HNHacker News
TopNewBestAskShowJobs

ikmckenz

306 karma · joined January 25, 2022

submissionscomments
ikmckenz··on Former German spy chief arrested for attempted treason
We don’t know what country he was spying for, but we do know it’s not Russia. From the very short article: > The case does not involve Russia, according to information obtained by Sueddeutsche Zeitung.
ikmckenz··on FBI used iPhone notification data to retrieve deleted Signal messages
This is different than push data, which already does not contain any content or metadata in Signal. This is about local OS caches, whereas for push notifications Signal only sends a push saying “message received” which wakes the device up and triggers the device to pull the message from the server over the regular e2e encrypted path.
ikmckenz··on Every single board computer I tested in 2025
I really want a small SBC with USB-C DP Alt mode that I can stuff into a ~60%ish mechanical keyboard-sized case to make into a headless laptop thing so I can justify buying some display glasses like the XReal One or similar. Seems like it would be the ultimate travel computing solution.
ikmckenz··on Good Bad ISPs
Parent comment was talking about relay nodes, not exit nodes. The risk of running a relay node is essentially zero in a free country.
ikmckenz··on Good Bad ISPs
I think the hosts that Tor recommends against because there are already so many nodes hosted on them like OVH and Hetzner are perfectly happy with their (quite good) reputations.
ikmckenz··on I found a vulnerability. they found a lawyer
That’s almost what we already have with the CVE system, just without the legal protections. You report the vulnerability to the NSA, let them have their fun with it, then a fix is coordinated to be released much further down the line. Personally I don’t think it’s the best idea in the world, and entrenching it further seems like a net negative.
ikmckenz··on Apple patches decade-old iOS zero-day, possibly exploited by commercial spyware
Your opinion is that Apple should have just handed over Jamal Khashoggi‘s information to the Saudi Arabian agents who were trying to kill him, because then Saudi Arabia wouldn’t have been incentivized to hack his phone? I think you’ll find most people’s priorities differ from yours.
ikmckenz··on The Day the Telnet Died
OpenSSH has been moving quite quickly in the direction of multiple, privilege separated processes, each also heavily sandboxed with pledge and unveil
ikmckenz··on OpenBSD-current now runs as guest under Apple Hypervisor
As of 2025 OpenBSD has support for AMD SEV and SEV-ES, with support for SEV-SNP work-in-progress, so with the right hardware yes it's able to isolate itself sufficiently https://www.bsdcan.org/2025/timetable/timetable-Confidential...
ikmckenz··on India orders smartphone makers to preload state-owned cyber safety app
> very deep interests in things i was completely unaware that they existed ... say goodbye to the cognitive ability of a large chunk of future generations

I would think very deep interests in niche or obscure topics is correlated with increased cognitive ability, not a decrease.

ikmckenz··on Bitcoin's big secret: How cryptocurrency became law enforcement's secret weapon
Is this comment AI written?
ikmckenz··on Look, Another AI Browser
Why won't these sites simply block this browser?
ikmckenz··on ADS-B Exposed
What's the story behind adsbexchange selling out?
ikmckenz··on The treasury is expanding the Patriot Act to attack Bitcoin self custody
No, historically the vast majority of communication was not recorded, and so a warrant could not be used to access the communication. The fact of the modern world is that for the first time in history almost everything we do is recorded, and so subject to those warrants.
ikmckenz··on The great AI delusion is falling apart
> They forgot about training and practice. Try it with airplanes. "The results surprised us. Given Boeing 777 they thought they will get from London to New York in 7 hours, but they actually couldn't even get off the ground. In fact they couldn't even start the engines."

If your "AI Assistant" is as hard to operate as a trans-Atlantic flight on a Boeing 777, perhaps it's not a very good assistant?

ikmckenz··on Private sector lost 33k jobs, badly missing expectations of 100k increase
I would expect that data to be mostly noise though, after all, there is pretty strong evidence towards some soft form of "set point" level of happiness: https://en.wikipedia.org/wiki/Hedonic_treadmill
ikmckenz··on XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
All of them are real? You have a 100% rate of reports closed as valid?
ikmckenz··on XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
Related: https://arstechnica.com/gadgets/2025/05/open-source-project-...
ikmckenz··on By default, Signal doesn't recall
Except for the fact that the security of Session is drastically worse than Signal.

