HN user

selectively

-17 karma
Posts0
Comments116
View on HN
No posts found.

Obnoxious author. Refusing to 'pay twice' for a game they care enough about to go through all this trouble + deeply obnoxious bit about Windows 11 at the end of of the post.

Gruber is a monstrous person. He's also written many different pieces that are more or less content-free anti-Korean racist screeds. The world would be much better if he'd retire and never speak in public again.

Lunatic, likely AI generated comments here.

This is an app for deliberately causing pollution. The users of that app should be criminally prosecuted and lose their license/spend a few months in prison. The price differential between this device/app and a generic ODB dongle you can buy on Amazon for ~$10 is entirely made up by the criminal features EZ Lynk offers.

The app being software versus hardware doesn't change the legal or moral situation involving it. Much like the DOJ would demand identities of people importing PlayStation 1 modchips back in the 90s, the users of this equally criminal application will be provided to the DOJ.

(The buyers are the NSA, the IDF, Cellebrite, NSO and its successor corporation and that kind of thing. Depends on what you are offering)

You'll learn who the buyers are if you routinely have the really good stuff to sell! If you are offering iOS zero click on a semi-regular basis, the buyer is going to want to try to deal with you directly and preferably offer you a more regular form of employment, if you are interested. Some national governments may offer certain benefits to you, depending on your situation.

All depends on what you have to offer. If you were able to offer this https://arstechnica.com/security/2025/09/microsofts-entra-id... or something of that magnitude, a lot of problems in your life would just go away. The buyers would all be Five Eyes and the intelligence gain of having that kind of access even briefly is priceless.

In a more Western-centric context, imagine if you had a flaw like that, same 'no logs are generated' and 'every single customer account is accessible' but the impacted vendor was Alibaba Cloud. The researcher would get to name their price. That's the real world, that's the world we share. We shouldn't be blind to that.

There are two options:

1. Status quo. Researchers are free to disclose to a vendor, free to sell vulns to legitimate companies, free to do full disclosure if they want. This situation benefits security. Researchers are able to pay their bills while also doing meaningful research into OSS projects that are unable to fund the kind of security audit they need. Harm reduction, of sorts.

2. Everyone is a bad actor. No one is going to do this work for free/for a bounty. Horrible flaws will be found and shared with ransomware gangs and the like. 0day will sell for a percentage of the ransom winnings. Researchers will live like kings, everyone else will suffer.

Which do you prefer?

Who cares about how you are seen when you are selling 0day for big bucks? The bad actor makes more money than the 'legitimate' one without breaking any law. Punishing someone who didn't alert distros despite a patch being available encourages the company to simply find flaws and sell them for profit - it pays more to begin with.