HNHacker News
TopNewBestAskShowJobs

captn3m0

11,480 karma · joined September 29, 2011

https://captnemo.in http://about.me/n3m0

[ my public key: https://keybase.io/captn3m0; my proof: https://keybase.io/captn3m0/sigs/MrazMfyap5PnbYUKQhtqeLGfctJcwxsDB6Oo0t6ABxM ]

my email: me@captnemo.in

meet.hn/city/in-Bengaluru

Socials: - github.com/captn3m0 - x.com/captn3m0 - t.me/captn3m0

Interests: Books, Cybersecurity, DevOps, Fintech, Open Source, Privacy, Web Development

---

hnchat:Z44vjhzI6AG5YXzEY5pD

submissionscomments
captn3m0··on RSS Feeds for Last.fm
Is the code public? I'd like to port this to https://rss-bridge.org/
captn3m0··on What I did at Recurse Center
I did during the pandemic. Drop me a message if you wanna chat.
captn3m0··on Show HN: Make math automatic with Mathy
I made something similar for my partner a while ago for math drills but this is way better (and more comprehensive). I gave up after 3-5 modules. Kudos.
captn3m0··on Microsoft killed FoxPro in 2007. Anyway, here's FoxPro revived
RLHF. The reviewers that rated the models preferred it.
captn3m0··on ZuckOff is a free app that sees Meta glasses before they see you
They could, by incorporating recent research: https://www.core77.com/posts/145408/KAIST-Develops-a-Way-to-...
captn3m0··on ZuckOff Is a Free App That Sees Meta Glasses Before They See You
Does it beep louder as the BT signal strength changes and the camera comes closer?
captn3m0··on Show HN: Restarted – a 2026 remake of the classic 2015 startup generator
I got Shopify: https://restarted.io/?z=3119517161
captn3m0··on LG says we're fake news [video]
Basic mode is a feature across Google TV: https://support.google.com/googletv/answer/10408998?hl=en

So lots of manufacturers support this.

captn3m0··on ElevenLabs, TwelveLabs, ThirteenLabs
I run a reverse engineering collective that is called 52 Labs: https://52-1ab.github.io/.

> 52 1ab (Pronounced 52 Lab) is a Software Research group dedicated to interoperabilty research in India. It is named after the Section 52(1) (ab) of The Copyright Act which states:

>> The following act shall not constitute an infringement of copyright:

>> the doing of any act necessary to obtain information essential for operating inter-operability of an independently created computer programme with other programmes by a lawful possessor of a computer programme provided that such information is not otherwise readily available.

captn3m0··on Phones should have a 'guest lock' feature
iOS has a hidden album but the UX isn't great: https://support.apple.com/en-us/104987
captn3m0··on GLM-5.3: Frontier coding with emergent cyber capabilities
I am guessing you are approved for the Cyber Verification Program. I also applied and got approved in an hour (on a Saturday!), but it only applies to Opus and Sonnet: https://support.claude.com/en/articles/14604842-real-time-cy.... It let me use Opus for cybersecurity work, pretty much everything except for Ransomware development. It would occasionally still trip and start saying no till I added a note about CVP in my claude.md.

No one gets to use Fable for Cybersecurity work, and Mythos is not available under CVP. Only for select few customers, and there isn't an application form?

captn3m0··on Tell HN: Namecheap gave my account to an unverified third party
Namecheap also suspended my primary domain because of a bug at their end: https://captnemo.in/blog/2026/05/05/namecheap-whois/

tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.

I know a few other people that were impacted.

captn3m0··on Reverse-engineering is cheap now
I reversed Super Hexagon these last few weeks and ported it to the Playdate (the yellow console from Panic with a crank): https://old.reddit.com/r/PlaydateConsole/comments/1v1zxmt/i_...

The multiplier comes from being able to design arbitrary fast feedback loops - Claude wrote Python scripts to do decompilation matching for itself, and then use Frida traces from the original as a verification harness.

captn3m0··on Web-based cryptography is always snake oil
There are a lot of other implementations of this idea that don't necessarily rely on trust-on-first-use. The securedrop team explicitly includes malicious JS served by the primary-domain in the threat-model and made WEBCAT[0] as an outcome of that research. Their article on webcrypto is much better than this one.

The solution obviously is to go out-of-band:

> When a user visits a website that has enrolled in WEBCAT, before the site can load the content is checked against a signed manifest to ensure that it has not been tampered with (more on enrollment later). If everything checks out, the page loads normally. If, however, any content does not match what’s expected, the page load is aborted and a warning is displayed, protecting the user from potentially malicious content before it can execute.

[0]: https://securedrop.org/news/introducing-webcat-web-based-cod...

