HNHacker News
TopNewBestAskShowJobs

tony101

5,494 karma · joined April 23, 2015

submissionscomments
tony101··on Permission Slip: App to take back control of your data
From their FAQ:

“Permission Slip helps you exercise your right to privacy under the California Consumer Privacy Act (CCPA) by acting as your ‘authorized agent’ and sending data requests to companies for you.”

https://www.permissionslipcr.com/faq.php

The California Attorney General is monitoring companies’ compliance with authorized agent requests:

“The sweep also focuses on businesses that failed to process consumer requests submitted via an authorized agent, as required by the CCPA. Requests submitted by authorized agents include those sent by Permission Slip, a mobile application developed by Consumer Reports that allows consumers to send requests to opt-out and delete their personal information.”

https://oag.ca.gov/news/press-releases/ahead-data-privacy-da...

tony101··on Permission Slip: App to take back control of your data
Refer to https://digital-lab.consumerreports.org/2022/11/16/introduci...
tony101··on Secure messengers in war time
> “ 1. it is not free software”

What are you talking about?

https://github.com/signalapp/Signal-Android/blob/master/LICE...

https://github.com/signalapp/Signal-iOS/blob/master/LICENSE

https://github.com/signalapp/Signal-Server/blob/master/LICEN...

tony101··on We are seeing continued DDoS attacks against our infrastructure
ProtonMail managed to figure it out after the DDoS attack they faced 5 years ago:

https://protonmail.com/support/knowledge-base/email-ddos-pro...

tony101··on We are seeing continued DDoS attacks against our infrastructure
ProtonMail managed to figure it out after the DDoS attack they faced 5 years ago:

https://protonmail.com/support/knowledge-base/email-ddos-pro...

tony101··on Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
A reminder that you can pair lock your iPhone to prevent analysis by Cellebrite or similar tools: https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-wit...
tony101··on Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
I wonder if the intention here is to deter Cellebrite from parsing Signal files? Or to pressure them into fixing their security vulnerabilities?
tony101··on Effort to disrupt exploitation of Microsoft Exchange Server vulnerabilities
The warrant is actually quite specific, down to the exact URL paths of the shells to be searched and removed.

See pages 20 and 21 of https://www.justice.gov/opa/press-release/file/1386631/downl...

tony101··on Effort to disrupt exploitation of Microsoft Exchange Server vulnerabilities
Why would it not be a valid warrant? The web shells are evidence of a crime.

Also, the typical remedy for a defective warrant is suppression of seized evidence, not criminal prosecution.

tony101··on Effort to disrupt exploitation of Microsoft Exchange Server vulnerabilities
It is not a crime because they had a search warrant signed by a judge. https://www.justice.gov/opa/press-release/file/1386631/downl...
tony101··on Effort to disrupt exploitation of Microsoft Exchange Server vulnerabilities
No. "This warrant authorizes the use of remote access techniques to search the electronic storage media identified in Attachment A and to seize and copy from the electronic storage media identified in Attachment A the web shells, used by actors to communicate with and distribute files to victim computers to infect them with malware, as evidence and/or instrumentalities of the computer fraud and conspiracy in violation of Title 18, United States Code, Sections 1030(a)(2) (theft from a protected computer), 1030(a)(5)(A) (damage to a protected computer) and 371 (conspiracy). This authorization includes the use of remote access techniques to access the web shells and issue commands through the web shells to the software running on the electronic storage media to delete the web shells themselves.

This warrant does not authorize the seizure of any tangible property. Except as provided above, this warrant does not authorize the seizure or copying of any content from the electronic storage media identified in Attachment A or the alteration of the functionality of the electronic storage media identified in Attachment A."

https://www.justice.gov/opa/press-release/file/1386631/downl...

tony101··on Effort to disrupt exploitation of Microsoft Exchange Server vulnerabilities
Indeed, there is a search warrant signed by a judge: https://www.justice.gov/opa/press-release/file/1386631/downl...

