<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: umanghere</title><link>https://news.ycombinator.com/user?id=umanghere</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 24 Jul 2026 04:13:34 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=umanghere" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by umanghere in "OpenAI and Hugging Face address security incident during model evaluation"]]></title><description><![CDATA[
<p>This is bizarre. I used to work in offensive security, doing a lot of vulnerability research and exploit development. Given the nature of the work and the fact that our products were subject to export controls, we used to work in an actual, airgapped environment - emphasis on the word _actual_. We had mirrors of package registries that would be synced once a day, and if a dep you wanted wasn’t mirrored, you needed to ask IT to have it mirrored.<p>We considered this just good discipline. I am sure that IT would have loved to allow just the mirror to have internet access, but it was an active decision not to let it, because it had potential to exfiltrate data out of the development network.<p>Reading this telling of the story, I can’t help but walk away with the conclusion that these frontier labs lack rigour when it comes to securing their models, especially given how much they hype up their models’ capabilities.<p>Utterly bizarre.</p>
]]></description><pubDate>Wed, 22 Jul 2026 07:52:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49003203</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=49003203</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49003203</guid></item><item><title><![CDATA[New comment by umanghere in "Bun Rust rewrite: "codebase fails basic miri checks, allows for UB in safe rust""]]></title><description><![CDATA[
<p>I completely encourage you to write this as a blog post, you’ve articulated all of the concerns I had with Go’s package management wonderfully.</p>
]]></description><pubDate>Sat, 16 May 2026 08:33:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48158126</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=48158126</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48158126</guid></item><item><title><![CDATA[New comment by umanghere in "Peer Pressure Works on AI Too"]]></title><description><![CDATA[
<p>Fascinating article, and I am surprised how well peer pressure works on LLMs.<p>Somewhat tangential though, but I find the amount of perl clutching from the AI industry about writing malware code a bit ridiculous. Most of the examples cited in the article are just a Google search away. I do not think that the LLM generating malware for you lowers the bar one bit.</p>
]]></description><pubDate>Wed, 25 Feb 2026 11:36:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=47150211</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=47150211</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47150211</guid></item><item><title><![CDATA[Peer Pressure Works on AI Too]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.robkopel.me/field-notes/peer-pressure/">https://www.robkopel.me/field-notes/peer-pressure/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47150199">https://news.ycombinator.com/item?id=47150199</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Wed, 25 Feb 2026 11:34:34 +0000</pubDate><link>https://www.robkopel.me/field-notes/peer-pressure/</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=47150199</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47150199</guid></item><item><title><![CDATA[New comment by umanghere in "Ghidra by NSA"]]></title><description><![CDATA[
<p>I started reverse engineering at 13 with an IDA Pro of questionable provenance - at that time, I found it quite difficult.<p>One thing which really helped me (and I wholeheartedly recommend) is to write simple programs, run them through the compiler and then in the disassembler. It really helps build a correspondence between program structure and its object code.<p>Eventually, you can make it even more fun and challenging by stripping debug symbols and turning on compiler optimisations.<p>Happy reversing!</p>
]]></description><pubDate>Mon, 16 Feb 2026 22:00:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=47040906</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=47040906</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47040906</guid></item><item><title><![CDATA[New comment by umanghere in "Ask HN: Share your personal website"]]></title><description><![CDATA[
<p><a href="https://umangis.me" rel="nofollow">https://umangis.me</a>
Not a lot of content, but enough to be of some interest to a few niches.</p>
]]></description><pubDate>Wed, 14 Jan 2026 23:01:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=46625214</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=46625214</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46625214</guid></item><item><title><![CDATA[New comment by umanghere in "The six dumbest ideas in computer security (2005)"]]></title><description><![CDATA[
<p>> 4) Hacking is Cool<p>Pardon my French, but this is the dumbest thing I have read all week. You simply <i>cannot</i> work on defensive techniques without understanding offensive techniques - plainly put, good luck developing exploit mitigations without having ever written or understood an exploit yourself. That’s how you get a slew of mitigations and security strategy that have questionable, if not negative value.</p>
]]></description><pubDate>Sun, 14 Jul 2024 10:46:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=40960132</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=40960132</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40960132</guid></item><item><title><![CDATA[New comment by umanghere in "X plans to collect biometric data, job and school history"]]></title><description><![CDATA[
<p>I don’t mean to sound argumentative, but that’s a knee jerk response.<p>It’s possible to reverse engineer the OS code to verify that the biometrics indeed end up on the SEP’s encrypted storage, and several people have done this in the past.<p>Here’s an excellent presentation on the SEP, found by just a simple Google search. [0]<p>[0]: <a href="https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-Demystifying-The-Secure-Enclave-Processor.pdf" rel="nofollow noreferrer">https://www.blackhat.com/docs/us-16/materials/us-16-Mandt-De...</a></p>
]]></description><pubDate>Thu, 31 Aug 2023 16:44:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=37340023</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=37340023</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37340023</guid></item><item><title><![CDATA[New comment by umanghere in "Open Source distributions for macOS 13.5"]]></title><description><![CDATA[
<p>In my opinion, a better submission title would be: Open Source distributions for macOS 13.5 have been released.<p>The current title is a bit misleading, because several parts of macOS, including those covered partially by the OSS releases, are proprietary.</p>
]]></description><pubDate>Wed, 16 Aug 2023 20:42:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=37153506</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=37153506</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37153506</guid></item><item><title><![CDATA[New comment by umanghere in "Record whistleblower award went to a tipster on Ericsson"]]></title><description><![CDATA[
<p><a href="https://archive.is/Kxdeh" rel="nofollow">https://archive.is/Kxdeh</a></p>
]]></description><pubDate>Fri, 26 May 2023 07:29:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=36081144</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=36081144</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36081144</guid></item><item><title><![CDATA[New comment by umanghere in "OpenAI Sued for Fraud Allegations"]]></title><description><![CDATA[
<p>It took forever to get the document off SFTC’s website, so I mirrored it behind CloudFront for everyone’s convenience.<p><a href="https://blog.umangis.me/static/08539708.pdf" rel="nofollow">https://blog.umangis.me/static/08539708.pdf</a></p>
]]></description><pubDate>Sun, 07 May 2023 15:53:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=35852714</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=35852714</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35852714</guid></item><item><title><![CDATA[A first look at Rust in the 6.1 kernel]]></title><description><![CDATA[
<p>Article URL: <a href="https://lwn.net/SubscriberLink/910762/a26f968ea086e32d/">https://lwn.net/SubscriberLink/910762/a26f968ea086e32d/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=33191171">https://news.ycombinator.com/item?id=33191171</a></p>
<p>Points: 6</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 13 Oct 2022 14:08:56 +0000</pubDate><link>https://lwn.net/SubscriberLink/910762/a26f968ea086e32d/</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=33191171</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33191171</guid></item><item><title><![CDATA[SQLite: Wal2 Mode Notes]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.sqlite.org/cgi/src/doc/wal2/doc/wal2.md">https://www.sqlite.org/cgi/src/doc/wal2/doc/wal2.md</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=32435601">https://news.ycombinator.com/item?id=32435601</a></p>
<p>Points: 63</p>
<p># Comments: 15</p>
]]></description><pubDate>Fri, 12 Aug 2022 07:40:24 +0000</pubDate><link>https://www.sqlite.org/cgi/src/doc/wal2/doc/wal2.md</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=32435601</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32435601</guid></item><item><title><![CDATA[New comment by umanghere in "Hardware-accelerated Linux virtual machines on jailbroken iPhone 12 / iOS 14.1"]]></title><description><![CDATA[
<p>Unfortunately it can’t be done even if you target an M1 iPad — virtualization is locked behind an entitlement that’s not publicly available on iOS.</p>
]]></description><pubDate>Tue, 07 Jun 2022 08:08:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=31651186</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=31651186</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31651186</guid></item><item><title><![CDATA[New comment by umanghere in "Booting a Mac Studio from an external SSD, and what it doesn’t solve"]]></title><description><![CDATA[
