<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: progval</title><link>https://news.ycombinator.com/user?id=progval</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 30 May 2026 21:11:53 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=progval" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by progval in "Shift will clean homes for free to train future robots"]]></title><description><![CDATA[
<p>Nothing in the article says the cameras are inside.</p>
]]></description><pubDate>Sat, 30 May 2026 07:10:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48333514</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=48333514</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48333514</guid></item><item><title><![CDATA[New comment by progval in "Robinhood now lets your AI agents trade stocks"]]></title><description><![CDATA[
<p>Didn't work last time <a href="https://www.theguardian.com/uk-news/2020/nov/06/companies-house-forces-business-name-change-to-prevent-security-risk" rel="nofollow">https://www.theguardian.com/uk-news/2020/nov/06/companies-ho...</a></p>
]]></description><pubDate>Fri, 29 May 2026 18:34:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48327422</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=48327422</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48327422</guid></item><item><title><![CDATA[New comment by progval in "Tech CEOs are apparently suffering from AI psychosis"]]></title><description><![CDATA[
<p>These? <a href="https://nitter.net/VictorTaelin/status/2043810543035920672" rel="nofollow">https://nitter.net/VictorTaelin/status/2043810543035920672</a> / <a href="https://nitter.net/VictorTaelin/status/2059327831679578511" rel="nofollow">https://nitter.net/VictorTaelin/status/2059327831679578511</a></p>
]]></description><pubDate>Wed, 27 May 2026 20:42:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=48300344</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=48300344</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48300344</guid></item><item><title><![CDATA[New comment by progval in "The AI bubble isn't like the internet bubble"]]></title><description><![CDATA[
<p>Are there estimates of their failure rate?</p>
]]></description><pubDate>Tue, 26 May 2026 11:39:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48278350</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=48278350</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48278350</guid></item><item><title><![CDATA[New comment by progval in "Bug 1950764: Work Around Crash on Intel Raptor Lake CPU"]]></title><description><![CDATA[
<p>According to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1950764#c23" rel="nofollow">https://bugzilla.mozilla.org/show_bug.cgi?id=1950764#c23</a> , it is not getting fixed.</p>
]]></description><pubDate>Mon, 25 May 2026 08:03:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48264539</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=48264539</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48264539</guid></item><item><title><![CDATA[New comment by progval in "We're testing new ad formats in Search and expanding our Direct Offers pilot"]]></title><description><![CDATA[
<p>Microsoft has you covered: <a href="https://notes.zachmanson.com/copilot-edited-an-ad-into-my-pr/" rel="nofollow">https://notes.zachmanson.com/copilot-edited-an-ad-into-my-pr...</a> / <a href="https://news.ycombinator.com/item?id=47570269">https://news.ycombinator.com/item?id=47570269</a></p>
]]></description><pubDate>Thu, 21 May 2026 13:30:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48222306</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=48222306</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48222306</guid></item><item><title><![CDATA[New comment by progval in "EU to crack down on TikTok, Instagram's 'addictive design' targeting kids"]]></title><description><![CDATA[
<p>It even includes email providers with a spam filter.</p>
]]></description><pubDate>Tue, 12 May 2026 12:31:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=48107314</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=48107314</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48107314</guid></item><item><title><![CDATA[New comment by progval in "Dirty Frag: Universal Linux LPE"]]></title><description><![CDATA[
<p>They don't have to publish a working exploit as soon as the embargo is broken, though.</p>
]]></description><pubDate>Thu, 07 May 2026 20:58:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48054885</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=48054885</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48054885</guid></item><item><title><![CDATA[New comment by progval in "Dirty Frag: Universal Linux LPE"]]></title><description><![CDATA[
<p>"sudo" in "sudo echo 3 > /prox/sys/vm/drop_caches" does not do anything because only runs echo, not the write.<p>And if a machine is already exploited, it's too late to do just that. You need to rebuild the whole disk image because anything on it could be compromised.</p>
]]></description><pubDate>Thu, 07 May 2026 20:56:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48054856</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=48054856</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48054856</guid></item><item><title><![CDATA[New comment by progval in "Utah to hold websites liable for users who mask their location with VPNs"]]></title><description><![CDATA[
<p>There is no evidence it is actually coming from Meta. The Reddit researcher the article cites generated their entire "analysis" in three days using Claude: <a href="https://news.ycombinator.com/item?id=47659552">https://news.ycombinator.com/item?id=47659552</a><p>Their website also added this page since I posted that comment: <a href="https://web.archive.org/web/20260411112604/https://tboteproject.com/notice/" rel="nofollow">https://web.archive.org/web/20260411112604/https://tboteproj...</a> where they claim their website is under "surveillance" because it got a few thousand requests from Google Cloud et al, most of them to a single page. This shows how low their standards are.</p>
]]></description><pubDate>Sun, 03 May 2026 15:20:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=47997836</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=47997836</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47997836</guid></item><item><title><![CDATA[New comment by progval in "This Month in Ladybird – April 2026"]]></title><description><![CDATA[
<p>Common enough that Mozilla has full-time engineers working on triaging compatibility issues, so they can either be fixed in Firefox or reported to webmasters. Here are the reports they get: <a href="https://webcompat.com/issues" rel="nofollow">https://webcompat.com/issues</a></p>
]]></description><pubDate>Sun, 03 May 2026 05:48:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=47993774</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=47993774</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47993774</guid></item><item><title><![CDATA[New comment by progval in "Eka’s robotic claw feels like we're approaching a ChatGPT moment"]]></title><description><![CDATA[
<p>Some of them will be paid by subscription <i>and</i> have ads</p>
]]></description><pubDate>Fri, 01 May 2026 22:37:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=47981306</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=47981306</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47981306</guid></item><item><title><![CDATA[New comment by progval in "An open letter asking NHS England to keep its code open"]]></title><description><![CDATA[
<p>> pause OSS contribution and usage<p>What do you mean by that? They can't possibly stop using Linux/Kubernetes/Chrome (including Edge)/almost all programming languages/nginx/...</p>
]]></description><pubDate>Fri, 01 May 2026 19:11:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=47978839</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=47978839</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47978839</guid></item><item><title><![CDATA[New comment by progval in "Copy Fail"]]></title><description><![CDATA[
<p>Ah indeed, it can be used to overwrite the page cache for files on read-only volumes.</p>
]]></description><pubDate>Wed, 29 Apr 2026 19:28:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47953209</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=47953209</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47953209</guid></item><item><title><![CDATA[New comment by progval in "Copy Fail – CVE-2026-31431"]]></title><description><![CDATA[
<p>Yes. Alpine in rootless Podman doesn't work (after replacing "/usr/bin/su" with "/bin/su" in the .py, running the .py just doesn't do anything) while it does in Debian in rootless Podman on the same host.</p>
]]></description><pubDate>Wed, 29 Apr 2026 19:17:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=47953040</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=47953040</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47953040</guid></item><item><title><![CDATA[New comment by progval in "Copy Fail"]]></title><description><![CDATA[
<p>So this replaces a SUID binary, in order to run as PID 0. The website claims it can escape "Kubernetes / container clusters" and "CI runners & build farms" but I don't see anything supporting the claim it can escape a container (or specifically, a user namespace).<p>I ran the exploit in rootless Podman, and predictably it doesn't escape the container.<p>They also claim their script "roots every Linux distribution shipped since 2017.", but only tested four; and it doesn't work on Alpine</p>
]]></description><pubDate>Wed, 29 Apr 2026 19:14:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=47952990</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=47952990</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47952990</guid></item><item><title><![CDATA[New comment by progval in "Copy Fail"]]></title><description><![CDATA[
<p>The binary "zip" isn't the exploit, it's the shellcode. The exploit is the rest, which changes the code of a SUID executable (su).</p>
]]></description><pubDate>Wed, 29 Apr 2026 18:34:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=47952479</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=47952479</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47952479</guid></item><item><title><![CDATA[New comment by progval in "Before GitHub"]]></title><description><![CDATA[
<p>> make a WASM slave and thousands of developers can give their CPU/Memory/Disk for build slaves<p>WASM isn't a magic bullet for sandboxing. CI environments assume a full Linux. So you need to either ran a VM (with the attack surface that implies) or a write an x86 emulator in WASM (which would be very slow).<p>You also need anti-abuse to stop bitcoin miners from using your system. GitHub probably have full-time employees working on it.<p>> Like bitcoin mining, there could be some competition between 3 parallel builds to pick the winner if the output is the same.<p>It's a lot more complicated because many builds are not deterministic, you need to store artefacts, build secrets, etc.<p>Companies like golem.network or iex.ec have been working on this problem for a decade and they are still not easy to use.</p>
]]></description><pubDate>Wed, 29 Apr 2026 13:02:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=47947784</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=47947784</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47947784</guid></item><item><title><![CDATA[New comment by progval in "Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign"]]></title><description><![CDATA[
<p>Use a package repository that fast-tracks security updates, like Debian Stable.</p>
]]></description><pubDate>Thu, 23 Apr 2026 21:42:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=47882475</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=47882475</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47882475</guid></item><item><title><![CDATA[New comment by progval in "French government agency confirms breach as hacker offers to sell data"]]></title><description><![CDATA[
<p>> I'm tired of having to connect on EDF' shitty website to get a new PDF every three months.<p>It doesn't look like this app can generate "justificatifs de domicile", only substitutes for an identity card or passport.<p>> Why do the put three stats about trains on your linked page?!<p>I was wondering about that too</p>
]]></description><pubDate>Thu, 23 Apr 2026 20:27:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=47881407</link><dc:creator>progval</dc:creator><comments>https://news.ycombinator.com/item?id=47881407</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47881407</guid></item></channel></rss>