HNHacker News
TopNewBestAskShowJobs

mmsc

3,253 karma · joined May 22, 2021

https://joshua.hu/about

https://www.linkedin.com/in/joshua-alexander-rogers/

https://github.com/megamansec

Security, hacking, travel, lulz, vodka.

submissionscomments
mmsc··on Email obfuscation: What works in 2026?
> Also, a note to those who make fancy "me+someservice@somedomain.com" addresses:

Just wait until one of these companies demands an email from the registered email address of your account!

mmsc··on Hong Kong police can now demand phone passwords under new security rules
Ah, finally catching up to ... The UK, Australia, Ireland, France, the Netherlands, and probably a lot more.
mmsc··on A Japanese glossary of chopsticks faux pas (2022)

  こすり箸 Kosuribashi:
 To rub waribashi (disposable chopsticks) together to remove splinters.
I don't know about Japan, but everybody does this in Taiwan.
mmsc··on Aquasecurity/Trivy GitHub Repository and Homebrew Cask Compromised (again)
The offending commit seems to be: https://github.com/aquasecurity/trivy/commit/1885610c6a34811... which updates the action to `actions/checkout@70379aad1a8b40919ce8b382d3cd7d0315cde1d0 # v6.0.2`. https://github.com/actions/checkout/commit/70379aad1a8b40919... is not actually in `actions/checkout` but a fork, and it pulls malicious code from the typo-squatted "scan.aquasecurtiy.org" (note the _tiy_).

Any system with Trivy 0.69.4 on it (and being run) can be assumed to be compromised.

mmsc··on Glassworm is back: A new wave of invisible Unicode attacks hits repositories
GitHub advertises itself as warning about those Unicode characters: https://github.blog/changelog/2025-05-01-github-now-provides...

Of course, it doesn't work though. I reported this to their bug bounty, they paid me a bounty, and told me "we won't be fixing it": https://joshua.hu/2025-bug-bounty-stories-fail#githubs-utf-f...

The exact quote is "Thanks for the submission! We have reviewed your report and validated your findings. After internally assessing your report based on factors including the complexity of successfully exploiting the vulnerability, the potential data and information exposure, as well as the systems and users that would be impacted, we have determined that they do not present a significant security risk to be eligible under our rewards structure." The funny thing is, they actually gave me $500 and a lifetime GitHub Pro for the submission.

mmsc··on Iran-backed hackers claim wiper attack on medtech firm Stryker
Require dual sign off
mmsc··on The death of social media is the renaissance of RSS (2025)
> an LLM can ingest unstructured data and turn it into a feed.

An LLM can try to do that, yes. But LLMs are lossy compression. RSS feeds are accurate, predictable, and follow a pre-defined structure. Using LLMs to ingest data which can easily be turned into an parseable data structure seems strange: use the LLM to do the "next part" of the formula (comprehension, decision making, etc)

There is also LLMs.txt https://llmstxt.org/ eg https://joshua.hu/llms.txt / https://joshua.hu/llms-full.txt

mmsc··on Making Firefox's right-click not suck with about:config
https://paulgraham.com/disagree.html

Please consider reading.

mmsc··on Hardening Firefox with Anthropic's Red Team
It's cool that Mozilla updated https://www.mozilla.org/en-US/security/advisories/mfsa2026-1... because we were all wondering who had found 22 vulnerabilities in a single release (their findings were originally not attributed to anybody.)
mmsc··on Making Firefox's right-click not suck with about:config
> Did you really make a blog post to tell the world that you don't know some things? That's not usual

You are focusing on 5 words out of a 1000-word post. Get a grip lol.

In a world of usual, I like to be unusual.

mmsc··on Making Firefox's right-click not suck with about:config
> Mine also isn't anywhere nearly as confusing as his by default

You can run the following and try it for yourself. Don't forget to highlight some text before right-clicking an image (e.g. https://en.wikipedia.org/wiki/The_World_Factbook)

  TMPPROF="$(mktemp -d /tmp/ff-tmp.XXXXXX)"
  /Applications/Firefox.app/Contents/MacOS/firefox -no-remote -profile "$TMPPROF"
mmsc··on Making Firefox's right-click not suck with about:config
It's gleaned from my locale. .hu is irrelevant; my alternative keyboard on my system is Polish
mmsc··on Making Firefox's right-click not suck with about:config
You're right, I didn't know about what that "..." meant. It's kind of obvious what I meant though: "I don't know why all of these have ..." I've added that information to the post.

