<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: psifertex</title><link>https://news.ycombinator.com/user?id=psifertex</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 06 Sep 2026 08:29:16 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=psifertex" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by psifertex in "For Linux kernel vulnerabilities, there is no heads-up to distributions"]]></title><description><![CDATA[
<p>It's not abhorrent. It's quite common and the correct thing to do here.<p>Them not disclosing doesn't make you safer. The people that want to abuse this could be actively exploiting it shortly after the commit went live. Waiting more time before the blog / marketing release is NOT the help you think it will be.<p>This is a very, very, old debate in the security community, just read the rest of this thread and you'll see plenty of explanation as to why.</p>
]]></description><pubDate>Mon, 04 May 2026 22:24:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48015753</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=48015753</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48015753</guid></item><item><title><![CDATA[New comment by psifertex in "Copy Fail"]]></title><description><![CDATA[
<p>They did not, in fact, botch anything. They notified the responsible party and followed a practice that is pretty much the accepted norm (and for good reason).<p>How recursive should their notifications be? Just the tip three distros? The top dozen? Every embedded Linux router company? How about every hosting provider?<p>They did what they're supposed to without being paid for it. The only other good source of funding for security research besides marketing budgets for security companies will NOT result in a disclosure timeline you'd be happier with. ;-)</p>
]]></description><pubDate>Fri, 01 May 2026 05:25:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=47971548</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=47971548</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47971548</guid></item><item><title><![CDATA[New comment by psifertex in "For Linux kernel vulnerabilities, there is no heads-up to distributions"]]></title><description><![CDATA[
<p>I doubt it will and I hope it doesn't.<p>External security research happens for one of only a few reasons typically:<p>1) hobbyists who are learning or just like to do it for fun
2) bug bounties (good luck with those in most open source)
3) marketing for security companies
4) non-public research going to CNO/CNE<p>If you want to kill 3, the output of 1 will not come close to 4 and the public is NOT better off with fewer public bugs.</p>
]]></description><pubDate>Fri, 01 May 2026 04:57:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47971433</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=47971433</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47971433</guid></item><item><title><![CDATA[New comment by psifertex in "For Linux kernel vulnerabilities, there is no heads-up to distributions"]]></title><description><![CDATA[
<p>You could try to make that case either way, but as has been pointed out by others all over this thread, the system we've landed on (90/+30) is industry standard after over two and a half decades of experimentation.<p>Anything else inevitably has worse for the public good.<p>Having spent that entire time and then some on both offensive and defensive teams, I assure you longer delays after notification do NOT decrease the overall risk to the public.<p>There's a reason we've landed where we have as a security community.</p>
]]></description><pubDate>Fri, 01 May 2026 04:50:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=47971400</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=47971400</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47971400</guid></item><item><title><![CDATA[New comment by psifertex in "Ghidra by NSA"]]></title><description><![CDATA[
<p>I'm curious what you would consider better UX?<p>We have actually been more inspired by Jetbrains lately than VS Code. Take that for what you will.<p>We do try to pick simple sane defaults while still allowing enough customization to adapt to different workflows.<p>Actually working on a startup wizard for first time users if they want to more closely replicate the feel of other RE tools since muscle memory is hard to break.</p>
]]></description><pubDate>Tue, 17 Feb 2026 13:13:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=47047152</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=47047152</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47047152</guid></item><item><title><![CDATA[New comment by psifertex in "Rethinking CLI interfaces for AI"]]></title><description><![CDATA[
<p>IDEs have changed a lot in the last 50 years. Just like we shouldn't advocate for hand writing assembly for all code, we shouldn't be stuck using CLI tooling the same way.<p>I share your apprehension regarding the current AI landscape changing so quickly it causes whiplash but I don't think a mindset of "it's been fine for 50 years" is going to survive the pace of development possible by better LLM integration.</p>
]]></description><pubDate>Sat, 19 Jul 2025 17:46:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=44617622</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=44617622</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44617622</guid></item><item><title><![CDATA[New comment by psifertex in "Defcon stiffs badge HW vendor, drags FW author offstage during talk"]]></title><description><![CDATA[
