I use Lookify.io which lets you look up a carrier without creating an account - you can also see if anyone else flags it as spammy but who knows if the reports are anything other than anecdotal
HN user
Magicstatic
This is the craziest part of the whole article - imagine you wanted to own something like "555-FOOD" - to have this vanity number work in every area code, you'd be looking at hundreds of thousands of dollars (annually?) if you used Verizon to route the calls
Link to company confirming payment: https://twitter.com/josephdelong/status/1431314816698916865
Link to researcher writeup: https://www.paradigm.xyz/2021/08/two-rights-might-make-a-wro...
This has been refuted and is simply misleading: https://twitter.com/jon_bottarini/status/1428569700859056129
Anecdote: Out of every bank and financial institution I have ever tried hacking (ethically, as part of bug bounty programs) Goldman Sachs is hands down, without a doubt, the most secure externally. By a long shot. They have what basically amounts to a central authentication service that 95% of their public facing IP’s resolve to. Their sub domains are locked down, they have a reasonably good patch schedule, they swiftly denylist your IP after running light scanners - it’s not a joke. I challenge you to find a vulnerability - when you do - get some money for it: https://hackerone.com/goldmansachs
Many of us including myself are unable to fathom living a life like this, but I imagine this man will die in peace with a flock of sheep to his name, listening to the cuckoos.
And he will be just as happy (if not happier) as any of us reading this article.
Sincere question - not meant to be inflammatory: Do you actually believe that most employees in the United States are coerced/forced to sign employment contracts, or are you simply playing devil's advocate?
My favorite part of this response is in the footnote on page two, which states:
If your client sincerely fears that this depiction is too realistic to be perceived as parody, Krazam’s video should be the least of its reputational concerns.
Followed by screenshots from the video showing the DocuSign "Docustage" and Meme Center (Sponsored by GE). At the end of the video itself, the Coachella participant is banned from the event because their "vibes are not compliant with the Coachella policy".
Glad EFF stepped in here to protect small creators such as this one.
Is this a security problem? Depends on who you ask - but I'm willing to bet it would fall into the "accepted risk" category for the Facebook security team if they had to evaluate this.
The reality is that phone number lookup services are available all over the web which provide even more information (first+last name, address, zip code, social media profile links, etc etc etc) for free (https://www.bestfreephonelookup.com/phone-number/ as an example) - these services get their info from data aggregators and usually - your carrier! I don't see how Facebook exposing (in _limited_, very specific circumstances) the first name of a persons phone number being a security issue.
All the people in this thread screaming GDPR violation don't understand that if someone decides to stop using Facebook and delete their account, this method to lookup someone will not work. Sidenote: If you're really paranoid about having your phone number expose your real name when you're using any type of service online, just sign up for a Google Voice (voice.google.com) account and link it to your cell phone - I use this whenever I sign up for anything online and it saves me a ton of spam and scam calls.
EDIT: Facebook removed the ability to use the in-app search box in Facebook to find people based on just a phone number, this has been removed for at least 2 years.
I don’t even know where to start with this post:
- This isn’t even necessarily a hack. At best, this is a mild inconvenience to the user accounts that you are locking out, on what appears to be a legacy system, due to a quasi-brute force.
- You are “hacking” this company, without their permission, because you want “payback” that Amazon didn’t hire you for what you perceive to be a racially opinionated interviewer. Despite whether this theory (yes, it is purely speculation) is true or not, I would imagine this is HR 101 and a company as large as Amazon would go to great lengths to ensure that this is not the case.
- Your sense of entitlement goes even further, despite having illegally “hacked” a company, after all of this you expect a payment from them?
If anything, this post reaffirms that they made the right decision in not hiring you for the role you were being considered for, and guarantees that you won’t have an opportunity to interview again.
What’s peculiar about this is that parental restrictions itself on iOS has always been flawed, Apple knew about it, and it’s still an issue to this day. The sole purpose of parental restrictions on iPhone was to block adult websites... and that worked as well as you can imagine: https://www.jonbottarini.com/2017/03/09/bypassing-apples-ios...
Was able to reproduce on my machine. macOS High Sierra 10.13 (17A405)
This is incredible.
Great website, never heard of it before. Will definitely be using it as a resource in the future!
That was my tweet believe it or not. I had to turn notifications off on my phone because out of nowhere it was getting bombarded with shares/likes...
As a researcher, I am incredibly, incredibly excited to see H1 grow and more companies come online. I pay a good portion of my rent through bug bounties and I have to admit the gamification and ease of working with H1 makes it fantastic for someone like me.
As with most events that have occurred since Trump took the presidency, I am concerned, but optimistic. She has my full support, I hope she makes great changes to a system that desperately needs it.
Pop-ups like that have long been shown to improve conversion rates... at the increase of pissing off people who wouldn't have been a conversion anyway.
I usually have them for other projects I am working on - rarely do I purchase a domain just to let it sit there, but that's just me.
Not in the market to domain squat... gotta put them to use somehow.
Probably around 20.
My best one: Legal18s.com
I totally want to create a portal for "young professionals who want to study the intricacies of law and legal issues that we face today as a nation" just as a joke. I have no real plans for the domain.
Interesting enough, HN itself was actually susceptible to this and it was reported by a security researcher:
I think what's interesting is that Sacks was put into this position at the request of the board and shareholders. For the most part, this will be a interesting transition for Zenefits as they deal with the wave after wave of bad news...
So disappointed that when I visit reddit.horse now it doesn't show a badly photoshopped picture of Snoo riding a horse...
Here is a message I received from Gandi.net regarding the .blog domain:
-----------------
Hello,
You are getting this email because you have performed a pre-order with your handle {redacted} for the domain name {redacted}.
Unfortunately, this order is currently in error, because the domain name in question has been defined as Premium by the registry. This decision is of course beyond our control and frequently corresponds to a list of common and/or connotative words that allow registered to apply special rates to them.
This means that in your case, we have placed the order in error, because the price that you initially paid is no longer the price that the registry is charging for it.
If you would like to know the price, in order to eventually purchase it, then reply to this email, so that our support team can obtain that for you from the registry.
As long as you are considering this, do not cancel your order, since this will cause you to lose your place in the waiting list.
If, however, you no longer wish to register the domain, you can cancel it from the link provided below, and your prepaid account will be refunded for the order:
This is incredibly impressive and I just wanted to say I have used your service 100+ times. You have saved me many spam emails, my hat is off to you.
If you indeed did build 10minutemail.com - I applaud you. May I ask how much you make (roughly) off of the service? It seems to be the go-to for most temporary email services, at least that I know of.
Hi David -
Love the new design. I wanted to ask you - Is it possible we can see the return of the affiliate program sometime soon with Weebly?
Thanks and best of the luck!
Unfortunately this is nothing new. Facebook advertising has long been seen as garbage in many respects, especially when it comes to "liking" a page.
After $1,000 spent, I would estimate over 75% of all the accounts that liked my clients page were fake. Pretty inexcusable.
I'm with this guy.... get over it.
Understood. Thank you
Thank you for bringing this to my attention... second question: Why isn't everyone and their sister shorting the Asian market right now? Or are they?