Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mtud
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
mtud
5mo ago
We’re splitting this across two threads, but if you give Codex access to jadx and the Archer android app you might be able to get something without that problem. The TPLink management protocol has a few different “transport” types - tmpcli
2.
▲
by
mtud
5mo ago
I had been trying to find that again! It was instrumental in some RE/VR I did last year on tmp and the differences between the UDP socket (available without auth) and the TCP socket. Thanks for making that. I can't remember the de
3.
▲
by
mtud
5mo ago
You should give codex access to the mobile app :) The app, for a lot of routers, connects via an ssh tunnel to UDP/TCP sockets on the router. Would probably give you access to more data/control.
4.
▲
Axios compromised on NPM – Malicious versions drop remote access trojan
(stepsecurity.io)
1934 points
by
mtud
6mo ago
|
807 comments
5.
▲
by
mtud
6mo ago
Supply chain woes continue
6.
▲
Hyrumrand – Golang random number generator based on random map iteration order
(github.com)
2 points
by
mtud
9mo ago
|
0 comments
7.
▲
by
mtud
10mo ago
Sure, but unlike the CRL checks the server gets to directly know how recently the client fetched the update if my understanding is correct. Knowing which landmarks the client has would likely give you a fairly precise picture of the update
8.
▲
by
mtud
11mo ago
The model file is small enough to have in Git (safetensors is only 600MB) but the Gemma TOS make me unsure if I’m required to have the same “Read and accept the Gemma TOS” limitation that they have on their public huggingface model. As for
9.
▲
Show HN: ShellAI – Local Terminal Assistance with SLM
(github.com)
5 points
by
mtud
11mo ago
|
3 comments
10.
▲
by
mtud
11mo ago
It can't possibly be updating continuously in real time, can it? Especially for battery devices, a constant background thread polling for updates seems untenable.
11.
▲
by
mtud
11mo ago
> During the TLS handshake, the client tells the server which treeheads it has. I don’t love the idea of giving every server I connect to via TLS the ability to fingerprint me by how recently (or not) I’ve fetched MTC treeheads. Even wor
12.
▲
by
mtud
11mo ago
Different machines will need to have variations in when they grab updates to avoid thundering herd problems. I could see the list of client-supplied available roots being added to client fingerprinting code for passive monitoring (e.g. JA4)
13.
▲
by
mtud
1y ago
You can generate short-lived and single-use credentials for users.
14.
▲
by
mtud
1y ago
Without TURN, two clients that want to do streaming communication connect directly to each other, letting both ends know things like IP addresses, supported protocols, and other fingerprintable features. This was the norm for a long time -
15.
▲
by
mtud
2y ago
The U.S. Naval Research Lab (NRL) has been deploying this tech - free space optics (FSO) - for about a decade. https://www.doncio.navy.mil/chips/ArticleDetails.aspx?ID=555...