<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: MajesticHobo2</title><link>https://news.ycombinator.com/user?id=MajesticHobo2</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 24 Sep 2026 19:44:47 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=MajesticHobo2" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by MajesticHobo2 in "VSCode's SSH Agent Is Bananas (2025)"]]></title><description><![CDATA[
<p>Is it? I've read the article twice (yesterday when you posted it and last year when it was first published), and that was not my interpretation.</p>
]]></description><pubDate>Thu, 24 Sep 2026 15:33:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=49832100</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=49832100</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49832100</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "VSCode's SSH Agent Is Bananas (2025)"]]></title><description><![CDATA[
<p>This part of VSCode's architecture is acceptable to me. The reverse direction, where a compromised remote can do whatever it wants to my local machine, is not.</p>
]]></description><pubDate>Wed, 23 Sep 2026 21:52:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=49823093</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=49823093</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49823093</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "GPT-6 Astra"]]></title><description><![CDATA[
<p>That is a linear growth problem whose answer is very easy to intuit.</p>
]]></description><pubDate>Fri, 04 Sep 2026 00:36:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=49559041</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=49559041</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49559041</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "Tailcat – Like netcat, but over Tailscale’s data plane"]]></title><description><![CDATA[
<p>You also don't want adversaries to be able to disrupt long-lived streams with bad password guesses, since I think part of Wormhole's security model is it will terminate the session if the other side gets it wrong.</p>
]]></description><pubDate>Wed, 26 Aug 2026 23:48:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49457492</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=49457492</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49457492</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "Tailcat – Like netcat, but over Tailscale’s data plane"]]></title><description><![CDATA[
<p>They say it's rate-limited, so at least it probably won't scale to large botnets or similar...</p>
]]></description><pubDate>Wed, 26 Aug 2026 23:43:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=49457443</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=49457443</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49457443</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "Tailcat – Like netcat, but over Tailscale’s data plane"]]></title><description><![CDATA[
<p>notabug wontfix; that's the end-to-end (E2E) principle in action. Bring your own all of that.</p>
]]></description><pubDate>Wed, 26 Aug 2026 23:40:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49457417</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=49457417</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49457417</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "Show HN: Firefox in WebAssembly"]]></title><description><![CDATA[
<p>Browser sandboxing is now fully solved.</p>
]]></description><pubDate>Wed, 15 Jul 2026 21:56:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=48927590</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=48927590</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48927590</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "We Are the Last People Who Know How It Works"]]></title><description><![CDATA[
<p>It's the same style I see on Twitter and LinkedIn a lot.</p>
]]></description><pubDate>Tue, 30 Jun 2026 22:35:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48740145</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=48740145</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48740145</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "We Are the Last People Who Know How It Works"]]></title><description><![CDATA[
<p>Why does it have to be deliberate? It's not surprising that people exposed to output from LLMs will unconsciously pick up their linguistic habits.</p>
]]></description><pubDate>Tue, 30 Jun 2026 22:30:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48740102</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=48740102</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48740102</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "Carrot Disclosure: Forgejo"]]></title><description><![CDATA[
<p>I'd say also add a test that shows the HTML injection (which spurred the PR) isn't possible. Given an attacker-controlled URL of:<p><pre><code>    foo onclick
</code></pre>
the following shouldn't render:<p><pre><code>    <a class="item muted sidebar-item-link" href=foo onclick>
</code></pre>
The following should:<p><pre><code>    <a class="item muted sidebar-item-link" href="foo onclick"></code></pre></p>
]]></description><pubDate>Wed, 29 Apr 2026 01:36:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=47943184</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=47943184</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47943184</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "Vulnerability research is cooked"]]></title><description><![CDATA[
<p>It was definitely partially about model quality. The frontier models are capable of producing valid findings with (reasonably) complex exploit chains on the first pass (or with limited nudging) and are much less prone to making up the kinds of nonsensical reports that were submitted to curl. Compared to now, the old models essentially didn't work for security.<p>If those script kiddies had been using today's models instead and _still_ didn't do any filtering, a lot more of those bugs would have been true positives.</p>
]]></description><pubDate>Mon, 30 Mar 2026 22:02:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=47580266</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=47580266</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47580266</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "Vulnerability research is cooked"]]></title><description><![CDATA[
<p>> With decompilation I think there's a higher risk of it missing the intention of the code.<p>I'm not sure but suspect the lack of comments and documentation might be an advantage to LLMs for this use case. For security/reverse engineering work, the code's actual behavior matters a lot more than the developer's intention.</p>
]]></description><pubDate>Mon, 30 Mar 2026 20:54:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47579594</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=47579594</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47579594</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "Vulnerability research is cooked"]]></title><description><![CDATA[
<p>That was then, this is now. The new models are scarily good. If you're skeptical, just take an hour to replicate the strategy the article references. Point Claude at any open-source codebase you find interesting and instruct it to find exploitable vulnerabilities. Give it a well-defined endpoint if you want (e.g., "You must develop a Python script that triggers memory corruption via a crafted request") and see how well it does.</p>
]]></description><pubDate>Mon, 30 Mar 2026 20:33:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=47579372</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=47579372</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47579372</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "We mourn our craft"]]></title><description><![CDATA[
<p>Third or fourth, maybe, not first.</p>
]]></description><pubDate>Sun, 08 Feb 2026 04:03:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=46931232</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=46931232</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46931232</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "OpenSSL: Stack buffer overflow in CMS AuthEnvelopedData parsing"]]></title><description><![CDATA[
<p>Yes, but it would likely have to be chained with other bugs - at minimum, something that gives you an info leak.</p>
]]></description><pubDate>Tue, 27 Jan 2026 19:54:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=46785535</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=46785535</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46785535</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "Fixing a Buffer Overflow in Unix v4 Like It's 1973"]]></title><description><![CDATA[
<p>Yeah, somebody came up with one here: <a href="https://news.ycombinator.com/item?id=46469897">https://news.ycombinator.com/item?id=46469897</a></p>
]]></description><pubDate>Fri, 09 Jan 2026 01:07:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=46548863</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=46548863</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46548863</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "Humans May Be Able to Grow New Teeth Within Just 4 Years"]]></title><description><![CDATA[
<p>It’s a phase 1 clinical trial designed only to assess safety and determine the appropriate dosage. Future trials will focus on efficacy.</p>
]]></description><pubDate>Wed, 31 Dec 2025 00:21:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=46439902</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=46439902</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46439902</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "We pwned X, Vercel, Cursor, and Discord through a supply-chain attack"]]></title><description><![CDATA[
<p>Wouldn't platforms see the supposed XSS payloads in their logs and publish analyses of them, or at the very least, announce that they happened?</p>
]]></description><pubDate>Thu, 18 Dec 2025 23:36:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=46320343</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=46320343</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46320343</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "XKeyscore"]]></title><description><![CDATA[
<p>I'm sure they can store far more than 20 TB now, but it is true that the content pool is much larger. I would guess it's not a favorable ratio.</p>
]]></description><pubDate>Sun, 07 Dec 2025 23:17:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=46186395</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=46186395</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46186395</guid></item><item><title><![CDATA[New comment by MajesticHobo2 in "Show HN: Cadence – A guitar theory app"]]></title><description><![CDATA[
<p>Thanks for making this! I've been looking for something like this for a while.</p>
]]></description><pubDate>Wed, 22 Oct 2025 23:05:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=45676276</link><dc:creator>MajesticHobo2</dc:creator><comments>https://news.ycombinator.com/item?id=45676276</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45676276</guid></item></channel></rss>