frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Belgian CVD is deeply broken

https://devae.re/posts/belgian-cvd-is-deeply-broken/
10•piecrumpled•6h ago

Comments

PeterStuer•1h ago
For non Belgians, ItsMe is an identity/digital signature/2FA app used almost universally in banking, ecommerce and gov in Belgium.

The 'attack' is getting the victim to confirm the identity or signature for you through social engineer them to initiate the set up of a parralel session.

This is possible for inplementations of ItsMe that only rely on Phonenumber/Application, and do not validate the actual session, e.g. by having the user scan an in session QR code.

xchip•1h ago
I'm going to say something unpopular, but unfortunately that attitude is far too common in Belgium, everywhere.. In business, with contractors, with lawyers, in restaurants...

They are rude, they will deny everything, if you try to escalate they threaten you (even if you show them evidences and no matter how well you documented things)... but then if you hold your ground they give up.

I'm not sure if they really believe they are right or they are trying to gaslight you hoping that you will give up

Anyway, thanks for pointing the issue out and don't let this cultural issue stop you from doing the right thing. In the end they will chicken out.

I think this part of the Belgian culture is getting on everybody's nerves. I think this extra 'arrogance tax' makes people think it twice before doing business in Belgium.

I would definitely would like to see more intellectual honesty and sportsmanship.

Thanks for your hard work and for putting up with this.

FirmwareBurner•59m ago
>They are rude, they will deny everything, if you try to escalate they threaten you (even if you show them evidences and no matter how well you documented things)

From my experience as an immigrant, it's exactly the same in Germany and Austria. For the locals who grew up into the system it doesn't feel terrible, but if you grew up in a country with common sense in business, this is infuriating.

>I think this extra 'arrogance tax' makes people think it twice before doing business in Belgium.

I think this is an intentional feature, not a bug. It's a hidden form of protectionism against EU's freedom of movement and trade, to discourage foreigners or small businesses from chapter countries with hustle mentality, to come in and displace entrenched local businesses who would like to have their cake and eat it too, since this pattern appears way too often in EUs rich countries to be just a coincidence. They specifically DON'T WANT YOUR business be opened there because then you're a competitor to the business establishment status quo there, but they can't outright say that.

sunshine-o•40m ago
I am not sure this is specific to Belgium, I have seen this attitude in many countries unfortunately.

The worst is this attitude is also applied internally in those organisations. Too often, everybody knows about some critical vulnerabilities but talking about them will get you in big troubles. This also apply to security consultants and "auditors".

The saddest part is Belgium was, if I remember correctly, at the forefront of online banking security in the early 2000s with strong auth physical tokens and digital signatures [0]

They seem to have switch to this itsme system to cut costs.

- [0] https://en.wikipedia.org/wiki/OneSpan#History

pornel•57m ago
The related "Belgium is unsafe for CVD" post explains that if you discover any vulnerability in anything in Belgium, it automatically creates a legal obligation on you, with a 24h deadline, to report this secretly and exclusively to Belgian authorities, with logs of everything you've done, even if you're not a Belgian citizen and don't reside in Belgium.

This is a very short deadline, with onerous requirements. They most likely won't give you permission to share any information about this vulnerability with anyone else. If it's a common vulnerability affecting non-Belgian entities, you'll be required to leave them uninformed and vulnerable.

The most rational response for law-abiding vulnerability researches is to stay away from everything Belgian and never report anything to them.

RagnarD•29m ago
Moral of the story: Belgium richly deserves the consequences of actual hacking.

Show HN: A NASA Scientist's way to answer life questions turned into a Web App

https://lifemap.kuber.studio/
1•kuberwastaken•12m ago•0 comments

When Is Tech Not Hype? Tulips, Toilets, Trains – and Tabs

https://ajmoon.com/posts/when-is-tech-not-hype-tulips-toilets-trains-and-tabs
1•alex-moon•13m ago•0 comments

Show HN: Terminal-based image viewer using ANSI colors (~300kb, written in C)

1•FerkiHN•16m ago•2 comments

Europe's Quantum Leap Challenges US Dominance

https://cepa.org/article/europes-quantum-leap-challenges-us-dominance/
1•donutloop•19m ago•0 comments

Seriously skip this. Do not look at this garbage comic made by chatgpt.

https://files.catbox.moe/54thkz.png
2•lihaciudaniel•20m ago•1 comments

Self-Destruct SSD

https://industrial.teamgroupinc.com/en/news-detail/P250Q/
3•geox•25m ago•1 comments

Show HN: Compare Speech APIs Live (OpenAI, Google, Deepgram, Soniox, etc.)

https://soniox.com/compare/
3•easwee•26m ago•1 comments

Patent Trolls Account for 1 in Every 4 US Patent Cases: 2024 data says

https://insights.greyb.com/npe-litigation-trend/
7•nitin_flanker•26m ago•0 comments

Converting YouTube ad revenue into trees [video]

https://www.youtube.com/watch?v=T5YF95r_Bew
2•neilbowers•35m ago•2 comments

Show HN: Sync-in – Secure, open-source platform for file collaboration and sync

https://sync-in.com/
1•johaven•38m ago•0 comments

An assessment tool to better prepare for cybersecurity interview

https://cyber-career-launch-yasens.replit.app/
1•priyanshu_101•38m ago•1 comments

Memories Without Brains

https://aeon.co/essays/what-can-slime-mould-teach-us-about-biological-memory
2•the-mitr•38m ago•0 comments

For Algorithms, Memory Is a Far More Powerful Resource Than Time

https://www.wired.com/story/for-algorithms-a-little-memory-outweighs-a-lot-of-time/
4•Anon84•53m ago•1 comments

How WebAssembly is powering WordPress

https://wasmer.io/posts/how-webassembly-is-powering-wordpress
1•syrusakbary•54m ago•0 comments

A Chip8 Emulator For 68000-based Macs

https://hackaday.com/2025/07/15/a-chip8-emulator-for-68000-based-macs/
1•siev•55m ago•0 comments

Does tennis have a doping problem, or a truth problem?

https://www.damianreilly.co.uk/p/magic-potions-and-unanswered-questions
3•myrtlehinch•57m ago•0 comments

How AI on Microcontrollers Actually Works: Registering Operators

https://danielmangum.com/posts/ai-microcontrollers-registering-operators/
1•hasheddan•57m ago•0 comments

Cats as Horror Movie Villains

https://gwern.net/cat-horror
1•mparramon•58m ago•0 comments

New WeTransfer ToS allows them to make derivative works of yours without payment

https://akanchasrivastava.org/read-the-fine-print-or-risk-giving-it-all-away/
3•OgsyedIE•59m ago•0 comments

General Projects

https://digi.ninja/projects_general.php
1•cyber_master•59m ago•0 comments

What Business Do

https://melihozkurt.com/what-business-do/
2•melihozkurt•1h ago•0 comments

Grow a Garden Calculator

https://www.grow-a-garden-calculator.app/
2•zerogpt_plus•1h ago•1 comments

Google exec: 'We're going to be combining ChromeOS and Android'

https://www.theverge.com/news/706558/google-android-chromeos-combining-sameer-samat
1•pjmlp•1h ago•0 comments

Code highlighting with Cursor AI used for $500k theft

https://securelist.com/open-source-package-for-cursor-ai-turned-into-a-crypto-heist/116908/
24•Daviey•1h ago•15 comments

Cognition Buys Windsurf, Nvidia Can Sell to China, Grok 4 and Kimi

https://stratechery.com/2025/cognition-buys-windsurf-nvidia-can-sell-to-china-grok-4-and-kimi/
2•feross•1h ago•0 comments

Stop Apple from Buying Mistral AI

https://old.reddit.com/r/BuyFromEU/comments/1m0apxy/stop_apple_from_buying_mistral_ai/
6•doener•1h ago•1 comments

Practical notes on getting LLMs to generate new ideas

https://www.seangoedecke.com/idea-mill/
3•ingve•1h ago•0 comments

Show HN: Free Chrome extension to right-click text to your favorite AI chat

https://github.com/tohmsc/aianywhere
2•sourcetms•1h ago•0 comments

Nextdoor reboots app to power daily life

https://www.axios.com/2025/07/15/nextdoor-app-ai-reboot
1•gpi•1h ago•0 comments

Inventors of Google Earth also invented an interviewing machine (1992)

https://artcom.de/en/?project=mediatel
1•rafaepta•1h ago•0 comments