HNHacker News
TopNewBestAskShowJobs

janmo

2,625 karma · joined May 4, 2020

submissionscomments
janmo··on Infosec 101 for Activists
Seems like they didn't give enough.

https://edition.cnn.com/2024/09/23/tech/telegram-ceo-durov-a...

janmo··on Huawei's Ascend 910C delivers 60% of Nvidia H100 inference performance
The H100 is sold around 25k USD, with a production cost of only around $3k USD according to estimates.

Also it is heavily export controlled meaning many countries can't get their hand on it.

So even with the 910C consuming more electricity and having lower yields there will certainly be a market for it.

janmo··on Infosec 101 for Activists
The ones that don't end up shut down, in legal trouble or in jail.

See Lavabit, Tor Mail, Telegram, EncroChat, Sky ECC and others.

janmo··on Infosec 101 for Activists
As I pointed out they also route all of their traffic through Cloudflare. They also have been caught red-handed logging the IP of an activist despite having previously advertised that they didn't keep any logs. Now they are using misleading terms such as "privacy by default" which according to them means that by default they won't log you but that they can be "forced" to log a user if a law enforcement agency asks them to do so...

Sources: https://therecord.media/protonmail-forced-to-collect-an-acti... https://x.com/andyyen/status/1884907496705339544

janmo··on Infosec 101 for Activists
This is pretty much the 101 on how to get "caught". It is laughable that they recommend using ProtonMail and ProtonVPN and that there is not a single mention of things such as TOR.

Regarding Proton specifically:

- Proton has been lying about them not logging their users IP and other information in the past. It got caught red-handed in 2021 when they transmitted the data of a user to a french intelligence agency called DGSI. Source(s): https://therecord.media/protonmail-forced-to-collect-an-acti...

- Now they say: "Privacy by default", what they mean by it that by default they do not log the user's information but if an agency asks them to log then they "are required by law" to log the user's data. But the user has no way to know if he is still in the "privacy mode" or has switched to the "surveillance mode".

- It is actually possible that they log everything and use the "by default" wording as a "plausible denial". By saying that your account had been flagged earlier by law enforcement or an intelligence agency.

- All Proton mail traffic goes through Cloudflare. Let that sink in. Yes, they says that the traffic is encrypted using https and that Cloudflare can't see it's content, which might be true. But even if it is true Cloudflare gets to see a ton of interesting meta data, such as the end user's IP, the exact time and the length of what the user is being sending or receiving. Source: So even if you are in Switzerland and you use ProtonMail which is in Switzerland too, your connection still gets tunneled through an American company. Source: https://x.com/andyyen/status/1884907496705339544

janmo··on DoubleClickjacking: A New type of web hacking technique
I tried it on a VM, it did work. [WIN + R] opens the run app down left in the left corner.

[CRTL + V] pastes a small code snippet in the run app and once [ENTER] is pressed it closes the run app and in the background downloads and executes a larger code snippet from a malicious website.

So if you press exactly what they told you to press it would install a malware on your computer. Now this typically targets people that don't even know what the run app is.

janmo··on DoubleClickjacking: A New type of web hacking technique
There is also a technique where they ask you to press: [Win + R] + [CRTL + V] + [ENTER] to verify that you are human.

This will install malware code that was put in the clipboard by using javascript.

janmo··on "Hetzner decided to cancel our account and terminate all servers"
When they receive a DMCA they will contact you and give you 24hours to reply and fix it. If you do not comply they will turn off your IP.

However this is more related to EU regulation rather than Hetzner itself.

Hosting things within the EU has become really tough.

janmo··on Show HN: It took me 5() months to build a Plausible alternative
Regarding the pricing here is what I would do:

- Unlimited and free but basic metrics are public for everyone to see (similar to what Github did before)

- Paid but priced at page view consumption, for example: 12,000 page views a month will be charges 1.20 USD, 140,000 page views a month something like 5.20 USD etc...

This is something I might be willing to subscribe to.

janmo··on The Crime Messenger
They don't need a warrant if OVH just hands it out to them which they do.

