Viewing profile — dagrz
dagrz
HN member- Joined
- Mon, Jun 20, 2011, 4:21 AM UTC
- HN karma
- 76
- Public activity
- 39 items
- HN profile
- View on Hacker News ↗
About dagrz
No profile information was provided.
Recent public activity
-
comment
Comment #40532243
Author here. There's no complaint. It's an observation rather than an absolute good or bad. It's something you have the consider in designing your application.
- story
-
comment
Comment #39283911
How would you feel if an attacker could read your AWS resource tags? Turns out they can! We’ve found a way to enumerate various metadata from public resources and created a tool to…
- story
- story
-
comment
Comment #37045368
Author here. There's been a lot of great work recently on hacking Github-AWS OIDC integrations but I've think we've undersold how bad it is. Here's my guide to finding all the vuln…
- story
- story
-
comment
Comment #11258045
I feel like Secure Code Warrior has solved this problem much better with gamification. https://www.securecodewarrior.com/
-
comment
Comment #5769697
This applies to everything you do which depends on review. Want a particular job? Put in more effort than everyone else. Create a ‘I want to work for you’ website. Be prepared at t…
-
comment
Comment #5631734
Author here - As an information security manager at a large organisation, this scares me. As much as we train our users and put governance structures in place to help them do the r…
- story
-
comment
Comment #4942227
This is awesome. I don't know much about typography but every time I try to learn something, I give up pretty quickly because of the overwhelming amount of (boring) information. I …
- story
-
comment
Comment #4652758
Is it me or does the author of this article, and the abusers of the exploits he writes about, land on the wrong side of both the law and common morality? Surely EA being a "terribl…
- story
-
comment
Comment #4391014
Whenever I see a new post about this saga I feel compelled to post this mini documentary about it before everyone gets into the same old arguments. Sex, Lies and Julian Assange htt…
- story
-
comment
Comment #4364321
You are pointing your anger in the wrong direction. The reality is that security is a hard problem, much too hard for Blizzard, much too hard for RSA, much too hard for banks, and …
- story
- story
-
comment
Comment #4280155
For the scenerio you mentioned, just having the login/comment submissions work over SSL results in zero added security. In short, this is because of tools such as SSL strip. A bett…
-
comment
Comment #4260265
There are a few people who blog about some great ideas they have. Check out the one by Bosco Tan at http://boscotan.tumblr.com/
- story
- story