HNHacker News
TopNewBestAskShowJobs

13throwaway

174 karma · joined June 15, 2013

submissionscomments
13throwaway··on Verizon revives "zombie cookie" device tracking on AOL's ad network
I don't know of any ISPs that are currently MITMing HTTPS. That seems like something that would be big news and get a CA revoked. Do you have a source for that?
13throwaway··on The biggest leak of TTIP documents yet: more than 100 confidential papers
Download them all with wget:

wget -O - "http://pastebin.com/raw.php?i=fA7z2BPi" | wge -i -

13throwaway··on Ask HN: Are you working on a Reddit replacement? What is it?
The problem you run into with a decentralized site is you have to mirror massive amounts of data. I think this is what killed usenet. Also spam is hard to fight.

I wonder if a federated Reddit would work. Different subreddits could be hosted on different servers but the accounts could all be connected.

13throwaway··on Ask HN: Are you working on a Reddit replacement? What is it?
I have been thinking it would be cool to have a Reddit replacement ran by a non profit, similar to Wikipedia. Does anyone here have experience running something like that? I understand non profits are very complex to run.
13throwaway··on To Apple, Love Taylor
App economics are much different from music economics.

From what I have observed, most people (the casual listener) will listen to the free streaming services (pandora, apple radio, etc). When people want to listen to a specific song they listen to it on youtube.

13throwaway··on The Yuri Gadyukin Wikipedia Hoax (2013)
Here it is: https://en.wikipedia.org/wiki/Wikipedia:List_of_hoaxes_on_Wi...
13throwaway··on Show HN: Bot accepts every pull request for its own code
"GitHub plays programmer" This is going to be great!
13throwaway··on GitHub under ongoing DDoS attack
You can access those pages by removing the final slash.
13throwaway··on Opportunistic Encryption for Firefox
The problem with allowing self-signed certificates has always been distinguishing if a site should be signed by a CA or not. Consider the follow situation:

Alice sends Bob a link: http://example.com

Bob trusts Alice and now knows that example.com is probably ment to be accessed over HTTP. Now for the next example:

Alice sends Bob a link: https://example.com

With the current implementation of browsers Bob knows that example.com should present a CA signed certificate. But what if example.com wants to encrypt their data, but for whatever reason uses a self-signed certificate? Some people say that Bob's browser should not display a "big scary" warning, but instead display a UI similar to when accessing a HTTP site. However, in this situation HTTPS has lost some meaning. I think http2 should work as follows:

http2:// - encrypted, not verified

https2:// - encrypted and verified

This way the protocol still conveys the same level of information.

However, if it were completely up to me, I would say ditch the CAs and use namecoin to verify certificates.

13throwaway··on The HTTPS-Only Standard
Using something like Namecoin https://en.wikipedia.org/wiki/Namecoin and storing the cert hashes in the blockchain would allow for decentralized verification.

In order to be an improvement over the CA model a new system would have to satisfy all 3 points of zooko's triangle. https://en.wikipedia.org/wiki/Zooko%27s_triangle

13throwaway··on Scrap the SCP. How to copy data fast using pigz and nc
You could try piping it through ssh, I don't know how that would effect the speed though.

tar -cf - /u02/databases/mydb/data_file-1.dbf | pigz | ssh user@destination "pigz -d | tar xf - -C /"

13throwaway··on Foobar
Do you know why the new interstellar movie is on that domain? https://interstellar.withgoogle.com
13throwaway··on CA Security Council – Myths about CA's
It would be great to see namecoin become more popular. It would mean we could just use self signed certificates and store the fingerprint in the namecoin record.
13throwaway··on Verizon Wireless injecting tracking UIDs into HTTP requests
Go to this page over a cellular connection. (Turn off your wifi) http://checkyourinfo.com/request Then look for a long number.
13throwaway··on Verizon Wireless injecting tracking UIDs into HTTP requests
I just checked my AT&T phone and I have an X-Acr header too.
13throwaway··on Verizon Wireless injecting tracking UIDs into HTTP requests
Here's a scary thought: How do we know every ISP isn't doing this, it would be undetectable if they only injected these on certain domains e.g. facebook, google. However I don't see how much more tracking ability that would grant over IP tracking.
13throwaway··on Facebook Rooms
From what I can tell it seems like room names are not unique. I think this is the reason for the "join by screenshot" feature.
13throwaway··on Disable sharing of Spotlight searches with Apple
I noticed iOS 8 has been doing this too via api.smoot.apple.com
13throwaway··on Signaling Post-Snowden Era, New iPhone Locks Out N.S.A
How about the FBI? http://www.huffingtonpost.com/2014/09/25/james-comey-apple-e...
13throwaway··on 71 TiB DIY NAS Based on ZFS on Linux
Can somebody give me some recommendations on how to do this with encryption? I am fine sshing into my server and putting in a password after reboot.
13throwaway··on Icann bids to stop Iran web domain seizure
I think Namecoin would be a good solution.

https://en.wikipedia.org/wiki/Namecoin

13throwaway··on Cell Phone Guide For US Protesters, Updated 2014 Edition
Redphone can talk to iPhone users with the signal app.
13throwaway··on Netflix Open Connect Content Delivery Network
I wonder what measures they have in place to protect against someone cracking this open and dumping the entire video library.
13throwaway··on Netflix Open Connect Content Delivery Network
Because Netflix uses something like 45% of North American internet traffic, they need to do something like this in order to efficiently deliver video. Of course this is going to give Netflix better ability to stream, but I don't think it is unfair.

It would be unfair if Netflix was paying to "speed up its traffic" (read as: slow down competitor's traffic).

13throwaway··on Ask HN: Review my startup – itripd.com
You entire site needs to be available only over https. Otherwise login cookies and passwords can be stolen.

How to setup a free SSL certificate on apache. https://www.digitalocean.com/community/tutorials/how-to-set-...

13throwaway··on Satoshi's Hashrate
Use the "reader" button (the three lines in the corner). It's a little known feature but great on sites like this.
13throwaway··on Internet hiccups today? You're not alone. Here's why
That would be a good question for Randell Munroe. https://what-if.xkcd.com
13throwaway··on DAVdroid: An open-source CalDAV/CardDAV synchronization app for Android 4+
StartSSL offers free certs.
13throwaway··on DAVdroid: An open-source CalDAV/CardDAV synchronization app for Android 4+
If you add it to that directory it won't show any warnings. Still, not so good for the average person because it requires root and might not persist between updates.
13throwaway··on DAVdroid: An open-source CalDAV/CardDAV synchronization app for Android 4+
Did you try adding your CA to /system/etc/security/ ?
Page 1 of 3Next →