Hacker Newsnew | past | comments | ask | show | jobs | submit | gen6acd60af's commentslogin


What, because they used a single em—dash?


Got it, thanks for pointing it out.


Commenters of HN:

Your past thoughts have been dredged up and judged.

For each $TOPIC, you have been awarded a grade by GPT-5.1 Thinking.

Your grade is based on OpenAI's aligned worldview and what OpenAI's blob of weights considers Truth in 2025.

Did you think well, netizen?

Are you an Alpha or a Delta-Minus?

Where will the dragnet grading of your online history happen next?


Of all the people on the entire internet, I would hope HN posters understand best that anything and everything posted online already has and also will at some point be used in such ways.


>This submission has been flagged by the Auto-Reviewer v7.0

But we already have this on HN ;-)

[dupe]


Worth pointing out:

That domain has never been mentioned on HN before this, it does not appear in search engine results apart from those indexing that comment, and it has no recorded history of any kind.


Was reading that account's history because it felt LLM-ish, I guess that's the smoking gun!


Concerning.

It's interesting research, but will Truffle Security use the email addresses for lead gen or marketing purposes, like how they mined users' pingbacks from their XSS Hunter fork for stats?

https://portswigger.net/daily-swig/new-xss-hunter-host-truff...


This one?

>Claude's output was thoroughly reviewed by Cloudflare engineers with careful attention paid to security and compliance with standards.

>To emphasize, this is not "vibe coded". Every line was thoroughly reviewed and cross-referenced with relevant RFCs, by security experts with previous experience with those RFCs.

Some time later...

https://github.com/advisories/GHSA-4pc9-x2fx-p7vj / CVE-2025-4143

>The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp, did not correctly validate that redirect_uri was on the allowed list of redirect URIs for the given client registration.


Sorry, my code has bugs sometimes.



>Based on the GitHub repo at github.com/rpastuszak/enso

That GitHub repo URL doesn't exist, nor does the user namespace.

Could you please clarify where you are seeing this?

The author's GitHub profile appears to be https://github.com/paprikka.



See also (AFAIK most of these support JSless challenges out of the box): haproxy-protection, go-away, anticrawl



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: