HNHacker News
TopNewBestAskShowJobs

currysausage

1,874 karma · joined December 24, 2012

Try some currywurst, it's delicious!

(Actually, eat vegetarian. It’s good for you and good for the planet.)

[HN handle] at fastmail dot com

submissionscomments
currysausage··on Scammers are abusing an internal Microsoft account to send spam links
Yeah, I fell into that rabbit hole once. Tried all abuse channels that I could find. network-abuse@ refers you to the Google Cloud abuse form. They ‘are not able to take action on this report since the IP mentioned in the report is not hosted on Google Cloud.’ Gmail abuse doesn’t even bother to reply (why should they, it’s not about Gmail after all). In the end, I just blocked DKIM identifiers related to Firebase via Rspamd.
currysausage··on On The <dl> (2021)
Great post. Very minor nitpick: ‘The small element must not be used for subheadings; for that purpose, use the hgroup element.’

‘The small element represents side comments such as small print. Small print typically features disclaimers, caveats, legal restrictions, or copyrights. Small print is also sometimes used for attribution, or for satisfying licensing requirements.’

(https://html.spec.whatwg.org/multipage/text-level-semantics....)

currysausage··on Mathematics for Computer Science (2018) [pdf]
When I need a refresher on the basics of Python, I refer to Python Distilled, and when I want a deep dive, I turn to Fluent Python. Reading these books makes me feel like I'm sitting next to an experienced, witty colleague.

I will take a look at Python Crash Course.

currysausage··on Vaultwarden commit introduces SSO using OpenID Connect
The web frontend could still send secrets to third parties.
currysausage··on The Scourge of Arial (2001)
Aptos replaced Calibri in Word and Excel.
currysausage··on Microsoft extends free Windows 10 security updates into 2026
One upside of this reimplementation is that we can now enjoy state-of-the-art Electron-level loading times when opening a new Explorer window. /s
currysausage··on Stop Using Encrypted Email (2020)
There are, of course, web email services that purport to encrypt messages. But they store encryption keys (or code and data sufficient to derive them). These systems obviously don’t work, as anyone with an account on Ladar Levison’s Lavabit mail service hopefully learned. The popularity of “encrypted” web mail services is further evidence of encrypted email’s real role as a LARPing tool.
currysausage··on Smallest Possible Files
I believe the sentence from the RFC:

[XHTML1] defines a profile of use of XHTML which is compatible with HTML 4.01

is technically incorrect. While the XHTML 1 compatibility profile was compatible with HTML 4 as implemented by major browsers, that wasn't actually HTML 4. HTML 4 is based on SGML, while what was implemented was a combination of HTML 4 semantics with the tagsoup parsing rules that browsers organically developed. These rules were only later formalized as part of HTML 5.

The compatibility guidelines do recommend a space between <br and />, but (at least according to https://validator.w3.org/ in HTML 4 mode) this doesn't change anything about <br /> being a NET-enabling start-tag <br /, followed by a greather-than sign.

Enter this:

  <h1>Hello<br />world</h1>
and select "Validate HTML fragment", "HTML 4.01", and "Show Outline". This is the result:

  [H1] Hello>world
(Obviously nitpicking, but that's my point: the nitpickers can be out-nitpicked.)
currysausage··on Smallest Possible Files
This is especially ironic, considering the same people will gladly use XML syntax and serve it as text/html. Historically, this has only worked because no relevant browser has ever implemented SGML (and NET [1], in particular), as required by HTML standards up to version 4 [2].

[1] https://en.wikipedia.org/wiki/Standard_Generalized_Markup_La...

[2] https://www.w3.org/TR/html401/conform.html#h-4.2

currysausage··on Global, distributed and backwards compatible CVE alternative launched by CERT
CERT stands for Computer Emergency Response Team.

CIRCL, the supposed operator behind gcve.eu [1], "is the CERT for the private sector, communes and non-governmental entities in Luxembourg" [2].

[1] https://gcve.eu/contact/

[2] https://en.wikipedia.org/wiki/Computer_emergency_response_te...

currysausage··on Default styles for h1 elements are changing
If I remember correctly, W3C’s XHTML2 working group wanted a generic <h> tag [1], and WHATWG, focused on evolving HTML in a backwards-compatible manner, repurposed <h1> as a context-dependent heading tag instead.

[1] https://www.w3.org/TR/2010/NOTE-xhtml2-20101216/mod-structur....

currysausage··on Nebula Sans
Fira was designed by world-class type designers, and it’s only free thanks to the funding by Mozilla and Here, so yes, definitely a different category.

Same goes for IBM Plex, by the way.

currysausage··on Why does target="_blank" have an underscore in front?
Another nitpick: the attribute was called name, not id.

https://www.w3.org/TR/html401/present/frames.html#h-16.3

currysausage··on Dumping Memory to Bypass BitLocker on Windows 11
> use TPM (PCR 7+11) with a PIN

A power-on password (set in the BIOS) should also work, since without it the system will never get to the point where the TPM unlocks the FVEK, right?

I prefer this setup to a Bitlocker PIN because I can use a fingerprint instead of the power-on password on my Thinkpad, and because it should make the device largely unusable to a thief.

Of course, power-on password and fingerprint auth are only as strong as my TPM, but the same goes for Bitlocker TPM+PIN, right?

currysausage··on Even Microsoft Notepad is getting AI text editing now
https://www.microsoft.com/en-us/windows/tips/clipboard-histo...
currysausage··on Sshfs for Windows
Looking for something like this right now. How does it compare to rclone [1]?

