HN user

caffeinewriter

1,979 karma

[ my public key: https://keybase.io/sushi; my proof: https://keybase.io/sushi/sigs/TIhhBjRSP6Xxdh09gFzIFLNIKJYm9Sn8LAs4tR95gKk ]

Posts364
Comments143
View on HN
learn.microsoft.com 2y ago

Microsoft PowerToys: Utilities to Customize Windows

caffeinewriter
11pts3
axesslab.com 7y ago

Captchas Suck (2017)

caffeinewriter
2pts0
en.wikipedia.org 10y ago

Eternal September

caffeinewriter
2pts0
en.wikipedia.org 10y ago

Head/tail Breaks

caffeinewriter
1pts0
en.wikipedia.org 10y ago

Hofstadter's Law

caffeinewriter
3pts0
www.slate.com 10y ago

Where's _why? (2012)

caffeinewriter
2pts0
www.i-programmer.info 10y ago

The Reason for the Weird PHP Function Names (2013)

caffeinewriter
1pts0
stackoverflow.com 10y ago

Why Is Node.js Single Threaded? (2013)

caffeinewriter
3pts0
medium.com 10y ago

Proxima Nova, ca. 1981

caffeinewriter
1pts0
philipwalton.com 10y ago

What No One Told You About Z-Index (2013)

caffeinewriter
141pts26
www.shrinktank.com 10y ago

A Psychologist's Perspective on Kanye West (2013)

caffeinewriter
1pts0
blogs.msdn.com 10y ago

Secret Santa is NP-Complete (2006)

caffeinewriter
45pts17
www.searchtwitch.com 10y ago

Show HN: Search Twitch – Search Live Twitch Streams

caffeinewriter
1pts1
en.wikipedia.org 10y ago

Etaoin shrdlu

caffeinewriter
4pts1
nyctaxi.herokuapp.com 10y ago

NYCTaxi – A Day in the Life of a New York City Taxi

caffeinewriter
3pts0
en.wikipedia.org 11y ago

Baker-Miller Pink

caffeinewriter
5pts0
blog.stackexchange.com 11y ago

How We Built Our Blog

caffeinewriter
2pts0
en.wikipedia.org 11y ago

Deadlock

caffeinewriter
1pts0
dietjs.com 11y ago

Diet.js – A Node.js Web Framework in 335 SLOC

caffeinewriter
1pts0
stackoverflow.com 11y ago

Thinking in AngularJS with a JQuery Background

caffeinewriter
3pts0
en.wikipedia.org 11y ago

Secure Remote Password protocol

caffeinewriter
1pts0
www.emojitracker.com 11y ago

EmojiTracker: Realtime emoji use on Twitter

caffeinewriter
1pts0
www.watchpeoplecode.com 11y ago

Watch People Code

caffeinewriter
5pts1
github.com 11y ago

Show HN: Getignore – Shell script to fetch language-specific .gitignore files

caffeinewriter
1pts0
en.wikipedia.org 11y ago

EURion constellation

caffeinewriter
3pts1
en.wikipedia.org 11y ago

Sturgeon's law

caffeinewriter
1pts0
explorableexplanations.com 11y ago

Explorable Explanations

caffeinewriter
1pts0
en.wikipedia.org 11y ago

Kleptography

caffeinewriter
2pts0
www.reinterpretcast.com 11y ago

Roll Your Own DNS-Based CDN

caffeinewriter
2pts0
en.wikipedia.org 11y ago

Poka-yoke

caffeinewriter
1pts0

Huh. The researchers seemed to gloss over the Cloudflare Pages URL, but it's actually pretty interesting. I haven't had a chance to look at it in depth yet, but it appears to use the search-ms: URL protocol to show an attacker controlled WebDAV server to serve the malware.

The server hosting the malicious files seems to be down now, but this post details a similar attack:

https://micahbabinski.medium.com/search-ms-webdav-and-chill-...

It also seems to be part of a phishing kit, or potentially generated with AI due to the presence of the following comment.

    // Замени на свой URL
Which in English is:
    // Replace with your URL
And various other descriptive comments like
    // Полностью очищаем страницу (Completely clear the page)
    // Создаём новый контейнер с индикатором загрузки (Creating a new container with a loading indicator)
    // Через 3 секунды скрываем Cloudflare и запускаем загрузку (In 3 seconds, we hide Cloudflare and start the download.) [Though this was next to a 900ms timeout, so there's definitely been some tweaking]
They're the kind of comments that don't really make sense if the author is writing them themselves, but would if they're using something off the shelf, or asking some LLM to output code. The descriptive comments of what the code's doing definitely makes me lean towards the latter.

I'd call D&D more of a framework for collaborative storytelling that can absolutely be played as a game. The DM leads the adventure, the players decide how to respond to things. Everyone plays D&D a bit differently.

The most straightforward adventures that typically have a "win condition" are one shots/self-contained adventures from either WoTC or 3rd Party Publishers, like Curse of Strahd, Waterdeep: Dragon Heist, etc.

