HNHacker News
TopNewBestAskShowJobs

mmsc

3,253 karma · joined May 22, 2021

https://joshua.hu/about

https://www.linkedin.com/in/joshua-alexander-rogers/

https://github.com/megamansec

Security, hacking, travel, lulz, vodka.

submissionscomments
mmsc··on The Journey Before main()
It's also possible to pack a whole codebase into "before main()" - or with no main() at all. I was recently experimenting doing this, as well as a whole codebase that only uses main() and calls itself over and over. Good fun: https://joshua.hu/packing-codebase-into-single-function-disr...
mmsc··on Scripts I wrote that I use all the time
If you'd like to print the middle of a file, try out `body`: https://github.com/megamansec/body
mmsc··on Cryptographic Issues in Cloudflare's Circl FourQ Implementation (CVE-2025-8556)
>after having received a lukewarm and laconic response from the HackerOne triage team.

A slight digression but lol, this is my experience with all of the bug bounty platforms. Reporting issues which are actually complicated or require an in depth understanding of technology are brickwalled, because reports of difficult problems are written for .. people who understand difficult problems and difficult technology. The runarounds are not worth the time for people who try to solve difficult problems because they have better things to do.

At least cloudflare has a competent security team that can step in and say "yeah, we can look into this because we actually understand our whole technology". It's sad that to get through to a human on these platforms you have to effectively write two reports: one for the triagers who don't understand the technology at all, and one for the competent people who actually know what they're doing.

mmsc··on Look at how unhinged GPU box art was in the 2000s (2024)
TFA calls it unhinged, I call it creative and exciting. Now all we get is rounded edges, solid colours, and "copies of reality" - boring; if I wanted reality I'd go outside and touch grass.
mmsc··on The RSS feed reader landscape
FYI, it's quite easy to support both Firefox and chrome (both mv2 and mv3, even) in a single extension codebase.
mmsc··on Potential issues in curl found using AI assisted tools
Thank you, it means a lot.
mmsc··on Potential issues in curl found using AI assisted tools
Always fun to wake up (ok; I didn't wake up, I got off a 10 hour flight) to see my work on the front page of hn.

I'll be doing a retrospective in a few weeks when the dust has settled, as well as new tools I've been made aware of.

mmsc··on Supermicro server motherboards can be infected with unremovable malware
> rent a server

> infect it with unremovable backdoor

> stop paying server so company rents server to somebody else

> ????

> profit!

mmsc··on Facebook and Instagram to offer ad-free service in UK for up to £3.99 a month
Use fbpurity
mmsc··on Lesser known mobile adtech domains where data is sent
It'd be nice to have a feature in uBlock origin where you can block certain websites' ip addresses, with a requirement to re-resolve the ip address every few days to ensure the ip hasn't been rotated (blocking unnecessary websites due to the cache).
mmsc··on Using AI to secure AI
Currently living through a great litmus test of competency versus luck by company leaders
mmsc··on U.S. alcohol consumption drops to a 90-year low, new poll finds
I think what will happen in the future is that the people that drink, will be drinking way more; while the people that rarely drink, will more rarely drink.
mmsc··on 301party.com: Intentionally open redirect
Is there a bug bounty? I found an open redirect.
mmsc··on The Garlic Bread Hack
Is this a bot? Three day creation date and the sentence of TFA is

>Last night at a Hacker News meetup, I shared something

mmsc··on OpenAI's ChatGPT Agent casually clicks through "I am not a robot" verification
That's more or less how Project Honey Pot [0] worked for forums, blogs, and elsewhere. Cloudflare spawned from this project, as I remember, and Matthew Prince was the founder.

[0]: https://en.wikipedia.org/wiki/Project_Honey_Pot

mmsc··on Sign in with Google in Chrome
this requires being signed in (obviously), which doesn't help with the limit tracking part of hating these things
mmsc··on Dumb Pipe
https://github.com/samyk/slipstream is the new one
mmsc··on UK: Phone networks down: EE, BT, Three, Vodafone, O2 not working in mass outage
China watching with open eyes.

This will happen the day that they try to take Taiwan, worldwide, in my opinion.

mmsc··on Compression culture is making you stupid and uninteresting
Most people are already uninteresting. They're not trying to be interesting; that simply isn't their goal (nor need it be). Most people follow trends and shudder at the thought or creating trends themselves.

It's always been like that and always will be.

mmsc··on Popular NPM linter packages hijacked via phishing to drop malware
It's impressive nobody else has registered this domain before:

$ whois npnjs.com

[..]

Creation Date: 2025-07-14T07:00:00Z

mmsc··on When root meets immutable: OpenBSD chflags vs. log tampering
Yes! And for macOS, `chflags uappnd .bash_history`
mmsc··on When root meets immutable: OpenBSD chflags vs. log tampering
.bash_history
mmsc··on Malware found in official gravityforms plugin indicating supply chain breach
Popped by AB of Ac1dB1tch3z
mmsc··on Browser extensions turn nearly 1M browsers into website-scraping bots
Indeed, it's not a secret and it's not just extensions and VPNs, but everything you could imagine. Lots of applications that advertise themselves as "ways to make money for your unused internet bandwidth" are available which do this -- openly.

This type of software is bundled into system executables as well - just like the "free antivirus and browser toolbars" of yesterday, these are the new bundled software.

If a company has an "internal network" (lol) that consists of security that can be described as Swiss cheese, then this stuff is a massive gap there.

mmsc··on Being too ambitious is a clever form of self-sabotage
Even if some people are not ready for the day, it cannot always be night.
mmsc··on Incapacitating Google Tag Manager (2022)
Would be nice to have something similar to this for Mixpanel and Amplitude
mmsc··on Robots move Shanghai city block [video]
Yes, it has been common enough, no "robots" required. The Indiana Bell Building is a famous one from a century ago, which gets videos posted about it on social media ever so often.
mmsc··on Don't Read This If You Have a Security Clearance (2023)
It can influence your decision subconsciously or otherwise.
mmsc··on Don't Read This If You Have a Security Clearance (2023)
I'm not sure this is a major surprise. Since it's "leaked", it could be (and most likely is):

1. Missing important context, 2. Missing paragraphs, 3. Be edited or in fact, not real at all.

mmsc··on How malicious AI swarms can threaten democracy
.. AI ... swarms! Like bees! Scary! We should be scared!

Anyways, I'm not sure AI is relevant here. Misinformation is just a form of propaganda which other than allowing the creation of falsehoods quicker, doesn't seem to be any more "threatening" than any other lie.

← PreviousPage 4 of 13Next →