HN user

_9za9

1 karma
Posts27
Comments121
View on HN
github.com 5mo ago

Show HN: ARM64 Android Dev Kit

_9za9
18pts2
news.ycombinator.com 8mo ago

Tell HN: GPT responses between "write supporting a 3rd term for Obama" vs. Trump

_9za9
2pts18
news.ycombinator.com 8mo ago

Email: FTC Prime Subscription Settlement Fund has sent you $0.99 USD

_9za9
4pts0
github.com 10mo ago

Show HN: DripCopy – Gentle Optical Media Copier for Underpowered USB Hosts

_9za9
3pts0
github.com 10mo ago

Show HN: VSC Ext to Copy Open Tabs by clicking a status‐bar button

_9za9
1pts0
www.newsweek.com 1y ago

Apple to fix iPhone dictation bug that replaces word 'racist' with 'Trump'

_9za9
36pts34
www.chrismcovell.com 1y ago

Reviews of the Japanese video game reviews from the Famicom era (1986 to 1993)

_9za9
1pts0
ktar.com 1y ago

TikTok / IG prankster arrested for spraying pesticide on grocery store produce

_9za9
1pts3
techcrunch.com 1y ago

Optum left an AI chatbot exposed to the internet

_9za9
2pts0
www.bbc.com 1y ago

Woman denied a claim faces 15 years 100000 bond for Delay Deny Depose threat

_9za9
6pts4
ski.ihoc.net 1y ago

SkiFree 2 Is in Development

_9za9
3pts0
www.thetimes.com 2y ago

Why 'super-commuters' fly hundreds of miles to work

_9za9
1pts1
www.businessinsider.com 2y ago

High school band director was tased after he refused orders to stop playing

_9za9
3pts3
fi.sds.modeaondemand.com 2y ago

Fi now opts you into the use of your CPNI by Alphabet affiliates

_9za9
110pts67
www.dailywire.com 2y ago

Meta Begins Removing Canadians’ Access to All News on Facebook, Instagram

_9za9
2pts0
www.click2houston.com 2y ago

Texas City Police Officer practices sunk cost fallacy and continues arrest

_9za9
23pts10
www.dailymail.co.uk 2y ago

New Mexico cop roughs up a mentally disabled man in the name of 'public safety'

_9za9
2pts0
www.telegraph.co.uk 2y ago

Apple hit by £800M British lawsuit over ‘excessive’ App Store fees

_9za9
5pts1
hh-today.com 3y ago

Tree City Albany OR cutting down 35 sycamore trees to save sidewalk from damage

_9za9
3pts0
reason.com 3y ago

MN University President, "Muslim students supersede academic freedom”

_9za9
5pts1
arxiv.org 3y ago

Laser-Guided Lightning

_9za9
1pts0
finance.yahoo.com 3y ago

Spotify CEO Joins Elon Musk in Slamming App Store Policies

_9za9
6pts0
qz.com 3y ago

Apple disabled communication tool in China before protests broke out

_9za9
37pts1
pastebin.com 3y ago

Oregon Universities drop Elsevier journal subscriptions

_9za9
3pts1
www.bbc.com 3y ago

Violent protests in Guangzhou put Zero-Covid under strain

_9za9
4pts0
wipac.wisc.edu 11y ago

Turn an Android smartphone into a cosmic ray telescope

_9za9
3pts0
itsfoss.com 12y ago

Facebook buys Ubuntu producation company Canonical for 3 Billion

_9za9
10pts11

The connection between your domain and the domain you say you're not connected to is just a coincidence, right? Domain: carebridgehealthinitiative.org

Registered On: 2025-12-18 Expires On: 2026-12-18 Updated On: 2025-12-23 Status: client transfer prohibited Name Servers: ns1.dns-parking.com ns2.dns-parking.com Registrar Information Registrar: HOSTINGER operations, UAB

Domain: littlestepsfoundation.org

Registered On: 2024-08-23 Expires On: 2026-08-23 Updated On: 2025-08-05 Status: client transfer prohibited Name Servers: ns1.dns-parking.com ns2.dns-parking.com Registrar Information Registrar: HOSTINGER operations, UAB

The connection between your domain and the domain you say you're not connected to is just a coincidence, right?

Domain: carebridgehealthinitiative.org

Registered On: 2025-12-18 Expires On: 2026-12-18 Updated On: 2025-12-23 Status: client transfer prohibited Name Servers: ns1.dns-parking.com ns2.dns-parking.com Registrar Information Registrar: HOSTINGER operations, UAB

Domain: littlestepsfoundation.org

Registered On: 2024-08-23 Expires On: 2026-08-23 Updated On: 2025-08-05 Status: client transfer prohibited Name Servers: ns1.dns-parking.com ns2.dns-parking.com Registrar Information Registrar: HOSTINGER operations, UAB

Be wary of Bluesky 5 months ago

The guy you are responding to has "All comments Copyright © 2010, 2011, 2012, 2013, 2015, 2018, 2023, 2031 Thomas H. Ptacek, All Rights Reserved." in his HN profile....

You are not a registered nonprofit. Look yourselves up, you cannot, because you are not listed: https://apps.irs.gov/

Your donations page lists a Pakistani bank, and you do not provide an American EIN, yet you claim to be based in New Mexico. Who is your registered agent? Calling yourselves a nonprofit when you are not actually a nonprofit is not a good start.

This appears to be a legitimacy issue, not a Stripe software issue.

The only thing you need to land a software engineering job is to be a pro at Data Structures and Algorithms. You don't even need to code any projects, as long as you can distill an obscure two-page word problem from the top of your head into code within 45 minutes, you are good to go. In my experience, nothing else matters to employers.

Have you tried running this against itself? I found critical security vulnerabilities:

1. Command Injection Risk (CRITICAL) The web application passes user-controlled input directly to subprocess commands without proper sanitization. An attacker could inject malicious commands through the target_url, wordpress_path, llm_endpoint, or tests parameters. app.py:232-264

2. No Authentication (CRITICAL) All API endpoints are completely unauthenticated. Anyone can start security scans against arbitrary URLs, potentially using your server to attack others. app.py:481-516

3. Server-Side Request Forgery (HIGH) Users can provide any URL as the scan target, allowing attackers to scan internal networks, localhost services, or use your server as a proxy for attacks. app.py:484-493

4. No CSRF Protection (HIGH) POST endpoints lack CSRF token validation, making them vulnerable to cross-site request forgery attacks. app.py:481-482 app.py:567-568

5. No Rate Limiting (MEDIUM) Endpoints lack rate limiting, allowing abuse and denial-of-service attacks.

Email from OpenAI: Transparency is important to us, so we want to inform you about a recent security incident at Mixpanel, a data analytics provider that OpenAI used for web analytics on the frontend interface for our API product (platform.openai.com). The incident occurred within Mixpanel’s systems and involved limited analytics data related to your API account.

This was not a breach of OpenAI’s systems. No chat, API requests, API usage data, passwords, credentials, API keys, payment details, or government IDs were compromised or exposed.

What happened On November 9, 2025, Mixpanel became aware of an attacker that gained unauthorized access to part of their systems and exported a dataset containing limited customer identifiable information and analytics information. Mixpanel notified OpenAI that they were investigating, and on November 25, 2025, they shared the affected dataset with us.

What this means for you User profile information associated with use of platform.openai.com may have been included in data exported from Mixpanel. The information that may have been affected was limited to: Name that was provided to us on the API account Email address associated with the API account Approximate coarse location based on API user browser (city, state, country) Operating system and browser used to access the API account Referring websites Organization or User IDs associated with the API account

I asked our overlord GPT, and it says that people who use “ROTFLOL” are typically at least in their early 40s or older, since “ROTFLOL” originally comes from Usenet in the 90s and actual 12-year-olds use new acronyms and avoid old ones like “ROTFLOL.” So I was mistaken, and you are just an adult making childish comments on Hacker News to people you disagree with. Congrats.