<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Ansil849</title><link>https://news.ycombinator.com/user?id=Ansil849</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 25 Apr 2026 21:12:42 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Ansil849" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[The Other Players Who Helped Almost Make the Biggest Backdoor Hack]]></title><description><![CDATA[
<p>Article URL: <a href="https://theintercept.com/2024/04/03/linux-hack-xz-utils-backdoor/">https://theintercept.com/2024/04/03/linux-hack-xz-utils-backdoor/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=39925870">https://news.ycombinator.com/item?id=39925870</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Thu, 04 Apr 2024 02:23:10 +0000</pubDate><link>https://theintercept.com/2024/04/03/linux-hack-xz-utils-backdoor/</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=39925870</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39925870</guid></item><item><title><![CDATA['Wild West' of neuroscience drives new laws on brain privacy]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.context.news/ai/brain-privacy-at-stake-as-wild-west-neuroscience-drives-new-laws">https://www.context.news/ai/brain-privacy-at-stake-as-wild-west-neuroscience-drives-new-laws</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=39802381">https://news.ycombinator.com/item?id=39802381</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 23 Mar 2024 19:14:50 +0000</pubDate><link>https://www.context.news/ai/brain-privacy-at-stake-as-wild-west-neuroscience-drives-new-laws</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=39802381</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39802381</guid></item><item><title><![CDATA[Privacy or safety? U.S. brings 'surveillance city to the suburbs']]></title><description><![CDATA[
<p>Article URL: <a href="https://www.context.news/digital-rights/privacy-or-safety-us-brings-surveillance-city-to-the-suburbs">https://www.context.news/digital-rights/privacy-or-safety-us-brings-surveillance-city-to-the-suburbs</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=35905008">https://news.ycombinator.com/item?id=35905008</a></p>
<p>Points: 8</p>
<p># Comments: 1</p>
]]></description><pubDate>Thu, 11 May 2023 17:04:15 +0000</pubDate><link>https://www.context.news/digital-rights/privacy-or-safety-us-brings-surveillance-city-to-the-suburbs</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=35905008</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35905008</guid></item><item><title><![CDATA[New comment by Ansil849 in "Google Lets Anyone See Original Uncropped Images – Proof of Concept"]]></title><description><![CDATA[
<p>This was mentioned in the article from yesterday, <a href="https://theintercept.com/2023/02/14/whistleblower-image-crop-document/" rel="nofollow">https://theintercept.com/2023/02/14/whistleblower-image-crop...</a></p>
]]></description><pubDate>Wed, 15 Feb 2023 16:00:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=34805599</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=34805599</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34805599</guid></item><item><title><![CDATA[Google Lets Anyone See Original Uncropped Images – Proof of Concept]]></title><description><![CDATA[
<p>Article URL: <a href="https://docs.google.com/document/d/18YHtX3v6tiSTG4DwBvsGW6EJaOPBLmZ4LDU1Od83alg/edit">https://docs.google.com/document/d/18YHtX3v6tiSTG4DwBvsGW6EJaOPBLmZ4LDU1Od83alg/edit</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=34805339">https://news.ycombinator.com/item?id=34805339</a></p>
<p>Points: 3</p>
<p># Comments: 1</p>
]]></description><pubDate>Wed, 15 Feb 2023 15:46:51 +0000</pubDate><link>https://docs.google.com/document/d/18YHtX3v6tiSTG4DwBvsGW6EJaOPBLmZ4LDU1Od83alg/edit</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=34805339</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34805339</guid></item><item><title><![CDATA[New comment by Ansil849 in "The Ex-CIA Agents Deciding Facebook’s Content Policy"]]></title><description><![CDATA[
<p>>  It might stun you to learn that the US is part of the west and isn't blocking RT.<p>Golly gee, you sure got me there on that! Let's rephrase to "parts of the West", what impact does that have on the argument that Western powers engage in media censorship as well?<p>> I don't want to stun you too much, but the west is not some uniform block of countries.<p>LOL. You understand it is _literally_ called the "Western Bloc", right? <a href="https://en.wikipedia.org/wiki/Western_Bloc" rel="nofollow">https://en.wikipedia.org/wiki/Western_Bloc</a></p>
]]></description><pubDate>Fri, 22 Jul 2022 15:59:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=32193467</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32193467</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32193467</guid></item><item><title><![CDATA[New comment by Ansil849 in "The Ex-CIA Agents Deciding Facebook’s Content Policy"]]></title><description><![CDATA[
<p>>  I'm in the US<p>That's great. The block is in the EU. Which is in...the West.</p>
]]></description><pubDate>Fri, 22 Jul 2022 15:59:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=32193451</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32193451</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32193451</guid></item><item><title><![CDATA[New comment by Ansil849 in "The Ex-CIA Agents Deciding Facebook’s Content Policy"]]></title><description><![CDATA[
<p>Sure:<p>RT- Russia Today English<p>RT- Russia Today UK<p>RT - Russia Today Germany<p>RT - Russia Today France<p>RT- Russia Today Spanish<p>Sputnik’<p>Source: <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L:2022:065:FULL&from=EN" rel="nofollow">https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L...</a><p>Or here's a mass media summary if you don't want to read the official documentation: <a href="https://www.reuters.com/world/europe/eu-bans-rt-sputnik-banned-over-ukraine-disinformation-2022-03-02/" rel="nofollow">https://www.reuters.com/world/europe/eu-bans-rt-sputnik-bann...</a></p>
]]></description><pubDate>Fri, 22 Jul 2022 15:48:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=32193275</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32193275</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32193275</guid></item><item><title><![CDATA[New comment by Ansil849 in "The Ex-CIA Agents Deciding Facebook’s Content Policy"]]></title><description><![CDATA[
<p>I'm so tired of "whataboutism" being used to as some attempt to shut down an argument. It is perfectly valid to point out hypocritical arguments. And it might stun you to know that the West isn't solely composed of the US. Try going to RT from the EU - <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L:2022:065:FULL&from=EN" rel="nofollow">https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L...</a><p>Take special note not just of the block, but of the anticircumvention provisions.</p>
]]></description><pubDate>Fri, 22 Jul 2022 15:42:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=32193186</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32193186</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32193186</guid></item><item><title><![CDATA[New comment by Ansil849 in "The Ex-CIA Agents Deciding Facebook’s Content Policy"]]></title><description><![CDATA[
<p>> The great firewall of China prevents most of their citizens from seeing news that isn’t the party line<p>Totally not like how access to Russian news outlets has been blocked by parts of the West.</p>
]]></description><pubDate>Fri, 22 Jul 2022 15:27:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=32193013</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32193013</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32193013</guid></item><item><title><![CDATA[New comment by Ansil849 in "The Ex-CIA Agents Deciding Facebook’s Content Policy"]]></title><description><![CDATA[
<p>You should not. But if it makes you feel any better, Americans do the same thing by allowing Chinese tech like Zoom and TikTok operate in their country.</p>
]]></description><pubDate>Fri, 22 Jul 2022 15:26:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=32192985</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32192985</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32192985</guid></item><item><title><![CDATA[New comment by Ansil849 in "Analyzing iOS 16 Lockdown Mode: Browser Features and Performance"]]></title><description><![CDATA[
<p>Lockdown is literally presented by Apple as being for people targeted by APTs like those developed by NSO Group, therefore I expect it to prevent attack vectors used by these APTs, like exploitation of the Developer program to facilitate sideloading malicious apps. I don't feel like this is an unrealistic expectation, and not having the mode actually do that amounts to security theater, which is a far cry from decrying everything as such.</p>
]]></description><pubDate>Thu, 21 Jul 2022 11:52:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=32178259</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32178259</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32178259</guid></item><item><title><![CDATA[New comment by Ansil849 in "Analyzing iOS 16 Lockdown Mode: Browser Features and Performance"]]></title><description><![CDATA[
<p>> "What constitutes an enterprise that should be allowed to have 'enterprise apps'"<p>Apple has a list of requirements - <a href="https://developer.apple.com/programs/enterprise/" rel="nofollow">https://developer.apple.com/programs/enterprise/</a> - for example, a company needs to have at least 100 employees. The issue, however, seems to be how stringently these requirements are enforced, or whether they are at all. In the case of Hermit, the Italian spyware company seems to have created a fake company and tricked Apple into granting the fake company access to the developer program. Now, the interesting question for me is whether the fake company actually managed to pass all of the requirements, like giving Apple a list of 100 fake employees, and whether Apple actually performed their due dilligence and checked whether the employee list was real, or whether they accepted it at face value, or didn't even require it.<p>In other words, I think a key takeaway from the latest incident is Apple needs to take accountability and harden their Enterprise program entry requirements, and I haven't seen anything about that being the case.</p>
]]></description><pubDate>Thu, 21 Jul 2022 11:39:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=32178169</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32178169</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32178169</guid></item><item><title><![CDATA[New comment by Ansil849 in "Analyzing iOS 16 Lockdown Mode: Browser Features and Performance"]]></title><description><![CDATA[
<p>> Running an enterprise app still is not a trivial single tap on iOS.<p>Yes, but still successful, as Hermit demonstrated. So my question is whether Lockdown mode would have prevented APTs like Hermit which it claims to prevent against. If not, then the move is security theater which doesn't address the actual flaws (like poor vetting into the Enterprise Program) being successfully leveraged in the wild.</p>
]]></description><pubDate>Thu, 21 Jul 2022 11:27:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=32178087</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32178087</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32178087</guid></item><item><title><![CDATA[New comment by Ansil849 in "Analyzing iOS 16 Lockdown Mode: Browser Features and Performance"]]></title><description><![CDATA[
<p>> High-level targets (for whom this mode is specifically advertised) are likely aware of the dangers of installing apps.<p>I firstly don't believe this is true at all, plenty of high-level targets are not tech savvy; but more to the point of Lockdown mode, you could then say the same thing about most of its other features ("High-level targets are likely to already be aware of the dangers of doing $thing_Lockdown_prevents").</p>
]]></description><pubDate>Thu, 21 Jul 2022 11:15:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=32177991</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32177991</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32177991</guid></item><item><title><![CDATA[New comment by Ansil849 in "Analyzing iOS 16 Lockdown Mode: Browser Features and Performance"]]></title><description><![CDATA[
<p>> So this would have prevented Hermit as you'd need to install a new configuration profile to allow sideloading of applications from that source.<p>Are you sure that's true? I haven't seen a Hermit sample firsthand, but from everything I've read about it targets did not need to install an MDM profile, they simply needed to click a link. Looking at Apple's distribution guidelines - <a href="https://support.apple.com/en-bw/guide/deployment/depce7cefc4d/web" rel="nofollow">https://support.apple.com/en-bw/guide/deployment/depce7cefc4...</a> - MDM is listed as one option, and simply going to a link is listed as another:<p>> There are two ways you can distribute proprietary in-house apps:
> 
> Using MDM
> 
> Using a website<p>It seems like the latter was used, so I don't think installation of a custom profile was required, which brings me back to my original question of whether Lockdown would have prevented it.</p>
]]></description><pubDate>Thu, 21 Jul 2022 11:11:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=32177966</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32177966</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32177966</guid></item><item><title><![CDATA[New comment by Ansil849 in "Analyzing iOS 16 Lockdown Mode: Browser Features and Performance"]]></title><description><![CDATA[
<p>It's not clear to me if Lockdown Mode would have prevented Hermit, the latest mobile APT which targeted iOS via sideloading by enrolling in the Apple Developer Enterprise Program.<p>The list of lockdown features don't seem to explicitly list that in-house app sideloading is disabled - is it? If not, then this mode seems like security theater from Apple, in that it doesn't actually lock down the parts of the attack surface that are actively being leveraged. How about instead, or better yet alongside this, Apple explains how they granted entry in the Enterprise program to the spyware company, and what measures they're taking to prevent it from happening again.</p>
]]></description><pubDate>Thu, 21 Jul 2022 10:58:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=32177866</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32177866</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32177866</guid></item><item><title><![CDATA[New comment by Ansil849 in "Visa changes chargeback dispute program"]]></title><description><![CDATA[
<p>Wanted to say thank you everybody for your nuanced responses, this has helped me understand the issue better.</p>
]]></description><pubDate>Thu, 21 Jul 2022 10:54:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=32177835</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32177835</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32177835</guid></item><item><title><![CDATA[New comment by Ansil849 in "Visa changes chargeback dispute program"]]></title><description><![CDATA[
<p>> You can't take back someone's education<p>Sure you could, you could rescind someone's diploma so that they no longer have the degree.</p>
]]></description><pubDate>Thu, 21 Jul 2022 00:04:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=32174114</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32174114</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32174114</guid></item><item><title><![CDATA[New comment by Ansil849 in "Visa changes chargeback dispute program"]]></title><description><![CDATA[
<p>> How failure to generate income on their degrees is a lender's problem? Clearly,there is an issue with inflated costs of getting a degree and finding a job with a low-demand degree, but why try solving it at the lender's expense?<p>Yeah, I've never really understood this logic either. If someone lends money from me to, let's say go buy a tow truck, and then is not able to repay the loan because there are too many other folks with tow trucks (or for whatever other reason), why should that be my problem? I gave money with the expectation that it would be paid back. That is by definition what lending is, yet student loans are somehow touted as an exception where repayment shouldn't be seen as compulsory.</p>
]]></description><pubDate>Wed, 20 Jul 2022 23:47:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=32173965</link><dc:creator>Ansil849</dc:creator><comments>https://news.ycombinator.com/item?id=32173965</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32173965</guid></item></channel></rss>