Viewing profile — vin10
vin10
HN member- Joined
- Mon, Sep 11, 2023, 9:58 AM UTC
- HN karma
- 337
- Public activity
- 23 items
- HN profile
- View on Hacker News ↗
About vin10
Recent public activity
-
comment
Comment #48119219
There should be a metric for sites hosting malicious content! https[:]//erasmus-plus.ec.europa.eu/sites/default/files/2026-05/mortal-kombat-2-cs.pdf
-
comment
Comment #46330729
it's a (then-)safe default from the age when having 1GB of RAM and 2GB of swap was the norm: https://linux-kernel.vger.kernel.narkive.com/U64kKQbW/should...
-
comment
Comment #46330585
> he way stuff fails when it runs out of memory is really confusing have you checked what your `vm.overcommit_ratio` is? If its curious what kind of failures you are alluding to.
-
comment
Comment #46330561
For anyone feeling brave enough to disable overcommit after reading this, be mindful that default `vm.overcommit_ratio` is 50% which means that if no swap is available, on a system…
- comment
-
comment
Comment #44126242
Nice usability features definitely. Apart from that how would you say it compares against something like sysdig falco / cilium + tetragon? Apart from this a major issue is DNS base…
-
comment
Comment #43927811
Interesting project, I think I just found a way to crash the sandbox, just reported via an advisory.
-
comment
Comment #43904323
I would have expected at least Virustotal to flag them if that were the case. It does more than just looking up in a database of known malicious URLs and I think the reputation of …
-
comment
Comment #43897580
It is the same for nested links as well. They mostly have a chain of links, each one taking you to a new one with hop count ranging anywhere from 5 up to 10 or more.
- story
-
comment
Comment #41072790
> If you wouldn't trust running it on your host, you probably shouldn't run it in a container as well. - From a Docker/Moby Maintainer
- story
-
comment
Comment #40444834
It is guarded by a warning and requires explicit approval similar to browsers but yes, it does broaden the attack surface: https://gitlab.com/gnachman/iterm2/-/commit/fc9ae5c90f53c…
-
comment
Comment #40437497
It is the first one, they need to be printed and clicked.
- story
- comment
- story
- comment
-
comment
Comment #39634268
This is a very well formulated suggestion. Nicely written!
-
comment
Comment #39633742
You are right about short expiry times but another catch here is that if pre-signed URLs are being leaked in an automated fashion, these services also keep the downloaded content f…
- story
-
comment
Comment #38761436
OP here. Another interesting attack vector I have been working on is OSC 8 for hyperlink support in terminals. Mostly they allow arbitrary url schemes including "ssh://" without an…
- story