Viewing profile — bdelay
bdelay
HN member- Joined
- Mon, Aug 15, 2016, 2:59 PM UTC
- HN karma
- 240
- Public activity
- 27 items
- HN profile
- View on Hacker News ↗
About bdelay
No profile information was provided.
Recent public activity
-
comment
Comment #42023644
How much notification did you give the developers before you disclosed? Did you enforce a timeline?
-
comment
Comment #36456307
If you're new, it's the same advice as any other field. Find a way to stand out. Build a portfolio, have great grades, come from a good university program, ping contacts from your …
-
comment
Comment #36456192
It looks like you made the best of a frustrating situation and, at the very least, have an excellent piece for your portfolio. With the rise in number of new security engineers all…
-
comment
Comment #22720914
I took Seacord's virtual class (CMU SEI? Can't remember) on Secure C coding a few years back and own, love, and regularly use the The CERT C Secure Coding Standard. I learned from …
-
comment
Comment #19657079
See the Note from Harman section. Hence, as the check wasn't working, I never ran into the check. Dat file signatures may very well be in the header or stored somewhere else.
-
comment
Comment #19653846
Thanks! I wish there was a service I could pay for where I could ask lawyers vague security-research related questions like this. Right now I wouldn't even know where to begin look…
-
comment
Comment #19653580
Not sure. Have an extra Tesla you can send me?
-
comment
Comment #19653507
Okay, that's really cool. Tempted to see if I can get some AWS credits or spend a bit of cash and throw an 8xGPU instance at this for a few days...
- comment
-
comment
Comment #19653244
Never assume anything. Well done. :)
-
comment
Comment #19653184
I agree, but I don't have a consulting-firm/reputation/team of lawyers etc. to hide behind. Reporting flaws to companies related to embedded is often still scary today. The point o…
-
comment
Comment #19653121
You are correct. I don't believe those accounts worked over ssh due to a lack of password, just local serial.
-
comment
Comment #19653109
Two reasons I didn't do that: 1. I believe Harman had a previous device hacked back around 2014 due to a weak shadow hash. My guess was that they learned their lesson and made the …
- comment
- story
-
comment
Comment #18441241
My guess is that yes, absolutely, but very few people know about it / a Doctor or nurse was blamed. Medical system security does not seem very good. When I was operating in the are…
- comment
-
comment
Comment #17450338
Just read the r7800 had the best range for an all-in-one unit. Not sure if it's true, but it has been an amazing router. I picked one up for myself -- they are 130$ refurbished on …
-
comment
Comment #17450005
Parents live in a smaller town with two awful ISP selections. They had a bunch of WiFi devices on an ISP router and the connection quality and latency was just terrible when more t…
- story
-
comment
Comment #15639330
Well done to the author. I always found working on more obscure systems to be a lot more entertaining as a hobby and I'd definitely recommend it -- you'll almost never run into the…
-
comment
Comment #13867200
I don't think anyone with experience hacking kindles believed it was a permanent solution. Unfortunately, most of the technical expertise in that area is fleeting. I'd recommend an…
-
comment
Comment #12294268
I don't believe Amazon officially pays for security flaws. They ended up sending me a free Kindle (pretty funny) and got an interview out of it. That didn't end up going anywhere, …
-
comment
Comment #12293500
Started out cracking software on embedded systems a long time ago. That led to an understanding of ASM and reverse engineering. Going from there to exploitation isn't a giant leap.…
-
comment
Comment #12291564
Correct. At the time, this worked on the Paperwhite 2, 3, Voyage, and Touch. Forgot which version of the touch, they update that one a lot. I'll try to clarify that a bit better wh…