Live data from Hacker News

Anonymous GitHub account mass-dropping undisclosed 0-days

github.com

291–300 of 407 posts

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#291

Earlier quoted context omitted.

I used to be an em-dash user, but now my opinion is that I’d rather be perceived as someone who does not want to be confused with an LLM. So I’ve changed my writing style.

My feeling is that my writing doesn't sound anything like an LLM, so if someone thinks I'm an LLM because I used an em-dash, that's on them. That, or I royally screwed up and need to do a better job as a writer. At least with today's LLMs.

> if someone thinks I'm an LLM because I used an em-dash, that's on them.

I'll go a step further: I think I'd rather actively filter out people whose AI detection is that naïve.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#292

Earlier quoted context omitted.

Do you have a definition of "smart" such that there is something an AI could do to prove itself intelligent? Or are you just defining "fast" as something only horses can do, and considering that a useful insight about cars?

A future AI may be intelligent, but LLMs are clearly not. They have no agency, no ability to reason, and no world model. The most effective way to use them is to treat them as next token prediction machines, because that’s what they are. edit: downvotes but no rebuttals. feel free to show me where the agency, reasoning from first principles, world model etc exists. or you can ask an llm and they'll tell you they don'…

[flagged]

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#293
post #54
post #40

0-days-vibes-vulns ? There should be a new category, for spotting and handling the em-dashes of this brave new world of vulns and making the old fossils like me only picking my head up for the old painfully still hand-crafted artisanal ones instead. A kind of label, like free-range for eggs, in sum.

Yes, big pet peeve of the new world. Every em dash is apparently an AI trigger. Back in my day, they were a sign of great respect within my people.

I'm still waiting for the interrabang to become compromised as well. They've already taken my em dash, and my use of the Oxford command, apparently, is an insant flag.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#294
post #231

Do NOT, under any circumstances, use any material in this repository maliciously. This is good-faith, open-disclosure vulnerability research intended to get more people interested in exploring this area of cybersecurity. Reminds of the message in the The Anarchist Cookbook before one the recipes that essentially said: "This is really dangerous, don't ever do it, here is how you do it."

The old book didn't say "... maliciously." though?

Of course not. You can melt things w thermite without being malicious. Like my friend's toolbox for instance.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#295

Earlier quoted context omitted.

And my point is that sexual abuse is a subcategory of abuse. You didn't imply until now that I was wrong about animal abuse already being illegal. In that case, a bestiality law doesn't fix the actual problem, right? It's a band-aid partial fix.

I'm not sure what your point is, to be blunt. It seems like you wanted to make some weird argument about the semantics of the word "abuse", and are now implying one of: 1) Beastiality isn't sexual abuse 2) Beastiality laws are pointless because it was already illegal under existing abuse laws (it wasn't, as we've repeatedly discussed) 3) Sexual abuse requires physical harm all of which are pretty gross (1,3) and/or p…

You got 2 wrong. It's: 2) If the existing abuse law doesn't include sexual abuse, we need to fix that law, not add a new one.

And that's not a pointless argument. If we're still allowing the whole category of non-physical abuse to animals, except for bestiality, that's a terrible job of lawmaking.

And just on a tangent here now that I'm reading the law they added, does it really make sense to have a blanket exemption for "accepted animal husbandry practices"? Some of those procedures are just as exploitative and unnecessary. It makes me think this law isn't putting animal welfare first.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#296
PHP one appears to be a convoluted way of executing arbitrary code on a local server conditioned on the ability of already executing arbitrary PHP code. In other words, not a security issue at all. The cookie parsing issue might be a bug with security implications if you talk to hostile SOAP servers (didn't look deeper into it but it's plausible) but I can't see how it can be effectively exploited without having a level of access on the target server which makes the whole exploiting question moot.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#297

Earlier quoted context omitted.

Keyboard layout specific. Macs with their default English layout use “option-shift-dash” which is really easy to remember (and relatively discoverable, as such things go) which is why using proper m-dashes (not just double-dashes) used to be a strong indicator a poster was using a Mac, before LLMs took the character over. On iOS you type it by pressing dash and holding until alternative options come up, same way you…

Macs have two possible ways. If you have key repeat enabled, option+shift+dash. Some newer Mac users may have the mode on where holding a key pops up an iOS-style bubble of alternate options, in which case they will just hold hyphen.

That "new" feature has been around since at least 2011.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#298

Earlier quoted context omitted.

Such claims can both be true and pointless. For those of us who have to decide what actions to take, there is a point in differentiating between bugs and vulnerabilities, and breathlessly proclaiming "we found a vulnerability but we don't have an exploitation vector or proof that there's a meaningful security consequence" is annoying and likely to get the proclaimer ignored in the future.

The context in which that statement was made, and in which I’m repeating it, I think, is just to say that any bug has the potential to be used maliciously. Ignore it, fine, but also don’t overreact to the intended message…

Phrased this way, nothing changes: both true and irrelevant. In other words, any action taken in response to this message is an overreaction. It's just noise.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#299

Looks like a bunch of re worded copies of existing CVE and a few new lower severity things. I only call them low sev because they seem to require the user to do things that are already inherently dangerous. Just my 2 cents from a quick scan. Edit: To be clear still interesting finds. I think with some chaining some of them might be more severe. Like the ovpn one and windows potentially registering vpn app as default…

Yea, that's what's confusing. some of these are like lower level slop but some are like genuine criticals. Floci, libssh2, c-ares, FFmpeg, and the PHP one are all LEGIT./ The Ghidra one for example, not so much. I cant help but wonder if this was halfway completed research folder and they just published it as is

PHP one is at best a moderate-level bug in SOAP client which I don't see any realistic way to exploit (the whole convoluted setup in the POC assumes PHP execution access, which begs the question why bother if you already can execute arbitrary code?) - does not look like "genuine critical" at all.

Re: Anonymous GitHub account mass-dropping undisclosed 0-days

#300

we have got to stop putting our bank accounts and SSNs on computers

Your SSN had been already stolen in the Equifax breach - unless you're so young or recently arrived that you haven't had SSN by then, in which case it had been stolen in one of a dozens of the breaches since then. And if somehow you avoided all that, it will be stolen in the inevitable next breach, which would happen regardless of what you do.
Post reply on HN