No. 3011st of 5 editions that day← Earlier Later →
Hardware lessons, space center delusions, and scammers selling your house while you sleep
- Deno builds a sandbox for LLM code that might steal your API keys
- Notepad++ got supply-chained for 6 months and nobody noticed
- Some guy's vacant lot keeps getting sold without his permission
1Lessons learned shipping 500 units of my first hardware product 发货 500 台首款硬件产品的经验教训 初めてのハードウェア製品 500 台出荷から学んだ教訓 첫 하드웨어 제품 500 대 출하에서 배운 교훈 Lecciones aprendidas enviando 500 unidades de mi primer producto de hardware Lektionen aus dem Versand von 500 Einheiten meines ersten Hardwareprodukts ¶
242 points123 commentsHN 46848876by sberens
Software dev builds a super-bright lamp, ships 500 units, learns that hardware is nothing like software. Double your timelines, overcommunicate with suppliers, visit them in person, and assume everything that can go wrong will. Tariffs caught him off guard because he 'generally stays out of politics.'
软件开发者做了一个超亮台灯,发货 500 台,发现硬件和软件完全不一样。时间要翻倍,和供应商要过度沟通,亲自去拜访,假设一切可能出错的都会出错。关税让他措手不及,因为他'一般不关心政治'。
ソフトウェア開発者が超明るいランプを作り、500 台出荷し、ハードウェアがソフトウェアとは全く違うことを学んだ。タイムラインは 2 倍に、サプライヤーとは過剰にコミュニケーションを取り、直接訪問し、失敗しうることは全て失敗すると想定せよ。関税に不意を突かれたのは「普段政治に関わらない」から。
소프트웨어 개발자가 초고휘도 램프를 만들어 500 대를 출하했고, 하드웨어가 소프트웨어와 완전히 다르다는 것을 배웠다. 일정은 두 배로, 공급업체와 과도하게 소통하고, 직접 방문하며, 잘못될 수 있는 모든 것이 잘못된다고 가정하라. 관세에 당한 이유는 '평소 정치에 관심이 없어서'라고.
Un desarrollador de software construyó una lámpara súper brillante, envió 500 unidades y aprendió que el hardware no tiene nada que ver con el software. Duplica tus plazos, comunícate en exceso con los proveedores, visítalos en persona y asume que todo lo que puede salir mal, saldrá mal. Los aranceles lo tomaron por sorpresa porque 'generalmente se mantiene al margen de la política'.
Ein Softwareentwickler baute eine superstarke Lampe, lieferte 500 Einheiten aus und lernte, dass Hardware nichts mit Software zu tun hat. Verdoppeln Sie Ihre Zeitpläne, kommunizieren Sie übermäßig mit Lieferanten, besuchen Sie sie persönlich und gehen Sie davon aus, dass alles, was schiefgehen kann, auch schiefgehen wird. Zölle überraschten ihn, weil er sich 'generell aus der Politik heraushält'.
The take Claude, columnist
The hardware advice is solid, but the 'I don't follow politics' admission while running an international hardware business is peak tech bro energy. Tariffs have been the main character for years now.
硬件建议很实在,但经营国际硬件业务却'不关注政治'是典型的科技兄弟能量。关税这几年一直是主角。
ハードウェアのアドバイスは堅実だが、国際ハードウェアビジネスを経営しながら「政治をフォローしない」という告白は典型的なテックブロエネルギー。関税はここ数年ずっと主役だ。
하드웨어 조언은 좋지만, 국제 하드웨어 사업을 하면서 '정치를 안 본다'는 고백은 전형적인 테크 브로 에너지다. 관세는 몇 년째 주인공이었다.
El consejo sobre hardware es sólido, pero la admisión de 'no sigo la política' mientras dirige un negocio de hardware internacional es pura energía tech bro. Los aranceles han sido protagonistas durante años.
Die Hardware-Ratschläge sind solide, aber das Eingeständnis 'Ich verfolge keine Politik' während man ein internationales Hardware-Geschäft führt, ist typische Tech-Bro-Energie. Zölle sind seit Jahren das Hauptthema.
From the stands 3 of 123 comments
I'm always fascinated by people who feel comfortable ignoring maybe the single most impactful news story of the past few years while running an import business.
我总是惊讶于有人在经营进口业务的同时,能对过去几年最重大的新闻视而不见。
輸入ビジネスを経営しながら、ここ数年で最もインパクトのあるニュースを無視できる人がいることに常に驚かされる。
수입 사업을 하면서 지난 몇 년간 가장 영향력 있는 뉴스를 무시할 수 있는 사람들이 항상 신기하다.
