HNHacker News
TopNewBestAskShowJobs

______-

611 karma · joined May 3, 2021

submissionscomments
______-··on There Are Aliens, but Probably Not Here
Also https://fakenous.net/ looks like someone's installing a new Wordpress. I've seen this situation before and was able to literally install Wordpress on someone's server.
______-··on Cool URIs don't change (1998)
Onionland people had plenty of warning though. My old v2 Onion bookmarks are all discarded. The new V3 addresses are a good indicator of which .onion operators are serious and want to stay online no matter what.
______-··on Ethics of AI
I don't have issues with AI being used by benevolent people for benevolent purposes. It's when this stuff falls into the wrong hands that would bother me.

This is the only reason AI hasn't exploded yet (we know we're playing with fire with AI). It's called our 'final invention' for a reason.

______-··on Apple's iCloud+ “VPN”
> I'd also really like to see Apple come clean about the iCloud backup encryption debacle

Are you referring to this article?:

https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

It's why I only use my Apple ID for grabbing apps from the app store. I have disabled all the `cloud storage` features of iCloud. iCloud is a privacy nightmare.

______-··on Matrix has become the messaging app of choice for top-secret communications
There's also another obscure and less well known messaging app called CWTCH https://cwtch.im/ It's still in development though...
______-··on Reality Winner, NSA contractor in leak case, out of prison
> this is a very long and weird sentence

Looks programmatically generated. The whole account is the same style of incoherent nonsense. Probably powered by https://en.wikipedia.org/wiki/GPT-3

There's a few other accounts I've seen here on HN that just spout random incoherent nonsense text, presumably to accumulate karma so they can power their sockpuppet ring and upvote any story they wish to the frontpage of HN.

______-··on Stripe Identity
> It could be Equifax levels of problematic if there would be a intrusion

I'm sure they're not as lax as Equifax. I would hope that Stripe compartment all these documents so that a compromise of one database is not a compromise of the whole database. That's basic data storage hygiene in the information age. `Don't put all your eggs in one basket` as the saying goes.

______-··on LSD and psilocybin increase the fractal dimension of brain activity
I don't take downvotes personally. I've learned to accept them as meaningless gestures that make people feel powerful and in control, when infact no-one is really in control here. We're all acting :)
______-··on LSD and psilocybin increase the fractal dimension of brain activity
I never hallucinated after trying shrooms, even at high doses. I found this odd, since I have read about countless people saying they saw stuff that wasn't there or saw colorful fractal geometry.

So my conclusion is that shrooms simply increased my perception and allowed in more information, and that all this fractal geometry is already there, just waiting to be discovered.

It's just like tuning into a higher frequency. It's not fake or generated by the brain, simply observed for what it is.

______-··on Infosec Core Competencies
You also have to have a rebellious and slightly sly streak in you. This helps if you're going to do social engineering. You may have to learn to be more charismatic or learn superficial charm[0] and be able to play people's emotions.

Another thing: some people just fall into blackhat/whitehat/greyhat hacking naturally after learning that Everything is Broken[1].

[0] https://en.wikipedia.org/wiki/Superficial_charm

[1] https://medium.com/message/everything-is-broken-81e5f33a24e1

> Once upon a time, a friend of mine accidentally took over thousands of computers. He had found a vulnerability in a piece of software and started playing with it. In the process, he figured out how to get total administration access over a network. He put it in a script, and ran it to see what would happen, then went to bed for about four hours. Next morning on the way to work he checked on it, and discovered he was now lord and master of about 50,000 computers. After nearly vomiting in fear he killed the whole thing and deleted all the files associated with it. In the end he said he threw the hard drive into a bonfire. I can’t tell you who he is because he doesn’t want to go to Federal prison, which is what could have happened if he’d told anyone that could do anything about the bug he’d found. Did that bug get fixed? Probably eventually, but not by my friend. This story isn’t extraordinary at all. Spend much time in the hacker and security scene, you’ll hear stories like this and worse.

