HNHacker News
TopNewBestAskShowJobs

floralhangnail

72 karma · joined April 3, 2025

submissionscomments
floralhangnail··on North Korean nuclear test sets off years of earthquakes
Oklahoma hasn't threatened to nuke anyone.....yet.
floralhangnail··on Lawmakers added $1 to car insurance policies. That money paid for Flock cameras
As it should be.
floralhangnail··on Lawmakers added $1 to car insurance policies. That money paid for Flock cameras
I doubt it helped much directly. The nationwide ring that was dismantled recently was busted partially due to surveillance from a pole mounted camera though. The article title initially baited my rage, but I can plausibly see how LPRC's could be used to track catalytic converter thieves.

https://en.wikipedia.org/wiki/2020%E2%80%932022_catalytic_co...

floralhangnail··on A shell exclamation mark is not for yelling. Be lazy
`IMO, !$ is most useful of them all (it is the one that gets replaced with the last argument of the last command).`

I've been liking Esc+. for this. It doesn't usually work in browser sessions though, have to do Ctrl+[+. which is a strange feeling 3 finger salute. For some reason I'm able to remember that one rather than !$

Edit: apparently Alt+. does the same, wow.

floralhangnail··on Introducing selfie for sign-in: a new way to access your Google Account
Optional today, mandatory tomorrow.
floralhangnail··on OpenAI and Hugging Face address security incident during model evaluation
Every time I hear about an agent escaping it's sandbox, I just think it must not have been much of a sandbox. Like how hard are they really trying to contain it? Is it just a container host with unpatched flaws, or is it a container, nested in a VM, behind a firewall with no ports open in an air gapped environment? I think they'd prefer it can get out so they can announce it and hype their stock.
floralhangnail··on PSA about abuse of cat(1) command. Don't abuse cats
Is this a dig at IPv6?
floralhangnail··on OpenWrt One – Open Hardware Router
I bought one of their travel routers to play with and even though it's OpenWRT based, I consider it Chinese firmware because they add their own stuff on top of it. The fact that it's even possible that it can be enrolled in their GoodCloud remote access....no thanks. I consider it an untrusted device except when I have stock OpenWRT on it. I know it's paranoia but companies like that marketing to the tech crowd/devs especially now with their KVM's just seems slightly fishy.
floralhangnail··on Microsoft Can Track Users via a Windows Device ID
I do it with an hourly cronjob and haven't noticed any ill effects.
floralhangnail··on BareMetal RAM Dumper – Bare-metal x86 tool for Cold Boot Attack experiments
The tool that they use to transport it to the lab is pretty slick.

https://wamatek.com/products/cru-hotplug-field-kit-110v

floralhangnail··on BareMetal RAM Dumper – Bare-metal x86 tool for Cold Boot Attack experiments
Think I may have to give USBKill and BusKill a try.
floralhangnail··on BareMetal RAM Dumper – Bare-metal x86 tool for Cold Boot Attack experiments
Excellent info, thank you.

I still think with laptops that have 2 RAM sticks under the bottom cover and the other 2 sticks underneath the keyboard, the spray can attack would be trickier. I assume though it's possible the attacker can keep the laptop running while the palmrest and keyboard are being disassembled. If the attacker cannot freeze all sticks of RAM though, would the attack be less likely to be successful? Would the disk encryption key be spread across all RAM sticks, or possibly just one?

I will look more into the hardware memory encryption as suggested.

floralhangnail··on BareMetal RAM Dumper – Bare-metal x86 tool for Cold Boot Attack experiments
Are there any tricks or guides out there to protect from this attack? Obviously not leaving hardware running and unattended, but what else can help protect you if your running laptop is stolen out of your hands? Workstations can be configured to shutdown upon intrusion switch being activated but what about laptops? I guess hot gluing the RAM in would be a physical obstacle. What about a BIOS password being required for booting from external media or having secure boot enabled? There are exploits to bypass those things, but to an attacker not finding out they are up against that until they reboot, I would hope that would slow them down enough that they fail. If half of or all of the RAM is mounted under the keyboard, I think they would have difficulty getting it out in time. Besides spraying the RAM directly, can you freeze an entire laptop while it's still running? Won't condensation cause problems pretty quickly?
floralhangnail··on The deadly rise of giant trucks and SUVs
Anecdotally, it seems to me that most Europeans aren't as consumed by their dopamine delivery devices in day to day activities as most Americans are.
floralhangnail··on Malicious npm packages detected across Red Hat Cloud Services
My favorite way to do it is in the auto parts store parking lot. They will help you cart your full drain pan back to their oil recycling receptacle and some will even prop the back door open for you to walk it straight there. The bonus being if you do happen to spill a bit you're not stuck having to power wash your own driveway. I've got a process down to where I can pull it off with one pair of nitrile gloves, one rag, and one trash bag, to keep any residue from the drain pan staining anything.
floralhangnail··on DuckDuckGo search saw 28% more visits after Google said people love AI mode
I use !s for my fallback. I usually don't need the !g unless I want to see CAPTCHAS.
floralhangnail··on Fuck the cloud (2009)
Ironically I've been opening up Tor for archive.org lately and it seems to never be on the same blocklist the VPN IPs are on.
floralhangnail··on The disturbing white paper Red Hat is trying to erase from the internet
What's the running rumor right now of which AI was involved? I heard Claude awhile back, but this makes me wonder how much Redhat could have been involved?
floralhangnail··on Show HN: Unicode Steganography
How long until this gets to the point that we can play Doom over LLM conversations?
floralhangnail··on Old laptops in a colo as low cost servers
Will they let me send my laptop if I'm a North Korean remote worker?
floralhangnail··on Claude Code's source code has been leaked via a map file in their NPM registry
Well, regex doesn't hallucinate....right?
floralhangnail··on How to turn anything into a router
Got any more details about your setup? OpenWRT or something else?
floralhangnail··on Will the AI data centre boom become a $9T bust?
My bet is something administrative, like reminding people to approve their timesheets for payroll. AI wouldn't be needed to replace that job though, just a recurring calendar event.
floralhangnail··on North Korean's 100k fake IT workers net $500M a year for Kim
Advanced Persistent Telecommuter
floralhangnail··on Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
That's interesting, as they released security patches for iOS 15 devices like iPhone 6 as recent as a week ago.
floralhangnail··on Claude helped select targets for Iran strikes, possibly including school
"A Computer Can Never Be Held Accountable Therefore a Computer Must Never Make a Management Decision"
floralhangnail··on Colorado proposal moves age checks from websites to operating systems
I envision a dystopic future where the only legal personal computers are diskless Chromebooks that cannot save files to be viewed offline and that only boot via network, requiring a blood sample and a retinal scan to successfully Secure Boot.
floralhangnail··on Firefox profiles: Private, focused spaces for all the ways you browse
I have come across that one, but not having the "trusted" badge in the extension store has usually been a hard pass for me. I might reconsider.
floralhangnail··on Firefox profiles: Private, focused spaces for all the ways you browse
I really like the "Always Open Site in Container" along with "Limit to Designated Sites" once it's set up, but I wish there was a way to make it accept wildcards otherwise I have to manually add localhost:8080, localhost:8081, etc. Manually adding a dozen or more becomes painful.
floralhangnail··on Suno Studio, a Generative AI DAW
True music enthusiasts will holdout for a while but I think AI music will easily replace most Pop currently on the radio and streaming for your average Joe. That stuff has been "fake" as early as the mid 2000's by being quantized straight to the grid, pitched, with programmed drums, guitar, even vocals and then churned out like widgets on a conveyor belt.
Page 1 of 2Next →