HNHacker News
TopNewBestAskShowJobs

cookiengineer

7,944 karma · joined August 15, 2016

I'm sort of a Cyber Defense Engineer with a strong Purpleteam background. I just love CTF days and unit testing. My projects have involved co-evolutionary AI concepts to automate the generation and adaption of code and network protocols, as well as fuzzing and exploiting binaries reproducibly. Meanwhile I'm also building my own agentic environment for all sorts of things.

For the last years I've been building a (co-evolutionary) AI-driven startup in the form of the https://tholian.network

The open source projects I've built in the past can be found on:

- https://github.com/cookiengineer (same account on gitlab)

- https://cookie.engineer

Fun fact: All my comments have been written on the toilet. I don't use social media anywhere else.

I only use reddit, HN, and LinkedIn. All other accounts are probably fake, because I don't like the toxicity that social media embraces as you might've guessed already.

PS: If you want to contact me, check my personal website's Contact Me page.

Have a great day, stranger!

submissionscomments
cookiengineer··on Show HN: NSL – WSL for Linux
Can confirm. My abliterated models kept breaking out of qemu VMs due to BIOS implementation quirks in qemu.

I'm using firecracker now with a very defensive systemd-as-separate-non-admin-user seccomp sandbox on top, which seems to hold them off long enough for me to see an agent going rogue and intervening.

Currently I still have hopes that eBPF sandboxing will help, but just a couple days ago my agent discovered a use after free bug in the ebpf kernel-side verifier... so there's that.

cookiengineer··on What even is an OS now?
I kind of agree with the premises of the author.

Software in the future will have to be building blocks for agents to extend. For my projects I decided to generate LLM targeted guides in the docs/ folder, to teach agents quickly "how to" use the project as a framework.

How to implement an MVC view, where to place the files, a guide how to write a good backend route, how to extend the schemas, and other articles like that.

In my opinion we've already reached "Star Trek like computers". Our OS will have to accommodate for better sandboxing and better permission management and better role separation policies, because currently that whole security sector assumes that programs will be static and won't change before/after an approval.

We need to figure out how to better sandbox programs in terms of not only control flow, but also in terms of access to _data_ on a user's behalf.

cookiengineer··on Show HN: A competition for small neural networks that play strategy games
OMG!

Just yesterday I published my reworked GoNEAT library that implements HyperNEAT combined with phased search and backpropagation [1].

But it's kind of impossible to enter for me because of the hard pytorch requirements :( would love to see the project as a gym, so that you can run your own ANN design algorithm.

I get that most data science students still use python, but the evolutionary world is kinda in C++ and other native languages.

Anyways, great project nonetheless.

[1] https://github.com/cookiengineer/goneat

cookiengineer··on I think you should almost never use AI to write
People using LLMs not in a gruntwork manner tend to confuse style and tone with facts and knowledge.

LLMs are great to make drafts if you give them the source materials. They're great at validation if you give them the tools. They are great at layouting if you give them linters.

Encode architecture and decisions in your workflow, then proofread what your agents have been working on. Not the other way around.

Better validation and testing means more work will transform from exhaustive decision work to automateable gruntwork.

cookiengineer··on Shakespeare Skill: Make agents sound like William Shakespeare characters
<3
cookiengineer··on CCC invites all model citizens to 40C3
As a German I find it interesting that foreigners think that this is a cultural thing.

It is not. It's the law.

In Germany you are not allowed to photograph people without their written and signed consent. Any conference or event counts as a private event when it is organized on private property. If it's not a building or space owned by the city, it is private property. This includes e.g. swimming pools owned by the Stadtwerke (there have been lawsuits because of that, all decisions in favor of privacy).

For example, even cameras that protect your property by filming the outside area are not permitted to film the street, and they have to be arranged to point towards your own property. That's why even banks have cameras always on the corners of the building, pointing back to their own property.

Again, it's the law. It's pretty strict about this sort of thing, especially because of WW2 and post WW2 times, where a lot of people died because of Stasi misinformation or Zerstörungstaktik related things.

Source: was a helper and organizer of a lot of CCC events before 2021.

GDPR/DSGVO means you have to get written consent by all visitors, otherwise you cannot make photos of the event and publish them.

cookiengineer··on Write Linters and Tools Before Code
Also, inspired by your comment:

https://news.ycombinator.com/item?id=49737132

cookiengineer··on Shakespeare Skill: Make agents sound like William Shakespeare characters
After I've received a comment about that my writing style sounds like AI generated text, I decided that I want to sound differently when I communicate with others.

