HNHacker News
TopNewBestAskShowJobs

jakejarvis

1,098 karma · joined May 6, 2008

https://jarv.is/

jake (at) jarv.is

[ my public key: https://keybase.io/jakejarvis; my proof: https://keybase.io/jakejarvis/sigs/VssoQRISbhOAElwEbfmqpseJJlReccc3cjwhhBS1k_s ]

openpgp4fpr:3BC6E5776BF379D36F6714802B0C9CF251E69A39

submissionscomments
jakejarvis··on Show HN: Lnk – Git-native dotfiles manager
Acquired by Zoom (yes, that Zoom) and left to rot. A huge loss for the internet IMO. :(
jakejarvis··on Three areas where Google Search lags behind competitors: code, cooking, travel
I've noticed the same, and it's an incredibly hard habit to break!
jakejarvis··on Apple’s privacy changes hurt Snap and Facebook but benefited Google
I believe a big chunk (the majority?) of this comes from a fairly simple deal to set Google as the default search engine in Safari. Facebook doesn't have something similar to leverage, that I can think of at least.

https://9to5mac.com/2021/08/25/analysts-google-to-pay-apple-...

jakejarvis··on Travis CI Leaked Secure Environment Variables
They posted this insanely embarrassing "security bulletin" yesterday as well: https://blog.travis-ci.com/2021-09-13-bulletin

> As a reminder from the Support Team, cycling your secrets is something that all users should do on a regular basis per your company’s security process. If you are unsure how to do this please contact Support and we would be happy to help you.

...and that's it. That's the full "bulletin."

jakejarvis··on Slack is down
root / hunter2
jakejarvis··on How HN crushed David Walsh's blog
Since the post mentions already relying on Cloudflare for help with traffic, I enabled Cloudflare's new Automatic Platform Optimization [0] on a client's website as a test last week. Thought it would be another overhyped WP caching solution but it truly feels magical. I believe it's powered by CF Workers and stores the pure HTML in KV on the backend, but all of that is handled for you and automagically updated/purged by the plugin on any site change.

Highly recommend trying it. I'm seeing the vast majority of visits now are not hitting the origin server at all — for assets or the page itself. At least it's a good stopgap until we can convince everyone to move 100% static...one can dream, right?

[0] https://blog.cloudflare.com/automatic-platform-optimizations...

jakejarvis··on HomePod Mini
Binged Schitt’s Creek over the last few weeks and David shouting “Alexis!” triggered all of my Sonos speakers. Every. Single. Time.
jakejarvis··on Spamtoberfest
> it's enough to file a Pull Request, not needing for it to be accepted

This part never made any sense to me. Such an easy fix to make.

jakejarvis··on Say goodbye to hold music
Huh? Google already controls the entirety of the Phone app — if you're convinced they want to eavesdrop on your calls, they certainly don't need you to enable this feature to do so.

Also, the post states this is done completely on-device and links to a page with significant details on this: https://support.google.com/phoneapp/answer/10104618

jakejarvis··on The High Privacy Cost of a “Free” Website
Commento is super easy to self-host with Docker, highly recommend it!

https://gitlab.com/commento/commento

jakejarvis··on UHS hospitals hit by reported country-wide Ryuk ransomware attack
Much of the article pulls from interesting/terrifying first-hand reports on Reddit, which are still pouring in:

> We are down in Florida. It’s a hot mess in the ER today. EMS diversion on cardiac patients because the cath lab is down.

> I work at an inpatient psych site in Philly PA. The nurses told me they asked the patients what they take for morning meds and then didn’t even distribute evening meds bc they have no record of their medications.

> We have no access to anything computer based including old labs, ekg's, or radiology studies. We have no access to our PACS radiology system. No patients died tonight in our ED but I can surely see how this could happen in large centers due to delay in patient care.

https://www.reddit.com/r/hacking/comments/j17aj1/cyberattack...

jakejarvis··on DuckDuckGo browser seemingly sends domains a user visits to DDG servers
That's my understanding of how it's worked for decades...

1. Check for <link rel="icon" ...> tag(s)

2. Check for /favicon.ico

3. ...give up?

Someone correct me if I'm wrong!

jakejarvis··on DuckDuckGo browser seemingly sends domains a user visits to DDG servers
And the iOS browser it seems: https://github.com/duckduckgo/iOS/blob/1ae03d7221180bd6791cf...
jakejarvis··on The irony of Apple homepage and Safari WebP support
Their stubbornness around WebM is even more frustrating to me, honestly.
jakejarvis··on GitHub Is Down
Or Gitea, if you want to use a fraction of the resources! I use it solely as a GitHub backup — you can mirror Git repositories from anywhere and it pulls changes on a schedule. Literally set it up this week, thank goodness.

https://gitea.io/en-us/

jakejarvis··on GitHub Is Down
Even our static assets from raw.githubusercontent.com are throwing 500s. Whatever it is, it sounds like a pretty widespread failure...
jakejarvis··on Wunderlist Is Shutting Down
What a shame. But I really appreciated (and was shocked by) how long they kept it maintained after acquisition, and I’m finding Microsoft To-Do a comfortable equivalent so far.
jakejarvis··on Upcoming changes to our CDN for GitLab.com
via https://gitlab.com/gitlab-com/gl-infra/readiness/tree/master...:

> 1. Once traffic is ensured to flow though Cloudflare, we initiate decommission of Route53.

> We would disable the transfer lock and generate an auth code.

> immediately after, we move the domain over to the Cloudflare registry

I love the overall plan but this part would worry me... The most obvious contingency plan when you're putting so many eggs into one basket is to keep a kill-switch somewhere like your domain registrar, where you can abandon ship entirely by switching nameservers in the worst of scenarios, right?

