Live data from Hacker News

Viewing profile — syntheticcorp

syntheticcorp

HN member
Joined
Thu, Oct 31, 2019, 3:35 AM UTC
HN karma
94
Public activity
67 items

About syntheticcorp

No profile information was provided.

Recent public activity

  1. comment
    Comment #41355855

    I get your point but I think pentesters are perfectly capable of thinking in graphs, including web security. Bug chains are the immediate example, where a couple of CVSS 4-7 vulns …

  2. comment
    Comment #40616419

    It’s pretty infrequent outside of target attacks. Most recent is probably the roundcube XSS CVE-2023-43770 that was actively exploited as 0day by a threat actor last year.

  3. comment
    Comment #39363289

    Specifically, Marriott was deauthing rather than just plain jamming.

  4. comment
    Comment #38971259

    You can’t serve a valid certificate chain to the client even if you control their traffic, because your malicious certificate isn’t signed by a trusted CA. And you can’t get a CA s…

  5. comment
    Comment #38962274

    Control over a clients DNS doesn’t let the VPN provider view the contents of TLS encrypted traffic. However they can view unencrypted data from connections like SNI headers, DNS qu…

  6. comment
    Comment #37454272

    It’s a vlc issue with h265 - I actually noticed this with videos from defcon last year. Pull the YouTube version or reencode to h264 to fix.

  7. comment
    Comment #37365389

    Yes it can do that now, at least on Windows 10

  8. comment
    Comment #36449805

    I’ve also encountered that a few times where a fairly anodyne bug in a codepath prevents a serious security bug from being reachable. With my attacker hat on it is very tempting to…

  9. comment
    Comment #35105850

    The commenter you’re replying to is CTO of Cloudflare, so I’d say they likely know why the company makes these blog posts.

  10. comment
    Comment #34887586

    Found it, pg 47 https://www.cs.auckland.ac.nz/~pgut001/pubs/defending.pdf

  11. comment
    Comment #34089992

    Browsers already include this feature in a coarse grained (but utterly sufficient) manner in the form of a scroll bar.

  12. comment
    Comment #34046429

    It’s a good disassembler that is fairly expensive. https://hex-rays.com/ida-pro/

  13. comment
    Comment #33212926

    Yes it is still optional. I travelled on an ESTA a few months ago , left the social media handles section blank, and they made no comment at the border. That said it is still very …

  14. comment
    Comment #33070908

    Rate limiting access to the enclave? Somewhat related, I fear this is where we are going to end up with secure attestation, limiting web access to approved devices.

  15. comment
    Comment #32554845

    I work in offense and they can be a huge impediment. Significant work goes into bypassing or staying undetected from these products. While not all the detection occurs at runtime, …

  16. comment
    Comment #31971147

    ESNI has been dropped, a new spec alters how it works and renames it Encrypted client hello (ECH) https://blog.mozilla.org/security/2021/01/07/encrypted-clien...

  17. comment
    Comment #31214821

    I’ve worked in tech in NZ for 7 years or so, never actually met someone who calls themselves an SRE. Obviously I know the term, but IME we don’t use that title here

  18. comment
    Comment #31198850

    I can’t believe you can get 30 year fixed in the US , that’s amazing. The longest terms I can see where I live are 5 year fixed.

  19. comment
    Comment #31198823

    I suppose you could have income from interest on capital or stock dividends

  20. comment
    Comment #31059197

    Are you aware which website you’re on? Having strong opinions on esoteric topics is a HN mainstay. Also as a non-American driving in the US made me think about a lot of things I wo…

  21. comment
    Comment #30437870

    There is none. This has been asserted for years on HN but I’ve never seen a modicum of evidence for it.

  22. comment
    Comment #30186279

    NK did personally target security researchers for compromise. See the TAG post referenced inTFA.

  23. comment
    Comment #29680979

    Postal 2 and manhunt are two fairly popular video games that were legally censored. Banned modern movies I am less familiar with, but there were many banned historically where the …

  24. comment
    Comment #29612047

    Average adult would include women, which are much weaker than men. It is sad if it applied to just men.

  25. comment
    Comment #29576509

    If it’s in the class path? Deserialisation gadgets.