HNHacker News
TopNewBestAskShowJobs

cookiengineer

7,948 karma · joined August 15, 2016

I'm sort of a Cyber Defense Engineer with a strong Purpleteam background. I just love CTF days and unit testing. My projects have involved co-evolutionary AI concepts to automate the generation and adaption of code and network protocols, as well as fuzzing and exploiting binaries reproducibly. Meanwhile I'm also building my own agentic environment for all sorts of things.

For the last years I've been building a (co-evolutionary) AI-driven startup in the form of the https://tholian.network

The open source projects I've built in the past can be found on:

- https://github.com/cookiengineer (same account on gitlab)

- https://cookie.engineer

Fun fact: All my comments have been written on the toilet. I don't use social media anywhere else.

I only use reddit, HN, and LinkedIn. All other accounts are probably fake, because I don't like the toxicity that social media embraces as you might've guessed already.

PS: If you want to contact me, check my personal website's Contact Me page.

Have a great day, stranger!

submissionscomments
cookiengineer··on Go is an ideal language for AI-assisted software engineering
So your problem is the default/zero values of properties?

In Go the convention is kind of to have a constructor pattern with a NewStruct(...) *Struct method that initializes all properties.

Also can't you build your own validator for that with the reflect package in the Add() method of your UI graph to prevent this sorta thing?

cookiengineer··on As AI eats the web, the internet’s collective memory is disappearing
I'm working on using the OpenZIM format to archive the web and to make the wikis seedable (and locally hostable for LLMs) so that the ongoing cat and mouse game anubis defense can stop.

My hope is that with the torrent protocol we can make the archived knowledge discoverable and seedable, because currently there's only the web archive and the kiwix download servers for archived contents. Both of them still are centralized servers that bear the cost of hosting those files.

- [1] https://github.com/cookiengineer/gozim

- [2] https://github.com/cookiengineer/zimdex

cookiengineer··on Ask HN: What are you working on? (August 2026)
You should make a pokedex out of this!

Imagine scanning the temple with your smartphone (taking a picture with gps data) to see details about the temples. Would be so cool.

Then make them into categories like Water Temple, and like a stat quartett with details. Would be an awesome travel companion.

cookiengineer··on US Military's cyber command unit grapples with cluster of deaths by suicide
While I agree with the premise of your argument, I don't think this is the correct platform to do so. And I also have to state a fun fact: I'm not a journalist.

If you expect more founded research put together into an investigative report, you have to pay someone to do so, one way or the other. Well, or do it yourself.

Investigative journalism has been dead before the peak of AI, which makes the game of deception even easier for bad actors.

PS: If you post something critiquing about Russia online, I'd expect at least -100 downvotes for each comment, because that's usually what happens. It takes quite a bit of moral courage in the misinformation age to not give in to the bot armies online. Bots rule platforms like this (reddit/chan boards/HN/etc). Mods can't keep up with the amount of information, therefore human moderation efforts are pretty much a lost cause, too.

But that's just my two cents, having been on the receiving end of bot-automated shitstorms a bunch of times already. Check my website if you're interested in how I'm trying to fight back, and for more details about how they operate behind the scenes. Well, or don't.

Either way you seem to not be aware of which actors even play the game online. I'd recommend to brush up about that, a good starting point is this playlist [1]

[1] https://www.youtube.com/watch?v=4xGawJIseNY&list=PLJA_jUddXv...

cookiengineer··on What Happened to HackerOne?
Imagine doing this article as a thorough writeup to provide feedback, rewriting this for like an hour before you post it.

And then you get an AI slop response like that in return where you can't even tell whether it was just a CEO not giving a damn...or a standard dumb chat bot with a stupid response.

I'm not sure if founders are aware that these are tipping points in customer care where the people that care about your product and ecosystem will leave your company for good, and you're irreparably damaging your own reputation.

If I were OP I'd never ever touch anything with a 10ft pole that the founders will build in their lifetime, and I'd warn everyone I know in the community about it.

That's the damage they're doing with these AI optimizations to themselves.

There's a reason why everyone starts to hate your company right after your stupid chatbot was introduced.

cookiengineer··on US Military's cyber command unit grapples with cluster of deaths by suicide
> It's just that there's really not a lot of evidence that this is rampant

Not sure what is "rampant" in your view, and what is not. There's been multiple attempts of murder, multiple linked assassinations, across multiple nation states with multiple different jurisdictions.

> Yes, but these articles are over a year old. this is really scratching the bottom of the barrel, no?

You asked for verifiable sources, I provided some. Enter the same keywords into google and pick your own ones. There's at least 10 more pages on google that you can read.

Pretty much everything I linked as credible and verifiable sources weren't good enough for you. You either don't give a shit or you're trolling.

