HNHacker News
TopNewBestAskShowJobs

rtev

291 karma · joined June 29, 2022

submissionscomments
rtev··on CrowdStrike Update: Windows Bluescreen and Boot Loops
Solarwinds is still dealing with the reputation damage and fallout today from that breach. People don’t forget about this stuff. the lawsuits will likely be hitting crowdstrike for years to come
rtev··on SAPwned: SAP AI vulnerabilities expose customers' cloud environments and privat
About to be acquired by Google for $23 billion as well!
rtev··on Hacker Tool Extracts All the Data Collected by Windows' New Recall AI
It’s supposedly only accessible to LocalSystem. If they were to encrypt it, it could just be decrypted anyway. Still, it’s a huge liability and a major blunder by Microsoft.
rtev··on Hacking millions of modems and investigating who hacked my modem
Sam is a very famous security researcher, so I would be shocked if he wasn’t making upwards of $350,000 a year. These articles he writes make him a significant amount of money via reputation boost.
rtev··on Home buyers need 80% more income to buy than 4 years ago
This appears to be what happens when rich people that don’t need houses buy them anyway as investments. There should be laws preventing a person from owning more than three houses in the United States.
rtev··on Kagi Changelog 2/13: Faster and more accurate instant answers and Wikipedia page
Yahoo returns thousands of results for dorking queries where Kagi and Google return an identical list of 5-6 results. Pretty disappointing for me as a paying customer to learn that Kagi is basically a Google wrapper
rtev··on Homemade Pasta. Now Is the Time (2021)
Anyone know why this is happening?

error: subprocess-exited-with-error python3 setup.py egg_info did not run successfully.

rtev··on Security researchers collect awards for Tesla exploits at Pwn2Own Automotive
A vendor pays to have their software included in this competition, where many of the world’s best offensive security pros compete.
rtev··on SEC.gov – approval of 11 Bitcoin spot ETF [pdf]
Looks like the “hack” on Twitter was just a botched rollout as suspected?
rtev··on Apple Shuts Down Flipper Zero's Ability to Shut Down iPhones
Weeks after defcon, I saw they had a job listing asking for someone with Bluetooth experience and experience preventing denial of service attacks. Sounds like they finally hired someone that knew what was going on here.
rtev··on Q-Transformer
Lucidrains also created the much-missed EpicMafia, which still doesn’t have a good replacement after shutting down. Exceptionally skilled person!
rtev··on Common pesticides in food reducing sperm count worldwide, study says
This is the most sus thing I’ve read in a long time
rtev··on The urgent need for memory safety in software products
i don’t feel that this is true in the slightest.

so many critical exploits use the same characters and lengths as intended inputs. Also, if firewalls were a replacement for secure code, no one would be talking about memory safety.

rtev··on Gitlab Critical Security Release: 16.3.4 and 16.2.7
I don’t think it is.

Microsoft has a track record for delaying fixes and marking important issues as “not a bug”, so I’m less impressed with their security.

As terrible a corporation as Oracle is, their security response team has been one of the most effective and fast-paced I’ve ever reported to. With that said, they pay nothing to researchers, so Gitlab certainly shows they care more about security.

rtev··on Gitlab Critical Security Release: 16.3.4 and 16.2.7
The reason you see so many critical Gitlab security fixes is because they take security so seriously.

They pay huge bounties for security vulnerabilities in their products, so they get the best researchers responsibly disclosing bugs.

rtev··on CWE Top Most Dangerous Software Weaknesses
Typescript applications suffer from many of these vulnerabilities. JS apps have a specific class of critical vulnerabilities as well, prototype pollution. If I had to write a web application with security in mind, I personally would pick Python. It’s possible to make mistakes in any language though, and the environment an app is deployed in can independently introduce many vulnerabilities.
rtev··on Excess weight, obesity more deadly than previously believed
It’s very weird that out of 95 comments in this thread (at the time of writing), practically half of them are one person.
rtev··on 1Password Park – St. Thomas Ontario
LastPark has child predators under the bridge that the park officials haven’t noticed yet
rtev··on Amazon funds seaweed farming at offshore wind farm to test CO2 capture
I should have added “/s”
rtev··on Amazon funds seaweed farming at offshore wind farm to test CO2 capture
This is all just a scam run by Big Cow to get some tasty Asian flavors in the trough.
rtev··on Google Ran Out of Ideas
While I generally agree with this, it totally misses the mark by leaving out Chrome. As long as Chrome dominates the web, Google stays on top
rtev··on AI-powered Bing Chat spills its secrets via prompt injection attack
I have yet to hear a convincing threat model for this actually representing a vulnerability. I don’t think there is one.
rtev··on Orion Browser
Tavis Ormandy is one of the leading security experts in the world. Here’s a blog post that highlights a number of the risks related to password manager extensions: https://lock.cmpxchg8b.com/passmgrs.html
rtev··on The flight tracker that powered ElonJet has taken a left turn
Taking it down doesn’t make flight tracking infeasible, just moderately less accessible. Any sufficiently motivated attacker is going to be able to get the information without a problem. Isn’t it better to have the information more public to increase awareness?

I’ve also really enjoyed seeing how much negativity these peoples’ wasteful habits receive. That’s just me personally though.

rtev··on Orion Browser
Much of the risk associated with password managers is only applicable when using the browser extensions. I know it’s a minor inconvenience, but I would advise sticking with the lack of extension.
rtev··on Fun with Gentoo: Why don't we just shuffle those ROP gadgets away?
Very cool, thank you for sharing! Not only does ROP facilitate traditional binary exploitation, but it’s also used in cutting-edge evasive techniques. By abusing ROP instead of direct calls, red teamers are able to heavily obfuscate activities from endpoint detection and response.
rtev··on Ask HN: Where are all the parties?
Sounds like you’ve landed on the wrong path of the last of Erikson’s stages.
rtev··on OpenAI used Kenyan workers on less than $2 per hour to make ChatGPT less toxic
Did you read the article?
rtev··on Among many U.S. children, reading for fun has become less common
Reading quickly with deep comprehension is a superpower. Arts and culture of reading aside, kids that don’t read much limit themselves in the pace they can learn and advance.
rtev··on Show HN: Otterkit – COBOL compiler for .NET
This is awesome.
Page 1 of 6Next →