HNHacker News
TopNewBestAskShowJobs

s-mon

62 karma · joined April 29, 2023

submissionscomments
s-mon··on Anthropic acquires Bun
Congratulations to the team. Knowing some of the folks on the Bun team I can not say I am surprised. They are the top 0,001% of engineers, writing code out of love. I’m hugely bullish on Anthropic, this is a great first acquisition.
s-mon··on Hosting a website on a disposable vape
And its faster than Vercel!
s-mon··on Around 6k porn sites start checking ages in UK
Vistors are successfully bypassing age verification by using showing pictures of movie characters or their dog to complete photo age verification.
s-mon··on Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say
Something to understand about the word “leak” is that it implies at some point it was keeping things in. Microsoft security is so underfunded and garbage, it is fundamentally making technology as a whole unsafe.

Example: if Kroger or whatever your supermarket of choice distributed meat that was infected they would get sued to bits. Microsoft distributes thousands of malicious NPM dependencies and underfund the NPM security team - if there is such a thing - resulting in an entire industry of supplychain security companies to exist. No other registry has the issue of malicious packages as badly as NPM since Microsoft acquired Github.

Microsoft just does not know how to handle security, which is why so many security companies exist to fill their gaps. I don’t trust their security practices one bit tbh.

s-mon··on USB-C hubs and my slow descent into madness (2021)
Back at one of my previous employers we had a long internal briefing about why our latest device did not have USB-C when other solutions on the market by then had.

The connector is solid but my god have there been disasters because of USB-C.

1. Power distribution upto high wattage, not always with auto sensing, 2. Wites rated to different data transmission speeds. 3. USB standard data transfers and Thunderbolt over the same connector and wire but most accessories are not rated for Thunderbolt.

Omg I love it and I hate it.

s-mon··on I was wrong about robots.txt
Having worked on bot detection in the past. Some really simple old fashioned attacks happened by doing the opposite of what the robots.txt file says.

While I doubt it does much today, that file really only matters to those that want to play by the rules which on the free web is not an awful lot of the web anymore I’m afraid.

s-mon··on Show HN: FlopperZiro – A DIY open-source Flipper Zero clone
Wondering what the hotels in Vegas around Defcon will think of it this year lol.
s-mon··on Show HN: I wrote a new BitTorrent tracker in Elixir
Love Elixir so much, building a kick-ass notification engine with it now. Its so so good.
s-mon··on Q-learning is not yet scalable
While I like the blogpost, I think the use of unexplained acronyms undermines the opportunity of this blogpost to be useful to the wider audience. Small nit: make sure acronyms and jargon is explained.
s-mon··on Faster, easier 2D vector rendering [video]
Great presentation and thanks for sharing the slides. Wondering, can any of these methods be used for 3D too?
s-mon··on Zod 4
Who else here is going to the Zod meetup tonight?
s-mon··on We identified a North Korean hacker who tried to get a job at Kraken
https://www.wired.com/story/north-korea-stole-your-tech-job-... - same day, what a coincidence!
s-mon··on 10k WordPress Websites Found Delivering macOS and Microsoft Malware
Poor Wordpress...
s-mon··on DeepSeek: X2 Speed for WASM with SIMD
Love WASM (used to be love hate...)
s-mon··on Over 5k WordPress sites caught in WP3.XYZ malware attack
Crazy, Wordpress hasn’t had the best 12 months…
s-mon··on Show HN: An AI that reliably builds full-stack apps by preventing LLM mistakes
Man this is so cool!
s-mon··on How the British Airways' breach kickstarted today's web security challenge
Hey folks,

CEO of c/side here. Sorry to keep you waiting. Answering a few points here:

1. This is not an ad, or at least it was not intended to be one. We feel like this is a microsite which like most blogs has a little "this is who we are" ending. Same concept as the Cloudflare blog which we all appreciate and love. We noticed vendors in the security space talk about the BA attack but often share misinformation about what happened. Information is scattered among various channels and old news publications but since the court documents were released no one did a proper recap. We care so we managed to buy the domain, which was not hard, but indicates that we are not just a salesy brand we are genuinely deep in client-side security and feel its important to talk about the attacks that happened otherwise companies do not take action and consumers become victims.

2. Yes, this domain name is still flagged on some DNS filter providers. Threat feeds are an outdated concept that create a false sense of security and pollute the web if not kept up to date. Especially in the case of client-side attacks they are grossly ineffective as vendors consume the threat-feeds but don't actively monitor the dataflow or served code meaning targeted attacks fly under the radar. The BAways domain has not been used in an attack for over 5 years. You've all been very helpful in flagging the DNS you use and we'll reach out to those vendors to correct the flagging of the domain. There is no malicious action on this domain anymore, it purely serves as a reminder to educate on the risks of unmonitored client-side executions.

3. To finish: Client-side security is important. When I speak to security engineers, they get it. It's a vital part of the supply-chain and it is overlooked. However, executives are often not aware of the issue and feel it is negligible. This is partly because the world has stopped covering client-side attacks for some reason and put them under umbrella terms like "data leaks". Malicious pop-ups are blocked by most browsers, but those pop-ups often originate from malicious JS. Stealthy attacks are easy to pull off so imagine a small percentage of pop-up's that were blocked stealing user credentials. Between the Polyfill attack, the data leak of Kaiser Permanente and many other attacks over 500K websites were impacted in 2024, millions in fines, millions of user credentials, sensitive information and credit cards leaked. The aim of this blogpost is to get people to talk and understand that posture management means monitoring the entire posture, not just NPM, not just a simple vulnerability scan, not just the server side and internal networking but active monitoring of all bases.

I hope this context helps and thanks for your engagement.

s-mon··on New TTPs in Stealing PII and Financial Information from Magento Websites
Can’t help but notice how Magento is the centre of so much misery.
s-mon··on How I Experience Web Today (2021)
The amount of client-side fetched third party tools fighting for the upper layer is so funny and accurate. Intercom + cookie settings + a newsletter popup + ads…
s-mon··on How I Experience Web Today (2021)
Cookie banners… the most silly idea made by non technical people mandated upon technical people. Does anyone remember P3P? If that was pushed and managed better it would have solved the entire problem.
s-mon··on AMD EPYC 9965 Delivers Better Performance/Power Efficiency vs AmpereOne 192-Core
Thats insane! I wonder how the cooling works.
s-mon··on uBlock Origin has blocklisted PolyfillIO in it's badware list
More here: https://cside.dev/blog/more-than-100k-websites-targeted-in-w...
s-mon··on Show HN: pgxman – npm for Postgres extensions
We've removed the animation for not so this should no longer happen. Unfortunately animations can be very heavy.
s-mon··on Hacking the Education System
Thanks for your positive response. Reminds me of the risks of not having enough human interaction outside of study time.
s-mon··on 'It's quite soul-destroying': how we fell out of love with dating apps
I’ve met amazing people through these apps but that was when I was younger and earlier in career. Nowadays, I hardly find time to respond to important texts let alone respond to some person 5km away about how my day went.
s-mon··on The product manager role is a mistake
I read: 'I had a bad experience with a product manager, so all are bad.'

I agree that there are tons of bad PMs out there. But allow me to summarize what a good PM does:

Talk to customers; either to dig deep into their use case, deescalate a situation, figure out solutions, or conduct research. Monitor the rest of the market. Plan launches, pricing, and coordinate with sales teams, etc. - I had Product Marketing staff before, but they missed context and delivered bad experiences. I find it way harder to find a good product marketing manager than a good product manager. The PM is the DRI (Directly Responsible Individual) and therefore takes a lot of shit. The PM acts as a filter so you can continue doing your job. A good PM can even write a line of code here and there. Prototyping is part of the job. Roadmap, strategy, vision, build vs. buy... often the center of friction between what the business wants, what customers want, what the business can afford, and what engineers want to build. Finding a middle ground. You are right; these are not skills you learn in school. A PM wears a lot of hats. People with a solution architect or engineering background with a customer-facing element to their past tend to have the best chance of being a good PM. But by no means is the PM job an unnecessary one - do you want to figure out how to price a product and be responsible if sales can't sell it? I hope you come across a good PM in your career.

'Just hire great people' - what's new?

PS: The success of a PM highly depends on the engineering culture. If engineers are convinced all PMs are useless and they have no real job, or as a real-life example: engineer thinks A, PM shows data that shows B, but engineer just thinks the data is wrong and will do A anyway... it will be a highly frustrating collaboration for both. Please keep an open mind.

s-mon··on The SEC cracks down on greenwashing
FINALLY
s-mon··on Hydra – Tone of Voice
I liked the Monzo tone of voice doc a lot but this is cleaner.
s-mon··on Hydra Cloud is now Generally Available
Hey, I’m Simon. Product Lead at Hydra. Happy to answer any questions.
s-mon··on Show HN: Hydra 1.0 – open-source column-oriented Postgres
This looks wild! Been looking for a good event based logs DB and didn’t want to go full clickhouse. This will do!
Page 1 of 2Next →