Live data from Hacker News

Infosec company pwned by 4chan user

maia.crimew.gay

201–210 of 234 posts

Re: Infosec company pwned by 4chan user

#201

Earlier quoted context omitted.

> but the day I stop needing to dive into xrandr and figure out why the screen is rotated but the mouse coordinates aren't or some other 1990s level problem will be a happy one. I'm sympathetic to wanting legacy mindhorrors replaced with modern stuff, but genuine question: When do you ever have such problems xD I've multimonitored on X11 for like 4 years and never experienced that.

Have you tried to multimonitor different combinations of HiDPI + regular DPI on x11? Last time I tried to make different scaling displays work together on x11 the experience was so nightmarish that I went back to windows.

Doing so literally as I type this. I can confirm it works and has for at minimum 5+ years for me.

Re: Infosec company pwned by 4chan user

#202
post #137

Earlier quoted context omitted.

No, the most comedic mistake is to have a public-facing Jenkins running. I mean in general you wouldn't make your CI accessible from the outside, but especially not Jenkins. That software has probably more CVEs every year than all of our other tooling combined.

The most comedic mistake is to have a running jenking in 2023

[deleted]

Re: Infosec company pwned by 4chan user

#203

I suspect this leak was made by the author themselves and submitted to 4chan via Tor or a VPN. I don't have hard evidence to back this up but if you read the Wikipedia article about them, it's pretty easy to put two and two together.

>and submitted to 4chan via Tor or a VPN.

4chan blocks both Tor and VPNs. It's a terrible place to leak things, but a hacker can most probably find innocuous IPs.

Re: Infosec company pwned by 4chan user

#204

Earlier quoted context omitted.

The most comedic mistake is to have a running jenking in 2023

Highly customizable CI tool.

..written in Java.

In case anyone needs reminding, Java developers, on purpose, put a line in a logging library that can fetch and execute code when given a url string for a log statement.

Nobody should be touching anything Java in 2023.

Re: Infosec company pwned by 4chan user

#206

Earlier quoted context omitted.

Highly customizable CI tool.

..written in Java. In case anyone needs reminding, Java developers, on purpose, put a line in a logging library that can fetch and execute code when given a url string for a log statement. Nobody should be touching anything Java in 2023.

Yes, we all sat down and unanimously agreed that we should perform JNDI lookups to execute arbitrary code stored in an LDAP directory.

No regrets.

Re: Infosec company pwned by 4chan user

#207

Earlier quoted context omitted.

0 times out of ten for me. First I blocked the annoying cat, then I got to the bottom, was assaulted by blinking buttons and decided I didn’t need to know what else they were saying anyway.

You would not have enjoyed the late 90s.

It was okay back then, I was young and didn’t know you could design websites that are easier on the eyes.

Re: Infosec company pwned by 4chan user

#208
post #60

Earlier quoted context omitted.

0 times out of ten for me. First I blocked the annoying cat, then I got to the bottom, was assaulted by blinking buttons and decided I didn’t need to know what else they were saying anyway.

Oh my, assaulted ? By that single blinking icon? I hope you're ok.

"assault on the senses" is a well-known idiom. Or so I thought. Apparently it’s offensive to quite a few of you, I’m sorry.

Re: Infosec company pwned by 4chan user

#209

Earlier quoted context omitted.

0 times out of ten for me. First I blocked the annoying cat, then I got to the bottom, was assaulted by blinking buttons and decided I didn’t need to know what else they were saying anyway.

Oh man, never visit Tumblr

That’s actually not as bad, as it’s usually just some big meme gifs that I can disable with my animation blocker extension.

Re: Infosec company pwned by 4chan user

#210

Earlier quoted context omitted.

Yet everyone on HN complains about ads Yes I blocked it with ublock

Because at the end of the day, the problem with ads isn't that they're annoying, or get in the way, or are garish, or whatever else. The problem with ads is that they are ads. They're an overt attempt to hijack your attention implant ideas in your head, ideas that are antithetical to your own wellbeing. A little cat chasing my cursor is just plain fun. No malice involved.

> A little cat chasing my cursor is just plain fun. No malice involved.

There’s a browser setting, "prefers reduced motion" for accessibility reason. And yes, I have that enabled.

Post reply on HN