Hacker Newsnew | past | comments | ask | show | jobs | submit | avemg's commentslogin

Having recently gone through this exercise with our IAM vendor to secure our MCP service, OAuth DCR scares me in that context. With redirect flows, which are usually what you're using when you're plugging your MCP into an agent, the spec says nothing about how to secure that. I really don't want to allow just anybody to register a client with an arbitrary callback. That's opening us up to phishing. Register your client with a malicious callback url and then trick users into clicking a link that initiates that flow. Our legitimate idp will authenticate them and then send then hand their access tokens off to an attacker.

The spec handwaves around this talking about initial access tokens which a client would obtain first in order to register but the details are sparse and probably unworkable when we're talking about every end user being a client.

Ideally i would be able to specify an allowlist of redirect patterns so i could limit it to say, chatgpt or whatever else. But that would be a non-standard behavior so my IAM vendor isn't in a hurry to do it.


exactly! allowlist or some sort of marketplace or app store like you like or not


This is mentioned right in the article itself.


Yep! Extremely annoying when traveling with my family of four!


Because Etsy is not a general second-hand marketplace. Its niche is artisans making small batch items. And making your own thing at the scale of ebay is not exactly a small feat.


I’ve def bought some CD keys off Etsy. They’ll list anything.


Etsy used to have strict limitations on what was allowed to be sold. I'm not sure how effective it was, but since that restriction has been removed, you're right, they'll list anything. Etsy has become a graveyard for dropshipped garbage, and the odd CD key, apparently! CD keys I can get behind.


If by “artisans” you mean “people ordering stuff off Alibaba”.


Sadly that was Etsy 10 years ago but today is a dropshipping front


I'm tickled at the idea of asking antirez [1] if he's ever written a PoC for a CVE.

[1] https://en.wikipedia.org/wiki/Salvatore_Sanfilippo


I actually like when that happens. Like when people "correct" me about how reddit works. I appreciate that we still focus on the content and not who is saying it.


That's not really what happened on this thread. Someone said something sensible and banal about vulnerability research, then someone else said do-you-even-lift-bro, and got shown up.


That's true in this particular case, but I was talking more about the general case.


This happens over and over in these discussions. It doesn't matter who you're citing or who's talking. People are terrified and are reacting to news reflexively.


Hi! Loved your recent post about the new era of computer security, thanks.


Thank you! Glad you liked it.


Personally, I’m tired of exaggerated claims and hype peddlers.

Edit: Frankly, accusing perceived opponents of being too afraid to see the truth is poor argumentative practice, and practically never true.


Sure he wrote a port scanner that obscures the IP address of the scanner, but does he know anything about security? /s

Oh, and he wrote Redis. No biggie.


That's both wholly different branches than finding software bugs


I am going to ask a question that I’m a little scared to ask because I suspect it’s really dumb, but here goes: is it at all feasible or practical to have a way to jettison a runaway battery from the aircraft? I guess most of the time the problems happen because nobody knows there’s a problem before it’s gotten too out of control for that.


You’d have to devise some sort of fire proof mini airlock, large enough for a laptop or whatever the largest device you expect to deal with. This would be pretty expensive and not very practical, but even if it was, then you’d have to deal with the ethical and legal issues of where it lands and whether or not it might cause a fire there too, to say nothing of injuring someone or damaging property.


> You’d have to devise some sort of fire proof mini airlock

Maritime patrol aircraft like the P-8 already have such a system, for releasing sonobuoys and float-flares while at altitude.

So it's not a technical issue, more one of regulation and maintenance.


Sure, I wasn’t trying to imply that it couldn’t be done, only that it would be expensive and impractical for civilian aviation, especially when there are good alternatives.


> then you’d have to deal with the ethical and legal issues of where it lands

Meh, it's a risk reduction thing. Aircraft sometimes dump fuel too in emergencies: https://en.wikipedia.org/wiki/Fuel_dumping

Earth is covered with a lot of water too, if you could eject it... risk is approaching zero on dumping a flaming battery over ocean.


dumped fuel does not land on the ground, it evaporates



it'd get caught by a bird


it was on a taxiway. The fire truck had to cross the runway to get to it.


Thanks for the info, I wasnt sure if the fire truck crossing the runway was normal operation.


I'm familiar with this strategy but there's one thing about it that I don't understand: After death, the loans are an estate liability, right? Doesn't the estate need to be settled before heirs get their inheritance? If i had an outstanding $1MM loan, wouldn't the estate need to liquidate some of that $RIVN at the $67 basis in order to pay the loan? and then whatever $RIVN was left over would go to the heirs at a stepped-up basis?


The step up in basis happens when you die, so the estate has no capital gain. Then the debts are paid, then the heirs get whatever they're supposed to get.


Ok thank you. That was the key to my misunderstanding.


I conflated the two, since it all happens pretty quickly, but the estate is actually the recipient of the updated basis. So the estate sells @ current price, pays the negligible difference on gains from appreciation while the estate settles, if any happened, and then passes out the rest.


Jeff Epstein? The New York financier?


Do we need to wait for a tragedy before we do something? Good on the airlines and regulators for recognizing a burgeoning problem and taking action before (hopefully) it leads to unnecessary deaths.


> Do we need to wait for a tragedy before we do something?

Yes, absolutely. It isn't pleasant to think about, but laws and regulations are meaningless if they aren't based on actual numbers. If I wanted to propose some new feature at work, people would understandably want to see some numbers and not just “feels nice” lol


People have died during fires on the tarmac while trying to evacuate. Every second saved could mean another person lives.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: