HN user

f2n

875 karma
Posts19
Comments95
View on HN
cloudyday.tech.blog 8y ago

Why are there toilets on my openSUSE wallpaper?

f2n
6pts1
www.threat9.com 8y ago

RouterSploit 3.0: Exploitation Framework for Embedded Devices

f2n
1pts0
github.com 8y ago

Windows10_ntfs_crash_dos: PoC for a NTFS crash in various Windows versions

f2n
2pts0
osmocom.org 8y ago

Osmo-fl2k: VGA dongles as transmit-only SDR

f2n
3pts1
twitter.com 8y ago

Russian government told APKMirror to stop serving Telegram APKs in Russia

f2n
1pts0
github.com 8y ago

Jo: a small utility to create JSON objects

f2n
2pts0
infosec.rm-it.de 8y ago

iOS camera QR code URL parser bug

f2n
1pts0
www.eff.org 8y ago

Secure Messaging? More Like a Secure Mess

f2n
2pts0
www.eff.org 8y ago

EFF and 23 Groups Tell Congress to Oppose the CLOUD Act

f2n
65pts1
eprint.iacr.org 8y ago

Handycipher: A Low-Tech, Randomized, Symmetric-Key Cryptosystem [pdf]

f2n
2pts0
www.samba.org 8y ago

Samba: Authenticated users can change other users' password

f2n
96pts13
www.engadget.com 8y ago

Voting-machine makers are already worried about Defcon

f2n
2pts0
beta.latimes.com 8y ago

In Vermont, lawmakers lead the way on legalizing recreational pot

f2n
3pts0
www.thestranger.com 8y ago

Facebook, Google Ask for Time to Comply with Seattle's Election Transparency Law

f2n
3pts1
www.nvidia.com 8y ago

NVIDIA GeForce driver deployment in datacenters is forbidden now

f2n
358pts200
blog.twitter.com 8y ago

Introducing Vireo: A Lightweight and Versatile Video Processing Library

f2n
61pts8
rejected.us 8y ago

We All Face Rejection

f2n
1pts1
www.troyhunt.com 8y ago

HTTPS on Your Landing Page Is Important

f2n
639pts288
research.googleblog.com 8y ago

Introducing Appsperiments: Exploring the Potentials of Mobile Photography

f2n
1pts0

It wont let you vefiry by entering a code

That's odd because I've absolutely verified numerous Signal clients by entering a code, without granting access to my SMS (I use Google Voice so my SMS database is basically empty except for random spam from my shitty carrier)

You've linked that thread a couple of times here, never really elaborating on the nature of your concerns, nor do you elaborate on the specific nature of your concerns in the ticket. Have you considered elaborating on the nature of your concerns? Is there a specific vulnerability in chromium you feel could be exploited here?

It'll be interesting to see how this works, given that the Signal Desktop client's main page (background.html) includes a CSP that restricts it from running inline or external scripts. It can only run JS that's already in the Signal Desktop package (in theory).

The fact that this isn't being described as an issue with CSPs or electron makes me wonder how it could possibly work.

The owner of this website (through-the-interface.typepad.com) has banned your IP address

Whelp, I guess I didn't care that much.

GitHub Checks API 8 years ago

These look really nifty. I'm hoping GitLab will add similar. I particularly like that the build can be failed due to a specific line. I've noticed that all of the CI output can be confusing for some, and it becomes difficult to suss out the specific error messages amid all the other output.

Native apps have led to slow, bloatware-, spyware-, and malware-infested mobile devices. The browser is a much better sandbox, giving much less permissions to the untrusted code.

Why is is_anonymous = true for a tor relay? Why are relays and exit nodes given the same flag? As a tor relay operator, I anticipate this being misused, like so many before it, to arbitrarily block all tor relays by people who don't know or care how tor works.

Dissident.ai 8 years ago

"Tech is the center of our modern lives. But it's broken."

on a page that doesn't properly render without running Javascript from 2 third-party services. There are also multiple third party javascript includes explicitly for surveillance/metrics. I agree that the system is broken but I don't trust these clowns to help

Try using an email address with .wedding or .solutions TLD. Loads of absolutely brain-dead sites refuse to allow them, sometimes they validate by TLD length (all TLDs are 2 or 3 characters, apparently) or other times rejection TLDs they haven't whitelisted.