<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: arwt</title><link>https://news.ycombinator.com/user?id=arwt</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 11 Oct 2026 09:52:56 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=arwt" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by arwt in "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"]]></title><description><![CDATA[
<p>You can. See: <a href="https://docs.astral.sh/uv/reference/cli/#uv-run--exclude-newer" rel="nofollow">https://docs.astral.sh/uv/reference/cli/#uv-run--exclude-new...</a><p>How you use it depends on your workflow. An entry like this in your pyproject.toml could suffice:<p><pre><code>  [tool.uv]
  exclude-newer = "5 days"</code></pre></p>
]]></description><pubDate>Tue, 24 Mar 2026 23:45:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=47511213</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=47511213</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47511213</guid></item><item><title><![CDATA[New comment by arwt in "100M-Row Challenge with PHP"]]></title><description><![CDATA[
<p>You can check the benchmarks here: <a href="https://github.com/tempestphp/100-million-row-challenge/blob/main/leaderboard.csv" rel="nofollow">https://github.com/tempestphp/100-million-row-challenge/blob...</a><p>A "good" run seems to be around 20-40s mark.</p>
]]></description><pubDate>Thu, 26 Feb 2026 02:20:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=47160986</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=47160986</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47160986</guid></item><item><title><![CDATA[Use digests, not tags, in your Dockerfiles]]></title><description><![CDATA[
<p>Article URL: <a href="https://interrupt.sh/blog/dockerfile-tags/">https://interrupt.sh/blog/dockerfile-tags/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47081940">https://news.ycombinator.com/item?id=47081940</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 20 Feb 2026 00:26:42 +0000</pubDate><link>https://interrupt.sh/blog/dockerfile-tags/</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=47081940</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47081940</guid></item><item><title><![CDATA[Discovering Domains via NS Correlation]]></title><description><![CDATA[
<p>Article URL: <a href="https://interrupt.sh/blog/discovering-domains-via-ns-correlation/">https://interrupt.sh/blog/discovering-domains-via-ns-correlation/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47039950">https://news.ycombinator.com/item?id=47039950</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 16 Feb 2026 20:33:11 +0000</pubDate><link>https://interrupt.sh/blog/discovering-domains-via-ns-correlation/</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=47039950</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47039950</guid></item><item><title><![CDATA[Show HN: Killer Crossword]]></title><description><![CDATA[
<p>I used to play this daily with friends, but the original (killercrossword.com - I found this via a Show HN years ago!) appears to be down nowadays, so I have recreated it with the help of my mate Claude.<p>It's a crossword with no clues, just a grid with a few pre-filled letters to get you started. You deduce the words from the letter intersections alone. Like Wordle, there's one set of puzzles per day (resets at midnight local time).<p>The goal is simple: complete the grid in as little time as possible, using as few hints as you can. Then share your score with friends. If the first puzzle is too easy, you can attempt a harder "master" version of it.<p>The entire thing is self-contained, so feel free to save the page and host it elsewhere if you want to guarantee long-term playability.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47009974">https://news.ycombinator.com/item?id=47009974</a></p>
<p>Points: 4</p>
<p># Comments: 1</p>
]]></description><pubDate>Sat, 14 Feb 2026 00:39:51 +0000</pubDate><link>https://killer-crossword.interrupt.sh/</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=47009974</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47009974</guid></item><item><title><![CDATA[1-Click RCE to steal your Moltbot data and keys]]></title><description><![CDATA[
<p>Article URL: <a href="https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys">https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46848769">https://news.ycombinator.com/item?id=46848769</a></p>
<p>Points: 178</p>
<p># Comments: 72</p>
]]></description><pubDate>Sun, 01 Feb 2026 19:47:47 +0000</pubDate><link>https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=46848769</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46848769</guid></item><item><title><![CDATA[New comment by arwt in "SEC obtains final consent judgments against former FTX and Alameda executives"]]></title><description><![CDATA[
<p>There are hundreds of shady crypto projects in the world right now, each one shadier than the last.<p>World order is out of the door, and has been for a while -- they are all probably fighting amongst themselves to get her onto their board ASAP.</p>
]]></description><pubDate>Sat, 24 Jan 2026 04:04:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=46740949</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=46740949</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46740949</guid></item><item><title><![CDATA[New comment by arwt in "Laracasts: I'm Done [video]"]]></title><description><![CDATA[
<p>Reminds me of the Tailwind situation.<p>I feel bad for Jeff and more importantly all of the staff members who are now out of a job. Laracasts was the first ever sort of online course I paid for, and I got immense value out of it at that time.<p>But times change. This is more true now than ever.<p>It is a brutal world. Good luck to them.</p>
]]></description><pubDate>Sat, 24 Jan 2026 03:49:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=46740890</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=46740890</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46740890</guid></item><item><title><![CDATA[New comment by arwt in "Certificate Transparency Log Explorer"]]></title><description><![CDATA[
<p>I implemented something similar a while back (exists just as a portfolio demo now: subpinger (dot) interrupt (dot) sh).<p>If you want go for that sort of "live" feeling, you should consider implementing websocket streaming instead of HTTP polling, it will feel a lot nicer for users.<p>Are you actually ingesting certificates or are you just showing a stream of entries from different logs? I figure the former as nothing seems to be searchable -- and ingesting this data can get very expensive very quickly.<p>Nevertheless, cool project! I am constantly thinking about ways to turn CT log data into meaningful, actionable streams for others. If you'd be up for working on something together, give me a shout!</p>
