<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: x1sec</title><link>https://news.ycombinator.com/user?id=x1sec</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 23 Apr 2026 16:51:57 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=x1sec" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by x1sec in "A woman who can smell Parkinson's is inspiring research into diagnosis (2020)"]]></title><description><![CDATA[
<p>Could you describe the smell?</p>
]]></description><pubDate>Wed, 14 Feb 2024 02:51:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=39365808</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=39365808</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39365808</guid></item><item><title><![CDATA[New comment by x1sec in "Autorize – Authorization enforcement detection extension for Burp Suite"]]></title><description><![CDATA[
<p>By "extensibility" does this mean the ability to write your own extensions? Being able to develop and contribute plugins back to the community (similar to Burp's BApp store) could really accelerate the competitiveness of Caido up against Burp.</p>
]]></description><pubDate>Sat, 30 Dec 2023 02:00:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=38812254</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38812254</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38812254</guid></item><item><title><![CDATA[New comment by x1sec in "Autorize – Authorization enforcement detection extension for Burp Suite"]]></title><description><![CDATA[
<p>Caido[1] a interception proxy written in Rust, is positioning itself as a "lightweight" alternative to Burp. It can't compete yet with Burp in terms of functionality, although the product is certainly looking promising.<p>Perhaps the only contender to Burp in respect to functionality/features is ZAP[2].<p>EDIT: You can run your own collaborator type setup with Project discovery's interactsh[3].<p>Further EDIT: A downvote might be because of the mention of Rust / closed source - this is explicitly mentioned because a large pain point for Burp is it's a Java memory hog. If Caido was written in C++ with Qt, this fact would be notable for the exact same reason.<p>[1] <a href="https://caido.io/" rel="nofollow">https://caido.io/</a><p>[2] <a href="https://www.zaproxy.org/" rel="nofollow">https://www.zaproxy.org/</a><p>[3] <a href="https://github.com/projectdiscovery/interactsh">https://github.com/projectdiscovery/interactsh</a></p>
]]></description><pubDate>Fri, 29 Dec 2023 12:00:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=38804064</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38804064</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38804064</guid></item><item><title><![CDATA[New comment by x1sec in "Autorize – Authorization enforcement detection extension for Burp Suite"]]></title><description><![CDATA[
<p>This is not a new plugin; it (and similar extensions) have been available for Burp and a staple for testers for a few years now.<p>Automating authorisation checks has less to do with novelty seeking and more to do with the practicalities of ensuring adequate coverage within the assigned engagement time frame.</p>
]]></description><pubDate>Fri, 29 Dec 2023 06:43:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=38802330</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38802330</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38802330</guid></item><item><title><![CDATA[New comment by x1sec in "You've just been fucked by psyops [video]"]]></title><description><![CDATA[
<p>In the Q&A section, the speaker remarks:<p>"There is a part of the talk where I am trying to perform a little bit.. the thing that I'm also talking about. My background is in art .. and we always try to think about form and content being kind of the same thing.."<p>Thoroughly entertaining, well executed.</p>
]]></description><pubDate>Thu, 28 Dec 2023 13:09:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=38793106</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38793106</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38793106</guid></item><item><title><![CDATA[New comment by x1sec in "Operation Triangulation: What you get when attack iPhones of researchers"]]></title><description><![CDATA[
<p>Perhaps a physical switch that connects or disconnects the electrical signal from the microphone to the handset could be a more convenient approach.<p>There is a photo of Mark Zuckerberg with a cut off 3.5mm jack plugged into his laptop - likely to achieve a similar outcome.</p>
]]></description><pubDate>Thu, 28 Dec 2023 04:34:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=38790078</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38790078</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38790078</guid></item><item><title><![CDATA[New comment by x1sec in "Operation Triangulation: What you get when attack iPhones of researchers"]]></title><description><![CDATA[
<p>How frequent?</p>
