HNHacker News
TopNewBestAskShowJobs

parable

149 karma · joined January 15, 2026

submissionscomments
parable··on I'm addicted to buying domains for my vibe-coded apps that get 0 visitors
Not an ad or promotion, I'm just also addicted to buying cool domains and I remember seeing this up for sale: DomainEmpire.com is currently trying to sell sesqui.net, registered in 1987, for $33,000. I think they have others that are cheaper, but you'll have to scrape WHOIS data for each domain to find their creation dates.
parable··on Turn off and restrict access to Apple Intelligence features on Mac
I don't really care if anything else gets blocked as a side effect, except for Find My. As far as I know, `fmfd` and `findmydeviced` are the binaries responsible for that feature, so if I whitelist those binaries I should be fine.

Through my own usage of Little Snitch, it appears that all the iCloud-related features use individual binaries and that iCloud connections go to specific hosts for specific use cases (e.g. pxxx-contacts.icloud.com, pxxx-quota.icloud.com, pxxx-caldav.icloud.com). I'd assume the AI features are the same - specific hosts and binaries that I can block.

parable··on Turn off and restrict access to Apple Intelligence features on Mac
Is it possible to block Apple Intelligence from sending data over the Internet via Little Snitch? I would assume it is, but I'm not sure if anything significant has changed in macOS 27 that makes this impossible now. I don't really mind the local features - I'd rather they stay disabled, but it's not the end of the world - but I really don't want any data leaving my Mac.
parable··on Framework discloses data breach via Metabase 0-day
This would be nice, and I hope I get to see a future like this, but I moreso meant that I don't see a solution for this issue given the current landscape of things. Ideally, yes, companies wouldn't collect the data and it would be illegal to do so. However, this currently isn't the case, so what can be done that lets all sides win? Something has to give, and I'm certain users will receive the short end of the stick at all times - at least, until there are better laws in place.
parable··on Framework discloses data breach via Metabase 0-day
Metabase can be self-hosted, but you cannot self-host Salesforce or Mixpanel or many of the other products I'm referring to. In an ideal world, every company would self-host their own instances of all of their products, since that ultimately forces them to be solely responsible for their customers' data. Using the cloud versions of these products shifts the blame from the company itself to the vendor when things go sideways, so it makes more sense for them to do this instead of taking responsibility.
parable··on Framework discloses data breach via Metabase 0-day
While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days.

I don't see a solution to this in the near future. I initially thought up something quite simple: assign every customer a unique ID and use that where possible to reference a customer. That solution, however, renders the analytics and CRM tools nearly useless. There has to be a better way, though, other than haphazardly giving out customer metadata to other vendors. All of that information should stay in-house.

As for why metadata is important: I've said this before, but metadata can't easily be changed. I'd much prefer having my password or credit card number leaked in plaintext since I can change those identifiers trivially. I can't change my name, phone number, or address as easily.

parable··on 1k Data Breaches Later, the Disclosure Lag Is Worse
I've had a similar thought in the past. I was thinking about the feasibility of a law being introduced where each company making over a certain amount of money per year must begin a VDP (and optionally a BBP) so that security flaws can be reported to them easily. This can easily be done by simply opening up security@companydomain and using security.txt (https://securitytxt.org). Reports must receive a response in N days, where N is calculated based on available staff, resource allocation, and revenue of the company. If they don't receive a response after N days, this can be escalated to some government agency which can take action against the company for failing to respond to a report on time.
parable··on 1k Data Breaches Later, the Disclosure Lag Is Worse
Companies can and do get away with arguing that they have a "lawful basis" to collect whatever data they'd like. It's unfortunate.

IANAL, but the law seems a bit vague to me, and it appears that companies use that vagueness to their advantage. Maybe I'm just not articulating my arguments correctly.

parable··on 1k Data Breaches Later, the Disclosure Lag Is Worse
> Otherwise, just assume everything you do online is public and act accordingly.

This is such a depressing reality. It's also what governments want you to believe. If you aren't able to speak your mind about anything anonymously, then you won't be able to, say, spread ideas that go against them.

Admitting defeat at all and not even trying to teach people about privacy results in the "I don't care, what's the point?" attitude that plagues many people today.

parable··on 1k Data Breaches Later, the Disclosure Lag Is Worse
I use Snusbase (https://snusbase.com). They've been around since around 2016 and haven't had any issues legally - they're the longest-standing data breach search engine besides HIBP, as far as I know.

(This is not an advertisement.)

parable··on 1k Data Breaches Later, the Disclosure Lag Is Worse
Hashes can be cracked, and end users won't understand how to create password hashes to check which one was leaked. Plus, salts exist.

Passwords shouldn't matter anyways. Use a password manager and be done with it. The real issue is metadata which can't easily be changed - phone numbers, addresses, and the like. If any of that data is leaked, it becomes much harder to contain impact. You can't move addresses every time your address gets leaked online.

parable··on 1k Data Breaches Later, the Disclosure Lag Is Worse
I wish that were the case, but because of there being barely any consequences for breaches, it's much more profitable to store everything you can and sell it to the highest bidder. Make it a huge risk to store data, then companies will start treating data like a live hand grenade.
parable··on 1k Data Breaches Later, the Disclosure Lag Is Worse
I'd also add a third issue to this list: data retention. Too many companies I've dealt with have privacy policies that state something to the tune of "we'll hold onto your data for as long as required" without giving much of an explanation as to how long "as required" is.
parable··on Rootshell: A new E2EE email service hosted in Iceland
I find it very hard to trust any email service that claims to be E2EE without an audit by a reputable firm like Cure53 or Trail of Bits.

I signed up to give it a brief test and immediately noticed that emails are returned from the server in plain text. This means that the emails are decrypted on the server, which defeats the entire purpose of E2EE. The encrypted email contents and metadata should be returned to the user and decrypted on the client.

It's also painfully obvious that the entire thing is vibe-coded. While that in itself isn't an issue, it raises scrutiny. If the author doesn't have a full understanding of the code their LLM generates, some nasty bugs could be lurking.

Not very promising.

parable··on Platypus – create native Mac applications from command line scripts
I'm not sure how I haven't heard of this yet. There have been too many times I've wished I could convert a command-line script to a native application easily for me not to try this.
parable··on 1-Click GitHub Token Stealing via a VSCode Bug
Kudos for the public disclosure. Too many people haven't been happy with MSRC and it's starting to boil over (see the Nightmare Eclipse situation, too). Maybe all of these disclosures will cause them to do some introspection and realize they're the problem. I highly doubt that, but one can dream.
parable··on The newest Instagram “exploit” is the goofiest I've seen
It seems pretty trivial to just add a check in the agent's tool call to determine if the email is actually the one on file (or one that has previously been on file). I'm not sure why it's taking them so long to remediate.
parable··on The newest Instagram “exploit” is the goofiest I've seen
The bug still exists - two of my friends have lost access to their accounts as of an hour ago. They've partially recovered but are unable to change their passwords, so their accounts are still technically in the hands of the attacker(s).
parable··on The newest Instagram “exploit” is the goofiest I've seen
It appears the exploit hasn't been patched: https://x.com/vxunderground/status/2061636614267273332

I've heard the new "method" has to do with setting your location to Singapore or something, but I have yet to confirm anything.

parable··on The newest Instagram “exploit” is the goofiest I've seen
The original 2FA did not get thoroughly bypassed, because otherwise I would've lost my username, so that's false - at least, based on my experience.

However, there are separate vulnerabilities that allow for 2FA to be bypassed on Instagram. I assume they were chained to take over specific high-value accounts. The 2FA removal happens as a service - most people charge around $1,000+ - so it wasn't viable for most lower-value accounts. Anything that was worth over $1k probably had the bypass applied to it.

parable··on The newest Instagram “exploit” is the goofiest I've seen
I suggest you try signing into your Instagram account via the app or website to check if you've been compromised. It could very well be a bot trying to obtain your recovery method hints but you could've also fallen victim to this exploit, especially if you have a short or valuable username.
parable··on The newest Instagram “exploit” is the goofiest I've seen
If there's no recovery email address set, or that email has expired, there are no recovery methods to verify with. The account is locked "for good". I use quotes because in some cases I've been able to recover Gmail accounts with similar characteristics by simply trying often on my home IP address using Google Chrome.
parable··on The newest Instagram “exploit” is the goofiest I've seen
This still happens. Meta doesn't do much to protect against this, they just fire more people and hire new agents when they find out one was bribed.
parable··on The newest Instagram “exploit” is the goofiest I've seen
It's against Meta's terms to buy and sell accounts, thus the bank would never do such a deal unless you structured it a certain way: create a business, the account becomes property of the business, then Chase buys the business and thus the account. This is how certain Twitter accounts were sold a long time ago. $10k for @chasebank (which is what I assume your handle is) is quite good regardless, though.
parable··on The newest Instagram “exploit” is the goofiest I've seen
Meta's aware and tries their best to act on it, but the real solution is simply not hiring outsourced support workers. It's really that simple. They have the money to hire people in-house for good wages, which would solve the root issue: the outsourced workers are desperate for money and gladly will take bribes.
parable··on The newest Instagram “exploit” is the goofiest I've seen
Correct, which is the problem here - they don't want to, and you can't force them to.
parable··on The newest Instagram “exploit” is the goofiest I've seen
Likely a bot spamming the reset endpoint to fetch your recovery method hints. Happens all the time. I'd ignore and just sign into your account via the app or website to make sure everything's fine. WhatsApp is indeed used to send reset codes to accounts if the phone number on file is registered to WhatsApp, but I'm unsure as to how that integration actually works, as I don't use WhatsApp.
parable··on The newest Instagram “exploit” is the goofiest I've seen
Your account might be rate limited from performing additional password resets. Try the hacked account flow by selecting "Can't reset your password" (or whatever the app says) when trying to do a password reset. That's how I was able to sign back in despite being unable to request additional reset codes.

Have you lost your username? Instagram should allow you to revert it once you're back in.

parable··on The newest Instagram “exploit” is the goofiest I've seen
You're lucky you weren't affected by this. Several people I know with three-letter usernames had theirs stolen over the last few days.

When I recovered my account that had been stolen through this exploit (luckily, my username hadn't been changed), I was sent a code to my email address and then asked to use my TOTP code, backup code, or a video selfie. I used my TOTP code and was let in just fine. They certainly have the ability to make such a feature. Keep in mind, however, that several unpatched TFA bypasses exist for Instagram currently. People offer it as a service for around $1,000 on Telegram. Where there's a TOTP code input, there's a way to bypass it.

parable··on The newest Instagram “exploit” is the goofiest I've seen
Or sell it, and pocket some cash for yourself. If this person has a short or otherwise valuable username, they could sell it for possibly thousands or tens of thousands of dollars.
Page 1 of 2Next →