HNHacker News
TopNewBestAskShowJobs

mstef

399 karma · joined November 22, 2008

submissionscomments
mstef··on I Cut My Google Search Dependence in Half
sure all data collected is of value to someone, browsing history is definitely. however this is decentralized, and needs targeted attacks, so depending on your threat model, this might be bad, but for most of the users it's probably better than giving a search engine your search queries for pages you visited earlier.
mstef··on Omnom: Self-hosted bookmarking with searchable, wysiwyg snapshots
sure, for bookmarking that's fine. but it does not help against linkrot, or censorship, or pages changing with time.
mstef··on Omnom: Self-hosted bookmarking with searchable, wysiwyg snapshots
btw it is perfectly fine to circumvent a paywall with archive.ph and then to snapshot it with omnon so your bookmark never linkrots away. also when i say "js manipulation" i also mean stuff like captchas, or dynamic documents that you change by interacting with it, or even private services like e.g. rocket chat hidden behind some barrier like http auth, or private vpn. archive.ph will never have access to what your browser might have access to.
mstef··on Omnom: Self-hosted bookmarking with searchable, wysiwyg snapshots
looks nifty, but does it do snapshotting?
mstef··on Omnom: Self-hosted bookmarking with searchable, wysiwyg snapshots
omnom is for snapshotting, not for circumventing paywalls. i'm merely comparing the snapshot feature of the two projects. circumventing paywalls is out of scope.

your bookmarks will never linkrot away.

mstef··on Omnom: Self-hosted bookmarking with searchable, wysiwyg snapshots
the difference is, that archive.ph snapshots something in headless. omnom snapshots the exact same state that your browser is displaying you. so if there is js interactions that change the dom, those will be snapshotted, unlike with archive.ph.

also lets not forget that archive.ph wraps everything in their own frame and has their own way of mangling the result. not in a bad way, it's just not the original as it would have been rendered in your browser.

mstef··on Omnom: Self-hosted bookmarking with searchable, wysiwyg snapshots
btw if you want to have a look at more than a decade of snapshots, try https://links.ctrlc.hu/ my private and membership invitation-only instance.
mstef··on The European Union must keep funding free software
this is a recent (1-2 months old) report on the impact of the NGI0 programme:

https://op.europa.eu/en/publication-detail/-/publication/257...

there was also a fosdem talk about this, if you prefer AV to text, finding it i leave as an exercise to the interested parties...

mstef··on Zig vs. Rust at work: the choice we made
besides the docs, there is also all the source code in /usr/lib/zig/std... very useful to learn zigisms and the API of the std library itself...
mstef··on Memory-safe, clean implementation of classic Posix "BC" calculator
what's next that urgently needs mem-safety? /bin/true?
mstef··on Memory-safe, clean implementation of classic Posix "BC" calculator
this must be parody. what exactly is the threatmodel where memory-safety matters for a calculator? did these devs miss the point of popping a calc.exe? surely no bc has ever been used for LPE or RCE.
mstef··on Ask HN: What's the best book you've read so far in 2024?
john scalzi: starter villain

note, if your wife doesn't like to be woken up, do not try to read this next to her in bed. you will LoL, and wake her up.

mstef··on Backdoor in upstream xz/liblzma leading to SSH server compromise
this backdoor had nothing at all to do with memory safety.
mstef··on A brief history of the U.S. trying to add backdoors into encrypted data (2016)
i believe the cryptomuseum has a more extensive list than the one in the link: https://www.cryptomuseum.com/intel/nsa/backdoor.htm particularly one is interesting as i have reverse engineered and proven its existence: https://www.cryptomuseum.com/crypto/philips/px1000/nsa.htm
mstef··on How much garden you would need to survive on
The book Environment, Power, and Society for the Twenty-First Century: The Hierarchy of Energy by Howard T. Odum is an eye-opener in this regard. Odum studied this topic for decades and presents some numbers how much energie needs to be spent to feed a person in different regions of the world. It turns out the cheapest to feed humans is if they live sparsely in a rain forest.
mstef··on “Make” as a static site generator (2022)
haha, utterson also uses m4 for templating: https://github.com/stef/utterson/tree/master
mstef··on “Make” as a static site generator (2022)
utterson https://github.com/stef/utterson/tree/master is generating blogs using make for a 14 years now...
mstef··on LobbyFacts – Exposing lobbying in European institutions
haha. hello OG
mstef··on LobbyFacts – Exposing lobbying in European institutions
lobby costs is a self reported value based on their spending on lobbyings, including for example staff, office rent, events, etc.

not having ep passes or meetings with the ec, only means less direct contact, or possibly having outsourced this contact.

mstef··on LobbyFacts – Exposing lobbying in European institutions
yes, back in the days CEO (Corporate Europe Observeratory https://corporateeurope.org/) alter-eu (https://www.alter-eu.org/), and a bunch of other NGOs where using (and also sponsoring it). But it is also well known by the OCCRP people (one of whom actually started the whole thing).
mstef··on LobbyFacts – Exposing lobbying in European institutions
a few years ago i was maintaining lobbyfacts. ama
mstef··on U.S. safety agency to consider ban on gas stoves amid health fears
what a coincidence this article was just 4h ago linked here: https://news.ycombinator.com/item?id=34308734 and is similar policymaker influencing pseudo science conflating correlation and causation...
mstef··on Cooking on gas could be behind kids' asthma symptoms
yes, and that is more of a lobbyist paper aimed at policymakers, it refers to some TNO studies as the "scientific" basis for the claims, but those studies are not publicly available, at least they're not linked directly in the references section, and searching for them also doesn't give immediate results. the other thing they refer to are "simulations" which have little value in proving the statements. otherwise the whole thing is a confusion between causality and correlation. as it stands i consider this a bullshit paper pushing some political agenda, possibly by induction heating manufacturers or electricity companies.
mstef··on Ask HN: Is there a spiritual successor to del.icio.us?
you should try omnom, v1 has been created when del.icio.us was sold. it has been revamped into a v2 earlier this year: https://github.com/asciimoo/omnom

distinguishing features: selfhosted, in-browser-snapshots-as-currently-rendered for archival and against linkrot.

mstef··on Ask HN: Is there a good reason for disallowing some characters from a password?
let me quote NIST Special Publication 800-63B: https://pages.nist.gov/800-63-3/sp800-63b.html#memsecret

> Verifiers SHALL require subscriber-chosen memorized secrets to be at least 8 characters in length. Verifiers SHOULD permit subscriber-chosen memorized secrets at least 64 characters in length. All printing ASCII [RFC 20] characters as well as the space character SHOULD be acceptable in memorized secrets. Unicode [ISO/ISC 10646] characters SHOULD be accepted as well.

mstef··on Show HN: We created a password and data manager for teams
do you guys have a whitepaper about how you do crypto?
mstef··on Show HN: Search Aggregate – Search results from lots of different sites
searx is doing exactly this, has opensearch support so can be added to your browser search bar.
mstef··on Bubblewrap: Unprivileged sandboxing tool for Linux
some time ago i made a comparison between different jailing tools: https://ctrlc.hu/~stef/jails.txt
mstef··on Ask HN: Alternatives to 1Password
you might want to read the whitepaper regarding bruteforce attacks: https://github.com/stef/pwdsphinx/blob/master/whitepaper.org...
mstef··on Ask HN: Alternatives to 1Password
what does rotation mean? you can change your passwords, both the "master" which i rather call input, and the output password as well. i mean you can have a new output password without changing your input password.

and no although i can only guess what you mean with vaultfile, an attacker still needs access to the sphinx server, which has protections against bruteforce attacks.

Page 1 of 3Next →