HNHacker News
TopNewBestAskShowJobs

morpheuskafka

4,148 karma · joined October 11, 2017

submissionscomments
morpheuskafka··on Cloudflare to cut about 20% of its workforce
I’m sure they don’t know what they are doing or necessarily care, but I’m still curious what the consultants even claim to be looking at to make the list? Job description, git activity, team level profitability, salary, etc?
morpheuskafka··on For Linux kernel vulnerabilities, there is no heads-up to distributions
I thought that was the entire design goal of the Unix model, didn't it originate in the times when hundreds of users logged on to a shared mainframe? There are still public Unix servers like SDF out there. SELinux is just an extra layer so that if someone gets root (ex. due to an exploit in your setuid code or cron jobs etc) it's not game over.
morpheuskafka··on An AI agent deleted our production database. The agent's confession is below
This is kind of a stretch, but especially if there were multiple operations beyond the "volumeDelete", the GraphQL definitely worsens readability here.

For someone reviewing and approving LLM calls or just double-checking before running a script or bash history, it would be a lot more readable if it were compliant with HTTP norms: curl -X DELETE example.com/api/volumes/uuid123 would make it very obvious that something was going to be deleted at the front and then what it is at the end of the command.

morpheuskafka··on Japan implements language proficiency requirements for certain visa applicants
Teaching English is humanities though, not IS, so that doesn't work. (To clarify, teaching at any sort of private company. A K12 school has a dedicated Instructor class that can't be used for anything else.) And translating (which requires proficiency) is IS in some cases I think?
morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
That was my first thought, but is it logical to assume that 5+ unrelated people took their finished tax return URL and linked it on a website/tweet/etc? Who would do that?

Even still, Fiverr could very well have GDPR/CCPA/etc liability as the host of these files, because they related to its services, it's not just a generic file host.

morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
Company is now telling media this is intended behavior and users knew these files were public / shared the URLs themselves. We need to get some media with wider scope to challenge that.
morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
The company put out its first statement:

> “Fiverr does not proactively expose users’ private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers. This type of content requires the buyer’s explicit consent before it can be uploaded. As always, any request to remove content is handled promptly by our team."

https://sqmagazine.co.uk/fiverr-security-flaw-private-docume...

It sounds like they are trying to claim the users involved published the links and that's why they are on Google? But how could anyone believe that multiple users intentionally published their SSN?

Re the takedown, I'm also guessing it's from Cloudinary. Maybe HTTP Referrer based?

morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
Interesting. Did the URL scheme change with any expiry or signature params (like S3s X-Amz-Expires)?
morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
Files are now returning 404s as of right now, 0900 UTC 4/15.

Would be interesting if someone with an account can check if they are visible to intended users or not, and if so, if their mitigation is robust (signed URLs?).

morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
Huh? I didn't ask for any money here or in the original email. (not that I couldn't use some, as I only have $1000 and four heavy suitcases right now, but anyway...)

I did include "bug bounty" in the email subject since they claimed to have a private program. Other than that, no mention of any kind of compensation. It probably doesn't even have any kind of resume value since it's not an actual code flaw/CVE, just an "unlocked door."

morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
The ironic thing is, since they clearly don't have much code review, they could have actually patched the site in this time! Turn on signatures and throw in a couple backend lines to generate one wherever the URLs appear. Even if you have to go back and redo it tomorrow for robust security or performance, it would be an improvement over this.

I'm not taking sides either way, but if you are of the all in on AI perspective as they are, shouldn't this be the ideal use case? It absolutely could have handled adding URL signing.

morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
At my last job, I opened up Shodan in my free time and clicked through our ASN with the free filters. In two minutes I found multiple iDRACs online. Surprisingly, none had default pw. But one had a public exploit vuln that was years old allowing takeover...

Turns out during the firewall hardware migration years ago, several units firewalls were switched to audit mode (not enforcing rules). So an entire institute (health research!) had their whole subnet public with zero firewalls, both the server OS and iDRAC interfaces. iDRAC isn't even supposed to be on the same VLAN per Dell let alone on the internet.

To top it off, after making some tickets (admittedly not all as serious, ex MFP web UIs on internet) from Shodan, I got pushback from the firewall team for causing units to submit to many changes.

