<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Magicstatic</title><link>https://news.ycombinator.com/user?id=Magicstatic</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 03 May 2026 08:30:42 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Magicstatic" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Android Goes All-In on Fuzzing]]></title><description><![CDATA[
<p>Article URL: <a href="https://security.googleblog.com/2023/08/android-goes-all-in-on-fuzzing.html">https://security.googleblog.com/2023/08/android-goes-all-in-on-fuzzing.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=37313603">https://news.ycombinator.com/item?id=37313603</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 29 Aug 2023 20:33:49 +0000</pubDate><link>https://security.googleblog.com/2023/08/android-goes-all-in-on-fuzzing.html</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=37313603</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37313603</guid></item><item><title><![CDATA[New comment by Magicstatic in "FCC threatens to disconnect Twilio for illegal robocalls"]]></title><description><![CDATA[
<p>I use Lookify.io which lets you look up a carrier without creating an account - you can also see if anyone else flags it as spammy but who knows if the reports are anything other than anecdotal</p>
]]></description><pubDate>Sun, 29 Jan 2023 18:45:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=34571263</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=34571263</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34571263</guid></item><item><title><![CDATA[New comment by Magicstatic in "Overview of the 555-XXXX phone number"]]></title><description><![CDATA[
<p>This is the craziest part of the whole article - imagine you wanted to own something like "555-FOOD" - to have this vanity number work in every area code, you'd be looking at hundreds of thousands of dollars (annually?) if you used Verizon to route the calls</p>
]]></description><pubDate>Mon, 14 Nov 2022 02:23:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=33589583</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=33589583</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33589583</guid></item><item><title><![CDATA[New comment by Magicstatic in "Security researcher receives $1M bug bounty for saving company from $350M bug"]]></title><description><![CDATA[
<p>Link to company confirming payment: <a href="https://twitter.com/josephdelong/status/1431314816698916865" rel="nofollow">https://twitter.com/josephdelong/status/1431314816698916865</a><p>Link to researcher writeup: <a href="https://www.paradigm.xyz/2021/08/two-rights-might-make-a-wrong/" rel="nofollow">https://www.paradigm.xyz/2021/08/two-rights-might-make-a-wro...</a></p>
]]></description><pubDate>Fri, 27 Aug 2021 19:16:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=28331886</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=28331886</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28331886</guid></item><item><title><![CDATA[Security researcher receives $1M bug bounty for saving company from $350M bug]]></title><description><![CDATA[
<p>Article URL: <a href="https://twitter.com/jon_bottarini/status/1431332757351845889">https://twitter.com/jon_bottarini/status/1431332757351845889</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=28331827">https://news.ycombinator.com/item?id=28331827</a></p>
<p>Points: 53</p>
<p># Comments: 5</p>
]]></description><pubDate>Fri, 27 Aug 2021 19:11:07 +0000</pubDate><link>https://twitter.com/jon_bottarini/status/1431332757351845889</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=28331827</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28331827</guid></item><item><title><![CDATA[New comment by Magicstatic in "Apple explicitly asks employees to merge their personal and work accounts"]]></title><description><![CDATA[
<p>This has been refuted and is simply misleading: <a href="https://twitter.com/jon_bottarini/status/1428569700859056129" rel="nofollow">https://twitter.com/jon_bottarini/status/1428569700859056129</a></p>
]]></description><pubDate>Fri, 20 Aug 2021 04:12:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=28242480</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=28242480</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28242480</guid></item><item><title><![CDATA[New comment by Magicstatic in "Goldman seems to be running networking software from 2008"]]></title><description><![CDATA[
<p>Anecdote: Out of every bank and financial institution I have ever tried hacking (ethically, as part of bug bounty programs) Goldman Sachs is hands down, without a doubt, the most secure externally. By a long shot. They have what basically amounts to a central authentication service that 95% of their public facing IP’s resolve to. Their sub domains are locked down, they have a reasonably good patch schedule, they swiftly denylist your IP after running light scanners - it’s not a joke. I challenge you to find a vulnerability - when you do - get some money for it: <a href="https://hackerone.com/goldmansachs" rel="nofollow">https://hackerone.com/goldmansachs</a></p>
]]></description><pubDate>Wed, 30 Jun 2021 14:23:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=27688916</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=27688916</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27688916</guid></item><item><title><![CDATA[New comment by Magicstatic in "I’ve had the same supper for 10 years"]]></title><description><![CDATA[
