<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Hizonner</title><link>https://news.ycombinator.com/user?id=Hizonner</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 09 May 2026 09:23:07 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Hizonner" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by Hizonner in "AI is breaking two vulnerability cultures"]]></title><description><![CDATA[
<p>> it'll become common/forced practice to pre-scan code.<p>You'd think.<p>But then you'd think people would do a lot of other things too. I hope, I guess.<p>The other danger is that "the cloud" may become even more overwhelmingly dominant. Which of course has its own large security costs.</p>
]]></description><pubDate>Fri, 08 May 2026 20:10:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=48068106</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48068106</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48068106</guid></item><item><title><![CDATA[New comment by Hizonner in "Ask HN: We just had an actual UUID v4 collision..."]]></title><description><![CDATA[
<p>> UUIDv4 is explicitly forbidden for a lot of high-assurance and high-reliability software systems for this reason.<p>Hmm. What do those systems do for cryptography? Just assume it won't work and not rely on it at all?</p>
]]></description><pubDate>Fri, 08 May 2026 20:04:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48068030</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48068030</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48068030</guid></item><item><title><![CDATA[New comment by Hizonner in "AI is breaking two vulnerability cultures"]]></title><description><![CDATA[
<p>> With skill, and usually not consistently and systematically.<p>How do you know? If the people who like to crow about vulnerabilities aren't doing it, it doesn't mean that the people who are actually in a position to <i>exploit</i> them systematically and effectively aren't doing it.<p>Those embargoes have always been dangerous, because they create a false sense of security. But, as you point out...<p>> With AI, anyone can do this to any software.<p>Yep. Even if it <i>hadn't</i> been true before, it's clear that <i>now</i> you just have to assume that everybody relevant will immediately recognize the security impact of any patch that gets published. That includes both bugs fixed and  bugs introduced.<p>... and as the AI gets better, you're going to have to assume that you don't even have to publish a patch. Or source code. Within <i>way</i> less time than it's going to take people to admit it and adjust, any vulnerability in any software <i>available for inspection</i> is going to be instant public knowledge. Or at least public among anybody who matters.</p>
]]></description><pubDate>Fri, 08 May 2026 19:53:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48067884</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48067884</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48067884</guid></item><item><title><![CDATA[New comment by Hizonner in "Ask HN: We just had an actual UUID v4 collision..."]]></title><description><![CDATA[
<p>It's a near certainty that something is badly wrong with the RNG, and, yes, probably in how it's seeded.<p>It's probably messing up the cryptography, too.</p>
]]></description><pubDate>Fri, 08 May 2026 13:57:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=48063213</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48063213</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48063213</guid></item><item><title><![CDATA[New comment by Hizonner in "Google Cloud fraud defense, the next evolution of reCAPTCHA"]]></title><description><![CDATA[
<p>> Uhm no the whole point of captchas is that it requires (or used to anyway) humans to solve them, thus limiting the rate to human speeds.<p>The CAPTCHA challenge page itself has to be served to a client that has not yet given any evidence that it's not a bot. It's just as expensive to serve the challenge page as it is to serve a cookie-setting page. Bots can infinitely retrieve the challenge page (and can also infinitely <i>try</i> to retrieve the underlying "authenticated" page, forcing you to process redirects).<p>The only reason it looks better to you is that a third party is serving the CAPTCHA. You could also have a third party serve the cookie-setting page.</p>
]]></description><pubDate>Thu, 07 May 2026 17:53:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48052536</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48052536</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48052536</guid></item><item><title><![CDATA[New comment by Hizonner in "Google Cloud fraud defense, the next evolution of reCAPTCHA"]]></title><description><![CDATA[
<p>How do you "determine" individual clients to show them CAPTCHAs? Yes, you can, and probably should, make some use of IP addresses, although that would work better if idiots hadn't polluted the Internet with quite so much NAT.<p>But you don't have to, and you definitely don't have to completely rely on it. Look for a cookie. If you don't see it, route the client through a page that sets it.<p>Yes, this is subject to flooding attacks... in exactly the same way that every CAPTCHA system is subject to flooding attacks. But it actually uses <i>fewer</i> resources per request than showing the CAPTCHA would.</p>
]]></description><pubDate>Thu, 07 May 2026 13:57:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48049541</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48049541</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48049541</guid></item><item><title><![CDATA[New comment by Hizonner in "Google Cloud fraud defense, the next evolution of reCAPTCHA"]]></title><description><![CDATA[
<p>Rate limit individual clients.</p>
]]></description><pubDate>Wed, 06 May 2026 22:14:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=48042609</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48042609</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48042609</guid></item><item><title><![CDATA[New comment by Hizonner in "Google Cloud fraud defense, the next evolution of reCAPTCHA"]]></title><description><![CDATA[
<p>Depends on your specific problem. Usually redesign your system not to need to care if the other end is a bot or not.</p>
]]></description><pubDate>Wed, 06 May 2026 21:52:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48042358</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48042358</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48042358</guid></item><item><title><![CDATA[New comment by Hizonner in "Google Cloud fraud defense, the next evolution of reCAPTCHA"]]></title><description><![CDATA[
<p>I'm not a heart surgery hobbyist, therefore I don't chop people's chests open, no matter who suggests it.</p>
