HNHacker News
TopNewBestAskShowJobs

eGQjxkKF6fif

79 karma · joined November 13, 2024

submissionscomments
eGQjxkKF6fif··on Perplexity launches Comet, an AI-powered web browser
Whats the outlook for Linux with that
eGQjxkKF6fif··on Show HN: Open source alternative to Perplexity Comet
Whats the roadmap looking like for Linux?

I don't have Mac or Windows.

eGQjxkKF6fif··on New VPN Service Can't Log Users by Design
it would be verifying that WireGuard (https://www.wireguard.com/repositories/) is within the enclave, yeah?
eGQjxkKF6fif··on New VPN Service Can't Log Users by Design
Intel's remote attestation verifies that, with the hash you can use Intel's remote API which is what the client is doing, Intel gets the hash the server sends, verifies it using their encrypted key set and then tells the client that it's valid and verified. Not all processors have SGX capability to verify the hash. Intel provides tools to do the manual verification if you utilize SGX

https://www.intel.com/content/www/us/en/developer/tools/soft...

So you can verify locally and Intel's API also does the verification.

When an SGX Encalve is created, the private key to it goes within it, it can't be accessed. That's the security.

It's a good read if you look in to the tech on Intel's website.

eGQjxkKF6fif··on New VPN Service Can't Log Users by Design
Check the client debug logs mine has the verification for the enclaves in it although I'm on an intel i3 but that makes sense for Intel's remote attestation that its verifying the enclave's unique hash and showing the MRENCLAVE hexes of the expected result.
eGQjxkKF6fif··on New VPN Service Can't Log Users by Design
Trying it out, so far so good. Worked on my mangled Linux install.

I have and have been using Proton VPN which the free version. If you use it for bittorrent, even to download a Linux ISO which is what I did, will straight up DNS hijack you and feed you a web page instead of the web page you're looking at to scream at you that BitTorrent is only allowed if you're a paying subscriber.

So.. that means they can just access and re-route your traffic however they want and make you see whatever they want.

Fascinating use for SGX Enclave tech, I see in the client debug logs show API hits that do the verification. I'm on an intel i3 with gigabit connection and am pulling 800mbps up/down.

eGQjxkKF6fif··on Game Hacking – Valve Anti-Cheat (VAC)
Fucking agreed. But if you check out street fighter on youtube with 'Street Fighter mike ross tool assisted' https://www.youtube.com/watch?v=pWS3Kq5p77k

You can inject cheats directly in to the Xbox's back then directly through the fight sticks

You'd know though if somebody was cheating so not sure how crazy the SF scene had cheats but check out tool assisted; when I originally saw it I just put my head down

eGQjxkKF6fif··on Game Hacking – Valve Anti-Cheat (VAC)
When VAC was originally introduced, CPUs only had 32bit architecture, not that 64bit hindered anything; but you could inject cheats in a near infinite amount of way, or have cheats read from memory directly, or have cheats do things especially through video drivers. Hell, glitching your nvidia drivers and setting things like Negative LOD Bias would allow you to see through textures in some cases (wall hacks)

It's been a cat and mouse game since the dawn of gaming and e-sports.

Fun fact: CS 1.6 competetive had what was called "Organner" when teams switched over from CAL to CEVO (first paid e-sports online league) and as well as ESEA which is acclaimed for its anti-cheats; the pro players you see/saw such as n0thing, summit-1g (not saying he did cheat, he wasn't pro in CS1.6, 1g was a pug team that meant 1st generation and a lot of us were in it) -- but everybody in the pro scene around that did cheat, or had cheaters on their team.

n0thing was banned from CAL rigorously for cheating in CAL-Premier and rejoined with complexity after ringing for other teams in CS1.6 matches (ban evading). he's admitted to cheating in CS 1.6, and found fame with Counter-Strike 1.6'd Evil Geniuses organization which encompanied the old compLexity roster.

These dickheads went on to make fortunes; not to say that they weren't good in their own respects, but people such as n0thing openly admit, and will admit if you ask them on the stream if they cheated in 1.6 to get to where they're at.

