HN user

epitactic

79 karma

https://gitlab.com/epitactic/

Posts6
Comments31
View on HN

sshd on your shared university server

Another attack scenario applies if the shared server hosts a web server:

If you have a shell and can bind a port, listening for HTTP requests. Example: nc -vvl 8080

Trick a victim into visiting your malicious port: http://example.com:8080/

The attacker gets the victim's cookies for http://example.com:80/ (and https://example.com:443/, if the "secure" flag is not set). And all other ports.

This attack succeeds because "Cookies do not provide isolation by port" (RFC6265 Section 8.5).

What is the fix? If only the cookie spec allowed binding to specific ports...

But an alternate fix could be requiring web browsers to only connect to privileged ports. 80 and 443, or any port <1024, thwarting the unprivileged user from exfiltrating cookies.

Unfortunately this ship has sailed and web browsers now have to support unprivileged ports forever. A more practical defense, in practice, is to consider this scenario out of scope, and/or implement application-level authentication. I am with you, and would have advocated privileged ports to defend against these attacks (with http and ssh and other services), but am not optimistic it will gain any traction. The world has moved on, and even multi-user shell servers are becoming increasingly rare (as much as I use them - still a proud Super Dimension Fortress member)

An interesting parallel, Facebook and Twitter also do not allow downvoting, which may also have similar negative effects as Spotify's lack of dislikes:

https://questioner.substack.com/p/our-violent-era

So Twitter artificially removes all the negative feedback (the downvotes) and only shows the positive feedback (the upvotes), leading many of their users to the mistaken impression that their insane ideas are immensely popular.

OpenBSD 7.0 5 years ago

ESXi (free version), it works well though if I had to do it again from scratch today, I'd probably go with KVM

OpenBSD 7.0 5 years ago

This is why I've setup my homelab with a hypervisor, you don't have to choose and can run each of these operating systems, for specific purposes they are best suited for. This is what I do:

OpenIndiana: file server (ZFS)

OpenBSD: firewall, router, network services (DHCP, DNS, NAT)

DragonflyBSD: game server

FreeBSD: other general application services

I haven't found a personal use case for NetBSD yet, though I would like to (it is great for embedded systems).

But what can we do to treat the cause, instead of just the symptoms?

By affecting the bottom line, increasing expenses and/or decreasing profits.

If they stop working (or rather work less – it's a spectrum)

AdNauseam is an interesting attempt in this space - a browser plugin to automatically "click every ad to fight surveillance" (their words). By clicking everything, clicks become less valuable, at least in theory, but it has not really caught on.

I feel the fix will be more along the lines of improving individual psychology and mental wellbeing, rather than entering the arms race of adversarial technology to block packet traffic (or whatever).

I agree with this. Ad blocking, ad clicking, packet blocking, is all thinking too small, always trying to catchup. It will always be behind and while useful for a niche subset of users, these kinds of technologies are more bandaids than a real solution to trigger fundamental changes to the advertising tracking industry.

What is a real, impactful solution? I don't know, but an area I have not seen explored much, considering by analogy:

Internet : Web :: Big Tech : ???

That is, the web layered on top of the Internet, as a disruptively transforming application, extracting and providing value.

Can another technology be created to build on the foundations provided by Big Tech, delivering value they provide, while avoiding their tracking/advertising downsides? I have little idea what this would look like in practice (how do you disrupt a billion dollar industry?), but if someone can crack this nut, it may change the world. Startup idea elevator pitch: disrupt Big Tech.

List of channels, covering a variety of topics:

Amazing Polly

And We Know (Romans 8:28)

Blessed2Teach

Destroying the Illusion

Dollar Vigilante

Dr. Charlie Ward

Dustin Nemos

Free Your Mind

InTheMatrixxx

In Pursuit Of Truth (IPOT)

James Red Pills America

Storm Is Upon Us

JustInformed Talk

Know More News

Linda Paris

MouthyBuddha

Nemos News Network

Edge Of Wonder

Patriot News Channel

PrayingMedic

Sarah Westall

SGT Report

Spaceshot76

Stroppy

The Last American Vagabond

Titus Frost

TruReporting

Truth and Art TV

WokeSocieties

RedPill78

World Alternative Media

X22Report

Good Lion Films

Oliver Janich

Citizen of Gotham

L. Lin Wood

Sidney Powell

CodeMonkeyZ

Submission statement: starting in October of last year, YouTube conducted what has been called a "massive purge" of channels. The BitBurned directory is an index of such (former) channels, with links to where they can be found on "alt-tech" (in contrast to Big Tech) services, including: Bitchute, Parler, Gab, and Rumble.