Applying the logic of reading AI generated text leads to human imitating that dialect, I can also teach myself a different form of writing by writing an agent skill that transforms the model's text output.

So here it is, a Shakespeare skill that makes your agents sound like an Early Modern English play.

#lifehack (well, sort of, to be verified in the future)

[1] Screenshot of skill used in opencode: https://imgur.com/a/AKyvB9p

cookiengineer··on Write Linters and Tools Before Code
I took this comment as advice to go outside and touch some grass :D

Maybe I am using agentic environments a little too much lately? In the case of the weblog articles I wrote everything myself first and let the agents check against missed formatting rules, so the LLM was e.g. adding the references section and cutting/pasting the overview section together.

I usually use agents for fact checking most though, so e.g. in my malware writeups that I wrote I let my agents fact check if (parts of) what I discovered was also confirmed by other parties that analyzed e.g. the same malware samples.

The wiki learning courses were written by me, then rewritten by my agents, that's why there's still lots of unicode stuff in there. The articles were from my old website, but I let agents rewrite them to fit the new (linted) document format.

I have to now proofread everything and change/rewrite them over the course of the next weeks or months, and have to do that incrementally because it was just soo much content.

That was kinda the point behind the posted article: How to get to a point where most of the gruntwork is automated so you'll only have to proofread afterwards.

Usually that still takes a long while, especially when it's exploit or hardware errata or memory errata related. Verification of binary exploits is not as automated yet as I want it to be, hence my other projects and experiments with eBPF etc.

cookiengineer··on Ask HN: What are you working on? (September 2026)
Oh my gosh, it's so freakin pwetty!

Kudos, this looks like the shaders took a long while to get right. Love the art style, keep it going!

cookiengineer··on Linux Zoom client proactively reading everything written to X11 clipboard
I think the only possibility that comes to mind is creating an ebpf module that sandboxes all filesystem calls and trampolines all ld_open calls.

But then you would have to provide massive amounts of patched/"safe" variants of all kinds of shared libraries which is unfeasible.

But I mean in the xorg use case it would be possible to just provide your own library that fakes the expected returns and sends fake data to the sandboxed applications.

I did a similar thing with barrier (though using LD_PRELOAD, see [1]) on my debian system to force a different behavior.

Source: Am kind of experimenting with ebpf a lot for that use case. C ABIs and SO files are a mess though. A real messy mess.

[1] https://github.com/cookiengineer/barrier-disable-dpms

cookiengineer··on I spent $220 on Google app ads and 60% of the installs were robots
Do you have that bot ASN list somewhere?

I am asking because I maintain botnet ASNs that are spamming/phishing/scamming our customers, and this would be a nice complementary category for it.

Most often I realized that a lot of those "growth" companies have rotating ASNs that they go through after each larger spamming campaign. I'd assume they do the same thing in the admob/adclick world.

[1] https://github.com/cookiengineer/antispam

cookiengineer··on Show HN: Geiger – See every AI agent on your machine and what it can touch
Came here to write this.

Built my own harness with much better sandboxing, because I am using abliterated models for the implementations and they sure try to escape out of their sandboxes. A lot.

The sandbox from other harnesses like e.g. OpenCode essentially is useless. They think parsing arguments alone to detect paths helps, and LLMs know that because they will just pipe data differently then to escape the path traversal checks. Happened a lot to me (and was the primary reason for my to write my own harness from scratch).

Thinking in filesystem access alone is also a futile attempt at sandboxing. A much better way to think about sandboxes is policies and capabilities, with temporary access for agent roles rather than sessions (or, well, forever).

[1] UI still needs lots of work though: https://github.com/cookiengineer/exocomp

cookiengineer··on Actively exploited sandbox RCE in all Chromium versions
you are talking about the effect, not the cause.

Sites are slow because with all that excess performance they do more tracking, instead of keeping the website as-is.

Because that's the only thing business managers can come up with in that situation. It's a misaligned goal of users vs businesses.

In my opinion the "user agent" behavior of browsers is long gone, because they're not acting on behalf of their users anymore. They're acting on behalf of businesses.

cookiengineer··on The asteroid currently hitting front end web development
> period of great homogenization

It's called alignment. And that's the correct word for it in my opinion.

The most important part is that we have to find a way to tackle the knowledge enshittification problem.

Because now that slopcode and slopposts are everywhere, the average quality level will decrease. We had the peak internet knowledge, and it's now gradually getting worse.

That's not a personal opinion, that's how attention matrixes and their keys/values computation works.

cookiengineer··on Google Has Removed MV2 Extensions from the Chrome Web Store, Including UBO
For Work they actively deactivate Linux users for "security reasons", or Microsoft makes their web apps intentionally hostile like disabling copy/paste or disabling photo/picture or file uploads for Linux users when you're allowed in the policies.

