<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: new23d</title><link>https://news.ycombinator.com/user?id=new23d</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 01 Aug 2026 02:22:20 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=new23d" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by new23d in "Hacker Public Radio"]]></title><description><![CDATA[
<p>Says Not Before: Thu, 09 Jul 2026 01:02:21 GMT ; Not After: Wed, 07 Oct 2026 01:02:20 GMT for me. Works fine, too.</p>
]]></description><pubDate>Thu, 30 Jul 2026 15:56:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=49111821</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=49111821</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49111821</guid></item><item><title><![CDATA[New comment by new23d in "Euro firms must ditch Uncle Sam's clouds and go EU-native"]]></title><description><![CDATA[
<p>netim.com has been reliable over the years for me</p>
]]></description><pubDate>Sat, 31 Jan 2026 12:56:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=46836256</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=46836256</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46836256</guid></item><item><title><![CDATA[New comment by new23d in "What data do coding agents send, and where to?"]]></title><description><![CDATA[
<p>Our report seeks to answer some of our questions for seven of the most popular agentic code editors and plugins. By intercepting and analysing their network flows across a set of standardised tasks, we aim to gain insight into the behaviour, privacy implications, and telemetry patterns of these tools in real-world scenarios. Incidentally, a side-effect was running into OWASP LLM07:2025 System Prompt Leakage for three of the chosen coding agents. You can see the system prompts in the appendix.</p>
]]></description><pubDate>Tue, 04 Nov 2025 12:11:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=45810027</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=45810027</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45810027</guid></item><item><title><![CDATA[What data do coding agents send, and where to?]]></title><description><![CDATA[
<p>Article URL: <a href="https://chasersystems.com/blog/what-data-do-coding-agents-send-and-where-to/">https://chasersystems.com/blog/what-data-do-coding-agents-send-and-where-to/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45810026">https://news.ycombinator.com/item?id=45810026</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 04 Nov 2025 12:11:25 +0000</pubDate><link>https://chasersystems.com/blog/what-data-do-coding-agents-send-and-where-to/</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=45810026</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45810026</guid></item><item><title><![CDATA[New comment by new23d in "Obfuscating outbound traffic via a Suricata "firewall""]]></title><description><![CDATA[
<p>Obfuscation via egress firewalls and evasive binary development with an iterative LLM agent.</p>
]]></description><pubDate>Fri, 11 Jul 2025 14:42:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=44532683</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=44532683</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44532683</guid></item><item><title><![CDATA[Obfuscating outbound traffic via a Suricata "firewall"]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.new23d.com/obfuscating-outbound-traffic-via-a-suricata-firewall/">https://www.new23d.com/obfuscating-outbound-traffic-via-a-suricata-firewall/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44532682">https://news.ycombinator.com/item?id=44532682</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Fri, 11 Jul 2025 14:42:18 +0000</pubDate><link>https://www.new23d.com/obfuscating-outbound-traffic-via-a-suricata-firewall/</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=44532682</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44532682</guid></item><item><title><![CDATA[New comment by new23d in "Why I no longer have an old-school cert on my HTTPS site"]]></title><description><![CDATA[
<p>Use AWS Route53?</p>
]]></description><pubDate>Sat, 24 May 2025 19:32:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=44083277</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=44083277</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44083277</guid></item><item><title><![CDATA[New comment by new23d in "Living-off-the-land Dynamic DNS for Route 53"]]></title><description><![CDATA[
<p>Making a dynamic DNS client with aws and jq CLI, with a least-privilege IAM role and a SystemD service.</p>
