Hacker Newsnew | past | comments | ask | show | jobs | submit | corvad's commentslogin

Looks like it was an Oracle PeopleSoft 0-day so I imagine there are a lot more systems vulnerable.

And, was this system exposed to internet without any VPN? Out was it also compromised?

I wonder if that was really a 0-day or an intentional backdoor?

it's Oracle, 99% chance it's a 0-day lol

it's Oracle, 99% chance it's a back-door lol

It's Oracle, 99% chance it's a security-bug in a back-door lol

Hmm ShinyHunters seems to be in the news quite a bit recently. Most high profile was the Canvas LMS hack last spring right during college finals. Wonder if there will be a ransom for this data as well.

They got paid for the Canvas hack allegedly about 10M$ by Infrastructure, so it makes sense to continue. This one probably has a larger price tag

This is why paying the ransom should carry the same sentence as the original hack itself.

they have been on an absolute roll for quite awhile now.

Click-bait title huh. This is not even close to a 0-day. I guess that word has lost all meaning to ArsTechnica huh.

ars and the register have always been closer to the onion than journalism

I think thats more for being able to have the status page not tied to your own infrastructure.

It’s super easy to just run a totally disconnected synthetic check.

This is not anything new they have been around since the tunnels project launched. What is more concerning is the AI slop webpage and just the "AI" centered relaunch of an existing product.


Using google foo it seems its mostly merch: https://www.google.com/search?q=site%3Astore.palantir.com


I would like to buy some incriminating evidence on foreign government officials.

It that still in stock and can it be delivered overnight by FedEx?

Asking for a friend . . .


Pixel Watch 4 seems to perform quite well as well it seems.


I have a biofeedback hobby and have done experiments with HRV. R-R intervals per pulse are quite useful. 5s reporting intervals are too long. Of course I use a EKG Polar Monitor although the literature seems to think a quality PPG or even an advanced radar-based system ought to perform well enough.


Yes, many states in the U.S. have recording laws that prohibit only one party giving consent to record. Aka: I give consent but the other party may not in which case it could be illegal.


Seems like it’s not recording, you can’t access an audio recording.

Just the output of what the AI thinks was in the audio

Also Android has had shazam style always on music recognition for years now with no issues, this isn’t that different


> this isn’t that different

It's entirely different. One is fingerprinting ambient audio against a corpus of known signatures to identify music, another is basically silently monitoring and summarizing every conversation it hears for later review.

I don't feel like my privacy is being invaded by a date's phone telling them what song was playing at the restaurant, but I would be disturbed if their phone produced a summary of our conversation, especially if any vulnerable topics came up.


I feel like I'd also be a little weirded out to find my date referencing the summary or transcript later, maybe that's just me. Like if I said something personal and they whipped out a notebook and wrote it down real fast, that's unnerving.


... but not particularly unfair on your interlocutor, just off putting


The Android feature is matching songs it hears to an on-device database of fingerprints, the other is recording, transcribing, and summarizing all conversations around it. Seems a little different.


Wanted to look at the study's data, but the link seems to be broken. https://www.apple.com/HRAccuracy/


It works fine now.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: