HN user

newscracker

8,123 karma

Techie.

Value privacy and freedom. Strong dislike for online tracking, privacy intrusions, DRM, etc.

Love (FLOSS) software like Mozilla Thunderbird, Mozilla Firefox (with several extensions), Ad blockers and tracking disablers, VLC, LibreOffice…donate money to them as a show of support.

For those who wonder why privacy matters, this is a concise article I always point to - "Privacy protects bothersome people" [1] by Martin Fowler. There's also "Nothing to Hide – a documentary about surveillance and you" [2]

Recommendations: Don't use WhatsApp [3]. Don't use Chrome browser. [4] Don't use Facebook (needs no explanations).

[1]: https://www.martinfowler.com/articles/bothersome-privacy.html

[2]: https://vimeo.com/189016018

[3]: https://www.eff.org/deeplinks/2016/08/what-facebook-and-whatsapps-data-sharing-plans-really-mean-user-privacy-0

[4]: https://blog.cryptographyengineering.com/2018/09/23/why-im-leaving-chrome/

hnchat:eemynUE5V50ZFdTyjq3S

Posts19
Comments2,145
View on HN
www.technologyreview.com 5y ago

Hackers are finding ways to hide inside Apple’s walled garden

newscracker
5pts0
www.reuters.com 5y ago

Singapore becomes first country to approve sale of lab-grown meat

newscracker
4pts0
siliconcanals.com 6y ago

French startup offering cookie-free adtech solution secures €2M funding

newscracker
2pts1
organize.readthedocs.io 6y ago

Organize – The file management automation tool

newscracker
2pts0
www.arkansasonline.com 6y ago

NYC Council votes to ban cashless stores

newscracker
2pts0
blog.mozilla.org 6y ago

Bringing California’s privacy law to all Firefox users in 2020

newscracker
4pts0
www.schneier.com 6y ago

The Eternal Value of Privacy (2006)

newscracker
1pts1
mjtsai.com 6y ago

Apple News No Longer Supports RSS

newscracker
781pts263
arstechnica.com 6y ago

Camscanner app adds trojan and malware

newscracker
5pts2
website-archive.mozilla.org 7y ago

Phoenix 0.1 (Pescadero) Release Notes and FAQ

newscracker
1pts0
www.vice.com 7y ago

'The Office' Leaving Netflix Is Going to Drive Viewers Back to Piracy

newscracker
2pts2
docs.google.com 7y ago

Mozilla's Position on Web Packaging

newscracker
3pts0
techcrunch.com 7y ago

Privacy is a commons

newscracker
2pts0
www.washingtonpost.com 7y ago

Netflix raising prices for 58M US subscribers as costs rise

newscracker
7pts2
www.theverge.com 7y ago

Facebook dating launches today

newscracker
1pts2
www.macrumors.com 7y ago

Apple Expanding Pilot Program Allowing Repairs of Select Vintage Macs Worldwide

newscracker
2pts1
www.hpe.com 10y ago

HPE spins off Enterprise Services to merge with CSC

newscracker
2pts0
time.com 12y ago

The Best Web Browser

newscracker
3pts0
www.change.org 12y ago

SpiderOak: Petition to open source all your code

newscracker
3pts5

The attack seems to work by spanning various instructions that if run through macOS’s Terminal utility could steal stored credentials from Chromium-based browsers along with data from cryptocurrency wallets, placing them into a zip archive then sent to a hacker-controlled domain.

What is it about Chromium based browsers that this attack narrows down to? Is it something technical in the ease of stealing information or just the imagined market share by the attackers? As per Cloudflare’s statistics browser share on macOS [1], it seems like Google Chrome users are a little less than two thirds of the total user base. But Safari still holds one third of the user base. Ignoring Safari seems like a poor mistake.

[1] https://radar.cloudflare.com/reports/browser-market-share-20...

I’ve used Wire in the past and liked that it uses email addresses for registration (as pointed out in this article). Wire also had multi-device message sync long before Signal did.

But on a different point, Wire is inferior to Signal. Signal has a painfully slow data transfer when switching devices. But given some time, the data transfer does work completely.

On Wire, my experience has been that all media in chats are stored on the Wire servers and the backups don’t contain the media. They contain links to the media, while the media may be erased on the servers after sometime. I’ve lost a lot of media from chats on Wire when switching devices and restoring the backup from the original device. Only the text of the messages remain. At that time, Wire’s backups were also device/platform specific.

Since I place a very high level of importance on retaining and transferring data, I wouldn’t recommend Wire to anyone who wants to retain chats for longer durations.

But when readers realised that Meta was trying to suppress it, the book became a global phenomenon. To date we’ve sold almost 200,000 copies.

The number of copies sold seems quite low for this book. It’s difficult to believe that across paperback, hardcover, ebooks and audiobooks, it hasn’t sold several million copies. This report is from February 2026 (just a month and a half ago).

HTML entities are often decoded automatically by server-side libraries, which means that even the most basic harvesters can get your email addresses without any special effort. This technique should be worthless—and, yet, it still stops most harvesters.

Anecdotal, but I’ve used HTML entities on a public static website for a long time using an href tag with mailto, and yet I’ve not seen any spam.

I guess any spammer who uses some level of GenAI to process and extract email addresses would have a lot more success against all the methods listed in this article.

Flighty Airports 4 months ago

The promise is that it informs you quickly about flight delays, flight cancellations and gate changes. In my limited experience, it didn’t work satisfactorily for a flight delay of a few hours. It could not provide any reliable updates.

It’s a nice app and service, but I wouldn’t trust all those reviews that are like “I knew before the aircraft pilot knew”. It has its own limitations.

In a way, this is like saying that one trusts total strangers in some random large tech company and total strangers in government agencies to read and/or manipulate conversations that kids have. This also paves the way to disallow E2EE for other classes of people based on arbitrary criteria. I don’t believe this is good for society overall.

Is there any smart TV that I can actually just use a TV how I want?

I’ve heard that large computer monitors and TVs intended to be used as displays can be used without connecting them to a network.

Or am I reduced to buying an Apple TV device and unplugging the TV from the internet entirely ?

An Apple TV is a good choice even otherwise. I’ve never seen a smoother and quicker interface on a native Smart TV (granted that I’ve only seen Android and webOS). I use my Apple TV as the only network connected device while my TV is not connected to any network ever. Once in a while, I update the TV’s firmware by downloading it to a thumb drive and plugging that into the USB port of the TV.

This is quite surprising to me, since I thought the percentage would be a lot lesser.

But I don’t really know what the Firefox team does with crash reports and in making Firefox almost crash proof.

I have been using it at work on Windows and for the last several years it always crashes on exit. I have religiously submitted every crash report. I even visit the “about:crashes” page to see if there are any unsubmitted ones and submit them. Occasionally I’ll click on the bugzilla link for a crash, only to see hardly any action or updates on those for months (or longer).

Granted that I have a small bunch of extensions (all WebExtensions), but this crash-on-exit happens due to many different causes, as seen in the crash reports. I’m too loathe to troubleshoot with disabling all extensions and then trying it one by one. Why should an extension even cause a crash, especially when its a WebExtension (unlike the older XUL extensions that had a deeper integration into the browser)? It seems like there are fundamental issues within Firefox that make it crash prone.

I can make Firefox not crash if I have a single window with a few tabs. That use case is anyway served by Edge and Chrome. The main reasons I use Firefox, apart from some ideological ones, are that it’s always been much better at handling multiple windows and tons of tabs and its extensibility (Manifest V2 FTW).

I would sincerely appreciate Firefox not crashing as often for me.

Try to beat this: https://fingerprint.com

I don’t know, but it seems like it’s overselling its capabilities. I tried with Firefox Focus and it said I’m using incognito (private mode) and assigned a unique visitor ID. Immediately tried with a private tab in Safari on iOS and it said I’m not using incognito (private mode) and assigned a new unique visitor ID. Then I switched networks and tried. One more unique visitor ID.

