HN user

tastroder

1,381 karma
Posts21
Comments661
View on HN
www.businessinsider.com 3mo ago

Oracle lays off employees as it curbs costs during AI buildout

tastroder
2pts0
netzpolitik.org 4y ago

Adtech’s new clothes might redefine privacy more than they reform profiling

tastroder
3pts0
www.businesswire.com 4y ago

Bugcrowd Awarded U.S. Patents for Crowd-Enabled Vulnerability Detection

tastroder
2pts1
harrisburgu.edu 6y ago

HU facial recognition software predicts criminality

tastroder
2pts2
techcrunch.com 6y ago

PEPP-PT contact tracing standard push could lead to fight Apple and Google

tastroder
1pts1
nadim.computer 6y ago

An Investigation into PEPP-PT

tastroder
4pts1
www.theregister.co.uk 6y ago

What do you not want? A bunch of Cisco SD-WAN, Webex vulnerabilities?

tastroder
2pts0
www.eevblog.com 6y ago

EEVblog #1290 – Hapbee: Anatomy of a Snake Oil Product [video]

tastroder
1pts0
www.upguard.com 6y ago

Identity and Access Misstep: How an Amazon Engineer Exposed Credentials and More

tastroder
1pts0
zombieloadattack.com 6y ago

ZombieLoad Attack (Update)

tastroder
1pts0
hackerone.com 6y ago

Developer Data Protection Reward Program

tastroder
1pts0
gizmodo.com 6y ago

'Time AI' Crypto Company Sues Black Hat After People Laughed at Its Tech

tastroder
2pts0
mobile.twitter.com 6y ago

YouTube deletes German election spot that cites constitution for hate speech

tastroder
8pts0
tools.cisco.com 7y ago

Cisco Advanced Malware Protection Windows Command Injection Vulnerability

tastroder
2pts0
www.defenseworld.net 7y ago

China Unveils New Armoured Vehicle Capable of Launching 12 Suicide Drones

tastroder
3pts0
translate.googleusercontent.com 7y ago

Some German banks play it safe when making transfers to N26 accounts

tastroder
1pts0
www.justice.gov 7y ago

Chief Executive and Associates Indicted for Conspiring with Drug Traffickers

tastroder
15pts8
www.bleepingcomputer.com 7y ago

Keyloggers Injected in Web Trust Seal Supply Chain Attack

tastroder
51pts8
www.youtube.com 7y ago

The Silver Tongue vs. the Iron Fist – Deviant Ollam BsidesOrl

tastroder
1pts0
www.theguardian.com 7y ago

Geoffrey Rush defamation case: actor set to win millions from News Corp

tastroder
3pts0
okfn.de 7y ago

OffeneGesetze: Opening Germany's Law Gazette

tastroder
3pts0
The Prompt API 3 months ago

chrome://on-device-internals reports "Model Name: v3Nano Version: 2025.06.30.1229 Folder size: 4,072.13 MiB" on a random Windows machine I just checked.

I clicked on a few red team "scenarios" if you want to call them that, a few of the tiles look like output of regular tools vaguely related to each but the rest - including the main "terminal" thing - seems more on the fictional side to the point I don't see this being educational.

There's plenty of training material out there these days actually using these tools in contained but realistic environments, if education is the goal just go for those.

Would he have not disclosed it if they offered hush money? We won’t know, for his case I hope not. In any case - what was he expecting?

A bog-standard responsible disclosure that any tech CEO should either be familiar with or have someone at hand that is, as is clearly communicated in that e-mail.

Both e-mails are OP reaching out to help this company out, the first fixing the vulnerability, the second giving them a chance for compliance / potential regulatory aspects they might want to follow. It's not on random people reporting security vulnerabilities to tutor random companies on this and both behaviors (non-responsiveness, then hostility) of this CEO, despite being sadly common, are actively harmful if you want to get productive security reports in the future. (And the company unilaterally signing up for bug bounty programs is rather irrelevant for independent researchers as well if they have no interest in participating in those.)

In terms of landing page it certainly worked, got me to check out the linked demos until I hit the signup nudge. Some of them don't seem to be available in English which might be a negative depending on your target audience.

Loading those exposes the e-mail of the account used to create the application (in [0], data->userInfo->email) and those "blocks" downloads contain the entirety of the prompts / applications, which is nice I guess but surely those are only required on the serverside?

[0] https://docs.trickle.so/api/nge/public/tao/objects/-/associa...

[dead] 2 years ago

Nothing, the whole repo and that post are spam intended to drive people to that e-book repository linked in the readme (which in turn is just a bunch of fake updates and likely engagement as well).

[dead] 2 years ago

There's no such thing as a best language that only depends on what year it is, what do you want to do with it and are you proficient with any language ecosystems already?

Since my test e-mails from a throwaway don't seem to go through: What checks does this perform? Since the policy pages don't name third parties like virustotal I assume it runs some OSS tools on your side?

Regarding the privacy policy and ToS: How do you see people using this in a corporate setting vs. something local? Most suspicious e-mail I encounter can't just be sent to random third parties.

sidenote: Some of the text is gray on gray and barely visible, e.g. on the main overview page when logged in and your policy pages.

That depends on the language pair(s) and sometimes the domain of texts you're translating.

Assuming you want to stick with the big cloud providers just sign up and test them on your content, they all have straightforward libraries.

Terribly sorry to harp on what the others in this thread have said but it seems like you've either been negligently briefed (due to the implausible scenarios you're describing and that you're posting this tied to your real identity, their first name on your website - assuming that's more real than the ChatGPT Ph.D. and other random entries there -, and your previous HN submission) or you're being lied to.

I meant your website and resume that you linked there. If this is not some weird thought scenario, pointing her to the public forum you use to discuss alternatives to her simply talking to whoever's responsible for her comsec doesn't seem like the greatest idea. If this is an actual problem it's not yours to solve and certainly has solutions that aren't this... convoluted.

This is from 21, not really news, and the paper version on arxiv and published at NeurIPS have quite a few citations. No one's suppressing this, people that don't reflect on their datasets or how they use them just either don't care or fail to acknowledge they're actual issues.

It's not, especially on the weekend. The freight delays might be somewhat of an issue over the next few days but on the passenger side it's a mild inconvenience at best. It disrupted the rail network country-wide to some degree but the public rail infrastructure in Germany isn't really known for it's reliability anyway.