HN user

rmast

132 karma
Posts20
Comments75
View on HN
github.com 2mo ago

Ghidra Decompiler in the Browser

rmast
2pts0
github.com 3mo ago

cmakefmt: A lightning-fast CMake file formatter

rmast
2pts0
blog.kulkan.com 3mo ago

Breaking into a Govee Smart Display: From UART Shell to Device Impersonation

rmast
1pts0
github.com 4mo ago

Pokemon-themed E-paper Home Assistant dashboard

rmast
3pts0
hanzilla.co 4mo ago

I Hacked My Laundry Card. Here's What I Learned

rmast
27pts6
developers.openai.com 4mo ago

Get free ChatGPT Pro for open-source maintainers

rmast
2pts0
www.youtube.com 4mo ago

Casting SALT like Metal – What Happens? [video]

rmast
2pts0
www.youtube.com 4mo ago

How many AA batteries does it take to power a PC setup? [video]

rmast
1pts0
zillowforwarcraft.com 4mo ago

Zillow for Warcraft

rmast
3pts0
www.microsoft.com 4mo ago

Project Silica's advances in glass storage technology

rmast
1pts0
medium.com 4mo ago

From Wi‑Fi Access to Root: Reverse Engineering a $50 CarPlay Dongle

rmast
3pts0
github.com 4mo ago

FemtoClaw: Ultralight Port of OpenClaw/PicoClaw for ESP32 and Raspberry Pi Pico

rmast
3pts0
www.youtube.com 4mo ago

Turning a 2 ton robot into a 3D printer [video]

rmast
2pts0
it4sec.substack.com 5mo ago

Hacking a NutriBullet blender via BLE: reverse-engineering the protocol

rmast
1pts0
surfactant.readthedocs.io 6mo ago

Show HN: Analyze binary capabilities using capa directly in your browser

rmast
1pts0
lucasteske.dev 6mo ago

Running custom code on a PAX credit card machine by swapping the SoC

rmast
2pts0
neodyme.io 6mo ago

Hacking a Consumer Drone: Dumping Firmware and Bruteforcing ECC

rmast
3pts0
surfactant.readthedocs.io 6mo ago

Show HN: Find hidden binary dependencies & subprocess calls in Python packages

rmast
2pts1
github.com 6mo ago

OGhidra: Automating dataflow analysis and vulnerability discovery via local LLMs

rmast
1pts1
pymsi.readthedocs.io 1y ago

Show HN: Inspect and extract files from MSI installers directly in your browser

rmast
135pts24

I was thinking that the other definition was right and this correction was wrong.

Then I did some searching and found multiple examples of both definitions in use, making things murky.

So I turned to Merriam-Webster’s dictionary: “ of, relating to, or being a vulnerability (as in a computer or computer system) that is discovered and exploited (as by cybercriminals) before it is known to or addressed by the maker or vendor”

And of course they use an “or” to make it ambiguous as to whether the days start counting when the vulnerability becomes known, or when the vendor has addressed it.

I applied for both. Heard back from neither. Mentioned two particular projects when applying, one with 2k stars and 5M monthly downloads, and another with 2M monthly downloads.

I was using it to craft a CTF challenge for summer students involving a simulated mechanical dial safe, but with the fence replaced by a IR beam break sensor and a microcontroller handling the check + flag message display.

For generating the initial 3D simulated safe using three.js it worked well, but then modifications to print a flag tripped the safeguards; eventually got it narrowed down the part in the prompt about it being for a CTF for students, and the "thinking" for the model seems to drift to ideas of encryption/obfuscation of the safe combo so students can't just read out the answer... which makes sense logically to help force students into turning the simulated dial instead. But whatever detection Anthropic I guess just naively sees the model thinking about "encryption" and "obfuscation" without taking into account any of the context.

For writing the dummy firmware, it tripped the safeguards while thinking about how to track dial position in the firmware and output the message; however, when I left out talk about safes and just told it to write firmware for a microcontroller hooked up to an i2c display for showing a message with a beam break sensor to determine the message, and an unspecified i2c chip for getting an unspecified number (e.g. internal wheel positions) it worked fine.

An unrelated software task I asked it to write some code to translate CustomActions in a Windows MSI installer into human readable stuff, which has (exclusively?) defensive security applications for recognizing malicious behavior in an MSI installer. Maybe I'm going crazy, but I'm guessing as part of its research into MSI installer custom actions Fable found articles about analyzing malicious MSI installers, and that probably tripped the safeguards.

Overall my impression is that the safeguards are perhaps using an overzealous and naive implementation that just looks for a list of banned words in the prompt or the thinking -- which drives me crazy when the model says my prompt looks fine, and then 10 minutes in some part of the thinking trips the safeguard.

Claude Fable 5 1 month ago

So in other words... the people Anthropic hired to do the R&D work of training a frontier model haven't finished training their replacement yet.

The things that are harder to get running in a browser via webassembly tend to have a GUI, network communication, or system calls that browsers don’t provide the APIs that are needed to support. But I’ve seen workarounds using websocket proxy servers to get around the lack of raw TCP or UDP socket access.

I’ve been surprised how easy it can be to get Python and C# code running in a browser.

I help maintain a project that is used as a dependency by a lot of security tools to handle PE files.

It’s disappointing that Anthropic and OpenAI never responded to the applications to their respective programs for open source maintainers. From my perspective it seems like their offers are primarily for the shiny well-known projects, rather than ones that get only a few million monthly installs but aren’t able to get thousands of stars due to being “hidden” as a dependency of popular tool.

If you read the epilogue, they weren't able to achieve the under $1000 price goal. Total cost ended up being around $1,450. Pretty good price reduction compared to CARA 1.0 though.

Hypothetically if I were to want a quadrupedal robot to experiment with it's not an impulse buy/build, but getting closer to that point... whereas $3000+ is a hard pass (e.g. Apple Vision Pro territory).

Agreed, many types of devices don’t need to be locked down so much.

I imagine the companies making the devices think they are “protecting” their secrets from competitors, though now it might be easier to ask an LLM for whatever feature they want to copy.

I was kinda of disappointed when that happened earlier this month, but not as much now after seeing this change. My primary use had been trying out some of the newer Anthropic and OpenAI models, which probably would have burned through $10 worth of credits rather quickly given their new pricing.

I mostly clicked the link because I was curious if Cirrus Labs operates Cirrus CI and if so how that would be impacted.

Looks like I’ll need to move the FreeBSD CI jobs for open source projects I maintain to another solution. Anyone have suggestions for alternatives?

That part is amazing. Back when I first heard of tart I thought it was amazing, with the one downside being the license.

Hopefully development on it continues, or a community maintained version keeps it going.

How about for a real life Rainbow Road made by the Quantum Mushroom startup? I think that might be the aerospace applications reference in the article:

CERN’s Knowledge Transfer Group has begun discussions with European startup company Quantum Mushroom to explore aerospace applications and powering for next-generation anti-gravity vehicles.

Nasdaq's Shame 4 months ago

I wouldn’t really mind seeing the SpaceX IPO flop initially. The God Emperor of Mars has quite the ego.

However, I’m pretty sure the opposite will happen and the stock valuation will go past the moon to mars and beyond.

Getting all the calories you need from (plain white) rice just about meet minimum protein needs for a sedentary lifestyle (around 50g protein). For every 100 calories of rice there are about 2.1g of protein, so for a 2000 calorie diet of just rice that would be 42g protein. But eating 10 cups of rice is a lot.

Protein-wise, an all cabbage diet would give you more if you’re meeting calorie needs - 5.1g protein per 100 calories, or 102g protein for 2000 calories worth of cabbage.. but that is a heck of a lot of cabbage (17ish lbs)!

Let’s be real though, people should be eating a varied diet and not just a single food. And perhaps not a junk food only diet.

Interesting how the depackaging was done - curious what the mill setup was looked like. It seems like achieving .001” on manual mills isn’t uncommon; which would be about 25 micrometers, so in line with the depth of passes that were being taken here. I can see how the magnified view of the part would be helpful.

If you wanted to do the clean-room approach for something like chardet in a less controversial way, instead of having the AI do all the work couldn’t the AI generate the spec and then a human (with no exposure to the original code) do an initial implementation based on the spec?

As part of the relicensing ZeroMQ did a few years ago, they sought permission from all previous contributors (yes, it was a multi-year effort). Code contributions that they weren’t able to get permission to relicense resulting in the corresponding lines being removed (or functionality rewritten from scratch).

I would imagine there must also be some aspect of uniqueness to it as well for even recognizing where a line of code came from… otherwise almost every Python script might have copied this line from a GPL licensed program:

`if __name__ == "__main__":`

I have no idea where that line first appeared, so figuring out what license it was originally written under would be difficult to track down, and most software only has license info at the file rather than line level.