Viewing profile — raesene9
raesene9
HN member- Joined
- Wed, Mar 18, 2015, 7:38 PM UTC
- HN karma
- 6,167
- Public activity
- 1,593 items
- HN profile
- View on Hacker News ↗
About raesene9
Any opinions expressed are purely my own and not necessarily those of any employer, past, present, or future.
Personal Site - https://www.mccune.org.uk Blog - https://raesene.github.io Mastodon - @raesene@infosec.exchange Blue Sky - @mccune.org.uk
Recent public activity
-
comment
Comment #49173399
Same Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago , it turned out to be a marketing campaign, with U…
-
comment
Comment #49082185
So one of the factors in this is that Kubernetes disables the default seccomp policy provided by the container runtime, by default (you can re-enable it ofc, but you have to know t…
-
comment
Comment #49080517
Rootless helps, but less now that it used to (pre-2026). There have been a lot of local privilege escalation vulnerabilities in the Linux kernel (dirtyfrag, fragnesia, CIFSwitch et…
-
comment
Comment #49005109
They address that in the article :) to quote :- "So where's this huge price gap coming from? token pricing, prompt caching, and effort-per-task. On SWE for example, K3 works much h…
-
comment
Comment #49003917
As other have mentioned, and I'm the same. Leaving "Co-Authored by:" feels like open disclosure of how the project was created. That way if a consumer does not want to use LLM gene…
-
comment
Comment #48976273
Interesting write-up and I do think LLM assisted/powered exploit disclosure is a real concern (I've been able to get models to create container breakouts from Linux LPEs relatively…
-
comment
Comment #48891905
Future returns are never guaranteed but over the course of the orgs history (since 1965) they've done a fair bit better than the S&P 500.... https://www.visualcapitalist.com/warren…
-
comment
Comment #48891279
You might find some areas to criticize Berkshire Hathaway but I don't see being lazy as one of them. This is one of the most successful investment companies of all time and they go…
-
comment
Comment #48890691
I'd say for some sectors and users, we're already seeing that. After GLM-5.2's release there were quite a few stories about it picking up use. Then looking at Openrouter's stats we…
-
comment
Comment #48883348
It's an interesting thing and we can only speculate from the outside, but there's some obvious reasons why they'd literally hand out money in the form of free compute to people who…
-
comment
Comment #48883308
I think until they produce full financial information, which will happen I expect when their S-1 is published, we won't have a good picture on Anthropics true position. There's a l…
-
comment
Comment #48850937
Interesting write-up. Having been a bookkeeper a long time ago, I'm not too surprised at this being susceptible to automation by an LLM backed system. It seems also that the classe…
-
comment
Comment #48848910
If you're going to have "blessed" plugins, which seems like a good idea, you'll need a review and possibly hosting process. - Review to check that the plugin is reasonable quality/…
-
comment
Comment #48831376
It provides a right to privacy if the company allows personal messaging services on the device, but I don't think it provides a right to having personal messaging apps on the devic…
-
comment
Comment #48761186
I have a similar experience, for the last 5+ years I've worked in companies where very few of the people I work with are British which does require care on both language and idiom.…
-
comment
Comment #48758704
The later Opus models (4.7/4.8), Sonnet 5, and particularly Fable 5 will refuse to do tasks related to offensive security. One example I've hit is working on a benchmark of how wel…
-
comment
Comment #48699961
If you want to chat with Claude about this, I'd recommend using Opus 4.6. IME it's happy to talk about (and even write) PoC exploits
-
comment
Comment #48695826
Yep I've got one I built and it's absolutely fine for my use cases has a web interface/API custom kernels and rootfs, even the facility to set-up custom Kubernetes clusters. It's b…
-
comment
Comment #48566647
Well its document management feature didn't used to have Anti-Virus support which caused me a load of problems back in the 90's when Word Macro viruses were common. :P
-
comment
Comment #48566635
The original research for this is at https://soroush.me/downloadable/microsoft_iis_tilde_characte...
-
comment
Comment #48554354
Worth noting that, this isn't just a risk with npm or other package managers. If you're using LLM agents in the directory of a cloned repo, there's risks in skills, hooks etc autom…
-
comment
Comment #48551589
that probably depends on how much security and resource isolation you need. Multi-Tenant security in Kubernetes is not a simple thing, for a wide variety of reasons, and noisy neig…
-
comment
Comment #48425576
The one I remember most is, when experimenting with Opus 3.5 for the first time, I asked it to generate a Firecracker backed local VM creation and management tool, something I'd wa…
-
comment
Comment #48413810
not really, there are a number of security companies doing analysis of any new packages looking for supply chain attacks, so if you wait a couple of days, till their analysis is co…
-
comment
Comment #48398274
I think perhaps the reason you are seeing quite a few commenters expressing skepticism to your comment "You go to a university because you are deeply interested in understanding th…