HNHacker News
TopNewBestAskShowJobs

safeplanet-fesa

78 karma · joined May 29, 2019

submissionscomments
safeplanet-fesa··on NordVPN confirms it was hacked
Over the course of the disclosure of the connection between NordVPN, Tesonet, and possibly ProtonVPN, Proton's story kept changing. They said contradicting things multiple times. They locked the Reddit thread. Why did Proton keep changing their story if they had nothing to hide? I will keep reminding this every time the issue gets raised. There is a compilation [0] of changing Proton's responses and them successively admitting more and more things not in their favor. The compilation starts at the part called "Online accusations fly".

[0] https://restoreprivacy.com/lawsuit-names-nordvpn-tesonet/

safeplanet-fesa··on NordVPN confirms it was hacked
What about the data-mining and selling infrastructure of NordVPN, known as Tesonet? Are those intact? Also interesting to know how their legal departments are doing, such as the Panamanian shell and the Lithuanian headquarters.

http://vpnscam.com/wp-content/uploads/2018/08/2018-08-24-09_...

http://vpnscam.com/hola-vpn-and-nordvpn-partners-in-data-min...

http://vpnscam.com/nordvpn-protonvpn-proton-mail-owned-by-te...

safeplanet-fesa··on Chrome 77 Breaking Drag and Drop Events
Jokes on them, I still use Chromium 67 from chromium.woolyss.com. It's the last version before WebRTC became unremovable. Now it's impossible to download this version, only the new ones. Woolyss should have kept it, like they keep Chromium 49, the last version before Chromium stopped running on XP and Vista. And I understand the risks of running an obsolete version, but it's a trade-off. For some time I was thinking of updating it, but then Google came up with lots of anti-consumer browser-crippling features.
safeplanet-fesa··on VPN⁰: A Privacy-Preserving Distributed VPN
I'm not willing to really try to prove that BAT embedded in Brave is a fundamentally flawed project. Because there are so many project of this kind in the current blockchain industry that I dislike very much, that I don't have enough time and motivation to dispute every such project. People who see what kind of clownade current blockchain industry is, will see it on their own. Those who don't think so, I don't want to convince (I tried before a lot, but marketing of big "blockchain" projects overpowers any words of a couple of geeks).

1. The power of blockchain is in its cryptographic strength. Without cryptographic strength a blockchain is worthless. Strength of a system is defined by the weakest link. The weak link of Brave + BAT is in inability to mathematically prove an ad view. Neither there is a known way to cryptographically mine coins by viewing ads. This means, there are no cryptographically secure methods to pay for ads. What you made is a program that displays an ad and ask your server to send coins to the user. Of course, this can be spoofed. Hackers can reverse engineer how Brave communicates with your backend and spoof it. There is no cryptographic way to prove that an ad has been shown. Hackers can make the windows with ads invisible etc, and still receive reward. And I'm sure they are doing it, but as long as spoofing rates are within your business model, you don't mind because everyone is making money and you don't want to ruin the party.

2. I'm not a proponent of Bitcoin particularly. I dislike everyone who creates a new coin for a fake reason, for something that doesn't need a new coin and issues a trillion tokens. I am for progress, and I don't mind when a new really innovative coins appears with a separate blockchain, but I hate when a new coin is created just to issue a trillion of tokens, give it away for free, and in this way giving it perceivable value. It at least must be mined, and some resources (electricity and hardware) must be spent to back up its value; a trillion token issued out of nothing don't have value. I would not care if it was just a silly useless project, which GitHub is full of, but there is an irresistible temptation to create a heap of tokens, keep a little bit, give the rest away, apply some sleazy marketing and make people believe that there is some value behind the tokens. A decent project must avoid at all cost creation of a new token without a reason that absolutely requires a new token, and instead use an existing token that has value behind it (resources are being spent on creation of that heap of digital money).

