HNHacker News
TopNewBestAskShowJobs

landr0id

1,326 karma · joined March 1, 2012

[ my public key: https://keybase.io/lander; my proof: https://keybase.io/lander/sigs/EH5ZD_-bXVwuHyJBpOud37S7telhzEEkGtmhbeIL0rQ ]
submissionscomments
landr0id··on U.S. postal inspectors shut down website selling counterfeit postage labels
Thanks for the links. I'm confused how this works and the USPS report seems to be heavily redacted around details.

I would assume that the tracking number has the address details tied to it (I mean, based on support claims with USPS it definitely does), but maybe there's some obscure package type where destination is not distinct and they abuse that in a pool with other sellers, then at the last mile it gets sorted appropriately?

Seems wild that this market even exists considering how USPS flat rate postage exists.

Was your package something heavy or extremely light which makes weight-based shipping more economical?

landr0id··on How one Twitch chat message became code execution on a streamer’s PC
It's not just moving a code pointer. They had to migrate CEF runtimes (Alloy to Chrome) which, as I understand from the few minutes of reading I did to understand the complexities outlined in the PR, was necessary because Alloy was removed in M128. So OBS was using the last version of legacy runtime and needed to migrate. I imagine they wanted to do a decent amount of testing to ensure compat.
landr0id··on How one Twitch chat message became code execution on a streamer’s PC
While problematic, this is pointing the finger at the wrong thing. The version of the browser was from 2024. The permutations of full chain exploits permitting sandbox escape since then is probably pretty high.

It's a patch gap, plain and simple. Removing the sandbox certainly did not help things.

landr0id··on Portal by Spotify cut my Claude Code token usage by 90%
I used to date a girl who was a designer and had to plead with her that breaking behaviors I'm used to is not a positive UX.

"But it adds motion" was the classic reply.

landr0id··on Boot a Virtual iPhone via Apple's Virtualization.framework
It's useful for security research since you can do kernel debugging and inspection of the device not possible in the simulator.

As others pointed out it's also useful for e.g. click/spam farms which need a "real" iPhone.

landr0id··on Malicious Rust crate Arrayref runs a build-time payload
[3] is no longer true. They're definitely not unprepared for an incident like this. It's not the first time they've done it and they published an update to their process in Feb:

https://blog.rust-lang.org/2026/02/13/crates.io-malicious-cr...

Not having an advisory INSTANTLY available isn't a sign of a decaying org. Chill.

landr0id··on Zig's Incremental Compilation Internals
Comments like these are why, even if Fil-C has cool technical accomplishments, I find it hard to speak positively about it. You unfortunately seem to forgo all nuance and push disingenuous arguments which fuel the cycle with similarly disingenuous people.

I'll do you a favor though and cite a few things related to "lobbying"

The White House put out an RFI regarding open-source security: https://bidenwhitehouse.archives.gov/wp-content/uploads/2024...

Rust foundation's response: https://www.regulations.gov/comment/ONCD-2023-0002-0045

Neither have anything to do with making "programming in C illegal".

landr0id··on Zig's Incremental Compilation Internals
>you must go through a system provided shared library rather than make syscalls directly

Just to add to this, on Windows for example you're really only supposed to invoke syscalls via ntdll as the syscall table is not stable so their numbering changes over time. You cannot guarantee forward or backward compat if you do not use the library.

If you look at some of the syscalls in https://github.com/j00ru/windows-syscalls, you can see they clearly do change over time too.

landr0id··on How Our Rust-to-Zig Rewrite Is Going
I still don't think that does anything regarding use-after-frees, only double-frees.

Here's the code: https://codeberg.org/ziglang/zig/src/commit/e44e927d33d37c44...

The closest callout in the doc comment is:

>Never reuses memory addresses, making it easier for Zig to detect branch on undefined values in case of dangling pointers. This relies on the backing allocator to also not reuse addresses.

