HNHacker News
TopNewBestAskShowJobs

plausibility

99 karma · joined June 9, 2013

Contact: chris@gibsonsec.org
submissionscomments
plausibility··on LinkedIn Larpmaxxing
Trolls posting absolute garbage /b/ are at least trying to evoke some feeling in you. Hard to say the same from the ‘I had dinner with my wife on a yacht. Here’s what it taught me about Series A VC relationships’ posting full of Claudisms and emojis.

Who’s the target audience for that?

plausibility··on Kids turned low-traffic NPR Spotify comments into a secret group chat
When I had my computer mouse taken away because I got in school suspension (for getting domain admin in the local AD no less), I promptly learned how mouse control via keyboard worked.

Feels like a rite of passage.

plausibility··on Reverse engineering my e-scooter and rewriting the firmware in Rust
I've been surprised how much Astra prefers to go off script to "find the answer" than Sol was unprompted.

I've been doing some PCB design lately, and I was working up the firmware with Codex and asked about how to handle a specific part of my SPI setup. The firmware and KiCad hardware are in different folders/repos so none of it was in-context, but Astra just decided to `find` the folder nearby, then read the KiCad net lists by directly invoking the KiCad CLI on the .kicad_sch/.kicad_pcb files it found. Topped it off by reading the Espressif code vendored in my PlatformIO install to make sure everything would work.

plausibility··on Introducing Ad Blocker for Firefox on iOS
To be fair, Firefox on iOS is also WebKit based thanks to Apples’s rules. Much of a muchness in this aspect.
plausibility··on Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
Presumably it’s just because the GitHub markdown engine doesn’t block HTML comments in issues. It’s useful in README files if you’ve got funky tables and need to explain what to change to any contributors.

Seems like they might want to do something about that just for comments.

plausibility··on Advertise in ChatGPT
I’ve been wondering for a while if these ludicrously high numbers are just MAU and count people running 16 free accounts load balanced for more access without paying.

No way 1/7 people globally use ChatGPT?

plausibility··on EFF to 4th Circuit: Electronic Device Searches at the Border Require a Warrant
The rebrand here is because for something to be porn, the person in it has to be able to consent. Children can’t consent, thus it’s material showing sexual abuse.

I think this new name is generally accepted at wide and will stick around in perpetuity from now on.

plausibility··on Mythical Man Month
I feel like that’s tied to the hardware the companies are using. All the banks I’ve worked at run z/OS mainframes, can they even deploy modern run of the mill Go/Python/Rust code or is getting off COBOL reliant on hardware changes?
plausibility··on The reporters at this news site are AI bots. OpenAI appears to be funding it
I think a lot of these simpler bots are simply karma farming to sell at a later date for astroturfing. If you want to shit stir politics on an election year, it’s easier to get past the AutoModerator gates if you’ve got a 5 year old account with a benign history and a few thousand comment karma.
plausibility··on Android’s new sideload settings will carry over to new devices
If I was a hostile phone OS designer, I would make it use the time reference given by nearby cell networks, GPS, or an RTC in the motherboard rather than the local clock. That’s closer to ‘true’ time if you want to make sure a day has actually passed.
plausibility··on Meow.camera
If you have a premium Shodan[0] account, they have an ‘Images’ view which is filtered VNC and other Remote Desktop screenshots and links to view them directly with the IP. Lots of security cameras, some SCADA industrial access control screens, and lately seemingly people who I guess are hacking vulnerable Windows boxes and changing the wallpapers to anti Israel stuff.

[0]: https://shodan.io

plausibility··on New accounts on HN more likely to use em-dashes
When you’re trying to type a URL there’s a period next to the space bar where your right thumb usually hits space, but if you’re just texting iOS won’t show that. That’s my theory, just muscle memory.
plausibility··on New accounts on HN more likely to use em-dashes
The thing they’re describing is people hand holding lapel mics right up to their mouth, rather than clipping them to their lapel or shirt or anything (where I assume they’re designed to go still). Seems more ‘indie filmmaker’ where actually clipping it on seems too polished, and why would you trust someone who’s from Big Lapel Mic on TikTok.

This lead to other people clipping them onto random objects to make fun of the trend for a while.

plausibility··on Tech Independence
At the lower or easier end, there’s your standard containerisation tools like Docker Compose or the Podman equivalents. Just move your compose files and zip the mount folders and you can move stuff easily enough.

Middle ground you’ve got stuff like Ansible for if you want to install things without containers, but still want it to be scripted. I don’t use these much since they feel like the worst of both worlds.

Higher end in terms of effort is using something like NixOS, where you get basically Terraform for everything in your distro.

plausibility··on Anthropic: Developing a Claude Code competitor using Claude Code is banned
It’s pretty much table stakes to block or restrict or just investigate more closely if requests come from an IP address in a data centre provider or VPN provider ASN though.

I worked at a cloud company a while ago, and if free tier user requests came from another cloud providers IPs we’d have to double check it wasn’t fraud since that happened more often than residential ranges.

plausibility··on US Judge invalidates blood glucose sensor patent, opens door for Apple Watch
My understanding is it's like iPhone purchased in Japan always having the shutter noise no matter where they're taking a picture.

Apple Watches purchased and activated in USA after the patent lawsuit cut off date won't have the feature enabled, even if you travel or move.

plausibility··on I Don't Have Spotify
This is kind of the confusion I mean. Sometimes YouTube Music has audio tracks that you are seemingly different to the "X Artist - Topic" videos you can find on YouTube proper. I'll have to revisit this again to see if it's all the same now, because the last time I was looking into it a few years ago not everything I had organised in playlists on YTM was available via regular YouTube playlists I could rip with yt-dlp.
plausibility··on I Don't Have Spotify
Tidal has lots of downloader clients you can install due to its often technical but niche user base. May I suggest Tidal-Media-Downloader[0]?

Now if only there was a way to download things from YouTube Music with a Premium subscription. It's practically impossible to search for "YouTube Music download" without falling into the 'youtube-dl YouTube mp3 audio tracks!' SEO hole. Vague naming on Google's part.

[0]: https://github.com/yaronzz/Tidal-Media-Downloader

plausibility··on Ask HN: Life-changing purchases since 2020? (Under $100 and under $1000)
The English language version of that saying rhymes better I think: > Buy once, cry once.

I used to have a large Honeywell air purifier I special ordered to Australia that required a step down voltage transformer, it's really surprising how much better the air feels when it's truly clean.

plausibility··on Ask HN: Life-changing purchases since 2020? (Under $100 and under $1000)
The usual problem with toothbrush bristles is they become microscopically worn down, so they don't scrape off plaque as effectively. Even if you can't see the problem, it might not be working as well as a fresh head will.

You can find electron microscope scans of fresh toothbrushes and worn ones in this[0] Applied Science YouTube video.

[0]: https://youtu.be/cwN983PnJoA

plausibility··on Ask HN: Google Ads Rejected My SaaS as Compromised Site
There was something similar shown here on HN a few months back (but for current Googlers) [0]. Apparently this counts as commercial bribery. I guess ex Google Ads folk giving their market expertise to another company as an SEO Consultant might not be a problem, unless somehow they're breaking an NDA about divulging company secrets or special sauce?

[0] https://news.ycombinator.com/item?id=40431126 "Show HN: Pls Fix – Hire big tech employees to appeal account suspensions (plsfix.co)"

plausibility··on Google loses antitrust suit over search deals on phones
Look no further for evidence than New Zealand. There are two major grocery store chains (Foodstuffs, who own New World, Four Square, and Pak n Save) and Woolworths Group -- obviously we have the smaller Asian marts and produce stores too, but most people only have one of the big stores nearby to their towns.

There are two major building materials suppliers (Carters and Fletchers). There's one manufacturer of drywall (Gib) that is easier to get council plan approval for than any other cheaper manufacturers of drywall because they provide some material strength documents that saves the councils some engineering review time and effort.

We technically have 4 major banks, but 3 of them are just offshoots of big Australian banks and siphon the insane profits offshore.

The government keeps making investigation commissions into breaking these up, but doesn't do anything. The companies just point fingers back and forth at each other blaming "the competition" for price gouging. Meanwhile the recommendation from the politicians is we cut back on avocado toast, lattes, and our Netflix subscription.

plausibility··on Open source AI is the path forward
It is more common when it comes to numbers I guess. There are ~5 ancestors in this comment chain, if I would agree roughly 4-6 is acceptable.
plausibility··on Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain
Huh, that was a pretty quick turn around for Apple, glad to know.

Now if only they'd stop trying to get me to enable iCloud Drive just because I use an iPhone for work.

plausibility··on Updating from macOS Ventura to Sonoma Silently Enables iCloud Keychain
One thing I learned from using Little Snitch is that a lot of Apple apps are seemingly immune from these types of firewalls, due to Apple shenanigans around k-ext signing etc [0].

Ref also [1]: > In Big Sur Apple decided to exempt many of its apps from being routed thru the frameworks they now require 3rd-party firewalls to use (LuLu, Little Snitch, etc.) > Q: Could this be (ab)used by malware to also bypass such firewalls? > A: Apparently yes, and trivially so

[0] https://x.com/patrickwardle/status/1318437929497235457 [1] https://x.com/patrickwardle/status/1327726496203476992

plausibility··on Peter Jackson on how Tolkien stopped a Beatles LOTR film (2021)
I think it's just because he had no illusions as to the good and bad uses it would bring. I've used Palantir Foundry heavily at work, and it is good for remotely viewing events and communicating mind-to-mind to executives with pretty dashboards. Definitely nicer optics than their Gotham platform used by USA law enforcement since e.g. it helps Airbus identify issues on their plane fleets before they occur.

Plus from talking to the Palantir engineers, the CEO and Thiel are both weirdo nerds, so it's fitting.

plausibility··on Tell HN: Your Android carrier can remotely turn settings on
The WiFi spec has something called "active scanning" [0] for clients (as opposed to passive scanning, where the client listens for the periodic AP beacons). There's something called a "directed probe request" [1] that a client can send during active scanning which will contain the AP's SSID it's directed towards. Whether or not your particular device sends these direct probe requests is probably configurable and different per client. According to this [2] post, Android devices will sometimes send SSIDs in a scan, but not all of them and not always. Might be possible to find the logic here in the Android source code, I assume it's there somewhere.

[0]: https://www.wi-fi.org/knowledge-center/faq/what-are-passive-... [1]: https://dot11ap.wordpress.com/active-scanning-probes/ [2]: https://stackoverflow.com/questions/36264440/phone-doesnt-se...

plausibility··on The Framework Laptop Is Great for a Linux-Friendly, Upgradeable/Modular Laptop
Something I've noticed a lot with tech products is that they "cost the same" (in number value) in USD as well as Euros or GBP, which actually makes them cheaper in the US. Take for example, the Awair Element air quality meter:

- Ordering in the US: USD$299[0] (~£224) - Ordering in the UK: GBP£299[1] (~$360 USD at the time of writing)

Even including 20% VAT in UK it should only cost around £270 by my calculations. Is shipping really that expensive? I find similar issues buying things online in Australia (and that's before expensive shipping, duty, import GST, etc.)

[0]: https://store.getawair.com/products/awair-element [1]: https://ukstore.getawair.com/products/awair-element

plausibility··on Reverse Engineering Snapchat: Obfuscation Techniques
I did some more searching, and I think it was Hacktech then. According to [0], Evan dropped by because of the project by Ash Bhat and Ankit Ranjan, apparently some of the organisers called him since he lived nearby. Seems you were right.

[0] http://appstorechronicle.com/2014/01/exclusive-snapchat-hack...

plausibility··on Reverse Engineering Snapchat: Obfuscation Techniques
Was this perhaps LA Hacks [0] in 2014, or Hacktech [1]? Evan Spiegel attended LA Hacks, but I had someone who was attending Hacktech email me for help with the Snapchat API for their project. (I was part of Gibson Security, and published some early Snapchat API research [2] online in 2013)

[0] https://en.wikipedia.org/wiki/LA_Hacks

[1] https://medium.com/hacktech-2014/everyones-watching-hacktech...

[2] https://gibsonsec.org/snapchat/fulldisclosure/

Page 1 of 2Next →