Live data from Hacker News

Viewing profile — pipeline_tux

pipeline_tux

HN member
Joined
Tue, Oct 12, 2010, 10:34 AM UTC
HN karma
82
Public activity
33 items

About pipeline_tux

No profile information was provided.

Recent public activity

  1. comment
    Comment #38046754

    I haven't tested with either of those unfortunately, but I do regularly test when connected to a VPN using OpenVPN. From a PC/Mac, if you can reconfigure your browser to proxy traf…

  2. comment
    Comment #38044058

    Thanks for the kind words and feedback! There should be a real-time table when you're running a scan so that sounds like a bug. Having a real-time table is surprisingly light on re…

  3. comment
    Comment #38043171

    Thanks for the suggestion. I've added it to the todo list.

  4. comment
    Comment #38043128

    Hi! Yeah, it seems like we've identified similar problems and addressed them in reasonably similar ways. Likewise, I've went with SQLite as the project file format, with the files …

  5. comment
    Comment #38042722

    Thanks! Yeah, it was definitely an ambitious choice, but I think it results in a better product, and I'm really happy with how it's turning out. For now it's just me part time, but…

  6. comment
    Comment #38042497

    Usability and performance (for example when deployed on lower-end customer machines) are two major ones. Admittedly they have been getting better over time. It's also not uncommon …

  7. comment
    Comment #38042397

    No, it doesn't unfortunately. In a professional testing world, we'd normally just ask clients nicely to disable that for our testing. If you're testing something where you don't ha…

  8. comment
    Comment #38042343

    Correct. Burp is the main competitor, but it's been around a long time and I wanted to develop something from scratch to address a number of the problems myself and other pentester…

  9. comment
    Comment #38042063

    Thanks! The tool has a built in certificate authority (CA) to generate TLS certificates. So to intercept TLS traffic from a phone, you export the CA's root certificate and import i…

  10. comment
    Comment #38040992

    Correct, ZAP is one of the main competitors, and the core functionality is the same. While there's a browser Head-up Display, the primary UI is still a Java desktop-based applicati…

  11. comment
    Comment #38040898

    Thanks! There's a few points of difference in terms of approach/philosophy. Firstly, I really wanted to focus on usability. So there's a native UI on each platform, using GTK on Li…

  12. story
    Show HN: Pākiki Proxy – An intercepting proxy for penetration testing

    Hey HN, I've been working on an intercepting proxy for penetration testing over the last few years in my spare time. Some points of difference from the existing tools: * The UIs ar…

  13. comment
    Comment #12230936

    Torrents are filling the gap where the traditional media companies are still failing. Here in NZ there are 7 different streaming services that I can immediately think of, each with…

  14. comment
    Comment #10917265

    As someone who works in infosec, this doesn't surprise me at all. I've tested many applications which claim to be secure, designed for security/privacy sensitive tasks, yet are ver…

  15. comment
    Comment #6552421

    The OWASP testing guide is a very good start: https://www.owasp.org/images/5/56/OWASP_Testing_Guide_v3.pdf It covers the process of a web application test and explains 90% of the v…

  16. comment
    Comment #3476218

    I'm sure that the 911 operator won't mind, especially if it is or could be a genuine emergency.

  17. comment
    Comment #2958801

    In which case the NSA say "Oops, it was a genuine mistake. Sorry." With 200,000 lines of code, there will almost certainly be unintentional security holes that haven't been found.

  18. comment
    Comment #2958280

    I don't necessarily think there will be one, but I wouldn't be surprised either. Security flaws can be extremely subtle and 200,000 lines of code is a lot to review... Given that t…

  19. comment
    Comment #2699970

    They provide a list of backup codes which you're meant to print and put in your wallet.

  20. comment
    Comment #2598089

    > My reading is that you couldn't brute force it, you'd have one chance to set up the iframe with the cookie file in it which needs the username, or at least just one chance per cl…

  21. comment
    Comment #2597491

    > Cookiejacking Exploit Hits Internet Explorer, Targets Your Login Info This makes it sound like they're going to be able to get your password... No major website will be storing y…

  22. comment
    Comment #2519329

    Mine cost me nothing. I got some wood scraps from a local kitchen factory and built a couple of tables, at the right height, to stand on top of my standard desk.

  23. comment
    Comment #2426156

    Yep, that's pretty much how they work. I can't find the details of it now, but the "smart" ones also do some colour transformations on the image so detection will work irrespective…

  24. comment
    Comment #2422810

    Relatively... The browsers themselves won't write anything to disk but this doesn't stop things like plugins (EG: Flash, Java, media players, etc) from writing to disk, or lower le…

  25. comment
    Comment #2422634

    You'd be surprised at what your web browser and operating system cache... That one session where you forgot to switch to incognito mode could leave hundreds of images on the hard d…