HNHacker News
TopNewBestAskShowJobs

akdev1l

844 karma · joined October 27, 2023

submissionscomments
akdev1l··on California moves to exempt Linux from its age-verification law after backlash
You can brute force the real age this way.

Do binary search and you don’t even need that many calls.

1. Is person older than 50? 2. Older than 25? 3. Older than 18? 4. Older than 9? 5. Younger than 14? 6. Older than 16?

akdev1l··on Goodbye Visa and Mastercard: 130M Europeans switching to sovereign payment
You could still have this 1-click experience with another system.

Like you could set some rule like “this vendor is approved for charges below $50”. We don’t need the legacy system for that.

(I don’t know if any payment systems can do that atm, just that if we wanted we could make them do that)

Visa seemed not to care too much about fraud though so at some level they do prefer ease of use over security

akdev1l··on Frontier AI has broken the open CTF format
My biology teacher in school once tried to teach us that winds created by God. Not like spiritually or something but that God literally made the wind I guess.

My “earth sciences” teacher also once tried to argue with me against the universal law of gravitation. (no, she was not referring to Special/General Relativity. She didn’t agree two objects in a vacuum fall at the same speed regardless of mass.

akdev1l··on A 0-click exploit chain for the Pixel 10
As an anecdote, I provided fragnesia.c and the subsequent proposed patch to fix the issue and while it was not able to discover an entirely new vulnerability, I think it was able to find 2 new ways of exploiting the same underlying bug.

This is quite impressive considering I’m just a dumbass with a Claude subscription.

akdev1l··on Dirtyfrag: Universal Linux LPE
The JVM has nothing to do with Android. There is no JVM running android apps.

There was Dalvik VM at one point but now it’s just the Android Runtime.

akdev1l··on Dirty Frag: Universal Linux LPE
A very comprehensive SELinux deployment for one.

SELinux will stop any process in android from loading kernel modules, that’s not allowed. The android permission model as a whole is ultimately backed by SELinux.

akdev1l··on Dirty Frag: Universal Linux LPE
The thing is that we could simply split those modules into separate packages

No reason why you couldn’t just `dnf install -y kmod-rxrpc` if for whatever reason you need that.

akdev1l··on CopyFail was not disclosed to Gentoo developer
interesting but in that case no point in keeping the x bit either and suid binaries should just be 4700 ?
akdev1l··on For Linux kernel vulnerabilities, there is no heads-up to distributions
F44 is safe as the kernel is greater than 6.18.22
akdev1l··on For Linux kernel vulnerabilities, there is no heads-up to distributions
Without read permissions you cannot execute the binary, that would not make any sense.

To execute the binary it needs to be read from disk and loaded into memory.

In fact if you have read permissions but not executable permissions on a specific binary then you can still execute it by calling the linker directly /bin/ld.so.1 /path/to/binary (the linker will read and load the binary and then jump to the entry point without an exec() call)

akdev1l··on Copy Fail
> you dont test exploit pocs on your daily driver.

Do you just like making fake points and pretending other people said them?

akdev1l··on Copy Fail
what the blog says and what the code does are two different things.

For all I know the blog itself is a honey pot. I need to know what the code does before I run it.

akdev1l··on Copy Fail
Disagree because to run the PoC you really ought to understand what it’s doing.

And this code is not readable at all. It is failing at letting people confirm the exploit easily.

akdev1l··on Copy Fail
Agreed lmao the PoC itself looks like you’re getting attacked

Which I guess is true but I would like to verify the attack is the intended one

akdev1l··on Copy Fail – CVE-2026-31431
You’d have to reinstall the su binary itself I guess
akdev1l··on Copy Fail
No, Android doesn’t have suid binaries to exploit like in the PoC
akdev1l··on My audio interface has SSH enabled by default
there’s barely any hacking here

the guy found this through looking at the firmware but nmap -p 22 would have also found this

