Live data from Hacker News

Viewing profile — infotogivenm

infotogivenm

HN member
Joined
Sun, Oct 07, 2018, 2:34 PM UTC
HN karma
467
Public activity
179 items

About infotogivenm

No profile information was provided.

Recent public activity

  1. comment
    Comment #42530515

    source integrity is probably the more applicable feature for gp’s concerns

  2. comment
    Comment #40846289

    > Nah I don’t get it then… Do you never end up having to privesc in your pentests on linux systems? No doubt it depends on customer profile but I would guess personally on at least…

  3. comment
    Comment #40846134

    Think “illegitimate” access to www-data. It’s very common on linux pentests to need to privesc from some lower-privileged foothold (like a command injection in an httpd cgi script)…

  4. comment
    Comment #40305064

    Fidelity, who remains a stakeholder in the private company and gets insight to internal financials, has cut the valuation of their holding by 75% so far [1]. While twitter might no…

  5. comment
    Comment #40219470

    Em, that seems an extremely generous comparison, where did you come up with that? Last I checked for example systemd relies on polkit for policies, which drags in a javascript inte…

  6. comment
    Comment #40177845

    I’m surprised no one has written a tool (probably would involve disabling SIP) to import/export passkeys on macOS. They’re in memory, right?

  7. comment
    Comment #39220923

    https://newsletterhunt.com/emails/48880

  8. comment
    Comment #39152723

    Came here to mention this. I used this exact setup (used a laptop battery bank off of amazon as a UPS for my home modem), and came home months later to find the bank had caught fir…

  9. comment
    Comment #38933129

    It is fairly common to have noexec on /dev/shm; filesystem configurations are always up to the admin so they could feasibly set anything.

  10. comment
    Comment #38764875

    One good example is bringing up equipment that comes out-the-box with a default password. This is common on BMCs for example, and you have to initially provision things somehow.

  11. comment
    Comment #38762954

    It’s covered under footnote #1: > First, some vendors make it difficult to associate an SSH key with a user. Then, many vendors do not support certificate-based authentication, mak…

  12. comment
  13. comment
    Comment #38641668

    I’ve noticed the code reader is worthless on even slightly out of date browsers now, and even on newer browsers it tends to choke and stutter on large files. Sad :( it used to be t…

  14. comment
    Comment #38637789

    If you have metadata for a couple of messages it is no longer a needle. Not sure what your point about APNS tokens is - I agree, once they hone in on who received the messages Appl…

  15. comment
    Comment #38626286

    Ah good point, radar/ultrasonics were what I was thinking of, not lidar. Looks like they’re still gone.

  16. comment
    Comment #38626270

    I mean, the current requirement for human attentiveness and intervention probably has something to do with avoiding disaster scenarios.

  17. comment
    Comment #38625949

    I can imagine it could be useful, e.g. if you already have metadata on “dates when user A messaged user B”, and are trying to de-anonymize user B.

  18. comment
    Comment #38625890

    Are they still all-in on “pure vision” self-driving? I thought they had pivoted back to lidar but can’t seem to find any sources for that.

  19. comment
    Comment #38623768

    Correct. Worst rental car experience of my life.

  20. comment
    Comment #38418015

    The point of killing third party cookies is to prevent a tracking identifier cookie that uniquely identifies your browser from being reused across different sites. So you can of co…

  21. comment
    Comment #38417593

    I believe third-party cookies have been blocked on Safari and FF by default for many years

  22. comment
    Comment #38393300

    Can you elaborate? I have not kept up with the eSNI/ECH stuff... How will filtering still be possible?

  23. comment
    Comment #38001680

    What part of the world do you live in? Just curious, I travel very often but have yet to see any convenient way to spend bitcoin everyday.

  24. comment
    Comment #37689729

    the biden laptop story was temporarily banned for less than 24hrs as it violated various twitter rules for hacked content and nudity. The “Twitter Files” ( cue x-files theme ) show…

  25. comment
    Comment #37590258

    Nice. A similar project, but more license-constrained, is fuse-t for macos: https://github.com/macos-fuse-t/fuse-t