HNHacker News
TopNewBestAskShowJobs

mmsc

3,253 karma · joined May 22, 2021

https://joshua.hu/about

https://www.linkedin.com/in/joshua-alexander-rogers/

https://github.com/megamansec

Security, hacking, travel, lulz, vodka.

submissionscomments
mmsc··on After millions of years, why are carnivorous plants still so small?
One day it'll The Day of the Triffids
mmsc··on It's the end of observability as we know it (and I feel fine)
>If I pay someone a salary, they need to understand the actually answer the give me. And their butt needs to be on the line if the answer is wrong.

What's that got to do with AI exactly? Sure, there's the chance that this AI thing will disappear tomorrow and they won't be able to do anything, but so too is the chance the stackoverflow disappears

mmsc··on OpenAI o3-pro
I understand that things are moving fast and all, but surely the.. 8? models which are currently available is a bit .. overwhelming for users that just want to get answers to their questions of life? What's the end goal with having so many models available?
mmsc··on Bruteforcing the phone number of any Google user
Depends on the company. Also It can be a good way to say to management, "look, this old deprecated shit needs to be replaced because it's insecure; maintenance is a security issue"
mmsc··on Show HN: Most users won't report bugs unless you make it stupidly easy
>for your users doing _free_ software testing for you!

In comparison to _paid_ software testing, which doesn't change the point at all: if they were paid to find bugs, they wouldn't be paid for useless and unactionable reports.

>you’re complaining that listening to your users is hard

Sometimes - and I'd wager most of the time - they are, yes, unless your product solely attracts technically competent and advanced users that can attempt to understand/reason about what is causing the issue.

mmsc··on Show HN: Most users won't report bugs unless you make it stupidly easy
The difficulty in reporting a bug comes from the friction required to filter the "page doesn't work" with no further explanation reports, or the "my neighbour is a spy for the government and I have proof" reports (real types of reports for a browser company, for example, which surely exist for other places users think that "is" the internet like Facebook).

I agree that reporting bugs can be hard, but the amount of spam that follows an effective open form, of craziness to uselessness, outweighs the useful bug reports.

Having two types of reports: one which is a simple screenshot taker with the ability to draw a circle over what is wrong, and one which is a more detailed report, would be useful.

Some LLM that filters out what is a useless report be a useful report would be good, too.

mmsc··on What happens when people don't understand how AI works
This can be generalized to "what happens when people don't understand how something works". In the computing world, that could be "undefined behavior" (of which itself is .. defined as undefined) in the C programming language, or anything as simple as "functionality people didn't know because they didn't read the documentation"
mmsc··on Dystopian tales of that time when I sold out to Google
>the true purpose of crypto

What's the latest version of this one these days?

mmsc··on Beating Google's kernelCTF PoW using AVX512
Amazing stuff, but also reads like a comedy due to the obstacles to win this challenge. Real rube goldberg stuff.
mmsc··on Beating Google's kernelCTF PoW using AVX512
b-b-but, my linux distribution is perfect for multi-tenant/multi-user purposes!!
mmsc··on The flip phone web: browsing with the original Opera Mini
I don't think anybody will build a browser over the "released" source code either, if it was officially opensourced by Opera. There were some people from CIS countries doing something with that leaked code, not sure if they still provide updates for it though. There's also https://github.com/PrestoXen/openopera-patches

fd: i used to work for the big O

mmsc··on The flip phone web: browsing with the original Opera Mini
Presto source code was leaked years ago.
mmsc··on Show HN: Sshsync – CLI tool to run shell commands across multiple remote servers
are there any linux distributions which don't require python installed, other than embedded?
mmsc··on Updated rate limits for unauthenticated requests
Even with authenticated requests, viewing a pull request and adding `.diff` to the end of the URL is currently ratelimited at 1 request per minute. Incredibly low, IMO.
mmsc··on Multiple security issues in GNU Screen
Seems like a prime target for Jia Tan.
mmsc··on Multiple Security Issues in GNU Screen
TFA says upstream asked for the review.
mmsc··on Multiple security issues in GNU Screen
It's surprising that upstream was involved in this. Around 5 years ago, I came to the (sad) conclusion that GNU screen development had completely halted. Is that still not the case?

Does screen have the functionality to add a new window to an existing screen without attaching to the screen yet?

mmsc··on How are cyber criminals rolling in 2025?
They're usually designed so only Google sees it. It's for SEO, not to trick people.
mmsc··on All four major web browsers are about to lose 80% of their funding
This is literally some browsers' solution. They have an internal domain list and use the chrome UA for those
mmsc··on Hyperscaling Have I Been Pwned with Cloudflare Workers and Caching
So have most websites in the world. I recently found out report-uri.com uses Cloudflare turnstile which specifically blocks the type of activity that I imagine one would actually want from a CSP-violation.

I like to write about these cases in my spare time, e.g.https://joshua.hu/losing-sight-vision-mission-of-your-role-p... and https://joshua.hu/losing-sight-vision-mission-of-your-role-p.... My all time favorite was when I was in hospital and couldn't connect to my travel insurance company's website because they blocked IP addresses from the country I was in (wasn't cloudflare though, I don't think: https://joshua.hu/losing-sight-vision-mission-of-your-role)

mmsc··on Show HN: Morphik – Open-source RAG that understands PDF images, runs locally
Have you thought about some type of preprocessing to make the PDFs "simpler"? https://github.com/freedomofpress/dangerzone does something like that in its first stage.
mmsc··on Pope Francis has died
Parent comment is specifically about sexual identity and so on so I'm not sure what superstitious groups has to do with that.

Also the vast majority of the world believes in superstitious things so again the argument seems to be "everyone's insane except for me"

mmsc··on Pope Francis has died
If you step back for a second, you are claiming that billions of people are insane.

Taking a singular, highly-specific (in the context of humanity and for the thousands of years that Catholicism has existed) issue and conflating it to insanity or sanity is, perhaps, insane in of itself.

mmsc··on The order of files in /etc/ssh/sshd_config.d/ matters
Except that doesn't tell you what it's doing, that tells you what it _might_ do, if you (re)start the server.

sshd -T reads the configuration file and prints information. It doesn't print what the server's currently-running configuration is: https://joshua.hu/sshd-backdoor-and-configuration-parsing

mmsc··on Utah becomes first US state to ban fluoride in its water
If your water was sourced """naturally""" from a spring with a high fluoride levels, I wonder if you'd call that an additive.
mmsc··on Heavy chatbot usage is correlated with loneliness and reduced socialization
Imagine being schizophrenic (or anything like that) and hearing from Snowden that yes, "they really are always listening", and now you've got chat bots to give instant confirmation of all the other things you think of due to your mental disorder.

It's going to be mental.

mmsc··on Improved ways to operate a rude crawler
These types of satirical posts are great, and its great that they can not only be entertaining but also provide new information (I had never heard of TCP SACK).

P.S: all I have to say to this guy spamming HN at the moment is mentioned in this (great) article: GET over it.

mmsc··on Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos
Paid Github organizations have a policy to block third-party actions. Would be nice if there was a way to allow third-party actions as long as they are referenced by hash, not version.
mmsc··on A 2FA app that tells you when you get `314159` (2024)
>Yup, among the sane! If there are any bastions left, we’re working on eradicating them

The communities of trolls trolling trolls have been replaced by larger communities of nazis training nazis to attack and terrorize. Thank you for eradicating the former, paving way for the latter.

mmsc··on A 2FA app that tells you when you get `314159` (2024)
The amusing thing being that the original source of this is hn, not 4chan [1]. deserves a spot on https://news.ycombinator.com/highlights imo.

[1]: https://news.ycombinator.com/item?id=1012082

← PreviousPage 5 of 13Next →