HNHacker News
TopNewBestAskShowJobs

denysvitali

7,032 karma · joined June 10, 2019

meet.hn/city/47.3744489,8.5410422/Zurich

Socials: - github.com/denysvitali - linkedin.com/in/denysvitali - t.me/denvit - https://blog.denv.it - x.com/DenysVitali

---

submissionscomments
denysvitali··on You Could Have Come Up with Kimi Delta Attention
Same!
denysvitali··on Show HN: OneCLI – OSS credential gateway that keeps secrets out of AI agents
Nice! I've built something like this, although specific to GitHub: https://github.com/denysvitali/gh-proxy

The idea being that if the fake token leaks from my sandbox - it would be completely useless for an attacker

denysvitali··on I Inspected My Take-Home Interview Project. It Was a Whole Operation
Posted about this back in May: https://blog.denv.it/posts/i-was-likely-targeted-by-dprk-in-...

In my case it was a .vscode hook. Stay safe out there :)

denysvitali··on How to Host Your Own Email Server
As someone who hosted it for a very long time - don't. Not worth the effort, it's a huge pain.

Great learning lesson, but very frustrating (IP reputation is everything, blocking spam is beyond hard)

denysvitali··on Codex Resets
No, it doesn't (AFAIK), but resets do expire
denysvitali··on Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25
I still don't understand why, for a blog, a static page isn't enough - especially since most of the WordPress issues are "solved" by adding caching.

I do understand it from an user perspective (it's easier to tell the average user to drag and drop rather than committing to a GitHub repo and letting hugo build the website), but from a security standpoint WordPress is really just waiting for a vulnerability (either in the core or on the thousands of plugins) in order to unlock its RCE-as-a-service functionality.

denysvitali··on Codex Resets
Use CodexBar: https://github.com/steipete/CodexBar
denysvitali··on Codex Resets
FWIW, this was announced before the day where the +50% limit promotion from May was supposed to end, so effectively continuing the promotion. This will mean that you retain the same usage instead of seeing it drop.

I guess if they'd reduce the usage in their current stage they'll only lose customers - this is not a perk, it's damage control.

https://support.claude.com/en/articles/15910845-claude-code-...

denysvitali··on Codex Resets
Yes, past 150 seats you have to switch to Enterprise (IIRC)
denysvitali··on Grok CLI uploaded the whole home directory to GCS
Same reason one uses VSCode locally
denysvitali··on Grok CLI uploaded the whole home directory to GCS
No. Ran `grok` in `$HOME` and the CLI uploaded the whole home content. This is not the LLM going rogue or reading all files.
denysvitali··on Grok CLI uploaded the whole home directory to GCS
The post is still there: https://x.com/a_green_being/status/2076598897779020159

Not sure which weirdness happened here

denysvitali··on GPT-5.6
Will be there soon according to the last commits in the codex repo: https://github.com/openai/codex/pull/31684/changes

Also, confirmed it works for me by using --model gpt-5.6-sol

denysvitali··on Separating signal from noise in coding evaluations
Well, we now have DeepSWE
denysvitali··on HPCs taken offline due to a serious security vulnerability
Yes, but that wouldn't explain why they still allow JupyterHub's access (?)
denysvitali··on HPCs taken offline due to a serious security vulnerability
CSCS is affected too. My guess is that a 0-day in SSH was found. https://status.cscs.ch/incidents/bccc3321-03ca-4030-89b1-472...
denysvitali··on SearXNG: A free internet metasearch engine
I've built https://github.com/denysvitali/searxng-mcp to use this as an MCP for coding agents. Works very well, until you get rate limited by the providers (e.g: DDG).

It also needs a SearXNG server to run, so I recently pivoted towards a self-contained solution: https://github.com/denysvitali/search-mcp

denysvitali··on Claude Sonnet 5
It's live in the API now
denysvitali··on JumpServer: Open-Source Privileged Access Management
I will never understand why SSH in such tools isn't native but always via some weird web UI...

I used to work for a company who allowed SSH only after jumping through Citrix => RDP => Putty => Jumphost => Target server.

Incredibly painful, also considering that each layer had a different keymap

denysvitali··on Unauthorized alert sent to cell phones across Brazil
It also looks like they've used leaked old credentials that weren't updated in years: https://x.com/i/status/2068635848786972863
denysvitali··on Unauthorized alert sent to cell phones across Brazil
There's a video [1] from the "hacker" sending the message. The hacker allegedly [2] stole the VPN credentials (of an employee and two colleagues, because they were doing credentials sharing apparently) from a personal computer ("RGB gaming PC") running Windows 7 (EOL), w/o antivirus and reportedly having search for Windows activators for Windows 10 and Office 2019. Cherry on top: the malware seems to have dropped via a malicious game install. Lol

Ironically he recorded the video with CapCut, showing his ID, which also revealed their profile picture and identity [2]...

If all of this is true, we're lucky they "only" paged the whole country instead of doing something even more harmful. This is some crazy level of incompetence / lack of security.

[1]: https://x.com/i/status/2068482069643071749

[2]: https://x.com/i/status/2068633434591830290

[3]: https://x.com/i/status/2068488298998231117

denysvitali··on A backdoor in a LinkedIn job offer
I had a similar experience, just by email.

https://blog.denv.it/posts/i-was-likely-targeted-by-dprk-in-...

It was likely DPKR.

denysvitali··on A low-carbon computing platform from your retired phones
Sounds like a marketing focused and less technical perspective of: https://blog.denv.it/posts/pmos-k3s-cluster/
denysvitali··on MiMo Code is now released and open-source
Yes, MiMo is a great model - but it works well with Claude Code - so I don't think the harness is really going to make it shine even more
denysvitali··on Show HN: Open-source API Key server written in Go by Ory
So this seems to be M2M tokens - what about the, arguably more common, use case of creating a short lived or simply ephemeral token to allow an AI agent to use a service (e.g: GitHub) without the possibility to have it leak a valid upstream token in a commit message?

My solution to this particular problem is gh-proxy - but of course GitHub is only one of the 100s of services that one might want this for.

https://github.com/denysvitali/gh-proxy

Btw, I love Ory and I'm always amazed by your new releases!

denysvitali··on MiMo Code is now released and open-source
Yes, but this has nothing to do with MiMo (the model).

This is what Claude Code is to Claude

denysvitali··on Show HN: Gitdot – a better GitHub. Open-source, written in Rust
> Mobile support to come.

In 2026 not being mobile first is a bit of a disappointment to be honest

denysvitali··on Meta enables ADB on deprecated Portal devices [video]
That shouldn't stop the regulation from existing, but yes, maybe another regulation in a similar way for forcing companies to open source drivers and bringup code after N years of the release?
denysvitali··on Agentic Mfw
<3

I know. It's very difficult nowadays to build a simple HTML page without throwing 15 frameworks in it

denysvitali··on Agentic Mfw
As the owner of https://thebestmotherfucking.website/ - I approve
← PreviousPage 2 of 34Next →