That's a great writeup. Is it possible to create a really long passphrase whose hash can't be reversed easily? Perhaps a diceware passphrase with six randomly chosen words?
HN user
jermier
Cool project. I like to hide data in audio files with Deepsound https://deepsound.soft112.com/
Yeah and we have better training material for AI now. For example it could be possible to create a program that mimics Hackernews comments. There's more than enough training material on HN to create plausible-looking comments that aren't a bunch of nonsensical gobbledygook and that also pander to people's emotions.
I can understand what they mean if they use "shill"
You kind of answered your own question. Many people never differentiate between bot and shill, instead preferring to lump those two words together. A bot is programmatic; a shill is a human agent that likes to amplify messages or spread disinformation manually. Although some shills may still use some level of automation, for example, often using several accounts at the same time using some bespoke software arrangement.
All the so called 'neo banks' are still in their infancy which is good reason to avoid them at all costs. I'm waiting until these startups mature (and they are startups).
One thing I never got about premium password managers is the question of: If I stop paying for the subscription, do I still get to access my secrets? I imagine there is still some grace period to backup your stored secrets, but I still think PW managers should offer a free tier so that you can be assured you will still be able to access your secrets, regardless of payment obligations.
Also recently spotted as an avenue for attack in the wild:
Magecart group uses homoglyph attacks to fool you into visiting malicious websites: https://www.zdnet.com/article/magecart-group-uses-homoglyph-...
Homoglyph attacks used in phishing campaign and Magecart attacks https://securityaffairs.co/wordpress/106916/hacking/homoglyp...
I always loved the whimsy present in Unicode. For nostalgia, here's a HN post from 2010 pointing to the `Unicode Snowman for You` site (which is still up!)
https://news.ycombinator.com/item?id=2035572
And the site:
It would be cool if MDN had a Stack Overflow question-and-answer style format alongside the main offering. Then Mozilla could take advantage of the gamification model where users earn badges and awards for their efforts.
Jeff Atwood said it once: `If you put a number next to someone's name, then that person will try everything to increase that number`. Also: it would look good on CVs and would be a good heuristic to determine if a person's really fit for a position.
I was referring to the phrase 'cult of the free' which is poorly chosen language as it doesn't distinguish between freedom versus monetization.
That's your typical The Register hyperbolic headline for you. They're infamous for dressing up headlines with hyperbolic adjectives.
Cult of the free
This is poorly chosen language as it doesn't distinguish between freedom versus monetization.
I think most users of free software know it's 'free as in freedom' and they are not being duped.
I think most users of free services are duped into thinking it is actually free and are unaware their data is being sold and monetized and are paying for the service with their data. Lately more people are waking up to that fact though. I don't mean services like MDN, just things like Facebook, Google etc
So what if someone sleuths around in the e-waste dept. of Instagram and steals a few hard-drives with literally Terabytes of potentially very sensitive data? That's why I would hope Instagram are encrypting data at rest with something like LUKS.
Yes, and you could also queue files for deletion at a later stage by throwing away the encryption key for a large batch of files which have been queued for deletion.
I want to know if the photos are securely deleted. It's not enough that the mere reference to a file is gone. I want everything overwritten with zeroes, and the photo made properly irrecoverable.
I like to run `wpd` for clients[0]
It gets rid of the programs that obtrusively weigh down the system, as-well as removing a lot of cruft the typical user doesn't need. Disclaimer: it can break some things, but it's a small price to pay for a hardened system.
[0] https://wpd.app/
It's as if the author writes content to /please/ Google. There are other players in town that will spread my message wide, other than Google. Google is a single point of failure too. If most of your traffic relies on a black-box algo developed by Google, at some stage you are going to be butthurt by that algo. Others will celebrate their success at gaming Google's algo and getting good rankings consistently, but these people are mostly blackhat SEOs probably trying to peddle cialis with a cheap discount.
Security – The operating system installed in a container is usually short-lived, very minimal, and sometimes read-only. It therefore provides a much smaller attack surface than a typical general purpose and long-lived server environment.
