<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: john_strinlai</title><link>https://news.ycombinator.com/user?id=john_strinlai</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 30 Apr 2026 08:44:38 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=john_strinlai" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by john_strinlai in "Copy Fail – CVE-2026-31431"]]></title><description><![CDATA[
<p>><i>I need to know what the code does before I run it.</i><p>its literally code meant to exploit your system. you should be running it in an environment built for that <i>already</i>.<p>you dont test exploit pocs on your daily driver.</p>
]]></description><pubDate>Thu, 30 Apr 2026 00:03:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47956300</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47956300</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47956300</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail – CVE-2026-31431"]]></title><description><![CDATA[
<p>mainline was patched a month ago</p>
]]></description><pubDate>Wed, 29 Apr 2026 22:29:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=47955567</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47955567</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47955567</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail – CVE-2026-31431"]]></title><description><![CDATA[
<p>the asterisk is my oops, trying to format the comment in italics to differentiate my comment from the text provided by the author. sorry for the confusion</p>
]]></description><pubDate>Wed, 29 Apr 2026 21:13:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47954759</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47954759</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47954759</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail"]]></title><description><![CDATA[
<p>><i>Disagree because to run the PoC you really ought to understand what it’s doing.</i><p>that is contained in the report, which will look similar to the blog. the maintainers will have an open line of contact with the reporters as well. the poc is a small part of the entire report. its not like the linux maintainers <i>only</i> received this poc and have to work out the vulnerability from it alone.<p>><i>It is failing at letting people confirm the exploit easily.</i><p>it confirms the exploit incredibly easy. just run it, and you get confirmation.</p>
]]></description><pubDate>Wed, 29 Apr 2026 20:59:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=47954572</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47954572</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47954572</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail"]]></title><description><![CDATA[
<p>what value do you believe renaming the variable from "g" to something else provides the linux maintainers?</p>
]]></description><pubDate>Wed, 29 Apr 2026 20:52:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=47954471</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47954471</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47954471</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail"]]></title><description><![CDATA[
<p>agreed regarding the RHEL version!<p>i just dont understand huffing and puffing over <i>"os as g"</i> in a 10-line poc script, and saying <i>"well i would never approve this"</i>. its not enterprise code. its not code that will ever be used anywhere else, for anything. its sole purpose is to prove that the exploit is real, which it does!<p>the rest of the information is in the actual vulnerability report. the poc is a courtesy to the reportee, so that they can confirm that the report itself isnt bullshit.<p>evidently, given the downvotes i am getting, people think exploit scripts should be enterprise quality code. ¯\_(ツ)_/¯ half of the reports i see flowing through mailing lists dont even have a poc.<p>amazingly HN-like to be upset about a variable name</p>
]]></description><pubDate>Wed, 29 Apr 2026 20:51:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47954456</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47954456</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47954456</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail"]]></title><description><![CDATA[
<p>in this specific case, they offer an alternative mitigation if your chosen distro has not updated yet:<p>For immediate mitigation, block AF_ALG socket creation via seccomp or blacklist the algif_aead module:<p><pre><code>    echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif-aead.conf
    rmmod algif_aead 2>/dev/null</code></pre></p>
]]></description><pubDate>Wed, 29 Apr 2026 20:46:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=47954365</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47954365</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47954365</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail"]]></title><description><![CDATA[
<p>id imagine that they received more than just the poc in the report they received</p>
]]></description><pubDate>Wed, 29 Apr 2026 20:17:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=47953977</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47953977</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47953977</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail"]]></title><description><![CDATA[
<p>><i>As a code author/reviewer, I would never write "os as g" and I would absolutely never approve review of any code that used this.</i><p>lucky for them, its an exploit script, not enterprise code.<p>all that needs to be "reviewed" is whether or not it exploits the thing its supposed to.<p>edit: yall really think a 10-line proof of concept script needs to undergo a code review? wild. i shouldnt be surprised that the top comment on a cool LPE exploit is complaining about variable naming</p>
]]></description><pubDate>Wed, 29 Apr 2026 19:35:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47953327</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47953327</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47953327</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail – CVE-2026-31431"]]></title><description><![CDATA[
<p>after work i have to stop at Y87794H0US1R65VBXU25 for some groceries.</p>
]]></description><pubDate>Wed, 29 Apr 2026 19:30:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=47953242</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47953242</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47953242</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail"]]></title><description><![CDATA[
