<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: jerrythegerbil</title><link>https://news.ycombinator.com/user?id=jerrythegerbil</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 09 Aug 2026 07:05:03 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=jerrythegerbil" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by jerrythegerbil in "US Military's cyber command unit grapples with cluster of deaths by suicide"]]></title><description><![CDATA[
<p>The LLMs play a part, but it’s the tempo; the pace.<p>Fully autonomous w/LLM isn’t true. Leadership wants it true. The technological capabilities and acceptance of scapegoating a machine got rejected by society, so that leaves perfectly capable individuals as the gatekeepers of decision making, completely overloaded by the amount of information they need to deal with.<p>If you as a human can’t keep up, but the onslaught continues, and you’ll be held responsible for the outcome regardless… yeah. People will punch their ticket out. It’s not unique to LLMs, but LLMs have certainly automated the process of reaching the worst possible conclusion.<p>Don’t for a second try to hold the computers accountable or blame them for this outcome. This is a leadership issue and always will be. Believing otherwise is just allowing suicides to be scapegoated as a computer’s doing.</p>
]]></description><pubDate>Sat, 08 Aug 2026 17:24:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=49223818</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=49223818</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49223818</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Show HN: ssh ssh.place"]]></title><description><![CDATA[
<p>An ssh server would exploit a vulnerability in the ssh client when it connects.<p>For example, openssh has both a client and server. There’s been vulnerabilities in openssh, in the client. Those vulnerabilities aren’t reachable unless you’re connecting to a server attempting to exploit you, so the risk is quite low because you know and trust most servers you’re connecting to with ssh.<p>To sum it up: Connecting to this server is probably fine, but in doing so most people are doing something significantly riskier without realizing it.</p>
]]></description><pubDate>Mon, 03 Aug 2026 05:12:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49151455</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=49151455</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49151455</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "OpenAI and Anthropic unite against open-weight AI risks to their bottom line"]]></title><description><![CDATA[
<p>This AI generated article about closed-weights model providers collaborating for additional scrutiny of open weights models, where the article itself has the tell-tale structure of being written by Claude Opus, which is aware it is a closed-weight model.<p>Thank goodness no one is taking any of this seriously, because it could never be anything more than a machine generated hatchet job.<p>A faster and better educated understanding of the subject matter could be achieved by standing in front of a wood chipper and dropping a brick in it to see what happens. “Yes, there were results! But why? Why to literally every variable involved?”</p>
]]></description><pubDate>Thu, 23 Jul 2026 13:47:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=49021537</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=49021537</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49021537</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "“We have information that Moonshot distilled Fable for the development of K3”"]]></title><description><![CDATA[
<p>“However, large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable.”<p>What’s actually happening behind the scenes is that certain inference providers will classify a prompt and it’s re-routed transparently to Anthropic and that’s used for distillation training, only distilling the complicated traces they need, originating from real user prompts and traces. These inference providers are explicitly blocked in the claude cli if you reverse engineer it.<p>The real picture is that these Chinese labs have figured out how to get exactly what they need, at a high quality, directly from distinct and unique real user prompts.<p>It’s only “covert” because Anthropic doesn’t like it, while simultaneously being perfectly fine to do.</p>
]]></description><pubDate>Wed, 22 Jul 2026 17:24:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=49010238</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=49010238</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49010238</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Americans are angry about data centers. Politicians are feeling the pressure"]]></title><description><![CDATA[
<p>A datacenter was built a couple hundred feet from my apartment complex around 2013-2014. Absolutely none of your comment would have even remotely held true at the time, and my family moved away as a direct result.<p>Assuming positive intent, what’s different nowadays that makes it all different? It would actually make me pretty happy to hear about the incredible leaps and bounds that’ve been taken.</p>
]]></description><pubDate>Sun, 19 Jul 2026 23:08:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48972528</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48972528</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48972528</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Pre-Authentication RCE in WordPress Core"]]></title><description><![CDATA[
<p>“Pre-Authentication” and “Unauthenticated” are meaningfully different things, and for the purposes of marketing reach you always want to push for “Unauthenticated” if possible.<p>Typically Pre-Authenticated means knowing some additional contextual information such as the userID or something like that is required for exploitation, but actual authentication is not required. The impact is limited by how easy it is to know that pre-authentication information, which remains unknown.</p>
]]></description><pubDate>Sat, 18 Jul 2026 04:25:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48955210</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48955210</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48955210</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Texas wins court order to suspend domain name for violating age-verification law"]]></title><description><![CDATA[