I also got in trouble with our Qualys analyst for undermining his work because he hadn't gotten to that units annual review yet, even though I didn't even have a Qualys login. (And even if I had found it there, since when do we wait for annual reviews to fix that?)

It took at least three weeks internally to get it fixed, and by that I mean only the iDRAC IP blocked with the server itself still wide open.

And that's only because I mentioned it to my manager (awesome guy and not formally responsible for firewall rules) after an unrelated no firewall host incident came through and he authorized an emergency rule.

morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
One founder of Fiverr's LinkedIn photo is in a racecar and posted about supply chain security a week ago.

The other also runs an insurance company (Lemonade) and just posted his drink to celebrate their 1B customers.

I never used their platform but tried a couple jobs on Upwork and drove Uber for 1000 trips. It is absolutely enraging how the CEO class lives day to day like they are some sort of "visionary" for taking a cut of other people's work while taking zero responsibility for even their own app's quality.

At one point the Uber app still told you to call a phone number for some support paths that had a recording telling you to use the app instead. Companies have systematically cut any kind of support, testing, and apparently security.

This also ties in nicely with the Delve debacle about how perfunctory those security certifications are.

morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
I've never tried their platform, but I once made an account on Upwork and it is absolutely ridiculous. I'm sure they are very similar.

People are asking for AWS help and giving root passwords to random contractors. A lot of people asking for CPA letters for loans and help with tax problems but their budget is under $100. And outright fraud posts are often seen asking for people to open bank accounts or otherwise bypass KYC.

Upwork now has an AI feature to help write job posts, so all the time you can see things like "If you want to attract freelancers like X, I can change it." So now the job posts are all written like corporate ones talking about "highly experienced in X" but pay almost nothing. Half the time the clients don't even know the words in their own post. And it charges every time someone applies to a job and then more to boost to top of list because every job gets 30+ applications supposedly.

morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
@janoelze -- that was my thought too, though less so that they wouldn't share a claim of not being notified at all with a third party, but more that those kind of things need to go through legal/comms/etc not whoever runs the security mailbox. if the person running the email box is not the CISO, surely they at least need the CISOs approval to say something beyond a thank you or followup questions? (and if they are the CISO, then they have bigger things to worry about then replying...)
morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
I have uploaded the email here: https://gist.github.com/aidanbh/3da7cecb3e2496e5c5110b88f21b...

(technically, I guess that doesn't prove anything other than it is in my Sent folder? it has a message ID but I guess only the purelymail admin could confirm that)

In any event, this should never have required an outside reminder. The indexing issue may be something non obvious. But the core decision not to use signed/expiring URLs is nothing less than good old security by obscurity.

morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
They may be part of it, but as a publicly traded company, there's got to be a at least a few people there with a fancy pedigree (not that that actually means they are good at their job or care). But if such a test existed, they presumably would have passed it.

They also have an ISO 27001 certificate (they try to claim a bunch of AWSs certs by proxy on their security page, which is ironic as they say AWS stores most of their data while apparently all uploads are on this).

morpheuskafka··on Tell HN: Fiverr left customer files public and searchable
They probably wouldn't act immediately as there's no way for them to enable signing without breaking their client's site. The only cleanup you could do without that would be having google pull that subdomain I guess?

(Fiverr itself uses Bugcrowd but is private, having to first email their SOC as I did.)

morpheuskafka··on Backblaze has stopped backing up OneDrive and Dropbox folders and maybe others
Everyone is acting like this is obviously wrong, and they clearly should have communicated the change and made it visible in the exclusion settings.

However, there is a very good reason for not backing up what is in effect network attached storage. Particularly for OneDrive, as it often adds company SharePoint sites you open files from as mountpoints under your OneDrive folder (business OneDrive is basically a personal Sharepoint site under the hood). Trying to back them up would result in downloading potentially hundreds of gigabytes of files to the desktop only to them reupload them to OneDrive. That would also likely trigger data exfiltration flags at your corporate IT.

A Dropbox/OneDrive/Drive/etc folder is a network mount point by another name. (Many of them are not implemented as FUSE mounts or equivalent OS API, not folders on disk.) It's fundamentally reasonable for software that promises backing up the local disk not to backup whatever network drives you happen to have signed in/mounted.

morpheuskafka··on Can Claude Fly a Plane?
Surely at least part of the issue here is that even an LLM operates in two digit tokens per second, not to mention extra tokens for "thinking/reasoning" mode, while a real autopilot probably has response times in tens of milliseconds. Plus the network latency vs a local LLM.
morpheuskafka··on The End of Eleventy
> Who uses 11ty? NASA, CERN, the TC39 committee, W3C, Google, Microsoft, Mozilla, Apache, freeCodeCamp, to name a few.

> Imagine if Build Awesome actually reached out to people who regularly make static sites. You know, the userbases on NeoCities or MelonLand or 32-bit Cafe?

One minute you are saying large companies use the product, the next that it was always for hobbyists and shouldn't target corporate features?

> In truth, I myself have started a business that has a near identical concept to Build Awesome. Berry House is my independent web studio

> The difference is though that my model is pay-what-you-can, or pro bono. I developed Calgary Groups for a client and charged $5/hour for my dev work.

That is not a business -- no profit motive. (Working less than minimum wage, even.) Not a good benchmark for comparing what an actual business like Font Awesome should do.

morpheuskafka··on Small models also found the vulnerabilities that Mythos found
Everyone is commenting that this doesn't count because they pointed it at the specific files that Mythos already found vulnerable.

But sometimes you do know where vulnerabilities are and still don't know what they are. For example, an update may be released in beta changing the part of the Mac or Windows kernel or some app, but they haven't published the CVE yet. If locally runnable (even with significant compute costs) LLMs can find and exploit it based on either the location of the changed file or the actual diff of the compiled output, we could see exploits before the update ever went to production?

morpheuskafka··on HBO Obtains DMCA Subpoena to Unmask 'Euphoria' Spoiler Account on X
I doubt that. Someone who doesn't like reading wouldn't think of "spoiling a book" as a prank category that comes to mind or understands it to be a serious upset rather than just slightly annoying. Also, they'd likely feel that going to a bookstore and shouting things relating to a book serious is "cringe" or whatever you want to call it, if they aren't the type to even go to a bookstore in the first place.
morpheuskafka··on OpenAI backs Illinois bill that would limit when AI labs can be held liable
> to lazy engineering around known concerns?

That implies that it is already illegal to provide this information. But is it? If a human did so with intent to further a crime, it would be conspiracy. But if you were discussing it without such intent (e.x. red teaming/creating scenarios with someone working in chemistry or law enforcement), it isn't. An AI has no intent when it answers questions, so it is not clear how it could count as conspiracy. Calling it "lazy engineering" implies that there was a duty to prevent that info from being released in the first place.

morpheuskafka··on OpenAI backs Illinois bill that would limit when AI labs can be held liable
> neurotoxic agents from items you can get at most everyday stores

I mean, bleach and ammonia will do that. So I'm not sure that's really much of an accomplishment for AI.

morpheuskafka··on Rescuing old printers with an in-browser Linux VM bridged to WebUSB over USB/IP
Most network printers don't have that much right? I remember seeing a few 256MB sticks in those old copiers that served a whole buildings.
morpheuskafka··on Rescuing old printers with an in-browser Linux VM bridged to WebUSB over USB/IP
If you are using an LLM, wouldn't it have been a lot easier to just have the LLM find the relevant CUPS driver decompile or just capture the USB traffic, and rewrite it in Go or something native? (No need to deal with the system printing framework, the goal was just an app that accepts JPEG input.)
morpheuskafka··on Sam Altman may control our future – can he be trusted?
They are a private company. They have zero obligation to sell anything to any part of the government or military. The only reason they are involved in "public affairs" is because they want to profit from the government. Moreover, long before this DoW controversy, they had plenty of nationalist and anti-China rhetoric in their press releases, more so than the other AI firms.
morpheuskafka··on Gemma 4 on iPhone
It looks like there is some sort of glow effect on the text that isn't rendering right on your browser? It arguably doesn't have the best contrast, but seems to be as intended in Safari 26.3. Looks similar on Chrome macOS too: https://imgur.com/yq5PrKm.
morpheuskafka··on German implementation of eIDAS will require an Apple/Google account to function
What happens if someone is banned from both companies (even for a very legitimate reason such as hosting illegal content -- they still need to access government services)?
← PreviousPage 3 of 34Next →