HNHacker News
TopNewBestAskShowJobs

WelcomeShorty

856 karma · joined August 16, 2021

A security-focused professional based in Switzerland who brings extensive experience in both technical and regulatory aspects of cybersecurity. Particularly active in discussions about EV technology, security vulnerabilities, and European tech regulations, while often sharing personal experiences and practical advice drawn from a long career in tech.

Roast

Spends so much time talking about EV charging that they probably have range anxiety while walking Claims to be security-focused but probably still uses 'password123' for their coffee machine So Swiss they probably organize their HN bookmarks with the precision of a Geneva watch

Thanks to: https://hn-wrapped.kadoa.com/WelcomeShorty?share

submissionscomments
WelcomeShorty··on SoundCloud confirms breach after member data stolen, VPN access disrupted
Just checked and my account was created (and last used) in 2013...

So at least they get some old accounts to become active again :D

WelcomeShorty··on AWS multiple services outage in us-east-1
Your remark made me laugh, but..:

"Oct 20 3:35 AM PDT The underlying DNS issue has been fully mitigated, and most AWS Service operations are succeeding normally now. Some requests may be throttled while we work toward full resolution."

https://health.aws.amazon.com/health/status

WelcomeShorty··on Can you smuggle data in an ID card photo?
In Switzerland we're one step ahead: ID photos get taken at the counter where they're issued.

You get 2, 3 takes and pick the best. Efficient and secure.

WelcomeShorty··on Most IT companies fail to serve security.txt for RFC 9116 in 2025
We've had people warn for the spam avalanche when we wanted to implement it company wide (about 500 domains).

After 3 years: ZERO spam

WelcomeShorty··on Show HN: I hate online Lorem Ipsum Generator so I made my own
With an expired certificate?
WelcomeShorty··on Tesla retreat from EV charging leaves growth of U.S. network in doubt
- May not require a membership. Must accept credit cards. May not charge more without a membership. Must display price per KwH before charging. Phone-based and car-based payment interfaces allowed but must not be required of the customer.

Cries in European. It'd solve some of my absolute pet peeves with charging: no membership, no over charging without membership AND display price BEFORE charging.

The "bill shock" experience is real here. It happens I pay 2x the average price at random locations without any possibility to see that before I'm finished.

WelcomeShorty··on So you want to abolish time zones (2015)
> "What time does the work day start in Australia?"

Is a really bad example, since Australia has 6... or 9, depending how you look at it.

https://www.timeanddate.com/time/zone/australia

WelcomeShorty··on Just one bad packet can bring down a vulnerable DNS server thanks to DNSSEC
I am "forced" to allow "our" domains to be DNSSEC because... an auditor suggested it as a possible improvement and some manager thought it a good idea to do whatever said auditor proposes.

The argument that absolutely nothing that the world relies on, is not being singed (google Facebook reddit Cisco MicroSoft etc) holds no clout with the believers, unfortunately.

WelcomeShorty··on RSS is still pretty great
https://theoldreader.com/

Just toss in a site you like, it'll (try to) find the RSS feed, and you're done.

I have about 50 sites added in the old reader, and it makes following them easy.

WelcomeShorty··on LubeLogger: Self-hosted, open-source vehicle service records and tracker
I used to track all of this as well. Now I drive an EV and there is absolutely nothing left to track.

The only thing I get to "spreadsheet" with is the ever disappointing km/KW. Which is something I try to avoid to not trigger my range rage.

WelcomeShorty··on Ask HN: How to find time to learn after full-time job?
Priorities.

We all have 24 hours, there is no "finding time", it is just prioritising one thing over the another.

In the mids of my booming (cough) career, I was blessed with 4 children within 5 years. My prios shifted and still I was able to progress in my job, maintain social contacts and sleep :)

Turns out I was maxing my work hours to the absolute max before, and with far less pure time spend doing my job, I reached the same quality & respect. I had been spending my energy / time wrong / sub optimal.

Since that "revelation" I can do soo much more, that I deem important. Including spending very serious quality time with my children & partner. Much more than I was able before.

WelcomeShorty··on The KGB, the Computer and Me – The Cuckoo's Egg Story (1990) [video]
This really made my day, what a fantastic blast from the past.
WelcomeShorty··on One-Pedal Driving Explained
Simply because I've been driving TVs for a while and "in the beginning" when there was no rules for brake lights to be turned on when regenerative breaking, I got into trouble (German highways) with cars driving behind me and not being able to anticipate / react fast enough when I used it.

I quickly learned to force the break lights and started to follow this issue closely. That's how I became aware of the number.

How the EU saddled for 1.3 and not 1.2 or 1.4 is beyond my knowledge.

WelcomeShorty··on Please don't make me use another QR code restaurant menu
With the (ATM) highest version of QR codes and the minimal error correction, you're limited to 4,296 bytes(0).

And V40 is not something I've seen(1) in the wild :)

0: https://www.qrcode.com/en/about/version.html 1: https://commons.wikimedia.org/wiki/File:Qr-code-ver-40.svg

WelcomeShorty··on One-Pedal Driving Explained
The European Union has a regulation that requires EVs to illuminate their brake lights anytime the regenerative-braking system’s deceleration rate exceeds 1.3 meters per second squared, or about 0.13 g.
WelcomeShorty··on Bing Gained Less Than 1% Market Share Since Adding Bing Chat
And my prediction, based on a pool of 3, is that this 1% will be gone a day later.