<p><a href="https://dnschecker.org/#A/motherless.com" rel="nofollow">https://dnschecker.org/#A/motherless.com</a></p>
]]></description><pubDate>Fri, 17 Jul 2026 23:44:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48953561</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48953561</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48953561</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Meta loses bid to dismiss US states' claims that FB, Instagram addict children"]]></title><description><![CDATA[
<p>MKULTRA was about using drugs to alter state and produce uninhibited truthfulness.<p>Social media has a direct impact on dopamine and uninhibited oversharing.<p>The mechanism isn’t even ambiguous, which is exactly why there’s a case, about the production of a deliberately addictive substance. The chemicals and effects differ, but it’s deliberate use and production as the same exact means to an end do not.<p>There’s zero ambiguity here of the alignment on an end goal.<p>Side note: is META hiring and can you refer me?</p>
]]></description><pubDate>Wed, 01 Jul 2026 17:16:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48750185</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48750185</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48750185</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "HackerRank open sourced its ATS. My resume scored 90/100. Oh wait 74. No – 88"]]></title><description><![CDATA[
<p>> Gates that reduce resume flow-through are only useful if their reduction is correlated with quality.<p>The volume is infeasible to review everyone for quality, even at an hour scale. The conclusion and solution is inevitable, though I wish it were different. 35% is actually really good if you’re not coming in through a referral.<p>The current reality is <1% and the person reviewing you is exhausted.</p>
]]></description><pubDate>Mon, 29 Jun 2026 05:23:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=48715137</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48715137</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48715137</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "HackerRank open sourced its ATS. My resume scored 90/100. Oh wait 74. No – 88"]]></title><description><![CDATA[
<p>> I fail 65% of the time. Same exact resume, different luck.<p>As someone who’s run hiring pipelines for technical roles in the past few years, that’s actually a fantastic number. I objectively hate saying that, but it’s true.<p>35% chance of elevating a technical individual to the next stage with no effort? I’ve seen as many as 100+ applicants an hour even when including a domain specific screener question. That’s 35 “screened” applicants in an hour. Were valid candidates screened out? Yes. Does you still have a candidate pool 35x larger than you need? Unfortunately, also yes.<p>The volume of applicants is SO HIGH such that your chances of getting moved to the next stage are actually markedly worse if AI isn’t involved. If you didn’t apply immediately (using an AI bot) there’s 50+ people ahead of you, and an exhausted technical leader if they ever make it to your resume.<p>Referral bonuses exist for a reason.</p>
]]></description><pubDate>Mon, 29 Jun 2026 05:01:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=48714996</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48714996</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48714996</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Vulnerability reports are not special anymore"]]></title><description><![CDATA[
<p>Vulnerability reports were never special.<p>The _demonstration_ of security impact through vulnerability reports was special. The automation of “demonstration of impact” with AI isn’t that at all. The last mile is human and always was. This isn’t to say it won’t change in the future, but that’s a fact of where we are now.<p>Vulnerability reports aren’t special anymore. They never were. It was the impact, the demonstration, the communication that was special.<p>When you realize that this is being written from the perspective of someone who does vulnerability reporting in a professional capacity, you’ll connect the dots. We took care to be kind and succinct because for many of us, we learned our skills from being on the development side of things first.<p>Vulnerability reports aren’t special anymore. The only ones that felt special were the ones with human touch, the ones doing their job as an adversarial thinker, and taking the care to understand that net positive outcomes require coordination even if both parties don’t see eye to eye.<p>Nothing has changed. It never was. You’re just inundated with AI slop; which as a practitioner who uses AI regularly I can say with absolute confidence. The end result is the same, the volume is increased, but the special thing was never the report itself.<p>Finding a vulnerability was always the easy but high toil part. It was the care to communicate succinctly and be invested in the outcome that was special.<p>Godspeed.</p>
]]></description><pubDate>Wed, 24 Jun 2026 02:30:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=48654413</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48654413</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48654413</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Would Claude Fable's shadownerfing making an anticompetitive class action case"]]></title><description><![CDATA[
<p>Model X is available for inference from both company Y (which created the model) and company Z (who actually provides part of the inference capacity for company Y anyways).<p>Company Z and company Y have invested heavily in each other, but company Z has leverage because they control the necessary compute resources.<p>The only leverage company Y has is  gating features and capabilities such that you must go through company Y for appropriate authorizations for full usage (which is actually just company Y’s model on company Z’s inference).<p>Class action? No idea.<p>Getting rug pulled by your inference providers when they realize the only reason they need you is because you intentionally handicap the model under the guise of <pick a reason, probably something that sounds scary like nuclear/cyber/biowarfare/keeping children safe>? Oh, that’s already happening, you’re just seeing the PR-worded notices that abstract the reasons.</p>
