<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Allwinkt</title><link>https://news.ycombinator.com/user?id=Allwinkt</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 31 Aug 2026 08:13:31 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Allwinkt" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by Allwinkt in "Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel"]]></title><description><![CDATA[
<p>The worst part is that in 2020 they explicitly documented that the remote filename is attacker controlled,but still allowed it to reach system()
This is C security 101: never pass untrusted input through a shell. This should have been caught in the review!</p>
]]></description><pubDate>Sun, 30 Aug 2026 12:09:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49497982</link><dc:creator>Allwinkt</dc:creator><comments>https://news.ycombinator.com/item?id=49497982</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49497982</guid></item><item><title><![CDATA[New comment by Allwinkt in "Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel"]]></title><description><![CDATA[
<p>The worst part is that in 2020 they explicitly documented that the remote filename is attacker controlled,but still allowed it to reach system()
That is C security 101: never pass untrusted input through a shell. This should have been caught in review!</p>
]]></description><pubDate>Sun, 30 Aug 2026 12:08:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=49497970</link><dc:creator>Allwinkt</dc:creator><comments>https://news.ycombinator.com/item?id=49497970</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49497970</guid></item></channel></rss>