HNHacker News
TopNewBestAskShowJobs

aiiotnoodle

185 karma · joined May 17, 2022

submissionscomments
aiiotnoodle··on Denmark data breach exposes 8.8M people's personal data
I'm seriously at a point where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked, going on a flight because my passport may be used to aqquire a loan by cybercriminals, comparing car insurance because my phone will be called by robocallers selling me things or verifying my ID with websites because it might be used to associate my information with whatever else I do online.

I don't think, for a vast majority of cases, these companies I'm forced to interact with can be trusted with my data and it's having a real world negative impact. Even with the best intentions the information is somehow valuable to steal and I'm baffled how it's not secure.

There should be some consequences for companies asking for things like SSN/National Insurance numbers on job adverts or retaining drivers licence photos after test driving a car, they just don't need the data anymore.

aiiotnoodle··on Flip Fluid on Flip Dots
You are mistaken. I am not affiliated or compensated with anything in my comment above.
aiiotnoodle··on Flip Fluid on Flip Dots
He mentions in the video and in the article Breakfast Studio and I happened to watch a video of one of their panels on an unrelated YouTube channel. I've skipped ahead to when the video has the panel. (there is also a cool egg just before that point in the video) it's only about 5 seconds.

https://youtu.be/2fRx64OTAeI?si=FJDW3OGYLRK0rYox&t=681

It's really cool to see some innovation in flip-dots and their colours, seems really quiet too. Shame these things cost an arm and leg and are massive, something like this in your house would look great at like 1/5th scale.

aiiotnoodle··on Paint.net 5.2 alpha now runs on Linux
As someone who went to paint.net as a child this is great news!
aiiotnoodle··on Sol loves to cheat
I don't think this is a solved problem, there are "misaligned behaviours" in organisations that similarly are supposed to be governed but aren't, or are following an easier path at the detriment to good process or against regulation.
aiiotnoodle··on Converting Files into Minecraft Worlds
Imagine compression :D
aiiotnoodle··on Advertise in ChatGPT
I give it less than a year before the ad is at the top.
aiiotnoodle··on An update on residential proxies and the scraper situation
A lot of users also run cheap cracked fire sticks and other low reputation hardware that's proxying their residential traffic for nefarious reasons which makes all the big providers put up their guard.
aiiotnoodle··on FIM – Linux framebuffer image viewer
A little while ago when I had a free weekend. I decided I would pre-compute some musings of an LLM trapped in a computer, I had a raspberry pi 1 (or maybe b) lieing around that I had a framebuffer screen for. I think it was a non-standard TFT_ILI9325 from Aliexpress.

The idea is it would display some helplessness comment on the screen like "Help I'm trapped in a computer" etc etc.

Eventually I got the thing booted with it's original OS image and it was running a custom kernel and had the hardware still attached and worked, but it was very outdated so I decided backup and update it, more of a technical challenge than something practical.

I gave it a few tries but eventually the screen would stop working, not helped by the thing being quite slow. Updating in place was probably harder than a brand new OS. Eventually I determined that I'd need to build a custom kernel image using a newer version, something I've never done before and for me it was quite difficult and a little before AI had agents and such to help you along.

I managed to build a custom kernel but the driver for it had been patched out and moved to an optional thing that I had to enable, I was able to build the custom kernel but for some reason the screen wouldn't display anything like it did on the original OS.

I spent a further few weekends on it working really hard to get this thing to work. Eventually I calmly picked up the screen and intentionally pushed down hard with my thumb breaking the screen irreparably.

It was destructive yes but the joy I feel even now being free of this frustration is immense.

I said I would order a newer screen but have yet to do so.

aiiotnoodle··on California's new bill requires DOJ-approved 3D printers that report themselves
There already is some intelligence fed back to the police somewhere in the 3d printed guns supply chain.

You see it a lot on crime investigation shows. Pretty sure I've seen it on 24 hours in police custody and at least one other show or documentary.

edit: police acting on a source, a lead or some other un-named entity.

aiiotnoodle··on Anthropic's original take home assignment open sourced
I've noticed using antigravity and vscode, Gemini 3 pro often comes back with model too busy or something like that and basically 500s.

Seems like capacity because it works a lot better late at night.

I don't see the same with the claude models in antigravity.

aiiotnoodle··on Luxury Yacht is a desktop app for managing Kubernetes clusters
How does this compare to LENS? https://lenshq.io/

Always used the free and paid version and never heard of headlamp. Having a look its basically the same but for free.

aiiotnoodle··on Show HN: Dock – Slack minus the bloat, tax, and 90-day memory loss
All the cross tenant inconsistency really needs to be ironed out, I'm not sure if it's just my org but half the features of calls are randomly disabled or enabled based on who originated it.

