<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: cartoonworld</title><link>https://news.ycombinator.com/user?id=cartoonworld</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 30 Apr 2026 07:15:56 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=cartoonworld" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by cartoonworld in "Vulnerability research is cooked"]]></title><description><![CDATA[
<p>I feel like the dream of static analysis was always a pipe.<p>When the payment for vulns drops i'm wondering where the value is for hackers to run these tools anymore? The LLMs don't do the job for you, testing is still a LOT OF WORK.</p>
]]></description><pubDate>Mon, 30 Mar 2026 20:49:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47579537</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=47579537</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47579537</guid></item><item><title><![CDATA[New comment by cartoonworld in "Vulnerability research is cooked"]]></title><description><![CDATA[
<p>lots of security issues form at the boundaries between packages, zones, services, sessions, etc. Static analysis could but doesn't seem to catch this stuff from my perspective. Bugs are often chains and that requires a lot of creativity, planning etc<p>consider logic errors and race conditions. Its surely not impossible for llm to find these, but it seems likely that you'll need to step throught the program control flow in order to reveal a lot of these interactions.<p>I feel like people consider LLM as free since there isn't as much hand-on-keyboard. I kinda disgree, and when the cost of paying out these vulns falls, I feel like nobody is gonna wanna eat the token spend. Plenty of hackers already use ai in their workflows, even then it is a LOT OF WORK.</p>
]]></description><pubDate>Mon, 30 Mar 2026 20:46:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=47579515</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=47579515</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47579515</guid></item><item><title><![CDATA[New comment by cartoonworld in "GrapheneOS – Break Free from Google and Apple"]]></title><description><![CDATA[
<p>Thanks, this is very good information!<p>To answer your question, I thought it might just be slightly harder to extract secrets or exploit a running process directly. Thats all I was saying.</p>
]]></description><pubDate>Tue, 17 Feb 2026 13:33:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=47047320</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=47047320</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47047320</guid></item><item><title><![CDATA[New comment by cartoonworld in "GrapheneOS – Break Free from Google and Apple"]]></title><description><![CDATA[
<p>5G CSS is harder yes, but keep in mind that most 5G is the 5G_NSA variety, and is really just riding on the same cell bands, no mmwave here. You probably notice that your phone often slips out of 5g, or you inhabit different modes here.<p>Essentially, 5G is sort of a lie. Phones spend a lot of time exchanging information via 4g/lte, and just like 2g/3g and 3g/4g, there are simply downgrades that can be performed in the field, without getting too far into the weeds.<p>5G matters not for this.</p>
]]></description><pubDate>Tue, 17 Feb 2026 13:32:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=47047307</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=47047307</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47047307</guid></item><item><title><![CDATA[New comment by cartoonworld in "GrapheneOS – Break Free from Google and Apple"]]></title><description><![CDATA[
<p>well, a concerted attack could easily subvert the baseband if you have a few million dollars and the correct letterhead or private contacts.<p>GrapheneOS really wants the software in the phone to not pwn the phone. This is good. Its a different, and much more difficult problem to secure the connection to the telco, and the larger internet, because the transport is attacker controlled.<p>Think of it this way: Say you use Qubes because security is valued very highly for you. Even if you run Qubes, if your router is controlled by your attacker, what kind of a security guarantee could you really get for yourself?</p>
]]></description><pubDate>Tue, 17 Feb 2026 13:29:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=47047286</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=47047286</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47047286</guid></item><item><title><![CDATA[New comment by cartoonworld in "GrapheneOS – Break Free from Google and Apple"]]></title><description><![CDATA[
<p>GrapheneOS have hardened_malloc which is a huge advantage, I think. It makes the weird machines problem much harder. I would say be very careful, because you can still get previews of images, or old and weird media formats that could be exploitable, and android/GrapheneOS doesn't have the same sorts of policy as say Apple with the iMessage blast door. They control safari, etc.<p>Android's attack surface seems pretty jagged. For example there is only one webrender engine on iOS, where you can run anything you like on Android/GrapheneOS.</p>
]]></description><pubDate>Tue, 17 Feb 2026 11:38:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47046417</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=47046417</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47046417</guid></item><item><title><![CDATA[New comment by cartoonworld in "GrapheneOS – Break Free from Google and Apple"]]></title><description><![CDATA[
