Hacker Newsnew | past | comments | ask | show | jobs | submit | more hashstring's commentslogin

This.


The fact that you try to make this about “being cool” is absurd.


The vendor requested embargo timelines can get pretty crazy.

Intel requested an embargo for 21 months for SRBDS/Crosstalk.

For Downfall, a more recent one, Intel requested a 12 month embargo to release a microcode update.


For all I know, that might be a reasonable ask for these kinds of vulnerabilities --- not that researchers have to honor them.


What about turn JS off on your favourite iOS browser?


That wouldn't prevent possible malware apps using WKWebview from getting out of the jail they are running out right?


Yes, I agree.

However I also expect that Swift-compiled apps can do this without a web browser component.

It’s a different threat model though, having installed a malicious app vs browsing a malicious site.


Which is the reason alongside telemetry I tend to favor using websites over apps.

Having said that there are apps that are considered mainstream and not malicious by the general population but can become a convenient backdoor for, say, a state actor.


No need to turn JS off. Turn on Lockdown mode which disables Javascript JIT and WASM, which might be enough


It’s not.


Brave on iOS can limit Javascript to trusted sites.


They carefully added “immediate”.


Right, and “where two subdomains of the same site can be merged into one process” is normal right, given Site Isolation ≠ Origin Isolation.

A PSL flaw is important, but also a low-cost fix.

Thanks for pointing this out.


It makes a lot of sense.

Twitter is not the community that it used to be. Twitter used to provide me with new updates and cool communities of people.

Since the platform got repurposed to become X, the feeds became a negative in my day— so much ragebait, violence and other negative content that pushed me away.

Apart from the fact that the algorithm was tweaked to become Elon and Trump biased [1] and that link load times to “undesired” websites got artificially increased [2], the whole monetisation strategy attracted cheap, ragebait content [3]. The platform started paying out for 5M+ impressions. This incudes negative and positive impressions and essentially drives up polarising content more than anything.

I believe the issue isn’t about community notes at all, as some suggest, that is such a small thing and critical replies were always a thing. In contrast I believe the real problem is: 1) there’s no point engaging on a platform where every feature can and will be manipulated to serve personal agendas that you do not have control over. 2) Maintaining a presence on X has become a liability– it’s damaging to a set of brands both now and likely in the future.

I’m glad the Guardian and other accounts are moving away from X.

[1] https://www.independent.co.uk/tech/elon-musk-trump-x-algorit... [2] https://news.ycombinator.com/item?id=37130060 [3] https://web.archive.org/web/20230714080253/https://help.twit...


Awesome, can I get a promocode? Looks very interesting.


Sure! Hope u like it! Promo: 93YL9NM3WNHN

(To redeem, click on your profile icon, go to “Redeem Gift Card or Code” and enter the code. Each promo code is one time use only, so to anyone else reading this please ask for one in a new comment if you would like one!)


Hey there, Thank you so much— just redeemed. This is a really fun small cool app. I played it for ~5 minutes, but I think I am beginning to like it a lot. One thing I found is that you can click “Click here to feel an example” quite a few times and there’s no lock on it while the example is playing. I clicked it accidentally twice and so it bugged a bit. Secondly, I am wondering if its possible to also tap on the outside of my phone for example, if I really were to use this app without “anyone noticing” then I would much rather do that, that and plus I think it would be neat. But that’s just sharing my personal thoughts. Thank you and I’m going to share this app with some folks that I think will like it.


Thats a good point! I only added a lock on the button that says "Click Me" and not the others - something I can tweak in an update :)

I am really happy you like the app!! The only issue with tapping on the outside of the phone would be how the phone could detect it (not sure if the gyroscope or something could be accurate enough). Someone had suggested volume buttons so maybe that is an option to explore.

Thank you for your feedback though and for sharing it! I appreciate it! :)


I believe it should be accurate enough, I can tap three times on the back of my phone to make it switch to dark mode. Cheers.

https://support.apple.com/en-us/111772


Thats great to know, will look into it - thx!


I am grateful too, but I don’t think that this person could have earned more via blackmarkets. This backdoor in ssh was NOBUS. You cannot exploit it unless you have the private key.


Project Zero is not defensive. Infosec Twitter has both sides.

I do agree with you that defense is a large part of the industry. My perspective is even that most organizations are looking for “defense” roles. The field is very wide (e.g., folks working on cryptography to sec ops).


It is defensive, but for the best guys out there, the carrot is on offensive side. You are not getting rewarded for doing perfectly secure systems, unless you work in very big company.

It means that most of the average guys build defense, and then the best guys test them and pick the money when something is found. While we could prevent most issues if those best guys help on building the systems instead.

But they have no motivation, because they get more money from other things.


I think that you might actually observe that finding attacks on systems is common, while developing a “perfectly secure system” is much harder to do, if not impossible.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: