Viewing profile — LukasReschke
LukasReschke
HN member- Joined
- Tue, Sep 29, 2015, 4:39 PM UTC
- HN karma
- 229
- Public activity
- 52 items
- HN profile
- View on Hacker News ↗
About LukasReschke
No profile information was provided.
Recent public activity
- story
- story
- story
-
comment
Comment #25879855
Earlier discussion from yesterday: https://news.ycombinator.com/item?id=25869798
-
comment
Comment #25870635
> Most rewrites fails because the team rewriting is not the team that did the initial development. Looking at https://github.com/owncloud/core/graphs/contributors , most of the ini…
-
comment
Comment #25870592
> Plus as far as I know neither ownCloud nor nextCloud went through a security audit This is inaccurate. Nextcloud does receive security audits and is in fact also used by quite so…
-
comment
Comment #25703036
I've been working on an open-source Identity Access Management solution in the past few months: https://gatekeeper.page/en/ Gatekeeper aims to enable small and medium-sized enterpr…
- story
-
comment
Comment #25424933
> So what do you think is going on in this piece (5 years old), where Alex Stamos characterizes the issue as "trivial and of little value"? I sadly wasn't there at the time, and St…
-
comment
Comment #25424813
I'd advise anyone against trying that for a system not owned by them. (e.g., someone's else website) As soon as you do that, you venture into dangerous territory. Companies are req…
-
comment
Comment #25424686
I was part of "big corp" for the past three years and was involved in many bug bounty reports. A reasonable claim like "I think this should be higher because XYZ" gets investigated…
-
comment
Comment #25424367
How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount" vs. "I think the impact is bigger because of Y"? For me, the first …
-
comment
Comment #25424288
Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Partici…
-
comment
Comment #25424241
> Companies always say they will investigate the full impact of a vulnerability when you follow the protocol they urge of "as soon as you find something, report it and don't try to…
-
comment
Comment #13963456
Just as a remark, we run a bug bounty program at https://hackerone.com/nextcloud offering up to $5,000 for Remote Code Executions. If someone here feels challenged: We look forward…
- story
-
comment
Comment #13167499
Fair enough, there is some kind of marketing-ishy statement in that. I give you that :-) But considering the security features that we include such as Same-Site Cookies, CSP using …
-
comment
Comment #13167440
We don't offer any PPA for the server repository ourselves. Mainly because we didn't had many good experience in the past with repositories. So what we're focusing on is providing …
- story
- story
-
comment
Comment #12040021
> Is it the locations services workaround thing? That's correct.
- story
-
comment
Comment #11828856
I highly doubt that the planned features are related. Seems just to be a try to make the press release look less worse... Disclaimer: I quit ownCloud to work now at Nextcloud.
-
comment
Comment #11828548
Happy to answer this. First of all: Makes using a specific programming language a software much less secure? Probably not. You can do mistakes in every programming language. But si…
-
comment
Comment #11826439
Good questions! Note, that I'm affilated with Nextcloud so obviously a bit biased. Only because a project is very transparent about security vulnerabilities does not necessarily me…