HNHacker News
TopNewBestAskShowJobs

ryanl0l

86 karma · joined April 12, 2016

https://news.ycombinator.com/user?id=ryanlol
submissionscomments
ryanl0l··on Microsoft criticized for changing the pop-up box encouraging users to upgrade
Perhaps you should be running the LTS version then?
ryanl0l··on The Tor Project: Building the Next Generation of Onion Services
By spending 5 seconds on google, or alternatively by using your intuition.

Googling "hidden service multiple ports" instantly answers every single one of your questions, and the answers are rather obvious.

Who would've thought that adding a new port is as easy as just adding another port definition?

Honestly, if this is a problem you shouldn't be trying to host hidden services by yourself anyway. Even if Tor took literally one click to set up the other software will still fuck you, like apaches mod-status.

ryanl0l··on Australia’s Offshore Cruelty
Are you saying Australia would be immune to the same problems certain places in Europe, i.e. Rinkeby, are experiencing?
ryanl0l··on Microsoft criticized for changing the pop-up box encouraging users to upgrade
Why is windows 10 a shitty product?

Why is windows 7 a good product?

ryanl0l··on Facebook admits rogue employees may have shown bias against conservatives
Without bias how do you pick your stories? Without bias how do you pick your sources? Bias towards official sources is ubiquitous.

Bias is an integral part of journalism, it's up to the reader to understand this fact and collect information from multiple sources (if they're so inclined).

ryanl0l··on The Tor Project: Building the Next Generation of Onion Services
The Tor hidden service setup process seems extremely simple to me.

First google result I get for "tor hidden service instructions" is https://www.torproject.org/docs/tor-hidden-service.html.en which explains the two config lines you need to add to create a hidden service

Literally all you have to do is add this into your config file.

  HiddenServiceDir /hidden/service/path
  HiddenServicePort $EXTERNALPORT $INTERNALIP:$INTERNALPORT
If you're hosting anything at all this shouldn't be even remotely difficult.
ryanl0l··on Telsa Driver Caught Napping *While Driving* – Presumably Using Autopilot
And this is probably still significantly safer than your typical commuter.
ryanl0l··on BCHS Stack - BSD, C, Httpd, SQLite
>The amount of arrogance here is astounding. For one thing it's a trope that Linux doesn't have good documentation, RHEL has better docs than anything I've seen from BSD

I think you'll have to accept that many people simply don't agree with your opinion here.

ryanl0l··on Microsoft criticized for changing the pop-up box encouraging users to upgrade
Should MS just wait until those people get their bank accounts emptied and their data held for ransom?

This seems like the nicer option.

ryanl0l··on Microsoft criticized for changing the pop-up box encouraging users to upgrade
Maybe if you wanted a stable OS you should be running the LTS version instead.
ryanl0l··on Microsoft criticized for changing the pop-up box encouraging users to upgrade
>What is a bigger threat to your machine's security than not being able to use it at all?

What kind of a threat is that?

Is your computer worth more than the contents of your bank account?

ryanl0l··on Microsoft criticized for changing the pop-up box encouraging users to upgrade
So do you honestly believe that upgrading away from windows 7 somehow hurts security?
ryanl0l··on The Secret of Billions
No, it isn't.
ryanl0l··on Netflix launches its own speed test website, Fast.com
For, you know, commenting?
ryanl0l··on Roundcube Webmail 1.2.0 released with PGP support
Sure, but I'd imagine that most email traffic is automated non-sensitive stuff (i.e. flight confirmations for example). That stuff is simply not going to be e2e encrypted any time soon, if ever.

Are people going to start filling in their pubkeys when they book a flight? What about when they're at the airport and need to pull up the record locator on a different device?

I'm sure more emails will start being encrypted, but that'll mostly be communications between people. Those probably aren't particularly interesting to google anyway.

ryanl0l··on Netflix launches its own speed test website, Fast.com
As if that's not intentionally completely obvious? I've never voted on anything on this account, or on anything posted by this account.

Anyhow, if you find my behaviour disagreeable may I suggest shooting an email to hn@ycombinator.com

ryanl0l··on TOTP SSH port fluxing
>Nmap is pretty darn fast if you disable feature detection!

No it isn't, nmap is ridiculously slow no matter what you do.

The only thing it does well is version detection, but you can do that too way faster.

If you specifically need nmaps version detection, sure use it. Otherwise you might be better off using masscan, it tends to do a pretty good job even with the default banner grabbing.

ryanl0l··on Netflix launches its own speed test website, Fast.com
Netflix pays fixed licensing fees, giving them money certainly isn't going to do much to help those lighting technicians and sound engineers very much.

Perhaps those lighting technicians and sound engineers should just leave the industry that insists upon making it ridiculously difficult to give them money, if I want to get a high quality digital copy of a movie or TV series the only option is logging into BTN or PTP and grabbing a bluray remux.

