<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: 0x0</title><link>https://news.ycombinator.com/user?id=0x0</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 15 Jun 2026 12:03:18 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=0x0" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by 0x0 in "Dav2d"]]></title><description><![CDATA[
<p>Just recently noticed this got posted to deb-multimedia, although I think there is a typo in the package description....<p><a href="https://www.deb-multimedia.org/dists/unstable/main/binary-amd64/package/dav2d" rel="nofollow">https://www.deb-multimedia.org/dists/unstable/main/binary-am...</a><p>... it says "fast and small AV1 video stream decoder"<p>... should probably be "AV2" ?</p>
]]></description><pubDate>Sat, 02 May 2026 20:30:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=47990175</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=47990175</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47990175</guid></item><item><title><![CDATA[New comment by 0x0 in "Running Adobe's 1991 PostScript Interpreter in the Browser"]]></title><description><![CDATA[
<p>Details here: <a href="https://eclecticlight.co/2023/09/25/postscripts-sudden-death-in-sonoma/" rel="nofollow">https://eclecticlight.co/2023/09/25/postscripts-sudden-death...</a></p>
]]></description><pubDate>Fri, 01 May 2026 19:01:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=47978702</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=47978702</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47978702</guid></item><item><title><![CDATA[New comment by 0x0 in "Running Adobe's 1991 PostScript Interpreter in the Browser"]]></title><description><![CDATA[
<p>Such a shame that macOS lost all its built-in postscript support including Preview.app in recent versions :(</p>
]]></description><pubDate>Fri, 01 May 2026 17:29:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47977506</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=47977506</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47977506</guid></item><item><title><![CDATA[New comment by 0x0 in "For Linux kernel vulnerabilities, there is no heads-up to distributions"]]></title><description><![CDATA[
<p>I find it curious to call someone dropping a weaponized root exploit before major distros or even LTS kernel git branches have patches ready "good guys". This could have been handled with much more grace.</p>
]]></description><pubDate>Thu, 30 Apr 2026 22:19:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=47968993</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=47968993</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47968993</guid></item><item><title><![CDATA[New comment by 0x0 in "For Linux kernel vulnerabilities, there is no heads-up to distributions"]]></title><description><![CDATA[
<p>The disclosure doesn't appear very "full". Looks like this was slipped into mainline linux among dozens of other mostly-irrelevant "CVEs" with nobody highlighting the fact that it is in fact dirty-cow-on-steroids.<p><a href="https://x.com/spendergrsec/status/2049566830771970483" rel="nofollow">https://x.com/spendergrsec/status/2049566830771970483</a><p><a href="https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/" rel="nofollow">https://lore.kernel.org/linux-cve-announce/2026042214-CVE-20...</a><p>Or is everyone expected to upgrade and reboot every 48 hours for all eternity and just deal with potential regressions all the time?<p>I think this reflects poorly on the original reporters. If you have a weaponized 700-byte universal local root exploit script ready to go, perhaps you should coordinate with major distros for patches to be available before unleashing it on the world. No matter how "veteran" you are.</p>
]]></description><pubDate>Thu, 30 Apr 2026 19:49:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=47967367</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=47967367</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47967367</guid></item><item><title><![CDATA[New comment by 0x0 in "Copy Fail – CVE-2026-31431"]]></title><description><![CDATA[
<p>Dropping a public exploit on github before distros have patches available isn't very cool, or is that just how veterans roll these days?</p>
]]></description><pubDate>Wed, 29 Apr 2026 20:44:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=47954341</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=47954341</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47954341</guid></item><item><title><![CDATA[New comment by 0x0 in "21,864 Yugoslavian .yu domains"]]></title><description><![CDATA[
<p>Enumeration of the entire DNS space is not available in general, but it does appear that some TLDs offer complete zone files for legitimate research purposes, see for example <a href="https://czds.icann.org/help#zone-files" rel="nofollow">https://czds.icann.org/help#zone-files</a></p>
