Live data from Hacker News

Viewing profile — Fibonar

Fibonar

HN member
Joined
Thu, Jan 25, 2024, 11:58 PM UTC
HN karma
229
Public activity
11 items

About Fibonar

No profile information was provided.

Recent public activity

  1. comment
    Comment #47536513

    I've updated the timeline to clarify I did in fact email them. I’m not yet at the point of having Claude write my emails for me, in fact it was my first one sent since joining the …

  2. comment
    Comment #47535608

    I went to read the advisory post and chose double clicking it from Finder instead of vim for whatever reason. I was actually on a call with my manager as it happened, I had time to…

  3. comment
    Comment #47533804

    I’ve entertained myself with CTF walkthroughs on YouTube before and had been meaning to try it out. But yeah I feel it falls under the same category as lock picking, fun to LARP, u…

  4. comment
    Comment #47532805

    The best part was that I didn't even mean to ask Claude who to contact! I was still in disbelief that I was one of the first people affected, so I asked for existing reports on the…

  5. comment
    Comment #47532693

    I’m a big proponent of it within our company! CC tried to style it to blend in with our blog but it was kind of a disaster. Definitely had a new appreciation for the out-of-the-box…

  6. comment
    Comment #47532498

    So I've been thinking about this a lot since it happened. I've already added dependency cooldowns https://nesbitt.io/2026/03/04/package-managers-need-to-cool-... to every part of o…

  7. comment
    Comment #47531968

    Callum here, I was the developer that first discovered and reported the litellm vulnerability on Tuesday. I’m sharing the transcript of what it was like figuring out what was going…

  8. story
    My minute-by-minute response to the LiteLLM malware attack

    Related: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised - https://news.ycombinator.com/item?id=47501426 (483 comments)

  9. comment
    Comment #47524810

    Initial person to report the malware to PyPI here. My cynical take is that it doesn't really matter how tightly scoped the agent privileges are if the human is still developing cod…

  10. comment
    Comment #47523683

    Dev who submitted the PyPI report here. I hear what you're saying, but in this case it was all human error that got me. It was a mix of getting too comfortable with uvx installing …

  11. comment
    Comment #47523497

    Yep my coworker hnykda, first reply confirming the report, got his account deleted for a while earlier. Definitely not the best way of handling this...