______-··on Library fires have always been tragedies – just ask Galen
Thanks, wow you could keep it on a 16gb USB flash drive!
______-··on Library fires have always been tragedies – just ask Galen
> Comparing the Library of Alexandria with random web sites is unwarranted. Libraries are curated

I wasn't trying to compare, just making an analogy / metaphor. As in: how many libraries of Alexandria do we lose each day on the web? Because it it's too high a number, then the web is fundamentally broken.

> And websites who can't afford hosting, and there's hosting for $5 these days, BTW, self-curate themselves out of existence

But it shouldn't have to be like that. I've seen some real gems out there that disappeared and weren't backed up on Wayback. Literally all the owner needed was $5 as you say and the site could continue.

______-··on Library fires have always been tragedies – just ask Galen
How much data was the Library of Alexandria? A gigabyte? I ask because I see sites disappearing off the net all the time. I've even seen sites being shut down because of the pandemic. Some people got COVID and were financially drained and couldn't afford the $15.00 it takes to renew a domain along with a bare minimum hosting bundle. It's very sad to witness. Archive.org's Wayback Machine is doing a great job, but even that is problematic since we don't know how long even that will be around, and we might need an archival site that backs up Wayback!
______-··on I Miss the Old Internet (2019)
https://alex.flounder.online/gemlog/2021-01-08-useless.gmi
______-··on I Miss the Old Internet (2019)
Some Tor hidden services, or `Onionland` as it's called are very similar to the early web. For some reason a lot of the pages look like Angelfire[0]. I can't figure out why though. Perhaps the technical challenge of setting up an .onion was so hard that the webmasters were glad just to have something hosted and the bulk of their energy was spent on the hidden service and they didn't spend 5 hours creating a Javascript single page app in their free time.

[0] https://en.wikipedia.org/wiki/Angelfire

______-··on Doing something is better than doing nothing for most people: study (2014)
> The investigation found that most would rather be doing something – possibly even hurting themselves – than doing nothing or sitting alone with their thoughts

This brings up an old saying I learned years ago:

    If you're going to do nothing, don't do it here
Meditation is being active doing nothing. It's paradoxical, just like Zen koans are paradoxical. I don't meditate in the cross legged position however, and drift in and out of meditation doing everyday humdrum things like waiting for a bus to arrive, or my favorite: pretending to sleep, so I can actually fall asleep. Each preamble before sleep is itself meditation, and we can find ourselves meditating doing humdrum things like washing the dishes. You don't need to go to a monastery or wellness center to meditate. We are natural meditators!
______-··on Making invisible glue code first-class
It's worth researching the demoscene[0] and how demos that looked very complex were made with as few lines of code as possible. Every byte was accounted for and nothing went to waste.

This is a common thing in games and Super Mario even re-used the cloud sprite for the bushes[1]

Now we have to deal with gargantuan Electron apps that hog your PC's resources for housing what essentially is a lightweight webapp.

[0] https://en.wikipedia.org/wiki/Demoscene

[1] https://www.todayifoundout.com/index.php/2010/01/the-clouds-...

______-··on Working in the open: Enhancing privacy and security in the DNS
> Sending all DNS requests to Cloudflare

I like to combine DoH with a VPN. The VPN doesn't see my DNS queries, and Cloudflare just sees a vague IP based in some vague colocation center. There is still plaintext SNI[0] to worry about though, which is being mitigated with something called ECH[1]. `Oblivious DoH`[2] is worth reading about too.

[0] https://www.cloudflare.com/learning/ssl/what-is-sni/

[1] https://blog.cloudflare.com/encrypted-client-hello/

[2] https://blog.cloudflare.com/oblivious-dns/

______-··on How to think clearly
I've taken a liking to mulling over large pieces of content instead of paying attention to quick little soundbites that you find on social media. It makes me think clearly.

Just taking the time to indulge in reading a lofty tome is a real social media killer.

Although: I am prone to distilling the gist of core concepts that took many pages to explain. I probably got that trait from social media. Everything has to be reduced down to a soundbite or clever haiku-like quote.

