Live data from Hacker News

Viewing profile — christophetd

christophetd

HN member
Joined
Wed, Jun 07, 2017, 2:19 PM UTC
HN karma
212
Public activity
52 items

About christophetd

https://infosec.exchange/@christophetd

Recent public activity

  1. story
  2. story
  3. story
  4. story
  5. story
  6. story
  7. comment
    Comment #33735696

    The malicious commit (2cd2223dcd90fa9d9c72851427602aa0e179e061) was not signed. Sorry you feel like the writing isn't frank.

  8. comment
    Comment #33735179

    If the maintainer themselves added the backdoor, can't they be considered a malicious actor?

  9. comment
    Comment #33733833

    Yes, that would be caching. We kept the first sentence, as it's still possible his account was compromised (we have no strong evidence to prove it, but no strong evidence to refute…

  10. comment
    Comment #33733793

    Thanks for the heads-up, the goal was mostly avoiding that typing the author's name in Google brings up this post. I'll have it blurred for the sake of consistency, though.

  11. comment
    Comment #33731874

    We just updated the wording. Thanks for the feedback.

  12. comment
    Comment #33731055

    One of the authors of the post here. We prefer sticking to the facts rather than speculating the account was compromised without having a solid proof. Someone on /r/netsec also had…

  13. comment
    Comment #33731014

    Hello! One of the authors of the post here. Just added a sentence in the introduction to make it crystal clear: > While FastAPI itself is not impacted, this is an interesting occur…

  14. comment
    Comment #33730884

    Hello there! I'm one of the authors of the post. Sorry you feel we "hyped it up", that was definitely not the intent. The malicious package is targeting FastAPI applications. The p…

  15. story
  16. story
  17. story
  18. story
  19. comment
    Comment #33188365

    Author here - have a look at the methodology section at the bottom of the page. Feel free to ask if anything is unclear.

  20. comment
    Comment #33188355

    Author here - sorry you feel like this is content marketing. I identify myself as a cloud security engineer, so that's a clear antigoal. The intent is to show what's the systematic…

  21. comment
    Comment #33177665

    Sure. My point is that Trusted Advisor is also a commercial product, as opposed to IAM Access Analyzer which is free.

  22. comment
    Comment #33176825

    One of the authors here - confirming that "40 percent of organizations have at least one IAM user that has AWS Console access and does not have multi-factor authentication" is abou…

  23. comment
    Comment #33175831

    Hello! One of the authors here. We did release some (hopefully) actionable guidance alongside the study[1]. Trusted Advisor is a fair point, but note that most of its security chec…

  24. story
  25. story