Live data from Hacker News

Viewing profile — ylk

ylk

HN member
Joined
Thu, Aug 11, 2016, 10:40 AM UTC
HN karma
491
Public activity
132 items

About ylk

No profile information was provided.

Recent public activity

  1. story
  2. story
  3. comment
    Comment #48277161

    The URL was meant to be https://badhost.org , the site accidentally still has the old canonical meta tag.

  4. story
    BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass

    https://arstechnica.com/information-technology/2026/05/milli...

  5. comment
    Comment #48021457

    You're correct, thank you. Sadly I can't edit my comment anymore. Sorry for the confusion.

  6. comment
    Comment #48015020

    There are (illegal) marketplaces initial access brokers sell session cookies on. Some companies try to defend against that by e.g. checking whether it's even possible that you trav…

  7. comment
    Comment #48014233

    For reference, this is how Google says Chrome stores passwords encrypted in memory and uses an elevated service to prevent other processes from impersonating Chrome and gaining acc…

  8. comment
    Comment #47094853

    This is not how CVEs work at all. You can be pretty vague when registering it. In fact they’re usually annoyingly so and some companies are known for copy and pasting random text i…

  9. comment
    Comment #47046744

    > The baseband can do a lot, it has dma There's an IOMMU: > Is the baseband isolated? > Yes, the baseband is isolated on all of the officially supported devices. Memory access is p…

  10. comment
    Comment #45501024

    fwiw, they're using CVSSv3. In CVSSv4, it's probably an 8.7: https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L...

  11. comment
  12. comment
    Comment #45083479

    > Android 16 no longer provides device trees for Pixels as part of the Android Open Source Project. It's important to note it doesn't provide those for any other devices. There are…

  13. comment
    Comment #44909938

    The screen is a 16:10 screen with some extra pixels added next to the notch. By default, the system uses a resolution of 1512x982 (14"), which you can change to 1512x945 (16:10) to…

  14. comment
    Comment #44236350

    You don’t have to assume, the docs in the repo tell you that it does run a Linux kernel in each VM. It’s one container per VM.

  15. comment
    Comment #44173228

    Not trying to argue that this happens regularly, but some recent (last 6 months or so) minted update contained breaking changes.

  16. comment
    Comment #42710899

    > a feature that can only be appreciated by a subculture of people (privacy advocates) Just because it can’t be “appreciated” by all users doesn’t mean it’s only “for” a small sub-…

  17. comment
    Comment #42597491

    What you write sounds plausible at first, but then there’s this example from the German KSK: „In 2018, the German Federal Criminal Police Office uncovered a plot involving unknown …

  18. comment
    Comment #42551169

    It’s recommended to have at least two anyway, to still have access to your accounts in case one is lost. That means you can keep one key at your desktop and you’d only need to go u…

  19. comment
    Comment #42518663

    I agree that it's annoying that there's now a limit on the amount of credentials you can store on hardware keys. But while older Yubikeys only support 25 resident keys, models with…

  20. comment
    Comment #42518581

    Just use a password manager that doesn't sync by itself then https://keepassxc.org/docs/KeePassXC_UserGuide#_passkeys

  21. comment
    Comment #42448934

    I’m saying most people who do phishing likely don’t care to implement passkey detection to display a relevant error message to the user, as it’s not worth the effort, as of now

  22. comment
    Comment #42448930

    There are syncable and hardware-bound passkeys and you are free to use a password manager that syncs your passkeys. iPhones don’t even let you create a passkey with the built in pa…

  23. comment
    Comment #42446411

    Register a passkey on a different device or get a hardware key or whatever. Or call Microsoft support and complain to them. This doesn’t feeling like an honest discussion anymore.

  24. comment
    Comment #42446340

    Honestly don’t care to spend time on looking up the various states of 2fa proxies. But I’ve learnt so far that attackers don’t build/use the most advanced tooling you can think of …

  25. comment
    Comment #42445152

    Find your phone: https://www.icloud.com/find/ Scanning a QR code: https://support.apple.com/en-us/102680 The time investment could even be worth it, since "Signing in with a passke…