Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ahoog42
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
System over Model: Zero-Day Discovery at the Jagged Frontier
(aisle.com)
2 points
by
ahoog42
5mo ago
|
0 comments
2.
▲
AI threats in the wild: The current state of prompt injections on the web
(security.googleblog.com)
4 points
by
ahoog42
5mo ago
|
0 comments
3.
▲
by
ahoog42
5mo ago
at what point do model providers optimize for the "pelican riding a bicycle" test so they place well on Simon's influential benchmark? :-)
4.
▲
Token-efficient access to all your data sources
(max.cloud)
2 points
by
ahoog42
6mo ago
|
0 comments
5.
▲
by
ahoog42
1y ago
any notes or pointers on how to get comfortable with k8? For a simple nodejs app I was looking down the pm2 route but I wonder of learning k8 is just more future proof.
6.
▲
by
ahoog42
1y ago
if you are on a Zoom/video call, does anyone know if you would have to declare that your "recording" it? I'm thinking more from the legal perspective of wiretapping/consent laws. If you have live transcripts/su
7.
▲
by
ahoog42
1y ago
regarding data collection, both android and ios provide multiple ways to review, approve/deny, and manage access to data. it's certainly not perfect but is being constantly improved. And for the HN crowd, you can always run mobile
8.
▲
You Are Reading Reddit a Lot More These Days
(nymag.com)
6 points
by
ahoog42
1y ago
|
5 comments
9.
▲
Apple devices offer speech to text transcription in developer betas, shows test
(9to5mac.com)
4 points
by
ahoog42
1y ago
|
0 comments
10.
▲
by
ahoog42
1y ago
If you want to be alerted to new/updated SEC cybersecurity filings, you can subscribe to my free alerts [1] or see the full index of cybersecurity incidents [2] on my tracker (I check SEC EDGAR every 5 mins). [1] https://www
11.
▲
by
ahoog42
1y ago
Jonathan Sawday’s 2023 book “Blanks, Print, Space, and Void in English Renaissance Literature: An Archaeology of Absence.” [1] explores this phenomenon as well across multiple mediums. It also won the Modern Language Association's top
12.
▲
French Competition Watchdog Fines Apple $162.4M over App Tracking Transparency
(wsj.com)
6 points
by
ahoog42
2y ago
|
1 comments
13.
▲
by
ahoog42
2y ago
This is exactly how we built viaForensics in 2009. For the first five years, we performed mobile forensic investigations and gave trainings based on the Android and iOS forensic books we wrote. We were able to self fund software development
14.
▲
by
ahoog42
2y ago
Despite their goal of enforcing in 2017, it is still not a hard requirement. Back then, about 80% of the apps we tested disabled ATS either partially or fully [1]. It’s rare to see Apple walk something back [2], but here is a blog at the ti
15.
▲
by
ahoog42
2y ago
We analyzed the iOS app[1] and observed similar traffic as well as a number of basic security issues (hardcoded encryption keys, use of 3DES and some traffic over HTTP). [1] https://www.nowsecure.com/blog/2025/02&#
16.
▲
by
ahoog42
2y ago
Any example code or blogs/docs that demonstrate making graphs/diagrams and/or hooking it up to a local code base?
17.
▲
by
ahoog42
2y ago
agreed the 3DES is a difficult choice to explain. To top it off the encryption key was hardcoded in the .ipa, the IV was null and then reused.
18.
▲
by
ahoog42
2y ago
Yes, the Android app has multiple vulnerabilities but we focused this report on iOS (it took nearly 40 hours to write the report). Our recommendation is people avoid using the mobile apps. If you want to test the model, I'd suggest Hug
19.
▲
Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App
(nowsecure.com)
17 points
by
ahoog42
2y ago
|
6 comments
20.
▲
by
ahoog42
3y ago
Congrats, very exciting. Do you support configuring things like usernames and passwords? How do you handle MFA?
21.
▲
by
ahoog42
3y ago
Actually there has been more, e.g. LoanDepot, Inc [1], and then various amended 8-Ks. I’ve been hacking on a side project to parse the 8-K data which is all over the place, including some companies still reporting under old “items” like 8.0
22.
▲
by
ahoog42
4y ago
Great points. Static binary analysis looks for the version string but doesn’t currently do deeper analysis of reversed code to see if it’s patched. Could go either way. And determining if the code is triggered and exploitable is quite chall
23.
▲
by
ahoog42
4y ago
I decided to review SBOMs from about 3,800 popular mobile apps to see if any included vulnerable versions of OpenSSL v3.0.x. No mobile apps did (not surprised) but what did surprise me was 98% of the OpenSSL versions included in these apps
24.
▲
by
ahoog42
12y ago
Please let me know if there's any questions or just an FYI link. I recently shared some thoughts on challenges faced when scaling a company - https://medium.com/@ahoog42/go-go-go-stop-a-lesson-in-scalin...
25.
▲
by
ahoog42
12y ago
We're Chicago-based startup [1] that helps secure mobile apps and devices and recently completed a 12.5m Series A. If you're interested in mobile security, you can get an idea about our work in a recently vulnerability we helped S
26.
▲
by
ahoog42
12y ago
If you want to easily do traffic inspection and forensic analysis of stored data for iOS and Android, you can check out the free Community Edition of our mobile app testing lab [1]. Disclaimer, co-founder here. [1] https://www.no