See pages 18 to 21.

tony101··on Effort to disrupt exploitation of Microsoft Exchange Server vulnerabilities
Warrant signed by judge: https://www.justice.gov/opa/press-release/file/1386631/downl...

See pages 18 to 21.

This is a search. Specifically, the web shells are (1) evidence of a crime, (2) contraband, fruits of crime, or other items illegally possessed, and (3) property designed for use, intended for use, or used in committing a crime. Any one of these three would be a valid basis for a search warrant.

tony101··on Effort to disrupt exploitation of Microsoft Exchange Server vulnerabilities
Warrant signed by judge: https://www.justice.gov/opa/press-release/file/1386631/downl...

See pages 18 to 21.

tony101··on iOS 14 and Facebook Pixel causing increase in PSL inclusion requests
https://developer.apple.com/documentation/apptrackingtranspa...
tony101··on New HIV vaccine with a 97% antibody response rate in phase I human trials
False. Regular intercourse can transmit HIV, too.

https://www.cdc.gov/hiv/basics/hiv-transmission/ways-people-...

tony101··on Google Photos circumvents iOS 14 photos privacy features
iOS indeed allows users to specify which photos an app has access to.

https://www.techrepublic.com/article/how-to-use-the-limited-...

In this case, Google Photos detects this and blocks the user from using the app unless they get full access to everything.

tony101··on Google Photos circumvents iOS 14 photos privacy features
Apple App Store Review Guidelines, Section 5.1.1:

"(iv) Access: Apps must respect the user’s permission settings and not attempt to manipulate, trick, or force people to consent to unnecessary data access. For example, apps that include the ability to post photos to a social network must not also require microphone access before allowing the user to upload photos. Where possible, provide alternative solutions for users who don’t grant consent. For example, if a user declines to share Location, offer the ability to manually enter an address."

https://developer.apple.com/app-store/review/guidelines/#pri...

tony101··on Chrome’s address bar will use https:// by default
> "I'm all for HTTPS everywhere but right now for my products it's either: https with self-signed certificate, which basically makes any modern browser tell its user that they're in a very imminent danger of violent death should they decide to proceed, or just go with good old HTTP but then you hit all sorts of limitations, and obviously zero security."

How about what Plex did for its self-hosted media servers?

"First they solved the problem of servers not having a domain name or a stable IP (they are mostly reached via bare dynamic IPs or even local IPs) by setting up a dynamic DNS space under plex.direct"

"Then they partnered with Digicert to issue a wildcard certificate for *.HASH.plex.direct to each user, where HASH is - I guess - a hash of the user or server name/id."

"This way when a server first starts it asks for its wildcard certificate to be issued (which happened almost instantly for me) and then the client, instead of connecting to http://1.2.3.4:32400, connects to https://1-2-3-4.625d406a00ac415b978ddb368c0d1289.plex.direct... which resolves to the same IP, but with a domain name that matches the certificate that the server (and only that server, because of the hash) holds."

https://blog.filippo.io/how-plex-is-doing-https-for-all-its-...

tony101··on California Passes Regulation Banning "Dark Patterns" Under Landmark Privacy Law
The press release is specific and limited too:

"The newly-approved regulations ban so-called “dark patterns” that delay or obscure the process for opting out of the sale of personal information. Specifically, it prohibits companies from burdening consumers with confusing language or unnecessary steps such as forcing them to click through multiple screens or listen to reasons why they shouldn’t opt out."

https://oag.ca.gov/news/press-releases/attorney-general-bece...

tony101··on California Passes Regulation Banning "Dark Patterns" Under Landmark Privacy Law
That is not within the CA Attorney General's control. The statute (CCPA) specifies opt-out, not opt-in, for most consumers. (The exception is for children under 16, who get an opt-in process.)
tony101··on U.S. senators reintroduce bill to make daylight saving time permanent
It's the opposite problem where I live. With DST the sun does not rise until 8 AM.

