HNHacker News
TopNewBestAskShowJobs

rurcliped

186 karma · joined April 17, 2018

submissionscomments
rurcliped··on Maybe Flagship Models Shouldn't Be World Class Exploit Writers?
It's needed in general-purpose models because there are billions of persons who can use these models to develop (personally or organizationally) valuable software, and all of these persons deserve the ability to test their software against the best exploit-development resources that exist.

The so-called "safeguards" preventing this, on balance, probably do more harm than good. The best argument in favor of these safeguards is perhaps the temporary one: today, there is simply too much deployed critical software that was developed in a more carefree age. Therefore, one might favor a tradeoff: try to introduce artificial friction against exploit development targeting old software (during the process of patching all of it), with the side effect that new software ends up less resilient than it could have been.

But in the steady state (which may be a very small number of years from now), every practical capability for exploit development should be a routine part of the software creation and maintenance lifecycle.

rurcliped··on Show HN: VibeGuard – security linter for AI-generated code
Love this! Think you haven't pushed CONTRIBUTING.md yet? Anyways, is there data around what met the bar for patterns.py? Like, five instances in different projects got a patterns.py rule, anything less than that usually dropped?
rurcliped··on Curl will not accept vulnerability reports during July 2026
With more advance notice, someone could have found resources to fork curl with different vulnerability management expectations, e.g., "will not accept or otherwise handle any vulnerability reports during the month beginning 21 December 2026. We call it The Winter of Our Discontent."
rurcliped··on Live Nation illegally monopolized ticketing market, jury finds
For many events, the demographics lean toward age groups where people have jobs with work schedules that aren't known more than a few weeks in advance. The initially planned friend group (e.g., four people) can have little overlap with who is actually free on the event date and actually attends. Also, if the event has assigned seating, people buying their own tickets typically has the adverse outcome that you can't sit together.
rurcliped··on Show HN: Report idling vehicles in NYC (and get a cut of the fines) with AI
feature request: AI-based risk analysis, with a model of which types of commercial vehicles at that location are likely to be controlled by organized crime
rurcliped··on United Airlines to launch Starlink wi-fi in spring 2025
To disambiguate, the person on the plane could learn to use hand signals (e.g., Cued Speech) and the AI model can be trained on that.
rurcliped··on Judge dismisses DMCA copyright claim in GitHub Copilot suit
"use, display, and perform Your Content through the GitHub Service" might allow a wide range of uses on GitHub Pages websites, even if https://example.github.io is monetized (monetization is permitted by https://docs.github.com/en/site-policy/github-terms/github-t... in a few cases)
rurcliped··on OpenSSH 9.6
It is discuused here: https://lists.mindrot.org/pipermail/openssh-unix-dev/2023-De... - the HPN-SSH maintainer says "I do have an issue with [the OpenSSH 9.6] release in that it breaks interaction with HPN-SSH. The client seems to be window limited to 2MB sending regardless of what is being advertised by the receiver."
rurcliped··on Ask HN: Name my startup
for "Thats exactly what we will be doing initially! Our tablets taste much better than Bite!" I might go with the brand "habitablets" and the tagline "where self-care meets planet-care"

the idea is that "habitablets" are a type of "tablets" that (when widely adopted to reduce packaging waste and shipping waste) will ultimately make our planet more "habitable"

