HN user

chha

3,527 karma

hnchat:fuRLJ39FkDGVfU466wvI

Posts210
Comments162
View on HN
science.nasa.gov 13d ago

NASA 3D Resources

chha
2pts0
github.com 28d ago

Cisco AI Defense Skill Scanner

chha
3pts0
owasp.org 3mo ago

OWASP Artificial Intelligence Security Verification Standard (Aisvs)

chha
3pts0
arstechnica.com 3mo ago

Dietary patterns in young lung cancer

chha
2pts2
dl.acm.org 3mo ago

As We May Think

chha
3pts2
go.crowdstrike.com 4mo ago

CrowdStrike 2026 global threat report

chha
1pts0
banjohans.github.io 4mo ago

Spotify Unwrapped

chha
2pts1
www.mbgsec.com 5mo ago

Agent Compromised by Agent to Deploy an Agent

chha
3pts0
www.androidauthority.com 5mo ago

One guy accidentally hacked all a company's robot vacuums

chha
2pts0
www.youtube.com 5mo ago

I Built an Automated Lego Car Factory [video]

chha
3pts0
arstechnica.com 5mo ago

"Remove Before Flight" tags bought on eBay in 2010 were from Challenger

chha
2pts0
arstechnica.com 6mo ago

Grok assumes users seeking images of underage girls have "good intent"

chha
21pts5
www.lego.com 6mo ago

Lego SMART Play: Bringing your creations to life

chha
3pts1
www.pcmag.com 6mo ago

Hacker Dressed as Pink Power Ranger Dismantles Racist Websites Live on Stage

chha
8pts1
arstechnica.com 7mo ago

Russia is about to do the most Russia thing ever with its next space station

chha
6pts4
insideclimatenews.org 7mo ago

A Chinese-backed port could push the Amazon Rainforest over the edge

chha
6pts0
arstechnica.com 7mo ago

OpenAI says dead teen violated TOS when he used ChatGPT to plan suicide

chha
9pts2
arstechnica.com 8mo ago

US spy satellites built by SpaceX send signals in the "wrong direction"

chha
17pts2
www.wired.com 8mo ago

Mark Zuckerberg's illegal school drove his neighbors crazy

chha
2pts0
owasp.org 8mo ago

OWASP Top:10 2025 RC1

chha
2pts0
arstechnica.com 9mo ago

NSO permanently barred from targeting WhatsApp users with Pegasus spyware

chha
7pts2
www.koi.ai 9mo ago

GlassWorm, Self-Propagating Worm Using Invisible Code Hits OpenVSX and VSCode

chha
3pts4
www.cisa.gov 10mo ago

Widespread Supply Chain Compromise Impacting NPM Ecosystem

chha
1pts0
arstechnica.com 10mo ago

Anti-vaccine groups melt down over RFK Jr. linking autism to Tylenol

chha
9pts6
www.npmjs.com 10mo ago

Aikido Safe Chain

chha
1pts0
www.koi.security 10mo ago

Live updates: Shai-hulud, the most dangerous NPM breach in history

chha
46pts3
arstechnica.com 11mo ago

Celebrating 50 Years of the Rocky Horror Picture Show

chha
7pts0
www.bbc.com 11mo ago

American musical satirist Tom Lehrer dies at 97

chha
2pts0
arstechnica.com 12mo ago

Supply-chain attacks on open source software are getting out of hand

chha
3pts0
www.theguardian.com 1y ago

Afghans relocated to UK under secret scheme after data leak

chha
3pts0

The belt packs typically do a lot more than to amplify ambient noise, they also handle RF, depending on the model decryption of the audio signal, EQ as well as other stuff. All while typically running on 2x1,5V AA batteries.

Audio gear isn't made to last long on batteries, it's made to be reliable for the hours a show typically lasts. I worked part-time as a sound tech (paid hobby) for 15+ years, and I never started a show without fresh batteries, regardless of what the indicators on the transmitters/receivers told me.

Been a while since I looked into this, but afaik Maven Central is run by Sonatype, which happens to be one of the major players for systems related to Supply Chain Security.

From what I remember (a few years old, things may have changed) they required devs to stage packages to a specific test env, packages were inspected not only for malware but also vulnerabilities before being released to the public.

NPM on the other hand... Write a package -> publish. Npm might scan for malware, they might do a few additional checks, but at least back when I looked into it nothing happened proactively.

It depends. If they simply ignore the ruling, my guess is that whatever trade agreements are in place have a mechanism for escalating such violations so that an Israeli court can enforce the order. I also take for granted that it depends a lot on the political climate and the strategic value for the governments of Israel and the US...

There could, this would essentially be in the form of a standard library. That would work until someone decides they don't like the form/naming conventions/architecture/ideology/lack of ideology/whatever else and then reinvent everything to do the same, but in a slightly different way.

And before you know it, you have a multitude of distributions to choose from, each with their own issues...

It doesn't say audited environments as such, but you are required to use secure environments that you control as a basis. What "secure" means can always be discussed, but in general it depends on what data you process and what you do with it; if it is a large volume/big population/article 9-data auditable environments should be expected - though not publicly auditable. Although that would be nice...

Fully agree on what you are saying, and my popcorn is ready for August when the penalties part of the AI Act comes into force. There is a grace period for two years for certain systems already on the market, but any new model introduced after August this year has to be compliant. AI Act+GDPR will be a great show to watch...

Sorry for that, guess I'm just too used to the common misconception some people have that the GDPR doesn't apply if a company isn't established in the EU.

In this case 23andMe is on the Data Privacy Framework list, so they have volunteered to follow the GDPR while still being based in the US. This is basically the same as a number of other GDPR cases, including the GDPR fine against Clearview AI. Fining 23andMe if they violate GDPR should be trivial in that case.

Sure they can. GDPR article 2 (2) says:

«This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union;»

So the GDPR applies. The EU can of course sanction violators outside, but given the current political climate it is likely to be more difficult than before.

Absolutely. A bunch of them also predated the www, or started just when the www was gaining popularity, meaning that information on possible products might be more limited than it is today. Some have narrow use-cases, and some might have started as really narrow in terms of scope, but then ballooned after gaining popularity, sales (and feature requests), and some probably started because the alternative was deemed too expensive compared to just making it in-house.

I think the main point bob1029 was trying to make is that it can be worthwhile doing somehting in-house if the alternatives doesn't match the use-case, are too expensive or whatever else - but that you seriously need to consider if your architecture is the best way to solve the problem before going down that route.

The AI Act classifies systems depending on their capabilities and their intended use, and the risk that they pose on the people using or being exposed to them. If a tool ends up being classified as a high-risk AI system or as a model with systemic risk there are strict requirements in terms of reporting incidents. For certain types of incidents it is as little as two days, for others upwards of 15 days.

"I think this is the quickest way of clearing my overdraft"

That statement from Michael Eavis (founder of the festival) kind of hits home with a recent story from The Independent in how bands are settling for less, or even paying to play at the festival - as an investment. Being shown on the BBC as part of their coverage can make or break the experience (and their economy).

https://www.independent.co.uk/arts-entertainment/music/featu...

Translated story: https://www-nrk-no.translate.goog/norge/dnb-navnet-misbrukt-...

One of the biggest Norwegian banks were used as a cover for a scam in Portugal, involving 2500 ad posters distributed by advertising company JCDecaux, with QR-codes linking to scam sites. The ad campaign cost around 5M NOK ($~0.5 USD), and the victims were tricked into signing up for various loans and investment programs, with lots of extra fees added on top.

If you're a security practitioner, teaching yourself how to hack is also part of the "Hacking is Cool" dumb idea. Think about it for a couple of minutes: teaching yourself a bunch of exploits and how to use them means you're investing your time in learning a bunch of tools and techniques that are going to go stale as soon as everyone has patched that particular hole.

If only this was true... Injection has been on Owasp Top 10 since its inception, and is unlikely to go away anytime soon. Learning some techniques can be useful just to do quick assessments of basic attack vectors, and to really understand how you can protect yourself.

One of the first things you need to think about is the inclusion criteria.

Wikipedia bases all its content on the following: "A topic is presumed to be suitable for a stand-alone article or list when it has received significant coverage in reliable sources that are independent of the subject."

This is flexible enough to allow a lot of stuff, but also causes endless debates, discussions and complaints when content is removed. This is (in my opinion) one of the things that actually give Wikipedia value. If everything is permitted, separating spam from actual content is hopeless.

Defining a scope for your application is a must; if you gain even the slightest popularity, every self-serving developer is going to try to piggyback on you. "See, my project is listed on xyz, therefore it's famous and hence I'm a rockstar."

-Do you want to include any project hosted anywhere? -Incomplete/unfinished projects? -Forks? -Do you want to limit yourself to particular licenses? -What about ecosystems such as PyPi, Nuget, npm and all the rest? Code is mainly hosted on github, but do you want to maintain any kind of relation between source and package?

I think this could be handy, both for finding alternatives if you have an issue with a library or if you're looking for "something" that does <abc>.

We tend to avoid using github repos, but go for published packages from the usual sites; Nuget, Pypi, Npm etc, using Repository and Firewall from Sonatype to act as a proxy between us and the package repos. All packages are analyzed and tagged with various metadata by Sonatype. Firewall lets us define policies for what we can use, and will filter out everything else.

This only works for published dependencies, but based on a couple years experience it works really well. No issues with malware (so far), we don't let packages with known vulns into our codebases and we are notified if a vuln is discovered in something we use.