HNHacker News
TopNewBestAskShowJobs

ds

5,050 karma · joined November 26, 2009

Herding cats @ https://redact.dev - Delete your digital footprint

Personal site and contact info -> http://harknesslabs.com

submissionscomments
ds··on Show HN: Redact – Automated deletion for your content on social networks
No, we just believe in the mission of privacy and they seem like the biggest supporters in the business. They paved the road we now walk upon, so its due to give them something back.

*edit- Seeing comments below, I can see the issues. We will remove the 'Support the EFF' banner for now until we can do it in a better manner.

ds··on Show HN: Redact – Automated deletion for your content on social networks
Yeah, electron :)
ds··on Show HN: Redact – Automated deletion for your content on social networks
Hey HN- Im one of the team members at redact. Redact is a cross platform electron app which allows you to delete content programmatically from most of the big sites out there (we are adding more every day). Meaning, you could say something like "Delete all posts I made on instagram with less than 15 likes in 2019" or (very soon) "Delete all my tweets that are political" We have been working on this for a little over a year. As you can imagine, working with some of these legacy services is less than ideal. (looking at you skype)

When we launched, we were aware of tons of other free services that let you delete content, but we found that most of them were either unmaintained and broken, not feature rich enough or complicated for grandmas to install. "Ok, so first- download Kali linux to a thumb drive. Then reboot into it and install python and clone this repo...."

Our goal with redact is to make privacy as accessible to the general public as possible. There are tons of services that let you delete 'public' data about you (for instance, deleting your whitepages.com page) but we found very few which took care of content YOU created across more than 1 service.

ds··on Stripe Payment Links
I built something like this way back in 2008, since paypal let you set a IPN dynamically. Was basically a pastebin behind a paywall. I found it incredibly difficult to market, but I think I was doing it wrong because gumroad took off many years later

https://www.redferret.net/tiny-checkout-very-cool-little-onl... https://web.archive.org/web/20090227044608/http://www.tinych...

ds··on Complexities of e-mail validation logic
If your email is <RFC>fan 69™@root I am not going to let you signup. Sending emails cost money and bouncing emails affects your sender reputation. Also, for every user out there using <RFC>fan 69™@root as their email address, there is going to be thousands of people accidently entering their email address incorrectly and not getting a alert about it. Yes you could do fancy shit like checking mx records and whatnot, but come on- Im not going to maintain/build that infrastructure for the one out of a million people who are trying to use that address.

Developer time is precious at a startup and supporting <RFC>fan 69™@root while still denying b ob@gmailcom is very, very far down the list of things to do.

In summary: I don't suggest doing 'perfect' email validation to RFC spec. You will save money/devtime and make more of your users happy by not doing it.

ds··on AMD Reports Q1 2021 Earnings
This is not true. Every major prebuilt company has significant delays on 3080s and 3090s. I just checked.

ibuypower: 6 weeks

nzxt: 4 weeks

originpc: 4 weeks

maingear: 12 weeks

alienware: 5 weeks

ds··on Teamspeak 5 to be based on the Matrix protocol
Id be willing to bet discord makes more gross profit from nitro sales in one week than TS/Vent make in a year, combined.
ds··on Teamspeak 5 to be based on the Matrix protocol
Not to be negative, but teamspeak and ventrilo represent some of the biggest failures of 'getting stuck in your lane' ever. They got fat on hosted server revenue and never iterated. Both of them had years (decade?) on discord and never thought to make their product free, web based or have a better chat. Ventrilo still has no official ios/android app (lol). Both remind me of craigslist, actually- Except that craigslist is still going strong (for now).

Both still exist, granted- And many still use them. Its just that discord really shouldnt exist, it should have been one of these players. The head start they had should have been insurmountable.

Also, apologies for not really commenting on the subject at hand (TS supporting matrix) - Its just I so rarely hear about TS/Vent that I thought it worth me shouting into the ether my disappointment I am not talking to all my friends on vent/ts in 2021.

ds··on Double Blind Passwords a.k.a. Horcruxing
The best password manager would be a physical device which requires a tap to unlock a password.

Trezor password manager got close, but it seems like they abandoned it and they never supported local (sd card) storage.

Basically, It would be a yubikey style device, secured by a master password. You could have nice browser plugins for listing all your available passwords and single click logins, etc.. Everything that lastpass/1password does from a UI standpoint.

The difference would be that decrypting/unlocking passwords would require you to physically tap on the device each time to approve the unlock- and the screen would say "Unlock password for github.com?". Basically, this system makes it impossible for some trojan remote-control virus to be able to get your passwords, even if they have your master password. The BEST they can hope for is just to sit quietly on your PC for months, slowly storing all the passwords you decide to unlock.

Alas, doesnt seem like this device is going to exist any time soon. As I said, the best bet was trezor but they dont seem to care about it anymore. Too bad, they were so close.

ds··on Zero-click, wormable, cross-platform remote code execution in Microsoft Teams
Whats the reason to even participate in most bug bounties for serious shit like this knowing you could get 10-100x more submitting to Zerodium? Is it the hope of getting on some 'hall of fame' which might land a job offer?

Like, If I found a exploit for something random like skype/slack/etc.. that let you run code on any targets machine with zero interaction, there is zero chance my first stop would be the bug bounty program. For serious exploits, I believe you can get up to 2 million bucks with zerodium. Just seems like a no brainer.

Now that said, I would definitely use the bug bounty program for boring/low impact stuff like XSS and whatnot that has limited value/impact as nobody else would likely ever buy it for that much higher of a price.

ds··on AMD Zen 3/Ryzen 5000 announcement [video]
This. If they cant get it under control, it wont effect intel as much as you think.

Some say its yield issues, but who knows. 4900HS laptops are selling out like crazy and not keeping up with demand- New laptops arent using the chips because of lack of inventory. They are absoultely beasts though. The zephyrus g14 absolutely dominates on performance + battery life.

ds··on Reasonably priced color e-ink display
Havent looked into this much- What is the maximum 'refresh' rate you can get out of something like this?
ds··on SEC issues $3.8M whistleblower award
Just a FYI- You arent going to find any info on what case/fraud this has to do with. IIRC, the SEC announces these payments up to 24 (!) months from the original enforcement action, so that there is no real way to figure out which company was blown. I suppose if you want to, you could go back 2 years in time for every SEC enforcement and find all of them above 38m in penalties.
ds··on iMessage for Windows: A labor of love that will never see light of day (2018)
So, I may be missing something, but...

You can get imessage for windows with way less effort and full functionality. Just have a VNC window to a mac with imessage on it. There you go, every functionality of imessage on windows. All it requires is a mac mini.

ds··on A Message About Vanguard From Our Security and Privacy Teams
To be fair, this happens regardless, every day. Nobody believes anyone suspected of cheating, ever. And I mean ever. Just go look at the steam forums and the thousands of "i was falsely banned posts". If what you are saying was true, we would have seen this already happen for steam on reddit every day, which it doesnt.

Also, thats not to say you cant have a second and third tier of support to escalate your case to if you think you were wrongly banned, which wouldnt go to the grunts.

ds··on A Message About Vanguard From Our Security and Privacy Teams
That heavy lifting wasnt done by myself so I unfortunately dont have a answer for you. This was around a decade ago however, so I would not be surprised if the traffic was unencrypted.
ds··on A Message About Vanguard From Our Security and Privacy Teams
Depends, there are many methods of doing it. Many games let you hear gunshots/grenades/etc.. that are far away. You can use those sounds to show a radar spot.
ds··on A Message About Vanguard From Our Security and Privacy Teams
Valve also put a significant amount of work into this system. Asking every game developer to build that system for their game seems like alot to ask- Especially when they can just drop in a few lines of code // third party software package and have cheating 'handled'.

'Not invented here' is a blessing and a curse.

ds··on A Message About Vanguard From Our Security and Privacy Teams
The inherent issue with anti cheats as compared to anti-virus software is user intention.

A user who installs a anti virus program wants that program to do its job and find bad actors. The virus on the other hand is completely unwanted by both the user and the software- Its existence is threatened by all fronts.

However, a anti-cheat lives in a extremely adversarial environment. The cheater (and the cheat) wants the cheat on its computer. As such, the user will be willing to do extra steps to assist the cheat. This makes the anti-cheat software in this case, the 'un-wanted' virus, so it has to exist in the most hostile of environments and somehow detect programs which have higher privileges than itself.

That said, Cheating is something that will not go away. Years and years ago, I developed with a friend of mine a completely undetectable cheat for all games on the HL2 platform. It involved a second computer, which man-in-the-middled all network data to the client computer. This second computer then would display a 'radar' of where enemies were. As the anti cheat would have no possible way of knowing the existence of this second computer, there was not much they could do.

If you wanted to get more aggressive with the system above, you could have that second computer modify outbound requests as well. So if you shoot your gun and it would have hit the ground, it will now instead shoot a enemy in the head- as such even something like a aimbot is entirely possible with this setup.

However, there is indeed a anti cheat which can detect all known cheats and its basically what Valve did/does for CS:GO - Allow users to report suspected cheaters and then have the community analyze the reports. This catches all blatant cheats, but unfortunately will never get rid of radar/esp cheaters, only aimbots and the like.

Honestly, it sounds to me like there is a business model in the above. Years ago we had companies like evenbalance/punkbuster, easy anticheat, etc.. which provided software based anti-cheat systems. As you would expect, most would by bypassed and a daily cat and mouse game would ensue. The solution imo is to create a SaaS where you essentially provide a reporting + monitoring tool. Users of your game can report suspected cheaters (which includes the demo file / vod / replay / whatever) and your trained wet-ware staff would review all reports and take action where necessary. No invasive software necessary. Actually, no software on the end users computer at all would be necessary- It is all done on another users PC.

In fact, if someone is interested in doing the above, hit me up. Sounds like a easy win.

ds··on Court: Violating a site’s terms of service isn’t criminal hacking
Its really not that clear and we will need to wait for the courts to figure out what means what.

