HNHacker News
TopNewBestAskShowJobs

f2n

875 karma · joined December 10, 2017

submissionscomments
f2n··on Content moderation became an industrial process
Well yes but if you use their trash mobile site then the lack of NSFW content is the least of your concerns.
f2n··on Content moderation became an industrial process
What's wrong with marking content NSFW? Its not censoring it, simply providing a warning to those who may be in a place where their screen is visible and that might not be appropriate.
f2n··on How the modern containerization trend is exploited by attackers
>I'm not familiar with monero, but aren't all transactions in cryptocurrency public and permanent?

Not with monero (and possibly other cryptocurrencies)

f2n··on Tor: 1100 relays still run end-of-life tor versions
I had the Tor Project's repos added, but I guess no auto updates.
f2n··on Tor: 1100 relays still run end-of-life tor versions
Thanks for posting, turns out one of these was mine. I forgot that it existed. 1213 days of uptime, still running Debian Wheezy (don't worry, i'm bringing it up to date now)
f2n··on Amazon device recorded private conversation, sent it out to random contact
No, it would get customers used to ignoring the LEDs on it.
f2n··on Another flaw in Signal desktop app leaks chats in plaintext
> It wont let you vefiry by entering a code

That's odd because I've absolutely verified numerous Signal clients by entering a code, without granting access to my SMS (I use Google Voice so my SMS database is basically empty except for random spam from my shitty carrier)

f2n··on Evolving Chrome's security indicators
Do you have a source for that? I assumed the lessons learned from SPDY and QUIC eventually went into HTTP 2
f2n··on Browser extension that strips Google Analytics tokens from URL query strings
I used to use something called UTM Mangler that would replace the referral links with shock sites. I felt that was much better than simply removing them.

Here's the github, it looks like the chrome extension linked in the README is no longer there: https://github.com/huntwelch/UTM-Mangler

f2n··on WHOIS blackout period likely starting in May
I don't understand how any of those are remotely related to whois being removed. It's not like it represented anyone that could feasibly be sued before, just a whoisguard service, usually
f2n··on Al Jazeera open-sources InterviewJS, turns interviews into interactive chats
Also using Firefox 60, demo is a blank page.
f2n··on Remote zero-click JavaScript code execution on Signal desktop
You've linked that thread a couple of times here, never really elaborating on the nature of your concerns, nor do you elaborate on the specific nature of your concerns in the ticket. Have you considered elaborating on the nature of your concerns? Is there a specific vulnerability in chromium you feel could be exploited here?
f2n··on Remote zero-click JavaScript code execution on Signal desktop
So let's say I'm able to run HTML in Signal Desktop. How do I include an arbitrary script without getting the user to download the script first?
f2n··on Remote zero-click JavaScript code execution on Signal desktop
It'll be interesting to see how this works, given that the Signal Desktop client's main page (background.html) includes a CSP that restricts it from running inline or external scripts. It can only run JS that's already in the Signal Desktop package (in theory).

The fact that this isn't being described as an issue with CSPs or electron makes me wonder how it could possibly work.

f2n··on The future of AutoCAD
My traffic is coming from a Digital Ocean NYC, in the US
f2n··on The future of AutoCAD
The owner of this website (through-the-interface.typepad.com) has banned your IP address

Whelp, I guess I didn't care that much.

f2n··on GitHub Checks API
These look really nifty. I'm hoping GitLab will add similar. I particularly like that the build can be failed due to a specific line. I've noticed that all of the CI output can be confusing for some, and it becomes difficult to suss out the specific error messages amid all the other output.
f2n··on Say yes to the progressive web
The only API they don't support that I know of that somewhat bothers me is that notifications can't have buttons or actions. The bugzilla issue[0] has been sitting without much updates for a while.

[0] https://bugzilla.mozilla.org/show_bug.cgi?id=1190681

f2n··on Say yes to the progressive web
Native apps have led to slow, bloatware-, spyware-, and malware-infested mobile devices. The browser is a much better sandbox, giving much less permissions to the untrusted code.
f2n··on Hijack of Amazon’s domain service used to reroute web traffic for two hours
It does not help for that scenario, but it forces the attackers to jump through another hoop, and publish that a new cert was issued for the domain.
f2n··on Hijack of Amazon’s domain service used to reroute web traffic for two hours
>HSTS wouldn't help users clicking through warning

Actually it would have! Chrome and possible other browsers do not allow clicking throw certificate validation issues on sites with HSTS. For example, try to get to https://badssl.finn.io in Chrome.

f2n··on Using USB-VGA dongles as SDR transmitter
...yes, as I said, as long as you aren't fucking shit up for others. I thought I was very clear about that.
f2n··on Using USB-VGA dongles as SDR transmitter
They will say that, despite it having no bearing in reality. The only time the FCC cares is if you're fucking shit up for others.
f2n··on Show HN: IP Geolocation and Threat Data API
Why is is_anonymous = true for a tor relay? Why are relays and exit nodes given the same flag? As a tor relay operator, I anticipate this being misused, like so many before it, to arbitrarily block all tor relays by people who don't know or care how tor works.
f2n··on Random Darknet Shopper: A Live Mail Art Piece
At least they used the correct numbers of w's in the URL.
f2n··on Dissident.ai
"Tech is the center of our modern lives. But it's broken."

on a page that doesn't properly render without running Javascript from 2 third-party services. There are also multiple third party javascript includes explicitly for surveillance/metrics. I agree that the system is broken but I don't trust these clowns to help

f2n··on Vodafone.pt is rewriting CSP headers to whitelist Vodafone and jQuery
I don't think anyone is arguing this is particularly worse than any other MITM performed by ISPs against their users.
f2n··on The dots do matter: how to scam a Gmail user
Try using an email address with .wedding or .solutions TLD. Loads of absolutely brain-dead sites refuse to allow them, sometimes they validate by TLD length (all TLDs are 2 or 3 characters, apparently) or other times rejection TLDs they haven't whitelisted.
f2n··on Portland Anarchist Road Care Fixes Potholes Anonymously (2017)
Or have the law changed.
f2n··on 1.1.1.1: Fast, privacy-first consumer DNS service
Call your ISP and ask them why they're blocking access to some websites. Ask them if there are any other websites they're blocking. Tweet about it. Etc
Page 1 of 4Next →