Viewing profile — keisborg
keisborg
HN member- Joined
- Wed, Jan 01, 2025, 4:25 PM UTC
- HN karma
- 40
- Public activity
- 24 items
- HN profile
- View on Hacker News ↗
About keisborg
No profile information was provided.
Recent public activity
-
comment
Comment #44699741
One step closer to container breakout? Gaining root access give you a bigger attack surface for kernel exploits.
-
comment
Comment #44380724
I cannot answer for all the program owners, but I imagine that there are other concerns than reproducibility
-
comment
Comment #44379364
The policies states it’s not allowed to use automated tools, not to submit report using automated tools alone. Human review does not really change that.
-
comment
Comment #44378064
«XBOW submitted nearly 1,060 vulnerabilities. All findings were fully automated, though our security team reviewed them pre-submission to comply with HackerOne’s policy on automate…
-
comment
Comment #44016437
I looked through most of the charts, and I it seems like you cannot get the best of two worlds. Can you get good edge retention, ease of sharpening and toughness at the same time? …
-
comment
Comment #43971680
I love term how it plays on the words and the negative association we have with anti-personell mines If we could have a ban on anti-personell computers…
-
comment
Comment #43811022
I get a cloudflare puzzle when I try to visit this link :(
-
comment
Comment #43801507
Ed Martin seems like a SME when he himself has been influenced by foreign agencies and spoke their case.
-
comment
Comment #43538088
Link is paywalled. Not possible to read
-
comment
Comment #43479729
We do not know why you are in jail, but because you are in jail you must have done something bad. We cannot just let bad people roam freely
-
comment
Comment #43408691
We all are
-
comment
Comment #43337969
So, they are basically saying that bash is vulnerable to arbitrary command execution?
-
comment
Comment #43337789
I would hope so, but on Tarlogics blog post, it is mentioned “modifying chips arbitrarily”, “infecting chips with malicious code”, “obtain confidential information stored on them”.…
-
comment
Comment #43336919
It it possible to create firmware that is encrypted and cannot be read out. Espressif state there is no security issues, but I have a feeling that these debug commands may be used …
-
comment
Comment #43299742
There was someone that figured out how to detect if the output was piped or not to bash on the webserver, can consider the fact and chose to be malicious or not
-
comment
Comment #43293075
My understanding of the article is that it was about shutting down the program that keeps the nuclear navy afloat, not about a backdoor with a switch to turn off the arsenal
-
comment
Comment #43251106
Yeah, it says it will create an SVG in seconds, but seconds later, there is no SVG. Did not occur to me that I had to log in, but probably won’t as I cannot be bothered to follow b…
-
comment
Comment #43132638
I feel that dockerhub no longer can be the steward for the default docker repo because of this and the limitations they previously have implemented. It is time for them to hand ove…
-
comment
Comment #43126246
Exactly this. And when a base image has a new release, all images based on this will also need an update
-
comment
Comment #43125986
It is not immediately clear to me if the limit is per repo/package or globally in the hub. For instance, I fear it will not be possible to add a new kubernetes node to my cluster w…
-
comment
Comment #42862021
An old trick is to add a page to the robots disallow list, but the page should also be findable by crawlers. If a bot visits this page, you know it’s a bad actor.
-
comment
Comment #42750728
Sounds like a job for nepenthes: https://news.ycombinator.com/item?id=42725147
-
comment
Comment #42750706
Monitor access logs for links that only crawlers can find. Edit: oh, I got your point now.
-
comment
Comment #42566986
I am curious of up to which level this manual is sound and become crazy