I’m not claiming that fingerprinting is not possible, but this website is not good at it. Seems like it uses plain cookies.

When I use Windows, Everything is one of the first tools I install. I also disable Windows search and indexing.

I use this with Keypirinha [1], which is a launcher (kinda like Quicksilver [2] on Mac) that integrates with Everything using the Everything package. [3]

This combo makes finding files as well as launching programs (or doing quick calculations or currency conversions) a breeze!

[1] https://keypirinha.com/

[2] https://qsapp.com/index

[3] https://keypirinha.com/packages/everything.html

It doesn’t explicitly state anything about the email contents in the privacy policy page. People generally trust their email providers to not snoop in their emails. I wonder why anyone should trust a cloud based service (such as this).

A4 Paper Stories 7 months ago

If you have a Pro or Pro Max model of iPhone from the last several years, it has a LiDAR that allows the pre-installed Measure app to measure lengths/heights, etc., using the camera. Several higher end Android phones may also have the same.

You can search "!w Gabriel Weinberg" and it will open the Wikipedia article because of the leading exclamation mark and w

Just for anyone else who isn’t aware, the bang commands can be anywhere in the search string, and need not necessarily be at the beginning.

All these queries will take you to Wikipedia for the term:

"!w Gabriel Weinberg"

"Gabriel !w Weinberg"

"Gabriel Weinberg !w"

Many a times when I find the default DuckDuckGo search results inadequate and want to go to Google search, I just put a “!g” as a separate term anywhere within the search string and hit enter. This is especially useful on mobile where the search string may be a lot longer than the visible text box and I can’t be bothered to move the cursor.

I love that duck.ai provides a more private way to use different smaller and medium (?) scale LLMs.

I don’t like the duck.ai interface much (choosing a different LLM is not easy once you’re already in a conversation), but I use it a lot more than I use the DuckDuckGo search engine (the results from the latter aren’t great).

Just like with DuckDuckGo search, where I start a search and then use the !g bang command to go to Google for better results if needed, I try duck.ai and then move to ChatGPT (without any account) when even the best models in duck.ai aren’t good enough.

For most simpler queries though — where I’m just looking to learn a bit about something as opposed to finding a solution for a specific (more complex) question or problem — duck.ai with its GPT 5 models are more than adequate (even the 4o mini is fine).

A couple of quick observations and comments after skimming through this (some of these are mentioned or hinted at in the RFC).

With HTTPS used almost everywhere, using this QUERY method (when standardized) could prevent bookmarking specific “GET” URLs if the developers thoughtlessly replace GET everywhere with QUERY.

One of the advantages of GET is the direct visibility, which makes modifications simple and easy for almost anyone (end users, testers, etc.).

The larger question I have is who will choose to adopt it sooner, with web servers, web application frameworks and web browsers in the mix.

I read through this. I don't think Proton Mail is a good replacement for Signal (it's worse because Proton does log and share IP addresses of users with a court order).

One thing I dislike about Signal on its privacy posture is that the moment you register, anyone who already has Signal and has your phone number in their contacts list will get a message saying you're on Signal. This is a good way for others with bad intentions to know about your presence on the platform. The options to hide your phone number are available only after registering on Signal (after this broadcast has already happened) and when the user figures out that this is possible somewhere deep in the settings.

On registration Signal could ask whether to inform all random people who happen to have your number. But since unused/discarded phone numbers are recycled by carriers to other customers within a matter of weeks or months or years (depending on where you are), your presence on Signal may be sent to someone you've never ever known or has known you. Signal ought to remove this broadcast on registration. Telegram (and I guess WhatsApp) also suffer from the same issue.

Never on iOS or any other Apple platform. Signal is designed not to be able to backup to iCloud either. The only option iOS users have had over the last few years is to do a device to device transfer where both phones are expected to be in physical proximity and it takes hours to transfer the data. Lost phone has meant losing all chats.

