<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ahoog42</title><link>https://news.ycombinator.com/user?id=ahoog42</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 23 Sep 2026 15:26:54 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ahoog42" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[System over Model: Zero-Day Discovery at the Jagged Frontier]]></title><description><![CDATA[
<p>Article URL: <a href="https://aisle.com/blog/system-over-model-zero-day-discovery-at-the-jagged-frontier">https://aisle.com/blog/system-over-model-zero-day-discovery-at-the-jagged-frontier</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47909248">https://news.ycombinator.com/item?id=47909248</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 26 Apr 2026 10:55:21 +0000</pubDate><link>https://aisle.com/blog/system-over-model-zero-day-discovery-at-the-jagged-frontier</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=47909248</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47909248</guid></item><item><title><![CDATA[AI threats in the wild: The current state of prompt injections on the web]]></title><description><![CDATA[
<p>Article URL: <a href="https://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html">https://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47883385">https://news.ycombinator.com/item?id=47883385</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 23 Apr 2026 23:05:31 +0000</pubDate><link>https://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=47883385</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47883385</guid></item><item><title><![CDATA[New comment by ahoog42 in "Qwen3.6-27B: Flagship-Level Coding in a 27B Dense Model"]]></title><description><![CDATA[
<p>at what point do model providers optimize for the "pelican riding a bicycle" test so they place well on Simon's influential benchmark? :-)</p>
]]></description><pubDate>Wed, 22 Apr 2026 17:53:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=47866947</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=47866947</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47866947</guid></item><item><title><![CDATA[Token-efficient access to all your data sources]]></title><description><![CDATA[
<p>Article URL: <a href="https://max.cloud">https://max.cloud</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47529497">https://news.ycombinator.com/item?id=47529497</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 26 Mar 2026 12:10:30 +0000</pubDate><link>https://max.cloud</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=47529497</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47529497</guid></item><item><title><![CDATA[New comment by ahoog42 in "Litestream v0.5.0"]]></title><description><![CDATA[
<p>any notes or pointers on how to get comfortable with k8? For a simple nodejs app I was looking down the pm2 route but I wonder of learning k8 is just more future proof.</p>
]]></description><pubDate>Fri, 03 Oct 2025 18:40:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=45466273</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=45466273</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45466273</guid></item><item><title><![CDATA[New comment by ahoog42 in "Show HN: Dayflow – A git log for your day"]]></title><description><![CDATA[
<p>if you are on a Zoom/video call, does anyone know if you would have to declare that your "recording" it? I'm thinking more from the legal perspective of wiretapping/consent laws. If you have live transcripts/subtitles does that change any legal requirement.</p>
]]></description><pubDate>Thu, 25 Sep 2025 11:56:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=45371787</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=45371787</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45371787</guid></item><item><title><![CDATA[New comment by ahoog42 in "Do not download the app, use the website"]]></title><description><![CDATA[
<p>regarding data collection, both android and ios provide multiple ways to review, approve/deny, and manage access to data. it's certainly not perfect but is being constantly improved. And for the HN crowd, you can always run mobile security/privacy tools like mobSF to inspect the app. I'm not suggesting we should have to do this but we can and frankly browser fingerprinting is opaque, also constantly evolving and quite good at tracking and data collection. i'm not sure avoid the better ux of a native app is much worse and given the privacy tools and data available, I generally prefer the native app</p>
]]></description><pubDate>Sat, 26 Jul 2025 10:36:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=44692986</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=44692986</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44692986</guid></item><item><title><![CDATA[You Are Reading Reddit a Lot More These Days]]></title><description><![CDATA[