______-··on Ask HN: Tools you have made for yourself?
Not really a computer program, but a list of all the best sites to visit that all spawn from a single folder in Firefox. It's opinionated, and one of the links is of course Hackernews, but also other sites like lobste.rs and old.reddit.com/r/programming etc Firefox lets you spawn a bunch of tabs and it saves me from having to manually click each link's URL. I use it very heavily. I am very thankful for the `Open all in tabs` feature.
______-··on London and Switzerland seeking to dodge G7 global minimum tax
> But London and Switzerland are already working to ensure they don't get badly hit by the minimum tax rate, as they fear it will make their financial districts less attractive

Well they're missing the point of this imposition, because it was designed expressly to avoid companies choosing 'favorable' locations to manage their tax affairs. Suck it up London and Switzerland.

______-··on How Hard is your Email to Say? (2020)

    at@at.at
And there's a HTML page for it:

https://at.at/

______-··on Privacy Analysis of FLoC
Yes but disabling JS as a default wipes out whole classes of attacks against your browser.

On top of disabling JS, just a simple AD blocker like uBlock Origin greatly diminishes the amount of profiling. There is no silver bullet however. It depends on your threat model.

If you really don't want to be tracked and profiled, using the Tor Browser Bundle is worthwhile, but even that is problematic since it's heavily surveilled (both at the entry node and exit nodes).

______-··on Privacy Analysis of FLoC
> FLoC is premised on a compelling idea: enable ad targeting without exposing users to risk

The second you open your browser you are exposed to risk. Many times I have had to tweak the default settings of my browser to comply with my (non paranoid) requirements. Basic things like putting DuckDuckGo as the default search engine, turning off various JS APIs like HTML5 Canvas, WebGL, using AD-blockers and other addons, tweaking about:config and hardening it, etc

Call me a power user if you want, but all this hardening stuff should ship out-of-the-box.

______-··on Ad tech firms test ways to connect Google’s FLoC to other data
You're just added to a (very large pool) of people who browse with JS turned off. Turning JS off as a default is a common thing.
______-··on Link shorteners: the long and short of why you shouldn’t use them
> A long token is used precisely because it is long and unguessable

This. So much fun can be had by enumerating link shortener URLs. I've experimented with enumerating some services' URL schema. Most of the time the link pointed to innocuous things like Amazon affiliate links or whatnot. Sometimes you would find interesting content that made you go 'wow!', but that was very rare.

______-··on Link shorteners: the long and short of why you shouldn’t use them
https://www.kerstner.at/2012/07/shortening-strings-using-bas...
______-··on Link shorteners: the long and short of why you shouldn’t use them
> My link shortening tool provides me with analytics

I run a link shortener site, and use it privately and don't publicly expose the API.

One thing I noticed regarding analytics, is that the click count is always skewed. When I post a shortened URL on Twitter, within seconds the click count is always `>10` views. After further investigation, it seems there are automated bots that scoop up URLs the very second they are posted.

Also Twitter runs little microbrowsers that scan the page for metadata which helps them create a 'preview' of the link.

After looking at the useragents of some requests I'm seeing generic Firefox UAs which I can only assume are random surveillants (not bots) who habitually scan Twitter for interesting or anomalous content. We truly do live in a world where nothing is left `unseen` (by bots or actual humans).

______-··on Ad tech firms test ways to connect Google’s FLoC to other data
You can't detect if WebGL's turned on/off if JS is turned off. You need JS turned on to detect WebGL's presence
______-··on Ad tech firms test ways to connect Google’s FLoC to other data
> End the arms race on fingerprinting

Google is known to fingerprint you on their sites[0] and this practice will continue unless some sort of political action is taken to make fingerprinting illegal. WebGL is not the only heuristic used to reliably determine it's a specific device accessing a site, but a whole slew of techniques can be used to reliably determine it is 'you' who is on a site (you can even detect if a browser is running in a virtual machine, among many other techniques to fingerprint).

To mitigate this, I do most of my browsing with JS disabled by default, and if I really need JS turned on (for a site I trust like my bank), then I temporarily turn it on for that specific site. Also you can just disable WebGL in Firefox in about:config but keep in mind, there are many other techniques Google and `ADTech` in general can use to fingerprint you.

[0] https://jonatron.github.io/webgl-fingerprinting/

Page 1 of 6Next →