HNHacker News
TopNewBestAskShowJobs

bink

2,474 karma · joined August 27, 2016

submissionscomments
bink··on Disney+: New user agreement allows ads before movies in all subscriptions
Mind sharing them with the rest of the class?
bink··on Hackers Got Inside a Flock Camera
There are a lot of theoretical vulnerabilities in various encryption algorithms used by TLS/SSL/DNS. There are also older protocols that have known vulnerabilities but yet don't present a realistic threat to most types of services. I've worked for more than one company that had to decide whether disabling an algorithm and blocking 5-10% of your customers was worth the tradeoff. Having these debates with researchers is tedious.

That said, there are numerous options that should be enabled and several protocols that should be disabled. It just isn't worth the spam you get if you allow submissions for these type of issues.

bink··on Hackers Got Inside a Flock Camera
The TLS/SSL and DNS carveouts are pretty normal. There are a million security options for those services and enabling them all would often mean denying access to anyone running a browser/client more than a few weeks old. Documenting them all would be a PITA so most policies simply prohibit them entirely.

Testing against customers is also a common prohibition for obvious reasons.

bink··on Gateway 2000's hilariously bad ads in the 90s (Part II)
I think there's "bad" in the sense that it didn't accomplish the goal of selling a product (maybe not the case here) and "bad" in the sense that it made many readers cringe or was seen as stupid/tacky. I'm seeing more of the latter in these ads.
bink··on Google DeepMind CEO Demis Hassabis is stepping down
It's just a jump to the left...
bink··on American Airlines flights grounded nationwide due to IT outage: FAA
Boy would I love to see the incident report for these types of incidents. It seems to happen once or twice a year for some airline and yet things never seem to get better.
bink··on I found a WordPress RCEs with GPT5.6 and $25
I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far more (and they aren't).
bink··on A Second-Grade Teacher Revived a Beloved Video Game
Still has a paywall for me.
bink··on The shingles vaccine may reduce the risk of dementia
Not exactly. My doctor wanted to start me on a medicine that would make me more likely to develop shingles so he asked me to get the vaccine series before he'd prescribe the medicine. I guess there's no such thing as a prescription for a vaccine, so I just went to my local pharmacy. I made the mistake of writing on the form that I had no health issues. The pharmacist came out and said because I wasn't 50 and had no health issues they weren't allowed to administer the vaccine. Even after I explained my condition and the doctor's request they still refused. They wouldn't even let me fill out a new form. I had to go to a different pharmacy which conveniently didn't ask about my current health status.

It's stupid too, because the question I answered "wrong" wasn't clear. It basically sounded like they were asking me if I currently had a cold or covid.

bink··on A peek into Reddit's anti-spam internals
I appealed a warning I was given for quoting a Simpsons episode (promoting violence, Reddit-wide and not from a sub) and was my appeal was granted.
bink··on Microsoft 0-day feud escalates as researcher threatens another exploit dump
Responding to bug bounty reports is a thankless job. Especially these days it's a flood of AI spam, language barriers, "pay me first", incomplete reports, huge egos, and people who think every find should be treated as a critical vulnerability. The people who handle these reports often do so after-hours or on holidays. In smaller companies they're also often the ones who manage the triage, patching, testing, and security release process. In larger companies they have to find owners for every line of code and convince those code owners of the severity (often knowing that neither or them will be rewarded for doing the work).

All it takes is one wrong person to be assigned as a report comes in, a person who doesn't understand the real value of a bounty program, or one person having a bad day to completely ruin a company's reputation. It seems like that might have happened here (of course MS has done this before so who knows if it'll matter in the end).

Microsoft needs to be completely transparent and to do so immediately. They should, with the reporters permission, release all communications. They can exclude technical details if patches aren't available yet. Doing anything less is going to prevent a lot of people from using their bounty program in the future and we'll all be worse off for it. They almost certainly made a mistake and they need to own up to it.

bink··on Solving the “Zork” Mystery
I had Claude code up a Slack bot so I could play any Z-machine game co-op with friends. We started up Zork 1, wandered the available map, made it to the cellar, walked north, and hit a room that was insta-death. We still haven't gotten back into it.

https://gitlab.com/briann/slork

bink··on CISA tries to contain data leak
Krebs was fired in 2020, not 2025.
bink··on Waymo pauses Atlanta service as its robotaxis keep driving into floods
Now imagine if the power is out and cell service is down. We saw that happen in San Francisco and it was chaos.
bink··on Incident Report: May 19, 2026 – GCP Account Suspension
The absence of any explanation for the suspension does seem intentional. If it were me that's one of the first things I would've asked so that I could make sure it doesn't happen again.
bink··on New Nginx Exploit
The exploit they chose assumes ASLR is disabled for simplicity's sake, but if you read the full writeup they say they could've used the vulnerability to map memory layout. It's nice to have ASLR but some types of vulnerabilities can be used to bypass it.
bink··on Bitcoin trader recovers wallet with help of Claude
The guy also had to plug in an old hard drive for Claude to search. Sounds like he had an idea the wallet was on there to begin with.
bink··on AWS North Virginia data center outage – resolved
I can't believe any town would vote for a paper mill. It smells like a paper mill.
bink··on AWS North Virginia data center outage – resolved
It's worse when your region has issues and your customer's infrastructure is fine.
bink··on Project Glasswing: Securing critical software for the AI era
I watched the talk as well and it's very interesting. But isn't this just a buffer overflow in the NFS client code? The way the LLM diagnosed the flaw, demonstrated the bug, and wrote an exploit is cool and all, but doesn't this still come down to the fact that the NFS client wasn't checking bounds before copying a bunch of data into a fixed length buffer? I'm not sure why this couldn't have been detected with static analysis.
bink··on Marc Andreessen is wrong about introspection
I honestly think there's more going on here. It seems to be primarily the vain billionaires that are going off the deep end. I experimented with stimulants when I was young and I remember being shocked at how they changed my personality. I went from pretty stoic to wanting to fight people over the slightest perceived insult. I can't help but think these billionaires with their expensive implants, hair and skin treatments, blood boys, etc. are on some life-extending or performance enhancing stimulants that are affecting their state of mind.
bink··on Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747)
One of the exploits writes a public key to the authorized_keys file, so it does require SSH be open as well.
bink··on Drone Attack on Parked U.S. Army BlackHawk in Iraq a Harbinger of What's to Come
And some Canada Gooses too?
bink··on Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
Ironically, Trivy was the first known compromised package and its purpose is to scan container images to make sure they don't contain vulnerabilities. Kinda like the LLM in your scenario.
bink··on Illinois Introducing Operating System Account Age Bill
Kids aren't stupid. They'll just create another account when they're old enough to figure it out. They'll tell their friends how to do it and the rest of us will be stuck with these stupid prompts forever like it's a cookie banner.
bink··on Digg is gone again
Absolutely. They kinda brag about it now. But I think it was just the founders making multiple accounts. It sounds like the new Digg was worried about bots scaring people away from the site with thinly disguised ads.
bink··on Digg is gone again
One of the things I always disliked about the original Digg was their threading. The slashdot like feed where the oldest comments were at the top and there was only one level of replies tended to encourage the "first" comments and harmed the quality of the discussion. I was glad to see it use a reddit-like comment thread for the new site, but it also meant there wasn't much reason to use it over reddit.

I'm a bit surprised with Alexis' involvement they didn't anticipate the bot problem. Alexis left reddit several years ago but I'm sure he's still in touch with the folks who run the place. It would've been worth it to talk to them about the threats they currently face and how they deal with them.

bink··on An old photo of a large BBS (2022)
DESQview was absolutely not crashy. I ran several different types of BBS software in it without issues. The "DESQview (or worse...)" comment raised the hair on the back of my neck. DESQview was revolutionary at the time and I was annoyed at having to use Windows many years later.

ASCII windows may not have been everyone's cup of tea but I loved it.

bink··on Amazon is holding a mandatory meeting about AI breaking its systems
I've had the same problem for the last few days, just repeated CAPTCHAs.
bink··on Restoring a Sun SPARCstation IPX part 1: PSU and NVRAM (2020)
Back in the day we would've just added our IP to the .rhosts file and no password would be required at all!

It does have me thinking about what versions of SSH would run on such an old OS. I'm sure there were versions available at one time... and since it's vulnerable to remote exploit anyways the version wouldn't really matter.

Page 1 of 22Next →