<p>Article URL: <a href="https://nymag.com/intelligencer/article/why-you-are-reading-reddit-a-lot-more-these-days.html">https://nymag.com/intelligencer/article/why-you-are-reading-reddit-a-lot-more-these-days.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44645467">https://news.ycombinator.com/item?id=44645467</a></p>
<p>Points: 6</p>
<p># Comments: 5</p>
]]></description><pubDate>Tue, 22 Jul 2025 11:12:54 +0000</pubDate><link>https://nymag.com/intelligencer/article/why-you-are-reading-reddit-a-lot-more-these-days.html</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=44645467</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44645467</guid></item><item><title><![CDATA[Apple devices offer speech to text transcription in developer betas, shows test]]></title><description><![CDATA[
<p>Article URL: <a href="https://9to5mac.com/2025/06/18/apple-devices-offer-amazing-speech-to-text-transcription-in-developer-betas-shows-test/">https://9to5mac.com/2025/06/18/apple-devices-offer-amazing-speech-to-text-transcription-in-developer-betas-shows-test/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44309030">https://news.ycombinator.com/item?id=44309030</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 18 Jun 2025 11:46:53 +0000</pubDate><link>https://9to5mac.com/2025/06/18/apple-devices-offer-amazing-speech-to-text-transcription-in-developer-betas-shows-test/</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=44309030</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44309030</guid></item><item><title><![CDATA[New comment by ahoog42 in "Coinbase says hackers bribed staff to steal customer data, demanding $20M ransom"]]></title><description><![CDATA[
<p>If you want to be alerted to new/updated SEC cybersecurity filings, you can subscribe to my free alerts [1] or see the full index of cybersecurity incidents [2] on my tracker (I check SEC EDGAR every 5 mins).<p>[1] <a href="https://www.board-cybersecurity.com/alerts/" rel="nofollow">https://www.board-cybersecurity.com/alerts/</a><p>[2] <a href="https://www.board-cybersecurity.com/incidents/tracker/" rel="nofollow">https://www.board-cybersecurity.com/incidents/tracker/</a></p>
]]></description><pubDate>Fri, 16 May 2025 11:15:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=44003963</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=44003963</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44003963</guid></item><item><title><![CDATA[New comment by ahoog42 in "108B Pixel Scan of Johannes Vermeer's Girl with a Pearl Earring"]]></title><description><![CDATA[
<p>Jonathan Sawday’s 2023 book “Blanks, Print, Space, and Void in English Renaissance Literature: An Archaeology of Absence.” [1] explores this phenomenon as well across multiple mediums.<p>It also won the Modern Language Association's top award — the James Russell Lowell Prize for the most outstanding book published in 2023.<p>[1] <a href="https://academic.oup.com/book/46695" rel="nofollow">https://academic.oup.com/book/46695</a></p>
]]></description><pubDate>Thu, 01 May 2025 16:33:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=43859992</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=43859992</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43859992</guid></item><item><title><![CDATA[French Competition Watchdog Fines Apple $162.4M over App Tracking Transparency]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.wsj.com/tech/french-competition-watchdog-fines-apple-162-4-million-over-app-tracking-transparency-2cd07cdc">https://www.wsj.com/tech/french-competition-watchdog-fines-apple-162-4-million-over-app-tracking-transparency-2cd07cdc</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43533569">https://news.ycombinator.com/item?id=43533569</a></p>
<p>Points: 6</p>
<p># Comments: 1</p>
]]></description><pubDate>Mon, 31 Mar 2025 11:08:10 +0000</pubDate><link>https://www.wsj.com/tech/french-competition-watchdog-fines-apple-162-4-million-over-app-tracking-transparency-2cd07cdc</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=43533569</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43533569</guid></item><item><title><![CDATA[New comment by ahoog42 in "Fast Cash vs. Slow Equity"]]></title><description><![CDATA[
<p>This is exactly how we built viaForensics in 2009. For the first five years, we performed mobile forensic investigations and gave trainings based on the Android and iOS forensic books we wrote. We were able to self fund software development for the first five years. When we moved from forensics to mobile app security, we required more capital to build our automated software which led to our Series A.<p>Having an established business with customers in revenue, obviously significantly helps in the fundraising process and evaluation. The other huge advantage is you can benefit significantly from the Qualified Small Business Stock statute which provide an exemption/shield on federal taxes when you sell that is the _greater of_ either $10m or 10x times your valuation at the time of funding.</p>
]]></description><pubDate>Mon, 24 Feb 2025 13:42:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=43159442</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=43159442</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43159442</guid></item><item><title><![CDATA[New comment by ahoog42 in "South Korean regulator accuses DeepSeek of sharing user data with ByteDance"]]></title><description><![CDATA[
<p>Despite their goal of enforcing in 2017, it is still not a hard requirement. Back then, about 80% of the apps we tested disabled ATS either partially or fully [1]. It’s rare to see Apple walk something back [2], but here is a blog at the time that talked about it [3].<p>[1] <a href="https://www.nowsecure.com/blog/2017/12/29/enable-ios-app-transport-security-ats/" rel="nofollow">https://www.nowsecure.com/blog/2017/12/29/enable-ios-app-tra...</a><p>[2] <a href="https://developer.apple.com/news/?id=12212016b" rel="nofollow">https://developer.apple.com/news/?id=12212016b</a><p>[3] <a href="https://www.klundberg.com/blog/app-transport-security-delay/" rel="nofollow">https://www.klundberg.com/blog/app-transport-security-delay/</a></p>
]]></description><pubDate>Wed, 19 Feb 2025 12:40:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=43101425</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=43101425</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43101425</guid></item><item><title><![CDATA[New comment by ahoog42 in "South Korean regulator accuses DeepSeek of sharing user data with ByteDance"]]></title><description><![CDATA[
<p>We analyzed the iOS app[1] and observed similar traffic as well as a number of basic security issues (hardcoded encryption keys, use of 3DES and some traffic over HTTP).<p>[1] <a href="https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/" rel="nofollow">https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers...</a></p>
]]></description><pubDate>Wed, 19 Feb 2025 01:00:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=43097246</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=43097246</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43097246</guid></item><item><title><![CDATA[New comment by ahoog42 in "Grok3 Launch [video]"]]></title><description><![CDATA[
<p>Any example code or blogs/docs that demonstrate making graphs/diagrams and/or hooking it up to a local code base?</p>
]]></description><pubDate>Tue, 18 Feb 2025 14:53:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=43090158</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=43090158</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43090158</guid></item><item><title><![CDATA[New comment by ahoog42 in "Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App"]]></title><description><![CDATA[
<p>agreed the 3DES is a difficult choice to explain. To top it off the encryption key was hardcoded in the .ipa, the IV was null and then reused.</p>
]]></description><pubDate>Fri, 07 Feb 2025 03:12:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=42968870</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=42968870</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42968870</guid></item><item><title><![CDATA[New comment by ahoog42 in "Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App"]]></title><description><![CDATA[
<p>Yes, the Android app has multiple vulnerabilities but we focused this report on iOS (it took nearly 40 hours to write the report). Our recommendation is people avoid using the mobile apps. If you want to test the model, I'd suggest Hugging Face/ollama or a hosted solution (multiple companies are now offering that).</p>
]]></description><pubDate>Fri, 07 Feb 2025 03:10:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=42968846</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=42968846</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42968846</guid></item><item><title><![CDATA[Multiple Security and Privacy Flaws in DeepSeek iOS Mobile App]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/">https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42967527">https://news.ycombinator.com/item?id=42967527</a></p>
<p>Points: 17</p>
<p># Comments: 6</p>
]]></description><pubDate>Thu, 06 Feb 2025 23:24:59 +0000</pubDate><link>https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=42967527</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42967527</guid></item><item><title><![CDATA[New comment by ahoog42 in "Launch HN: CamelQA (YC W24) – AI that tests mobile apps"]]></title><description><![CDATA[
<p>Congrats, very exciting. Do you support configuring things like usernames and passwords? How do you handle MFA?</p>
]]></description><pubDate>Thu, 21 Mar 2024 13:11:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=39778084</link><dc:creator>ahoog42</dc:creator><comments>https://news.ycombinator.com/item?id=39778084</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39778084</guid></item></channel></rss>