Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
captn3m0
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
captn3m0
25d ago
I run a reverse engineering collective that is called 52 Labs: https://52-1ab.github.io/ . > 52 1ab (Pronounced 52 Lab) is a Software Research group dedicated to interoperabilty research in India. It is named after the Se
2.
▲
by
captn3m0
1mo ago
iOS has a hidden album but the UX isn't great: https://support.apple.com/en-us/104987
3.
▲
by
captn3m0
1mo ago
I am guessing you are approved for the Cyber Verification Program. I also applied and got approved in an hour (on a Saturday!), but it only applies to Opus and Sonnet: https://support.claude.com/en/articles/1460484
4.
▲
Show HN: Porting Super Hexagon to the Playdate
(captnemo.in)
3 points
by
captn3m0
2mo ago
|
0 comments
5.
▲
by
captn3m0
2mo ago
Namecheap also suspended my primary domain because of a bug at their end: https://captnemo.in/blog/2026/05/05/namecheap-whois/ tl;dr: Namecheap configured Domain Privacy on my domain, which isn'
6.
▲
by
captn3m0
2mo ago
I reversed Super Hexagon these last few weeks and ported it to the Playdate (the yellow console from Panic with a crank): https://old.reddit.com/r/PlaydateConsole/comments/1v1zxmt/i_... The multiplier co
7.
▲
A Prototype Original iPod
(blog.panic.com)
4 points
by
captn3m0
2mo ago
|
1 comments
8.
▲
by
captn3m0
2mo ago
There are a lot of other implementations of this idea that don't necessarily rely on trust-on-first-use. The securedrop team explicitly includes malicious JS served by the primary-domain in the threat-model and made WEBCAT[0] as an out
9.
▲
by
captn3m0
2mo ago
This is a OS port (iOS) of an existing functional and maintained fork (MacOS) of the official release (Windows). Most of these low-hanging bugs would have been caught upstream by now.
10.
▲
by
captn3m0
2mo ago
upstream is a MacOS+linux build. https://github.com/fbraz3/GeneralsX .
11.
▲
by
captn3m0
3mo ago
Do we know how Apple sends these? Is it just a notification, or also email?
12.
▲
by
captn3m0
3mo ago
There are 2 complete folds in the Isaac 0 video around 0:40, but speeded up: https://m.youtube.com/watch?v=KhImSR8GuCE The about page claims 1000+ lbs of laundry folded every week.
13.
▲
by
captn3m0
3mo ago
10% apparently for .tk. I also remember .tv windfall, which is 8-9% of their GDP.
14.
▲
by
captn3m0
3mo ago
I wrote superbright to be able to force it: https://github.com/captn3m0/superbright (fork of BrightIntosh). The display does get hit after 10-15 minutes of this though.
15.
▲
by
captn3m0
3mo ago
When I read the title, I thought it would be for research papers.
16.
▲
by
captn3m0
3mo ago
Hooks are not a new standard. Package managers have always supported hooks. It is just a call to get us to parity.
17.
▲
by
captn3m0
3mo ago
> The problem of everchanging malware isn't fixable by global policies and global rulesets. But it is an important tool that's missing in our toolbox. You could do most of the above, and still get pwned by a typo in an `npx` co
18.
▲
by
captn3m0
3mo ago
Package-level hooks are everywhere: https://github.com/ecosyste-ms/package-manager-hooks I wrote this in response to the recent AUR attacks. The problem isn’t really too many dependencies - it is that most users cannot
19.
▲
by
captn3m0
3mo ago
Aliases and pre-hooks are nowhere near the guarantees you want, that’s what I am arguing - not everything is invoked from a blessed shell. Safely-bump-does.sh is also impossibly hard to write because you are replicating _all of the work NPM
20.
▲
by
captn3m0
3mo ago
Author here - people are definitely looking at other places. This just happens to be where the attacks are, and gets disproportionate attention as a result. Do you have examples of campaigns that weren’t flagged? Everything except xz had a
21.
▲
by
captn3m0
3mo ago
`PreInstall` mainly. But `PreFetch/PreBuild` also for source-repositories, such as AUR helpers. homebrew doesn't support hooks as a system package manager: https://github.com/ecosyste-ms/package-manager-hooks
22.
▲
by
captn3m0
3mo ago
(Author here). I don’t really care _how and what you decide to do with it_, the post is about package managers giving users the ability to decide. Dependency Cooldowns can be implemented with global hooks, git-commit-signing checks can be i
23.
▲
by
captn3m0
3mo ago
(Author here). It isn’t a matter of pre-install hooks. I don’t want known malware on my system irrespective of whether it runs at install-time or not. Pre-install hooks are going away in NPM, but we will have code injected in index.js next.
24.
▲
by
captn3m0
3mo ago
Has anyone reversed their SDKs to run a swarm that captures enough traffic to see what requests are actually getting made?
25.
▲
by
captn3m0
3mo ago
You can route an encrypted video stream through a server, same as messages. Zoom supports this as well now. You can’t do fancy stuff like transcoding at the server to support an older client, but WhatsApp dropped support for non-e2e really-
26.
▲
by
captn3m0
3mo ago
There is also microformats.
27.
▲
by
captn3m0
3mo ago
This was published in April, and we are far from consensus on what is “varnish”. Lots of distributions are now packaging vinyl and calling it varnish, some are pointing to the varnish repo instead (Fedora, Homebrew). I’d left a comment last
28.
▲
by
captn3m0
3mo ago
> I don't think there exist a password manager that is explicitly designed for a compromised/hostile device. The crypto people tried this with hardware only password managers but they were too annoying. I have a halfway solutio
29.
▲
by
captn3m0
3mo ago
And as we can see from Australia, this doesn’t need a blockchain.
30.
▲
Oil prices fall on US-Iran agreement
(cnn.com)
3 points
by
captn3m0
3mo ago
|
2 comments
More ›