WhatsApp, which is infamous by association with Meta, backs up to Google Drive or wherever.

Wherever you can host something like WordPress, you can host Campfire

I’m going to be pedantic here, but this statement is not true. I host a website on a provider that allows WordPress (PHP) along with MySQL, but

System requirements & installation

Campfire is packed as a Docker container image

the web host provider does not allow Docker (it runs on BSD).

I’d suggest improving the system requirements section by actually stating the system requirements. To me the mention of Docker without other details is a black box that I cannot have any intuition for.

I feel what this article says based on some recent (non-catastrophic) experiences. I think I’m probably an above average user when it comes to Excel skills. I love spreadsheets. But I struggle with formulas like index, match, vlookup/xlookup and many others, and even more so when it requires nesting one within another and coming up with the underlying logic that leads to some complex nested formulas.

Over the past couple of months, I’ve tried some smaller models on duck.ai and also ChatGPT directly to create some columns and formulas for a specific purpose. I found that ChatGPT is a lot better than the “mini” models on duck.ai. But in all these cases, though these platforms seemed more capable than me and could make attempts to explain their formulas, they were many a times creating junk and “looping” back with formulas that didn’t really work. I had to point out the result (blank or some #REF or other error) multiple times and they would acknowledge that there’s an issue and provide a working formula. That wouldn’t work either!

I really love that these LLMs can sort of “understand” what I’m asking, break it down in English, and provide answers. But the end result has been an exercise in frustration and waste of time.

Initially I really thought and believed that LLMs could make Excel more approachable and easier to use — like you tell it what you want and it’ll figure it out and give the magic incantations (formulas). Now I don’t think we’re anywhere close to that if ChatGPT (which I presume powers Copilot as well) struggles and hallucinates so much. I personally don’t have much hope with the (comparatively) smaller and older models.

Authenticate where? How does the authentication prove that the intended recipient is the one who has clicked on the link and should be able to view? What happens if the email is forwarded with the link? What should one do to forward the email to someone without this encryption?

Organizations may need ways to store, archive and manage received email content from others.

I don’t understand what problem this solves for organizations and how.

Microsoft Outlook 365 has a somewhat similar feature where the email is just a link to hosted content on its servers (this kind of functionality isn’t new or recent on other platforms). It doesn’t require any authentication by the recipient. IIRC, the sender can also decide on the expiry of the content.

Last I checked, Proton Mail does not support standard email client protocols. So you’re stuck with its apps and a browser interface or with buying a paid subscription and using a bridge software on desktop to use a client like Thunderbird. Getting mails out of Proton Mail is also not as easy as setting up a client with IMAP or using other tools like imapsync.

Signal Secure Backups 11 months ago

Chat messages with some people can hold a lot of value. Nostalgia, recalling past incidents/events, missing someone, etc. Sometimes even the most trivial of messages can be looked at with fondness and longing.

I’m personally very glad that Signal finally implemented this. It’s been such a short sighted strategy to promote itself like a mass market messaging platform while not allowing people to keep, move and restore memories.

Since it’s opt-in, those who don’t want it don’t have to use it. They’re well served by the self-destructing message timers in chats.

Not paying with cash 11 months ago

I feel there’s very little hope for privacy and freedom if people like the author — who claim to be for privacy and understand the implications of digital payments — choose cards all the time “because it’s convenient”. Convenience and coercion (by the businesses not accepting cash or governments forcing more “cashless”) are what the common person succumbs to.

I’m not saying that everyone should switch to cash for everything all the time. But the more that privileged people switch to digital payments and eschew cash, the more difficult it becomes for those who rely on or want to use cash to do so.

Choosing privacy could mean a little more (or a lot more, depending on one’s views) inconvenience. Hopefully there are still enough people who use cash and keep cash payments alive for longer (which helps many other people who may not be as privileged or as educated as a different crowd).