HN user

DanBlake

4,129 karma

harknesslabs.com

Posts58
Comments583
View on HN
itunes.apple.com 7y ago

Show HN: Google Analytics for your personal location

DanBlake
1pts2
torrentfreak.com 9y ago

RIAA, BPI, IFPI sue largest YouTube ripping site

DanBlake
2pts4
harknesslabs.com 10y ago

2 Factor Auth Bypass: Protect yourself with $$

DanBlake
2pts1
news.ycombinator.com 10y ago

Ask HN: What does the iphone actually encrypt?

DanBlake
3pts1
waywt.com 10y ago

Show HN: Our spinoff startup, WAYWT.com

DanBlake
4pts2
www.popularmechanics.com 10y ago

'Kamikaze drones' begin use in israel

DanBlake
1pts0
blog.pagefair.com 10y ago

Leading 'anti adblock' provider gets hacked- pushed malware to end users

DanBlake
93pts55
thenextweb.com 10y ago

Adblock plus tried to buy Purify for more than 1M in cash

DanBlake
1pts0
www.youtube.com 10y ago

The last audio cassette factory [video]

DanBlake
20pts6
harknesslabs.com 10y ago

Startup Connections Matter

DanBlake
1pts0
www.hollywoodreporter.com 11y ago

How 3,000 Fake Weapons Get Through Security at Comic-Con

DanBlake
1pts0
everydaycarry.com 11y ago

What I carry with me every day: dhh

DanBlake
2pts2
www.reddit.com 11y ago

Reddit bans a top 10 subreddit with over 150k subscribers

DanBlake
30pts29
www.independent.co.uk 11y ago

Night vision eyedrops allow vision of up to 50m in darkness

DanBlake
2pts0
everydaycarry.com 11y ago

What I carry with me every day: Alex Payne

DanBlake
1pts0
everydaycarry.com 11y ago

Whats in Matt Mullenwegs Bag

DanBlake
2pts0
harknesslabs.com 11y ago

How to save Radio Shack from certain death

DanBlake
6pts1
news.ycombinator.com 11y ago

Ask HN: Twitter/tumblr/etc “in a box” platform?

DanBlake
1pts1
www.everydaycarry.com 11y ago

Show HN: EverydayCarry.com – See what everyone carrys with them

DanBlake
1pts0
everydaycarry.com 11y ago

Show HN: EverydayCarry.com

DanBlake
9pts1
www.cbc.ca 11y ago

Twitpic shutting down over Twitter trademark dispute

DanBlake
2pts0
harknesslabs.com 11y ago

Why hasnt the imgur for video arrived yet?

DanBlake
3pts1
www.businessinsider.com 11y ago

Massive iCloud zero day being exploited for explicit celebrity photos

DanBlake
7pts0
popbox.io 11y ago

Show HN: Self destructing, encrypted messaging with file upload

DanBlake
40pts30
priceonomics.com 11y ago

How Much Should a Landlord Pay a Tenant to Move Out of an Apartment?

DanBlake
33pts77
binbox.io 11y ago

Show HN: Encrypted pastebin with Bitcoin ad network

DanBlake
7pts2
status.linode.com 12y ago

Linode Freemont down from DDoS

DanBlake
15pts7
binbox.io 12y ago

Ad network that pays bitcoins to share links

DanBlake
4pts0
harknesslabs.com 12y ago

Crap to stop doing on startup websites

DanBlake
61pts56
harknesslabs.com 12y ago

Stop comparing this to the 2000 bubble

DanBlake
31pts42

Been working on this for about a year. Basically my first real 'startup' since I launched Tinychat nearly a decade ago. Essentially, this is google analytics for where you have been. It makes use of a local database on the phone itself so you have control over your data. The only external calls it makes are anonymous ones to either google or foursquare to get names of places if you stay there for more than 15 minutes.

This app was created to answer questions that are not possible to easily answer now, like "What are my top 10 restaurants in miami" or "when was the last time I was at the dentist". While perhaps the audience for such data isnt as large as social platforms, I believe that there is enough utility in this for it to succeed.

The app itself is built in react (so android version coming in next few weeks) and makes use of custom geofence zones to accurately (in testing, more accurate than any other app in the ios app store) get your location and track your path with minimal battery drain of about 3-5% per day. All this done in the background.

Right now, the analytics options are just getting started but we are building out a full suite of detailed 'drill downs' for people to explore their data, even with the ability for you to write your own queries if you choose.

Id appreciate any comments or criticisms, be as harsh as you want- This app was a huge undertaking and if there are shortcomings I want to hear them.

Golds value comes entirely from the fact that we as a society give it value.

The beauty line doesnt work, because then platinum shouldnt have any serious value despite its rarity (it just looks like silver basically)

The industrial value is laughable, but read comments below/above to debate that more at length.

The scarcity line doesn't work, because you have elements like bismuth which are also (Arguably) more beautiful than gold https://66.media.tumblr.com/61ce390242a79a767772d4b2027eb902... but command prices far less despite being .025 vs .0031 on the PPM abundance on earth. Or even look at ruthenium which has a similar look to platinum and is even rarer than gold. Did I mention it also goes for about 400 an ounce? Quite a savings over gold.

The only thing that makes sense is that we as a collective have decided gold has value of X.

I think its been around 7 years since a public exploit has been dropped for the apple airport extreme. YMMV though, as Apple has stopped selling them which means support is likely going to be minimal in the future if something does pop up. Alot of it is likely security through obscurity though as obviously the code is closed source and it uses a custom management interface vs web-access.

If you want to go the modern (better) route, enterprise equipment such as ubiquity or cisco with strict rules are likely your best bet. The budget option being a openwrt install with one of their recommended routers

So, thats more code you want me to write, to support how many total potential users on the planet? I'm good. They knew what they signed up for when they chose to use an email like that and I am sure every single one of them has another email they use for this case.

In fact, I bet many of them are so frustrated with the errors of nothing working that they dont even attempt to sign up for things with the email most times.

I disagree. While n@ai might be a technically valid email, its such a extreme edge case ( maybe 1 out of 1,000,000 people have a email like this) that its worth denying that person registration to keep the likely thousands of erroneous emails from being entered incorrectly and the time that goes into correcting them. Same thing goes for addresses like "<>;@\'`{}|.a"@παράδειγμα.δοκιμή

Honestly, if you decide to use a email like n@ai you already know what to expect. Most services wont let you sign up, And even if they do most will likely incur errors in the application when you attempt to do things.

In reality, while it may be 'in spec' to use such a email, we can all hope that edge cases that allow it are changed and the legacy 'rules' that allowed it in the first place phased out completely.

So, in practice in the 'real world'- n@ai is not a valid email address and never will be. If I create a web application you can bet your bottom dollar I wont allow it and I will create less work for myself by doing so.

Does a password management / U2F solution exist that would let you view all password titles with a master password but only dispense the actual passwords, one at a time, via a button press? Would prevent having your entire password DB stolen if you were keylogged/mitmd/whatever.

Picture of what I kind of mean here : https://pbs.twimg.com/media/Diylx-0X4AIjrqO.jpg

*edit- slide #2 and #3 are backwards. The passwords are stored on the USB device, if that wasnt clear. Master password allows you to view password titles and essentially 'unlock' the usb device. However, every action needs to be confirmed one by one. So for instance, you could in theory export 'all' passwords in one shot, but it would present you with that prompt on the device itself.

My first instinct reading this was to think about the gothamist/dnainfo kerfuffle.

However, Checking the new yorkers revenue shows around 200 million/yr, I definitely did not expect that and likely means it can easily support a union. (unless the new yorker is loaded with debt, which it might be)

Considered this before, but it doesnt work. IIRC, the law applies to euro citizens both living in country and abroad. As such, geoip blocking is not a working strategy. (a french citizen who lives in japan still had GDPR rights) A better one would likely be a clickwrap agreement for all users stating "European citizens are not allowed on this service" which they have to click a "I am not european" tickbox to.

Technically this was possible before this.

Since the email to each slack user is an @company.com address all you need to do is take control of the employees email address, reset the slack password and login as the target user.

This seems very at-odds with previous rulings (specifically, relating to craigslists many past dealings). Strikes me as being very unlikely to stand up to appeal. Also, linkedin will likely modify their websites behavior (make you click to agree before you view a profile) which would create a binding 'click wrap' stopping companies from scraping them.

Knolling 9 years ago

Hmm, cloudflare should have taken care of that with a feature they have. Il check whats going on

As a windows 10 user, I would have definitely moved to a 'windows phone' anytime before ~2010. What would have gotten me to move would have been some sort of seamless 'handoff' from my desktop computer to my phone. I still think the opportunity is there for them to do that. I dont mean the ability to run desktop apps of course, but maybe some new take on 'remote desktop' which had a ios like UI. I just imagine leaving my house and going to work where I take my phone out and just plug it into some dock and I magicly have my home environment. And when I am on the go, I have some 'ios-ified' version of my home setup.

The only other phone I know of that kind of tried to do this was the atrix, which afaik was a failure

Just took a quick look at this. If you are located in the 'mining valley' of Washington where power is ~2c/kwh you are still getting healthy profits.

A computer with 7 GTX 1070 graphics cards should produce ~230 mh/s and draw 1 kw. This would cost approximately $30/month in power factoring in kw demand + cooling.

The above setup will currently generate $385/month in ETH.

So basically for miners who are in the right spot with the right facility, this is still profitable. The question is of course for how long. You also need to factor in the cost of equipment, datacenter, employees and difficulty/price.

But even if you dont have a facility in washington and just mine from your apartment, your power cost would probably be $100 a month. So its still 'profitable', just not nearly as much as it was in the run up.

Cliffnotes: 'professional' miners dont care. Even with the 'crash' today, they are making more per day than they were before the entire run up. For instance the 'worst' time for mining was December 2016 where you would only make $7.50 a day gross in ETH.

Years and years ago when we first launched a video chat room app, they denied it. They said it wasnt allowed to have a listing of rooms. So we simply had the app request a file from our server on app launch. If the file was present, we hid rooms. Once we got approved we just removed the file. We kept that up for a few months but it seemed like after the initial approval apple never bothered to check again so we just abandoned it after that.

I can only add my experience with etsy on the affiliate side. TheHunt.com previously sent them significant traffic (as in, hundreds of thousands of visitors) via their affiliate program. We then got a email that they were going to change our rates to be something like 5x less than our current rates because we were high volume. Needless to say we removed every etsy product on our site and replaced them with amazon/farfetch/etc.. products within a week. We actually ended up tripling our revenue off of the etsy traffic so I am glad it happened.

It did show a lack of appreciation for traffic on their end they were so willing to let us go without a fight. No room to budge on rates or even suggest a alternative- Not sure if that was management or department based decision but it was certainly enlightening.

Unrelated, but I read a article a while back which said something similar, but it was based on the fact that our entire mathematical system is designed around "base 10" and as such is only relevant in many constructs to our specific human 'ten fingered', interpretation of math.

Seems like something like Chaos monkey should have been able to predict and mitigate a issue like this. Im actually curious if anyone uses it at all- Curious if anyone in here at a large company (over 500 employees) has it deployed or not.

Shit, I use this for image search. Basically we let users submit the title of items they own (for everydaycarry.com), we do a google image search for that title and display back the top 5 results from googles image search to the user, letting them click on the appropriate product. We then link that product to the google image source URL.

Anyone know of a alternative product that would let this keep happening? When we implemented this originally, I did not find any competing options from either Microsoft, Amazon or Yahoo- That was 2 years ago though, so things may have changed for image search API's.

This is interesting. I am not well versed on yubikey, but does it allow you to have a similar setup with other password managers, like keepass? (Meaning, one press per one password) Or is it just a substitute for typing a master password?

Does firefox run each tab in its own process yet? Or live inside a sandbox? I switched from firefox + noscript to chrome after accepting that firefox's security (even with noscript enabled) was just so far behind that of chrome.