HNHacker News
TopNewBestAskShowJobs

mmsc

3,253 karma · joined May 22, 2021

https://joshua.hu/about

https://www.linkedin.com/in/joshua-alexander-rogers/

https://github.com/megamansec

Security, hacking, travel, lulz, vodka.

submissionscomments
mmsc··on Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM
Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.
mmsc··on Notepad++ hijacked by state-sponsored actors
https://interactives.lowyinstitute.org/features/one-china-co...
mmsc··on Notepad++ hijacked by state-sponsored actors
No it's not and if you do believe that, you are taking an overly reductionist viewpoint.

99% countries, as they say, "acknowledge China's viewpoint".

mmsc··on Notepad++ hijacked by state-sponsored actors
If the political messages said "gas the Jews", "exterminate the Ukrainians and give Ukraine to Russia", and "Taiwan has and always will be a province of china", you probably wouldn't use notepad++.
mmsc··on The state of Linux music players in 2026
mocp is all you need
mmsc··on eBay explicitly bans AI "buy for me" agents in user agreement update
https://en.wikipedia.org/wiki/EBay_stalking_scandal
mmsc··on eBay explicitly bans AI "buy for me" agents in user agreement update
Nothing? Don't forget when their security team sent pigs heads to people and terrorized them:)
mmsc··on Cloudflare zero-day: Accessing any host globally
The article was clearly written by an LLM. It would make no sense to use https for a challenge like that, indeed.
mmsc··on We found cryptography bugs in the elliptic library using Wycheproof
(2024).

There are other vulnerabilities in that library too. I reported some (with some PRs) https://github.com/indutny/elliptic/pull/338, https://github.com/indutny/elliptic/pull/337, https://github.com/indutny/elliptic/issues/339 but I assume they'll never get fixed.

The library is dead and should be marked as vulnerable on npmjs tbh.

mmsc··on LLVM AI tool policy: human in the loop
fwiw, the tool is `gixy`, now called `gixy-next`: https://github.com/megamansec/gixy-next
mmsc··on Happy Public Domain Day 2026
Metropolis becoming public domain in 2026 couldn't be more perfect, since the film is set in 2026.

It is eerily similar to our times, too, unfortunately.

mmsc··on LLVM AI tool policy: human in the loop
This AI usage is like a turbo-charger for the Dunning–Kruger effect, and we will see these policies crop up more and more, as technical people become more and more harassed and burnt out by AI slop.

I also recently wrote a similar policy[0] for my fork of a codebase. I had to write this because the original developer took the AI pill, and starting committing totally broken code that was fulled of bugs, and doubled down when asked about it [1].

On an analysis level, I recently commented[2] that "Non-coders using AI to program are effectively non-technical people, equipped with the over-confidence of technical people. Proper training would turn those people into coders that are technical people. Traditional training techniques and material cannot work, as they are targeted and created with technical people in mind."

But what's more, we're also seeing programmers use AI creating slop. They're effectively technical people equipped with their initial over-confidence, highly inflated by a sense of effortless capability. Before AI, developers were once (sometimes) forced to pause, investigate, and understand, and now it's just easier and more natural to simply assume they grasp far more than they actually do, because @grok told them this is true.

[0]: https://gixy.io/contributing/#ai-llm-tooling-usage-policy

[1]: https://joshua.hu/gixy-ng-new-version-gixy-updated-checks#qu...

[2]: https://joshua.hu/ai-slop-story-nginx-leaking-dns-chatgpt#fi...

mmsc··on MongoDB Server Security Update, December 2025
>Memory exfiltration, potentially containing passwords and secrets

and potentially not, too. totally overhyped

mmsc··on MongoDB Server Security Update, December 2025
It wasn't an RCE.
mmsc··on Staying ahead of censors in 2025
Does anybody know what the situation is like in China these days? What's the most commonly used tool for proxying now?

Does basically all network leaving China still get ratelimited at a few megabytes per second?

mmsc··on Hunting for North Korean Fiber Optic Cables
>one for tourists (requires a local SIM card only available in a specific hotel in Pyongyang).

I do not think that exists. I imagine the diplomats and other foreigners living there will have this, though.

When I was there two times (in Pyongyang, and in villages in the north east & Rason) any access to the outside world was prohibited via a network other than telephone (I could make outgoing phone calls via the hotel). Even traveling very close to the border (which they use jammers to block outside connections), my guides were annoyed when they saw I was trying to connect to the Chinese network from my phone.

The only place I saw any access "to the outside world" was in Rason (https://en.wikipedia.org/wiki/Rason_Special_Economic_Zone), where one of the casinos had a computer which could be used to access the internet (through the Chinese GFW, of course).

mmsc··on Critical RCE Vulnerabilities in React and Next.js
That was a typo, yeah. It should be

  console.log(config.isAdmin); // true!
mmsc··on Critical RCE Vulnerabilities in React and Next.js
https://archive.md/2025.12.03-165833/https://www.wiz.io/blog...

