HNHacker News
TopNewBestAskShowJobs

nominated1

458 karma · joined October 10, 2014

submissionscomments
nominated1··on PHP-FPM remote code execution bug exploited in the wild
Right, portscanning won’t work on Wireguard. Port knocking can provide an additional layer of protection against an unknown vulnerability, even for Wireguard. Sorry for the confusion.
nominated1··on PHP-FPM remote code execution bug exploited in the wild
It’s more evidence that you should assume everything is vulnerable and layer protection.

For a home network simple multi-port knocking should be enough (combined with --ctstate NEW even better). If port knocking or SPA is too cumbersome then at least consider limiting access based on GeoIP, block tor exit nodes, etc (ipset is pretty amazing).

This can be applied to any service on your network btw, including Wireguard. I like knowing that a portscan of my network shows nothing open. I don’t end up on a list that gets used in the next ‘spray and pray’ attack.

Disclaimer: I’m not advocating this for serious use due to replay attacks and IP spoofing via a VPS. This is for home network protection (a boring Class C non target).

nominated1··on Sea urchin population soars 100x in five years
I thought the same thing after watching the recent Nature program "The Serengeti Rules"

https://www.pbs.org/wnet/nature/the-serengeti-rules-41dfru/2...

nominated1··on Eat, Drink and Be Wary: Ex-CIA Officer Reveals How Eateries Are Key to Spycraft
For those of us not in the loop.

the guy = John Lansing

USA organization for external propaganda = USAGM (U.S. Agency for Global Media).

nominated1··on Baltimore Blew Off Ransomware Demand Only to Find Data Had Never Been Backed Up
> paying the ransom is no _guarantee_ you actually recover

I’ve only helped recover from ransomware once about 2 years ago. When we ran the decryption program provided after paying it decrypted ~97% of the data. Some files were just permanently corrupted. Windows Server with ECC memory fwiw.

Fun note but the owner wanted to reboot after decryption and I yelled “No!” across the room, wanting to clone the known good data first. Good thing too, a reboot started the encryption all over again… good times.

I heard they were hit again but took my advice and setup Backblaze.

nominated1··on Stupid Unix Tricks
> Otherwise, you will miss out on better ciphers as they are added and would be stuck on this one forever.

You’ve identified issues with whitelisting but blacklisting isn’t perfect either. For example, many don’t trust NIST and may want to prevent the use of any of their future curves. Blacklisting fails here.

When updating to a newer version of SSH I think it’s good practice to ‘man ssh_config’ and at least look at KexAlgorithms, HostKeyAlgorithms and Ciphers.

nominated1··on DNS Security: Threat Modeling DNSSEC, DoT, and DoH
> I preemptively agree that Cloud Flare is not one of those organizations.

Would you please elaborate on your distrust of Cloudflare? I’m not looking to call you out. Quite the opposite, I appreciate your candor. I just feel like I’m missing some context.

nominated1··on Firefox Privacy How-To Guide
Unfortunately the info provided by about:support doesn’t separate changes made via the gui and changes made via about:config. It also includes settings that may have been altered by Add-ons.

Another benefit to using a user.js file is that your changes are persistent. If Mozilla changes a setting via an upgrade, like they did with experiments and plan to do with DoH, your changes aren’t overridden.

nominated1··on Firefox Privacy How-To Guide
Many of these sites suggest making edits via “about:config”. The problem is it’s difficult to keep track of which settings you’ve altered. I highly recommend you use a user.js [1] file. The best part is you can make notes so later you knows why a setting was enabled or disabled.

The only downside is if you decide to undo a setting in user.js you’ll also have to make the same change in about:config.

[1] http://kb.mozillazine.org/User.js_file

nominated1··on Hiren’s BootCD Based on Windows 10 PE X64
As a Linux user would this be an option for installing Bios and Intel ME updates on machines with Windows only tools available? Or is Windows-To-Go still a safer option?
nominated1··on California power outage triggers chaos in science labs
I was born and raised in the Bay Area and remember when there was a vote that would have brought SMUD in instead of PG&E. I don’t ever remember PG&E coming out to our property (South Bay), despite having large trees near power lines.