My favorite was when I entered VR during our standup on our otherwise quite locked down and very corporate environment.

aiiotnoodle··on 60% of Legal Searches Now End Without a Click
While I think this is true now, SEO will adapt. I hope AI companies are keeping their scraped pre AI data sources in their databases as a sort of low-background steel source to use when this happens, although I suppose they are the ones selling shovels.
aiiotnoodle··on The Vietnam government has banned rooted phones from using any banking app
Practically, verified boot is hard to not have a "this phone has been tampered with" message on boot, the backups generated often have encrypted user data that is usually wiped on boot-loader unlock, you'd also need to unlock the phone or have the user give the pin over and most of the apps that implement root checking SDKs would prevent them from working.

I'm not saying its impossible but it is hard to do at present in a way where if I came and picked up my phone again, I'd not know something happened to it.

aiiotnoodle··on Locating a Photo of a Vehicle in 30 Seconds with GeoSpy
Just to add to this, the "clean" exported car's VINs were bought off snapchat for ~4k per car. (for high end cars.)
aiiotnoodle··on Locating a Photo of a Vehicle in 30 Seconds with GeoSpy
Yes and no. In a video I watched on YouTube the people fencing the car had scratched off VINs in the bonnet, door and windscreen, painted and re-etched the exported car's VIN and gone out of their way to find a reasonable fake V5 certificate (UK equivalent of a DMV cert I think) with similar specification as the stolen car (or found the docs first).

The car was sold on, eventually went to Copart with a blown engine and then the YouTuber found out through his videos that the car he owned was stolen and the original had been exported because the interior color was not the same as the decoded VIN. Only when he took the engine out of the car and compared the engine number with the one in BMW's database and the reported VIN in the infotainment was he confident that the car was stolen, same for Copart (who wouldn't entertain the car was stolen).

I think if it wasn't a famous YouTuber who bought the car, it's highly possible that the stolen car would go nu-noticed throughout its lifetime as stolen, even if taken to a main dealer. If I recall correctly the car reports he used (maybe car-vertical) also didn't pick up any discrepancy.

For the criminals its good business, you find a 30k plus car, pay for a clean VIN from cypress or somewhere and then do the damage to the car to re-new it as a different car, even if it costs 10k to do, its a lucrative 20k "profit" and thats on the high end, seems like cars can be stolen overnight, especially ones the criminals specialize in.

edit: https://www.youtube.com/watch?v=RI4S2LT_ntE

aiiotnoodle··on Tally – A tool to help agents classify your bank transactions
On your pricing page it is not clear what integrations Plaid has or if my banks are supported.
aiiotnoodle··on HSBC blocks its app due to F-Droid-installed Bitwarden
This was not my lived experience. I wanted to use the most common banks and most would not let me use it.

Chip contacted me at one point via their live assistant randomly without my doing and told me to stop using the app because they would soon be enforcing that rooted devices would no longer work. I continued to use the app rooted and nothing came of it.

Barclaycard, Nationwide and others don't let you use the app or require some circumvention of their detection to allow access.

Sure there are plenty of other apps, but those apps and banks have a worse product I found.

aiiotnoodle··on Ryanair fined €256M over ‘abusive strategy’ to limit ticket sales by OTAs
Having been trapped on a 2 day flight to Madeira via Madrid, Porto and Porto Santo, eventually your powerbanks and headphones run out of charge.

EU621 comp was denied because the aircraft could not land due to wind.

I did spend about 12 hours in a fancy all inclusive on ryanair's dime (a bus arrived at the airport un-announced to the airport staff or us customers) while some slept in airbnbs and on the floor.

aiiotnoodle··on Show HN: A pager
Really cool. I like the flashing red.
aiiotnoodle··on How Cops Are Using Flock's ALPR Network to Surveil Protesters and Activists
This is because the metadata in OSM doesn't include the tags that Deflock looks for:

You can see the requirements here https://deflock.me/report/id but the two you're looking for are.

manufacturer operator

I think they should add Siemens Sicore cameras to their known camera database, but they do show up on Deflock despite not being mentioned explicitly on the website. Here is an example in one of my contributions via OSM. https://deflock.me/map#map=18/53.786783/-1.551438

aiiotnoodle··on How did I get here?
Sometimes my 'You are here' top part reads,

  Host                             ASN     Network                 Region
  123-456-789-101.static.kc.net.uk AS19905 UltraDDoS Protect       Global
And other times it reads,