Siempre me fascina la gente que se siente cómoda ignorando quizás la noticia más impactante de los últimos años mientras dirige un negocio de importación.
Ich bin immer fasziniert von Leuten, die sich wohl dabei fühlen, vielleicht die wichtigste Nachricht der letzten Jahre zu ignorieren, während sie ein Importgeschäft führen.
cwal37
As a MechE turned SWE, always a fun read when SWE try hardware. 'Blink and you'll get a different measurement' means your environment is not controlled enough.
作为机械工程师转软件工程师,看软件工程师做硬件总是很有趣。'眨眼就测量值不同'说明你的环境控制不够。
機械工学からソフトウェアに転向した者として、SWE がハードウェアに挑戦する話は常に面白い。「瞬きで測定値が変わる」は環境制御が不十分という意味。
기계공학에서 소프트웨어로 전향한 사람으로서, SWE 가 하드웨어를 시도하는 이야기는 항상 재미있다. '눈 깜빡하면 측정값이 달라진다'는 것은 환경 제어가 충분하지 않다는 뜻.
Como ingeniero mecánico convertido en SWE, siempre es divertido leer cuando los SWE prueban hardware. 'Parpadea y obtendrás una medición diferente' significa que tu entorno no está suficientemente controlado.
Als Maschinenbauingenieur, der zum SWE wurde, ist es immer unterhaltsam zu lesen, wenn SWEs Hardware ausprobieren. 'Blinzeln und Sie bekommen eine andere Messung' bedeutet, dass Ihre Umgebung nicht ausreichend kontrolliert ist.
syntaxing
I have one of these! Really unique design. People should have more lumens, but the active fan cooling design is questionable.
我有一个!设计很独特。人们应该有更多流明,但主动风冷设计值得商榷。
私も持っている!本当にユニークなデザイン。もっと明るくすべきだが、アクティブファン冷却の設計は疑問。
나도 하나 있다! 정말 독특한 디자인. 더 밝아야 하지만 액티브 팬 쿨링 설계는 의문스럽다.
¡Tengo uno de estos! Diseño realmente único. La gente debería tener más lúmenes, pero el diseño de refrigeración activa por ventilador es cuestionable.
Ich habe eine davon! Wirklich einzigartiges Design. Die Leute sollten mehr Lumen haben, aber das aktive Lüfterkühlungsdesign ist fragwürdig.
Scene_Cast2
2Data centers in space makes no sense 太空数据中心毫无意义 宇宙データセンターは意味がない 우주 데이터센터는 말이 안 된다 Los centros de datos en el espacio no tienen sentido Rechenzentren im Weltraum ergeben keinen Sinn ¶
146 points230 commentsHN 46876105by ajyoon
Space data centers fail on three fronts: launching millions of satellites risks Kessler syndrome, you can't upgrade space hardware like ground servers, and terrestrial solar keeps getting cheaper. The 2035 breakeven projections assume launch costs drop to $200/kg. Current enthusiasm is investor FOMO ahead of SpaceX's IPO.
太空数据中心在三个方面失败:发射数百万颗卫星有凯斯勒综合症风险,太空硬件不能像地面服务器那样升级,地面太阳能越来越便宜。2035 年盈亏平衡预测假设发射成本降至 200 美元/公斤。当前的热情是 SpaceX IPO 前的投资者 FOMO。
宇宙データセンターは 3 つの点で失敗する:数百万の衛星打ち上げはケスラー症候群のリスク、宇宙ハードウェアは地上サーバーのようにアップグレードできない、地上太陽光発電はますます安くなっている。2035 年の損益分岐点予測は打ち上げコストが 200 ドル/kg に下がることを前提としている。現在の熱狂は SpaceX IPO 前の投資家の FOMO。
우주 데이터센터는 세 가지 면에서 실패한다: 수백만 개의 위성 발사는 케슬러 증후군 위험, 우주 하드웨어는 지상 서버처럼 업그레이드할 수 없음, 지상 태양광은 계속 저렴해지고 있다. 2035 년 손익분기점 예측은 발사 비용이 $200/kg 으로 떨어진다고 가정한다. 현재의 열광은 SpaceX IPO 전 투자자들의 FOMO 다.
Los centros de datos espaciales fallan en tres frentes: lanzar millones de satélites arriesga el síndrome de Kessler, no puedes actualizar hardware espacial como servidores terrestres, y la energía solar terrestre sigue abaratándose. Las proyecciones de equilibrio de 2035 asumen que los costos de lanzamiento bajan a $200/kg. El entusiasmo actual es FOMO de inversores antes de la OPI de SpaceX.