]]></description><pubDate>Tue, 25 Mar 2025 19:20:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=43474818</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=43474818</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43474818</guid></item><item><title><![CDATA[Living-off-the-land Dynamic DNS for Route 53]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.new23d.com/living-off-the-land-dynamic-dns-for-route-53/">https://www.new23d.com/living-off-the-land-dynamic-dns-for-route-53/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43474817">https://news.ycombinator.com/item?id=43474817</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 25 Mar 2025 19:20:48 +0000</pubDate><link>https://www.new23d.com/living-off-the-land-dynamic-dns-for-route-53/</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=43474817</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43474817</guid></item><item><title><![CDATA[New comment by new23d in "Why are UK electricity bills so expensive?"]]></title><description><![CDATA[
<p>Exactly the same happened with me. Picking up the phone and responding to email (in weeks, not hours or days) didn't lower my bills. This sort of marketing is perhaps deflection.</p>
]]></description><pubDate>Fri, 20 Dec 2024 23:00:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=42475956</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=42475956</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42475956</guid></item><item><title><![CDATA[New comment by new23d in "An analysis of CRL sizes from various CAs"]]></title><description><![CDATA[
<p>We'll be working on that in the coming days. Thought the data at this point was a good start.</p>
]]></description><pubDate>Wed, 24 Jul 2024 19:38:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=41061028</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=41061028</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41061028</guid></item><item><title><![CDATA[New comment by new23d in "An analysis of CRL sizes from various CAs"]]></title><description><![CDATA[
<p>Some initial observations:<p>• Google's CRLs from the same intermediate CA (same public key) have different URLs and different content when pulled from different hosts (google.com, youtube.com).<p>• DigiCert has sharded according to 'assurance' class, algorithm, year and acquisition's name.<p>• Sectigo also has sharded according to 'assurance' class [1].<p>• GlobalSign has sharded by the yearly quarter presumably.<p>• HTTP Cache-Control maxage (or s-maxage), 'Expires' and 'Next Update' within the CRL file are not in sync.<p>• Some CAs other than Let's Encrypt also do not publish CRL URLs in the leaf certificates.<p>[1] <a href="https://www.sectigo.com/knowledge-base/detail/Sectigo-Intermediate-Certificates-ECC/kA01N000000rfGE" rel="nofollow">https://www.sectigo.com/knowledge-base/detail/Sectigo-Interm...</a></p>
]]></description><pubDate>Wed, 24 Jul 2024 16:06:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=41058461</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=41058461</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41058461</guid></item><item><title><![CDATA[New comment by new23d in "Intent to end OCSP service"]]></title><description><![CDATA[
<p>We collected some data [1] on the viability of only CRLs as the future (phasing out OCSP) - motivated by Let's Encrypt's announcement today [2].<p>Data is on CRL availability, number of entries, expiry & refresh times, etc. from various x509 leaf server SSL certificates.<p>[1] <a href="https://news.ycombinator.com/item?id=41058138">https://news.ycombinator.com/item?id=41058138</a>
[2] <a href="https://news.ycombinator.com/item?id=41046956">https://news.ycombinator.com/item?id=41046956</a></p>
]]></description><pubDate>Wed, 24 Jul 2024 15:40:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=41058171</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=41058171</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41058171</guid></item><item><title><![CDATA[New comment by new23d in "An analysis of CRL sizes from various CAs"]]></title><description><![CDATA[
<p>We collected some data on the viability of only CRLs as the future (phasing out OCSP) - motivated by Let's Encrypt's announcement today [1].<p>Data is on CRL availability, number of entries, expiry & refresh times, etc. from various x509 leaf server SSL certificates.<p>[1] <a href="https://news.ycombinator.com/item?id=41046956">https://news.ycombinator.com/item?id=41046956</a></p>
]]></description><pubDate>Wed, 24 Jul 2024 15:36:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=41058139</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=41058139</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41058139</guid></item><item><title><![CDATA[An analysis of CRL sizes from various CAs]]></title><description><![CDATA[
