Readit News logoReadit News
zndr commented on XBOW, an autonomous penetration tester, has reached the top spot on HackerOne   xbow.com/blog/top-1-how-x... · Posted by u/summarity
mellosouls · 8 months ago
Have XBow provided a link to this claim, I could only find:

https://hackerone.com/xbow?type=user

Which shows a different picture. This may not invalidate their claim (best US), but a screenshot can be a bit cherry-picked.

zndr · 8 months ago
If you scroll down on [the leaderboard](https://hackerone.com/leaderboard?year=2025&quarter=2&owasp=...) page to Country and select United States, xbow is currently on top
zndr commented on Transformer models: an introduction and catalog   arxiv.org/abs/2302.07730... · Posted by u/mariuz
theredlancer · 3 years ago
Where's Cliffjumper and Ironside?
zndr · 3 years ago
I'm glad I'm not the only one looking for a taxonomy of refugees from the great Cybertron wars
zndr commented on Waymo's collision avoidance testing   blog.waymo.com/2022/12/wa... · Posted by u/EvgeniyZh
threeseed · 3 years ago
I wouldn't rule out Cruise.

They already have robotaxis in SF and are expanding into Arizona and Texas by the end of this year.

zndr · 3 years ago
Saying they have taxi's in SF is a bit hyperbolic. I have an invite to that program and it's

- only after 10pm - used such an odd slice of the city I not only can't get picked up, it doesn't GO any where I go.

I would love to use either of these programs both for the novelty and because I think Autonomous driving is great, but I literally can't use the program I do have access to.

zndr commented on Tell HN: After 10 years of experiments, custom username emails receive no spam    · Posted by u/sbf501
OrangeMonkey · 4 years ago
I'm glad you had a good experience. I had a different one.

I've ran my own domain for longer than you have, and many emails have been compromised.

Some are 100% from companies selling the emails to sister companies.

The majority, though, is from a company itself being compromised by hackers / database access / etc. LinkedIn, Neopets, ProFlowers, TeeSpring, etc. I can go on.

zndr · 4 years ago
Seconding this.

And to compound this after doing a half ass job of what OP has done, I recently moved my custom google apps free domain to have a second reception domain i use JUST for this with a `.email` TLD (side note: the amount of tools that don't see modern TLD's as valid is enraging)>

I made the (maybe poor) choice of donating to political campaigns before the last US election using these emails

- `Biden-campaign@` - `democrats@` - `<specific local race@`

All of those I've had to unsubscribe from about 2-3 dozen total OTHER email lists as those emails are literally sold/given out to other campaigns. the biden one being the worst.

Also if you have your own business you'll start getting solicitations, LOTS of solicitations. And god forbid your email is on an old resume, or somewhere else.

Now, is any of this "technically" spam? Maybe but not really. Do I consider it worthless? yes.

But to site your last specific one. I did a search for an address I know was on a compromised product. Specifically a game Heroes of Newerth. They were hacked in I believe 2015 and the list was sold. My email was my old method `name+hon@email.domain`. I get like 20~ emails to that a year and all of them go to spam or are flagged as spam automatically.

zndr commented on Apple execs: Let's take a 30% cut of Uber and Lyft's membership programs (2018)   twitter.com/TechEmails/st... · Posted by u/mdoms
mindwok · 4 years ago
I feel like these marketplaces could maybe justify 30% on the purchase of an app up front, where there are clear benefits to the exposure and platform offered by them. But ongoing revenue is really attributable to the app itself and feels to me much harder to justify.

At this point I’d be happy if Apple just let me install apps outside their ecosystem, then they could at least defend themselves by saying if the developers aren’t happy with the terms of the App Store they can offer alternative methods.

zndr · 4 years ago
It's more than that: it's the fact that all of the payment info is there. Every step, field entry, hurdle you put infront of a consumer is usually associated a significant increase in "cart abandonment". By apple allowing you to just apple pay straight in and avoid CC, and billing address etc, they are decreasing the hurdles and increasing the conversion.

Is it worth 30%? In 2013? Maybe In 2021? Definitely not. It should be closer to 5%.

That being said I do like using Apple subscriptions because they make it REALLY easy to cancel them, all in one place, something that can't be said for a lot of other services.

zndr commented on Gitlab S-1   sec.gov/Archives/edgar/da... · Posted by u/laminarflow
LewisVerstappen · 4 years ago
Interesting, thanks for the link.

Median salary seems to be $170k according to Levels.fyi -> https://www.levels.fyi/company/GitLab/salaries/Software-Engi...

zndr · 4 years ago
You can actually see their salary calculator here https://about.gitlab.com/handbook/total-rewards/compensation...
zndr commented on Housing First [pdf]   hcd.ca.gov/grants-funding... · Posted by u/idworks1
majormajor · 4 years ago
That's not the goal according to whom?

I think there's multiple sides of the argument that getting everyone off the streets is the goal:

From one angle, if someone's in such a bad state that they refuse shelter, is it really better from a "help them get back on their feet" to leave them there?

From another angle, we treat very few other civic obligations as "optional." If you don't want to pay sales tax, you still have to, for instance.

zndr · 4 years ago
Often, it's not the simple. Some times it takes months of trust building. Sometimes the person is part of a community, a community they may have been part of for months or years. Yes their life isn't easy, but putting them in housing might remove them from that support network. Often times people are terrified to move away from the only group of people they've known.

this is deeply on display in the "According to Need" podcast series released by 99% invisible recently. https://99percentinvisible.org/need/

Ideally everyone would see the benefits and realize this is better, but these people have a lifetime of other issues and being houseless is only part of it.

zndr commented on Amazon workers vote against unionizing in Alabama   wsj.com/articles/amazon-i... · Posted by u/cwwc
TheAdamAndChe · 5 years ago
Collective bargaining lets the employees push back against issues that would otherwise risk their career. For example, an individual speaking up against horrible working conditions, metric-focused managers, and ignorance of unsafe practices would risk getting fired, so the issues would persist. A union would have the leverage required to push back against such issues.
zndr · 5 years ago
While you're correct, Amazon is so large that this single center being nuked from their org chart would have been an inconvenience. I think it's very easy for us to say "this would help you" but the reality is, it might have drawn a line in the sand, at the cost of every single employee's job.
zndr commented on Gitlab Support is no longer processing MFA resets for free users   about.gitlab.com/blog/202... · Posted by u/WalterSobchak
cmeacham98 · 6 years ago
Is it just me, or does this make my MFA-protected account safer?

I wish conpanies offered this as a feature, in the sense I'm much more worried about someone SEing their way into my account rather than me losing access to all my MFA methods and backup codes or whatever.

zndr · 6 years ago
Yes 100% it does make it safer.
zndr commented on Don't close your MacBook with a cover over the camera   support.apple.com/en-us/H... · Posted by u/ra7
causality0 · 6 years ago
The question is whether this is a firmware implementation that's just waiting for a 0-day or if the +V for the CMOS sensor is literally wired to the LED. If the latter I'd like to see a picture of it.
zndr · 6 years ago
It isn't the led is physically slaved to the power of the camera, the previous version was firmware fixed and was hacked, hence the change.

u/zndr

KarmaCake day112October 9, 2019View Original