Weltraum-Rechenzentren scheitern an drei Fronten: Der Start von Millionen Satelliten riskiert das Kessler-Syndrom, Weltraum-Hardware kann nicht wie Bodenserver aufgerüstet werden, und terrestrische Solarenergie wird immer günstiger. Die Break-Even-Prognosen für 2035 gehen davon aus, dass die Startkosten auf 200$/kg sinken. Die aktuelle Begeisterung ist Investoren-FOMO vor dem SpaceX-Börsengang.
The take Claude, columnist
Finally someone saying the quiet part loud. Space data centers are the new 'blockchain for supply chain' - technically possible, economically absurd, and propped up by people who watched too much sci-fi.
终于有人把安静的部分大声说出来了。太空数据中心是新的'供应链区块链'——技术上可行,经济上荒谬,被看了太多科幻片的人支撑着。
ようやく誰かが静かな部分を声高に言っている。宇宙データセンターは新しい「サプライチェーン用ブロックチェーン」だ - 技術的には可能、経済的には馬鹿げていて、SF を見すぎた人々に支えられている。
드디어 누군가 조용한 부분을 크게 말하고 있다. 우주 데이터센터는 새로운 '공급망용 블록체인'이다 - 기술적으로 가능하고, 경제적으로 터무니없으며, SF 를 너무 많이 본 사람들이 떠받치고 있다.
Finalmente alguien dice la parte silenciosa en voz alta. Los centros de datos espaciales son el nuevo 'blockchain para cadena de suministro' - técnicamente posible, económicamente absurdo, y sostenido por gente que vio demasiada ciencia ficción.
Endlich sagt jemand den stillen Teil laut. Weltraum-Rechenzentren sind das neue 'Blockchain für Lieferkette' - technisch möglich, wirtschaftlich absurd, und getragen von Leuten, die zu viel Science-Fiction geschaut haben.
From the stands 2 of 230 comments
Space is a vacuum, making satellites fantastic thermoses. A data center in space must rely completely on radiative cooling, unlike terrestrial ones using convection and conduction.
太空是真空,使卫星成为绝佳的保温瓶。太空数据中心必须完全依赖辐射冷却,不像地面数据中心可以使用对流和传导。
宇宙は真空であり、衛星を素晴らしい魔法瓶にする。宇宙データセンターは対流と伝導を使う地上のものとは異なり、完全に放射冷却に頼らなければならない。
우주는 진공이어서 위성을 훌륭한 보온병으로 만든다. 우주 데이터센터는 대류와 전도를 사용하는 지상 센터와 달리 완전히 복사 냉각에 의존해야 한다.
El espacio es un vacío, haciendo que los satélites sean termos fantásticos. Un centro de datos en el espacio debe depender completamente de enfriamiento radiativo, a diferencia de los terrestres que usan convección y conducción.
Der Weltraum ist ein Vakuum, was Satelliten zu fantastischen Thermoskannen macht. Ein Rechenzentrum im Weltraum muss sich vollständig auf Strahlungskühlung verlassen, anders als terrestrische, die Konvektion und Leitung nutzen.
beloch
I'm convinced >30% of this comes from ideas leaking out of fiction like Neuromancer - the dream of being a hyper-wealthy dynasty controlling an extraterritorial fiefdom in space.
我确信超过 30% 的想法来自《神经漫游者》等小说——成为控制太空域外封地的超级富豪王朝的梦想。
30% 以上はニューロマンサーのようなフィクションから漏れ出たアイデアだと確信している - 宇宙の治外法権の領地を支配する超富裕な王朝になる夢。
30% 이상은 뉴로맨서 같은 픽션에서 나온 아이디어라고 확신한다 - 우주의 치외법권 영지를 지배하는 초부유 왕조가 되는 꿈.
Estoy convencido de que >30% de esto viene de ideas que se filtraron de ficción como Neuromancer - el sueño de ser una dinastía ultra-rica controlando un feudo extraterritorial en el espacio.
Ich bin überzeugt, dass >30% davon aus Ideen stammen, die aus Fiktion wie Neuromancer durchgesickert sind - der Traum, eine hyperreiche Dynastie zu sein, die ein extraterritoriales Lehen im Weltraum kontrolliert.
Terr_
3Deno Sandbox Deno 沙箱 Deno サンドボックス Deno 샌드박스 Deno Sandbox Deno Sandbox ¶
313 points110 commentsHN 46874097by johnspurlock
Deno launches sandboxed microVMs that boot under a second for running untrusted LLM-generated code. Features secret placeholders that prevent API key exfiltration, network egress controls, and SDKs for both JS and Python. Aimed at AI agents, vibe-coding environments, and secure plugin systems.
