HN user

eloy

863 karma

https://eloydegen.com

Posts14
Comments101
View on HN

Author here, thanks! I just thought it was fun to make kind of a polyglot shell script-blog post :D

"yeah but you could serve a different page with the curl UA"

ok, then you just change about:config?

I really do not like Google as a company, but this is one of those cases where I agree with them. It was always clear that websites could track you in incognito mode. Somehow people thinking that Google is not a website that can do that does not make it Google's fault. You still have to accept Google's cookie banner when opening the site in incognito, giving another indication they track you.

Let me rephrase: > just don't make a unnecessarily complex web app, so it will be fast

Lots of apps include features that were never really asked for by the customer, but are included because it was easier for the developer.

I think minification should be done on another layer: HTTP compression and HTTP parallelization and that kind of stuff. And just don't make a complex web app, so it will be fast.

A survey conducted in the 1990s revealed some extraordinary facts: 90% of all American CEOs believed that selling a new product without advertisements would be impossible; 85% were convinced that advertisements persuade people into buying things they don’t need, and 51% — a majority — believed that advertisements persuaded people into buying things they don’t even want.¹

Uhh. So, this point to a book called Less is More — How Degrowth Will Save the World. In that book this statement is indeed made, and as a source it points to "Andre Gorz, Capitalism, Socialism, Ecology, trans. Chris Turner (London: Verso, 1994).". But in that book I can't find any reference to it. Was is completely made up?

I wish I had it! I think I would have to travel to some physical German archive to lookup old magazines... Or maybe Apple itself has the original digital version in their archives.

RIP Gorbachev, one of the few genuinely good people in politics.

After he retired from politics, he was featured in several advertisements:

- In 1994 for Apple Computer: https://www.upi.com/Archives/1994/10/07/The-first-advertisem...

- In 1998 for Pizza Hut: https://en.wikipedia.org/wiki/Gorbachev_Pizza_Hut_commercial

- In 2000 for the ÖBB, the Austrian railways: https://www.youtube.com/watch?v=bLscz8kEg6c

- In 2007 for Louis Vuitton: https://www.nytimes.com/2007/11/05/business/media/05vuitton....

Wi-Fine 4 years ago

Is it? I just checked https://hstspreload.org/, and it seems that twitter.com, facebook.com, outlook.com, cloudflare.com and gmail.com are all preloaded.

Or do you mean that downgrade attacks are still easy to deploy? Under what circumstances?

Wi-Fine 4 years ago

Hi! Author of that website here.

Can some mod or the OP that submitted this post change the title to "Wi-Fine: it is fine to use public Wi-Fi"? The current one is not very descriptive.

Also, let me know if any of you have comments to me specifically.

ECC matters 6 years ago

He does explain it:

We have decades of odd random kernel oopses that could never be explained and were likely due to bad memory. And if it causes a kernel oops, I can guarantee that there are several orders of magnitude more cases where it just caused a bit-flip that just never ended up being so critical.

It might be false, but I think it's a reasonable assumption.

C3Voc (CCC video operation center) does not want the raw stream to stay online, the edited version will appear soon online here: https://media.ccc.de/v/rc3-11511-watching_the_watchers_-_how...

I have watched the stream, it consists of an overview of security holes in SS7 and newer protocols. The vulnerabilities are either blocked by the ISP, or not blocked but require the attacker to have a lot of information about the target. An exception to this is https://simjacker.com/ which is unlikely to be blocked and only requires the full phone number of the victim.

An interesting point in the talk was the missing "economy of scale" in the pricing system of the surveillance companies. If you want to spy on more victims, the costs rises exponentially, because it becomes more likely that the attacker will be blocked by the ISP.

I don't want a browser to bypass DNS settings to use something else instead.

In an ideal situation, me neither. But there are a lot of users who use for example Windows 7, which will never get encrypted DNS on system level. Browsers get updates and can provide more DNS security for the average user. Not a single average user is going to configure a DNSCrypt client on their computer.

Especially since DNS encryption and anonymization is already done on the router for the whole network.

So you would prefer using a DHCP provided DNS server on untrusted Wi-Fi networks and let it snoop on DNS queries?

Yes, but you can also use Coreboot without blobs on this particular machine, so it doesn't really matter. Libreboot is just a Coreboot fork which is only compatible with machines that are usable without blobs. And they deliver the firmware as a blob, for more easy installation, Coreboot is basically a git repo.

Nice to see I'm not the only one still using an X200, it's still a pretty decent machine with an SSD, 4GiB RAM and coreboot. I fully agree with Drew.