In fact, in January, the sun rises here at 7:40 AM Standard Time. Which would be 8:40 AM Daylight Time.

It would be terrible to have to wake up an hour before sunrise.

tony101··on U.S. senators reintroduce bill to make daylight saving time permanent
I have the opposite problem where I live. With DST the sun does not rise until 8 AM.

In fact, in January, the sun rises here at 7:40 AM Standard Time. Which would be 8:40 AM Daylight Time.

It would be terrible to have to wake up an hour before sunrise.

tony101··on U.S. senators reintroduce bill to make daylight saving time permanent
I have the opposite problem where I live. With DST the sun does not rise until 8 AM.

In fact, in January, the sun rises here at 7:40 AM Standard Time. Which would be 8:40 AM Daylight Time.

It would be terrible to have to wake up an hour before sunrise.

tony101··on U.S. senators reintroduce bill to make daylight saving time permanent
How about we do it the other way: Eliminate daylight saving time and make standard time permanent?
tony101··on Bitcoin Is Time
Transfer funds across borders without dealing with multi-business-day bank delays or capital controls in countries like China. Accept donations or other online transactions without relying on Visa/Mastercard.
tony101··on Why hot new social app Clubhouse spells nothing but trouble
"A generous friend had a few invitations to extend, and she offered me one. After that, she had an attack of what one can only describe as donor’s remorse, because in order to be able to extend the invitation to me she had to grant Clubhouse access to all her contacts!"

This does not appear to be in compliance with privacy laws such as GDPR.

tony101··on Coinbase valued above $100B, ahead of direct listing
I'm not assuming that. I said "it's not perfect" and simply listed the security measures that I am aware of :)
tony101··on Coinbase valued above $100B, ahead of direct listing
It's not perfect, but I believe Coinbase uses a combination of cold (offline) storage for most of its coins and insurance for the rest. Also, as you probably already know, people should not hold large sums on exchanges if they can use secure their own keys (and wallets) instead.

> "Coinbase prioritizes the security of our customer's digital currency through a combination of online “hot storage” and offline “cold” storage. Coinbase maintains 98% or more of customer digital currency in cold storage, with the remainder in secure hot servers as necessary to serve the liquidity needs of our customers. All digital currency that Coinbase holds in its online hot storage is insured. If Coinbase were to suffer a breach of its online hot storage, the insurance policy would pay out to cover any customer funds lost as a result."

https://help.coinbase.com/en/coinbase/other-topics/legal-pol...

tony101··on Police playing music while being filmed, seemingly to trigger copyright filters
> The real problem here is that there is no consequence for incorrect takedowns. If content is taken down and then it turns out to be fair use, no one suffers a penalty.

There are exceptions to this. See Lenz v. Universal Music Corp., 801 F.3d 1126 (9th Cir. 2015).

"Lenz v. Universal Music Corp., 801 F.3d 1126 (9th Cir. 2015), is a decision by the United States Court of Appeals for the Ninth Circuit, affirming the ruling in 2008 of the US District Court for the Northern District of California, holding that copyright holders must consider fair use in good faith before issuing a takedown notice for content posted on the Internet."

https://en.wikipedia.org/wiki/Lenz_v._Universal_Music_Corp.

"In ... Lenz v. Universal Music Corp., decided by the Ninth Circuit on September 14, 2015, a mother's 29-second home video of her two toddlers dancing to Prince's 1984 song "Let's Go Crazy" has made important new law with respect to "takedown notices" under the Digital Millennium Copyright Act ("DMCA"), holding that copyright holders must consider fair use before sending a takedown notification. This decision increases the potential liability for copyright holders seeking to enforce their rights through the DMCA and should serve as a warning to ensure fair use is considered before sending a takedown notice."

https://www.jonesday.com/en/insights/2015/09/ninth-circuit-s...

Page 1 of 13Next →