HN user

blocke

915 karma
Posts1
Comments155
View on HN

The hotels I've stayed out with this functionality all had an Aruba Wireless system with a hospitality model AP on a 1-gang wall box somewhere near the floor or strapped to the back of the TV.

Aruba wireless (like many enterprise wireless vendors) has a mDNS proxying and filtering system which is essential for places like college campuses. Airplay and Miracast (infrastructure mode) both use mDNS for service discovery. In Aruba the system is called Airgroup. When seeing a new MAC address the wireless controllers queries the RADIUS server. The RADIUS server can return a configuration for that new MAC address which tells the controller what other devices can interact with this new device using mDNS.

I always assumed this vendor adds and removes Airgroup configuration to allow the phone and the TV to see mdns from each other while preventing this from other nearby devices on the same VLAN or SSID. This trick might be enough but also pushing a DACL to the wireless controller to properly packet filter all network traffic from unapproved devices would strengthen the solution.

The bugzilla tickets linked from that article frustrates me. They should autoplay Yakety Sax music as they dodge around fixing the real @#$@ing bug:

Just copy Chrome and confine all modal dialog boxes such as HTTP basic auth and Javascript alert() to the individual browser tab. No individual tab should every be allowed to pop a modal that prevents interaction with any other tab, any other browser window.

This problem immediately goes away and you don't need to play rate limit wackamole games or do stupid things like have a dialog box that asks if you want to see another modal dialog box.

As someone who interacts with HTTP basic auth frequently Firefox's behavior here is maddening. Fix the bad UI.

Edit: Oh, and here is a 13 year old bug about the real issue: https://bugzilla.mozilla.org/show_bug.cgi?id=377496

Tons of places outside of F500 are doing that. At work we just disabled IMAP for almost all O365 accounts and any other method of authentication that doesn't implement our two factor authentication. The rising number of compromised accounts because the user used the same password elsewhere, apparent bruteforce attacks, etal forced the issue.

Of course MDM is not required for any of this. Worst case is on Android you're forced to use Microsoft's Outlook app.

I'll give 4500 a whirl to see if it increases the success rate. It's a good idea. However it's not inconceivable to have sites like cafes that only allow 80/tcp and 443/tcp because that was an option in the UI on their wifi router for guest networks.

At this point if I was designing a VPN for client devices I'd have a mode that looked at as close to HTTPS as possible. There is one tool to tunnel over websocket but this was already sucking up too much of my play time. :)

Cisco AnyConnect, while expensive and bloated, works great as it initially connects on 443/tcp and then tries to setup UDP. If UDP fails it just sticks with the TCP connection and "just works".

I setup Wireguard and was pleased with the setup. Unfortunately I tried to use it over the next week only to quickly realize I should have kept my OpenVPN install instead.

Outbound port filtering is incredibly common on public and guest wifi networks and I found three use cases in my first week where OpenVPN on 443/tcp would have worked fine. The inability to use Wireguard over TCP and bypass most outbound port filtering by using tcp 443/etal makes it unusable in my daily life. I can understand why TCP isn't performant but my choice isn't performance vs non-performant. It's works somewhat vs GFY.

And yes I've seen the udp over tcp forwarding hacks. They don't work on iOS and some look outright dangerous (hello open proxy).

Hopefully this can be addressed before Wireguard hits 1.0.

Surveillance of 60 million devices? Do the users all know?

https://www.latimes.com/business/technology/la-fi-tn-ride-ha...

"The company doesn't work directly with services such as Uber and Lyft, but a number of apps, such as Sherpashare (which is primarily used by ride-hailing drivers for services like Uber and Lyft), HopSkipDrive, eDriving and a variety of navigation apps use Zendrive's technology to monitor ride safety."

Hurray for malware. What other apps is this hiding in?

My response to this site as someone who has had a paid Dropbox account for years:

Oh no. Oh... no. follow link to dropbox.com Ugh. What happened?

I'm now under the impression Dropbox will go out of business and I need to explore alternatives.

Edit: I think I identified what makes me intensely dislike it. The color scheme and design screams "This is no longer for you, it's for hipsters."

MacBook Pro 10 years ago

The touch bar examples shown are a usability disaster. You're going to hide UI from the screen and make me keep looking at the keyboard to find functionality?

I stopped looking at the keyboard every 10 seconds when I learned how to touch type.

The presenter spent most of his time looking at the keyboard and not the screen.

This gimmick will disappear when Apple decides a touch screen is needed to complete the slow merge with iOS.

You can pin radio stations. Unfortunately it only grabs a handful of songs at the top of the playlist. So dumb.

Edit: Radio station downloading now seems to grab at least twice the amount it used to. Which puts it firmly in the "meh" category when it comes to usefulness.

Play Music's Youtube integration is a pointless distraction that makes me less likely to continue to pay for the service, not more.

If I want to watch music videos I'll go to the Youtube app. So damn annoying when I accidently tap the play video hover button when I really meant to swipe to the next song.

If it weren't for YouTube's popularity I'd say the integration was a sign of desperation.

"The offline playback stuff continues to be pretty clunky to set up. If I know I am going on a road trip and will be driving out of range, actually adding that music to the device is a huge pain, and often the easiest way is just to leave the device playing music for days and let it build up a cache. Horrible."

