HNHacker News
TopNewBestAskShowJobs

RandomGerm4n

575 karma · joined August 9, 2023

submissionscomments
RandomGerm4n··on reCAPTCHA Mobile Verification Is Bringing the Play Integrity API to Desktops
The intention behind it doesn't matter at all. In the end, it just means that only a few major operating systems are allowed, and the market is divided up among the established manufacturers. Anyone new to the market faces a major problem right off the bat, and trying to build something yourself doesn't work either.
RandomGerm4n··on Mullvad exit IPs are surprisingly identifying
In many countries, a VPN provider can be significantly more trustworthy than an ISP. In Germany, for example, you can have your home searched simply for insulting a politician. The ISP will then immediately hand over the data to the authorities, which most VPN providers do not do. The same goes for torrents. If some random law firm sends a letter to Telekom saying, “Hey, your customer downloaded a movie please give us his data,” they’ll do it right away. Mullvad, ProtonVPN, or even dubious VPN providers like NordVPN don’t do that.
RandomGerm4n··on Hackers breach JDownloader's website to serve malware-laced downloads
Not all plugins are open source. Some of them are included in the jdclosed dependency which is just a blob. The developers claim this is to prevent sites from patching them. However this approach is not compatible with the GPL and the developers have simply been ignoring this for years.
RandomGerm4n··on Google broke reCAPTCHA for de-googled Android users
The AusweisApp is Open Source and available on Windows, Linux and even FreeBSD too. You just need some NFC Scanner that works via USB and then you can use it without a mobile device. https://www.ausweisapp.bund.de/open-source-software
RandomGerm4n··on Hackers breach JDownloader's website to serve malware-laced downloads
There are still warez sites that upload content in RAR archives, which are then split into individual parts. A download manager can then download them all one after another instead of having to do it manually. There are also hosting sites with weird CAPTCHAs or various waiting times.
RandomGerm4n··on Hackers breach JDownloader's website to serve malware-laced downloads
I wish there was finally a decent alternative to this junk. JDownloader pretends to be GPL, but parts of it are closed source. Plus, the Windows installer on the official site is a gamble, and you can only find a clean installer in the forum. The developers claim it’s "just adware", but since it’s a web-based installer, different things are offered depending on your IP address. Some of these install themselves even if you decline them, and some also contain real malware. It was actually to be expected that they wouldn't secure their website properly and that someone else would end up spreading malware as a result. The only reason to still use this software is that it works with every obscure filehoster out there. Alternatives like pyload are much less effective at bypassing all the security measures these sites put in place to block download managers. It also lets you download videos from streaming sites that other tools like yt-dlp refuse to support.
RandomGerm4n··on Dirty Frag: Universal Linux LPE
Perhaps we should consider designing distributions to be more tailored to specific purposes. Since no one needs the affected module on a desktop computer, distributions designed for that purpose should no longer include it by default. If this approach were consistently followed, significantly fewer systems would be vulnerable to such exploits. For most users a system with a kernel as minimalistic as the Android GKI kernel combined with sensible SELinux policies, would likely be sufficient.
RandomGerm4n··on Windows API is Successful Cross-Platform API (2024)
EOL doesn't mean you can't install or use it anymore. It simply means you shouldn't use it anymore because security updates are no longer available. You face the same problem with Windows software that is no longer updated. The only difference is that no one tells you it's no longer supported.
RandomGerm4n··on Windows API is Successful Cross-Platform API (2024)
You can also simply use Flatpak with the Freedesktop Runtime. It runs everywhere regardless of the distribution. For games Steam offers something similar with the Steam Runtimes. You simply develop for that one container and the software will still be running in 20 years. Even though, of course, making software proprietary isn’t best practice. If you make everything open source from the start the various Linux distributions and users can adapt it themselves for their distribution and eventually modernize it as well.
RandomGerm4n··on This Month in Ladybird – April 2026
There would still be piracy sites. So their choice would be between everyone watching it for free or offering their service without drm.
