HN user

ev1

2,564 karma
Posts7
Comments930
View on HN

So far I haven't seen a single major company doing phone based (insecure) 2fa not use the number for marketing, data abuse, etc.

Non-standards based "authenticator" dedicated apps phone home and spy on you. Intentionally trying to break or block actual TOTP.

Side note: the McDonald's app is nice in not requiring (or apparently even allowing) passwords to log in. However, there's a problem with its state transition, where the user needs to exit from the dialog that sends the sign-in link before they go to their email and click on the sign-in link, otherwise the user gets dumped to the next step without having actually signed in.

The mcdonalds app loads several dozen data collection sdks, pihole practically had a meltdown when it launched

The answer is generally "move" unfortunately. Surge pricing for things like club and concert nights runs orders of magnitude higher than normal rides for the same wear and tear. These don't really happen in small towns, and in larger places it's multiple times a night nearly every night.

I have not installed the TM app - you can add a ticket to Apple Wallet from the website, and every order I've seen has "don't have a phone? go to the box office for tickets when you arrive" somewhere

I see entire massive threads requested and responded in a single compressed call to /api/graphql/xxx/TweetDetail

Loading an entire next page is also a single call to the same endpoint. There is nowhere remotely that I see the mobile client even making a hundred gql calls for tweets.

Is there something I'm missing or is he misusing "app" when he means backend service to service GQL calls?

Reddit fingerprints you very aggressively. Cookies are not used here. Every single pageload, they scan all your fonts, plugins, etc.

They also exfiltrate this data back in ways to prevent blocking, by completely randomizing the API endpoint used to submit it and also not use a dedicated endpoint. For example on each pageload it might send to /submit, or /register, or /friend, it'll just pick a random valid endpoint and "front" that

They also continue to do this while you are logged out to tie your IP to the fingerprint.

    hxxps://www.redditstatic.com/reddit-init.en.4-tSxFR4sOk.js


^F "Arial"

Commonly spoofed fingerprints will result in a permanent ban automatically.

Amusingly, some of my friends that use it for Marketplace express a desire for Craigslist to be popular again, if not only for the absolutely insane people on Marketplace that demand to pay $20 for an item listed at $300 and then start spamming you and making public posts about how you're a thief and scammer for trying to rip off a single parent who just wanted to get their kid a present for $20, linking your profile the entire time.

It makes the days going back to the office feel more refreshing, like I have more oxygen

For some reason, every time I'm in a conference room I inevitably pass out. Even if I'm not tired and perfectly energetic on the way in, I can count on one hand the number of times I haven't just mentally gone while in one. Wonder why.

For younger group, you don't generally know or give out your number in the first place for person to person communication, which means that for the rare chances you are expecting, say, a medical call once a quarter or less, it's a scam. I don't know my best friend of 10+ years phone number but I can reach them in multiple ways.

If you're older the ratio probably tips it further into the "likely to be a valid call" I'm guessing.

I receive something on the order of one legitimate call every 5-8 months, everything else is spam/scam. There is absolutely no point in me accepting a call.

A formal phone call is generally synchronous, not asynchronous. It is extremely blocking behaviour and I hate it. Joining a group call with a few friends or even just 1-2 other people on discord or whatever else that you can drop out at any time without notice is a different type of "mood" and completely different set of standards. You can drop in and out in seconds, pop in to say hi and leave while you have your airpods in on while riding bart, , or spend hours just discussing dumb shit, etc.

I don't know how well this generalises, but in my sample size most people including myself don't even know our own phone number if asked. You don't exchange phone numbers. You might hold out your phone for the other person to scan your Snapchat QR or tell them @hn2022 and a platform like instagram. If you say hn#2022 people know automatically which platform that is. A sizable amount don't even have phone numbers and opt for data plan only for cost savings if paying for their own plan.

In my groups (gen z), I do not know a single person that even makes calls, ever. Phones are on silent/dnd.

If you ever get a "real" phone call (not via discord, whatsapp, etc) it's either something you are explicitly expecting unavoidably (you would try as hard as possible to get them to email you or text you) or it's a scammer.

trusted solution from a trusted company that gives me the ability to conduct serious work and send/receive sensitive business data over a variety of connections in a secure way

which would put me in the position of having to whitelist an entire coworking space or coffee shop when I need to tell an external service how to allow my computer to connect

Zscaler. Not b2c. Does exactly what you are trying to do, including private connections to third parties (and services "behind VPN" onprem). Not blacklisted/banned from major random sites for spam, etc.

Ask HN 4 years ago

Include 2FA seeds or backup codes, or put a backup yubikey somewhere recoverable offsite.