]]></description><pubDate>Fri, 27 Mar 2026 09:09:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47540481</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=47540481</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47540481</guid></item><item><title><![CDATA[New comment by 0x0 in "Dolphin Progress Release 2603"]]></title><description><![CDATA[
<p>The breakout engineering to exploit Dolphin has already happened, see for example:<p>* <a href="https://dougallj.wordpress.com/2016/11/13/exploiting-dolphin-part-1/" rel="nofollow">https://dougallj.wordpress.com/2016/11/13/exploiting-dolphin...</a><p>* <a href="https://gist.github.com/hthh/502ae16db55612f64d3966769a154c3e" rel="nofollow">https://gist.github.com/hthh/502ae16db55612f64d3966769a154c3...</a><p>* <a href="https://github.com/dolphin-emu/dolphin/pull/4447" rel="nofollow">https://github.com/dolphin-emu/dolphin/pull/4447</a></p>
]]></description><pubDate>Thu, 12 Mar 2026 15:56:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=47352689</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=47352689</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47352689</guid></item><item><title><![CDATA[New comment by 0x0 in "Don't use passkeys for encrypting user data"]]></title><description><![CDATA[
<p>> "they can't be provisioned by the website itself."<p>It's funny, we used to have a html tag that would exactly that: <keygen /></p>
]]></description><pubDate>Sat, 28 Feb 2026 11:18:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47193781</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=47193781</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47193781</guid></item><item><title><![CDATA[New comment by 0x0 in "10 Years of Let's Encrypt"]]></title><description><![CDATA[
<p>They were great in the beginning, and then when you issued a few more certs than they liked you were asked to pony up some $$$, and then when you did that and actually "verified" who you were on a personal international phone call, you got a grace, and then issued a few more, they decided they didn't like you so they would randomly reject your renewals close to the expiration date, and then they got bought out by some scummy foreign outfit which apparently caused the entire CA to be de-listed as untrustworthy in all major browsers. Quite the ride.<p>Also, the only website I've ever encountered that actually used the HTML <keygen> tag.</p>
]]></description><pubDate>Tue, 09 Dec 2025 20:44:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=46210387</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=46210387</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46210387</guid></item><item><title><![CDATA[New comment by 0x0 in "Sending DMARC reports is somewhat hazardous"]]></title><description><![CDATA[
<p>Same here, and the worst part is the duplicates appear to reuse the same Message-id, which confuses macOS Mail.app to no end :-/</p>
]]></description><pubDate>Wed, 03 Dec 2025 10:58:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=46133003</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=46133003</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46133003</guid></item><item><title><![CDATA[New comment by 0x0 in "Running Unsupported iOS on Deprecated Devices"]]></title><description><![CDATA[
<p>It's actually a requirement by app store connect to use a modern sdk for uploading binaries, and modern sdk versions will often raise the minimum supported ios version, so this is not always the developer's fault. See for example <a href="https://developer.apple.com/news/upcoming-requirements/?id=02212025a" rel="nofollow">https://developer.apple.com/news/upcoming-requirements/?id=0...</a></p>
]]></description><pubDate>Thu, 27 Nov 2025 06:18:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=46066288</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=46066288</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46066288</guid></item><item><title><![CDATA[New comment by 0x0 in "Apple will phase out Rosetta 2 in macOS 28"]]></title><description><![CDATA[
<p>I'm sure there's lots of x86_64 specific code in the macOS userland that is much more than just a recompile - things like safari/javascriptcore JIT, various quartz composer core animation graphics stack and video encoder decoder stack libraries, as well as various objective-c low level pointer tagging and message passing ABI shenanigans and so on. This is probably why 32bit intel mac app support was dropped pretty hard pretty fast, as the entire runtime and userland probably required a lot of upkeep. As just one example, 32bit intel objective-c had "fragile instance variables" which was a can of worms.</p>
]]></description><pubDate>Wed, 29 Oct 2025 10:03:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=45744744</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=45744744</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45744744</guid></item><item><title><![CDATA[New comment by 0x0 in "Apple will phase out Rosetta 2 in macOS 28"]]></title><description><![CDATA[
