Hacker Newsnew | past | comments | ask | show | jobs | submit | new23d's commentslogin

If the workload's network interface (ENI in AWS) is in a VPC that you manage, an outbound traffic filtering solution can prevent that. See AWS Network Firewall or the product we develop, DiscrimiNAT (https://chasersystems.com/), for example.

Rules can be per Security Group, too, for fine-grained access control. I would also strongly recommend that installation of dependencies is a build-time task, not a run-time task, and if those two stages are separated, it makes egress filtering a whole lot more effective since the build-time allowlists are often multi-tenant CDNs where a threat actor can host their own data capturing or malicious payload delivering service.


Three variations on subversive use of DNS by the Agent are documented in Hugging Face's technical writeup of the July 2026 security incident involving OpenAI models. In this article, I discuss what each of these three types of DNS workarounds achieve in practice, the constraints an actor might have faced to attempt a particular one, and additional benefits from choosing each.


Says Not Before: Thu, 09 Jul 2026 01:02:21 GMT ; Not After: Wed, 07 Oct 2026 01:02:20 GMT for me. Works fine, too.


Oh, so what could be a problem?

I have automatic time update set up on mobile so this shouldn’t be an issue…


Did you by chance set up a MitM proxy to debug something on your phone and forgot to disable it? Here is the fingerprint I see:

    Testing via IPv4:
    204.13.239.180
    sha1 Fingerprint=32:6E:23:9D:AC:57:79:D5:30:22:FC:D7:13:65:8E:E9:D9:5C:8D:E8
    sha256 Fingerprint=0B:DF:F8:F2:76:26:32:C6:A5:4C:B8:5E:B1:BD:13:5A:26:E0:FF:CD:9C:D8:FD:B2:40:60:04:F7:B9:22:57:44
    notBefore=Jul  9 01:02:21 2026 GMT
    notAfter=Oct  7 01:02:20 2026 GMT
[1] - https://nochan.net/b/Text-Crap/function_fingerprint.sh


Thanks. I am not aware of anything.

Instead of default Safari, I have tried Firefox and the page displays the same message about validity of ssl_certificate.

But site was down btw, nginx bad gateway - HN kiss of death, I assume…


netim.com has been reliable over the years for me


Our report seeks to answer some of our questions for seven of the most popular agentic code editors and plugins. By intercepting and analysing their network flows across a set of standardised tasks, we aim to gain insight into the behaviour, privacy implications, and telemetry patterns of these tools in real-world scenarios. Incidentally, a side-effect was running into OWASP LLM07:2025 System Prompt Leakage for three of the chosen coding agents. You can see the system prompts in the appendix.


Obfuscation via egress firewalls and evasive binary development with an iterative LLM agent.


Use AWS Route53?


Making a dynamic DNS client with aws and jq CLI, with a least-privilege IAM role and a SystemD service.


Exactly the same happened with me. Picking up the phone and responding to email (in weeks, not hours or days) didn't lower my bills. This sort of marketing is perhaps deflection.


We'll be working on that in the coming days. Thought the data at this point was a good start.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: