HNHacker News
TopNewBestAskShowJobs

rlk

31 karma · joined September 3, 2015

submissionscomments
rlk··on Dropbox's Jan 1st 2027 terms of service
Looks like the major changes are:

- some stuff about Teams that's mostly only relevant if you're using your work email for a personal account

- minimium age 13 -> 18; add "Dropbox may use and rely on information from third parties, including age signals from app stores, for the purpose of enforcing this restriction."

- free accounts may be terminated after 6 months of no use (previously 12 months)

- removed "If you reside in the EU, the European Commission provides for an online dispute resolution platform, which you can access here: https://ec.europa.eu/consumers/odr." from the dispute resolution process.

rlk··on Montana referendum to outlaw corporate campaign contributions [video]
I couldn't find a link to the ballot initiative itself anywhere on the campaign's website, but this appears to be it:

https://sosmt.gov/wp-admin/admin-ajax.php?juwpfisadmin=false...

Linked from here if the above URL stops working: https://sosmt.gov/elections/ballot_issues/proposed-2026-ball...

rlk··on 301party.com: Intentionally open redirect
I found a couple of fun tricks you can do with this (for some definition of "fun" anyway).

Go's http.Redirect function allows non-3xx statuses, and also renders a trivial page with a status message and link:

https://301party.com/451?url=javascript:alert(%27hello%27)

Alas not infinitely recursive but enough to make your browser give up:

https://301party.com/301?url=/301?url=/301?url=/301?url=/301...

[edit to add:] https://301party.com/0 causes a panic

rlk··on Why does storing 2FA codes in your password manager make sense?
There are a couple of differences:

1. While a password manager should associate a TOTP seed with a domain and only fill codes on that domain, the codes are still visible to you. A convincing phishing attack might trick you into manually entering a code into a fake page. Passkeys don't allow this.

2. TOTP codes are derived from a seed shared between the client and server, so an attacker who gets read access to the server's database could generate your codes. With passkeys, the server can only validate a signature, not generate them.

rlk··on Fly Machines: An API for Fast-Booting VMs
> Sex workers, who have long been censored by moderation systems, refer to themselves on TikTok as “accountants”

https://www.washingtonpost.com/technology/2022/04/08/algospe...

rlk··on Tailscale Authentication for Minecraft
Minecraft authentication requires a Microsoft account. People may not want to have one for ideological reasons, or not want to attach a game to the account they use for other purposes.

Also, not encouraging it, but disabling authentication allows players with pirated copies of MC to play on the server

rlk··on Show HN: Cryptochat, encrypted P2P chat over ICMP
It's a neat idea, but I hope nobody uses it for anything actually sensitive until the crypto is fixed:

The app uses counter mode encryption with no nonce. In counter mode, the encryption process uses a stream of pseudo-random bytes generated by encrypting an incrementing counter with the secret key. The message is then XORed against this keystream.

For this to be secure, you need the keystream to be different for each message. Otherwise, if you have multiple messages where the plaintext is XORed against the same keystream, you can take the XOR of any two ciphertexts, and you have:

    C1 ^ C2 = (P1 ^ K) ^ (P2 ^ K)
            = (P1 ^ P2) ^ (K ^ K)
            = (P1 ^ P2) ^ 0
            = P1 ^ P2
And now you can break that by statistical techniques, or just trial and error.

(Obligatory crypto challenges link: http://cryptopals.com/sets/3/ )