<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: vengefulduck</title><link>https://news.ycombinator.com/user?id=vengefulduck</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 17 Apr 2026 03:35:57 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=vengefulduck" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by vengefulduck in "Egg prices are soaring. Are backyard chickens the answer?"]]></title><description><![CDATA[
<p>I think the problem with this argument is the assumption that nature is inherently good. Nature is cruel and uncaring. Moving beyond it is a good thing imo. We’re just lucky that as a species by the roll of the dice we were given the power by nature to usurp it.</p>
]]></description><pubDate>Thu, 20 Feb 2025 16:14:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=43116490</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=43116490</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43116490</guid></item><item><title><![CDATA[New comment by vengefulduck in "Even Microsoft Notepad is getting AI text editing now"]]></title><description><![CDATA[
<p>Have you used VLC on MacOS tho? Full screen video looks very slick and is tough to differentiate from native quicktime other than having support for more codecs and features.<p>The non full screen UI is a little more crusty but still looks better than the windows version imo.</p>
]]></description><pubDate>Thu, 07 Nov 2024 20:25:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=42080563</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=42080563</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42080563</guid></item><item><title><![CDATA[New comment by vengefulduck in "What is an SBAT and why does everyone suddenly care"]]></title><description><![CDATA[
<p>Browsers enforce that certificates are signed by two independent CT logs. The public keys of which is shipped by the browser. So a MITM would need to compromise a trusted CA and two CT logs to be able to pull off an attack undetected. Maybe not impossible but much more difficult than just a single CA compromise.</p>
]]></description><pubDate>Thu, 22 Aug 2024 15:09:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=41321172</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=41321172</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41321172</guid></item><item><title><![CDATA[New comment by vengefulduck in "Dutch Students Delay Graduation Due to Housing Shortages"]]></title><description><![CDATA[
<p>Assuming that living with your parents is a safe option which for many, especially LGBT people it isn’t.</p>
]]></description><pubDate>Thu, 02 May 2024 21:10:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=40241404</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=40241404</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40241404</guid></item><item><title><![CDATA[New comment by vengefulduck in "Tesla recalls all cybertrucks for faulty accelerator pedals"]]></title><description><![CDATA[
<p>Of course, this is the only explanation. No one can just make stuff up on the internet. That’s impossible.</p>
]]></description><pubDate>Fri, 19 Apr 2024 17:39:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=40089766</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=40089766</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40089766</guid></item><item><title><![CDATA[New comment by vengefulduck in "Opera becomes the first major browser with built-in access to local AI models"]]></title><description><![CDATA[
<p>Browsers are just mini OSs at this point. It’s probably best just to accept it. Honestly in some respects (security, isolation, resource management) they do a better job than the operating system they run on top of.</p>
]]></description><pubDate>Wed, 03 Apr 2024 17:32:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=39920426</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=39920426</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39920426</guid></item><item><title><![CDATA[New comment by vengefulduck in "Cracking Meta's Messenger Certificate Pinning on macOS"]]></title><description><![CDATA[
<p>Even as a user I don’t there’s a good reason to love cert pinning. If you’re going up against adversaries that can compromise web pki they also probably have some other exploits up their sleeve to pwn you.<p>Cert pinning pretty much serves to protect companies from people reversing their protocols and little else imo.</p>
]]></description><pubDate>Wed, 06 Mar 2024 01:55:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=39611376</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=39611376</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39611376</guid></item><item><title><![CDATA[New comment by vengefulduck in "Blocking Visual Studio Code embedded reverse shell before it's too late"]]></title><description><![CDATA[
<p>Write access to .bashrc is plenty to very sneakily get sudo access tho.<p><pre><code>  alias sudo='./.my-evil-sudo-binary'
</code></pre>
