HNHacker News
TopNewBestAskShowJobs

lightswitch05

429 karma · joined July 28, 2013

https://www.github.developerdan.com/
submissionscomments
lightswitch05··on Invisible Manipulation: ways our data is being used against us
I agree that this is a glaring omission. Car insurance companies already have monitoring devices you can plug into your ODBII connector that monitors all your driving behavior. OnStar also has the ability to report driving behaviors to insurance companies. Or how about companies that claim your credit worthiness can be judged by your Facebook friends and posts. How long until these extremely invasive practices become so profitable that companies make it required? I worked for a company whose Heath insurance offered $50 to employees that got a heath screening through them. The next year it was no longer a discount, but a fee if you did not participate.
lightswitch05··on Why I’m Worried About Google
I'm also a Firefox and DDG user and I agree that the re-captcha issue is big. Between a pi-hole, uMatrix, and cookie-autodelete I'm able to seriously limit Google's impact on my daily browsing, but there is no way around the re-captcha. Without the google cookie following me around its even more apparent since I'm automatically in a higher risk tier for the re-captcha. I often spend several minutes on it clicking one image after another - its so bad I've started considering doing a screen recording to show others how long it takes. Google cannot be avoided and with AMP its just getting worse.
lightswitch05··on Mmm, Pi-hole
As far as I know, the pi-hole maintainers do not maintain any of the default block lists. I maintain a list [1] that is then feed into the popular host list by Steven Black [2] - which is a default list.

I definitely do not want to break things for people and I'm happy to remove any reasonable domains from the list. I wouldn't consider google analytics a reasonable one to remove - but you get the idea. I hate to hear you had a bad experience of it. If my list had the breaking domains for you, I would of loved to have a ticket opened where we could discuss it. Sometimes it isn't clear cut between ads & tracking and useful services.

[1] https://github.com/lightswitch05/hosts

[2] https://github.com/StevenBlack/hosts

lightswitch05··on Certificate transparency logs and how they are a gold mine to bug hunters
I love CT logs! I use them to discover subdomains for my hosts file block list [1]. While it can't expand on domains that use wildcard certs - or no certs at all - it's better then nothing since hosts files don't support wildcard blocking.

Some things I've learned while working with them:

* CertSpotter [2] is a fantastic CT client written in Go that supports pattern matching. I've been running it locally with `.` match pattern and so far have a 4 gig file of unique domain names. I'm excited to see the end result once it catches up to current time.

* https://crt.sh/ is a great website to search CT logs and supports wildcards. It's currently the workhorse behind my hosts project, but I hope to remove them as a dependency once my own domain list is caught up to present day

* It looks like OP's tool is just a thin client for entrust API [3] and is not actually downloading logs directly - which isn't clear in the article. It made more since once I figured that out because these logs are huge and go back years.

[1] https://github.com/lightswitch05/hosts

[2] https://github.com/SSLMate/certspotter

[3] https://www.entrust.com/ct-search/

lightswitch05··on One Year Without AMP
I think you might have missed the point of my comment. If you block AMP scripts, you will definitely encounter broken sites. The point I was trying to make are that those broken sites are mostly junk anyways. Overloaded with ads, tracking, and other manipulative content geared at turning me into the product. I haven't missed those sites any. However, I recognize that I'm not the average user, which is why these blocks are in my aggressive list. I initially put the blocks into my regular block list which is then consumed by Steven Black's hosts [1]. Very quickly a ticket was opened to whitelist AMP [2]. Funny enough, the user requesting that AMP be white listed posted screen shots of broken advertisements disguised as 'news' articles. To make everyone happy I moved it to my aggressive list which isn't included in Steven's project.

Anyways, long story short, I don't like AMP and don't mind the occasional broken site. But it's definitely not for everyone.

[1] https://github.com/StevenBlack/hosts

[2] https://github.com/StevenBlack/hosts/issues/657

lightswitch05··on One Year Without AMP
I block AMP and its related domains in my aggressive blocking hosts list[1]. I've found many AMP related sites are purely for marketing, or 'news' articles that are thinly veiled ads. I haven't missed it at all. I also don't use Google, so perhaps that it part of it, but I applaud your decision to remove AMP. The web isn't meant to be centralized in this way.

[1] https://github.com/lightswitch05/hosts/blob/master/tracking-...

lightswitch05··on The Bullshit Web
AMP is terrible. I flat out block it in my hosts file and haven't missed it yet. Its pretty much just used for advertising anyway. Or for 'news' articles that are thinly disguised ads
lightswitch05··on Three quarters of Android apps track users with third party tools
That is like saying Facebook does not own the content uploaded to it. These analytic tools are the ones doing the collection, at the end of the day it is their data that they allow you to use.
lightswitch05··on Three quarters of Android apps track users with third party tools
I believe the point of the article is that the data belongs in 3rd party hands. You might not be doing anything nefarious with the data, but that data does not belong to you and it is outside of your control to protect your users.

Given IP addresses, device identifiers, application identifiers, and timestamps - these 3rd party applications now have some pretty valuable signals that can be aggregated with other signals from other tracking methods to create a detailed profile linking users across devices, browsers, and geo locations.

lightswitch05··on Android getting “DNS over TLS” support
Are we talking about the same company that exploited Safari to bypass privacy protections? https://www.eff.org/deeplinks/2012/02/time-make-amends-googl...
lightswitch05··on DuckDuckGo vs Google
Personally, I value my privacy more than the small amount of time tweaking my search query to get the results I actually wanted vs. the out-of-context results I got. I think anyone using DuckDuckGo is of the same opinion. When you think about it: total loss of internet privacy for some slightly better search results? Pretty massive trade off of with some serious consequences.

However, I do get your point. Without that extra context, the search results can only ever only be so good.

lightswitch05··on Chrome's insane password security strategy
who the hell uses the saved password feature? Seriously, its a password, everyone knows you should never write down you passwords. why would saving it be any different? Chrome still has to provide the feature to compete with other browsers, but just because a feature exists doesn't mean you should use it. Think about it, he was able to import passwords from another browser. What does that say about how other browsers store their passwords? It is a stupid assumption that a saved password is secure.
lightswitch05··on Table-to-JSON
Your more than welcome to submit a pull request for any new features you'd like me to add/support. As for my code. I wrote it in a day for a specific page. After seeing people with similar needs on stack-overflow I decided to clean it up a bit and make it a plugin, never really spent a whole lot of time on it. I think my filterable plugin deserves more attention this this one does (http://lightswitch05.github.io/filterable)
lightswitch05··on Table-to-JSON
I am the creator, thanks for posting it on here! I had no idea so many people would have any interest it it, for me, it had a vary narrow use-case
lightswitch05··on Table-to-JSON
I've had multiple people ask me about that. There are already tools out there that do it, so I didn't really have any motivation to make it
lightswitch05··on Table-to-JSON
Hey, great question! Well, I don't know why other people might need this plugin, but I needed to gather data from a dynamic user-editable table. Its not all that complicated getting data from an HTML table, but my specific table is dynamic in sense of how many column and rows are available. Also the heading names. I considered keeping track of the contents as the user edited it, but in the end it was just easiest to get the end result rather than keeping track of all the edits. So, thats where table-to-JSON came from. Had no clue so many people would be interested in such a simple plugin.
← PreviousPage 3 of 3