Live data from Hacker News

Viewing profile — nullcathedral

nullcathedral

HN member
Joined
Fri, Dec 12, 2025, 1:50 PM UTC
HN karma
105
Public activity
24 items

About nullcathedral

hn username @ hn username dot com

happy to discuss infosec, vulndev, etc.

There’s apparently a generative AI “artist” using the same name. We’re not related.

Recent public activity

  1. comment
  2. story
  3. comment
    Comment #47431250

    I wouldn't be surprised if we saw a headline in a few years when we find out other actors (e.g. China, Russia) have been buying this data en-masse too.

  4. comment
    Comment #47431238

    Yikes. Why are private organizations so happy to participate in mass surveillance.

  5. comment
    Comment #47431118

    I got bored so I decided to take another look at Roundcube :)

  6. story
  7. comment
    Comment #47397474

    This was one of my most frustrating disclosures, feedback on the process is very welcome :)

  8. story
  9. comment
    Comment #47397274

    Did you request a SSL certificate? Those are public, actors use those to scan any newly requested website for known vulnerabilities and other misconfigurations. I suspect you're ju…

  10. comment
    Comment #47397186

    Sonnet 4.6 and Opus 4.6 are still available here. Pro+ subscription.

  11. comment
    Comment #47337764

    Do you run a dedicated "AI SRE" instance for each customer or how do you ensure there is no potential for cross-contamination or data leakage across customers? Basically how do you…

  12. comment
    Comment #47337354

    I think the underlying point is valid. Agents are a potential tool to add to your arsenal in addition to "throw shit at the wall and see what sticks" tools like WebInspect, Appscan…

  13. comment
    Comment #47128246

    The website gave it away for me, felt very AI generated

  14. comment
    Comment #47127956

    One approach (Claude Code) is to evolve it over time. Start small and run /insights often and use that to refine the CLAUDE.md as needed. https://github.com/trailofbits/claude-code…

  15. comment
    Comment #47127843

    Feel free to correct me, but the ML classifier appears to be rather bare. Less than 20 hardcoded payloads with randomized URL encoding as the only augmentation. How does this gener…

  16. comment
    Comment #46938466

    Good suggestion! Thanks. I'll go write up a welcome post soon :)

  17. comment
    Comment #46938036

    Author here! Are you referring to the "What’s inside this vendor’s VMware images?" on the about page? That is merely an illustration of what goes on inside my head. This is the fir…

  18. comment
    Comment #46937693

    Author here! I have looked at Thunderbird. I'll go and look at some others as well, should have probably done that earlier.

  19. story
  20. comment
    Comment #46620428

    https://nullcathedral.com Just waiting on some vendors to patch bugs before I can drop the first set of posts :)

  21. comment
    Comment #46520558

    I'd say I agree with you there for the low-hanging fruit. The deep research (there's an image filter here but we can bypass it by knowing some obscure corner of the SVG spec) is wh…

  22. comment
  23. comment
    Comment #46520222

    Maybe in the future when labs train more specifically on offensive work, lots of hand holding needed right now. Even simple stuff like training the models to recognize when they're…

  24. comment
    Comment #46519620

    I work in this space. The productivity gains from LLMs are real, but not in the "replace humans" direction. Where they shine is the interpretive grunt work: "help me figure out whe…