<p>Many of us including myself are unable to fathom living a life like this, but I imagine this man will die in peace with a flock of sheep to his name, listening to the cuckoos.<p>And he will be just as happy (if not happier) as any of us reading this article.</p>
]]></description><pubDate>Sat, 08 May 2021 04:11:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=27083782</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=27083782</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27083782</guid></item><item><title><![CDATA[New comment by Magicstatic in "Changes at Basecamp"]]></title><description><![CDATA[
<p>Sincere question - not meant to be inflammatory: Do you actually believe that most employees in the United States are coerced/forced to sign employment contracts, or are you simply playing devil's advocate?</p>
]]></description><pubDate>Tue, 27 Apr 2021 02:23:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=26951163</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=26951163</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26951163</guid></item><item><title><![CDATA[New comment by Magicstatic in "EFF's reply to cease-&-desist letter – “Virtual Coachella” parody video"]]></title><description><![CDATA[
<p>My favorite part of this response is in the footnote on page two, which states:<p>>If your client sincerely fears that this depiction is too realistic to be perceived as parody, Krazam’s video should be the least of its reputational concerns.<p>Followed by screenshots from the video showing the DocuSign "Docustage" and Meme Center (Sponsored by GE). At the end of the video itself, the Coachella participant is banned from the event because their "vibes are not compliant with the Coachella policy".<p>Glad EFF stepped in here to protect small creators such as this one.</p>
]]></description><pubDate>Thu, 08 Apr 2021 16:38:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=26740866</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=26740866</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26740866</guid></item><item><title><![CDATA[EFF's reply to cease-&-desist letter – “Virtual Coachella” parody video]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.eff.org/ar/document/eff-letter-re-virtual-coachella-video">https://www.eff.org/ar/document/eff-letter-re-virtual-coachella-video</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=26740323">https://news.ycombinator.com/item?id=26740323</a></p>
<p>Points: 230</p>
<p># Comments: 35</p>
]]></description><pubDate>Thu, 08 Apr 2021 15:55:15 +0000</pubDate><link>https://www.eff.org/ar/document/eff-letter-re-virtual-coachella-video</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=26740323</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26740323</guid></item><item><title><![CDATA[New comment by Magicstatic in "Look Up Unknown Phone Numbers Using Facebook Reset Password"]]></title><description><![CDATA[
<p>Is this a security problem? Depends on who you ask - but I'm willing to bet it would fall into the "accepted risk" category for the Facebook security team if they had to evaluate this.<p>The reality is that phone number lookup services are available all over the web which provide even more information (first+last name, address, zip code, social media profile links, etc etc etc) for free (<a href="https://www.bestfreephonelookup.com/phone-number/" rel="nofollow">https://www.bestfreephonelookup.com/phone-number/</a> as an example) - these services get their info from data aggregators and usually - your carrier! I don't see how Facebook exposing (in _limited_, very specific circumstances) the first name of a persons phone number being a security issue.<p>All the people in this thread screaming GDPR violation don't understand that if someone decides to stop using Facebook and delete their account, this method to lookup someone will not work. Sidenote: If you're really paranoid about having your phone number expose your real name when you're using any type of service online, just sign up for a Google Voice (voice.google.com) account and link it to your cell phone - I use this whenever I sign up for anything online and it saves me a ton of spam and scam calls.<p>EDIT: Facebook removed the ability to use the in-app search box in Facebook to find people based on just a phone number, this has been removed for at least 2 years.</p>
]]></description><pubDate>Mon, 04 Jan 2021 17:37:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=25634906</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=25634906</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25634906</guid></item><item><title><![CDATA[City of Tucson, AZ invites remote workers with over $7,500 in benefits]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.startuptucson.com/remotetucson">https://www.startuptucson.com/remotetucson</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=25282828">https://news.ycombinator.com/item?id=25282828</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 02 Dec 2020 22:50:41 +0000</pubDate><link>https://www.startuptucson.com/remotetucson</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=25282828</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25282828</guid></item><item><title><![CDATA[New comment by Magicstatic in "How did I hack Sizmek?(an Amazon company)"]]></title><description><![CDATA[
<p>I don’t even know where to start with this post:<p>- This isn’t even necessarily a hack. At best, this is a mild inconvenience to the user accounts that you are locking out, on what appears to be a legacy system, due to a quasi-brute force.<p>- You are “hacking” this company, without their permission, because you want “payback” that Amazon didn’t hire you for what you perceive to be a racially opinionated interviewer. Despite whether this theory (yes, it is purely speculation) is true or not, I would imagine this is HR 101 and a company as large as Amazon would go to great lengths to ensure that this is not the case.<p>- Your sense of entitlement goes even further, despite having illegally “hacked” a company, after all of this you expect a payment from them?<p>If anything, this post reaffirms that they made the right decision in not hiring you for the role you were being considered for, and guarantees that you won’t have an opportunity to interview again.</p>
]]></description><pubDate>Thu, 21 May 2020 00:13:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=23253537</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=23253537</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=23253537</guid></item><item><title><![CDATA[New comment by Magicstatic in "How Apple's Screen Time is outsmarted by kids, frustrating parents"]]></title><description><![CDATA[
<p>What’s peculiar about this is that parental restrictions itself on iOS has always been flawed, Apple knew about it, and it’s still an issue to this day. The sole purpose of parental restrictions on iPhone was to block adult websites... and that worked as well as you can imagine: <a href="https://www.jonbottarini.com/2017/03/09/bypassing-apples-ios-10-restrictions-settings-twice/" rel="nofollow">https://www.jonbottarini.com/2017/03/09/bypassing-apples-ios...</a></p>
]]></description><pubDate>Wed, 16 Oct 2019 00:44:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=21265851</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=21265851</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=21265851</guid></item><item><title><![CDATA[Gmail conversation between Steve Chen and an early YouTube user (2005)]]></title><description><![CDATA[
<p>Article URL: <a href="https://imgur.com/a/anrsXiX">https://imgur.com/a/anrsXiX</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=18525692">https://news.ycombinator.com/item?id=18525692</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 25 Nov 2018 06:26:40 +0000</pubDate><link>https://imgur.com/a/anrsXiX</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=18525692</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=18525692</guid></item><item><title><![CDATA[Ethical hacker makes $120k USD in one week hacking EOS smart contracts]]></title><description><![CDATA[
<p>Article URL: <a href="https://twitter.com/GuidoVranken/status/1003782704310247424">https://twitter.com/GuidoVranken/status/1003782704310247424</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=17233835">https://news.ycombinator.com/item?id=17233835</a></p>
<p>Points: 25</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 05 Jun 2018 00:08:00 +0000</pubDate><link>https://twitter.com/GuidoVranken/status/1003782704310247424</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=17233835</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=17233835</guid></item><item><title><![CDATA[Abusing Internal API to Achieve IDOR in New Relic]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.jonbottarini.com/2018/01/02/abusing-internal-api-to-achieve-idor-in-new-relic/">https://www.jonbottarini.com/2018/01/02/abusing-internal-api-to-achieve-idor-in-new-relic/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=16139120">https://news.ycombinator.com/item?id=16139120</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 13 Jan 2018 11:11:03 +0000</pubDate><link>https://www.jonbottarini.com/2018/01/02/abusing-internal-api-to-achieve-idor-in-new-relic/</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=16139120</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=16139120</guid></item><item><title><![CDATA[New comment by Magicstatic in "Login as root on macOS High Sierra by just leaving a blank password"]]></title><description><![CDATA[
<p>Was able to reproduce on my machine. macOS High Sierra 10.13 (17A405)<p>This is incredible.</p>
]]></description><pubDate>Tue, 28 Nov 2017 20:39:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=15801272</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=15801272</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15801272</guid></item><item><title><![CDATA[HackerOne passes $18M in bounties paid out to hackers]]></title><description><![CDATA[
<p>Article URL: <a href="https://twitter.com/Hacker0x01/status/880559332701618177">https://twitter.com/Hacker0x01/status/880559332701618177</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=14667542">https://news.ycombinator.com/item?id=14667542</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 29 Jun 2017 23:04:28 +0000</pubDate><link>https://twitter.com/Hacker0x01/status/880559332701618177</link><dc:creator>Magicstatic</dc:creator><comments>https://news.ycombinator.com/item?id=14667542</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=14667542</guid></item></channel></rss>