HNHacker News
TopNewBestAskShowJobs

jvbotelho

5 karma · joined July 21, 2026

submissionscomments
jvbotelho··on Show HN: Skewrun – fix Kerberos clock skew per-process, no root (open source)
Im a dev and i have been learning cybersec and acting as appsec eng

During the ctfs, boxes and etc the KRB_AP_ERR_SKEW found me a lot, the usual "correction" for it is to change the entire system clock or use some one liners that always get bugged or dont work in every environment, so i decided to create the skewrun to solve it and to also practice the knowledge ive been getting, also decided to do it with rust to be able to create libs/crates others could use in theirs projects and help the community.

So Skewrun is a wrapper that reads the DC time (CLDAP → SMB → NTP) with protocol fallback in case of errors and calculates the offset in the microsecond then injects it in the process being wrapped by LD_PRELOAD resulting in the tool/script being synced with the DC without the need to change the system clock and without root.

As i said, its lib-first, with the crate ad-time dealing with the time extraction and etc and the skewrun being the cli to orchestrate it

Ive also written some ADRs with the decisions and choices made, research done, one of the nicest is the ADR-0002 that talks about the till from AS-REQ that is a Windows hardcoded constant, in the first iterations i was using now+10h what even broke in one test because the local clock was too far behind, the lib is also proptested and fuzzed in the CI

But yeah, it still have some limitations, whereas the ad-time is OS agnostic the skewrun only runs in linux because it need the libfaketime and it doesnt work with static bins (like Go) but the cli will detect and warn about it if you try

Now for the fun part, how to test it xD, you can simply run "cargo install skewrun", for me is the easiest path but you can also use the static pre-compiled musl bin available in the github release or build from source. and if you just wanna see it running first, theres a ~35s asciinema here: https://asciinema.org/a/1261342 (also a gif in the readme)

So, what do you think? the ad-time as a crate makes sense to be used outside skewrun? and has anybody dealt with this kind of problem without LD_PRELOAD, any ideas of how to make it deal with satic bins and/or be trully OS agnostic?

jvbotelho··on Code review: slapping an AI reviewer on top of an AI author doesn't cut it
There is also this paper that says that this AI loop makes the security worse getting almost 40% rise of vulns after just 5 iterations https://arxiv.org/html/2506.11022v2
jvbotelho··on Does code quality still matter?
And we should also look at the security perspective, Devs with AI produce 10x more "security findings" (https://www.theregister.com/2025/09/05/ai_code_assistants_se...)

Another report says that AI code has 3 times more vulns then human ones with 45% being related with the OWASP top 10 (https://www.veracode.com/blog/genai-code-security-report/)

jvbotelho··on Why the OpenAI escape is the most worrying AI mishap yet
Im personaly waiting the hype pass and some analysis/explanation be done or posted somewhere, for now im pretty skeptical, worth noting OpenAI is still unprofitable and with the whole fuss about anthropic's mythos and etc i'd take it with a grain of salt, as far as i've read about, it seems that was a human error result, bad isolated infra (it was supposed to be isolated from the internet) + "unlimited" tokens to the model run on
jvbotelho··on Ask HN: What Are You Working On? (July 2026)
im developing some FOSS cybersec tools lately and im getting some nice feedback so it motivates me, the tools are

Skewrun -> a tool that solves the Kerberos KRB_AP_ERR_SKEW (Clock Skew Too Great) error, allowing you to run tools like Impacket or NetExec from a Linux attack machine whose clock is heavily desynchronized from the target Windows domain, without requiring root privileges to change the system time. (https://github.com/JVBotelho/skewrun)

GhostHound -> an Bloodhound opengraph lib that deals with Tombstone reanimation as a BloodHound attack path, enumerating CN=Deleted Objects and who can restore them (https://github.com/JVBotelho/ghosthound), this one even landed in Bloodhound's documentation as community lib

jvbotelho··on Build a website for AI pics for dating apps in 20 hours, launched ads, failed
as colesantiago said, you did it for "free", almost anyone can do the same, and it seems you just build "yet another ai wrapper", so whats the value for your user?