<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: captn3m0</title><link>https://news.ycombinator.com/user?id=captn3m0</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 01 Sep 2026 12:08:09 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=captn3m0" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by captn3m0 in "ElevenLabs, TwelveLabs, ThirteenLabs"]]></title><description><![CDATA[
<p>I run a reverse engineering collective that is called 52 Labs: <a href="https://52-1ab.github.io/" rel="nofollow">https://52-1ab.github.io/</a>.<p>> 52 1ab (Pronounced 52 Lab) is a Software Research group dedicated to interoperabilty research in India. It is named after the Section 52(1) (ab) of The Copyright Act which states:<p>>>    The following act shall not constitute an infringement of copyright:<p>>>        the doing of any act necessary to obtain information essential for operating inter-operability of an independently created computer programme with other programmes by a lawful possessor of a computer programme provided that such information is not otherwise readily available.</p>
]]></description><pubDate>Sun, 23 Aug 2026 05:37:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49406282</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=49406282</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49406282</guid></item><item><title><![CDATA[New comment by captn3m0 in "Phones should have a 'guest lock' feature"]]></title><description><![CDATA[
<p>iOS has a hidden album but the UX isn't great: <a href="https://support.apple.com/en-us/104987" rel="nofollow">https://support.apple.com/en-us/104987</a></p>
]]></description><pubDate>Fri, 14 Aug 2026 08:36:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=49296077</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=49296077</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49296077</guid></item><item><title><![CDATA[New comment by captn3m0 in "GLM-5.3: Frontier coding with emergent cyber capabilities"]]></title><description><![CDATA[
<p>I am guessing you are approved for the Cyber Verification Program. I also applied and got approved in an hour (on a Saturday!), but it only applies to Opus and Sonnet: <a href="https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude-opus-and-sonnet" rel="nofollow">https://support.claude.com/en/articles/14604842-real-time-cy...</a>. It let me use Opus for cybersecurity work, pretty much everything except for Ransomware development. It would occasionally still trip and start saying no till I added a note about CVP in my claude.md.<p>No one gets to use Fable for Cybersecurity work, and Mythos is not available under CVP. Only for select few customers, and there isn't an application form?</p>
]]></description><pubDate>Fri, 14 Aug 2026 08:15:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=49295940</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=49295940</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49295940</guid></item><item><title><![CDATA[Show HN: Porting Super Hexagon to the Playdate]]></title><description><![CDATA[
<p>Article URL: <a href="https://captnemo.in/superhexagon/">https://captnemo.in/superhexagon/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49062624">https://news.ycombinator.com/item?id=49062624</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 26 Jul 2026 21:31:33 +0000</pubDate><link>https://captnemo.in/superhexagon/</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=49062624</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49062624</guid></item><item><title><![CDATA[New comment by captn3m0 in "Tell HN: Namecheap gave my account to an unverified third party"]]></title><description><![CDATA[
<p>Namecheap also suspended my primary domain because of a bug at their end: <a href="https://captnemo.in/blog/2026/05/05/namecheap-whois/" rel="nofollow">https://captnemo.in/blog/2026/05/05/namecheap-whois/</a><p>tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.<p>I know a few other people that were impacted.</p>
]]></description><pubDate>Thu, 23 Jul 2026 22:57:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=49029194</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=49029194</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49029194</guid></item><item><title><![CDATA[New comment by captn3m0 in "Reverse-engineering is cheap now"]]></title><description><![CDATA[
<p>I reversed Super Hexagon these last few weeks and ported it to the Playdate (the yellow console from Panic with a crank): <a href="https://old.reddit.com/r/PlaydateConsole/comments/1v1zxmt/i_ported_super_hexagon_to_the_playdate/" rel="nofollow">https://old.reddit.com/r/PlaydateConsole/comments/1v1zxmt/i_...</a><p>The multiplier comes from being able to design arbitrary fast feedback loops - Claude wrote Python scripts to do decompilation matching for itself, and then use Frida traces from the original as a verification harness.</p>
]]></description><pubDate>Tue, 21 Jul 2026 06:58:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48988985</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48988985</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48988985</guid></item><item><title><![CDATA[A Prototype Original iPod]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.panic.com/a-prototype-original-ipod/">https://blog.panic.com/a-prototype-original-ipod/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48896466">https://news.ycombinator.com/item?id=48896466</a></p>
<p>Points: 4</p>
<p># Comments: 1</p>
]]></description><pubDate>Mon, 13 Jul 2026 18:08:36 +0000</pubDate><link>https://blog.panic.com/a-prototype-original-ipod/</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48896466</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48896466</guid></item><item><title><![CDATA[New comment by captn3m0 in "Web-based cryptography is always snake oil"]]></title><description><![CDATA[
<p>There are a lot of other implementations of this idea that don't necessarily rely on trust-on-first-use. The securedrop team explicitly includes malicious JS served by the primary-domain in the threat-model and made WEBCAT[0] as an outcome of that research. Their article on webcrypto is much better than this one.<p>The solution obviously is to go out-of-band:<p>> When a user visits a website that has enrolled in WEBCAT, before the site can load the content is checked against a signed manifest to ensure that it has not been tampered with (more on enrollment later). If everything checks out, the page loads normally. If, however, any content does not match what’s expected, the page load is aborted and a warning is displayed, protecting the user from potentially malicious content before it can execute.<p>[0]: <a href="https://securedrop.org/news/introducing-webcat-web-based-code-assurance-and-transparency/" rel="nofollow">https://securedrop.org/news/introducing-webcat-web-based-cod...</a><p>[1]: <a href="https://securedrop.org/news/browser-based-cryptography/" rel="nofollow">https://securedrop.org/news/browser-based-cryptography/</a></p>
]]></description><pubDate>Sun, 05 Jul 2026 10:05:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48792831</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48792831</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48792831</guid></item><item><title><![CDATA[New comment by captn3m0 in "Command and Conquer Generals natively ported to macOS, iPhone, iPad using Fable"]]></title><description><![CDATA[
<p>This is a OS port (iOS) of an existing functional and maintained fork (MacOS) of the official release (Windows).<p>Most of these low-hanging bugs would have been caught upstream by now.</p>
]]></description><pubDate>Sun, 05 Jul 2026 06:06:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48791645</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48791645</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48791645</guid></item><item><title><![CDATA[New comment by captn3m0 in "Command and Conquer Generals natively ported to macOS, iPhone, iPad using Fable"]]></title><description><![CDATA[
<p>upstream is a MacOS+linux build. <a href="https://github.com/fbraz3/GeneralsX" rel="nofollow">https://github.com/fbraz3/GeneralsX</a>.</p>
]]></description><pubDate>Sat, 04 Jul 2026 20:56:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48789017</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48789017</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48789017</guid></item><item><title><![CDATA[New comment by captn3m0 in "Espionage Against the European Parliament"]]></title><description><![CDATA[
<p>Do we know how Apple sends these? Is it just a notification, or also email?</p>
]]></description><pubDate>Fri, 03 Jul 2026 21:34:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48780270</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48780270</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48780270</guid></item><item><title><![CDATA[New comment by captn3m0 in "Weave Robotics launches Isaac 1, a $7,999 home robot with Fall 2026 deliveries"]]></title><description><![CDATA[
<p>There are 2 complete folds in the Isaac 0 video around 0:40, but speeded up: <a href="https://m.youtube.com/watch?v=KhImSR8GuCE" rel="nofollow">https://m.youtube.com/watch?v=KhImSR8GuCE</a><p>The about page claims 1000+ lbs of laundry folded every week.</p>
]]></description><pubDate>Wed, 01 Jul 2026 22:03:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48753717</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48753717</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48753717</guid></item><item><title><![CDATA[New comment by captn3m0 in ".self: A new top-level domain designed to support self-hosting"]]></title><description><![CDATA[
<p>10% apparently for .tk. I also remember .tv windfall, which is 8-9% of their GDP.</p>
]]></description><pubDate>Mon, 29 Jun 2026 22:10:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48725985</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48725985</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48725985</guid></item><item><title><![CDATA[New comment by captn3m0 in "Streaming services' obnoxiously loud ads become illegal on July 1 in California"]]></title><description><![CDATA[
<p>I wrote superbright to be able to force it: <a href="https://github.com/captn3m0/superbright" rel="nofollow">https://github.com/captn3m0/superbright</a> (fork of BrightIntosh). The display does get hit after 10-15 minutes of this though.</p>
]]></description><pubDate>Sat, 27 Jun 2026 21:41:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48702037</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48702037</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48702037</guid></item><item><title><![CDATA[New comment by captn3m0 in "No AI Co-Authors. A Manifesto"]]></title><description><![CDATA[
<p>When I read the title, I thought it would be for research papers.</p>
]]></description><pubDate>Wed, 24 Jun 2026 07:13:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48656309</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48656309</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48656309</guid></item><item><title><![CDATA[New comment by captn3m0 in "Package Managers need global hooks"]]></title><description><![CDATA[
<p>Hooks are not a new standard. Package managers have always supported hooks. It is just a call to get us to parity.</p>
]]></description><pubDate>Tue, 23 Jun 2026 20:47:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48651153</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48651153</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48651153</guid></item><item><title><![CDATA[New comment by captn3m0 in "Package Managers need global hooks"]]></title><description><![CDATA[
<p>> The problem of everchanging malware isn't fixable by global policies and global rulesets.<p>But it is an important tool that's missing in our toolbox. You could do most of the above, and still get pwned by a typo in an `npx` command. Capability based access management is not likely to land in any large package manager in the next few years, and we need solutions that work today.</p>
]]></description><pubDate>Tue, 23 Jun 2026 12:53:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=48644214</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48644214</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48644214</guid></item><item><title><![CDATA[New comment by captn3m0 in "Package Managers need global hooks"]]></title><description><![CDATA[
<p>Package-level hooks are everywhere: <a href="https://github.com/ecosyste-ms/package-manager-hooks" rel="nofollow">https://github.com/ecosyste-ms/package-manager-hooks</a><p>I wrote this in response to the recent AUR attacks. The problem isn’t really too many dependencies - it is that most users cannot be auditing everything they install and we need mechanisms that help users where they are.<p>I audit my AUR pkg builds, and I would have likely caught any malware. But so would a Dependency Cooldown or a third-party threat feed. Package Managers should make it easy to build this tooling via hooks.</p>
]]></description><pubDate>Tue, 23 Jun 2026 07:40:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48641611</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48641611</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48641611</guid></item><item><title><![CDATA[New comment by captn3m0 in "Package Managers need global hooks"]]></title><description><![CDATA[
<p>Aliases and pre-hooks are nowhere near the guarantees you want, that’s what I am arguing - not everything is invoked from a blessed shell. Safely-bump-does.sh is also impossibly hard to write because you are replicating _all of the work NPM does in transitive dependency resolution_. Unless you are re-generating the lock file from scratch - it isn’t safe. Just updating package.json isn’t sufficient for eg.</p>
]]></description><pubDate>Tue, 23 Jun 2026 07:34:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48641579</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48641579</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48641579</guid></item><item><title><![CDATA[New comment by captn3m0 in "Package Managers need global hooks"]]></title><description><![CDATA[
<p>Author here - people are definitely looking at other places. This just happens to be where the attacks are, and gets disproportionate attention as a result.<p>Do you have examples of campaigns that weren’t flagged? Everything except xz had a 1 day window and Dependency Cooldowns are super effective against most campaigns for that reason.<p>See papers at <a href="https://kokkonisd.github.io/" rel="nofollow">https://kokkonisd.github.io/</a> for eg.</p>
]]></description><pubDate>Tue, 23 Jun 2026 07:30:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48641551</link><dc:creator>captn3m0</dc:creator><comments>https://news.ycombinator.com/item?id=48641551</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48641551</guid></item></channel></rss>