<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: infotogivenm</title><link>https://news.ycombinator.com/user?id=infotogivenm</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 22 Jul 2026 00:52:49 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=infotogivenm" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by infotogivenm in "How to Create HTML/ZIP/PNG Polyglot Files"]]></title><description><![CDATA[
<p>source integrity is probably the more applicable feature for gp’s concerns</p>
]]></description><pubDate>Sat, 28 Dec 2024 12:17:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=42530515</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=42530515</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42530515</guid></item><item><title><![CDATA[New comment by infotogivenm in "RegreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems"]]></title><description><![CDATA[
<p>> Nah<p>I don’t get it then… Do you never end up having to privesc in your pentests on linux systems? No doubt it depends on customer profile but I would guess personally on at least 25% of engagements in Linux environments I have had to find a local path to root.</p>
]]></description><pubDate>Mon, 01 Jul 2024 14:44:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=40846289</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=40846289</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40846289</guid></item><item><title><![CDATA[New comment by infotogivenm in "RegreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems"]]></title><description><![CDATA[
<p>Think “illegitimate” access to www-data. It’s very common on linux pentests to need to privesc from some lower-privileged foothold (like a command injection in an httpd cgi script). Most linux servers run openssh. So yes I would expect this turns out to be a useful privesc in practice.</p>
]]></description><pubDate>Mon, 01 Jul 2024 14:26:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=40846134</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=40846134</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40846134</guid></item><item><title><![CDATA[New comment by infotogivenm in "Indians who pre-ordered Teslas in 2016 are giving up and chasing refunds"]]></title><description><![CDATA[
<p>Fidelity, who remains a stakeholder in the private company and gets insight to internal financials, has cut the valuation of their holding by 75% so far [1]. While twitter might not have been profitable when purchased, it was structured as a growth stock (that is, expected to invest most profit back into the product, in order to continue to multiply revenue) and had yearly revenues of $5B.<p>1. <a href="https://fortune.com/2024/03/30/fidelity-x-stake-73-decline-since-elon-musk-twitter-takeover/#" rel="nofollow">https://fortune.com/2024/03/30/fidelity-x-stake-73-decline-s...</a></p>
]]></description><pubDate>Thu, 09 May 2024 03:32:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=40305064</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=40305064</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40305064</guid></item><item><title><![CDATA[New comment by infotogivenm in "Run0, a systemd based alternative to sudo, announced"]]></title><description><![CDATA[
<p>Em, that seems an extremely generous comparison, where did you come up with that? Last I checked for example systemd relies on polkit for policies, which drags in a javascript interpreter engine. If the author thinks BNF is complex…</p>
]]></description><pubDate>Wed, 01 May 2024 04:21:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=40219470</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=40219470</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40219470</guid></item><item><title><![CDATA[New comment by infotogivenm in "Passkeys: A shattered dream"]]></title><description><![CDATA[
<p>I’m surprised no one has written a tool (probably would involve disabling SIP) to import/export passkeys on macOS. They’re in memory, right?</p>
]]></description><pubDate>Sat, 27 Apr 2024 06:46:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=40177845</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=40177845</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40177845</guid></item><item><title><![CDATA[New comment by infotogivenm in "Texas Tempts Tesla"]]></title><description><![CDATA[
<p><a href="https://newsletterhunt.com/emails/48880" rel="nofollow">https://newsletterhunt.com/emails/48880</a></p>
]]></description><pubDate>Thu, 01 Feb 2024 20:24:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=39220923</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=39220923</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39220923</guid></item><item><title><![CDATA[New comment by infotogivenm in "Tiny UPS for Tiny NAS"]]></title><description><![CDATA[
<p>Came here to mention this. I used this exact setup (used a laptop battery bank off of amazon as a UPS for my home modem), and came home months later to find the bank had caught fire at some point, melted, and was no longer functional. Would not recommend</p>
]]></description><pubDate>Sat, 27 Jan 2024 04:56:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=39152723</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=39152723</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39152723</guid></item><item><title><![CDATA[New comment by infotogivenm in "Unprivileged process injection techniques in Linux"]]></title><description><![CDATA[
<p>It is fairly common to have noexec on /dev/shm; filesystem configurations are always up to the admin so they could feasibly set anything.</p>
]]></description><pubDate>Tue, 09 Jan 2024 22:24:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=38933129</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38933129</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38933129</guid></item><item><title><![CDATA[New comment by infotogivenm in "Non-interactive SSH password authentication"]]></title><description><![CDATA[
<p>One good example is bringing up equipment that comes out-the-box with a default password. This is common on BMCs for example, and you have to initially provision things somehow.</p>
]]></description><pubDate>Mon, 25 Dec 2023 18:35:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=38764875</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38764875</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38764875</guid></item><item><title><![CDATA[New comment by infotogivenm in "Non-interactive SSH password authentication"]]></title><description><![CDATA[
