<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: chasemiller</title><link>https://news.ycombinator.com/user?id=chasemiller</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 19 Apr 2026 05:00:53 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=chasemiller" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by chasemiller in "I hacked Monster Energy"]]></title><description><![CDATA[
<p>"ETHICAL hacker"<p>...yeah... I don't think those words mean what you think they mean...</p>
]]></description><pubDate>Sat, 23 Aug 2025 20:35:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=44998928</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=44998928</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44998928</guid></item><item><title><![CDATA[New comment by chasemiller in "Google’s OAuth login doesn’t protect against purchasing a failed startup domain"]]></title><description><![CDATA[
<p>yeah, google likes to have fun with the Bug Bounty program. See: <a href="https://bughunters.google.com/about/rules/google-friends/6625378258649088/google-and-alphabet-vulnerability-reward-program-vrp-rules#reward-amounts-for-security-vulnerabilities" rel="nofollow">https://bughunters.google.com/about/rules/google-friends/662...</a></p>
]]></description><pubDate>Tue, 14 Jan 2025 17:33:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=42700634</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=42700634</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42700634</guid></item><item><title><![CDATA[New comment by chasemiller in "Google’s OAuth login doesn’t protect against purchasing a failed startup domain"]]></title><description><![CDATA[
<p>Yes, it's a failure on DankStartup's part.<p>Not really much different than a user buying dankstartup.net, setting up a catch-all email, observing what comes in, and performing password resets for those accounts, allowing for account takeovers.<p>Calling it a vuln in oauth may be a bit hyperbolic, but Google could help prevent it.</p>
]]></description><pubDate>Tue, 14 Jan 2025 17:30:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=42700590</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=42700590</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42700590</guid></item><item><title><![CDATA[New comment by chasemiller in "Object Linking and Embedding"]]></title><description><![CDATA[
<p>OLEs were a phisher's dream</p>
]]></description><pubDate>Wed, 08 May 2024 13:21:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=40297829</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=40297829</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40297829</guid></item><item><title><![CDATA[New comment by chasemiller in "How to register a Kei truck in Pennsylvania"]]></title><description><![CDATA[
<p>@danwilkerson, were you driving around the north hills ~1 hour ago?<p>Just passed one of these and thought to myself, huh, that's pretty neat, only to come home to see this post.</p>
]]></description><pubDate>Sun, 16 Jul 2023 23:18:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=36752385</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=36752385</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36752385</guid></item><item><title><![CDATA[New comment by chasemiller in "Show HN: I made a crowdsourced hourly rate dataset for freelancers/contractors"]]></title><description><![CDATA[
<p>This.</p>
]]></description><pubDate>Thu, 27 Oct 2022 16:04:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=33359608</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=33359608</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33359608</guid></item><item><title><![CDATA[New comment by chasemiller in "Twitter accounts dropping “.eth” from usernames"]]></title><description><![CDATA[
<p>And? Just people sharing their Ethereum Name Service (ENS) names. Still some of the biggest players in the crypto/NFT space on that list.</p>
]]></description><pubDate>Fri, 08 Apr 2022 16:26:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=30959160</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=30959160</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30959160</guid></item><item><title><![CDATA[New comment by chasemiller in "Ask HN: Is domain squatting still profitable? Is there a solution?"]]></title><description><![CDATA[
<p>I think it's important to differentiate between domain name squatters and domain name investors. Squatters are typically registering trademarked names with the hopes of flipping them to the trademark holder, or registering accidentally expired domains names with the hopes of selling them back to the previous registrant (as in OP's case). This is wrong.<p>Legitimate domain name investors are typically investing in generic words, brandables, or exact search term match domains.<p>I used to get mad about domain investors having every name I wanted to use for a project, until someone analogized it to real estate investing. Everybody would open their store on Fifth Ave. in New York City if they could afford it. Unfortunately, storefronts there are very limited. This is basically what generic, one-word .com domains are (frequent sales of $1M+). Domain names are just digital real estate.</p>
]]></description><pubDate>Sun, 08 Aug 2021 16:04:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=28107687</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=28107687</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28107687</guid></item><item><title><![CDATA[New comment by chasemiller in "US Treasury to Allow Blockchains, Stablecoins for Bank Payments"]]></title><description><![CDATA[
<p>This explains the 30% 24hr growth of Stellar. Stellar has been working in this area for years and is built to facilitate exactly these types of transactions. I think they are probably the best positioned to take this on.<p>Also, Stellar USDC support was already slated for February.</p>
]]></description><pubDate>Tue, 05 Jan 2021 15:41:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=25646632</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=25646632</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25646632</guid></item><item><title><![CDATA[New comment by chasemiller in "We View Nikola’s Response as a Tacit Admission of Securities Fraud"]]></title><description><![CDATA[
<p>I... just... wow.</p>
]]></description><pubDate>Tue, 15 Sep 2020 14:52:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=24481836</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=24481836</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24481836</guid></item><item><title><![CDATA[New comment by chasemiller in "Cybersecurity Pros Name Their Price as Hacker Attacks Swell"]]></title><description><![CDATA[
<p>Completely agree. We're working on an idea to handle the boring stuff as part of YC's Startup School 2019. GDPR, HIPAA, CCPA, PCI, etc. compliance + penetration testing and risk assessments.<p>We'll be building it at: <a href="https://secquity.com" rel="nofollow">https://secquity.com</a> or if anyone has any specific questions, feel free to reach out at info@secquity.com</p>
]]></description><pubDate>Thu, 08 Aug 2019 00:57:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=20640855</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=20640855</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=20640855</guid></item><item><title><![CDATA[New comment by chasemiller in "Cybersecurity Pros Name Their Price as Hacker Attacks Swell"]]></title><description><![CDATA[