<p>Yes, actually, if you know someone there they were selling extras:<p><a href="https://defcon.org/html/links/dc-news.html" rel="nofollow">https://defcon.org/html/links/dc-news.html</a></p>
]]></description><pubDate>Mon, 12 Aug 2024 00:46:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=41220294</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=41220294</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41220294</guid></item><item><title><![CDATA[New comment by psifertex in "Defcon stiffs badge HW vendor, drags FW author offstage during talk"]]></title><description><![CDATA[
<p>I don't know why people think this, you're not the first person I've heard it from either.<p>First, I literally saw them do shots during a talk yesterday for some first-time presenters. Secondly that WASN'T the "old defcon" either! Drinking is a relatively new tradition in the history of the con. I've spoken twice. Once at DC 17 (no shot offered) and once at DC 23 (shots were offered). There's video proof:<p>No drinking, DC 17: <a href="https://www.youtube.com/watch?v=okPWY0FeUoU" rel="nofollow">https://www.youtube.com/watch?v=okPWY0FeUoU</a>
Asked to drink, opted for a coin instead (we were asked beforehand): <a href="https://youtu.be/6dmvtbrM6hs?feature=shared&t=1153" rel="nofollow">https://youtu.be/6dmvtbrM6hs?feature=shared&t=1153</a></p>
]]></description><pubDate>Mon, 12 Aug 2024 00:45:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=41220289</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=41220289</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41220289</guid></item><item><title><![CDATA[New comment by psifertex in "Dogbolt Decompiler Explorer"]]></title><description><![CDATA[
<p>Can I just say, thanks to the person who posted this for waiting until this week to do so.  (Side note: I suspect it was due to the recent coverage from C++ Weekly which is a great resource: <a href="https://www.youtube.com/watch?v=h3F0Fw0R7ME" rel="nofollow noreferrer">https://www.youtube.com/watch?v=h3F0Fw0R7ME</a>)<p>As recently as last week we had some horrible performance problems but it looks like the queue (<a href="https://dogbolt.org/queue" rel="nofollow noreferrer">https://dogbolt.org/queue</a>) is mostly still fine! Other than the long pole of a few of the decompilers being backed up, things are humming along quite smoothly! Josh + Glenn have done some great work on it! (<a href="https://github.com/decompiler-explorer/decompiler-explorer/commits/master">https://github.com/decompiler-explorer/decompiler-explorer/c...</a>)</p>
]]></description><pubDate>Tue, 05 Dec 2023 00:47:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=38525560</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=38525560</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38525560</guid></item><item><title><![CDATA[New comment by psifertex in "Dogbolt Decompiler Explorer"]]></title><description><![CDATA[
<p>Yes, lets! And before hacker summer camp when we're way way too busy! :-)</p>
]]></description><pubDate>Tue, 05 Dec 2023 00:44:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=38525541</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=38525541</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38525541</guid></item><item><title><![CDATA[New comment by psifertex in "Dogbolt Decompiler Explorer"]]></title><description><![CDATA[
<p>Binary Ninja likewise is empty and keeps up just fine as well. It's not a coincidence that the two commercial products that are funding it are both confident enough to put their stuff online like this.<p>And it's no conspiracy theory or intentional sandbagging, you can see the implementation: <a href="https://github.com/decompiler-explorer/decompiler-explorer">https://github.com/decompiler-explorer/decompiler-explorer</a><p>and if anyone can improve the other tools performance we'd be happy to accept it. We reached out to the Ghidra devs: <a href="https://github.com/NationalSecurityAgency/ghidra/issues/5228">https://github.com/NationalSecurityAgency/ghidra/issues/5228</a> but they didn't have any silver bullets for us either.</p>
]]></description><pubDate>Tue, 05 Dec 2023 00:42:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=38525518</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=38525518</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38525518</guid></item><item><title><![CDATA[New comment by psifertex in "Dogbolt Decompiler Explorer"]]></title><description><![CDATA[
<p>Yup, I'm aware of both of those, but none of those tools listed so far are intended for the IR to be for human-consumable unlike disassemblers and decompilers. You think disassembly is verbose compared to a decompiler? Go look at the equivalent Vex (Valgrind's IR) for any non-trivial disassembly. It's suuuper verbose.<p>As far as I know, BNIL (<a href="https://docs.binary.ninja/dev/bnil-overview.html" rel="nofollow noreferrer">https://docs.binary.ninja/dev/bnil-overview.html</a>) is the only one that is designed to be readable and it still wouldn't make sense to include it in an IL comparison such as the one done here for decompilation in my opinion.</p>
