Viewing profile — infotogivenm
infotogivenm
HN member- Joined
- Sun, Oct 07, 2018, 2:34 PM UTC
- HN karma
- 467
- Public activity
- 179 items
- HN profile
- View on Hacker News ↗
About infotogivenm
No profile information was provided.
Recent public activity
-
comment
Comment #42530515
source integrity is probably the more applicable feature for gp’s concerns
-
comment
Comment #40846289
> Nah I don’t get it then… Do you never end up having to privesc in your pentests on linux systems? No doubt it depends on customer profile but I would guess personally on at least…
-
comment
Comment #40846134
Think “illegitimate” access to www-data. It’s very common on linux pentests to need to privesc from some lower-privileged foothold (like a command injection in an httpd cgi script)…
-
comment
Comment #40305064
Fidelity, who remains a stakeholder in the private company and gets insight to internal financials, has cut the valuation of their holding by 75% so far [1]. While twitter might no…
-
comment
Comment #40219470
Em, that seems an extremely generous comparison, where did you come up with that? Last I checked for example systemd relies on polkit for policies, which drags in a javascript inte…
-
comment
Comment #40177845
I’m surprised no one has written a tool (probably would involve disabling SIP) to import/export passkeys on macOS. They’re in memory, right?
-
comment
Comment #39220923
https://newsletterhunt.com/emails/48880
-
comment
Comment #39152723
Came here to mention this. I used this exact setup (used a laptop battery bank off of amazon as a UPS for my home modem), and came home months later to find the bank had caught fir…
-
comment
Comment #38933129
It is fairly common to have noexec on /dev/shm; filesystem configurations are always up to the admin so they could feasibly set anything.
-
comment
Comment #38764875
One good example is bringing up equipment that comes out-the-box with a default password. This is common on BMCs for example, and you have to initially provision things somehow.
-
comment
Comment #38762954
It’s covered under footnote #1: > First, some vendors make it difficult to associate an SSH key with a user. Then, many vendors do not support certificate-based authentication, mak…
- comment
-
comment
Comment #38641668
I’ve noticed the code reader is worthless on even slightly out of date browsers now, and even on newer browsers it tends to choke and stutter on large files. Sad :( it used to be t…
-
comment
Comment #38637789
If you have metadata for a couple of messages it is no longer a needle. Not sure what your point about APNS tokens is - I agree, once they hone in on who received the messages Appl…
-
comment
Comment #38626286
Ah good point, radar/ultrasonics were what I was thinking of, not lidar. Looks like they’re still gone.
-
comment
Comment #38626270
I mean, the current requirement for human attentiveness and intervention probably has something to do with avoiding disaster scenarios.
-
comment
Comment #38625949
I can imagine it could be useful, e.g. if you already have metadata on “dates when user A messaged user B”, and are trying to de-anonymize user B.
-
comment
Comment #38625890
Are they still all-in on “pure vision” self-driving? I thought they had pivoted back to lidar but can’t seem to find any sources for that.
-
comment
Comment #38623768
Correct. Worst rental car experience of my life.
-
comment
Comment #38418015
The point of killing third party cookies is to prevent a tracking identifier cookie that uniquely identifies your browser from being reused across different sites. So you can of co…
-
comment
Comment #38417593
I believe third-party cookies have been blocked on Safari and FF by default for many years
-
comment
Comment #38393300
Can you elaborate? I have not kept up with the eSNI/ECH stuff... How will filtering still be possible?
-
comment
Comment #38001680
What part of the world do you live in? Just curious, I travel very often but have yet to see any convenient way to spend bitcoin everyday.
-
comment
Comment #37689729
the biden laptop story was temporarily banned for less than 24hrs as it violated various twitter rules for hacked content and nudity. The “Twitter Files” ( cue x-files theme ) show…
-
comment
Comment #37590258
Nice. A similar project, but more license-constrained, is fuse-t for macos: https://github.com/macos-fuse-t/fuse-t