<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: dnet</title><link>https://news.ycombinator.com/user?id=dnet</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 11 Jun 2026 04:35:35 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=dnet" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Unauthenticated RCE as Qsecofr via IBM i Management Central]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.silentsignal.eu/2026/06/05/unauthenticated-rce-as-qsecofr-via-ibm-i-management-central/">https://blog.silentsignal.eu/2026/06/05/unauthenticated-rce-as-qsecofr-via-ibm-i-management-central/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48411055">https://news.ycombinator.com/item?id=48411055</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 05 Jun 2026 11:40:18 +0000</pubDate><link>https://blog.silentsignal.eu/2026/06/05/unauthenticated-rce-as-qsecofr-via-ibm-i-management-central/</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=48411055</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48411055</guid></item><item><title><![CDATA[New comment by dnet in "SSH Secret Menu"]]></title><description><![CDATA[
<p>In newer versions, it's disabled by default and you have to do something like this to enable in ~/.ssh/config:<p><pre><code>    Host *
    EnableEscapeCommandline yes</code></pre></p>
]]></description><pubDate>Wed, 11 Mar 2026 08:57:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=47333198</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=47333198</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47333198</guid></item><item><title><![CDATA[New comment by dnet in "Apple has locked my Apple ID, and I have no recourse. A plea for help"]]></title><description><![CDATA[
<p>See <a href="https://doctorow.medium.com/como-is-infosec-307f87004563" rel="nofollow">https://doctorow.medium.com/como-is-infosec-307f87004563</a><p>> This is the same failure mode of all security-through-obscurity. Secrecy means that bad guys are privy to defects in systems, while the people who those systems are supposed to defend are in the dark, and can have their defenses weaponized against them.</p>
]]></description><pubDate>Sat, 13 Dec 2025 13:08:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=46254275</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=46254275</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46254275</guid></item><item><title><![CDATA[New comment by dnet in "A webshell and a normal file that have the same MD5"]]></title><description><![CDATA[
<p>I assume the scanner is a separate library/service that receives the contents and returns a boolean safe/malicious result, and the implementation using MD5 to avoid expensive re-scans is an internal detail hidden from the caller.</p>
]]></description><pubDate>Wed, 24 Sep 2025 10:50:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=45358621</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=45358621</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45358621</guid></item><item><title><![CDATA[New comment by dnet in "Show HN: Base, an SQLite database editor for macOS"]]></title><description><![CDATA[
<p>While the default is indeed to lock the entire database, it has been an option for 15 years to avoid this: <a href="https://www.sqlite.org/wal.html" rel="nofollow">https://www.sqlite.org/wal.html</a></p>
]]></description><pubDate>Tue, 26 Aug 2025 06:27:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=45022956</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=45022956</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45022956</guid></item><item><title><![CDATA[New comment by dnet in "Stripe is PayPal circa 2010"]]></title><description><![CDATA[
<p>> After several lawsuits and years of backlash Paypal has stopped seizing people's money illegally.<p>Flipper Zero project might disagree:<p><a href="https://nitter.lacontrevoie.fr/flipper_zero/status/1567194641610465281" rel="nofollow">https://nitter.lacontrevoie.fr/flipper_zero/status/156719464...</a><p><a href="https://www.dailydot.com/debug/flipper-zero-paypal/" rel="nofollow">https://www.dailydot.com/debug/flipper-zero-paypal/</a></p>
]]></description><pubDate>Sun, 09 Oct 2022 12:42:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=33140469</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=33140469</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33140469</guid></item><item><title><![CDATA[Hungary's top weather experts fired after wrong forecast on national holiday]]></title><description><![CDATA[
<p>Article URL: <a href="https://telex.hu/english/2022/08/23/hungarys-top-weather-experts-fired-for-wrong-forecast-on-national-holiday">https://telex.hu/english/2022/08/23/hungarys-top-weather-experts-fired-for-wrong-forecast-on-national-holiday</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=32567860">https://news.ycombinator.com/item?id=32567860</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 23 Aug 2022 17:06:09 +0000</pubDate><link>https://telex.hu/english/2022/08/23/hungarys-top-weather-experts-fired-for-wrong-forecast-on-national-holiday</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=32567860</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32567860</guid></item><item><title><![CDATA[New comment by dnet in "How to Store an SSH Key on a Yubikey"]]></title><description><![CDATA[
<p>I made my own CA for this because nothing else could provide transparency regarding certificate issuance (whether an attacker issued a "spare" backdoor certificate)<p>- source code: <a href="https://github.com/silentsignal/zsca" rel="nofollow">https://github.com/silentsignal/zsca</a><p>- my talk about the design and results: <a href="https://pretalx.hsbp.org/camppp7e5/talk/D3E9HN/" rel="nofollow">https://pretalx.hsbp.org/camppp7e5/talk/D3E9HN/</a></p>
]]></description><pubDate>Mon, 30 May 2022 10:45:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=31557585</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=31557585</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31557585</guid></item><item><title><![CDATA[New comment by dnet in "Common libraries and data structures for C"]]></title><description><![CDATA[
<p>Why do you mention AVR? AVR-GCC has C++ support, that's what made the original Arduino (before they switched to ARM) approachable to beginners.</p>
]]></description><pubDate>Tue, 17 May 2022 06:13:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=31406621</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=31406621</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31406621</guid></item><item><title><![CDATA[New comment by dnet in "Plaid is an evil nightmare product from Security Hell"]]></title><description><![CDATA[
<p>> I'm not even sure it's working in the EU yet?<p>It's called PSD2 and it applies EU-wide since September 2019. Banks have to make _some_ form of API available to third parties. However, these third parties must meet certain criteria and get a license in one of the member states. This makes sense since they can access financial data, and they only have to do it once. So a fintech licensed in e.g. Belgium can access the APIs of a bank in France and vice versa. Since banks already have most of the necessary rules and paperwork in place, I've seen many banks themselves become PSD2 clients as well, offering customers the ability to manage "foreign" bank accounts through their app as well.</p>
]]></description><pubDate>Sat, 19 Feb 2022 12:17:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=30396570</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=30396570</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30396570</guid></item><item><title><![CDATA[New comment by dnet in "Apple added an orange dot that’s a showstopper for live visuals"]]></title><description><![CDATA[
<p>Not sure about VLC, but ffmpeg has great support for Blackmagic, you just have to download the Blackmagic SDK, compile ffmpeg with Blackmagic support (and the SDK in path) and then you'll have a separate input/output device available in ffmpeg. The other great thing about this approach is that this way audio also takes a dedicated, integrated path, bypassing OS layers and maintaining sync with much less effort.</p>
]]></description><pubDate>Mon, 20 Dec 2021 20:25:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=29629839</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=29629839</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29629839</guid></item><item><title><![CDATA[Our new tool for enumerating hidden Log4Shell-affected hosts]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.silentsignal.eu/2021/12/12/our-new-tool-for-enumerating-hidden-log4shell-affected-hosts/">https://blog.silentsignal.eu/2021/12/12/our-new-tool-for-enumerating-hidden-log4shell-affected-hosts/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=29533252">https://news.ycombinator.com/item?id=29533252</a></p>
<p>Points: 22</p>
<p># Comments: 3</p>
]]></description><pubDate>Sun, 12 Dec 2021 20:25:07 +0000</pubDate><link>https://blog.silentsignal.eu/2021/12/12/our-new-tool-for-enumerating-hidden-log4shell-affected-hosts/</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=29533252</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29533252</guid></item><item><title><![CDATA[New comment by dnet in "Maintenance windows are a mistake"]]></title><description><![CDATA[
<p>Erlang supports hot reloading by design with no limitations. There can even be some threads using the old and some using the new version simultaneously. It was designed for phone exchanges where they aimed for 9 nines of availability. You can install it on most mainstream operating systems.</p>
]]></description><pubDate>Tue, 05 Oct 2021 11:38:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=28758023</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=28758023</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28758023</guid></item><item><title><![CDATA[New comment by dnet in "A Docker footgun led to a vandal deleting NewsBlur's MongoDB database"]]></title><description><![CDATA[
<p>Not necessarily -- there can be a number of reasons one can access localhost over the loopback interface that does _not_ imply root access: SSRF, misconfigured tunnels, or just a plain unpriviliged account where the attacker couldn't perform privilege escalation (either because the attacker's incompetence or the system being up-to-date and/or hardened)</p>
]]></description><pubDate>Tue, 29 Jun 2021 05:53:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=27672284</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=27672284</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27672284</guid></item><item><title><![CDATA[New comment by dnet in "Abusing JWT public keys without the public key"]]></title><description><![CDATA[
<p>Yet we've had people argue that they wouldn't give us the public part of their JWT RSA signing keypair, because "they wouldn't publish that anyway", hence this post.</p>
]]></description><pubDate>Mon, 08 Feb 2021 09:46:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=26062528</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=26062528</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26062528</guid></item><item><title><![CDATA[Abusing JWT public keys without the public key]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.silentsignal.eu/2021/02/08/abusing-jwt-public-keys-without-the-public-key/">https://blog.silentsignal.eu/2021/02/08/abusing-jwt-public-keys-without-the-public-key/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=26062216">https://news.ycombinator.com/item?id=26062216</a></p>
<p>Points: 2</p>
<p># Comments: 2</p>
]]></description><pubDate>Mon, 08 Feb 2021 09:00:05 +0000</pubDate><link>https://blog.silentsignal.eu/2021/02/08/abusing-jwt-public-keys-without-the-public-key/</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=26062216</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26062216</guid></item><item><title><![CDATA[New comment by dnet in "Switzerland – Europe's Silicon Valley for Developers?"]]></title><description><![CDATA[
<p>Tresorit comes from Hungary, they just made a business entity in Switzerland to look better from security/privacy perspective. See <a href="https://en.wikipedia.org/wiki/Tresorit#History" rel="nofollow">https://en.wikipedia.org/wiki/Tresorit#History</a></p>
]]></description><pubDate>Fri, 27 Nov 2020 18:00:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=25231022</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=25231022</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25231022</guid></item><item><title><![CDATA[New comment by dnet in "Brow.sh: a modern text-based browser"]]></title><description><![CDATA[
<p>Regular SSH won't work if your IP address changes since it uses TCP where sessions are tied to (IP address, port) tuples. However mosh uses UDP and its own session management scheme, so you can "roam" between IP addresses and your session will stay alive, you can continue typing and will receive screen updates as if nothing has happened.</p>
]]></description><pubDate>Wed, 18 Nov 2020 11:17:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=25135505</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=25135505</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25135505</guid></item><item><title><![CDATA[New comment by dnet in "Ask HN: Captcha Alternatives?"]]></title><description><![CDATA[
<p>That wouldn't work for HTTP(S) or anything else that works over TCP since the reply would go towards the fake source IP address, thus the attacker couldn't even get past the 3-way TCP handshake.</p>
]]></description><pubDate>Tue, 01 Sep 2020 07:50:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=24339486</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=24339486</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24339486</guid></item><item><title><![CDATA[New comment by dnet in "GitHub was down"]]></title><description><![CDATA[
<p>But those wouldn't take most of the world's public git repos down all at once just because of a single issue. Single points of failure have a bad reputation for a reason.</p>
]]></description><pubDate>Mon, 13 Jul 2020 07:12:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=23817889</link><dc:creator>dnet</dc:creator><comments>https://news.ycombinator.com/item?id=23817889</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=23817889</guid></item></channel></rss>