Viewing profile — BobDaHacker
BobDaHacker
HN member- Joined
- Thu, Jul 31, 2025, 6:54 AM UTC
- HN karma
- 271
- Public activity
- 23 items
- HN profile
- View on Hacker News ↗
About BobDaHacker
No profile information was provided.
Recent public activity
-
comment
Comment #48560234
[dead]
- story
- story
-
comment
Comment #48552824
That's a different thing. RTMP ingest endpoints aren't behind the same API layer, they're just open media endpoints that accept a connection if you have the stream key. The stream …
-
comment
Comment #48551595
I am not much of a football gal myself, so I didn't know they were a shitty org.
-
comment
Comment #48551592
Also, I am not much of a football gal myself, so I didn't know they were a shitty org.
-
comment
Comment #48551585
As much as I like being butt fucked, I dont wanna go to prison :3
-
comment
Comment #48551441
Yeah I used Claude as a writing assistant for the initial draft. I'm autistic and long-form writing isn't my strong suit, getting a 4000 word blog post to flow well is genuinely ha…
-
comment
Comment #48551432
Good question! So RTMP doesn't really have a clean way to handle two publishers on the same stream key. What would actually happen is the two streams fighting for the ingest endpoi…
-
comment
Comment #48551406
Yeah I see this type of crap often honestly, especially at big companies.
-
comment
Comment #48551401
I blocked my network traffic before clicking it cuz I've seen a lot of things without confirmation pop-ups. At least there was a confirmation pop-up.
-
comment
Comment #48550937
Registered on FIFA's public Agent Platform with my ID, got added to their Microsoft Entra tenant, and found the Angular app only checked roles client-side. The backend APIs served …
- story
-
comment
Comment #45149086
Burger King
- story
-
comment
Comment #44968996
Yes. I really hope this teaches them a lesson and they fix it before 4chan acts but that problem won't happen. Also If I would have stayed quiet and not informed the public that th…
-
comment
Comment #44968987
I do want people's privacy to be protected, this app has been insecure since day one, and they obviously don't care, it's been 9 months. I posted about it since they obviously didn…
- comment
- story
- comment
- story
-
comment
Comment #44743152
You absolutely nailed it. As the researcher who found these vulns, I can confirm the over-engineering is real. They literally had internal user IDs (ofId) already implemented and w…
-
comment
Comment #44743145
Hi HN, I'm the researcher who found these vulnerabilities. Happy to answer questions. A few clarifications on the technical side: The XMPP issue wasn't just about JIDs containing e…