Hell, often these communities have content available at a significantly higher quality than any of the official releases. See DIMENSIONs 20GB mad men episodes for example.

I personally just frequent the cinemas, and try to pay for the few TV series that I can, despite it often being impossible here.

ryanl0l··on Roundcube Webmail 1.2.0 released with PGP support
>They couldn't. They would have to show ads from other history and not the email's contents. This would also break features such as (server-side) search and reminders (eg. flight tomorrow) via Google Now.

Sure they could, all incoming emails aren't magically going to become e2e encrypted.

ryanl0l··on $12M stolen from 1,400 convenience store ATMs across Japan in 2 hours
A more accurate title would probably be "120M stolen from hacked South African bank via 1,400 convenience store ATMs across Japan"
ryanl0l··on FBI Harassing Core Tor Developer, Demand Meeting, but Refusing to Explain Why
It's obvious that the FBI isn't trying to serve a NSL here. If that's what they wanted to do, they'd have done it.
ryanl0l··on FBI Harassing Core Tor Developer, Demand Meeting, but Refusing to Explain Why
>They absolutely affect the validity if people claim non-receipt. Subpoenaing cooperative people is easy - you use mail, or email, or whatever you want and they acknowledge the thing and respond. That's why email is common.

I'm well aware that it's easier to claim non-receipt, but that has no effect on the validity of the subpoena. An emailed subpoena is still valid.

>So hand-served (and signed letter) subpoenas remain relevant for when people are dodging you. The fact that many people do respond to email subpoenas doesn't relate to whether non-respondents can be charged for their failure.

I never claimed they don't, all I claimed was that email is a valid way of delivering subpoenas.

And I'm sure non-respondents can be charged for their failure if it can be proven that they actually saw the subpoena. Not all illegal activities are easy to prosecute.

ryanl0l··on FBI Harassing Core Tor Developer, Demand Meeting, but Refusing to Explain Why
The method of delivery doesn't really have any bearing on the validity of the subpoena, however with some methods it may be easier for the recipient to fraudulently claim that they didn't receive it.

I'm sure they'll use alternate methods if the emails are ignored.

ryanl0l··on FBI Harassing Core Tor Developer, Demand Meeting, but Refusing to Explain Why
I'm aware of exit nodes as I've myself been subject to such attention, but I don't think that really fits chinathrows description.
ryanl0l··on FBI Harassing Core Tor Developer, Demand Meeting, but Refusing to Explain Why
Based on my read of her blog post there was nothing stopping the FBI from doing just that while she was in the US.

It'll definitely be very easy for them to do that if she ever wants to enter the US in the future.

ryanl0l··on FBI Harassing Core Tor Developer, Demand Meeting, but Refusing to Explain Why
There's no need to prove that the subpoena was delivered unless the recipient claims otherwise. Email is regularly used to deliver subpoenas (in fact, it's probably the most common way to deliver them).

Quick google found several public examples of such subpoenas, like https://cock.li/transparency/2015-12-15-subpoena/00-2015-12-...

And in any case, if the recipient fraudulently claimed that they had not received the subpoena they'd be committing crime.

Edit: Am I wrong? Is the subpoena I linked a fake?

ryanl0l··on Steam now accepts Bitcoin for purchases
>Then why does it only happen using bitcoin?

Because some people insist on waiting for the payment to settle before actually providing the services, although it's not nearly as common as it used to be.

This is just completely unrealistic with credit cards where settlement times are far longer than with bitcoin, days or months.

>Wherever you want to lay the blame (anywhere but bitcoin) it's a problem for anyone using bitcoin, making it more useless than (not "immensely superior" to, as claimed) using a credit card or Paypal, which makes it a problem for bitcoin.

I don't know, I use bitcoins to pay for things regularly and pretty much everyone accepts zero-confirmation transactions nowadays (which is pretty much the same as accepting credit card payments, except the settlement will most likely take less than an hour).

ryanl0l··on Steam now accepts Bitcoin for purchases
Exactly like bitcoin payments then, except bitcoin settlements only take hours.
ryanl0l··on Namecheap live chat social engineering leads to loss of 2 VPS
Most will require a password reset email, I'd say that's significantly better than asking for ID scans.

Edit: Since I'm getting some downvotes I'd really like to know how one could possibly argue that asking for ID scans is better than email resets. You can't really forge the ability to receive email at an address, but you can very easily replace the name on an ID scan.

ryanl0l··on Namecheap live chat social engineering leads to loss of 2 VPS
>Also let me reiterate this is an isolated event.

Is it? Does that mean that my ability to reset your users solusvm passwords with or without 2fa constitutes as a 1337 0day?

Hey BTW, remember that time you got hacked through your support site and didn't tell anyone?

← PreviousPage 2 of 2