Slashdot Mirror


User: zachriggle

zachriggle's activity in the archive.

Stories
0
Comments
16
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 16

  1. Re: We're becoming more and more idiots on Why Attackers Are Using C# For Post-PowerShell Attacks (forcepoint.com) · · Score: 1

    Are you saying fileless / in-memory only exploitation, post-exploitation donâ(TM)t exist?

    Welcome to 2002, go read about any exploit kit from the past decade.

  2. As a long-standing member of the computer security industry, having done vulnerability research my entire career [0], there's exactly two sentiments in the industry:

    1.) This is cool! I'll do this in my free time, it's fun!
    2.) Fuck you, pay me.

    The problem with #1 is that as soon as you hit any real resistance, it stops being fun. Have you tried landing a patch at GNU.org or in the upstream kernel? Biggest pain in the rear, ever.

    The current state of affairs is that you can remain a White Hat and report vulnerabilities to Google in any open source software [1] or even Android specifically [2] and earn TENS OF THOUSANDS OF DOLLARS PER BUG. You can find even more companies / projects to assist through BugCrowd or HackerOne.

    Alternately, if you don't mind your bugs being sold to any number of nation states, just take your research to Apple iOS, and either Exodus [3] or VUPEN-nee-Zerodium will pay you A MOTHER FUCKING MILLION DOLLARS [4] for the right bugs.

    All of this whining is coming from the same open-source community leader (Torvalds) that has publicly shunned GRSecurity [5] one of the groups that has been trying to help for 20 years, and has stated that infosec industry members should "Please just kill yourself now. The world would be a better place." [6]

    So to you, Mr. Torvalds, I say:

    FUCK YOU, PAY ME.

    [0]: https://www.linkedin.com/in/za...
    [1]: https://www.google.com/about/a...
    [2]: https://www.google.com/about/a...
    [3]: https://rsp.exodusintel.com/
    [4]: https://zerodium.com/program.h...
    [5]: https://lkml.org/lkml/2017/6/2...
    [6]: https://web.archive.org/web/20...

  3. Re:Duh? on Dropbox Authentication: Insecure By Design · · Score: 2

    If I steal your SSH key, and then you change your password, I can still access your box.

    The only difference here is that you're no longer in control of the effective authorized_hosts file, Dropbox is. Yes, they should regenerate the key every time you change your password.

    The article's hysteria seems to be much more about the file, rather than the fact that a password change doesn't change your API key / secret key / etc.

  4. Duh? on Dropbox Authentication: Insecure By Design · · Score: 2, Informative

    If your local machine is accessed by an untrustworthy party and they get your shared secret/API token/whatever, they can impersonate you. ALSO: Applications store your login information locally when you request that they save your login information!!! News at eleven.

  5. Re:The more competition, the better on Microsoft Ready To "Take On'' Google and Apple TV · · Score: 1

    An XBox isn't at the same price point as either a Google or Apple TV. Even Sony has $90 BluRay players that do NetFlix, Hulu Plus, and Amazon On Demand, among other things.

  6. Re:Market cap? on Apple Passes $300B Market Cap, 2nd In the World · · Score: 1

    It's called Piercing the Corporate Veil. If you've got some time, the Buffalo Creek Disaster is an excellent book that outlines most of the specific situations you talked about.

  7. Re:Still confused on Firesheep Author Reflects On Wild Week · · Score: 1

    Mod parent up insightful, or GP down.

  8. Re:CmdrTaco drags big brass ones along the ground on iPad Review · · Score: 1

    Look at the Meebo application. Supports every network under the sun with Push notification. The Meebo servers keep you signed in, the app just signs you into the Meebo server. Push notifications work just like text messages -- but over AIM, Facebook, Google Talk, etc.

  9. Re:Apple is scared of write once run anywhere on How the iPad Is Already Reshaping the Internet (Sans Flash) · · Score: 1

    alen, I'd like you to meet Javascript/AJAX/DOM/HTML5. Javascript/AJAX/DOM/HTML5, alen.

  10. Re:There has never been this type of device. on How the iPad Is Already Reshaping the Internet (Sans Flash) · · Score: 0, Redundant

    Mod parent up.

  11. Re:Here we go again on How the iPad Is Already Reshaping the Internet (Sans Flash) · · Score: 1

    Right, because the content publishers aren't getting their panties in a bunch over being one of the first "iPad-compatible" websites with HTML5. You're not factoring into the equation that many of the consumers that will be using an iPad may very well start to use these "compatible" websites just because they are "specifically designed for iPad" and have compatible video. http://www.apple.com/ipad/ready-for-ipad/

  12. Re:Ummm.. on How the iPad Is Already Reshaping the Internet (Sans Flash) · · Score: 3, Insightful

    All of these news sites also happen to provide video to go with their news. This video is now offered in HTML5 when browsed to by an iPad.

  13. Re:I wonder if the economy will change that back.. on RIP the Campus Computer Lab, 1960-2009 · · Score: 1

    Something else to consider is whether you actually save money by *not* purchasing the laptop, in the time and gas spent going to/from the computer lab. Also, assuming the school does away the computer labs and the Technology Fee is removed (which is several hundred dollars per semester) a laptop may end up being cheaper.

  14. Re:Printing on RIP the Campus Computer Lab, 1960-2009 · · Score: 1

    I am a student at Michigan State University. They have a system where I can print from any platform (via Windows sharing or LDP) to any printer, anywhere on campus. There is a networked printer in each wing of each dorm, in every computer lab, and in all of the libraries. This works well with the campus-wide network (migrating to Wireless-N, IIRC). Prints are $.05 per page side, an extra $.05 per side for color. All of the printer billing is integrated into the standard billing system.

  15. Wow, I'm lucky! on Kutztown Students get Felony Charges · · Score: 1

    It seems that the school tech administrators are gettnig more anal retentive every day. Compared to these guys, I lucked out. Banned from school computers for life for downloading PuTTy. (To get my homework nonetheless. I had misplaced the file on my webserver, and had to move it so that I could download it. That's it.)

  16. Already been done... on Matrix-Style Bullet Time for Realtime Online Games · · Score: 2, Interesting

    http://www.specialistsmod.net/

    The game has had bullet-time for quite some time, and only effects players in your immediate area. This allows the rest of the game to go along unhampered by your slow-flying bullets.