HNHacker News
TopNewBestAskShowJobs

gexcolo

156 karma · joined March 3, 2013

vc@cock.li https://vc.gg/
submissionscomments
gexcolo··on Defcon stiffs badge HW vendor, drags FW author offstage during talk
Am I missing something about how this story went missing from the front page? There is at least one story with less points posted 12 hours earlier that is still visisble there.

https://archive.is/dtRg2 https://archive.is/8HK5y https://archive.is/yk5uU

Is there any transparency that could tell us why this change was made?

gexcolo··on 36C3 Staff Assaulted Me for Political Reasons
I'm the author of this post. What people who are unaware of the layout of the congress center don't realize is that the video starts when we were leaving. The door "inside" is actually to get "outside". I was told to leave in 5 minutes, I stayed where I was maybe 2 minutes and started walking (I'm not leaving anything out, it was just more of the first audio recording), and then was prevented from leaving the event by masked thugs who pretend to be real security guards on paper.

People assume I did something to deserve this, and I can live with that. But in reality it was nothing more than the list of domain names I own. I did my best to describe that here.

gexcolo··on Why Bother with What Three Words?
Hey, weird ask, but I am going to be visiting Mongolia in 3 months with a small group of online pals. Want to be friends? My email is on my profile!
gexcolo··on How Many Computers Are in Your Computer?
im a computer computer
gexcolo··on Ask HN: Low-maintenance alternatives to Gmail?
you shouldn't trust him, he gets google alerts and finds threads on hacker news and posts wacky comments like this one
gexcolo··on How to Run Your Own Mail Server (2017)
Sure, the mail storage currently takes up 1.01TB, using dovecot's mdbox. This mail store started in January 2016, after the service got raided twice by german authorities[0] (at request of u.s. gov), otherwise it would be larger.

I'm not going to run like per-user stats but I know historically there's been about 11kb per E-mail on average, so that's about 90 million mails stored. The MTA itself sends and receives a bit over 20 million E-mails annually, so the extra from that is probably from the mailing list I run on the same server (where each message only counts as 1 for statistical purposes)

How I prevent outgoing abuse is a black box, but I do it well enough that mail from my server almost never ends up in spam. But given that it's a free service I definitely don't have the budget to warm up and dynamically scatter mail across IP space to maximize deliverability. Cool technique, though!

[0] https://archive.is/etfDM

[0] https://archive.is/etfDM

gexcolo··on How to Run Your Own Mail Server (2017)
I run an E-mail server with over 250,000 users. I started by following some generic "dovecot+postfix+mysql" tutorial on howtoforge and I'm still using mostly the same setup over 4 years later.

>Then your email doesn't work and you could be missing out on important communications

Pretty much every E-mail server will retry sending your E-mail for a long time (like 2 days is default on postfix). Once your mail server comes back up all of your E-mail you missed during the downtime will come in slowly as messages are retried

>you're scrambling to figure out how the spammers managed to exploit your setup this time

Any tutorial should point you in the right direction restricting open relay on your mail server, just basically requiring authentication to send E-mail outside of your server.

>I started writing an SMTP protocol handler in Haskell

Do you have any link to your progress? Postfix's configuration definitely shows age, but all of the options do important things that you could actually want to change. It seems other MTAs either have just as complicated configuration (to do the same things), or have stunted functionality.

>being secure and resistant to attacks by default

I agree about sensible and more secure defaults in configuration. But the application security of postfix and dovecot are both pretty robust[0][1]. Considering they are 19 and 15 years old, both applications have seen several developer-lifetimes of effort.

>we need more guides like this for us poor souls who do go down this route

I agree, though mediocre howtoforge tutorials seem to have worked fine for this poor soul.

[0] https://www.cvedetails.com/product/14794/Postfix-Postfix.htm...

[1] https://www.cvedetails.com/vendor/6485/Dovecot.html

gexcolo··on Introducing the Keybase filesystem
I use PGP every day. Who messages me, how often, and at what times, is still private information and I should have a say in where and how that happens. My PGP-encrypted conversations tend to be much more sensitive than any other medium I use.

The cryptography is almost certainly not broken. That does not mean it won't be broken in the future. I would have the same concern if my TLS-encrypted traffic was being saved. If my ISP was saving TLS traffic or my XMPP provider (the one that I don't host, anyway) was saving OTR conversations, I would be equally concerned.

Even worse, actually. TLS (usually, nowadays) and OTR both employ forward secrecy. PGP does not, at least traditionally.

gexcolo··on Introducing the Keybase filesystem
What bugs me about the direction Keybase is going is that they still have not implemented a way of disabling the ability for users to send me encrypted messages.

I do not want Keybase to hoard encrypted messages I will never be able to read because I do not want to install their application on my computer. My Github issue for this has gone largely ignored:

https://github.com/keybase/keybase-issues/issues/2808

I am thinking I am long overdue to placeholder my account until this is solved. I already have 10 encrypted messages I will never be able to read. I joined Keybase as a public key repository with external verification support, not for them to store private conversations -- encrypted or not.

gexcolo··on Operation Luigi: How I hacked my friend without her noticing
>In fact, I'm sure a simple script could cover the majority of cases

I'm sure you could get some funding to provide that as a service.

gexcolo··on Operation Luigi: How I hacked my friend without her noticing
It might not be the digest you asked for, but it's the summary we deserve: http://n-gate.com/hackernews/2017/07/31/0/
gexcolo··on Ask HN: Who wants to be hired? (March 2017)
Yes, I do: https://vc.gg/blog/so-its-been-a-while.html
gexcolo··on Introducing the Invisible reCAPTCHA
Both v1 and v2 have noscript versions. Here is what the v2 noscript version looks like:

https://vc.gg/B9zmj4hi https://vc.gg/CTskizZe

gexcolo··on Ask HN: Who wants to be hired? (March 2017)
Location: U.S. citizen living in Bucharest, Romania

Remote: Yes

Willing to relocate: If not in U.S.

Technologies: Linux (openvpn, postfix/dovecot/spamassassin, mysql, nginx), devops/automation (ansible, capistrano), security (burp, snort, nmap), Python, PHP, Bash

(many many more not listed here)

Résumé/CV: https://vc.gg/ (autoplay video), real resume by request

Email: vc@cock.li

I'm an experienced linux system administrator currently employed for a U.S. company. In my spare time I run a public E-mail provider with 132,000 users, and a VPS provider with >$1K MRR. I'm interested in positions in the security or sysadmin space, with bonus points for companies providing services that respect users' privacy, or provide a tangibly beneficial product or service as part of their business model. I'm also open to development work but only as an aside. Sysadmin first, programmer second. A sense of humor is required as my side projects aren't exactly politically correct, though I keep work and my personal ventures completely separate.

Due to my work providing privacy-oriented services, I recently had $2,000 worth of electronics seized at the U.S. border because I refused to decrypt my electronic devices. Because of this, relocating to the U.S. is not an option.

gexcolo··on I Had My Electronics Seized by U.S. Customs and Border Protection
Thanks for this information. In my example, I was departing Amsterdam for the U.S.
gexcolo··on I Had My Electronics Seized by U.S. Customs and Border Protection
I'm the author of OP's post. Can you provide me more information about this? I've always wondered if that was the case, but I was once given a lengthy interview in the Amsterdam airport on my way to DEFCON last year, which gave the opposite impression.
gexcolo··on I Had My Electronics Seized by U.S. Customs and Border Protection
This is probably because I had set up DNSSEC on my nameservers, but my registrar doesn't yet support DNSSEC for .li. I plan on moving to another registrar once the domain is closer to expiry. I guess I'll try to do something sooner than that to remove the DNSSEC entries that my nameserver is returning.
gexcolo··on I Had My Electronics Seized by U.S. Customs and Border Protection
I'm the author of the OP's post. When I left the U.S. one of the questions that I was asked (that I refused to answer) was whether I used any social media and what the accounts were. The sites that they listed as examples were Facebook and WhatsApp, which I found particularly interesting.
gexcolo··on Show HN: ClapChat – Instant messaging for HN users
Does it have an API?
gexcolo··on Ask HN: $1k+ side projecters, what was the best thing you did to market it?
It's not my E-mail. Except for the ones that are. But most of them aren't.
gexcolo··on Ask HN: $1k+ side projecters, what was the best thing you did to market it?
>are you up at night wondering if you've made a novice error and a user or someone who dislikes one of your users is rooting around in your hardware up to no good?

I dropped a database on accident yesterday because I assumed that replication was broken (it wasn't). If someone has managed to root my servers I hope they clean stuff up a bit.

>And is there any profit to be made at your current size for your revenue?

Cock.li operates not-for-profit, making it a break-even operation that operates financially separate from cockbox. Cockbox took about $2-3K of investment to get going on rented IP space, total to date I have invested about $9K on server hardware to support up to 180 "slots" (sold GB of memory aka $10MRR) and IP space to support a bit more than that (1x/24 aka 255 IPv4 addresses and a /48 IPv6). Considering ongoing expenses are hardware replacements and colocation costs, profit margins are very high.

gexcolo··on Ask HN: $1k+ side projecters, what was the best thing you did to market it?
I run https://box.cock.li/ , a VPS provider that caters to shitposters and people that kind of like that eerie feeling that your server could shut down at any moment.

I don't really have any idea what I'm doing, but I don't really know how to run a mail server either but I seem to be doing okay with https://cock.li/ (this is where most of my customers are from)

It's currently at about $2K total revenue, and once this transfer of IP space finishes I can properly scale to about $1.8K MRR.

gexcolo··on Richard Stallman's Personal Site
If memory serves me correctly, RMS doesn't actually manage his own website. He has a number of volunteers that help update the website and post political notes. Those notes are likely a message from him to his volunteers, or the volunteers reminding themselves.
gexcolo··on Cock.li server seized again by German prosecutor, service moves to Romania
"Mr. Canfield" here,

I don't know if I would say I was "trusting of authorities" but I'm definitely distrusting now. I didn't bother with FDE because I figured it was more trouble than it was worth for a server that I ultimately don't own and can't control or protect against the oodles of key recovery attacks I'd have to worry about. In the event of a seizure I don't want to be like "hey uh they might have gotten everything maybe not!" so it's just not something I bothered with.

The situation is different now though as the service is being colocated instead of hosted on a rented server, which gives me a lot more freedom what can be done to secure the server against data theft. I'm also hosting with a privacy-conscious host (FlokiNET) I know will cooperate with me and fight bullshit government requests if/when they arrive (not saying what happened with Germany is bullshit, it's yet to be seen and I've been advised not to speculate).

Data theft aside, the service is in a more secure position it's ever been in. There's comfort in that, at least...

gexcolo··on The Free Internet Project
The United Kingdom is colored Yellow, yet there is Internet censorship in the UK:

https://en.wikipedia.org/wiki/Internet_censorship_in_the_Uni...

The description mentions the ISP-controlled, opt-in "filtering" plans, but not the state-mandated no-opt-out censorship of an indeterminate number of websites (the lists are not public)

gexcolo··on [dead]
This is fake. You can read the source code of the page to see.

Can we get this removed from the front page?