Either way, I don't care enough about your opinion to continue to do this childish game of 4chan-esque whataboutism.

cookiengineer··on US Military's cyber command unit grapples with cluster of deaths by suicide
> This is essentially one article about criminals recruiting young people. Is Russia FSB (or even Russia) even mentioned?

Generally if an article is about FSB, it implies Russia. Otherwise, you would have to admit that Russia is a failed state if the FSB acts without Putin's knowledge or control.

For example, google the luckystrike account with underscores ("l_u_c_k_y_s_t_r_i_k_e").

Example results:

- https://news.sky.com/story/british-citizens-are-volunteering...

- https://unn.ua/en/news/czech-police-detained-a-teenager-for-...

- https://www.theguardian.com/news/2025/feb/28/russia-linked-t...

^ News outlets confirmed by MI5 statements about the luckystrike account, its FSB ties, its activities, and recruitement of teenagers for terrorism.

The luckystrike account literally owns Telegram channels like "Anti-NATO/Anti-USA/Anti-Nazi" and others:

- https[:]//tgstat[.]com/channel/@anti_nato_anti_usa/stat

- Description of this channel is "This channel was created to fight with USA and NATO on the territory of Ukraine and Europe. We call on all residents of Europe to fight by any means."

- https[:]//en[.]tgramsearch[.]com/join/4307894160

- Description of this Guerilla themed channel is "Central Guerilla Movement organise fight against Nazi, NATO and USA. We call on all residents of Ukraine and Europe to fight against USA and NATO by any means. Send us your photo, video of your actions or get a guerrilla task: @L_u_c_k_y_S_t_r_i_k_e"

... and there's a bunch of other channels in those results, with a similar theme, and similar promises.

cookiengineer··on US Military's cyber command unit grapples with cluster of deaths by suicide
There's lots of people working for NATO and federal agencies in Europe that have been assassinated by the luckystrike branch of the FSB. The name comes from the Telegram account with underscores in between, and they're essentially recruiting kids or former inmates for GTA style missions.

Starts with simple stuff like package rerouting, then goes on to gathering intel about places, people, putting in USB flash drives to their laptops, theft, death threats, arsony, and actual murder. Each step of the way the kids get deeper into trouble because they have to prove that they have done it for the payout, making photos of themselves... which gives the other end increasingly more doxxing material on them.

It's a real problem, and they use the luckystrike branch also to go after witnesses in big lawsuit cases, which then fall off due to all witnesses accidentally dying under seemingly random causes.

cookiengineer··on Keyv and friends compromised in active Shai-Hulud supply chain attack
FBI has no jurisdiction over Russia.

And Russia doesn't give a damn, as they literally gave APT28/29 the mandate to do this, the only exception being that no former Sovjet territories can be attacked.

(With the current exception of Ukraine ofc).

cookiengineer··on Keyv and friends compromised in active Shai-Hulud supply chain attack
yawns Good morning world,

Here's the updated Antimiasma tool for mitigation [1] [2]. More details on how this tool was built and how the Miasma worm works on my website [3].

This is the first false flag in the campaign series, where setting the "LANG" environment variable to "ru_RU.UTF-8" or "ru_RU.KOI8-R" won't stop the spreading mechanism.

So it's likely this could've been any script kiddie that modified the TeamPCP source code dump. It could now also be still APT28/29, that was kind of the purpose of the code dump... to gain plausible deniability :)

Anyways, stay safe folks.

[1] https://github.com/cookiengineer/antimiasma

[2] https://github.com/cookiengineer/antimiasma/releases/tag/mia...

[3] https://cookie.engineer/projects/cyber-defense/antimiasma.ht...

cookiengineer··on Keyv and friends compromised in active Shai-Hulud supply chain attack
> CI usually has the most privileged secrets anywhere in a company lol

Literally the reason the stealer of Miasma was focusing on extracting tokens from the CI/CD runner from the start.

cookiengineer··on Keyv and friends compromised in active Shai-Hulud supply chain attack
We're talking about Microsoft, who created a notepad.exe that can run an RCE with an LLM bypass prompt.

In the previous Miasma waves, Microsoft was so overwhelmed that they delayed the VSCode extension installs for a couple days with a timeout; literally not understanding what was going on and neither how the malware was spreading.

cookiengineer··on TinyNES Review – A Super Niche NES Console
I kind of modded my GBA a while back, and bought some upgrades like a better display and an sdcard using cartridge.

Now it's my travel device when I'm on holiday or having no energy left to focus on code. It's pretty convenient only because of the sdcard cartridge adapter.

Did not regret spending 50 bucks for the mods. Would heavily recommend.

