HN user

kidbomb

108 karma

[ my public key: https://keybase.io/kidbomb; my proof: https://keybase.io/kidbomb/sigs/5jwEUI1NV6PbVngUylFoQ0OWZ8XDG35RESmBkjqbQ0c ]

Posts23
Comments20
View on HN
www.youtube.com 23d ago

LLM Optimization

kidbomb
2pts0
www.youtube.com 1mo ago

Mark Rober demonstrate relay attacks by "stealing a car" [video]

kidbomb
6pts2
www.1010220.com 1mo ago

1010220

kidbomb
3pts0
www.youtube.com 4mo ago

$75M Crypto Wallet Bulk Hack [video]

kidbomb
4pts0
medium.com 6mo ago

A year in the life of a Staff Engineer

kidbomb
6pts2
github.com 6mo ago

Prompt Injection Defenses

kidbomb
1pts0
kidbomb.github.io 11mo ago

CVE 2025-23266 (NVIDIAScape) – An update

kidbomb
3pts0
kidbomb.github.io 11mo ago

CVE 2025-23266 (NVIDIAScape) – A Detailed writeup

kidbomb
3pts0
cloudsecuritychampionship.com 11mo ago

Contain Me If You Can

kidbomb
1pts0
securitylabs.datadoghq.com 1y ago

I Spy: Escalating to Entra ID's Global Admin with a First-Party App

kidbomb
2pts0
blog.palantir.com 1y ago

Operational Responsibility

kidbomb
1pts0
www.nvidia.com 1y ago

GPU-Accelerated TensorFlow

kidbomb
2pts0
blog.frizk.net 1y ago

Attacking UEFI (2017)

kidbomb
2pts0
eclypsium.com 1y ago

Direct Memory Access Attacks – A Walk Down Memory Lane

kidbomb
1pts0
eng.lyft.com 1y ago

Extending our Envoy mesh with staging overrides

kidbomb
1pts0
hackaday.com 1y ago

Man-in-the-Middle PCB Unlocks HP Ink Cartridges

kidbomb
82pts41
news.ycombinator.com 2y ago

Ask HN: Should a risk assessment list all dependent tools?

kidbomb
6pts4
www.askamanager.org 2y ago

The new hire who showed up is not the same person we interviewed (2022)

kidbomb
61pts14
en.wikipedia.org 2y ago

Glomar Response

kidbomb
2pts0
enable.hp.com 6y ago

3D printed applications to support Coronavirus containment efforts

kidbomb
1pts0
en.wikipedia.org 6y ago

Mari0

kidbomb
2pts0
samcurry.net 6y ago

Exploiting Null Byte Buffer Overflow for a $40k Bounty

kidbomb
1pts0
www.mnin.org 7y ago

Cryptography of SSH (2006)

kidbomb
62pts6

Most of my friends have either joined religious groups or running teams. I never realized that, besides the philosophical and health components, there was also a social one to it.

Gym has made wonders for me. Most of my friends are either on crossfit or running groups. I have joined a kickboxing gym. This helps you on multiple levels: - It provides you a routine - It makes you meet other people - It makes you exercise regularly

All of the above stave off the loneliness.

Also, get a hobby where you mind focus on one thing only. Play a instrument. Draw. Solve puzzles. Jimmy Carr had a similar issue and he started to play with legos.

Working remotely by yourself every day sucks

The best thing is to have the OPTION to either work at home or at the office.

Sometimes, you need the focus. But sometimes, you need to see people.

Identity management is a mess on Azure! I still cannot understand the difference between app registrations and enterprise applications, and how they tie into service principals.

They also have a lot of different resources, such as Graph API, Entra ID.

Manage identities are simpler, since they are Azure constructions, so they work more or less like a IAM role. But then you try to use them with Entra ID APIs and things fall apart.

IMHO the second problem goes deeper:

Sign In with Apple is allowing you to "create an account"(author's words) on @company.com, which should not be supported in the firat place. Instead, it should rely in a central directory controlled by company.com for authentication

"Create an Apple account with support@company.com email"

Wait - how is that workflow possible and supported?

In my head, authorization under @company.com would be delegated to a central directory, instead of relying on Apple ID. It is effectively an authentication bypass.

Lessons learned from this:

- CS: Have a staging (production-like) environment for proper validation. It looks like CS has one of these bu they have just skipped it - IT Admins: Have controlled roll-outs, instead of doing everything in a single swoop. - CS: Fuzz test your configuration

Anything I have missed?

This part caught my eye:

"Note that this information only applies to dormakaba Saflok systems; several other lock manufacturers use MIFARE Classic keycards and are not affected by the Unsaflok vulnerability"

So it is likely they way that Saflok implemented MIFARE Classic. Will start to read about this protocol more.