<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: parable</title><link>https://news.ycombinator.com/user?id=parable</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 17 Sep 2026 18:07:08 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=parable" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Hacking xAI for unreleased models and confidential documents]]></title><description><![CDATA[
<p>Article URL: <a href="https://schizo.org/blog/hacking-xai">https://schizo.org/blog/hacking-xai</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49293794">https://news.ycombinator.com/item?id=49293794</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Fri, 14 Aug 2026 01:29:53 +0000</pubDate><link>https://schizo.org/blog/hacking-xai</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=49293794</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49293794</guid></item><item><title><![CDATA[New comment by parable in "Framework discloses data breach via Metabase 0-day"]]></title><description><![CDATA[
<p>This would be nice, and I hope I get to see a future like this, but I moreso meant that I don't see a solution for this issue given the current landscape of things. Ideally, yes, companies wouldn't collect the data and it would be illegal to do so. However, this currently isn't the case, so what can be done that lets all sides win? Something has to give, and I'm certain users will receive the short end of the stick at all times - at least, until there are better laws in place.</p>
]]></description><pubDate>Fri, 07 Aug 2026 08:49:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49207602</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=49207602</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49207602</guid></item><item><title><![CDATA[New comment by parable in "Framework discloses data breach via Metabase 0-day"]]></title><description><![CDATA[
<p>Metabase can be self-hosted, but you cannot self-host Salesforce or Mixpanel or many of the other products I'm referring to. In an ideal world, every company would self-host their own instances of all of their products, since that ultimately forces them to be solely responsible for their customers' data. Using the cloud versions of these products shifts the blame from the company itself to the vendor when things go sideways, so it makes more sense for them to do this instead of taking responsibility.</p>
]]></description><pubDate>Fri, 07 Aug 2026 08:41:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49207534</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=49207534</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49207534</guid></item><item><title><![CDATA[New comment by parable in "Framework discloses data breach via Metabase 0-day"]]></title><description><![CDATA[
<p>While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days.<p>I don't see a solution to this in the near future. I initially thought up something quite simple: assign every customer a unique ID and use <i>that</i> where possible to reference a customer. That solution, however, renders the analytics and CRM tools nearly useless. There has to be a better way, though, other than haphazardly giving out customer metadata to other vendors. All of that information should stay in-house.<p>As for why metadata is important: I've said this before, but metadata can't easily be changed. I'd much prefer having my password or credit card number leaked in plaintext since I can change those identifiers trivially. I can't change my name, phone number, or address as easily.</p>
]]></description><pubDate>Fri, 07 Aug 2026 06:22:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=49206576</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=49206576</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49206576</guid></item><item><title><![CDATA[Klue OAuth breach victim list grows as Icarus hackers claim attack]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/">https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48605915">https://news.ycombinator.com/item?id=48605915</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 20 Jun 2026 02:54:41 +0000</pubDate><link>https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48605915</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48605915</guid></item><item><title><![CDATA[New comment by parable in "1k Data Breaches Later, the Disclosure Lag Is Worse"]]></title><description><![CDATA[
<p>I've had a similar thought in the past. I was thinking about the feasibility of a law being introduced where each company making over a certain amount of money per year must begin a VDP (and optionally a BBP) so that security flaws can be reported to them easily. This can easily be done by simply opening up security@companydomain and using security.txt (<a href="https://securitytxt.org" rel="nofollow">https://securitytxt.org</a>). Reports must receive a response in N days, where N is calculated based on available staff, resource allocation, and revenue of the company. If they don't receive a response after N days, this can be escalated to some government agency which can take action against the company for failing to respond to a report on time.</p>
]]></description><pubDate>Mon, 08 Jun 2026 09:02:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48442914</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48442914</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48442914</guid></item><item><title><![CDATA[New comment by parable in "1k Data Breaches Later, the Disclosure Lag Is Worse"]]></title><description><![CDATA[
<p>Companies can and do get away with arguing that they have a "lawful basis" to collect whatever data they'd like. It's unfortunate.<p>IANAL, but the law seems a bit vague to me, and it appears that companies use that vagueness to their advantage. Maybe I'm just not articulating my arguments correctly.</p>
]]></description><pubDate>Mon, 08 Jun 2026 08:42:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48442788</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48442788</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48442788</guid></item><item><title><![CDATA[New comment by parable in "1k Data Breaches Later, the Disclosure Lag Is Worse"]]></title><description><![CDATA[
<p>> Otherwise, just assume everything you do online is public and act accordingly.<p>This is such a depressing reality. It's also what governments want you to believe. If you aren't able to speak your mind about anything anonymously, then you won't be able to, say, spread ideas that go against them.<p>Admitting defeat at all and not even <i>trying</i> to teach people about privacy results in the "I don't care, what's the point?" attitude that plagues many people today.</p>
]]></description><pubDate>Mon, 08 Jun 2026 08:15:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48442593</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48442593</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48442593</guid></item><item><title><![CDATA[New comment by parable in "1k Data Breaches Later, the Disclosure Lag Is Worse"]]></title><description><![CDATA[
<p>I use Snusbase (<a href="https://snusbase.com" rel="nofollow">https://snusbase.com</a>). They've been around since around 2016 and haven't had any issues legally - they're the longest-standing data breach search engine besides HIBP, as far as I know.<p>(This is not an advertisement.)</p>
]]></description><pubDate>Mon, 08 Jun 2026 08:02:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48442515</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48442515</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48442515</guid></item><item><title><![CDATA[New comment by parable in "1k Data Breaches Later, the Disclosure Lag Is Worse"]]></title><description><![CDATA[
<p>Hashes can be cracked, and end users won't understand how to create password hashes to check which one was leaked. Plus, salts exist.<p>Passwords shouldn't matter anyways. Use a password manager and be done with it. The real issue is metadata which can't easily be changed - phone numbers, addresses, and the like. If any of that data is leaked, it becomes much harder to contain impact. You can't move addresses every time your address gets leaked online.</p>
]]></description><pubDate>Mon, 08 Jun 2026 08:00:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48442502</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48442502</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48442502</guid></item><item><title><![CDATA[New comment by parable in "1k Data Breaches Later, the Disclosure Lag Is Worse"]]></title><description><![CDATA[
<p>I wish that were the case, but because of there being barely any consequences for breaches, it's much more profitable to store everything you can and sell it to the highest bidder. Make it a huge risk to store data, <i>then</i> companies will start treating data like a live hand grenade.</p>
]]></description><pubDate>Mon, 08 Jun 2026 07:29:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48442304</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48442304</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48442304</guid></item><item><title><![CDATA[New comment by parable in "1k Data Breaches Later, the Disclosure Lag Is Worse"]]></title><description><![CDATA[
<p>I'd also add a third issue to this list: data retention. Too many companies I've dealt with have privacy policies that state something to the tune of "we'll hold onto your data for as long as required" without giving much of an explanation as to how long "as required" is.</p>
]]></description><pubDate>Mon, 08 Jun 2026 07:24:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48442266</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48442266</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48442266</guid></item><item><title><![CDATA[New comment by parable in "Rootshell: A new E2EE email service hosted in Iceland"]]></title><description><![CDATA[
<p>I find it very hard to trust any email service that claims to be E2EE without an audit by a reputable firm like Cure53 or Trail of Bits.<p>I signed up to give it a brief test and immediately noticed that emails are returned from the server in plain text. This means that the emails are decrypted on the server, which defeats the entire purpose of E2EE. The encrypted email contents and metadata should be returned to the user and decrypted on the client.<p>It's also painfully obvious that the entire thing is vibe-coded. While that in itself isn't an issue, it raises scrutiny. If the author doesn't have a full understanding of the code their LLM generates, some nasty bugs could be lurking.<p>Not very promising.</p>
]]></description><pubDate>Wed, 03 Jun 2026 21:40:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48390515</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48390515</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48390515</guid></item><item><title><![CDATA[New comment by parable in "Platypus – create native Mac applications from command line scripts"]]></title><description><![CDATA[
<p>I'm not sure how I haven't heard of this yet. There have been too many times I've wished I could convert a command-line script to a native application easily for me not to try this.</p>
]]></description><pubDate>Wed, 03 Jun 2026 07:23:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=48380971</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48380971</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48380971</guid></item><item><title><![CDATA[New comment by parable in "1-Click GitHub Token Stealing via a VSCode Bug"]]></title><description><![CDATA[
<p>Kudos for the public disclosure. Too many people haven't been happy with MSRC and it's starting to boil over (see the Nightmare Eclipse situation, too). Maybe all of these disclosures will cause them to do some introspection and realize they're the problem. I highly doubt that, but one can dream.</p>
]]></description><pubDate>Wed, 03 Jun 2026 07:17:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=48380934</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48380934</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48380934</guid></item><item><title><![CDATA[New comment by parable in "The newest Instagram “exploit” is the goofiest I've seen"]]></title><description><![CDATA[
<p>It seems pretty trivial to just add a check in the agent's tool call to determine if the email is actually the one on file (or one that has previously been on file). I'm not sure why it's taking them so long to remediate.</p>
]]></description><pubDate>Wed, 03 Jun 2026 01:32:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48378677</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48378677</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48378677</guid></item><item><title><![CDATA[New comment by parable in "The newest Instagram “exploit” is the goofiest I've seen"]]></title><description><![CDATA[
<p>The bug still exists - two of my friends have lost access to their accounts as of an hour ago. They've partially recovered but are unable to change their passwords, so their accounts are still technically in the hands of the attacker(s).</p>
]]></description><pubDate>Tue, 02 Jun 2026 20:28:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48375800</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48375800</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48375800</guid></item><item><title><![CDATA[New comment by parable in "The newest Instagram “exploit” is the goofiest I've seen"]]></title><description><![CDATA[
<p>It appears the exploit hasn't been patched: <a href="https://x.com/vxunderground/status/2061636614267273332" rel="nofollow">https://x.com/vxunderground/status/2061636614267273332</a><p>I've heard the new "method" has to do with setting your location to Singapore or something, but I have yet to confirm anything.</p>
]]></description><pubDate>Tue, 02 Jun 2026 02:55:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48365428</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48365428</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48365428</guid></item><item><title><![CDATA[New comment by parable in "The newest Instagram “exploit” is the goofiest I've seen"]]></title><description><![CDATA[
<p>The original 2FA did not get thoroughly bypassed, because otherwise I would've lost my username, so that's false - at least, based on my experience.<p>However, there are separate vulnerabilities that allow for 2FA to be bypassed on Instagram. I assume they were chained to take over specific high-value accounts. The 2FA removal happens as a service - most people charge around $1,000+ - so it wasn't viable for most lower-value accounts. Anything that was worth over $1k probably had the bypass applied to it.</p>
]]></description><pubDate>Tue, 02 Jun 2026 01:11:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48364666</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48364666</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48364666</guid></item><item><title><![CDATA[New comment by parable in "The newest Instagram “exploit” is the goofiest I've seen"]]></title><description><![CDATA[
<p>I suggest you try signing into your Instagram account via the app or website to check if you've been compromised. It could very well be a bot trying to obtain your recovery method hints but you could've also fallen victim to this exploit, especially if you have a short or valuable username.</p>
]]></description><pubDate>Tue, 02 Jun 2026 01:08:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48364638</link><dc:creator>parable</dc:creator><comments>https://news.ycombinator.com/item?id=48364638</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48364638</guid></item></channel></rss>