Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Laya the open source version of Jev(convaiinnovations.com ↗)
    114comments
  2. A graphical desktop for the ZX Spectrum(github.com/mindbox77 ↗)
    31comments
  3. Tin: full-text search for Postgres(planetscale.com ↗)
    19comments
  4. AI-generated posters don’t have to be horrible(john.hartnup.uk ↗)
    422comments
  5. Human brain is two separate organs, Stanford Medicine-led research finds(stanford.edu ↗)
    176comments
  6. “The Secret Life of Circuits” is here(coredump.cx ↗)
    47comments
  7. Black Holes or Black Hole Stars? Astronomers Spar over 'Little Red Dots'(quantamagazine.org ↗)
    11comments
  8. What Zig felt like, coming from Rust(besok.github.io ↗)
    91comments
  9. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    533comments
  10. Asking Authors About Their Own Papers(medium.com/tmlrorg ↗)
    26comments
  11. I built the fastest PHP webserver in the world(qbixserver.com ↗)
    12comments
  12. San Francisco Onion Futures Company(onionfutures.com ↗)
    105comments
  13. Agreement between the USA and Denmark (1951,2004) [pdf](state.gov ↗)
    1comments
  14. If math is more than proof, we need to better celebrate the rest of it(terrytao.wordpress.com ↗)
    185comments
  15. GPT-6 Astra Solves a WWI German Radio Cipher(prinzai.com ↗)
    126comments
  16. Learning Another Language May Be One of the Best Ways to Keep Your Brain Healthy(theconversation.com ↗)
    33comments
  17. Cloudflare Quick Tunnels(cloudflare.com ↗)
    300comments
  18. How to Write with an LLM(sockpuppet.org ↗)
    360comments
  19. You can run Git on object storage if you re-make packfiles(tigrisdata.com ↗)
    23comments
  20. Communication by means of modulated Johnson noise(pnas.org ↗)
    18comments
  21. Ray Ozzie and the Optimism of Being Early(reproof.app ↗)
    8comments
  22. Saving another 100TB of RAM(cloudflare.com ↗)
    89comments
  23. SDCC – Small Device C Compiler(sourceforge.net ↗)
    23comments
  24. Science Is Open Software(jepedersen.dk ↗)
    47comments
  25. From Stonemasons to Carpenters(thelastsoftwareengineer.substack.com ↗)
    4comments
  26. Why building a Rust LSP is hard(rust-glancer.github.io ↗)
    44comments
  27. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    122comments
  28. OpenJev(openjev.com ↗)
    278comments
  29. Ctenophores: Wonders of Biology(quantamagazine.org ↗)
    7comments
  30. How OpenAI Used Its Own LLMs to Design Its Jalapeño Chip(ieee.org ↗)
    119comments

Webseclab – Web security test cases and a construction toolkit

114 pointsby 11y agogithub.com
6 comments
11y agoHN ↗

This can't be because the most advanced unit in the entire United States Military reminded the world that, last month, they already played the trump card can it?

http://www.army.mil/article/141734/Army_cyber_defenders_open...

Nah; that must be a coincidence. After all, why would somebody after the US Military try to convince people that their security was better? Do you honestly think Yahoo has better stuff than the Tony Stark of the armed forces?

Please. Let's see, Ycombinator's got some ex-Yahoo's as alumni, I'm sure they'll chime in and disagree with me any moment. Yep yep. Bring it.

11y agoHN ↗

Clearly he didn't even read the first word of the title. =)

11y agoHN ↗

If you're planning on scanning all of your web apps at scale, you probably want to know what you can find and what you'll miss.

As for competitors, I think there is WavSep but I'm not sure how suitable it is for Yahoo's use case (it looks like an overgrown J2EE app). People involved in that project infrequently rank scanners on their blog:

* https://code.google.com/p/wavsep/

* http://sectooladdict.blogspot.ro/2014/02/wavsep-web-applicat...

I have the feeling that the Yahoo bug bounties are about to get a whole lot harder to claim.

11y agoHN ↗

This is good news. Yahoo has demonstrated that they can manage the largest bug bounty program in the world. Now it's time to elevate the difficulty of finding vulnerabilities to the same status as Google or Facebook.

Unfortunately, this will do nothing for the engineering hours being sunk into monitoring the thousands of invalid reports submitted each year.