Live data from Hacker News

Viewing profile — harmon

harmon

HN member
Joined
Sun, Mar 21, 2021, 8:58 PM UTC
HN karma
88
Public activity
38 items

About harmon

No profile information was provided.

Recent public activity

  1. comment
    Comment #45210754

    Fine, Kerberoasting abuses TGS-REPs which are colloquially referred to as TGS tickets or TGSs*. You know what I meant.

  2. comment
    Comment #45201029

    > It's wild to me that this could happen just from solving the puzzle that allows the user's account to use the user's privileges (only) on the service... ? Yes, it is an unfortuna…

  3. comment
    Comment #45199026

    If you have the user's credentials then you can indeed connect to the service as you normally would. The advantages of performing this attack are: 1. You can obtain the service acc…

  4. comment
    Comment #45197924

    Managed and group managed service account passwords are typically 240 characters long and rotate every 30 days. It is highly unlikely that an attacker can crack these.

  5. comment
    Comment #45197587

    This article is somewhat incorrect. Kerberoasting abuses Ticket Granting Service tickets (TGSs, which are used to request access to a registered service in Active Directory), not T…

  6. comment
    Comment #43832897

    As these tariffs are objectively likely to drive up costs, hurt user demand, and lower revenue for the company, I would argue that they have a duty to their shareholders and other …

  7. comment
    Comment #40981496

    As I understand it, you can only write off a business's expenses against that business's income, not income from other sources. For example, if you have a W2 income source and you …

  8. comment
  9. comment
    Comment #38088620

    I agree, honestly I feel a much better solution to this problem would be to extend the same tax advantages that you allude to when talking about a personal company to W2 employees.…

  10. story
  11. comment
    Comment #34811438

    Mass surveillance is out of control as you say, and I am a strong proponent of reigning in warrantless wiretaps and governmental overreach. However, as many people have stated, a p…

  12. comment
    Comment #34666541

    So I used to be in a very similar boat as you: I was depressed while working towards a STEM degree in college and ended up almost failing out with a 2.X GPA. I didn't see a path fo…

  13. comment
  14. comment
    Comment #31996208

    Ultimately if users are satisfied and happy, does it even matter if it is fake? The end goal is not to create a real relationship, it is to create a happy fantasy for the buyer.

  15. comment
    Comment #31977622

    > The endless pursuit of growth is usually a byproduct of ego or at the behest of some intangible idea of "creating shareholder value." If you don't want to grow that's fine, but t…

  16. comment
    Comment #31960151

    The existence of an "active" God as portrayed in most religions would complicate things tremendously though. If an entity can inject energy into the system or can alter system prop…

  17. comment
    Comment #31954058

    Even if you only take courses that aren't wastes of time, there just isn't that much to do on a typical day. I remember when I was in school I was taking something like 5 AP course…

  18. comment
    Comment #31900506

    > Hot take: It’s fine when it happens to extreme hubris with paper wealth. It is not fine when it was someone unsophisticated chasing the herd who lost a meager sum that was meanin…

  19. comment
    Comment #31899210

    Exactly this. Every project is going to impact the environment. The end goal of a risk assessment is not to bring the environmental risk to zero, it is to bring it down to an accep…

  20. comment
  21. comment
    Comment #31885149

    The story in the article was completely preventable if banks just tried harder. The default 2FA solution should be Google authenticator or an analogous tech. If SMS MUST be used, i…

  22. comment
  23. comment
  24. story
  25. comment