<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ZoFreX</title><link>https://news.ycombinator.com/user?id=ZoFreX</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 20 May 2026 11:24:18 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ZoFreX" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Bundler Is Still Vulnerable to Dependency Confusion Attacks]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.zofrex.com/blog/2021/04/29/bundler-still-vulnerable-dependency-confusion-cve-2020-36327/">https://www.zofrex.com/blog/2021/04/29/bundler-still-vulnerable-dependency-confusion-cve-2020-36327/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=26987392">https://news.ycombinator.com/item?id=26987392</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 29 Apr 2021 22:03:09 +0000</pubDate><link>https://www.zofrex.com/blog/2021/04/29/bundler-still-vulnerable-dependency-confusion-cve-2020-36327/</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=26987392</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26987392</guid></item><item><title><![CDATA[New comment by ZoFreX in "Amazon's Vanishing Cardboard Box"]]></title><description><![CDATA[
<p>This seems to be an internet meme, because it's repeated in every discussion on this topic but I never see any citation for it.<p>It also doesn't seem to hold up to scrutiny - even if the initial packing of the vehicle holds everything in place, what happens once a few packages are removed?</p>
]]></description><pubDate>Tue, 16 Jul 2019 19:13:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=20452996</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=20452996</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=20452996</guid></item><item><title><![CDATA[New comment by ZoFreX in "India’s destruction of satellite threatens ISS, says Nasa"]]></title><description><![CDATA[
<p>Largely yes. Or at least a lot less of a problem.<p>The biggest risk from space garbage is that the small stuff is not trackable, so at any point it could slam into satellites or, god forbid, people or space stations. It's going fast enough that despite being small this would have dreadful consequences.<p>Larger items can be tracked, and therefore can be avoided, so they don't pose a risk any more than non-junk large items like other satellites and so on. There's quite a lot of room so if you know where things are it's not hard to avoid them.<p>Some amount of garbage is sadly unavoidable at this point in our development of space travel. For example many rockets are multi stage and jettison those stages, farings to protect satellites are jettisoned, and so on. That all falls into the "large and trackable" category so it's not a terrible problem, at least not yet. So the main current strategy for avoiding creating problems is to avoid creating small garbage, and people work very hard at that - being careful not to lose tools or even a single nut or bolt.<p>And yes, before you mention it, "lots of room" is a relative statement and this is not an infinitely sustainable strategy. But people are working on methods to capture and clean up garbage, and as those get more feasible we'll be able to go and clean up all this large garbage that we are tracking. So even with a long-term perspective, the large stuff is less of a problem.</p>
]]></description><pubDate>Tue, 02 Apr 2019 11:33:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=19552956</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=19552956</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=19552956</guid></item><item><title><![CDATA[New comment by ZoFreX in "India’s destruction of satellite threatens ISS, says Nasa"]]></title><description><![CDATA[
<p>Also, to prove a rocket you need to have a dummy payload of some kind. Whatever you think about the stunt of using a Tesla as that dummy payload, there was going to be a payload of some kind however that decision went. The fact it was a car doesn't change the collision risk or debris amount compared to using a mass simulator.</p>
]]></description><pubDate>Tue, 02 Apr 2019 11:25:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=19552912</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=19552912</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=19552912</guid></item><item><title><![CDATA[New comment by ZoFreX in "Show HN: Mkcert – Valid HTTPS certificates for localhost"]]></title><description><![CDATA[
<p>Windows doesn't have fine-grained permissions for adding to or changing certificate stores, though. When you run "mkcert -install" you'll get a generic prompt for mkcert requiring admin permissions, not a prompt for it changing certificate stores.<p>I believe the point is that any software asking for admin could fiddle with your certificate stores, so there's no sense in asking for a higher standard of integrity from software that tells you it will do so.</p>
]]></description><pubDate>Mon, 07 Jan 2019 11:12:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=18844329</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=18844329</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=18844329</guid></item><item><title><![CDATA[New comment by ZoFreX in "Apple Engineers Its Own Downfall with the Macbook Pro Keyboard"]]></title><description><![CDATA[
