HNHacker News
TopNewBestAskShowJobs

spyc

640 karma · joined June 17, 2017

submissionscomments
spyc··on Sourcehut account takeover via build logs (XSS in ansi2html)
A free-for-life "Professional hackers" package (https://sourcehut.org/pricing/) would be the minimum compensation in my eyes.
spyc··on bzip3
Please report any build errors in the GitHub issue tracker so that the isseu can be fixed for everyone. Thank you!
spyc··on bzip3
How is this source code the original source and which parts? Please elaborate.
spyc··on The August 17 outage
I think he meant to say "prioritize" so that availability related work sees results sooner — "acceleration" — than it would without an increase in priority.
spyc··on libexpat now funded by the City of Munich for up to 6 months
That's a great question!
spyc··on Curl will not accept vulnerability reports during July 2026
Both libexpat ("Expat") and uriparser are following the curl security vacation and will not accept new vulnerability reports before 2026-08-01, starting today.

[1] https://github.com/libexpat/libexpat/issues/1277

[2] https://github.com/uriparser/uriparser/issues/323

spyc··on Show HN: Tacopy – Tail Call Optimization for Python
The current implementation breaks semantics of functions with tail recursion from within loops: https://github.com/raaidrt/tacopy/issues/1
spyc··on Python, the movie. The programming language's origin story comes to the screen
Potentially the movie itself is also or more of interest. The related thread is: https://news.ycombinator.com/item?id=45056377
spyc··on Memory-safe sudo to become the default in Ubuntu
Both implementations of doas for Linux have (the same) unfixed security issue:

- https://github.com/Duncaen/OpenDoas/issues/106

- https://github.com/slicer69/doas/issues/110

I have a hard time recommending doas over sudo on Linux when the issue has been fixed in sudo but not in doas.

spyc··on Redis is open source again
Lost trust for sure. Who knows if Redis would be AGPL now if Valkey did not exist.
spyc··on You might want to stop running atop
If anyone wonders what atop looks like at runtime or what it would be useful for, there's a video dedicated to the tool at https://www.youtube.com/watch?v=27AtCR5ftyM .
spyc··on Problems with the heap
I see, thanks!
spyc··on Problems with the heap
Update: I found https://www.bismuth.sh/ at https://news.ycombinator.com/user?id=ianbutler .
spyc··on Problems with the heap
I'm reading "I can go into why another time." like "I don't have time" personally, not like "I am not allowed to say".
spyc··on Problems with the heap
Hi! Three things:

- There is no commit with a SHA1 like that in atop Git history and what you shared is too long for a SHA1, it looks more like a SHA256. Did you share the right checksum? The only other way I can read this is that it's a SHA256 checksum of one of the past atop release tarballs or artifacts. I have not yet checked those.

- I have tried finding your tool Bismuth but all I find is things KDE and crypto currencies. Please share a link to the Bismuth that you are working on.

- You technically said that you are working on Bismuth /and/ found something, not that you found the bug /through/ Bismuth. Please clarify if and how that was the case.

Thank you!

spyc··on Recursion kills: The story behind CVE-2024-8176 in libexpat
There are parsers that only implement a tiny subset of XML. And Expat has compile time flags to disable some of that machinery where not needed. It's arguably no longer XML then though.
spyc··on Recursion kills: The story behind CVE-2024-8176 in libexpat
Thank you!
spyc··on Recursion kills: The story behind CVE-2024-8176 in libexpat
Thanks for sharing that research!
spyc··on Recursion kills: The story behind CVE-2024-8176 in libexpat
"Quickly kill the process" is still a denial of service security problem.
spyc··on Recursion kills: The story behind CVE-2024-8176 in libexpat
Correct.
spyc··on Recursion kills: The story behind CVE-2024-8176 in libexpat
Did you see the article references [1][2] from 2006 and 2017 that already argue that recursion is a security problem? It's not new just not well-known.

[1] https://www.researchgate.net/publication/220477862_The_Power...

[2] https://www.qualys.com/2017/06/19/stack-clash/stack-clash.tx...

spyc··on Recursion kills: The story behind CVE-2024-8176 in libexpat
That idea works in general but causes false positives: No artificial limit you pick is "right" and the false positives can be avoided by getting rid of the recursion altogether.

PS: It's not one single function, not direct but indirect recursion.

spyc··on Recursion kills: The story behind CVE-2024-8176 in libexpat
The point of termination is beyond stack overflow here, that's the problem. And unlike heap, stack does not tell you gently that it's running out.
spyc··on Most IT companies fail to serve security.txt for RFC 9116 in 2025
Not if you need to report the same thing to multiple parties. And why make it hard to someone who does whitehat work for you.
spyc··on Most IT companies fail to serve security.txt for RFC 9116 in 2025
That's not a good reason to not host the file.
spyc··on Most IT companies fail to serve security.txt for RFC 9116 in 2025
People who spent hours finding the right security contacts for companies without luck would likely disagree. The key failure is not the single missing file, but that security contacts are too hard to find and the effect that has.
spyc··on Ext4 data corruption in 6.1 stable
The way I read https://lore.kernel.org/stable/20231205122122.dfhhoaswsfscuh... 6.5+ should be okay. PS: Please correct me if not!
spyc··on Ext4 data corruption in 6.1 stable
Could you share your source on how/when/if O_DIRECT is required? Have a link?
spyc··on Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days
The backing Git repository is at https://github.com/MegaManSec/Squid-Security-Audit
spyc··on New make --shuffle mode
One way would be not using "cmake --build" but invoking make directly yourself after calling CMake.
Page 1 of 3Next →