The greyed out options have no point because 99.99% of the links I click are already clean. Like so many of the other privacy enhancing options, just provide an option to "clean links automatically."

mmsc··on Making Firefox's right-click not suck with about:config
loael
mmsc··on Firefox 148 Launches with AI Kill Switch Feature and More Enhancements
Also forgot `browser.ml.chat.menu`, `browser.ml.linkPreview.enabled`. If only there was a way to get rid of "Email image", and "Set image as desktop background".
mmsc··on Emails to Outlook.com rejected due to a fault or overzealous blocking rules
I wonder if Microsoft actually likes running their free email service still. They wiped a ton of old Hotmail and Live.com emails some years ago (and then allowed new people to register those deleted names). I imagine they don't get much out of it anymore.
mmsc··on Technical Excellence Is Not Enough
That's because it was generated by an LLM.
mmsc··on Firefox 148 Launches with AI Kill Switch Feature and More Enhancements
Try disabling widget.macos.native-context-menus
mmsc··on Georgian wine culture dates back, uninterrupted, approximately 8k years
Yes, that's why it's great. They have the best of everything around and have imo perfected it. It's difficult to think of certain foods that are actually unique to any "country", tbh.
mmsc··on Firefox 148 Launches with AI Kill Switch Feature and More Enhancements
Thanks! I didn't know that.

I think that's a good workaround, but I'll have to re-enable it when I actually need to print something.

mmsc··on Firefox 148 Launches with AI Kill Switch Feature and More Enhancements
I'm also missing:

  dom.text-recognition.enabled
  browser.search.visualSearch.featureGate
  extensions.formautofill.addresses.enabled
  extensions.formautofill.creditCards.enabled
  widget.macos.native-context-menus
The last one removes the "Services" option when right-clicking an image or highlighted text.
mmsc··on Firefox 148 Launches with AI Kill Switch Feature and More Enhancements
`dom.text_fragments.enabled` to remove "Copy link to highlight" on right-click. Yes, it can be useful, but I never use it and the very rare occasion of needing to use it when opening a page, I can just search it myself.

`privacy.query_stripping.strip_on_share.enabled` to remove "Copy clean link". I would rather it just did that clean link thing automatically, but I don't actually care about clean links -- it's just annoying having two "copy link" next to each other (especially with one which is greyed out 99% of the time!)

mmsc··on Firefox 148 Launches with AI Kill Switch Feature and More Enhancements
In addition to completely disabling AI, I found the following setting extremely convinent to disable in about:config. They clutter up my right-click on a link or on text selection.

  browser.translations.select.enable
  dom.text_fragments.enabled
  privacy.query_stripping.strip_on_share.enabled
  devtools.accessibility.enabled
Now if only I could get rid of "Print selection" and "Services" when right-clicking, too (on MacOS)
mmsc··on Writing code is cheap now
Spaghetti code was always a thing though
mmsc··on Carelessness versus craftsmanship in cryptography
This argument doesn't hold because paid cryptography libraries aren't any better and equally provide their code as-is.
mmsc··on Instagram's URL Blackhole
Instagram blocks me from sending Facebook.com in DMs to people. No idea why and support doesn't help.
mmsc··on Green’s Dictionary of Slang - Five hundred years of the vulgar tongue
Orwell's Down and Out in Paris and London documented some of the swear words of his time [0].

It's interesting reading them as a native speaker, as there's so few that I could even begin to guess what they mean.

[0]: https://www.telelib.com/authors/O/OrwellGeorge/prose/Downand...

mmsc··on Upcoming changes to Let's Encrypt and how they affect XMPP server operators
No. HTTPS certificates are being abused for non-https purposes. CAs want to sell certificates for everything under the sun, and want to force those in the ecosystem to support their business, even though https certificates are not designed to be used for other things (mail servers for example).

If CAs don't want hostility from browser companies for using https certificate for non-http/browser applications, they should build their own thing.

mmsc··on Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM
Suing for negligence and friends is how car companies -- when it is found out they've built something highly unsafe/dangerously broken -- happens. I don't see the difference.
mmsc··on Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM
Yes. These companies should be shut down in the name of national security, seriously.
← PreviousPage 2 of 13Next →