HN user

elahd

380 karma

https://elahd.com

[ my public key: https://keybase.io/elahd; my proof: https://keybase.io/elahd/sigs/bl8yEk4w-1Hd05wx2ZYqt8cGRuIhTvNdGThdom8p0_4 ]

Posts4
Comments88
View on HN

In addition to changing bar size, would you consider supporting a multi-level bar? This is a Windows (pre-11) taskbar behavior where you can drag the top of the taskbar bar up to add additional rows of windows. uBar supports this, but the app overall doesn't behave well with my multi-monitor setup. Currently using Taskbar, but it's also buggy and only supports a single row.

This is great, but I'd be more interested in seeing how congestion pricing impacts travel times for buses, specifically, (within and around the congestion zone, including express routes from the outer boroughs), as well as overall transit ridership.

@gotmedium, would you consider integrating:

1. MTA's Bus Time feed: https://bustime.mta.info/wiki/Developers/Index and 2. MTA bus/MNRR/LIRR/Access-A-Ride ridership feed: https://data.ny.gov/Transportation/MTA-Daily-Ridership-Data-... 3. Equivalent feeds for city-connected NJ transit services.

Verizon, actually. Not the mail tubes specifically, but they own Empire City Subway, a 130 year old company rents out sub-street conduit for telecom. Their tubes are visible when streets are dug up for construction.

https://www.empirecitysubway.com/

https://en.wikipedia.org/wiki/Empire_City_Subway

Looks like their lowest rate (<=2.5" conduit) is $3,660/mile/yr, not including installation, permitting, and city franchising fees. Still interested?

They've been connected since 1991[1]. Amtrak runs trains from Canada/Chicago/Vermont into Penn using this connection. Trains run down Metro North's Hudson Line, through a junction in Spuyten Duyvil[2], down the West Side Line[3] (former northern section of the High Line[4]), and into Penn through a tunnel under the LIRR's West Side Yard[5]. You can see the connection here[6] (follow "EC Freedom Tunnel"). The connection under the West Side Yard was built in '86. The rest of the tracks are over 100 years old.

[1] https://en.wikipedia.org/wiki/West_Side_Line#Empire_Connecti...

[2] https://goo.gl/maps/DgeeiQzryseFg6A5A

[3] https://en.wikipedia.org/wiki/West_Side_Line

[4] https://en.wikipedia.org/wiki/High_Line

[5] https://en.wikipedia.org/wiki/West_Side_Yard

[6] https://www.openrailwaymap.org/?style=standard&lat=40.756798...

I use ESET NOD32 and am happy with it. It does its job with "dignity" (no Norton-style hyperbolic popups), consumes little resources, and is inexpensive. It does a great job blocking malware and has a nice blocker for "potentially unwanted applications" (https://help.eset.com/glossary/en-US/unwanted_application.ht...).

The cheapest licenses are available on Amazon. Either NOD32 or Smart Security do the job -- I buy whatever is cheapest when the licenses expire.

I'm the family IT guy for my immediate family. Around five years ago, after fixing the nth malware infection on family computers, I bit the bullet and bought a few multi-seat ESET licenses for my parents, siblings, and their families. I haven't had to fix a virus/malware issue since then. Prior to this, they were all just using Windows Defender. I used one of the licenses on my own computers, so I have direct experience with the software, as well.

I install Unchecky (https://unchecky.com/) along with NOD32. This is a free tool that provides a second layer of protection against drive-by toolbar installs.

I figured this was:

1) An experiment to test the level of familiarity that non-technical users have with two factor authentication. That is, does a person who incidentally enabled SMS 2FA understand that having to enter an SMS code every time they log in is a pattern called "two factor authentication" as opposed to just some weird part of Google's login workflow.

2) An artifact of a user's security preferences living in a protected space that can't be accessed by Gmail's frontend. Gmail's dev team got an order to encourage users to enable 2FA and this is the best they could do.

3) A ploy to get people to review their 2FA settings -- or to be sold Titan Security Keys. Google's security team has sent me several emails over the past few months encouraging me to buy these, claiming that I'm at an increased risk of a targeted attack. I'm not fully bought in to their motives.

(All conjecture.)

Mitmproxy 7.0 5 years ago

You may be able to intercept a firmware update and load a binary poisoned with your own CA cert. (Lots of factors at play here, of course.)

I'm working on a similar problem (https://github.com/elahd/esp2ino/issues/16) with a project I maintain to sideload IoT device firmware (https://github.com/elahd/esp2ino).

I've been using both mitmproxy and IOXY (https://github.com/NVISOsecurity/IOXY), an intercepting proxy made specifically for MQTT. IOXY is a small, less mature project, but it's definitely worth checking out as a compliment to mitmproxy. Many devices managed via AWS IoT phone home over MQTT and, my limited experience aside, it looks like many don't bother validating certificates when authenticating over this protocol.

