HNHacker News
TopNewBestAskShowJobs

peppermint_tea

195 karma · joined November 13, 2020

submissionscomments
peppermint_tea··on Re-thinking electronic mail
once you receive a message that you actually want, you could validate the signature and every subsequent communication from this sender is more likely a desired email than a spam
peppermint_tea··on Re-thinking electronic mail
no, because they belong to a residential ip block. it is easy to test... and the error message is without ambiguity.
peppermint_tea··on Re-thinking electronic mail
I would also challenge the "Google and Gmail account for a very small amount of the global mail-flow". 100% of the companies I worked at use office365 and Gsuite.
peppermint_tea··on Re-thinking electronic mail
google block residential ips. even with a specific message. not based on reputation, based on ip block. I am well aware that smtp have been abused for decades now, I run my own mail server and have no problem sending to google outlook etc. my point was only regarding blocking residential ip. google definitely does that (on top of many isp's) and it is not part of how the smtp protocol works. no conspiracy here.
peppermint_tea··on Re-thinking electronic mail
The solutions are already there... there is a lack of will from the corporations to implement them. google checking gpg signature? nope.

The internet is unfortunately not user-centric enough, there is much more value in sending crap html emails "only 10 hours left 50% discount" and scanning your emails than there is to provide users with secure communications.

let's all sign our emails to raise awareness of google's & outlook shortcoming

P.S : we tend not to sign our emails since it is not the standard, standard is de-facto dictated by google and outlook now.

P.P.S : seeing an unsigned email would raise suspicion if the standard was the opposite, a filter could even classify between signed and unsigned

P.P.P.S : you would only bother to verify the identity for the emails you care for

P.P.P.P.S : if you think google does not dictate the standards, feel free to point to me the part of the rfc that mention that residential ips are not valid.

peppermint_tea··on Ask HN: Please Give Me Advice
it is not about being liked, it is about feeling better. walking have always been my to go solution when I have the blues (not full blown depression though). I am not saying it will fix all your issues, but it MAY improve them a bit and it won't make them worst. (not sure if your notion of health included exercice)
peppermint_tea··on The Racial Experience of a White Working Class American Boy
+ gerrymandering
peppermint_tea··on The epidemiological relevance of the Covid-vaccinated population is increasing
hahaha, was worth google'ing it
peppermint_tea··on The epidemiological relevance of the Covid-vaccinated population is increasing
sorry to hear for your father. I do love remote meetings though, I can mute myself and go do something else.
peppermint_tea··on The epidemiological relevance of the Covid-vaccinated population is increasing
to me, it was clear from the start that the vaccine was not PREVENTING the transmission of the virus, they were talking about a REDUCED transmission... but politicians(leading by polls) we were so in the rush(arguably legitimately) to restore the economy that we came up with paperwork for the vaccinated as a solution (which I fill monthly to travel and I present to eat chineese food). And some citizen were so in the rush(arguably legitimately) to go back to "normal" that they just let go of the other known working measures like masks and social distancing(take the tube in London to see what I mean)

Even If I am fully vaccinated, I do not wish to send someone who have decided not to take the vaccine to the ER. Even if it was in my opinion a bad decision. I do not mind wearing a mask while we collect more data to have a more efficient response.

peppermint_tea··on For DNSSEC (2015)
Good arguments on both side, but personally, i'll keep on using it and I would really like my bank to do the same... :(

dig +dnssec nsa.gov

peppermint_tea··on Messaging and chat control
this is exactly why I created a chat service you can host on your home pc... I believe centralization by big corporations plus laws passed with various objectives made by various governments is the end of the internet as we know it. A tool meant to connect the humans from different countries, culture and religions to exchange ideas, discuss, share knowledge and empower people against corrupted governments.

I believe peer to peer is the way to go and we tech people have a duty to inform and vulgarize technologies and outcomes to our close relatives.

This is the digital legacy we will leave to future generations.

peppermint_tea··on Google starts adding “no reliable sources” tag to some search engine results
my javascript blocker indicate me that reclaim the net website use ajax.googleapis.com and static.cloudflareinsight.com... a bit ironic.
peppermint_tea··on Bandcamp's app is no longer listed on Google Play
can't talk for OP, but they got a 10 year boycott from me because of this : https://wikileaks.org/PayPal-freezes-WikiLeaks-donations.htm...
peppermint_tea··on The Slander Industry
on a second thought, we could re-use the names and some of the texts on these slander sites with the newly generated posts (with the generated picture) to give website administrators a hard time figuring out which post is a real person and which one is a duplicate, bonus, google will index all these "john doe" and "jane doe", bluring the real person/victim in a ton of results with different pictures so anyone looking at the results will think the site is total garbage (which it is)
peppermint_tea··on The Slander Industry
this makes my blood boil, the author is obviously technically savvy, but how damaging it can be for someone (even technically inclined) in this day and age.

related horror story: https://www.nytimes.com/2021/01/30/technology/change-my-goog...

it would be a real shame if an organised group of person would start posting programatically to these slander sites with material from https://thispersondoesnotexist.com/ and randomly generated names. Storing all these pictures will cost something afterall.

peppermint_tea··on Why I distrust Google Cloud more than than AWS or Azure
although not a complete cloud solution, I just read the "how it works section" and it is quite cool. price is awesome too.
peppermint_tea··on Closing web browser windows doesn't close connections
thank you, I learned about service worker lately while doing some web development(not my usual cup of tea) and I backed off and used a rss feed instead because I found modern web too intrusive/google centric. Just disabled service worker in my firefox (+no script)
peppermint_tea··on Interview with CEO of rsync.net: “no firewalls and no routers”
happy customer here.

I do a simple rsync of my precious but not too sensitive data, daily.

and for the more sensitive stuff, gpg before sending daily as well, the copies will add up but I prefer it that way.

10/10 great business

peppermint_tea··on Show HN: I Made a Chat Server
thanks for your comment,

about my temporary choice for aws:

the reason is explained here : https://temporary.chat/qa.html

"I dont like your dns, registrar etc : took amazon for the ease of use and because I am familiar with it, but it is not my final choice, my goal is to make this as portable as possible so it can be deployed in virtual machines, on personal computers etc. I will not start using amazon services even if they are dirt cheap and I know how to leverage them. I do not want this project to be locked on a specific cloud platform. "

Middlesex, GB??? - > i'm in montreal canada

about the source code: ansible playbooks have a structure, src folder is not gonna fly here. "split the client" -> there is no client

but I can probably improve the repository structure, yes.

And, if you want to be so "security hacker like nobody knows" > I have no such ambitions.

create fancy profile picture with no face > I don't see how if I choose to put my face online or not is relevant here.

Get a decent username no hash gabage > the hash garbage is a md5sum for the word "git", I don't have imagination.

Hide your WhoIs Information from the domain > On 17 May 2018 the ICANN Board adopted a Temporary Specification for gTLD Registration Data. https://www.icann.org/resources/board-material/resolutions-2...

Got I disapointed? Yeah > It is okay, I know the project is not quite secure it it's actual form (even if a put a bit of effort on the security side) it is a work in progress.

Would I trust this app even if the source code would be readable in any way > if you cannot read my source code, I highly doubt you'll be able to read the signal source code (which I looked at)

thanks for your comment.

peppermint_tea··on Show HN: SendFiles.online – Make a file into a URL quickly
the service works well, nothing to add :)

you still having issue ending up in spam even when using mailgun? (based on the disclaimer on your site). I dislike how emails are now filtered by some close source algorithm, and that even if you respect all the RFC's you might end up in spam, effectively hurting your legit email.

peppermint_tea··on Show HN: I Made a Chat Server
done
peppermint_tea··on Show HN: I Made a Chat Server
redeploying on a more beefy instance with 8G ram :)
peppermint_tea··on Show HN: I Made a Chat Server
got an out of memory :)

HN loved it too much, running this on a 5$ machine with 1G ram :)

it's back now

peppermint_tea··on Show HN: I Made a Chat Server
even if user i_found_you seems to be out, i'll address his concerns here :

thanks for your comment,

about my temporary choice for aws:

the reason is explained here : https://temporary.chat/qa.html

"I dont like your dns, registrar etc : took amazon for the ease of use and because I am familiar with it, but it is not my final choice, my goal is to make this as portable as possible so it can be deployed in virtual machines, on personal computers etc. I will not start using amazon services even if they are dirt cheap and I know how to leverage them. I do not want this project to be locked on a specific cloud platform. "

Middlesex, GB??? - > i'm in montreal canada

about the source code: ansible playbooks have a structure, src folder is not gonna fly here. "split the client" -> there is no client

but I can probably improve the repository structure, yes.

And, if you want to be so "security hacker like nobody knows" > I have no such ambitions.

Got I disapointed? Yeah > It is okay, I know the project is not quite secure it it's actual form (even if a put a bit of effort on the security side) it is a work in progress.

thanks for your comment.

peppermint_tea··on Show HN: I Made a Chat Server
first of all, apologies for the repost, a user commented on my original post that I should use "Show HN" so first and last time (or next time in 6 months, according to the guidelines).

preface : After my cellphone started having camera focus issues & fell in the river(with me), I got very annoyed with the QR code required by signal (I ended up resizing the QR code it in gimp, printing it out on paper, and scanning it with my half-dead phone to be able to re-link my computer to signal). I am still waiting for my Librem5 (yes I drank the cool aid).

going in the deep: I like to develop my own solutions in general instead of using existing technology (a.k.a i'm re-inventing the wheel)

My solution is not as good as signal and I know it. The two things that annoy me about signal is that [1]it requires a phone number and [2]it relies heavily on the domain whispersystems.org.

The good part about my app/server (I think) is that:

1 - you can host it at home and it does not even require a domain name. (you can deploy with bare ip)

2 - it is user friendly enough (GUI, pictures upload)

3 - encryption in transit is automatic (let's encrypt or self-sign)

4 - you can destroy conversations in one click

5 - you can choose many different modes of deployment (single room, multi room, per-room certificates, wildcard certificates etc(more to come))

6 - receiving notifications on PING only (more like slack with the @ or irc with the name... something signal lacks)

The bad parts about my app/server (I think) is that:

1 - notifications via rss are not ideal, but it is the best way I found to make that app/server as standalone as possible (no 3rd party api calls required after installation).

2 - I am a jack of all trades, master of none, so I am pretty sure you can point at everything I wrote in any language and find flaws (I don't consider myself a developper)

3 - everything in there is file based, so... speed, scale and inodes :)

4 - api is not complete nor nice at the moment (work in progress)

5 - real end to end encryption is not yet implemented (I will go with good ol' gpg here(not sure how yet, let's add more tuck tape)

6 - deployment process needs improvements. (I am the only one that deployed it so far but i'm sure it does)

Any feedback is welcome, you can also try to hack it and I will gladly provide assistance if you want to deploy your own instance.

I will probably need help to achieve this, but I would love to see this becoming a great product made by the people, for the people with little nodes all over the place.

Just like a phone number, you will know to reach your friend(s) at friends.domainx.com. with more savvy people hosting it for less savvy friends, so the data remains in the hands of people that know each others in real life instead of big corp$.

P.S : you can use the demo for quick file sharing and destroy the room after.

thank you for your time and (hopefully) interest!

peppermint_tea··on So I am creating a chat server
aahh, thanks, will do
peppermint_tea··on U.S. Used Patriot Act to Gather Logs of Website Visitors
yes, see how the collared rkelly accomplice here :

https://www.theregister.com/2020/10/09/google_search_arrest/

the judge are not supposed to allowed fishing expeditions, but in this case, the lookup requested was quite narrow. they still requested a search warrant.

peppermint_tea··on Deploy your own messaging system with file transfer at home (web based)
DISCLAIMER : This project is in development, I still have to add some security and features.

I started working on a personal project to create my own chat server (web based) that can be hosted pretty much everywhere (on ubuntu 20.04) (virtual machines, personal computers, public clouds, vps, bare metal at home, etc.) and that requires no client installation, just a browser.

it is now in beta but works for text and file sharing (up to 100M by default but you can change that)

the source code is here : https://github.com/ba9f11ecc3497d9993b933fdc2bd61e5/temporar... (see README.md and CONTRIBUTING.md )

deployments are done with ansible and 2 modes are available for now : single room and random rooms

rooms can be either public or password protected. All rooms are destroyable with a single click (a real destroy that actually remove the files.

Encryption is done by default either with let's encrypt (if you deploy on a domain or subdomain) or a certification authority where the key gets destroyed after the only certificate is created (if you deploy on an ip) (a helper page is created to show the fingerprint of the certificate and instruction per browser on how to install the cert)

I plan to add more deployment modes in the future (rooms with customized names, expert mode to submit gpg messages via an api)

screenshot of the chat page & landing pages can be found here :

https://imgur.com/a/vhiiy8j

or you can try it live at :

https://temporary.chat/

any enthusiasts that want to deploy one at home, any experts that want to point security flaws, any user that want to report a bug or a lack of features. Any UX experts that think I made a terrible job are more than welcome to comment. My mail address can be found in the repo.

Hopefully somebody else than me will see value in this project :)

thank you for reading!

← PreviousPage 4 of 4