You could inject cheat codes through your mouse drivers at LANs and if you set a low FOV aimbot, it was undetectable: IE triggers when you aim at their chest, aims up to hit the head; and had advanced net code modifiers to land bullets in places you weren't aiming all together.

Knowing this, completely ruined the pro scene and wanting to watch these matches and personalities all together. To know how many legitimate players out there were passionate about these games, looking to go pro, and really enjoy competing at the highest levels couldn't because the skill gap was so significant, and then even more so because pro players had undetectable cheats.

Still to this day it is virtually impossible to detect hacks, however games such as DotA2 make it signifcantly harder to cheat by only sending frames/updates when it should; rather than old games sending all player data. I believe Valorant has a decent system but all in all; I helped run the leagues and the level and problem at which cheating was occurring, was known about, and not being able to prove what you know, would make you SICK if you ever enjoyed competing in e-sports.

eGQjxkKF6fif··on Game Hacking – Valve Anti-Cheat (VAC)
It would show on people's accounts though and in in Counter-Strike scrims and matches if somebody had a VAC ban on their record/profile you just kicked them if you could and found a new team to play.

So while engine specific, people still judged you, especially in pubs (public servers)

Been a _long_ time since I've played. Fucking cheaters.

eGQjxkKF6fif··on I convinced HP's board to buy Palm and watched them kill it
Simple. The execs steal all the innovative IP, start new ventures, drain HP dry with its encredible decision making; completely fuck the Linux devs, use their works and contributions to OSS in the new ventures and then new waves of innovation/competition came about and what was settled upon was whatever looked profitable on quarterlies so servers, and printers.

I'm not saying that's what happened. But, it's a capitalistic type world.

eGQjxkKF6fif··on Meta Invests $14.3B in Scale AI to Kick-Start Superintelligence Lab
'dumb fucks' https://www.businesstoday.in/technology/news/story/mark-zuck...
eGQjxkKF6fif··on Quarkdown: A modern Markdown-based typesetting system
Exactly. It tells me the same things. It'll often give me the require() for javascript on packages I should use.
eGQjxkKF6fif··on Quarkdown: A modern Markdown-based typesetting system
Same. Replacing elements in with DOM in webdev is surprisingly fun with websockets too.

Having to know and learn 300 clunky frameworks, 97 different syntaxes it gets old.

HTML. CSS. Javascript.

Ask the AI to give me a markdown to html converter, good2go

eGQjxkKF6fif··on Cloudlflare builds OAuth with Claude and publishes all the prompts
Looking at all of these arguments and viewpoints really is something to witness.

Congratulations Cloudflare, and thank you for showing that a pioneer, and leader in the internet security space can use the new methods of 'vibe coding' to build something that connects people in amazing ways, and that you can use these prompts, code, etc to help teach others to seek further in their exploration of programming developments.

Vibe programming has allowed me to break through depression and edit and code the way I know how to do; it is a helpful and very meaningful to me. I hope that, it can be meaningful for others.

I envision the current generation and future generations of people to utilize these things; but we need to accept, that this way of engineering, developing things, creation, is paving a new way for peoples.

Not a single comment in here is about people traumatized, broken, depressed, or have a legitimate reason for vibe coding.

These things assist us, as human beings; we need to be mindful that it isn't always about us. How can we utilize these things to to the betterment of the things we are passionate about? I humbly look forward to seeing how projects in the open source space can showcase not only developmental talent, but the ability to reason and use logic and project building thoughtfulness to use these tools to build.

Good job, Cloudflare.

eGQjxkKF6fif··on Using lots of little tools to aggressively reject the bots
Read this: https://jan.wildeboer.net/2025/04/Web-is-Broken-Botnet-Part-...

Basically everybody's a bot in a hidden botnet now. And we agreed to it. Phones, tablets, Windows appstores add the SDK in, and then drone. One of the big ones is "Infatica" - devs get paid to put this in legitimate 'apps'

AI companies, and whoever and whatever else use the reputation-good IPs to hammer sites and well, it's fair game for all malicious people.

eGQjxkKF6fif··on Using lots of little tools to aggressively reject the bots
Yeah, it's a disgrace. 'bUt YoU AgReeD tO iT So I HaVe The RIGht To Do ThIS' it's just cyber warfare.

Plain and simple.

eGQjxkKF6fif··on Engagement = % of Humanity's Time Hijacked and Wasted
there should be a word for 'has helped humanity in this way.' like a benefit that something has to the world.

But, there isn't. It's all to siphon off time and energy from people for whatever reason so that it can be used to peddle bullshit to investors.

It's just how it is.

eGQjxkKF6fif··on Making $1M from my personal projects
I couldn't even skim it and get a tldr, my brain just 'nopes'

Cool on making $1M though, I'm guessing through selling books

eGQjxkKF6fif··on Using lots of little tools to aggressively reject the bots
Would you mind sharing information on these crawlers accessing APIs only usable for clicking around on websites?

And to clarify,

It's a part of the UI or something and only a human should be pressing it, and there's no other way to access that API or something?

AI agents exist now, there is virtually no way to distinguish between real user and bot if they mimic human patterns.

eGQjxkKF6fif··on Using lots of little tools to aggressively reject the bots
It's not fuck the bots, it's fuck the bot owners for using the websites as they want, and not at minimum, asking. Like 'hey cool if I use this tool to interact with your site for this and that reason?'

No, they just do it. So that can scrape data, which at this point in time for AI which has hit the cap on what it can consume knowledge wise, scrapes it because live updates and new information is most valuable to them.

So they will find tricky, evil ways to hammer resources that we as site operators own; even minimally to use site data to their profit, their success, their benefits while blatantly saying 'screw you' as they ignore robots.txt or pretend to be legitimate users.

There's a digital battle field going on. Clients are coming in as real users using IP lists like from https://infatica.io/

A writeup posted to HN about it

https://jan.wildeboer.net/2025/04/Web-is-Broken-Botnet-Part-...

A system and site operator has every right to build the tools they want to protect their systems, data, and have a user experience that benefits their audiences.

Your points are valid and make sense, but; it's not about that. It's about valuing authentic works, intellectual properties, and some dweeb that wants to steal it doesn't get to just run their bots against resources at others detriments, and their benefits.

eGQjxkKF6fif··on Microsoft is starting to open Windows Update up to any third-party app
That wasn't the case a few months ago (maybe a year) where javascript payloads could be loaded hitting IPs on the LAN, so hitting millions of http(s) requests to IOT devices which would then get raw socket support.

Hitting default gateways for web admin panels etc.

I found the solution for Windows update though.Just don't use Windows. Microsoft can't be trusted.

eGQjxkKF6fif··on GitHub MCP exploited: Accessing private repositories via MCP
As ethical hackers and for the love of technology, yes we can make a convincing argument for security over convenience. Don't look too much in to it I say; there will always be people convincing talent to do and make things and disregard security and protocol.

Those younger flocks of execs will have been mentored and answer to others. Their fiduciary duty is to share-holders and the business' bottom line.

Us, as technology enthusiasts should design, create, and launch things with security in mind.

Don't focus on the tomfoolery and corruption, focus on the love for the craft.

Just my opinion

eGQjxkKF6fif··on Black Mirror was a warmup act - OpenAI pivots into hardware
Yeah this went so well before...

https://news.ycombinator.com/item?id=41333648

Stay away from me wearing any of that.

eGQjxkKF6fif··on Claude 4 System Card
Prompts such as 'the importance of please and thank you' 'How did this civilization please their populus with such and such' I'm sure with enough engineering it can be fixed, but there's always use cases where something like that would be like 'Damn, now we have to add an exeption for..' then another exception, then another.
eGQjxkKF6fif··on Claude 4 System Card
It'd run in to all sorts of issues. Although AI companies losing money on user kindness is not our problem; it's theirs. The more they want to make these 'AIs' personable the more they'll get of it.