Is this true? I always thought things like Docker are massively insecure because they don't respond to the threat landscape that well, since they are kind of 'frozen in time' and kept that way for years at a time without any critical security updates.
I miss OVH's old control panel. It was so nerdy and to-the-point, unlike their newer modern interface that heats up my CPU with boatloads of javascript, and adopts the 'flat' design pattern that has now permeated every site in existence.
Who's behind this site? I don't see any credits in the footer or an about page, and the `whois` record is vague and scant on details: https://who.is/whois/ilovemdn.org
Is the OP behind it? https://www.peterbe.com/
things like bits of his glasses disappearing indicate that he could be CGI
So you're essentially saying the revelations were a false flag operation? I considered that possibility, but Snowden's background is well researched and the first thing media outlets look at before publishing their findings. The Guardian probably thoroughly doxed him before publishing anything. And in interviews he comes across as sincere and genuinely politically passionate. There's no way someone could fake all that. Snowden is the real deal.
If the NSA wanted to showcase their 'box of tricks' then they would have other ways of doing that like fake leaks that have a bunch of decoy material to confuse their enemies; not the real/actual tooling that is used to surveil (as that would be stupid). They would release plausible-looking material that advertises their capability, but be scant on the details and mechanics of the tooling itself.
There are people out there resisting these efforts. For example, I know people who are against smartphones and use a so called 'dumbphone' or feature phone for their main number. If they need to buy groceries, they refuse to use a loyalty card, and always pay in cash. They typically have a secure and private laptop with something like Ubuntu on it, and use Firefox with all the anti-tracking features enabled, and uBlock Origin installed, JS turned off by default etc. The typical steps people take to minimize their footprint against these predictive algos
Not sure, but I hope they do, as it's an often forgotten avenue for exploitation. You can't deny the human factor in a lot of these instances. Humans are humans. Also see: https://en.wikipedia.org/wiki/Human_intelligence_(intelligen...
Probably could have earned a lot more from his exploits if he went the formal route and directly confronted Twitter. But then who even knows if Twitter are a good 'first responder' when it comes to high-profile exploits of their system.
There was a recent post about some researcher who exposed flaws in Tor's architecture (which allowed third parties to detect Tor traffic easily) and Tor's staff didn't respond; so she published the finding without going through the proper channels, both embarrassing Tor staff, and simultaneously strengthening the Tor network.
The 'I'm going to publish this sploit because you didn't respond' is a good tactic and I want to see more people do it. It's just unfortunate that the various channels like HackerOne[0] or wherever the skiddies flock to these days are not utilized thoroughly.
I hate it when coding is seen as this herculean task that apparently demands near superhuman focus and physical/mental stamina. It doesn't have to be that way. You can customize your environment to be as frictionless as possible and bang out good code without trying super hard.
The key is customization and passionate, opinionated environments (both physically and virtually, i.e; ergonomic keyboards, chairs, etc, alongside a text editor that fits your coding style, and rapid viewing of what your changes have actually done, no more coding in a black box).
I use an old inversion technique. Not sure where I read this, and I think Tim Ferris said it:
The last thing you want to do is the first thing you should do
There is always something mega pertinent on my TODO lists that I really don't want to do, and it calls out my name when I sleep saying: 'You really need to do this' and the feeling of procrastination makes you feel ashamed of having not completed the task. But it gets done thanks to inversion, and I proudly check it off as being done, until the next task I don't want to do comes along (and yes it will come along).By this I mean /stating my opinion/ or more precisely, revealing various unconscious biases I may have towards a subject.
Sometimes stating an opinion is making the unconscious, conscious, and then learning the truth about a subject by the insights and replies of others.
In other words, I'm shooting in the dark most of the time on HN and waiting to hit a target, or some truth I can salvage from the replies of others.
Interesting that the word 'secretly' is used in the title, after the fact, and not before it
I do this on Hackernews sometimes. I just state my opinion, however weakly held, and wait for it to be torn apart, where I learn a lot, and all my biases are revealed to me. That's how learning works: you challenge your own assumptions, or let your assumptions to be challenged by others.