<p>Bug bounties are a great way to get your feet wet. I've seen many devs (especially web devs) have a lot of success hacking on websites that are built with frameworks they are familiar with. I would recommend checking out Bugcrowd or Hackerone to get started.<p>Besides that, there are a ton of great online courses such as PWK/OSCP, and labs (HacktheBox).</p>
]]></description><pubDate>Thu, 08 Aug 2019 00:53:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=20640823</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=20640823</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=20640823</guid></item><item><title><![CDATA[New comment by chasemiller in "Ask HN: With a single site per comment, which sites do you visit regularly?"]]></title><description><![CDATA[
<p>tweetdeck.twitter.com</p>
]]></description><pubDate>Fri, 03 May 2019 20:43:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=19822087</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=19822087</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=19822087</guid></item><item><title><![CDATA[New comment by chasemiller in "Keybase is now supported by the Stellar Development Foundation"]]></title><description><![CDATA[
<p>As a long time Keybase user and Stellar holder, I couldn't be more excited for this news! Congratulations to all!</p>
]]></description><pubDate>Thu, 08 Mar 2018 15:39:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=16544963</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=16544963</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=16544963</guid></item><item><title><![CDATA[New comment by chasemiller in "Schools warned over hackable heating systems"]]></title><description><![CDATA[
<p>>Mr Munro said it had taken him less than 10 seconds to find more than 1,000 examples.<p>I, too, can use Shodan.</p>
]]></description><pubDate>Fri, 15 Dec 2017 20:23:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=15934759</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=15934759</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15934759</guid></item><item><title><![CDATA[New comment by chasemiller in "Changes to Evernote’s Pricing Plans"]]></title><description><![CDATA[
<p>An OK product/service that I have stuck with for too long out of stubborness/laziness. I would understand these changes if it seemed like there was actually active development happening on the product.<p>I'd say "any suggested alternatives" as well, but I think I can just read the other comments. :)</p>
]]></description><pubDate>Tue, 28 Jun 2016 20:33:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=11997317</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=11997317</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11997317</guid></item><item><title><![CDATA[New comment by chasemiller in "Show HN: Truebill – Find and track paid subscriptions, cancel with one click"]]></title><description><![CDATA[
<p>Wow, beautiful site!<p>I'm loving this trend of services to save me money (Paribus is one other example that I love). However, I too am concerned about handing financial information over to a third party. I'd love to hear the business model.</p>
]]></description><pubDate>Wed, 17 Feb 2016 18:36:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=11120122</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=11120122</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11120122</guid></item><item><title><![CDATA[New comment by chasemiller in "Show HN: Building a Market for Penetration Testing"]]></title><description><![CDATA[
<p>Hey @kenbaylor! I think that this is an awesome approach to addressing the issue of the infosec employee shortage. I've actually been kicking around the idea of building something similar for a while now, so it's exciting to see someone making progress in the area!<p>I saw the StealthWorker table at Shmoocon and wanted to swing by and ask some questions, but I got distracted by some of the other goings-on. Anyways, I finally got around to signing up a few days ago.<p>One issue that I have from the pentester's point of view is the lack of transparency after sign up. I haven't seen any confirmation that my application was received and is under review. However, I understand that StealthWorker is still in its infancy so this is understandable.<p>Excited to see what the future of StealthWorker holds!</p>
]]></description><pubDate>Thu, 28 Jan 2016 23:19:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=10992317</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=10992317</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=10992317</guid></item><item><title><![CDATA[New comment by chasemiller in "Ask HN: How do startups value security?"]]></title><description><![CDATA[
<p>The equity questions was mostly theoretical to get a better idea of how startups value security among their early employees. I completely agree that the business model would likely be unsustainable.</p>
]]></description><pubDate>Sun, 10 Jan 2016 16:42:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=10875900</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=10875900</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=10875900</guid></item><item><title><![CDATA[New comment by chasemiller in "Ask HN: How do startups value security?"]]></title><description><![CDATA[
<p>Hey dsacco, thanks for the great reply! I am a security guy on the outside of the startup world looking in and I was just trying to get a better feel for what the security landscape looks like.<p><i>You'll find that startups between seed funding and Series A are most likely to care about security. They have the funding to pay external firms for audits but they won't want to invest in a full-time security team just yet. After that, if they eventually get to "enterprise" level they'll care more about security and have both an in-house team and external reviews.</i><p>I figured this was the case. Pre-seed startups are too concerned with getting something to market and most who raise (and have something worth owning equity in) would have the funds to outsource to you.<p><i>As for your proposal of equity, I would never do this. Frankly, security services are closer to insurance than they are to building positive value. I have interacted with many startup founders, and most would not take an equity proposal like that for this reason. There are several obstacles.</i><p>The equity for security question was mostly hypothetical to get a better understanding for how security is valued among early employees. When I read the title of Jason's article, "It’s Time For You To Make Security a Core Feature — Not a Tax" all I could think of is what a hard sell that would be to both founders and customers, and you confirmed my assumptions. I completely agree that the business model is not sustainable.<p>Thanks again!</p>
]]></description><pubDate>Sun, 10 Jan 2016 16:40:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=10875894</link><dc:creator>chasemiller</dc:creator><comments>https://news.ycombinator.com/item?id=10875894</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=10875894</guid></item></channel></rss>