Viewing profile — cryptbe
cryptbe
HN member- Joined
- Sat, Sep 18, 2010, 12:32 AM UTC
- HN karma
- 546
- Public activity
- 138 items
- HN profile
- View on Hacker News ↗
About cryptbe
No profile information was provided.
Recent public activity
-
comment
Comment #48274427
Oh hey, this is our work! We helped Anthropic analyze and report this bug. For the record, this bug has nothing to do with our recent MIE attack [1] [2], which exploited two differ…
-
comment
Comment #48081364
Nope. Try the PoC on macOS: https://github.com/califio/publications/blob/main/MADBugs/fr... The script downloads and sets up FreeBSD on QEMU, then runs the exploit. The exploit is …
-
comment
Comment #48078821
You're always super kind to me :)
-
comment
Comment #48078660
Nice to randomly encounter our own work here. Check out our blog post for a fun walkthrough: https://blog.calif.io/p/cve-2026-7270-how-i-get-root-on-free... AI-generated working ex…
-
comment
Comment #47817014
The feature is enabled by default. You can test it by yourself.
-
comment
Comment #47816895
This is a good title, thanks! There was iTerm2 in the original title, but it overflowed to the subtitle in Substack. I've now updated the blog post.
-
comment
Comment #47816807
Disclosure: I didn't discover the vulnerability. I wrote the blog post. Thanks for releasing a fix! It was surprising that there wasn't an official release, even though the bug imp…
-
comment
Comment #47816740
Disclosure: I didn't discover the vulnerability. I wrote the blog post. >The author was able to develop an exploit by prompting an LLM with just the upstream commit Yes, I was able…
-
comment
Comment #47602991
>Key point is that Claude did not find the bug it exploits. It found the bug man. You didn't even read the advisory. It was credited to "Nicholas Carlini using Claude, Anthropic".
-
comment
Comment #47598213
>But you would expect running "git status" or "git ls-files" in the unzipped directory to completely pwn your system? Probably not either. That’s fair, but it would be pretty unusu…
-
comment
Comment #47598164
I think we can agree that Git is at least partly responsible for this issue, if not more. That said, even being aware of that doesn’t necessarily help much in practice. When you’re…
-
comment
Comment #47598028
Yes, likely. And git is not going to fix it. So isn't it fair to expect the editor maintainers to do something about it, to protect their users, no?
-
comment
Comment #47597991
Disclosure: I didn’t discover the bugs, but helped write the blog post. These issues are technically classified as local code execution (AV:L), but they go against a pretty strong …
-
comment
Comment #47597792
When I wget a tarball, unzip, and emacs a.txt inside, I don't expect that it'd execute arbitrary commands. I think people should be aware of this risk, especially when it looks lik…
- story
- story
- story
- story
-
comment
Comment #40234348
Thanks for sharing. I'm one of the co-authors of the blog post. Let me know if you have any questions! tl;dr: We analyzed a LockBit v3 variant, and rediscovered a bug that allows u…
- story
- story
-
comment
Comment #25383578
It really is turned off. Companies like Google get huge fines when they break their promise -- even accidentally.
-
comment
Comment #25383473
You can use Google Search and tell Google not to log your search history or use the data for advertising purposes. See my comment [1] for how to turn on these privacy controls. [1]…
-
comment
Comment #25383456
Google provides decent security/privacy controls, see my comment on how to turn them on [1]. If you have any specific concerns, I'd love to learn more and see if there's anything I…
- comment