HNHacker News
TopNewBestAskShowJobs

ahoog42

40 karma · joined December 21, 2013

submissionscomments
ahoog42··on Qwen3.6-27B: Flagship-Level Coding in a 27B Dense Model
at what point do model providers optimize for the "pelican riding a bicycle" test so they place well on Simon's influential benchmark? :-)
ahoog42··on Litestream v0.5.0
any notes or pointers on how to get comfortable with k8? For a simple nodejs app I was looking down the pm2 route but I wonder of learning k8 is just more future proof.
ahoog42··on Show HN: Dayflow – A git log for your day
if you are on a Zoom/video call, does anyone know if you would have to declare that your "recording" it? I'm thinking more from the legal perspective of wiretapping/consent laws. If you have live transcripts/subtitles does that change any legal requirement.
ahoog42··on Do not download the app, use the website
regarding data collection, both android and ios provide multiple ways to review, approve/deny, and manage access to data. it's certainly not perfect but is being constantly improved. And for the HN crowd, you can always run mobile security/privacy tools like mobSF to inspect the app. I'm not suggesting we should have to do this but we can and frankly browser fingerprinting is opaque, also constantly evolving and quite good at tracking and data collection. i'm not sure avoid the better ux of a native app is much worse and given the privacy tools and data available, I generally prefer the native app
ahoog42··on Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom
If you want to be alerted to new/updated SEC cybersecurity filings, you can subscribe to my free alerts [1] or see the full index of cybersecurity incidents [2] on my tracker (I check SEC EDGAR every 5 mins).

[1] https://www.board-cybersecurity.com/alerts/

[2] https://www.board-cybersecurity.com/incidents/tracker/

ahoog42··on 108B Pixel Scan of Johannes Vermeer's Girl with a Pearl Earring
Jonathan Sawday’s 2023 book “Blanks, Print, Space, and Void in English Renaissance Literature: An Archaeology of Absence.” [1] explores this phenomenon as well across multiple mediums.

It also won the Modern Language Association's top award — the James Russell Lowell Prize for the most outstanding book published in 2023.

[1] https://academic.oup.com/book/46695

ahoog42··on Fast Cash vs. Slow Equity
This is exactly how we built viaForensics in 2009. For the first five years, we performed mobile forensic investigations and gave trainings based on the Android and iOS forensic books we wrote. We were able to self fund software development for the first five years. When we moved from forensics to mobile app security, we required more capital to build our automated software which led to our Series A.

Having an established business with customers in revenue, obviously significantly helps in the fundraising process and evaluation. The other huge advantage is you can benefit significantly from the Qualified Small Business Stock statute which provide an exemption/shield on federal taxes when you sell that is the _greater of_ either $10m or 10x times your valuation at the time of funding.

ahoog42··on South Korean regulator accuses DeepSeek of sharing user data with ByteDance
Despite their goal of enforcing in 2017, it is still not a hard requirement. Back then, about 80% of the apps we tested disabled ATS either partially or fully [1]. It’s rare to see Apple walk something back [2], but here is a blog at the time that talked about it [3].

[1] https://www.nowsecure.com/blog/2017/12/29/enable-ios-app-tra...

[2] https://developer.apple.com/news/?id=12212016b

[3] https://www.klundberg.com/blog/app-transport-security-delay/

ahoog42··on South Korean regulator accuses DeepSeek of sharing user data with ByteDance
We analyzed the iOS app[1] and observed similar traffic as well as a number of basic security issues (hardcoded encryption keys, use of 3DES and some traffic over HTTP).

[1] https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers...

ahoog42··on Grok3 Launch [video]
Any example code or blogs/docs that demonstrate making graphs/diagrams and/or hooking it up to a local code base?
ahoog42··on Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App
agreed the 3DES is a difficult choice to explain. To top it off the encryption key was hardcoded in the .ipa, the IV was null and then reused.
ahoog42··on Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App
Yes, the Android app has multiple vulnerabilities but we focused this report on iOS (it took nearly 40 hours to write the report). Our recommendation is people avoid using the mobile apps. If you want to test the model, I'd suggest Hugging Face/ollama or a hosted solution (multiple companies are now offering that).
ahoog42··on Launch HN: CamelQA (YC W24) – AI that tests mobile apps
Congrats, very exciting. Do you support configuring things like usernames and passwords? How do you handle MFA?
ahoog42··on Microsoft actions following attack by nation state actor Midnight Blizzard
Actually there has been more, e.g. LoanDepot, Inc [1], and then various amended 8-Ks. I’ve been hacking on a side project to parse the 8-K data which is all over the place, including some companies still reporting under old “items” like 8.01 vs the new 1.05 material cybersecurity incident item.

If folks are interested in this space, I just got the mailing list [2] running last night and you can see a list of all the current incidents on my Incident Tracker [3].

I have many more data points I plan on tracking as well as adding 10-K GRC items to the list (potentially helpful for CISOs, other risk managers and investors to eval a companies risk management maturity).

Welcome any feedback!

[1] https://www.board-cybersecurity.com/incidents/tracker/202401...

[2] https://www.board-cybersecurity.com/alerts/

[3] https://www.board-cybersecurity.com/incidents/tracker/

ahoog42··on Why did the OpenSSL punycode vulnerability happen?
Great points.

Static binary analysis looks for the version string but doesn’t currently do deeper analysis of reversed code to see if it’s patched. Could go either way.

And determining if the code is triggered and exploitable is quite challenging. Dynamic analysis can help here, provided you have the coverage.

More generally tho, istm that there will be instances when the version is unpatched and there is some exploitable vector (even if it’s just crashing the app). My hope is to raise awareness for developers (and security) about 1) transitive dependencies and 2) some really old OpenSSL versions in very popular mobile apps. I don’t believe most folks think about this and awareness can lead to shipping safer apps.

ahoog42··on Why did the OpenSSL punycode vulnerability happen?
I decided to review SBOMs from about 3,800 popular mobile apps to see if any included vulnerable versions of OpenSSL v3.0.x. No mobile apps did (not surprised) but what did surprise me was 98% of the OpenSSL versions included in these apps were vulnerable to older CVEs. About 16% of the apps included OpenSSL, mostly as a transitive dependency.

I posted additional details in this blog+video: https://www.andrewhoog.com/post/how-to-detect-openssl-v3-and...

ahoog42··on Chicago startups to watch in 2015
Please let me know if there's any questions or just an FYI link. I recently shared some thoughts on challenges faced when scaling a company - https://medium.com/@ahoog42/go-go-go-stop-a-lesson-in-scalin...
ahoog42··on Chicago startups to watch in 2015
We're Chicago-based startup [1] that helps secure mobile apps and devices and recently completed a 12.5m Series A.

If you're interested in mobile security, you can get an idea about our work in a recently vulnerability we helped Samsung patch impacting 200m+ devices. [2]

Over 50% of our company is remote and we're hiring 30+ people this year. If you're interested in mobile and/or security, would love to hear from you. [3]

[1] https://www.nowsecure.com/ [2] https://www.nowsecure.com/blog/2015/01/27/samsung-corrupdate... [3] https://www.nowsecure.com/careers/

ahoog42··on Ask HN: How can I verify that WhatsApp uses E2E encryption?
If you want to easily do traffic inspection and forensic analysis of stored data for iOS and Android, you can check out the free Community Edition of our mobile app testing lab [1].

Disclaimer, co-founder here.

[1] https://www.nowsecure.com/apptesting/community/