Viewing profile — yfiapo
yfiapo
HN member- Joined
- Thu, Mar 29, 2018, 6:07 PM UTC
- HN karma
- 155
- Public activity
- 28 items
- HN profile
- View on Hacker News ↗
About yfiapo
No profile information was provided.
Recent public activity
-
comment
Comment #45657814
Highly likely to be coincidence. Typically an exposed access key. Exposed password for non-MFA protected console access happens but is less common.
-
comment
Comment #43894825
I agree this was a security concern and it was reported and addressed appropriately. With that said as things go this is pretty minor; perhaps a medium severity issue. Information …
-
comment
Comment #43891448
The term was used by OpenBSD starting in 1999 for a group of devs getting together for a few days or a week and hacking on specific projects together in person. Not sure about earl…
-
comment
Comment #37733576
The link goes to the press release. The actual advisory ( https://www.cisa.gov/news-events/cybersecurity-advisories/aa... ), linked from the press release, contains quite a bit mor…
-
comment
Comment #33287723
Thanks, missed that.
-
comment
Comment #33287445
> We're not done with our request payload yet! We sent: > Host: neverssl.com > This is actually a requirement for HTTP/1.1, and was one of its big selling points compared to, uh...…
-
comment
Comment #30723531
This feels akin to excessively auto-completing shells to me. It is pretty awesomely quick when you are starting, but it feels like it has to impact learning/muscle memory which giv…
-
comment
Comment #30282858
I don't know if this is everyone's reasons but for me it is: - it does too much. doesn't follow the Unix norms of doing one thing and doing it well. things like DNS resolution, tim…
-
comment
Comment #27577203
This honestly seems like it could be interesting but I don't grok it at all being dropped in with zero context.
-
comment
Comment #27576273
The article you linked is from five years ago when the new badges were being initially tested. They have been rolled out for years with color photos. Both styles still work and if …
-
comment
Comment #24358688
That's cool. As another alternative, this is the one I bought at start of lockdown which does everything but the USB-C: https://smile.amazon.com/gp/product/B0851CMHP2/ Not particul…
-
comment
Comment #24128056
I was diagnosed with ADHD almost twenty years ago as a young adult. In my experience learning about how your mind works and spending time to come up with the best system and techni…
-
comment
Comment #23227451
Ah, but there is so much value in fresh eyes. Miod, who has been involved with OpenBSD development for 20 years and has surely seen those function names a thousand times, provided …
-
comment
Comment #23225849
That's neat to see. This may not be a big story but as a fan of OpenBSD who doesn't currently have time to read the CVS log I appreciate it. OpenBSD source is one of the cleanest I…
-
comment
Comment #23225735
I don't see any additional context but this does appear to be a new thing. Two commits credited to Carmack in the OpenBSD source and they are dated 5/16/2020 and 5/17/2020.
-
comment
Comment #23002092
Thank you for even trying to answer my rambles! :-) I think my contention with the iron is the tipping point and how quickly it goes. Pop-sci tv makes it seem like you fused a sing…
-
comment
Comment #22996839
I'm sure there are great explanations out there but I haven't had time to read up on them, but a few of the space things that always bother me when I watch pop-sci space tv: - "as …
-
comment
Comment #20849870
Cool that there are some specialty tools in this space and will use if I hit that performance challenge. Minor nit, I found the performance table ( https://github.com/eBay/tsv-util…
-
comment
Comment #20840210
I'm sure that will be the case for certain companies. For companies who routinely deal with PII, PCI, or other regulated data the security teams are likely to be much more worried …
-
comment
Comment #20662517
Site doesn't appear to be working in Firefox or Chrome at the moment. No idea what it is supposed to show based on the title.
-
comment
Comment #20442113
Mmmkay. Have fun with that. The attempt is also incomplete. I suspect this would miss ranges advertised through AWS's BYOIP ( https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec…
-
comment
Comment #20233680
I've worked for a company with a whale client like that (maybe not total shutdown bad but pretty close). The argument for why they never bothered to just acquire the startup was th…
-
comment
Comment #19256198
Hmm, I'm straining my own analogy already so I won't try to beat that horse any deader. :-) I am mostly trying to argue the positives of centralized inspection at network chokepoin…
-
comment
Comment #19256113
I don't work for a bank so I can't speak definitively to their applications. A few sample applications I see listed as certificate pinned in Netskope (a CASB) though include: Adobe…
-
comment
Comment #19256045
The other side of the argument is frequently discounted and as an IT security person myself I understand that. However, there is a real challenge for companies who deal with large …