rurcliped··on $8B Sam Bankman-Fried criminal trial starts today
Suppose you have office space in the jail, and give him (or anyone else) the opportunity to apply for remote jobs at anyplace willing to hire him - with the caveat that he loses office access unless he demonstrates that he's maximizing his potential to earn money, all of which will go directly to compensating victims. (Assume that he can't have Zoom calls with arbitrary colleagues of his choice. He can only have Zoom calls with Bill Lumbergh.)
rurcliped··on Croc: Easily and securely send things from one computer to another
a recent audit claims the author "doesn't have enough resources to address" security issues: https://www.openwall.com/lists/oss-security/2023/09/08/2 https://github.com/schollz/croc/issues/594 etc.
rurcliped··on I am an inspector at a globally significant bank, what should I ask
What data is stored about an employee's justification for viewing a customer account? Is there an enumerated set of justifications such as "direct customer inquiry" versus "to be used for upselling other banking products" versus "IT debugging" etc. or is it free-form text? Is the justification process more complex if the bank knows that the customer is a public figure, celebrity, or maybe anyone who meets Wikipedia'a notability requirements?
rurcliped··on Browsers barely care what HTTP status code your web pages are served with
Years ago, many decisions to hide error details were a cargo cult reaction to CVE-2012-4929. To review, CVE-2012-4929 works like this:

1. the attacker can see (but not decrypt) the victim's TLS traffic to example.com

2. an attacker-controlled website makes the victim send many different invalid requests to example.com, each of which gets an error message

3. some data in each request is attacker-controlled, but authentication data in headers is filled in by the victim's browser

4. example.com compresses response data before encrypting it

5. because repetitions affect compression, the response size is smallest when the authentication data matches part of the attacker-controlled data

6. after enough requests, the attacker knows the authentication data to login to example.com as the victim

One workaround for CVE-2012-4929 was to set up the server so that an error message never depended on the request data. Before CVE-2012-4929 was announced, people thought it was sufficient to sanitize the error message (i.e., avoid XSS) but CVE-2012-4929 prompted a shift toward producing exactly the same error message for all invalid requests. (Not sure, but I think this was the original motivation for Google's famous "That's an error. That's all we know." messages.)

There were better CVE-2012-4929 defenses later, but the cargo cult had already formed. (Some subset of) a generation of developers believed that customized error messages were Very Bad because they enabled account takeover.

rurcliped··on Why is there no open source firmware for laser or inkjet printers? (2019)
Possibly because the firmware could be modified, and not print the required yellow dots or other tracking data:

https://www.eff.org/pages/list-printers-which-do-or-do-not-d...

"Some of the documents that we previously received through FOIA suggested that all major manufacturers of color laser printers entered a secret agreement with governments to ensure that the output of those printers is forensically traceable."

rurcliped··on How can we get more signups for codehooks.io, a new bootstrapped BaaS?
If I were evaluating this, my top four concerns would be:

1. "NoSQL document database with MongoDB-like queries ... powered by the open source database engine RocksDB" doesn't give me enough confidence that my application will work. Some limitations are unstated. For example:

(easy question) MongoDB documents are limited to 16 MB. Facebook's RocksDB Overview says "There is no limit to the size of a key or a value." Your insertOne documentation doesn't state a limit. Is it 16 MB?

(harder question) Your getMany documentation doesn't describe its interaction with the RocksDB "snapshot" concept (one of the big advantages of RocksDB over other NoSQL products). Facebook's Iterator documentation says "If ReadOptions.snapshot is given, the iterator will return data as of the snapshot. If it is nullptr, the iterator will read from an implicit snapshot as of the time the iterator is created. ... be aware that in case an iterator getting stale, it can block resource from being released. So make sure you destroy or refresh them if they are not used after some time, e.g. one second." Does this imply that each call to getMany operates on a unique snapshot? If so, do you plan to add an API in which the user can specify that multiple getMany calls must operate on the same snapshot?

2. The name of a space (e.g., "dev") is part of the URL used by clients. Is this avoidable? It can interfere with migration of applications to codehooks from other platforms.

3. Your story about unanticipated use (or abuse) seems to be 'We've got you covered by creating a price "ceiling", which reduces the price with 90%.' That's good but I would probably also need billing alerts. I would probably also want request rate limits similar to AWS WAF (e.g., 100 requests per IP address in a 5-minute period) without writing my own auth hooks.