]]></description><pubDate>Thu, 28 Dec 2023 02:01:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=38789128</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38789128</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38789128</guid></item><item><title><![CDATA[New comment by x1sec in "Operation Triangulation: What you get when attack iPhones of researchers"]]></title><description><![CDATA[
<p>In a week, a lot of data can be exfiltrated. Then after you have rebooted, the threat actor reinfects your device.<p>Frequently rebooting the device can’t hurt but it likely isn’t going to prevent a threat actor from achieving their objectives.<p>The best mitigation we have is to enable lockdown mode.</p>
]]></description><pubDate>Wed, 27 Dec 2023 22:57:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=38787904</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38787904</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38787904</guid></item><item><title><![CDATA[New comment by x1sec in "Let's Build a Compiler (1988)"]]></title><description><![CDATA[
<p>A port of the tutorial's Pascal code to C which emits x86 assembly:<p><a href="https://github.com/lotabout/Let-s-build-a-compiler">https://github.com/lotabout/Let-s-build-a-compiler</a></p>
]]></description><pubDate>Tue, 26 Dec 2023 23:19:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=38777144</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38777144</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38777144</guid></item><item><title><![CDATA[New comment by x1sec in "x86-64 Assembly Language Programming with Ubuntu (2022)"]]></title><description><![CDATA[
<p>> Of course it is quite common to need to read it<p>This is a notable differentiation - Writing assembly is a different skill to reading it from a disassembly. Reverse engineering, malware analysis etc. does not inherently require you to be able to write asm, although it certainly would help.</p>
]]></description><pubDate>Mon, 25 Dec 2023 03:12:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=38759324</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38759324</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38759324</guid></item><item><title><![CDATA[New comment by x1sec in "Apple allows some iOS apps to track user locations via lists of nearby SSIDs"]]></title><description><![CDATA[
<p>SSID / BSSID is often enough to pinpoint the location. Recently someone debated this with me, so I asked him what his wifi AP name was, then proceeded to provide their home address.<p>How? By searching it in <a href="https://wigle.net" rel="nofollow noreferrer">https://wigle.net</a>.<p>That ended the debate quite swiftly.</p>
]]></description><pubDate>Thu, 21 Dec 2023 19:04:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=38725149</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38725149</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38725149</guid></item><item><title><![CDATA[New comment by x1sec in "Ask HN: A Bash guide for Posix shell programmers?"]]></title><description><![CDATA[
<p>Recently having stumbled across the VSCode shellcheck plugin[1] - it's been particularly educational as it provides not only corrections but improvement tips. For example the common practice of:<p>if [ $? -ne 0 ]; then<p>Will get flagged and an improvement will be suggested with an explanation on why [2]<p>[1] <a href="https://marketplace.visualstudio.com/items?itemName=timonwong.shellcheck" rel="nofollow noreferrer">https://marketplace.visualstudio.com/items?itemName=timonwon...</a><p>[2] <a href="https://www.shellcheck.net/wiki/SC2181" rel="nofollow noreferrer">https://www.shellcheck.net/wiki/SC2181</a></p>
]]></description><pubDate>Mon, 18 Dec 2023 09:15:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=38680571</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38680571</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38680571</guid></item><item><title><![CDATA[New comment by x1sec in "Ask HN: How to figure out a good direction/goals for the year ahead?"]]></title><description><![CDATA[
<p>Cal Newport, the author of 'Deep Work'[1] releases frequent content on Youtube [2] that attempts to address the kind of challenges expressed by the author.<p>[1] <a href="https://www.goodreads.com/en/book/show/25744928" rel="nofollow noreferrer">https://www.goodreads.com/en/book/show/25744928</a><p>[2] <a href="https://www.youtube.com/@CalNewportMedia" rel="nofollow noreferrer">https://www.youtube.com/@CalNewportMedia</a></p>
]]></description><pubDate>Sun, 17 Dec 2023 20:22:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=38676046</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38676046</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38676046</guid></item><item><title><![CDATA[New comment by x1sec in "Eclipse: The Demo that Sold 3D to Nintendo"]]></title><description><![CDATA[