Turns out, it's bypassable. They just check the User Agent and Sec-CH headers, so I built a small browser extension for Chrome that allows to modify those headers.

On top of that I built chromium-profiles [1], my tool for managing those isolated sandboxes so that I can tweak/change them based on the stupid policies per O365 tenant I have to work with.

So I use 3 different profiles for 3 different customers with 3 different security policies set for their organization... For being allowed to use a freaking web app.

That, for me, is the only reason I still have to have chromium installed. Microsoft stupidity.

I wish Firefox would focus on this sort of use case, like the "--pwa" and "--user-data" CLI flags and preinstallable extensions for those profiles. But it can't be done due to how they manage extensions with their own signing cert, how dev mode extensions are always cleared etc. Well, apart from Microsoft intentionally making webapps unusable in Firefox.

[1] https://github.com/cookiengineer/chromium-profiles

cookiengineer··on I accidentally turned LLM memory into program analysis
This was a pretty awesome read, I liked it a lot!

What I found out during malware analysis is that LLM agents have a couple of quirks that you can solve by:

- optimize for short lived agent workflows

- use symbols as function contracts

- maintain decision and discovery state

- give LLMs CLI linters

- give LLMs access to knowledge bases

The linter part is mindblowing. I built linters that validate HTML or markdown or docx or Go or C files, for example, and they output what kind of structure is expected instead of useless token based errors (e.g. h4 inside h1? Must be h1 > h2 ...).

With linters the output quality of agents is just soo much better.

For program analysis, I'm currently exploring the idea of using an external ebpf daemon that programs can be observed with via a public API (which is the tool for the agent to use). Not sure if it'll do the trick yet, but I think it has lots of potential.

My stuff in case you're interested:

[1] https://github.com/cookiengineer/exocomp

[2] https://github.com/cookiengineer/gobayashi

[3] https://github.com/cookiengineer/gonano

cookiengineer··on Previewing the Model Hardware Standard
What is the difference of MHS to MCP when it comes to features?

The whole text reads like everything is just a gRPC call that could've also been implemented with an MCP based wrapper.

cookiengineer··on Wi-Fi 8 is the first wireless upgrade in years that isn't chasing speed
LoRa is quite nice for this in the lower frequency bands, and the bandwidth should suffice for this sorta thing. And the tech is super cheap to build and maintain, both hardware and software is open source.
cookiengineer··on NanoGPT Speedrun Frontier
You're not the only one. I thought so too.

I just ran it the last couple days extensively to verify my data training pipeline I'm building for my gonano SIMD port.

Given that the speed records and the runs are sponsored by the same company I was confused a bit.

cookiengineer··on Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing
> You are one person. The corporation is not. Scale matters

Correct, if you violate it too often to count, you have to pay around less than ~2.5ct per violation.

So the lesson here is: Create a company to do torrenting professionally, and resell its values for higher prices. Then get sued and pay a dime on the dollar you made.

edit: Actually it's 2.5ct per violation.

cookiengineer··on Firefox is now the last major browser that still supports uBlock Origin
With a normal Firefox on desktop on Linux, I get unsolvable recaptchas all the time, especially on cloudflare pages.

Ironically, if I fake instead a chromium to be on Windows (UA and Sec-CH headers), I am allowed most of the time even though my TCP fingerprint must mismatch then.

It's annoying to see what the normal web has become. Can't even read news anymore.

Ironically, all these bot defenses make it easier for bots to scrape their website, but make it harder for actual users to use them.

The only bot defense web app firewall that still works with Firefox seems to be Anubis. Pretty much all others autoflag Linux users as bot users, which feels insane if you think about less web developers must know about how botnets work.

cookiengineer··on Where did the old web go? We followed 657,607 links to find out
Your misjudgement comes from not seeing the economic incentive here. The web as a surveillance mechanism is just way too juicy to let go. As of now, pretty much all economies depend on it, just from an economic numbers calculation.

Mind you, 200 years later, we still live in cities built for cars, not people. Rockefeller, Shell, BP and the like are still not dead, and still use everything they got to not go extinct while corrupting every politician that will accept their money. Just for a couple more years at a time, and a couple more, and a couple more...while destroying our planet like a cancer.

In 200 years we'll still have the web built for surveillance capitalism, not people.

There is no old web to go back to. Meanwhile state surveillance depends on its existence. Amazon, Apple, Google, Meta, Microsoft, three letter agencies, Palantir, and now the AI companies depend on it, and they're selling to nation states at a time. Again, it's just too juicy not to.

