Viewing profile — technion
technion
HN member- Joined
- Fri, Jun 19, 2015, 2:57 AM UTC
- HN karma
- 6,968
- Public activity
- 1,595 items
- HN profile
- View on Hacker News ↗
About technion
No profile information was provided.
Recent public activity
-
comment
Comment #49217399
Im supposed to be doing endpoint work with people working in this field amd basically have to convince compliance they'll need to be local administrators to do their job. They get …
-
comment
Comment #49175725
Dies it matter? Im sitting on the ops end of this myself right now where marketing purchased something like 15 new domains on Godaddy and both me and the Web developers that built …
-
comment
Comment #49161304
As someone managing dns for a lot of orgs, the part that kills me is the amount of crappy sass'es that demand you add a big include to your spf. If they already have a skim record …
-
comment
Comment #49013705
Companies make this hard, a bit like various email scams where legit company communication comes from seemingly random domains (hello paypal). Often the company is legit, but there…
-
comment
Comment #48985211
Compromising a crappy wordpress site means compromising mailbox credentials. https://lolware.net/blog/2020-09-02-autodiscover-circus/
-
comment
Comment #48917286
This isn't LinkedIn specific - the easily misclickable "one click to logon with Google" button showing up in browsers was a huge mistake and should never have existed. Reddit has s…
-
comment
Comment #48887185
Making them "fashionable" seems to be a selling point, as seen woth the last advertising positioning largely to the woman's fashion industry. They are definitely aiming to not look…
-
comment
Comment #48799125
There's an astounding amount of .DS_Store showing up - I hadn't realised how common it apparently is for people to accidentally upload this.
-
comment
Comment #48768857
Our helpdesk deals with 2-300 users per day that logon every single day yet forgot their password. This type of thinking doesn't work in large enough orgs dealing with end users.
-
comment
Comment #48655835
Vulnerable dependencies are very different to compromised or backdoored dependencies though. Noone's taking over Solarwinds because their build tools had a ReDOS involving input fr…
-
comment
Comment #48654991
I'm reading the ZeroBounce docs and it seems very relevant. Look at this step: "We recheck all unknown emails using IPs from different geographical locations". This matches exactly…
-
comment
Comment #48654565
All of them. My personal tax agent only accepts forms and sends them back via email. I had a conversation with him about using password protected zips and he just told me he won't …
-
comment
Comment #48653793
Yeah, it did always get me as a design issue. I get that "there's more to ask them" is valid. But there's never an indication of "OK I've said everything now". You only find out wh…
-
comment
Comment #48593985
If they run a mortgage broking business, they should have a very different experience to what's described in this post about setting up like a personal machine. They presumably hav…
-
comment
Comment #48579285
As an Australian.. politically I need to worry about business data touching China. It will come up at a Risk Advisory Committee meeting as a serious issue. In actual personal pract…
-
comment
Comment #48500744
You can find the link to the victims leaks page and screenshots of it working right here: https://www.ransomlook.io/group/the%20gentlemen They appear genuinely prolific.
-
comment
Comment #48470645
A lot of those same people seemed perfectly capable of insisting on 60 day password rotation back when they could use nist guidance as an authority to appeal to (for about five yea…
-
comment
Comment #48470551
Claude, for my non Gmail domain, expects me to click a magic link on every device I wish to use it. Its wild that a product like that cannot take a password, or a passkey.
-
comment
Comment #48319521
Ten times shorter just means "readable without losing an excess of time on ramble" and I feel like someone's comeback to this will be "you should ask an AI to summarise".
-
comment
Comment #48317196
The researcher's own statements note that the zero days were not found with AI. And honestly I think that's the part that Microsoft is most upset about, because every internal part…
-
comment
Comment #48205201
The problem with all these permissions ideas: VSCode in most cases is expected to be able to push to a git repo. Many developers these days use it over the CLI for pushes and pulls…
-
comment
Comment #48189856
Note that despite being named here as "Azure Linux" and being described as a "General purpose Linux OS for Azure", once you go to the product documentation it's referred to as "Mic…
-
comment
Comment #48155317
A hospital could not learn a bigger lesson from this person than their existing big players. (Screams in "deployed in 2026 a new product that only works in internet explorer" in he…
-
comment
Comment #47981693
Yeah, all my friends watched it when it was new. After an episode played we would talk about it the next day. Im pretty sure none of us saw the final few seasons, with it moving to…
-
comment
Comment #47943481
I guess I woukd say youre fortunate to have not worked in a "we cannot use github.com because we take security very seriously" environment. Because always tells me you'll be runnin…