<p>Pikuma has a 25 hour “NES Programming with 6502 Assembly” that is both accessible to beginners with little to no prior knowledge and being packed with content. [1]<p>He also has other interesting courses which touch upon “retro” programming in a very accessible manner. [2]<p>[1] <a href="https://pikuma.com/courses/nes-game-programming-tutorial" rel="nofollow noreferrer">https://pikuma.com/courses/nes-game-programming-tutorial</a><p>[2] <a href="https://pikuma.com/courses" rel="nofollow noreferrer">https://pikuma.com/courses</a></p>
]]></description><pubDate>Tue, 05 Dec 2023 11:17:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=38529494</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=38529494</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38529494</guid></item><item><title><![CDATA[A friend asked me to find out why his lightbulb app was asking for his location]]></title><description><![CDATA[
<p>Article URL: <a href="https://twitter.com/haxrob/status/1676416949499338752">https://twitter.com/haxrob/status/1676416949499338752</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=36601100">https://news.ycombinator.com/item?id=36601100</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 05 Jul 2023 14:40:13 +0000</pubDate><link>https://twitter.com/haxrob/status/1676416949499338752</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=36601100</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36601100</guid></item><item><title><![CDATA[New comment by x1sec in "Discovering that a Bluetooth car battery monitor is siphoning location data"]]></title><description><![CDATA[
<p>I'm not sure if either of you will read this message - I kept my word and looked into the app<p><a href="https://twitter.com/haxrob/status/1673874637632196608" rel="nofollow noreferrer">https://twitter.com/haxrob/status/1673874637632196608</a></p>
]]></description><pubDate>Wed, 28 Jun 2023 14:41:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=36507155</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=36507155</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36507155</guid></item><item><title><![CDATA[New comment by x1sec in "Discovering that a Bluetooth car battery monitor is siphoning location data"]]></title><description><![CDATA[
<p>I'm confused by what you mean here, could you elaborate?<p>For clarification - you purchase the hardware then you are required to download the phone application. You find this app by scanning the QR code printed on the physical device's box. This app is free. It does not link to a premium version.</p>
]]></description><pubDate>Tue, 27 Jun 2023 07:21:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=36489867</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=36489867</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36489867</guid></item><item><title><![CDATA[New comment by x1sec in "Discovering that a Bluetooth car battery monitor is siphoning location data"]]></title><description><![CDATA[
<p>> The article seems to be suggesting the device itself is gathering data and reporting back covertly ... but I believe it's just the AMap library included by the app developer doing its thing.<p>If this is the take away, then I need to think about how I have phrased things. The GPS co-ordinates are sent two separate companies:<p>1) The Bluetooth device developer (bm2.quicklynks.com)<p>2) AMap (dualstack-cgicol.amap.com)<p>Looking at the decomplication and HTTP REST messages, it is very clear the app developer is deliberately sending GPS to their servers. They send a JSON object with the battery voltages, bluetooth device address and lat/lng in the same request.<p>The cell data, wifi beacon data - this is exclusively collected by AMap services and is not apparent without investing significant time reverse engineering their SDK.</p>
]]></description><pubDate>Tue, 27 Jun 2023 06:03:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=36489398</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=36489398</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36489398</guid></item><item><title><![CDATA[New comment by x1sec in "Discovering that a Bluetooth car battery monitor is siphoning location data"]]></title><description><![CDATA[
<p>Hey thanks, Daneel - A bit of accountability always helps!</p>
]]></description><pubDate>Tue, 27 Jun 2023 05:56:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=36489361</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=36489361</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36489361</guid></item><item><title><![CDATA[New comment by x1sec in "Discovering that a Bluetooth car battery monitor is siphoning location data"]]></title><description><![CDATA[
<p>Google do offer Android app developers guidance in this regard:<p><a href="https://developer.android.com/guide/topics/connectivity/bluetooth/permissions" rel="nofollow noreferrer">https://developer.android.com/guide/topics/connectivity/blue...</a></p>
]]></description><pubDate>Tue, 27 Jun 2023 01:59:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=36488119</link><dc:creator>x1sec</dc:creator><comments>https://news.ycombinator.com/item?id=36488119</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36488119</guid></item></channel></rss>