Live data from Hacker News

Viewing profile — aja12

aja12

HN member
Joined
Wed, Dec 18, 2024, 11:10 AM UTC
HN karma
33
Public activity
32 items

About aja12

After being a lurker for about 5 years, I finally created an account, due to... I don't really know. Enthusiastic about self-hosting and cybersecurity. Proficient in Python, interested in learning Rust. Mostly using HN as procrastination, and as a great source of amazing open source tools.

Recent public activity

  1. comment
    Comment #47506688

    From an exterior viewpoint, all this portrayal of Trump as either insane or an idiot is as useless and dangerous as the sanewashing. I believed Trump was insane/an idiot during his…

  2. comment
    Comment #47059251

    Yes! When I learned of Anna's Archive a few years back I too was frustrated by the lack of a short explainer of how to access single files, existence of an API, etc. Now I'm enviou…

  3. comment
    Comment #46729378

    Being in the same boat as you I switched to OpenCode with z.ai GLM 4.7 Pro plan and it's quite ok. Not as smart as Opus but smart enough for my needs, and the pricing is unbeatable…

  4. comment
    Comment #46695225

    Actually, the real countermeasure to PTH is to disable NTLM auth and rely only on Kerberos (and then monitor NTLM as a very strong indicator that someone or something is attempting…

  5. comment
    Comment #46695159

    > cloud-based synchronization Well I don't disagree that it might be possible to abuse cloud sync in some way to export the secrets, but it's not quite as egregious as just includi…

  6. comment
    Comment #46691981

    >Most TOTP apps support backups/restores, which defeats this. Citation needed? Yubico authenticator doesn't (the secure enclave is the Yubikey). I'd be very surprised if MS Authent…

  7. comment
    Comment #46383771

    From someone who has not tried the software but might be interested if it gains traction: You should decide whether you are building this for yourself or as a product to others. Ea…

  8. comment
    Comment #46036307

    Yet. When ChatControl will be in place, it'll only be a matter of time

  9. comment
    Comment #45820309

    Bullshit journalism. This was not a post heist report, every buzzword chasing so called news outlets out there are repeating ad nauseam findings that were listed in a report produc…

  10. comment
    Comment #44971643

    Baseband SoC running their own OS independent from Android/iOS and staying asleep (while still listening for incoming signals) is very much no longer in conspiracy theory territory…

  11. comment
    Comment #43715080

    As a pentester, who does not love CVSS[0], I found the article explaining how to replace CVSS with CVSS very amusing [0] CVSS is often poorly understood and used by internal teams …

  12. comment
    Comment #43288648

    First of all, I'm not a gun control activist, and I do agree with some of your views. However: > I think this is a uniquely American problem because America is a unique country. No…

  13. comment
    Comment #43256437

    Oh please Apple is extremely user-hostile, going to great lengths to strip users of control of their devices, gaslighting them into staying in the walled garden (with great success…

  14. comment
    Comment #43228905

    An important part of GP's comment was "until proven otherwise" We have no proof of extraterrestrial life. Yet.

  15. comment
    Comment #43227182

    > A big part of the reason I use Apple products is that they protect not only me, but my family who don't know what the implications of sideloading are. I know that the apps my pho…

  16. comment
    Comment #43227063

    > Yes and infected Xcode and various SDKs you get on your laptop are actually the biggest threat to iOS security (other than just literally malicious devs). Devs torrenting an xcod…

  17. comment
    Comment #43191250

    That's fallacious for two reasons: 1: you can set secure defaults at one place globally, but your code must be correct all the time to be free of SQLi 2: it's usually not the same …

  18. comment
    Comment #43127072

    Did you invite him on purpose?

  19. comment
    Comment #43011581

    Why are people downvoting your comment? It's not against the guidelines, is it? I strongly think you are wrong, and I strongly disagree with your points, but I don't see why your o…

  20. comment
    Comment #43011551

    Of course. And it's fine? I'm a proponent of GPL for this reason, I see it as an ideology to which I subscribe, I don't see the problem?

  21. comment
    Comment #43008789

    If you do that on the server side, per account, it works. Small DoS risk, but it remains acceptable

  22. comment
    Comment #43008788

    If you do that on the server side, per account, it works. Small DoS risk, but it remains acceptable

  23. comment
    Comment #42997523

    What's the harm? Having multiple alternatives to any component of the software stack is a good thing, and it fosters understanding and improvement, doesn't it?

  24. comment
    Comment #42978211

    Pivot into cybersecurity? As a pentester, a mountain of security bugs in a mountain of AI produced slop that no one understands is the ideal provider of job security, I guess Maybe…

  25. comment
    Comment #42843974

    > Probably not worth the added complexity, but in theory, the package could be published immediately with the existing compression and then in the background, replaced with the Zop…