Live data from Hacker News

Viewing profile — keisborg

keisborg

HN member
Joined
Wed, Jan 01, 2025, 4:25 PM UTC
HN karma
40
Public activity
24 items

About keisborg

No profile information was provided.

Recent public activity

  1. comment
    Comment #44699741

    One step closer to container breakout? Gaining root access give you a bigger attack surface for kernel exploits.

  2. comment
    Comment #44380724

    I cannot answer for all the program owners, but I imagine that there are other concerns than reproducibility

  3. comment
    Comment #44379364

    The policies states it’s not allowed to use automated tools, not to submit report using automated tools alone. Human review does not really change that.

  4. comment
    Comment #44378064

    «XBOW submitted nearly 1,060 vulnerabilities. All findings were fully automated, though our security team reviewed them pre-submission to comply with HackerOne’s policy on automate…

  5. comment
    Comment #44016437

    I looked through most of the charts, and I it seems like you cannot get the best of two worlds. Can you get good edge retention, ease of sharpening and toughness at the same time? …

  6. comment
    Comment #43971680

    I love term how it plays on the words and the negative association we have with anti-personell mines If we could have a ban on anti-personell computers…

  7. comment
    Comment #43811022

    I get a cloudflare puzzle when I try to visit this link :(

  8. comment
    Comment #43801507

    Ed Martin seems like a SME when he himself has been influenced by foreign agencies and spoke their case.

  9. comment
    Comment #43538088

    Link is paywalled. Not possible to read

  10. comment
    Comment #43479729

    We do not know why you are in jail, but because you are in jail you must have done something bad. We cannot just let bad people roam freely

  11. comment
    Comment #43408691

    We all are

  12. comment
    Comment #43337969

    So, they are basically saying that bash is vulnerable to arbitrary command execution?

  13. comment
    Comment #43337789

    I would hope so, but on Tarlogics blog post, it is mentioned “modifying chips arbitrarily”, “infecting chips with malicious code”, “obtain confidential information stored on them”.…

  14. comment
    Comment #43336919

    It it possible to create firmware that is encrypted and cannot be read out. Espressif state there is no security issues, but I have a feeling that these debug commands may be used …

  15. comment
    Comment #43299742

    There was someone that figured out how to detect if the output was piped or not to bash on the webserver, can consider the fact and chose to be malicious or not

  16. comment
    Comment #43293075

    My understanding of the article is that it was about shutting down the program that keeps the nuclear navy afloat, not about a backdoor with a switch to turn off the arsenal

  17. comment
    Comment #43251106

    Yeah, it says it will create an SVG in seconds, but seconds later, there is no SVG. Did not occur to me that I had to log in, but probably won’t as I cannot be bothered to follow b…

  18. comment
    Comment #43132638

    I feel that dockerhub no longer can be the steward for the default docker repo because of this and the limitations they previously have implemented. It is time for them to hand ove…

  19. comment
    Comment #43126246

    Exactly this. And when a base image has a new release, all images based on this will also need an update

  20. comment
    Comment #43125986

    It is not immediately clear to me if the limit is per repo/package or globally in the hub. For instance, I fear it will not be possible to add a new kubernetes node to my cluster w…

  21. comment
    Comment #42862021

    An old trick is to add a page to the robots disallow list, but the page should also be findable by crawlers. If a bot visits this page, you know it’s a bad actor.

  22. comment
    Comment #42750728

    Sounds like a job for nepenthes: https://news.ycombinator.com/item?id=42725147

  23. comment
    Comment #42750706

    Monitor access logs for links that only crawlers can find. Edit: oh, I got your point now.

  24. comment
    Comment #42566986

    I am curious of up to which level this manual is sound and become crazy