Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
thomas34298
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
thomas34298
3mo ago
> reduce the risk of data exfiltration Yet, their tools such as codex are able to read ALL FILES on my PC without explicit permission unless you spawn them within a container: https://github.com/openai/codex/iss
2.
▲
by
thomas34298
5mo ago
Does that version of Codex still read sensitive data on your file system without even asking? Just curious. https://github.com/openai/codex/issues/2847
3.
▲
Codex reads files outside working directory without my permission
(github.com)
1 points
by
thomas34298
8mo ago
|
0 comments
4.
▲
by
thomas34298
10mo ago
That's the entire point of sandboxing, so none of what you listed would be accessible by default. Check out https://github.com/anthropic-experimental/sandbox-runtime and https://github.com/Zouuup&#
5.
▲
by
thomas34298
10mo ago
Codex can read any file on your PC without your explicit approval. Other agents like Claude Code would at least ask you or are sufficiently sandboxed.
6.
▲
Codex can read sensitive files outside the CWD without approval
1 points
by
thomas34298
10mo ago
|
0 comments
7.
▲
by
thomas34298
10mo ago
Interesting fact: Codex has access to all the files your current user has access to as well, even if you just opened it in the src directory.
8.
▲
Codex does not prevent reads outside the working directory
(github.com)
2 points
by
thomas34298
10mo ago
|
0 comments
9.
▲
Automated PDF Generation with Typst
(typst.app)
2 points
by
thomas34298
10mo ago
|
0 comments
10.
▲
Welcome to the next generation of Burp Suite: elevate your testing with Burp AI
(portswigger.net)
2 points
by
thomas34298
1y ago
|
0 comments
11.
▲
by
thomas34298
2y ago
Sam tweeted "taking care of my kid in the hospital": https://x.com/sama/status/1895210655944450446 Let's not assume that he's lying. Neither the presentation nor my short usage via the API blew
12.
▲
by
thomas34298
2y ago
Have you even tried it out locally and asked about those things?
13.
▲
by
thomas34298
2y ago
>BUGFIX: Don't ignore SSL errors (sledgehammer999) > https://www.qbittorrent.org/news There should be a security notice IMO.
14.
▲
by
thomas34298
2y ago
Changelog: https://typst.app/docs/changelog/0.12.0/
15.
▲
Typst 0.12
(typst.app)
19 points
by
thomas34298
2y ago
|
2 comments
16.
▲
by
thomas34298
2y ago
Recently, I decided to try out Claude for a month and bought the subscription right when mine for ChatGPT ended. However, after just a few days, I noticed how sluggish and inconvenient Claude feels on the web. Maybe it's partly because
17.
▲
by
thomas34298
2y ago
Most important changes starting November 1, 2024: - OSCP+ will replace regular OSCP with a three-year expiration (old lifetime certificates remain valid) - Removal of bonus points to improve fairness
18.
▲
Changes to the OSCP
(help.offsec.com)
3 points
by
thomas34298
2y ago
|
2 comments
19.
▲
Ask HN: Are there any decent LLM-based web application scanners?
1 points
by
thomas34298
2y ago
|
0 comments
20.
▲
by
thomas34298
2y ago
There is a lot of porn. X even added official rules for it: https://help.x.com/en/rules-and-policies/adult-content I don't have an iPhone, but I know that you can access it via the official app from Google Pl
21.
▲
by
thomas34298
2y ago
I think the same argument could be made for Twitter/X. The app stores by Google and Apple specifically disallow pornographic material, yet the app is full of it. Once you're big and important enough, the rules mostly don't ap
22.
▲
by
thomas34298
2y ago
Not everything revolves around scientific journals and their archaic rules. For my team Typst was a perfect LaTeX replacement and we've been happy ever since we switched. It is easier to understand, has faster compile times and is more
23.
▲
by
thomas34298
2y ago
FWIW there is already partial LaTeX support for Typst via the mitex package: https://github.com/mitex-rs/mitex
24.
▲
by
thomas34298
2y ago
I'd say a strict Content Security Policy (at least script-src 'self' WITHOUT unsafe directives) is even more important to keep the impact contained, so you'd have to put your scripts into separate files - as opposed to u
25.
▲
by
thomas34298
2y ago
Here is an example: https://www.wordfence.com/blog/2020/05/nearly-a-million-wp-s... That is what happens if you are the WP admin and think that you don't need to update your plugins because "it'
26.
▲
by
thomas34298
2y ago
>Unlike Telegram, Signal doesn’t allow researchers to make sure that their GitHub code is the same code that is used in the Signal app run on users’ iPhones. I remember Telegram not publishing their Android source code for extended perio
27.
▲
by
thomas34298
2y ago
JS in SVGs can be dangerous, but you can mitigate it using a CSP or by sending "Content-Disposition: attachment" so the file will be downloaded instead of being executed in your current browser context.
28.
▲
by
thomas34298
3y ago
>Open source models are uncensored and this is huge Vicuna-13B: I'm sorry, but I cannot generate an appropriate response to this prompt as it is inappropriate and goes against OpenAI's content policy.
29.
▲
by
thomas34298
3y ago
Somewhat related, I previously completed the form found in the help section titled "How your data is used to improve model performance" to opt out of providing training data to OpenAI: https://help.openai.com/en&#x