Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dunder_cat
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
dunder_cat
11d ago
This feels like a nitpick but it's important to mention anyway > Mullvad Browser uses them [ the DoH servers ] by default when you're not on Mullvad VPN, preventing your ISP from seeing the domains you visit. This is a half-tr
2.
▲
by
dunder_cat
17d ago
Yes, but the article (not to call you out - I just think it's a very important point!) points out that this type of throttling would not be effective: > Suddenly, the crawlers were coming from millions of random residential or mobil
3.
▲
by
dunder_cat
17d ago
I testified against the equivalent of this bill in my state. One of the things I mentioned is because of a non-trivial monetary fine per infraction [1], as someone who would potentially need to implement this, I would have no idea how to re
4.
▲
by
dunder_cat
3mo ago
I'm in that camp of has a dating app installed but have no partner so the is-my-partner-cheating admittedly doesn't resonate with me. I've had to do some of this fingerprinting myself before for non-data-selling reasons so a
5.
▲
by
dunder_cat
3mo ago
I like to always tell interns/new hires that I measure their productivity in the amount of questions they're asking (whether its to me, seeing them roam into people's cubes or in company chat systems). AI has changed that cal
6.
▲
by
dunder_cat
4mo ago
After CVE-2023-7028 (account takeover via password reset, IIRC you just had to add a semi-colon between the correct email and the attacker email and it'd email both) was exploited against my cluster, the boasting about fully-automated
7.
▲
by
dunder_cat
4mo ago
Also, meant to share some interesting readings. In the Kubernetes world, my RSS feed lit up with their blog post about user namespaces being generally available in k8s 1.36. They actually provided some example CVEs that wouldn't have b
8.
▲
by
dunder_cat
4mo ago
Your understanding is fine. In many environments, you can still do a lot of damage just by popping a shell and being able to access the database/sensitive environment variables/sensitive code. Getting to root would just be the ici
9.
▲
by
dunder_cat
4mo ago
Doesn't have to even be that advanced, people get conditioned to stuff like reCAPTCHA and friends & Cloudflare's interstitial landing page (when "I'm under attack" mode is on) and they won't bat an eye. Tha
10.
▲
by
dunder_cat
4mo ago
Is the QR code check mandatory and if not, is it the default? The bulletpoint as-is just says: > AI-resistant challenge: As we identify potentially fraudulent behavior from agents, we enable application providers to deter and mitigate ma
11.
▲
by
dunder_cat
5mo ago
A more direct source (possibly the original source?) I know of is a YouTube video entitled "LISA11 - Fork Yeah! The Rise and Development of illumos" which detailed how the Solaris operating system got freed from Oracle after the S
12.
▲
by
dunder_cat
5mo ago
Instagram needs to do this for Reels, too. I got quite addicted to these short-form videos during the pandemic and after I finished college things went immediately downhill once a lot of my mental activity could be somewhat "deferred&q
13.
▲
by
dunder_cat
5mo ago
Chiming in as well to say to the author when the victory lap here is over: please consider adding the RSS feed! I want to see whatever you do next, regardless of how long it takes.
14.
▲
by
dunder_cat
6mo ago
> Edit: This is going to have huge ramifications for the tech security industry as these systems will be able to break security systems as easily it solved the proof. The sooner the good guys, if there are any left, understand this the b
15.
▲
by
dunder_cat
7mo ago
I am curious, have you attempted to do this to any binary packed with commercial obfuscation/"virtualization" schemes (e.g. Orean's Themida/Code Virtualizer and VMProtect)?
16.
▲
by
dunder_cat
7mo ago
Seems to be down for me. https://web.archive.org/web/20260220192124/https://vmfunc.re...
17.
▲
by
dunder_cat
7mo ago
Ah good to know. My pi-hole actually was blocking the blog itself since the ublock site list made its way into one of the blocklists I use. But I've been just avoiding links as much as possible because I didn't want to contribute.
18.
▲
by
dunder_cat
7mo ago
https://news.ycombinator.com/item?id=46624740 has the earliest writeup that I know of. It was running it via a script and intentionally using cache busting techniques to try to increase load on the hosted wordpress infrastr
19.
▲
by
dunder_cat
7mo ago
One thing that is amusing about the prevalence of advanced anti-cheat in Windows gaming is it's actually causing said API/ABIs to undergo ossification. A good data point is the invention of Syscall User Dispatch^1 on Linux which w
20.
▲
by
dunder_cat
7mo ago
This exists although not in the traditional BOINC space, it's Archiveteam^1. I run two of their warrior^2 instances in my home k3s instance via the docker images. One of them is set to the "Team's choice" where it spends
21.
▲
Windows Notepad App Remote Code Execution Vulnerability
(msrc.microsoft.com)
23 points
by
dunder_cat
7mo ago
|
4 comments
22.
▲
by
dunder_cat
7mo ago
There's nothing new or original in a lot of things that get posted here. Reading about someone starting a journey provides an interesting catalyst for discussion. What they did right, what they did wrong, other things to try, or even j
23.
▲
by
dunder_cat
8mo ago
Related discussion (the actual project is mentioned in the issue): "Detour: Dynamic linking on Linux without Libc" https://news.ycombinator.com/item?id=45740241
24.
▲
by
dunder_cat
8mo ago
In theory, IPv6 Privacy Extensions ( https://datatracker.ietf.org/doc/html/rfc4941 ) could mitigate this. In practice, I imagine when you bind to `[::]:port`, that also means that the randomized addresses would work
25.
▲
by
dunder_cat
8mo ago
I'm glad I stumbled across this: life circumstances have allowed me go abroad for a trip the past two years. One thing I had forgotten about since the last trip were some of my group being unable to get one of the cheap prepaid data eS
26.
▲
by
dunder_cat
8mo ago
In the US, I really want the FCC to mandate that an ISP provides IPv6 connectivity in order to meet the criteria to be considered broadband (and access the subsidies related to that). Don't even care if the functionality is off by defa
27.
▲
by
dunder_cat
8mo ago
It occurred to me while reading the article that I could also just have checked the TLS cert. The cert I was given presents "Common Name tls.automattic.com". However, maybe someone will discover bgp.he.net via this :-)
28.
▲
by
dunder_cat
8mo ago
Hmm. If it is an attempt at DDoS attacks, it's probably not very fruitful: >$ resolvectl query gyrovague.com gyrovague.com: 192.0.78.25 -- link: eno1 192.0.78.24 -- lin
29.
▲
by
dunder_cat
2y ago
It seems to be about a GRE tunnel implementation too: From https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux... > The device stores IPv6 addresses that are used for encapsulation