Viewing profile — entuno
entuno
HN member- Joined
- Tue, Jul 04, 2023, 8:56 PM UTC
- HN karma
- 1,074
- Public activity
- 217 items
- HN profile
- View on Hacker News ↗
About entuno
No profile information was provided.
Recent public activity
-
comment
Comment #48725182
In most cases I'd think it's more of a deterrent for commercial entities, because spending money create complexity. Most employees are not in a position to just directly spend thei…
-
comment
Comment #48658249
There's an assumption in here that every developer is spending a load of money on the latest and most capable LLMs to scan for bugs in their code before every release. But the last…
-
comment
Comment #48658179
There is a history of companies and organisations threatening legal action against security researchers when they report vulnerabilities in their systems or products. Sometimes eve…
-
comment
Comment #48658147
If I've stumbled across what I think is a security issue in your systems, there is zero chance that I'm going to get out my credit card and pay you for the privilege of responsibly…
-
comment
Comment #48644550
Historically there have been vulnerabilities in various applications due to HTTP method tampering, and in the days of people accidentally leaving WebDAV enabled then methods like P…
-
comment
Comment #48644381
AWS CloudFront blocks GET requests with a body, so it doesn't even have to be a particularly strict setup or an explicit WAF.
-
comment
Comment #48553652
It would be very dependent on the exact circumstances - who made a complaint, what exactly they're accusing you of, what evidence there is, how high profile it is, the current dipl…
-
comment
Comment #48553267
Legally speaking, no - it would still be a criminal offence. Practically speaking, there is zero chance that the USA would extradite someone to Iran, even if they weren't currently…
-
comment
Comment #48529660
The Daily Mail is a trashy tabloid, so it's not surprising. Weird to see it posted here as though it's a credible source for anything.
-
comment
Comment #48492343
They can be pretty shitty if you're a pedestrian or cyclist, because quite a lot of them don't "see" you, so you just get blinded by the full beams.
- story
-
comment
Comment #47989616
There's been a lot of nice quality of life changes in the 3.7 builds (which has now become 5.0.0) that make going back to the older versions a bit painful. Also some pretty major g…
-
comment
Comment #47822905
Against the Storm (and excellent rouguelite city-builder) does this in a really cool way. Pausing is a core mechanic of the game, and you frequently pause while you place building …
-
comment
Comment #47780394
> The reason that the rich were so rich, Vimes reasoned, was because they managed to spend less money. The "boots" item feels less true, because expensive doesn't seem to be as cor…
-
comment
Comment #47780288
Expensive doesn't guarantee high quality, but very cheap almost always means low quality. A £200 pair of boots might be great and last for a decade, or might be overpriced and fall…
-
comment
Comment #47767347
Financial costs won't solve the problem for companies, because they're hard to enforce. You'd be weighting up the cost of dealing with the fallout of getting hacked against the cos…
-
comment
Comment #47764573
Plus it gives the ransomware gangs a whole new angle they can use. So, remember how you illegally paid us a ransom a few months ago? Unless you want to go to prison, then you bette…
-
comment
Comment #47764288
It's one of those ideas that sounds nice in theory, but doesn't survive contact with the real world. In the same way that many people would say that you shouldn't negotiate with te…
-
comment
Comment #47165891
I've also seen roads that have these kind of signs, but they only apply during busy hours. However, as with any traffic controls they're useless if they're not actually enforced. W…
-
comment
Comment #47139695
If that'd been the design from the start, then sure. But it's not at all obvious that setHTML is safe with arbitrary user input (for a given value of "safe") and innerHTML is dange…
-
comment
Comment #47139636
It's certainly an improvement over people trying to homebrew their own sanitisers. But that distinction of being XSS-safe is a potentially subtle one, and could end up being danger…
-
comment
Comment #47136906
This kind of thing always makes me nervous, because you end with a mix of methods where you can (supposedly) pass arbitrary user input to them and they'll safely handle it, and met…
-
comment
Comment #47089925
And that it took this long to get an answer to that question.
-
comment
Comment #47001733
"Critical security fixes may be evaluated on a case-by-case basis" didn't exactly give much confidence that they'd even be doing that.
-
comment
Comment #46991956
And hopefully they're the same four same bullet points..