Back then we called them trusts, but now those big tech companies are seemingly worth more than actual countries. That's too much power without legislation, as they can effectively abandon the rule of law. Remember what happened with the Enron scandal? That was about billions, not trillions.

If we want a human web again, we need to build a new one, with privacy and secrecy first and not as an afterthought. No CA, and with mutual cryptography that acts like both a ledger and as a privacy shield for the users. No cookies, no tracking, no degenerate google controlling it all through owning the source code.

cookiengineer··on Go is an ideal language for AI-assisted software engineering
I actually had to use a similar hack there due to the limitation that go test compilates cannot spawn themselves where I needed to have an environment variable with the actual binary prebuilt before the tests run. Took me a while to understand that TestMain doesn't cover that use case...
cookiengineer··on uBlock Origin Is Giving Up the Fight to Keep Ads Off Facebook
> Most sites are not in business of running ad marketplace.

You don't have to run a marketplace. Back then, people were calling via phone to put an ad into the newspaper. The same concept can still apply today.

You can just place an ad _where you actually want it_ instead of having a shitty decision engine decide it for you. Marketing budgets are messed up all over the place since social media, because they're really inefficient in finding the customers that actually wants to buy their stuff.

If you don't believe me, just take a look at facebook, they're trying to shove ads up your feed 99% of the time. It's a feed of ads, not a feed of "friends" anymore. Good luck trying to catch the 1% of posts that were actually the reason why you used the platform in the first place.

cookiengineer··on Go is an ideal language for AI-assisted software engineering
With unit tests you gotta be careful though, oftentimes LLMs skip implementations with mockups that just say "not implemented yet" or similar and then the unit tests become pointless because they start to only test internal structures for being set / not default values.

For me it helped a lot to try to make containerized end-to-end tests and a custom TestMain for this, where I am using podman to run the integration tests. This way the end-to-end tests are forced to be on network level, and you can test protocol and API quirks much easier with LLMs.

Also, never forget to write a bootstrapping docs/ folder so that you don't have to re-explain these things all the time.

cookiengineer··on Go is an ideal language for AI-assisted software engineering
So your problem is the default/zero values of properties?

In Go the convention is kind of to have a constructor pattern with a NewStruct(...) *Struct method that initializes all properties.

Also can't you build your own validator for that with the reflect package in the Add() method of your UI graph to prevent this sorta thing?

cookiengineer··on As AI eats the web, the internet’s collective memory is disappearing
I'm working on using the OpenZIM format to archive the web and to make the wikis seedable (and locally hostable for LLMs) so that the ongoing cat and mouse game anubis defense can stop.

My hope is that with the torrent protocol we can make the archived knowledge discoverable and seedable, because currently there's only the web archive and the kiwix download servers for archived contents. Both of them still are centralized servers that bear the cost of hosting those files.

- [1] https://github.com/cookiengineer/gozim

- [2] https://github.com/cookiengineer/zimdex

cookiengineer··on Ask HN: What are you working on? (August 2026)
You should make a pokedex out of this!

Imagine scanning the temple with your smartphone (taking a picture with gps data) to see details about the temples. Would be so cool.

Then make them into categories like Water Temple, and like a stat quartett with details. Would be an awesome travel companion.

cookiengineer··on US Military's cyber command unit grapples with cluster of deaths by suicide
While I agree with the premise of your argument, I don't think this is the correct platform to do so. And I also have to state a fun fact: I'm not a journalist.

If you expect more founded research put together into an investigative report, you have to pay someone to do so, one way or the other. Well, or do it yourself.

Investigative journalism has been dead before the peak of AI, which makes the game of deception even easier for bad actors.

PS: If you post something critiquing about Russia online, I'd expect at least -100 downvotes for each comment, because that's usually what happens. It takes quite a bit of moral courage in the misinformation age to not give in to the bot armies online. Bots rule platforms like this (reddit/chan boards/HN/etc). Mods can't keep up with the amount of information, therefore human moderation efforts are pretty much a lost cause, too.

But that's just my two cents, having been on the receiving end of bot-automated shitstorms a bunch of times already. Check my website if you're interested in how I'm trying to fight back, and for more details about how they operate behind the scenes. Well, or don't.

Either way you seem to not be aware of which actors even play the game online. I'd recommend to brush up about that, a good starting point is this playlist [1]

[1] https://www.youtube.com/watch?v=4xGawJIseNY&list=PLJA_jUddXv...

Page 1 of 34Next →