frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Releasing rainbow tables to accelerate Net-NTLMv1 protocol deprecation

https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables
32•linolevan•1h ago

Comments

ubuntulover2011•1h ago
pretty cool
postepowanieadm•1h ago
Can't wait for someone to decide one of protocols used by google needs to be deprecated.
bawolff•1h ago
Plenty of protocols used by google over the years have been deprecated. The difference being that google actually stops using insecure protocols when they are discovered to be insecure instead of trying to sweep things under the rug.

Keep in mind we are talking about a protocol from 1987. How many protocols from 1987 is google currently using?

schmuckonwheels•57m ago
Google does whatever is convenient and makes them money. Altruism was never part of the equation.
bawolff•52m ago
Sure. Not being hacked is good for business.

Keep in mind that google is primarily a cloud business. That means that they take on a lot more of a risk, as when they are hacked its a them problem vs traditional software where its much more the customer's problem. Security is very much about incentives, and the incentives line up better for google to do the right thing.

schmuckonwheels•47m ago
It's more about when Google assumed full control of the cloud, the browser, the OS, and everything in between they self-appointed themselves as the unelected standards board of the Internet, and forced everyone else to follow their whims and timelines. Some of which are completely insane.
Retr0id•1h ago
Well, you'll be waiting 20 years or so post-deprecation if you want an equivalent timeline.
schmuckonwheels•1h ago
Google thrives on being the Internet's biggest bully.

It turns out when nerds get a billion dollars they like being bullies too.

aunty_helen•1h ago
> under 12 hours using consumer hardware costing less than $600 USD

Great, so someone with half a motherboard can break this hash

schmuckonwheels•1h ago
"To demonstrate how crappy most front door locks are, to boost our company's social media cred we will be leaving drills and a dish of bump keys at the entrance of the neighborhood."
bigfatkitten•58m ago
NTLMv1 rainbow tables have been available for 15-20 years. The only thing new is that Google are publishing theirs.
throawayonthe•11m ago
you say that like it's a negative analogy
observationist•49m ago
This empowers script kiddies, but not significantly moreso than they already were. Of all the places this is still in use, they've been exposed for years, so this isn't likely to result in a a bunch of new exploitations.

However, it's most likely to be used by governments, with legacy servers that are finicky, with filesharing set up that's impacted other computers configured for compatibility, or legacy ancient network gear or printers.

I wonder who they're pushing around, and what the motivation is?

bigfatkitten•34m ago
Mandiant is Google's incident response consulting business. Having worked for many years in that field myself (though not for Mandiant), they're probably sick of going to the same old engagements where companies have been getting owned the same way over and over again for the last 15 years.

What releases like this do is give IT ops people the ammunition they need to convince their leadership to actually spend some money on fixing systemic security problems.

Retr0id•32m ago
I suspect Mandiant hears a lot of "this is impractical to exploit so we don't care" from their clients. Now they have a compelling rebuttal to that.
TacticalCoder•49m ago
Holy smoke. I honestly thought the 90s called and wanted their Windows exploits back (TFA mentions 1999). I do remember talk about this from many moons ago.

But we are in two-thousand-twenty-FUCKING-six.

It's unbelievable. Just plain unbelievable.

1970-01-01•46m ago
They're just dumping them out as 2GB blobs onto a cloud? Where is the zippy search UI? Very lazy behavior for the hyper giant Google.
bflesch•19m ago
I wonder how the Mandiant acquisition is regarded within google.

Was it a success? Is Mandiant a cash cow or was it basically an acquihire?

The big "contact mandiant" button next to the post feels a bit like trying to stay relevant and acquire more customers.

Miyazaki's Sherlock

https://animationobsessive.substack.com/p/miyazakis-sherlock
1•ani_obsessive•1m ago•0 comments

2026 May Be the Year of the Mega IPO

https://www.nytimes.com/2026/01/14/technology/ai-ipo-openai-anthropic-spacex.html
1•bookofjoe•1m ago•1 comments

Rcarmo/rdp-HTML5: RDP web client with Golang back end

https://github.com/rcarmo/rdp-html5
1•rcarmo•2m ago•0 comments

Show HN: IncidentPost – Write public incident postmortems without heavy tooling

1•ededft•4m ago•0 comments

At the phase 'build a startup cause I can't get hired, and maybe I'll get hired'

