<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: entuno</title><link>https://news.ycombinator.com/user?id=entuno</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 18 Aug 2026 14:59:29 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=entuno" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by entuno in "Vulnerability reports are not special anymore"]]></title><description><![CDATA[
<p>In most cases I'd think it's <i>more</i> of a deterrent for commercial entities, because spending money create complexity. Most employees are not in a position to just directly spend their organisation's money, so that $0.05 will often mean needing to get approval, purchase orders, deciding which cost centre it comes from, needing an invoice, etc, etc.<p>Very few people are going to invest that much effort when they're trying to do the company that they're reporting to a favour.</p>
]]></description><pubDate>Mon, 29 Jun 2026 21:02:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48725182</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=48725182</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48725182</guid></item><item><title><![CDATA[New comment by entuno in "Vulnerability reports are not special anymore"]]></title><description><![CDATA[
<p>There's an assumption in here that every developer is spending a load of money on the latest and most capable LLMs to scan for bugs in their code before every release.<p>But the last couple of decades have shown us that huge numbers of developers aren't even following basic and <i>free</i> secure development practices, let alone pouring money into expensive scanning tools.</p>
]]></description><pubDate>Wed, 24 Jun 2026 11:37:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48658249</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=48658249</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48658249</guid></item><item><title><![CDATA[New comment by entuno in "Vulnerability reports are not special anymore"]]></title><description><![CDATA[
<p>There is a history of companies and organisations threatening legal action against security researchers when they report vulnerabilities in their systems or products.<p>Sometimes even when the testing has been completely offline - I know people who have downloaded some software, carried out testing against a local copy of it, and then faced legal threats when they tried to report serious security vulnerabilities to the vendor.<p>It's one of the reasons that some researchers don't bother trying to talk to the vendors and just go straight to full disclosure, or if they do report to vendors they do so anonymously. But if you have to pay, that's creating a link back to yourself which makes the latter much harder.</p>
]]></description><pubDate>Wed, 24 Jun 2026 11:30:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48658179</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=48658179</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48658179</guid></item><item><title><![CDATA[New comment by entuno in "Vulnerability reports are not special anymore"]]></title><description><![CDATA[
<p>If I've stumbled across what I think is a security issue in your systems, there is zero chance that I'm going to get out my credit card and pay you for the privilege of responsibly disclosing it to you. <i>Especially</i> if it's the vulnerability is in the site hosting the contact form.</p>
]]></description><pubDate>Wed, 24 Jun 2026 11:27:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48658147</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=48658147</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48658147</guid></item><item><title><![CDATA[New comment by entuno in "The new HTTP QUERY method explained"]]></title><description><![CDATA[
<p>Historically there have been vulnerabilities in various applications due to HTTP method tampering, and in the days of people accidentally leaving WebDAV enabled then methods like PUT and DELETE could be very damaging. Plus the issues with TRACK and TRACE.<p>Given that most websites only ever use a handful of methods (even once you account for REST APIs using PUT, PATCH and DELETE now), and that list very rarely changes, the WAF developers tend to look at this question from the opposite angle: when you know there are only half a dozen widely used methods, why would you allow anything else <i>by default</i>?</p>
]]></description><pubDate>Tue, 23 Jun 2026 13:18:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48644550</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=48644550</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48644550</guid></item><item><title><![CDATA[New comment by entuno in "The new HTTP QUERY method explained"]]></title><description><![CDATA[
<p>AWS CloudFront blocks GET requests with a body, so it doesn't even have to be a particularly strict setup or an explicit WAF.</p>
]]></description><pubDate>Tue, 23 Jun 2026 13:04:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=48644381</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=48644381</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48644381</guid></item><item><title><![CDATA[New comment by entuno in "A backdoor in a LinkedIn job offer"]]></title><description><![CDATA[
<p>It would be very dependent on the exact circumstances - who made a complaint, what exactly they're accusing you of, what evidence there is, how high profile it is, the current diplomatic position (which changes by the hour), etc, etc. I don't think you can really get a simple answer for this kind of question.</p>
]]></description><pubDate>Tue, 16 Jun 2026 11:40:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48553652</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=48553652</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48553652</guid></item><item><title><![CDATA[New comment by entuno in "A backdoor in a LinkedIn job offer"]]></title><description><![CDATA[
<p>Legally speaking, no - it would still be a criminal offence.<p>Practically speaking, there is zero chance that the USA would extradite someone to Iran, even if they weren't currently at war with them. Whether they did anything about it would probably depend on exactly what the situation was - there's a big of difference between targeted IRGC or defence systems and ransomwaring an Iranian hospital or scamming random citizens.<p>Where they'd probably get you is if you tried to monetise it, and get stolen/extorted cryptocurrencies (or whatever) into your bank account. But that could easily fall under tax evasion laws rather than computer misuse ones, because they'd be a lot easier to prove in court.</p>
]]></description><pubDate>Tue, 16 Jun 2026 10:51:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48553267</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=48553267</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48553267</guid></item><item><title><![CDATA[New comment by entuno in "Measles surge in Utah sparks fears US could undo decades of progress"]]></title><description><![CDATA[
<p>The Daily Mail is a trashy tabloid, so it's not surprising. Weird to see it posted here as though it's a credible source for anything.</p>
]]></description><pubDate>Sun, 14 Jun 2026 17:03:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48529660</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=48529660</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48529660</guid></item><item><title><![CDATA[New comment by entuno in "Car headlights don't have to be this blinding"]]></title><description><![CDATA[
<p>They can be pretty shitty if you're a pedestrian or cyclist, because quite a lot of them don't "see" you, so you just get blinded by the full beams.</p>
]]></description><pubDate>Thu, 11 Jun 2026 16:13:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=48492343</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=48492343</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48492343</guid></item><item><title><![CDATA[YellowKey Bitlocker Bypass Vulnerability]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/Nightmare-Eclipse/YellowKey">https://github.com/Nightmare-Eclipse/YellowKey</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48114997">https://news.ycombinator.com/item?id=48114997</a></p>
<p>Points: 87</p>
<p># Comments: 20</p>
]]></description><pubDate>Tue, 12 May 2026 21:42:27 +0000</pubDate><link>https://github.com/Nightmare-Eclipse/YellowKey</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=48114997</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48114997</guid></item><item><title><![CDATA[New comment by entuno in "NetHack 5.0.0"]]></title><description><![CDATA[
<p>There's been a lot of nice quality of life changes in the 3.7 builds (which has now become 5.0.0) that make going back to the older versions a bit painful.<p>Also some pretty major gameplay and balance changes, some of which are pretty controversial. But overall, I think that it's a big improvement, and although I don't necessarily agree with all the changes it certainly makes the mid and late game a lot more interesting and varied (not to mention dangerous) than it was in 3.6.7.</p>
]]></description><pubDate>Sat, 02 May 2026 19:29:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=47989616</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=47989616</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47989616</guid></item><item><title><![CDATA[New comment by entuno in "Game devs explain the tricks involved with letting you pause a game"]]></title><description><![CDATA[
<p>Against the Storm (and excellent rouguelite city-builder) does this in a really cool way. Pausing is a core mechanic of the game, and you frequently pause while you place building or things like that - and all the visual animations stop (fire, rain, trees swaying, etc).<p>But when you find a broken ancient seal in the forest, the giant creepy eyeball moving around in it keeps moving even when you pause the game, which helps emphasise how other-worldly it is.</p>
]]></description><pubDate>Sun, 19 Apr 2026 09:08:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47822905</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=47822905</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47822905</guid></item><item><title><![CDATA[New comment by entuno in "Sam Vimes 'Boots' Theory of Socio-Economic Unfairness"]]></title><description><![CDATA[
<p>> The reason that the rich were so rich, Vimes reasoned, was because they managed to spend less money.<p>The "boots" item feels less true, because expensive doesn't seem to be as correlated with "good quality" as it used to. But the general statement still very much stands.<p>Things like financial products that charge higher interest rates to poorer people, or services that offer discounts for paying annually rather than monthly are great examples of this. And less direct things, like being able to drive to cheaper shops and buy in bulk, or being able to do preventative maintenance to avoid a cheap fix turning into an expensive one.<p>It can still apply to individual items, as long as you're careful about what you buy and do your research to make sure you're <i>actually</i> buying high quality boots, and not just cheap ones with an expensive logo on the side.</p>
]]></description><pubDate>Wed, 15 Apr 2026 15:22:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=47780394</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=47780394</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47780394</guid></item><item><title><![CDATA[New comment by entuno in "Sam Vimes 'Boots' Theory of Socio-Economic Unfairness (2022)"]]></title><description><![CDATA[
<p>Expensive doesn't guarantee high quality, but very cheap almost always means low quality. A £200 pair of boots might be great and last for a decade, or might be overpriced and fall apart after six months. But a £5 pair are definitely going to be crap.</p>
]]></description><pubDate>Wed, 15 Apr 2026 15:14:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47780288</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=47780288</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47780288</guid></item><item><title><![CDATA[New comment by entuno in "Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It"]]></title><description><![CDATA[
<p>Financial costs won't solve the problem for companies, because they're hard to enforce. You'd be weighting up the cost of dealing with the fallout of getting hacked against the cost of paying the random and the <i>chance</i> that you might get caught and fined. If that former cost is existential for the business, then it'd always be worth paying and taking the risk.<p>The only real way around that would personal consequences for the owners/directors of the company - "get caught paying a ransom and the whole board goes to jail" would certainly discourage people. And also provide a wonderful opportunity for blackmail when people did.<p>Not to mention all the problems of fining public sector organisations, and how counter-productive that usually is.</p>
]]></description><pubDate>Tue, 14 Apr 2026 15:57:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=47767347</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=47767347</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47767347</guid></item><item><title><![CDATA[New comment by entuno in "Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It"]]></title><description><![CDATA[
<p>Plus it gives the ransomware gangs a whole new angle they can use.<p><i>So, remember how you illegally paid us a ransom a few months ago? Unless you want to go to prison, then you better...</i><p>We're already seeing this against companies who pay ransoms and fail to report the breaches when they're legally required to - but it would be much worse if it's against individuals who are criminally liable.</p>
]]></description><pubDate>Tue, 14 Apr 2026 12:11:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=47764573</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=47764573</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47764573</guid></item><item><title><![CDATA[New comment by entuno in "Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It"]]></title><description><![CDATA[
<p>It's one of those ideas that sounds nice in theory, but doesn't survive contact with the real world. In the same way that many people would say that you shouldn't negotiate with terrorists or kidnappers; but if it's <i>their</i> loved one who's being held and tortured they'll very quickly change their mind.<p>Getting to a world where no one pays ransoms and the ransomware groups give up and go away would be the ideal, and we'd all love to get there. But outlawing paying ransoms basically sacrificing everyone who gets ransomwared in the meantime until we get to that state for the greater good.<p>And where companies get hit, they'll try hard to find ways around that, because the alternative may well be shutting down the business. But if something like a hospital gets hit, are governments really going to be able to stand behind the "you can't pay a ransom" policy when that could directly lead to deaths?</p>
]]></description><pubDate>Tue, 14 Apr 2026 11:39:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=47764288</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=47764288</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47764288</guid></item><item><title><![CDATA[New comment by entuno in "The Physics and Economics of Moving 44 Tonnes at 56mph"]]></title><description><![CDATA[
<p>I've also seen roads that have these kind of signs, but they only apply during busy hours.<p>However, as with any traffic controls they're useless if they're not actually enforced. Which is a shame, because it'd be absolutely trivial to automate that detection with cameras.</p>
]]></description><pubDate>Thu, 26 Feb 2026 13:35:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=47165891</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=47165891</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47165891</guid></item><item><title><![CDATA[New comment by entuno in "Goodbye InnerHTML, Hello SetHTML: Stronger XSS Protection in Firefox 148"]]></title><description><![CDATA[
<p>If that'd been the design from the start, then sure. But it's not at all obvious that setHTML is safe with arbitrary user input (for a given value of "safe") and innerHTML is dangerous.</p>
]]></description><pubDate>Tue, 24 Feb 2026 17:16:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=47139695</link><dc:creator>entuno</dc:creator><comments>https://news.ycombinator.com/item?id=47139695</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47139695</guid></item></channel></rss>