HNHacker News
TopNewBestAskShowJobs

C4K3

252 karma · joined November 14, 2015

[ my public key: https://keybase.io/c4k3; my proof: https://keybase.io/c4k3/sigs/LKlUWlMqqsFXygY4Iz7wIgxT_2VMplU4YeTlMKAmOMw ]
submissionscomments
C4K3··on CoMaps – FOSS Offline Maps
As the other commenter mentioned the web editor is probably the most beginner-friendly editor. It might seem a little daunting but it's actually not that difficult to edit OSM. When you save your change there's an option to request a review of it. That'll get an experienced contributor to take a look at it and help clear up any mistakes.

OSM also has a public database of GPS tracks that contributors use to aid in mapping. Even just walking the trails with GPS tracking on and then uploading the tracks to OSM without doing anything else is a valuable contribution that will allow other contributors to map the trails at some point in the future.

C4K3··on Frontier AI has broken the open CTF format
Its article was reorganized (moved from plain Capture the Flag to Capture the flag (cybersecurity)) 5 years ago. It's been on Wikipedia since 2004 https://en.wikipedia.org/w/index.php?title=Capture_the_flag&...
C4K3··on Ed25519-CLI – command-line interface for the Ed25519 signature system (2024)
Keybase or any of the tools inspired by keybase (foks.pub etc)
C4K3··on Show HN: Ez FFmpeg – Video editing in plain English
There was an ffmpeg drag-and-drop GUI that let you create ffmpeg commands visually instead of having to remember all the right arguments. Inputs, filters and outputs are all nodes in a graph, and then you connect them together. When done you would export it as an ffmpeg command to run.

As an occasional user this was a lot easier to use than having to remember all of the commands, and it did it all without hiding the complexity from the user.

Unfortunately it looks like they tried to monetize it but then later shut down. It doesn't look like they posted the source code anywhere.

https://web.archive.org/web/20230131140736/https://ffmpeg.gu...

C4K3··on Signal Protocol and Post-Quantum Ratchets
At the very least they should have excluded any chats with disappearing messages enabled from being included in backups.

With disappearing messages off it was already reasonable to assume that a compromise of a counterparty's phone would result in exposure of all previous messages, so enabling backups wouldn't expose you to new risk.

That would cater to those who want to keep their chat history forever without exposing those with disappearing messages enabled to new risk.

C4K3··on Reverse Engineering iOS 18 Inactivity Reboot
They conclude that there's no wireless component to the feature.

This feature is not at all related to wireless activity. The law enforcement document's conclusion that the reboot is due to phones wirelessly communicating with each other is implausible. The older iPhones before iOS 18 likely rebooted due to another reason, such as a software bug.

C4K3··on Not setting up Find My bricked my MacBook
You don't have to pay import taxes to bring ferraris in if it's just temporary for a vacation.

See https://en.wikipedia.org/wiki/Customs_Convention_on_the_Temp...

C4K3··on What's the right UX for an expired certificate?
Browsers could add the less severe warning before the certificate expires, for example 3 days before it expires have a "this certificate is about to expire, are you sure you want to continue?" warning. That would maintain the security guarantees around expiration while still getting the attention of users/administrators.
C4K3··on ssh whoami.filippo.io
I learned about this when I encountered a server with an aggressive fail2ban that wouldn't let me log in because I had too many ssh keys. It apparently counted every wrong key as an auth attempt, so it blocked me before my ssh client tried the right key. Since then I've used IdentitiesOnly=yes
C4K3··on Recovering a password-protected ThinkPad T60
A reasonable solution would be to have a "Do you want to disassociate this phone from your iCloud account?" prompt as part of the factory reset.
C4K3··on iOS 16 Available September 12th
Personally I think the screen being made bigger is a downside, makes it harder to use one-handed.

Still, it's too bad there isn't a 14 mini.

C4K3··on DuckDuckGo email protection beta now open
https://sneakemail.com/ is another one that's been around for a long time.
C4K3··on Using a catch-all domain is a mistake
I've been doing this for close to a decade and sometimes salespeople and customer service people will ask to confirm, but that takes 5 seconds and isn't awkward (in my opinion.)

It has more benefits than knowing who leaked your email, it lets you easily filter your incoming email by who you gave the email to, and when your email is leaked it lets you shut off that email address. Of course you can also filter your email by the sender's domain, but that isn't as consistent, and doesn't help at all when your email address has been leaked.

It's true that you do have to set it up so that you can send email from the addresses to avoid not being able to reply by email, and you will want a password-manager or something to remember exactly what email you used, for convenience.

Personally I'm glad I've done this, it's made it much easier to organize my emails.

C4K3··on FTC fines Twitter $150M for using 2FA phone numbers for ad targeting
You don't have to use microsoft authenticator. TOTP is a big step up from SMS and most/good apps won't violate your privacy.
C4K3··on HTTPS Everywhere will sunset in January 2023
The best you can do is set HSTS and redirect from http to https.

You not serving http won't prevent a MITM from serving http to the victim.

C4K3··on I stopped to watch kids playing at recess – security was called
In South Park in San Francisco there's a little playground that has a sign saying adults are not allowed without children, which if anything feels backwards to me. It's a nice place to sit, eat and chat, and I've never seen anybody complain about adults being there, but I imagine there has to be some busybody who thought a rule like that would be a good idea. Maybe they have the rule so they can selectively enforce it against people?
C4K3··on Bash-oneliner: A collection of handy Bash one-liners and terminal tricks
I wonder if it isn't possible to get it to save your command to history when you do Ctrl-C.

I tried a naive way by trapping sigint but couldn't get it to work.

C4K3··on Ask HN: MacBooks seems to be the only viable option these days
I have one of those macbook keyboards (2018 macbook pro) and it is easily the worst keyboard I have ever used. I do not understand how a keyboard like that could possibly have made it onto a $3000 laptop.

Which is funny because the touchpad is by far the best touchpad I've ever used, it's the first touchpad I'd ever used that made me think a touchpad could compete with a mouse. It even made me start donating to the linux touchpad improvement project that got posted on HN [1].

My thinkpad is the exact opposite. Decent keyboard for a laptop but terrible touchpad.

[1] https://www.gitclear.com/blog/linux_touchpad_update_december...

C4K3··on Tell HN: Startups harvesting GitHub commit emails for marketing purposes
This has been going on for a long time. There was a company called geekedin that scraped data off public git repositories (among other things) and who then had their database leaked back in 2016.

https://www.troyhunt.com/8-million-github-profiles-were-leak...

C4K3··on An Ode to Apple’s Hide My Email
Another one that's come up in the past is https://sneakemail.com/
C4K3··on B773 at Paris on Apr 5th, airplane did not respond to commands
Why is it possible for a pilot to "fight" the autopilot? From my (layman's) point of view, it seems logical that either the pilot would be in control or the autopilot would be in control, but not both at the same time.
C4K3··on Show HN: A website to find public pianos
Map based on that data: https://www.mapcontrib.xyz/t/e5c83c-OpenPianosMap (via https://github.com/brunetton/OpenPianosMap)
C4K3··on Ask HN: What is the most unique website you’ve come across on the internet?
also https://ugenr.dk/ if you ever wanted the number flying out at you.
C4K3··on Ask HN: Gmail account security
One site I've found particularly annoying in this regard is ebay. I'll log in, enter a 2FA code (both SMS and email), do whatever I need to, and then 30 minutes later I'll get an email saying my password has been reset because of suspicious activity. ("your eBay account has been secured because your login information may have been used without your permission") This has happened several times now. At least they haven't canceled any of my orders or anything.
C4K3··on Swiss army restricts use of messenger apps for military purposes
It is not just for the phone, the passphrase you set is also used to encrypt your data on the signal servers. Signal claims to use intel SGX to secure the passphrase on their servers, though.
C4K3··on Clever uses of pass, the Unix password manager
Some distros package browser extensions, so you can install them via your regular package manager. For example arch packages firefox-extension-passff (I haven't personally used it though)
C4K3··on Tell HN: Lost then regained access to Google account, with correct credentials
You can get around the youtube restrictions using yt-dlp (fork of youtube-dl) There are video players such as mpv that integrate with youtube-dl/yt-dlp so you can watch videos without saving them.
C4K3··on The data behind New York's increasingly dirty electricity peaks
Lithium batteries are used on the grid, for example https://en.wikipedia.org/wiki/Gateway_Energy_Storage
C4K3··on Show HN: Unclack – a macOS app that mutes your microphone while you type
I wish push-to-talk was more common. On linux I've been using this little python script that implements global push-to-talk by (un)muting the microphone in pulseaudio when you push a button. https://gitlab.com/somini/inpulse-to-talk

Time to see if there's something equivalent for mac.

C4K3··on FATCA Pushes “Accidental” Americans to Give Up US Citizenship
A surprising number of Americans seem to think it's reasonable to tax non-residents, so such legislation may be hard to get passed.

If you support such legislation, consider supporting lobbying groups such as American Citizens Abroad https://www.americansabroad.org/

Page 1 of 3Next →