Hacker Newsnew | past | comments | ask | show | jobs | submit | lccarrasco's commentslogin

Optionally, they can give you competitor's swag.


They're used as gifts for abundance in our festival called Alasitas, you can read more about it in the wiki page: https://en.wikipedia.org/wiki/Alasitas


I'd always wondered about this but never thought to ask!


People worried about the morality aspect could sell the exploit, donate the money and report the issue to the manufacturer anyways.


I don't think Zerodium payouts are lump sum... I believe they are staggered in order to mitigate against this stuff.


So far as I know, essentially all grey market vulnerability sales are tranched, which is an important consideration when comparing bounty payouts to the grey market.


What makes you think the seller’s donation is going to counterbalance the harm of his now-weaponized exploit?


The report to the manufacturer with the remark that there is a existing weaponized exploit will lead to a much faster fix. And why you are so sure that there was no weaponized exploit out there before?


So you are okay with submitting the exploit on a silver platter to people who murder dissidents because “you can’t be so sure that there wasn’t an existing weaponized exploit”?


> You get 3 guesses on what happened and probably need just one.

They had no validation on file type and you could upload & access a script that executed commands server-side?


Bingo.

It's really not pretty what can happen when you have a juicy target, plenty of time, and a perfect idea of how you can use it to your advantage.

Fortunately they weren't at all malicious... just looking for ways to grow their little empire to play their war games and hopefully make some cash.


Something similar has been done in China around 3 years ago ~ http://www.chinadaily.com.cn/business/2017-10/10/content_330...


The picture in the bottom of the article shows that varying sizes of pearls need to be counted at the same time, making using weight very unreliable.

Even if only similar size pearls are allowed, small variations multiplied by a large amount of pearls can cause issues, such as distinguishing 100 pearls of 99 grams each from 99 pearls of 100 grams each.


They could use a simple sorting machine that sorts pearls based on size (like how most coin sorting machines work - run all coins over a small hole, the smallest coins fall through, then run have a slightly larger hole after that, and so on).

Then they could have a simple optical/laser sensor below each hole to count how many smallest, smaller, small, medium, large, larger, and largest pearls fall through each hole.

The benefit would then be that if customers wanted pearls of a certain size, they are already sorted.

Maybe there is an enterprising user here that reads this, can easily create it, and reaches out to pearl companies.


$100/mo/dev is deemed profitable to the company si I guess they are happy rather going for contracts for hardware machines


What? A contractor usually will sign a contract and intellectual property agreements to their name, it's obviously not their right to share company information with a third party.


Subcontracting is not against the rules unless the contract specifically says so. Your job as the prime contractor is to manage the subcontractors so that means IP and privacy concerns etc... Houses are built by subs for example. Defense software is built by subs.


Lower privacy can be a failing from a consumer point of view, but an advantage for regulated businesses.


Don't businesses like keeping their financials private? (At least that's what I learned in a business class 20 years ago.)

Perkins Coie released a report [0] saying that privacy coins are compatible with regulation.

[0] https://www.perkinscoie.com/en/news-insights/anti-money-laun...


I believe that the cure for death would not be distributed evenly at first, and by the time everyone has access to it, there are two options:

1.- We haven't solved the problems caused by overpopulation, and in that case standards of living will drop and people will either have less children or choose to end their lives voluntarily.

2.- We have solved them and there is no longer any issue.


What about 3) standard of living will drop and people will have their lives ended involuntarily (ie war)?


Technically you'd have to round to 20 cents, since you can't get 10, 30, 50 etc. cents from 20s.


We already have 10 cent coins.

The common pattern is 1, 2, 5, 10, 20, 50, ...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: