Live data from Hacker News

Viewing profile — jeffmcjunkin

jeffmcjunkin

HN member
Joined
Wed, Jan 02, 2013, 4:52 PM UTC
HN karma
1,276
Public activity
82 items

About jeffmcjunkin

Information security professional living in Southern Oregon. Forensics, incident response, and networking interest me most.

Recent public activity

  1. comment
    Comment #48484250

    Confirmed: https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-wor...

  2. comment
    Comment #47785855

    Can confirm. Matching decompilation in particular (where you match the compiler along with your guess at source, compile, then compare assembly, repeating if it doesn't match) is v…

  3. comment
    Comment #47682353

    Can confirm.

  4. story
  5. comment
    Comment #45205367

    I absolutely agree that Microsoft could do better, but they are making progress in removing support entirely for broken (from a security perspective) older protocols such as NTLMv1…

  6. comment
    Comment #45205275

    The RC4 encryption type correlates to the DES hash (more commonly the "NT" hash), so PingCastle has the right warning.

  7. comment
    Comment #45144868

    KeySavvy is the normal workaround for this. $99 extra cost to both sides for them to handle the title verification and shipping, and to act as the dealer to make it qualify for EV …

  8. comment
    Comment #44393710

    Thank you, this was affecting me too.

  9. story
  10. comment
    Comment #43667503

    From https://personal.math.ubc.ca/~CLP/about/ : > For various reasons we have christened these notes “CLP” - none of those reasons can be found [here]( https://en.m.wikipedia.org/w…

  11. comment
    Comment #42029747

    Recently, yes :) https://www.cnn.com/2023/08/06/us/oregon-drivers-pump-own-fu...

  12. comment
    Comment #41638985

    We don't advance as a society unless people ask new questions. Having folk willing to spend some time answering those questions (in public, no less!) helps others. It's really, rea…

  13. comment
    Comment #40503060

    Title needs a small fix, it should be `ping ff02::1` (with two colons) to be a valid IPv6 address, match the actual command, and match the original title.

  14. comment
    Comment #40432526

    FWIW I've heard the term "dark fiber" used in both ways as well. Whenever there's ambiguity in jargon, I just avoid that jargon and use more words to describe the actual concept.

  15. comment
    Comment #39612011

    That helps with "we've encrypted your data; pay us for the key" but doesn't help you with "we've made copies of your patient records, leadership's emails; pay us or we publish it a…

  16. comment
    Comment #39610083

    Sorry, it was alluded to elsewhere: https://infosec.exchange/@iagox86/112045097519922098 There's more to the story that Rapid7 didn't want to air publicly, and none of it is good f…

  17. comment
    Comment #39608289

    Yup, silently patching (like JetBrains did) has a lot of downsides. Let alone the deception from JetBrains to the Rapid7 team. (Disclosure: I know some of the folk on the Rapid7 si…

  18. comment
    Comment #37705670

    For whatever reason, Domain Fronting is considered more of an attack behavior, used by red teamers and penetration testers. Doubling down on that behavior likely didn't seem as app…

  19. comment
    Comment #36947163

    Ahem, that's _9000_.

  20. comment
    Comment #33046573

    Nearly 100% have on-prem AD (full name: "Active Directory: Domain Services"). Azure AD is a separate identity provider -- to a first approximation it's HTTPS and cookies, not Kerbe…

  21. comment
    Comment #33046565

    In contrast, the vast majority of companies with Azure AD also have on-prem AD (full name: "Active Directory: Domain Services") with some type of synchronization between them. Usua…

  22. comment
    Comment #28225851

    Smart cards are essentially a big Secure Enclave themselves. The whole point of a smart card (same as a military CAC, and almost the same as a TPM chip on computers) is to sign ope…

  23. comment
    Comment #27467706

    Title doesn't quite fit, how about this instead? "Privilege escalation with polkit: Rooting Linux with a 7-year-old bug"

  24. comment
    Comment #26160670

    Bugs get patched. Features are protected, and sometimes simultaneously abused. Thank you!

  25. comment
    Comment #25413320

    It strongly implies that the vendor was thoroughly compromised, in order to insert backdoors into their software (possibly amongst other attacker actions).