<p>It’s covered under footnote #1:<p>> First, some vendors make it difficult to associate an SSH key with a user. Then, many vendors do not support certificate-based authentication, making it difficult to scale. Finally, interactions between public-key authentication and finer-grained authorization methods like TACACS+ and Radius are still uncharted territory<p>Keys (with/without certs) are the best route, but not always possible for every situation.</p>
]]></description><pubDate>Mon, 25 Dec 2023 14:43:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=38762954</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38762954</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38762954</guid></item><item><title><![CDATA[New comment by infotogivenm in "Lessons from building GitHub code search [video]"]]></title><description><![CDATA[
<p>I’ve noticed the code reader is worthless on even slightly out of date browsers now, and even on newer browsers it tends to choke and stutter on large files. Sad :( it used to be the best</p>
]]></description><pubDate>Thu, 14 Dec 2023 14:28:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=38641668</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38641668</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38641668</guid></item><item><title><![CDATA[New comment by infotogivenm in "Apple now requires a judge's consent to hand over push notification data"]]></title><description><![CDATA[
<p>If you have metadata for a couple of messages it is no longer a needle. Not sure what your point about APNS tokens is - I agree, once they hone in on who received the messages Apple would know the device.</p>
]]></description><pubDate>Thu, 14 Dec 2023 04:30:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=38637789</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38637789</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38637789</guid></item><item><title><![CDATA[New comment by infotogivenm in "Tesla FSD Timeline"]]></title><description><![CDATA[
<p>Ah good point, radar/ultrasonics were what I was thinking of, not lidar. Looks like they’re still gone.</p>
]]></description><pubDate>Wed, 13 Dec 2023 12:19:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=38626286</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38626286</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38626286</guid></item><item><title><![CDATA[New comment by infotogivenm in "Tesla FSD Timeline"]]></title><description><![CDATA[
<p>I mean, the current requirement for human attentiveness and intervention probably has <i>something</i> to do with avoiding disaster scenarios.</p>
]]></description><pubDate>Wed, 13 Dec 2023 12:17:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=38626270</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38626270</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38626270</guid></item><item><title><![CDATA[New comment by infotogivenm in "Apple now requires a judge's consent to hand over push notification data"]]></title><description><![CDATA[
<p>I can imagine it could be useful, e.g. if you already have metadata on “dates when user A messaged user B”, and are trying to de-anonymize user B.</p>
]]></description><pubDate>Wed, 13 Dec 2023 11:49:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=38625949</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38625949</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38625949</guid></item><item><title><![CDATA[New comment by infotogivenm in "Tesla FSD Timeline"]]></title><description><![CDATA[
<p>Are they still all-in on “pure vision” self-driving? I thought they had pivoted back to lidar but can’t seem to find any sources for that.</p>
]]></description><pubDate>Wed, 13 Dec 2023 11:42:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=38625890</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38625890</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38625890</guid></item><item><title><![CDATA[New comment by infotogivenm in "GM says it's dropping Apple CarPlay and Android Auto because they're unsafe"]]></title><description><![CDATA[
<p>Correct. Worst rental car experience of my life.</p>
]]></description><pubDate>Wed, 13 Dec 2023 07:26:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=38623768</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38623768</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38623768</guid></item><item><title><![CDATA[New comment by infotogivenm in "Preparing for the end of third-party cookies"]]></title><description><![CDATA[
<p>The point of killing third party cookies is to prevent a tracking identifier cookie that uniquely identifies your browser from being reused across different sites.<p>So you can of course host your own scripts and run them on your own origin, lets call it site1.com. But when your site1.com includes a third party iframe to e.g. googleanalytics.com, and that frame sets a cookie on itself, the cookie is now silently dropped. Then when site2.com later includes the googleanalytics.com frame, the frame cannot immediately link the two browsers. There are other ways to “link” browsers across origins, like browser fingerprinting or in many cases just IP, but they are not usually guaranteed to be 100% reliable.<p>Blocking third party cookies is standard obvious privacy functionality, but google has held out because it affects their bottom line. So IIUIC they had to wait until they implemented something that protects their bottom line (the chrome-only “privacy sandbox”).</p>
]]></description><pubDate>Sun, 26 Nov 2023 00:06:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=38418015</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38418015</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38418015</guid></item><item><title><![CDATA[New comment by infotogivenm in "Preparing for the end of third-party cookies"]]></title><description><![CDATA[
<p>I believe third-party cookies have been blocked on Safari and FF by default for many years</p>
]]></description><pubDate>Sat, 25 Nov 2023 23:07:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=38417593</link><dc:creator>infotogivenm</dc:creator><comments>https://news.ycombinator.com/item?id=38417593</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38417593</guid></item></channel></rss>