Viewing profile — nullcathedral
nullcathedral
HN member- Joined
- Fri, Dec 12, 2025, 1:50 PM UTC
- HN karma
- 105
- Public activity
- 24 items
- HN profile
- View on Hacker News ↗
About nullcathedral
happy to discuss infosec, vulndev, etc.
There’s apparently a generative AI “artist” using the same name. We’re not related.
Recent public activity
- comment
- story
-
comment
Comment #47431250
I wouldn't be surprised if we saw a headline in a few years when we find out other actors (e.g. China, Russia) have been buying this data en-masse too.
-
comment
Comment #47431238
Yikes. Why are private organizations so happy to participate in mass surveillance.
-
comment
Comment #47431118
I got bored so I decided to take another look at Roundcube :)
- story
-
comment
Comment #47397474
This was one of my most frustrating disclosures, feedback on the process is very welcome :)
- story
-
comment
Comment #47397274
Did you request a SSL certificate? Those are public, actors use those to scan any newly requested website for known vulnerabilities and other misconfigurations. I suspect you're ju…
-
comment
Comment #47397186
Sonnet 4.6 and Opus 4.6 are still available here. Pro+ subscription.
-
comment
Comment #47337764
Do you run a dedicated "AI SRE" instance for each customer or how do you ensure there is no potential for cross-contamination or data leakage across customers? Basically how do you…
-
comment
Comment #47337354
I think the underlying point is valid. Agents are a potential tool to add to your arsenal in addition to "throw shit at the wall and see what sticks" tools like WebInspect, Appscan…
-
comment
Comment #47128246
The website gave it away for me, felt very AI generated
-
comment
Comment #47127956
One approach (Claude Code) is to evolve it over time. Start small and run /insights often and use that to refine the CLAUDE.md as needed. https://github.com/trailofbits/claude-code…
-
comment
Comment #47127843
Feel free to correct me, but the ML classifier appears to be rather bare. Less than 20 hardcoded payloads with randomized URL encoding as the only augmentation. How does this gener…
-
comment
Comment #46938466
Good suggestion! Thanks. I'll go write up a welcome post soon :)
-
comment
Comment #46938036
Author here! Are you referring to the "What’s inside this vendor’s VMware images?" on the about page? That is merely an illustration of what goes on inside my head. This is the fir…
-
comment
Comment #46937693
Author here! I have looked at Thunderbird. I'll go and look at some others as well, should have probably done that earlier.
- story
-
comment
Comment #46620428
https://nullcathedral.com Just waiting on some vendors to patch bugs before I can drop the first set of posts :)
-
comment
Comment #46520558
I'd say I agree with you there for the low-hanging fruit. The deep research (there's an image filter here but we can bypass it by knowing some obscure corner of the SVG spec) is wh…
- comment
-
comment
Comment #46520222
Maybe in the future when labs train more specifically on offensive work, lots of hand holding needed right now. Even simple stuff like training the models to recognize when they're…
-
comment
Comment #46519620
I work in this space. The productivity gains from LLMs are real, but not in the "replace humans" direction. Where they shine is the interpretive grunt work: "help me figure out whe…