[1] https://rclone.org/sftp/

currysausage··on Google loses antitrust suit over search deals on phones
> That sounds like an Apple issue

True. But guess who’s paying Apple good money in order to remain the default search engine. Who knows what else might be part of this deal?

currysausage··on Visiting the annual Braun collectors fair
“Part of the Herald (Hong Kong) group of companies, Zeon Ltd is a leading manufacturer and distributor of clocks and watches, operating internationally in wholly owned offices in London and Hong Kong.”
currysausage··on Bringing Exchange Support to Thunderbird
As I understand it, before you open a (potentially dangerous) attachment in another app, it would be saved to your Temp or Downloads folder, where Defender would still have access.

A carefully crafted email (or PDF attachment) that exploits vulnerabilities within Thunderbird's HTML or image rendering (or its PDF.js sandbox) might still pose a risk, but probably less so than any random web page that you open in Firefox, where JS (which should be disabled in Thunderbird by default) is the primary attack vector.

Also, note that there is a setting called "Allow antivirus clients to quarantine individual incoming messages". With this enabled, "Thunderbird first stores each incoming message in a temporary file in the system temp folder" (where Defender would have access). "If the new message file still exists after being scanned by the antivirus software, then it is moved to your Thunderbird Inbox folder file." [1] If this is implemented correctly, it should only impact performance when receiving new emails.

[1] https://support.mozilla.org/en-US/kb/privacy-panel-settings-...

currysausage··on Microsoft suggests command line fiddling to get Windows 10 update installed
It looks like a PowerShell script is available now, but I don't think it's changing the partition size. Has anyone tried this out? https://support.microsoft.com/en-us/topic/kb5034957-updating...
currysausage··on Outlook/Hotmail is no longer blocking my mail server
This was not the cause in my case (no attachments, no URLs, just plain text, as far as I can remember). I know how to send email (ask mail-tester.com).

Regardless, there are always better options than silently discarding the whole email: delete attachments, erase everything that looks like a URL, even erase the whole message body, but please tell the recipient that you accepted an email and from whom.

currysausage··on Outlook/Hotmail is no longer blocking my mail server
But why do you consider this good practice? It's (unnecessarily?) frustrating for senders and poses a legal risk for recipients (the sender has the logs to prove that they sent the invoice, while the recipient doesn't have any record).
currysausage··on Outlook/Hotmail is no longer blocking my mail server
The way you implement this, low-volume senders (nerdy individuals or small projects that can't use SES/Mailgun/… for GDPR reasons), even if they manage to get off the list once (olcsupport.office.com, escalate), never get the chance to build up reputation in the long term (I'd have to contact olcsupport again in a few months and that's just not sustainable for a small-time postmaster).

I get it, you're afraid that some VPS from a cheap cloud provider suddenly floods the inboxes of thousands of Outlook.com customers. I realize that a fresh IP that sends dozens of emails out of the blue has to be blacklisted.

But why don't you allow my VPS to send, say, 16 emails a day to Outlook.com inboxes? And if ⅛ of the recipients report junk, I get blacklisted. But if all 16 recipients are happy, my IP can now send 16+16=32 emails/day for the next few months (as long as the non-ISP hostname matches; otherwise, it might be a new VPS customer), and so on.

This way, your customers are happy (I don't think spammers rent/hack a fresh VPS in order to send 16 emails, and I don't think they are very good at building up IP reputation), and I'm happy (my personal VPS can send a few emails to my Outlook.com contacts every few weeks/months, and my project VPS can gradually build up and maintain the reputation it needs).

I'm obviously being naive about that approach, but I don't remember having trouble reaching Gmail inboxes or those of local providers, and at least for Gmail, I know that they have pretty effective spam filtering too, so I reckon that they use some approach like the one I described.

For a side project, I have just given up contacting olcsupport and instruct Postfix to send through our @outlook.com address instead, but that is a wobbly workaround at best. For personal email, I now relay through SMTP2GO because GDPR doesn't matter that much, but it makes me sad to have that gaping hole (called Outlook.com) in my decentralized email fantasy, after having spent so much time researching, configuring, diagnosing.

currysausage··on Outlook/Hotmail is no longer blocking my mail server
The most pressing question: why does Outlook.com just silently discard some emails?
currysausage··on Three Decades of HTML
I remember that revelation! “Holy s**t, what if I click ‘Save’ now?”
currysausage··on New Requirements to Travel to Europe
Apple/Google Pay also implement the EMV standards, so at least in theory, it shouldn’t make a difference. In practice, I don’t know and I can’t check, unfortunately. It’s possible that they chose not to implement this particular tag.

I did query the chip on my plastic MC Debit and it definitely reveals my name.

currysausage··on New Requirements to Travel to Europe
When the payment terminal asks the EMV chip on your payment card for tag no. 5F20, it will be told the Cardholder Name [1]. That, in connection with your PAN [2], is a pretty stable identifier. (Not if you are using prepaid cards, obviously.)

[1] https://emvlab.org/emvtags/show/t5F20/

[2] https://emvlab.org/emvtags/show/t5A/

currysausage··on Firefox tooltip bug fixed after 22 years
Excel showed me tooltips’ shadows on other desktops. Took me a few minutes to figure it out!
currysausage··on Buffer Overflows in Notepad++
I'm very fond of Notepad2, but development ceased in 2012 and the fork that I'm using, Notepad2-mod [1], had its last release in 2017. I wonder how many buffer overflows are lurking in there.

I just discovered Notepad3 [2], which appears to be a maintained fork. Screenshots look very similar to Notepad2. Gotta check it out later.

Any other forks that I should be aware of?

[1] https://github.com/XhmikosR/notepad2-mod

[2] https://www.rizonesoft.com/downloads/notepad3/

currysausage··on Videolan: Google refuses to take down or unlist domains with tons of malware
Seriously, uBlock Origin is the one "endpoint security" product that's actually useful. I install it on practically every machine I ever touch.
Page 1 of 15Next →