HNHacker News
TopNewBestAskShowJobs

h43z

477 karma · joined November 29, 2012

https://h.43z.one https://x.com/h43z
submissionscomments
h43z··on Late.sh – a command-line Clubhouse for computer people
It's just something everyone should be aware of.

It's up to you to decide if it's okay that you send a server provider (in this case late.sh) a bunch of your public keys which he could for example use to probe other servers to see if you have access to them.

Everyone has different opsec.

h43z··on Late.sh – a command-line Clubhouse for computer people
OpenSSH server is designed not to reveal whether a username exists.
h43z··on Late.sh – a command-line Clubhouse for computer people
If I have your public key I could probe a server to see if it recognizes that public key. Which would tell me information you might not want to be leaked.
h43z··on Late.sh – a command-line Clubhouse for computer people
By default SSH leaks all of the below public keys (if they exist) + all public keys in your ssh-agent to a server you connect to.

  ~/.ssh/id_ecdsa.pub
  ~/.ssh/id_ecdsa_sk.pub
  ~/.ssh/id_ed25519.pub
  ~/.ssh/id_ed25519_sk.pub
  ~/.ssh/id_xmss.pub
  ~/.ssh/id_dsa.pub
running `ssh late.sh` would do exactly that.

At the very bottom of the website they give you a command that would not leak your public keys.

`ssh-keygen -t ed25519 -f ~/.ssh/late_throwaway && ssh -o IdentitiesOnly=yes -i ~/.ssh/late_throwaway late.sh`

this would only send the late_throwaway public key

h43z··on Late.sh – a command-line Clubhouse for computer people
Reminder to be cautious about leaking public keys.

Once you leak your public key it could be used to check if another server recognizes that leaked public key.

h43z··on Statement on US government directive to suspend access to Fable 5 and Mythos 5
Today frontier models became Groypers.
h43z··on Show HN: Localhorst – Websites Hosted in the Browser
Right click, view source?
h43z··on Is Firefox Firefucked?
Firefox is really in a sad state. The politics, ideology is getting worse and the tech is still bad. Kind of crazy that they waste everyones battery and cpu https://b.43z.one/2025-02-12/

Am I the one who is crazy and nitpicking here?

h43z··on Upcoming Changes to Let's Encrypt Certificates
Did I understand that correctly that I will be able to get a certificate for an IP?
h43z··on Cloudflare Radar: AI Insights
I recently wanted to find out which company crawls the deepest. The openAI bot was the most thorough one, it followed 405 links [1].

[1] https://deep.43z.one

h43z··on Lucky 13: a look at Debian trixie
Doesn't feel like much of an explanation to me.

  # UMASK is the default umask value for pam_umask and is used by
  # useradd and newusers to set the mode of the new home directories.
  # 022 is the "historical" value in Debian for UMASK
  # 027, or even 077, could be considered better for privacy
  # There is no One True Answer here : each sysadmin must make up his/her
  # mind.
h43z··on Lucky 13: a look at Debian trixie
Can someone explain why we are still using a umask of 022 in ubuntu and debian?

Would it really be so hard to make that switch to a more privacy focused umask?

h43z··on A small change to improve browsers for keyboard navigation
The span one is the important one though as most of the modern web does not use <button> anymore.
h43z··on A small change to improve browsers for keyboard navigation
I don't see it working on firefox for buttons but on chrome. Both don't work on other html elements (div,span,..).
h43z··on A small change to improve browsers for keyboard navigation
I used to use vimium (and tried similar extensions) but it always scared me how big the codebase was for most of the popular extensions. In the end I came up with a tiny extension for just the things I need https://github.com/h43z/jkscroll
h43z··on A small change to improve browsers for keyboard navigation
This works on links and buttons in chrome. In firefox just on links. In both it doesn't work for other html elements.
h43z··on A small change to improve browsers for keyboard navigation
The links yes, but what about buttons or other html elements?
h43z··on Show HN: Stasher – Burn-after-read secrets from the CLI, no server, no trust
Do I understand this correctly that the server here is only needed to make sure the secret it's only read once?
h43z··on How to Firefox
If you want to navigate websites more with your keyboard I created a dead simple extension. All it injects is this tiny snippet into each site.

    addEventListener('keydown', event => {
      if(event.key !== 'Enter')
        return
    
      elementWithSelection = getSelection().anchorNode?.parentElement
    
      if(!elementWithSelection)
        return
    
      elementWithSelection.click()
      getSelection().empty()
    })
This allows you to use the native CTRL+f and / search basically like the ' search.

The ' search let's you "click" on links by pressing enter.

The snippet let's you do the same for the other searches too so you can navigate the modern web where often navigations and actions are behind buttons and sometimes even divs (not just links). Unfortunately you can't activate those without this little hack.

The extension will be available at https://addons.mozilla.org/en-US/firefox/addon/click-on-sele... soon (after mozilla approves).

I use this trick in a slightly bigger extension too https://github.com/h43z/jkscroll/blob/main/content-script.js...

h43z··on Complete silence is always hallucinated as "ترجمة نانسي قنقر" in Arabic
Oh it's like any other. Then just add another one!
h43z··on When root meets immutable: OpenBSD chflags vs. log tampering
Do I understand that correctly that in order for logs to rotate you have to reboot?
h43z··on Libxml2's "no security embargoes" policy
The only obstacle here appears to be the psychological issues of the maintainers themselves. I know it maybe hard to say "fuck off" but they will have to learn to say that to stop being exploited.
h43z··on Covert web-to-app tracking via localhost on Android
What does this have to do with the issue here? A website can just connect to 127.0.0.1 , no DNS needed.

I think what you are thinking of are dns rebinding attacks.

h43z··on Watt The Fox?
I use the extension on desktop without problems. I guess it depends on what websites you visit. I would disable the extension for ones that do play/stop sounds a lot.
h43z··on Watt The Fox?
Cool to hear. This should deserve to be a high priority bug. Thanks for your work on firefox.
h43z··on Why blog if nobody reads it?
Blogging is like mediation. It's primarily good for yourself. It's just a bonus if others like it.
h43z··on The Origins of Wokeness
Still can't believe we all changed our branch names from master to main.
h43z··on Show HN: Keypub.sh – OAuth for the terminal using SSH keys
Just a reminder for everyone that by default SSH leaks all of the below public keys (if they exist) + all public keys in your ssh-agent to every server you connect to.

    ~/.ssh/id_ecdsa.pub
    ~/.ssh/id_ecdsa_sk.pub
    ~/.ssh/id_ed25519.pub
    ~/.ssh/id_ed25519_sk.pub
    ~/.ssh/id_xmss.pub
    ~/.ssh/id_dsa.pub
Your "leaked" public keys can be used to check if a certain server recognizes that key.
h43z··on What Is Vim?
My ode to why speed even matters https://h.43z.one/vimsteps/0
h43z··on Show HN: Magic-cli – A copilot for your command line
I've never seen this extra measure "curl --proto '=https' ..."
Page 1 of 4Next →