HN user

lschueller

425 karma

Cyber security analyst at day, tinkering at night. Pro tomatoes.

Posts82
Comments119
View on HN
en.wikipedia.org 12d ago

Project Cybersyn

lschueller
4pts0
twitter.com 1mo ago

Humanity Protocol Hacked for $36M

lschueller
2pts1
www.theregister.com 1mo ago

Council of Europe hacked in ShinyHunters' PeopleSoft heist

lschueller
11pts1
red.anthropic.com 1mo ago

Anthropic: Measuring LLMs' impact on N-day exploits

lschueller
6pts0
techxplore.com 1mo ago

AI model predicts building fire spread, redirecting evacuees to safer exits

lschueller
2pts0
www.reuters.com 1mo ago

SpaceX wins Texas tax breaks for chip project, ahead of record IPO

lschueller
13pts0
www.bellingcat.com 1mo ago

Banned Russian Submunitions Found After Mali's Military Announces Airstrikes

lschueller
8pts0
cyberscoop.com 1mo ago

Federal audit reveals NIST's NVD is plagued by poor planning and duplication

lschueller
3pts0
www.bigtechnology.com 1mo ago

The Chatbots and Agents Are Going to Merge

lschueller
3pts0
www.theregister.com 1mo ago

Europe told to cool its datacenter boom before water and power run short

lschueller
5pts0
techxplore.com 1mo ago

Biobased magnetic sensors printed from iron and cellulose

lschueller
3pts0
cyberscoop.com 1mo ago

UK spy chief labels AI 'unstoppable force' with off., def. ramifications

lschueller
4pts0
www.techradar.com 1mo ago

Charter Communications confirms data breach of apparently 40M records

lschueller
4pts0
theins.press 1mo ago

Malware dev tries to steal Claude users' secrets, leaks own GitHub private token

lschueller
7pts4
phys.org 1mo ago

Perfect randomness realized for the first time

lschueller
4pts0
www.theregister.com 1mo ago

AI hiring algorithms reject Black, Asian job seekers at higher rates

lschueller
6pts1
factcheck.afp.com 1mo ago

Altered photos of Biden, Trump with Xi spread online

lschueller
3pts0
www.theregister.com 2mo ago

Jailbroken Gemini helped Russian-speaking fraudster target MAGA crypto users

lschueller
6pts0
bigthink.com 2mo ago

The quantum realm, the cosmological realm, and the multiverse, in 69 minutes

lschueller
4pts0
www.bigtechnology.com 2mo ago

Believe It or Not, the Government Is Adopting AI to Make Your Life Easier

lschueller
2pts2
bigthink.com 2mo ago

Kairos: The ancient Greek art of knowing when to act

lschueller
20pts0
bigthink.com 2mo ago

Pigs could end the transplant waiting list

lschueller
7pts1
cyberscoop.com 2mo ago

Researchers say AI just broke every benchmark for autonomous cyber capability

lschueller
2pts0
status.hetzner.com 2mo ago

Ask HN: Hetzner Down Again?

lschueller
2pts1
www.tomshardware.com 2mo ago

'Dirty Frag' exploit leaks out, gives root on most Linux machines

lschueller
16pts4
krebsonsecurity.com 2mo ago

Canvas Breach Disrupts Schools and Colleges Nationwide

lschueller
16pts0
factcheck.afp.com 2mo ago

Resurfaced 2025 clip fuels false Musk-Ramaphosa snub claim amid Starlink row

lschueller
1pts0
www.theregister.com 2mo ago

C++ survey finds AI use rising, though trust is in short supply

lschueller
5pts0
nautil.us 2mo ago

For Every Patient Their Own Drug

lschueller
1pts0
www.tomshardware.com 2mo ago

Student stops fоur Taiwan high-speed trains with software defined radios

lschueller
3pts0

I'm afraid not. My impression is, most are just prompting for the tool they need right now, accept bugs and maybe even security gaps, but save time and pain not searching for an established tool. Which is fine and understandable for private things. But I wonder, how often this happens in professional environments. But maybe I'm just wrong... I have not seen any resarch or evaluation for this claims. Would be interesting, though

Cloudflare Drop 13 days ago

Yes, but this is the perfect circle of slop: generate an ai landing page, throw it into cloudflare drop, ai adopts it, start all over again. For genuine, professional content, I would assume, almost no one uses cloudflare drop, as they already have something in place to test and quickly host some page. Moreover, I expect that scammers and phishing campaigns will have a use for it to quickly up some landing page without leaving a large footprint.

There are established ways / protocols to hold and provide cryptographically valid proof of a verification process, without any need to keep the actual id images in any storage. And to my knowledge there is no requirement for compliant KYC (Know your customer) to provide their ID as a proof as long as the verification process itself is compliant and audited in accordance to certain criteria.

You can compare this in a certain way to file hashes. A successful verification with a predefined minimum level of credibility can be encrypted to a special string for later being used, if a service needs to verify the person again. It doesn't matter then, that the original passport images or video ident has been deleted the second after id verification has been completed.

Oh, and what I think is missing, are the fees for the mandatory membership in the industry and trade chamber (IHK) and of course the Berufsgenossenschaft. Especially the IHK is one of a kind... They are absolutely useless and a big bloated mess of self-governance, chaotic and really badly organized internally, but great at billing. When I've dealt with an attempt of fraud couple of years ago, I called them and asked if they have some kind of blacklists, guidelines or someone there, who could help in the case you get an business inquiry you suspect of being fraudulent. Thought, when i pay a yearly fee to them, maybe they have some experience with similar cases from other companies, who might reported attempta of fraud or fraudulent billing. Basically, one perso told me, they don't have a legal department, then I called the legal department directly, they forwarded me to the particular office, who again told me, he never heard of fraud attempts and he doesn't know if there is someone.. And this was the IHK in Hamburg. One of the largest chambers. Absolute joke.

Luckily, it seems you do not plan to import physical goods... This would be a next round of applications, fees, registers and id numbers. There are several countries out there, offering to set up a company legally and in accordance to european legislation within a couple days.

The fees you paid, seem quite high tbh. In particular for notary and court reg. I have the impression that the rates in Berlin are quiet above average.

It's not too hard to find vulnerabilities like this out there, but it is a true pleasure to see how well described and at the same time well documented the vulnerabilities and disclosure process in this case are handled. This makes it particularly useful to learn from as a real-life example. Well written, thank you for this cool piece of security work.

In the big picture I am again and again fascinated by this. One of the oldest commercial services out there (post / shipping) proves repeatedly to be very innovative and strong in realization of new stuff like this. They were the first or one of the first, who deployed electrical cargo vans. https://de.wikipedia.org/wiki/Streetscooter

To be accurate, they bought the startup. But still: they didn't wait for the automotive company to come up with a e cargo van.

Create a free account to keep playing. Sign up or log in to create an account, save your progress, and continue this difficulty.

And here we are again. A nice idea, ai generated, for grabbing email addresses... Not even trying to give it a human touch. Is this the new spam? Hundreds of sites and web apps forcing you to sign up with a temp email address for no good reason?

Thank you for sharing this statement. In other words, we now experience the secondary costs of the AI boom (and supply chain pressure). It won't get cheaper. I fully understand the decision of Hetzner. And even though I like low prices, the prices are still fair imo.

Thank you for the link.

Yes, they are real. And quite active. Some unverified source threw around the number of >1000 victims in 2026 alone. I think it was ransomware.live. At least a couple of hundred can be counted as victims with more or less certainty. The affiliates business is very very active currently.. as Brian Krebs summarized in a couple of blog posts already.

Feels like almost everyone with some it background in russia tries to jump on one of the raas as an affiliate at the moment. More and more new faces are entering the stage right now.

Inflated use of the term zero-day, while none of the described vulnerabilities is actually a zero-day. But it sounds and clicks good.. thank you for the PoC.

Please do not confuse funding with traction. These things are not related necessarily. In best case, a funded team gets traction and will be able to perform in a profitable relation to that funding. Your angle should be building a small but steady user base and build on that. While others are competing against time and expectations, you compete against visbility and trust. Your competitors aren't your competition you should care about. It should be, how to communicate to the users more effectively.

You need a chrystal clear usp. The site looks like it is for everybody, it is for everything, all at once and without any specialty compared to the thousands of other ai websites and service. The generic questions always are, who should use it and why.. That needa to be answered within the first 3 seconds. E.g. Animation Artists use it for getting from idea to clip in 5 minutes instead of 5 hours...

Isn't this a bit of lame pr to share a very general blog post on hacker news? There are some rough milestone mentioned, what they plan to achieve in the future. But nothing about achieved metrics, track records, finished projects or even linka to this projects. This creates an impression of just greenwashing.

The Buy button is kinda signaling, that they don't understand, what Winamp and this whole time was about... New tools with a frenetic mdding scene behind it, max customization, no tutorials, but digging through every file to see what you can change, bulky windows, which all needed to be arranged aside, like browser, napster, icq, winamp, your cs server chat in a thick browser.

IPv8 2 months ago

Sorry, but how can an ip layer be an >integrated network management< ?

The github repo is completely empty. No draft / documentation? Looking forward to see a bit more of the technicalities

The number of websites and services with really bad ai layout and a perverted thirst for emails are skyrocketing lately... This has just a closed, undocumentd inhouse verification service on top. I can't find any useful info about the verififcation app.