Viewing profile — ylk
ylk
HN member- Joined
- Thu, Aug 11, 2016, 10:40 AM UTC
- HN karma
- 491
- Public activity
- 132 items
- HN profile
- View on Hacker News ↗
About ylk
No profile information was provided.
Recent public activity
- story
- story
-
comment
Comment #48277161
The URL was meant to be https://badhost.org , the site accidentally still has the old canonical meta tag.
-
story
BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass
https://arstechnica.com/information-technology/2026/05/milli...
-
comment
Comment #48021457
You're correct, thank you. Sadly I can't edit my comment anymore. Sorry for the confusion.
-
comment
Comment #48015020
There are (illegal) marketplaces initial access brokers sell session cookies on. Some companies try to defend against that by e.g. checking whether it's even possible that you trav…
-
comment
Comment #48014233
For reference, this is how Google says Chrome stores passwords encrypted in memory and uses an elevated service to prevent other processes from impersonating Chrome and gaining acc…
-
comment
Comment #47094853
This is not how CVEs work at all. You can be pretty vague when registering it. In fact they’re usually annoyingly so and some companies are known for copy and pasting random text i…
-
comment
Comment #47046744
> The baseband can do a lot, it has dma There's an IOMMU: > Is the baseband isolated? > Yes, the baseband is isolated on all of the officially supported devices. Memory access is p…
-
comment
Comment #45501024
fwiw, they're using CVSSv3. In CVSSv4, it's probably an 8.7: https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L...
- comment
-
comment
Comment #45083479
> Android 16 no longer provides device trees for Pixels as part of the Android Open Source Project. It's important to note it doesn't provide those for any other devices. There are…
-
comment
Comment #44909938
The screen is a 16:10 screen with some extra pixels added next to the notch. By default, the system uses a resolution of 1512x982 (14"), which you can change to 1512x945 (16:10) to…
-
comment
Comment #44236350
You don’t have to assume, the docs in the repo tell you that it does run a Linux kernel in each VM. It’s one container per VM.
-
comment
Comment #44173228
Not trying to argue that this happens regularly, but some recent (last 6 months or so) minted update contained breaking changes.
-
comment
Comment #42710899
> a feature that can only be appreciated by a subculture of people (privacy advocates) Just because it can’t be “appreciated” by all users doesn’t mean it’s only “for” a small sub-…
-
comment
Comment #42597491
What you write sounds plausible at first, but then there’s this example from the German KSK: „In 2018, the German Federal Criminal Police Office uncovered a plot involving unknown …
-
comment
Comment #42551169
It’s recommended to have at least two anyway, to still have access to your accounts in case one is lost. That means you can keep one key at your desktop and you’d only need to go u…
-
comment
Comment #42518663
I agree that it's annoying that there's now a limit on the amount of credentials you can store on hardware keys. But while older Yubikeys only support 25 resident keys, models with…
-
comment
Comment #42518581
Just use a password manager that doesn't sync by itself then https://keepassxc.org/docs/KeePassXC_UserGuide#_passkeys
-
comment
Comment #42448934
I’m saying most people who do phishing likely don’t care to implement passkey detection to display a relevant error message to the user, as it’s not worth the effort, as of now
-
comment
Comment #42448930
There are syncable and hardware-bound passkeys and you are free to use a password manager that syncs your passkeys. iPhones don’t even let you create a passkey with the built in pa…
-
comment
Comment #42446411
Register a passkey on a different device or get a hardware key or whatever. Or call Microsoft support and complain to them. This doesn’t feeling like an honest discussion anymore.
-
comment
Comment #42446340
Honestly don’t care to spend time on looking up the various states of 2fa proxies. But I’ve learnt so far that attackers don’t build/use the most advanced tooling you can think of …
-
comment
Comment #42445152
Find your phone: https://www.icloud.com/find/ Scanning a QR code: https://support.apple.com/en-us/102680 The time investment could even be worth it, since "Signing in with a passke…