Viewing profile — outloudvi
outloudvi
HN member- Joined
- Wed, Aug 01, 2018, 12:22 AM UTC
- HN karma
- 205
- Public activity
- 100 items
- HN profile
- View on Hacker News ↗
About outloudvi
Recent public activity
-
comment
Comment #49000804
Went through the comment page and found this comment that explains well on most of the popular opinions. Thank you, hennell!
-
comment
Comment #48995631
I agree cooldown is not harmful in general. What I intended to say is that people (mostly) only know a security company is not trustable because they once failed to detect a malwar…
-
comment
Comment #48995529
I agree that LLM does not (and believe it never) fully replace researchers, but it produces artifacts (e.g. writeups, PoCs) at a cheaper price. That makes me think LLM impacts huma…
-
comment
Comment #48995389
After reading the comments I now agree a short-length cooldown (maybe 1 or 3 days) is beneficial, given the following assumptions: - Independent security companies are scanning the…
-
comment
Comment #48995252
Sorry! That's 100% on me failing to make the analogy understood. Shall have thought about that... but I'm playing too many Unity games recently.
-
comment
Comment #48995191
Thanks for your explanation on the definition of "security theater"! > But if it turns out they can’t serve as the cooldown vanguard, then we have great evidence that they shouldn’…
-
comment
Comment #48994991
I applaud you if you do setup automated security scanners, without counting on external security groups or individuals (that doesn't have a security contract with your company). Th…
-
comment
Comment #48994908
> The idea of not moving quickly to new software versions has been around for decades. There are COBOL users and CentOS 6 users. They aren't affected by this issue. They might need…
-
comment
Comment #48994529
I think it's great if people actually use LLM for the analysis. I did mention it in the solution part in the post: > Run LLM-assisted audit on vendored code.
-
comment
Comment #48994431
I also believe sandboxing will get more and more important. There might be some trade-off on user experience or convenience, but given the security enhancement and (LLM agent's) fr…
-
comment
Comment #48994387
I do appreciate these security companies a lot (for example, Snyk), but I feel it hard to believe this is sustainable. Especially in the current world where LLM is devaluing securi…
- story
-
comment
Comment #48878545
May I put some contents against GCP's AUP in my repo, wait for Grok Build to upload them, and report the bucket to Google?
-
comment
Comment #48201834
> Sadly, the RDS kernel module this requires is only default on Arch Linux among the common distributions we tested. Sir, what do you mean by "Sadly"? I know your write-ups are mos…
-
comment
Comment #47911457
The article speaks well but the situation for coding is more severe. Shells are not needed once they are not in needed. Code does not: customer need is always there. Before forgott…
-
comment
Comment #47175744
These companys don't care about the reputation of their domains anymore at the moment they start to send spams. However, email senders (SendGrid, Mailgun etc.) care about the reput…
-
comment
Comment #47164658
I usually check the "Received" header and report to the email service provider. Once in a while I receive a response saying the case is properly handled. These providers are the on…
-
comment
Comment #47025012
> Is there good public discussion on root expiration? Haven't seen a specific one but I guess the most relavant public discussion on root CA-led device bricking issues might have o…
- story
-
comment
Comment #46213141
While the style and headline seems like Hacker News, the usernames seem increasingly alike Slashdot.
- story
-
comment
Comment #45528588
I'm worried about the situation when Dark Patterns are not widely recognized enough as a malicious practice for users. Half a month ago I see someone on Twitter defending its own p…
-
comment
Comment #43688149
Vercel has a fairly generous free quota and a non-negligible high pricing scheme - I think people still remember https://service-markup.vercel.app/ . For the crawl problem, I want …
-
comment
Comment #37545422
The reveal.js slide itself probably isn't the best way for readers. The reveal.js project actually provides a PDF export feature which can be more helpful. Anyway, it's an asahilin…
- story