Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. I Built Non-Autoregressive Decision Models with RL a Year Ago(convaiinnovations.com ↗)
    155comments
  2. AI-generated posters don’t have to be horrible(john.hartnup.uk ↗)
    514comments
  3. A graphical desktop for the ZX Spectrum(github.com/mindbox77 ↗)
    76comments
  4. Human brain is two separate organs, Stanford Medicine-led research finds(stanford.edu ↗)
    192comments
  5. Tin: full-text search for Postgres(planetscale.com ↗)
    50comments
  6. “The Secret Life of Circuits” is here(coredump.cx ↗)
    57comments
  7. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    568comments
  8. Supabase (YC S20) Is Hiring for OrioleDB(supabase.link ↗)
    discuss
  9. Black Holes or Black Hole Stars? Astronomers Spar over 'Little Red Dots'(quantamagazine.org ↗)
    19comments
  10. New evidence for hidden chambers beyond Tutankhamun's tomb(nature.com ↗)
    10comments
  11. GPT-6 Astra Solves a WWI German Radio Cipher(prinzai.com ↗)
    139comments
  12. San Francisco Onion Futures Company(onionfutures.com ↗)
    123comments
  13. Asking Authors About Their Own Papers(medium.com/tmlrorg ↗)
    46comments
  14. Almost Never Use AI to Write Anything Substantive(erichgrunewald.substack.com ↗)
    15comments
  15. What Zig felt like, coming from Rust(besok.github.io ↗)
    128comments
  16. If math is more than proof, we need to better celebrate the rest of it(terrytao.wordpress.com ↗)
    201comments
  17. Cloudflare Quick Tunnels(cloudflare.com ↗)
    301comments
  18. How to Write with an LLM(sockpuppet.org ↗)
    364comments
  19. Adventures in Microcontroller Circuit Debugging(bigmessowires.com ↗)
    1comments
  20. You can run Git on object storage if you re-make packfiles(tigrisdata.com ↗)
    27comments
  21. Saving another 100TB of RAM(cloudflare.com ↗)
    93comments
  22. Communication by means of modulated Johnson noise(pnas.org ↗)
    20comments
  23. People who know the most often sound the least certain(vrash.substack.com ↗)
    discuss
  24. SDCC – Small Device C Compiler(sourceforge.net ↗)
    25comments
  25. Science Is Open Software(jepedersen.dk ↗)
    51comments
  26. Ray Ozzie and the Optimism of Being Early(reproof.app ↗)
    16comments
  27. Why building a Rust LSP is hard(rust-glancer.github.io ↗)
    49comments
  28. OpenJev(openjev.com ↗)
    282comments
  29. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    128comments
  30. Ctenophores: Wonders of Biology(quantamagazine.org ↗)
    11comments

Webseclab – Web security test cases and a construction toolkit

114 pointsby 11y agogithub.com
6 comments
11y agoHN ↗

This can't be because the most advanced unit in the entire United States Military reminded the world that, last month, they already played the trump card can it?

http://www.army.mil/article/141734/Army_cyber_defenders_open...

Nah; that must be a coincidence. After all, why would somebody after the US Military try to convince people that their security was better? Do you honestly think Yahoo has better stuff than the Tony Stark of the armed forces?

Please. Let's see, Ycombinator's got some ex-Yahoo's as alumni, I'm sure they'll chime in and disagree with me any moment. Yep yep. Bring it.

11y agoHN ↗

Clearly he didn't even read the first word of the title. =)

11y agoHN ↗

If you're planning on scanning all of your web apps at scale, you probably want to know what you can find and what you'll miss.

As for competitors, I think there is WavSep but I'm not sure how suitable it is for Yahoo's use case (it looks like an overgrown J2EE app). People involved in that project infrequently rank scanners on their blog:

* https://code.google.com/p/wavsep/

* http://sectooladdict.blogspot.ro/2014/02/wavsep-web-applicat...

I have the feeling that the Yahoo bug bounties are about to get a whole lot harder to claim.

11y agoHN ↗

This is good news. Yahoo has demonstrated that they can manage the largest bug bounty program in the world. Now it's time to elevate the difficulty of finding vulnerabilities to the same status as Google or Facebook.

Unfortunately, this will do nothing for the engineering hours being sunk into monitoring the thousands of invalid reports submitted each year.