[1]: https://securedrop.org/news/browser-based-cryptography/

captn3m0··on Command and Conquer Generals natively ported to macOS, iPhone, iPad using Fable
This is a OS port (iOS) of an existing functional and maintained fork (MacOS) of the official release (Windows).

Most of these low-hanging bugs would have been caught upstream by now.

captn3m0··on Command and Conquer Generals natively ported to macOS, iPhone, iPad using Fable
upstream is a MacOS+linux build. https://github.com/fbraz3/GeneralsX.
captn3m0··on Espionage Against the European Parliament
Do we know how Apple sends these? Is it just a notification, or also email?
captn3m0··on Weave Robotics launches Isaac 1, a $7,999 home robot with Fall 2026 deliveries
There are 2 complete folds in the Isaac 0 video around 0:40, but speeded up: https://m.youtube.com/watch?v=KhImSR8GuCE

The about page claims 1000+ lbs of laundry folded every week.

captn3m0··on .self: A new top-level domain designed to support self-hosting
10% apparently for .tk. I also remember .tv windfall, which is 8-9% of their GDP.
captn3m0··on Streaming services' obnoxiously loud ads become illegal on July 1 in California
I wrote superbright to be able to force it: https://github.com/captn3m0/superbright (fork of BrightIntosh). The display does get hit after 10-15 minutes of this though.
captn3m0··on No AI Co-Authors. A Manifesto
When I read the title, I thought it would be for research papers.
captn3m0··on Package Managers need global hooks
Hooks are not a new standard. Package managers have always supported hooks. It is just a call to get us to parity.
captn3m0··on Package Managers need global hooks
> The problem of everchanging malware isn't fixable by global policies and global rulesets.

But it is an important tool that's missing in our toolbox. You could do most of the above, and still get pwned by a typo in an `npx` command. Capability based access management is not likely to land in any large package manager in the next few years, and we need solutions that work today.

captn3m0··on Package Managers need global hooks
Package-level hooks are everywhere: https://github.com/ecosyste-ms/package-manager-hooks

I wrote this in response to the recent AUR attacks. The problem isn’t really too many dependencies - it is that most users cannot be auditing everything they install and we need mechanisms that help users where they are.

I audit my AUR pkg builds, and I would have likely caught any malware. But so would a Dependency Cooldown or a third-party threat feed. Package Managers should make it easy to build this tooling via hooks.

captn3m0··on Package Managers need global hooks
Aliases and pre-hooks are nowhere near the guarantees you want, that’s what I am arguing - not everything is invoked from a blessed shell. Safely-bump-does.sh is also impossibly hard to write because you are replicating _all of the work NPM does in transitive dependency resolution_. Unless you are re-generating the lock file from scratch - it isn’t safe. Just updating package.json isn’t sufficient for eg.
captn3m0··on Package Managers need global hooks
Author here - people are definitely looking at other places. This just happens to be where the attacks are, and gets disproportionate attention as a result.

Do you have examples of campaigns that weren’t flagged? Everything except xz had a 1 day window and Dependency Cooldowns are super effective against most campaigns for that reason.

See papers at https://kokkonisd.github.io/ for eg.

captn3m0··on Package Managers need global hooks
`PreInstall` mainly. But `PreFetch/PreBuild` also for source-repositories, such as AUR helpers.

homebrew doesn't support hooks as a system package manager: https://github.com/ecosyste-ms/package-manager-hooks as an example.

I think the packaging ecosystem is varied enough that this should be left for the package managers to decide. Yarn allows dependency resolution and WebFetch overrides in its hooks for eg.

captn3m0··on Package Managers need global hooks
(Author here). I don’t really care _how and what you decide to do with it_, the post is about package managers giving users the ability to decide.

Dependency Cooldowns can be implemented with global hooks, git-commit-signing checks can be implemented, LLM-scans can be implemented, someone can run the code in a jail and use the eBPF logs to publish a threat feed.

Modern language packaging is also _source available_, and we have a huge leg up over traditional virus scans - we have the source code almost always. You can do amazing static analysis.

Yes, it’s hard work. But package managers are doing it already. Yay and Paru both now support hooks. I’m offering to help for AUR to publish more metadata: https://lists.archlinux.org/archives/list/aur-dev@lists.arch...

captn3m0··on Package Managers need global hooks
(Author here). It isn’t a matter of pre-install hooks. I don’t want known malware on my system irrespective of whether it runs at install-time or not. Pre-install hooks are going away in NPM, but we will have code injected in index.js next.

Modern package managers are not amenable to letting another script override its resolutions, and that is what needs fixing.

captn3m0··on Nearly half of LG smart TV apps contain residential proxy SDKs
Has anyone reversed their SDKs to run a swarm that captures enough traffic to see what requests are actually getting made?
Page 1 of 34Next →