Viewing profile — pwman
pwman
HN member- Joined
- Sat, Sep 04, 2010, 3:43 AM UTC
- HN karma
- 132
- Public activity
- 60 items
- HN profile
- View on Hacker News ↗
About pwman
Recent public activity
-
comment
Comment #18984020
This has been the case since at least 2003... The agents also see you page history, search terms, can cobrowse with you to show you things. Anything to make them quicker and more e…
-
comment
Comment #16115559
Have you had your levels checked by your doctor? My doctor said I was low for a year, as they came up I started sleeping much better -- can't see many other differences.
-
comment
Comment #15455110
That's not how AppArmor works provided you lock down your server software properly -- say the server running is NTP -- that NTP server is only able to read /etc/ntp/* and /usr/sbin…
-
comment
Comment #14469487
LastPass
-
comment
Comment #13943693
A request to https://1min-ui-prod.service.lastpass.com was necessary to attack this, that request has a referring URL sent by default by Chrome / Firefox / Safari.
-
comment
Comment #13706540
Considering your size you should definitely checkout a trial of LastPass Teams: https://www.lastpass.com/teams Full Disclosure: Work for LastPass
- story
-
comment
Comment #10921606
Interesting, I hadn't heard of Password Alert -- we should definitely share notes if you're open to it -- I'd love to be able to generalize what we're doing to other domains if we …
-
comment
Comment #10919876
Yes, we're pushing the notification to a new tab (which can't be blocked or interfered with) once it goes through QA -- likely early next week. Also even multifactor now must be ne…
-
comment
Comment #10917801
LastPass has pushed Google for years to give us a way to avoid using the browser viewport: infobars was a solution to this issue -- you can see one of my pleas for it back in Janua…
-
comment
Comment #10844749
LastPass doesn't have access to your symmetric key, it doesn't have access to your private RSA key either. It's all locally encrypted and locally generated. LastPass does have acce…
-
comment
Comment #10783930
Washington DC has been doing it as long as I can remember: https://en.wikipedia.org/wiki/Slugging Basically pickup someone random so you can utilize HOV.
-
comment
Comment #10702657
Heartbleed showed us that many certificate authorities reissue certificates from the original date they were first issued.
-
comment
Comment #10502846
LastPass has AD Sync capability and has for years with large customers using it: https://enterprise.lastpass.com/enterprise-administration-ba...
-
comment
Comment #10443200
Some of your sites are storing your password in plain text, see http://plaintextoffenders.com/ for a few. Once a single one of those is hacked your method is exposed and it goes fr…
-
comment
Comment #10253917
Yes, but it's after 100,000 rounds of PBKDF2.
-
comment
Comment #10220397
Understood -- you may want to consider a combination open source command line version + mobile + mac apps: https://github.com/LastPass/lastpass-cli If your coworkers aren't using s…
-
comment
Comment #10220369
In fact LastPass didn't have it at first, but after dozens of impassioned pleas from people with disabilities we made the decision to add it with a very strong warning against usin…
-
comment
Comment #10218551
Full Disclosure: I work at LastPass. > "Turning on 2FA did not worked most of the times" If you have a security issue here we'd appreciate a report at https://lastpass.com/security…
-
comment
Comment #10040840
Mozilla used to be the best place in the world for extension developers -- it was natural to have your best extension on Firefox because you could release early and often. Active d…
-
comment
Comment #9444358
Correct -- It's a pet peeve of mine when login processes obscure this saying invalid password when the sign up process doesn't -- if you're going to tell people usernames aren't av…
-
comment
Comment #8545195
LastPass - https://LastPass.com/jobs - Fairfax, VA (DC metro, Dunn Loring metro stop) Our open tech roles are: - Software Engineer iOS - Software Engineer OSX - Junior Software Eng…
-
comment
Comment #8117183
How are LastPass' organization features broken? Over 7,500 companies are using them successfully. https://enterprise.lastpass.com/enterprise-administration-ba...
-
comment
Comment #8023968
It's not a 'we let them publish' it's a we respected their wishes in that we would hold off on talking about it until they published.
-
comment
Comment #8023963
If we stole the thunder from security researchers by announcing about things they've found before they can we'd risk that they'd consider holding back. I feel it's the right move t…