Live data from Hacker News

Viewing profile — dagrz

dagrz

HN member
Joined
Mon, Jun 20, 2011, 4:21 AM UTC
HN karma
76
Public activity
39 items

About dagrz

No profile information was provided.

Recent public activity

  1. comment
    Comment #40532243

    Author here. There's no complaint. It's an observation rather than an absolute good or bad. It's something you have the consider in designing your application.

  2. story
  3. comment
    Comment #39283911

    How would you feel if an attacker could read your AWS resource tags? Turns out they can! We’ve found a way to enumerate various metadata from public resources and created a tool to…

  4. story
  5. story
  6. comment
    Comment #37045368

    Author here. There's been a lot of great work recently on hacking Github-AWS OIDC integrations but I've think we've undersold how bad it is. Here's my guide to finding all the vuln…

  7. story
  8. story
  9. comment
    Comment #11258045

    I feel like Secure Code Warrior has solved this problem much better with gamification. https://www.securecodewarrior.com/

  10. comment
    Comment #5769697

    This applies to everything you do which depends on review. Want a particular job? Put in more effort than everyone else. Create a ‘I want to work for you’ website. Be prepared at t…

  11. comment
    Comment #5631734

    Author here - As an information security manager at a large organisation, this scares me. As much as we train our users and put governance structures in place to help them do the r…

  12. story
  13. comment
    Comment #4942227

    This is awesome. I don't know much about typography but every time I try to learn something, I give up pretty quickly because of the overwhelming amount of (boring) information. I …

  14. story
  15. comment
    Comment #4652758

    Is it me or does the author of this article, and the abusers of the exploits he writes about, land on the wrong side of both the law and common morality? Surely EA being a "terribl…

  16. story
  17. comment
    Comment #4391014

    Whenever I see a new post about this saga I feel compelled to post this mini documentary about it before everyone gets into the same old arguments. Sex, Lies and Julian Assange htt…

  18. story
  19. comment
    Comment #4364321

    You are pointing your anger in the wrong direction. The reality is that security is a hard problem, much too hard for Blizzard, much too hard for RSA, much too hard for banks, and …

  20. story
  21. story
  22. comment
    Comment #4280155

    For the scenerio you mentioned, just having the login/comment submissions work over SSL results in zero added security. In short, this is because of tools such as SSL strip. A bett…

  23. comment
    Comment #4260265

    There are a few people who blog about some great ideas they have. Check out the one by Bosco Tan at http://boscotan.tumblr.com/

  24. story
  25. story