HNHacker News
TopNewBestAskShowJobs

vpShane

150 karma · joined June 15, 2025

www.vp.net | Privacy isn't secrecy. | Our WireGuard runs in an SGX Enclave, not even we can access your VPN traffic.
submissionscomments
vpShane··on Mozilla appoints new CEO Anthony Enzor-Demeo
LibreWolf ftw, I switched to it, installed my extensions and am not looking back. Would be nice to have a mobile Firefox(LibreWolf) with all extensions, I should go look around F Droid again.

in ff if you're reading this go to about:config and type privacy - why these aren't immediately obvious in the Settings is beyond me

vpShane··on SoundCloud has banned VPN access
That's one way to look at it, mine is no data goes out or in unencrypted, and for me it's simple. Adtech? "No." - let packet kiddies get my home IP address? "No."

It's as simple as that: No thanks, then I slide the slider on WireGuard and then I have an encrypted tunnel that all of my devices can communicate with each other, use a DNS through the tunnel with domains blocked and I can control what phones home and what doesn't. I'm not concerned with foreign governments, snoopy neighbors, war driving, or anything.

I can't solve all the problems but there are no what ifs on my end, *What if" -> No.

I'm not a number in some algorithm or malicious because I route my data securely, I'm a human being.

vpShane··on SoundCloud has banned VPN access
Should be interesting to see how the internet blocks those of us who don't want to be fingerprinted, ID'd, or reveal our home IP addresses. YouTube already blocks embeds to login and prove I'm not a bot, funnily it doesn't work and embeds never play. Reddit will block me unless I'm signed in which I don't mind too much, but the daily beast and many others block me which is a shame because I'm a real human being using the internet as intended.

Instead of blocking or limiting features to whitelist users with approved behavioral patterns and limit / block those that don't -- such as loading a page and immediately commenting or doing things that normal humans don't do, they block IP addresses and ASNs.

I just close the browser tab and remind myself not to waste my time caring, there'll be other platforms.

My router is setup for WireGaurd and it'll never be disabled.

Shame on SoundCloud

vpShane··on Microsoft AI
https://www.reddit.com/r/AskReddit/s/Cb5TEZj3hV

?

vpShane··on VPN location claims don't match real traffic exits
Naw you'll have to email dang and ask him they have a auto system, I got auto shadow banned once and had to email them, they said I didn't do anything wrong and then restored all my comments. I went like 3 months thinking nobody liked my comments enough to give me an up point. Worth reaching out about their auto mod is sensitive
vpShane··on VPN location claims don't match real traffic exits
Enough to buy like 512MB of DDR5 RAM maybe
vpShane··on Linux CVEs, more than you ever wanted to know
Any hops along the paths and whatever they split off to by whoever. And of course they can, even with HTTPS the Client Hello is unencrypted.

Unencrypted data transmission just isn't a thing I'm interested in with it being 2025.

vpShane··on Linux CVEs, more than you ever wanted to know
They're not useless. And I'm well aware of how MITM attacks work. Any hops along the path from my VPN endpoint to the server unencrypted can be, and are: viewed with plaintext. With a self signed certificate I can choose to accept the certificate or not. I'm not arguing to use them, I'm saying I've moved on from http, which is reasonable for me to do in today's 'get all of their data' age.
vpShane··on Linux CVEs, more than you ever wanted to know
I enjoy this person's writings, and contributions. I am Linux's biggest fan and research cyber security daily.

I would prefer https.

vpShane··on Linux CVEs, more than you ever wanted to know
It's not about threat, it's about privacy. I understand your statements but 'what is the threat in this case' to answer that: I don't want to know, I've moved on from those worries. Always encrypt.
vpShane··on Linux CVEs, more than you ever wanted to know
It did for Librewolf -- what I moved to from Firefox. Self-Signed certs I'm down with, http I'm not, and never will be for any reason. Plain-text data transmissions have no acceptable reasoning.
vpShane··on A.I. Videos Have Flooded Social Media. No One Was Ready
I stopped using social media even to stay connected - I look at hacker news to stay up to date with tech, and reddit for cyber security related subs but the FBPurity I installed a year or so ago, and my account was still small just friends and family of maybe ~30-50 people. Mostly, for an animal shelter I volunteer at and community events.

