HNHacker News
TopNewBestAskShowJobs

elnerd

24 karma · joined August 13, 2025

submissionscomments
elnerd··on Dropbox's Jan 1st 2027 terms of service
Does this mean that young adults that work for companies that use Dropbox, cannot collaborate with others using Dropbox?
elnerd··on US confirms for first time it has deployed space weapons
Every spacefaring nation seems to have had their go in blowing up satellites using anti satellite weapons [1] and smashing satellites into other satellites [2]

[1] https://en.wikipedia.org/wiki/Anti-satellite_weapon [2] https://www.theguardian.com/science/2019/apr/02/a-terrible-t...

elnerd··on AWS: Inaccurate Estimated Billing Data – $1.7 billion
I once got a wildly inaccurate billing estimate shortly after I created my AWS account. I could not find a out which resources that would cost me so dearly, and saw no other option to delete the entire account.

A few hours later, I got a mail saying the estimate was wrong.

Now, I cannot create an AWS account using my email address because you cannot create a new account using the same email address…

elnerd··on The only scalable delete in Postgres is DROP TABLE
I’m using Postgres for my DNS log service. I only store data for 90 days. To delete data, my strategy is to use partitions based on month. At the start of every month, I drop one partition.

I am not sure of this is the best way to do this, but it works for me.

elnerd··on Gmail thinks I'm stupid, so I left
I changed from Gmail to proton many years ago.

The only pain point I have is the search. Understandable, the emails are encrypted and search has to be done on the client. That works when using the web hi as you have the option to index all emails.

I do not find this option in the iOS app :(

elnerd··on The American Missile Crisis
Same goes for logistics, which is an extension to your point:

https://walton.uark.edu/clc/posts/when-supply-chain-is-the-b...

elnerd··on Project Glasswing: Securing critical software for the AI era
Yesterday, I took a web application, downloaded the trial and asked AI to be a security researcher and find me high and critical severity bugs.

Even vanilla models spew out POC for three RCE’s in less than an hour

elnerd··on RAM kits are now sold with one fake RAM stick alongside a real one
I have a fully populated server with 2x7K62 and 16x64GB (3200 mhz) for my home lab. Do you know how to check if I am affected by this?
elnerd··on An AI agent published a hit piece on me
«Document future incidents to build a case for AI contributor rights»

Is it too late to pull the plug on this menace?

elnerd··on Mobile carriers can get your GPS location
I just read gnutella page on Wikipedia, no mention of bad actors
elnerd··on Vulnerable WhisperPair Devices – Hijack Bluetooth Accessories Using Fast Pair
I have the impression this is not the same. In the linked video, they talked about unauthenticated functions in BLE if I recall correctly…
elnerd··on Apple testing new App Store design that blurs the line between ads and results
In related news, 10% of Meta ads are malicious, and they have Meta seems to have little incentive to stop it.

https://www.reuters.com/investigations/meta-is-earning-fortu...

elnerd··on Kubernetes egress control with squid proxy
Would it be be trivial to have a init container to do CA injection? Maybe though mutating admission controller? Then some CNI magic to redirect outbound traffic to do transparent proxying?
elnerd··on 10 Years of Let's Encrypt
One domain parking actor is responsible for nearly 10% of all issued ssl certificates. 185.53.178.99. This is just one of many bad actors.
elnerd··on Disrupting the first reported AI-orchestrated cyber espionage campaign
We soon will have to implement paradoxes in our infrastructure.
elnerd··on Samsung makes ads on smart fridges official with upcoming software update
I unsubscribed from Spotify for this very reason.
elnerd··on Are these real CVEs? VulDB entries for dnsmasq rely on replacing config files
Just because you cannot see how a vulnerability can be exploited does not mean that others can. As you describe, people seem to assume that the only way the config file ends up on the server is «physically» editing it.

An anecdote: I have been struggling with exploiting a product that relies on MongoDb, I can replace the configuration file, but gaining RCE is not supported «functionality» in the embedded version as the __exec option came in a newer version.

A parser bug would be most welcome here.

elnerd··on ./watch
What’s the emulator he used when designing the firmware?
elnerd··on EVs are depreciating faster than gas-powered cars
It is strange how EVs are measured by how far they can go full charge when this is a metric I never have seen for fossile cars. It tells a story how inconvenient EVs or the charging network really is
elnerd··on Privacy Badger is a free browser extension made by EFF to stop spying
You are actually more likely to buy a car just after you have bought a car than the 10 years you did not need to buy a car. Maybe not cars, but I’ve heard this argument for kitchen appliances. If you for some reason return the item you just bought, you may buy what you get ads for. Maybe you regret you did not get the premium one, especially when they shove it in your face afterwards…
elnerd··on Slack has raised our charges by $195k per year
Getting the rug pulled under you does not qualify as an experience you need. It happens, but should not be in the curriculum for kids.

I am sure that being forced to spend time on this steals time from more interesting projects.

elnerd··on An attacker’s blunder gave us a look into their operations
After thinking of it for a while, I do not think it is such a big issue. The threat actor was probably an adversary to existing huntress customers and the EDR probably reacted to his tooling and mistakes.

When doing red team engagements, we do the same, install same security solutions as the customer and work around it. It could be what happened here?

That the analysts spotted him and were able to connect it to existing cases is just good craftsmanship.

I no longer feel that it’s relevant to discuss a red line here. Huntress just did their job.

elnerd··on An attacker’s blunder gave us a look into their operations
Unrelated story; how politician gave us a look into their financial adventures.

I am curious where the red line is.

Any criminal activity or just behavior that the analysts find interesting?