Viewing profile — _slih
_slih
HN member- Joined
- Mon, Feb 09, 2026, 9:04 PM UTC
- HN karma
- 238
- Public activity
- 99 items
- HN profile
- View on Hacker News ↗
About _slih
No profile information was provided.
Recent public activity
-
comment
Comment #47718964
signal did everything right on their end. encrypted push, content only shown if the user opts in. the weak link is iOS caching decrypted notification content in an unencrypted sqli…
-
comment
Comment #47718904
[flagged]
-
comment
Comment #47718863
same threat group hit filezilla last month with a fake domain. this time they didn't even need a fake domain, they compromised the real one's api layer. the attack is evolving from…
-
comment
Comment #47718836
[flagged]
-
comment
Comment #47693853
flock says customers own their data and control access. but their national lookup tool means 5,000+ agencies can search your city's cameras without your city's permission. 'custome…
-
comment
Comment #47693832
5,000 flock networks searched per query. cities that approved cameras for local burglary investigations are now having their data searched for immigration enforcement by fish and w…
-
comment
Comment #47629212
yo, livekit acts as independent controller for call detail records under their own dpa. that means proton's privacy constraints don't even apply to that data. livekit can hand call…
-
comment
Comment #47629182
palantir is a US company subject to the cloud act. patient data from 123 hospital trusts is now one mlat request away from us law enforcement regardless of where the servers sit.
-
comment
Comment #47629167
the attestation is a real step forward for silicon provenance. the problem is your board, firmware, bmc, and nic still come through the same opaque supply chain as before. the proc…
-
comment
Comment #47601695
rpki adoption is the new ipv6 adoption. it looks great until you realize it only validates who owns the prefix, not the path to get there lol
-
comment
Comment #47601669
the privacy manifest declares no data collected while the app sends your device model, ip address, session count, and a persistent tracking id to onesignal on every launch. false a…
-
comment
Comment #47543468
I think everyone's glossing over that this extends to anyone who knows the password. Your sysadmin, your business partner, your spouse. Hong Kong just turned your company's entire …
-
comment
Comment #47543452
Forget the Iran attribution for a second. The FBI director's personal email was already in leaked credential databases from prior breaches.
-
comment
Comment #47531875
FBI director was asked point blank if he'd commit to not buying Americans' location data. he said no.
-
comment
Comment #47531865
two verdicts in two days, $375m in new mexico and $6m in LA. meta's insurance company already got cleared of covering these claims. if even ten more states follow, meta is paying o…
-
comment
Comment #47519136
the fine is 0.6% of last year's profit. the lobbying budget probably costs more.
-
comment
Comment #47507814
cloud providers design for software failures and network partitions. they do not design for drone strikes. the redundancy model assumes your availability zones won't get hit by the…
-
comment
Comment #47507777
the ban covers all foreign-made consumer routers but practically every router is manufactured abroad, even the ones sold by American companies. the only domestic exception is Starl…
-
comment
Comment #47493554
hack back assumes you know who hit you. attribution in cyber is hard enough for the NSA
-
comment
Comment #47493539
second breach in a month from the same initial credential compromise. the first rotation didn't fully revoke access. the attacker walked right back in. no persistence needed.
-
comment
Comment #47493524
telling users on a cybersecurity website to click past certificate warnings is training them to do the exact thing every security awareness program says never to do. DISA runs the …
-
comment
Comment #47427367
the supply chain for offensive tooling is now indistinguishable from the supply chain for malware. take care of your security team!
-
comment
Comment #47427333
the product got deployed across the government while the security review was still in progress. then fedramp approved it because it was already everywhere. seem like i saw a lobbyi…
-
comment
Comment #47425367
Thanks for the heads up. The links are in the text body. Demo dashboards here: https://awsight.com/demo.html and main site: https://awsight.com . I posted as a text submission so I…
-
comment
Comment #47425252
A few technical details: checks run via scheduled API queries across your services. No agents or collectors run in your account. The cross-account role is scoped to read/list calls…