<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: tryauuum</title><link>https://news.ycombinator.com/user?id=tryauuum</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 29 Jul 2026 02:17:51 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=tryauuum" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by tryauuum in "Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages"]]></title><description><![CDATA[
<p>no, I mean the attacker boots his own copy of Windows or Ubuntu, which is supposedly trusted by the UEFI keys. Will tpm somehow detect that it shouldn't unlock secrets for this boot?</p>
]]></description><pubDate>Tue, 28 Jul 2026 21:35:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=49090240</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=49090240</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49090240</guid></item><item><title><![CDATA[New comment by tryauuum in "Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages"]]></title><description><![CDATA[
<p>It all weird still<p>Suppose the physical attacker doesn't reset the bios. He boots Ubuntu or any other os which is signed. Will the tpm unlock and give out the key? I guess it depends on the setup and it's possible to unlock only on your own signed kernel but I doubt this is a default?</p>
]]></description><pubDate>Tue, 28 Jul 2026 21:12:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=49089967</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=49089967</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49089967</guid></item><item><title><![CDATA[New comment by tryauuum in "Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages"]]></title><description><![CDATA[
<p>holy hell! snap-based kernel<p>can someone explain like I'm 5, what's the point of during storing disk encryption keys in TPM? What kind of attack or attacker do we protect from?<p>my logic is following: 
- if the attacker is remote and somehow modifies my kernel... Yes, the tpm and hardware attestation (is this the term?) would have saved me. But I'm fucked anyway since the attacker already has root on my computer<p>- if the attacker is local -- yes, with tpm they cannot steal just the hard drive and bruteforce it offline. But they can just reset bios and install their own os and trick me into typing the os passwords? Or even if they cannot trick me (hard to spoof my os UI) they can just install a physical keylogger?</p>
]]></description><pubDate>Tue, 28 Jul 2026 18:07:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=49087701</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=49087701</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49087701</guid></item><item><title><![CDATA[New comment by tryauuum in "Half a Second – a book about the XZ backdoor"]]></title><description><![CDATA[
<p>So Microsoft did something good? I thought they are too busy keeping my personal data in a prison and writing tight bash loops wasting 100 percent of a core</p>
]]></description><pubDate>Sun, 19 Jul 2026 11:30:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48967119</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48967119</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48967119</guid></item><item><title><![CDATA[New comment by tryauuum in "Mysteries of Telegram Data Centers (2022)"]]></title><description><![CDATA[
<p>I've never had a twitter account so all these people hating durov for his exile marketing look weird to me. I'm not disagreeing with what you say but it's like a whole another subsection of world opened to me</p>
]]></description><pubDate>Thu, 16 Jul 2026 19:12:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=48938914</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48938914</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48938914</guid></item><item><title><![CDATA[New comment by tryauuum in "Mysteries of Telegram Data Centers (2022)"]]></title><description><![CDATA[
<p>> You people are just racist towards Russians and need help.<p>>> That doesn’t exclude the statements about Telegram to be correct though.<p>just attack the telegram from the technical standpoint, then no complains about "racist towards russians" will be given. Like, mentioning the lack of user-friendly E2EE is great already. Saying things like "Durov who supposedly lives in exile has visited Russia over 50 times" is meh. How can one intepret it in any other way is "Russia is evil and visiting Russia is thus evil"?<p>and regarding the cracking contests — one of the telegram bugs was actually uncovered this way, see <a href="https://habr.com/ru/articles/206900/" rel="nofollow">https://habr.com/ru/articles/206900/</a></p>
]]></description><pubDate>Wed, 15 Jul 2026 19:38:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48926035</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48926035</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48926035</guid></item><item><title><![CDATA[New comment by tryauuum in "TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access"]]></title><description><![CDATA[
<p>that's stupid. getent passwd will fetch the user list from the network depending on setup. Have fun fetching 40000 records from the network every call</p>
]]></description><pubDate>Wed, 15 Jul 2026 11:07:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=48919045</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48919045</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48919045</guid></item><item><title><![CDATA[New comment by tryauuum in "EU Parliament greenlights Chat Control 1.0"]]></title><description><![CDATA[
<p>come on guys, stop upvoting me and answer the question please</p>
]]></description><pubDate>Fri, 10 Jul 2026 13:14:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48859475</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48859475</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48859475</guid></item><item><title><![CDATA[New comment by tryauuum in "We won $92,337 bug bounty using a single kernel 0-day"]]></title><description><![CDATA[
<p>whoa, didn't expect a wall of text<p>When I said about "no mitigations except for the kernel updates" I meant exactly that. Some sysctl config to flip, some kernel module to unload. Apparently such thing doesn't exist in this one</p>
