HNHacker News
TopNewBestAskShowJobs

ebfe1

258 karma · joined December 27, 2019

submissionscomments
ebfe1··on Show HN: Linkidex – save and sort the URLs you care about
I did something similar for personal use with cloudflareworker that would trigger and send it to a personal slack (probable not the best storage but works for now). The best part i found was I learnt Progressive Web App to be able to "install" it to phone and let you hit the share button to ship the url to my worker and it would take care of it for me. Not sure if OP already have it in the app but i find that to be very useful
ebfe1··on Run SQL on CSV, Parquet, JSON, Arrow, Unix Pipes and Google Sheet
we need more shameless plug on this thread ... the more benchmark, the better! I think this would be a fun weekend afternoon :)
ebfe1··on Run SQL on CSV, Parquet, JSON, Arrow, Unix Pipes and Google Sheet
This is cool...Totally reminded me about several tools pop up on HN every now and then in the past for similar task so i did a quick search:

clickhouse-local - https://news.ycombinator.com/item?id=22457767

q - https://news.ycombinator.com/item?id=27423276

textql - https://news.ycombinator.com/item?id=16781294

simpql- https://news.ycombinator.com/item?id=25791207

We need a benchmark i think..;)

ebfe1··on Namecheap CEO offers $10k bounty for changing someone else's domain via helpdesk
love the bounty proposal but may I suggest creating a bounty target specifically for this and share it with everyone so whitehat folks can have a crack at it without raising concerns about hacking customers accounts? :)
ebfe1··on Ask HN: What are your thought about emoji on work slack messages?
Aye!
ebfe1··on Ask HN: What are your thought about emoji on work slack messages?
Agree... I'm blessed that my company is remote first and people are super chill but I guess my worry comes from a sudden realisation when I looked back at my chat and felt somewhat embarrassed for excessive use of emoji... I'm sure even if someone finds it annoying, they won't complain, hence the random question ^^;;
ebfe1··on Ask HN: Can I see your scripts?
Sure - You can find my script here https://gist.github.com/santrancisco/9d14e0105316cfa15f98f0f...

After that, it's just the matter of putting a crontab job to run archive job every night. Note that i have no way yet to know when the mouse move in macosx as xdotool no longer work with mac so right now it takes screenshot of every monitor and resize it down... it might be too much and could eat up your HDD. i like the nix version since I did a dirty job with mouse location so whenever i take a break from incident or walk away from my desk, the screenshot script stops.

ebfe1··on Ask HN: Can I see your scripts?
Since everyone here like scripting, May I suggest, if you have not used it already, checkout Xbar (https://xbarapp.com/) for Mac and Argos (https://argos-scripts.github.io/) for Linux.

I have used these 2 on my machines for the last 4 years and writing tons of script for myself, here are a few:

- Displaying internet/internal ip and allow me to click it to put in clipboard

- taskwarrior

- Simple conversion script that take my clipboard & encode/decode in base64, hex, url encoding, convert epoch to UTC,

- "auto type" my clipboard by simulating keystrokes- particular useful for pasting text into terminal that disable clipboard

- An incident response switch that would trigger a script to take screenshot every 5 seconds when my mouse moves, reduce image quality and save it to a folder in my homedrive. Another script will GPG encrypt it at the end of the day so i can go back and get screenshot or look back at incident if needed.

ebfe1··on Take more screenshots
I love taking screenshots and even wrote a script a while back to take screenshot when there is mouse movement periodically when handling incidents, i also have crontab job to compress and gpg encrypt the folder with my key at the end of the day if it's not empty. This, together with another script to record all terminal activities during incident helped me a lot of time in the past when writing up post incident write-up after many late nights!

Unfortunately i only see the old version here with flameshot taking screenshot at full resolution.. my few later versions turn screenshot to black and white and applied a few imagemagick tweaks to make screenshot file incredibly smaller to store but you get the idea :): https://gist.github.com/santrancisco/9d14e0105316cfa15f98f0f...

ebfe1··on Moving to zsh (2019)
A more sneaky use case is for reverse shell payload when you have code execution :)
ebfe1··on Ask HN: Can I see your cheatsheet?
As for me, I put together some spaghetti bash functions for taking note while using the terminal (eg run tnote function will let me select one of the last 10 commands, type a description of what it does and move on with my day...i can come back later and sort it out into my notes)...

I then write another small bash script that use consolemd and surge(probably will move to github page at some point) to generate a simple webpage with simple markdown JavaScript library to serve it up along with all the files generated by consolemd so i can use curl in terminal and have it colorfully displayed.

The cheatsheet site is here https://ch.ebfe.pw/.

And you can try it in terminal: curl https://ch.ebfe.pw/intel/splunk

And my code can be found here if you are interested:

https://github.com/santrancisco/cheat

ebfe1··on PyPI: Python packets steal AWS keys from users
This is also why I like to put honey credentials everywhere, including in my .aws/credentials... You will never know when it might save you XD If you cant be bother with setting up cloudtrail+metric alert, canarytokens peeps can generate one for you ;)

https://canarytokens.org/generate#

Like any other tools though, i recommend to have a script to trigger it every now and then to make sure it works (and alert you about it so you dont go into panic mode)... for personal stuff, I usually have a specific day in the month i expect to see some canary tokens fire :)

ebfe1··on This may be how your number is exposed for phishing
Thanks, Perhaps I was paranoid but I have had several users reported to me "I have never shared my phone numbers with Linkedin or on social media". The data is very current afaik since I have had users who only recently joined getting CEO gift card sms.
ebfe1··on This may be how your number is exposed for phishing
Hi all, A while back I had to deal with some sms phishing sent pretending to be our CEO. Many people received the text said they never exposed their mobile phone on linkedin or social sites, I went on a hunt and stumbled across this website which basically had everyone email+ phone number. There were also clues from the phisher that he may have gotten information from here as he made mistakes on CEO name (the site still listed the wrong name) or company name that was sighted in the site (one word instead of 2 ...)

I wonder how/where they got this data? Did some third party phone app(messenger, whatsapp) dump our contact list somewhere and map those information out? This site is cheap to sign up for an account and it's a sweet honey pot for mass sending CEO phishing campaign.

ebfe1··on ffsend: A fully featured Firefox Send command line client
Oh wow! I didn't know this reply got so much like, thank you! Sendlight.ml looks awesome and on that note, to make things easy to share between devices, i made a simple "tunnel" mode as well, you can try it here: https://www.relaysecret.com/tunnel

The way it works is super simple: the anchortag is base on the tunnel name (first round of sha256 if my memory serves me well) and the actual "tunnel id" is a few first characters of the second round of sha256. This way by enter the same "tunnel" both devices can share file without the need to share long complicated urls. The files in tunnel only lives up to a day.

Unlike sendlight though, it is not peer2peer webrtc and it is using the same lambda backend to create signed urls for s3 and encryption done in browser like before, just a neat little trick to have a simple way to setup "room" between devices ;)

ebfe1··on ffsend: A fully featured Firefox Send command line client
100% this but note that the user entered password is not included in the anchor tag so if you add a password, recipient still needs to enter the password to be able to decrypy and download ;)
ebfe1··on ffsend: A fully featured Firefox Send command line client
Aha that is a great question! There are 2 parts of the key, one is the anchor tag key (the part behind # that you see in download url) and your password. The anchor tag key part is ALWAYS generated randomly in the browser so that your file will be encrypted no matter what even if you forget to enter password and hit upload.

Note that the anchor tag part does not leave the browser so it is one of the clever thing firefox send used to share some id/key. You can double check it in the network tab ;) If you are worry about that key being leaked somehow, adding a password ontop is a good measure.

ebfe1··on ffsend: A fully featured Firefox Send command line client
If anyone is interested, after firefox send shutdown, i wrote https://www.relaysecret.com, its footprint is extremely small (1 lambda function that does all signing for s3 upload/download, simple frontend code that does encryption in browser using web crypto api with no 3rd party Js, no 3rd party css, no tracking. Anchor tag is used for additional random key material (so it wont leave ya browser and files will always be encrypted regardless).

You can roll your own too with the terraform code in it. It costs me barely anything (never go over free tier limit) to run it because files never live more than 10 days (there is a catchall lifecycle rule on the bucket) and when users select durations, i also put them in bucket prefix that has lifecycle rule place on objects under them for that duration. Note that we can't rely on lifecycle rule all the time so i also make sure when lambda is called to access the object, it checks the time-stamp, the duration and if it is meant to expire and not yet cleaned up by s3 - lambda function deletes it.

I learnt a ton of cool things about s3 after this neat little project and really dig the API, the lifecycle rule, signing url etc...

Ps: for these type of tool, you should definitely mitm it to see if plaintext file or password ever leave the browser... Relaysecret does leave one item unencrypted and that is the file name. You can change it upon upload but i like to leave it there so people know what they are downloading. I have simple idea of encrypting that with just the anchor key but haven't gotten around to put that in yet.

ebfe1··on Show HN: Tasqueue – A simple, customisable distributed job/worker in Go
Noice! I am keen to give this a go.. the broker code are small and seems easy enough to implement for different backends.

having a quick glance, it does remind me a lot of que-go (https://github.com/bgentry/que-go) that is inspired by similar project written in ruby which use postgresql lock cleverly to take tasks from queue, work on it and release lock.

I liked the implementation so much and how easy it was to write worker for it, i ended up modifying it to use go channel (https://github.com/santrancisco/cque) as queue for worker task.. i used it in several personal projects over the years for cli tools that can leverage from having async tasks/jobs handle by workers.

ebfe1··on Terraform vs. AWS CloudFormation
Personally I like to use both and for specific jobs.