RandomGerm4n··on Copy Fail
That would only work if the user had access to a binary that they wanted to run as root. Ideally this shouldn’t happen at all for most users. There is almost never a legitimate reason to run any program as root unless for example it is a service that absolutely requires it. In Fedora based distributions SELinux also prevents systemd from running any binaries or scripts that the user has access to as root. Removing setuid binaries and strictly limiting features like user namespaces through SELinux would make Linux significantly more secure. It’s absolutely ridiculous that even an outdated Android smartphone is more secure than the average Linux distribution these days.
RandomGerm4n··on Copy Fail
That is why we should get rid of setuid binaries. GrapheneOS does not use them and was therefore not affected. On the desktop there is also a project called Secureblue based on Fedora Atomic that is moving in a similar direction and has already eliminated a large number though not all setuid binaries. As an alternative to sudo, su, and pkexec there is for example run0, which is available in distributions using systemd. Since systemd 259 there is now also the --empower parameter which like sudo elevates the privileges of the regular user. Essentially any distribution could start removing sudo and create an alias so that users don’t have to adjust immediately.
RandomGerm4n··on Show HN: Adblock-rust Manager – Firefox extension to enable the Brave ad blocker
I’m a Firefox user myself but there are some very valid arguments against it on Android as well. Firefox on Android is significantly more vulnerable to exploits, lacks internal sandboxing and doesn’t properly isolate tabs from each other.
RandomGerm4n··on Show HN: Adblock-rust Manager – Firefox extension to enable the Brave ad blocker
One thing doesn't rule out the other. Just because a browser has a built-in adblocker doesn't mean you can't replace it with another one if it's not working well. Every browser should have at least a basic adblocker enabled by default. Anything else is a major security risk. In the context of web browsers ads are the main entry point for malware. Either through exploits delivered via ad banners or by tricking users into downloading something. Many search engines such as Google display fake search results that lead to infected versions of otherwise secure software. Additionally some sites offering downloads have ads disguised as download buttons that lead to something else. A browser manufacturer should try to protect its users from such things.
RandomGerm4n··on Show HN: Adblock-rust Manager – Firefox extension to enable the Brave ad blocker
Can this extension effectively block ads on YouTube? When I manually enabled the Rust ad blocker in about:config and added filter lists there, ads still appeared on YouTube and some porn sites. While uBlock Origin blocks everything.
RandomGerm4n··on Waymo says can't avoid bike lanes because riders want to be dropped off in them
This statement should be grounds for immediately banning Waymo from operating. If a driver says they can’t follow traffic rules they should lose their driver’s license until they’ve proven they’re fit to drive again. I can’t think of any reason why it should be any different for autonomous systems. If they can’t follow traffic rules they shouldn’t be allowed to drive.
RandomGerm4n··on Turtle WoW classic server announces shutdown after Blizzard wins injunction
Only a very small percentage of players purchase microtransactions. In addition Turtle doesn't have any payment information because the transaction went through a third-party service. So Blizzard would have to take legal action against that service first. Also the server itself is not “piracy.” The server is based on VMaNGOS which is open source and contains no Blizzard code. VMaNGOS can be downloaded legally from GitHub. Turtle WoW created its own content for the server some of which runs on the server side and some on the client side. The only thing that is actually "piracy" is the distribution of the game client (which they unfortunately did) as it belongs to Blizzard.
RandomGerm4n··on Turtle WoW classic server announces shutdown after Blizzard wins injunction
There is no customer list. The only thing Blizzard could do is ban anyone using the same IP address as someone on Turtle WoW. However since NAT is widespread in many countries and many people don’t have their own IPv4 address this would result in an extremely high number of false positives. Not to mention that multiple people could be sharing the same internet connection. Besides there’s no reason to do that. Someone who also plays on the official server is paying for a subscription. Banning that person now would just mean less revenue for Blizzard.
RandomGerm4n··on Turtle WoW classic server announces shutdown after Blizzard wins injunction
They aren't modifying the ROM. They've rebuilt all the mechanics from scratch. The ROMs are only there for the graphical assets.
RandomGerm4n··on Turtle WoW classic server announces shutdown after Blizzard wins injunction
PokeMMO does not include any game assets itself. It is also not an emulator but its own engine. You’ll need to obtain the ROMs from elsewhere and place them in the appropriate folder so that the PokeMMO client can extract the files. In many countries it is legal to recreate a game as long as you do not use any code or assets from the original. The player is the one committing copyright infringement if they do not dump the ROM from their own cartridge.
RandomGerm4n··on Turtle WoW classic server announces shutdown after Blizzard wins injunction
I think you're confusing this with Ascension which is a different server. Turtle was more like Classic WoW but with additional content that fits in as if the official expansions had never existed. So basically it's like Old School Runescape for WoW.
RandomGerm4n··on Someone bought 30 WordPress plugins and planted a backdoor in all of them
This is probably a controversial opinion but this case is yet another example of why it should be prohibited to sell repositories and storefronts. If you want to take over someone else’s user base you should be forced to display a message to the users and actively ask them whether they trust the new owner as well. Simply passing the whole thing on to someone else in secret who could then compromise the WordPress plugin, a browser extension or something similar should not be allowed.
RandomGerm4n··on Has Mythos just broken the deal that kept the internet safe?
Hopefully, this will finally lead to a shift in thinking so that security practices like those used in GrapheneOS become more widespread in the future. Most software developers simply patch security vulnerabilities as soon as they become aware of them rather than taking preventive measures where possible. Finding an exploit that works in Vanadium on GrapheneOS is significantly harder than on standard Android running Chrome. There are now projects in the desktop space such as Secureblue which aim to adopt security practices similar to those of GrapheneOS. They have Trivalent which is inspired by Vanadium and applications use the hardened_malloc familiar from GrapheneOS by default.
RandomGerm4n··on Session is shutting down in 90 days
The problem with XMPP is that most clients use an outdated and insecure implementation of OMEMO. This includes popular clients such as Conversations and Gajim. Currently only Profanity and Kaidan use the latest version and you must always assume that the encryption has been secretly downgraded because the other person is using an insecure client. I highly recommend Soatek's blog post on this topic. https://soatok.blog/2024/08/04/against-xmppomemo/
RandomGerm4n··on Session is shutting down in 90 days
That’s not really a big deal since the session encryption was insecure anyway. It feels almost like a honeypot after they've removed forward secrecy. If you’re looking for a decentralized alternative SimpleX Chat is a more secure option.
RandomGerm4n··on Veracrypt project update
That's especially ridiculous because this whole security mechanism that Microsoft is forcing on Windows user doesn't even work. There are tons of leaked certificates and on forums dedicated to game hacking you can find guides on how to get your hands on one yourself. People there use them to write kernel drivers for cheating in games. Game developers often blacklist these in their anti-cheat software so that the game no longer launches on a computer using a driver with that certificate. Microsoft however does not do this and malware developers can then simply use the certificates for their own purposes. So all this nonsense is basically just a restriction on regular users and honest developers while the “bad guys” can get around it.
RandomGerm4n··on German implementation of eIDAS will require an Apple/Google account to function
Users have the right to modify any app running on their own device. Software security should never depend on the user having no control over their own device. Smartphones are essentially just regular computers, and on them you can use a debugger and do whatever you want. Viewing smartphones as closed systems like game consoles where you need the manufacturer’s permission for everything only leads us into the dystopia that Richard Stallman described as early as 1997 in his short story "The Right to Read"
RandomGerm4n··on German implementation of eIDAS will require an Apple/Google account to function
I attestation should be abolished altogether. An app should have absolutely no way of knowing what kind of device it’s running on or what changes the user has made to the system. It is up to each individual to ensure the security of their own device. App developers should do no more than offer recommendations. If someone wants to use GrapheneOS, root their device (not recommended), or run the whole thing in an emulator, a homemade compatibility layer under Linux, or a custom port for MS-DOS, that should be possible.
RandomGerm4n··on Naming rights to street auctioned in San Francisco
I wonder what would happen if someone tried to name a street something obscene or illegal
RandomGerm4n··on Hong Kong police can now demand phone passwords under new security rules
That is exactly why a Duress Pin, like the one in GrapheneOS, should be standard everywhere. Ideally, it should also include an option to visibly destroy the device by overheating it, to ensure that no one can accuse you of not having actually deleted the data and keep asking for a password.
← PreviousPage 2 of 3Next →