back
user profile
seanieb
1,522karma·339submissions·July 15, 2010
about
Working on computer security & encryption stuff.
https://conic.al
recent activity (339 total)
comment
It’s not. The Secret Service already has identified nation stare actors as being responsible.
comment
Missing the key context: > “While forensic examination of these devices is ongoing, early analysis indicates cellular communications between nation-state threat actors and individuals that are know…
comment
Howard Lutnick stated it was yearly in the video.
comment
They said at the signing that it was per year. No idea if it’s applicable to existing h1-b’s. https://bsky.app/profile/atrupar.com/post/3lz7tewnfrr23 …
comment
Privacy.
comment
Why did the socket.dev story from last night get flagged off the front page? https://news.ycombinator.com/item?id=45256210 …
comment
There have been practical suggestions that could prevent this but NPM has not yet adopted: - Prevent publishing new package versions for 24–48 hours after account credentials are changed. - Require su…
comment
socket.dev is a well known a reputable company, and their founder is pretty well known and trusted too. And looking that their blog post it looks like detected a real attack.
comment
Scanning everyone’s messages does not meet the bar of necessity. Especially when you look at their reasoning, child safety. Every country in EU should be ashamed of the funding they give police to inv…
comment
His detailed clarification came post my reply to you. Prior to that his statement was that most of their employees were no longer living in Russia. Which implied that some percentage of employees stil…
comment
The AdGuards CTO and cofounder just replied to my comment, called it misinformation, but then confirmed that a large amount of their team continues to work from Russia. If you trust Devs working in Ru…
comment
Lots of Russian apps and services registered in Malta or Cyprus, but their devs continue to live in Russia. And naive users think they’re using a European app or service. For example Adguard.
comment
A wide open door to get foreign political donations (see: bribery) in plain sight.
comment
TLDR; Microsoft didn’t have rate-limiting on their TOTP MFA if you opened different tabs. Allowing attackers enough guesses to get the users MFA code.
comment
Is this a flying imsi-catcher network? Could it spoof cell phone carriers in foreign countries to MITM their calls, sms and data?
comment
Weren’t lots of those planes leased from an Irish company, and now effectively stolen property?
comment
"You're probably not vulnerable to the CUPS CVE"
https://xeiaso.net/notes/2024/cups-cve/ …
33 pts
comment
It looks like it wasn’t a software update, it was a AV definitions update, so internal to the CA application.
comment
When Russia enables it, amplifies it, builds their disinformation and propaganda machine around those facts and there’s no counter weight it gets into the realm of anti-democratic adjacent. There’s no…
comment
Durov travels freely to and from Russia and several of their employees are still based in Russia. So yeah, the FSB have leverage if they need to use it.
comment
Well reading that was a frustrating waste of time. They absolutely used a bait title. What they found amounts to nothing in security terms.
comment
Can’t help but think Elons lawsuit will trigger more releases by OpenAI. His core arguments are BS, but raised legitimate questions about their non-profit status and lack of non-profit related activit…
2 pts
comment
The idea that Keycloak solves security issues makes me giggle. It's CVE's should shed some light on what I mean. - https://www.cvedetails.com/vulnerability-list/vendor_i…
comment
You're swapping out your DNS for a Russian controlled DNS service. Seems dumb IMO.
comment
Apple is an American company and we’re not actively paying for a hot war against China.
comment
AdGuard is a Russian company, with Russian engineers, the majority of AdGuard developers and other employees working from Moscow, registered in Cyprus. Not a great recipe. Hard pass on security ground…