Viewing profile — Fibonar
Fibonar
HN member- Joined
- Thu, Jan 25, 2024, 11:58 PM UTC
- HN karma
- 229
- Public activity
- 11 items
- HN profile
- View on Hacker News ↗
About Fibonar
No profile information was provided.
Recent public activity
-
comment
Comment #47536513
I've updated the timeline to clarify I did in fact email them. I’m not yet at the point of having Claude write my emails for me, in fact it was my first one sent since joining the …
-
comment
Comment #47535608
I went to read the advisory post and chose double clicking it from Finder instead of vim for whatever reason. I was actually on a call with my manager as it happened, I had time to…
-
comment
Comment #47533804
I’ve entertained myself with CTF walkthroughs on YouTube before and had been meaning to try it out. But yeah I feel it falls under the same category as lock picking, fun to LARP, u…
-
comment
Comment #47532805
The best part was that I didn't even mean to ask Claude who to contact! I was still in disbelief that I was one of the first people affected, so I asked for existing reports on the…
-
comment
Comment #47532693
I’m a big proponent of it within our company! CC tried to style it to blend in with our blog but it was kind of a disaster. Definitely had a new appreciation for the out-of-the-box…
-
comment
Comment #47532498
So I've been thinking about this a lot since it happened. I've already added dependency cooldowns https://nesbitt.io/2026/03/04/package-managers-need-to-cool-... to every part of o…
-
comment
Comment #47531968
Callum here, I was the developer that first discovered and reported the litellm vulnerability on Tuesday. I’m sharing the transcript of what it was like figuring out what was going…
-
story
My minute-by-minute response to the LiteLLM malware attack
Related: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised - https://news.ycombinator.com/item?id=47501426 (483 comments)
-
comment
Comment #47524810
Initial person to report the malware to PyPI here. My cynical take is that it doesn't really matter how tightly scoped the agent privileges are if the human is still developing cod…
-
comment
Comment #47523683
Dev who submitted the PyPI report here. I hear what you're saying, but in this case it was all human error that got me. It was a mix of getting too comfortable with uvx installing …
-
comment
Comment #47523497
Yep my coworker hnykda, first reply confirming the report, got his account deleted for a while earlier. Definitely not the best way of handling this...