<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: mmsc</title><link>https://news.ycombinator.com/user?id=mmsc</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 25 May 2026 00:43:11 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=mmsc" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by mmsc in "Project Glasswing: An Initial Update"]]></title><description><![CDATA[
<p>Aisle has hundreds of CVEs with publicly available models: <a href="https://aisle.com/wall-of-fame" rel="nofollow">https://aisle.com/wall-of-fame</a></p>
]]></description><pubDate>Fri, 22 May 2026 22:39:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48242519</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=48242519</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48242519</guid></item><item><title><![CDATA[CVE-2026-42511 Breakdown: RCE in FreeBSD]]></title><description><![CDATA[
<p>Article URL: <a href="https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability">https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48054981">https://news.ycombinator.com/item?id=48054981</a></p>
<p>Points: 28</p>
<p># Comments: 1</p>
]]></description><pubDate>Thu, 07 May 2026 21:03:54 +0000</pubDate><link>https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=48054981</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48054981</guid></item><item><title><![CDATA[Finding and Fixing 24 CVEs in WeKan]]></title><description><![CDATA[
<p>Article URL: <a href="https://aisle.com/blog/finding-and-fixing-24-cves-in-wekan-with-aisles-analyzer">https://aisle.com/blog/finding-and-fixing-24-cves-in-wekan-with-aisles-analyzer</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47951378">https://news.ycombinator.com/item?id=47951378</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 29 Apr 2026 17:14:53 +0000</pubDate><link>https://aisle.com/blog/finding-and-fixing-24-cves-in-wekan-with-aisles-analyzer</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47951378</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47951378</guid></item><item><title><![CDATA[New comment by mmsc in "Carrot Disclosure: Forgejo"]]></title><description><![CDATA[
<p><a href="https://codeberg.org/forgejo/governance/src/commit/5c07b3801537212ed6be1edfec298d7b004ce92d/SECURITY-POLICY.md" rel="nofollow">https://codeberg.org/forgejo/governance/src/commit/5c07b3801...</a><p>> Failure to comply with these rules will be criticized publicly, and we reserve the right to no longer coordinate with you or your project in the future.<p>lol</p>
]]></description><pubDate>Wed, 29 Apr 2026 00:06:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=47942543</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47942543</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47942543</guid></item><item><title><![CDATA[AISLE Discovers 38 CVEs in OpenEMR Healthcare Software]]></title><description><![CDATA[
<p>Article URL: <a href="https://aisle.com/blog/aisle-discovers-38-critical-security-vulnerabilities-in-healthcare-software-used-by-100000-providers">https://aisle.com/blog/aisle-discovers-38-critical-security-vulnerabilities-in-healthcare-software-used-by-100000-providers</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47936347">https://news.ycombinator.com/item?id=47936347</a></p>
<p>Points: 177</p>
<p># Comments: 113</p>
]]></description><pubDate>Tue, 28 Apr 2026 16:06:01 +0000</pubDate><link>https://aisle.com/blog/aisle-discovers-38-critical-security-vulnerabilities-in-healthcare-software-used-by-100000-providers</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47936347</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47936347</guid></item><item><title><![CDATA[New comment by mmsc in "GPT‑5.5 Bio Bug Bounty"]]></title><description><![CDATA[
<p>How is that a scam? You don't get participation awards for solving half of a puzzle...</p>
]]></description><pubDate>Sat, 25 Apr 2026 15:47:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=47902308</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47902308</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47902308</guid></item><item><title><![CDATA[New comment by mmsc in "Kernel code removals driven by LLM-created security reports"]]></title><description><![CDATA[
<p>Unmaintained code is a security issue in of itself, so this is of course a net benefit.</p>
]]></description><pubDate>Wed, 22 Apr 2026 14:10:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=47863926</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47863926</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47863926</guid></item><item><title><![CDATA[System over Model: Zero-Day Discovery at the Jagged Frontier]]></title><description><![CDATA[
<p>Article URL: <a href="https://aisle.com/blog/system-over-model-zero-day-discovery-at-the-jagged-frontier">https://aisle.com/blog/system-over-model-zero-day-discovery-at-the-jagged-frontier</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47767511">https://news.ycombinator.com/item?id=47767511</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 14 Apr 2026 16:09:20 +0000</pubDate><link>https://aisle.com/blog/system-over-model-zero-day-discovery-at-the-jagged-frontier</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47767511</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47767511</guid></item><item><title><![CDATA[New comment by mmsc in "Installing every* Firefox extension"]]></title><description><![CDATA[
<p>The website of this blog and their connections listed are a sight to behold. I miss that version of the internet.</p>
]]></description><pubDate>Sat, 11 Apr 2026 07:45:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47728421</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47728421</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47728421</guid></item><item><title><![CDATA[New comment by mmsc in "Filing the corners off my MacBooks"]]></title><description><![CDATA[
<p>As long as it's not hydrofluoric acid...</p>
]]></description><pubDate>Sat, 11 Apr 2026 06:27:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47728004</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47728004</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47728004</guid></item><item><title><![CDATA[New comment by mmsc in "Top laptops to use with FreeBSD"]]></title><description><![CDATA[
<p>> You say "works perfectly". I do not think it means what you think it means.<p>Copying some files from a different machine is not that burdensome. The point is, it works.</p>
]]></description><pubDate>Thu, 09 Apr 2026 15:52:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=47705292</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47705292</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47705292</guid></item><item><title><![CDATA[New comment by mmsc in "Top laptops to use with FreeBSD"]]></title><description><![CDATA[
<p>FreeBSD works perfectly on intel MacBooks if you've got one laying around: <a href="https://joshua.hu/FreeBSD-on-MacbookPro-114-A1398" rel="nofollow">https://joshua.hu/FreeBSD-on-MacbookPro-114-A1398</a></p>
]]></description><pubDate>Thu, 09 Apr 2026 13:25:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=47703434</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47703434</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47703434</guid></item><item><title><![CDATA[New comment by mmsc in "Email obfuscation: What works in 2026?"]]></title><description><![CDATA[
<p>> Also, a note to those who make fancy "me+someservice@somedomain.com" addresses:<p>Just wait until one of these companies demands an email from the registered email address of your account!</p>
]]></description><pubDate>Thu, 02 Apr 2026 08:53:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=47611754</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47611754</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47611754</guid></item><item><title><![CDATA[New comment by mmsc in "Hong Kong police can now demand phone passwords under new security rules"]]></title><description><![CDATA[
<p>Ah, finally catching up to ... The UK, Australia, Ireland, France, the Netherlands, and probably a lot more.</p>
]]></description><pubDate>Fri, 27 Mar 2026 14:22:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=47543000</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47543000</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47543000</guid></item><item><title><![CDATA[New comment by mmsc in "A Japanese glossary of chopsticks faux pas (2022)"]]></title><description><![CDATA[
<p><p><pre><code>  こすり箸 Kosuribashi:
 To rub waribashi (disposable chopsticks) together to remove splinters.
