- Hive Five
- Posts
- ๐ Hive Five 194 - How The Internet You Loved Died
๐ Hive Five 194 - How The Internet You Loved Died
The Elite College Students Who Canโt Read Books, The Darkest Side of Bug Bounty, Amazon Paid $2.1M+ in Bounties, Buy-For-Life Gear, The Internet's Best Festival, and more...
Hi friends,
Greetings from the hive!
Over the weekend, I watched some League of Legends World Championship.
Watching the best teams from around the globe battle it out is an exhilarating experience.
Sundayโs match featuring FlyQuest was especially inspiring, despite their loss. It was remarkable to see Korean and Chinese pros and streamers praising the team's performance.
In an emotional post-game interview, FlyQuestโs Bwipo said:
"Itโs tough to stay positive but we made you guys believe. That was the goal."
Even for someone who hasn't played League in years, I believe.
What did you do this weekend?
Let's take this week by swarm!
๐ The Bee's Knees
Monetization & Monopolies: How The Internet You Loved Died. Or Why Tech Monopolies Are Actually Good For Society. MORE
The 3 AI Use Cases: Gods, Interns, and Cogs. 1) Gods: Super-intelligent, artificial entities that do things autonomously. 2) Interns: Supervised copilots that collaborate with experts, focusing on grunt work. 3) Cogs: Functions optimized to perform a single task extremely well, usually as part of a pipeline or interface. MORE
The Elite College Students Who Canโt Read Books. To read a book in college, it helps to have read a book in high school. MORE
Bug bounty is a peculiar game between hunters, clients, and intermediaries. Jason Haddix reveals darker secrets, tips, and tricks to address the unfairness that can arise in this arena. MORE
Blaklis, a seasoned bounty hunter, shares his journey from easy wins to epic challenges in the realm of bug bounties. MORE | SLIDES
Upgrade Yourself โ
You're getting the free version. Members get more โ including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Want to sponsor an upcoming issue? Letโs partner up!
Table of Contents
๐ฐ Updates
๐ฏ My work
๐ผ Work
๐ Productivity
Simonโs Jina Reader tool transforms any website into a Markdown file, allowing for easy reading and sharing of web content. MORE
Neovim key combinations people wished they'd learned sooner. MORE
Five practical ways professionals can leverage ChatGPT to enhance their work. MORE
Danny explores Obsidian beta features: editable page preview and web clipper. MORE
The Engineering Leader: Strategies for Scaling Teams and Yourself: Cate Huston in conversation. MORE
๐ Community
๐ Celebrate
Tarek has joined Bugcrowd as an Application Security Engineer, and is excited to work with the community of bug hunters and triage their findings. MORE
โก๏ธ Timeline
Announcing the Nuclei Templates Community Leaderboard and Rewards. MORE
Recon Royale is an exciting competitive platform where participants submit subdomains for a specified target domain. Players accumulate points based on the accuracy of their submissions, striving to achieve the prestigious title of King. MORE
Amazon Paid Hackers $2.1M+ in Bounties. Check it out in this H1-0131 vlog by NahamSec. MORE
Intigriti is hosting a Capture The Flag (CTF) competition on November 14-15, open to seasoned hackers, bug bounty researchers, and beginners alike. MORE
NeovimConf is looking for sponsors. MORE
๐ Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@victoriadotdev | Victoria.dev | Skills for Tech Leaders | Software engineering leadership. Become a better technology leader: Cybersecurity, core @owasp_wstg.
@N_C_B | Noah Callahan-Bever | IDEA GENERATION.
@bellafusari1 | bells | An ellie waltman fanpage with a knack for breaking software.
@proabiral | Abiral | Organising THREAT CON.
@PhillipWylie | Phillip Wylie | Offensive Security Expert horizon3ai | Phillip Wylie Show Podcast Host.
๐ Level up
๐ฐ Read
Android app vulnerabilities go beyond SSL pinning and rooting. Going from Notification to WebView XSS. MORE
ading2210 discovered vulnerabilities in the Chromium web browser that allowed a sandbox escape from a browser extension. Google paid $20k for the bug report. MORE
Alex discusses their efforts to be more deliberate with digital data, including organizing files and keeping only what they'll use. They're using static websites for tiny archives as part of this process. MORE
BattleDash breached 700 million Electronic Arts accounts, exposing user data. Also, I learned that EA has no bug bounty program. MORE
The 3 AI Use Cases: Gods, Interns, and Cogs. 1) Gods: Super-intelligent, artificial entities that do things autonomously. 2) Interns: Supervised copilots that collaborate with experts, focusing on grunt work. 3) Cogs: Functions optimized to perform a single task extremely well, usually as part of a pipeline or interface. MORE
๐ก Tips
Peter, while traveling long-term, carefully built up a gear list to track what worked and what needed replacing, using it to refine their equipment over time. MORE
Video scraping: extracting JSON data from a 35-second screen capture for less than 1/10th of a cent. MORE
Exercises that prevent yourself from living a life with chronic back pain. MORE
The "Indian Warren Buffet" on how he built his $100M+ fortune: Shamelessly Cloning. MORE
A look into why The McMaster Carr website is so blazing fast. It employs various techniques to achieve exceptional speed, including server-rendered HTML, prefetching, CDN caching, client-side caching with service workers, and more. MORE
๐ง Wisdom
What the smartest people do on the weekend is what everyone else will do during the week in ten years. MORE
ChatGPT purportedly generates horoscope-like content by leveraging a recently announced memory feature, but this is merely a superficial parlor trick, lacking any genuine depth or insight. MORE
Real Phone Calls to the UK's Minister of Loneliness. In 2019, 30% of young people reported feeling lonely some, or all the time. MORE
Bill Wear (aka Stormrider), a technical author at Canonical, contemplates the discipline of mastering one's mind. MORE
"The only thing we truly possess, the only thing we might, with enough care, exert some mastery over, is our mind."
