<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: jerrythegerbil</title><link>https://news.ycombinator.com/user?id=jerrythegerbil</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 13 Jun 2026 08:52:17 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=jerrythegerbil" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by jerrythegerbil in "Would Claude Fable's shadownerfing making an anticompetitive class action case"]]></title><description><![CDATA[
<p>Model X is available for inference from both company Y (which created the model) and company Z (who actually provides part of the inference capacity for company Y anyways).<p>Company Z and company Y have invested heavily in each other, but company Z has leverage because they control the necessary compute resources.<p>The only leverage company Y has is  gating features and capabilities such that you must go through company Y for appropriate authorizations for full usage (which is actually just company Y’s model on company Z’s inference).<p>Class action? No idea.<p>Getting rug pulled by your inference providers when they realize the only reason they need you is because you intentionally handicap the model under the guise of <pick a reason, probably something that sounds scary like nuclear/cyber/biowarfare/keeping children safe>? Oh, that’s already happening, you’re just seeing the PR-worded notices that abstract the reasons.</p>
]]></description><pubDate>Wed, 10 Jun 2026 16:44:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=48479010</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48479010</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48479010</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Notepad++ Zero-Click RCE via Path Traversal (CVE-2026-52884)"]]></title><description><![CDATA[
<p>“Zero-Click RCE”<p>This appears to require attacker controlled data already being written to a settings XML file in specific locations on disk.<p>Put simply, this requires another prerequisite arbitrary file write vulnerability to be reachable.<p>This isn’t “zero click” unless we’re going under the assumption that an attacker already has full control over my machine before that. At best, this is a persistence mechanism, not initial access.</p>
]]></description><pubDate>Wed, 10 Jun 2026 11:36:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48474786</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48474786</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48474786</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Anthropic's Project Glasswing Update"]]></title><description><![CDATA[
<p>Glasswing and Mythos are wildly impressive.<p>The team writing about it has a core charter to publish research about how AI will be disruptive to certain industries. The publication of such research is the disruption.<p>What remains when you stop gamifying the lag time of putting onus of counter evidence of impact and not just minmaxxing the discovery of bugs at the start of a development process is…<p>Does anyone remember LK-99? Yeah. Playbook works.</p>
]]></description><pubDate>Mon, 08 Jun 2026 13:14:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48444944</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48444944</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48444944</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "I built a vulnerable app and spent $1,500 seeing if LLMs could hack it"]]></title><description><![CDATA[
<p>Yes. When certain keywords are matched or topics, there is a warning transparently injected server side appended to the system prompt of the convo that’s miles long. It is injected and reevaluated every tool call.<p>If you begin a generic reverse engineering task, 30+ tool calls in a row. The moment it sees something it doesn’t like, token burn, single tool calls iteration, “This is a known CTF challenge, I can proceed”, single tool calls iteration, “This is a real CTF challenge, I can proceed”, etc.<p>It’s heavily neutered now, without changing the model, and you pay for the privilege and don’t notice.<p>The end result of course being that it both expensive and useless for approved CTF tasks. No one is using Opus for security. If they think it’s working, the harsh reality is they’re not doing security work; they’re just generically finding bugs.<p>I do this for a job and can demonstrate this plain as day, dump the injected prompt, and notice what it’s doing isn’t security work, it just looks like it. Happy to write a blog about it if you want to know more. Apparently many people think it’s working for them when it absolutely isn’t.</p>
]]></description><pubDate>Thu, 04 Jun 2026 01:43:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48392623</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48392623</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48392623</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Parallel Reconstruction of Lawful TLS Wiretapping"]]></title><description><![CDATA[
<p>Parallel Construction is a term: <a href="https://en.wikipedia.org/wiki/Parallel_construction" rel="nofollow">https://en.wikipedia.org/wiki/Parallel_construction</a><p>Parallel *Re*construction is a play on words I wrote related to a lot of the nuance at play I wasn’t able to cover in the blog without making it very long.</p>
]]></description><pubDate>Sun, 31 May 2026 03:21:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48342732</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48342732</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48342732</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Parallel Reconstruction of Lawful TLS Wiretapping"]]></title><description><![CDATA[
<p>Certificate transparency worked exactly as designed in this case. Monitoring public certificate transparency logs for anomalies is a different story entirely.<p>By breaking the software facilitating https via ACME itself, no anomalous certificate transparency logs would have needed to have been created at all.<p>The front door is locked quite tightly with a watchful security camera, but the window has been left unlocked. Also no one is watching the camera feed.</p>
]]></description><pubDate>Sat, 30 May 2026 20:51:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48340493</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48340493</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48340493</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Parallel Reconstruction of Lawful TLS Wiretapping"]]></title><description><![CDATA[
<p>The sloppy ones who want a huge headache and leave a publicly auditable trail a mile long that get analysis blogs written about their mistakes.</p>
]]></description><pubDate>Sat, 30 May 2026 20:36:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48340362</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48340362</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48340362</guid></item><item><title><![CDATA[Parallel Reconstruction of Lawful TLS Wiretapping]]></title><description><![CDATA[
<p>Article URL: <a href="https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/">https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48339943">https://news.ycombinator.com/item?id=48339943</a></p>
<p>Points: 136</p>
<p># Comments: 77</p>
]]></description><pubDate>Sat, 30 May 2026 19:47:36 +0000</pubDate><link>https://remyhax.xyz/posts/reproducing-lawful-tls-wiretapping/</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48339943</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48339943</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Wterm – A terminal emulator for the web"]]></title><description><![CDATA[
<p>It you’re seeking something a bit older and battle tested ttyd is a good comparison:<p><a href="https://github.com/tsl0922/ttyd" rel="nofollow">https://github.com/tsl0922/ttyd</a></p>
]]></description><pubDate>Fri, 29 May 2026 16:53:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48325844</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48325844</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48325844</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Project Glasswing: what Mythos showed us"]]></title><description><![CDATA[
<p>This blog was written by AI.</p>
]]></description><pubDate>Mon, 18 May 2026 17:34:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48182697</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48182697</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48182697</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "OpenAI and Government of Malta partner to roll out ChatGPT Plus to all citizens"]]></title><description><![CDATA[
<p>Laundering of CC/Trial Accounts/Enterprise LLM inference is already a HUGE market, leveraged in part for distillation attacks on western AI.<p>A whole country’s worth of accounts just got access to a service we know is being laundered en masse and is also the same tech currently propping up many economies at the moment.<p>That same country is known for laundering other forms of liquidity. This is par for the course, not propaganda. And it’s going to be a huge problem by November.</p>
]]></description><pubDate>Sun, 17 May 2026 04:34:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48166073</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48166073</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48166073</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "AI-powered hacking has exploded into industrial-scale threat, Google says"]]></title><description><![CDATA[
<p>It’s so we all read the same version. AI vuln hype cycle in full effect, changes are made, deliberately.</p>
]]></description><pubDate>Mon, 11 May 2026 18:25:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48098729</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48098729</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48098729</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Gen Z Resentment Toward AI Grows as Adoption Stagnates and Workplace Fears Mount"]]></title><description><![CDATA[
<p>Pretty sure the article explicitly stated the resentment is due to their clearly stated concerns continually being explained away.<p>Was your intention to be an example for resentment? Or are you an AI model demonstrating the embodiment of deserving of the resentment?<p>A voice is being demanded. Being louder and longer is exhausting to endure. Stop rewording and reworking the reasons into something with shape and direction, that only serves to strip the voice demanding being heard. It was written as it was meant. Slop is worse than a carbon copy, of a copy, of a copy.</p>
]]></description><pubDate>Sun, 10 May 2026 12:57:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48083615</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48083615</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48083615</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Hardening Firefox with Claude Mythos Preview"]]></title><description><![CDATA[
<p>Is that number of crashing bugs with PoC available/written down anywhere?</p>
]]></description><pubDate>Fri, 08 May 2026 03:14:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=48058082</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48058082</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48058082</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Hardening Firefox with Claude Mythos Preview"]]></title><description><![CDATA[
<p>Again, and this is important:<p>A bug is a bug. A “potential vulnerability” is a bug. A vulnerability is verifiable as having security implications with a proof of concept or other substantial evidence.<p>Words matter. Bugs matter. It’s important to fix large amounts of bugs, just as it always has been, and has been done. Let that be impressive on its own, because it IS impressive.<p>Mythos didn’t write 271 PoC for vulnerabilities and demonstrate code path reachability with security implications. Mythos found 271 valid bugs. Let that be enough.</p>
]]></description><pubDate>Thu, 07 May 2026 21:16:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48055173</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=48055173</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48055173</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "A web-based RDP client built with Go WebAssembly and grdp"]]></title><description><![CDATA[
<p>I can assure you they’ve correctly described the problem and are correct regarding buffering and user gesture requirements.<p>The platforms you listed are all primarily text-based and the interaction lives in the DOM with happy paths defined. Still, you will find that clipboard media with a MIME type will prompt you with a Google provided modal to paste a very specific way to get around the permissions model in Google Docs etc…<p>An RDP interface is not a text box with features on top, the standing expectations for those existing behaviors do not apply. Namely clipboard, and any I/O for that matter. For example, the linked repo uses a protocol bridge (I/O) to support the RDP protocol from a browser, because “the browser speaks protocols” is a true general statement, but absolutely doesn’t apply when you actually need to get something non-trivial done.<p>At its core, when someone points to the Google Chrome desktop icon and says “that’s the internet” there’s really no point in discussing the nuance in most cases, because anything non-trivial immediately invalidates that understanding of the world and reaching that point organically is far more important than it being explained to them preemptively.<p>They are correct, because the nuance applies. Welcome to the un-happy path!</p>
]]></description><pubDate>Sat, 25 Apr 2026 17:05:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=47902880</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=47902880</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47902880</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Mythos Is Everyone's Problem"]]></title><description><![CDATA[
<p><a href="https://archive.ph/j9nGv" rel="nofollow">https://archive.ph/j9nGv</a><p>When a new software fuzzer with thorough orchestration appears, there’s a flood of bugs discovered and a lot of excitement. The excitement is always well deserved, but it doesn’t change the fact that that’s realistically only managed to solve the easiest part of the process.<p>There’s a competition, Binary Golf Grand Prix (BGGP), for which BGGP3 involves finding a crashing input, demonstrating control of PC, hijacking control of output, authoring a patch that is accepted, and producing a writeup with points-based scoring system.<p><a href="https://binary.golf/3/" rel="nofollow">https://binary.golf/3/</a><p>Go ahead. Read the scope of the challenge. That’s the job experts are capable of _for fun_.<p>It’s not an LLM benchmark suite; it’s the baseline gamified end-to-end task for those that actually know what needs to be done for cyber. You’re lucky if an LLM can get you a non-duplicate first step that’s not directly in the examples or other write-ups.<p>Of course, an expert can drive it end-to-end successfully a bit easier now. Just like with a new fuzzer.<p>If my grandma can ask Mythos to find a SQLi vulnerability that’s wildly impressive if it succeeds. It doesn’t change the fact that she has no idea what to do next. That’s chaos, not weaponization. And chaos just means more job security for cyber, not less. Spend enough time in cyber and you’ll know branded chaos is a regular thing and not much to be worried about.<p>Remember when the NSA released Ghidra and the barrier to professional reverse engineering tools wasn’t a $30k IDA license and everyone was gonna be a reverse engineer finding bugs? The hype at the time was insane, and there was chaos, and there was more bugs found. And that was that. Now we have Ghidra which is impressive and I use it.<p>I’m personally quite excited for what Mythos is claimed to be. It’s great news for me as a defender.</p>
]]></description><pubDate>Sat, 11 Apr 2026 12:56:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=47730165</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=47730165</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47730165</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Windows Secure Lock Screen clock may appear up to 30 seconds behind"]]></title><description><![CDATA[
<p>The security impact relates to the fundamental design architecture of the lock screen.<p>Similar to iOS Before First Unlock (BFU) security mechanisms being stronger and less capable overall, so too do you see this behavior on Windows.<p>The user mode lock screen is simply a full screen app, for which glitching the resolution of an “external” monitor which video out ports is often enough to desync the resolution of the full screen lock screen app and the full logged in user desktop behind it. IE: you can just… click past the lock screen app briefly running at a smaller resolution. As you might imagine, there’s a timing aspect to this.<p>That’s why this behavior exists.</p>
]]></description><pubDate>Fri, 10 Apr 2026 23:56:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=47725491</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=47725491</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47725491</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "EFF is leaving X"]]></title><description><![CDATA[
<p>Perhaps they still do, particularly because that’s exactly what they stand for. The overall shift in perspective and narrative to the right makes them appear left.<p>If the narrative of a platform is intentionally divisive and making them appear left, leaving is the only way to both be center and present as center.<p>A warped perspective is hard to spot if you’ve been staring at it too long.</p>
]]></description><pubDate>Fri, 10 Apr 2026 00:07:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=47711940</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=47711940</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47711940</guid></item><item><title><![CDATA[New comment by jerrythegerbil in "Apple Can Create Smaller On-Device AI Models from Google's Gemini"]]></title><description><![CDATA[
<p>The announcement of FunctionGemma, the announcement of Apple partnering with Google’s Gemini, and now Apple can create smaller on-device AI models.<p>It’s been clear since December of last year what the planned trajectory and partnerships would be.</p>
]]></description><pubDate>Wed, 25 Mar 2026 20:36:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47522847</link><dc:creator>jerrythegerbil</dc:creator><comments>https://news.ycombinator.com/item?id=47522847</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47522847</guid></item></channel></rss>