HN user

aja12

33 karma

After being a lurker for about 5 years, I finally created an account, due to... I don't really know. Enthusiastic about self-hosting and cybersecurity. Proficient in Python, interested in learning Rust. Mostly using HN as procrastination, and as a great source of amazing open source tools.

Posts0
Comments31
View on HN
No posts found.

From an exterior viewpoint, all this portrayal of Trump as either insane or an idiot is as useless and dangerous as the sanewashing.

I believed Trump was insane/an idiot during his 1st mandate. I no longer believe so.

I firmly believe he is an ingenious antagonist with ulterior motives using advanced manipulation and destabilization techniques. He moved the Overton window so far and fast that the world doesn't know how to react, and any reaction will be too little too late.

Trump is taking the USA's economical/social structure apart at a frightening pace, and unfortunately a lot hinge on the USA elsewhere.

He should not be seen as incompetent/unfit for office, he should be seen as a hostile entity to get rid of yesterday.

And I fear it's too late, the USA won't react until he's made the "necessary constitution changes" and been elected for his 3rd mandate.

Getting rid of Europe's ties with the USA will be arduous but I don't see any alternative

Yes! When I learned of Anna's Archive a few years back I too was frustrated by the lack of a short explainer of how to access single files, existence of an API, etc. Now I'm envious of LLMs somehow

Actually, the real countermeasure to PTH is to disable NTLM auth and rely only on Kerberos (and then monitor NTLM as a very strong indicator that someone or something is attempting PTH)

Of course kerberos tickets can be abused too in a lot of fun ways, but on a modern network PTH is pretty much dead and a surefire way to raise a lot of alerts

(You are absolutely right that privileged accounts must never login on less privileged assets, however!)

cloud-based synchronization

Well I don't disagree that it might be possible to abuse cloud sync in some way to export the secrets, but it's not quite as egregious as just including the secrets by default in an app backup

Not perfect, but (imho) still better than SMS 2FA, mail 2FA, or lack of 2FA

Most TOTP apps support backups/restores, which defeats this.

Citation needed? Yubico authenticator doesn't (the secure enclave is the Yubikey). I'd be very surprised if MS Authenticator and Authy (which I don't use but are the most popular apps that I know of) support such backups

From someone who has not tried the software but might be interested if it gains traction:

You should decide whether you are building this for yourself or as a product to others. Each stance is perfectly valid but are somewhat not compatible, the software can be very opinionated or intuitive but attempts to be both seem to often fail.

If you are building opinionated software for yourself and are ok with alienating a part of the userbase: great, some great software are built this way! (Alacritty, Kakoune come to mind). This should be clearly communicated to prospecting users though, it may need to convey "this software has strong opinions you may not agree with, that's fine but it may not suit you" somehow.

If you aim for maximum reach: expect your sense of what is "intuitive" to constantly be challenged, and to have to make many difficult compromises. You also need to take feedback from a more forgiving angle, and above all, assume good faith from your users. In this instance, GP stated their enthusiasm for your shared vision of the problem space, and your knee-jerk reaction was calling them a troll.

Builders of opinionated software should pay trolls no heed and refrain from engaging, and builders for maximum reach should think trolls don't exist.

footnote: `toad run` expecting a folder and not a command seems to fall in the "opinionated" ballpark

Bullshit journalism. This was not a post heist report, every buzzword chasing so called news outlets out there are repeating ad nauseam findings that were listed in a report produced by ANSSI in 2014! 2014! Eleven. Years. Ago! Did Louvre kept obsolete software around all this time, yes they probably did but this "Louvre" password claim just grinds my gears

Burner Phone 101 11 months ago

Baseband SoC running their own OS independent from Android/iOS and staying asleep (while still listening for incoming signals) is very much no longer in conspiracy theory territory and more an established fact now. I don't have the source at hand but it's in one of the standards. And the purpose is very clear: LEA like Interpol must be able to locate any IMEI at any point if in tower range, regardless of the power state of the "main" OS

Replacing CVE 1 year ago

As a pentester, who does not love CVSS[0], I found the article explaining how to replace CVSS with CVSS very amusing

[0] CVSS is often poorly understood and used by internal teams so for our internal engagements, we prefer words like "minor", "medium", "major", "critical" to describe criticity and impact and "easy", "medium", "hard" to describe exploitation difficulty (which loosely translates to likelihood), and the reasoning behind all this is very similar to what CVSS does

First of all, I'm not a gun control activist, and I do agree with some of your views.

However:

I think this is a uniquely American problem because America is a unique country. No other nations have the incredible wealth, diversity, and rights of America, and looking to other countries to emulate is imo, a mistake.

- increased wealth should be correlated with a reduction in shootings,

- population diversity is not a unique feature of the USA, it is comparable, or arguably lower, than most European countries,

- same for rights: the rights of a USA citizen are comparable to the average EU citizen. Many EU countries allow the possession of guns (although most forbid taking arms out of one's home unless it's for transport, e.g., to the firing range, and most EU states vehemently forbid concealed carry). There are some differences regarding Free Speech, however, where most EU countries allow it largely, but restrict hate speech more.

It's true that shootings are a somewhat unique USA problem, but I'd look more into cultural differences than into rights and demographics.

Oh please

Apple is extremely user-hostile, going to great lengths to strip users of control of their devices, gaslighting them into staying in the walled garden (with great success), while simultaneously siphoning as much user data as it can get away with, and employing as many dark patterns as it can to prevent the users from exercising their rights (it's worse than Meta in this regard).

Truly, Apple always amazes me with its ability to put expensive rose tinted glasses on its users's noses.

A big part of the reason I use Apple products is that they protect not only me, but my family who don't know what the implications of sideloading are. I know that the apps my phone runs have been given the green light by Apple.

The malware my family is most exposed to nowadays have names: Onedrive, iCloud, Google Drive. They are all designed to collect all the user's data, are all opt-out, opting out is filled with dark patterns. And regarding dark patterns, having recently gone through the motions of downloading all my data and then deleting my X, Facebook, Instagram, Microsoft, Google and Apple accounts, I can confidently say that Apple is by far the _worst_. Yes, when it comes to exercising one's rights, Apple is worst than even _Facebook_.

Users are much less exposed to non-branded malware nowadays, as the incentives to torrent random crap have mostly disappeared, and protection against spam/fishing has improved.

Yes and infected Xcode and various SDKs you get on your laptop are actually the biggest threat to iOS security (other than just literally malicious devs). Devs torrenting an xcode and then infecting their users is a thing.

Would it happen as often if the tooling was free?

That's fallacious for two reasons:

1: you can set secure defaults at one place globally, but your code must be correct all the time to be free of SQLi

2: it's usually not the same persons who configure the DB and who write the code.

Security is an onion, not a coconut.

Why are people downvoting your comment? It's not against the guidelines, is it?

I strongly think you are wrong, and I strongly disagree with your points, but I don't see why your opinion should disappear, lest this thread turn into an echo chamber.

Pivot into cybersecurity? As a pentester, a mountain of security bugs in a mountain of AI produced slop that no one understands is the ideal provider of job security, I guess

Maybe pentesting can be partly automated, but "the devil is in the details" and a pentester's primary quality is to look where the automated software won't.

I don't know, truly. The future is somewhat foggy.

Probably not worth the added complexity, but in theory, the package could be published immediately with the existing compression and then in the background, replaced with the Zopfli-compressed version.

Checksum matters aside, wouldn't that turn the 5% bandwidth savings into an almost double bandwidth increase though? IMHO, considering the complexity to even make it a build time option, the author made the right call.

I'm a bit at a loss there. Has _anyone_ ever considered Signal to be anonymous? Or Discord? If so, I have bad news: they are not anonymous. At all. Not even slightly anonymous. Nor did they ever claim to be, they only claim to not be able to read your messages (Signal claims that, I don't know about Discord, I doubt it). And that claim has flaws (sure the crypto is sound but have you thoroughly reviewed and compiled the version you are using right now?)

At the very best, they are weakly pseudonymous, but that's about it. And yes, loading media by default has always been a staple of applications who prioritize their users' convenience at the expense of some security, a fine choice for the usual threat model of their users. And embedding media in messages has always been a staple of deanonymization attacks.

So ok, the tracking pixel has been shown to still be a relevant technique today, that's nice but not surprising.

If you want to remain anonymous though, don't use Discord or even Signal, and I'd advise against posting on HN either. Maybe, if you automate the pasting of messages (no js!) that has been reworded by a local llm from throwaway accounts through whonix, at random times that can't be correlated to your timezone, you _might_ have your chances. Don't bet on it.

Anonymity does not exist any longer.

Very Wrong Math 2 years ago

From what I've learned reading AdmiralCloudberg's plane crashes analysis [1]: altitude heavily matters in fuel consumption. Jet planes use a lot less fuel at a higher altitude, up to the point that a plane on the verge of running out of fuel at a medium altitude might manage to squeeze in 50 or 100 more miles of flight by climbing 5000 feet, even accounting for the increased fuel consumption during climb. I guess that correlates with speed as well. Turbofan engines, on the other hand, are more fuel efficient than jet engines at lower altitudes, hence they remain common for interstate transit. The difference seems to be directly caused by the effect of air "thickness" on the engines.

[1] https://admiralcloudberg.medium.com/

Like sibling comments, after using poetry for years (and pipx for tools), I tried uv a few months ago

I was so amazed of the speed, I moved all my projects to uv and have not yet looked back.

uv replaces all of pip, pipx and poetry for me, I does not do more than these tools, but it does it right and fast.

If you're at liberty to try uv, you should try it someday, you might like it. (nothing wrong with staying with poetry or pyenv though, they get the job done)