But what really matters is that intelligence agencies are sniffing in your data at OVH and that the company wants you to think otherwise.

janmo··on The Crime Messenger
The key aspect here is that both Sky ECC and Encrochat got F. over by the modern day equivalent of Crypto AG which is the french hosting provider OVH.

While intelligence agencies were pumping in real-time all the data from Encrochat's and Sky ECC;s dedicated OVH servers, the OVH co-founder Octave Klaba and their ex-CEO Michel Paulin were selling the company with statements like:

- We don't dig in our customer's data unlike the the "others".

- US secret services have no access to our data.

However there are many interesting anecdotes:

1) For many years OVH was hiding a "maintenance" backdoor in "/etc/ssh/authorized_keys2", authorized_keys2 was used for ssh protocol 2 which was depreciated in 2001 yet OVH was using it to store a maintenance key until around 2018. This was very poorly documented and a user warned of the backdoor on HN back in 2012. https://news.ycombinator.com/item?id=4839414

2) In 2013 the TOR hidden service hosting provider "Freedom hosting" was taken down, "they" had rented 400 servers at OVH and in June 2013 "they" let all but one expire, likely moving to another provider, this is when through an unknown way the FBI obtained the IP address of the only remaining server at OVH. The server was imaged but it contained an encrypted "container". The FBI claims that they were able to break the encryption within a week using "cryptanalysis" and to recover the "root" password used to encrypt these "containers". This is total BS, they must just have used the ssh maintenance key or added "something" to the server when they did the imaging.

Source criminal complaint Eric Eoin Marques: https://www.justice.gov/d9/press-releases/attachments/2019/0...

3) Later that same year Silk Road was taken down. It is undisputed that law enforcement lied about key parts in their investigation.

According to law enforcement Ross Ulbricht was ssh'ing into the Silk Road server using a "VPN server". When they got to the "VPN server" it had been wiped out BUT, the hosting provider had kept "VPN" "logs"??? which led them to the IP address of a cafe where Ross Ulbricht had been. Ross Ulbricht kept a list with all the servers he was and had been operating. There is no mention of a VPN server, however in the "retired" server section there is a "VNC Desktop" server with the note "SR related". This appears to be a server running a virtual desktop that Ross Ulbricht was using to connect to the Silk Road. It was a VPS hosted at ... OVH and rented through an intermediary called momentovps. But it gets even worse, just bellow he listed another VPS at OVH and it has the remark "Will / personal backup / deadman switch"...

Source: Silk Road Exhibit GX-264

4) The creation story is quite strange. OVH was offering very low prices while not having any funding. The secret was that for years Xavier Niel who is one of Octave Klaba's competitors and has been outed as being a former agent for the french government was hosting the OVH servers in his datacenter for FREE. Obviously if you do not pay for the electricity, internet and rent life is easy. The question is what did Xavier Niel get in return? According to him (Interview on BFMTV) he did it out of generosity. Of course...

Now we pretty much know that Pavel Durov founder of Telegram got his french passport because he agreed to work with the french intelligence agencies but failed to deliver. Guess who was the first person he called when he got arrested, and then the person he met once he was released? Xavier Niel!

janmo··on Telegram will now hand over phone number and IP for criminal suspects
In a sense the surveillance in the "west" and in particular in the EU is worse than what you have in China.

At least the Chinese they know that all their conversations are being monitored and read by the government.

In the EU many people still live under the illusion of GDPR, data privacy, democracy etc...

janmo··on Hezbollah hand-held radios detonate across Lebanon, sources say
I guess from now on they will fly it in directly from China.
janmo··on Hezbollah hand-held radios detonate across Lebanon, sources say
True, probably the NSA wanted to smear the Chinese when in fact they are the ones implanting bugs in hardware.
janmo··on Hezbollah hand-held radios detonate across Lebanon, sources say
If the mossad was able to plant explosives without being caught, I wouldn't be surprised if they also planted bugs (indiscriminately) in many electronic devices delivered to Lebanon such as TVs, computers, phones etc...

Similar to the spy chips implants within the Supermicro server motherboards.

janmo··on Hezbollah pager explosions kill several people in Lebanon
In my case they did it at the store where I came to pick it up. That's how I got aware of it.