So like the first thing you would do to attack the device

I found an issue exactly like this on an ISP-provided router. I am nowhere near geohot but also didn’t even do as much as the guy in the article lmao

akdev1l··on Meta tells staff it will cut 10% of jobs
It was. Not anymore. See: layoffs.
akdev1l··on Meta tells staff it will cut 10% of jobs
Also Google has a whole YouTube inside of it
akdev1l··on Meta tells staff it will cut 10% of jobs
I am convinced Mark Zuckerberg does more harm than good for Facebook

like literally they lucked out on the landing the business model early but it feels it has been in an ongoing decline and everything else they have tried has failed spectacularly (and particularly things Mark has put his whole weight behind)

They never became anything more than the ad company

akdev1l··on I am building a cloud
It depends, you could have an application with something like

FROM scratch

COPY my-static-binary /my-static-binary

ENTRYPOINT “/my-static-binary”

Having multiple processes inside one container is a bit of an anti-pattern imo

akdev1l··on I am building a cloud
Also Amazon definitely uses k8s for stuff.

Teams are free to use EKS internally.

akdev1l··on Windows 9x Subsystem for Linux
It’s good use for AI

Have the model spit out example programs to study the API

akdev1l··on Framework Laptop 13 Pro
> The driver can only provide a set of input coordinates to the applications. By default, the system will behave as if you've clicked at the point of a single touch, or mouse-button dragged when you single-finger drag.

Yeah no. All of this depends on everything up to the application.

A gtk2 application will have no support for anything. A GTK3 application running on xwayland will have poorer support as well. And anyway most applications just treat the touchscreen as an invisible pointer as it says there.

Just to give an example of some basic thing that doesn’t work reliably: you can’t reliably use a long press gesture. In most apps that will be equivalent to holding the left click (aka does nothing but a long click). On iOS you will get a contextual menu to select/format text or whatever. (You can find a real report of this issue here: https://www.reddit.com/r/kde/s/crLHZhHkuM - “how do I right click using the touchscreen?” from barely 6 months ago)

Your claim that this is an equivalent experience to an iPad is just false.

I’ve been around long enough to remember setting up TouchEgg, the situation is better now but still not equivalent at all.

Anyway originally I wanted to reply to provide balance to your take so casual readers wouldn’t install Linux on their tablets and expect iPadOS. I think that has been sufficiently achieved by this comment chain, readers can choose which side to take :-)

Cheers!

akdev1l··on I don't want your PRs anymore
I think the author of the article is missing this point.

When you actually work alongside people and everyone builds a similar mental model of the codebase then communication between humans is far more effective than LLMs.

For random contributions then this doesn’t apply

akdev1l··on Framework Laptop 13 Pro
There is a whole section on touchscreen annoyances from the Linux Surface project: https://github.com/linux-surface/linux-surface/wiki/Installa...

> Any gesture functionality is dependent on the software you are running. This includes both, the application (e.g. Firefox) and the desktop environment (e.g. GNOME). The driver can only provide a set of input coordinates to the applications. By default, the system will behave as if you've clicked at the point of a single touch, or mouse-button dragged when you single-finger drag.

I love Linux but no need to embellish the current state imo

I am glad that it is working really well for you though

akdev1l··on Framework Laptop 13 Pro
>With Wayland, it's borderline identical.

Come on lol. I have a couple steam decks and both are really clunky.

Most applications are not built using GTK4 nor Qt6 for that matter.

On my steam deck the keyboard never pops up by itself so I have to use a key combination and it feels like I am moving a ghost mouse around the place (rather than proper touch screen support)

I ran gnome on the deck for a while but anyway the on-screen keyboard provided by the gnome sucked so bad that I gave up (sucked as in, it groups all the keys around the center of the screen tightly together and very small)

I also have an M1 iPad Pro. No comparison because those issues simply don’t exist on iOS.

akdev1l··on Framework Laptop 13 Pro
It supports them via libinput.

Everything around actually a Linux device with a touchscreen sucks.

Like on-screen keyboard will be inconsistent depending on the framework of the app.

comparing to iOS which was built from the ground up around that input method is simply not fair lol.

akdev1l··on Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock
Yeah but then it will only use the certificate on the yubikey and not ask for a password so we’re back to 1FA
akdev1l··on Show HN: Smol machines – subsecond coldstart, portable virtual machines
How does it compare to podman with crun-vm ?
← PreviousPage 2 of 13Next →