<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Deathcrow</title><link>https://news.ycombinator.com/user?id=Deathcrow</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 10 May 2026 08:43:04 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Deathcrow" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by Deathcrow in "XZ backdoor: "It's RCE, not auth bypass, and gated/unreplayable.""]]></title><description><![CDATA[
<p>This is only correct if the sshd backdoor is the only malicious code introduced into the library.</p>
]]></description><pubDate>Sun, 31 Mar 2024 06:47:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=39881998</link><dc:creator>Deathcrow</dc:creator><comments>https://news.ycombinator.com/item?id=39881998</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39881998</guid></item><item><title><![CDATA[New comment by Deathcrow in "XZ backdoor: "It's RCE, not auth bypass, and gated/unreplayable.""]]></title><description><![CDATA[
<p>Is there really a failed login attempts? If it never calls the real functions of ssh in case of their own cert+payload why would sshd log anything or even register a login attempt? Or does the backdoor function hook in after sshd already logged stuff?</p>
]]></description><pubDate>Sun, 31 Mar 2024 06:13:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=39881865</link><dc:creator>Deathcrow</dc:creator><comments>https://news.ycombinator.com/item?id=39881865</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39881865</guid></item><item><title><![CDATA[New comment by Deathcrow in "XZ backdoor: "It's RCE, not auth bypass, and gated/unreplayable.""]]></title><description><![CDATA[
<p>Also, in a more optimistic scenario without sockpuppets, it's unlikely that malicious and underhanded contributions will be caught by anyone that isn't a security researcher.</p>
]]></description><pubDate>Sun, 31 Mar 2024 05:59:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=39881822</link><dc:creator>Deathcrow</dc:creator><comments>https://news.ycombinator.com/item?id=39881822</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39881822</guid></item><item><title><![CDATA[New comment by Deathcrow in "XZ backdoor: "It's RCE, not auth bypass, and gated/unreplayable.""]]></title><description><![CDATA[
<p>>A very tight SELinux policy could catch sshd executing something that ain’t a shell but hardening to that degree would be extremely rare I assume.<p>Huh, ssh executes things that aren't shells all the time during normal operation. No? i.e. 'ssh myserver.lan cat /etc/fstab'</p>
]]></description><pubDate>Sun, 31 Mar 2024 05:51:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=39881789</link><dc:creator>Deathcrow</dc:creator><comments>https://news.ycombinator.com/item?id=39881789</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39881789</guid></item><item><title><![CDATA[New comment by Deathcrow in "Everything authenticated by Microsoft is tainted"]]></title><description><![CDATA[
<p>no one can do what you suggest. it's nonsense.</p>
]]></description><pubDate>Fri, 29 Sep 2023 17:40:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=37707671</link><dc:creator>Deathcrow</dc:creator><comments>https://news.ycombinator.com/item?id=37707671</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37707671</guid></item><item><title><![CDATA[New comment by Deathcrow in "Patch OpenSSL on November 1 to avoid “critical” security vulnerability"]]></title><description><![CDATA[
<p>companies that abuse on call duty for planned maintenance suck. If it's something predictable or plannable, it's not on call. Hire people to work that day.</p>
]]></description><pubDate>Sat, 29 Oct 2022 17:24:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=33386126</link><dc:creator>Deathcrow</dc:creator><comments>https://news.ycombinator.com/item?id=33386126</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33386126</guid></item><item><title><![CDATA[New comment by Deathcrow in "Kiwi Farms is down across all domains as DDoS-Guard terminates service"]]></title><description><![CDATA[
<p>Facebook has probably killed more people with face detection and name tagging in photos alone.</p>
]]></description><pubDate>Mon, 05 Sep 2022 18:49:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=32727770</link><dc:creator>Deathcrow</dc:creator><comments>https://news.ycombinator.com/item?id=32727770</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32727770</guid></item><item><title><![CDATA[New comment by Deathcrow in "Blocking Kiwifarms"]]></title><description><![CDATA[
<p>>Is this real? I'm having trouble believing this shit.<p>Yes it's real and if you think making and distributing homemade hormones to children is vile and dangerous, you're apparently a transphobe nowadays.</p>
]]></description><pubDate>Sun, 04 Sep 2022 14:52:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=32713699</link><dc:creator>Deathcrow</dc:creator><comments>https://news.ycombinator.com/item?id=32713699</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32713699</guid></item><item><title><![CDATA[New comment by Deathcrow in "Google Search Is Dying"]]></title><description><![CDATA[
<p>Yup. IMHO spam has become so good at mimicking genuine content, it's hard to recognize even for a human curator. There's so many websites in the top google results that I'm sure are entirely AI generated, which exist for the sole purpose to propagate affiliate links and ads.</p>
]]></description><pubDate>Tue, 15 Feb 2022 21:06:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=30352720</link><dc:creator>Deathcrow</dc:creator><comments>https://news.ycombinator.com/item?id=30352720</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30352720</guid></item><item><title><![CDATA[New comment by Deathcrow in "Game dev: Linux users were only 0.1% of sales but 20% of crashes and tickets"]]></title><description><![CDATA[
<p>I'm sure those statistics are entirely real and not pulled out of his ass at all.<p>Also didn't Planetary Annihilation have that awful chromium based UI?</p>
]]></description><pubDate>Mon, 07 Jan 2019 16:31:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=18846588</link><dc:creator>Deathcrow</dc:creator><comments>https://news.ycombinator.com/item?id=18846588</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=18846588</guid></item></channel></rss>