But it's not really clear what this means. "branch on undefined values" would I think indicate that maybe they're doing a fill pattern that the compiler can detect at runtime when dereferenced? But I don't see it in the `free` path. It's not clear if this is deterministic or not either.

landr0id··on How Our Rust-to-Zig Rewrite Is Going
>The DebugAllocator catches use-after-free (at least on page-level)

To clarify, is that to say that you have to use the `std.heap.page_allocator` as its backing allocator?

landr0id··on How Our Rust-to-Zig Rewrite Is Going
>ReleaseSafe catches use-after-free errors through runtime checks which panic if the program tries to use freed memory.

I don't know Zig so maybe they know something I don't, but I have seen no evidence that it catches any type of use-after-free including double-free?

While writing a blog post (below) I went through the documentation to figure out the possible runtime memory safety checks Zig can insert. The term "use-after-free" or "UaF" never occurs on that documentation page. Searching for "safety-checked" doesn't yield any related hits either.

Unless maybe they're using the DebugAllocator in release builds? Even that does not reliably surface UaF.

https://landaire.net/memory-safety-by-default-is-non-negotia...

landr0id··on Codex Micro
For the Nomad: The caps slightly rotate. If you look at them from the side profile, they are also all varying heights. I found enough variance in the physical layout of keys that I was constantly making mistakes and pressing multiple keys simultaneously. It has this gimmicky magnetic riser on the back which the magnets fell out of. The display is just a gimmick but has a fun Tamagotchi-type thing that analyzes WPM, so that's cool at least.

The company itself had crazy production delays on both the Nomad and the Knob1, and seem to depend on hypebeast marketing. For $400 you would expect a very premium product and it's easy to argue that they missed the mark pretty hard.

Oh I also placed a pre-order and they refused to cancel after many delays. Unfortunately after that point it was too late for a chargeback.

*just found a random review if you want to see other opinions. The comments discuss some of the weird company shenanigans: https://old.reddit.com/r/MechanicalKeyboards/comments/1ngka3...

landr0id··on Codex Micro
If anyone is looking at this thinking it looks pretty and wants to check out Work Louder's keyboards, let me save you the time. Their keyboards must be made by designers who do not type much because they are both not pleasant to type on and not very high-quality.

The Nomad [E] might be one of the worst keyboards I've ever purchased, and I owned one of the original butterfly switch MacBooks.

landr0id··on Cargo-nextest: 3x faster than cargo test, per-test isolation, first-class CI
Big fan of nextest and this is my first time seeing this site. I'll be real I feel a bit ridiculous commenting this but you might want to consider rephrasing this:

>Treat tests as cattle, not pets. Detect and terminate slow tests.

Not sure saying, "hey, treat your tests as an animal you can kill at will" paints the right image.

landr0id··on CS2 Fog Of War: Server-sided anti-wallhack occlusion culling for CS2 servers
Yeah my bad for not defining it. "Extra-Sensory Perception", basically as you said I believe is the most common feature -- but in general I think encompasses cheats that generally boost your "senses". So it could use audio to visually draw on your screen/radar where the sound came from.

The screenshot in this repo is kind of similar to wallhacks, but you could imagine this could easily be extended to show dropped items and the 3D audio location: https://github.com/ryanjpwatts/esp-analysis

landr0id··on CS2 Fog Of War: Server-sided anti-wallhack occlusion culling for CS2 servers
I wonder how often wall hacks are actually used in high-level competitive play by cheaters vs ESP. ESP seems like the better route to avoid manual review flagging suspicious activity. Audible cues (which this currently does not mitigate, and I'm not sure it can) are things that can genuinely separate players by skill and you'd think someone running such a cheat just has very good hearing.

>CS2FOW uses static baked map geometry. Dynamic occluders such as doors, breakables, props, smokes, particles, and projectiles are intentionally out of scope for now.

Market window on Mirage just became more powerful on these servers :)

Very cool project nonetheless.

landr0id··on To study how chips work, MIT researchers built their own operating system
I suppose they did make their work public after all :)

Thank you for pulling up the references.

landr0id··on To study how chips work, MIT researchers built their own operating system
Not to take away from the authors' work, but this was actually the approach taken by some engineers while Spectre / Meltdown were still under embargo. Not sure if they ever mentioned their work publicly so I will avoid naming them, but some talented folks from Microsoft who basically came to the same conclusion that a specialized environment free of noise was necessary both to test mitigations and find variants.
landr0id··on Apple unveils new accessibility features
I didn't really mind the fn keys being there. I rarely use function keys unless I'm RDP'd to a Windows machine.

