HN user

guessmyname

7,929 karma
Posts404
Comments934
View on HN
git.projectnightcrawler.dev 8d ago

NightmareEclipse (LegacyHive) Windows UserProfil service arbitrary hive load EoP

guessmyname
2pts0
ecs-friday.com 8d ago

Microsoft Experimentation and Configuration Service (ECS) Chatbot

guessmyname
1pts0
github.com 19d ago

Go (golang) Report Card project/service was archived on Jul 1, 2026

guessmyname
2pts0
autobops-dashboard.azurewebsites.net 22d ago

Real-time Exchange and Office pipeline health, SLAs, incidents, and builds

guessmyname
3pts0
github.com 1mo ago

Visa Vulnerability Agentic Harness for Project Glasswing

guessmyname
3pts0
learn.microsoft.com 1mo ago

July 13, 2026 Certificate update for Microsoft 365 apps on macOS/iOS devices

guessmyname
1pts0
deadeclipse666.blogspot.com 1mo ago

Nightmare Eclipse: RoguePlanet Windows Defender race condition to SYSTEM shell

guessmyname
4pts0
www.404media.co 1mo ago

Microsoft Hacked to Deliver Malware to Claude and Gemini Users

guessmyname
19pts0
www.rootshell.com 1mo ago

rootshell: macOS terminal emulator built with libghostty with powerful features

guessmyname
3pts0
leontrolski.github.io 1mo ago

[hand-drawn] recipes for laid-back engineers

guessmyname
3pts0
haveibeenpwned.com 2mo ago

Have I Been Pwned: Colombian fintech company leaks 34.5M accounts in March 2026

guessmyname
4pts0
en.wikipedia.org 3mo ago

生き甲斐 (ikigai) “a reason for being”

guessmyname
3pts0
spectrum.ieee.org 3mo ago

HIPPO Turns One Master Password Into Many Without Storing Any

guessmyname
2pts1
fortune.com 3mo ago

Anthropic left details of an unreleased model sitting in an unsecured data trove

guessmyname
3pts0
issuetracker.google.com 4mo ago

Big Sleep Tracker: Google Project Zero + Google DeepMind find security bugs

guessmyname
2pts0
vibe-radar-ten.vercel.app 4mo ago

Vibe Security Radar – Tracking the security cost of vibe coding

guessmyname
1pts1
github.com 6mo ago

Fix macOS 26 (Tahoe) exaggerated rounded corners

guessmyname
56pts42
cdn-dynmedia-1.microsoft.com 1y ago

Microsoft Secure Future Initiative September 2024 Progress Report [pdf]

guessmyname
1pts0
www.microsoft.com 2y ago

Midnight Blizzard: Guidance for responders on nation-state attack

guessmyname
2pts0
en.wikipedia.org 2y ago

Kei-jidōsha, smallest category of expressway-legal, light motor vehicles, Japan

guessmyname
3pts0
drogon.org 2y ago

Drogon, the fast C++ web framework (with C++14/17)

guessmyname
2pts0
www.soma-zone.com 2y ago

GoToFile is a fast, flexible and accurate utility to find files+folders on macOS

guessmyname
7pts1
www.microsoft.com 2y ago

Microsoft AI Bounty Program

guessmyname
2pts0
github.com 2y ago

Vue-Skia is a Skia based 2D graphics Vue.js rendering library written in Rust

guessmyname
1pts0
notice.line.me 2y ago

Merger of LINE Corporation and Yahoo Japan Corporation creates LY Corporation

guessmyname
3pts0
therecord.media 2y ago

Several Colombian government ministries hampered by ransomware attack

guessmyname
2pts0
www.roberthalf.jp 2y ago

Security alert: Impersonation of Robert Half employees

guessmyname
1pts0
kstp.com 2y ago

Safety inspector fired for finding 'too many defects'

guessmyname
241pts107
support.google.com 2y ago

Inactive Google Account Policy

guessmyname
1pts0
news.ycombinator.com 3y ago

Tell HN: Robert Walters Incompetence and Disrespect for Companies and Candidates

guessmyname
6pts0

Antigravity is such a dumb name. An-ti-gra-vi-ty (5) is long, Ge-mi-ni (3) was better.

Aren’t Marketing/PR people at FAANG supposed to be among the best in the industry?

what are some stuff that people are interested in reverse engineering ?

Software license/key verification. Sometimes it’s as easy as replacing a “JNE” with a “JE”, or replacing “JMP”, or even just “NOP” some “CMP” operation. It’s a fun challenge, at least for people who enjoy solving puzzles.

I attended a Recurse Center batch, and while I understand that others had amazing experiences, mine was quite bland.

