Hacker Newsnew | past | comments | ask | show | jobs | submit | captn3m0's commentslogin

I run a reverse engineering collective that is called 52 Labs: https://52-1ab.github.io/.

> 52 1ab (Pronounced 52 Lab) is a Software Research group dedicated to interoperabilty research in India. It is named after the Section 52(1) (ab) of The Copyright Act which states:

>> The following act shall not constitute an infringement of copyright:

>> the doing of any act necessary to obtain information essential for operating inter-operability of an independently created computer programme with other programmes by a lawful possessor of a computer programme provided that such information is not otherwise readily available.


iOS has a hidden album but the UX isn't great: https://support.apple.com/en-us/104987

I am guessing you are approved for the Cyber Verification Program. I also applied and got approved in an hour (on a Saturday!), but it only applies to Opus and Sonnet: https://support.claude.com/en/articles/14604842-real-time-cy.... It let me use Opus for cybersecurity work, pretty much everything except for Ransomware development. It would occasionally still trip and start saying no till I added a note about CVP in my claude.md.

No one gets to use Fable for Cybersecurity work, and Mythos is not available under CVP. Only for select few customers, and there isn't an application form?


Namecheap also suspended my primary domain because of a bug at their end: https://captnemo.in/blog/2026/05/05/namecheap-whois/

tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.

I know a few other people that were impacted.


I reversed Super Hexagon these last few weeks and ported it to the Playdate (the yellow console from Panic with a crank): https://old.reddit.com/r/PlaydateConsole/comments/1v1zxmt/i_...

The multiplier comes from being able to design arbitrary fast feedback loops - Claude wrote Python scripts to do decompilation matching for itself, and then use Frida traces from the original as a verification harness.


There are a lot of other implementations of this idea that don't necessarily rely on trust-on-first-use. The securedrop team explicitly includes malicious JS served by the primary-domain in the threat-model and made WEBCAT[0] as an outcome of that research. Their article on webcrypto is much better than this one.

The solution obviously is to go out-of-band:

> When a user visits a website that has enrolled in WEBCAT, before the site can load the content is checked against a signed manifest to ensure that it has not been tampered with (more on enrollment later). If everything checks out, the page loads normally. If, however, any content does not match what’s expected, the page load is aborted and a warning is displayed, protecting the user from potentially malicious content before it can execute.

[0]: https://securedrop.org/news/introducing-webcat-web-based-cod...

[1]: https://securedrop.org/news/browser-based-cryptography/


This is a OS port (iOS) of an existing functional and maintained fork (MacOS) of the official release (Windows).

Most of these low-hanging bugs would have been caught upstream by now.


upstream is a MacOS+linux build. https://github.com/fbraz3/GeneralsX.


Do we know how Apple sends these? Is it just a notification, or also email?


https://support.apple.com/en-us/102174

>A Threat Notification is displayed at the top of the page after the user signs into account.apple.com.

>Apple sends an email and iMessage notification to the email addresses and phone numbers associated with the user’s Apple Account.

You can see what it looks like in https://reddit.com/r/iphone/comments/1c10jai/i_have_received...

I wonder how they detect it, is it for known IOCs that they've already found elsewhere, or do they have heuristic detection that flags things that might need further investigation.


There are 2 complete folds in the Isaac 0 video around 0:40, but speeded up: https://m.youtube.com/watch?v=KhImSR8GuCE

The about page claims 1000+ lbs of laundry folded every week.


That's fine. Like a robot lawnmower - if it does it every day, it doesn't need to be as fast as a person.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: