<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: iancarroll</title><link>https://news.ycombinator.com/user?id=iancarroll</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 30 Jul 2026 10:13:39 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=iancarroll" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by iancarroll in "Codex Security"]]></title><description><![CDATA[
<p>Looks great but the CLI output is not particularly interesting while the scan is running. I wish it could show token usage, some kind of progress, etc.</p>
]]></description><pubDate>Tue, 28 Jul 2026 22:11:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=49090634</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=49090634</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49090634</guid></item><item><title><![CDATA[New comment by iancarroll in "Una GPS smart watch – Repairable, USB-C charging, developer-friendly"]]></title><description><![CDATA[
<p>I've wasted so much money on vendor charging cables in the past 10 years while traveling or moving that I would probably buy this just for the USB-C port, assuming it is actually
splash proof.<p>I wonder what HR sensor they use. Samsung apparently has an average error of 7% which is pretty bad, so I wonder if this would be worse. [0]<p>[0] <a href="https://www.cnet.com/tech/mobile/i-ran-30-miles-testing-5-smartwatches-to-find-out-which-ones-you-can-actually-trust/" rel="nofollow">https://www.cnet.com/tech/mobile/i-ran-30-miles-testing-5-sm...</a></p>
]]></description><pubDate>Tue, 28 Jul 2026 17:47:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=49087434</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=49087434</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49087434</guid></item><item><title><![CDATA[New comment by iancarroll in "Opaque, Interoperable Passkey Records (and a Go API)"]]></title><description><![CDATA[
<p>We use github.com/go-webauthn/webauthn with no complaints!</p>
]]></description><pubDate>Tue, 21 Jul 2026 15:57:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48994053</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48994053</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48994053</guid></item><item><title><![CDATA[New comment by iancarroll in "Driving in China as a Tourist"]]></title><description><![CDATA[
<p>In Shenzhen, they told me that I can take the full test on any visa if my permitted length of stay is 90 days or more. Supposedly the US embassies now issue 90 day visas for Americans, so I am hoping to try that route soon as I have already been through two temporary licenses...</p>
]]></description><pubDate>Mon, 06 Jul 2026 00:30:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48799414</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48799414</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48799414</guid></item><item><title><![CDATA[New comment by iancarroll in "Driving in China as a Tourist"]]></title><description><![CDATA[
<p>Surprised to see this here but happy to answer any questions! Driving across China and getting to use the latest EVs has been quite fun and I hope to do it even more in the future.</p>
]]></description><pubDate>Sun, 05 Jul 2026 21:14:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48798008</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48798008</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48798008</guid></item><item><title><![CDATA[Backstage access: an unauthenticated SQL injection in Front Gate Tickets]]></title><description><![CDATA[
<p>Article URL: <a href="https://ian.sh/frontgate">https://ian.sh/frontgate</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48752354">https://news.ycombinator.com/item?id=48752354</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 01 Jul 2026 20:01:25 +0000</pubDate><link>https://ian.sh/frontgate</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48752354</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48752354</guid></item><item><title><![CDATA[New comment by iancarroll in "Deno Desktop"]]></title><description><![CDATA[
<p>Most apps (on desktop or mobile) open third party auth flows inside the user's default browser, which makes this a non-issue. For one, if you embed the Google login flow into your app then I can't reuse my existing session in my browser. But it also exposes my full credentials to your app for no reason, which is a good thing to avoid.</p>
]]></description><pubDate>Mon, 22 Jun 2026 17:42:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48633317</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48633317</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48633317</guid></item><item><title><![CDATA[New comment by iancarroll in "Loupe – A iOS app that raises awareness about what native apps can see"]]></title><description><![CDATA[
<p>Apps installed via the MAS have sandboxing applied to them, so this isn't really true.</p>
]]></description><pubDate>Sun, 21 Jun 2026 01:46:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=48614899</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48614899</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48614899</guid></item><item><title><![CDATA[New comment by iancarroll in "Tesla allegedly in autopilot mode crashes into Texas house, woman killed"]]></title><description><![CDATA[
<p>The latest FSD does not attempt to check if your hands are on the wheel at all.</p>
]]></description><pubDate>Sat, 20 Jun 2026 22:52:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48613744</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48613744</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48613744</guid></item><item><title><![CDATA[New comment by iancarroll in "Temporary Cloudflare accounts for AI agents"]]></title><description><![CDATA[
<p>My Cloudflare enterprise order form has costs for overages for Workers and the following language about everything else:<p>> If Customer exceeds any of the Total Quantity for the Services below, Cloudflare will invoice Customer in arrears at a rate that corresponds to the rate set forth in the table after this 
one labeled “Excess Usage Pricing.” If no such Excess Usage Pricing table has been added by the Parties to this order form or if such table does not include the Service(s) for which 
Customer has exceeded the Total Quantity, then the Parties will negotiate in good faith an increase in the Fees for such Service(s). Should the Parties fail to reach an agreement on 
an increase within thirty (30) days of Customer’s receipt of notice from Cloudflare that Customer has exceeded its usage cap for the Service(s), Cloudflare will have the right to 
immediately terminate such Service for its convenience, and without liability to Customer or any third party.</p>
]]></description><pubDate>Sat, 20 Jun 2026 20:28:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48612698</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48612698</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48612698</guid></item><item><title><![CDATA[New comment by iancarroll in "How we run Firecracker VMs inside EC2 and start browsers in less than 1s"]]></title><description><![CDATA[
<p>Your whole account is undisclosed marketing for this service. Fingerprinting in this manner is highly unlikely to be viable - there are too many middleboxes at the TCP layer to try and fingerprint on it.</p>
]]></description><pubDate>Wed, 17 Jun 2026 20:22:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48576291</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48576291</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48576291</guid></item><item><title><![CDATA[New comment by iancarroll in "Gov.uk has replaced Stripe with Dutch provider Adyen"]]></title><description><![CDATA[
<p>0.5% is a pretty incredibly low interchange rate in any case. But if you are saying that half of it is going to scheme fees, I doubt it is funding rewards programs for consumers.</p>
]]></description><pubDate>Sat, 06 Jun 2026 10:07:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48423326</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48423326</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48423326</guid></item><item><title><![CDATA[New comment by iancarroll in "Cloudflare Flagship"]]></title><description><![CDATA[
<p>Well, OpenAI already sold it (but kept the team), so it’s in someone else’s hands now.</p>
]]></description><pubDate>Wed, 27 May 2026 15:52:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48296114</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=48296114</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48296114</guid></item><item><title><![CDATA[New comment by iancarroll in "Cal.com is going closed source"]]></title><description><![CDATA[
<p>I know plenty of security researchers who exclusively use Claude Code and other tools for blackbox testing against sites they don’t have the source code for. It seems like shutting down the entire product is the only safe decision here!</p>
]]></description><pubDate>Wed, 15 Apr 2026 15:59:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=47780988</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=47780988</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47780988</guid></item><item><title><![CDATA[New comment by iancarroll in "ChatGPT won't let you type until Cloudflare reads your React state"]]></title><description><![CDATA[
<p>It’s pretty interesting to me that Cloudflare is collecting additional client-side data for individual customers. This is not widely done by most anti-bot solutions.</p>
]]></description><pubDate>Mon, 30 Mar 2026 04:33:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47570419</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=47570419</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47570419</guid></item><item><title><![CDATA[New comment by iancarroll in "I decompiled the White House's new app"]]></title><description><![CDATA[
<p>A bit skeptical of how this article is written as it seems to be mostly written by AI. Out of curiosity, I downloaded the app and it doesn't request location permissions anywhere, despite the claims in the article.<p>I've noticed Claude Code is happy to decompile APKs for you but isn't very good at doing reachability analysis or figuring out complex control flows. It will treat completely dead code as important as a commonly invoked function.</p>
]]></description><pubDate>Sat, 28 Mar 2026 16:48:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=47556256</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=47556256</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47556256</guid></item><item><title><![CDATA[New comment by iancarroll in "Verizon imposes new roadblock on users trying to unlock paid-off phones"]]></title><description><![CDATA[
<p>Verizon did manage to convince the FCC that this was enough a problem to change their settlement agreement[0] requiring more frequent unlocks. If you believe their numbers, they lost 700,000 phones to fraud in 2023, although a lot of those were probably any unlocked phone that defaulted on its payments.<p>[0] <a href="https://www.reuters.com/business/media-telecom/fcc-revises-verizon-phone-unlocking-rules-after-significant-fraud-issues-2026-01-12/" rel="nofollow">https://www.reuters.com/business/media-telecom/fcc-revises-v...</a></p>
]]></description><pubDate>Sat, 14 Feb 2026 22:33:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=47019091</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=47019091</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47019091</guid></item><item><title><![CDATA[New comment by iancarroll in "6-Day and IP Address Certificates Are Generally Available"]]></title><description><![CDATA[
<p>That is a very old article that seems to be outdated now.</p>
]]></description><pubDate>Fri, 16 Jan 2026 19:52:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=46651297</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=46651297</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46651297</guid></item><item><title><![CDATA[New comment by iancarroll in "Flock Hardcoded the Password for America's Surveillance Infrastructure 53 Times"]]></title><description><![CDATA[
<p>Although I don’t like Flock, I’m a bit skeptical of the claims in the article. Most screenshots appear to be client-side JavaScript snippets, not API responses from this key.<p>In the bug bounty community, Google Maps API key leaks are a common false positive, because they are only used for billing purposes and don’t actually control access to any data. The article doesn’t really prove ArcGIS is any different.</p>
]]></description><pubDate>Fri, 09 Jan 2026 23:31:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=46560883</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=46560883</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46560883</guid></item><item><title><![CDATA[New comment by iancarroll in "Chase to become new issuer of Apple Card"]]></title><description><![CDATA[
<p>Chase issues cards on both the Visa and Mastercard network (i.e. certain cobrands and the Freedom Flex), so I doubt this was a serious consideration.</p>
]]></description><pubDate>Thu, 08 Jan 2026 05:37:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=46537599</link><dc:creator>iancarroll</dc:creator><comments>https://news.ycombinator.com/item?id=46537599</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46537599</guid></item></channel></rss>