- Password manager for both password storage and 2FA OTP generation. (Not the best practice, but the convenience is worth the trade-off.)

- Password manager for almost all 2FA backup code storage. Both the best place and the dumbest place to store these. "The best" because it's pretty secure; "the worst" because it's a single point of failure AND if I can access my password manager I already have access to my 2FA OTPs. I regularly make an encrypted backup of my password vault.

- Authy for 2FA OTP generation for my password manager.

- A printed card in my wallet for 2FA backup codes for my email account and password manager. Password manager master password is kept in a safe (in case I get hit in the head and forget it).

This isn't perfect, but it fits my risk profile.

We do, but like many things here, it varies from state to state: https://en.wikipedia.org/wiki/Vehicle_inspection_in_the_Unit....

In New York, where I live, inspections are done by private mechanics (with a state license). There's a posted inspection standard (https://dmv.ny.gov/brochure/new-york-state-vehicle-safetyemi...). Lights must be "of an approved type," but I'm not sure how you can reliably check this in a shop.

Also, some mechanics are more stringent than others. Some are outright shady. New York sets a flat $37 fee for inspections, paid to the mechanic. The fee is low, so there's an awful incentive here to look for high-margin items that "need" to be repaired to pass the inspection. Brakes and windshield wipers are some of those items. A set of aftermarket light fixtures -- if they can even be identified -- not so much. (This is anecdotal, but I've experienced this type of inspection on more than one occasion.)

Other states, like New Jersey, do inspections solely at state-owned inspection facilities.

Regarding sales, it's not illegal to manufacture off-spec fixtures. It's illegal to have them on your car on a public road.

Verified by Twilio 7 years ago

The telephone network is international. The US is limited in its ability to enforce anti-spam laws against operations running out of other countries. (They also seem unwilling or unable to enforce these laws domestically, but that's a completely separate issue.)

Raspberry Pi 4 7 years ago

I have a Pi running Pi-hole, Home Assistant, Node Red, and some custom scripts. It uses a parts bin 2.5" laptop hard drive (via a USB to SATA cable) as the sole boot and storage medium. You can set most Pis to boot from USB and totally avoid touching SD cards.

It was easy to configure and sped up the Pi quite a bit. No reliability issues in about a year of use.

Boot from USB instructions are at https://www.raspberrypi.org/documentation/hardware/raspberry....

.NYC requires that the owner have a physical presence in New York City. In addition to the standard whois owner/tech/billing/etc contact sections, .NYC requires a "Nexus" contact -- basically, a NYC-based address of either a person or business affiliated with the domain.

See http://www.ownit.nyc/faq, under "WILL PROXY REGISTRATIONS, SOMETIMES CALLED “DOMAIN PRIVACY” BE ALLOWED ON MY .NYC DOMAIN NAME?"

Basically, it's the registrar's policy to prohibit obfuscating the actual domain owner. Resellers like Namecheap have to abide by these policies.

I can't speak for EU domains, or for the reasoning behind the .NYC policy.

True. This can by bypassed one contact at a time by editing the contact's text tone. The text tone edit screen has an "Emergency Contact" switch that overrides DND for that contact. AFAIK there's no way to turn on app notifications.

This setup definitely isn't ideal. Just want to share the approach for people who find the tradeoffs acceptable.

This is doable on iOS.

Settings > Do Not Disturb with the following settings:

- Do Not Disturb: On

- Scheduled: Off

- Silence: Always

- Allow Calls From: All Contacts

You'd lose the ability to use Do Not Disturb to silence your phone, say, overnight, but this would do what you're describing.

Personally, I've opted in to T-Mobile's spam block feature. I don't get any robocalls.

I've had the same experience with my immediate family (siblings, parents, in-laws). A few years ago, I made pretty clear that if their next phone wasn't an iPhone, they were on their own with regards to support. I set up iCloud backup (with a premium storage tier) and installed ESET NOD32 on every computer that I "support." There hasn't been a single "support call" in 3 years (aside from hardware and forgotten passwords).

It sounds cold, but now I actually get to enjoy time with family instead of being bombarded with technical questions. They're also less frustrated with their devices.

In addition to the problems related to working around utilities, subways built with cut and cover create a lot of street level noise when operating. Also, buildings vibrate every time a train runs by. Bored subways are imperceptible from above ground.

I wasn't referring to EV certificates, just to verifying simple ownership of the domain for the purposes of MITM and other attacks of that kind. Let's Encrypt would inform you that the page that appears when you visit googIe.com was indeed served by the owner of that domain (barring server compromises or cert leaks, but that's a separate issue). LE and "basic" certificates do not attempt to answer the question of who owns the domain -- that's also an entirely separate problem.

The encryption part is easy -- you don't need CAs for that -- but they're a necessary evil when it comes to verifying ownership. You need to delegate trust to someone, otherwise using the internet becomes too cumbersome.