I always liked blockchain, I will always like it. I use Monero much. But the current blockchain industry is full of projects that are fake blockchains, centralized blockchains and especially systems where a blockchain and a product cannot be cryptographically linked. Such as reselling electricity through blockchain, track fruits from a farm to a shop through blockchain etc. I only don't understand if people pretend that they don't see this because everyone has a share in the growing industry, or they are really so stupid that they don't see the fundamental problem.

safeplanet-fesa··on VPN⁰: A Privacy-Preserving Distributed VPN
Exactly. I am a big hater of everything that even remotely feels like a shitcoin. BAT is a silly useless project; I would not hate it if there was no conflict of interests, even if it's a silly project; but there is a huge conflict of interest - the developers want to make money out of thin air by issuing their tokens.

I already wrote this before in another comment. Basic Attention Token is not a secure cryptographic system. The idea to pay tokens for shown ads cannot be cryptographically secure. There is no known way to have a cryptographically strong "Proof-of-Watch". All that browser does is, when a user watches an ad, it communicates to its backend and asks the backend to send a token to an address attached to the user. It's not a cryptographic system that mines coins by showing ads.

It's a useless gimmick that has nothing to do with cryptocurrency. The real coins are so valuable because they are cryptographically strong. This thing is centralized and its mechanism of payments for ad views is not cryptographically strong. The token has some value only because of peoples' stupidity.

safeplanet-fesa··on Clarifying ProtonMail and Huawei
The best way to learn about the incident is to read the discussions first-hand from the Hacker News, for example, by searching "inurl:ycombinator protonvpn tesonet". There is no point in reading any journalistic articles if you can read Proton's responses here, except one article [0] - a compilation of changing Proton's responses and them successively admitting more and more things not in their favor. The compilation starts at the part called "Online accusations fly".

[0] https://restoreprivacy.com/lawsuit-names-nordvpn-tesonet/

safeplanet-fesa··on Everything I googled in a week as a professional software engineer
I use "inurl:ycombinator", saves even more time when typing manually.
safeplanet-fesa··on Want 1.5TB of RAM in Your PC? It Will Cost You
I have an even broader question: why do articles talking about some subject, have a random image representing the subject attached? For example, if an article talks about coffee, there will be a picture of a random cup of coffee or a random coffee tree field. I have never understood the point of it, but this has always existed in all forms of journalism.
safeplanet-fesa··on Driving an Ambulance in the Age of Narcan
I agree, drug withdrawal is painful with opioids and unbearably hellish is GABAergics, and quitting can be very hard. But having purpose in life is what defines if one will stay clean forever or will relapse time after time. I can also add that some people no matter of their actual conditions just don't have any meaning in life and they don't have any drive to participate in the routine and maintain proper life because they either have poor chances for good life or simply because they never asked to be born. Probably the strongest urge to use a drug comes, in fact, from boredom. Some people just need to kill time. To get by from the morning till the evening, when they can go to bed and sleep.
safeplanet-fesa··on Ask HN: What software do you pay for personally?
It's wise of you not to trust the ratings. Practically all VPN provider rating websites give those score based purely of their affiliate fees [0]. I would recommend not to purchase any subscriptions. This whole "VPN for privacy" thing more and more looks like a meme created by the industry of useless entities that resell bandwidth. It's a very profitable industry because they do nothing but receive money, they don't protect you legally either; those who lie about their no-logs policy, without hesitation give your data away to the law enforcement agencies.

[0] http://vpnscam.com/is-purevpn-legit-proof-that-purevpn-bough...

safeplanet-fesa··on Ask HN: What software do you pay for personally?
I meant that using some paid VPN for privacy is not recommended because in most cases it doesn't improve privacy, only costs money. Obviously, there is nothing wrong with connecting to your own VPN server at home when you are away, in order to access your local network, or if you want want to browse Internet through your home ISP instead of your mobile ISP.