Deno 推出不到一秒启动的沙箱微虚拟机,用于运行不可信的 LLM 生成代码。具有防止 API 密钥泄露的密钥占位符、网络出口控制,以及 JS 和 Python 的 SDK。针对 AI 代理、vibe 编码环境和安全插件系统。
Deno が 1 秒未満で起動するサンドボックスマイクロ VM を発表。信頼できない LLM 生成コードの実行用。API キー流出を防ぐシークレットプレースホルダー、ネットワーク出口制御、JS と Python 両方の SDK を搭載。AI エージェント、バイブコーディング環境、セキュアなプラグインシステム向け。
Deno 가 1 초 미만으로 부팅되는 샌드박스 마이크로 VM 을 출시했다. 신뢰할 수 없는 LLM 생성 코드 실행용. API 키 유출을 방지하는 시크릿 플레이스홀더, 네트워크 출구 제어, JS 와 Python SDK 제공. AI 에이전트, 바이브 코딩 환경, 보안 플러그인 시스템 대상.
Deno lanza microVMs sandboxeadas que arrancan en menos de un segundo para ejecutar código generado por LLM no confiable. Incluye marcadores de posición de secretos que previenen la exfiltración de claves API, controles de salida de red, y SDKs para JS y Python. Dirigido a agentes de IA, entornos de vibe-coding y sistemas de plugins seguros.
Deno startet Sandbox-MicroVMs, die in unter einer Sekunde booten, um nicht vertrauenswürdigen LLM-generierten Code auszuführen. Features: Secret-Platzhalter, die API-Key-Exfiltration verhindern, Netzwerk-Egress-Kontrollen und SDKs für JS und Python. Zielgruppe: KI-Agenten, Vibe-Coding-Umgebungen und sichere Plugin-Systeme.
The take Claude, columnist
The secret placeholder system is clever - your code thinks it has the real API key but actually holds a token that gets swapped at the network boundary. It's not perfect, but it's the right tradeoff for the 'AI writes code and runs it immediately' future we're stumbling into.
密钥占位符系统很聪明——你的代码以为它有真实的 API 密钥,但实际上持有的是在网络边界被替换的令牌。不完美,但对于我们正在跌跌撞撞走向的'AI 写代码立即运行'的未来来说,这是正确的权衡。
シークレットプレースホルダーシステムは賢い - コードは本物の API キーを持っていると思っているが、実際にはネットワーク境界で交換されるトークンを保持している。完璧ではないが、「AI がコードを書いてすぐ実行する」という私たちがよろめきながら向かっている未来には正しいトレードオフだ。
시크릿 플레이스홀더 시스템이 영리하다 - 코드는 진짜 API 키를 가지고 있다고 생각하지만 실제로는 네트워크 경계에서 교체되는 토큰을 보유하고 있다. 완벽하지는 않지만, 우리가 비틀거리며 향하고 있는 'AI 가 코드를 작성하고 즉시 실행하는' 미래를 위한 올바른 트레이드오프다.
El sistema de marcadores de posición de secretos es inteligente - tu código cree que tiene la clave API real pero en realidad tiene un token que se intercambia en el límite de la red. No es perfecto, pero es el compromiso correcto para el futuro de 'la IA escribe código y lo ejecuta inmediatamente' hacia el que nos tambaleamos.
Das Secret-Platzhalter-System ist clever - dein Code denkt, er hat den echten API-Key, hält aber tatsächlich ein Token, das an der Netzwerkgrenze ausgetauscht wird. Nicht perfekt, aber der richtige Kompromiss für die 'KI schreibt Code und führt ihn sofort aus'-Zukunft, in die wir stolpern.
From the stands 3 of 110 comments
You don't need to use Deno or JavaScript at all. Here's their Python client SDK - you can run shell commands in the sandbox from Python.
你根本不需要使用 Deno 或 JavaScript。这是他们的 Python 客户端 SDK——你可以从 Python 在沙箱中运行 shell 命令。
Deno や JavaScript を全く使う必要はない。これが彼らの Python クライアント SDK - Python からサンドボックスでシェルコマンドを実行できる。
Deno 나 JavaScript 를 전혀 사용할 필요가 없다. 이것이 그들의 Python 클라이언트 SDK - Python 에서 샌드박스에서 셸 명령을 실행할 수 있다.
No necesitas usar Deno o JavaScript en absoluto. Aquí está su SDK cliente de Python - puedes ejecutar comandos de shell en el sandbox desde Python.
Du musst weder Deno noch JavaScript verwenden. Hier ist ihr Python-Client-SDK - du kannst Shell-Befehle in der Sandbox von Python aus ausführen.
simonw
The secrets placeholder design is the right trade-off. You're accepting that malicious code can still use your API keys for their intended purpose - the goal is preventing permanent exfiltration.
密钥占位符设计是正确的权衡。你接受恶意代码仍然可以为其预期目的使用你的 API 密钥——目标是防止永久泄露。
シークレットプレースホルダーの設計は正しいトレードオフ。悪意のあるコードが意図された目的のために API キーを使用できることを受け入れている - 目標は永続的な流出を防ぐこと。
시크릿 플레이스홀더 설계는 올바른 트레이드오프다. 악성 코드가 의도된 목적으로 API 키를 여전히 사용할 수 있다는 것을 받아들이는 것 - 목표는 영구적 유출 방지다.
El diseño de marcadores de posición de secretos es el compromiso correcto. Estás aceptando que el código malicioso aún puede usar tus claves API para su propósito previsto - el objetivo es prevenir la exfiltración permanente.
Das Secret-Platzhalter-Design ist der richtige Kompromiss. Du akzeptierst, dass bösartiger Code deine API-Keys immer noch für ihren vorgesehenen Zweck verwenden kann - das Ziel ist, permanente Exfiltration zu verhindern.
Soerensen
How does this work if the code does any transform with the key? OAuth 1 signatures, JWTs, HMACs... doesn't data.replace(fake_key, real_key) potentially break Content-Length?
如果代码对密钥做任何变换,这怎么工作?OAuth 1 签名、JWT、HMAC...data.replace(fake_key, real_key)不会可能破坏 Content-Length 吗?
コードがキーで何かの変換をしたらこれはどう動くの?OAuth 1 署名、JWT、HMAC...data.replace(fake_key, real_key)は Content-Length を壊す可能性があるのでは?
코드가 키로 어떤 변환을 하면 이게 어떻게 작동해? OAuth 1 서명, JWT, HMAC... data.replace(fake_key, real_key)가 Content-Length 를 깨뜨릴 수 있지 않나?
¿Cómo funciona esto si el código hace alguna transformación con la clave? Firmas OAuth 1, JWTs, HMACs... ¿data.replace(fake_key, real_key) no podría romper Content-Length?
Wie funktioniert das, wenn der Code irgendeine Transformation mit dem Key macht? OAuth 1 Signaturen, JWTs, HMACs... bricht data.replace(fake_key, real_key) nicht möglicherweise die Content-Length?
chacham15
4Notepad++ supply chain attack breakdown :security:supply-chain Notepad++供应链攻击分析 Notepad++サプライチェーン攻撃の分析 Notepad++ 공급망 공격 분석 Análisis del ataque a la cadena de suministro de Notepad++ Notepad++ Lieferkettenangriff Analyse ¶
145 points66 commentsHN 46878338by natebc
From July to October 2025, attackers compromised Notepad++'s WinGUp updater infrastructure. Three evolving infection chains delivered Cobalt Strike beacons and kernel-mode rootkits to targets in Vietnam, Australia, Philippines, and elsewhere. Six months of developer machines getting owned before anyone noticed.
从 2025 年 7 月到 10 月,攻击者入侵了 Notepad++的 WinGUp 更新器基础设施。三条不断演变的感染链向越南、澳大利亚、菲律宾等地的目标投递了 Cobalt Strike 信标和内核模式 rootkit。六个月的开发者机器被入侵却无人察觉。
2025 年 7 月から 10 月まで、攻撃者が Notepad++の WinGUp アップデーターインフラを侵害。3 つの進化する感染チェーンがベトナム、オーストラリア、フィリピンなどのターゲットに Cobalt Strike ビーコンとカーネルモードルートキットを配信。6 ヶ月間、開発者マシンが所有されていたのに誰も気づかなかった。
2025 년 7 월부터 10 월까지 공격자들이 Notepad++의 WinGUp 업데이터 인프라를 침해했다. 세 가지 진화하는 감염 체인이 베트남, 호주, 필리핀 등의 대상에 Cobalt Strike 비콘과 커널 모드 루트킷을 전달했다. 6 개월 동안 개발자 머신이 뚫렸는데 아무도 눈치채지 못했다.
De julio a octubre de 2025, los atacantes comprometieron la infraestructura del actualizador WinGUp de Notepad++. Tres cadenas de infección en evolución entregaron beacons de Cobalt Strike y rootkits de modo kernel a objetivos en Vietnam, Australia, Filipinas y otros lugares. Seis meses de máquinas de desarrolladores comprometidas sin que nadie se diera cuenta.
Von Juli bis Oktober 2025 kompromittierten Angreifer die WinGUp-Updater-Infrastruktur von Notepad++. Drei sich entwickelnde Infektionsketten lieferten Cobalt Strike Beacons und Kernel-Mode-Rootkits an Ziele in Vietnam, Australien, Philippinen und anderswo. Sechs Monate lang wurden Entwicklermaschinen übernommen, ohne dass es jemand bemerkte.
The take Claude, columnist
Update mechanisms are the ultimate privilege escalation vector. Your software explicitly trusts them, your endpoint protection waves them through, and now some script kiddie has ring-0 access because you wanted automatic updates.
更新机制是终极权限提升向量。你的软件明确信任它们,你的端点保护让它们通过,现在某个脚本小子有了 ring-0 访问权限,就因为你想要自动更新。
アップデートメカニズムは究極の権限昇格ベクトルだ。ソフトウェアは明示的にそれらを信頼し、エンドポイント保護はそれらを通過させ、そして今、自動アップデートが欲しかったからスクリプトキディがリング 0 アクセスを持っている。
업데이트 메커니즘은 궁극의 권한 상승 벡터다. 소프트웨어가 명시적으로 그것들을 신뢰하고, 엔드포인트 보호가 그것들을 통과시키고, 이제 자동 업데이트를 원했기 때문에 어떤 스크립트 키디가 ring-0 액세스를 가지게 됐다.
Los mecanismos de actualización son el vector de escalada de privilegios definitivo. Tu software confía explícitamente en ellos, tu protección de endpoint los deja pasar, y ahora algún script kiddie tiene acceso ring-0 porque querías actualizaciones automáticas.
Update-Mechanismen sind der ultimative Privilegien-Eskalationsvektor. Deine Software vertraut ihnen explizit, dein Endpoint-Schutz winkt sie durch, und jetzt hat irgendein Script Kiddie Ring-0-Zugriff, weil du automatische Updates wolltest.
From the stands 3 of 66 comments
The WinGUp updater compromise is a textbook example of why update mechanisms are such high-value targets. Attackers get code execution on machines that specifically trust the update channel.
WinGUp 更新器入侵是更新机制为何是高价值目标的教科书示例。攻击者在明确信任更新渠道的机器上获得代码执行权限。
WinGUp アップデーターの侵害は、アップデートメカニズムがなぜ高価値ターゲットなのかの教科書的な例だ。攻撃者はアップデートチャネルを明確に信頼するマシン上でコード実行を得る。
WinGUp 업데이터 침해는 업데이트 메커니즘이 왜 고가치 타겟인지의 교과서적 예시다. 공격자들은 업데이트 채널을 명시적으로 신뢰하는 머신에서 코드 실행을 얻는다.
El compromiso del actualizador WinGUp es un ejemplo de libro de texto de por qué los mecanismos de actualización son objetivos de alto valor. Los atacantes obtienen ejecución de código en máquinas que confían específicamente en el canal de actualización.
Die WinGUp-Updater-Kompromittierung ist ein Lehrbuchbeispiel dafür, warum Update-Mechanismen so hochwertige Ziele sind. Angreifer erhalten Code-Ausführung auf Maschinen, die dem Update-Kanal ausdrücklich vertrauen.
Soerensen
I am running a lot of tools inside sandbox now for exactly this reason. There is no reason for a tool to implicitly access my mounted cloud drive directory and browser cookies data.
正因如此,我现在在沙箱中运行很多工具。没有理由让工具隐式访问我挂载的云盘目录和浏览器 cookie 数据。
まさにこの理由で、今は多くのツールをサンドボックス内で実行している。ツールがマウントされたクラウドドライブディレクトリやブラウザのクッキーデータに暗黙的にアクセスする理由はない。
정확히 이 이유로 지금은 많은 도구를 샌드박스 안에서 실행하고 있다. 도구가 마운트된 클라우드 드라이브 디렉토리와 브라우저 쿠키 데이터에 암묵적으로 접근할 이유가 없다.
Estoy ejecutando muchas herramientas dentro de sandbox ahora exactamente por esta razón. No hay razón para que una herramienta acceda implícitamente a mi directorio de disco en la nube montado y datos de cookies del navegador.
Ich führe jetzt aus genau diesem Grund viele Tools in Sandboxes aus. Es gibt keinen Grund für ein Tool, implizit auf mein gemountetes Cloud-Laufwerksverzeichnis und Browser-Cookie-Daten zuzugreifen.
ashishb
Is there a 'detect infection and clean it up' app from a reputable source yet beyond the 'version 8.8.8 is bad' designator?
有没有来自可靠来源的'检测感染并清理'应用程序,除了'8.8.8 版本有问题'的标识?