It's not obvious but the way to do this is to "pin" (aka mark as keeping for offline) playlists on the device. Create a few travel playlists, pin them on the device, put the device on wifi or change the data settings in the app, go to the web client and mass drag and drop songs onto the travel playlists. I manage about 6 GB worth of offline music this way and it works decently. Once in a while you have to go into settings and tap "Refresh Music" to get it to recognize a new playlist but I maybe do that once a month.

I use the Kindle app for Android because that is where the indie authors seem to be. I use the app in spite of itself. The Kindle app on Android has over the past few years been such a buggy piece of shit that I curse it's very existence. It alone has demonstrated that Amazon can't competently develop mobile apps worth a damn and made me laugh when I heard Amazon was making a phone.

Once a month Amazon seems to make a release that outright breaks a critical flow in the app. For the past couple weeks I've had to use the website to skim through books because every time the app tries to open the store view for a book the app instead opens Chrome with "about:blank" as the URL. /facepalm

I'll ignore the fact the tablet version gets a proper store interface (when it's not completely broken) but the cellphone version gets a regurgitated ancient web view that was last updated a half decade ago.

I can only conclude that Kindle isn't profitable for Amazon at all and they throw appropriate talent at it... that is none at all.

Does Apple give a rip about iBooks? Google doesn't seem to give a crap about getting indies on Google Play.

Nexus Player 12 years ago

We live in a sea of available entertainment and sources of amusement. Why be so attached to one particular form of entertainment when the cartel that controls it doesn't make it easy or inexpensive to consume?

Nexus 6 12 years ago

7" screen was the perfect size for reading books and comics in my opinion. I'd preferred to have gotten a new 7" with smaller bezels. Might as well skip this Nexus generation.

Nexus 6 12 years ago

As someone against having any form of debt other than a mortgage or useless obligation such as a cellular contract:

$649 is where I stop paying attention to the Nexus line.

The hours worked to afford the device and it's needed case and accessories make the 6" screen not worth it.

And trying to hide the cost behind a cellular contract brings that cost over a thousand dollars. Stupid.

Nexus 6 12 years ago

That isn't a physical button, it's a speaker. Dual front facing speakers.

Rogue DHCP servers should not be a problem in any decently engineered enterprise or college campus network. Cisco switches have included DHCP snooping for years which when used only allows authorized switch ports to act as a DHCP server. Any decent enterprise wireless platform should either have transparent firewall functionality to block client DHCP responses or an equivalent to DHCP snooping.

If you've properly deployed these tools you've greatly limit the potential impact of a DHCP based worm.

Home router? Anyone test this against Linksys junk yet?

I'm not using the API only the "see for yourself" link on the MMS page at https://www.twilio.com/mms.

Webpage says it's sent but nothing ever arrives to the phone. I'll send an email to help@twilio.com with my phone number if someone over there wants to try a few test sends for debug info.

As a side note I just tested using the SMS page and it seems to work now. When I last tried it a couple months ago when swapping SIMs and trying to test SMS it silently failed with both sets of phone numbers and SIM Cards while every other SMS source I could try worked fine. That appears to not be an issue anymore so it's just MMS.

MMS to and from the phone works fine with Verizon and AT&T cellphones so I'd imagine there is some plumbing somewhere going wrong in my case.

Thanks.

People need to stop buying terrible phones. Consumers keep rewarding companies who don't keep up with their promises and thus no one ends up giving a crap.

In my opinion if you're not going to buy a Nexus device or a Moto E/G/X then you might as well buy Apple. The Android One program will hopefully add more to that.

The only Nexus phones here that don't already have a fix available is the phone they announced as being end of life. 4.4 is not affected and is available for the Nexus 4, 5, both generations of 7 and I believe the 10.

Dear Galaxy Nexus users... It's time to let go.

"What I find utterly unfathomable is that the state wrote ONLY 43 POs totalling 132 Million fucking dollars."

Actually since you mentioned it:

"The purchase orders state that the purchase had to be split across multiple POs due to ADPICS controls. OHA explained that this was due to limitation on the authority of the OHA purchaser entering the POs into the ADPICS procurement system."

So they had to split the POs up to get them past the business rules implemented in their accounting platform? Heh.

(http://www.oregon.gov/DAS/docs/co_assessment.pdf page 36)

Looks like the important thing here is now is that you don't have to care that Android runs on your dash computer. It's that the phone is using your cars built in display, touchpad, buttons, microphones and speakers as an attached display, speakers, and inputs to the phone.

The actual apps run on your phone and so your car gets updates when the software on the phone gets updates.

This mode is highly preferable to the end-user apps living in the dash computer as that will not get upgraded worth a damn over the life of the car no matter what.

This is exactly what I'd want to see in this situation and I can't wait to get an aftermarket replacement to cover the gap until I need my next car.

Network engineers in campus and enterprise environments have been building a DC network overlay for years in the form of Power over Ethernet. All of those VOIP phones, access points, and security cameras all need DC power with UPS backup and the network closet has become where that power is provided.

On our campus it's reaching the point where every switch we'll be buying will soon be PoE. I imagine many places are far ahead of us on this.

What is the max cable length of USB Pd?