Hacker Newsnew | past | comments | ask | show | jobs | submit | theunixbeard's commentslogin

New Zealand in this case!

More behind-the-scenes info could be provided by HN's @JustinSkycak:

* https://news.ycombinator.com/user?id=JustinSkycak

Here's a blog post of his talking about Matteo among other things:

* https://www.justinmath.com/math-academys-eurisko-sequence-5-...


Happy Tiller user as well, with a bit of effort customizing your Google Sheets and you can out-do any SaaS app on the marketplace.


Be warned: The Pixel 5A has a manufacturer defect where they just die out of nowhere:

https://support.google.com/pixelphone/answer/11833075?hl=en

This just happened to me after 1.5 years of usage of my Pixel 5A.

Luckily Google extended the usual 1-year warranty to be 2-years to give free replacements (which I took advantage of and in fact was given a free upgrade to a 6A)... But be prepared for your phone to die out of nowhere.


Looks like PE and venture-backed tech have a bad rep these days given how cynical the comment section is...

It seems the core problem at hand attempting to be solved is baby boomer small business owners retiring and having no one to buy their business (or pass down to who actually wants to run it)...

That seems like a worthy problem to tackle. Definitely will keep an eye on this company over the years to see if the model pans out or not.


For anyone who likes spreadsheets but wishes the boring data input bits were a little more automated, check out: https://www.tillerhq.com

Imagine a Google sheet where 1 tab pulls in all your transactions from each of your banks / credit cards / investment accounts and the other tabs are... Whatever you can imagine.

I am a huge fan, after I graduated from mint.com I've never looked back after finding Tiller.

You can customize to your hearts content (it's Google Sheets, after all), plus they have handy template sheets to get started with.

I personally have sheets to track my monthly spending (by category), my networth, my checking account balance vs sum of all credit card bills, my progress on credit card signup bonus minimum spend challenges are more.



Presumably if your site is behind Cloudflare then this strategy won't work, right? Since the IP addresses that Security Trails sees are just of Cloudflare rather than your actual Heroku IPs...?

Or is it possible in the Cloudflare dashboard there is somewhere to see your Heroku server's IP address?


You need to put in the herokudns.com address that the CNAME is pointing at – e.g. stark-wisteria-rnbgkawldfk6gq7m8308ytts.herokudns.com in our case.


For me the securitytrails.com website just crashes. I put my DNS target: "stark-horse-mrp4jeowu9yvwpnnma32x6hd.herokudns.com", clicked "Run Check" and it seems to redirect to a failed (no CSS) webpage. Anyone else experiencing this?

EDIT: I MANAGED to make it work with this:

https://www.nslookup.io/

Make sure to go through all the tabs at the top (Cloudflare DNS, Google DNS) - for me they were all "no A records found". Only "Authoritative" gave me 3 A records which I successfully managed to use.


That seems to happen when you put in a DNS target that doesn't have any records in SecurityTrails. In that case, it is best to use nslookup


Yeah securitytrails.com was working for me, but went down about 10 mins ago.


Thanks so much, it worked for us.


We use cloudflare. If you look up the IP address for your public domain name, you will get the cloudflare IP, yes. If you lookup the IP address of the CNAME target, you will get the heroku IP.


on Cloudflare do you create A records (with found IPs) with name "www" or "mydomain.com"? also do you make that A record proxied or no? Thank you!


For my domain (https://www.poof.io), it's www.

If you just use something like https://poof.io, then it would be @. Depends on your site.

There should be a few historical IP addresses, but you would create an A record for each of them.


Use an A record and type in @. Proxied is fine.


Worked for us on Cloudflare


We use Cloudflare + Heroku and it worked for us.


Awesome work, Albert! Looks like you are crushing it on HackerOne, over $37K in bounties?

https://hackerone.com/albertspedersen?type=user

You've obviously got a strong career in Security in the future. Have you looked at any Crypto projects? Seems like there are some massive bounties on https://immunefi.com and similar sites.


Security professionals of this caliber often make $37k in monthly compensation, each and every month. That's only $230/hour. If you can do work like this, your consulting rate is at least that for penetration testing.

Bug bounty programs are a bad deal for researchers. The payout for this bug is absurdly low.


Yep. On the hiring side, you can absolutely see this when you get someone's resume. A person with in-industry experience will often not list their HackerOne profile (if they even have one), while students mostly do in my experience.

Payouts are a joke and progress is slow. It wasn't that long ago people were overwhelmingly just arrested or threatened for reporting these kinds of things but thankfully that's becoming rarer.

The amounts for these bounties though seem to be a token gesture and not much else, especially considering the damage someone could have caused with this.


One thing that wasn't immediately clear from the blog posts --- does Cloudflare's solution allow configuration to also send emails from the custom domain email address?

In GMail (and using Google Domains to host my DNS) I've configured this by inputting various settings as per the guide here:

https://support.google.com/mail/answer/22370?hl=en

The key relevant step is: "For school or work accounts, enter the SMTP server (for example, smtp.gmail.com or smtp.yourschool.edu) and the username and password on that account."

Is that kind of thing supported with Cloudflare?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: