<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: iancarroll</title><link>https://news.ycombinator.com/user?id=iancarroll</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 10 Jun 2026 09:54:28 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=iancarroll" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by iancarroll in "Gov.uk has replaced Stripe with Dutch provider Adyen"]]></title><description><![CDATA[
<p>0.5% is a pretty incredibly low interchange rate in any case. But if you are saying that half of it is going to scheme fees, I doubt it is funding rewards programs for consumers.</p>
]]></description><pubDate>Sat, 06 Jun 2026 10:07:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48423326</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48423326</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48423326</guid></item><item><title><![CDATA[New comment by iancarroll in "Cloudflare Flagship"]]></title><description><![CDATA[
<p>Well, OpenAI already sold it (but kept the team), so it’s in someone else’s hands now.</p>
]]></description><pubDate>Wed, 27 May 2026 15:52:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48296114</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48296114</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48296114</guid></item><item><title><![CDATA[New comment by iancarroll in "Cal.com is going closed source"]]></title><description><![CDATA[
<p>I know plenty of security researchers who exclusively use Claude Code and other tools for blackbox testing against sites they don’t have the source code for. It seems like shutting down the entire product is the only safe decision here!</p>
]]></description><pubDate>Wed, 15 Apr 2026 15:59:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=47780988</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=47780988</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47780988</guid></item><item><title><![CDATA[New comment by iancarroll in "ChatGPT won't let you type until Cloudflare reads your React state"]]></title><description><![CDATA[
<p>It’s pretty interesting to me that Cloudflare is collecting additional client-side data for individual customers. This is not widely done by most anti-bot solutions.</p>
]]></description><pubDate>Mon, 30 Mar 2026 04:33:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47570419</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=47570419</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47570419</guid></item><item><title><![CDATA[New comment by iancarroll in "I decompiled the White House's new app"]]></title><description><![CDATA[
<p>A bit skeptical of how this article is written as it seems to be mostly written by AI. Out of curiosity, I downloaded the app and it doesn't request location permissions anywhere, despite the claims in the article.<p>I've noticed Claude Code is happy to decompile APKs for you but isn't very good at doing reachability analysis or figuring out complex control flows. It will treat completely dead code as important as a commonly invoked function.</p>
]]></description><pubDate>Sat, 28 Mar 2026 16:48:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=47556256</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=47556256</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47556256</guid></item><item><title><![CDATA[New comment by iancarroll in "Verizon imposes new roadblock on users trying to unlock paid-off phones"]]></title><description><![CDATA[
<p>Verizon did manage to convince the FCC that this was enough a problem to change their settlement agreement[0] requiring more frequent unlocks. If you believe their numbers, they lost 700,000 phones to fraud in 2023, although a lot of those were probably any unlocked phone that defaulted on its payments.<p>[0] <a href="https://www.reuters.com/business/media-telecom/fcc-revises-verizon-phone-unlocking-rules-after-significant-fraud-issues-2026-01-12/" rel="nofollow">https://www.reuters.com/business/media-telecom/fcc-revises-v...</a></p>
]]></description><pubDate>Sat, 14 Feb 2026 22:33:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=47019091</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=47019091</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47019091</guid></item><item><title><![CDATA[New comment by iancarroll in "6-Day and IP Address Certificates Are Generally Available"]]></title><description><![CDATA[
<p>That is a very old article that seems to be outdated now.</p>
]]></description><pubDate>Fri, 16 Jan 2026 19:52:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=46651297</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=46651297</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46651297</guid></item><item><title><![CDATA[New comment by iancarroll in "Flock Hardcoded the Password for America's Surveillance Infrastructure 53 Times"]]></title><description><![CDATA[
<p>Although I don’t like Flock, I’m a bit skeptical of the claims in the article. Most screenshots appear to be client-side JavaScript snippets, not API responses from this key.<p>In the bug bounty community, Google Maps API key leaks are a common false positive, because they are only used for billing purposes and don’t actually control access to any data. The article doesn’t really prove ArcGIS is any different.</p>
]]></description><pubDate>Fri, 09 Jan 2026 23:31:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=46560883</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=46560883</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46560883</guid></item><item><title><![CDATA[New comment by iancarroll in "Chase to become new issuer of Apple Card"]]></title><description><![CDATA[
<p>Chase issues cards on both the Visa and Mastercard network (i.e. certain cobrands and the Freedom Flex), so I doubt this was a serious consideration.</p>
]]></description><pubDate>Thu, 08 Jan 2026 05:37:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=46537599</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=46537599</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46537599</guid></item><item><title><![CDATA[New comment by iancarroll in "India orders smartphone makers to preload state-owned cyber safety app"]]></title><description><![CDATA[
<p>The GFW is certainly looking for traffic to block, but it is not really going to invade much privacy, as it cannot decrypt anything using HTTPS/TLS.</p>
]]></description><pubDate>Mon, 01 Dec 2025 19:13:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=46111679</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=46111679</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46111679</guid></item><item><title><![CDATA[New comment by iancarroll in "India orders smartphone makers to preload state-owned cyber safety app"]]></title><description><![CDATA[
<p>I don't think there is any reason to assume they would allow forced code execution just because they allow data residency for mainland accounts. And unfortunately, China is likely a much larger and more profitable consumer market than India - presumably they can still export phones produced inside India without this.</p>
]]></description><pubDate>Mon, 01 Dec 2025 18:59:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=46111488</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=46111488</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46111488</guid></item><item><title><![CDATA[New comment by iancarroll in "India orders smartphone makers to preload state-owned cyber safety app"]]></title><description><![CDATA[
<p>Even in mainland China, where iOS does have a large amount of changes to comply with local regulations, Apple does not pre-install any apps from anyone.</p>
]]></description><pubDate>Mon, 01 Dec 2025 18:40:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=46111206</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=46111206</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46111206</guid></item><item><title><![CDATA[New comment by iancarroll in "Show HN: Wealthfolio 2.0- Open source investment tracker. Now Mobile and Docker"]]></title><description><![CDATA[
<p>It’s great that you have coverage across multiple countries. I’ve noticed most budget apps cannot handle multiple currencies at all, much less automated sync across multiple countries.</p>
]]></description><pubDate>Sat, 22 Nov 2025 19:12:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=46017388</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=46017388</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46017388</guid></item><item><title><![CDATA[New comment by iancarroll in "Open Source Implementation of Apple's Private Compute Cloud"]]></title><description><![CDATA[
<p>Aren’t they both hardware backed, just changing the X in “trust X”?</p>
]]></description><pubDate>Thu, 06 Nov 2025 16:15:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=45836792</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=45836792</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45836792</guid></item><item><title><![CDATA[New comment by iancarroll in "The cryptography behind electronic passports"]]></title><description><![CDATA[
<p>Not an expert but my understanding is that active authentication only occurs after the basic “I can see the MRZ data” authentication passes first. You can’t skip proving you can read the MRZ in any scenario.</p>
]]></description><pubDate>Sat, 01 Nov 2025 14:32:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=45781920</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=45781920</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45781920</guid></item><item><title><![CDATA[New comment by iancarroll in "Accessing Max Verstappen's passport and PII through FIA bugs"]]></title><description><![CDATA[
<p>Good-faith security research[0] is the only way this industry will move forward, for better or worse. It is clear that most companies do not want to invest in anything further like VDPs.<p>[0] <a href="https://www.justice.gov/archives/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act" rel="nofollow">https://www.justice.gov/archives/opa/pr/department-justice-a...</a></p>
]]></description><pubDate>Thu, 23 Oct 2025 00:59:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=45677031</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=45677031</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45677031</guid></item><item><title><![CDATA[New comment by iancarroll in "Accessing Max Verstappen's passport and PII through FIA bugs"]]></title><description><![CDATA[
<p>Actual legal threats are uncommon but I have seen some companies try to offer a bribe disguised as a retroactive bug bounty program, in exchange for not publishing. Obviously it is important to decline that.</p>
]]></description><pubDate>Wed, 22 Oct 2025 20:30:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=45674761</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=45674761</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45674761</guid></item><item><title><![CDATA[New comment by iancarroll in "Compare Single Board Computers"]]></title><description><![CDATA[
<p>That’s a nice list, thanks!</p>
]]></description><pubDate>Sun, 19 Oct 2025 20:57:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=45637913</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=45637913</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45637913</guid></item><item><title><![CDATA[New comment by iancarroll in "Compare Single Board Computers"]]></title><description><![CDATA[
<p>Clicking on “ARM” only seems to show Raspberry Pi’s and not the other ARM boards listed on the site.</p>
]]></description><pubDate>Sun, 19 Oct 2025 20:31:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=45637681</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=45637681</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45637681</guid></item><item><title><![CDATA[New comment by iancarroll in "Chess.com regional pricing: A case study"]]></title><description><![CDATA[
<p>Many cards in the US do not charge any foreign transaction fees, and Alipay/WeChat waive their fees on small ticket items as well.</p>
]]></description><pubDate>Wed, 08 Oct 2025 05:10:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=45512296</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=45512296</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45512296</guid></item></channel></rss>