However, a lot of D&D groups I've played with might have characters die, but will rarely have a group "lose". However, because every group runs things a bit differently, a different group can drastically change how the game feels.

During the initial kerfuffle, a Unity employee did quote one of their lawyers saying the following[1]:

Our terms of service provide that Unity may add or change fees at any time. We are providing more than three months advance notice of the Unity Runtime Fee before it goes into effect. Consent is not required for additional fees to take effect, and the only version of our terms is the most current version; you simply cannot choose to comply with a prior version. Further, our terms are governed by California law, notwithstanding the country of the customer.

The communication around this rollout was absolute rubbish. Even employees were trying to get clarity, and they were forced to figure it out and real time.

[1] https://forum.unity.com/threads/unity-plan-pricing-and-packa...

I know for me (as someone who would likely never have had to pay a dime under either pricing scheme) the crux of the issue was unilateral, retroactive changes to a license that was supposed to be tied to the software version, as well as the nebulous "we'll know what to charge you because of our proprietary data model, trust us" messaging that they first went with.

That, combined with the fact that there was no safeguard for the install fee to be capped at some percentage of gross revenue made it so clear that they were trying to get something out of their free to play market specifically, which seems to have been to force their F2P customers to use their Unity Ads service over Applovin or similar competitors since they gave credits towards the runtime fee if you vertically integrated with Unity.

- Plainly Difficult (Short Disaster Documentaries with a significant focus on Nuclear Disasters): https://www.youtube.com/channel/UCb0MyY46T9ZYOzDHkYnIoXg

- Fascinating Horror (More Disaster Documentaries): https://www.youtube.com/channel/UCFXad0mx4WxY1fXdbvtg0CQ

- Half As Interesting (Short Educational-y/Humorous Explainer Videos): https://www.youtube.com/channel/UCuCkxoKLYO_EQ2GeFtbM_bw

- Technology Connections (Deep dives on everyday/vintage technology): https://www.youtube.com/channel/UCy0tKL1T7wFoYcxCe0xjN6Q

- Displaced Gamers (Code analysis and discussion of vintage video games and game systems): https://www.youtube.com/channel/UCWoSKWs8h6lFdiEDAjuIfpA

- ColdFusion (Short documentaries on companies and technology): https://www.youtube.com/c/ColdFusion

- Modern Vintage Gamer (Taking a look at retro tech/gaming): https://www.youtube.com/user/jimako123

- Economics Explained (Explaining Economics): https://www.youtube.com/user/JitaLounge

- Nostalgia Nerd (More vintage tech): https://www.youtube.com/user/nostalgianerdvideos

- LiveOverflow (Reverse Engineering, Hacking, and CTFs): https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w

- styropyro (Lasers and Electricty, taken to extremes): https://www.youtube.com/user/styropyro

- NileRed (Chemistry Experiments): https://www.youtube.com/user/TheRedNile

- The Thought Emporium (Biohacking and other science-y things): https://www.youtube.com/user/TheChemlife

- Fredrik Knudsen (Longer form documentaries about various historical events and internet incidents): https://www.youtube.com/channel/UCbWcXB0PoqOsAvAdfzWMf0w

- bigclivedotcom (Electronics teardowns): https://www.youtube.com/user/bigclivedotcom

- Sebastian Lague (Game development tutorial-ish things relating to procedural generation): https://www.youtube.com/user/Cercopithecan

- Two Minute Papers (Breakdowns of research papers with a particular focus on AI): https://www.youtube.com/user/keeroyz

- VWestlife (Technology, with a focus on audio equipment): https://www.youtube.com/user/vwestlife

- Chubbyemu (Medical case studies): https://www.youtube.com/channel/UCKOvOaJv4GK-oDqx-sj7VVg

- Tech Rules (Video game AI/tech breakdowns and analysis): https://www.youtube.com/c/TechRules

- DIY Perks (Actually interesting/useful DIY projects): https://www.youtube.com/user/DIYPerks

- Biographics (Explainer videos focused on historical people): https://www.youtube.com/channel/UClnDI2sdehVm1zm_LmUHsjQ

- Geographics (Explainer videos focused on geographical locations by the same person as Biographics): https://www.youtube.com/channel/UCHKRfxkMTqiiv4pF99qGKIw

- MattKC (Vintage Tech repairs/mods): https://www.youtube.com/c/MattKC

- LGR (Weird and cool retro tech showcases): https://www.youtube.com/user/phreakindee

- Game Maker's Toolkit (Game design deep dives): https://www.youtube.com/user/McBacon1337

- People Make Games (Stories about games and game design): https://www.youtube.com/channel/UCZB6V9fUov0Mx_us3MWWILg

- Every Frame A Painting (Movie analysis, no longer active, but still worth a watch): https://www.youtube.com/user/everyframeapainting

I was thinking on that. You still need peripherals if you're using a Mac Mini, though that's no different than if you were using another desktop. Still though, if you don't use, or don't want to use a Mac as your daily driver, that's a dedicated machine just to build/publish an extension for a browser. IMO, there's a slightly stronger case for iOS apps, but requiring that for a browser extension is much harder to justify.

Synchronous communication typically means something that demands your attention as soon as something is sent. Asynchronous communication is something that typically handled whenever you're ready for it. To put it in programming terms, synchronous communication "blocks" until you deal with it, where as asynchronous doesn't require you to deal with it until you're ready to.

https://www.worldwidelearn.com/education-advisor/questions/s...

https://status.net/articles/synchronous-vs-asynchronous-comm...

I mean, when a lawyer takes a case on contingency, they're essentially gambling their time on hopes of an outcome where their share (30-50% isn't uncommon, if I remember correctly) would make the time and effort spent on the case worth it. Against a company the size of Disney, with incentive to make the case as long and painful as possible to try and discourage other creators from trying to get what they're owed, it would likely take thousands of man hours, and tens of thousands of dollars out of pocket. Between discovery, filing fees, appeals, all for a victory that would result in (and I'm just completely guessing based on essentially no data) only hundreds of thousands of dollars. Lawsuits can very much end up being pyrrhic victories based on the costs incurred alone, not to mention the emotional toll that fighting a protracted legal battle can inflict upon a person.

Alright, since linking the entirety of title 17 isn't exactly easy to refer to as a source, the relevant part is 17 USC 203.^1

It's probably one of the more complex parts of copyright law. There's a few well-known cases of section 203 being used to claw back copyright decades down the line. (Note: I'm am very much not a lawyer)

In 1938, John Steinbeck granted Viking Press rights to publish 13 of his works, including Of Mice And Men, The Grapes of Wrath, and Tortilla Flats, as long as they were kept in print and for sale. In 2005, John Steinbeck's son and granddaughter served notice to Penguin Publishing, who were the interested party at the time, that they were terminating the agreement.^2

This section was originally designed to give artists who may have essentially (or even literally) given away their rights due to inequitable bargaining power a chance to recoup their property down the line with at least several years notice that they are planning on terminating the agreement.^3 In practice, however, it's kind of a mess, and to say that it would allow an artist or their heirs to terminate a grant to the public domain is dubious. It's something that would likely see its way to the supreme court should it ever come to pass.

I've included a couple other articles here just in the general interest of providing more info.^4^5

[1] https://www.copyright.gov/docs/203.html

[2] http://billgablelaw.com/sites/law/files/TakingItBack.pdf

[3] https://abovethelaw.com/2019/05/terminators-mount-up-section...

[4] https://media2.mofo.com/documents/190700-all-shook-up.pdf

[5] https://wiki.creativecommons.org/wiki/Case_Law

Humans Not Invited 6 years ago

Quite a few "people" have solved it it looks like, and it's riddled with persisted XSS attacks once you get past it.

Here's the returned response when you succeed: https://hasteb.in/iyifapud.html

I found the "man" category to be the easiest to pretend to be a bot on.

There are definitely some games that just don't translate as well to Tabletop Sim, but as far as shared tabletop experiences, TTS blows every other one I've tried out of the water on the widest variety of games. I use it for D&D, Wizards' Academy, and I own about half of the official DLC games.

There's a lot more regulation and guidance around taking down a phishing site at the domain level, rather than at the provider level. (E.g. Hosting company, CloudFlare and other DNS providers, etc.) If I remember correctly, ICANN requires takedowns to be either compelled by law enforcement, or done through the UDRP[1], whereas the providers themselves are typically more able to quickly respond to abuse. In addition, phishing domains are typically short lived, as once they're flagged by Google Safe Browsing[2] and the like, they're essentially worthless to the ne'er-do-wells that purchase them, regardless of if they're actually taken down.

[1] http://www.icann.org/en/dndr/udrp/policy.htm [2]: https://safebrowsing.google.com/

Honestly, I'm glad they didn't. There's not much use in a whois privacy service if they'll give up the info just because a company says "this is infringing".

I feel like the title "Facebook sues Namecheap for registering phishing domains" is somewhat misleading.

We found that Namecheap’s proxy service, Whoisguard, registered or used 45 domain names that impersonated Facebook and our services, such as instagrambusinesshelp.com, facebo0k-login.com and whatsappdownload.site. We sent notices to Whoisguard between October 2018 and February 2020, and despite their obligation to provide information about these infringing domain names, they declined to cooperate.

Specifically, they're suing Namecheap and their proxy service for not providing information about the true registrants of the allegedly infringing domains.

It's not uncommon for compromised computers to be used as nodes in DDOS-for-hire networks, (though compromised IoT devices seem to be in vogue at the moment) proxies for ne'er-do-wells, sending spam, and other activities that might not be apparent to the user of the computer in the slightest, but still have effects that reach out to the world at large.

That's a channel-specific option though. You can set per-channel bitrate, but it's not something Discord does automatically to accommodate lower throughput clients.

I think you're quite correct. If you're investing in obfuscation, you're probably making the wrong investment. Malicious actors have to obfuscate to avoid detection for as long as possible, and benign actors would probably be better served focusing on their core tech. That said, obfuscation is very good at increasing the difficulty of interpreting and understanding the purpose of code.