back
user profile

seanieb

1,522karma·339submissions·July 15, 2010
about
Working on computer security & encryption stuff. https://conic.al
recent activity (339 total)
comment
Kinda hard to say it was just her. Yahoo! was already pretty much dead when she arrived.
4y ago·view thread
comment
Much like the truism I heard over the last week “friends don’t let friends use us-east-1”, this is one I heard a few years ago “Everything under the Apache umbrella is shit or will turn to shit.”
4y ago·view thread
comment
Azure is a tire fire too. Their platform security is garbage in comparison to AWS or GCP.
4y ago·view thread
comment
And they couldn’t estimate accurately how fast the Taliban was recapturing Afghanistan, a country they occupied for over a decade! Too many cooks in that kitchen!
4y ago·view thread
comment
Oh this is interesting. Often bug bounty’s claim a published private key wasn’t in use or sensitive. This gives researchers the ability to call BS on that.
4y ago·view thread
comment
A talk by Moxie at CCC deals with this exact question. > “ Considerations for distributed and decentralized technologies from the perspective of a product that many would like to see decentralize. …
4y ago·view thread
comment
Same influencers that flog the grind culture, selling vitamins one minute and NFT’s the next.
4y ago·view thread
comment
“Secure”… not a chance. Flash was a tyre fire and even Adobe would say so. They did their best with massive resources, and still couldn’t claim it was secure. Please please please don’t claim this pro…
4y ago·view thread
comment
This is on par with Google launching Gmail with 1GB + “infinity” space. The other email providers didn’t know what hit them. It took them years to catchup.
4y ago·view thread
comment
As soon as Linux desktop software becomes anyway profitable to develop and maintain, I’m sure companies like Dropbox will build for it. That’s not Dropbox’s problem. It doesn’t help that Linux isn’t r…
4y ago·view thread
comment
In theory… Can you name a popular large project or product where memory safety issues have been overcome this way?
4y ago·view thread
comment
Ideally you could edit ALL of your incorrect comments. And put the correction on top.
5y ago·view thread
comment
They can’t decrypt your messages. You would first need to send them your unencrypted messages before they can read them… please correct your comment. There’s enough misinformation in the world.
5y ago·view thread
comment
Great journalism eh?!
5y ago·view thread
comment
No they can’t arbitrarily decrypt messages. This process happens AFTER a user has complained and forwarded the unencrypted messages to WhatsApps abuse team. You’re first instinct is correct this is a …
5y ago·view thread
comment
This story is FUD, pointing out that WhatsApp users can forward messages they received to WhatsApp’s abuse team, when reporting abuse… I’m not a fan of FB, but the series of stories on this reporting …
5y ago·view thread
comment
When will people stop writing C? The memory safety issues make go, rust etc. much better solutions.
5y ago·view thread
comment
This just isn’t true in practice. Can you point to a popular c project that’s accomplished this? I bet there are a few tiny ones that make such claims but haven’t received scrutiny.
5y ago·view thread
comment
Real estate investors buying existing properties, without substantial capital investment into upgrades/renovations, are exactly the same as concert ticket scalpers. Their business is of little b…
5y ago·view thread
comment
Where’s Ireland’s IDA now?
5y ago·view thread
comment
So you’re technically correct, operationally incorrect. When CSAM is detected there is also the possibility of new, unhashed, CSAM being found amongst the suspects other files.
5y ago·view thread
comment
It's a government commission. That's it's entire purpose. "The FTC is a bipartisan federal agency with a unique dual mission to protect consumers and promote competition."
5y ago·view thread
comment
The word "researchers" is doing a lot of work in your comment. What's being researched is important and the FTC makes the distinction in their statement, "good-faith research in th…
5y ago·view thread
comment
Without any context or common sense applied, sure.
5y ago·view thread
comment
All that text for a feature that no one, including the author uses correctly. Messaging your mates to reassure them everything is correct via Signal after you update your device and your safety number…
5y ago·view thread
comment
Still a lot of these in Google cache... Passwords etc. can be changed, but the protocols and the information about readiness.. oh boy... absolutely classified. Somewhere in Europe there's a numb…
5y ago·view thread
comment
7ish years as a security engineer and all my gut instincts tell me that you’re site has auth bugs just from hearing the spec. It might be perfectly secure, but if I was put on your project tomorrow I’…
5y ago·view thread
comment
If the users browser doesn’t have samesite, you’ve got much bigger problems that JWTs wont solve.
5y ago·view thread