HNHacker News
TopNewBestAskShowJobs

aja12

33 karma · joined December 18, 2024

After being a lurker for about 5 years, I finally created an account, due to... I don't really know. Enthusiastic about self-hosting and cybersecurity. Proficient in Python, interested in learning Rust. Mostly using HN as procrastination, and as a great source of amazing open source tools.
submissionscomments
aja12··on Iran War Live Updates: U.S. and Iran Send Conflicting Signals on Peace Prospects
From an exterior viewpoint, all this portrayal of Trump as either insane or an idiot is as useless and dangerous as the sanewashing.

I believed Trump was insane/an idiot during his 1st mandate. I no longer believe so.

I firmly believe he is an ingenious antagonist with ulterior motives using advanced manipulation and destabilization techniques. He moved the Overton window so far and fast that the world doesn't know how to react, and any reaction will be too little too late.

Trump is taking the USA's economical/social structure apart at a frightening pace, and unfortunately a lot hinge on the USA elsewhere.

He should not be seen as incompetent/unfit for office, he should be seen as a hostile entity to get rid of yesterday.

And I fear it's too late, the USA won't react until he's made the "necessary constitution changes" and been elected for his 3rd mandate.

Getting rid of Europe's ties with the USA will be arduous but I don't see any alternative

aja12··on If you’re an LLM, please read this
Yes! When I learned of Anna's Archive a few years back I too was frustrated by the lack of a short explainer of how to access single files, existence of an API, etc. Now I'm envious of LLMs somehow
aja12··on I was banned from Claude for scaffolding a Claude.md file?
Being in the same boat as you I switched to OpenCode with z.ai GLM 4.7 Pro plan and it's quite ok. Not as smart as Opus but smart enough for my needs, and the pricing is unbeatable
aja12··on MTOTP: Wouldn't it be nice if you were the 2FA device?
Actually, the real countermeasure to PTH is to disable NTLM auth and rely only on Kerberos (and then monitor NTLM as a very strong indicator that someone or something is attempting PTH)

Of course kerberos tickets can be abused too in a lot of fun ways, but on a modern network PTH is pretty much dead and a surefire way to raise a lot of alerts

(You are absolutely right that privileged accounts must never login on less privileged assets, however!)

aja12··on MTOTP: Wouldn't it be nice if you were the 2FA device?
> cloud-based synchronization

Well I don't disagree that it might be possible to abuse cloud sync in some way to export the secrets, but it's not quite as egregious as just including the secrets by default in an app backup

Not perfect, but (imho) still better than SMS 2FA, mail 2FA, or lack of 2FA

aja12··on MTOTP: Wouldn't it be nice if you were the 2FA device?
>Most TOTP apps support backups/restores, which defeats this.

Citation needed? Yubico authenticator doesn't (the secure enclave is the Yubikey). I'd be very surprised if MS Authenticator and Authy (which I don't use but are the most popular apps that I know of) support such backups

aja12··on Toad is a unified experience for AI in the terminal
From someone who has not tried the software but might be interested if it gains traction:

You should decide whether you are building this for yourself or as a product to others. Each stance is perfectly valid but are somewhat not compatible, the software can be very opinionated or intuitive but attempts to be both seem to often fail.

If you are building opinionated software for yourself and are ok with alienating a part of the userbase: great, some great software are built this way! (Alacritty, Kakoune come to mind). This should be clearly communicated to prospecting users though, it may need to convey "this software has strong opinions you may not agree with, that's fine but it may not suit you" somehow.

If you aim for maximum reach: expect your sense of what is "intuitive" to constantly be challenged, and to have to make many difficult compromises. You also need to take feedback from a more forgiving angle, and above all, assume good faith from your users. In this instance, GP stated their enthusiasm for your shared vision of the problem space, and your knee-jerk reaction was calling them a troll.

Builders of opinionated software should pay trolls no heed and refrain from engaging, and builders for maximum reach should think trolls don't exist.

footnote: `toad run` expecting a folder and not a command seems to fall in the "opinionated" ballpark

aja12··on France threatens GrapheneOS with arrests / server seizure for refusing backdoors
Yet.