For instance this: https://www.theguardian.com/technology/2013/mar/18/at-and-t-...

All they did was "scrape publicly facing data"

ds··on Court: Violating a site’s terms of service isn’t criminal hacking
Feels like this is going to create some headaches for prosecuting CFAA cases if the verdict stands.

I suspect the definition of 'unauthorized access' will need to be more clearly defined since I know many cases in the past relied around users doing shit that was unauthorized by the TOS.

ds··on Zoom meetings aren’t end-to-end encrypted, despite marketing
So, I got around a issue like this in the past by using url fragments. I imagine the same thing could work for zoom?

Basically you would join a meeting by going to zoom.us/meeting-id-number#secrethashtag

The "secrethashtag" is never sent to the server, but can be accessed by javascript on the client end. Im not sure if this would be acceptable for security nuts though, as I am sure they would make the argument zoom could insert some nefarious js to intercept the url fragment.

ds··on Cloud Storage for $2 per TB per month
So I did a quick look and it seems like the total usage of siacoin is not that large.

https://siastats.info/hosts_network Only 710 TB is in use. Or about $20k worth of hardware TOTAL for the entire network, according to the above URL.

Also, why is this a cryptocurrency at all? Wouldnt this business be drastically simplified by simply paying people out//letting people rent space with either USD or bitcoin?

ds··on Cloud Storage for $2 per TB per month
The most important thing not addressed here is demand. Last I checked (granted, this was a while ago) it simply wasnt there- Meaning if you built this rig you might only be able to rent out a small part of it.

If this has changed I would be interested in hearing about it-

One other thing I am not understanding is how this makes financial sense, even if the demand is there. If I am buying a rig for 4500 bucks to get 200TB, making "570 a year in profit" is nowhere near exciting enough. Practically any other use pays more. Renting a dedicated server for a game, web hosting, hell even GPU mining makes more.

(a single 1080ti can do about 1$ a day in gross revenue on grin/eth/etc - which can be had used for ~400 bucks- Or you can get a p102 which is the mining card version with no display output for 250 bucks) - Payback with power costs/etc.. well below the 10 year threshold of siacoin)

Now where it might be interesting (IF there is demand), is just adding harddrives to an existing infrastructure already in place. So if you are a GPU miner and have 1000 rigs already in place, just adding a single 4TB harddrive to each machine might not be too bad- They go for about $50 each used and according to this, will pay back $8 a month with minimal extra costs

ds··on Craigslist releases new mobile app for iOS and Android
If I had equity in craigslist as a employee or investor I would be furious.

Think about how much value has been lost to offerup & letgo because they literally took over a decade to release a official mobile app. There is no excuse besides incompetence and gross negligence.

There should unironically be employee lawsuits at the management.

ds··on Alcohol breath tests are often unreliable
Ive always been curious and it seems like nobody really answers the question, perhaps because the act of driving drunk is so faux pas:

If you know that you are drunk and you are pulled over, is it better to refuse the breath test or not?

The only advice I have ever heard which made sense didnt answer that question but suggested you stall as long as possible so that the maximum amount of time would go by before you take the 'official' test at the police station, which should in theory result in a lower blood alcohol percent.

ds··on A deep dive into iOS Exploit chains found in the wild
From the article, a reboot will do it. You dont need a hard reset :

"The implant binary does not persist on the device; if the phone is rebooted then the implant will not run until the device is re-exploited when the user visits a compromised site again. "

ds··on Media Can’t Stop Presenting Horrifying Stories as ‘Uplifting’ Perseverance Porn
The reason is pretty simple to understand- Those who can afford health insurance dont want their standard of care reduced on a 'free for everyone' system. Looking at the existing bureaucratic issues the current 'free' health programs have ( VA, Medicare, Medicaid, etc.. ) seems to indicate their fears might be well placed. In the VA for instance, you can go months just to get a first visit.

Basically, people who have a job and get health insurance dont want to be lumped in with the commoners and get worse care/longer wait times/less options/etc... Its fucked up, but its not hard to understand the pushback. They dont want their health care experience to turn into a 6 hour trip to the DMV.

ds··on Amateur radio digital communications 44.0.0.0/8 partial sell-off
Would be interesting to know the salary of the board will be in the future. It looks and smells like a cash grab to benefit those at the top with cushy jobs to be a pseudo VC under the guide of giving "grants".

If they were being honest with themselves, they would donate the entirety to the EFF instead of this bullshit maneuver.

Just to add, even if they dont get a salary at all (I would be shocked), the responsible thing for them to do would be to give the money away to the EFF or another org who knows how to best put the money to use.

The idea we are entrusting a group thats financial statement going back the past few years show just 5k-10k in assets with a 100 million dollar windfall is insane. If they dont fuck it all up within the first 6 months I will be shocked. More likely though will be some lawsuits which delays any use of the funds.

ds··on HBO's Chernobyl may yet become the highest rated TV Show ever
Its good, but I think its easier to be good for 6 episodes than it is for multiple seasons. Even if you disregard that- Is it better than Band of Brothers?
← PreviousPage 3 of 4Next →