<p>fyi a Cell Site Simulator can masquerade as the legitimate telco operator and push type 0 messages to the handset.<p>What that means is they can push malicious settings and configurations (Definitely) and probably malicious firmware to the handset at will. They don't need to code this, they buy the software packages from the usual suspects. Adversary simply needs to put a drt box or a hailstorm or what-not close enough to the handset to do the work.<p>The baseband can do a lot, it has dma (if I recall correctly) and can almost certainly screen look, and extract information from some but not all base bands. This varies.<p>GrapheneOS cannot really influence this, but hardened_malloc could conceivably help. What would be great is a bench firmware re-flash, but I don't want to do this every single day.</p>
]]></description><pubDate>Tue, 17 Feb 2026 11:32:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47046356</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=47046356</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47046356</guid></item><item><title><![CDATA[New comment by cartoonworld in "The engineer who invented the Mars rover suspension in his garage [video]"]]></title><description><![CDATA[
<p>Cool!<p>I just popped in to add that NASA employee Charles White, a scientist involved with the Mars Rover project, also helped make a Burning Man Mars Rover Car (back before Playa Burning Man was completely and utterly torched twice over by Military Industrial Complex Vacationers and Billionaires) and you can hear an interview with him here on Charles White's yt channel: <a href="https://youtu.be/BKGROOedAgI" rel="nofollow">https://youtu.be/BKGROOedAgI</a> (
Mars Rover Art Car interview with Ray Cirino and Charles White )<p>Charles White is a pretty good guy in my opinion, we play the same video game (EvE: Online) Where Charles White is a very, very well known community member who is known as "The Space Pope". He officiates weddings at our Iceland Fanfest gathering and also runs a Suicide Prevention Outreach group in EvE: Online, as well as teaching leadership skills.<p>Here's Charles White giving a presentation as an Official NASA employee about Space and our solar system at EvE Fanfest 2016: 
<a href="https://www.youtube.com/watch?v=Atm6Y_JYPEU" rel="nofollow">https://www.youtube.com/watch?v=Atm6Y_JYPEU</a><p>Heres a interview about EvE: Online with the Space Pope: <a href="https://www.youtube.com/watch?v=dWuj7LfyN4U" rel="nofollow">https://www.youtube.com/watch?v=dWuj7LfyN4U</a><p>anyhow sorry to hijack this about EvE: Online but we have lots of cool people like Scott Manley playing, too: <a href="https://www.youtube.com/watch?v=huZlA0eg12U" rel="nofollow">https://www.youtube.com/watch?v=huZlA0eg12U</a></p>
]]></description><pubDate>Fri, 30 Jan 2026 13:23:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=46824096</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=46824096</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46824096</guid></item><item><title><![CDATA[New comment by cartoonworld in "County pays $600k to pentesters it arrested for assessing courthouse security"]]></title><description><![CDATA[
<p>I mean it was fine for <i>these guys</i> because they got huge press and happen to be in an industry that can handle this. They've got experience, current employment, industry contacts, and there's really barely a functional college curriculum, or certification track for this. You #1 need to be trusted to break in since you know, they teach each other how to break into high-security facilities.<p>I really just wanna point out that getting contracts for government administrative building is already like, way in and near the top of the game, this could have set them back 9 months or none at all, still, someone has to be held accountable when there is an obvious miscarriage like this.<p>I mean they called their boss! They had a special letter! Why didn't shitty sheriff just like demand that the security chief come out and make some calls? 600k sounds fair I suppose but 6 years sure doesn't when its an elected official!</p>
]]></description><pubDate>Fri, 30 Jan 2026 11:05:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=46822991</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=46822991</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46822991</guid></item><item><title><![CDATA[New comment by cartoonworld in "Valve: HDMI Forum Continues to Block HDMI 2.1 for Linux"]]></title><description><![CDATA[
<p>Sure it does, it just always relied on external encoders.<p>I use audacity for recording vinyl occasionally, but for CD audio I have a bunch of cli scripts. Much easier.</p>
]]></description><pubDate>Thu, 11 Dec 2025 09:04:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=46229172</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=46229172</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46229172</guid></item><item><title><![CDATA[New comment by cartoonworld in "Hyundai Paywalls Brake Pads replacement on Ioniq 5 N"]]></title><description><![CDATA[
<p>I have, they're tiny shoes and it'll lock up your rear wheels at best.<p>I would suggest that anybody reading NOT try this unless you have a quite large and empty lot with no public access. Pay close attention, they are not called Emergency Brakes, they are called Parking Brakes.<p>The stated purpose of these brakes are to ensure your car wont roll away while parked. Anybody with a manual transmission knows the ritual of shifting into 1 or Reverse and turning their wheels toward the curb while parked even while the parking brake is engaged.<p>They won't serve you in an emergency. Here's Mitch Hedberg on "Emergency brake": <a href="https://www.youtube.com/watch?v=kMKV1B0vuI8" rel="nofollow">https://www.youtube.com/watch?v=kMKV1B0vuI8</a></p>
]]></description><pubDate>Mon, 17 Nov 2025 06:04:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=45951190</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=45951190</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45951190</guid></item><item><title><![CDATA[New comment by cartoonworld in "Hyundai Paywalls Brake Pads replacement on Ioniq 5 N"]]></title><description><![CDATA[
<p>They also don't really stop a moving car, its a parking brake.<p>Just wanted to add, a EPB used for emergency stop in his scenario is just using the regular stopping brakes, its not an emergency brake either.</p>
]]></description><pubDate>Sun, 16 Nov 2025 17:05:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=45946579</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=45946579</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45946579</guid></item><item><title><![CDATA[New comment by cartoonworld in "Hyundai Paywalls Brake Pads replacement on Ioniq 5 N"]]></title><description><![CDATA[
<p>You can almost always pop the cable (if you have to) and hit the rotor with a hammer, or use a puller.<p>If that doesn't work you hit it with a hammer from the other side until the parking brake shoes pop out of the pins and come off with the rotor.</p>
]]></description><pubDate>Sun, 16 Nov 2025 16:57:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=45946503</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=45946503</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45946503</guid></item><item><title><![CDATA[New comment by cartoonworld in "Hyundai Paywalls Brake Pads replacement on Ioniq 5 N"]]></title><description><![CDATA[
<p>Most people doing the right thing use a torque limiter to "gun" the wheel on and then set final torque with the tires just touching the ground (for friction) which is totally adequate.<p>The thing people might forget is to clear the corrosion off of the wheel and hub which can be a problem if it breaks away as you drive.</p>
]]></description><pubDate>Sun, 16 Nov 2025 16:51:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=45946465</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=45946465</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45946465</guid></item><item><title><![CDATA[New comment by cartoonworld in "Hyundai Paywalls Brake Pads replacement on Ioniq 5 N"]]></title><description><![CDATA[
<p>Thats the same case with all brakes in use more or less. Also modern brakes have two hydraulic systems, in the case that one of the loops (front or rear) breaks there should be sufficient pressure to apply the brakes still.<p>Sometimes its front/rear and sometimes it is diagonal, but it should still do the emergency trick.</p>
]]></description><pubDate>Sun, 16 Nov 2025 16:46:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=45946433</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=45946433</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45946433</guid></item><item><title><![CDATA[New comment by cartoonworld in "How my speed date got stolen onstage at a live comedy dating show"]]></title><description><![CDATA[
<p>At the time hacker meant informal programmer, among other things. “I’m hacking on my book review website” “I’m hacking on a desktop filesharing app.” Those hackers sometimes got a nice swing at it and this place has indeed always been a finance-friendly venue for these nerds to commingle.<p>It’s 2025 and things move along. People still post their file sharing tools here, but yeah I agree that it does hit different now.</p>
]]></description><pubDate>Sat, 15 Nov 2025 16:06:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=45938335</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=45938335</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45938335</guid></item><item><title><![CDATA[New comment by cartoonworld in "Lawmakers want to ban VPNs"]]></title><description><![CDATA[
<p>Very related:<p><a href="https://en.wikipedia.org/wiki/Crypto_Wars" rel="nofollow">https://en.wikipedia.org/wiki/Crypto_Wars</a></p>
]]></description><pubDate>Sat, 15 Nov 2025 08:15:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=45935868</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=45935868</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45935868</guid></item><item><title><![CDATA[New comment by cartoonworld in "Secret Boat Strike Memo Justifies Kills by Claiming Targeting Drugs, Not People"]]></title><description><![CDATA[
<p>Its almost certainly cocaine</p>
]]></description><pubDate>Sat, 15 Nov 2025 05:40:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=45935325</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=45935325</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45935325</guid></item><item><title><![CDATA[New comment by cartoonworld in "Secret Boat Strike Memo Justifies Kills by Claiming Targeting Drugs, Not People"]]></title><description><![CDATA[
<p>I feel like we could do better, quite easily. People are very gung-ho (jing-go?) on this and it seems clear to me that we can use our significant technological advantages and investigatory prowess to target these bad actors just like any other day at the office.<p>This is quite the departure and it is quite troubling to me. The ESA launch site is down there iirc, seems like we have natural allies who would join a push, but instead we sent a carrier group.</p>
]]></description><pubDate>Sat, 15 Nov 2025 05:38:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=45935319</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=45935319</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45935319</guid></item><item><title><![CDATA[New comment by cartoonworld in "Show HN: Epstein Files Organized and Searchable"]]></title><description><![CDATA[
<p>The chilling effect of the executive. The current admin leverages government agencies against the corporation who will report on this if not to their liking.<p>And more!</p>
]]></description><pubDate>Sat, 15 Nov 2025 05:29:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=45935282</link><dc:creator>cartoonworld</dc:creator><comments>https://news.ycombinator.com/item?id=45935282</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45935282</guid></item></channel></rss>