Live data from Hacker News

Viewing profile — raesene9

raesene9

HN member
Joined
Wed, Mar 18, 2015, 7:38 PM UTC
HN karma
6,167
Public activity
1,593 items

About raesene9

[ my public key: https://keybase.io/raesene; my proof: https://keybase.io/raesene/sigs/UfV9QKNwlG--NbKX9kE5NvJhPFfxDaP5xRnn8ES-9oI ]

Any opinions expressed are purely my own and not necessarily those of any employer, past, present, or future.

Personal Site - https://www.mccune.org.uk Blog - https://raesene.github.io Mastodon - @raesene@infosec.exchange Blue Sky - @mccune.org.uk

Recent public activity

  1. comment
    Comment #49173399

    Same Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago , it turned out to be a marketing campaign, with U…

  2. comment
    Comment #49082185

    So one of the factors in this is that Kubernetes disables the default seccomp policy provided by the container runtime, by default (you can re-enable it ofc, but you have to know t…

  3. comment
    Comment #49080517

    Rootless helps, but less now that it used to (pre-2026). There have been a lot of local privilege escalation vulnerabilities in the Linux kernel (dirtyfrag, fragnesia, CIFSwitch et…

  4. comment
    Comment #49005109

    They address that in the article :) to quote :- "So where's this huge price gap coming from? token pricing, prompt caching, and effort-per-task. On SWE for example, K3 works much h…

  5. comment
    Comment #49003917

    As other have mentioned, and I'm the same. Leaving "Co-Authored by:" feels like open disclosure of how the project was created. That way if a consumer does not want to use LLM gene…

  6. comment
    Comment #48976273

    Interesting write-up and I do think LLM assisted/powered exploit disclosure is a real concern (I've been able to get models to create container breakouts from Linux LPEs relatively…

  7. comment
    Comment #48891905

    Future returns are never guaranteed but over the course of the orgs history (since 1965) they've done a fair bit better than the S&P 500.... https://www.visualcapitalist.com/warren…

  8. comment
    Comment #48891279

    You might find some areas to criticize Berkshire Hathaway but I don't see being lazy as one of them. This is one of the most successful investment companies of all time and they go…

  9. comment
    Comment #48890691

    I'd say for some sectors and users, we're already seeing that. After GLM-5.2's release there were quite a few stories about it picking up use. Then looking at Openrouter's stats we…

  10. comment
    Comment #48883348

    It's an interesting thing and we can only speculate from the outside, but there's some obvious reasons why they'd literally hand out money in the form of free compute to people who…

  11. comment
    Comment #48883308

    I think until they produce full financial information, which will happen I expect when their S-1 is published, we won't have a good picture on Anthropics true position. There's a l…

  12. comment
    Comment #48850937

    Interesting write-up. Having been a bookkeeper a long time ago, I'm not too surprised at this being susceptible to automation by an LLM backed system. It seems also that the classe…

  13. comment
    Comment #48848910

    If you're going to have "blessed" plugins, which seems like a good idea, you'll need a review and possibly hosting process. - Review to check that the plugin is reasonable quality/…

  14. comment
    Comment #48831376

    It provides a right to privacy if the company allows personal messaging services on the device, but I don't think it provides a right to having personal messaging apps on the devic…

  15. comment
    Comment #48761186

    I have a similar experience, for the last 5+ years I've worked in companies where very few of the people I work with are British which does require care on both language and idiom.…

  16. comment
    Comment #48758704

    The later Opus models (4.7/4.8), Sonnet 5, and particularly Fable 5 will refuse to do tasks related to offensive security. One example I've hit is working on a benchmark of how wel…

  17. comment
    Comment #48699961

    If you want to chat with Claude about this, I'd recommend using Opus 4.6. IME it's happy to talk about (and even write) PoC exploits

  18. comment
    Comment #48695826

    Yep I've got one I built and it's absolutely fine for my use cases has a web interface/API custom kernels and rootfs, even the facility to set-up custom Kubernetes clusters. It's b…

  19. comment
    Comment #48566647

    Well its document management feature didn't used to have Anti-Virus support which caused me a load of problems back in the 90's when Word Macro viruses were common. :P

  20. comment
    Comment #48566635

    The original research for this is at https://soroush.me/downloadable/microsoft_iis_tilde_characte...

  21. comment
    Comment #48554354

    Worth noting that, this isn't just a risk with npm or other package managers. If you're using LLM agents in the directory of a cloned repo, there's risks in skills, hooks etc autom…

  22. comment
    Comment #48551589

    that probably depends on how much security and resource isolation you need. Multi-Tenant security in Kubernetes is not a simple thing, for a wide variety of reasons, and noisy neig…

  23. comment
    Comment #48425576

    The one I remember most is, when experimenting with Opus 3.5 for the first time, I asked it to generate a Firecracker backed local VM creation and management tool, something I'd wa…

  24. comment
    Comment #48413810

    not really, there are a number of security companies doing analysis of any new packages looking for supply chain attacks, so if you wait a couple of days, till their analysis is co…

  25. comment
    Comment #48398274

    I think perhaps the reason you are seeing quite a few commenters expressing skepticism to your comment "You go to a university because you are deeply interested in understanding th…