Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jerrythegerbil
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
1.
▲
by
jerrythegerbil
23d ago
As someone who uses NCD nearly every day, I have concerns about how it’s been used here. But while we’re “guessing”: Xiaomi MiMO
2.
▲
Agentic AI in a Smolbox
(remyhax.xyz)
3 points
by
jerrythegerbil
1mo ago
|
1 comments
3.
▲
by
jerrythegerbil
1mo ago
The LLMs play a part, but it’s the tempo; the pace. Fully autonomous w/LLM isn’t true. Leadership wants it true. The technological capabilities and acceptance of scapegoating a machine got rejected by society, so that leaves perfectly
4.
▲
by
jerrythegerbil
2mo ago
An ssh server would exploit a vulnerability in the ssh client when it connects. For example, openssh has both a client and server. There’s been vulnerabilities in openssh, in the client. Those vulnerabilities aren’t reachable unless you’re
5.
▲
by
jerrythegerbil
2mo ago
This AI generated article about closed-weights model providers collaborating for additional scrutiny of open weights models, where the article itself has the tell-tale structure of being written by Claude Opus, which is aware it is a closed
6.
▲
by
jerrythegerbil
2mo ago
“However, large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable.” What’s actually happening behind the scenes is that certain inference providers will cla
7.
▲
by
jerrythegerbil
2mo ago
A datacenter was built a couple hundred feet from my apartment complex around 2013-2014. Absolutely none of your comment would have even remotely held true at the time, and my family moved away as a direct result. Assuming positive intent,
8.
▲
by
jerrythegerbil
2mo ago
“Pre-Authentication” and “Unauthenticated” are meaningfully different things, and for the purposes of marketing reach you always want to push for “Unauthenticated” if possible. Typically Pre-Authenticated means knowing some additional conte
9.
▲
by
jerrythegerbil
2mo ago
https://dnschecker.org/#A/motherless.com
10.
▲
by
jerrythegerbil
3mo ago
MKULTRA was about using drugs to alter state and produce uninhibited truthfulness. Social media has a direct impact on dopamine and uninhibited oversharing. The mechanism isn’t even ambiguous, which is exactly why there’s a case, about the
11.
▲
by
jerrythegerbil
3mo ago
> Gates that reduce resume flow-through are only useful if their reduction is correlated with quality. The volume is infeasible to review everyone for quality, even at an hour scale. The conclusion and solution is inevitable, though I wi
12.
▲
by
jerrythegerbil
3mo ago
> I fail 65% of the time. Same exact resume, different luck. As someone who’s run hiring pipelines for technical roles in the past few years, that’s actually a fantastic number. I objectively hate saying that, but it’s true. 35% chance o
13.
▲
by
jerrythegerbil
3mo ago
Vulnerability reports were never special. The _demonstration_ of security impact through vulnerability reports was special. The automation of “demonstration of impact” with AI isn’t that at all. The last mile is human and always was. This i
14.
▲
by
jerrythegerbil
3mo ago
Model X is available for inference from both company Y (which created the model) and company Z (who actually provides part of the inference capacity for company Y anyways). Company Z and company Y have invested heavily in each other, but co
15.
▲
by
jerrythegerbil
3mo ago
“Zero-Click RCE” This appears to require attacker controlled data already being written to a settings XML file in specific locations on disk. Put simply, this requires another prerequisite arbitrary file write vulnerability to be reachable.
16.
▲
by
jerrythegerbil
3mo ago
Glasswing and Mythos are wildly impressive. The team writing about it has a core charter to publish research about how AI will be disruptive to certain industries. The publication of such research is the disruption. What remains when you st
17.
▲
by
jerrythegerbil
4mo ago
Yes. When certain keywords are matched or topics, there is a warning transparently injected server side appended to the system prompt of the convo that’s miles long. It is injected and reevaluated every tool call. If you begin a generic rev
18.
▲
by
jerrythegerbil
4mo ago
Parallel Construction is a term: https://en.wikipedia.org/wiki/Parallel_construction Parallel *Re*construction is a play on words I wrote related to a lot of the nuance at play I wasn’t able to cover in the blog withou
19.
▲
by
jerrythegerbil
4mo ago
Certificate transparency worked exactly as designed in this case. Monitoring public certificate transparency logs for anomalies is a different story entirely. By breaking the software facilitating https via ACME itself, no anomalous certifi
20.
▲
by
jerrythegerbil
4mo ago
The sloppy ones who want a huge headache and leave a publicly auditable trail a mile long that get analysis blogs written about their mistakes.
21.
▲
Parallel Reconstruction of Lawful TLS Wiretapping
(remyhax.xyz)
136 points
by
jerrythegerbil
4mo ago
|
77 comments
22.
▲
by
jerrythegerbil
4mo ago
It you’re seeking something a bit older and battle tested ttyd is a good comparison: https://github.com/tsl0922/ttyd
23.
▲
by
jerrythegerbil
4mo ago
This blog was written by AI.
24.
▲
by
jerrythegerbil
4mo ago
Laundering of CC/Trial Accounts/Enterprise LLM inference is already a HUGE market, leveraged in part for distillation attacks on western AI. A whole country’s worth of accounts just got access to a service we know is being launder
25.
▲
by
jerrythegerbil
4mo ago
It’s so we all read the same version. AI vuln hype cycle in full effect, changes are made, deliberately.
26.
▲
by
jerrythegerbil
4mo ago
Pretty sure the article explicitly stated the resentment is due to their clearly stated concerns continually being explained away. Was your intention to be an example for resentment? Or are you an AI model demonstrating the embodiment of de
27.
▲
by
jerrythegerbil
4mo ago
Is that number of crashing bugs with PoC available/written down anywhere?
28.
▲
by
jerrythegerbil
4mo ago
Again, and this is important: A bug is a bug. A “potential vulnerability” is a bug. A vulnerability is verifiable as having security implications with a proof of concept or other substantial evidence. Words matter. Bugs matter. It’s importa
29.
▲
by
jerrythegerbil
5mo ago
I can assure you they’ve correctly described the problem and are correct regarding buffering and user gesture requirements. The platforms you listed are all primarily text-based and the interaction lives in the DOM with happy paths defined.
30.
▲
by
jerrythegerbil
5mo ago
https://archive.ph/j9nGv When a new software fuzzer with thorough orchestration appears, there’s a flood of bugs discovered and a lot of excitement. The excitement is always well deserved, but it doesn’t change the fact tha
More ›