]]></description><pubDate>Wed, 06 May 2026 21:35:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48042188</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48042188</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48042188</guid></item><item><title><![CDATA[New comment by Hizonner in "Google Cloud fraud defense, the next evolution of reCAPTCHA"]]></title><description><![CDATA[
<p>... which is why you'll get locked out if you happen to visit an unusual number of sites in a day.</p>
]]></description><pubDate>Wed, 06 May 2026 19:35:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48040643</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48040643</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48040643</guid></item><item><title><![CDATA[New comment by Hizonner in "Google Cloud fraud defense, the next evolution of reCAPTCHA"]]></title><description><![CDATA[
<p>... You... think... it would be a good thing.<p>Don't you...</p>
]]></description><pubDate>Wed, 06 May 2026 18:51:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=48040076</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48040076</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48040076</guid></item><item><title><![CDATA[New comment by Hizonner in "Google Cloud fraud defense, the next evolution of reCAPTCHA"]]></title><description><![CDATA[
<p>... or you'll need to stop using reCAPTCHA if you want to get any traffic on your Web site.<p>I know, people will slavishly knuckle under, but let me dream for a few minutes.</p>
]]></description><pubDate>Wed, 06 May 2026 18:48:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48040039</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48040039</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48040039</guid></item><item><title><![CDATA[New comment by Hizonner in "White House Considers Vetting A.I. Models Before They Are Released"]]></title><description><![CDATA[
<p>Um, I realize the Trump administration doesn't pay a lot of attention to what it does and does not have authority to do, but I'm having trouble imagining what they'd even <i>claim</i> their authority was...</p>
]]></description><pubDate>Mon, 04 May 2026 20:09:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48014292</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=48014292</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48014292</guid></item><item><title><![CDATA[New comment by Hizonner in "Firefox Has Integrated Brave's Adblock Engine"]]></title><description><![CDATA[
<p>Yep, but your typical Apple user is happy to blame everybody but themselves and Apple.</p>
]]></description><pubDate>Sat, 25 Apr 2026 14:05:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47901650</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=47901650</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47901650</guid></item><item><title><![CDATA[New comment by Hizonner in "Firefox Has Integrated Brave's Adblock Engine"]]></title><description><![CDATA[
<p>Reading comprehension is the defining feature of a good commenter.</p>
]]></description><pubDate>Sat, 25 Apr 2026 14:02:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=47901639</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=47901639</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47901639</guid></item><item><title><![CDATA[New comment by Hizonner in "It's time to reclaim the word "Palantir" for JRR Tolkien"]]></title><description><![CDATA[
<p>"Conservative" can mean a lot of things.
Tolkien didn't have anything particularly useful to contribute to politics and nobody should be using him as a guide to anything... but nonetheless there'd have been no limit to the layers of Tolkien's contempt for somebody like Peter Thiel.</p>
]]></description><pubDate>Thu, 23 Apr 2026 14:56:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=47876503</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=47876503</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47876503</guid></item><item><title><![CDATA[New comment by Hizonner in "Scammer used an AI-generated MAGA girl to grift men"]]></title><description><![CDATA[
<p>> It's really not clear to me how MAGA people getting scammed will encourage their world view,<p>Young MAGA-adjacent dumbass who can't get laid sees pretty girl spouting MAGA stuff, reads all her posts and follows her or whatever, The Algorithm(TM) feeds him more MAGA stuff and MAGA posters, his whole social and information environment becomes that much more MAGA. Works even if he knows from the beginning that she's AI, but just likes the eye candy.<p>> or that there's meaningful room for further embittering them.<p>Young dumbass who can't get laid sends money, doesn't get the engagement he wants and/or realizes she's AI, can't accept feeling stupid, further projects his problems onto everything and everybody outside of himself, seeks out material that enourages him to do that...</p>
]]></description><pubDate>Tue, 21 Apr 2026 19:00:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=47852983</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=47852983</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47852983</guid></item><item><title><![CDATA[New comment by Hizonner in "Scammer Used an AI-Generated MAGA Girl to Grift 'Super Dumb' Men"]]></title><description><![CDATA[
<p>How about empathy for the other people they'll make miserable if you encourage their worldview , and maybe the people they'll make miserable if you further embitter them?</p>
]]></description><pubDate>Tue, 21 Apr 2026 15:50:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=47850503</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=47850503</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47850503</guid></item><item><title><![CDATA[New comment by Hizonner in "NSA is using Anthropic's Mythos despite blacklist"]]></title><description><![CDATA[
<p>A few months of restricting access to people they think will actually <i>fix</i> problems is a big deal. Obviously only an idiot would think it could or should be kept under wraps forever.</p>
]]></description><pubDate>Mon, 20 Apr 2026 13:54:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47834400</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=47834400</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47834400</guid></item><item><title><![CDATA[New comment by Hizonner in "NSA is using Anthropic's Mythos despite blacklist"]]></title><description><![CDATA[
<p>> The whole artificial scarcity Anthropic created around Mythos / Glasswing is quite brilliant to be honest (I’m Not saying ethical, just brilliant). The commercial gains are one side of course.<p>You mean the obvious commercial <i>losses</i> caused by keeping an expensively created product effectively off the market altogether?<p>What the actual fuck is with people who come up with stuff like this?</p>
]]></description><pubDate>Mon, 20 Apr 2026 13:51:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47834344</link><dc:creator>Hizonner</dc:creator><comments>https://news.ycombinator.com/item?id=47834344</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47834344</guid></item></channel></rss>