HN user

denysvitali

6,426 karma

meet.hn/city/47.3744489,8.5410422/Zurich

Socials: - github.com/denysvitali - linkedin.com/in/denysvitali - t.me/denvit - https://blog.denv.it - x.com/DenysVitali

---

Posts164
Comments1,060
View on HN
www.saiflow.com 1d ago

The CCS2 Attack Surface on EV Chargers (SSH Root:Root)

denysvitali
4pts0
codex-resets.com 4d ago

Codex Resets

denysvitali
309pts200
twitter.com 9d ago

Grok CLI uploaded the whole home directory to GCS

denysvitali
439pts404
twitter.com 13d ago

GitHub Status – Let's put out an impact statement first

denysvitali
3pts0
twitter.com 14d ago

HPCs taken offline due to a serious security vulnerability

denysvitali
2pts3
github.com 14d ago

FlockCamRE – Reverse Engineering of Flock Cameras

denysvitali
2pts0
sec-consult.com 20d ago

Hands-Free Lockpicking: Critical Vulns in Dormakaba's Access Control System

denysvitali
1pts0
archive.org 22d ago

Lidl Self-Checkout SSD Image (GK Retail)

denysvitali
2pts0
sparr.substack.com 23d ago

An impossible first task at Google

denysvitali
4pts0
emma.egomnia.com 27d ago

The worst LLM: Emma-5

denysvitali
2pts0
github.com 29d ago

GPT-5.6 leaks in Codex PR

denysvitali
1pts0
postfinance.github.io 1mo ago

TOPF – Talos Orchestrator by PostFinance

denysvitali
1pts0
ps.tc 1mo ago

Usbliter8 – An A12/A13 SecureROM Exploit

denysvitali
3pts0
mll.sh 1mo ago

Humiliating IIS servers for fun and jail time

denysvitali
365pts98
www.proofpoint.com 1mo ago

UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency

denysvitali
3pts0
www.artofuki.com 1mo ago

The Meaning of Symbols

denysvitali
1pts1
github.com 1mo ago

Goose – Local Companion for WHOOP 5.0 built in <24h

denysvitali
8pts1
github.com 1mo ago

Bumblebee: R/O inventory collector for package, extension, and dev tool metadata

denysvitali
1pts0
blog.denv.it 1mo ago

I was likely targeted by DPRK in a sophisticated developer malware campaign

denysvitali
5pts0
blog.denv.it 2mo ago

Goodbye Travel Agents, Hello AI Agents

denysvitali
6pts0
noahclements.com 2mo ago

Welcome to Hell Developer

denysvitali
75pts33
www.1x.tech 2mo ago

Neo Factory – Building Your Neo

denysvitali
2pts0
www.figure.ai 2mo ago

Ramping Figure 03 Production

denysvitali
1pts0
www.rdw.nl 3mo ago

RDW Approval of Tesla FSD in Netherlands (With Rest of EU to Follow)

denysvitali
5pts1
twitter.com 3mo ago

Tesla FSD Supervised approved in Netherlands with more EU countries to follow

denysvitali
3pts0
www.youtube.com 3mo ago

Show HN: I'm a Happy Engineer [video]

denysvitali
3pts0
twitter.com 4mo ago

Final Testing Phase of Tesla FSD (Supervised) in EU

denysvitali
2pts1
twitter.com 4mo ago

GPT-5.4 Thinking and GPT-5.4 Pro

denysvitali
93pts2
www.stepsecurity.io 4mo ago

Hackerbot-Claw: An AI-Powered Bot Actively Exploiting GitHub Actions

denysvitali
4pts0
twitter.com 5mo ago

Claude Sonnet 4.6

denysvitali
2pts0

As someone who hosted it for a very long time - don't. Not worth the effort, it's a huge pain.

Great learning lesson, but very frustrating (IP reputation is everything, blocking spam is beyond hard)

I still don't understand why, for a blog, a static page isn't enough - especially since most of the WordPress issues are "solved" by adding caching.

I do understand it from an user perspective (it's easier to tell the average user to drag and drop rather than committing to a GitHub repo and letting hugo build the website), but from a security standpoint WordPress is really just waiting for a vulnerability (either in the core or on the thousands of plugins) in order to unlock its RCE-as-a-service functionality.

Codex Resets 4 days ago

FWIW, this was announced before the day where the +50% limit promotion from May was supposed to end, so effectively continuing the promotion. This will mean that you retain the same usage instead of seeing it drop.

I guess if they'd reduce the usage in their current stage they'll only lose customers - this is not a perk, it's damage control.

https://support.claude.com/en/articles/15910845-claude-code-...

I will never understand why SSH in such tools isn't native but always via some weird web UI...

I used to work for a company who allowed SSH only after jumping through Citrix => RDP => Putty => Jumphost => Target server.

Incredibly painful, also considering that each layer had a different keymap

There's a video [1] from the "hacker" sending the message. The hacker allegedly [2] stole the VPN credentials (of an employee and two colleagues, because they were doing credentials sharing apparently) from a personal computer ("RGB gaming PC") running Windows 7 (EOL), w/o antivirus and reportedly having search for Windows activators for Windows 10 and Office 2019. Cherry on top: the malware seems to have dropped via a malicious game install. Lol

Ironically he recorded the video with CapCut, showing his ID, which also revealed their profile picture and identity [2]...

If all of this is true, we're lucky they "only" paged the whole country instead of doing something even more harmful. This is some crazy level of incompetence / lack of security.

[1] https://x.com/i/status/2068482069643071749

[2] https://x.com/i/status/2068633434591830290

[3] https://x.com/i/status/2068488298998231117

So this seems to be M2M tokens - what about the, arguably more common, use case of creating a short lived or simply ephemeral token to allow an AI agent to use a service (e.g: GitHub) without the possibility to have it leak a valid upstream token in a commit message?

My solution to this particular problem is gh-proxy - but of course GitHub is only one of the 100s of services that one might want this for.

https://github.com/denysvitali/gh-proxy

Btw, I love Ory and I'm always amazed by your new releases!

Agentic Mfw 2 months ago

<3

I know. It's very difficult nowadays to build a simple HTML page without throwing 15 frameworks in it

Not necessarily for the "without sharing" part, but to increase the reliability of the jailbreak. The same prompt isn't guaranteed to return the same result, but combining the internal thinking with the prompt might be a more effective way