4. I didn't find a discussion of runtime secrets (e.g., something like "flyctl secrets").

rurcliped··on We found critical vulnerabilities in Hive Social
At least one other person reported Hive Social vulnerabilities recently: https://twitter.com/zhuowei/status/1597739467645030400
rurcliped··on Ask HN: What are some blog posts that you have enjoyed going through?
https://blog.miki.it/2014/7/8/abusing-jsonp-with-rosetta-fla... (this was somewhat more exciting when Flash still existed)
rurcliped··on Taylor Swift – The Eras Tour onsale explained
I feel that the goal should be providing tickets to the fans who most want to be there. For example, Round 1 would be for fans who feel confident that a Taylor Swift Eras show would be the best event they would ever experience. A fan in Round 1 must agree that they are banned for life from other Ticketmaster purchases, and banned for life from any other attendance at a Ticketmaster contracted venue. In Round 2, maybe a person is only banned for ten years. In Round N, maybe a person is banned from future concerts but can still use Ticketmaster for sporting events, etc. Ticket prices are the same in every round and there's no dynamic pricing or resale: the only difference is the fan's level of ban commitment. However, the more lenient rounds might not occur if tickets are sold out in the stricter rounds.

This does more to "maximize joy" than the other plausible alternatives. For example, Verified Fan can only select fans who have a life situation allowing them to virtually wait in line (stay active on their device) for hours, and are also lucky enough to be selected. A lottery can only select fans who are lucky, regardless of whether they especially care about Taylor Swift or just enjoy concerts in general. An auction can only select fans who have the most money.

If there's no practical way to implement this, I can still write my dystopian novel about the identity verification and tracking measures where, if a Round 1 person actually shows up at the venue, the full force of society ensures that they are banned for life after that one show.

rurcliped··on Athena-OS: An Arch Linux-based distro focused on Cybersecurity
It looks like MIT didn't maintain their 1789164 U.S. trademark registration number for Athena: "computer programs, and instruction manuals sold therewith, which collectively provide a set of integrated network services; namely, user authentication, file service, name service, messaging service, mail service, network management service, and print service ... Cancellation Date ... February 12, 2016"

https://en.wikipedia.org/wiki/Project_Athena

(they do have registration number 1722642 for "Athena ... educational services; namely, courses of instruction at the college and graduate level and research services" but this doesn't look closely related)

rurcliped··on [dead]
The withserve.com homepage refers to the fakercloud.com domain, which seems to host code for Potentially Unwanted Browser Reconfiguration or other unexpected content. It would be better to only use example domains under your company's control, or the example.com domain.
rurcliped··on Ask HN: A webmaster “transfers” thousands of articles to a new host manually
The web developer might be very competent, but choose to use the word "manually" to support a higher cost proposal for the project.
rurcliped··on Can anyone give us honest advice on our app's landing page?
Landing page - the primary problem I had was trying to understand what your product does. The phrase "shared by your Twitter friends" implies that you have introduced a new concept ("friends"), perhaps a group of like-minded individuals who are curating Twitter on behalf of one another. In other words, unless a Tweet is shared by at least one member of my "friend" group, I will NEVER see that Tweet in my email. This is potentially very valuable to consumers who have a limited amount of free time, and only want to read manually vetted content. However, I think your product doesn't actually do that. Instead, your product provides "A summary of your Twitter home timeline" - and that may, in general, include niche topics that are very important to me but not relevant to any of my friends. This is also valuable but has a different audience. Ideally, the landing page would make it clear which of these product variants I'm actually buying.