2•danver0•5m ago•1 comments

Ralph Loop Built into AWS Kiro

https://kiro.dev/blog/run-all-tasks/
1•nslog•6m ago•0 comments

Landscape beneath Antarctica's icy surface revealed in unprecedented detail

https://www.bbc.com/news/articles/c9qpx2qqeq7o
1•ranit•7m ago•0 comments

Floss and Training LLMs

https://chronicles.mad-scientist.club/tales/on-floss-and-training-llms/
1•birdculture•10m ago•0 comments

Californians have a new privacy tool for deleting their data

https://apnews.com/article/california-data-privacy-tech-tip-cb6a69cb238abc62e136f02b4996e570
2•geox•11m ago•0 comments

ChatGPT and Codex Are About to Get a Helluva Lot Faster

https://jpcaparas.medium.com/chatgpt-and-codex-are-about-to-get-helluva-lot-faster-51ad25a7eed0
2•zenoware•11m ago•1 comments

Statistical Rethinking 2026 [video]

https://www.youtube.com/watch?v=ztbYkBPDOgU
1•Anon84•15m ago•0 comments

Trump Sets Fraudster Free from Prison for a Second Time

https://www.nytimes.com/2026/01/16/us/politics/trump-fraudster-pardon.html
4•2OEH8eoCRo0•17m ago•0 comments

Mothers Against Decapentaplegic

https://en.wikipedia.org/wiki/Mothers_against_decapentaplegic
2•md224•18m ago•0 comments

Omero: Pervasive User Interfaces in the Plan B Operating System

https://www.youtube.com/watch?v=iKy2UxFLhgQ
1•rfmoz•24m ago•0 comments

What are we actually rushing towards with AI?

https://slowdown.lovable.app
2•liveink•25m ago•0 comments

Building a Quake PC

https://fabiensanglard.net/quake_pc/
3•roskelld•26m ago•1 comments

I Got a Job in an Awful Job Market

https://rebekahbastian.substack.com/p/i-got-an-awesome-job-in-an-awful
2•mooreds•26m ago•0 comments

The Dilbert Afterlife (By Scott Alexander)

https://www.astralcodexten.com/p/the-dilbert-afterlife
3•inglor_cz•31m ago•0 comments

The crisis whisperer: how Adam Tooze makes sense of our bewildering age

https://www.theguardian.com/business/2026/jan/15/the-crisis-whisperer-how-adam-tooze-makes-sense-...
1•Caiero•32m ago•0 comments

Make boxes from dried citrus rind

https://pixey.org/p/confluency/917527402164543260
1•sohkamyung•33m ago•0 comments

PAZ O.S. – A "Bio-Civic" Alignment Framework for Ethical LLMs

https://github.com/carropereziago-blip/PAZ-O.S-GLOBAL
1•PiSounds•34m ago•1 comments

FCC Poised to Exempt Amateurs from Foreign Adversary Reporting Requirements

https://www.arrl.org/news/fcc-poised-to-exempt-amateurs-from-foreign-adversary-reporting-requirem...
1•7402•36m ago•0 comments

FTC Finalizes Order Banning GM from Sharing Driver Data

https://www.pcmag.com/news/ftc-finalizes-order-banning-gm-from-sharing-driver-data?test_uuid=04Ip...
9•CGMthrowaway•40m ago•0 comments

Ask HN: Browser extension vs. native app for structured form filling?

2•livrasand•40m ago•0 comments

IETF@40

https://www.ietf.org/blog/ietf-40/
2•sohkamyung•44m ago•0 comments

Re: Mix: open-source repairable blender

https://github.com/openfunkHQ/reMix
2•rishikeshs•45m ago•0 comments

I thought Grammarly was essential. It wasn't

https://www.makeuseof.com/stopped-paying-for-grammarly-once-found-free-open-source-alternative/
3•chilipepperhott•54m ago•0 comments

I have settled on XChaCha20+Blake3 as the AE suite of choice for my projects

https://mccarty.io/chacha20-blake3/
2•enz•59m ago•0 comments

For profit university offers scholarship to RuneScape skill cape recipients

https://usv.edu/max-achievement-scholarship
1•rickcarlino•59m ago•1 comments

Show HN: Neurop Forge: Live Demo /Real AI Action

https://neurop-forge.onrender.com/demo/google
1•LBWasserman•59m ago•0 comments