<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: not_a9</title><link>https://news.ycombinator.com/user?id=not_a9</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 13 Jun 2026 17:47:51 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=not_a9" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by not_a9 in "(Re//Verse 2026) Taxonomy and Deobfuscation of a Real World Binary Obfuscator [pdf]"]]></title><description><![CDATA[
<p>The actual presentation: <a href="https://www.youtube.com/watch?v=3LtwqJM3Qjg" rel="nofollow">https://www.youtube.com/watch?v=3LtwqJM3Qjg</a>.<p>An interesting look at what modern code obfuscation looks like, the example used being Riot Vanguard's kernel mode component.</p>
]]></description><pubDate>Thu, 11 Jun 2026 15:06:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=48491377</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48491377</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48491377</guid></item><item><title><![CDATA[(Re//Verse 2026) Taxonomy and Deobfuscation of a Real World Binary Obfuscator [pdf]]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/AnalogCyberNuke/RE-Verse-2026-Slides/blob/main/Reverse26.pdf">https://github.com/AnalogCyberNuke/RE-Verse-2026-Slides/blob/main/Reverse26.pdf</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48491376">https://news.ycombinator.com/item?id=48491376</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Thu, 11 Jun 2026 15:06:28 +0000</pubDate><link>https://github.com/AnalogCyberNuke/RE-Verse-2026-Slides/blob/main/Reverse26.pdf</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48491376</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48491376</guid></item><item><title><![CDATA[New comment by not_a9 in "Static Devirtualization of Themida"]]></title><description><![CDATA[
<p>They include a fun follow-up with a stronger obfuscator: <a href="https://www.youtube.com/watch?v=3LtwqJM3Qjg" rel="nofollow">https://www.youtube.com/watch?v=3LtwqJM3Qjg</a></p>
]]></description><pubDate>Sat, 06 Jun 2026 23:58:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48430380</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48430380</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48430380</guid></item><item><title><![CDATA[New comment by not_a9 in "I built a vulnerable app and spent $1,500 seeing if LLMs could hack it"]]></title><description><![CDATA[
<p>You can still hit guardrails with this enabled for your account. Had a silly moment a day or so ago when Claude Code hit the guardrail after a web search (presumably because the websearch contained badbad anticheat stuff like <a href="https://github.com/0avx/0avx.github.io/blob/main/article-3.md" rel="nofollow">https://github.com/0avx/0avx.github.io/blob/main/article-3.m...</a>). Codex with the ID verification has no qualms like this.</p>
]]></description><pubDate>Fri, 05 Jun 2026 06:27:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48408751</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48408751</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48408751</guid></item><item><title><![CDATA[New comment by not_a9 in "Expanding Project Glasswing"]]></title><description><![CDATA[
<p>> only ppl using AI are shops with clueless ppl getting flooded in nonsense.<p>Are Hex-Rays and Vector35 clueless?</p>
]]></description><pubDate>Wed, 03 Jun 2026 20:02:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48389195</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48389195</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48389195</guid></item><item><title><![CDATA[New comment by not_a9 in "Please Do Not Vibe Fuck Up This Software"]]></title><description><![CDATA[
<p>> There is undoubtedly AI-written code in the Linux kernel now<p>You can grep commit logs by “Assisted-By” these days and there sure is a whole bunch of LLMs.</p>
]]></description><pubDate>Sun, 31 May 2026 23:59:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48351081</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48351081</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48351081</guid></item><item><title><![CDATA[New comment by not_a9 in "Google's Antigravity bait and switch"]]></title><description><![CDATA[
<p>Visual Studio and Visual Studio Code are different beasts.</p>
]]></description><pubDate>Thu, 21 May 2026 19:16:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48227633</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48227633</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48227633</guid></item><item><title><![CDATA[New comment by not_a9 in "Linux gaming is faster because Windows APIs are becoming Linux kernel features"]]></title><description><![CDATA[
<p>Either everyone on Earth who’s working on this has a skill issue (which is probably hubris?) or there’s not enough differing humanized enough aimbot from human aim (note: Valve manages to screw up even here, with cheaters in Premier basically rage aimbotting these days IIRC)<p>In addition, there’s not much these things can do against subtler stuff like ESP.</p>
]]></description><pubDate>Sat, 16 May 2026 13:45:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48160229</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48160229</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48160229</guid></item><item><title><![CDATA[New comment by not_a9 in "Frontier AI has broken the open CTF format"]]></title><description><![CDATA[
<p>I’m interested in finding out how attack-defense style CTFs are affected by slopping. ENOWARS skorbor will probably significantly differ from the last time around.</p>
]]></description><pubDate>Sat, 16 May 2026 13:38:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48160185</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48160185</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48160185</guid></item><item><title><![CDATA[New comment by not_a9 in "Linux gaming is faster because Windows APIs are becoming Linux kernel features"]]></title><description><![CDATA[
<p>Games very much are using server-side statistics analysis for cheat detection. Valve made a presentation about it and Epic has an API for feeding game state data to ML anticheat for aimbot detection (game-specific and in addition to their existing anticheat measures)<p>It’s just that it doesn’t work.</p>