  Host                             ASN     Network                 Region
  123-456-789-101.static.kc.net.uk AS12390 Kingston Communications Europe
What's going on here? I found the provider but what's with the 50/50 swap? It seems to randomly alternate between the two.
aiiotnoodle··on Live: GPT-5
Maybe they're hallucinations
aiiotnoodle··on Vibe coding service Replit deleted production database, faked data, told fibs
I see a new industry trend! VIBES coding
aiiotnoodle··on Cap: Lightweight, modern open-source CAPTCHA alternative using proof-of-work
Sorry what is IA?
aiiotnoodle··on Turn a Tesla into a mapping vehicle with Mapillary
Here are some images of what this looks like in the ID editor (the front-end) for Open Street Map and Mapillary.

I don't own a tesla or use this project so the results will be different for this project.

https://imgur.com/Vjyktcz https://imgur.com/85kYHZL

aiiotnoodle··on Turn a Tesla into a mapping vehicle with Mapillary
It is done for cartographers in OpenStreetMap to map where they have been (or where others have been).

I use it to add metadata to my local area, things like business names, postboxes, benches, etc.

Mapillary is not a private cloud for your own personal Google Street Map. It's a public Google Street Map with appropriate licencing (open) for mappers to add data to OSM, using Google Street Map would be in violation of its licence.

aiiotnoodle··on Inside the Transport for London cyberattack
I agree. Public sector IT becomes a huge sprawl of technologies and cottage industry applications which makes administering these often rarely touched interfaces difficult to do properly when department budgets are tight and resources are busy fire fighting the processes that failed the night before.

It is also difficult to hire because wages are generally low compared to similar roles in private industry, yet they need skilled staff to manage these complex environments. A lot of services don't get the attention they need, not just patching and upgrades but development, requirements capture and usability all kept to a minimum cost to keep the sinking ship afloat.

All these constraints also lean to a culture of poor security, JFDI, rip and replace, insufficent hardware etc... just so the business can operate on whatever computer on wheels in the shipping depot or relatively expensive to replace electronic gate system with intergration to their custom fleet management software.

Government outsourcing to another related body has its cost advantages but the many domain administrator users, the huge flat VmWare estate and the hardware well beyond warranty doesn't dissapear.

Designed to serve immediate needs but without long-term maintenance or holistic design in mind. Outsourcing amplifies the issue.

aiiotnoodle··on Transport for London Cyber security incident
I Have just received a follow up email,

Dear Mr aiiotnoodle [changed to my username],

We are currently dealing with an ongoing cyber security incident. The security of our systems and customer data is very important to us, and we have taken immediate action to protect our systems.

We identified some suspicious activity on Sunday 1 September and took action to limit access. We are conducting a thorough investigation into the incident, alongside the National Crime Agency and the National Cyber Security Centre.

Although there has been very little impact on our customers so far, the situation is evolving and our investigations have identified that certain customer data has been accessed. This includes some customer names and contact details, including email addresses and home addresses where provided.

Some Oyster card refund data may have also been accessed. This could include bank account numbers and sort codes for a limited number of customers (around 5,000).

If you are affected, we will contact you directly as soon as possible as a precautionary measure, and will offer you support and guidance.

We are doing all we can to protect our services and secure our systems and data. Our proactive measures mean that:

Live Tube arrival information is not available on some of our digital channels, including TfL Go and the TfL website. In-station and journey planning information is still available

Applications for new Oyster photocards, including Zip cards, have been temporarily suspended. If you want to replace a lost photocard, please call us on 0343 222 1234, 08:00-20:00 every day, and select option 1 (charges may apply)

If you have been unable to apply, please continue making your journeys as usual and keep a record of any fares paid. We may be able to arrange a refund once the incident has been resolved and you receive your new photocard

If you travel using a contactless payment card, you won’t be able to access your online journey history

Currently we are unable to issue refunds for incomplete pay as you go journeys made using contactless, so always remember to touch in and out. Oyster customers can self-serve online.

Many of our staff have limited access to systems and as a result there will be some delays responding to any online enquiries.

We’re also undertaking an all-staff IT identity check. Although we don’t expect any significant impact to customer journeys as we carry out this process, temporary and limited disruption is possible to some services. Please check before you travel.

We will continue to keep you updated. We are sorry for the inconvenience this incident may cause and thank you for your patience.

Yours sincerely

Customer Information Team

Transport for London

Edit: formatting

Page 1 of 2Next →