HNHacker News
TopNewBestAskShowJobs

f2n

875 karma · joined December 10, 2017

submissionscomments
f2n··on What Is Going to Happen With Whois?
Thank god. I get somewhere between 2 and 10 spam emails to my dedicated whois address every day. Requiring the publication of email addresses with every domain is absurd and serves no purpose.
f2n··on TDLib – Build Your Own Telegram Client
I'd imagine I would have thought the same thing before I actively used a messaging tool that supports message editing (I use Slack for work)

Further, the goal of Signal is not to work well for people who are accustomed to the various quirks of text-based communications that have existed since forever, but to provide a secure, modern communication client that normies don't find difficult to use. Message editing has become a standard feature of any usable modern messaging client.

f2n··on TDLib – Build Your Own Telegram Client
Because one is human and one mistypes...

I'm normally on the Signal side of this argument, Telegram is trash and should not be used, but basic features like message editing are legitimate requests. I use Signal heavily and a number of times a day at least I or someone I'm chatting with corrects a previous poorly phrased or incorrectly typed messages. Because Signal has no mechanism for that, it usually involves retyping most of the message or the relevant word and adding an asterisk. I believe if Signal had built-in message editing support it would be used far more than I currently see corrections.

To be clear, I would expect Signal to allow me to see previous versions of a message and clearly indicate that it's been changed, but message editing is a valid feature that Signal should absolutely implement.

f2n··on Tinder's lack of encryption allows spying
If the details in the post are correct, a tool like driftnet[0] should make abusing this pretty easy. Go forth and do bad things

[0] http://www.ex-parrot.com/~chris/driftnet/

f2n··on Tinder's lack of encryption allows spying
Because if shit like this gets magically patched and no one gets hurt, most people will continue to not care and groups like Tindr can continue to be lazy and do shit like this.
f2n··on “Get Out of Jail Free” Cards in New York
1. Okay so print out a bunch for your locality

2. How much validation of signature is there? Do other police officers memorize each others signatures? That seems unlikely

3. I'm sure it'd be pretty easy to get a list of a large number of police officers for any given locality.

f2n··on Private landowners blocking access to public lands in the American West
Definitely do that too
f2n··on Private landowners blocking access to public lands in the American West
Sounds like a great opportunity for some IRL trollin. Get it on film + name and shame the venue.
f2n··on “Get Out of Jail Free” Cards in New York
The picture doesn't make it look too difficult to reproduce, why don't you just print a bunch of cards? That was my first thought upon seeing these.
f2n··on Blizzard games were vulnerable to DNS rebinding attack
It says Authorization, but this is really more of an anti-CSRF token, not an actual authorization credential, and anti-CSRF tokens are completely legitimate to return over an unauthenticated HTTP endpoint.
f2n··on [dead]
Well, the two undocumented blocked ports that I've found are ports 25 and port 587, for sending mail. They claim that this is how they control spam problems. But I can't really take them seriously after spending hours debugging this, only to find they're doing it on purpose.
f2n··on [dead]
Pretty sure they still just give out a /128, and also silently drop outbound TCP connections on some ports over IPv6 (without documenting it)
f2n··on [dead]
I've been comparing DO and Linode, and quickly finding out that Linode is missing things that are super handy for automated infrastructure building like a metadata service and userdata required for cloudinit. Does vultr offer such options?

EDIT: Got to a desktop machine and poked around their site for a few minutes, they appear to offer metadata support (https://www.vultr.com/metadata/) but I don't see anything for user data, which is unfortunate and seems really easy to add.

EDIT2: I can't find specific documentation on how to access the user data but they have a page on cloud-init which makes reference to such an option (https://www.vultr.com/docs/getting-started-with-cloud-init)

f2n··on Jitsi: Open-Source Video Conferencing
What does "supports jitsi" mean? Jitsi is an XMPP client, last I checked, are you just saying Matrix supports XMPP?
f2n··on A Security Issue in Intel’s Active Management Technology
I think what you're missing is that if you don't use AMT, all of the other boot security built into the system can be bypassed. Presumably this is important because if you don't want to use AMT you probably would assume that it's secure by default, but it turns out it's not.
f2n··on WDMyCloud Multiple Vulnerabilities
Quite the opposite, actually: Everyone should expect to be backdoored by proprietary products if they use them, and take appropriate security measures.
f2n··on GitMask – Develop Anonymously
>First, open source doesn't start and end with GitHub.

I didn't mean to imply it is, but if an open source project finds it easier to use one platform (such as github), trying to subvert that by emailing patches sounds like a very annoying thing to do. It seems similar to submitting pull requests to the Linux Kernel on GitHub, which explicitly requests that you submit patches on the mailing list.

f2n··on GitMask – Develop Anonymously
>If you have an account and you're participating in a project in any way through github.com, you're part of its social network.

What part of GitHub does this person have a problem with? It's entirely unclear what they mean by social network. Is that like, showing the commits you make on your profile? Having a page that shows what you've worked on at all? This seems like good ways to be difficult to work with in open source projects for zero benefit.

f2n··on GitMask – Develop Anonymously
I wonder how long that will last until GitHub bans them for (presumably) massive amount of spam. The fact that it's PRs only, not just issues, makes it a bit harder, but I can't imagine it'd be that hard to abuse
f2n··on Announcing the OpenWrt/LEDE merge
I was unaware of the SSDP component of that project, but it seems to require having the Physical Web app installed. Their BTLE beacons work on Android devices without anything special installed on the client. Maybe the SSDP does work on stock android but just takes a bit? This doesn't work if the client has to have a specific app installed to receive it.
f2n··on Facebook, Google Ask for Time to Comply with Seattle's Election Transparency Law
The original title, "Facebook and Google Say They Need More Time to Comply with Seattle’s Election Transparency Law", is longer than HN will let me submit but IMO the removal of the word "more" is important. Not sure if the mods can go over the character cap, but if so please do for this.
f2n··on Ask HN: What to do about my parent's Internet?
>most residential broad band contract prohibit sharing of service in that way

Or just ignore that and don't tell them. as long as you're not doing this as a business or at large scale I couldn't possibly imagine they would notice.

f2n··on MedleyText
So a closed source electron app? No thanks...
f2n··on Senators blast DHS facial scanning at airports
Sure, but there's no legal requirement for them to notify me that such behavior is occurring. And in the case of this article, it's not exactly something you have the option not to participate in. I guess my point is that is should be be seen an an acceptable or reasonable or non-invasive thing.
f2n··on Senators blast DHS facial scanning at airports
Invasive facial recognition in physical places seems to be the future. A nightclub I walk by on my way to work has a sign up outside stating that they're operating facial recognition cameras. At least they disclose it, I suspect many more places aren't. We need legal recourse against this sort of invasive spying by both private and public parties.
f2n··on Buy, sell, send and receive Bitcoin Cash on Coinbase
Per their twitter, "Coinbase employees have been prohibited from trading in Bitcoin Cash for several weeks."

https://twitter.com/coinbase/status/943290391419174912

f2n··on Consumers are frustrated by endless streaming services
Okay, ignore the people saying bittorrent isn't illegal: Who cares that it's illegal?
f2n··on Consumers are frustrated by endless streaming services
Meanwhile, bittorrent is completely free and requires absolutely no subscription.
f2n··on HTTPS on Your Landing Page Is Important
The people doing random things with fake .dev domains were going to get bit in the ass one way or another. You can't just make up your own domain and hope no one ever does anything conflicting with it.
f2n··on HTTPS on Your Landing Page Is Important
It's moving that direction. As it stands, any website can opt-in to this behavior for future visitors with HSTS[0], or even for first time visitors with HSTS preload[1]. And Google has been doing HSTS preload on their .google TLD for several years, and recently rolled it out to their .foo and .dev [2] TLDs

[0] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security

[1] https://hstspreload.org/

[2] https://security.googleblog.com/2017/09/broadening-hsts-to-s...

← PreviousPage 3 of 4Next →