Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Laya the open source version of Jev(convaiinnovations.com ↗)
    142comments
  2. A graphical desktop for the ZX Spectrum(github.com/mindbox77 ↗)
    53comments
  3. AI-generated posters don’t have to be horrible(john.hartnup.uk ↗)
    462comments
  4. Human brain is two separate organs, Stanford Medicine-led research finds(stanford.edu ↗)
    182comments
  5. Tin: full-text search for Postgres(planetscale.com ↗)
    43comments
  6. Supabase (YC S20) Is Hiring for OrioleDB(supabase.link ↗)
    discuss
  7. Asking Authors About Their Own Papers(medium.com/tmlrorg ↗)
    37comments
  8. “The Secret Life of Circuits” is here(coredump.cx ↗)
    51comments
  9. Black Holes or Black Hole Stars? Astronomers Spar over 'Little Red Dots'(quantamagazine.org ↗)
    14comments
  10. I built the fastest PHP webserver in the world(qbixserver.com ↗)
    32comments
  11. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    552comments
  12. San Francisco Onion Futures Company(onionfutures.com ↗)
    117comments
  13. New evidence for hidden chambers beyond Tutankhamun's tomb(nature.com ↗)
    5comments
  14. GPT-6 Astra Solves a WWI German Radio Cipher(prinzai.com ↗)
    132comments
  15. If math is more than proof, we need to better celebrate the rest of it(terrytao.wordpress.com ↗)
    193comments
  16. What Zig felt like, coming from Rust(besok.github.io ↗)
    108comments
  17. Agreement between the USA and Denmark (1951,2004) [pdf](state.gov ↗)
    16comments
  18. Cloudflare Quick Tunnels(cloudflare.com ↗)
    301comments
  19. How to Write with an LLM(sockpuppet.org ↗)
    360comments
  20. You can run Git on object storage if you re-make packfiles(tigrisdata.com ↗)
    24comments
  21. Saving another 100TB of RAM(cloudflare.com ↗)
    90comments
  22. Communication by means of modulated Johnson noise(pnas.org ↗)
    19comments
  23. SDCC – Small Device C Compiler(sourceforge.net ↗)
    23comments
  24. Ray Ozzie and the Optimism of Being Early(reproof.app ↗)
    11comments
  25. Science Is Open Software(jepedersen.dk ↗)
    51comments
  26. Why building a Rust LSP is hard(rust-glancer.github.io ↗)
    44comments
  27. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    123comments
  28. OpenJev(openjev.com ↗)
    280comments
  29. Ctenophores: Wonders of Biology(quantamagazine.org ↗)
    8comments
  30. From Stonemasons to Carpenters(thelastsoftwareengineer.substack.com ↗)
    4comments

Webseclab – Web security test cases and a construction toolkit

114 pointsby 11y agogithub.com
6 comments
11y agoHN ↗

This can't be because the most advanced unit in the entire United States Military reminded the world that, last month, they already played the trump card can it?

http://www.army.mil/article/141734/Army_cyber_defenders_open...

Nah; that must be a coincidence. After all, why would somebody after the US Military try to convince people that their security was better? Do you honestly think Yahoo has better stuff than the Tony Stark of the armed forces?

Please. Let's see, Ycombinator's got some ex-Yahoo's as alumni, I'm sure they'll chime in and disagree with me any moment. Yep yep. Bring it.

11y agoHN ↗

Clearly he didn't even read the first word of the title. =)

11y agoHN ↗

If you're planning on scanning all of your web apps at scale, you probably want to know what you can find and what you'll miss.

As for competitors, I think there is WavSep but I'm not sure how suitable it is for Yahoo's use case (it looks like an overgrown J2EE app). People involved in that project infrequently rank scanners on their blog:

* https://code.google.com/p/wavsep/

* http://sectooladdict.blogspot.ro/2014/02/wavsep-web-applicat...

I have the feeling that the Yahoo bug bounties are about to get a whole lot harder to claim.

11y agoHN ↗

This is good news. Yahoo has demonstrated that they can manage the largest bug bounty program in the world. Now it's time to elevate the difficulty of finding vulnerabilities to the same status as Google or Facebook.

Unfortunately, this will do nothing for the engineering hours being sunk into monitoring the thousands of invalid reports submitted each year.