And wait till the next time the user authenticates, they wont see anything amiss and you just silently delete the alias after you’ve got the sudo password.<p>Also even without root dumping .ssh and the browser’s cookie jar is probably plenty to achieve lateral movement and you don’t need root for that.</p>
]]></description><pubDate>Sat, 23 Sep 2023 18:57:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=37626274</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=37626274</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37626274</guid></item><item><title><![CDATA[New comment by vengefulduck in "Linux has achieved a 3% desktop market share"]]></title><description><![CDATA[
<p>Installable web apps would give you a workaround for that wouldn’t it?</p>
]]></description><pubDate>Wed, 12 Jul 2023 01:24:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=36689382</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=36689382</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36689382</guid></item><item><title><![CDATA[New comment by vengefulduck in "Microsoft is testing a built-in cryptocurrency wallet for the Edge web browser"]]></title><description><![CDATA[
<p>Hahahahaha. Yeah, sure cryptocurrency never comes crashing down.  It certainly would never lose 60% of its value in 6 months. That would never happen. What a perfect store of value. /s</p>
]]></description><pubDate>Sun, 19 Mar 2023 14:59:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=35219625</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=35219625</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35219625</guid></item><item><title><![CDATA[New comment by vengefulduck in "Password protect a static HTML page"]]></title><description><![CDATA[
<p>The math used in AES (Rijndael) utilize operations in GF(2^8) tho, so you're doing operations using Galois fields whether your utilizing GCM or CBC. I don't really see how adding the GCM mode utilizing GF(2^128) on top is significantly more difficult or error prone than implementing the AES block cipher itself. You should still be familiar with operations over Galois fields regardless if you've for some reason (foolishly imo) decided you want to implement AES cryptographic primitives on your own.<p>Regardless there's no good reason not to use a vetted open source implementation instead, preferably with an even higher level of abstraction so your not having to worry about ciphers or modes of operation at all[1].<p>[1] <a href="https://doc.libsodium.org/secret-key_cryptography/secretbox" rel="nofollow">https://doc.libsodium.org/secret-key_cryptography/secretbox</a></p>
]]></description><pubDate>Sun, 19 Feb 2023 06:16:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=34855001</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=34855001</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34855001</guid></item><item><title><![CDATA[New comment by vengefulduck in "Blink virtual machine now supports running GUI programs"]]></title><description><![CDATA[
<p>The fact that any Xorg client can become a key logger without any user input or authentication is a pretty big security hole imo.<p>By design Xorg has no isolation between clients so they can all read each others input, control others windows, and inject keystrokes into other applications. That’s unacceptable in the modern age and makes any attempt at sandboxing or separation of privileges for GUI applications completely pointless.</p>
]]></description><pubDate>Fri, 03 Feb 2023 16:38:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=34643502</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=34643502</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34643502</guid></item><item><title><![CDATA[New comment by vengefulduck in "Hard truths I learned when I got laid off from my SWE job"]]></title><description><![CDATA[
<p>Even when applying to companies that are LGBTQ friendly? I sometimes self identify on applications if the company has a good reputation with that kind of thing because I’d expect It would give me some diversity points. But maybe that’s not the best idea.</p>
]]></description><pubDate>Wed, 28 Dec 2022 19:26:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=34164773</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=34164773</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34164773</guid></item><item><title><![CDATA[New comment by vengefulduck in "Convergent Encryption and Why No One Uses It (2020)"]]></title><description><![CDATA[
<p>I submitted this in light of the recent iCloud end to end encryption announcement which seems to indicate they're using Convergent Encryption here:<p><a href="https://support.apple.com/en-ca/guide/security/sec973254c5f/web#:~:text=convergent%20encryption" rel="nofollow">https://support.apple.com/en-ca/guide/security/sec973254c5f/...</a></p>
]]></description><pubDate>Wed, 07 Dec 2022 20:57:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=33900118</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=33900118</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33900118</guid></item><item><title><![CDATA[Convergent Encryption and Why No One Uses It (2020)]]></title><description><![CDATA[