Installing it, scrolling down was constant sponsor ads being blocked, reels of women from bot accounts that steal influencers' videos and repost them, new-age spirituality memes 'Let go of what does not serve you' and 'Return to Source to find your real self' - quotes from philosophers who never said the quote, 'How to hack' tutorial images -- all removed from fbpurity

I'd have to scroll for a minute before getting anything from the local community groups, the shelter's posts, and rarely did I see somebody else's post, and usually it was talking about Trump or politics or 'are we in a simulation?' but for the most part it's all brain rot.

Toxic, deceptive brain rot. There's no use trying to get others to exit the psychological magnet that has them hooked and doom scrolling and posting non-stop with their views.

The botfarms would plague every local community group and most people activity were calling out the bots. Bots swaying the comments on posts' comment sections for local news, people getting LIVID in the comments over trolls/bots.

Businesses being FB exclusive only with no Google presence, no maps presence.

Delete it, trust me, you'll be happier. There is no 'purity'

vpShane··on Netflix to Acquire Warner Bros
He did buy an entire island in Hawaii and makes it a decent place for the natives (from what I hear) but otherwise...

Billionaire Drools That “Citizens Will Be on Their Best Behavior” Under Constant AI Surveillance

https://futurism.com/the-byte/billionaire-constant-ai-survei...

Is the kind of mindset behind this guy.

vpShane··on Cloudflare outage on December 5, 2025
twice in a month _so far_
vpShane··on India scraps order to pre-install state-run cyber safety app on smartphones
> That is not a US government program.

You're right, it isn't. It's a foreign one (allagedly) and they used the tools telecoms and agencies use to monitor data, sms, call logs with IMEI/IMS mapping. Those, do belong to government agencies.

> You also brought up ECH, DoH, DoT, Android's fake cell tower detection, and Android's NEARBY_WIFI_DEVICES permission that also demonstrate a strong industry-wide push to limit mass surveillance, contributing to my argument that GGP's assertion that nothing has changed is incorrect.

This sounds more like you want to be correct; data brokers and mass surveillance are at an all time high, with platform providers requiring biometrics, ID uploads, data being sold, re-sold, re-sprinkled.

Android devices that can not utilize the latest Android OS (16+) to my knowledge can not access these features, by default DoH, DoT are not enabled by default. Whether the device itself can show if a fake cell tower is being used is only one step. The telecom and infrastructure companies that provide 5g have more tech layered on top of it that is indeed vulnerable, salt typhoon sat dormant in major telecom and internet backbone devices for over a year before being discovered.

We don't know whos cyber campaigns or who's involved in surveillance. I'll often get customers sharing the same stories where they call their ISPs and the ISP operator will list all the websites the customer viewed in casual conversation over the phone; which is scary.

> No, it doesn't. Just because someone proposes something doesn't mean the EU wants it, especially when the EU completely removes that proposal from the table.

Yes, it does. Many countries are in favor of it in the EU and even if it fails, they keep proposing it until it'll pass.

The U.N. just signed a multi-nation treaty with 72 countries, including Russia, China, and Iran to swap data with other intelligence and law enforcement agencies with the data its collected as its joint mission to, on paper look like a good thing but broaden surveillance and share that data among countries. https://vp.net/l/en-US/blog/72-Nations-Create-Global-Surveil...

The U.S. isn't involved with that, but here in the U.S. states are just now proposing VPN bans and requiring logging for major AI providers.

Most things are walled gardens.

The claims that it's getting better need all of us to put in a lot more work. Security, privacy, data integrity all go hand in hand.

Those SSIDs have among them, tracking that tracks MAC addresses, which can also be scanned out of the air using basic tools like aircrack-ng

A simple 'Share Your Location with this website' popup on a browser is more than enough to geo-locate you and provides enough information to geo-locate others on the same network.

It getting better is just not true. I wish that were the case, but it's going to take a lot of work for all of us.

vpShane··on Kea DHCP: Modern, open source DHCPv4 and DHCPv6 server
Actually, yes, that'd be great!
vpShane··on India scraps order to pre-install state-run cyber safety app on smartphones
tell that to salt typhoon who collected copious amounts of data on all of us.

https still uses unencrypted client hello's (ECH) across the vast majority of the internet, showing which domain the client is visiting in plaintext for multi-site servers to do SNI. DNS is still plaintext on most consumer routers/models provided by ISPs, stingray technology exists in the wild and is widely used to mimic cell towers. E2EE is not popular in consumer applications, even Telegram isn't E2EE and the main ones that claim they are like X's new Chat they have the keys on; Matrix having E2EE still shows meta data in plain text, room names in plain text.

While iMessages, RCS, Signal are mostly mainstream, most people are unaware of the need for E2EE. RCS is its own set of issues.

Pegasus, Cellbright, I can go on and on with the spyware companies that can just send a text message and infect devices with 0click exploits.

We can have E2EE but if they can just see the screen or hook in to the messaging app's memory doesn't mean much.

Pick up your cell phone, is it connected to Wifi? Can it see other Wifis? Apps track those nearby SSIDs and report to major databases to have accurate geo-location data down to the spot we stand.

Don't get me started on Ad-Tech.

The EU wants to install backdoors on everybody's devices and get rid of encryption entirely.

Zero Trust Technologies are a fun thing to read in to, especially the need for them.

vpShane··on Amazon faces FAA probe after delivery drone snaps internet cable in Texas
Ah yeah I came up with the solution to that one. It's 'don't fly drones over our heads' approach. Also the 'upgrade the fragile infrastructure so a light breeze doesn't take out millions of people's power.'
vpShane··on Codex, Opus, Gemini try to build Counter Strike
Wow, that makes me want to check it out more thoroughly (if I had the time)

I remember when CS Pro Mod was being made between the transition of CS 1.6, Source, the 1.6 community didn't want to move over to Source, before GO/CS2 came around.

Cool to see what's basically Quake1/doom style but this is a far fetch away from counter-strike. Although if netcode could be imagined and implemented I don't see why making a lower tier Counter-Strike wouldn't be doable. I'd play it if it were the quake style old-graphics version of CS that allowed for skill gaps.

Great article, love the nostalgic feeling.

vpShane··on Tech Titans Amass Multimillion-Dollar War Chests to Fight AI Regulation
Correct. And glad you're aware of the challenges with running them.

I'm not saying the options are favorable for everybody, I'm saying the options are there if it becomes locked in to 1-3 companies.

vpShane··on Tech Titans Amass Multimillion-Dollar War Chests to Fight AI Regulation
Yeah, but we can self-host them. At this point in the span of it, it's more about infrastructure and compute power to meet demand and Google won because it has many business models, massive cashflow, TPUs, and the infrastructure to build expanding on their current, which would take new companies ~25 years to map out compute, data centers and have a viable, tangible infrastructure all while trying to figure out profits.

I'm not sure about how the regulation of things would work, but prompt injections and whatever other attacks we haven't seen yet where agents can be hijacked and made to do things sounds pretty scary.

It's a race towards AGI at this point. Not sure if that can be achieved as language != consciousness IMO

vpShane··on Dark Mode Sucks
Yeah, it does. It's not the worst in the world but dark mode my eyes relax and I can better enter flow-states. Too much non-dark mode and I get eye floaters.

Probably has something to do with having an all black background on desktop / IRC, terminals, steam since 1996/1997->now

Even MSN Gaming Zone where I started was 'dark moded'

vpShane··on The privacy nightmare of browser fingerprinting
Of course. There's data where there isn't data.