<p>Counter-point, I haven't had a single Apple keyboard fail on me yet (although I do not own the new Macbook, so I don't have the dreadful one) and my Matias broke after just 1 year.</p>
]]></description><pubDate>Thu, 28 Jun 2018 10:43:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=17415708</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=17415708</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=17415708</guid></item><item><title><![CDATA[New comment by ZoFreX in "The dots do matter: how to scam a Gmail user"]]></title><description><![CDATA[
<p>It's not, necessarily.<p>It's a tradeoff between usability and security, and each site should make their own decision about what is right for them.<p>It obviously makes attacks like the one in the article easier, but there are other ways to mitigate that.<p>An example often given for when revealing an email is registered would definitely be bad is dating website and pornography websites - where identifying someone is a member alone could be embarrassing or compromising.<p>Outside of such scenarios, websites may decide the increased conversion from a more streamlined registration process and lower numbers of support requests for login issues outweigh the marginal security gains from hiding that information.</p>
]]></description><pubDate>Tue, 10 Apr 2018 09:50:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=16800156</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=16800156</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=16800156</guid></item><item><title><![CDATA[New comment by ZoFreX in "Tesla crash in September showed similarities to fatal Mountain View accident"]]></title><description><![CDATA[
<p>If people are using it, not paying attention, with the expectation that it will beep to tell you to take over that's a big problem. In situations like this divider issue it won't beep, it thinks everything is fine right up until it rams you into a stationary object. I think people may not be fully aware of all the potential failure modes of this tech?</p>
]]></description><pubDate>Thu, 05 Apr 2018 09:16:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=16763178</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=16763178</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=16763178</guid></item><item><title><![CDATA[New comment by ZoFreX in "Safari Password Generation"]]></title><description><![CDATA[
<p>> This should help you to have a backup next time you get locked out!<p>The official authenticator also displays a backup code which it tells you to keep a copy of somewhere safe...</p>
]]></description><pubDate>Sun, 04 Feb 2018 12:03:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=16302417</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=16302417</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=16302417</guid></item><item><title><![CDATA[New comment by ZoFreX in "Why Tesla's autopilot can't see a stopped firetruck"]]></title><description><![CDATA[
<p>The difference is (according to the article) that there is an abundance of objects at 0mph - signs, litter, barriers - so the system filters all of these out to avoid constantly braking. There is no such abundance of ignorable items going at 20mph.</p>
]]></description><pubDate>Fri, 26 Jan 2018 14:22:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=16239308</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=16239308</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=16239308</guid></item><item><title><![CDATA[New comment by ZoFreX in "AppStore Preferences can be unlocked by a local admin with any bogus password"]]></title><description><![CDATA[
<p>> it pauses with an incorrect password for a few seconds, then visually shakes indicating it's a wrong password<p>This is also the behaviour of the App Store preferences in version 10.13.1</p>
]]></description><pubDate>Wed, 10 Jan 2018 18:20:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=16117411</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=16117411</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=16117411</guid></item><item><title><![CDATA[New comment by ZoFreX in "HTTPS on Your Landing Page Is Important"]]></title><description><![CDATA[
<p>> Hopefully their mobile apps use HTTPS for everything too?<p>Well, HSBC's didn't: <a href="https://threatpost.com/banking-apps-found-vulnerable-to-mitm-attacks/129105/" rel="nofollow">https://threatpost.com/banking-apps-found-vulnerable-to-mitm...</a></p>
]]></description><pubDate>Thu, 14 Dec 2017 10:46:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=15921299</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=15921299</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15921299</guid></item><item><title><![CDATA[New comment by ZoFreX in "HTTPS on Your Landing Page Is Important"]]></title><description><![CDATA[
<p>NatWest are particularly terrible. Last time I checked, in-branch they were still using Internet Explorer to visit an http (not https) site on their intranet to launch via Java Web Start a thin client to log in to their (I assume) mainframe to actually do things.<p>There's a number of places in that chain of events that something could go nastily wrong, despite them owning every part of that chain.</p>
]]></description><pubDate>Thu, 14 Dec 2017 10:05:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=15921146</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=15921146</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15921146</guid></item><item><title><![CDATA[New comment by ZoFreX in "Brilliant Jerks in Engineering"]]></title><description><![CDATA[
<p>Being a jerk and disagreeing are orthogonal. You can be a jerk while agreeing with someone, and be a not-jerk while disagreeing.<p>I'm curious, in reference to the post, how you would have no problem working with a "Bob"? Is there really no behaviour there that would bother you in a coworker?</p>
]]></description><pubDate>Mon, 13 Nov 2017 18:22:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=15688646</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=15688646</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15688646</guid></item><item><title><![CDATA[New comment by ZoFreX in "Hyperloop One Becomes ‘Virgin Hyperloop One’"]]></title><description><![CDATA[
<p>Hence tilting - high speed vehicles tilt, low speed vehicles don't, and everything works out ok.</p>
]]></description><pubDate>Sat, 14 Oct 2017 09:47:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=15471506</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=15471506</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15471506</guid></item><item><title><![CDATA[New comment by ZoFreX in "Hyperloop One Becomes ‘Virgin Hyperloop One’"]]></title><description><![CDATA[
<p>Lateral acceleration is much more annoying to deal with than longitudinal or vertical, even if it's constant. Perhaps they could tilt in bends to convert some of that lateral to vertical?</p>
]]></description><pubDate>Fri, 13 Oct 2017 10:40:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=15464472</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=15464472</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15464472</guid></item><item><title><![CDATA[New comment by ZoFreX in "Google accused of racketeering in lawsuit"]]></title><description><![CDATA[
<p>> with a reputation as huge and important as Google's<p>Not trolling: What reputation?<p>Among non-techies, their reputation is one of creepy and spying.<p>Among techies, it's that company that keeps killing loved products.<p>Among developers, it's one of terrible support and awful job interviews.<p>Common to everyone is they are impossible to get hold of, a faceless and heartless machine that makes decisions you can't argue with.<p>None of this matters because they have the best products on the market in a few key areas and everyone keeps using those regardless of their reputation.<p>So what reputation do they have to lose? Their reputation is already bad, and it doesn't matter anyway, and they presumably know this as well as everyone else does.</p>
]]></description><pubDate>Sat, 07 Oct 2017 12:18:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=15423460</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=15423460</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15423460</guid></item><item><title><![CDATA[New comment by ZoFreX in "Transport for London plans to collect data from passengers' mobiles"]]></title><description><![CDATA[
<p>Anyone who hasn't seen this yet should take a look, it explains in detail:<p>- Why they are doing this
- What the potential passenger benefits are
- And bonus, it includes lots of cool infographics on passenger journeys</p>
]]></description><pubDate>Mon, 02 Oct 2017 15:26:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=15384525</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=15384525</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15384525</guid></item><item><title><![CDATA[New comment by ZoFreX in "Transport for London plans to collect data from passengers' mobiles"]]></title><description><![CDATA[
<p>They go into a lot of potential benefits in their paper here: <a href="http://content.tfl.gov.uk/review-tfl-wifi-pilot.pdf" rel="nofollow">http://content.tfl.gov.uk/review-tfl-wifi-pilot.pdf</a></p>
]]></description><pubDate>Mon, 02 Oct 2017 15:26:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=15384517</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=15384517</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15384517</guid></item><item><title><![CDATA[New comment by ZoFreX in "Transport for London plans to collect data from passengers' mobiles"]]></title><description><![CDATA[
<p>How would tracking the Oyster card ID that's registered to my name, address, and credit card # in their system be an improvement compared to tracking the hashed MAC address of my phone?</p>
]]></description><pubDate>Mon, 02 Oct 2017 15:25:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=15384505</link><dc:creator>ZoFreX</dc:creator><comments>https://news.ycombinator.com/item?id=15384505</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15384505</guid></item></channel></rss>