<p>Article URL: <a href="https://smarx.com/posts/2020/09/convergent-encryption-and-why-no-one-uses-it/">https://smarx.com/posts/2020/09/convergent-encryption-and-why-no-one-uses-it/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=33900098">https://news.ycombinator.com/item?id=33900098</a></p>
<p>Points: 11</p>
<p># Comments: 3</p>
]]></description><pubDate>Wed, 07 Dec 2022 20:55:52 +0000</pubDate><link>https://smarx.com/posts/2020/09/convergent-encryption-and-why-no-one-uses-it/</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=33900098</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33900098</guid></item><item><title><![CDATA[New comment by vengefulduck in "Apple introduces end-to-end encryption for backups"]]></title><description><![CDATA[
<p>Looking into the details it seems like they're using Convergent Encryption [1][2] in order to enable deduplication in iCloud drive and photos. Which would imply it is possible for an attacker to determine if your account is storing a file for which they know the plaintext. It's still a lot better than the status quo but that's a pretty big asterisk in my mind.<p>[1]<a href="https://support.apple.com/en-ca/guide/security/sec973254c5f/web#:~:text=convergent%20encryption" rel="nofollow">https://support.apple.com/en-ca/guide/security/sec973254c5f/...</a><p>[2] <a href="https://smarx.com/posts/2020/09/convergent-encryption-and-why-no-one-uses-it/" rel="nofollow">https://smarx.com/posts/2020/09/convergent-encryption-and-wh...</a></p>
]]></description><pubDate>Wed, 07 Dec 2022 20:53:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=33900077</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=33900077</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33900077</guid></item><item><title><![CDATA[New comment by vengefulduck in "Tumblr to Add Support for ActivityPub"]]></title><description><![CDATA[
<p>Your kidding right? Anything IO bound like an server isn’t going to be remotely affected by the speed of underlying language. There’s almost no compute required for a mastodon server just take HTTP requests and store and retrieve data from a database. The CPU is going to be active for a fraction of a millisecond before it becomes blocked on either the database or network.</p>
]]></description><pubDate>Fri, 25 Nov 2022 00:38:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=33737765</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=33737765</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33737765</guid></item><item><title><![CDATA[New comment by vengefulduck in "Bouncer – Private SMS Blocker"]]></title><description><![CDATA[
<p>I’m not so sure that’s true reading through the privacy notice when enabling SMS filtering it reads “You can install and use third-party SMS filters. If you do, the filter provider can access <i>all of the text and content included in incoming SMS and MMS messages</i> that you receive from unknown senders.”<p>That doesn’t sound like the same thing as the content blocker api it sounds like it provides plaintext access to sms messages. And it’s enough of a risk that I decided not to install it.</p>
]]></description><pubDate>Sat, 10 Sep 2022 15:03:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=32791245</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=32791245</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32791245</guid></item><item><title><![CDATA[New comment by vengefulduck in "Post-quantum encryption contender is taken out by single-core PC and 1 hour"]]></title><description><![CDATA[
<p>I don’t think you need to be from the west coast to understand people saying SIKE. It’s a pretty common phrase across the US. I’m from Colorado and I heard that a fair amount growing up. Agree on the appropriate name though it was my first thought  reading that it had been broken.</p>
]]></description><pubDate>Wed, 03 Aug 2022 15:37:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=32333174</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=32333174</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32333174</guid></item><item><title><![CDATA[New comment by vengefulduck in "Ask HN: Why do you use a VPN?"]]></title><description><![CDATA[
<p>They can usually still see Domain names. DNS traffic is normally sent in the clear and in the event it’s not the SNI field in TLS (https) is unencrypted. So your ISP can know which domains you visit but not the individual sites on those domains you visit. (i.e they would know you visited google.com but not  that you requested the page: google.com/q=your+question) Which depending on the site might not be all that sensitive but I’m sure you can think of a few examples of sites you wouldn’t want anyone to knowing you went to even if they couldn’t see which page.</p>
]]></description><pubDate>Wed, 06 Jul 2022 04:35:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=31996762</link><dc:creator>vengefulduck</dc:creator><comments>https://news.ycombinator.com/item?id=31996762</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31996762</guid></item></channel></rss>