<p>Disclosure timeline<p><pre><code>    2026-03-23Reported to Linux kernel security team
    2026-03-24Initial acknowledgment
    2026-03-25Patches proposed and reviewed
    2026-04-01Patch committed to mainline
    2026-04-22CVE-2026-31431 assigned
    2026-04-29Public disclosure (https://copy.fail/)
</code></pre>
kernel 6.19.14-arch1-1, the kernel in question from the parent comment, has been patched.</p>
]]></description><pubDate>Wed, 29 Apr 2026 19:25:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=47953169</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47953169</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47953169</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail"]]></title><description><![CDATA[
<p>><i>The website claims it can escape "Kubernetes / container clusters" and "CI runners & build farms" but I don't see anything supporting the claim it can escape a container </i><p>they state that the write-up is forthcoming. presumably there is some additional steps or modifications that will be detailed in the 'part 2'.<p><i>"Next: "From Pod to Host," how Copy Fail escapes every major cloud Kubernetes platform."</i></p>
]]></description><pubDate>Wed, 29 Apr 2026 19:24:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47953157</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47953157</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47953157</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail"]]></title><description><![CDATA[
<p>yes, it was reported on march 23rd, patches on april 1.<p>you are reading about it now <i>because</i> it has been patched.</p>
]]></description><pubDate>Wed, 29 Apr 2026 18:46:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=47952626</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47952626</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47952626</guid></item><item><title><![CDATA[New comment by john_strinlai in "Copy Fail"]]></title><description><![CDATA[
<p>can you remember what CVE-2021-44228 is without looking it up? CVE-2014-6271? CVE-2017-5753?<p>i bet if i told you their names, you would instantly know what vulns those are.<p>its easier to talk about things with names. it hurts no one. it takes approximately no effort or time.<p>CVEs are, for whatever reason, like the only thing on the planet that people seem to have a problem with when they receive a name. i am not sure why.</p>
]]></description><pubDate>Wed, 29 Apr 2026 18:39:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=47952543</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47952543</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47952543</guid></item><item><title><![CDATA[New comment by john_strinlai in "Zed 1.0"]]></title><description><![CDATA[
<p>yeah, all forms of criticism, all feature suggestions, any comparisons to other products/solutions, etc. should be outright banned by HN. if you aren't praising the thing, get out!<p>(do you comment this same type of thing on github, microsoft, apple, etc. posts? all of these comments seem absolutely tame compared to the vitriol in those threads. most top comments here are supportive. most of the negative ones are constructive.)</p>
]]></description><pubDate>Wed, 29 Apr 2026 17:04:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=47951236</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47951236</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47951236</guid></item><item><title><![CDATA[New comment by john_strinlai in "Your phone is about to stop being yours"]]></title><description><![CDATA[
<p>><i>The openness, freedom, customizability and accessibility (money wise) were the tenets that differentiated Android from Apple devices.</i><p>i have never heard someone outside of tech circles (e.g. HN) mention openness, freedom, or customization, even as a passing comment.<p>they use a phone to access mainstream apps (youtube, instagram, reddit, maybe their bank) and text/call. mention "apk" or "fdroid" and their eyes start to glaze over.<p>cheaper devices, sure, i agree with that as being the differentiator to the average non-techie. the rest is, at least in my experience, absolutely a "HN view".</p>
]]></description><pubDate>Tue, 28 Apr 2026 21:46:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=47941297</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47941297</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47941297</guid></item><item><title><![CDATA[New comment by john_strinlai in "Bankruptcies increase 11.9 percent"]]></title><description><![CDATA[
<p>><i>Personally, I’m anti credit in general and don’t have credit cards or a credit score.</i><p>if only people could choose to have or not have a credit score. that would be cool. unfortunately, equifax/transunion/experian are some of the original data vacuums and assign one whether you want one or not.</p>
]]></description><pubDate>Tue, 28 Apr 2026 20:38:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=47940387</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47940387</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47940387</guid></item><item><title><![CDATA[New comment by john_strinlai in "Bankruptcies increase 11.9 percent"]]></title><description><![CDATA[
<p>feel free to elaborate on the relationship you are drawing between that and the article</p>
]]></description><pubDate>Tue, 28 Apr 2026 19:30:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47939408</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47939408</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47939408</guid></item><item><title><![CDATA[New comment by john_strinlai in "Bankruptcies increase 11.9 percent"]]></title><description><![CDATA[
<p>><i>I'm more likely to believe inflation to be the cause</i><p>based on what?</p>
]]></description><pubDate>Tue, 28 Apr 2026 19:24:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=47939316</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47939316</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47939316</guid></item><item><title><![CDATA[New comment by john_strinlai in "Bankruptcies increase 11.9 percent"]]></title><description><![CDATA[
<p>><i>So obvious that I'm not sure why the question is even being asked.</i><p>its a rhetorical question.<p>the question is asked to make a point rather than to be answered.</p>
]]></description><pubDate>Tue, 28 Apr 2026 19:21:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=47939268</link><dc:creator>john_strinlai</dc:creator><comments>https://news.ycombinator.com/item?id=47939268</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47939268</guid></item></channel></rss>