]]></description><pubDate>Sat, 24 Jan 2026 02:56:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=46740628</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=46740628</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46740628</guid></item><item><title><![CDATA[Show HN: PopTogether – A calm game where strangers work together to pop bubbles]]></title><description><![CDATA[
<p>Article URL: <a href="https://poptogether.club/">https://poptogether.club/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46734417">https://news.ycombinator.com/item?id=46734417</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 23 Jan 2026 16:29:55 +0000</pubDate><link>https://poptogether.club/</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=46734417</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46734417</guid></item><item><title><![CDATA[New comment by arwt in "Ask HN: Purchasing a "Premium" Domain"]]></title><description><![CDATA[
<p>Is there anything stopping you from transferring it to a different registrar before renewal, who might not charge you as much?<p>Or is the renewal price for "premium" domains controlled by the registry (e.g. Verisign)?</p>
]]></description><pubDate>Sat, 17 Jan 2026 18:00:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=46660253</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=46660253</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46660253</guid></item><item><title><![CDATA[Inside PostHog: SSRF, ClickHouse SQL Escape and Default Postgres Creds to RCE]]></title><description><![CDATA[
<p>Article URL: <a href="https://mdisec.com/inside-posthog-how-ssrf-a-clickhouse-sql-escaping-0day-and-default-postgresql-credentials-formed-an-rce-chain-zdi-25-099-zdi-25-097-zdi-25-096/">https://mdisec.com/inside-posthog-how-ssrf-a-clickhouse-sql-escaping-0day-and-default-postgresql-credentials-formed-an-rce-chain-zdi-25-099-zdi-25-097-zdi-25-096/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46305321">https://news.ycombinator.com/item?id=46305321</a></p>
<p>Points: 110</p>
<p># Comments: 35</p>
]]></description><pubDate>Wed, 17 Dec 2025 20:50:13 +0000</pubDate><link>https://mdisec.com/inside-posthog-how-ssrf-a-clickhouse-sql-escaping-0day-and-default-postgresql-credentials-formed-an-rce-chain-zdi-25-099-zdi-25-097-zdi-25-096/</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=46305321</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46305321</guid></item><item><title><![CDATA[New comment by arwt in "Ask HN: Hetzner asking for passport for new account? just me, or everyone?"]]></title><description><![CDATA[
<p>You raised some red flags with the information you provided. This doesn't happen to everyone. A support rep from Hetzner has spoke a bit more about this process on WebHostingTalk before[1], although they don't get into which specific heuristics may result in flagged accounts for obvious reasons. I'd imagine it's a combination of things like unpaid balances on previous accounts, IP address reputation, uncommon e-mail domains and so on.<p>[1] <a href="https://www.webhostingtalk.com/showthread.php?t=1810197&p=10239313#post10239313" rel="nofollow">https://www.webhostingtalk.com/showthread.php?t=1810197&p=10...</a></p>
]]></description><pubDate>Tue, 25 Nov 2025 21:33:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=46051067</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=46051067</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46051067</guid></item><item><title><![CDATA[New comment by arwt in "Show HN: SadServers – Test your Linux troubleshooting skills"]]></title><description><![CDATA[
<p>Interesting idea! Looking forward to trying this once some VMs are available. :-)</p>
]]></description><pubDate>Thu, 27 Oct 2022 00:38:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=33351527</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=33351527</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33351527</guid></item><item><title><![CDATA[New comment by arwt in "Zooko's Triangle"]]></title><description><![CDATA[
<p>Very interesting read. Thank you!</p>
]]></description><pubDate>Thu, 18 Aug 2022 02:33:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=32504564</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=32504564</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32504564</guid></item><item><title><![CDATA[New comment by arwt in "Zooko's Triangle"]]></title><description><![CDATA[
<p>I'd love to see some insight as to how they were able to generate that domain name. Surely if they can do that (years ago, even), then a well-funded adversary would be able to generate the same now, given enough time.<p>Maybe it took x thousands of compute years to generate the secret key for `facebokcorewww` - and they didn't care about the last character. But still, let's say you're a government agency with endless resources - how hard would it be to recreate that private key? If a private corp can do it once with finite resources - why can't you?<p>Was it is just a stroke of luck for those working on it? What are the chances?</p>
]]></description><pubDate>Thu, 18 Aug 2022 02:01:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=32504322</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=32504322</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32504322</guid></item><item><title><![CDATA[New comment by arwt in "The new USB Rubber Ducky is more dangerous than ever"]]></title><description><![CDATA[
<p>The risk has always been there with this kind of attack. The severity, as always, depends on the attackers' modus operandi. Nothing has changed. Only the tools which are dropped onto the machine have changed - which really isn't specifically relevant to this kind of attack. (Spy|Mal)ware adapts, as it always will. Harvesting saved browser passwords is nothing new. In this case, it's a marketing gimmick.<p>It's fun that it is customisable via a programming language. But really - this doesn't add anything new to the table at all. I bet you could do all of this with the previous generation of rubber duckies with a little bit of know-how. Drop a basic reverse shell (providing no firewall restrictions or whatever), and you can do what you want.<p>The same prevention guidelines apply as always. Don't plug random USB devices into your computer.</p>
]]></description><pubDate>Thu, 18 Aug 2022 01:45:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=32504212</link><dc:creator>arwt</dc:creator><comments>https://news.ycombinator.com/item?id=32504212</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32504212</guid></item></channel></rss>