HN

CipherCue measured CDNs for 44,143 tracked European companies and found 89.6% of those using a CDN sit behind Cloudflare (country shares range ~79%–95.6%), highlighting high market concentration and the systemic outage risk when a single front-door provider has incidents. The analysis is based on HTTP/DNS fingerprinting of a cohort skewed to small/mid companies, detects CDNs via response headers (with caveats such as CloudFront/AWS ambiguity), and is not a representative sample of all firms.

cloudflare cdn europe concentration
328 pts 284 comments

The paper generalizes Ken Thompson's trusting‑trust attack beyond compilers by constructing a complete attack that manipulates finished ELF binaries (specifically GNU strip) to implant a payload that propagates across rebuilds. They demonstrate the attack in the NixOS bootstrap: a single tampered strip seeds a payload that survives dependency pruning and backdoors nearly every binary in a built graphical installer, enabling arbitrary malicious behavior across the distribution.

supply-chain security linux nixos
183 pts 40 comments

A GitHub repository offering a reconstructed, educational source-code recreation of the Stuxnet worm for static analysis and defensive research; it reproduces original modules, propagation methods, rootkits, and the PLC-targeting payload that manipulated Siemens Step 7/S7 PLCs. The project includes build instructions, analysis guidance, and legal disclaimers emphasizing academic/non-malicious use.

security malware industrial-control-systems reverse-engineering open-source
135 pts 45 comments
Intellectual Fly Is Open (2025) (bcantrill.dtrace.org)

The author warns that LinkedIn posts generated by LLMs are stylistically obvious, reduce authenticity, and drive readers away; LLMs are useful as tools for brainstorming and editing but shouldn’t replace your own voice.

llms ai linkedin writing authenticity
244 pts 134 comments
She Also Found It at the Movies (hedgehogreview.com)
Analyzing article...
← Prev
Page 23
Next →