Live data from Hacker News

Viewing profile — acorn221

acorn221

HN member
Joined
Mon, Jan 22, 2024, 4:39 PM UTC
HN karma
43
Public activity
53 items

About acorn221

https://a.rno.tt

Recent public activity

  1. comment
    Comment #49221446

    First DEF CON, first conference talk and I loved it.

  2. story
  3. comment
    Comment #48825638

    This is my extension, I made it because I hate the UX of PGP. It uses passkeys (or passwords) to encrypt all keys (public and private) at rest so your contacts can't get leaked eas…

  4. story
  5. story
  6. story
  7. story
  8. story
  9. story
  10. story
  11. story
  12. story
  13. story
  14. story
    Show HN: Chrome Extension Scanners, Spin AI vs. Am I Being Pwned

    This is a blog post I wrote comparing the scanning results with our own solution vs SpinAI. Multipassword going up in risk after they fixed a vulnerability was my favourite find.

  15. comment
    Comment #47620348

    ik lol, I was too lazy to change it

  16. comment
    Comment #47619620

    I thought I’d check to see whether or not they actually read what they were adding lol

  17. comment
    Comment #47618630

    If you want to go check for it, open linkedin on Chrome, open dev tools -> network tab -> magnifying glass at the top then search for "epstein" and you'll see it!

  18. story
  19. comment
    Comment #47615759

    Yeah I mean it's not very commonly used by extensions. I quite like it as it's completely isolated and not detectable. I built my first extension which uses it as the primary inter…

  20. comment
    Comment #47614576

    Yeah I agree. All new extensions should have this for their web_accessible_resources. With that said, the chrome web store ecosystem has bigger problems infront of them. For exampl…

  21. comment
    Comment #47614465

    Yeah, this is the easiest way to get around it

  22. comment
    Comment #47614457

    So these extensions allow linkedin to do this though, it's literally them saying "yes, this site can ping this resource" - called "web_accessible_resources". This is fair from Link…

  23. comment
    Comment #47614361

    They have! It's these developers either not knowing or not caring about it which is the issue! I did a blog post about this a while back showing how they do it, and how you can get…

  24. comment
    Comment #47614343

    Yeah I agree

  25. comment
    Comment #47614320

    This gave someone the opportunity to add in "Jeffery_Epstein_did_not_kill_himself" to linkedin's client facing code base through this. If you open dev tools -> network tab -> netwo…