Correct me if I'm wrong but when the Cloudflare dashboard went down a few weeks (months?) ago, no sort of DNS-level changes would have been possible. (Either way, I don't think you can even set external nameservers for domains on Cloudflare Registrar yet?)

Just curious about the thinking behind this particular move and why the pros outweigh the cons of leaving the domain where it is.

jakejarvis··on Apple's New Privacy Page
Don't get me wrong, I'm impressed with the progress Apple has made in spearheading consumer privacy practices — but unfortunately, half of the benefits listed here are negated by the fact that my iCloud backups are fully unencrypted (or "encrypted" with a common key that Apple holds; same thing in my view).

So, if I want convenient nightly backups (without plugging my phone in and using the "new" Catalina apps, which I'm still convinced are just new iTunes skins), Apple — and adversaries — will still have unfettered access to all my iMessages, Maps history, photos, health records, almost everything listed here and more [0][1].

Tim Cook has claimed a fix is coming for a while now [2], but meanwhile using iCloud for its intended purpose is a huge, and largely unadvertised, gaping hole in Apple's otherwise impressive privacy promises. :(

[0] https://www.theverge.com/2016/3/2/11144588/walt-mossberg-app...

[1] https://www.cellebrite.com/en/productupdates/move-your-inves...

[2] https://www.macrumors.com/2019/02/28/eff-user-encrypted-iclo...

jakejarvis··on Teen Hacker Finds Bugs in School Software That Exposed Millions of Records
My university switched to something called Canvas (right after I graduated, of course) and it's incredibly slick, on top of it being fully OSS. Sakai is out there too — the quality isn't much better than Blackboard but at least it's free!

https://www.instructure.com/canvas/

https://www.sakailms.org/

jakejarvis··on GitHub is down
Absolutely. I'm (cautiously) optimistic that some good can come from all this downtime in that sense.
jakejarvis··on GitHub is down
I feel like this whole year has served as one big reminder of how fragile the internet really is...
jakejarvis··on The Washington Post is preparing for post-cookie ad targeting
You can also set this directly in about:config under network.http.sendRefererHeader:

  0 = never send the header
  1 = send the header only when clicking on links and similar elements
  2 = (default) send on all requests (e.g. images, links, etc.)
If you want more granular control (like sending referrers but only the root of the domain) all of the various network.http.referer flags for Firefox are listed here:

https://wiki.mozilla.org/Security/Referrer

Doesn't have a few of the features that your extension has, but it's done the trick for me!

jakejarvis··on HTTP Security Headers – A Complete Guide
Great overview.

If anyone's interested, I wrote a guide a while ago on adding these headers via Cloudflare Workers, which can be helpful if you're hosting a static site on S3, GitHub Pages, etc. where you can't add these headers directly:

https://jarv.is/notes/security-headers-cloudflare-workers/

jakejarvis··on Firefox to Warn When Saved Logins Are Found in Data Breaches
1Password uses the HIBP API too [0] which has actually saved me a few times.

The mechanics behind the v2 API (using k-anonymity with hashes [1]) are pretty interesting too. Troy has clearly put a lot of thought and time into what started as a pet project a few years ago and should be infinitely commended!

[0] https://blog.1password.com/finding-pwned-passwords-with-1pas...

[1] https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...

jakejarvis··on How to Find Hidden Cameras in Your Airbnb
Thanks for posting my weird collection!

A personal spy cam in a rental home is bad enough, but the fact that there are so many open to the world (and therefore indexed on Shodan) makes it infinitely worse.

jakejarvis··on Details of the Cloudflare outage on July 2, 2019
Absolutely agree about an external monitoring service being a necessity. I was more referring to cloudflare.com (and specifically dash.cloudflare.com) being entirely served through Cloudflare itself, or the AWS console being hosted on AWS, etc.
jakejarvis··on Details of the Cloudflare outage on July 2, 2019
Always appreciate the transparency from you and Cloudflare. :)

My main fright during this outage wasn't really the outage itself, but the fact that I couldn't log into the dashboard and simply click the orange cloud to bypass Cloudflare in the meantime. I'm assuming that this is now covered by this mitigation:

>> 6. Putting in place an emergency ability to take the Cloudflare Dashboard and API off Cloudflare's edge.

If so, and if this would have prevented the dashboard outage even during the WAF fiasco, this is a huge comfort to me. Just curious, though: how far can you really go in separating Cloudflare "the interface" from Cloudflare "the network?"

And in general, what does everyone on HN think about mission-critical companies using their own infrastructure and being their own customer? Especially when the alternative is using a competitor?

jakejarvis··on How iOS 13 redraws your eyes so you're looking at the camera
I understand why this feels creepy in our tech bubble, but I think it's worth noting how popular apps like FaceTune have become the past few years [0] [1].

I'm certainly not defending this trend and I think it's incredibly unhealthy — especially for the average teenager who's already naturally self-conscious about their appearances. But a minor eye correction will be peanuts in the eyes of this crowd (no pun intended) compared to the amount of processing that most of their Instagram and Snapchat photos go through before being uploaded.

[0] https://www.theguardian.com/media/2018/mar/09/facetune-photo...

[1] https://abcnews.go.com/GMA/Living/photo-retouching-apps-affe...

jakejarvis··on I was seven words away from being spear-phished
That was probably the easiest part of their escapade, sadly — spoofing a WiFi access point with a fake portal comes to mind. Or posing as IT and mass-emailing the university directory (which are rather easy to scrape at most universities), keyloggers on lab computers, etc. Always possible that it could have been as simple as just asking!

Out of ~20,000 students and ~10,000 staff, they only needed to get lucky once, unfortunately.

Page 1 of 3Next →