Live data from Hacker News

Viewing profile — axsharma

axsharma

HN member
Joined
Mon, May 25, 2020, 9:28 PM UTC
HN karma
261
Public activity
193 items

About axsharma

Security Researcher & Tech Reporter

@Ax_Sharma AxSharma.com

Recent public activity

  1. story
  2. comment
  3. comment
  4. comment
  5. story
  6. comment
    Comment #44659924

    > "even if they've been a malicious actor the whole time" That is a sound argument, even if integrity of the package was to check out (if npm tracks this internally at all). Better…

  7. comment
    Comment #44659659

    Why not instead remove 'panya' as a maintainer from legitimate packages that were unaffected? No recent or malicious versions of Stylus have been published (which generally is the …

  8. story
  9. comment
    Comment #42973446

    Interesting, blogged about this Feb 5th https://www.sonatype.com/blog/fake-vs-code-extension-on-npm-...

  10. comment
    Comment #39763616

    Close, that's more gray with a tint.

  11. comment
  12. story
  13. comment
    Comment #39384709

    GOV.UK seems conflicted about it lol "You usually do not need a BRP to open a bank account. Contact the bank to check if you’ll need a BRP or if you can use a different document." …

  14. comment
    Comment #39326440

    Good point, rather interesting they state "in all our online journeys," rather than in-person. Anytime I've had to verify identity online for bank account opening, it entailed taki…

  15. comment
    Comment #39326112

    You need your passport if you've only got a vignette or in-passport visa sticker. BRP is often accepted, in lieu of driving license for bank account opening. https://www.lloydsbank…

  16. comment
    Comment #39326012

    While there is minimal or no passport control within the CTA, for example when travelling between UK and Ireland, the expectation is that the passenger is a citizen of a country wh…

  17. comment
    Comment #35443681

    The author here. The name eFile(.)com is bound to confuse some readers who may mistake it for IRS' e-file system/API. Probably why the company chose that brand name (SEO or whateve…

  18. comment
    Comment #34102639

    Probable explanation for the mysterious hacks on Xfinity accounts despite having 2FA enabled: 2FA bypass allegedly circulating privately "A researcher has told BleepingComputer tha…

  19. story
  20. comment
    Comment #34078494

    Add to it that they reviewed "all recent commits to Okta software repositories." Due diligence or indicative of the threat actor having write access? Many unanswered questions.

  21. comment
    Comment #33826258

    Same thought here. The domain appears to be associated with Ningbo Sunning Software, a Chinese vendor and likely a Mediatek partner than anything Android.

  22. story
  23. comment
    Comment #32518224

    How long 'til this gets DMCA'd...

  24. comment
    Comment #32513424

    Avanan had reported seeing this exploited by hackers back in July. https://www.avanan.com/blog/sending-phishing-emails-from-pay...

  25. comment
    Comment #32382053

    This, as others have pointed out via tweets and Tutanota themselves acknowledging the technicality on Reddit, is why I couldn't report on it (we received the blog from them too) an…