HN user

netsectoday

431 karma
Posts4
Comments119
View on HN

You can use capacitive water sensors taped to the outside of non-capacitive containers (aluminum foil, a resistor, an arduino, and a plastic 5 gallon container), but honestly all you need are DNI timers to "automate" any grow operation. Put your lights and pumps on a schedule and there is absolutely no reason to get more creative. If you do anything besides low-level timers you're making it complicated and brittle with no added benefit.

Do you know that Microsoft Bing maps also "steals" the OSM data? They did some very clever "reverse stealing" as well when they contributed back to the project by providing millions of accurate building footprints.

Yes, I'm being sarcastic. It's a win-win situation when ANY large mapping group joins OSM. At the very least; they will accidentally contribute road-level improvements when they work with the data. I rely upon OSM data and need these large players throwing their weight behind this mapping system.

All soil moisture sensors will eventually become uncalibrated, wear out, or fail.

The only automation you need to keep a plant alive is a timer attached to a water source. Also, don't forget to feed it with nutrients every month or so... they don't eat soil and letting a plant starve isn't proof you needed a moisture sensor.

I refused to reward Google with traffic on their newly forced ads for every youtube video. You should boycott them too until they U-turn on this bad decision.

Totally agree. I’m thinking in terms and concepts like “iptables”, “ipset”, “fail2ban”, “cidr”, “asn”… while everyone else is thinking about how to change their cloudflare settings.

OP even said they gave up on cloudflare but people are trying to upsell him on the higher tiers through this hn post!

You are 100% correct! They have been scamming BILLIONS of dollars from the world for a decade.

"Uber's Operating Losses Piled Up to $12 BILLION since 2014" (source is from 2018)

https://cdn.statcdn.com/Infographic/images/normal/17705.jpeg

"Uber Technologies Inc (UBER.N) on Thursday reported its first profitable quarter on an adjusted basis since it launched more than a decade ago - November 4, 2021"

https://www.reuters.com/technology/uber-posts-first-small-ad...

you really shouldn't be hacking some scripts on top of your bank login

You can hack whatever you want, but from a SECURITY perspective this is horrible and the banks know this. There are secure ways to store credentials for scripts but most people will just hard-code the values or stick them in unencrypted ENV vars. Also, who's fault is it when the bank updates their website and the selenium script does something horribly wrong? Tell me more about Disney...

When a selenium worker is attached to a pay-for-solution captcha service the infinite loop of captchas that can be solved but don't provide access would be meant to drain you financially. You uncovered a pretty sweet (dark) pattern implemented by Cloudflare to screw bot owners.

This is just #2 and #3 combined.

It sounds like this is working as intended and also wastes your time with un-passable captchas instead of you spending more time trying to figure out how to get around their bot protection.

Another observation here is that you really shouldn't be hacking some scripts on top of your bank login. The banks know this and they are trying everything possible to dissuade you from doing this.

Seeing that over 90% of my traffic load was malicious and abusive was frustrating.

That story nailed it.

If you’re curious, Cloudflare did pay me for the site. We made a deal for them to pay me $8.03; the cost of the domain registration. The goal was never to make money from the site.

A little more than $1, but basically the same idea.

If you expose a web server to the internet today you'll get 10 malicious requests for every 1 legitimate request.

This constant and unrelenting beating at your doors doesn't go away unless you add perimeter protection.

The options here are:

1) Block the IP and cidr ranges that are giving you trouble

2) Silently scan the connection request and block it when things look fishy

3) Provide a challenge in the return response that is difficult for bots to complete

Most of the bot protection on the internet is #2 where you don't notice you've been verified as a human and the site just loads. People hate #3 of completing a challenge, but the other option here is #1 where the site doesn't load at all.

I'd argue that bots are breaking the internet.

Anyone who monitors their web traffic would tell you the bots are ruining the web.

I hate these "are you human" checks too, but when a persistent threat is poking your defenses and legitimate web traffic is only 10% - 20% of your server load... you have to do something.

So the alternative here to receiving a challenge is that the site would just be blocked in your country or for your network provider.

Would you prefer to be outright blocked, or is it ok to have an annoying "are you human?" challenge?

Who tf cares?