https://soatok.blog/2025/01/14/dont-use-session-signal-fork/ https://soatok.blog/2025/01/20/session-round-2/

ikmckenz··on Google Play sees 47% decline in apps since start of last year
> the EU has not yet stomped them into mulch hard enough yet I see

This is literally the result of EU "stomping"

ikmckenz··on Rsync replaced with openrsync on macOS Sequoia
And yet I don't see Apple on the list of contributors of the OpenBSD Foundation (https://www.openbsdfoundation.org/contributors.html), shame.
ikmckenz··on Blasting Past WebP - An analysis of the NSO BLASTPASS iMessage exploit
The Isosceles blog post[0] on the initial webp exploit, linked by the article, says:

> Google's OSS-Fuzz project has fuzzed hundreds of open source libraries for many years now, including libwebp and many other image decoding libraries. It's possible to look in full detail at the code coverage for OSS-Fuzz projects, and it's clear that lossless support for WebP was being fuzzed extensively… In fact one of the first things that Google did after the WebP 0day was fixed was to release a new fuzzer specifically for the Huffman routines in WebP. I tried running this fuzzer for a bit (with a bit of backporting required due to API changes) and it predictably did not find CVE-2023-4863… This bug also shows that we have an over-reliance on fuzzing for security assurance of complex parser code. Fuzzing is great, but we know that there are many serious security issues that aren't easy to fuzz.

So perhaps it’s not so simple as throwing a fuzzer at it.

[0] https://blog.isosceles.com/the-webp-0day/

ikmckenz··on The Practical Limitations of End-to-End Encryption
An actual strongly encrypted messenger app like Signal is not really like a FBI fake-encrypted honeypot app like Anom
ikmckenz··on Wall Street’s ‘Private Rooms’
No, "I am XYZ hedge fund and I want to buy stock ABC" is not material non-public information to XYZ hedge fund. If it was, any buying or selling of stocks would always be illegal, since you would be "insider trading" on your desire to buy the stock.
ikmckenz··on Wall Street’s ‘Private Rooms’
> Isn't the problem that this allows for all kinds of forms of insider trading?

No, it doesn't. All trades are made public after they happen, as per regulations. There is no difference to insider trading regulations if a bad actor trades via a lit exchange or via a dark pool. Dark pools only "hide" pre-trade information, such as standing buy or sell limit orders.

ikmckenz··on U.S. Government Disclosed 39 Zero-Day Vulnerabilities in 2023, First-Ever Report
There is no such thing as a "Nobody But Us" vulnerability. Leaving holes in systems and praying enemies won't discover them, with the hope of attacking them ourselves is extremely foolish.
ikmckenz··on Paris P2P Festival and Hackathon
I have nothing to do with this event, but what do you gain from misrepresenting this? They also gave:

30 mins on the state of the libp2p project

30 mins on ipfs network measurements

1hr on optimizing libp2p for mobile

30 mins on an end-to-end encrypted mesh network chat service

20 mins on an ipfs DHT performance improvement

30 mins on the QUIC transport protocol

30 mins on hole punching in libp2p

30 mins on libp2p in the browser, which included discussion on WebRTC which you explicitly said was the kind of thing that wouldn't be covered (https://p2p.paris/en/talks/libp2p-browsers-future/)

Yes there's also some crypto stuff there (both crypto-currency stuff like bitcoin security, but also general cryptography stuff like zk proofs and post-quantum cryptography), but I struggle to understand why people react so negatively to legitimately interesting research because it happens to be coming from the cryptocurrency space.

ikmckenz··on Paris P2P Festival and Hackathon
Looks like past events had deep technical talks on libp2p's DHT (https://p2p.paris/en/talks/libp2p-dht/), and a novel gossip based pubsub protocol (https://p2p.paris/en/talks/gossipub/). Pretending that there is zero overlap between "crypto and blockchain bullshit" and p2p work is detrimental to everyone involved, there is serious p2p research and work being done both from crypto projects and from more traditional projects.
ikmckenz··on TikTok says it is restoring service for U.S. users
Except now they get to remain the owners and they don’t have to sell at fire sale prices, so it turned out to be the best possible outcome for their shareholders.
ikmckenz··on I have made the decision to disband Hindenburg Research
And those German short-sellers (and to a lesser extent their British counterparts) were aggressively bullied by their local government market regulators https://www.reuters.com/article/technology/germanys-long-lon...
Page 1 of 3Next →