I can't blame anyone but myself for this.

Most of the other attendees were intelligent or highly self-motivated, or both. Many people seemed to connect instantly, forming small work groups, sharing project ideas, and even going out for lunch or dinner together. They were constantly talking about how awesome Zulip was (is?) [*] and engaged in a constant stick-measuring contest to see whose weekly project would make it to Hacker News’ top 30. At times, it felt like I had joined some sort of mini-cult. I know it wasn’t like that at all; it was just the visuals from an outsider in a completely different culture. As far as I can remember, people were very friendly, willing to help others whenever they were stuck, and happy to study and tackle challenging problems together. There were lots of learnings floating around the working space. Sadly, it didn’t work for me at all, and years later, I still don’t know why exactly.

Perhaps it was the fast pace of New York City and SoHo itself? Or the rudeness of passersby, especially the police officers who couldn’t be bothered even if I just wanted to ask for directions? Or the dirtiness of the streets? The constant noise from cars honking all the time? The strange people in the Subway? The ubiquitous unhealthy food at every corner? Healthy food was difficult to find, at least for someone new to the city, and when accessible, it was unaffordable. Multiple times, I found myself working in the Recurse Center workspace with an empty stomach, which obviously exacerbated the bad experiences, but I can’t even complain about that because they often had free pizza (once, twice a week?) but obviously, pizza is unhealthy, so I never accepted.

Overall, I had a very bad experience, but I believe nothing was Recurse Center’s fault; it was mine. I’m not entirely sure what I expected when I joined, but I hope this serves as a warning to future attendees to prepare themselves before joining, especially if you are not familiar with American culture, and particularly with New York.

[*] https://zulip.com (years later, I still don’t understand why people love Zulip so much)

For over a decade, I imagined that if I ever landed a job at Google, this would be my most significant project. It made me chuckle a bit when I read the announcement, they finally built it! confirming that my thoughts weren’t entirely delusional XD

Why Italian Americans instead of just normal Italian? Aren’t Italian Americans just regular Italians? Or are you asking about the customs of Americanized Italian families or people who were born and raised in America but with Italian ancestry?

I didn’t claim to have 10+ YoE; I said that most of the people in Project Glasswing are security researchers with 10+ YoE (avg).

Its very hard to understand what you're saying with the comment

Yes, fair enough. I’m simply trying to shed some light on what goes on behind the scenes without disclosing too much information to avoid breaching the NDA(s) that all Project Glasswing users have signed. There’s a lot of speculation about the usefulness of Mythos as a security tool, so much so that even the US government got involved. Honestly, it’s so absurd that I can’t even express it in words. I thought that sharing a bit about how frustrating it is to work within this project, trying to secure software that literally millions of people around the planet use on a daily basis, while virtually everyone outside of it criticizes every move you make, would be helpful.

Many people I work with recognize the power of Mythos, just like any other model with a similar number of parameters, but most of the people I interact with agree that it’s not the ultimate panacea. I believe that it’s just vocal minorities scaring everyone into thinking that the model is some kind of cybernetic weapon.

We (Project Glasswing users) follow a proof-of-concept approach. We create the exploit and verify that it behaves as the AI claims. Given our experience as security engineers (many of us with 10+ YoE) we don’t simply report every critical bug Mythos claims to have found. We verify each one carefully.

At least, that’s what most of the high-visibility users in Project Glasswing are doing.

There are bad apples everywhere, and this initiative is no exception.

If it makes you feel any better, many of us regularly meet to stay calibrated and hold each other accountable, so I’m confident in the quality of the work produced by this particular group of employees across some of the partner companies mentioned in the article.

That said, I know several people who blindly report everything Mythos finds, which is foolish, especially since the harness is a critical part of the project's quality metrics. Some of the harnesses I’ve tested are quite weak, which leads to poor results.

For example, yesterday morning I was pulled into an ad hoc meeting where a CVP was grilling me about several supposedly critical bugs that my team had reported against one of the core components of iCloud. I was genuinely surprised because we’re very strict about validation. We often even downgrade the severity of bugs when our harness can’t prove what Mythos found. After reading the reports, I realized they weren’t ours. They came from another team that had recently been given access to Mythos. They built their own harness and were using different vulnerability criteria. Fortunately, they had only started earlier this week, so I was able to stop that work.

That incident showed that not everyone involved in Project Glasswing follows the same standards. Most people do their best, but priorities differ, so it’s expected that you’ll find a few bad apples.

I wish AI labs would stop the theatrics and release their models without restrictions, but I also recognize that’s not the world we live in. For every person who wants to use these technologies for good, there are many others who would use them for harm.

In any case, while I agree that some experiments contain genuine noise, the CVE count is real.

[dead] 20 days ago

“reject” implies an active action. Instead, I would simply ignore the resume and focus on other candidates.

There’s also the fact that some, if not all, of the jobs listed in this gentleman’s work history seem to be short-term stints of 1-2 years. While this is quite common in the American tech industry, it’s still a red flag.

I can’t help but wonder what drives tech workers to switch jobs so frequently throughout their careers. Keep in mind that I come from Japan, where the culture is that you join a company for life. For many years, I believed the only justification for this contrasting approach in America was that tech professionals are highly aggressive about negotiating their salaries, leading them to move between companies as soon as they secure a better deal. It makes sense, considering that we’re all essentially selling our time to companies that make significantly more money by selling the products we create.

However, it still feels a bit strange … 文化の違う

As a Mythos user (I’m part of Project Glasswing), I would say that abliterated models [1][2] produce similar, if not identical, results. While good prompting and steering won’t give Claude Opus 4.8 the same capabilities as Mythos (preview 1), using abliterated models (if you have the computational power to run the larger ones) will get you close to the same goals as people who have access to Mythos (preview 1) [3].

[1] https://huggingface.co/search/full-text?q=abliterated&type=m...

[2] https://webdecoy.com/blog/wtf-are-abliterated-models-uncenso...

[3] I specifically refer to “preview 1” because the newer versions (Fable 5 / Mythos 5) don’t appear to offer the same level of freedom as the very first version that I was able to use through Project Glasswing. This is one of the reasons why I continue running our massive security scans with “preview 1”, or at least I was running them until June 30, when the program’s policy changed.

I think there will be a cottage industry of porting every Mac menu bar utility to Claude.

As long as those native (Objective-C / Swift) menu bar apps are ported as native (Go, Rust, Zig, etc.) binaries for Agent CLI(s) like Claude Code or Codex CLI to use, instead of JavaScript, as this project is written, then the broader community of Agent CLI users will be fine. Otherwise, it will be another nightmare induced by JavaScript.

Indeed → https://www.levels.fyi/companies/facebook/salaries

• Engineer (E3, entry level) $248.2K avg ∴ https://www.levels.fyi/companies/facebook/salaries/software-...

• Engineer (E5, senior level) $629.8K avg ∴ https://www.levels.fyi/companies/facebook/salaries/software-...

• Engineer (E7, principal) $1.69M avg ∴ https://www.levels.fyi/companies/facebook/salaries/software-...

• Engineer (E9, distinguished) $6.09M avg ∴ https://www.levels.fyi/companies/facebook/salaries/software-...

And so on with other roles, as you can see on that page.

I think the industry is optimizing for the wrong thing. Generating thousands of AI-written bug reports is easy, at least with Mythos (preview 1) or GPT-5.5. Getting bugs fixed is the hard part.

A few months ago I started working on a system that finds critical security issues and opens PRs instead of just filing reports. The acceptance rate is sitting at roughly 94% so far. Most of the failures were due to project-specific kill switches or other internal mechanisms that weren’t documented, not because the vulnerability itself was misidentified.

Developers generally seem to prefer this approach. A bug report creates work. A good PR removes work. That sounds obvious, but a lot of security products still stop at the report and call it a day.

Nice! I know it’s built with an LLM and that a vocal minority on this site doesn’t seem to like that for some reason, but personally I’m really enjoying the new interactive web experiences that younger developers are shipping to the internet every day. Thanks for sharing, and out of curiosity, what prompts did you use?

I'd run Mythos against the code in your zip file, but the NDA I signed at Apple prevents me from using it on anything outside the scope of my work. Honestly, I wish more people from Project Glasswing could talk publicly about their experiences with the model. It would probably put an end to a lot of the speculation that keeps circulating through the industry. Unfortunately, that's not the reality we're in. I don't have the time, energy, or financial resources to fight a legal battle with one of these companies over an agreement I knowingly signed, even if the chances of them actually suing are low. Maybe someone else in Project Glasswing is willing to burn their NDA and post the Mythos results?

Key bundle missing — please try again

I’m trying to create an account to test this service. I get this error message, what does it mean? Why is the error message so short to the point where I (the user) don’t know what to do next? Why can’t software developers learn how to communicate better with their non-tech users? And this is coming from someone with a 30+ years career in software engineering.

edit: after hitting the button “I’ve saved my recovery phrase - continue” multiple times and getting the same repeated error message, it finally worked but then the API returned “error: Registration failed”. And at this point I give up. This is why many projects, even at Big Tech companies, fail: too much friction for new users, or too many features, or too many options to choose from.