Mismatched smart quotes are visible in this archive.

mmsc··on Critical RCE Vulnerabilities in React and Next.js
Note however, that proposal does not cover some other types of prototype pollution, such as:

  > let config = {};
  > Object.assign(config, JSON.parse('{"__proto__": {"isAdmin": true}}'));
  console.log({}.isAdmin); // true!
or:

  > console.log({}['constructor'] ? {}['constructor']('THIS MUST NOT BE EXPOSED') :  'pub')
  [String: 'THIS MUST NOT BE EXPOSED']
mmsc··on Critical RCE Vulnerabilities in React and Next.js
It seems like this vulnerability is yet another prototype pollution vulnerability.

There was a TC39 proposal a few years ago [0] that proposed to block the getting/setting of object prototypes using the bracket notation, which would have prevented this vulnerability.

At the moment, every single get/set with a square bracket, which uses untrusted data, needs to do some manual check to see whether variables contain "bad" keys like `__proto__`, `prototype,` `constructor`, and so on. This is incredibly annoying, and doesn't really fix the issue. It's possible also to freeze an object's prototype, but that causes other issues. It's also possible to use Object.create(null), and Object.hasOwn (also known as Object.prototype.hasOwnProperty), but again, this does not scale because it has to be done _every single time_.

Maybe it's time to revisit this from a language perspective, instead of continuous bandaid fixes for this language-specific vulnerability (a similar language-specific vulnerability exists in Python called class pollution, but it's .. extremely uncommon).

[0]: https://github.com/tc39/proposal-symbol-proto

mmsc··on Critical RCE Vulnerabilities in React and Next.js
>> According to Wiz data, 39% of cloud environments have instances vulnerable to CVE-2025-55182 and/or CVE-2025-66478.

> Numbers!

I do not see how such numbers are valuable to people reading this post, as the first indication of the existence of this vulnerability.

mmsc··on Critical RCE Vulnerabilities in React and Next.js
Hackernews' submission guidelines clearly state: "Please submit the original source. If a post reports on something found on another site, submit the latter." [0]

The Wiz post has significantly changed since it was first published (and how it looked when first posted to HN), FYI -- see [1]. When it was published, it was a summary of the React announcement, and was somehow longer than the original and yet provided less useful information than the original.

In any case, the "tell" is the syntactic structure (as Chomsky would say) and certain phrases used in the post.

[0]: https://news.ycombinator.com/newsguidelines.html

[1]: https://web.archive.org/web/20251203162416/https://www.wiz.i...

mmsc··on Critical RCE Vulnerabilities in React and Next.js
These wiz.io blog posts should be banned from HN; AFAICT, they're AI generated. Here's the original post with the details: https://react.dev/blog/2025/12/03/critical-security-vulnerab... - the vulnerability was not found by a Wiz employee at all, and the Wiz article (unlike the react.dev article) does not provide any meaningful technical information.

The important part to know:

- Even if your app does not implement any React Server Function endpoints it may still be vulnerable if your app supports React Server Components.

- The vulnerability is present in versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack

- Some React frameworks and bundlers depended on, had peer dependencies for, or included the vulnerable React packages. The following React frameworks & bundlers are affected: next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk.

mmsc··on Sending DMARC reports is somewhat hazardous
>I assume that putting a 'rua=' into your DMARC record makes it look more legitimate to (some) receiving systems.

Yes, Gmail for example will drop emails from mass-senders that don't implement both SPF and DKIM.

mmsc··on Okta's NextJS-0auth troubles
Keycloak has various vulnerabilities they haven't even responded to after a month of reporting them.
mmsc··on Okta's NextJS-0auth troubles
Same author, even!;)
mmsc··on Okta's NextJS-0auth troubles
Why would the company need to figure it out from commit hashes? It's all public, in public GitHub repositories, with the person's personal GitHub account: https://github.com/auth0/nextjs-auth0/pull/2381
mmsc··on Okta's NextJS-0auth troubles
(op here)

On the one hand, you're right, it is distasteful, I completely agree. On the other hand, GitHub and Google and the public domain internet isn't everybody's CV that they can pick and choose which of their actions are publicised, tailored towards only their successes.

mmsc··on AI Slop vs. OSS Security
>First, the typical AI-powered reporter, especially one just pasting GPT output into a submission form, neither knows enough about the actual codebase being examined nor understands the security implications well enough to provide insight that projects need.

How ironic, considering every time I've reported a complicated issue to a program on HackerOne, the triggers have completely rejected them because they do not understand the complicated codebase that they are triaging for.

Also the curl examples given in TFA completely ignore recent developments, where curl's maintainers welcomed and fixed literally hundred of AI-found bugs: https://www.theregister.com/2025/10/02/curl_project_swamped_...

mmsc··on Eating stinging nettles
There's a restaurant in Sarajevo which specializes in this stuff, called The Singing Nettle. Recommended.
← PreviousPage 3 of 13Next →