Live data from Hacker News

Viewing profile — LukasReschke

LukasReschke

HN member
Joined
Tue, Sep 29, 2015, 4:39 PM UTC
HN karma
229
Public activity
52 items

About LukasReschke

No profile information was provided.

Recent public activity

  1. story
  2. story
  3. story
  4. comment
    Comment #25879855

    Earlier discussion from yesterday: https://news.ycombinator.com/item?id=25869798

  5. comment
    Comment #25870635

    > Most rewrites fails because the team rewriting is not the team that did the initial development. Looking at https://github.com/owncloud/core/graphs/contributors , most of the ini…

  6. comment
    Comment #25870592

    > Plus as far as I know neither ownCloud nor nextCloud went through a security audit This is inaccurate. Nextcloud does receive security audits and is in fact also used by quite so…

  7. comment
    Comment #25703036

    I've been working on an open-source Identity Access Management solution in the past few months: https://gatekeeper.page/en/ Gatekeeper aims to enable small and medium-sized enterpr…

  8. story
  9. comment
    Comment #25424933

    > So what do you think is going on in this piece (5 years old), where Alex Stamos characterizes the issue as "trivial and of little value"? I sadly wasn't there at the time, and St…

  10. comment
    Comment #25424813

    I'd advise anyone against trying that for a system not owned by them. (e.g., someone's else website) As soon as you do that, you venture into dangerous territory. Companies are req…

  11. comment
    Comment #25424686

    I was part of "big corp" for the past three years and was involved in many bug bounty reports. A reasonable claim like "I think this should be higher because XYZ" gets investigated…

  12. comment
    Comment #25424367

    How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount" vs. "I think the impact is bigger because of Y"? For me, the first …

  13. comment
    Comment #25424288

    Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Partici…

  14. comment
    Comment #25424241

    > Companies always say they will investigate the full impact of a vulnerability when you follow the protocol they urge of "as soon as you find something, report it and don't try to…

  15. comment
    Comment #13963456

    Just as a remark, we run a bug bounty program at https://hackerone.com/nextcloud offering up to $5,000 for Remote Code Executions. If someone here feels challenged: We look forward…

  16. story
  17. comment
    Comment #13167499

    Fair enough, there is some kind of marketing-ishy statement in that. I give you that :-) But considering the security features that we include such as Same-Site Cookies, CSP using …

  18. comment
    Comment #13167440

    We don't offer any PPA for the server repository ourselves. Mainly because we didn't had many good experience in the past with repositories. So what we're focusing on is providing …

  19. story
  20. story
  21. comment
    Comment #12040021

    > Is it the locations services workaround thing? That's correct.

  22. story
  23. comment
    Comment #11828856

    I highly doubt that the planned features are related. Seems just to be a try to make the press release look less worse... Disclaimer: I quit ownCloud to work now at Nextcloud.

  24. comment
    Comment #11828548

    Happy to answer this. First of all: Makes using a specific programming language a software much less secure? Probably not. You can do mistakes in every programming language. But si…

  25. comment
    Comment #11826439

    Good questions! Note, that I'm affilated with Nextcloud so obviously a bit biased. Only because a project is very transparent about security vulnerabilities does not necessarily me…