Dr. Julie Gurner: "Stop running away from life. Start shaping it. You can do one thing today that intentionally pulls your work & life in the direction you want it to go. One thing. Start today." MORE
๐ Resources
This guide offers practical tips for delivering a captivating pitch or demo at a hackathon, emphasizing the importance of clear storytelling, concise messaging, and engaging visual aids to impress potential investors. MORE
Collection of sources from the Deep and Dark web that can be useful in Cyber Threat Intelligence contexts. MORE
Critical security vulnerabilities were discovered in Grav CMS, with two reported issues assigned CVE identifiers. MORE
CVE-2024-45186 discloses a security vulnerability in the open-source file transfer application FileSender that could expose sensitive MySQL and S3 credentials without authentication. MORE
๐ญ Quote
"Over thinking, over analyzing separates the body from the mind. Withering my intuition leaving all these opportunities behind."
๐ Explore
๐งฐ Tools
x-ray is a Python library for finding bad redactions in PDF documents. MORE
A proof-of-concept WordPress plugin fuzzer that led to the discovery of more than 300 vulnerabilities in WordPress plugins installed on almost 30 million sites. MORE
Graphinder is a tool that extracts all GraphQL endpoints from a given domain. MORE
vulnhuntr is a tool to identify remotely exploitable vulnerabilities using LLMs and static code analysis. World's first autonomous AI-discovered 0day vulnerabilities. MORE
AuthzAI is an automated tool that tests and analyzes API endpoints for potential permission model violations using OpenAI's structured outputs. MORE
๐ฅ Watch
XOXO, โthe internetโs best festivalโ according to The Verge, released their 2024 talks. MORE
Burnout is a prevalent issue in today's fast-paced world. The video examines the causes and effects of this phenomenon, offering insights on how to address it. MORE
Marcus, a security researcher, accidentally created a botnet while scanning the internet for vulnerabilities, leading to an unintentional DDoS attack on their own server. MORE
Scott Hanselman and Mark Russinovich discuss the concept of 'shipping the org chart', where teams' outputs reflect the organizational structure rather than a cohesive product. MORE
The conversation with Kristoffer Blasiak, Google's Mobile Vulnerability Rewards Program (VRP), suggests that there are many potential targets for Android research, despite a lack of people pursuing it. The scope of Android security is vast, with ample opportunities for those willing to explore it. MORE
๐ต Listen
An interview with Dr. Jonathan Bouman, who discusses his unique career path as both a hacker and a healthcare professional, exploring the ethical considerations of hacking in the context of healthcare. MORE
CEOs of public companies often discuss new AI initiatives, but few have actually built anything with it. Drew Houston of Dropbox has built a "Silicon Brain" and shares his insights on this endeavor. MORE
Harry is a master copywriter โ and thatโs not hyperbole. With Marketing Examples, heโs taught over 100,000 people how to write copy that rips. And guess what? Youโre next. MORE
Sam Parr and Shaan Puri talk to Peter Rahal about starting RXBAR with $10K and selling it for $600M, business ideas he would chase today, plus why heโs back with another bar. MORE
Get $200 to try DigitalOcean โ the go-to for all my recon, automation, and VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
๐ Technology
How Meta Movie Gen could usher in a new AI-enabled era for content creators. Movie Gen has four capabilities: video generation, personalized video generation, precise video editing, and audio generation. MORE | PAPER
Atomic CSS Devtools is a Chrome extension that presents Atomic CSS rules, think TailwindCSS, in a non-atomic format, making them easier to interpret and adjust. MORE
FingerprintJS is a client-side browser fingerprinting library that computes a hashed visitor identifier from queried browser attributes, persisting it across incognito/private mode and purged browser data. MORE
Sink is a straightforward, rapid, and secure link shortener with analytics, hosted on Cloudflare. MORE
Huly is an All-in-One Project Management Platform. An open-source alternative to Linear, Jira, Slack, Notion, Motion. MORE
๐ Interesting
The Deal With It GIF emoji generator allows users to create customized animated GIFs with the iconic "Deal With It" sunglasses. MORE
A visual representation of the land use in the Netherlands. MORE
YapThread, a new app, is awaiting iOS approval and will be fully released next week. It aims to transform zombie scrolling into meaningful connections by enabling users to save and discuss content. MORE
Discover how the High-Performance SQLite course shipped dark and light modes for videos. MORE
This is more sad than anything, but the internet has become overly saturated with advertisements, severely impacting the experience for regular users. Tech people (myself included) may not fully grasp the magnitude of this issue, as they often use ad blockers themselves. MORE
๐ Learned something?
Upgrade Yourself โ
You're getting the free version. Members get more โ including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Share Hive Five โ
Share this newsletter with your friends and colleagues.
1 REFERRAL = 20% OFF EVERYTHING IN THE STORE
Until next week, take care of yourself and each other,
Bee ๐
This newsletter may contain affiliate links that support its costs. These links lead to tools, courses, and resources that I've personally found helpful.