Viewing profile — harmon
harmon
HN member- Joined
- Sun, Mar 21, 2021, 8:58 PM UTC
- HN karma
- 88
- Public activity
- 38 items
- HN profile
- View on Hacker News ↗
About harmon
No profile information was provided.
Recent public activity
-
comment
Comment #45210754
Fine, Kerberoasting abuses TGS-REPs which are colloquially referred to as TGS tickets or TGSs*. You know what I meant.
-
comment
Comment #45201029
> It's wild to me that this could happen just from solving the puzzle that allows the user's account to use the user's privileges (only) on the service... ? Yes, it is an unfortuna…
-
comment
Comment #45199026
If you have the user's credentials then you can indeed connect to the service as you normally would. The advantages of performing this attack are: 1. You can obtain the service acc…
-
comment
Comment #45197924
Managed and group managed service account passwords are typically 240 characters long and rotate every 30 days. It is highly unlikely that an attacker can crack these.
-
comment
Comment #45197587
This article is somewhat incorrect. Kerberoasting abuses Ticket Granting Service tickets (TGSs, which are used to request access to a registered service in Active Directory), not T…
-
comment
Comment #43832897
As these tariffs are objectively likely to drive up costs, hurt user demand, and lower revenue for the company, I would argue that they have a duty to their shareholders and other …
-
comment
Comment #40981496
As I understand it, you can only write off a business's expenses against that business's income, not income from other sources. For example, if you have a W2 income source and you …
- comment
-
comment
Comment #38088620
I agree, honestly I feel a much better solution to this problem would be to extend the same tax advantages that you allude to when talking about a personal company to W2 employees.…
- story
-
comment
Comment #34811438
Mass surveillance is out of control as you say, and I am a strong proponent of reigning in warrantless wiretaps and governmental overreach. However, as many people have stated, a p…
-
comment
Comment #34666541
So I used to be in a very similar boat as you: I was depressed while working towards a STEM degree in college and ended up almost failing out with a 2.X GPA. I didn't see a path fo…
- comment
-
comment
Comment #31996208
Ultimately if users are satisfied and happy, does it even matter if it is fake? The end goal is not to create a real relationship, it is to create a happy fantasy for the buyer.
-
comment
Comment #31977622
> The endless pursuit of growth is usually a byproduct of ego or at the behest of some intangible idea of "creating shareholder value." If you don't want to grow that's fine, but t…
-
comment
Comment #31960151
The existence of an "active" God as portrayed in most religions would complicate things tremendously though. If an entity can inject energy into the system or can alter system prop…
-
comment
Comment #31954058
Even if you only take courses that aren't wastes of time, there just isn't that much to do on a typical day. I remember when I was in school I was taking something like 5 AP course…
-
comment
Comment #31900506
> Hot take: It’s fine when it happens to extreme hubris with paper wealth. It is not fine when it was someone unsophisticated chasing the herd who lost a meager sum that was meanin…
-
comment
Comment #31899210
Exactly this. Every project is going to impact the environment. The end goal of a risk assessment is not to bring the environmental risk to zero, it is to bring it down to an accep…
- comment
-
comment
Comment #31885149
The story in the article was completely preventable if banks just tried harder. The default 2FA solution should be Google authenticator or an analogous tech. If SMS MUST be used, i…
- comment
- comment
- story
- comment