Other comment - I think https://murmel.social/top violates the Twitter brand guidelines, and the Twitter company will eventually object. Their guidelines specify "credit Twitter by using the our logo" (from the https://about.twitter.com/content/dam/about-twitter/en/brand... page). Every Tweet must include the bird picture. Your https://murmel.social/top page is too easily misinterpreted to mean that some of the content is sourced from Twitter but other content is sourced from elsewhere, because the bird picture appears intermittently.

rurcliped··on Notes on OpenSSL remote memory corruption by Guido Vranken
The post says "the vulnerability has only existed for a week." Many Linux systems don't yet have a 3.0.4 package available, but apparently Homebrew is already installing the affected version:

https://formulae.brew.sh/formula/openssl@3 https://docs.brew.sh/FAQ#why-does-brew-upgrade-formula-or-br...

rurcliped··on Should you use semicolons in JavaScript?
In many environments, "For that reason, I decided to use semicolons" will cause all of your code to be automatically rejected, because https://standardjs.com/rules.html "No semicolons" is enforced at the SCM layer.
rurcliped··on Ask HN: Is it rational to avoid certain software features due to possible bugs?
We don't allow our admins to use Parted to change partition tables on production servers. We feel that this is rational because the documentation explicitly says that it might be buggy: https://www.gnu.org/software/parted/manual/parted.html "GNU Parted was designed to minimize the chance of data loss. For example, it was designed to avoid data loss during interruptions (like power failure) and performs many safety checks. However, there could be bugs in GNU Parted, so you should back up your important files before running Parted."
rurcliped··on RCE over ham radio – Reverse shell via WinAPRS memory corruption bug
With CVEs for ham radio, clearly the next step is to add ATT&CK tactics and techniques. If you compromise a PC that's connected to a ham radio, you might be able to transmit maliciously, or interfere with the radio owner's ability to transmit or receive. But it turns out that ham radio isn't only about communicating with other ham radio people - it's also about using PKI to store details of who you communicated with: https://lotw.arrl.org/lotw-help/developer-pki/

Private key disclosure seems catastrophic because of their scorched-earth security policy https://lotw.arrl.org/lotw-help/certificatesecurity/ where the server admins plan to invalidate all signed data, even if the same data had been sitting on the central server for years before the compromise happened. Yet, the docs don't recommend a password for the private key except on "shared or public computers." The adversary just looks for -----BEGIN PRIVATE KEY----- in a text file in a keys directory (the filename is the call letters).

In other words, although executing cmd.exe is a wonderful accomplishment, there's also the possibility of 1. wait for the PC and radio to be idle, 2. tune the radio to a clear frequency, 3. open the victim's private key file, 4. transmit the private key with Morse code.

rurcliped··on Don't use text pixelation to redact sensitive information
Redaction can be needed for a document, but redaction can also be needed for a video (car's license plate, credit card number, etc.). As far as I know, there's no video editing software that recommends black bars and, for example, the official Adobe documentation at https://helpx.adobe.com/premiere-pro/using/masking-tracking.... seems to recommend their Masking and Mask Tracking features.

Black bars may look very ugly in a video. Still, are video editing products recommending a process that has a high risk of leaking sensitive data? There might be reasons that attacking redaction in a video is harder than attacking redaction in a PDF. However, maybe it's actually easier in some cases, e.g., with several similar frames, the attack could take advantage of averaging across frames.

Unfortunately I don't see anything at https://hackerone.com/adobe that could get someone a bug bounty for researching this.

rurcliped··on A Particularly Sadistic MIT Mystery Hunt Puzzle
The specific URL on mitmh2022.com might not work as intended in all web browsers. To reach the puzzle in question, you may have to click on this link once, press the Public Access button on the resulting page, and then click on the same link a second time. Ultimately the https://www.bookspace.world/puzzle/lists-of-large-integers/s... URL will be shown.
rurcliped··on Ask HN: Which SaaS services expose their API over GraphQL?
Here's one: https://api.developer.monday.com
rurcliped··on Show HN: I'm 15 and building a live quiz app for classrooms: Quickz
another class of security issues that has been seen in other quiz apps is client-side disclosure of questions/answers, e.g., https://mentimeter.canny.io/feature-requests/p/make-sure-que...
Page 1 of 3Next →