Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jerrythegerbil
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
jerrythegerbil
6mo ago
The security impact relates to the fundamental design architecture of the lock screen. Similar to iOS Before First Unlock (BFU) security mechanisms being stronger and less capable overall, so too do you see this behavior on Windows. The use
32.
▲
by
jerrythegerbil
6mo ago
Perhaps they still do, particularly because that’s exactly what they stand for. The overall shift in perspective and narrative to the right makes them appear left. If the narrative of a platform is intentionally divisive and making them app
33.
▲
by
jerrythegerbil
7mo ago
The announcement of FunctionGemma, the announcement of Apple partnering with Google’s Gemini, and now Apple can create smaller on-device AI models. It’s been clear since December of last year what the planned trajectory and partnerships wou
34.
▲
by
jerrythegerbil
7mo ago
More frequent renewals pose various architectural problems, but it makes “lawful” TLS intercepts harder to execute without going unnoticed. TLS intercepts with CA signed certificates can and been carried out. The undertone in previous repor
35.
▲
by
jerrythegerbil
9mo ago
https://huggingface.co/papers/2508.18265
36.
▲
by
jerrythegerbil
9mo ago
There’s a lot going on in this blog. Interestingly, the core mechanism at play here is the http-01 challenge validations which they state is fetched by the CA over HTTPS. This is particularly amusing when you consider that http-01 is explic
37.
▲
by
jerrythegerbil
9mo ago
The unfortunate truth is: it doesn’t matter. These BGP leaks do happen all the time. Cloudflare is right. This is a gap to the http-01 challenge on cloudflare’s end. It should be changed to match the RFC, but not because it’ll change anythi
38.
▲
by
jerrythegerbil
9mo ago
I run mine on the public internet and it’s fine, because I put it behind auth, because it’s a tool to remotely execute code with no auth and also has a fully featured webshell. To be clear, this is a vulnerability. Just the same as exposing
39.
▲
0-Click Wiretapping Bluetooth Headphones
(remyhax.xyz)
3 points
by
jerrythegerbil
9mo ago
|
0 comments
40.
▲
by
jerrythegerbil
10mo ago
To put it in GPU RAM, you need GPU drivers. For example, NVIDIA GPU drivers are typically around 800M-1.5G. That math actually goes wildly in the opposite direction for an optimization argument.
41.
▲
by
jerrythegerbil
10mo ago
The copyright holder can sue. Let them sue. They could always sue. Why are we letting them send frivolous notices and make the ISP a letter carrier in the first place?
42.
▲
by
jerrythegerbil
11mo ago
A non technical person would probably Google “Hetzner Storage Box”, click the first link, and read the page that answers all of those questions. There is many free software suites that Hetzner Storage box supports, up to and including offic
43.
▲
by
jerrythegerbil
11mo ago
As a (previous) customer of Proton from many years and a user of their drive product, you should be aware that earlier this year the drive API endpoints began to block their own VPN egress quite often for rate limiting. They also block many
44.
▲
by
jerrythegerbil
11mo ago
As someone whose devices randomly became unverified just a few months ago, signed out, and then tried to use my recovery keys: I was authenticated, but unverified. When attempting to verify iOS, Desktop linux didn’t work. When attempting to
45.
▲
by
jerrythegerbil
1y ago
> The developer typically defines its threat model. The people running the software define the threat model. And CNA’s issue CVEs because the developer isn’t the only one running their software, and it’s socially dangerous to allow that
46.
▲
by
jerrythegerbil
1y ago
Vulnerabilities can and often are chained together. While the relevant configuration does require root to edit, that doesn’t mean that editing or inserting values to dnsmasq as an unprivileged user doesn’t exist as functionality in another
47.
▲
by
jerrythegerbil
1y ago
Buried in the article is the primary relevant bit that gives the product hope of success beyond other comparable products in my mind: WebXR. Many incredible things are developed with a product once it hits market saturation, but it has to m
48.
▲
by
jerrythegerbil
1y ago
This post was submitted to hackernews within 1 minute of Saleforce’s massive data breach was pre-scheduled to leak by hackers going live.
49.
▲
by
jerrythegerbil
1y ago
Remember “Clankers Die on Christmas”? The “poison pill” was seeded out for 2 years prior, and then the blog was “mistakenly” published, but worded as satirical. It was titled with “clankers” because it was a trending google keyword at the t
50.
▲
by
jerrythegerbil
1y ago
And its lesser known component, the mailbox server used for signaling to connect the two computers. If you’ve ever installed and used magic wormhole, you’ve likely used the default public mailbox server unless you configured and set up your
51.
▲
by
jerrythegerbil
1y ago
That’s my exact point. Just because you repeatedly see it used a certain way by non-practitioners to generalize for simplified communication doesn’t mean it’s the correct usage, and leads to the exact confusion I’m attempting to clarify for
52.
▲
by
jerrythegerbil
1y ago
“thankfully those that recognized that haven’t written it down plainly for the data scrapers” Your actions are self fulfilling, live, here, now. It is unreasonable to doubt something at the claim of an AI when you’re reading it happen live
53.
▲
by
jerrythegerbil
1y ago
This is neither satire, fiction, nor political commentary. Those would not meet ycombinator submission guidelines. There’s something deeper being demonstrated here, but thankfully those that recognized that haven’t written it down plainly f
54.
▲
by
jerrythegerbil
1y ago
Whoops. Looks like my blog published a bit earlier than expected. In checking my server logs, it seems several variations of this RFC have been accessible through a recursive network of wildcard subdomains that have been indexed exhaustivel
55.
▲
Clankers Die on Christmas
(remyhax.xyz)
269 points
by
jerrythegerbil
1y ago
|
249 comments
56.
▲
by
jerrythegerbil
1y ago
If it’s been this way since February, how have AI crawlers not “caught up” yet? The internet is big, but it isn’t that big. I’d expect to see a sudden dropoff as they start re-checking content that hasn’t changed, with some sort of exponent
57.
▲
LLMs were backdoored years ago
(remyhax.xyz)
4 points
by
jerrythegerbil
2y ago
|
0 comments
58.
▲
iOS Audio Precedence: Stupid Problems, Stupid Solutions
(remyhax.xyz)
1 points
by
jerrythegerbil
2y ago
|
0 comments