]]></description><pubDate>Wed, 10 Jun 2026 16:44:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=48479010</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48479010</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48479010</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Notepad++ Zero-Click RCE via Path Traversal (CVE-2026-52884)"]]></title><description><![CDATA[
<p>“Zero-Click RCE”<p>This appears to require attacker controlled data already being written to a settings XML file in specific locations on disk.<p>Put simply, this requires another prerequisite arbitrary file write vulnerability to be reachable.<p>This isn’t “zero click” unless we’re going under the assumption that an attacker already has full control over my machine before that. At best, this is a persistence mechanism, not initial access.</p>
]]></description><pubDate>Wed, 10 Jun 2026 11:36:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48474786</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48474786</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48474786</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Anthropic's Project Glasswing Update"]]></title><description><![CDATA[
<p>Glasswing and Mythos are wildly impressive.<p>The team writing about it has a core charter to publish research about how AI will be disruptive to certain industries. The publication of such research is the disruption.<p>What remains when you stop gamifying the lag time of putting onus of counter evidence of impact and not just minmaxxing the discovery of bugs at the start of a development process is…<p>Does anyone remember LK-99? Yeah. Playbook works.</p>
]]></description><pubDate>Mon, 08 Jun 2026 13:14:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48444944</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48444944</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48444944</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "I built a vulnerable app and spent $1,500 seeing if LLMs could hack it"]]></title><description><![CDATA[
<p>Yes. When certain keywords are matched or topics, there is a warning transparently injected server side appended to the system prompt of the convo that’s miles long. It is injected and reevaluated every tool call.<p>If you begin a generic reverse engineering task, 30+ tool calls in a row. The moment it sees something it doesn’t like, token burn, single tool calls iteration, “This is a known CTF challenge, I can proceed”, single tool calls iteration, “This is a real CTF challenge, I can proceed”, etc.<p>It’s heavily neutered now, without changing the model, and you pay for the privilege and don’t notice.<p>The end result of course being that it both expensive and useless for approved CTF tasks. No one is using Opus for security. If they think it’s working, the harsh reality is they’re not doing security work; they’re just generically finding bugs.<p>I do this for a job and can demonstrate this plain as day, dump the injected prompt, and notice what it’s doing isn’t security work, it just looks like it. Happy to write a blog about it if you want to know more. Apparently many people think it’s working for them when it absolutely isn’t.</p>
]]></description><pubDate>Thu, 04 Jun 2026 01:43:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48392623</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48392623</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48392623</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Parallel Reconstruction of Lawful TLS Wiretapping"]]></title><description><![CDATA[
<p>Parallel Construction is a term: <a href="https://en.wikipedia.org/wiki/Parallel_construction" rel="nofollow">https://en.wikipedia.org/wiki/Parallel_construction</a><p>Parallel *Re*construction is a play on words I wrote related to a lot of the nuance at play I wasn’t able to cover in the blog without making it very long.</p>
]]></description><pubDate>Sun, 31 May 2026 03:21:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48342732</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48342732</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48342732</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Parallel Reconstruction of Lawful TLS Wiretapping"]]></title><description><![CDATA[
<p>Certificate transparency worked exactly as designed in this case. Monitoring public certificate transparency logs for anomalies is a different story entirely.<p>By breaking the software facilitating https via ACME itself, no anomalous certificate transparency logs would have needed to have been created at all.<p>The front door is locked quite tightly with a watchful security camera, but the window has been left unlocked. Also no one is watching the camera feed.</p>
]]></description><pubDate>Sat, 30 May 2026 20:51:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48340493</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48340493</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48340493</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Parallel Reconstruction of Lawful TLS Wiretapping"]]></title><description><![CDATA[
<p>The sloppy ones who want a huge headache and leave a publicly auditable trail a mile long that get analysis blogs written about their mistakes.</p>
]]></description><pubDate>Sat, 30 May 2026 20:36:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48340362</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48340362</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48340362</guid></item><item><title><![CDATA[Parallel Reconstruction of Lawful TLS Wiretapping]]></title><description><![CDATA[
<p>Article URL: <a href="https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/">https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48339943">https://news.ycombinator.com/item?id=48339943</a></p>
<p>Points: 136</p>
<p># Comments: 77</p>
]]></description><pubDate>Sat, 30 May 2026 19:47:36 +0000</pubDate><link>https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48339943</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48339943</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Wterm – A terminal emulator for the web"]]></title><description><![CDATA[
<p>It you’re seeking something a bit older and battle tested ttyd is a good comparison:<p><a href="https://github.com/tsl0922/ttyd" rel="nofollow">https://github.com/tsl0922/ttyd</a></p>
]]></description><pubDate>Fri, 29 May 2026 16:53:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48325844</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48325844</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48325844</guid></item></channel></rss>