]]></description><pubDate>Thu, 09 Jul 2026 22:36:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48853315</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48853315</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48853315</guid></item><item><title><![CDATA[New comment by tryauuum in "EU Parliament greenlights Chat Control 1.0"]]></title><description><![CDATA[
<p>Today they already analyze the SSL handshake and traffic patterns in Russia. And if your valid https traffic crosses the border but doesn't behave like https (I don't know how they do it. Frequency of TCP packets and their size and the delay between?) your IP-address will be blocked<p>I want to stress that I'm speaking from experience. I personally installed a telegram proxy project which aimed to mirror the pattern of traffic and fool the censors</p>
]]></description><pubDate>Thu, 09 Jul 2026 20:54:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48852226</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48852226</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48852226</guid></item><item><title><![CDATA[New comment by tryauuum in "EU Parliament greenlights Chat Control 1.0"]]></title><description><![CDATA[
<p>> new technology that is designed to balance interests on all sides and actually enforce the guarantees IN CODE AND PROTOCOLS.<p>They will just call your code illegal in law. And if you will run it anyway, use deep packet inspection to drop your protocol packets, like they do in Russia</p>
]]></description><pubDate>Thu, 09 Jul 2026 18:26:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48850365</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48850365</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48850365</guid></item><item><title><![CDATA[New comment by tryauuum in "EU Parliament greenlights Chat Control 1.0"]]></title><description><![CDATA[
<p>That's cool and all but looks like we are running out of good countries<p>And if they all have censorship, they are not failing (when comparing them to each other)</p>
]]></description><pubDate>Thu, 09 Jul 2026 18:23:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48850317</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48850317</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48850317</guid></item><item><title><![CDATA[New comment by tryauuum in "EU Parliament greenlights Chat Control 1.0"]]></title><description><![CDATA[
<p>It's hard to compare US and EU internet freedom because a person usually spends most of their life in one place and is clueless about the life in other.<p>I've never lived in US, were there any cases of ISPs blocking websites in USA? Even DNS-level blocking counts</p>
]]></description><pubDate>Thu, 09 Jul 2026 18:17:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48850246</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48850246</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48850246</guid></item><item><title><![CDATA[New comment by tryauuum in "We won $92,337 bug bounty using a single kernel 0-day"]]></title><description><![CDATA[
<p>it's all so tiresome<p>so no mitigation except for kernel updates?</p>
]]></description><pubDate>Wed, 08 Jul 2026 12:12:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=48830908</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48830908</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48830908</guid></item><item><title><![CDATA[New comment by tryauuum in "Januscape: Guest-to-Host Escape in KVM/x86 [CVE-2026-53359]"]]></title><description><![CDATA[
<p>how dangerous is the vulnerability in practice? How hard is to actually achieve the KVM escape?</p>
]]></description><pubDate>Tue, 07 Jul 2026 12:59:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48817136</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48817136</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48817136</guid></item><item><title><![CDATA[New comment by tryauuum in "Januscape: Guest-to-Host Escape in KVM/x86 [CVE-2026-53359]"]]></title><description><![CDATA[
<p>Not all device files, only /dev/kvm. I assume the logic was "with /dev/kvm access the user can ...allocate memory and execute code, which they already can, so why not allow it?". Could also make rootless isolation easier</p>
]]></description><pubDate>Mon, 06 Jul 2026 21:13:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48810590</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48810590</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48810590</guid></item><item><title><![CDATA[New comment by tryauuum in "Ask HN: Who is quitting? (July 2026)"]]></title><description><![CDATA[
<p>"lock-in factor"?</p>
]]></description><pubDate>Thu, 02 Jul 2026 16:07:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=48763585</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48763585</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48763585</guid></item><item><title><![CDATA[New comment by tryauuum in "Xsnow "protestware" in Debian"]]></title><description><![CDATA[
<p>> don't, like, invade their country<p>I did not invade any country<p>At least this app just displays the flags and not prints such accusations</p>
]]></description><pubDate>Tue, 30 Jun 2026 18:59:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48737621</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48737621</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48737621</guid></item><item><title><![CDATA[New comment by tryauuum in "A native graphical shell for SSH"]]></title><description><![CDATA[
<p>this touches two pieces of my knowledge:<p><pre><code>    - microsoft is evil, I cannot delete my github account, will never use anything by this company
    - if the attacker knows your *public* key they can enumerate the list of the servers you have access to https://github.com/benjojo/ssh-key-confirmer</code></pre></p>
]]></description><pubDate>Tue, 30 Jun 2026 13:12:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=48732295</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48732295</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48732295</guid></item><item><title><![CDATA[New comment by tryauuum in "A native graphical shell for SSH"]]></title><description><![CDATA[
<p>wonder if anyone tried X over infiniband, latency would be so great</p>
]]></description><pubDate>Tue, 30 Jun 2026 13:07:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48732223</link><dc:creator>tryauuum</dc:creator><comments>https://news.ycombinator.com/item?id=48732223</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48732223</guid></item></channel></rss>