HNHacker News
TopNewBestAskShowJobs

moviuro

2,339 karma · joined October 9, 2014

I'm a cybersecurity engineer, an Archlinux and FreeBSD user. I write some things you might find not-so-useless at https://try.popho.be ; as well as code on https://gitlab.com/moviuro and https://git.sr.ht/~moviuro

[ my public key: https://keybase.io/moviuro; my proof: https://keybase.io/moviuro/sigs/SORQVrWsris9gTK1VNIxMBB8nbS1pKzIU1UzhKxa2tM ]

PGP 0x2cd96fee343c6799b9ceafad62009a2e0c22d9ab

GIT/CS d++(-) s+: !a C++ UB++L++ P L++ E- W++ N? o? K? w- O? M- V? PS+ PE- Y+ PGP++ t+@ 5? X R tv-- b++ DI D G e+++ h(---) r++ y?

submissionscomments

A Shared Vision of Software Bill of Materials (SBoM) for Cybersecurity [pdf]

cisa.gov·2 pts·moviuro·
0

Remote code execution in CentOS Web Panel – CVE-2025-48703

fenrisk.com·1 pts·moviuro·
0

The Performance Inequality Gap, 2024

infrequently.org·39 pts·moviuro·
14

A data corruption bug in OpenZFS?

despairlabs.com·220 pts·moviuro·
111

Pixel 8 and Pixel 8 Pro

blog.google·25 pts·moviuro·
4

Mashing Enter to bypass [FDE] with TPM, Clevis, dracut and systemd

pulsesecurity.co.nz·3 pts·moviuro·
0

Usable systemd Timers for Mortals

try.popho.be·4 pts·moviuro·
0

Setting Up a Gaslighting DNS

try.popho.be·1 pts·moviuro·
1

“MasquerAds” – Google’s Ad-Words Abused by Threat Actors

labs.guard.io·25 pts·moviuro·
4

A sane SSH(1) key management example

try.popho.be·77 pts·moviuro·
64

(KeepassX) Development Stopped

1 pts·moviuro·
2

I now operate a DoH proxy

try.popho.be·2 pts·moviuro·
0

Security Incident Disclosure (arbitrary code injection and auto-merge)

brew.sh·1 pts·moviuro·
0

Statement on DNS Encryption [pdf]

root-servers.org·80 pts·moviuro·
42

Exfiltrate Files Using the DNS

go350.com·58 pts·moviuro·
21

TikTok for Android 1-Click RCE

medium.com·2 pts·moviuro·
1

Purchasing Power Parity: fair pricing for [a] SaaS product

scastiel.dev·2 pts·moviuro·
0

Microsoft Repo Installed on [Raspbian]

cyberciti.biz·25 pts·moviuro·
7

Vulnerabilities Discovered in Tcl Android TVs

sick.codes·4 pts·moviuro·
0

Attack of the clones: Git clients remote code execution

blog.blazeinfosec.com·1 pts·moviuro·
0

A Practical Introduction to Container Security

cloudberry.engineering·2 pts·moviuro·
0

Using network namespaces to force VPN use on select applications

try.popho.be·2 pts·moviuro·
0

All your SPF are belong to us: Exploring trust [ ] through [ ] SPF Mining

medium.com·1 pts·moviuro·
0

PSD2 was meant to enhance security for users: how PSD2 will only irritate users

try.popho.be·3 pts·moviuro·
0

These Aren’t the Phish You’re Looking For: A Technique for Avoiding Blacklists

medium.com·2 pts·moviuro·
0

DOM XSS in Gmail with a little help from Chrome

opnsec.com·1 pts·moviuro·
0

CVE-2020-0796 – Windows SMBv3 LPE exploit SMBGhost

github.com·2 pts·moviuro·
0

GPG4WIN approved for National, European and NATO-restricted documents (German)

gnupg.com·2 pts·moviuro·
0

Mail is not hard, but it’s horrible (or “securitywashing”)

try.popho.be·1 pts·moviuro·
0

Pacman 5.2 Release (Archlinux)

allanmcrae.com·2 pts·moviuro·
0
Page 1 of 3Next →