Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cookiengineer
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
91.
▲
by
cookiengineer
4mo ago
Don't use github actions. Don't use toolchains that auto execute stuff. Simple as that, because that's the attack surface. https://cookie.engineer/weblog/articles/malware-insights-git... I wrote tha
92.
▲
by
cookiengineer
4mo ago
The main reason I am building my own agentic environment is that I need full control and reproducibility of what I am building. Post November and post openclaw agentic environments need to be built differently, and for selfhosting models th
93.
▲
by
cookiengineer
4mo ago
We need to make a gooey family of UI frameworks!
94.
▲
by
cookiengineer
4mo ago
Sadface :-( (Author of Gooey [1], a GUI framework for WebASM in Go) [1] https://github.com/cookiengineer/gooey
95.
▲
by
cookiengineer
4mo ago
Hey, that's my workflow! I also built a convenient CLI tool to switch identities on a per-repository basis. [1] [2] ...which makes working in enterprise environments much easier, as I can just have separate identities/keypairs for
96.
▲
by
cookiengineer
4mo ago
Most problems you described come from using LLMs with high temperatures and long lifecycles. The point behind agentic environments and an orchestrator/planner architecture is that you can delegate defined and specified tasks to short l
97.
▲
by
cookiengineer
4mo ago
I like to do that more subtly. If I want to have IT check on an ongoing engagement, I usually use Raspberry Pi based OUI/MAC addresses. Other than that, I can recommend going for IoT devices like VOIP phone MAC addresses in conference
98.
▲
by
cookiengineer
4mo ago
But it's got electrolytes! My question is now: Which company is gonna buy the IRS now?
99.
▲
by
cookiengineer
4mo ago
Wanted to add that the author has an amazing blog with lots of interesting papers: https://jedrzej.maczan.pl/
100.
▲
by
cookiengineer
4mo ago
> How are they “not obligated to be truthful”? Lying to investors is literally a crime. In the US? Hahaha, that was a good one, buddy.
101.
▲
by
cookiengineer
4mo ago
This was also previously known as witch hunts.
102.
▲
by
cookiengineer
4mo ago
Claude Code can't slopcode working GUIs That's the real reason. If you don't believe me, take a look at the leaked codebase from a couple weeks ago. It's the stuff of nightmares, because too many junior devs slopcoded in
103.
▲
by
cookiengineer
4mo ago
> Finally there’s the tools-for-thought/notetaking people. God save us. It’s always the same thing. Your folder with notes—pardon me, your “second brain”—plus an AI agent that writes, edits, synthesizes information, answers queries.
104.
▲
by
cookiengineer
4mo ago
I'll never forget that secret room with the four hanging keens... :(
105.
▲
by
cookiengineer
4mo ago
> Gophers are usually quite fast, perhaps an elderly turtle would be a better mascot? The slow turtle wins the race against the overly eager rabbit... so I'm okay with that
106.
▲
by
cookiengineer
4mo ago
Anybody remember the game Project IGI (I'm Going In)? That was the original stealth game in my opinion :D ... well, apart from XIII, NOLF, Commander Keen and Agent Sam, of course. The 90s sure had some awesome games
107.
▲
by
cookiengineer
4mo ago
Always pack your towel for space travel!
108.
▲
by
cookiengineer
5mo ago
> That's basically Torvolds full time job? It's actually more like 50 devs, each of them specialized in their own field, with 20+ years programming experience. And even they make mistakes sometimes (see the recent TOCTOU exploi
109.
▲
by
cookiengineer
5mo ago
Talking about LLM without harness/environment engineering is like talking about children on a playground without safety measurements. Managing agents is a lot like managing children. They will outsmart you 99% of the time. If your agen
110.
▲
by
cookiengineer
5mo ago
That's the joke ...because they never patch it, and are busy building robots instead.
111.
▲
by
cookiengineer
5mo ago
We're talking about a company with a security culture where opening a text file in notepad.exe can lead to an RCE. Assuming reasonable implementation standards at this point is the irrational assumption, not the rational one.
112.
▲
by
cookiengineer
5mo ago
Note that the NPM worms are spreading because the package providers are developing on their libraries without them noticing a malicious dependency. It is not users/consumers spreading the worm, it is developers spreading it. Your misma
113.
▲
by
cookiengineer
5mo ago
Actually bindings are usually generated like that, at build time (though with a build cache that nobody knows how it corrupts all the time). Examples that come to mind: webview/webview, webkit, cilium/ebpf and most other CGo proje
114.
▲
by
cookiengineer
5mo ago
I suppose that go's go:generate workflow can also be abused to land a worm like the ones spreading via npm, as you can build programs that just scrape the whole hard drive for git projects and patch the go.mod dependencies there, and y
115.
▲
by
cookiengineer
5mo ago
> its pretty obvious you have no idea how bitlocker works, and its various modes - TPM only, TPM+PIN, PIN only How could anybody besides a Microsoft employee, given the appearance of this bypass technique?
116.
▲
by
cookiengineer
5mo ago
> no, to access a bitlocker volume which automatically decrypts > thats an LPE, not an encryption backdoor No. RedSun and Bluehammer were LPEs > the USB stick doesnt decrypt bitlocker, it just gives you root after bitlocker was AUT
117.
▲
by
cookiengineer
5mo ago
> the only way to bypass PIN would be an actual backdoor in Bitlocker. no way around that. an actual backdoor in microsoft encryption was never documented, and there are Snowden documents showing FBI pressing Microsoft into introducing o
118.
▲
by
cookiengineer
5mo ago
If someone drops 5 confirmed ring 0 exploits/bypasses within 3 months and claims that they got a 6th one... why on earth would you doubt that the 6th one suddenly is fake? Do you know how hard discovering even one of those is? And how
119.
▲
by
cookiengineer
5mo ago
Note that RedSun and Bluehammer were silently patched, with no response to the CVEs by Microsoft, and not accrediting the researcher's work. That's what this is about. Microsoft doing bad security practices while trying to get awa
120.
▲
Microsoft BitLocker – YellowKey zero-day exploit
(tomshardware.com)
292 points
by
cookiengineer
5mo ago
|
158 comments
More ›