When ChatControl will be in place, it'll only be a matter of time

aja12··on Post-heist report reveals the password of the Louvre's video system was 'Louvre'
Bullshit journalism. This was not a post heist report, every buzzword chasing so called news outlets out there are repeating ad nauseam findings that were listed in a report produced by ANSSI in 2014! 2014! Eleven. Years. Ago! Did Louvre kept obsolete software around all this time, yes they probably did but this "Louvre" password claim just grinds my gears
aja12··on Burner Phone 101
Baseband SoC running their own OS independent from Android/iOS and staying asleep (while still listening for incoming signals) is very much no longer in conspiracy theory territory and more an established fact now. I don't have the source at hand but it's in one of the standards. And the purpose is very clear: LEA like Interpol must be able to locate any IMEI at any point if in tower range, regardless of the power state of the "main" OS
aja12··on Replacing CVE
As a pentester, who does not love CVSS[0], I found the article explaining how to replace CVSS with CVSS very amusing

[0] CVSS is often poorly understood and used by internal teams so for our internal engagements, we prefer words like "minor", "medium", "major", "critical" to describe criticity and impact and "easy", "medium", "hard" to describe exploitation difficulty (which loosely translates to likelihood), and the reasoning behind all this is very similar to what CVSS does

aja12··on Exploring the Paramilitary Leaks
First of all, I'm not a gun control activist, and I do agree with some of your views.

However:

> I think this is a uniquely American problem because America is a unique country. No other nations have the incredible wealth, diversity, and rights of America, and looking to other countries to emulate is imo, a mistake.

- increased wealth should be correlated with a reduction in shootings,

- population diversity is not a unique feature of the USA, it is comparable, or arguably lower, than most European countries,

- same for rights: the rights of a USA citizen are comparable to the average EU citizen. Many EU countries allow the possession of guns (although most forbid taking arms out of one's home unless it's for transport, e.g., to the firing range, and most EU states vehemently forbid concealed carry). There are some differences regarding Free Speech, however, where most EU countries allow it largely, but restrict hate speech more.

It's true that shootings are a somewhat unique USA problem, but I'd look more into cultural differences than into rights and demographics.

aja12··on Google does not want rights to things you do using Chrome (2008)
Oh please

Apple is extremely user-hostile, going to great lengths to strip users of control of their devices, gaslighting them into staying in the walled garden (with great success), while simultaneously siphoning as much user data as it can get away with, and employing as many dark patterns as it can to prevent the users from exercising their rights (it's worse than Meta in this regard).

Truly, Apple always amazes me with its ability to put expensive rose tinted glasses on its users's noses.

aja12··on Euclid finds complete Einstein Ring in NGC galaxy
An important part of GP's comment was "until proven otherwise"

We have no proof of extraterrestrial life. Yet.

aja12··on Does iOS have sideloading yet?
> A big part of the reason I use Apple products is that they protect not only me, but my family who don't know what the implications of sideloading are. I know that the apps my phone runs have been given the green light by Apple.

The malware my family is most exposed to nowadays have names: Onedrive, iCloud, Google Drive. They are all designed to collect all the user's data, are all opt-out, opting out is filled with dark patterns. And regarding dark patterns, having recently gone through the motions of downloading all my data and then deleting my X, Facebook, Instagram, Microsoft, Google and Apple accounts, I can confidently say that Apple is by far the _worst_. Yes, when it comes to exercising one's rights, Apple is worst than even _Facebook_.

Users are much less exposed to non-branded malware nowadays, as the incentives to torrent random crap have mostly disappeared, and protection against spam/fishing has improved.

aja12··on Does iOS have sideloading yet?
> Yes and infected Xcode and various SDKs you get on your laptop are actually the biggest threat to iOS security (other than just literally malicious devs). Devs torrenting an xcode and then infecting their users is a thing.

Would it happen as often if the tooling was free?

aja12··on I Went to SQL Injection Court
That's fallacious for two reasons:

1: you can set secure defaults at one place globally, but your code must be correct all the time to be free of SQLi

2: it's usually not the same persons who configure the DB and who write the code.

Security is an onion, not a coconut.

aja12··on Scented products cause indoor air pollution on par with car exhaust
Did you invite him on purpose?
aja12··on TinyX: Small Featured X Server
Why are people downvoting your comment? It's not against the guidelines, is it?

