Hacker Newsnew | past | comments | ask | show | jobs | submit | hashstring's commentslogin

Yes, the Outlook sender font is such a joke. They preach about 365 security but don’t practice basics.


The link [1] reads:

> On July 4, 2025, in a historic and unexpected move, Congress expanded RECA legislation, finally awarding overdue compensation to New Mexico families. Our newly revised film captures this emotional victory.

Were the families (at the very least) compensated to some extent at last?


Damn.


Eh, if you can pollute page caches this won’t safe you.

Think modifying shared libraries, ld preload, cron, I guess on some systems /etc/passwd even.

There are a lot of files readable that should definitely not be writable.


Fair enough -- a simpler change might be to poison /etc/passwd and call `su` to a user that has uid 0, since that requires no shell code nor a readable binary, and this seems to have worked in a slightly modified POC:

  f=g.open("/etc/passwd",0);
  e="rkeene:x:0:0:System administrator:/root:/run/current-system/sw/bin/bash\n".encode()
  ...
  g.system("/run/wrappers/bin/su - rkeene")


There is a PoC that does exactly that here: https://github.com/tgies/copy-fail-c


Well said.


Amsterdam Airport? Source?


Well, i don’t have a source. Its very hush hush, as even the part that the police is using it has been leaked by a redacted document. It’s crazy.

https://www.privacynieuws.nl/binnenlands-nieuws/politie-en-j...


Hm, ok, but you suspect that Amsterdam Airport (Schiphol Group I suppose) is using it?


If there’s something that screams late-stage capitalism any louder, I don’t want it…


What if they can’t protect your privacy, if they do not create a successful and sustainable business?


Why does STUN impact your QoS? I thought STUN was just for discovering your own external IP/port.


Makes me wonder.

Say 5% of the free tier users converts to a paying customer within 5 years. And user growth is constant. Then over time, you will get a much larger free tier user base, compared to your paying customers (in absolute numbers). At some point, it must become tempting to charge all free tier users a little bit to continue, because the group got so big, so there is a lot that can be earned there.

Is this wrong, or should we expect this?


Cloudflare still operates like this.


And they have become quite infamous for having aggressive sales tactics for anyone going over their internal metrics for the free tier (still under the public metrics for free).


If you’re going above those limits… come on lol.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: