HN user

q3k

8,725 karma

email: q3k@q3k.org

matrix: @q3k:hackerspace.pl

irc: q3k on libera.chat

Posts25
Comments1,655
View on HN
blog.nelhage.com 5mo ago

Computers Can Be Understood

q3k
2pts0
www.youtube.com 5mo ago

Suno, AI Music, and the Bad Future [video]

q3k
4pts0
www.404media.co 7mo ago

Man Charged for Wiping Phone Before CBP Could Search It

q3k
12pts3
social.hackerspace.pl 10mo ago

NPM package 'debug' v4.4.2 contains malware

q3k
31pts5
www.404media.co 1y ago

GlobalX, Airline for Trump's Deportations, Hacked

q3k
12pts2
blog.rahix.de 1y ago

Design for 3D-Printing

q3k
837pts210
blog.rahix.de 1y ago

CNC Adhesive Applicator

q3k
2pts0
github.com 1y ago

macOS Crash with UnixDatagram

q3k
3pts1
blog.rahix.de 1y ago

Flower Machine

q3k
43pts5
github.com 2y ago

Xzbot: Notes, honeypot, and exploit demo for the xz backdoor

q3k
849pts469
q3k.org 3y ago

wInd3x, the iPod Bootrom exploit 10 years too late

q3k
2pts0
twitter.com 5y ago

Public static final int EM_NATION_TYPE_UYGUR = 1;

q3k
228pts33
blog.sumtypeofway.com 5y ago

Bazel, Haskell, and Build-System Joy

q3k
3pts0
bugs.chromium.org 6y ago

Samsung Android: multiple interactionless RCEs and other remote access issues

q3k
2pts0
tbspace.de 7y ago

ProFTPd CVE-2019-12815

q3k
3pts0
twitter.com 7y ago

QuickJS Use-After-Free

q3k
3pts0
github.com 7y ago

Show HN: TPM2137 – a CTF challenge showcasing FPGA bitstream reverse engineering

q3k
2pts0
code.fb.com 7y ago

Efficient, reliable cluster management at scale with Tupperware

q3k
2pts0
github.com 7y ago

Show HN: Proof of Concept for CVE-2019-5736 (Docker Escape)

q3k
1pts0
www.crowdsupply.com 8y ago

NeTV2 – An open video development board

q3k
1pts0
blog.dragonsector.pl 8y ago

Reverse Engineering an Integrated Circuit for Pwn2Win 2017 CTF

q3k
67pts9
github.com 11y ago

Show HN: Crowbar, a tool to proxy TCP over plain HTTP

q3k
15pts4
blog.dragonsector.pl 11y ago

31C3 CTF – getting a shell via a phone UI

q3k
2pts0
arstechnica.com 12y ago

School cancels reading program rather than promote “hacker culture”

q3k
4pts0
russianroulette.sh 12y ago

Show HN: curl-to-shell russian roulette

q3k
2pts3

I don't mind the rejection (I know I'm not _that_ good, I understand there's tons of applications and I'm fine with that), but the wait and lack of clear feedback sucked.

The response was particularly unclear - was I rejected outright? Did I slip through the cracks and then the role got filled by someone else? Should I reapply, or am I not a fit for company culture? Or just maybe not a fit for the role? If I reapply, should it be with the same interview packet, or should I rethink it? Like, is it me or is is it you?

Even when I applied to Google (a famously 'bad' recruitment experience according to most) I was able to at least regularly talk to a human who would give me feedback from interviews. And when there was a lack of team fit they'd tell me so clearly and help me look for another role. They treated me like a human! Like, I could talk to someone! Oxide just gave me a canned answer without a signature attached and no way to actually talk to anyone.

Oh well, in the meantime I've actually found a meaningful job where the recruitment experience didn't feel like I'm just throwing messages in a bottle into the ocean and hoping to get a response.

The particular 'mess' I've encountered was I applied (wrote 11 pages of interview material) on 2024/09/29 and then received a canned 'yeah whoops sorry for taking this long, not interested' on 2025/03/24. That's almost 6 months of delay from submission to first contact.

Terrible process. You need to give feedback early if you're not interested in someone, not leave them hanging for nearly half a year.

Claude Tag 30 days ago

Today, 65% of our product team’s code is created by our internal version of Claude Tag.

That explains a lot.

I don't think there's anything novel here?

It's one of those things that every embedded dev kind of cobbles together on their own as they discover the limit of struct arrays stored in EEPROM.

Except this one actually seems worse in some ways, because to find a file you have to keep following what is effectively a single linked list of file headers until you find the file you need.

The authors even acknowledge this is just a copy of tar's approach, and even acknowledge that that was in turn done this way due to a lack of random seeking on tape systems at the time. But a microcontroller's EEPROM/SPI/... data is nothing like this? You can just do arbitrary seeks. So I'm not sure what they were going for here.

The implementation is also full of obvious bugs that will cause crashes or hangs or worse when operating on an untrusted or simply just corrupted filesystem: https://github.com/clisystems/utfs/blob/5f1a6f049a0ca5435afb...

I see cams intersecting eachother and still nothing that is actually ready to be manufactured or even looks like a design that has had any thought put into it. It's the CAD equivalent of idle doodling.

Do you have a single person on your team that's actually a mechanical engineer with practical industry experience?

A complete V8 internal combustion engine

Yeah, no, that's a lie. This isn't a CAD model. It's a fantasy 3d model that looks like it's straight out of Gearhead Garage (1999).

Any time I see these 'AI CAD' solutions it's always toys, toys, toys. Show me something functional that you've actually manufactured (shitty 3D prints don't count). Or at least show me something that can actually be assembled and isn't just a bunch of boxes with no fasteners to hold them together.

It's surprising to me how many people here seem offended that someone might just not want their code.

I guess it takes quite a lot of experience as a maintainer to realize that 'free' in 'free code contributions by strangers' is like 'free' in 'free puppy'.

So I can find a bug, I can fix it, but I am not allowed to tell them how exactly I did it.

You're allowed, they'll just ignore it. Same as how sqlite and some other projects operate.

Yeah, just found a consent banner for this. No CAPTCHA, and the following sentence buried half way through the consent screen:

By consenting, you confirm that you have permission from the telecom account holder to enable the Utiq technology on this internet connection.

I cannot adequately express my contempt for people who have designed and implemented this.

You are in control

But also:

The Utiq technology is linked to the internet connection. This means that anyone using the same connection will have access to the same consenthub view and will be able to manage Utiq consents given when using that connection. For example, when you share broadband connection with others in your household or if you use tethering/hotspot.

And of course the consent management panel is behind a CAPTCHA - god forbid someone automate revoking consent! I'm guessing no CATPCHA is needed to give consent, though.

Show HN: AI-enabled orphan grinder

Person A: yo wtf is wrong with you

Person B: Who are you (or who am I) to decide that? The entire point of a show HN is to be non-judgmental and charitable, otherwise it's just going to turn into a cynical echo-chamber. The famous Dropbox comment is a cautionary tale for a reason.

Why is it that every "I built a cool AI tool" author shared on this site can't be bothered to write the article themselves?

Because most AI hypers have extremely low standards for any form of text - be it code or prose. If one is to believe code doesn't matter, then why would would prose matter either?