Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
acorn221
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
1.
▲
by
acorn221
22d ago
Damn Rory, I didn't know you wrote fiction! Nice work here
2.
▲
by
acorn221
1mo ago
The only numbers I've got right now are the 2M+ weekly active users on the chrome web store listing - I've not got exact numbers for how many people use the card readers but I get the impression it's more common in the legacy
3.
▲
by
acorn221
1mo ago
Thanks! ItsMe actually uses the connective signing ext system to sign users up so it's likely lots of people signed up for itsme with this flow and just never uninstalled the extension and native host.
4.
▲
by
acorn221
1mo ago
The thumbnail is ai generated, the content is not. I'm OP here. I can't afford artists to draw all the thumbnails and I'm not going to refrain from using all the tools at my disposal.
5.
▲
by
acorn221
1mo ago
First DEF CON, first conference talk and I loved it.
6.
▲
by
acorn221
2mo ago
This is my extension, I made it because I hate the UX of PGP. It uses passkeys (or passwords) to encrypt all keys (public and private) at rest so your contacts can't get leaked easily. I do a bunch of vulnerability research with sensit
7.
▲
Show HN: PGP made convenient (encrypted at rest with passkeys)
(chromewebstore.google.com)
2 points
by
acorn221
2mo ago
|
1 comments
8.
▲
Show HN: The Extensions Scraping Your AI Chats
(amibeingpwned.com)
4 points
by
acorn221
4mo ago
|
0 comments
9.
▲
We Caught Prompt Security Leaking API Keys
(youtube.com)
2 points
by
acorn221
5mo ago
|
0 comments
10.
▲
WhatRuns extension malicious update: Full URL and AI chat exfiltration [video]
(youtube.com)
3 points
by
acorn221
5mo ago
|
0 comments
11.
▲
Show HN: CRXcavator, but Better
(amibeingpwned.com)
2 points
by
acorn221
5mo ago
|
0 comments
12.
▲
Show HN: Chrome Extension Scanners, Spin AI vs. Am I Being Pwned
(amibeingpwned.com)
2 points
by
acorn221
5mo ago
|
0 comments
13.
▲
by
acorn221
6mo ago
ik lol, I was too lazy to change it
14.
▲
by
acorn221
6mo ago
I thought I’d check to see whether or not they actually read what they were adding lol
15.
▲
I added Jeffery_Epstein_did_not_kill_himself to LinkedIn's client bundle
(imgur.com)
6 points
by
acorn221
6mo ago
|
6 comments
16.
▲
by
acorn221
6mo ago
If you want to go check for it, open linkedin on Chrome, open dev tools -> network tab -> magnifying glass at the top then search for "epstein" and you'll see it!
17.
▲
by
acorn221
6mo ago
Yeah I mean it's not very commonly used by extensions. I quite like it as it's completely isolated and not detectable. I built my first extension which uses it as the primary interface yesterday: https://github.com/
18.
▲
by
acorn221
6mo ago
Yeah I agree. All new extensions should have this for their web_accessible_resources. With that said, the chrome web store ecosystem has bigger problems infront of them. For example, loads of extensions outright just send every URL you visi
19.
▲
by
acorn221
6mo ago
Yeah, this is the easiest way to get around it
20.
▲
by
acorn221
6mo ago
So these extensions allow linkedin to do this though, it's literally them saying "yes, this site can ping this resource" - called "web_accessible_resources". This is fair from Linkedin IMO as I've seen loads of
21.
▲
by
acorn221
6mo ago
They have! It's these developers either not knowing or not caring about it which is the issue! I did a blog post about this a while back showing how they do it, and how you can get around it, it's not very complex for the devs. h
22.
▲
by
acorn221
6mo ago
Yeah I agree
23.
▲
by
acorn221
6mo ago
This gave someone the opportunity to add in "Jeffery_Epstein_did_not_kill_himself" to linkedin's client facing code base through this. If you open dev tools -> network tab -> network search icon (magnifying glass) ->
24.
▲
Show HN: PGP Made Convenient
(chromewebstore.google.com)
2 points
by
acorn221
6mo ago
|
0 comments
25.
▲
I built the best PGP toolset on Chrome
(chromewebstore.google.com)
3 points
by
acorn221
6mo ago
|
1 comments
26.
▲
by
acorn221
6mo ago
Bold claim, I know. It's opensource, has better UX and fewer requested permissions than every other PGP extension IMO. It uses passkeys as the primary flow (but you can use passwords) to fully E2EE your secrets. You can choose the sync
27.
▲
by
acorn221
6mo ago
I am OP here, feel free to ask questions!
28.
▲
Am I Being Pwned? See what your Chrome extensions are exfiltrating
(amibeingpwned.com)
2 points
by
acorn221
7mo ago
|
0 comments
29.
▲
I caught the WhatRuns Chrome Ext stealing AI chat data [video]
(youtube.com)
2 points
by
acorn221
7mo ago
|
0 comments
30.
▲
by
acorn221
7mo ago
I'm trying not to get sued - SensorTower have lawyers, I don't :( Presenting the facts here so you can make your own mind up!
More ›