For example, when we have tools that need to be deployed across 10+ AWS accounts managed by different Ops team, I hand them a CloudFormation template and they could run it, plug in the right parameters, pulling lambda code from the same S3 bucket we have etc... Totally agree with Writing Cloudformation is a pain but when you have it done once, it works consistently and we don't have to worry about terraform version, the tfstate etc... It just works.

I use terraform for more complicated setup, an environment that we keep adding ontop, share & manage among our team and need rebuild/redeploy often/quickly or an environment we need to spin up for various tasks (eg incident handling VPC, interview challenges, CTF events...) ... Terraform and its powerful reusable terraform modules/module registry make spinning up these environments in minutes make it extremely attractive.

Managing terraform version and tfstate is still a pain with terraform even with the help of remote S3 bucket & dynamodb lock but it is definitely better than when i first started and we had gpg encrypted tfstate.

With that said, I work in security and only very occasionally I need a big deployment like scalable spark cluster or multi-zone elasticsearch cluster etc... so perhaps I don't have enough indepth knowledge about each tools.

ebfe1··on MDcat – Simple Markdown to GitHub styled HTML converter
Not sure what you meant with gpu terminal emulator but i use consolemd https://github.com/kneufeld/consolemd to render markdown for terminal and it works really well.. i even built my cheatsheet site with it using simple bashscript (eg: curl https://ch.ebfe.pw/nix/xargs)
ebfe1··on No one likes ads. So let’s do something about it
I had an idea about making an advertising not-for-profit company... Ads aren't going anywhere so why not using it to save the planet or make people lives better... Drop the tracking, drop the click counts, perhaps targeting local news websites, display ads relevant to content they are reading base off referrer url content is probably a good start, promote somethingnlike #greenads mmovement on twitter, tiktok , get companies to advertise on the platform, more local news site to adopt it, transparency about profit + open about salary for staffs and shove the rest of money into charitable causes...

I'm sure there are plenty of flaws here but perhaps having Ads for good causes will at least make it more pleasant to the eyes than the current state...

ebfe1··on For sleep apnea, a mouth guard may be a good alternative to CPAP
After having sleep study done and bought an airsense 10 with the latest nasal pillow (very very comfortable, i slept like a log the first day I used it). Initially, I felt somewhat different/better but it was not totally obvious until i slept over at cousin's house without the machine and felt wrecked the next day. I then realised my coffee intake was half of what i usually have and I don't yawn during the day as much!
ebfe1··on Zenreader: A 4.7" E-Ink RSS Reader
Ohh I am 100% agree with this! sorry if I missed the LAN part in the original post. :Facepalm:
ebfe1··on Zenreader: A 4.7" E-Ink RSS Reader
Thanks for sharing the code mate. May i also suggest adding a token/password if you want to reduce attack surface. Also from a quick glance, this looks like it is vulnerable to ssrf style attack. This type of service is often vulnerable to it given the nature of it is fetching url on user's behalf. I would suggest either isolate it, have a whitelist of domains that you trust or having iptables to deny internal access.

Nice work regardless!

ebfe1··on The Nokia N900: the future that wasn’t
Had my N900 when it first came out and to this day it is still my most favourite device! I kept it for a long time as 2nd device, I had pwnphone on it for a ages and showed off to friends how i could Deauth all their wifi devices, run kismet, even crack WEP, turn off their TV with tvbgone app using infrared...
ebfe1··on Show HN: Doppler Share – Share one-off secrets with end-to-end encryption
My main concern with this or saltify.io is that when viewing network tab traffic in the browser, you can see the secret and the password are being sent back to their server. While we trust that our data are stored in encrypted form and the password+secret is only used in memory of serverside code to decrypt/encrypt, I would much prefer all of those operations being all done in the browser.
ebfe1··on Show HN: Doppler Share – Share one-off secrets with end-to-end encryption
Cool app! Doppler looks great but i have a tiny concern about the Bugsnag 3rd party script. Unless Doppler own Bugsnag, i think for a sensitive tool like secret sharing, you should remove it.

Shameless plug: I made a similar tool base off another project after FirefoxSend shuts down but deploy on AWS instead of GCP :) It is hosted here if anyone wanna take a look or roll their own https://www.relaysecret.com/. The design philosophy is the same (everything is encrypted on clientside, no plaintext or password leave clients browser, minimal backend).

ebfe1··on All DuckDuckGo bang operators on one page
Hi jchook, i would love to play with it and might try to port it to cloudflare worker for personal use :) I was thinking of exact same thing before bed last night when someone at work commented on how much revenue from Ad Google loses from "Im feeling lucky" feature which bypass all Ads
ebfe1··on Update on Firefox Send and Firefox Notes
If you want a minimal setup that does similar job with all encryption done in browser and absolute no plaintext, password send back to server, i just wrote https://www.relaysecret.com earlier this week. It is opensource, with minimal footprint on aws (1lambda, 1 gateway, 1 s3), deploy using terraform and should be very cheap to run. It's a pet project so i limit the filesize to 30mb but you can change that easily if you roll your own. :)
← PreviousPage 3 of 4Next →