<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: seethishat</title><link>https://news.ycombinator.com/user?id=seethishat</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 26 Jun 2026 22:40:43 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=seethishat" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by seethishat in "What happened after 2k people tried to hack my AI assistant"]]></title><description><![CDATA[
<p>I wonder, why not use an LSM like Tomoyo, App Armor or SELinux to not allow the AI to read the secrets file? That way you could be certain that it could not be tricked into doing so.</p>
]]></description><pubDate>Fri, 26 Jun 2026 14:48:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48687307</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48687307</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48687307</guid></item><item><title><![CDATA[New comment by seethishat in "What we call "age verification" is actually mass surveillance"]]></title><description><![CDATA[
<p>My main concern is transparency. How do we know that the ruling/governing class is not abusing these monitoring systems and exempting themselves from monitoring?<p>If we are all subject to the same monitoring and there are no exceptions, that would be fair. However, if some people are exempt from monitoring because of their connections, relations, etc. then that would be unfair.<p>And if some people are allowed to harass and stalk others based on some attribute (race, religion, nationality, etc.) because they are in a monitoring position (while others are not) then that would be unfair as well.<p>We need full transparency.</p>
]]></description><pubDate>Tue, 23 Jun 2026 14:58:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48646046</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48646046</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48646046</guid></item><item><title><![CDATA[New comment by seethishat in "Humiliating IIS servers for fun and jail time"]]></title><description><![CDATA[
<p>I agree. Hiding from a grizzly bear is a good strategy. But if that fails, you will need pepper spray and maybe a shotgun.<p>Bear Defense Plan: Hide, Non-lethal, Lethal.</p>
]]></description><pubDate>Wed, 17 Jun 2026 12:39:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=48569600</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48569600</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48569600</guid></item><item><title><![CDATA[New comment by seethishat in "Never talk to the police"]]></title><description><![CDATA[
<p>It is OK to talk to them. Just don't lie and don't answer questions. Doing either could land you in jail.</p>
]]></description><pubDate>Tue, 16 Jun 2026 17:07:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48558428</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48558428</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48558428</guid></item><item><title><![CDATA[New comment by seethishat in "Windows 11 users are tired of MS account requirements creeping into everything"]]></title><description><![CDATA[
<p>It's really about personal privacy. Your computer is likely to be stolen and sold. If you don't want others reading your email, viewing your pictures, seeing your tax returns, etc. then you should encrypt the drive.<p>I call this "The Pawn Shop Threat Model" ;)<p>And, IME it is likely to happen.</p>
]]></description><pubDate>Mon, 15 Jun 2026 13:17:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48540828</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48540828</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48540828</guid></item><item><title><![CDATA[New comment by seethishat in "πFS"]]></title><description><![CDATA[
<p>That conclusion is similar to the concept of 'unconditional security' especially WRT one-time pads. The key must be at least as long as the message itself.<p>Other forms of encryption are based on assumptions and conditions being true (e.g. factoring is a hard problem, etc.) that may or may not be true. We don't know.</p>
]]></description><pubDate>Thu, 11 Jun 2026 12:02:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48489202</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48489202</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48489202</guid></item><item><title><![CDATA[New comment by seethishat in "Even light drinking raises risk of cancer, heart disease, and early death"]]></title><description><![CDATA[
<p>This is true. Everything is in a constant state of decline (including our health). Enjoy it while you can.</p>
]]></description><pubDate>Tue, 09 Jun 2026 16:46:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48463589</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48463589</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48463589</guid></item><item><title><![CDATA[New comment by seethishat in "Ultra-processed foods in the global food system: The role of tobacco companies"]]></title><description><![CDATA[
<p>My problem is it is an experiment (synthetic nicotine that is socially acceptable) and kids are addicted to it. It's like candy. No one knows or complains because the users are not generating smoke, vapor or spit. They just swallow the synthetic nicotine.<p>Yes, people have used tobacco products for a long time. However, they have not sucked on them like candy and swallowed the contents 16 hours a day. They spit, exhaled, etc. Chewing tobacco and snuff are not acceptable and they ruin your teeth/gums. Smoking is not acceptable and it ruins your lungs/breathing ability. This stuff is socially OK, because no one can tell you are using it (no spit or smoke).<p>Check out all the reports of GI issues on reddit (QuittingZyn). This stuff causes all sorts of GI issues from the top of the stomach to the bottom of the bowel.</p>
]]></description><pubDate>Fri, 05 Jun 2026 13:27:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=48412256</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48412256</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48412256</guid></item><item><title><![CDATA[New comment by seethishat in "Ultra-processed foods in the global food system: The role of tobacco companies"]]></title><description><![CDATA[
<p>The newer synthetic nicotine pouches (Zyn, On, Velo) are everywhere in the USA and are being used by kids as young as 13. They are ruining the gut health of an entire generation of kids.<p>Edit: Both boys and girls are dependent on these things now and they seem socially acceptable (no smoke, no spit, just swallow the chemical nicotine). Get ready for a huge wave of GI problems due to this.</p>
]]></description><pubDate>Fri, 05 Jun 2026 12:49:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=48411701</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48411701</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48411701</guid></item><item><title><![CDATA[New comment by seethishat in "A walking tour of surveillance infrastructure in Seattle (2020)"]]></title><description><![CDATA[
<p>Until one of them communicates a threat, then it is a criminal matter.</p>
]]></description><pubDate>Tue, 02 Jun 2026 16:03:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=48372043</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48372043</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48372043</guid></item><item><title><![CDATA[New comment by seethishat in "OpenBSD 7.9"]]></title><description><![CDATA[
<p>They did for awhile, but removed it due to complexity and security issues.</p>