Now, if using paid VPN providers is just a useless advice, possibly partially spread by the VPN industry, using NordVPN is very harmful because it seems to be one of the least trustworthy VPN providers because of their close connections with the data mining industry. NordVPN seems to be the №1 because of their immense advertisement spendings that bury the controversy.

safeplanet-fesa··on Driving an Ambulance in the Age of Narcan
I strongly believe that calling medications by their brand name is a bad idea. It's marketing departments' work to put into peoples' heads their stupid and annoying brand names. They want people to seek %brand_name% rather than %chemical_name%. They want people not even to know actual names of the chemicals. It's so widespread that people start thinking that medications called by their brand names are more effective than their generics. Companies that produce and sell generics have to write on the packages "compares to the active ingredient of %brand_name%™" otherwise people will not buy it. People don't know what diphenhydramine is, they only know B......l, and it's the only antihistamine they know. For that reason, when two exactly same medications are located at the counter right next to each other, one plain small adequately-looking box with a generic, and another one is a colorful oversized stupidly-named box with words "ultra", "fast", "extra", that easily costs 3 times more, people go for the later. Don't propagate this practice.
safeplanet-fesa··on Ask HN: What software do you pay for personally?
NordVPN is a data mining fraud, that is inadequately aggressively advertised from every corner, that owns many websites with VPN rankings, that lies about being in Panama, that decreases your privacy much by retaining logs. The only valid reason to use it would be to avoid geo-blocking. If you use NordVPN for any other reason (such as, for privacy), you have been fooled, unfortunately. If you find this comment helpful, help others by informing them.

Besides that, try to read some writes about why you should not to use any VPN services. It's easy to find promotional articles of various VPN providers about how they enhance your privacy, but instead try to look for arguments against. Only if you live in an very oppressive country and trust someone without name your exit point more, than your ISP (not sarcasm), or if you want to bypass geo-blocking, it makes sense to use VPN providers. Otherwise, you are harming your privacy and paying for an overpriced service to someone who does nothing but resells bandwidth and studies your traffic.

safeplanet-fesa··on If you must run Windows 10
You can also search for *.etl files to find what is traced. There are Autologger and GlobalLogger for live kernel tracing. Some of the tracing entries are present by default, but others are added by Intel's drivers! I could not control my anger when I discovered it. And it's not the .sys files, but the .inf files that add entries to Autologger. Now if I need to install Intel's drivers I first clean the .inf files. It ruins driver's signature of course, but at least I will not have any tracing sessions constantly written to disk.
safeplanet-fesa··on YouTube should stop recommending garbage videos to users
I use my current YouTube account for two and a half years. In this time period I clicked "Not interested" in the right sidebar with suggestions around 3000 times - very many times, and I keep clicking it. Due to this huge effort, when I watch videos of my interest scope, I mostly receive good suggestions and I'm satisfied with the suggestion system; however when I occasionally watch something unusual to me, I do receive bad suggestions and I keep clicking "Not interested". But already for a year I have not been suggested any "TOP 10 LIFEHACKS", reaction videos of obnoxious clowns, no previews with useless arrows and circles, O-faces, social experiments and pop-music from YouTube's Trending. Whenever I sometimes open YouTube from another computer, I fall into such deep disgust that my face expression twists. Another thing not related to this: I still use old YouTube's theme, it's faster and looks better than this modern "polymer" for touchscreens.
safeplanet-fesa··on What happens when you launch Google Chrome for the first time?
I think that it's shady too. I don't know much about Brave and don't want to know. To me a huge red flag is that Brave tries to push its Basic Attention Token (BAT). BAT is a token of low quality because of the following reasons.

1. The developers try to make up a reason to create another coin for something, that doesn't need a coin; 2. The relationship between the browser and the coin is not cryptographically strong and will never be — it's impossible to prevent fraud when their system is just a program that checks for certain condition (an ad viewed) and communicates to its backend, instructing it to give some address a coin. 3. The developers created a billion of tokens out of thin air and now try to give it some value. And traders do believe that it has some value.

I personally don't tolerate shitcoins even the slightest. Thus, I see Brave as nothing, but a browser engine with a content filter and a shitcoin embedded.

safeplanet-fesa··on Kaspersky in the Middle – what could possibly go wrong?
I had to help some regular computer user to clean their computer; one of the user's requests was to "fix" their McAfee, meaning, to update the subscription and solve other "security threats" (not viruses) that McAfee reported. After seeing how indecent this antivirus is, how it uses real intimidation, and is very intrusive with constant pop-ups, we settled on not continuing the subscription and getting rid of it altogether.
safeplanet-fesa··on It's Never Too Late to Be Successful and Happy
The society will not like your attitude; expect to experience continuous peer pressure. Nearly everyone is hard-coded with the unconditional "never give up", "hope dies last" and so on. The common arguments "might as well make the best out of it", together with the anti-suicidal "if you are going to die, sell everything and give your life another chance", I find annoying. All attempts require efforts. Sometimes you know in advance that a reward will not justify an effort, sometimes it's a giant gamble of many years and you decide not to take the risk. I don't want to put an unbearable burden onto myself only to end up regretting it in the end, where I will know that I inflicted the pain of all efforts and the pain of the final defeat with my own hands. When you know that you could've idled while being sufficiently content and happy with your "unsuccessful" level, but you succumbed to momentary inebriation of inspiration and drove yourself into a trap where you are not happy with your prospects, but you don't want to give up because you already invested much efforts. Because of their inexhaustible fountain of optimism people tend to ignore that efforts are unpleasant, and one cannot sign oneself up to a giant contract of work just because muh "might as well make the best out of it".
safeplanet-fesa··on ‘Fingerprinting’ to Track Us Online Is on the Rise
Big online journals in terms of tracking are the worst. At the moment every big online journal is worse than any overpriced boutique shop that uses all kinds of filthy upselling techniques (fake discounts, spam, bait and switch, shaming etc) including tracking. They even register and submit mouse events of hovering it over some element, they appear to submit time duration of how long a part of a page was within your viewport. If you don't use any preventive measures, they will keep sending telemetry regularly as long as the page is open. The inadequate amounts of tracking scripts increase traffic by much and noticeably increase CPU consumption. Even without any throughout investigation, if you use some local extension that displays the amount of blocked scripts / DOM elements / requests, you will notice that online journals are always further ahead than any other website.

Thus, the article is written only for the purpose of profiteering on the current increased concerns of online tracking. It doesn't try to resolve the issue even a little.

safeplanet-fesa··on NordVPN sued by Torguard for blackmail [pdf]
I used to be one using and praising ProtonMail, but after the Tesonet scandal turned me around. The worst evidence for me was their responses, how they were constantly calling it a "smear campaign by PIA", often not providing any plausible explanations. Duh, PIA published it and put work into raising public awareness. They are competitors, they found your dirty laundry and published it, duuuuh. Whoever discovered it, doesn't matter, they couldn't respond to the actual facts, only repeating the annoying combination of words "smear campaign". I don't trust a single VPN provider and would rather trust my exit point to my ISP which is regulated by local laws, rather then trusting it to god know whom god knows where. I would be happy to see the issues of Tesonet and their links to NordVPN and ProtonMail/VPN raised again!
safeplanet-fesa··on NordVPN sued by Torguard for blackmail [pdf]
Likely, in Lithuania, where they are subject to data retention laws, which means they are obliged to keep data for 6 month. I can suggest to search for "NordVPN Tesonet", the scandal that happened a year ago or so. The data mining possibility is horrible on its own, but Reddit and Hacker News users have discovered much more on the way. Everything is already said and exposed, hard to believe how much influence in general media they have that they could bury the whole story.
safeplanet-fesa··on NordVPN sued by Torguard for blackmail [pdf]
NordVPN is one of the ugliest in the on its own shady VPN business. They did their best to slowly make the Tesonet scandal slide away. Here on HN some users provided extensive insights about their connections with the Lithuanian data mining company and convincingly demonstrated that NordVPN must be the most evil VPN honeypot and deceiver.