I’ve since left the Bay Area and now have SMUD. They come out every year to check brush and trees. This past summer they cut down a dying tree on the property at no cost. The arborist they sent out was extremely knowledgeable and didn’t mind that I took his time to ask about native replacements, etc.

nominated1··on China Says ‘Stay Tuned’ for Retaliation over U.S. Tech Blacklist
The outrage directed at China… that looks pretty authentic. It certainly isn’t what Wall Street wants. It certainly isn’t what the mainstream media wants as the talking point for the next election. I think they had decided on health insurance.

There’s no doubt that Trump is capitalizing on it and why wouldn’t he?

What makes you think this is fear-mongering? As in fake. The Hong Kong events, South Park, NBA, etc… this is as organic a shit storm as I’ve ever seen.

nominated1··on D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
The same way Dell and HP do with a Windows PC. The OpenWrt buildroot can help them do that too! ;-)
nominated1··on D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
Xiaomi sells routers in this price range that ship with OpenWrt. The buildroot even has config options for branding! It costs them nothing for the OS. It costs D-Link more to produce their mess.
nominated1··on Break before make, abstractions, and sleazy ISPs
> See this bullshit from ISPs is what something like DNS over HTTPs would help with.

I’ll start by saying I’ve setup DoH on my home router just for fun.

> Whilst seemingly not having the skills to block all public DoH providers in their network.

Now with my admin hat on - maintaining a list is an unnecessary burden. It’s a matter of sensibility not skill. Time is money after all.

DoT (DNS-over-TLS) probably should have won since it uses it’s own port (853) which makes it easily manageable, does the same thing and is more mature. The “but privacy” argument for DoH looks like a red herring.

nominated1··on Dnscrypt-proxy 2 – A flexible DNS proxy with support for encrypted DNS protocols
From their own documentation [1]

> The dnscrypt-proxy file is quite large, but can be compressed for a massive reduction of its size, from ~12 Mb down to ~2 Mb.

Routers typically have 8-16 Mb of storage. Even 2 Mb is a bit much but even if the size doesn’t bother you the memory usage is still relatively extreme when compared to the link I shared.

[1] https://github.com/dnscrypt/dnscrypt-proxy/wiki/Installation...

nominated1··on Dnscrypt-proxy 2 – A flexible DNS proxy with support for encrypted DNS protocols
I looked into this but Go on a little OpenWrt router seemed… silly.

If you’re interested in something lightweight for OpenWrt give this a try:

https://openwrt.org/docs/guide-user/services/dns/doh_dnsmasq...

nominated1··on Shift to electric vehicles will radically change auto factories
Until you can charge and go in 5 minutes gas will still be appealing to many. Currently it looks like a step backwards. Like stopping to rest and feed the horses.

Maybe if we had a universal battery and simple swap out solution. Something like a car wash where you drive onto a track and a machine swaps out the battery?

nominated1··on Websites have been quietly hacking iPhones for years, says Google
Warning Conspiracy Theory Ahead:

I’m not yet ready to crucify Apple for not issuing a press release listing sites and services affected. Same with the Google “deep dive” with it’s vague insinuations.

I suspect this is a big international incident like - “China bought hacks from Mossad to target Hong Kong” kind of big. For all we know there are gag orders in place and an ongoing investigation.

I will still use iOS devices too. They are still the most secure consumer available/friendly computing devices available imo. That said, I want to know more.

nominated1··on EU governments choose independence from US cloud providers with Nextcloud
Those quotes read like typical PR statements made by politicians. I was hoping for a bit more.

I can’t find it now but it wasn’t long ago that the NextCloud (or was it OwnCloud) FAQ had a note about security that read something like “we’re busy adding features we’ll get to security later”. It left me feeling uneasy. I would have hoped security would have been part of the design. Maybe I’m just getting old...

nominated1··on EU governments choose independence from US cloud providers with Nextcloud
Do EU Governments care about security? Has a proper audit of this monstrosity been done?

Or is this just another ploy to get better pricing?

nominated1··on Xfce 4.14 released
XFCE is like the Goldilocks DE for me. Not too New Age (Gnome 3) not too much (KDE) and not too little (tiling WM). It’s not the prettiest thing but if something bothers me I know I can tweak it and be happy.

Thanks team for keeping some of us sane!!

nominated1··on Walmart sues Tesla over fires at stores fitted with its solar panels
A friend of mine is a union electrician with 15 years in the trade. He’s helped install dozens of solar farms across Northern California. One thing I found interesting/unnerving was that apparently the spacing tolerances between panels is quite low. He said it’s their biggest concern when it comes to fires.

So, maintenance seems like a must. Especially on rooftops or structures that will naturally “settle” over time. If I had to guess, these tolerances weren’t properly maintained or the buildings/roofs themselves weren’t solid enough to begin with.

If anyone can shed more light on this (pun intended)…

nominated1··on Typical U.S. households don’t use most of their bandwidth
It depends on how you define “power user”. Many power users don’t understand a lot of the issues surrendering this either.

I’ve known many people who perceive stuttering, slow page loads and game lag as a result of a slow connection. The ISP’s could solve this but I’d imagine it works in their favor. While I’m more than capable of tweaking SQM/Cake (OpenWrt) values and testing (keeping ping times below 40ms), I believe a simple consumer friendly (read: automatic) solution is sorely needed.

nominated1··on Open letter from an Android developer to the Google Play team
> Yes everyone should be rich enough to buy a 1000 dollar Apple phone.

I bought an iPhone 7 from Net10 about 5 months ago for $220 shipped. It requires a minimum $20 a month plan for 12 months before I can unlock it. About 2 years ago I got my mom an iPhone SE for $140 with similar plan/unlock. Both brand new.

They’re not everyday prices and not the newest model but it is possible to go iOS without breaking the bank.

nominated1··on Katy Perry's Dark Horse Lawsuit Makes Waves in Music Industry
What, if any, blow-back can Todd Decker expect from this? Didn’t he just put his reputation in jeopardy?
nominated1··on Most internet service providers are gone – Sonic has survived and thrived
Visits site > Clicks Check Availability > Enters Address Info > Clicks Check Availability > Google Captcha > Selects Audio (because I've been caught in a loop too many times) > Clicks Play > Enters Text > Receives "Try Again Later..." > Closes Tab

There has got to be a better way. I mean Sonic just lost a potential customer because I won't "Try Again Later".

Ubuntu + Firefox FWIW

nominated1··on A "cure" for baldness could be around the corner
Like you I began going bald before the age of 20. I was teased a bit in highschool but nothing that I let get to me enough to leave scars. I don’t know how old you are but until my late 20’s I’d wear a hat and preferred social scenes where it was appropriate. By the time I hit my mid 30’s I was more comfortable. Now in my 40’s it’s a non-issue. Meanwhile, friends of mine who began thinning in their 30’s are still fretting about it. I wonder if they’ll be comfortable by their the time they hit 50.

Reasons I chose to go with a shaved head:

My dad wore a toupee and nobody was allowed over after dad took it off (he’d take it off immediately after work, apparently they’re not very comfortable). My uncle tried every new cream/lotion that came on the market and was obsessed (he died of brain cancer at age 62 btw). My grandfather, was just bald. Of the three my grandfather was the most confident and comfortable in his on skin.

I’m not telling you to just get over it, it’s demoralizing when you’re young. I just hope that with time you’ll become more comfortable with yourself. My wife and previous girlfriends never had a problem with it as many women don’t. At this point she tells me what length I should keep it and I just go with that.

nominated1··on MPAA Welcomes Netflix as New Member
I believe the MPAA is involved in pushing the recent CASE Act:

https://act.eff.org/action/prevent-copyright-trolling-tell-t...

https://www.techdirt.com/articles/20190711/00001742562/congr...

nominated1··on Firefox 67.0 Released
I've also read that it takes more power (battery) to render black than it does white. Combined with the need for more brightness it doesn't seem like a good solution.

Calibrating my monitors took them from having piercing bluish whites to more softer pinkish whites and reduced daytime eye strain significantly.

I then use Redshift at night with the undocumented "preserve" switch to combine my icc profile with the Redshift changes.

← PreviousPage 3 of 4Next →