-make client load something

-client doesn't load it

-add.fingerprint.point(client,'doesnltloadthings',1)

-detect if client does something only a certain browser does

-client does it

-add.fingerprint.point(client,'doesthisbrowsderthing',1)

-window was resized/moved, send a websocket snitch to the backend

- keep a consistent web socket open, or fetch a backend-api call for updates on X events - more calls are made, means user is probably scrolling, inject more things/different things.

I see some js obfuscators out there where I look at the js file and it's all mumbo jumbo.

It is indeed a privacy nightmare, where whatever we do feeds the algorithms to aide in making other people do things.

But it's also used in network security, organizations etc. Staff/employees will use the system a certain way, if something enters it without the behaviors, it's detectable. I assume that's what you mean in anti-fraud.

Sad part is we don't know what the data is ever used for, and it's often bought and sold and the cycle repeats.

vpShane··on Kodak ran a nuclear device in its basement for decades
Ah yes, nuclear energy, real hot, make water boil, make things happen.

You're telling me we don't have sci-fi energy harnessing capability to capture the nuclear energy itself and convert it to electricity?

It's 2025!

vpShane··on Big Tech Wants Direct Access to Our Brains
As if adtech and blackbox algorithms don't already have that. It's scary to think about, especially in regards to spirituality, but I've seen the implant(s) allow people who wouldn't be able to move at all, stuck there; be able to move the cursor around a screen. Be able to play video games, and communicate with their loved ones.

There's good in things, will it be used for good when somebody links their brain to their own super-AI? Probably not, but for medical purposes it makes more than enough sense.

To understand alzheimers, dementia, the good for it all is limitless. Do I want privacy invaded? God no, but we know what it's coming to. With Neuralink and Elon's squad of young-and-upcomings that leave things like xAI keys on git commits, HIPAA data even if protected means nothing if somebody (some random) can just connect in, take it, and then sell it.

For me, and it's just my opinion is that the risks outweigh consumer good, and it's for sure got 'evil super villain hooked to an AI' written all over it.

vpShane··on Nano Banana can be prompt engineered for nuanced AI image generation
You're definitely old and bitter, welcome to it.

You CREATED something, and I like to think that creating things that I love and enjoy and that others can love and enjoy makes creating things worth it.

vpShane··on Cybersecurity breach at Congressional Budget Office remains a live threat
Sounds about right.
vpShane··on Cloudflare scrubs Aisuru botnet from top domains list
This wouldn't raise serious concerns. Ask the customers/community if doing it before hand is something they agree with in some form of poll, then just do it. At the end of the day DNS is a million years old, out-dated and the mission is to help make a better internet. If Cloudflare straight up asked us all if it was cool to modify their DNS servers to identify / disrupt malicious use from botnets I'd agree. People not using DoH or internal things like dnscrypt-proxy need to get with the times.

There's ethical ways to do things: https://www.justice.gov/archives/opa/pr/court-authorized-ope...

I'm not saying I agree with it but we're all engineers, the internet and everything built on it was engineered, to put up with script kiddies and hacked computers and not-so-tech-savvy internet citizens using their devices and installing Infatica, and other malware/proxy services on their devices because it came within the agreement for installing some free app where their kids could 'pop bubbles' on their parents phones or some free desktop app included it; then distinguishing their IP addresses and IP-scores as they blend in with their regular human traffic makes it hard to block it. Ain't nobody got time for whack-a-mole internet, families and businesses will need to secure their networks.

Honestly I'd be ok with an up-to-date live list of all known infected IP addresses and their last timestamp for what, and who detected them as a bot/malicious IP address so I could just use some simple ipsets and iptables, or make a simple script to disallow things like posting, interactions while still allowing them to see content on websites would be ideal. Add a little banner 'you're infected, or somebody on your network is infected, this is how to fix it and practice best security, and more info on the subject'

These services switched from DDoS/attacks to renting out their hacked network spaces. They don't need to be making bank at our expense.

vpShane··on Using FreeBSD to make self-hosting fun again
Agreed. Our hardware, our software, our choice.
vpShane··on Anonymous credentials: rate-limit bots and agents without compromising privacy
Also things working and behaving differently across 10 browsers
← PreviousPage 2 of 4Next →