HN user

pgl

1,851 karma

Hello.

[ my public key: https://keybase.io/pgl; my proof: https://keybase.io/pgl/sigs/5wXtN7ZE9FDUlUhi2APUjPB6bO7j5Rv8rUlNND5fqUE ]

Posts45
Comments183
View on HN
research.empiricalsecurity.com 22d ago

The Vulnerability Identity Crisis

pgl
2pts0
research.nccgroup.com 3y ago

State of DNS Rebinding in 2023

pgl
5pts0
kellyjonbrazil.github.io 3y ago

JC – JSONifies the output of many CLI tools

pgl
411pts132
www.quad9.net 4y ago

German Court Rules Against Internet Security Non-Profit Quad9

pgl
298pts192
lookyloo.circl.lu 4y ago

Lookyloo

pgl
1pts1
twitter.com 5y ago

Graphs of relationships between DNS RFCs

pgl
9pts0
najinsan.wordpress.com 5y ago

I paid for Spotify playlist placements so you don’t have to

pgl
222pts109
twitter.com 5y ago

macOS monitoring application launches of Firefox

pgl
4pts0
github.com 7y ago

Show Facebook Computer Vision Tags Extension

pgl
1pts0
www.cpsc.gov 7y ago

Apple Recalls 15-Inch MacBook Pro Laptop Computers Due to Fire Hazard

pgl
48pts18
techcrunch.com 7y ago

Science publisher IEEE bans Huawei from peer-reviewing papers

pgl
2pts0
www.facebook.com 7y ago

Cyberwar in a Nuclear Age and Nuclear War in a Cyber Age [video]

pgl
1pts0
php.net 7y ago

PHP 7.3 released

pgl
1pts0
daniel.haxx.se 7y ago

How to DoH-only with Firefox

pgl
6pts0
github.com 8y ago

You're scaring us

pgl
11pts1
www.troyhunt.com 8y ago

I'm Sorry You Feel This Way NatWest, but HTTPS on Your Landing Page Is Important

pgl
8pts0
daniel.haxx.se 8y ago

The curl year 2017

pgl
1pts0
www.troyhunt.com 8y ago

Face ID Stinks [video]

pgl
56pts61
fcw.com 8y ago

Army looks to tap civilian talent for cyber force

pgl
14pts6
0.me.uk 8y ago

First part of phishing with EV

pgl
1pts0
zgp.org 8y ago

Fun with Facebook ads?

pgl
3pts0
scotthelme.co.uk 8y ago

Are EV certificates worth the paper they're written on?

pgl
88pts66
php.net 8y ago

PHP 7.2.0 Released

pgl
143pts75
nolanlawson.com 8y ago

Living with an open-source phone

pgl
7pts1
mjg59.dreamwidth.org 8y ago

Potential impact of the Intel ME vulnerability

pgl
193pts59
er.educause.edu 8y ago

Time for Password Expiration to Die

pgl
3pts0
www.troyhunt.com 8y ago

One Valuable Thing All Websites Have: Reputation (+Why It's Phishers Like It)

pgl
5pts0
daniel.haxx.se 8y ago

Firefox Quantum

pgl
201pts201
www.schneier.com 8y ago

Daphne Caruana Galizia's Murder and the Security of WhatsApp

pgl
5pts0
www.schneier.com 8y ago

Fraud Detection in Pokémon Go

pgl
4pts0

The missing context is that he was quote-tweeting a thread by Sandy Petersen titled "How Quake ruined id software":

https://x.com/SandyofCthulhu/status/2069592209645785294

How Quake ruined id Software.

There has been a lot of praise of Quake of late, with its 30th anniversary, and it's deserved. Quake is an amazing feat of art, programming, and design. I worked on it, and everything came together almost perfectly from all of us. We ended up with a free-wheeling, frenetic action game with enough of a visible world to grip the imagination.

... [thread continues] ...

HeyWhatsThat 5 months ago

Kind of - but when the country across the water is hundreds of km away, turning slightly to the left or right could mean you're facing a completely different country. But I'd also love to know which part of a country you're facing.

HeyWhatsThat 5 months ago

Related, but does anyone know of an app or site that can tell you what you're facing when you're standing on a beach? As in, what country or part of the country - so if you were standing on a Croatian beach somewhere and pointed it east, you could find out what part of Italy you're looking at.

I've always thought it would be cool to stand on a coast of Malta and tell if I'm facing Libya, Israel, or Greece.

Hah, amazing! That brings back memories. The PC where the guy with the red t-shirt is sitting is where one regular used to come in and send out his erotic fanfic. He'd bring in a floppy disk that he'd set up at home and always seemed to have problems getting it to read - so we'd have to go over and help him out all the time.

