Live data from Hacker News

Viewing profile — BobDaHacker

BobDaHacker

HN member
Joined
Thu, Jul 31, 2025, 6:54 AM UTC
HN karma
271
Public activity
23 items

About BobDaHacker

No profile information was provided.

Recent public activity

  1. comment
  2. story
  3. story
  4. comment
    Comment #48552824

    That's a different thing. RTMP ingest endpoints aren't behind the same API layer, they're just open media endpoints that accept a connection if you have the stream key. The stream …

  5. comment
    Comment #48551595

    I am not much of a football gal myself, so I didn't know they were a shitty org.

  6. comment
    Comment #48551592

    Also, I am not much of a football gal myself, so I didn't know they were a shitty org.

  7. comment
    Comment #48551585

    As much as I like being butt fucked, I dont wanna go to prison :3

  8. comment
    Comment #48551441

    Yeah I used Claude as a writing assistant for the initial draft. I'm autistic and long-form writing isn't my strong suit, getting a 4000 word blog post to flow well is genuinely ha…

  9. comment
    Comment #48551432

    Good question! So RTMP doesn't really have a clean way to handle two publishers on the same stream key. What would actually happen is the two streams fighting for the ingest endpoi…

  10. comment
    Comment #48551406

    Yeah I see this type of crap often honestly, especially at big companies.

  11. comment
    Comment #48551401

    I blocked my network traffic before clicking it cuz I've seen a lot of things without confirmation pop-ups. At least there was a confirmation pop-up.

  12. comment
    Comment #48550937

    Registered on FIFA's public Agent Platform with my ID, got added to their Microsoft Entra tenant, and found the Angular app only checked roles client-side. The backend APIs served …

  13. story
  14. comment
    Comment #45149086

    Burger King

  15. story
  16. comment
    Comment #44968996

    Yes. I really hope this teaches them a lesson and they fix it before 4chan acts but that problem won't happen. Also If I would have stayed quiet and not informed the public that th…

  17. comment
    Comment #44968987

    I do want people's privacy to be protected, this app has been insecure since day one, and they obviously don't care, it's been 9 months. I posted about it since they obviously didn…

  18. comment
  19. story
  20. comment
  21. story
  22. comment
    Comment #44743152

    You absolutely nailed it. As the researcher who found these vulns, I can confirm the over-engineering is real. They literally had internal user IDs (ofId) already implemented and w…

  23. comment
    Comment #44743145

    Hi HN, I'm the researcher who found these vulnerabilities. Happy to answer questions. A few clarifications on the technical side: The XMPP issue wasn't just about JIDs containing e…