<p>Article URL: <a href="https://chasersystems.com/blog/an-analysis-of-certificate-revocation-list-sizes/">https://chasersystems.com/blog/an-analysis-of-certificate-revocation-list-sizes/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41058138">https://news.ycombinator.com/item?id=41058138</a></p>
<p>Points: 1</p>
<p># Comments: 4</p>
]]></description><pubDate>Wed, 24 Jul 2024 15:36:12 +0000</pubDate><link>https://chasersystems.com/blog/an-analysis-of-certificate-revocation-list-sizes/</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=41058138</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41058138</guid></item><item><title><![CDATA[New comment by new23d in "Capturing Linux SSL/TLS plaintext without a CA certificate using eBPF"]]></title><description><![CDATA[
<p>TLS 1.3 and ESNI (now called Encrypted Client Hello - ECH) are separate standards, although you'll see ECH only enabled in bleeding edge stacks. In fact, ECH is still in IETF draft phase [1].<p>It can be disabled if an organisation wishes to. I wrote about how to do this in Chrome [2,3], and will write about Firefox when I get a chance.<p>[1] <a href="https://datatracker.ietf.org/doc/draft-ietf-tls-esni/" rel="nofollow">https://datatracker.ietf.org/doc/draft-ietf-tls-esni/</a>
[2] <a href="https://chasersystems.com/blog/disabling-encrypted-clienthello-in-google-chrome-and-why/" rel="nofollow">https://chasersystems.com/blog/disabling-encrypted-clienthel...</a>
[3] <a href="https://news.ycombinator.com/item?id=37823262">https://news.ycombinator.com/item?id=37823262</a></p>
]]></description><pubDate>Fri, 12 Jul 2024 07:20:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=40943350</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=40943350</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40943350</guid></item><item><title><![CDATA[New comment by new23d in "What the damaged Svalbard cable looked like"]]></title><description><![CDATA[
<p>Product appears to be an ID Tent from Evi-Paq. It has inches on the front 'leg' and cms on the rear.<p><a href="https://forensicssource.com/collections/evidence-markers/products/disposable-id-tent-white-f_327" rel="nofollow">https://forensicssource.com/collections/evidence-markers/pro...</a></p>
]]></description><pubDate>Sun, 26 May 2024 22:55:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=40486149</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=40486149</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40486149</guid></item><item><title><![CDATA[New comment by new23d in "Ask HN: Bootstrapped founder. Does it make sense to move out of SF for a while?"]]></title><description><![CDATA[
<p>Stay near a transport hub so you can connect with your prospects and customers regularly, by travelling. Working along side other founders in the B2B space would be extremely beneficial too.</p>
]]></description><pubDate>Mon, 20 May 2024 18:52:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=40418781</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=40418781</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40418781</guid></item><item><title><![CDATA[New comment by new23d in "Is the AWS Network Firewall safe? CyberRatings tests reveal concerns"]]></title><description><![CDATA[
<p>Wait till they get to the part where it can be easily bypassed. I spoke about it [1] at the fwd:cloudsec conference [2] in July 2022. Others have raised concerns about discovery of these bypasses too [3].<p>[1] <a href="https://www.youtube.com/watch?v=DKSa32qWiRw" rel="nofollow">https://www.youtube.com/watch?v=DKSa32qWiRw</a>
[2] <a href="https://fwdcloudsec.org/" rel="nofollow">https://fwdcloudsec.org/</a>
[3] <a href="https://canglad.com/blog/2023/aws-network-firewall-egress-filtering-can-be-easily-bypassed/" rel="nofollow">https://canglad.com/blog/2023/aws-network-firewall-egress-fi...</a></p>
]]></description><pubDate>Tue, 07 May 2024 15:15:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=40286680</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=40286680</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40286680</guid></item><item><title><![CDATA[New comment by new23d in "Pilot of Boeing flight says he lost control after instrument failure"]]></title><description><![CDATA[
<p>This is the FlightRadar24 playback of the flight: <a href="https://www.flightradar24.com/data/flights/la800#34506b53" rel="nofollow">https://www.flightradar24.com/data/flights/la800#34506b53</a><p>At time ~02:27, a dip in the altitude can be seen in the flight data chart.</p>
]]></description><pubDate>Tue, 12 Mar 2024 17:12:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=39682078</link><dc:creator>new23d</dc:creator><comments>https://news.ycombinator.com/item?id=39682078</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39682078</guid></item></channel></rss>