Hacker Newsnew | past | comments | ask | show | jobs | submit | drewvlaz's commentslogin

Wow did not realize a url could be set like that without promoting a page reload...


To be clear only the path and query parameters part of the url can change, the domain (or sub domain) stays intact.


Even scarier to me than the vulnerability is that Fidelity (whom I personally think is a good bank and investment company) was using a third party that allowed injection that could potentially steal a whole lot of money, affect markets, ruin or terminate billions of lives, and affect the course of humanity. What the fuck.


Their knowledge of finance is certainly better than their knowledge of web tech.

Historically and today.


That’s why I’m a Schwab junkie… but finance is a hotspot for this kind of stuff.


If it weren't already in the same domain you wouldn't be able to read a non-HttpOnly cookie anyway, so that's moot.


Well that's how SPAs work (single page applications)


One really has to wonder what their actual margins are though, considering the Claude Code plans vs API pricing


One of the largest issues I've experienced is LLMs being too agreeable.

I don't want my theories parroted back to me on why something went wrong. I want to have ideas challenged in a way that forces me to think and hopefully lead me to a new perspective that I otherwise would have missed.

Perhaps a large portion of people do enjoy the agreeableness, but this becomes a problem not only because I think there are larger societal issues that stem from this echo-chamber like environmental but also simply that companies training these models may interpret agreeableness as somehow better and something that should be optimized for.


That’s simple - after it tries to be helpful and agreeable I just ask for a “devils advocate” response. I have a much longer prompt I use sometimes involve being a “sparring partner”.

And I go back and forth sometimes between correcting its devils advocate responses and “steel man” responses.


This was quite a fun read, thanks!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: