HNHacker News
TopNewBestAskShowJobs

b8

1,226 karma · joined August 6, 2021

All comments Copyright © 2021, 2022, 2023, 2024, 2025, 2026, 2027, 2028, 2029, 2030, 2031, 2032, 2033 etc. Mason Corkern, All Rights Reserved. All comments, opinions etc. are those of myself.

mcorkern1@tulane.edu https://qf0.org/

submissionscomments
b8··on Signal Secure Backups
Since phones have a lot of storage, then why not constantly backup locally and overwrite it for newer versions (opt in of course)? Signal already has large operating cost, so a cloud backup with the very low subscription cost is concerning. It would help Signal to get rid of sms registration and move to something less costy.
b8··on ICEBlock handled my vulnerability report in the worst possible way
Am hour and a half isn't enough time to read a DM. Also, the vulnerability would be difficult to exploit.
b8··on Ask HN: Freelancer? Seeking freelancer? (September 2025)
SEEKING WORK | Louisiana, US | Remote or Onsite

Seasoned Penetration Tester with 2+ years of experience that has done contracted work for FAANGs and found serious 0days in their products. Former worked at NCC Group in Chicago and Black Lantern Security doing professional penetration testing.

Services that I offer: Web application penetration testing, source code review, AWS audits + architecture advice, and OSINT theat modeling.

Email: mcorkern1@tulane.edu

b8··on Ask HN: Who wants to be hired? (September 2025)
Seeking: Any role that I can use my technical skills in. Security analyst, consultant, technical support etc.

Location: Louisiana

Remote: Yes, and/or on-site. I'm experienced with both.

Willing to relocate: Yes

Technologies: C++, C#, Python.

Résumé/CV: Full resume on request.

Email: mcorkern1@tulane.edu

GitHub: https://github.com/qf0

Misc: I have over two years of full-time security consulting and blue team experience at NCC Group and Black Lantern Security. Also, I have two 0days and received CVEs under my name and a company research blog post to go along with it. Done contracting for FAANGs and found 0days in their products. Worked at IBM as a programmer too.

I'm eligible for a security clearance and willing to do government work. Already passed a FSP once, but was denied agency specific suitability.

b8··on Launch HN: April (YC S25) – Voice AI to manage your email and calendar
The subscription seems high and it doesn't seem practical to me. Goodluck though.
b8··on Walmart Fires VP in Tech for Taking Daily Kickbacks Starting from $30K
This reminds me of the classic Onion video: https://www.youtube.com/watch?v=rYaZ57Bn4pQ
b8··on 95% of Companies See 'Zero Return' on $30B Generative AI Spend
AI Customer Service is very frustrating to work with as a end user.
b8··on Counter-Strike: A billion-dollar game built in a dorm room
I started playing CS:GO back in 2013 and it was a lot of fun. I played nothing except de_dust_2 and sometimes mirage. It was a big leap from BF and CoD.
b8··on Counter-Strike: A billion-dollar game built in a dorm room
Rust and NukeTown are iconic maps from CoD. At least for younger folks like me who grew up on Xbox.
b8··on GDPR meant nothing: chat control ends privacy for the EU [video]
You can encrypt the email content with PGP or Age, sure. However, metadata such as the Subject line, sender and receiver are in plaintext. Lavabit fixed this, but requires money. You can use i2p tools to fix this too.
b8··on A privacy VPN you can verify
They claim to allow anonymous sign up and payments, but requires an email,an account, zip code and name for Crypto payments, but fake info could be used I guess. I tried ordering via Crypto, but it constantly gives me this error: "Unable to load order information. Try again".

Honestly, I feel more comfortable using Mullvad. This team has some folks with questionable backgrounds and I wouldn't trust Intel. Also VPN providers are usually in non-us countries due to things like the Lavabit, Yahoo incidents and the Snowden revelations.

b8··on ADHD drug treatment and risk of negative events and outcomes
It took 3 months just to get get an initial appointment with my Psychologist and then two months later to get formally tested. Another month wait afterwards to meet with her and get treatment started (Adderall, Xanax etc.). I moved to Kentucky for college and the college doctors as well as many local psychiatrists wouldn't refill my Adderall and Xanax. It took me 3 months of fighting with the college health center to get them to find me a place that would refill and take over my mental health care. My Psychologist couldn't refill them out of state. It's annoying long to get care and to have to fight with doctors.
b8··on I tried every todo app and ended up with a .txt file
I use Google Reminders and Tasks all in my calendar. Sometimes I'll use notepad or Google notes though.
b8··on I couldn't submit a PR, so I got hired and fixed it myself
Reminds me when I got banned from Amazon for suspected fraud (had an old account, but deleted my email and number since it was in a lot of DB dumps). After I got hired, I reached out to the guy in charge of the anti-fraud team at Amazon, and got unbanned. Emails to support etc. did nothing before I reached out internally (unbanned by 1am the next day).
b8··on Ask HN: Who wants to be hired? (August 2025)
Seeking: Any role that I can use my technical skills in. Security analyst, consultant, technical support etc. I'm pretty desperate to be candid.

Location: Louisiana

Remote: Yes, and/or on-site. I'm experienced with both.

Willing to relocate: Yes

Technologies: C++, C#, Python.

Résumé/CV: Full resume on request.

Email: mcorkern1@tulane.edu

GitHub: https://github.com/qf0

Misc: I have over two years of full-time security consulting and blue team experience at NCC Group and Black Lantern Security. Also, I have two 0days and received CVEs under my name and a company research blog post to go along with it. Done contracting for FAANGs and found 0days in their products. Worked at IBM as a programmer too.

I'm eligible for a security clearance and willing to do government work. Already passed a FSP once, but was denied agency specific suitability.

b8··on Ask HN: Freelancer? Seeking freelancer? (August 2025)
SEEKING WORK | Louisiana, US | Remote or Onsite

Seasoned Penetration Tester with 2+ years of experience that has done contracted work for FAANGs and found serious 0days in their products. Former worked at NCC Group in Chicago and Black Lantern Security doing professional penetration testing.

Services that I offer: Web application penetration testing, source code review, AWS audits + architecture advice, and OSINT theat modeling.

Email: mcorkern1@tulane.edu

b8··on Performance and telemetry analysis of Trae IDE, ByteDance's VSCode fork
Great work, glad to read about it in the Discord before u posted it here.
b8··on Ask HN: What are you working on? (July 2025)
Looking for a job and trying to get clients for my new security consulting startup. May start up a local malware cleaning service, but I don't think I'll get any clients since I can't afford a storefront and there's a few small computer repair stores near me. I live in a rural part of Louisiana, so yeah idk.
b8··on Graphene OS: a security-enhanced Android build
I'd install Graphene OS in a heartbeat on my Pixel if they'd add support for Google call screening and feature like Hold for me. Thise features are why I bought my pixel and it's too much of an inconvenience to go without them now. Spam calls have went down significantly and has saved me a lot of time.
b8··on Itch.io: Update on NSFW Content
How did OnlyFans overcome this issue? They were pressured by a payment processor to stop allowing NSFW content, but reverse their decision. How did that pan out?
b8··on Gemini with Deep Think officially achieves gold-medal standard at the IMO
Surprising since Reid Barton was working on a lean system.
b8··on Show HN: Jobs by Referral: Find jobs in your LinkedIn network
And people who do it for money will copy and paste whatever they want in there. I had strong friend referrals and got rejected anyway at Tesla and Amazon.
b8··on Show HN: Jobs by Referral: Find jobs in your LinkedIn network
There's sites where you can pay for referrals or ask for them for free on Blind though. Most people accept randos on LinkedIn, so unsure how many refer you. The only people who've referred me on Linkedin are my previous co-workers.
b8··on Ask HN: Who is hiring? (July 2025)
Do y'all have any plans to open up junior/mid level (2-3 YOE) roles for Web Application Pentesters and could sponsor a clearance?
b8··on Ask HN: Who wants to be hired? (July 2025)
Seeking: Any role that I can use my technical skills in. Security analyst, consultant, technical support etc. I'm pretty desperate to be candid.

Location: Louisiana

Remote: Yes, and/or on-site. I'm experienced with both.

Willing to relocate: Yes

Technologies: C++, C#, Python.

Résumé/CV: Full resume on request.

Email: mcorkern1@tulane.edu

GitHub: https://github.com/qf0

Misc: I have over two years of full-time security consulting and blue team experience at NCC Group and Black Lantern Security. Also, I have two 0days and received CVEs under my name and a company research blog post to go along with it. Done contracting for FAANGs and found 0days in their products. Worked at IBM as a programmer too.

I'm eligible for a security clearance and willing to do government work. Already passed a FSP once, but was denied agency specific suitability.

b8··on Ask HN: Freelancer? Seeking freelancer? (July 2025)
SEEKING WORK | Louisiana, US | Remote or Onsite

Seasoned Penetration Tester with 2+ years of experience that has done contracted work for FAANGs and found serious 0days in their products. Former worked at NCC Group in Chicago and Black Lantern Security doing professional penetration testing.

Services that I offer: Web application penetration testing, source code review, AWS audits + architecture advice, and OSINT theat modeling.

Email: mcorkern1@tulane.edu

b8··on Anticheat Update Tracking
Or just download and check the hash against older versions.
b8··on Detection of hidden cellular GPS vehicle trackers
Also that some devices log data locally and require manual pickup + review to avoid detection. Also LEO have been known to temporarily disable such devices when people do scans to detect them for Undercovers.
b8··on Detection of hidden cellular GPS vehicle trackers
Simply putting a fake plate would bypass that. Truckers usually have a pulley system on their plates to avoid tolls, so maybe more normal drivers will implement such a system or find a way to create something that messes up their camera OCR.
b8··on Denuvo Analysis
Empress has cracked Denuvo protected games within a few days of launch, so not its not stopping everyone [0]. After one person bypasses it then others do from the inspiration they got from the OG. There's a formal theory for it, but I can't recall it currently.

0. https://en.m.wikipedia.org/wiki/Empress_(cracker)

← PreviousPage 3 of 10Next →