</code></pre>
I don't know about Japan, but everybody does this in Taiwan.</p>
]]></description><pubDate>Sat, 21 Mar 2026 03:33:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=47463728</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47463728</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47463728</guid></item><item><title><![CDATA[Wikipedia: AI or Not Quiz]]></title><description><![CDATA[
<p>Article URL: <a href="https://en.wikipedia.org/wiki/Wikipedia:AI_or_not_quiz">https://en.wikipedia.org/wiki/Wikipedia:AI_or_not_quiz</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47449621">https://news.ycombinator.com/item?id=47449621</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 20 Mar 2026 02:18:56 +0000</pubDate><link>https://en.wikipedia.org/wiki/Wikipedia:AI_or_not_quiz</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47449621</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47449621</guid></item><item><title><![CDATA[New comment by mmsc in "Aquasecurity/Trivy GitHub Repository and Homebrew Cask Compromised (again)"]]></title><description><![CDATA[
<p>The offending commit seems to be: <a href="https://github.com/aquasecurity/trivy/commit/1885610c6a34811c8296416ae69f568002ef11ec" rel="nofollow">https://github.com/aquasecurity/trivy/commit/1885610c6a34811...</a> which updates the action to `actions/checkout@70379aad1a8b40919ce8b382d3cd7d0315cde1d0 # v6.0.2`.  <a href="https://github.com/actions/checkout/commit/70379aad1a8b40919ce8b382d3cd7d0315cde1d0" rel="nofollow">https://github.com/actions/checkout/commit/70379aad1a8b40919...</a> is not actually in `actions/checkout` but a fork, and it pulls malicious code from the typo-squatted "scan.aquasecurtiy.org" (note the _tiy_).<p>Any system with Trivy 0.69.4 on it (and being run) can be assumed to be compromised.</p>
]]></description><pubDate>Fri, 20 Mar 2026 02:08:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=47449542</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47449542</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47449542</guid></item><item><title><![CDATA[Aquasecurity/Trivy GitHub Repository and Homebrew Cask Compromised (again)]]></title><description><![CDATA[
<p>Article URL: <a href="https://opensourcemalware.com/repository/https%3A%2F%2Fgithub.com%2Faquasecurity%2Ftrivy%2F">https://opensourcemalware.com/repository/https%3A%2F%2Fgithub.com%2Faquasecurity%2Ftrivy%2F</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47449498">https://news.ycombinator.com/item?id=47449498</a></p>
<p>Points: 16</p>
<p># Comments: 4</p>
]]></description><pubDate>Fri, 20 Mar 2026 02:04:51 +0000</pubDate><link>https://opensourcemalware.com/repository/https%3A%2F%2Fgithub.com%2Faquasecurity%2Ftrivy%2F</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47449498</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47449498</guid></item><item><title><![CDATA[Always 'Copy Clean Link' When Possible on Firefox, with UserChrome.css]]></title><description><![CDATA[
<p>Article URL: <a href="https://joshua.hu/firefox-always-copy-clean-link-url-userchrome-css">https://joshua.hu/firefox-always-copy-clean-link-url-userchrome-css</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47408966">https://news.ycombinator.com/item?id=47408966</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 17 Mar 2026 05:23:15 +0000</pubDate><link>https://joshua.hu/firefox-always-copy-clean-link-url-userchrome-css</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47408966</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47408966</guid></item><item><title><![CDATA[New comment by mmsc in "Glassworm is back: A new wave of invisible Unicode attacks hits repositories"]]></title><description><![CDATA[
<p>GitHub advertises itself as warning about those Unicode characters: <a href="https://github.blog/changelog/2025-05-01-github-now-provides-a-warning-about-hidden-unicode-text/" rel="nofollow">https://github.blog/changelog/2025-05-01-github-now-provides...</a><p>Of course, it doesn't work though. I reported this to their bug bounty, they paid me a bounty, and told me "we won't be fixing it": <a href="https://joshua.hu/2025-bug-bounty-stories-fail#githubs-utf-filter-warning" rel="nofollow">https://joshua.hu/2025-bug-bounty-stories-fail#githubs-utf-f...</a><p>The exact quote is "Thanks for the submission! We have reviewed your report and validated your findings. After internally assessing your report based on factors including the complexity of successfully exploiting the vulnerability, the potential data and information exposure, as well as the systems and users that would be impacted, we have determined that they do not present a significant security risk to be eligible under our rewards structure." The funny thing is, they actually gave me $500 and a lifetime GitHub Pro for the submission.</p>
]]></description><pubDate>Sun, 15 Mar 2026 23:52:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=47393393</link><dc:creator>mmsc</dc:creator><comments>https://news.ycombinator.com/item?id=47393393</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47393393</guid></item></channel></rss>