]]></description><pubDate>Tue, 05 Dec 2023 00:38:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=38525482</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=38525482</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38525482</guid></item><item><title><![CDATA[New comment by psifertex in "Dogbolt Decompiler Explorer"]]></title><description><![CDATA[
<p>That was indeed the logic. The two main commercial solutions included (Binary Ninja made by Vector 35, where I'm one of hte founders) and Hex-Rays both pay for all the hosting costs. And it's not particularly cheap -- there's a fair amount of compute to drive the decompilers especially as some of them are... not very efficient.</p>
]]></description><pubDate>Mon, 04 Dec 2023 19:35:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=38522001</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=38522001</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38522001</guid></item><item><title><![CDATA[New comment by psifertex in "Dogbolt Decompiler Explorer"]]></title><description><![CDATA[
<p>IRs aren't generally suited toward small snippets of examination by human when you're starting with a full binary. I would imagine something like that would only work well when done for very small bits of assembly. Likewise, you might be interested in BNIL which is an entire stack of ILs that Binary Ninja is based on. (You can see it exposed in the cloud.binary.ninja UI or the demo)</p>
]]></description><pubDate>Mon, 04 Dec 2023 19:33:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=38521976</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=38521976</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38521976</guid></item><item><title><![CDATA[New comment by psifertex in "Dogbolt Decompiler Explorer"]]></title><description><![CDATA[
<p>We know! Similarly, the GH repo is actually the Decompiler Explorer:<p><a href="https://github.com/decompiler-explorer/decompiler-explorer/">https://github.com/decompiler-explorer/decompiler-explorer/</a></p>
]]></description><pubDate>Mon, 04 Dec 2023 19:32:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=38521957</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=38521957</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38521957</guid></item><item><title><![CDATA[New comment by psifertex in "Dogbolt Decompiler Explorer"]]></title><description><![CDATA[
<p>I do remember dogpile, but as one of the folks who named it, nope, that wasn't a conscious influence!</p>
]]></description><pubDate>Mon, 04 Dec 2023 19:31:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=38521945</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=38521945</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38521945</guid></item><item><title><![CDATA[New comment by psifertex in "IDA cybersecurity software provider Hex-Rays acquired"]]></title><description><![CDATA[
<p>It's been on the dev builds enabled by default for several months now and no longer labelled beta, but we're in the middle of a release process right now so at some point soon this week the current stable will have a full debugger release (though you can try that version now if you switch to dev)</p>
]]></description><pubDate>Wed, 19 Oct 2022 16:59:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=33264926</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=33264926</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33264926</guid></item><item><title><![CDATA[New comment by psifertex in "Decompiler Explorer"]]></title><description><![CDATA[
<p>Was this due to load or server restarts or are you still seeing errors? Pass me a GUID either publicly or privately (my handle on twitter accepts DMs or an email address at my handle.com as a domain) if you don't mind and I can take a closer look.</p>
]]></description><pubDate>Sun, 17 Jul 2022 18:31:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=32129611</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=32129611</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32129611</guid></item><item><title><![CDATA[New comment by psifertex in "Decompiler Explorer"]]></title><description><![CDATA[
<p>Binary Ninja can as well (sorry for the delay, been on vacation this week) though none of the tools will download and use PDBs that might be available via public servers or otherwise by default in the configuration we're using on dogbolt. It would potentially be possible but our goal isn't to provide a test of all tools in all possible configurations as much as it is to get a good overview. Once you start tweaking each tool differently you're better off running that sort of analysis locally.</p>
]]></description><pubDate>Sun, 17 Jul 2022 18:27:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=32129558</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=32129558</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32129558</guid></item><item><title><![CDATA[New comment by psifertex in "Decompiler Explorer"]]></title><description><![CDATA[
<p>And both companies behind those licenses (hi, I'm one of them!) donated licenses to support this.<p>That said, you're right. It's unlikely we'd ship our entire binaries plus code to live in-browser though the amount wasm stuff people are doing lately is fascinating.</p>
]]></description><pubDate>Thu, 14 Jul 2022 00:29:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=32090471</link><dc:creator>psifertex</dc:creator><comments>https://news.ycombinator.com/item?id=32090471</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32090471</guid></item></channel></rss>