Live data from Hacker News

Viewing profile — technion

technion

HN member
Joined
Fri, Jun 19, 2015, 2:57 AM UTC
HN karma
6,968
Public activity
1,595 items

About technion

No profile information was provided.

Recent public activity

  1. comment
    Comment #49217399

    Im supposed to be doing endpoint work with people working in this field amd basically have to convince compliance they'll need to be local administrators to do their job. They get …

  2. comment
    Comment #49175725

    Dies it matter? Im sitting on the ops end of this myself right now where marketing purchased something like 15 new domains on Godaddy and both me and the Web developers that built …

  3. comment
    Comment #49161304

    As someone managing dns for a lot of orgs, the part that kills me is the amount of crappy sass'es that demand you add a big include to your spf. If they already have a skim record …

  4. comment
    Comment #49013705

    Companies make this hard, a bit like various email scams where legit company communication comes from seemingly random domains (hello paypal). Often the company is legit, but there…

  5. comment
    Comment #48985211

    Compromising a crappy wordpress site means compromising mailbox credentials. https://lolware.net/blog/2020-09-02-autodiscover-circus/

  6. comment
    Comment #48917286

    This isn't LinkedIn specific - the easily misclickable "one click to logon with Google" button showing up in browsers was a huge mistake and should never have existed. Reddit has s…

  7. comment
    Comment #48887185

    Making them "fashionable" seems to be a selling point, as seen woth the last advertising positioning largely to the woman's fashion industry. They are definitely aiming to not look…

  8. comment
    Comment #48799125

    There's an astounding amount of .DS_Store showing up - I hadn't realised how common it apparently is for people to accidentally upload this.

  9. comment
    Comment #48768857

    Our helpdesk deals with 2-300 users per day that logon every single day yet forgot their password. This type of thinking doesn't work in large enough orgs dealing with end users.

  10. comment
    Comment #48655835

    Vulnerable dependencies are very different to compromised or backdoored dependencies though. Noone's taking over Solarwinds because their build tools had a ReDOS involving input fr…

  11. comment
    Comment #48654991

    I'm reading the ZeroBounce docs and it seems very relevant. Look at this step: "We recheck all unknown emails using IPs from different geographical locations". This matches exactly…

  12. comment
    Comment #48654565

    All of them. My personal tax agent only accepts forms and sends them back via email. I had a conversation with him about using password protected zips and he just told me he won't …

  13. comment
    Comment #48653793

    Yeah, it did always get me as a design issue. I get that "there's more to ask them" is valid. But there's never an indication of "OK I've said everything now". You only find out wh…

  14. comment
    Comment #48593985

    If they run a mortgage broking business, they should have a very different experience to what's described in this post about setting up like a personal machine. They presumably hav…

  15. comment
    Comment #48579285

    As an Australian.. politically I need to worry about business data touching China. It will come up at a Risk Advisory Committee meeting as a serious issue. In actual personal pract…

  16. comment
    Comment #48500744

    You can find the link to the victims leaks page and screenshots of it working right here: https://www.ransomlook.io/group/the%20gentlemen They appear genuinely prolific.

  17. comment
    Comment #48470645

    A lot of those same people seemed perfectly capable of insisting on 60 day password rotation back when they could use nist guidance as an authority to appeal to (for about five yea…

  18. comment
    Comment #48470551

    Claude, for my non Gmail domain, expects me to click a magic link on every device I wish to use it. Its wild that a product like that cannot take a password, or a passkey.

  19. comment
    Comment #48319521

    Ten times shorter just means "readable without losing an excess of time on ramble" and I feel like someone's comeback to this will be "you should ask an AI to summarise".

  20. comment
    Comment #48317196

    The researcher's own statements note that the zero days were not found with AI. And honestly I think that's the part that Microsoft is most upset about, because every internal part…

  21. comment
    Comment #48205201

    The problem with all these permissions ideas: VSCode in most cases is expected to be able to push to a git repo. Many developers these days use it over the CLI for pushes and pulls…

  22. comment
    Comment #48189856

    Note that despite being named here as "Azure Linux" and being described as a "General purpose Linux OS for Azure", once you go to the product documentation it's referred to as "Mic…

  23. comment
    Comment #48155317

    A hospital could not learn a bigger lesson from this person than their existing big players. (Screams in "deployed in 2026 a new product that only works in internet explorer" in he…

  24. comment
    Comment #47981693

    Yeah, all my friends watched it when it was new. After an episode played we would talk about it the next day. Im pretty sure none of us saw the final few seasons, with it moving to…

  25. comment
    Comment #47943481

    I guess I woukd say youre fortunate to have not worked in a "we cannot use github.com because we take security very seriously" environment. Because always tells me you'll be runnin…