What drove me crazy though was the escape key. They later added the physical escape key back but I think at that point it was a bit too late.

landr0id··on First public macOS kernel memory corruption exploit on Apple M5
GPU memory/shaders/etc. isn't protected by MTE or PAC. They said "data-only", so I guess GPU commands could fit into this description.
landr0id··on When life gives you lemons, write better error messages
Static analysis tools + MCP server + a debugger with an MCP server makes reverse engineering incredibly easy and low-cost.

I wrote a blog post about this recently: https://landaire.net/reverse-engineering-with-ai/

Just yesterday I completely reverse engineered several proprietary audio codecs from a game without even having to touch the static analysis tool myself.

landr0id··on Maybe you shouldn't install new software for a bit
They exploited a linear stack buffer overflow. Not a write-what-where or arb write. A linear stack buffer overflow in 2026! There are at least two distinct failures there:

1. No strong stack protectors.

2. No kASLR.

That's 20-year-old exploit methodology.

landr0id··on Maybe you shouldn't install new software for a bit
Ask yourself why Mythos was so easily able to develop a remote STACK buffer overflow vulnerability.
landr0id··on Maybe you shouldn't install new software for a bit
>Last I read, ASLR is a good thing to have, but overall is usually not difficult to defeat.

For local attackers there may be easier avenues to leak the ASLR slide, but for remote attackers it's almost universally agreed it significantly raises the bar.

>I don't think it's reasonable to say that an OS that lacks it isn't "serious" about security.

When they implemented it in 2019 it had been an 18-year-old mitigation. If you are serious about security, you implement everything that raises the bar. The term "defense-in-depth" exists for a reason, and ASLR is probably one of the easiest and most effective defense-in-depth measures you can implement that doesn't necessarily require changes from existing code other than compiling with -pie.

landr0id··on Maybe you shouldn't install new software for a bit
FreeBSD didn’t have user land ASLR until 2019 and, amongst other mitigations, still doesn’t have kASLR. It’s not a serious operating system for people who care about security. If you want FreeBSD and security take Shawn Webb’s HardenedBSD.
landr0id··on Mythos is the best cybersecurity news in a decade
Mythos hacked the site, wrote, and published the article
landr0id··on Why TUIs are back
Their GUI system (GPUI) is not very mature for use outside of Zed. GPUI is basically a UI framework in the truest sense: a framework for building UI... frameworks/components. It has core functionality for async execution, an ECS for grabbing shared resources, and a div.

It's basically like building a website with div and basic CSS.

gpui-component exists: https://github.com/longbridge/gpui-component

Up until sometime late 2025 GPUI wasn't even on crates.io, and it seems like the GPUI-component ecosystem still promotes using git deps. It was also in "read the code for docs" state for a very long time

It's been a while since I've used it, but there were weird things missing too like the Scollbar was located in Zed's UI component crates instead of core GPUI. Arbitrary text selection also is not possible, which is something I really value about egui.

landr0id··on Localsend: An open-source cross-platform alternative to AirDrop
https://www.iroh.computer/sendme

Iroh's protocol can figure out if the devices are on the same LAN and avoid going over the internet. It can work without a discovery server too -- i.e. completely LAN.

landr0id··on GitHub Stacked PRs
They wrote something that allowed them to virtualize Git -- can't remember the name of that. But it basically hydrated files on-demand when accessed in the filesystem.

The problem was I think something to do with like the number of git objects that it was scaling to causing crazy server load or something. I don't remember the technical details, but definitely something involving the scale of git objects.

landr0id··on GitHub Stacked PRs
>At the same time, the larger tech companies (Meta and Google, specifically) ended up building off of hg and not git because (at the time, especially) git cannot scale up to their use cases.

Fun story: I don't really know what Microsoft's server-side infra looked like when they migrated the OS repo to git (which, contrary to the name, contains more than just stuff related to the Windows OS), but after a few years they started to hit some object scaling limitations where the easiest solution was to just freeze the "os" repo and roll everyone over to "os2".

Page 1 of 11Next →