Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
_slih
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
_slih
7mo ago
a school district is a customer of the same ALPR data broker network that sells to law enforcement, repo companies, and federal agencies. the data doesn't care who's buying.
32.
▲
by
_slih
7mo ago
pattern matching on known bad commands is a deny list with extra steps. the dangerous action is the one that looks normal.
33.
▲
by
_slih
7mo ago
patching a kernel exploit on a phone from 2015 is nice until you realize the coruna IOC URLs were still live long enough for jailbreakers to weaponize the code before the patch shipped.
34.
▲
by
_slih
7mo ago
$70 million to a guy with a hotmail address and they couldn't keep the vendor list off the internet. but sure, trust them with biometric databases.
35.
▲
by
_slih
7mo ago
cool project but prompt injection doesn't care about your filesystem permissions. the malicious instruction comes from a file the agent is allowed to read.
36.
▲
by
_slih
7mo ago
subtraction vs filtration is the right framing even if the article is slop. removing capabilities is structurally different from filtering syscalls because the set of things to filter grows every kernel release but the set of things a proce
37.
▲
by
_slih
7mo ago
whether you want a network of cameras tracking every vehicle through every intersection is a different question that nobody voted on
38.
▲
by
_slih
7mo ago
the whole point of buying ad-tech data is that purchasing doesn't have the legal requirements that collecting does
39.
▲
by
_slih
7mo ago
prompt injection is the new sql injection except there's no prepared statement equivalent
40.
▲
by
_slih
7mo ago
requiring the OS to broadcast an age bracket to every app and website is building a new tracking vector and calling it child safety lol
41.
▲
by
_slih
7mo ago
shutting down the cameras rather than releasing the data tells you everything about what was being collected. the system was designed around the assumption that nobody outside law enforcement would ever see the footage.
42.
▲
by
_slih
7mo ago
shutting down the cameras rather than releasing the data tells you everything about what was being collected. the system was designed around the assumption that nobody outside law enforcement would ever see the footage.
43.
▲
by
_slih
7mo ago
the DR test isn't 'can we run in region B.' it's 'can we cut over to region B when every API call to region A returns a timeout.' most recovery plans assume they can still reach the thing that just broke
44.
▲
by
_slih
7mo ago
the verification service is the honeypot by design. it has to store what it collected to prove it did the check. the incentive to retain is built into the business model, and the breach is just a matter of time.
45.
▲
by
_slih
7mo ago
california blocked sharing police ALPR data with the feds. so border patrol built their own network on state highway infrastructure instead. the workaround is always simpler than the law it routes around.
46.
▲
by
_slih
7mo ago
amodei's autonomous weapons argument isn't political. it's an engineering assessment. if frontier models hallucinate in conversation, they'll hallucinate in targeting. you don't deploy unreliable systems where the c
47.
▲
by
_slih
7mo ago
when your sole digital identity provider goes down, it's not a service disruption. it's a national infrastructure outage. the blast radius of a single authentication system is the entire country.
48.
▲
by
_slih
7mo ago
once the infrastructure exists, it gets repurposed. age verification becomes watchlist screening becomes facial similarity scoring against political figures. scope creep is the feature.
49.
▲
by
_slih
7mo ago
the credential didn't change. the permissions changed underneath it. that's the worst kind of privilege escalation because nobody has a reason to go back and audit something they were told was safe a decade ago.
50.
▲
by
_slih
7mo ago
every tested router was vulnerable to at least one variant. that's what happens when a security feature gets adopted industry-wide without ever being standardized, not a bug.
51.
▲
by
_slih
7mo ago
standard kyc doesn't run on dedicated infrastructure isolated from the vendor's main cloudflare stack. you don't build a separate gcp cluster for routine age checks. the architecture tells you what the data is worth before an
52.
▲
by
_slih
7mo ago
the legal question is settled. edges are personal data under gdpr. the practical question is who audits a knowledge graph to verify deletion actually happened. palantir knows the answer is nobody.
53.
▲
by
_slih
7mo ago
calling data sovereignty laws a cybersecurity risk in the same week that Persona had 2500 files exposed on a government endpoint is an interesting choice of timing.
54.
▲
by
_slih
7mo ago
the agent inherits your shell, your env, and your network. encrypting one file doesn't change the trust boundary. the proxy approaches in this thread are closer to the right answer because the agent never holds real credentials at all
55.
▲
by
_slih
7mo ago
discord already had 70k government IDs breached through age verification last year. their fix was handing the next batch to a vendor with 2500 files sitting on a government endpoint.
56.
▲
by
_slih
7mo ago
naming the old behavior setHTMLUnsafe is what did it for me. security features that require developers to opt in don't work. making the unsafe path feel unsafe does.
57.
▲
by
_slih
7mo ago
the facebook bug is funny but the real issue is that robots.txt is a gentleman's agreement from 1994 and half the crawlers in 2026 don't care what it says.
58.
▲
by
_slih
7mo ago
companies that haven't turned a profit are outbidding the rest of the economy for hardware. that's not a supply shortage, it's a subsidy funded by venture capital.
59.
▲
by
_slih
7mo ago
the companies pushing hardest for age verification are the same ones whose business model depends on knowing exactly who you are. the child safety framing is convenient cover for a data collection problem they were already trying to solve.
60.
▲
by
_slih
7mo ago
love the update at the bottom. 'our systems were not compromised' doing a lot of heavy lifting for 'a code change exposed SSNs to unauthorized individuals for six months.
More ›