<p>I'm guessing they don't want to maintain and build and test x86_64 versions of all the macos libraries like Appkit and UIKit (including large changes like liquid glass) when they are no longer shipping x86_64 macOS versions. Which is not entirely unreasonable as I'm sure it takes a lot of effort to keep the whole ui library stack working properly on multiple archs.<p>Perhaps that's what they're hinting about with the note about a "subset of Rosetta". So maybe there is hope that the core x86_64 binary translator will stick around for things like VM and emulation of generic (linux? wine?) binaries, but they don't want to maintain a whole x86_64 macOS userspace going forward.<p>Space savings from not shipping fat binaries for everything will probably also be not insignificant. Or make room for a new fat binary for a future "arm64v2" :)</p>
]]></description><pubDate>Wed, 29 Oct 2025 07:14:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=45743608</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=45743608</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45743608</guid></item><item><title><![CDATA[Microsoft's Root Program and the 1.1.1.1 Certificate Slip]]></title><description><![CDATA[
<p>Article URL: <a href="https://unmitigatedrisk.com/?p=1092">https://unmitigatedrisk.com/?p=1092</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45127497">https://news.ycombinator.com/item?id=45127497</a></p>
<p>Points: 10</p>
<p># Comments: 1</p>
]]></description><pubDate>Thu, 04 Sep 2025 14:12:39 +0000</pubDate><link>https://unmitigatedrisk.com/?p=1092</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=45127497</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45127497</guid></item><item><title><![CDATA[New comment by 0x0 in "iOS 18.6.1 0-click RCE POC"]]></title><description><![CDATA[
<p>Surprised to see no patch available for watchOS, which can also receive images via iMessage. Not important enough to patch, or not vulnerable, or just not exploited in the wild yet?</p>
]]></description><pubDate>Tue, 26 Aug 2025 19:38:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=45031283</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=45031283</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45031283</guid></item><item><title><![CDATA[New comment by 0x0 in "Microsoft Edit"]]></title><description><![CDATA[
<p>I was hoping this would work over ssh in a macOS Terminal.app, but last I tried it was inserting all kinds of weird characters into the edited text files.<p>Windows ships an official OpenSSH server these days, but so far there haven't been any good official text editors that work over OpenSSH, as far as I know.<p>I've had to resort to "copy con output.txt" the few times I needed to put things into a text file over windows-opensshd...</p>
]]></description><pubDate>Wed, 25 Jun 2025 16:11:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=44378910</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=44378910</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44378910</guid></item><item><title><![CDATA[New comment by 0x0 in "Beating Google's kernelCTF PoW using AVX512"]]></title><description><![CDATA[
<p>If linux kernel security really is so bad that google had to add a proof-of-work to introduce a 4 second race for 0day submissions, I'm surprised they're ok with still using the Linux kernel as the base for Android.</p>
]]></description><pubDate>Fri, 30 May 2025 19:22:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=44139167</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=44139167</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44139167</guid></item><item><title><![CDATA[New comment by 0x0 in "Mozilla to shut down Pocket and Fakespot"]]></title><description><![CDATA[
<p>> Safari only exist on Apple devices<p>Webkit, at least, builds on a lot more platforms than you think. Take a look at <a href="https://build.webkit.org/#/builders" rel="nofollow">https://build.webkit.org/#/builders</a><p>I'm seeing at least three other <i>MAJOR</i> platforms:<p><pre><code>  • GTK-Linux-64-bit-Release-Build
  • PlayStation-Release-Build
  • Windows-64-bit-Release-Build</code></pre></p>
]]></description><pubDate>Thu, 22 May 2025 20:36:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=44066644</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=44066644</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44066644</guid></item><item><title><![CDATA[Microsoft Telnet Server MS-TNAP Authentication Bypass]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/gavz/hfwintelnet">https://github.com/gavz/hfwintelnet</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43837032">https://news.ycombinator.com/item?id=43837032</a></p>
<p>Points: 8</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 29 Apr 2025 19:35:03 +0000</pubDate><link>https://github.com/gavz/hfwintelnet</link><dc:creator>0x0</dc:creator><comments>https://news.ycombinator.com/item?id=43837032</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43837032</guid></item></channel></rss>