HNHacker News
TopNewBestAskShowJobs

AtomicByte

8 karma · joined December 24, 2024

submissionscomments
AtomicByte··on Bruteforcing the phone number of any Google user
Yes that does happen to be what is commonly done
AtomicByte··on Show HN: Open-source codex UI can use Claude code and codex for parallel tasks
Vibe coders gonna be vibing to this one
AtomicByte··on Radeon Software for Linux Dropping AMD's Proprietary OpenGL/Vulkan Drivers
Kinda sad
AtomicByte··on Bruteforcing the phone number of any Google user
This is super creative and cool. Brutecat back at it again heh
AtomicByte··on Science cuts may close WA LIGO observatory that confirmed theory of relativity
That's honestly disgusting. It shocks me how can people be so ignorant.
AtomicByte··on Xmonad: A dynamically tiling window manager that is written in Haskell
Functional programming confuses me. This is absolutely based tho
AtomicByte··on How Dot Files Became Hidden Files
Okay I had no idea they had history like that
AtomicByte··on Print CHR$(205.5+RND(1));: Goto 10
Creative coding is chillin as awesome as ever
AtomicByte··on Is every memecoin just a scam?
This was actually super informative
AtomicByte··on NASA's Magellan Mission Reveals Possible Tectonic Activity on Venus
Maybe they'll do it on uranus one day too
AtomicByte··on MCP: May Cause Pwnage – Backdoors in Disguise
I really don't want to waste my time explaining this to someone with clearly a subpar understanding of cybersecurity so I'll get an "AI" to:

The blog post "MCP: May Cause Pwnage" highlights critical security vulnerabilities in the Model Context Protocol (MCP) and its associated tools, such as the Inspector. These issues include default configurations that expose services to external networks by binding to 0.0.0.0, the use of GET requests for executing commands—making them susceptible to CSRF attacks—and the potential for DNS rebinding exploits due to the use of Server-Sent Events (SSE). While some may argue these are merely implementation flaws, the fact that these insecure practices are present in official SDKs and tools suggests systemic oversights in the protocol's design and default settings. Given MCP's growing adoption among major AI providers, addressing these vulnerabilities at the protocol level is crucial to ensure secure deployment and operation.

Security experts have echoed these concerns. For instance, in a podcast discussion, professionals highlighted the simplicity and severity of these exploits, emphasizing that such vulnerabilities are inherent in the protocol and its tools, not just in individual implementations. Critical Thinking - Bug Bounty Podcast

Do your research first, kids

AtomicByte··on Show HN: Xenolab – Rasp Pi monitor for my pet carnivourus plants
agree with dis ^
AtomicByte··on Blink AI: Your Instant Shopping Guide
we really are putting AI in everything atp now, aren't we?
AtomicByte··on I ruined my vacation by reverse engineering WSC
no idea there was so much going on behind the scenes of defendnot (I feel like someone sent it to me earlier; thought it was super cool)