Recent relevant articles of interest, showing this is an important topic:

https://news.ycombinator.com/item?id=27874527 Right or left, you should be worried about big tech censorship - eff.org - 2021-07-18 (309 comments)

https://news.ycombinator.com/item?id=27858032 Google Drive bans distribution of “misleading content” - support.google.com - 2021-07-16 (1531 comments)

https://news.ycombinator.com/item?id=27646686 YouTube takes down Xinjiang videos, forcing rights group to seek alternative - Reuters - 2021-06-26 (261 comments)

https://news.ycombinator.com/item?id=26215122 Online Speech Is Now an Existential Question for Tech - WSJ - 2021-02-21 (40 comments)

https://news.ycombinator.com/item?id=26045088 The war on disinformation is a war on dissent - humanevents.com - 2021-02-06 (437 comments)

https://news.ycombinator.com/item?id=25359003 YouTube to remove content that alleges widespread election fraud - blog.youtube - 2020-12-09 (3227 comments)

https://news.ycombinator.com/item?id=25097145 Conservatives flock to Parler, claiming censorship on Facebook and Twitter - npr.org - 2020-11-15 (876 comments)

It gets worse - gain of function research was banned under Obama until the ban was lifted in 2017 under Trump - https://www.thelancet.com/journals/laninf/article/PIIS1473-3...

The ban was actually lifted by the Obama administration, _11 days prior_ to Trump taking office.

Source: https://obamawhitehouse.archives.gov/blog/2017/01/09/recomme...

JANUARY 9, 2017 AT 9:06 Recommended Policy Guidance for Potential Pandemic Pathogen Care and Oversight

"Adoption of these recommendations will satisfy the requirements for lifting the current moratorium on certain life sciences research that could enhance a pathogen’s virulence and/or transmissibility to produce a potential pandemic pathogen (an enhanced PPP)."

I had the same question - it appears the We Are as Gods documentary is not out yet. According to IMDB, it will be released in March 2021 at the SXSW film festival (March 16-20).

Bloomberg only has this excerpt:

The tweet, which said Uighur women were no longer “baby-making machines,” was originally shared on Jan. 7, but wasn’t removed by Twitter until more than 24 hours later.

The complete tweet was archived on https://archive.is/nxC3r#selection-3959.0-3959.255

Chinese Embassy in US ‏Verified account @ChineseEmbinUS · 5h5 hours ago

"Study shows that in the process of eradicating extremism, the minds of Uygur women in Xinjiang were emancipated and gender equality and reproductive health were promoted, making them no longer baby-making machines. They are more confident and independent."

zipfiles where the first entry is an uncompressed file with the name "mimetype" that has the mimetype

The EPUB format also adopted this convention: https://www.w3.org/publishing/epub3/epub-spec.html#sec-intro...

"The EPUB Publication's resources are bundled for distribution in a ZIP-based archive with the file extension .epub. As conformant ZIP archives, EPUB Publications can be unzipped by many software programs, simplifying both their production and consumption.

The container format not only provides a means of determining that the zipped content represents an EPUB Publication (the mimetype file), "

This project looks amazingly promising, thank you for creating it and I wish you the best of luck in its success.

One humble suggestion/idea I offer to think about, related to:

It uses trust-based Peers to share the local cache. Peers can receive, interchange, and synchronize their downloaded media. This is especially helpful in rural areas, where internet bandwidth is sparse; and redundant downloads can be saved. Just bookmark Stealh as a Web App on your Android phone and you have direct access to your downloaded wikis, yay!

Trusted peers with a shared web cache is a good start, but how about _trustless_ peers? Is this possible?

Possibly using something like https://tlsnotary.org - which uses TLS to provide cryptographic proof of the authenticity of saved HTTPS pages (but unfortunately only works with TLS 1.0)

Thanks for this, found a review of Authentic8 Silo: https://uk.pcmag.com/password-managers/3921/authentic8-silo

Looks like they have been around a while (5+ years), and from their website https://www.authentic8.com, they are focused on the improved endpoint security aspect:

"The Browser for a Zero Trust Web"

Traditional browsers run on blind trust. Silo assumes zero trust by running the browser in the cloud.

Web code can’t be trusted. Organizations know that every page view means risk to the business. Silo restores your trust in the web through isolation, control and audit of the browser.

Isolate: Silo executes all web code on our servers. Nothing touches your endpoint, and untrusted endpoints can’t corrupt your environment or your data.

Mitigate risk: Shift your attack surface area off your network and devices to disposable, anonymous cloud infrastructure.

I am intrigued, wonder how well they are doing, and how well it works. Somewhat expensive, I've heard $10/month and $100/year for individuals. No online live free demo, but available on request.

With the Epitactic Cloud Browser, I'm only running the VPS temporarily as a demo, the way I envision it end-users can run their own instance either on a home server or virtual server, maintaining control and privacy.

In the sense that it proxies traffic through the cloud, almost. The target websites won't see your IP address (although I could add a X-Forwarded-For header passing the origin address like archive.is does: http://archive.is/faq - cloudbrowser.website does not currently do this), or other details of your web browser environment.

Almost all metadata is not transferred through. There are two exceptions I can think of:

1) Browser window size. This is actually a significant fingerprinting leak, since desktop users can resize the dimensions of their browser down to the pixel.Cloud Browser uses it to generate an appropriately-sized image, matching the Chrome instance in the cloud to the end-user's browser. Less of a problem with mobile devices where the browser window is fixed, but could help fingerprint the device type.

If you want to avoid this, disabling JavaScript will prevent Cloud Browser from using window.innerWidth, innerHeight, and devicePixelRatio, and it will default to 800x600x1. This may not match your device. The best way to solve this is probably to run your own Cloud Browser instance, configured for what you will browse it from.

Interestingly, Firefox is implementing a "letterboxing" feature, from TorBrowser, to reduce fingerprinting from this technique: https://nakedsecurity.sophos.com/2019/03/08/firefox-browser-...

2) Time of access. The time Cloud Browser accesses a website will be shortly after the end-user accesses the website, as you would expect from a proxy. Could allow some forms of fingerprinting, e.g. work hours, depending your browsing habits, or correlating with other non-cloud website accesses.

If you are concerned about this, Cloud Browser makes it very easy to share the cached pages offline, in a time-independent manner. That is, you can access the files in cache/ offline as needed. The online browser will try to load from the cache first, but automatically refresh with a live version when it is available. But you could setup a cron job to fetch the websites you commonly visit on a fixed schedule, then only browse through the cache while offline, and then websites wouldn't be able to see when you read them.

I've thought about developing this feature further, it could lead to a better user experience, and avoid some of the problems with running Cloud Browser on a VPS. The VPS would be needed for running headless Chrome, but it could upload the static HTML and images as plain files to any static hosting website, for quick and easy browsing. You would need to "subscribe" to the websites you want to visit, and they would have to be periodically refreshed, however.

Deepstream.live, sounded like it was neat, unfortunately, seems to now be down. The same poster also posted about webautomation.guru: https://news.ycombinator.com/item?id=18951821 titled "Show HN: Use Chrome Headless in the Cloud from the Browser", similar to mine, but it too is down for me. Looked a lot more advanced than cloudbrowser.website, though!

These remote browser services seem to be difficult to keep running... (expensive if not profitable, I assume. My VPS is good for a few more weeks.)

Yes indeed it could, I haven't tested it but according to Wikipedia, image maps were introduced in HTML 3.2, which was published as a W3C recommendation in 1997 (!), so in principle it should work. Maybe even earlier, there was a supplemental RFC for adding client-side image maps to HTML 2.0 published in 1996: https://tools.ietf.org/html/rfc1980 A Proposed Extension to HTML : Client-Side Image Maps.

Cloud Browser does use a few modern features, a bit of CSS and (optional) JS, but not for anything strictly essential. Again I haven't tested it on any old browsers, but if anyone does I welcome bug reports/patches at https://gitlab.com/epitactic/cloudbrowser/issues.

(I wonder if it would work on NCSA Mosaic? https://news.ycombinator.com/item?id=18428682 - well, Mosaic added the img tag, but not sure if imagemap was yet available.)

Sanitizing the DOM is another option, but the main problem I was trying to avoid by taking screenshots is the arms race between the cloud browser and websites, as also seen with ad blockers. A static screenshot in contrast is "up" a level, agnostic to the complex details of rendering an HTML5 website.

Another inspiration is image boards such as 4chan, where screenshots are a very common means of sharing information, including articles on websites, or even tweets. Even though it may not be technically ideal, and annotated text seems like it would be more efficient, in practice images as the lowest-common-denominator seem to be a reasonably effective format for sharing information.

On the other hand, if someone does come up with a true "browser in browser" implementation like you propose, I would be very interested in trying it out. Could be a promising idea, but a lot of work to get right.

The static mirror https://epitactic.gitlab.io/cloudbrowser/ is just a static HTML page + image hosted on GitLab Pages, so it should always be up, but the links there go back to the online demo which was down.

Unfortunately, I'm only hosting the demo on a quad-core 6GB VPS, which frequently runs out of memory. There is a known issue (https://gitlab.com/epitactic/cloudbrowser/issues/2) where old Chrome processes are not cleaned up for some reason. I've restarted the VPS, should be available again for now, for at least a while.

This is a good point, honestly I didn't consider it, or know of Guacamole but I agree it could be a better solution.

Looking into it more, maybe noVNC or Guacamole, with VNC or RDP, tethered to a remote browser instance. This would solve the problem of user interaction with the web page, which is currently very limited with Cloud Browser's image maps (hyperlinks only). On the other hand it would increase the end-user browser requirements (image maps date back to HTML 3.2! https://en.wikipedia.org/wiki/Image_map), but still not run the target website's content, so it could be worthwhile and most browsers actively in use now support HTML5.

Nice job with prerender.cloud! This looks like about the idea I had, but you took it a lot further, beyond the prototype stage into an actual product.

If you want to borrow the image map idea, feel free :). I'm not planning on developing cloudbrowser.website much further, moving onto other projects, but maybe I'll be a customer.

Thanks for the link, this Kantu XClick and XMove image-driven "real user simulation" project opens up some interesting possibilities.

It also points out a significant limitation of Cloud Browser's imagemap-based architecture. Screenshotting the page locks away the text behind an image, inaccessible to screen readers, copy and paste, or other interactions. This doesn't seem easy to solve, since the most the img tag offers for accessibility is an "alt" tag, which does not allow specifying which areas of the image contain what text. Sending the actual text (like html.brow.sh) would solve this problem, but then layout is up to the end-user browser again.

Client-side OCR'ing of the image may be a possible alternative, will look into it thanks!

Thanks!

That was essentially my envisioned use case, as well. Not only for devices that won't run JS but those where you might not want to. For example, a lot of news websites are surprisingly JavaScript heavy, slow and buggy, not something I necessarily want to run if I merely want to read what the news is talking about. Public read-only sites. Granted, arguably services like outline.com and archive.is already cover this use case better.

As for sites requiring credentials, the way I see it users could run the cloud browser on their own server. This has benefits even for public sites, adding additional privacy. However it is not something this Cloud Browser really supports yet, since there is no support for forms, text fields, or other interactivity with the exception of hyperlinks.

Indeed, image maps seemed to be the simplest way to implement this, fitting into my goal of reducing the complexity of the content rendered on the web client. I still use CSS, but only in one place (for showing the cached timestamp in the corner). Technically I do use JavaScript, although only for getting the window dimensions, and it is optional.

An absolutely positioned CSS div is an interesting idea, if I recall correctly I actually tried this first, but ran into various problems (with scaling as the page is zoomed in/out, I think) and the image map worked perfectly. area shape="rect" works well as it translates directly from puppeteer's await page $$('a') boundingBox().

Hello Hacker News, I made this as a quick weekend project after getting inspired by Ian Bicking's _The Firefox Experiments I Would Have Liked To Try_ submission last week, discussed at https://news.ycombinator.com/item?id=19304802. Specifically, the "cloud browser" concept. Also partly inspired by https://html.brow.sh/, but as a text-based browser browsh is much more limited than Cloud Browser.

https://cloudbrowser.website/ runs a headless Google Chrome instance on a VPS, loading a website and taking a screenshot using NodeJS puppeteer. The links are iterated to create an image map, so you can browse (many) websites as normal, but through the cloud. Not all websites work yet, but many do.

Why is this useful? While this is only a simple prototype, it is an experiment in a new way to browse the web which I believe shows promise. Websites have become increasingly complex, heavy on JavaScript and HTML5 features. Cloud Browser pushes this complexity to the cloud, so you can browse websites requiring JavaScript without enabling JavaScript on your end-user browser, for example.

It is still in its incipient stages, but I welcome any feedback/suggestions on how to expand and refine this concept, or better yet, code contributions ;) feel free to fork on GitLab.

Source code: https://gitlab.com/epitactic/cloudbrowser/

Live demo of Cloud Browser loading Hacker News: http://cloudbrowser.website/b/https://news.ycombinator.com/

Static mirror if the VPS is down: https://epitactic.gitlab.io/cloudbrowser/