Have you tried co-pilot? It is the worst. My 3 year old gives more coherent answers and paints better images.

WelcomeShorty··on Smart binoculars can identify 9k birds
They do. Lab diamonds to be precise:

https://www.swarovski.com/en-US/c-01/Categories/Jewelry/f/fl...

WelcomeShorty··on Live proxy and VPN detection
Cloudflare's Warp:

Proxy Score: 55/100 - Very likely a Proxy VPN Score: 15/55 - Could be a VPN (But Unlikely) Client Score: no client threat

And ipinfo gives me:

privacy: Object, vpn: false, proxy: false, tor: false, relay: false, hosting: true, service: "",

WelcomeShorty··on Donkey Kong: A Record of Struggle
Being from that time: it was't.

We spend much "downtime" learning, reading and writing (pseudo) code. Remember, coding was new, access to existing "examples" close to zero, so we had to figure a lot of stuff out.

Paper (no whiteboards either) was an excellent way to tinker, show off and bounce off ideas.

I still find myself writing / drawing a lot before I actually touch a keyboard.

WelcomeShorty··on Inside Job: How a Hacker Helped Cocaine Traffickers Infiltrate Europe's Ports
I had the pleasure to deal with both authorities and the business side of securing platforms that handle the container checks & harbour access.

The forces who are, let's call it "not happy" with any form of security (access control, logging, monitoring, malware, RATs etc.) is insane.

At times I felt nearly half of all involved parties were corrupt. Top to bottom. Commercial and governmental.

Sold absolutely zero solutions and decided to never again deal with the whole industry.

Edit: for completeness I should add that many did not want any additional security measures since this might leave the traffickers no other choice but to get more physical.

WelcomeShorty··on The Mirai Confessions: Three Young Hackers
Nicely written and I can only hope that some young, tech savvy person reads it and realises how persistent "law enforcement" can be and how scary it is to be targeted by them.
WelcomeShorty··on Canned food went from military rations to fancy appetizers
TIL!

I had to check and yes, the cans sold here (Switzerland) have the same code. Now I have a new hangup and that's buying those within the right range :)

WelcomeShorty··on Signal Public Username Testing (Staging Environment)
I have no idea either since:

"you’ll need to install and run a new build (links below), and register for a new account with a phone number (you can use the same one you’re using in Production)."

WelcomeShorty··on No dogs were harmed in the making of this app
> "Engineer" is the protected term, and you have to be licensed to use it.

The IEEE documented that a little different:

It is the IEEE-USA position that:

• Individuals who have graduated with an engineering degree from an ABET/EAC accredited program of engineering education should not be prohibited from using the title “Engineer.”

• The protected titles “Professional Engineer,” “Licensed Engineer,” “Registered Engineer,” and variations thereof, should be reserved for those whose education and experience qualify them to practice in a manner that protects public health, safety and welfare -- and who have been licensed to practice engineering by a jurisdiction.

From: https://ieeeusa.org/assets/public-policy/positions/workforce...

WelcomeShorty··on Security Vulnerability of Switzerland's E-Voting System
Once the "install malware" card has been drawn, you can forget security. Hell, with his argument, you can't even be sure you read what he wrote.

To all experts here: Give it a shot!

https://yeswehack.com/programs/swiss-post-evoting

https://gitlab.com/swisspost-evoting/e-voting/e-voting

WelcomeShorty··on HTTP/2 Rapid Reset: deconstructing the record-breaking attack
For those interested in more on the same topic, there is a decent list of blogs at the end of this:

https://www.cve.org/CVERecord?id=CVE-2023-44487

(and yes, that includes this article here as well).

WelcomeShorty··on The largest DDoS attack to date, peaking above 398M rps
To be effective, you need to either be prepared to hide behind google, Cloudflare or AWS, OR you need some pretty expensive deal with you (large) ISP who can (quickly) filter on their edge.

Sitting at the end of whatever network, you will not be able to do anything against a sufficient volume attack.

WelcomeShorty··on The largest DDoS attack to date, peaking above 398M rps
But these ISPs that give something and inform and even isolate their infected customers are few and far between.

Shout out to Dutch ISP XS4ALL who was (is?) very very strict and active in this space.

WelcomeShorty··on Bounties Damage Open Source Projects
The "99% of reports were incoherent garbage" is exactly what I become from unsolicited sources. They come mainly in via our (security.txt) email.

Since (2019) we have an externally managed bug bounty program (they have and manage the platform the initial triage of reports and paying the bounties (we decide what is accepted and how high the bounty is), our success rate (actionable reports) has sky rocketed.

Our devs love the reports since these are verified to be 1: documented so well, everyone can reproduce them, 2: scored reasonable (much less in house fighting if it's a low or a critical), 3: simple interaction with the individual who triaged | filed the finding (and eliminating the horrible interaction via 3 or more steps).

The money we spend on the bounties AND the service are easily offset by the quick turnaround times and saved internal struggles & meetings.

WelcomeShorty··on Amsterdam to use “noise cameras” against too loud cars
Fellow VFR1200 driver here.

You inspired me to exchange my Akrapovič (came with the bike when I bought it) to the stock pipe (which also came with the bike).

Page 1 of 9Next →