Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Laya the open source version of Jev(convaiinnovations.com ↗)
    89comments
  2. A graphical desktop for the ZX Spectrum(github.com/mindbox77 ↗)
    14comments
  3. AI-generated posters don’t have to be horrible(john.hartnup.uk ↗)
    381comments
  4. What Zig felt like, coming from Rust(besok.github.io ↗)
    58comments
  5. Tin: full-text search for Postgres(planetscale.com ↗)
    7comments
  6. Human brain is two separate organs, Stanford Medicine-led research finds(stanford.edu ↗)
    169comments
  7. “The Secret Life of Circuits” is here(coredump.cx ↗)
    37comments
  8. Asking Authors About Their Own Papers(medium.com/tmlrorg ↗)
    10comments
  9. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    523comments
  10. Black Holes or Black Hole Stars? Astronomers Spar over 'Little Red Dots'(quantamagazine.org ↗)
    7comments
  11. GPT-6 Astra Solves a WWI German Radio Cipher(prinzai.com ↗)
    121comments
  12. San Francisco Onion Futures Company(onionfutures.com ↗)
    98comments
  13. If math is more than proof, we need to better celebrate the rest of it(terrytao.wordpress.com ↗)
    175comments
  14. Learning Another Language May Be One of the Best Ways to Keep Your Brain Healthy(theconversation.com ↗)
    15comments
  15. I built the fastest PHP webserver in the world(qbixserver.com ↗)
    discuss
  16. Cloudflare Quick Tunnels(cloudflare.com ↗)
    299comments
  17. How to Write with an LLM(sockpuppet.org ↗)
    360comments
  18. Communication by means of modulated Johnson noise(pnas.org ↗)
    16comments
  19. You can run Git on object storage if you re-make packfiles(tigrisdata.com ↗)
    23comments
  20. SDCC – Small Device C Compiler(sourceforge.net ↗)
    22comments
  21. Saving another 100TB of RAM(cloudflare.com ↗)
    87comments
  22. Science Is Open Software(jepedersen.dk ↗)
    47comments
  23. From Stonemasons to Carpenters(thelastsoftwareengineer.substack.com ↗)
    4comments
  24. Why building a Rust LSP is hard(rust-glancer.github.io ↗)
    44comments
  25. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    120comments
  26. How OpenAI Used Its Own LLMs to Design Its Jalapeño Chip(ieee.org ↗)
    115comments
  27. Ctenophores: Wonders of Biology(quantamagazine.org ↗)
    6comments
  28. OpenJev(openjev.com ↗)
    276comments
  29. Ray Ozzie and the Optimism of Being Early(reproof.app ↗)
    7comments
  30. Goroutine Leak Profiles(go.dev ↗)
    6comments

Webseclab – Web security test cases and a construction toolkit

114 pointsby 11y agogithub.com
6 comments
11y agoHN ↗

This can't be because the most advanced unit in the entire United States Military reminded the world that, last month, they already played the trump card can it?

http://www.army.mil/article/141734/Army_cyber_defenders_open...

Nah; that must be a coincidence. After all, why would somebody after the US Military try to convince people that their security was better? Do you honestly think Yahoo has better stuff than the Tony Stark of the armed forces?

Please. Let's see, Ycombinator's got some ex-Yahoo's as alumni, I'm sure they'll chime in and disagree with me any moment. Yep yep. Bring it.

11y agoHN ↗

Clearly he didn't even read the first word of the title. =)

11y agoHN ↗

If you're planning on scanning all of your web apps at scale, you probably want to know what you can find and what you'll miss.

As for competitors, I think there is WavSep but I'm not sure how suitable it is for Yahoo's use case (it looks like an overgrown J2EE app). People involved in that project infrequently rank scanners on their blog:

* https://code.google.com/p/wavsep/

* http://sectooladdict.blogspot.ro/2014/02/wavsep-web-applicat...

I have the feeling that the Yahoo bug bounties are about to get a whole lot harder to claim.

11y agoHN ↗

This is good news. Yahoo has demonstrated that they can manage the largest bug bounty program in the world. Now it's time to elevate the difficulty of finding vulnerabilities to the same status as Google or Facebook.

Unfortunately, this will do nothing for the engineering hours being sunk into monitoring the thousands of invalid reports submitted each year.