HNHacker News
TopNewBestAskShowJobs

tryauuum

999 karma · joined October 3, 2018

submissionscomments
tryauuum··on Meta Blocks President Lula's Facebook Page, Campaign Ads 2 Weeks from Election
it's a part of internet. To properly block it, you need to block it on the IP level
tryauuum··on Meta Blocks President Lula's Facebook Page, Campaign Ads 2 Weeks from Election
It feels like your treat the facebook as some common good, and censorship made by it thus preposterous, something which should be punished

But it's a multimillion dollar corporation in a foreign country, to me the idea they owe you something is strange

---

Governments are still more powerful than corporations, this is why I am more afraid of the censorship of the internet by governments than of it by corporations

tryauuum··on Meta Blocks President Lula's Facebook Page, Campaign Ads 2 Weeks from Election
how do you block access to it without going to TCP/IP level? And when governments do that, everything goes to shit
tryauuum··on Meta Blocks President Lula's Facebook Page, Campaign Ads 2 Weeks from Election
Yes, this would be a better outcome. Or at least make it illegal for politicians to use facebook / TikTok

From where I am, one third of politicians in recent elections have tiktok. It's a shame, everyone knows about human rights violation in China but the european politicians have no issues with using tiktok.

tryauuum··on Meta Blocks President Lula's Facebook Page, Campaign Ads 2 Weeks from Election
nothing good usually comes out of governments censoring internet
tryauuum··on google.com/goto: Google's anti-scraping update
there was a source code leak and you can see some examples there which make the president's image more alluring. e.g. if you search for "Putin" they add an invisible "-crab" to your query

that's the most innocent example from the top of my head. There probably are many more serious censorship issues

tryauuum··on google.com/goto: Google's anti-scraping update
I wish yandex worked well, but the enshittification wave reached it too. It used to have such a great reverse image search, now it's useless
tryauuum··on Shopify is moving from React Native back to Swift and Kotlin
evaporating it so it's relocated somewhere else. Damn clouds
tryauuum··on Ask HN: Would you read a statistics textbook?
yes
tryauuum··on QBittorrent breaks out of sandbox to commit crimes
is there anything decent actually which is not on the internet? I thought it's an outdated place
tryauuum··on Github: Unauthenticated clone of a public repo intermittently returns 401
so true
tryauuum··on When Claude Code went rogue, years of Bengaluru heritage work disappeared
nice to see ai making the same mistakes as I did
tryauuum··on GitHub Outage Tracker: Is GitHub Cooked?
Please don't do it. Now somebody will come and will try to improve your bread analogy. We will be discussing bread for eons
tryauuum··on Was modern art a CIA psy-op? (2020)
I think it a reference to "default city" from the russian internet, when people noticed that people from Moscow never specify the city when talking about topics which would normally require knowledge of which city are they residents of

Eventually it evolved, sometimes people say "hey, I'm from DC" or "hey, I live in DC2" (that means the second largest city, Saint-Petersburg)

tryauuum··on We have launched "Nobody is Clean Challenge"
The page doesn't tell what the product does aside from "cleanness check". Of course my website is not "clean", who would want a clean white page for a website?
tryauuum··on IBM Simon (1994): the original smartphone, explained in its own ad [video]
man the woman in the video says "you got to try it to believe it", didn't you hear it
tryauuum··on Incident with Github.com
Have your seen safe_sleep.sh?
tryauuum··on Single log line is 49KB+ (ext4) / 110KB+ (btrfs) of systemd-journald disk writes
hello ValdikSS! nice to see you alive
tryauuum··on Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86
Doesn't this one need it as well? I see the shadow mmu
tryauuum··on More Tailscale tricks for your jailbroken Kindle
ah, to live in a country where the government doesn't block wireguard packets
tryauuum··on Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages
no, I mean the attacker boots his own copy of Windows or Ubuntu, which is supposedly trusted by the UEFI keys. Will tpm somehow detect that it shouldn't unlock secrets for this boot?
tryauuum··on Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages
It all weird still

Suppose the physical attacker doesn't reset the bios. He boots Ubuntu or any other os which is signed. Will the tpm unlock and give out the key? I guess it depends on the setup and it's possible to unlock only on your own signed kernel but I doubt this is a default?

tryauuum··on Ubuntu's TPM encryption switches to snap kernel that blocks deb kernel packages
holy hell! snap-based kernel

can someone explain like I'm 5, what's the point of during storing disk encryption keys in TPM? What kind of attack or attacker do we protect from?

my logic is following: - if the attacker is remote and somehow modifies my kernel... Yes, the tpm and hardware attestation (is this the term?) would have saved me. But I'm fucked anyway since the attacker already has root on my computer

- if the attacker is local -- yes, with tpm they cannot steal just the hard drive and bruteforce it offline. But they can just reset bios and install their own os and trick me into typing the os passwords? Or even if they cannot trick me (hard to spoof my os UI) they can just install a physical keylogger?

tryauuum··on Half a Second – a book about the XZ backdoor
So Microsoft did something good? I thought they are too busy keeping my personal data in a prison and writing tight bash loops wasting 100 percent of a core
tryauuum··on Mysteries of Telegram Data Centers (2022)
I've never had a twitter account so all these people hating durov for his exile marketing look weird to me. I'm not disagreeing with what you say but it's like a whole another subsection of world opened to me
tryauuum··on Mysteries of Telegram Data Centers (2022)
> You people are just racist towards Russians and need help.

>> That doesn’t exclude the statements about Telegram to be correct though.

just attack the telegram from the technical standpoint, then no complains about "racist towards russians" will be given. Like, mentioning the lack of user-friendly E2EE is great already. Saying things like "Durov who supposedly lives in exile has visited Russia over 50 times" is meh. How can one intepret it in any other way is "Russia is evil and visiting Russia is thus evil"?

and regarding the cracking contests — one of the telegram bugs was actually uncovered this way, see https://habr.com/ru/articles/206900/

tryauuum··on TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
that's stupid. getent passwd will fetch the user list from the network depending on setup. Have fun fetching 40000 records from the network every call
tryauuum··on EU Parliament greenlights Chat Control 1.0
come on guys, stop upvoting me and answer the question please
tryauuum··on We won $92,337 bug bounty using a single kernel 0-day
whoa, didn't expect a wall of text

When I said about "no mitigations except for the kernel updates" I meant exactly that. Some sysctl config to flip, some kernel module to unload. Apparently such thing doesn't exist in this one

tryauuum··on EU Parliament greenlights Chat Control 1.0
Today they already analyze the SSL handshake and traffic patterns in Russia. And if your valid https traffic crosses the border but doesn't behave like https (I don't know how they do it. Frequency of TCP packets and their size and the delay between?) your IP-address will be blocked

I want to stress that I'm speaking from experience. I personally installed a telegram proxy project which aimed to mirror the pattern of traffic and fool the censors

Page 1 of 22Next →