Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
0x0
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
0x0
2mo ago
I find it's a shame the article is absolutely littered with AI-isms, again, like another cool hack project the other day here on HN. It is incredibly jarring to read a line like "No Platform Builder, no SDK install, no CD key.&quo
2.
▲
by
0x0
3mo ago
Shame the article is absolutely littered with AI-isms.
3.
▲
by
0x0
3mo ago
I just wish Valve could add official macos-arm64 builds of the various hl2 games on Steam :-/
4.
▲
by
0x0
5mo ago
Just recently noticed this got posted to deb-multimedia, although I think there is a typo in the package description.... https://www.deb-multimedia.org/dists/unstable/main/binary-am... ... it says "fast
5.
▲
by
0x0
5mo ago
Details here: https://eclecticlight.co/2023/09/25/postscripts-sudden-death...
6.
▲
by
0x0
5mo ago
Such a shame that macOS lost all its built-in postscript support including Preview.app in recent versions :(
7.
▲
by
0x0
5mo ago
I find it curious to call someone dropping a weaponized root exploit before major distros or even LTS kernel git branches have patches ready "good guys". This could have been handled with much more grace.
8.
▲
by
0x0
5mo ago
The disclosure doesn't appear very "full". Looks like this was slipped into mainline linux among dozens of other mostly-irrelevant "CVEs" with nobody highlighting the fact that it is in fact dirty-cow-on-steroids.
9.
▲
by
0x0
5mo ago
Dropping a public exploit on github before distros have patches available isn't very cool, or is that just how veterans roll these days?
10.
▲
by
0x0
6mo ago
Enumeration of the entire DNS space is not available in general, but it does appear that some TLDs offer complete zone files for legitimate research purposes, see for example https://czds.icann.org/help#zone-files
11.
▲
by
0x0
6mo ago
The breakout engineering to exploit Dolphin has already happened, see for example: * https://dougallj.wordpress.com/2016/11/13/exploiting-dolphin... * https://gist.github.com/hthh/502ae16
12.
▲
by
0x0
7mo ago
> "they can't be provisioned by the website itself." It's funny, we used to have a html tag that would exactly that: <keygen />
13.
▲
by
0x0
9mo ago
They were great in the beginning, and then when you issued a few more certs than they liked you were asked to pony up some $$$, and then when you did that and actually "verified" who you were on a personal international phone call
14.
▲
by
0x0
10mo ago
Same here, and the worst part is the duplicates appear to reuse the same Message-id, which confuses macOS Mail.app to no end :-/
15.
▲
by
0x0
10mo ago
It's actually a requirement by app store connect to use a modern sdk for uploading binaries, and modern sdk versions will often raise the minimum supported ios version, so this is not always the developer's fault. See for example
16.
▲
by
0x0
11mo ago
I'm sure there's lots of x86_64 specific code in the macOS userland that is much more than just a recompile - things like safari/javascriptcore JIT, various quartz composer core animation graphics stack and video encoder deco
17.
▲
by
0x0
11mo ago
I'm guessing they don't want to maintain and build and test x86_64 versions of all the macos libraries like Appkit and UIKit (including large changes like liquid glass) when they are no longer shipping x86_64 macOS versions. Which
18.
▲
Microsoft's Root Program and the 1.1.1.1 Certificate Slip
(unmitigatedrisk.com)
10 points
by
0x0
1y ago
|
1 comments
19.
▲
by
0x0
1y ago
Surprised to see no patch available for watchOS, which can also receive images via iMessage. Not important enough to patch, or not vulnerable, or just not exploited in the wild yet?
20.
▲
by
0x0
1y ago
I was hoping this would work over ssh in a macOS Terminal.app, but last I tried it was inserting all kinds of weird characters into the edited text files. Windows ships an official OpenSSH server these days, but so far there haven't be
21.
▲
by
0x0
1y ago
If linux kernel security really is so bad that google had to add a proof-of-work to introduce a 4 second race for 0day submissions, I'm surprised they're ok with still using the Linux kernel as the base for Android.
22.
▲
by
0x0
1y ago
> Safari only exist on Apple devices Webkit, at least, builds on a lot more platforms than you think. Take a look at https://build.webkit.org/#/builders I'm seeing at least three other MAJOR platforms: •
23.
▲
Microsoft Telnet Server MS-TNAP Authentication Bypass
(github.com)
8 points
by
0x0
1y ago
|
1 comments
24.
▲
by
0x0
1y ago
So I guess you couldn't get certificates for any random (MX) domain, only for those where you can obtain an inbox / user account. Still really bad, especially for things like gmail.com, but also larger enterprises. Intense.
25.
▲
by
0x0
1y ago
I saw this on twitter a few hours ago on my phone, and misread the price as $25, so I was considering maybe putting in an order or even two, but when I revisited the site on my laptop and discovered it was $250, my curiosity hit a wall. Loo
26.
▲
OpenSSH 10.0
(openssh.com)
6 points
by
0x0
1y ago
|
0 comments
27.
▲
by
0x0
1y ago
I recently ran into an issue with this because building an iOS .ipa from the command line with xcodebuild apparently ends up shelling out to call rsync to copy some files between local directories, and because I had homebrew rsync earlier i
28.
▲
by
0x0
1y ago
Probably because the 6502 CPU had instructions for optimized access to the zero page (first 256 bytes of RAM), this would also apply to C64 and NES etc. If you want to use "Indirect Indexed" memory accesses then I think it also ha
29.
▲
by
0x0
2y ago
Most email providers support mail forwarding and distribution lists, but maybe they should have added some sort of opt-in confirmation when adding recipients outside the local domain...?
30.
▲
by
0x0
2y ago
I think I read somewhere that scammers set up an email distribution list / alias / forwarding from one something.onmicrosoft.com account to dozens of victims, and then they trigger a (real!) paypal email with that one something.on
More ›