Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cookiengineer
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
cookiengineer
2mo ago
While I agree with the premise of your argument, I don't think this is the correct platform to do so. And I also have to state a fun fact: I'm not a journalist. If you expect more founded research put together into an investigativ
32.
▲
by
cookiengineer
2mo ago
Imagine doing this article as a thorough writeup to provide feedback, rewriting this for like an hour before you post it. And then you get an AI slop response like that in return where you can't even tell whether it was just a CEO not
33.
▲
by
cookiengineer
2mo ago
> It's just that there's really not a lot of evidence that this is rampant Not sure what is "rampant" in your view, and what is not. There's been multiple attempts of murder, multiple linked assassinations, acros
34.
▲
by
cookiengineer
2mo ago
> This is essentially one article about criminals recruiting young people. Is Russia FSB (or even Russia) even mentioned? Generally if an article is about FSB, it implies Russia. Otherwise, you would have to admit that Russia is a failed
35.
▲
by
cookiengineer
2mo ago
There's lots of people working for NATO and federal agencies in Europe that have been assassinated by the luckystrike branch of the FSB. The name comes from the Telegram account with underscores in between, and they're essentially
36.
▲
by
cookiengineer
2mo ago
FBI has no jurisdiction over Russia. And Russia doesn't give a damn, as they literally gave APT28/29 the mandate to do this, the only exception being that no former Sovjet territories can be attacked. (With the current exception o
37.
▲
by
cookiengineer
2mo ago
yawns Good morning world, Here's the updated Antimiasma tool for mitigation [1] [2]. More details on how this tool was built and how the Miasma worm works on my website [3]. This is the first false flag in the campaign series, where
38.
▲
by
cookiengineer
2mo ago
> CI usually has the most privileged secrets anywhere in a company lol Literally the reason the stealer of Miasma was focusing on extracting tokens from the CI/CD runner from the start.
39.
▲
by
cookiengineer
2mo ago
We're talking about Microsoft, who created a notepad.exe that can run an RCE with an LLM bypass prompt. In the previous Miasma waves, Microsoft was so overwhelmed that they delayed the VSCode extension installs for a couple days with a
40.
▲
by
cookiengineer
2mo ago
I kind of modded my GBA a while back, and bought some upgrades like a better display and an sdcard using cartridge. Now it's my travel device when I'm on holiday or having no energy left to focus on code. It's pretty convenie
41.
▲
by
cookiengineer
2mo ago
> generics were a slippery slope. give it a decade and Go will be indistinguishable from c++ Lib boost will have conquered every language by then!!! :D Jokes aside, generics are unusable in a lot of languages due to their syntax choices.
42.
▲
by
cookiengineer
2mo ago
The comment length is too small to write a thorough malware analysis. That is why I linked my blogposts, the tool, and the whitepaper that I published about it. You have to read it first to come to your own conclusions. If you come to concl
43.
▲
by
cookiengineer
2mo ago
I was talking about _mutual_ TLS.
44.
▲
by
cookiengineer
2mo ago
> What kind of jerk would attack Arch Linux? The answer is: Russians Source: I'm the guy that built the antimiasma mitigation tool [1] and tracked their malware campaign iterations very closely. Set LANG to ru_RU.* and the malware i
45.
▲
by
cookiengineer
2mo ago
"abliterated moonshine" certainly has a ring to it
46.
▲
by
cookiengineer
2mo ago
> at least until we stop mixing up instructions with data. That's what I always say, but nobody listens to me :D Assembler had the same kind of design flaw, and we didn't learn anything from it as evident by LLM bypasses.
47.
▲
by
cookiengineer
2mo ago
The cheaper the relay mechanism is, the more noise/spam you'll get. Lots of servers online have a publicly exposed smtp port, where all kinds of script kiddies are just using a sendmail style email from another (not-owned) domain.
48.
▲
by
cookiengineer
2mo ago
^ this Additionally, I would probably guess correctly that almost all spam comes from rotating ASNs these days. Aka from companies that do "growth marketing" or other bullshit that isn't a valid business but just... spamming
49.
▲
Show HN: Experimental multi-head window manager made for programmatic use
(github.com)
1 points
by
cookiengineer
2mo ago
|
0 comments
50.
▲
by
cookiengineer
2mo ago
It's actually an effect that happens in the (re-)alignment process due to harmonic properties of the positional encoding in the attention matrix. (I recommend reading and implementing the Attention is all you need paper. By hand. Other
51.
▲
by
cookiengineer
2mo ago
> but only after I bugged them working as a Redteamer/Purpleteamer, I read this as you physically planting a (listening) bug in the HR office to get that info :D
52.
▲
by
cookiengineer
3mo ago
Europe is actually catching up right now. Not at the frontier like kimi and qwen 3.6 (yet) but it's just a matter of time until the European A3B models catch up, too. Apertus and Soofi, both open source (not only open weight) models: [
53.
▲
by
cookiengineer
3mo ago
Everything is open source if you know how to reverse engineer ;)
54.
▲
by
cookiengineer
3mo ago
This so much! For my current setup, the most efficient way is to use larger models for coordination, but a heretic'ed qwen 30B model for the implementations. If you build your agentic environment around specifications and test coverage
55.
▲
by
cookiengineer
3mo ago
Haha, I had to laugh a lot about this. This is essentially DNS, every single step of the way. Hosting wouldn't be hard if ISPs weren't so hostile with carrier-grade NATs, if HTTP/S wouldn't rely on DNS primarily, if legi
56.
▲
by
cookiengineer
3mo ago
This project was something that I had in the back of my head for a long time. I'm analyzing golang malware for my dayjob most of the time and I was annoyed by the typical decompiler pipelines that always try to generate Pseudo C code i
57.
▲
Godecompose: Go decompiler that uses pattern matchers
(github.com)
5 points
by
cookiengineer
3mo ago
|
1 comments
58.
▲
by
cookiengineer
3mo ago
> It would be nice to have an agreed-upon protocol for progress reporting. That was initially USR1 and USR2 as process signals, well, at least across binutils and coreutils. I just wish that UNIX architecture or POSIX would have been mod
59.
▲
by
cookiengineer
3mo ago
Fun fact that will blow your mind: Microsoft decided to send Windows NT 10.0 in the User-Agent header even on Windows 11 for compatibility reasons. That's literally the reason why the Sec-CH-* headers say Windows 11 but the User-Agent
60.
▲
by
cookiengineer
3mo ago
Unit tests don't test for branch coverage. That's the culprit, because LLMs tend to forget and remove a lot of branch logic in these kinds of tasks. If unit tests don't cover these specific if/elseif/else cases, the
More ›