Live data from Hacker News

Viewing profile — shellcromancer

shellcromancer

HN member
Joined
Tue, Oct 08, 2019, 10:01 PM UTC
HN karma
95
Public activity
11 items

About shellcromancer

Security Engineer @ tech companies.

https://shellcromancer.io

Recent public activity

  1. comment
    Comment #48660641

    Probably obvious but still omitted in the OpenAI post: chips are being made by TSMC [1]. Wasn't sure if Intel got it. 1. https://www.investing.com/news/stock-market-news/openai-unv…

  2. comment
    Comment #46852520

    > Additionally, the XML returned by the update server is now singed (XMLDSig) The latest and greatest cryptography powering everyone’s favorite SAML-based single-sign on.

  3. story
  4. comment
    Comment #43988343

    The FIDO Alliance (who wrote the WebAuthn spec with the W3C) has a draft specification for a format (Credential Exchange Format) and protocol (Credential Exchange Protocol) for mig…

  5. comment
    Comment #43375239

    Security Cryptography Whatever’s take on this week SAML non-sense will be fun.

  6. story
  7. comment
    Comment #41438457

    Fantastic research by NinjaLab. One of the most interesting parts to me from Yubico's advisory is that the Webauthn protocols attestation [1] is also defeated by this local cloning…

  8. comment
    Comment #39551321

    > The where operator will validate that the syntax is valid, but it will pass unknown function calls through to the underlying database. In RunReveal's case, we use Clickhouse unde…

  9. comment
    Comment #35528922

    Shameless self-plug for an alternative tax that affects operational security and reliability teams: https://audit-logs.tax Understanding how your breach impacts me, or detecting ho…

  10. story
  11. comment
    Comment #33779276

    Regardless of where it's rolled out first, this is a good example of reducing the attack surface from remote exploits (which China is known to have and use at contests like Tianfu …