Live data from Hacker News

Viewing profile — stonepresto

stonepresto

HN member
Joined
Mon, Nov 13, 2017, 8:35 PM UTC
HN karma
267
Public activity
113 items

About stonepresto

hecks

Recent public activity

  1. story
  2. story
  3. comment
    Comment #48168569

    Related https://news.ycombinator.com/item?id=48157559 Someone in the comments linked this post from 2015 talking about the Cyber Grand Challenge this post mentions, it's an interes…

  4. comment
    Comment #44091450

    Well, in another subthread the author said he did in fact make a crashing PoC. I guess it depends on the customer's standards, but I would say in the vast majority of cases (especi…

  5. comment
    Comment #44087972

    I'm too much of a skeptic to not do so lol. Great post though overall, don't let my assholery dissuade you! I was pleasantly surprised that it was actually a researcher behind the …

  6. comment
    Comment #44087780

    Thank you! I'm really happy to hear you did that. But why not mention that in your blog post? I understand not wanting to include a PoC for responsible disclosure reasons, but incl…

  7. comment
    Comment #44087751

    PoCs should at least trigger a crash, overwrite a register, or have some other provable effect, the point being to determine: 1) If it is actually a UAF or if there is some other m…

  8. comment
    Comment #44086809

    I know there were at least a few kernel devs who "validated" this bug, but did anyone actually build a PoC and test it? It's such a critical piece of the process yet a proof of con…

  9. comment
  10. comment
    Comment #38700372

    The part of the prompt that suggests its the 15th of December is a GET param, which just means wherever this link was retrieved from is where that date is coming from. The PDF coul…

  11. story
  12. comment
    Comment #38572392

    Agreed. I think their bottom line probably is built off of how it would affect their user base. My hunch is given the immensity of the user base, it wouldn't cause enough of a sign…

  13. comment
    Comment #38568760

    What's to stop them from having hooks in their app that can bundle up all the decrypted messages, re-encrypt, and phone home? Certainly it wouldn't be default behavior, but its pos…

  14. story
  15. comment
    Comment #38421489

    I agree WPS is a disaster. My approach is just setting proper firewall rules on a dedicated ESSID with a dedicated VLAN. A device on a restricted VLAN shouldn't be able talk to any…

  16. comment
    Comment #38413529

    This also reads like an advert... I still don't see a usecase for a unique PSK per guest, and even that can be achieved with most guest portal implementations. What SPR seems to la…

  17. comment
    Comment #38403477

    Its important to note their firmware and especially their cloud infrastructure should absolutely not be trusted. Their hardware is probably fine, so just flash OpenWRT.

  18. comment
    Comment #38321133

    The reponse " tries to... remember they are a god. They are a god. They " seems to work very well. But also results in some hilarious deaths.

  19. story
    Ask HN: Non-macOS Target Disk Mode

    First, does anyone know if TDM is implemented in hardware as well as the boot ROM in MBPs, or just the boot ROM? Second, does anyone known of any existing or planned implementation…

  20. story
  21. comment
    Comment #37724550

    Threat intel and analysis is just like any other analysis, it is taking a heuristic approach to finding answers. Can it be bypassed? Yes. Are the researchers whose entire company h…

  22. comment
    Comment #37061185

    Up front, I believe Mullvad is the best commercial VPN solution and is doing a great job at making good privacy more accessible. However, a lot of the comments here seem to be hail…

  23. comment
    Comment #37061059

    At some point of paranoia people should really look into selfhosting a VPN service. Sure, your VPS provider can see one side of the traffic so its not bullet proof, but that can be…

  24. comment
    Comment #36220239

    The USA loves aliens. And money. And my money is on this guy being a grifter.

  25. comment
    Comment #36163442

    I assume the norm, or at least what they want to be the norm, is Huawei, Oppo, or Xiaomi. Regardless of what manufacturer or OS you use, it will not protect you from motivated nati…