Hacker Newsnew | past | comments | ask | show | jobs | submit | speckx's commentslogin

I wish the "pause CF" button would work via API or via any other way, even if there is an outage like this.


I have a similar username on a "social media" site as the founder's username. I would get hateful personal messages, requests for favors, begging for money, etc., constantly. At first I would respond to correct people, but after years and years I stopped. I just disable notifications for that site and never read my mailbox, personal messages, etc. This has been going on for about 19 years now.




Which itself is^H^H was down. Wow.



503 Service Unavailable


The fact that they put their AWS secret keys on their website is incredible.


That’s exactly the kind of work I’d expect from TCS, I’m not sure why you are surprised.


The fact that it's nicely commented is even more so. Check out the other environment configs commented out, are they doing this by hand? Wild.


Even more importantly, why do the root keys expose EVERYTHING? Do they just have one account for all of their infra?


Sending it with AES encryption(with the key that the client has access to) makes it even worse, as someone knew this shouldn't be shared to client yet they shared it anyway.


If you’ve ever worked with Indian outsourcing firms it’s not


> These tokens allowed full access to the Azure AD Graph API in any tenant. Requesting Actor tokens does not generate logs. Even if it did they would be generated in my tenant instead of in the victim tenant, which means there is no record of the existence of these tokens.

Wow! No logs.

I wonder how Microsoft would notify affected tenants.


I get legitimate calls from my health insurance company. When they call, they are not allowed to say the company they call from, it's a HIPAA thing. Once I say the name of the health insurance company, they will confirm it. It's weird, but it's the way it is now.


My health insurance company asks for me by name (“is this …?”). And it’s to a number they know.


I was going to say, you can use alternatives, and they will show you what's blurred or has changed.


Don't forget the PTR record.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: