HNHacker News
TopNewBestAskShowJobs

StuntPope

3,169 karma · joined February 24, 2012

submissionscomments
StuntPope··on Trezor breach victims now getting malicious QR codes by postal mail
So you're saying a phishing QR code is not malicious?
StuntPope··on Show HN: DNSskills.md – agentic skills for certain DNS utilities
We've added agentic skills for five DNS utils we've had on the Domainhelp site for awhile (formerly easyWhois)

These ones are handy:

1. What is my public IP

2. What is my DNS resolver (handy)

3. Is this a homoglyph (have your openclaw check this before blindly following a link)

4. SPF Flattener

5. DNS Twister

More to come.

StuntPope··on Bought an expired domain. Then I inherited their AWS Root account
That's an excellent point.
StuntPope··on Show HN: Tunnel.to – dead simple localhost reverse tunnels
I run a DNS company (some of you can probably guess which one), and a few weeks ago one of my nephews was showing me his home setup and asking about local tunnels.

He already knew about Cloudflare Tunnels. I mentioned ngrok, localtunnel, etc., and then I started thinking about what a super-lightweight tunneling client might look like if it were optimized for clawbots, MCP servers, dashboards, and random services people are increasingly running on home networks and minis.

And then I remembered I owned the tunnel.to domain name.

At that point the idea kind of lodged in my brain and refused to leave until I built the thing.

Current state:

- lightweight relay-based tunnel service

- CLI-first

- public relay nodes in North America + Europe

- TLS

- no account required for basic usage

- intended to be dead simple to expose localhost services

Right now it’s centralized. Early days, but it's entirely doable to add:

- self-hosted relays

- private relays

- agent-oriented workflows

- lightweight auth/access controls

- better relay selection/failover

Given my background I'm also in a good position to preempt abuse, so it doesn't become a timesuck. The no-registration level assigns sub-hostnames so people can't set up obvious phishing sites.

(And yes, I told my nephew about it after it was finished. He said “cool”. Hasn’t used it yet.)

StuntPope··on Age verification now required for DNS resolution
You're thinking of resolvers.
StuntPope··on Age verification now required for DNS resolution
[flagged] lol.
StuntPope··on Age verification now required for DNS resolution
just one?
StuntPope··on Canada's "Strong Borders Act" (Bill C-2) Contains Four Surveillance Provisions
One thing I didn't realize until after this was posted was that the wiretaps ISPs will be ordered to perform under C-2 are warrantless. Just ministry orders.
StuntPope··on Itch.io Taken Down by Funko
easyDNS here. Our ears were burning as multiple people have mentioned us in this thread.

If you want to get with a registrar who is actually clueful about takedowns, we can help you out.

StuntPope··on Don’t let your domain name become a sitting duck
The Gell-Mann Amnesia is strong in this story and thead.

As I posted on Krebs' article:

This is neither news nor new. There have been prior panics around this “water is wet” type issue going back at least a decade.

(Search up “Floating Domains – Taking Over 20K DigitalOcean Domains via a Lax Domain Import System” – and others).

I also wrote about this on CircleID from the DNS operator’s perspective (“Nameserver Operators Need the Ability to “Disavow” Domains”) – after this same issue was used to DDoS attack another DNS provider by delegating a domain to their DNS servers without having setup an account there, and then doing a DNS reflection attack on that domain. That was over ten years ago.

The fact that people can delegate their own domains to somebody else’s nameservers without ever properly setting up a zone on those nameservers, or ever keeping track of where THEIR OWN DOMAINS point is 100% the responsibility of the domain owner – and to varying degrees a function of their REGISTRAR – who is the only entity that has any control over it.

It’s a weird flex for corporate registrars who purport to be “high touch” and exclusive, to simply shrug their shoulders and turn a blind eye to their own clients’ obviously broken and vulnerable nameserver delegations.

For our part this is specifically one of things we actively monitor and alert our clients about.

StuntPope··on VC Says Half of Google Staff Do 'No Real Work'
easyDNS and OpenDNS have completely different founders. You are probably confused with EveryDNS - was founded by the same person who started OpenDNS.
StuntPope··on Beware of EuroDNS
Default behaviour in a registrar transfer is to leave the nameservers as is - the rar has to explicitly send a new ns set in the transfer call to effect a change.

Are you positive you didn't accidentally tick a checkbox or anything to use their nameservers?

StuntPope··on Everybody's aware that Google will start enforcing DMARC Feb 1st, right?
I've been monitoring this with an eye toward creating a honeypot for DMARC abuse but so far been seeing zero messages come in.

Either the spammers haven't figured it out yet, or they realize it's a waste of time since all the messages are either mechanically processed or ignored.

StuntPope··on Everybody's aware that Google will start enforcing DMARC Feb 1st, right?
You'll still be able to to run personal email from your domain - I'd add SPF and a minimal DMARC and you'll be fine.
StuntPope··on Financial anxiety: The alarming side effect of inflation
It's called "The Cantillion Effect".
StuntPope··on Financial anxiety: The alarming side effect of inflation
They talk about inflation like it comes from a comet out of deep space.

Not one mention that inflation is caused by the government and central banks expanding the money supply.

StuntPope··on The Berkeley Hotel Hostage of Douglas Adams
Great story.

I was a huge HHGTTG fan (counting Disaster Area among my top musical influences)

When I was at UWO in the early 90's Douglas Adams came on campus for a book signing - it was to last about 45 minutes, and it was scheduled right in the middle of one of my exams.

So I decided to sit the exam, thinking "I'll catch up with him at a future book signing", alas he died before I ever got the chance.

StuntPope··on Why I’m betting on Nostr
I would recommend ponying up a few sats and using paid relays.

If you're just using free relays you will get inundated with spam.

I was running an open relay for awhile and closed it up because of this.

(Lightning is the magic lubricant that makes Nostr so promising).

StuntPope··on UK version of “Online Harms Bill” wants to prefilter content without due process
Wikileaks had their DNS cut off by Dynect - who lied about it being because of a non-existent DoS attack, when in reality they were getting their nuts squeezed by the State Department to deplatform them.

> Non-controversial sites do not get shut down.

A.k.a "nothing to hide, nothing to fear".

StuntPope··on UK version of “Online Harms Bill” wants to prefilter content without due process
Are you asking for a source on "ivermectin is not a horse de-wormer" Other than that it has been an FDA approved drug for over thirty years?

Or are you asking for a source on somebody getting deplatformed for saying that, and Dr. Peter McCullough comes to mind there.

The Great Barrington Declaration was also de-indexed from Google for disputing lockdowns.

StuntPope··on UK version of “Online Harms Bill” wants to prefilter content without due process
> I've seen people say this, but I've not actually observed that at all. > What got censored exactly?

Zerohedge was kicked off Twitter for suggesting that the Wuhan Institute of Virology was a likely candidate for the origin.

We're seeing that Fauci & Ecohealth co-ordinated the paper to "debunk" the lab leak theory and now the lab leak is looking to be the most likely culprit (it is not without precedent, the 1977 Russian Flu turned out to be a lab leak from gain-on-function research).

Ivermectin, was another. Complete with "horse de-wormer" smears and deplatforming campaigns all over the place.

If you don't know of any instances where this has happened, you either did a masterful job tuning it all out, or still believe 99% of the b/s.

StuntPope··on UK version of “Online Harms Bill” wants to prefilter content without due process
Nostr and SimpleX look promising.
StuntPope··on Phishing attack leaks 100K ChatGPT logins on Darkweb
Attackers would presumably have access to chat sessions of compromised accounts.
StuntPope··on State of Maryland lets domain expire, hilarity ensues
I originally read it on Zerohedge and figured that domain is probably less welcome on HN, even tho their reporting on it was more technically grounded than the Fox news piece.
StuntPope··on State of Maryland lets domain expire, hilarity ensues
Looks like the State of Maryland let the domain for the URL on their license plates expire, and has since been re-registered by a Filipino gambling site.
StuntPope··on Show HN: Make domain verification as easy as verifying an email or phone number
I've been thinking for some time about a mechanism that could be used to assert control over a domain that has a lot of third-party backlinks to it, as in widgets, ad networks, javascript etc.

Because when those domains become defunct or expire, anybody recognizing what they were could grab them and inject malicious code into all the websites with the broken widgets embedded (we've seen this happen with crypto miners, etc)

This kind of a mechanism (along with domainconnect) could work - but it would also need the browsers (perhaps with a plugin?) to verify a domain on embedded components before rendering them.

That would add a lot of DNS lookups though.

Overall a good effort. Would be good to see something along these lines gather some traction.

StuntPope··on Ask HN: Pro free speech domain registrars?
> EasyDNS has a history of being decent but has had an openly right wing slant for the last few years, which could translate into how they handle complaints for domains owned by the "other side".

easyDNS spokesbot here.

We take the same attitude toward our client domains regardless of political affiliation or orientation.

In the past we were the DNS provider for both BLM and Antifa, who brought in their fair share of takedown requests and are arguably left-of-centre.

When we were added as a defendant in a defamation suit because we wouldn't take the website down ahead of a court ruling, that was a legal battle between two different factions of socialists - which we're not a fan of - we still fought the lawsuit at our own expense.

Everybody seeking to deplatform an easyDNS customer because of their political ideology gets the same answer: "GFY".

StuntPope··on Canada’s cyber-security Bill C-26: Yet Another Government Power Grab
That is precisely the concern. Listen to the Law Bytes podcast with Michael Geist and Brenda McPhail - Geist is a University of Ottawa law professor and undisputed privacy expert - and they talk about exactly this.

(Or you could read the legislation itself, but Canadian bills are hard to read because they are these kind of Frankenstein concoctions of lines that are stricken from other acts and new lines that are added).

StuntPope··on Why the Cantillon Effect Creates Communism
Tax revenues don't cover it, which is where trillion dollar deficits come from.

Those deficits are filled in by bond issues. Those bonds have been increasingly monetized by the Fed:

https://fred.stlouisfed.org/series/FDHBFRBN

This known as "Quantitative Easing" - which is printing money.

StuntPope··on Jim Warren has died
I loved Dr Dobbs Journal. Used to buy it every month when I was in college and barely understood any of it.
Page 1 of 4Next →