HNHacker News
TopNewBestAskShowJobs

evan_a_a

163 karma · joined February 7, 2025

submissionscomments
evan_a_a··on How Mark Klein told the EFF about Room 641A [book excerpt]
Aka the Executive Director of the EFF.
evan_a_a··on Cybersec is a thankless job: expanding workload and shrinking pay packet
>Even that ignores the fact that major corporations are frequently attacked by state actors, so really the minimum standard for protection against expected threats should include those as well, but I will leave that aside for now since the overwhelming sentiment is that protection against state actors is so utterly hopeless it is not even worth mentioning.

It always has been, it's just now the state actors are more and more active (and visibly so).

evan_a_a··on Cybersec is a thankless job: expanding workload and shrinking pay packet
Pentests work to secure the product under test at the point in time of the test (if the company cares to fix the bugs...). The real solution is to design in security throughout the software lifecycle, not play pentest wack-a-mole game at the end of the cycle. If a pentester is finding trivial SQL injection in an app, then it is clear that the company never considered security. And unless the pentest makes them care, the cycle will just continue.
evan_a_a··on Cybersec is a thankless job: expanding workload and shrinking pay packet
It is an investment problem, they need to invest in security expertise, not security products and services. And that is the sad part, absent the company really caring to spend that money or an external demand (regulatory or customers) it just isn't going to happen. They'll just layer on more products and services and call it a day.
evan_a_a··on Cybersec is a thankless job: expanding workload and shrinking pay packet
The company I work for (consulting) upended the entire strategy to basically use pentests to sell managed services (XDR, NDR, SOC, vuln scanning, "continuous pentest") that does nothing to meaningfully move the needle on security. Which of course the market will buy, but it is incredibly demoralizing to see expertise sacrificed to the alter of recurring revenue.
evan_a_a··on Cybersec is a thankless job: expanding workload and shrinking pay packet
I forsee issues with really getting use out of any commodity language model in the hardware security context, because hardware systems notoriously lack standardization. And often times, the technical knowledge (datasheets, app notes) is locked behind vendor NDAs, or straight up not documented, only existing in the minds of engineers. The implementations of said designs are similarly highly proprietary, with little public "real" systems to train models on.

So the issue is two-fold:

* The knowledge must be documented and accessible for training.

* A bespoke model must be trained this documentation.

It is unlikely that both of these things happen in the general model context. Perhaps individual chip vendors will eventually pursue this, but I suspect it is just not a priority for them.

evan_a_a··on Cybersec is a thankless job: expanding workload and shrinking pay packet
I mean it in the sense that AI security hype and the larger geopolitical environment has woken up a lot of people to the reality that they need to consider security. And the ones that haven't woken up yet will get a wakeup call when they are breached. It also increases the demand for real security expertise, which is already scarce.

Also, in my niche (hardware and embedded product security), AI doesn't a have a functional impact to the work except in code analysis, but even that is difficult given the level of abstraction these systems are built at.

evan_a_a··on Cybersec is a thankless job: expanding workload and shrinking pay packet
Whenever I tell people I work in computer security, their first question is "are you worried about AI taking your job"? To which I just laugh and respond "AI is job security"
evan_a_a··on The future of everything is lies, I guess: Work
spoilers
evan_a_a··on Mythos Is Everyone's Problem
>branded chaos

I'm gonna use this term from now on, thanks.

evan_a_a··on Artemis II is not safe to fly
Orion is a Lockheed (CM) and Airbus (ESM) project.
evan_a_a··on LaGuardia pilots raised safety alarms months before deadly runway crash
SMS is mandated by the FAA
evan_a_a··on Ubuntu wants to strip some of GRUB features in 26.10 for security purposes
encryption does not protect against malicious modification; authentication does.
evan_a_a··on LaGuardia pilots raised safety alarms months before deadly runway crash
What you're describing is already well known in the aviation industry. Promotion of a positive safety culture is a key element if the Safety Management System (SMS) framework

https://www.faa.gov/about/initiatives/sms https://www.faa.gov/media/94731

evan_a_a··on Migrating to the EU
I'm using Startmail, based in NL: https://www.startmail.com
evan_a_a··on Migrating to the EU
Australia is a member of five eyes and the US basically treats them like the 51st state.
evan_a_a··on FBI is buying location data to track US citizens, director confirms
direct from the media server

https://media.ccc.de/v/38c3-wir-wissen-wo-dein-auto-steht-vo...

evan_a_a··on Despite Doubts, Federal Cyber Experts Approved Microsoft Cloud Service
MS was (and still is it seems) unable to produce the data flow diagrams that FedRAMP wanted, ones that other cloud providers had no problem with. If the documentation is in such dire state, then the system itself is likely to also be in a dire state. I.e. The documentation is a pile of shit, so the system is also a pile of shit.
evan_a_a··on Grace Hopper's Revenge
>2) The Tesla section is interesting. I'm not saying that you are wrong, just that their methods have not produced the promised results yet

The flaw in Tesla's engineering choice to rely on a camera based system for self driving is that it is extremely difficult to approximate human vision with cameras alone. The author also does not mention this and instead assumes that "camera == human eye" which is not true.

