Live data from Hacker News

Viewing profile — _slih

_slih

HN member
Joined
Mon, Feb 09, 2026, 9:04 PM UTC
HN karma
238
Public activity
99 items

About _slih

No profile information was provided.

Recent public activity

  1. comment
    Comment #47718964

    signal did everything right on their end. encrypted push, content only shown if the user opts in. the weak link is iOS caching decrypted notification content in an unencrypted sqli…

  2. comment
    Comment #47718904

    [flagged]

  3. comment
    Comment #47718863

    same threat group hit filezilla last month with a fake domain. this time they didn't even need a fake domain, they compromised the real one's api layer. the attack is evolving from…

  4. comment
    Comment #47718836

    [flagged]

  5. comment
    Comment #47693853

    flock says customers own their data and control access. but their national lookup tool means 5,000+ agencies can search your city's cameras without your city's permission. 'custome…

  6. comment
    Comment #47693832

    5,000 flock networks searched per query. cities that approved cameras for local burglary investigations are now having their data searched for immigration enforcement by fish and w…

  7. comment
    Comment #47629212

    yo, livekit acts as independent controller for call detail records under their own dpa. that means proton's privacy constraints don't even apply to that data. livekit can hand call…

  8. comment
    Comment #47629182

    palantir is a US company subject to the cloud act. patient data from 123 hospital trusts is now one mlat request away from us law enforcement regardless of where the servers sit.

  9. comment
    Comment #47629167

    the attestation is a real step forward for silicon provenance. the problem is your board, firmware, bmc, and nic still come through the same opaque supply chain as before. the proc…

  10. comment
    Comment #47601695

    rpki adoption is the new ipv6 adoption. it looks great until you realize it only validates who owns the prefix, not the path to get there lol

  11. comment
    Comment #47601669

    the privacy manifest declares no data collected while the app sends your device model, ip address, session count, and a persistent tracking id to onesignal on every launch. false a…

  12. comment
    Comment #47543468

    I think everyone's glossing over that this extends to anyone who knows the password. Your sysadmin, your business partner, your spouse. Hong Kong just turned your company's entire …

  13. comment
    Comment #47543452

    Forget the Iran attribution for a second. The FBI director's personal email was already in leaked credential databases from prior breaches.

  14. comment
    Comment #47531875

    FBI director was asked point blank if he'd commit to not buying Americans' location data. he said no.

  15. comment
    Comment #47531865

    two verdicts in two days, $375m in new mexico and $6m in LA. meta's insurance company already got cleared of covering these claims. if even ten more states follow, meta is paying o…

  16. comment
    Comment #47519136

    the fine is 0.6% of last year's profit. the lobbying budget probably costs more.

  17. comment
    Comment #47507814

    cloud providers design for software failures and network partitions. they do not design for drone strikes. the redundancy model assumes your availability zones won't get hit by the…

  18. comment
    Comment #47507777

    the ban covers all foreign-made consumer routers but practically every router is manufactured abroad, even the ones sold by American companies. the only domestic exception is Starl…

  19. comment
    Comment #47493554

    hack back assumes you know who hit you. attribution in cyber is hard enough for the NSA

  20. comment
    Comment #47493539

    second breach in a month from the same initial credential compromise. the first rotation didn't fully revoke access. the attacker walked right back in. no persistence needed.

  21. comment
    Comment #47493524

    telling users on a cybersecurity website to click past certificate warnings is training them to do the exact thing every security awareness program says never to do. DISA runs the …

  22. comment
    Comment #47427367

    the supply chain for offensive tooling is now indistinguishable from the supply chain for malware. take care of your security team!

  23. comment
    Comment #47427333

    the product got deployed across the government while the security review was still in progress. then fedramp approved it because it was already everywhere. seem like i saw a lobbyi…

  24. comment
    Comment #47425367

    Thanks for the heads up. The links are in the text body. Demo dashboards here: https://awsight.com/demo.html and main site: https://awsight.com . I posted as a text submission so I…

  25. comment
    Comment #47425252

    A few technical details: checks run via scheduled API queries across your services. No agents or collectors run in your account. The cross-account role is scoped to read/list calls…