HN user

rwestergren

519 karma
Posts39
Comments29
View on HN
randywestergren.com 6mo ago

Proxying Flutter Traffic on Android with Claude

rwestergren
1pts0
randywestergren.com 1y ago

Analyzing VPC Flow Logs to Reduce Nat Gateway Costs

rwestergren
2pts0
randywestergren.com 3y ago

Simplified SSO with AWS Application Load Balancer and Azure AD OIDC

rwestergren
1pts0
randywestergren.com 4y ago

Building Pymssql (FreeTDS) for Lambda

rwestergren
2pts0
randywestergren.com 4y ago

Event-driven access to my home after a run

rwestergren
114pts78
randywestergren.com 4y ago

Building pyodbc for Lambda's Python 3.9 Runtime

rwestergren
1pts0
randywestergren.com 4y ago

Unauthenticated Remote Code Execution in Motorola Baby Monitors

rwestergren
12pts0
randywestergren.com 5y ago

Mystery Timeouts with MS Graph API Webhook Subscriptions and AWS API Gateway

rwestergren
1pts0
randywestergren.com 6y ago

Fetching Vendor Data at Scale with Serverless

rwestergren
4pts0
randywestergren.com 6y ago

A closer look at recent HTTP/2 vulnerabilities affecting Kubernetes and others

rwestergren
63pts6
randywestergren.com 7y ago

XSS Vulnerabilities in Multiple iFrame Busters Affecting Top Tier Sites

rwestergren
1pts0
randywestergren.com 8y ago

Compromising OpenDrive's Cloud Storage Accounts – Or How Not to Do Session Mgmt

rwestergren
1pts0
randywestergren.com 8y ago

Persistent XSS in PNC’s Secure Email System

rwestergren
2pts0
randywestergren.com 8y ago

Reverse Engineering the OBi200 Google Voice Appliance: Part 3

rwestergren
1pts0
randywestergren.com 8y ago

Reverse Engineering the OBi200 Google Voice Appliance: Part 1

rwestergren
2pts0
randywestergren.com 9y ago

Bright City: A Highly Insecure Police and Municipal Government App

rwestergren
2pts0
randywestergren.com 9y ago

XSS Over SMS: Hacking Text Messages in Verizon Messages

rwestergren
1pts0
randywestergren.com 9y ago

Rave Panic Button: Vulnerabilities in a Nationwide Emergency Alert System

rwestergren
85pts27
randywestergren.com 9y ago

Persistent XSS in Verizon’s Webmail Client

rwestergren
1pts0
randywestergren.com 10y ago

Legislating Vulnerability Disclosure Programs into State-Level Government

rwestergren
1pts0
randywestergren.com 10y ago

Critical Vulnerability Compromising Verizon Email Accounts (Again)

rwestergren
4pts0
randywestergren.com 10y ago

Widespread XSS Vulnerabilities in Ad Code Affecting Top Tier Publishers

rwestergren
7pts2
randywestergren.com 10y ago

Hijacking Verizon FiOS Accounts [FIXED]

rwestergren
3pts0
randywestergren.com 10y ago

Running a Hidden Tor Service with Docker Compose

rwestergren
4pts0
randywestergren.com 10y ago

Reverse Engineering the Yik Yak Android App

rwestergren
8pts0
randywestergren.com 10y ago

Cutting the Lights: Vulnerabilities in a Billboard Lighting System

rwestergren
45pts5
randywestergren.com 10y ago

United Airlines Bug Bounty: An experience in reporting a serious vulnerability

rwestergren
164pts72
randywestergren.com 10y ago

Attacking Real Estate Showings in ShowingTime

rwestergren
3pts0
randywestergren.com 11y ago

Reverse Engineering the Subway Android App

rwestergren
39pts9
randywestergren.com 11y ago

Verizon Mobile APIs Part 2: Multiple vulnerabilities exposing customer info

rwestergren
1pts0

With increasingly aggressive usage limits (Claude weekly usage now), "agentic" style of token burning seems much less practical to me. Coming from Aider and trying tools like OpenCode, the "use models to discover the relevant files" etc pattern seems very token heavy and even wasteful - whereas with Aider you include relevant files up front and use your tokens for the real work.

I was scratching my head on how he was capturing requests without mentioning a proxy cert, but then I saw the security note at the bottom.

  You'll see that the data for these products is sent in plaintext to and from their servers
The API seems to have a valid cert and is listening over HTTPS - strange that the app client uses plaintext.
  curl https://api.petkt.com/
  {"error":{"code":97,"msg":"App is out of date, please upgrade"}}

The battery level isn't actually close to dying, in my case it just rapidly depletes from up to 40% when it's very cold. But that 40% remains intact seemingly with the screen off. Could be my phone also, but it has happened often enough that I wanted to solve it and thought this was an interesting approach.

For me, this was just a matter of convenience and not optimizing for most resilient or reliable solution. I do have backup plans for home entry.

I shared this elsewhere but I could have expressed the initial problem a little clearer, which actually was "enter my home without unlocking my phone which causes my phone to die in the cold."

Unlocking the screen caused the battery to drop immediately - it still had network connectivity prior to that.

Marlette Funding | Multiple Engineering Roles | Full-time | Wilmington, DE / REMOTE

Marlette Funding is a consumer financial technology (fintech) business on a mission to inspire financial confidence by helping people manage their day-to-day finances. We offer a digital financial platform with simple, accessible and personalized financial solutions including personal loans, credit cards, and a financial health product.

The company is a fast-growing fintech that has been recognized numerous times as a best workplace. If you are energized by working in a fun organization where communication is open, everyone feels included, creativity is embraced, personal growth is encouraged, and you can make positive impact on the business, Marlette is the place for you.

Senior frontend engineer: https://jobs.lever.co/marlettefunding/54bfe4d1-1fa6-4172-a40...

All open engineering positions: https://jobs.lever.co/marlettefunding?department=Technology&...

The author may have added this in after publishing:

Many people have asked, could viruses also use the Ψ technique to beat our immune systems? In short, this is extremely unlikely. Life simply does not have the machinery to build 1-methyl-3’-pseudouridylyl nucleotides. Viruses rely on the machinery of life to reproduce themselves, and this facility is simply not there. The mRNA vaccines quickly degrade in the human body, and there is no possibility of the Ψ-modified RNA replicating with the Ψ still in there.

Context and purpose of the bash script in question is important here. In the example, the author is writing a simple bootstrap script for a dev machine. A number of the critiques here, while valid, are aimed at different use-cases.

Appreciate the feedback! My point on the price concern was that the app was not developed solely for my county, it was resold to multiple customers - at least 2,000 according to the link I posted in another comment.

I'm not sure what other customers were charged for the app, but if they were all $70K (as my County was), then that's a hefty rake.

I understand what you mean, but an attacker wouldn't be able to decrypt during a MiTM attack since SSL is being used -- regardless of cert pinning. An effect of pinning is losing the ability to perform a self MiTM to decrypt traffic; this post simply demonstrates bypassing that.

I was pretty sure of the 3rd party integration, but still am not sure why they're checking if the user's device is rooted. I suppose for payment processing, they consider it a security risk?