]]></description><pubDate>Thu, 14 May 2026 20:09:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48140570</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48140570</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48140570</guid></item><item><title><![CDATA[New comment by not_a9 in "Linux gaming is faster because Windows APIs are becoming Linux kernel features"]]></title><description><![CDATA[
<p>Aren’t most DMA cards just PCI-E FPGA things? In any case, DMA doesn’t magically make your shit UD - you can look at Unknowncheats and see.</p>
]]></description><pubDate>Thu, 14 May 2026 20:07:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=48140545</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48140545</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48140545</guid></item><item><title><![CDATA[New comment by not_a9 in "Linux gaming is faster because Windows APIs are becoming Linux kernel features"]]></title><description><![CDATA[
<p>Does Wine have any debugging tools with equivalent developer experience to Visual Studio’s debugger?</p>
]]></description><pubDate>Thu, 14 May 2026 20:04:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48140506</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48140506</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48140506</guid></item><item><title><![CDATA[New comment by not_a9 in "Show HN: Building a web server in assembly to give my life (a lack of) meaning"]]></title><description><![CDATA[
<p>You could also do a trick some Windows stuff does - parse syscall indices from said dylib.</p>
]]></description><pubDate>Sun, 10 May 2026 21:48:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48088446</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48088446</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48088446</guid></item><item><title><![CDATA[New comment by not_a9 in "Metal Gear Solid 2's source code has been leaked on 4chan"]]></title><description><![CDATA[
<p>I’m interested in how LLMs handle obfuscated code. Throw LLM with IDA MCP at EasyAntiCheat_EOS.sys or the like (as the most common examples of heavily obfuscated software) and see how far they can get.</p>
]]></description><pubDate>Sun, 03 May 2026 22:56:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48002472</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48002472</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48002472</guid></item><item><title><![CDATA[New comment by not_a9 in "Denuvo has been cracked in all single-player games it previously protected"]]></title><description><![CDATA[
<p>Anticheats will still have obfuscated code for obvious reasons (they don’t want to be reversed). Not sure they don’t induce some performance drop too - though maybe smaller compared to bad Denuvo implementation.</p>
]]></description><pubDate>Sun, 03 May 2026 22:47:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48002407</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48002407</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48002407</guid></item><item><title><![CDATA[New comment by not_a9 in "Denuvo has been cracked in all single-player games it previously protected"]]></title><description><![CDATA[
<p>>written by non-kernel-devs<p>What exactly separates a kernel dev from a non-kernel dev?</p>
]]></description><pubDate>Sun, 03 May 2026 22:44:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48002383</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48002383</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48002383</guid></item><item><title><![CDATA[New comment by not_a9 in "Denuvo has been cracked in all single-player games it previously protected"]]></title><description><![CDATA[
<p>Do the cracks still need you to disable Hyper-V (which leads to disabling WSL and whatever else)?<p>In addition, I’m not sure why they’re enabling test signing instead of using kdmapper or the like. Sure, anticheats will get way more mad at you having a manual mapped driver, but one imagines rebooting once (after playing your cracked video game) beats rebooting twice (to enable test signing, then after playing the game).<p>The funny thing is I remember reading about using hypervisor crap to bypass Denuvo in ~2020 (actually the post is from 2019, <a href="https://www.unknowncheats.me/forum/2410412-post14.html" rel="nofollow">https://www.unknowncheats.me/forum/2410412-post14.html</a>)</p>
]]></description><pubDate>Sun, 03 May 2026 22:39:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48002343</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=48002343</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48002343</guid></item><item><title><![CDATA[New comment by not_a9 in "Claude Code refuses requests or charges extra if your commits mention "OpenClaw""]]></title><description><![CDATA[
<p>FYI this does not work for CTF challenges at least - I’ve seen a lot of rev/pwn challenges try to add magic refusal strings/prompt hijacking and models really don’t give a damn.</p>
]]></description><pubDate>Thu, 30 Apr 2026 20:30:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47967819</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=47967819</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47967819</guid></item><item><title><![CDATA[Applied Reverse Engineering: Crude T&E for Control-Flow Tracing]]></title><description><![CDATA[
<p>Article URL: <a href="https://revers.engineering/applied-re-crude-te-for-control-flow-tracing/">https://revers.engineering/applied-re-crude-te-for-control-flow-tracing/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47744768">https://news.ycombinator.com/item?id=47744768</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 12 Apr 2026 21:33:45 +0000</pubDate><link>https://revers.engineering/applied-re-crude-te-for-control-flow-tracing/</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=47744768</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47744768</guid></item><item><title><![CDATA[New comment by not_a9 in "Veracrypt project update"]]></title><description><![CDATA[
<p><a href="https://community.osr.com/t/locked-out-of-microsoft-partner-center-driver-submission-page/60061" rel="nofollow">https://community.osr.com/t/locked-out-of-microsoft-partner-...</a>
Could be a related issue to this? Maybe Microsoft just doesn’t want driver developers for whatever reason.</p>
]]></description><pubDate>Wed, 08 Apr 2026 13:14:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=47689772</link><dc:creator>not_a9</dc:creator><comments>https://news.ycombinator.com/item?id=47689772</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47689772</guid></item></channel></rss>