<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ammar2</title><link>https://news.ycombinator.com/user?id=ammar2</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 08 Oct 2026 02:47:32 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ammar2" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ammar2 in "Navier–Stokes Lost in Translation"]]></title><description><![CDATA[
<p>It's not that much of a stretch: give the LLM a top-level proposition for the thing you want to prove and have it hack away at it. Each sub-step is verified in lean so you know it's correct. But, the linked post definitely suggests otherwise.<p>That is definitely interesting because how do you know the 88 hours of work are correct before you throw another 17 hours of lean formalization work on it? You could end up just finding out there was some hallucination in the original work.</p>
]]></description><pubDate>Wed, 07 Oct 2026 17:13:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=49995755</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=49995755</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49995755</guid></item><item><title><![CDATA[New comment by ammar2 in "Navier–Stokes Lost in Translation"]]></title><description><![CDATA[
<p>That assumes the natural language paper came first and then was formalized in lean. I haven't looked too deeply into how these labs solve these problems (or if they even specify this publicly) but you could also start with lean and then write the natural language proof based on it.<p>For what it's worth the initial lean specifications for the top-level theorems generally come from human written formalizations such as in <a href="https://github.com/leanprover-community/mathlib4/blob/021ce68bf125a049beee22b3fc7664d78728e21d/Mathlib/NumberTheory/FLT/Basic.lean#L57-L63" rel="nofollow">https://github.com/leanprover-community/mathlib4/blob/021ce6...</a> so we can be reasonably confident about their correctness.</p>
]]></description><pubDate>Wed, 07 Oct 2026 16:34:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49995161</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=49995161</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49995161</guid></item><item><title><![CDATA[New comment by ammar2 in "Spaghettifying DRAM"]]></title><description><![CDATA[
<p>The Xbox does not use AMD's Platform Security Processor, they have their own custom controller on die with Microsoft hardware and their own custom BootROM. This custom security processor actually has its own bit of RAM entirely in the die and doesn't even go out to the DRAM at all.<p>See the slide on Tony Chen's presentation about Xbox One security <a href="https://youtu.be/U7VwtOrwceo?t=843" rel="nofollow">https://youtu.be/U7VwtOrwceo?t=843</a> and this video from the person who hacked the Xbox One <a href="https://youtu.be/FTFn4UZsA5U?t=299" rel="nofollow">https://youtu.be/FTFn4UZsA5U?t=299</a></p>
]]></description><pubDate>Thu, 13 Aug 2026 22:45:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=49292715</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=49292715</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49292715</guid></item><item><title><![CDATA[New comment by ammar2 in "Spaghettifying DRAM"]]></title><description><![CDATA[
<p>Not sure if it opens up that much on them as far as their security processors go. Modern consoles already treat DRAM as completely untrusted (an attacker could just sit on the DRAM bus and sniff/issue requests there).<p>The Xbox One for example encrypts all the DRAM it uses after it gets out of the main CPU die. See this part of Tony Chen's presentation <a href="https://youtu.be/U7VwtOrwceo?t=956" rel="nofollow">https://youtu.be/U7VwtOrwceo?t=956</a><p>Also see this bit on the Apple Secure Enclave in the "Memory Protection Engine" section which also explains how they encrypt stuff stored in DRAM: <a href="https://support.apple.com/guide/security/the-secure-enclave-sec59b0b31ff/web" rel="nofollow">https://support.apple.com/guide/security/the-secure-enclave-...</a></p>
]]></description><pubDate>Thu, 13 Aug 2026 18:16:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=49289925</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=49289925</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49289925</guid></item><item><title><![CDATA[New comment by ammar2 in "Buz – A fork of Bun using modern Zig, with sub-1s incremental builds"]]></title><description><![CDATA[
<p>Of note, even that 97% of original code that is now "safe in the rust sense" could violate invariants through safe blocks that cause memory-safety issues. I can't say exactly how the LLM-ported Rust code made use of unsafe but see <a href="https://www.ralfj.de/blog/2016/01/09/the-scope-of-unsafe.html" rel="nofollow">https://www.ralfj.de/blog/2016/01/09/the-scope-of-unsafe.htm...</a></p>
]]></description><pubDate>Fri, 24 Jul 2026 17:34:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=49039071</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=49039071</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49039071</guid></item><item><title><![CDATA[New comment by ammar2 in "I hate compilers"]]></title><description><![CDATA[
<p>If you feel like increasing your power as per your post, this is a somewhat decent first LLVM issue, take a look at WebAssemblyCFGStackify.cpp :)<p>llvm/test/CodeGen/WebAssembly/cfg-stackify-eh.ll and friends are existing tests that you can kinda mangle if you want to get a good reproducer.<p>Also take a look at <a href="https://discourse.llvm.org/t/reverse-iteration-bots/72224" rel="nofollow">https://discourse.llvm.org/t/reverse-iteration-bots/72224</a><p>Otherwise, happy to put my reproducer/patch on the bug after you file it!</p>
]]></description><pubDate>Thu, 18 Jun 2026 18:21:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=48589377</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48589377</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48589377</guid></item><item><title><![CDATA[New comment by ammar2 in "I hate compilers"]]></title><description><![CDATA[
<p>Not sure if it's a stated goal somewhere official but there's been plenty of fixes of the years moving stuff to be deterministic, e.g <a href="https://github.com/llvm/llvm-project/commit/cdbde3aacc1260a72d49b9aa7271b4bbec694e83" rel="nofollow">https://github.com/llvm/llvm-project/commit/cdbde3aacc1260a7...</a><p>The internal programming guide also says which collections to use for deterministic iteration order: <a href="https://llvm.org/docs/ProgrammersManual.html#llvm-adt-setvector-h" rel="nofollow">https://llvm.org/docs/ProgrammersManual.html#llvm-adt-setvec...</a><p>So definitely a bug here.</p>
]]></description><pubDate>Thu, 18 Jun 2026 17:15:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=48588488</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48588488</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48588488</guid></item><item><title><![CDATA[New comment by ammar2 in "Web Browsers on Video Game Consoles"]]></title><description><![CDATA[
<p>The PS5 also runs apps (games/browser) under a hypervisor. There was a hypervisor escape though coupled with webkit as an entrypoint:<p>* <a href="https://ps5dev.github.io/ps5-wiki/hypervisor" rel="nofollow">https://ps5dev.github.io/ps5-wiki/hypervisor</a><p>* <a href="https://github.com/PS5Dev/Byepervisor" rel="nofollow">https://github.com/PS5Dev/Byepervisor</a><p>* <a href="https://github.com/PS5Dev/PS5-UMTX-Jailbreak/blob/main/README.md" rel="nofollow">https://github.com/PS5Dev/PS5-UMTX-Jailbreak/blob/main/READM...</a></p>
]]></description><pubDate>Thu, 11 Jun 2026 17:48:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48493807</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48493807</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48493807</guid></item><item><title><![CDATA[New comment by ammar2 in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>> GitHub runs a great program on HackerOne<p>I agree, for the record here's my HackerOne profile <a href="https://hackerone.com/ammar2/hacktivity?type=user" rel="nofollow">https://hackerone.com/ammar2/hacktivity?type=user</a><p>Just for context, that 2023 bug was initially reported to GitHub's HackerOne program and they explicitly told me it was out of scope for them and to take it to MSRC:<p>> We have reviewed the report and determined that the vulnerabilities is in VS code and the fix will be implemented by Microsoft. As a result, it is not eligible for reward under the Bug Bounty program. Please follow-up with Microsoft via the report you submitted.<p>There was also an additional bug that allowed an attacker to exfiltrate private repo contents with a github.dev link that MSRC also marked as not having security impact.<p>I absolutely loved working with GitHub folks on the GitHub bug bounty program, they're responsive, go into technical details with you and are awesome to deal with. MSRC is like the polar opposite of that.</p>
]]></description><pubDate>Wed, 03 Jun 2026 18:48:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48388102</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48388102</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48388102</guid></item><item><title><![CDATA[New comment by ammar2 in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>heh, a friend actually pointed out a typo on a first draft and said "maybe you shouldn't fix it to show it's not LLM written".</p>
]]></description><pubDate>Wed, 03 Jun 2026 16:43:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=48386371</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48386371</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48386371</guid></item><item><title><![CDATA[New comment by ammar2 in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>It's not just based on that, if you read the linked report from 2023 (<a href="https://blog.ammaraskar.com/vscode-rce/" rel="nofollow">https://blog.ammaraskar.com/vscode-rce/</a>), I had a bug with the exact same impact of token exfiltration (It did need one additional click on the VSCode interface). They marked it as low severity, fixed it silently, didn't acknowledge that it had security impact and did not provide me any credit much less a bounty.</p>
]]></description><pubDate>Wed, 03 Jun 2026 15:36:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=48385519</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48385519</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48385519</guid></item><item><title><![CDATA[New comment by ammar2 in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>Update as of 3rd June: Microsoft has fixed this with a stopgap  fix by adding a confirmation when opening notebooks in web VSCode and not allowing trusted publisher to be skipped by commands (<a href="https://github.com/microsoft/vscode/pull/319705" rel="nofollow">https://github.com/microsoft/vscode/pull/319705</a>).<p>That's probably one of the fastest responses I've seen from a vendor.</p>
]]></description><pubDate>Wed, 03 Jun 2026 13:27:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48383729</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48383729</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48383729</guid></item><item><title><![CDATA[New comment by ammar2 in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>You cannot, it doesn't go through the regular OAuth flow. GitHub just automatically grants it a token.</p>
]]></description><pubDate>Wed, 03 Jun 2026 13:06:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48383489</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48383489</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48383489</guid></item><item><title><![CDATA[New comment by ammar2 in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>1 and 2 are correct, take a look at the PoC repo here: <a href="https://github.com/ammaraskar/github-dev-token-steal-poc/tree/main/.vscode/extensions/my-extension" rel="nofollow">https://github.com/ammaraskar/github-dev-token-steal-poc/tre...</a><p>We can try to just put a `my-extension/extension.js` for the most direct execution but the CSP blocks that. It's only a script-src CSP blocking it though, so fetching the package.json is still kosher. So we end up using it to contribute a keybinding instead.</p>
]]></description><pubDate>Wed, 03 Jun 2026 04:43:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=48379993</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48379993</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48379993</guid></item><item><title><![CDATA[New comment by ammar2 in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>Thank you, that's a very kind comment.<p>I have no interest in selling these vulnerabilities or sitting on them. At the same time, it feels really bad to have a vendor disrespect the hours it can take to make a proof-of-concept by just patching it silently and not crediting you or acknowledging it.</p>
]]></description><pubDate>Wed, 03 Jun 2026 04:24:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48379881</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48379881</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48379881</guid></item><item><title><![CDATA[New comment by ammar2 in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>> instead of clout<p>I'm catching up on the infosec twitter side but it seems like it was even worse. A lot of people have the same story as me in 2023 of "they silently patch the bug and don't even credit you" which really stinks.</p>
]]></description><pubDate>Wed, 03 Jun 2026 03:42:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48379625</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48379625</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48379625</guid></item><item><title><![CDATA[New comment by ammar2 in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>> it'd be awesome if the in-browser IDE launched with a temporary per-repo permission scope<p>That's actually exactly what they do for codespaces. The token only has read/write on the repo you activated for the codespace [1]. They should definitely consider doing that for github.dev as well.<p>[1] <a href="https://orca.security/resources/blog/hacking-github-codespaces-rce-supply-chain-attack/#h-what-is-the-immediate-impact" rel="nofollow">https://orca.security/resources/blog/hacking-github-codespac...</a></p>
]]></description><pubDate>Wed, 03 Jun 2026 03:38:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48379598</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48379598</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48379598</guid></item><item><title><![CDATA[1-Click GitHub Token Stealing via a VSCode Bug]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.ammaraskar.com/github-token-stealing/">https://blog.ammaraskar.com/github-token-stealing/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48371562">https://news.ycombinator.com/item?id=48371562</a></p>
<p>Points: 660</p>
<p># Comments: 101</p>
]]></description><pubDate>Tue, 02 Jun 2026 15:29:05 +0000</pubDate><link>https://blog.ammaraskar.com/github-token-stealing/</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48371562</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48371562</guid></item><item><title><![CDATA[New comment by ammar2 in "GitHub is investigating unauthorized access to their internal repositories"]]></title><description><![CDATA[
<p>Also, the Github enterprise code is "obfuscated" but it uses a trivially reversible method just meant to be a minor roadblock. After you get past that you get the full ruby source code, no minification or anything.<p>For a while the key was literally:<p>> This obfuscation is intended to discourage GitHub Enterprise customers from making modifications to the VM. We know this 'encryption' is easily broken.</p>
]]></description><pubDate>Wed, 20 May 2026 16:07:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48209994</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48209994</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48209994</guid></item><item><title><![CDATA[New comment by ammar2 in "Composer leaks contents of tokens configured as GitHub OAuth tokens"]]></title><description><![CDATA[
<p>Aah, the newlines were the thing I was missing. That makes sense then.</p>
]]></description><pubDate>Wed, 13 May 2026 20:16:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48126903</link><dc:creator>ammar2</dc:creator><comments>https://news.ycombinator.com/item?id=48126903</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48126903</guid></item></channel></rss>