Viewing profile — ahoog42
ahoog42
HN member- Joined
- Sat, Dec 21, 2013, 2:10 PM UTC
- HN karma
- 40
- Public activity
- 26 items
- HN profile
- View on Hacker News ↗
About ahoog42
No profile information was provided.
Recent public activity
- story
- story
-
comment
Comment #47866947
at what point do model providers optimize for the "pelican riding a bicycle" test so they place well on Simon's influential benchmark? :-)
- story
-
comment
Comment #45466273
any notes or pointers on how to get comfortable with k8? For a simple nodejs app I was looking down the pm2 route but I wonder of learning k8 is just more future proof.
-
comment
Comment #45371787
if you are on a Zoom/video call, does anyone know if you would have to declare that your "recording" it? I'm thinking more from the legal perspective of wiretapping/consent laws. I…
-
comment
Comment #44692986
regarding data collection, both android and ios provide multiple ways to review, approve/deny, and manage access to data. it's certainly not perfect but is being constantly improve…
- story
- story
-
comment
Comment #44003963
If you want to be alerted to new/updated SEC cybersecurity filings, you can subscribe to my free alerts [1] or see the full index of cybersecurity incidents [2] on my tracker (I ch…
-
comment
Comment #43859992
Jonathan Sawday’s 2023 book “Blanks, Print, Space, and Void in English Renaissance Literature: An Archaeology of Absence.” [1] explores this phenomenon as well across multiple medi…
- story
-
comment
Comment #43159442
This is exactly how we built viaForensics in 2009. For the first five years, we performed mobile forensic investigations and gave trainings based on the Android and iOS forensic bo…
-
comment
Comment #43101425
Despite their goal of enforcing in 2017, it is still not a hard requirement. Back then, about 80% of the apps we tested disabled ATS either partially or fully [1]. It’s rare to see…
-
comment
Comment #43097246
We analyzed the iOS app[1] and observed similar traffic as well as a number of basic security issues (hardcoded encryption keys, use of 3DES and some traffic over HTTP). [1] https:…
-
comment
Comment #43090158
Any example code or blogs/docs that demonstrate making graphs/diagrams and/or hooking it up to a local code base?
-
comment
Comment #42968870
agreed the 3DES is a difficult choice to explain. To top it off the encryption key was hardcoded in the .ipa, the IV was null and then reused.
-
comment
Comment #42968846
Yes, the Android app has multiple vulnerabilities but we focused this report on iOS (it took nearly 40 hours to write the report). Our recommendation is people avoid using the mobi…
- story
-
comment
Comment #39778084
Congrats, very exciting. Do you support configuring things like usernames and passwords? How do you handle MFA?
-
comment
Comment #39067069
Actually there has been more, e.g. LoanDepot, Inc [1], and then various amended 8-Ks. I’ve been hacking on a side project to parse the 8-K data which is all over the place, includi…
-
comment
Comment #33450338
Great points. Static binary analysis looks for the version string but doesn’t currently do deeper analysis of reversed code to see if it’s patched. Could go either way. And determi…
-
comment
Comment #33449054
I decided to review SBOMs from about 3,800 popular mobile apps to see if any included vulnerable versions of OpenSSL v3.0.x. No mobile apps did (not surprised) but what did surpris…
-
comment
Comment #9023486
Please let me know if there's any questions or just an FYI link. I recently shared some thoughts on challenges faced when scaling a company - https://medium.com/@ahoog42/go-go-go-s…
-
comment
Comment #9013023
We're Chicago-based startup [1] that helps secure mobile apps and devices and recently completed a 12.5m Series A. If you're interested in mobile security, you can get an idea abou…