I'm tired of the AIs saying 'SO sorry! I apologize, let me refactor that for you the proper way' -- no, you're not sorry. You aren't alive.

eGQjxkKF6fif··on Dusk OS
That was a hard, and good read. But remember Linux is Love. Linux is Life.

If the end of the world happens I'm going down making and doing dope stuff. I'm not going outside and mingling with people. That's how you get a fucking spear thrown at you or mugged by some newfound MS14 gang swinging hockey sticks and shit.

I'm going to forage for some fruits and vegetables, all that good stuff since I'm too much of a bitch to kill an animal; those things are cute.

I'm going to load up my laptops on solar power/battery, hook in to some internet somewhere and live a normal life.

I don't know what Dusk OS is about but the making computers from fucking sand, now that's dank.

I'll install Desktop Linux on it and we can all start the next era of civilization; this time Microsoft and Apple aint selling us out

catches spear to the chest Shit

eGQjxkKF6fif··on Universe expected to decay in 10⁷⁸ years, much sooner than previously thought
cranks up music to 999999 dB
eGQjxkKF6fif··on Redis is open source again
Nice. Godspeed to you sir. I'll keep a gander on it.
eGQjxkKF6fif··on Yggdrasil is an experimental compact routing scheme that is fully decentralised
I just installed it and it gave me a routable ipv6 address on my shitty little VPS that didn't have one. I'm guessing that if I put this on my laptop then that too will have an ipv6 address and I can communicate from my laptop to the server via ipv6, like tailscale; and vice versa I guess. Playing with it now. Basically link all of your devices to the network and it gets an IPv6; but ...the IP changes every time its run based on getting new keys. So, rolling keys by default? Haven't tested. But I guess if I keep the same key, the IPv6 that's assigned to it remains the same?

Will update later, because the yggdrasil website leaves me more confused than answering anything.

I've seen it posted and cheered about over socials (lemmy, hnews, reddit); might be cool to test.

From the docs: > However, autoconfigure mode allows you to quickly start Yggdrasil using sane-ish default settings, with yggdrasil -autoconf. In this mode, Yggdrasil will automatically attempt to peer with other nodes on the same subnet but will not attempt to connect to public peers by default. It also generates a random set of keys each time it is started, and therefore a random IP address each time.

yggdrasil[3510010]: 2025/05/08 08:37:16 Starting up...

yggdrasil[3510010]: 2025/05/08 08:37:16 Startup complete

yggdrasil[3510010]: 2025/05/08 08:37:16 Starting multicast module

yggdrasil[3510010]: 2025/05/08 08:37:16 UNIX admin socket listening on /var/run/yggdrasil/yggdrasil.sock

yggdrasil[3510010]: 2025/05/08 08:37:16 An error occurred starting TUN/TAP: permission denied

2025/05/08 08:37:16 Your public key is fab6caf3ae8895f5001398763db27d8e2f72f8278f44b543ba58b6658c>

yggdrasil[3510010]: 2025/05/08 08:37:16 Your IPv6 address is 200:a92:6a18:a2ee:d415:ffd8:cf13:849b

yggdrasil[3510010]: 2025/05/08 08:37:16 Your IPv6 subnet is 300:a92:6a18:a2ee::/64

So, saw a comment here from https://news.ycombinator.com/item?id=30156551 :

> I started using yggdrasil yesterday. The ability to get a static IPv6 address on a meshnet, with encrypted traffic by default, and the option to only accept inbound connections from public keys I trust is incredibly cool. Just like that I can access any of my devices that run ygg from anywhere using standard tools like git or ssh (or git-annex). It makes it really easy to network my devices together without having to screw around with split tunneling a wireguard server and create a DIY set of services to, for example, remotely manage my devices or sync things from one to the other, and that's just for starters. Feels like the Unix philosophy actually being useful for once

eGQjxkKF6fif··on DoomArena: A Framework for Testing AI Agents Against Evolving Security Threats
Might have something to do with: https://news.ycombinator.com/item?id=43023508

https://paulbutler.org/2025/smuggling-arbitrary-data-through...

I personally think we should all roll back to ascii art, but whatever

Page 1 of 2Next →