The espionage agency in question was the french DGSI.

janmo··on Hezbollah pager explosions kill several people in Lebanon
I guess it is better to weigh it just after the purchase from a random store and from there the weight should never change.
janmo··on Hezbollah pager explosions kill several people in Lebanon
Intelligence agencies put their bugs within the hardware of electronic devices you order online.

If you believe being the target of an intelligence agency never order anything online. They will put the bug inside, especially if it is an electronic device such as a phone/laptop/TV/coffee machine.

Best solution is to go buy it from a random store and have a good home security system.

Also weigh your electronic devices laptop/phone to check if the weight differs from its original weight, it should not deviate.

janmo··on Have ‘hobby’ apps become the new social networks?
You can do both at the same time ;)
janmo··on Have ‘hobby’ apps become the new social networks?
I can really recommend HelloTalk which is a language learning app. Meetup.com also used to be a good option but not so much anymore.
janmo··on Telegram CEO breaks silence after arrest
He will likely be very careful with what he says given that he is out on bond and could be put in jail anytime.
janmo··on Telegram founder charged with wide range of crimes in France
It is even possible that Durov has saved lives by not communicating user information to the french intelligence services.

Recently have been a bunch of scandals where french intelligence officers where involved in murder plots.

- There is "Haurus", a french intelligence officer who sold personal information on the darknet, in one case he sold personal information including the address of a drug dealer. Something that is believed to have helped in his murdered by a "competitor".

- There is the murder of racing driver "Laurent Pasquali" who is presumed to have been killed by a french intelligence officer. The plot involved over 20 people with several of them being french intelligence officers. In fact they got his personal information and address to plan the murder plot through the french intelligence database.

You can Google all this, it is true.

janmo··on The Arrest of Pavel Durov Is a Reminder That Telegram Is Not Encrypted
The title is not correct IMO, it is not "end-to-end encrypted" by default.

But the traffic between you and the Telegram server is always encrypted and the "end-to-end encryption" can be enabled.

janmo··on Telegram founder Pavel Durov arrested at French airport
The reason is clear. He wasn't sharing any personal and message data from its users with intelligence agencies and law enforcement.

Even ProtonMail which wrongly claims to be a privacy safe heaven does so!

janmo··on Kim Dotcom's extradition to the U.S. given green light by New Zealand
His mistake was to host content in the US.

"Megaupload is based in Hong Kong, but some of the alleged pirated content was hosted on leased servers in Ashburn, Va., which gave federal authorities jurisdiction, the indictment said." - Jun 25, 2012

https://www.cbc.ca/news/science/internet-file-sharing-giant-...

janmo··on CrowdStrike representatives issue trademark infringement notice to ClownStrike
I am familiar with CSC, and have received a multitude of fake DMCA takedown requests from them.They make it look like a DMCA but logos are usually trademarks (TM) and not copyright protected (c). So you cannot send a DMCA.

Basically their strategy is to flood the internet with fake DMCA, targeting everything that isn't seen as positive for the brand.

I 100% ignore their requests, and so far nothing has happened, keep in mind they send millions of it.

janmo··on Stripe acquires Lemon Squeezy
And now for sure they wont change that supplier. So yes it is suppressing competition.
janmo··on Content Injection Attack on GitHub
Funny at first, but this could have been exploited maliciously by let's displaying a message telling the user he has been disconnected and redirecting him to a phishing page.
janmo··on Google confirms the leaked Search documents are real
The main takeaway is that Google has been lying and gaslighting about their ranking factors.

The main lies that were uncovered is that they are indeed using clicks, and chrome browser data for ranking purposes.

Summary of their lies here: https://www.reddit.com/r/SEO/comments/1d2gllz/google_caught_...

janmo··on Google confirms the leaked Search documents are real
The main takeaway for me is that Google is caught lying. Many things were already assumed but Google used to deny them.

- They claimed that clicks were not a ranking factor, it turns out it is.

- Also turns out that they are using Chrome data for ranking purposes (Not good for the ongoing lawsuit)

- There is also a field called something like "is small personal site" and it presumed that those sites are penalized.

You can find a summary here: https://www.reddit.com/r/SEO/comments/1d2gllz/google_caught_...

← PreviousPage 2 of 13Next →