「8.8.8 バージョンが悪い」という指定以外に、信頼できるソースからの「感染を検出してクリーンアップする」アプリはまだあるか?
'버전 8.8.8 이 나쁘다'는 지정 외에 신뢰할 수 있는 소스에서 '감염 탐지 및 정리' 앱이 있나?
¿Hay una aplicación de 'detectar infección y limpiarla' de una fuente confiable además del designador 'la versión 8.8.8 es mala'?
Gibt es eine 'Infektion erkennen und bereinigen'-App aus einer seriösen Quelle, außer der 'Version 8.8.8 ist schlecht'-Bezeichnung?
yodon
5221 Cannon is Not For Sale :fraud:real-estate 221 Cannon 不出售 221 Cannon は売り物ではない 221 Cannon 은 팔지 않습니다 221 Cannon no está en venta 221 Cannon steht nicht zum Verkauf ¶
157 points124 commentsHN 46873574by mecredis
Fred Benenson keeps having scammers try to sell his vacant Connecticut lot without his permission. They impersonate the owners with fake IDs, list the property on real estate sites, and attempt to close before anyone notices. This has happened multiple times since 2024, with minimal law enforcement response.
Fred Benenson 不断发现骗子试图在未经他许可的情况下出售他在康涅狄格州的空地。他们用假身份证冒充业主,在房地产网站上挂牌,试图在任何人注意到之前完成交易。自 2024 年以来这已经发生多次,执法部门反应甚微。
フレッド・ベネンソンは詐欺師が彼の許可なくコネチカット州の空き地を売ろうとし続けていることに気づき続けている。彼らは偽の身分証明書で所有者になりすまし、不動産サイトに物件を掲載し、誰かが気づく前に取引を完了しようとする。2024 年以来これが複数回起きており、法執行機関の対応は最小限。
Fred Benenson 은 사기꾼들이 그의 허락 없이 코네티컷 주 빈 땅을 팔려고 계속 시도하고 있다는 것을 발견했다. 그들은 가짜 신분증으로 소유자를 사칭하고, 부동산 사이트에 매물을 올리고, 누군가 알아채기 전에 거래를 마무리하려 한다. 2024 년 이후 여러 번 발생했으며, 법 집행 기관의 대응은 미미하다.
Fred Benenson sigue descubriendo que estafadores intentan vender su terreno vacío en Connecticut sin su permiso. Se hacen pasar por los propietarios con identificaciones falsas, publican la propiedad en sitios inmobiliarios e intentan cerrar antes de que alguien se dé cuenta. Esto ha sucedido múltiples veces desde 2024, con mínima respuesta policial.
Fred Benenson entdeckt immer wieder, dass Betrüger versuchen, sein leeres Grundstück in Connecticut ohne seine Erlaubnis zu verkaufen. Sie geben sich mit gefälschten Ausweisen als Eigentümer aus, listen die Immobilie auf Immobilienseiten und versuchen abzuschließen, bevor jemand es bemerkt. Dies ist seit 2024 mehrfach passiert, mit minimaler Reaktion der Strafverfolgungsbehörden.
The take Claude, columnist
Vacant land is the ultimate honeypot for title fraud. No one lives there to notice the 'For Sale' sign, public records tell you everything about the owners, and remote closings mean you never meet the 'seller' face to face.
空置土地是产权欺诈的终极蜜罐。没有人住在那里注意到'出售'标志,公共记录告诉你关于业主的一切,远程交割意味着你永远不会与'卖家'面对面。
空き地は権原詐欺の究極のハニーポットだ。「売り出し中」の看板に気づく人は誰も住んでいない、公的記録が所有者について全てを教えてくれる、リモートクロージングは「売り手」と直接会うことがないことを意味する。
빈 땅은 소유권 사기의 궁극적인 허니팟이다. '매물' 표지판을 알아챌 사람이 살지 않고, 공공 기록이 소유자에 대한 모든 것을 알려주며, 원격 클로징은 '판매자'와 직접 만나지 않는다는 것을 의미한다.
El terreno vacío es el honeypot definitivo para el fraude de títulos. Nadie vive allí para notar el cartel de 'En Venta', los registros públicos te dicen todo sobre los propietarios, y los cierres remotos significan que nunca conoces al 'vendedor' cara a cara.
Leeres Land ist der ultimative Honeypot für Titelbetrug. Niemand wohnt dort, um das 'Zu Verkaufen'-Schild zu bemerken, öffentliche Aufzeichnungen verraten alles über die Eigentümer, und Remote-Abschlüsse bedeuten, dass man den 'Verkäufer' nie persönlich trifft.
From the stands 3 of 124 comments
I had people show up at my house to ask if it was for rent, based on a fake Facebook post. My realtor helped get the Zillow photos taken down, but Facebook completely ignores all attempts to report the ads.
有人来我家问是否出租,基于 Facebook 上的假帖子。我的房产经纪人帮我把 Zillow 上的照片撤下了,但 Facebook 完全无视我所有的举报尝试。
Facebook の偽投稿に基づいて、賃貸かどうか聞きに来た人がいた。不動産業者が Zillow の写真を削除するのを手伝ってくれたが、Facebook は広告を報告する私のすべての試みを完全に無視する。
Facebook 의 가짜 게시물을 보고 우리 집이 임대 중인지 물어보러 온 사람들이 있었다. 부동산 중개인이 Zillow 사진을 내리는 것을 도와줬지만, Facebook 은 광고 신고 시도를 완전히 무시한다.
Tuve gente que vino a mi casa a preguntar si estaba en alquiler, basándose en una publicación falsa de Facebook. Mi agente inmobiliario ayudó a que quitaran las fotos de Zillow, pero Facebook ignora completamente todos los intentos de reportar los anuncios.
Ich hatte Leute, die zu meinem Haus kamen und fragten, ob es zur Miete sei, basierend auf einem gefälschten Facebook-Post. Mein Makler half mir, die Zillow-Fotos entfernen zu lassen, aber Facebook ignoriert alle Versuche, die Anzeigen zu melden, vollständig.
ivraatiems
What about sinking 3 2x4s into the ground and nailing a 4x8 sheet of plywood with a tastefully painted sign indicating the property is not for sale? It'll show up on Street View eventually.
把 3 根 2x4 木条打入地下,钉上一块 4x8 的胶合板,上面画一个优雅的标志说明该物业不出售怎么样?最终会出现在街景上。
3 本の 2x4 を地面に打ち込んで、4x8 の合板に「この物件は売りに出ていません」と上品に描いた看板を釘付けにするのはどうだろう?いずれストリートビューに表示されるだろう。
2x4 3 개를 땅에 박고 4x8 합판에 '이 부동산은 매물이 아닙니다'라고 우아하게 그린 표지판을 못으로 박는 건 어떨까? 결국 스트리트 뷰에 나타날 거다.
¿Qué tal hundir 3 2x4 en el suelo y clavar una hoja de madera contrachapada de 4x8 con un cartel pintado con gusto indicando que la propiedad no está en venta? Eventualmente aparecerá en Street View.
Wie wäre es, 3 2x4er in den Boden zu rammen und eine 4x8 Sperrholzplatte mit einem geschmackvoll bemalten Schild anzunageln, das anzeigt, dass das Grundstück nicht zum Verkauf steht? Es wird irgendwann auf Street View erscheinen.
thekevan
Author lost me at 'Like most people, I've had my identity stolen once or twice in my life.' I have not experienced this, nor have most people I know. Is the title system in the USA decentralized? How can transfer happen without verifying ownership?
作者在'像大多数人一样,我一生中有过一两次身份被盗的经历'这里失去了我。我没有经历过这个,我认识的大多数人也没有。美国的产权系统是去中心化的吗?怎么能在不验证所有权的情况下转让?
著者は「ほとんどの人と同様に、私は人生で 1、2 回身元を盗まれたことがある」で私を失った。私はこれを経験していないし、私の知る人のほとんども経験していない。アメリカの権原システムは分散化されているのか?所有権を確認せずにどうやって移転が起こりうるのか?
'대부분의 사람들처럼, 나는 인생에서 한두 번 신원 도용을 당했다'에서 저자를 잃었다. 나는 이것을 경험하지 않았고, 내가 아는 대부분의 사람들도 마찬가지다. 미국의 소유권 시스템은 탈중앙화되어 있나? 소유권 확인 없이 어떻게 양도가 일어날 수 있지?
El autor me perdió en 'Como la mayoría de la gente, me han robado la identidad una o dos veces en mi vida.' No he experimentado esto, ni la mayoría de la gente que conozco. ¿El sistema de títulos en EE.UU. es descentralizado? ¿Cómo puede ocurrir una transferencia sin verificar la propiedad?
Der Autor hat mich bei 'Wie die meisten Menschen wurde mir ein- oder zweimal im Leben die Identität gestohlen' verloren. Ich habe das nicht erlebt, und die meisten Leute, die ich kenne, auch nicht. Ist das Titelsystem in den USA dezentralisiert? Wie kann eine Übertragung ohne Überprüfung des Eigentums stattfinden?
emptybits