HNHacker News
TopNewBestAskShowJobs

internalthief

8 karma · joined February 21, 2020

Work at an autonomous vehicle company on offensive security, breaking in and stealing all the things.
submissionscomments
internalthief··on textfiles.com
> Wetting the filter gives you a more "accurate" result, but you'll get a consistent cup of coffee either way if you commit to either always wetting it or not doing so.

The big difference that wetting a filter has is that certain filters have a slight taste associated with them. If you wet the filter first and throw that water away you get a cleaner/brighter cup without the paper filter adulterants.

internalthief··on Keys.pub – Manage cryptographic keys and user identities
Teams + git repositories for secrets is great too.

Makes it less likely that our secrets end up on Github where if Github were hacked, or an web account was hacked that our secrets become public.

internalthief··on As more of them die, grocery workers increasingly fear showing up at work
I live in an apartment complex, and my mailbox doesn't have a slot in it.

All of the junk mail I've received has come via the USPS, however since this all started happening I have received almost none.

The drop-off of junk mail delivery has been both welcome, and a sign of troubles for the USPS.

internalthief··on Bank of America: 58,000 small businesses ask for $6B in loans since 9 a.m
One of my favorite bagel shops is barely making payroll during this shutdown, and only because they are heavily innovating how they keep customers.

They are now offering meal kits, so you get a meal for two to four people in one easy go, they started shipping via USPS, and they are doing local deliveries. They make their own in-house butter, cheese and cream cheese so their kits do fairly well.

They are also increasing what other items they are selling, such as adding bread to their lineup. Which is absolutely fantastic.

But it's still hard for them, with the reduction in people coming in and sitting around they don't get people buying a bunch of coffee or having breakfast and then lunch while chatting. They have had to furlough some of their staff, and I really hope they make it through, because another favorite restaurant of mine is going under, they simply can't afford to keep going, even with a loan that would help pay salaries, there are other contracts and payables due that simply can't be covered with enough loans... loans against what collateral?

internalthief··on I think Catalina 10.15.4 broke SSH
I've been using the Belkin Thunderbolt 3 dock for years now, and have had 0 issues with crashes.
internalthief··on Full third-party cookie blocking and more
I doubt that this is going to be an issue for applications using ReactNative or other solutions to package websites as applications.

For applications that have you add it to your home screen using the app icon, it may be more of an issue, but why wouldn't you sync that data back up to the server?

internalthief··on Little Snitch and the deprecation of kernel extensions
Yes, absolutely.
internalthief··on Linux maintains bugs: The real reason ifconfig on Linux is deprecated (2018)
I was not aware of this!
internalthief··on Linux maintains bugs: The real reason ifconfig on Linux is deprecated (2018)
It's due to Apache not correctly matching the SNI when it is sent a FQDN ending in a period (.)

More information: https://news.ycombinator.com/item?id=22632959

internalthief··on Linux maintains bugs: The real reason ifconfig on Linux is deprecated (2018)
It seems that the server running on the other end doesn't properly match the certificate from the SNI if the domain sent by the browser is a FQDN (i.e. ends in a .)

For example, try the following:

  openssl s_client -connect jdebp.uk:443 -servername "jdebp.uk."
vs

  openssl s_client -connect jdebp.uk:443 -servername "jdebp.uk"
You'll notice that in the first case the default certificate is sent back, in the second case the certificate is correctly matched against the SNI.

According to the Server header returned:

  Server: Apache/2.4.41 (cPanel) OpenSSL/1.1.1d mod_bwlimited/1.4 Phusion_Passenger/5.3.7
Testing against an NGINX based server, I am not seeing the same results, in fact I am seeing the correct certificate being returned.
internalthief··on AWS’s Elastic Load Balancer is a Strangler
It is documented, at least on this page:

https://docs.aws.amazon.com/elasticloadbalancing/latest/appl...

Right at the top of the page, underneath the header "Limits"

> The maximum size of the response JSON that the Lambda function can send is 1 MB.

internalthief··on Chrome deploys deep-linking in latest build despite privacy concerns
The article isn't wrong, by forcing scroll to a certain location and embedding for example images that only load when scrolled into view the web server can know that someone was linked to a particular section of the website with the new deep-linking feature.

This is especially the case if the browser scrolls and doesn't load all prior resources automatically because they were never "in view".