]]></description><pubDate>Tue, 19 May 2026 14:37:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48193880</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48193880</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48193880</guid></item><item><title><![CDATA[New comment by seethishat in "OpenBSD 7.9"]]></title><description><![CDATA[
<p>I run it. Home firewall, office desktops and laptops. It's pretty stable and I'm fairly familiar with it. Really simple if you know Unix. I hope it never goes away, not sure what I would replace it with. Linux is so complicated now, it's just too much for me to deal with</p>
]]></description><pubDate>Tue, 19 May 2026 14:35:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48193852</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48193852</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48193852</guid></item><item><title><![CDATA[New comment by seethishat in "Mullvad exit IPs are surprisingly identifying"]]></title><description><![CDATA[
<p>I'm a long-time Mullvad user. I will continue to buy and use Mullvad VPN services (with my credit card that has my name on it) so long as it is legal to do so in my country.<p>VPNs are not 100% anonymous. They are not meant to be. Instead, they are meant to provide some level of privacy to law-abiding adults.<p>Most people would be embarrassed if their co-workers and neighbors knew the intimate personal details of their lives. Things they like, things they buy, things they do, etc. So, most people should use a VPN to protect their privacy.<p>By definition, 'most people' don't want or expect 100% anonymity online. They just want a bit of privacy in their personal life and their relationships. That's it.<p>VPNs don't protect (and are not intended to protect) criminals who want 100% anonymity from governments while committing online crimes. This is an important distinction. 'Most people' are not criminals and do not have this unrealistic expectation from Mullvad and other VPN providers.</p>
]]></description><pubDate>Fri, 15 May 2026 11:38:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48147343</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48147343</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48147343</guid></item><item><title><![CDATA[New comment by seethishat in "AI didn't delete your database, you did"]]></title><description><![CDATA[
<p>This reminds me of a James Micken's quote from "This World of Ours" in response to security people admonishing users for clicking links in email:<p><pre><code>    "It’s not clear what else there is to do with computers besides click on things..."
</code></pre>
If you have an API with exposed endpoints, it's not clear to the AI bot what else there is to do with the API besides call the endpoints.</p>
]]></description><pubDate>Tue, 05 May 2026 15:39:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48024031</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=48024031</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48024031</guid></item><item><title><![CDATA[New comment by seethishat in "US Bill Mandates On-Device Age Verification"]]></title><description><![CDATA[
<p>How many cameras do you drive past and walk by to get to the coffee shop ;)</p>
]]></description><pubDate>Fri, 17 Apr 2026 13:04:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=47805501</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=47805501</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47805501</guid></item><item><title><![CDATA[New comment by seethishat in "An AI Vibe Coding Horror Story"]]></title><description><![CDATA[
<p>I saw something very similar a few months ago. It was a web app vibe coded by a surgeon. It worked, but they did not have an index .html file in the root web directory and they would routinely zip up all of the source code which contained all the database connection strings, API credentials, AWS credentials, etc.) and place the backup in the root web directory. They would also dump the database to that folder (for backup). So web browsers that went to <a href="https://example.com/" rel="nofollow">https://example.com/</a> could see and download all the backups.<p>The quick fix was a simple, empty index.html file (or setting the -Indexes option in the apache config). The surgeon had no idea what this meant or why it was important. And the AI bots didn't either.<p>The odd part of this to me was that the AI had made good choices (strong password hashes, reasonable DB schema, etc.) and the app itself worked well. Honestly, it was impressive. But at the same time, they made some very basic deployment/security mistakes that were trivial. They just needed a bit of guidance from an experienced devops security guy to make it Internet worthy, but no one bothered to do that.<p>Edit: I do not recommend backing up web apps on the web server itself. That's another basic mistake. But they (or the AI) decided to do that and no one with experience was consulted.</p>
]]></description><pubDate>Tue, 14 Apr 2026 10:20:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=47763655</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=47763655</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47763655</guid></item><item><title><![CDATA[New comment by seethishat in "FBI used iPhone notification data to retrieve deleted Signal messages"]]></title><description><![CDATA[
<p>A lot of dumb criminals seem to carry smart phones. The irony.</p>
]]></description><pubDate>Fri, 10 Apr 2026 15:39:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=47719771</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=47719771</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47719771</guid></item><item><title><![CDATA[New comment by seethishat in "15 years, one server, 8GB RAM and 500k users – how Webminal refuses to die"]]></title><description><![CDATA[
<p>The major difference, here, is this is intended for multiple users (not one person). Imaging 5,000 users all using the device at the same time. The amount of memory, open file handles, network connections, etc. for many users at once adds up.</p>
]]></description><pubDate>Mon, 30 Mar 2026 11:48:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=47573053</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=47573053</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47573053</guid></item><item><title><![CDATA[New comment by seethishat in "Apple says no one using Lockdown Mode has been hacked with spyware"]]></title><description><![CDATA[
<p>We knew 30 years ago that message attachments (mostly email at that time) were a huge security problem. All those binary file types to parse... what could go wrong ;)<p>It's good to see Apple's Lockdown mode having such success by simply disabling message attachments.</p>
]]></description><pubDate>Fri, 27 Mar 2026 16:55:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=47545215</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=47545215</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47545215</guid></item><item><title><![CDATA[New comment by seethishat in "“Disregard That” Attacks"]]></title><description><![CDATA[
<p>If the main concern is preventing an LLM from taking some action (sending emails, text messages, adding calendar events or making phone calls), can't you just simply not allow the LLM to do that? Don't give it access.<p>It's not rocket science. If the LLM has no access to do those things, then it can't be tricked into doing those things.</p>
]]></description><pubDate>Fri, 27 Mar 2026 15:08:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=47543581</link><dc:creator>seethishat</dc:creator><comments>https://news.ycombinator.com/item?id=47543581</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47543581</guid></item></channel></rss>