Viewing profile — Herrera
Herrera
HN member- Joined
- Fri, Dec 11, 2015, 9:03 PM UTC
- HN karma
- 56
- Public activity
- 22 items
- HN profile
- View on Hacker News ↗
About Herrera
Recent public activity
- story
-
comment
Comment #43235954
Yeah, https://xsleaks.dev tracks most of the known ways to leak cross-origin data.
- story
- story
-
comment
Comment #22049835
Bleichenbacher'06 never dies.
- story
- story
-
comment
Comment #17863321
Interesting... I reported a variation of this issue to Google back in 2015 and they said they weren't "concerned about the premise of the attack in the bug description. You can alw…
- story
-
comment
Comment #13405990
I was playing with picture-in-picture attacks on Chrome some time ago and even proposed a way for mitigation, but it was dismissed. Here's the PoC I did: https://www.youtube.com/wa…
- story
- story
- story
-
comment
Comment #12261791
Really? That is strange, because there is ways this could be exploited... Can you link them to me?
-
comment
Comment #12119040
A somewhat related topic: A few months ago Google fixed a vulnerability on the inline installation. It was possible to start a install on the attacker's website and then redirect t…
-
comment
Comment #10913051
If you keep your left mouse button pressed you can cheat too.
- story
-
comment
Comment #10769837
You are right. You receive one image containing a inspirational message for your family and decide to send to your family members. Then it changes to a image asking for money to be…
-
comment
Comment #10751334
Yes, if you invest at least $1,000,000 and employ more than 10 people for two years you will be eligible to the EB-5 visa. It seems a good way to get a green card if you have the m…
-
comment
Comment #10721431
Thank you! I got involved with the security world recently and I'm really enjoying it. And I would like to clarify myself, the comment I made earlier was a little ambiguous. The bu…
-
comment
Comment #10720159
I already did report them. The first one was fixed (CVE-2015-6782), got $1k from Google. There are three more they are working on.
-
comment
Comment #10720062
It is not always enough. For example, recently I have found several ways to spoof the URL and HTTPS lock on Google Chrome. So phishing seems to be a concern.