>3) Wireless humanoid robots is a bad platform because we don't have the hardware to support them. Both battery density and compute efficiency is too low currently to support freestanding robots. Rip Roomba - long live its legacy

Boston Dynamics already has Atlas, with a 4 hour battery life and the ability to self-swap. That is already better than a human since it can presumably work non-stop for its entire runtime. Plus battery technology and compute efficiency are both still improving.

https://bostondynamics.com/products/atlas/

evan_a_a··on French railway operator tests solar on train tracks
What a waste of taxpayer dollars. There’s endless amounts of open land to put real solar farms on but no, let’s spend money on this nonsense.

https://youtu.be/7vItnxhWRqw

evan_a_a··on A lot of population numbers are fake
This is a literary device. The article continues to explain why this isn’t a simple problem, and it’s clear from the conclusion that the author understands the complexity.

>But it’s good to be reminded that we know a lot less about the world than we think. Much of our thinking about the world runs on a statistical edifice of extraordinary complexity, in which raw numbers—like population counts, but also many others—are only the most basic inputs. Thinking about the actual construction of these numbers is important, because it encourages us to have a healthy degree of epistemic humility about the world: we really know much less than we think.

evan_a_a··on Pavel Durov: "You'd have to be braindead to believe WhatsApp is secure in 2026"
He offers no proof, just “trust me bro”. If they actually had found flaws, they would’ve reported them. WhatsApp uses the Signal protocol, which is built by actual cryptographers using proper formal proofs. In contrast, MTProto is not designed from a formal cryptographic approach and is described by cryptographers as “brittle”. https://martinralbrecht.wordpress.com/2025/03/16/analysis-of...

Telegram also has no public security or cryptographic assessments, while meanwhile WhatsApp has had numerous components analyzed by cryptographers for security.

https://www.nccgroup.com/research-blog/public-report-whatsap... https://www.nccgroup.com/research-blog/public-report-whatsap... https://www.nccgroup.com/research-blog/public-report-whatsap... https://www.nccgroup.com/research-blog/public-report-whatsap... https://www.nccgroup.com/research-blog/public-report-meta-wh...

evan_a_a··on To establish that citizens of the US shall owe sole and exclusive allegiance [pdf]
This is typical for the senate. It’s called the “pro-forma session”. This is primarily done so that the senate is never truly in recess and thus blocks the president’s power to make recess appointments.

https://legalclarity.org/what-is-a-pro-forma-session-and-how...

evan_a_a··on Spanish track was fractured before high-speed train disaster, report finds
In Spain the high speed network is separate from the traditional network too. There is some inter connectivity to allow for high speed trains to call at traditional stations, but the high speed network is for high speed trains only.
evan_a_a··on In Europe, wind and solar overtake fossil fuels
In engineering the simple solution is often the best solution. Creating a demand-side network of devices is not that.

Plus, such a system would provide even more ways for nefarious actors to sabotage the grid, by influencing the demand side. For example, setting every appliance to run its load at the same time. The grid would be fucked.

evan_a_a··on Decorative Cryptography
I have bad news on that front.

https://tee.fail/

evan_a_a··on Bulgaria joins euro area from 1 January
Bulgaria has been an EU member state since 2007. This is only about adoption of the euro.
evan_a_a··on Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
This is a very standard part of responsible disclosure. Hacker finds bugs -> discloses them to the vendor -> (hopefully) the vendor communicates with them and remediates -> both sides publish the technical details. It also helps to demonstrate to the rest of the security world which companies will take reports seriously and which ones won’t, which is very useful information to have.
evan_a_a··on Samsung Removes Bootloader Unlocking with One UI 8
>They provide third party API's to use APPLE's RCS-Service. The alternative would have been to support registering alternative RCS-services as default on the OS (and then, allow the user to choose a service).

RCS messaging is carrier-controlled and configured via carrier bundles in iOS. Apple doesn't run a "RCS service". TelephonyMessageKit [0] in iOS 26+ exposes a standard interface to the carrier SMS, MMS, and RCS services, as applicable, allowing for 3rd party applications to send and receive carrier standards-based messages.

In 3GPP standards, RCS is just another service using the IP Multimedia Subsystem (IMS) framework. Carriers can either run their own RCS service in their IMS core or use a 3rd party service (as many do with Google's Jibe).

[0]: https://developer.apple.com/documentation/telephonymessaging...

evan_a_a··on Payment processors' bar on Japanese adult content endangers democracy (2024)
FedNow is a technological solution for instant payments, not a regulation. It’s a voluntary system for the banks to join. Further, banks are not required to offer instant payment services to their customers. The analogous technological solution in the EU is TIPS [0], which has been operational since 2018.

The IPR is a regulation that requires banks to support instant payments and offer them to customers.

[0]: https://www.ecb.europa.eu/paym/target/tips/html/index.en.htm...

← PreviousPage 2 of 3Next →