HNHacker News
TopNewBestAskShowJobs

MajesticHobo2

207 karma · joined August 10, 2018

submissionscomments
MajesticHobo2··on VSCode's SSH Agent Is Bananas (2025)
It's not. Or if it is, it's unclear. The article seems more focused on the integrity of remote development servers and deployment targets:

> Unlike Tramp, which lives off the land on the remote connection, VSCode mounts a full-scale invasion: it runs a Bash snippet stager that downloads an agent, including a binary installation of Node.

> I would be a little nervous about letting people VSCode-remote-edit stuff on dev servers, and apoplectic if that happened during an incident on something in production.

MajesticHobo2··on VSCode's SSH Agent Is Bananas (2025)
Is it? I've read the article twice (yesterday when you posted it and last year when it was first published), and that was not my interpretation.
MajesticHobo2··on VSCode's SSH Agent Is Bananas (2025)
This part of VSCode's architecture is acceptable to me. The reverse direction, where a compromised remote can do whatever it wants to my local machine, is not.
MajesticHobo2··on GPT-6 Astra
That is a linear growth problem whose answer is very easy to intuit.
MajesticHobo2··on Tailcat – Like netcat, but over Tailscale’s data plane
You also don't want adversaries to be able to disrupt long-lived streams with bad password guesses, since I think part of Wormhole's security model is it will terminate the session if the other side gets it wrong.
MajesticHobo2··on Tailcat – Like netcat, but over Tailscale’s data plane
They say it's rate-limited, so at least it probably won't scale to large botnets or similar...
MajesticHobo2··on Tailcat – Like netcat, but over Tailscale’s data plane
notabug wontfix; that's the end-to-end principle in action. Bring your own all of that.
MajesticHobo2··on Show HN: Firefox in WebAssembly
Browser sandboxing is now fully solved.
MajesticHobo2··on We Are the Last People Who Know How It Works
It's the same style I see on Twitter and LinkedIn a lot.
MajesticHobo2··on We Are the Last People Who Know How It Works
Why does it have to be deliberate? It's not surprising that people exposed to output from LLMs will unconsciously pick up their linguistic habits.
MajesticHobo2··on Carrot Disclosure: Forgejo
I'd say also add a test that shows the HTML injection (which spurred the PR) isn't possible. Given an attacker-controlled URL of:

    foo onclick
the following shouldn't render:

    <a class="item muted sidebar-item-link" href=foo onclick>
The following should:

    <a class="item muted sidebar-item-link" href="foo onclick">
MajesticHobo2··on Vulnerability research is cooked
It was definitely partially about model quality. The frontier models are capable of producing valid findings with (reasonably) complex exploit chains on the first pass (or with limited nudging) and are much less prone to making up the kinds of nonsensical reports that were submitted to curl. Compared to now, the old models essentially didn't work for security.

If those script kiddies had been using today's models instead and _still_ didn't do any filtering, a lot more of those bugs would have been true positives.

MajesticHobo2··on Vulnerability research is cooked
> With decompilation I think there's a higher risk of it missing the intention of the code.

I'm not sure but suspect the lack of comments and documentation might be an advantage to LLMs for this use case. For security/reverse engineering work, the code's actual behavior matters a lot more than the developer's intention.

MajesticHobo2··on Vulnerability research is cooked
That was then, this is now. The new models are scarily good. If you're skeptical, just take an hour to replicate the strategy the article references. Point Claude at any open-source codebase you find interesting and instruct it to find exploitable vulnerabilities. Give it a well-defined endpoint if you want (e.g., "You must develop a Python script that triggers memory corruption via a crafted request") and see how well it does.
MajesticHobo2··on We mourn our craft
Third or fourth, maybe, not first.
MajesticHobo2··on OpenSSL: Stack buffer overflow in CMS AuthEnvelopedData parsing
Yes, but it would likely have to be chained with other bugs - at minimum, something that gives you an info leak.
MajesticHobo2··on Fixing a Buffer Overflow in Unix v4 Like It's 1973
Yeah, somebody came up with one here: https://news.ycombinator.com/item?id=46469897
MajesticHobo2··on Humans May Be Able to Grow New Teeth Within Just 4 Years
It’s a phase 1 clinical trial designed only to assess safety and determine the appropriate dosage. Future trials will focus on efficacy.
MajesticHobo2··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
Wouldn't platforms see the supposed XSS payloads in their logs and publish analyses of them, or at the very least, announce that they happened?
MajesticHobo2··on XKeyscore
I'm sure they can store far more than 20 TB now, but it is true that the content pool is much larger. I would guess it's not a favorable ratio.
MajesticHobo2··on Show HN: Cadence – A guitar theory app
Thanks for making this! I've been looking for something like this for a while.
MajesticHobo2··on iOS 18.6.1 0-click RCE POC

  xxd IMGP0847.DNG | grep 03e400:
  0003e400: ffd8 ffc3 000e 0e10 800c 5002 0011 0001  ..........P.....
Look at the byte at offset 11 (0xb), it's there.
MajesticHobo2··on iOS 18.6.1 0-click RCE POC
Yes:

  dd status=none if=IMGP0847.DNG bs=1 skip=0x3e40b count=1 | xxd
  00000000: 02
MajesticHobo2··on iOS 18.6.1 0-click RCE POC
You need to click the link that says "RAW (33.0MB)". The filename should be "IMGP0847.DNG".
MajesticHobo2··on iOS 18.6.1 0-click RCE POC
I AirDropped the PoC to my vulnerable iPhone. It didn't cause a crash until I tried to edit it in the Photos app.
MajesticHobo2··on Cross-Site Request Forgery
That's exactly why I don't agree that GETs should be broadly exempted from CSRF protections. I'm not talking about CORS at all.
MajesticHobo2··on Cross-Site Request Forgery
The problem boils down to the lack of equivalence between a site and an origin. The article explains how https://app.example.com and https://marketing.example.com may sit at very different trust levels, but are considered the same site by the browser. You don't want https://marketing.example.com to be able to make requests to https://app.example.com with your authentication cookies, but SameSite wouldn't prevent that.
MajesticHobo2··on Cross-Site Request Forgery
Not sure I agree with this part:

> Allow all GET, HEAD, or OPTIONS requests.

> These are safe methods, and are assumed not to change state at various layers of the stack already.

Plenty of apps violate this assumption and do allow GET requests to alter state.

MajesticHobo2··on What is X-Forwarded-For and when can you trust it? (2024)
XFF handling is the bug that keeps on giving. I'd estimate I've seen incorrect parsing of it in at least half of the web applications I've audited professionally.

The funniest is when the app renders user IP addresses somewhere and you can get XSS through it.

MajesticHobo2··on Local-first software (2019)
You can use FTP and SVN.
Page 1 of 2Next →