<p>Just allowing kexts to be loaded should not increase the attack surface or expose the author to any currently known exploits. The reason that people avoid doing it anyways is because third party kexts have a history of obvious vulnerabilities and don't receive the same amount of eyeballs that first party kernel extensions do.<p>As you put it, it really is a desire for maximum security at play here.</p>
]]></description><pubDate>Thu, 21 Apr 2022 12:40:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=31108626</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=31108626</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31108626</guid></item><item><title><![CDATA[New comment by umanghere in "Apple unveils contactless payments via Tap to Pay on iPhone"]]></title><description><![CDATA[
<p>There are publicly available SecureROM dumps online, see <a href="http://securerom.fun" rel="nofollow">http://securerom.fun</a><p>The author(s) maintain the site out of personal interest.</p>
]]></description><pubDate>Tue, 08 Feb 2022 20:05:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=30263837</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=30263837</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30263837</guid></item><item><title><![CDATA[New comment by umanghere in "How PCI-Express works (2020)"]]></title><description><![CDATA[
<p>__padding replied to you, but unfortunately their comment is dead because of their account being new, so I’ve reposted it as I cannot vouch yet.<p>> __padding 45 minutes ago [dead] [–]<p>> Typically with devices like network cards (that also operate over PCI-E)
You send the device a circular list of descriptors (pointers) to a region of main memory.
In order to send data to the device, you write your network packet to the memory region associated with the pointer of the current ‘head’ of the descriptor list.
So far, you have a ring of pointers, one of those pointers points to a location you just wrote to in ram.
You then tell the device that the head of the list has changed (as you just wrote some data to the region that the head of the list is pointing to - so it can consume that pointer), the device then goes ahead and copies the data from ram into an internal buffer on the card. Once the data is consumed, the tail pointer of the ring buffer is updated to indicate that the card is finished with that memory region.</p>
]]></description><pubDate>Sat, 11 Sep 2021 13:01:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=28491642</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=28491642</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28491642</guid></item><item><title><![CDATA[New comment by umanghere in "M1racles: An Apple M1 covert channel vulnerability"]]></title><description><![CDATA[
<p>iPhones do not use the A1 chip as of quite a few years ago. Besides, the M1 and the A12+ have significant microarchitectural similarities, to the point that the DTK used the A12Z.<p>Furthermore, the keyboard app extension and the keyboard app are installed as a single package whose components are not supposed to communicate, hence why I brought this up.</p>
]]></description><pubDate>Wed, 26 May 2021 08:54:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=27287991</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=27287991</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27287991</guid></item><item><title><![CDATA[New comment by umanghere in "M1racles: An Apple M1 covert channel vulnerability"]]></title><description><![CDATA[
<p>While Marcan has written in a very entertaining fashion, there is perhaps one application of this vulnerability that wasn't considered.<p>If this can be reproduced on the iPhone, it can lead to 3rd party keyboards exfiltrating data. By default, keyboard app extensions are sandboxed away from their owning applications [0], but they may communicate with the app over this channel and leak data. It's not as easy as I describe because the app would have to be alive and scheduled on the same cluster, but it's within the realm of possibility.<p>[0]: <a href="https://developer.apple.com/library/archive/documentation/General/Conceptual/ExtensibilityPG/CustomKeyboard.html" rel="nofollow">https://developer.apple.com/library/archive/documentation/Ge...</a></p>
]]></description><pubDate>Wed, 26 May 2021 08:01:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=27287683</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=27287683</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27287683</guid></item><item><title><![CDATA[On Security Research Devices]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.umangis.me/on-security-research-devices/">https://blog.umangis.me/on-security-research-devices/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=26088448">https://news.ycombinator.com/item?id=26088448</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 10 Feb 2021 12:53:38 +0000</pubDate><link>https://blog.umangis.me/on-security-research-devices/</link><dc:creator>umanghere</dc:creator><comments>https://news.ycombinator.com/item?id=26088448</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26088448</guid></item></channel></rss>