HNHacker News
TopNewBestAskShowJobs

ColoursofOSINT

427 karma · joined June 12, 2023

submissionscomments
ColoursofOSINT··on Giphy is sharing your IP address and private data to 816 partners
Giphy also does not have a privacy policy for their Firefox extension, but run an analytics script, which I wrote about and sent them an email to which they ignored me despite sending conformation of receiving it.

No way to know the data being collected, or opt out.

https://www.coloursofosint.com/posts/Investigating-Firefox-P...

ColoursofOSINT··on German Court Fines Security Researcher for Reporting Company's Vulnerabilities
> I'm not at my best to argue this, since it's evening here and I had a couple of glasses of wine with dinner.

And you probably shouldn't be, this is a internet discussion, don't let it interrupt your life.

My argument was not that the password wasn't a line not to be crossed, but that laws can be based on a sliding scale.

ColoursofOSINT··on German Court Fines Security Researcher for Reporting Company's Vulnerabilities
What an interesting response.

You say essentially state that my information is not a “proper counter-argument.”, while in the same response argue that I am wrong because this is “this is common sense”, rather than any real response.

The court recognized there was a fence for privacy, but that is was applicable to certain situations, for example, the purpose of the recording. So it would be fine to record someone if they were in the background of your picture, but not if was for sexual purposes. Hence the numerous criteria to be considered. So its very much about making fences fuzzy, since they only apply to certain types of filming, the purpose, personal attributes....etc.

Thermal imaging and its effects on the fourth are not common sense. Thermal imaging was initially ruled to be fine, then appealed, ruled fine, then it ruled to not be fine, but only with a 5 - 4 ruling. With the dissenting opinion including “Heat waves, like aromas that are generated in a kitchen, or in a laboratory or opium den, enter the public domain if and when they leave a building.”

All you would have to do is read the Wikipedia article I gave to see that “Scalia's phrases "sense-enhancing technology" and "device that is not in general public use" in the Kyllo ruling have become influential in later rulings on police search procedures, but in an inconsistent fashion.[22] Several scholars and legal analysts noted the ambiguity in Scalia's use of those phrases.

To use your example, a police officer could “reach over” and see the illegal activity with his own eyes through a hole in your fence and that is legal. However, they could not use binoculars to get over your fence from a public area.

https://www.ojp.gov/ncjrs/virtual-library/abstracts/telescop...

ColoursofOSINT··on German Court Fines Security Researcher for Reporting Company's Vulnerabilities
"You can't base law on a sliding scale like entropy."

I would disagree. Courts decide on the sliding scale. I am no lawyer, but in Canada and the USA you have a "A Reasonable Expectation of Privacy" [1].

For example, see thermal imaging use by police[2].

[1]: https://www.cwilson.com/a-reasonable-expectation-of-privacy/

[2]:https://en.wikipedia.org/wiki/Kyllo_v._United_States

ColoursofOSINT··on Roundcube open-source webmail software merges with Nextcloud
You're correct, I'll retract my statement.

Both start with coll/cooll, I've got to increase my zoom apparently.

ColoursofOSINT··on Roundcube open-source webmail software merges with Nextcloud
What?

You said "i'm happy running it on my ...vps."

And now "Then I wouldn't use Roundcube either." So you're not running roundcube then?

Also, love how you said you loved roundcube because it works on "lightweight el cheapo VPS", and then backtracked once you found out it uses PHP.

ColoursofOSINT··on Crypto-Themed NPM Packages Found Delivering Stealthy Malware
Would love to read the article but the website seems to be blocking VPNs.

Oh well.

https://web.archive.org/web/20231125231757/https://blog.phyl...

ColoursofOSINT··on Sam Altman's sister, Annie Altman, claims Sam has severely abused her
Something more than a few tweets would be a start.
ColoursofOSINT··on Framework Laptop prices go as low as $639 thanks to refurbs and factory seconds
Never doubt the ability of an Apple Fanboy to turn conversation into anything about Macs.

Either that or God tier trolling.

ColoursofOSINT··on OpenAI's board has fired Sam Altman
Can I add to the speculation train despite having no other information?
ColoursofOSINT··on Sam Altman's sister, Annie Altman, claims Sam has severely abused her
These accusations have been made for some time now and they have cycled through popularity several times. Each time I have yet to see any proof.

Of course, with the recent news they are getting more attention, and once again, we have it surface. I will admit it’s a little weird that he has not sued her for such ruinous claims, but this is a family issue, so I can understand not escalating the issue.

As the author concludes, "However, Annie has not yet provided what I would consider direct / indisputable proof that her claims are true. Thus, rationally, I must consider Sam Altman innocent.”

To those complaining that this topic keeps getting removed from YC, imagine if every random allegation (with no proof) against some CEO got discussed.

I personally flagged this post as I have seen the same allegations with no change in information posted so many times.

ColoursofOSINT··on [dead]
Yep
ColoursofOSINT··on Monero Community Crowdfunding System (CCS) Wallet Hacked and Drained
Multisig would have been a good start for securing $500K.

I always assumed that "security minded" cryptocurrency people would have a good security model, but as this and the Lastpass breach shows, they don't practice what they preach. Also, love the deflection of blame to the Lastpass crypto thefts. If it was never stored there, it can't be from that.

I love how crypto is all about removing trust, and then the developers put all their trust in a single person.

ColoursofOSINT··on Zima Board – Hackable Single Board Server
Zimaboard came out of kickstarter a year and a half ago. Patience is a virtue.

Another reason why there aren't that many alternatives is that you can't use it for that much. It's like buying a car that can carry 50 kg. Great if thats your use case, but if you want anything more, there's no point. I can't really use it as a NAS, firewall etc. I think it certainly has uses, they are just ones that the average NAS/server people can do with a stronger server that can also do nextcloud, pi-hole, etc, in one, rather than have a device for each (which is way more costly).

ColoursofOSINT··on Zima Board – Hackable Single Board Server
I mean, it's nice to have the ports, but you have externally power the drives because the PSU is 3A, so one for the computer and that leaves 2A. Most HDDs need 2A to spin up so you can only have one drive. So no redundancy.

If I was to make a NAS (which is what I would be interested in) I would pay triple for something like the NAS killer 6 [3]. To be fair the Zimacube might be more of a challenge to this (but its not out yet).

I think its interesting though for a small, fanless sever. But (understandably, it's cheap) if you wanted something more, an extra $200 would be get you much more. I guess it depends on what you are looking for.

As for alternatives 1: https://www.kickstarter.com/projects/uptimelab/compute-blade ($60 + need pi) 2: Zimablade (lol).

Here's a solid blog post on it: https://www.martinrowan.co.uk/2023/01/is-a-zimaboard-the-rig...

[1]: https://shop.zimaboard.com/collections/all-products/products...

[2]: https://versus.com/en/intel-celeron-n3350-vs-intel-celeron-n...

[3]: https://forums.serverbuilds.net/t/guide-nas-killer-6-0-ddr4-...

ColoursofOSINT··on Android 14's user-profile data bug
Google recently [1] said that they were going to provide 7 years of updates.

I guess they never technically said that they were stable updates.

[1]: https://blog.google/products/pixel/software-support-pixel-8-...

ColoursofOSINT··on Android 14's user-profile data bug
I would rather have ransomware. At least paying would give you a chance to get the data back.
ColoursofOSINT··on Android 14's user-profile data bug
Good things is that GrapheneOS (seemingly) caught this early and fixed it.

https://grapheneos.social/@GrapheneOS/111309676504712576

ColoursofOSINT··on Pixel 8 Pro
I could also make my own operating system.

If I had the time, knowledge and money. Which I don't.

So, I rely and support others that do to ensure I have a functioning and constantly running system without much maintenance work, except donating one a year.

ColoursofOSINT··on Hackers stole access tokens from Okta's support unit
Okta try not to get hacked for a month challenge [level impossible].

In all seriousness, they seem to love getting pwnded. You would hope that the constant stock drops as a result of events like these would force change, but I guess not.

1. https://www.malwarebytes.com/blog/news/2023/01/okta-breached...

3. https://www.theverge.com/2022/4/20/23034360/okta-lapsus-hack...

3. https://techmonitor.ai/technology/cybersecurity/okta-cyberat...

ColoursofOSINT··on Signal commit Username Integration Test
Absolutely, not to mention if you ever switch numbers you have to change the signal information. For me, its fine for verification, but I want an identifier I ever have to change.
ColoursofOSINT··on Pixel 8 Pro
> But I am thoroughly on his side when it comes to the CalyxOS and Techlore drama.

Sure, that could be argued either way. To be honest, it's too complicated for me to really care about. I think GrapheneOS is a solid project, currently.

My biggest problem is that Daniel refuses to apologize or even acknowledge these issues. I try to judge people not by their mistakes, but by their responses to these mistakes.

My worry with GrapheneOS is that the same thing to Copperhead might happen to it. I don't know or care who was right/wrong in that situation. But the end result was that Daniel deleted the signing keys, so I am worried that if Daniel is pressured form either real or imaginary attacks, he might do the same to GrapheneOS.

I want the project to go on for as long as possible, and part of that requires honest reflection.

ColoursofOSINT··on Pixel 8 Pro
I use GrapheneOS, and I've donated to its development. To say that "None of the claims are true" and that they are "baseless" is incorrect.

Louis Rossman was a supporter of the project until he and Daniel had a failing out in which Daniel behaved inappropriately [1], all over a Youtube comment. There's proof for that and other claims [2, 4, 5].

Daniel can be a talented developer, privacy advocate and asshole at the same time.

It's sad to see him (and others, like yourself) say stuff like "examine the baseless claims", without providing any sources.

After all the drama with Calyxos, Techlore, Louis Rossmann etc, at some point one has to notice a pattern of behavior.

1: https://www.youtube.com/watch?v=4To-F6W1NT0

2: https://www.youtube.com/watch?v=Dx7CZ-2Bajg

3: https://github.com/AOSPAlliance/README/commit/cbd2a95cba7c2a...

4: https://web.archive.org/web/20210403012439/https://freenode....

5: https://web.archive.org/web/20210818110434/https://sethforpr...

ColoursofOSINT··on Mozilla's midlife crisis has taken it from pioneer to Google's weird neighbor
Understood.

I agree, I can get snarky. Although I don't quite agree with the strictness of the rules, this site is one of the most unique I have found, so something must be going right.

I'll respect the rules.

ColoursofOSINT··on New group attacking iPhone encryption backed by US political dark-money network
It's harder to run targeted ads if the data is encrypted.

Sometimes I feel that it's less about money and more about control, but control, in a weird future sense. I wonder if the thought process is, "we should collect this now, so we can use it later," without ever really knowing what it will be used for later.

ColoursofOSINT··on Mozilla's midlife crisis has taken it from pioneer to Google's weird neighbor
Fair enough.

Couldn't have emailed me though?

ColoursofOSINT··on Mozilla's midlife crisis has taken it from pioneer to Google's weird neighbor
> 1) Mozilla does have alternate sources of revenue, like Pocket and Mozilla VPN.

Not really though. All alternate sources are usually less then 5%. [1] As of 2021, they made 73% of total revenue from Google. [2] Mozilla VPN? You mean the one that refuses to fix CVEs? [3] Yikes. No thanks.

1:https://frankhecker.com/2020/08/15/how-mozilla-makes-money-a...

2:https://lunduke.locals.com/post/4387539/firefox-money-invest...

3:https://www.openwall.com/lists/oss-security/2023/08/03/1

ColoursofOSINT··on They studied dishonesty – Was their work a lie?
My favorite thing is that Gino is now suing DataColada [1], and basically is claiming that 'they were right in every other case and I supported them, but with me they are lying'.

1: https://datacolada.org/113

ColoursofOSINT··on Mistral releases ‘unmoderated’ chatbot via torrent
"Undeletable Chatbot That Gives Detailed Instructions on Murder, Ethnic Cleansing"

Got to say, I am disappointed in the fear tactics used here. Reminds me of "think of the children" being used to push back encryption.

I'm an adult, I don't need to be cocooned by some rules made by some nebulous group of people.

Oh no, not information on Ethnic Cleansing, almost as if a Wikipedia article could provide that information. While we at it, let's ban violent video games, movies, and art. Also, don't say murder, otherwise someone might just hear a no-no word and go kill someone.

Thankfully Kagi treats me like an adult.

ColoursofOSINT··on Framework – We are not sustainable
I thought this was about them going out of business.

Nearly had a heart attack.

Page 1 of 2Next →