Comment #10769837

    You are right. You receive one image containing a inspirational message for your family and decide to send to your family members. Then it changes to a image asking for money to be…

  19. comment
    Comment #10751334

    Yes, if you invest at least $1,000,000 and employ more than 10 people for two years you will be eligible to the EB-5 visa. It seems a good way to get a green card if you have the m…

  20. comment
    Comment #10721431

    Thank you! I got involved with the security world recently and I'm really enjoying it. And I would like to clarify myself, the comment I made earlier was a little ambiguous. The bu…

  21. comment
    Comment #10720159

    I already did report them. The first one was fixed (CVE-2015-6782), got $1k from Google. There are three more they are working on.

  22. comment
    Comment #10720062

    It is not always enough. For example, recently I have found several ways to spoof the URL and HTTPS lock on Google Chrome. So phishing seems to be a concern.