HN user

kjaftaedi

1,494 karma
Posts2
Comments416
View on HN

I think you are confused.

Sharing your salary is one thing.

Saying that you are an employee at X company and make X dollars is giving away both your salary and corporate information.

The key is not involving the company. Share your salary as much as you want, but don't go on social media and say 'I work for X' unless you are actually their representative.

All web servers respond to all hostnames. It is the default unless you have configured it otherwise.

In the event you are doing virtual hosts in Apache, you just add a single line:

ServerAlias www.example.com

And your webserver will respond when queried via this hostname.

So, even in the worst case scenario, we are talking about two very basic lines of text to accomplish your goal.

The whole setup should take about 60 seconds.

I am not trying to say that your approach is wrong, but just that there is a much simpler way to go about accomplishing this goal.

As far as "overthinking it".. I think we are going to have to disagree here because I am unable to see how your method of reverse engineering can possibly be simpler than something that takes practically no time or effort.

At any rate, this is not an argument, I just want you to be aware of your options as you continue your research.

I wish you luck as you continue exploring, and thanks for the writeup :)

Your comments give me the impression this isn't totally clicking just yet.

All that is necessary is to add an entry in your hosts file for hidusi[.]com that points to the IP of your existing server.

That's it. Step completed.

No localhost, no new site, just using what you have already.

In the event you are filtering hostnames on your web server, you would just add hidusi[.]com as another alias.

Please let me know if this is not clear because I believe understanding this concept will help you in the future.

This concept is not about explaining things in terms a 6 year old can understand.

It's about understanding the subject matter well enough that if necessary you could simplify and elaborate on topics to bring your audience to your level of understanding.

(i.e. - understanding your subject vs. being able to recite facts)

You really come to terms with how well you know a subject when you sit down and try to teach it to someone else.

Every system has a hosts file that you can edit for exactly this purpose.

No need to set up DNS at all.

Your system will resolve whatever hostnames you want to whatever IP addresses you want. You just add the entries to a text file.

It will always override whatever results come from DNS.

The author definitely went the long way with this approach.

We don't have bank account fees.

Another fun fact: pretty much everyone here pays off their credit card every month.

The bank will close your account if you do not.

Of course there are exceptions, but this is the general rule.

(if you need money the bank will lend it to you and help you arrange payments)

150% shameless cash grab and one of the largest wastes of community goodwill in some time.

Honestly if it weren't for the shady actions you described, I maybe could have bit my tongue.

But the wizard-of-oz game they are playing has been enough for me to tell people to contact me on Telegram instead.

Do they not realize they are taking trust away from signal? (aka the primary reason people use the app)

Your analogy is slightly better, but even then it still misses the whole idea of hubs and connecting flights, because it's not just your trip to the beach, it's a whole network of cars trips to the beach that also depend on your trip to the beach in order for the system to function.

Once you start removing trips and other people take your parking spot, you don't always get your parking spot back or even one close, sometimes you might have to find all your cars a new beach to use.

They have the option

That option is to lose their slot, if they lose their slots, they will probably lose an entire hub on their network that they can not regain.

It's not like you can just buy these slots back. In fact, slots are valuable for the simple reason that they can not be bought and sold. (unless airlines consolidate, and even then these transactions are heavily scrutinized)

You're basically saying it is better for them to tank their business so another airline can steal the slots from them.

And do you know what the competition will do? They will keep that slot at all cost regardless of whether their planes are full or not, because this is how airlines maintain their network.

Please consider familiarizing yourself with airline network operations before speaking authoritatively on the subject.

You're making a strawman / false equivalence.

They are forcing them to fly the planes.

The company has already decided the value of the slots exceed the lost passenger revenue.

The company could not fly the plane, but the governments rules force the situation.

The rules were changed during covid to alleviate this, but now that the rules have changed back, we see the same situation again.

Imagine if you were faced with an equivalent dilemma:

You are in a situation where you will lose the right to park in your own garage for a year.

To keep your garage rights all you have to do is drive around aimlessly for an hour.

Do you decide the environment is more important, or do you want to park in your garage?

You're leaving out a lot of valuable information.

Did you check your security log in github?

Do you have MFA enabled on your account?

Did you check your repository and account and make sure that all of the SSH keys saved are recognized and known to you?

Did you refresh all of your keys and make new ones?

You need to start at the beginning.. starting with the theft transactions is starting at the end.

----

Long story short, there is no way to tell you what happened without you investigating first.

It could be you just not MFAing your account and re-using passwords.. and someone logged into your github account and added their own private keys.

Really it could be a million different scenarios, but whatever happened, you need to investigate first.

Pretty much every computer magazine from the mid-late 80s onward had lewd software ads in the back.

Alas, I was too young to cleverly find a way to purchase these without my parents finding out, and was never able to locate a BBS that hosted this type of content.

When I was doing this, I would just use a tablet.

Android, iPad, Windows, they all have monitor extending software and have for at least a decade now.

Saves you the need to by a screen if you've already got a tablet lying around somewhere.

Agreed, but with the target unwilling to contact even his family in 10 years, and being in a completely different country than the one looking for him .. these things make the wiretap theory a little watery as well.

Your second theory would only work assuming google is participating in blanket facial recognition with various law enforcement.. which while possible, would be a small scandal if revealed.

I severely dislike Amazon and try to avoid supporting them, but, I do have the original echo with the video screen and it's better now than when I bought it.

At some point they even added the ability to control my Phillips Hue lights, whereas when I bought it, it didn't have whatever smart hub capabilities were needed for this to work and I was told I needed to upgrade to a newer device.

Instead over time they also found a way to bring the feature to me, which I appreciate.

Finding this person at random in an area of 100s of millions of people, and recognizing him 10 years later from a photo where his face is totally blurred?

I feel like there's another piece to this story that is being hidden.

The Facebook and Google finds are likely both came after whatever the original clue was.

My guess is they are protecting an informant.

Also, it's not like they maliciously inserted this thing to mine crypto for Norton itself.

No, but it is still malicious in the sense that it:

(1) does not inform the user or ask for consent

(2) seemingly does not offer an option to disable it

While I want to apply Occam's razor here, you'd have to assume all of the people that worked on this were negligent or unqualified... when sadly the more likely scenario is that these decisions were most likely intentional.

Agreed, but the line of thinking is to try and prosecute this.

You'd have to prove to the court that theranos used their bad techniques instead of their good ones.

I am not as optimistic they kept such detailed records of their crimes, and feel this would be a tough angle to successfully prosecute.

They had a fully functional lab though, it just wasn't using Theranos' devices.

This is what they did to Wallgreens, they sold them on the idea that they would have theranos machines in-store, but instead what they did was do IV blood draws (calling it a comparison check) .. and then would just process the samples the same way as everyone else using standard equipment.

People were getting good results because Theranos was using machines from Siemens in their hidden lab.