Live data from Hacker News

Viewing profile — mafriese

mafriese

HN member
Joined
Thu, May 09, 2019, 11:38 AM UTC
HN karma
215
Public activity
34 items

About mafriese

Meow

Recent public activity

  1. comment
  2. comment
  3. comment
    Comment #48067619

    I posted a comment on the announcement when it was posted here: >As someone who is working in incident response and malware analysis I have to say that is one of the worst ideas I …

  4. comment
    Comment #48045810

    As someone who is working in incident response and malware analysis I have to say that is one of the worst ideas I have ever seen. A lot of companies have issues with ClickFix [1] …

  5. comment
    Comment #47886587

    From my experience OpenAI has become very sensitive when it comes to using their tools for security research. I am using MCP servers for tools like IDA Pro or Ghidra (for malware a…

  6. comment
    Comment #47265227

    I’m not saying that this is related to Wikipedia ditching archive.is but timing in combination with Russian messages is at least…weird.

  7. comment
    Comment #46985655

    From the conclusion > Importantly, this work also highlights the defensive implications of such techniques. While Secure Boot and firmware integrity mechanisms would prevent this a…

  8. comment
    Comment #46748696

    maybe it's a mix of both :)

  9. comment
    Comment #46748377

    You can define the tools that agents are allowed to use in the opencode.json (also works for MCP tools I think). Here’s my config: https://pastebin.com/PkaYAfsn The models can call…

  10. comment
    Comment #46748217

    Nope it isn’t. I did it as a joke initially (I also had a version where every 2 stories there was a meeting and if a someone underperformed it would get fired). I think there are m…

  11. comment
    Comment #46747660

    Ok it might sound crazy but I actually got the best quality of code (completely ignoring that the cost is likely 10x more) by having a full “project team” using opencode with multi…

  12. comment
    Comment #45810177

    I am still torn on this issue. On the one hand, it feels like a copyright violation when other people's works are used to train an ML model. On the other hand, it is not a copyrigh…

  13. comment
    Comment #44004060

    I never doubted that it's possible but it's way harder than identifying bank accounts. There is a massive business behind crypto tracking, that's why companies like MasterCard have…

  14. comment
    Comment #44003399

    You can easily establish the connection from a bank account to a person. A connection from a crypto wallet to a person is extremely difficult. Money laundering with crypto is also …

  15. comment
    Comment #44003034

    > The threat actor appears to have obtained this information by paying multiple contractors or employees working in support roles outside the United States to collect information f…

  16. comment
    Comment #42192205

    This is perfect advertising for the Ladybird browser. I hope that some of the developers (if this really goes live on the release channel) will join other projects. I can understan…

  17. comment
    Comment #41705801

    Is this in any way better than eza? https://github.com/eza-community/eza

  18. comment
    Comment #40863930

    The website uses "Enter your 6-digit authentication code" as an example and then shows a 4-digit auth code in the text field https://imgur.com/a/u4STHPe

  19. comment
    Comment #40716630

    https://github.com/mafriese/scarecrow Can upload any files you want there. Direct DL for one of the files: https://github.com/mafriese/scarecrow/raw/main/autoruns.exe

  20. comment
    Comment #40716282

    This "thing" is always spawning 3 processes at the time. The processes are always the ones from the virustotal link. I can upload the DLL to a file sharing service of your choice i…

  21. comment
    Comment #40715995

    I don't understand why the software is built how it's built. Why would you want to implement licensing in the future for a software product that only creates fake processes and reg…

  22. comment
    Comment #32423197

    You guys are getting paid?

  23. comment
    Comment #30373661

    Use Bitwarden instead. fixed. https://bitwarden.com/

  24. comment
    Comment #28786378

    Because the 99$/year are for the dev platform and the 15%/30% cut are for using the infrastructure needed for in app purchases.

  25. comment
    Comment #28786251

    they do - the first 1m$ only cost 15% - It's btw the same with the Google Play Store