This article with the sections "Why I'm Right", "Why You're Wrong", and "Conclusion" is the perfect blogspam I'd expect from Viget. You guys don't have anything of value to say and I got this same "I'm better than you" treatment when I interviewed to be a dev at your shop years ago. I'm not salty because I got turned down; I'm responding today because you guys are pompous and are spreading that attitude with bad hiring practices in my area, and garbage blog posts in my neck of the internet.

I already have a docker registry too, so I guess I missed the point of your entire article. You can use the registry as a cache for build artifacts... that's what it's for. Your article was written like you just figured that out, and I was providing context to the other confused HN users.

There are legions of people who swore off anything M$ years ago when they found alternatives that worked better for them, and they stuck to it.

Here's the perspective from the outside: M$ has billions of lines of code, or more, and they just keep patching their software. They established their way of doing things years ago with DOS and have built on top of that since. That's how the entire industry has done it, but since M$ got so big they can't just refactor things and drop support without a billion people yelling at them, so they keep the old code and just keep patching.

They have so many people banging on their software that most of the failures are caught pretty quickly, but then there are the edge cases that don't fit into daily business activity and M$ gets pwned in that space. Their software is so vast that it doesn't cover their entire decision tree, so on the edges people begin to play around and find things not covered by testing. They might be complicated exploits that tie many things together, but it's not beyond the general public to find them with a little digging. This opens up a full exploit on M$ systems or infrastructure, then they get around to patching it a month or two later.

From the perspective of a CISO this is unacceptable. I prefer my auth software to be explicitly precise.

This might sound crazy to someone who is in an industry where "everyone is doing it", and there appears to be no other way to integrate but with M$. I'll let you know we both feel the same way because it's crazy to use (and pay for) such slovenly designed software.

This article is weirdly vague in the sense they didn't mention the registry is is an official docker container: https://hub.docker.com/_/registry

It also doesn't go into any of the detail about starting up / configuring the registry, or explaining that running your own version is like running you own private hub.docker.com.

The registry is great! It just doesn't seem to be maintained much anymore, maybe because it's feature complete, or maybe because Docker is trying to sell plans to their "hub".

For anyone else interested in advanced Docker features: check out Docker Swarm (the only way to reasonably run Docker Swarm is to manage your own Docker Registry).

Just a few things to note here...

I wrote the original "Wife swipes open the phone" comment, so that's the context you seem to be missing. Sure you can see a little dot on your phone when YOU run some experiment today and look for it, but was that indicator available in the exact situation where the targeted ad was displayed? No.

Also, this incident happened in the past and we know there have been dramatic API changes on both Apple and Facebook products. The limits of the API today don't reflect the capabilities that were available to developers in the past. I doubt Facebook is hacking the App Store process to use hidden APIs. It was probably just available in the past and my wife granted the facebook app complete access to the mic, so they took what they wanted.

I'd make sure to disable that permission today too, just in case.

One last thing is I just opened my iPhone again and hit record. I honestly didn't see the tiny orange pixel at the top of my phone until you pointed it out. I was basically looking for the green video indicator light to show. So I'm technically wrong about NO indication, you're welcome.

Goal posts? Is this a competition?

The phone was sitting between two people having a conversation, one of them "swiped it open" meaning it was off to begin with, then was immediately displayed an ad for that conversation, and upon hearing this the tech-savvy person in the house understood what happened, confirmed it with the mic access to facebook in the settings, and then disabled the behavior.

This is a message board about tech... comments aren't welcome anymore - we need evidence to participate?

I think it's interesting when a bunch of people chime in and say "Hey, yeah, I had some crazy thing happen to me, I'm in tech and understand how this stuff works, and there's a very small to zero chance this happened through some other parallel construction by the tech company, they just straight up listened to my conversation and showed me an ad".

This is what kicks off a handful of you to go packet sniffing and write up a blog post looking for this behavior. So yes, evidence is welcome but it doesn't seem like we are quite there yet.

The screen was off when the event happened...

1) Does your iPhone still record audio when the screen is off?

2) Can you see the audio indicator when the screen is off?

3) If a background app starts then stops recording audio while the screen is off, would you have an indicator that it recorded audio?