HNHacker News
TopNewBestAskShowJobs

helloworld4728

17 karma · joined October 10, 2025

submissionscomments
helloworld4728··on Apple has locked my Apple ID, and I have no recourse. A plea for help
If Apple has the ability to do this, why don’t they just brick all devices in Russia?
helloworld4728··on Bitchat for Gaza – messaging without internet
The user base size is huge. This is actively being used by tens of thousands
helloworld4728··on Bitchat for Gaza – messaging without internet
it’s not just chat over Bluetooth, the message is relayed over a mesh so you can chat with people much further than Bluetooth range.
helloworld4728··on Automated bank data analysis just leveled up
What does "TTP Plaid grade pipes" mean?
helloworld4728··on VisiCalc on the Apple II
I’ve always found it disconcerting that modern SaaS products advertise themselves as “spreadsheet replacements”. Actually, that’s the opposite of what I want.
helloworld4728··on When is it better to think without words?
A way that can be walked is not The Way

A name that can be named is not The Name

Tao is both Named and Nameless As Nameless, it is the origin of all things As Named, it is the mother of all things

A mind free of thought, merged within itself, beholds the essence of Tao

A mind filled with thought, identified with its own perceptions, beholds the mere forms of this world

helloworld4728··on How to Enter a City Like a King
Jesus and Omar bin Al Khattab entered Jerusalem like that.
helloworld4728··on Credential Stuffing
Oh boy this was a major problem at our budding fintech. Here's what DIDN't work:

1. Browser fingerprinting or ip bans. They used advanced fingerprint-shifting browsers and residential proxy ips.

2. Phone number 2FA. Significantly slowed legitimate user access but still didn't fully stop credential stuffers.

What did work:

3. rate limits and carefully tailored scripts that detected usage patterns and autobanned. Eventually they gave up on us guess wasn't worth the trouble. However I'm sure we lost a few legitimate users too in the process.

What I would try in the future:

- Passkeys as 2fa. Most browser automation platforms can't handle passkey auth inside a VM.