Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lucasluitjes
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
When Background AI Agents Become a Security Boundary Problem
(originhq.com)
2 points
by
lucasluitjes
4mo ago
|
0 comments
2.
▲
LeakyLM: AI Assistants Are Leaking Your Conversations
(leakylm.github.io)
1 points
by
lucasluitjes
4mo ago
|
1 comments
3.
▲
Show HN: testing Ansible playbooks *fast*
(github.com)
2 points
by
lucasluitjes
6mo ago
|
0 comments
4.
▲
by
lucasluitjes
6mo ago
The ones mentioned in this thread all use Kiwix for off-line wikipedia, OSM for maps, Khan for educational videos. It looks like internet-in-a-box is aimed at working well on low-powered devices, whereas nomad expects beefy hardware and inc
5.
▲
by
lucasluitjes
6mo ago
The full report can be found here: https://services.google.com/fh/files/misc/2025_state_of_ai_a... That 17% increase is in self-reported effectiveness. The software delivery throughput only went up 3%, at a c
6.
▲
by
lucasluitjes
7mo ago
I've been annoyed with Google search quality lately and was wondering how the others fared on this specific issue. Turns out, mostly not much better. Bing, DuckDuckGo, Qwant, Ecosia, Brave all had the github repo and nanoclaw.net (the
7.
▲
by
lucasluitjes
8mo ago
Agree with all of that, especially modern supply chain risk (imho the more important reason to opt for VM isolation rather than containerization). But the original article specifically talks Vagrant as an isolation solution, and describes i
8.
▲
by
lucasluitjes
8mo ago
It's the default behaviour for Vagrant. You put a Vagrantfile in your repo, run `vagrant up` and it creates a VM with the repo folder shared r+w to `/vagrant` in the VM.
9.
▲
by
lucasluitjes
8mo ago
> What you’re NOT protecting against: > a malicious AI trying to escape the VM (VM escape vulnerabilities exist, but they’re rare and require deliberate exploitation) No VM escape vulns necessary. A malicious AI could just add arbitra
10.
▲
by
lucasluitjes
9mo ago
Location: The Netherlands. I'm flexible with working hours, I usually work with clients from either Western Europe or the USA. Remote: Yes Willing to relocate: No, but willing to travel/visit Technologies: especially Ru
11.
▲
by
lucasluitjes
11mo ago
This. If you were writing a script to mass-scan the web for vulnerabilities, you would want to collect as many http endpoints as possible. JS files, regardless of whether they're commented out or not, are a great way to find endpoints
12.
▲
by
lucasluitjes
11mo ago
GrapheneOS is basically the Android equivalent of iOS Lockdown mode. Considering how the threat landscape has changed, it would be nice if Google offered this itself. Or became a long-term sponsor of GrapheneOS, seeing how great a job they&
13.
▲
by
lucasluitjes
1y ago
SEEKING WORK | REMOTE | Dev, DevOps, Security | Location: The Netherlands Willing to relocate: no, but willing to travel/visit. I'm flexible with working hours, I usually work with clients from either Western Europe or the USA. I
14.
▲
by
lucasluitjes
1y ago
TLDR: they wrapped prompts with concepts from Buddhism and got better performance on alignment tests. Actual prompts are in appendix D in this PDF: https://osf.io/az59t I'm curious what effects you would see with secul
15.
▲
Contemplative Artificial Intelligence
(arxiv.org)
3 points
by
lucasluitjes
1y ago
|
2 comments
16.
▲
by
lucasluitjes
1y ago
SEEKING WORK | REMOTE | Dev, DevOps, Security | Location: The Netherlands Willing to relocate: no, but willing to travel/visit. I'm flexible with working hours, I usually work with clients from either Western Europe or the USA. I
17.
▲
by
lucasluitjes
1y ago
> I have recently written security-sensitive code using Opus 4. I of course reviewed every line and made lots of both manual and prompt-based revisions. > Cloudflare apparently did something similar recently. Sure, LLMs don't mag
18.
▲
by
lucasluitjes
1y ago
I've seen LLMs generate plenty of wildly insecure code, but the percentage of insecure solutions out of the solutions that are functional, is even higher than I expected. Also, I'm curious how the average coder would fare on this
19.
▲
by
lucasluitjes
1y ago
Hardcoded API keys and poorly secured backend endpoints are surprisingly common in mobile apps. Sort of like how common XSS/SQLi used to be in webapps. Decompiling an APK seems to be a slightly higher barrier than opening up devtools,
20.
▲
by
lucasluitjes
1y ago
Ironically if you wanted to build that accurately and quickly, you would probably end up having an LLM classify content as being LLM-related or not. Keyword-based filtering would have many false positives, and training a model takes more ti
21.
▲
First fully 3D-printed microscope including lense
(strath.ac.uk)
2 points
by
lucasluitjes
2y ago
|
0 comments
22.
▲
by
lucasluitjes
2y ago
SEEKING WORK | REMOTE | Dev, DevOps, Security | Location: The Netherlands Willing to relocate: no, but willing to travel/visit. I'm flexible with working hours, I usually work with clients from either Western Europe or the USA. I
23.
▲
by
lucasluitjes
2y ago
Here you go: javascript:(function(){window.scrollTo({top:0,behavior:'smooth'});})();
24.
▲
by
lucasluitjes
2y ago
That is amazing research! Reminds me a bit of the 2017 research of RCE on a DNA sequencing machine by synthesizing shellcode in actual DNA/RNA molecules [0]. I was gonna say "next up: OSC" but I guess MIDI is still dominant.
25.
▲
by
lucasluitjes
2y ago
SEEKING WORK | REMOTE | Dev, DevOps, Security | Location: The Netherlands Willing to relocate: no, but willing to travel/visit. I'm flexible with working hours, I usually work with clients from either Western Europe or the USA. I
26.
▲
by
lucasluitjes
2y ago
I wonder: do mail servers determine the received timestamp based on when the connection was opened or when the last character was received? I guess OP could send them an unrelated question using this technique, and check in the reply what t
27.
▲
by
lucasluitjes
2y ago
If you want to beat other romantically inclined geeks running scripts, you could make sure your script is running somewhere with low latency to that static IP. Use traceroute, looking glass, tools to ping from multiple regions to find the p
28.
▲
by
lucasluitjes
2y ago
Cool! Skip to 2m18s in the video if you're just curious about what the AI summarization looks like, and how it handles comment threading. Any plans for a firefox version?
29.
▲
by
lucasluitjes
2y ago
But finally there is dark-mode! I'll take any number of blue round buttons if I don't have to stare at a white background anymore.
30.
▲
by
lucasluitjes
2y ago
My comment history is short if you're curious about the comment itself. But in general for writing sales copy, I found The Copywriter's Handbook by Robert Bly very helpful, especially the first five chapters. Some of it can seem a
More ›