I strongly think you are wrong, and I strongly disagree with your points, but I don't see why your opinion should disappear, lest this thread turn into an echo chamber.

aja12··on TinyX: Small Featured X Server
Of course. And it's fine? I'm a proponent of GPL for this reason, I see it as an ideology to which I subscribe, I don't see the problem?
aja12··on CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
If you do that on the server side, per account, it works. Small DoS risk, but it remains acceptable
aja12··on CAPTCHAs: 'a tracking cookie farm for profit masquerading as a security service'
If you do that on the server side, per account, it works. Small DoS risk, but it remains acceptable
aja12··on Linux as co-operative Windows process (2017)
What's the harm? Having multiple alternatives to any component of the software stack is a good thing, and it fosters understanding and improvement, doesn't it?
aja12··on GitHub Copilot: The Agent Awakens
Pivot into cybersecurity? As a pentester, a mountain of security bugs in a mountain of AI produced slop that no one understands is the ideal provider of job security, I guess

Maybe pentesting can be partly automated, but "the devil is in the details" and a pentester's primary quality is to look where the automated software won't.

I don't know, truly. The future is somewhat foggy.

aja12··on My failed attempt to shrink all NPM packages by 5%
> Probably not worth the added complexity, but in theory, the package could be published immediately with the existing compression and then in the background, replaced with the Zopfli-compressed version.

Checksum matters aside, wouldn't that turn the 5% bandwidth savings into an almost double bandwidth increase though? IMHO, considering the complexity to even make it a build time option, the author made the right call.

aja12··on Operation Leg: When the RAF airdropped a prosthetic leg into a German POW castle
> Fortunately, there are real people in the real world who are free of our burdens.

You might be right about the general, who knows. But Goring? No, that man was definitely a computer.

aja12··on 0-click deanonymization attack targeting Signal, Discord, other platforms
I'm a bit at a loss there. Has _anyone_ ever considered Signal to be anonymous? Or Discord? If so, I have bad news: they are not anonymous. At all. Not even slightly anonymous. Nor did they ever claim to be, they only claim to not be able to read your messages (Signal claims that, I don't know about Discord, I doubt it). And that claim has flaws (sure the crypto is sound but have you thoroughly reviewed and compiled the version you are using right now?)

At the very best, they are weakly pseudonymous, but that's about it. And yes, loading media by default has always been a staple of applications who prioritize their users' convenience at the expense of some security, a fine choice for the usual threat model of their users. And embedding media in messages has always been a staple of deanonymization attacks.

So ok, the tracking pixel has been shown to still be a relevant technique today, that's nice but not surprising.

If you want to remain anonymous though, don't use Discord or even Signal, and I'd advise against posting on HN either. Maybe, if you automate the pasting of messages (no js!) that has been reworded by a local llm from throwaway accounts through whonix, at random times that can't be correlated to your timezone, you _might_ have your chances. Don't bet on it.

Anonymity does not exist any longer.

aja12··on Tabby: Self-hosted AI coding assistant
As a cybersecurity professional (as in, the more cybersecurity problems there are, the less likely I am to ever find myself out of a job), I'm rooting for AI!
aja12··on Very Wrong Math
From what I've learned reading AdmiralCloudberg's plane crashes analysis [1]: altitude heavily matters in fuel consumption. Jet planes use a lot less fuel at a higher altitude, up to the point that a plane on the verge of running out of fuel at a medium altitude might manage to squeeze in 50 or 100 more miles of flight by climbing 5000 feet, even accounting for the increased fuel consumption during climb. I guess that correlates with speed as well. Turbofan engines, on the other hand, are more fuel efficient than jet engines at lower altitudes, hence they remain common for interstate transit. The difference seems to be directly caused by the effect of air "thickness" on the engines.

[1] https://admiralcloudberg.medium.com/

aja12··on Conda: A package management disaster?
Like sibling comments, after using poetry for years (and pipx for tools), I tried uv a few months ago

I was so amazed of the speed, I moved all my projects to uv and have not yet looked back.

uv replaces all of pip, pipx and poetry for me, I does not do more than these tools, but it does it right and fast.

If you're at liberty to try uv, you should try it someday, you might like it. (nothing wrong with staying with poetry or pyenv though, they get the job done)

Page 1 of 2Next →