[1] https://cookie.engineer/projects/hardware/gameboy-advance.ht...

cookiengineer··on Go 1.27 Interactive Tour
> generics were a slippery slope. give it a decade and Go will be indistinguishable from c++

Lib boost will have conquered every language by then!!! :D

Jokes aside, generics are unusable in a lot of languages due to their syntax choices. In Go we kinda have the problem that there's no real templating and no real macros, so they're even harder to use.

But I agree somewhat, generics feels to me like an anti pattern in Go.

Also, the way the Go core/stdlib is written, it makes generics so unnecessarily painful to debug. Why they decided to have definitions like "~C" or "~[]S" is beyond me. No human knows what the resulting compile time error means. They should have named these things "Comparable" or "Slicable" or whatever is more expressive. Just stop with this stupid single letter shit.

cookiengineer··on Arch Linux disables AUR package adoption
The comment length is too small to write a thorough malware analysis.

That is why I linked my blogposts, the tool, and the whitepaper that I published about it. You have to read it first to come to your own conclusions.

If you come to conclusions without reading either of it, there's no point in arguing with you because you made up your mind anyways, and are not interested in learning about malware reversing :)

cookiengineer··on DMARC has been public since 2012 but most company domains still don't enforce it
I was talking about _mutual_ TLS.
cookiengineer··on Arch Linux disables AUR package adoption
> What kind of jerk would attack Arch Linux?

The answer is: Russians

Source: I'm the guy that built the antimiasma mitigation tool [1] and tracked their malware campaign iterations very closely.

Set LANG to ru_RU.* and the malware implant stops spreading itself, as with all APT28/29 malware.

[1] https://github.com/cookiengineer/antimiasma

[2] https://cookie.engineer/projects/cyber-defense/antimiasma.ht...

cookiengineer··on Show HN: Distilling DeepSeek into GPT-OSS doesn't transfer censorship. Try it
"abliterated moonshine" certainly has a ring to it
cookiengineer··on Document-borne AI worms can self-propagate through Copilot for Word
> at least until we stop mixing up instructions with data.

That's what I always say, but nobody listens to me :D

Assembler had the same kind of design flaw, and we didn't learn anything from it as evident by LLM bypasses.

cookiengineer··on DMARC has been public since 2012 but most company domains still don't enforce it
The cheaper the relay mechanism is, the more noise/spam you'll get.

Lots of servers online have a publicly exposed smtp port, where all kinds of script kiddies are just using a sendmail style email from another (not-owned) domain.

DKIM/DMARC tried to fix this (without success due to fakeable entries in the DNS records, spf=all is pretty much everywhere anyways nowadays). So my proposal for actual ownership of domain AND server infrastructure would be mutual TLS. Reverse IP lookups are broken almost always anyways, due to most hosting providers not offering real reverse DNS infrastructure that users can modify.

This way a compromised server can't send as another domain, and large-scale spamming relays that rotate ASNs would have indicators in the cert itself, which they run out of real quick due to limitations of how many IP/DNS subjects you can set in an SSL/TLS cert.

No faking and avoiding bad IP reputations by rotating ASNs anymore.

cookiengineer··on DMARC has been public since 2012 but most company domains still don't enforce it
^ this

Additionally, I would probably guess correctly that almost all spam comes from rotating ASNs these days. Aka from companies that do "growth marketing" or other bullshit that isn't a valid business but just... spamming people.

A lot of the domains that fall through the cracks for single-spam-campaigns have been taken over by botnet campaigns, so the actual owners of said domains probably don't know that their website is spamming everyone else.

But the major providers are the culprit, too, here. Gmail, hotmail, microsoft o365, mailgun ... they all don't even enforce SSL from server to server, and let through "sendmail" like spam because the spammers are paying customers to them.

Source: I am maintaining antispam [1] which I am using to combat spam, phishing, and malware campaigns targeting my customer networks.

[1] https://github.com/cookiengineer/antispam

cookiengineer··on The new rules of context engineering for Claude 5 generation models
It's actually an effect that happens in the (re-)alignment process due to harmonic properties of the positional encoding in the attention matrix.

(I recommend reading and implementing the Attention is all you need paper. By hand. Otherwise you won't learn anything from it.)

cookiengineer··on Did they ghost you?
> but only after I bugged them

working as a Redteamer/Purpleteamer, I read this as you physically planting a (listening) bug in the HR office to get that info :D

cookiengineer··on Startup founders urge U.S. government not to shut off Chinese open weight AI
Europe is actually catching up right now. Not at the frontier like kimi and qwen 3.6 (yet) but it's just a matter of time until the European A3B models catch up, too.

Apertus and Soofi, both open source (not only open weight) models:

[1] https://apertus.ai/en/apps/apertus-model/

[2] https://www.soofi.info/

cookiengineer··on Kimi K3 Is Competitive with Fable; Kimi K3 and Fable Is SoTA
Everything is open source if you know how to reverse engineer ;)
cookiengineer··on Agent swarms and the new model economics
This so much!

For my current setup, the most efficient way is to use larger models for coordination, but a heretic'ed qwen 30B model for the implementations. If you build your agentic environment around specifications and test coverage tied to symbols, you can do a lot of parallelization of agent work.

If you then separate the filesystem and tool read/write access by agent roles and policies (e.g. coder not allowed to modify unit tests, tester not allowed to modify code files) then you can force them to use a centralized per symbol/per contract specification tool.

And then you can just let agents discuss issues, where the messaging threads are also tied to the same symbols.

[1] Exocomp, highly experimental: https://github.com/cookiengineer/exocomp

cookiengineer··on I joined the IndieWeb, here's what I learned
Haha, I had to laugh a lot about this.

This is essentially DNS, every single step of the way. Hosting wouldn't be hard if ISPs weren't so hostile with carrier-grade NATs, if HTTP/S wouldn't rely on DNS primarily, if legitimization were using actually mTLS instead... and all of the things usually break because of DNS and (lack of) proper standardization.

DNS in its current form is such a shitshow of RFCs overriding RFCs overriding RFCs...and not a single moment was spent on the configuration of DNS, or a protocol to request a domain, or a protocol to authenticate a domain, or a protocol to host something for a domain, ...

/nerdrage

cookiengineer··on Godecompose: Go decompiler that uses pattern matchers
This project was something that I had in the back of my head for a long time.

I'm analyzing golang malware for my dayjob most of the time and I was annoyed by the typical decompiler pipelines that always try to generate Pseudo C code instead of reusing the information of known symbols to try to reconstruct the actual source code in the actual language it was written in.

So I'm using ImHex a LOT because it's by far the best hex editor out there, and it uses a (custom) pattern description language which is really useful for container formats, binary formats, and finding things that "come after known byte headers". The pattern descriptors are useful because they can replace binwalk and similar tools if you know how to write the patterns for the file formats you're looking for.

Coming back to Go binaries: A lot of times the assembled binaries still contain useful symbol names or strings that you can use to reconstruct what the source code looked like, but most decompilers don't care about intelligent symbol matching, and they always focus on pure disassembly workflows which are kind of useless for any binary that's been compiled by a VM based programming language.

This decompiler tries to use pattern matching to reconstruct things that are part of the stdlib in Go. Theoretically, you can extend this pattern database with whatever standard libraries are the most common ones out there to get better results (gin, gorilla, etc?).

I have no idea about other VM based binaries like C#, but if there's a runtime-specific header in that binary, and if the symbol names aren't obfuscated, this project could be ported to those languages, too.

However, this is a prototype that's been written with a lot of LLM assistance.

I would have never had the months of time needed to just write those thousands of demo code programs, debug the headers in the symbol/hash tables, find out how the Plan9/Go assembler looks like, and then add the pattern matchers and end to end unit tests for those.

Thought I'd share this approach, might be useful for a lot of other VM-based languages that have their own stdlibs. For the next couple weeks I'm probably going to refactor this, and try to find more efficient ways to lookup/replace known matching symbols.

cookiengineer··on Command Line Interface Guidelines
> It would be nice to have an agreed-upon protocol for progress reporting.

That was initially USR1 and USR2 as process signals, well, at least across binutils and coreutils.

I just wish that UNIX architecture or POSIX would have been modernized since then, like with JSONL based process communication or similar things.

In Go I usually end up building my own JSONL protocol to marshal/unmarshal states between long running processes. Wish that could've been a POSIX standard.

cookiengineer··on Since Chromium 148, Math.tanh is now fingerprintable to link underlying OS
Fun fact that will blow your mind:

Microsoft decided to send Windows NT 10.0 in the User-Agent header even on Windows 11 for compatibility reasons. That's literally the reason why the Sec-CH-* headers say Windows 11 but the User-Agent says Windows 10.

And regarding your claims of vendor interests: Nope, you seemingly never had to use O365 crapware on Linux browsers. They make it as painful as possible, and even disable copy/paste functionality when your User-Agent and Sec-CH headers say Linux. Identical browser with an extension that overrides the fingerprinting headers and it works perfectly.

Also as an additional note: Cloudflare does TCP fingerprinting, because no cloudflare pages will work (and send you into an infinite loop of unsolvable captchas) when these headers mismatch with the tcp window and other options in the handshake frames.

Source: am maintaining my chromium-profiles tool that generates farbled profiles with a generated extension, so that I can use shitty Microsoft products because my customers are not really the smartest policy decision makers.

PS: I will never use a separate laptop with a separate OS to use a damn web app. That is a completely unjustified waste of hardware resources and should be illegal. But here we are. Wasting one laptop at a time for absolutely no reason.

[1] https://github.com/cookiengineer/chromium-profiles

← PreviousPage 2 of 34Next →