I worked at Cyberia's second location in Kingston in 1995, before getting hired by Easynet to do tech support on the top floor of the building where Cyberia London was located. It was an interesting time! This article captured the energy pretty well - but there was a whole lot going on at Easynet as well at the time, too.

FWIW, I think the claim was always that Cyberia was The UK's first internet cafe. At least, that's what I've always said.

He was such an amazing guy. We got to interview him on our tiny podcast[1] after we reached out and he so happily joined us for half an hour. His book, Manna (which is $0.99 to download from Amazon[2] or free on his website[3]) is still one of the most fascinating and interesting visions of the future that I've come across (although I don't totally agree it's the only reasonable option).

What a loss.

[1] https://www.youtube.com/watch?v=BA5v2cfJp1o

[2] https://www.amazon.co.uk/Manna-Two-Visions-Humanitys-Future-...

[3] https://marshallbrain.com/manna

Edit: Fixed "free to download from Amazon" - it's not

I love this part: "It represents additional work, additional risk, and additional unnecessary complexity", because it could be "refactored" into "additional work, risk, and complexity". I assume it hasn't been, because (in the author's opinion) it communicates the intended meaning better - which might be the case with code, too. "Well-designed" is subjective.

It all comes down to trust in the end, but over time I've come to trust Mullvad more and more. One particular example that sticks out to me is that they ended subscription based billing, specifically because it required them to hold customer information that they didn't want to have.

https://mullvad.net/en/blog/2022/6/20/were-removing-the-opti...

You can see an example of their lack of data retention from a post about when they were raided - there was nothing to find.

https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec...

Their blog is a good place if you want to get a sense of what they're like as a company.

https://mullvad.net/en/blog/

Mullvad really does have a commitment to privacy.

Some key points:

- Acts as a Google proxy, removes tracking links and caches results

- Only available for Mullvad paid users

- 100 free direct searches a day, unlimited cached searches (further search result pages count towards limit)

- Results cached over all users for 30 days

I think this may be referring to this study: https://pubmed.ncbi.nlm.nih.gov/29206091/

"Effects of caffeine administration on sedation and respiratory parameters in patients recovering from anesthesia"

Caffeine has been shown to enhance the speed of recovery from general anesthesia in murine models, though data in human patients is lacking. This is a retrospective review of intravenous caffeine administration (median dose 150 [125, 250] mg) to 151 heavily sedated patients in the post-anesthesia recovery area, to determine the association between caffeine administration and changes in sedation score, respiratory rate, and oxyhemoglobin saturation.

I only really noticed this properly when my DNS sinkholing server (Adguard home) started blocking t.co links and I was getting an error when say, clicking a linked news article

Mission accomplished!

(Why is it these kinds of discussions get snotty so quickly?)

I don't know how else an end user can express their preference.

IP addresses are PII under the GDPR with enough context - although honestly I don't want to go down that horrible rabbit hole.

But sure, sure, the site operators can do whatever they please. It's just Plausible banging on about being privacy friendly and ethical seems a bit ironic and is frustrating to see.

Edit: The DNT flag is explicitly ignored by Plausible as well: https://github.com/plausible/analytics/discussions/646

Plausible is a third party that logs visits for analytics purposes. An end user expresses their preference (eg, with some sort of blocking browser extension) that the site doesn't send details off to a third party. Then the analytics service provides an easy way to work around this preference, and if that's blocked again then they provide another way, etc. They explicitly work around the end user's choice.

Why does it matter what the reason is for the end user's preference? Or if the data is being stored in a way that's currently difficult to deobfuscate? It's ironic that the whole push is "end user privacy", ie something that benefits the end user, but multiple workarounds are offered when the end user (for whatever reason) doesn't want their visits logged on a third party.

I like Plausible, and ethical analytics services in general. I'd certainly use them over Google Analytics. But it does frustrate me that Plausible (and others) take the stance that because they are doing what they can to preserve privacy, they have an absolute right to collect telemetry about users.

This includes things like CNAME cloaking, and adding a local JS proxy script so that visits can be sent back to Plausible's servers to make it harder to block for the user. The user has expressed a clear preference for their visits not to be logged, and Plausible (to satisfy site owners who want every visit logged) have done whatever they can to circumvent that.

I get it - it's a business, and making sure the site owners are happy is a big part of making money. But it grates that the whole thing is supposed to be about privacy while ways to get around privacy preferences are baked in.

DNS Toys 4 years ago

Rule 53: if you can think of it, someone's done it in the DNS.

DNSFilter | REMOTE (worldwide) | Full time, permanent | https://careers.dnsfilter.com

DNSFilter is a protective DNS service that allows customers to configure policies which block DNS requests, based on the type of domain being queried. Plus there's all sorts of other benefits like our global Anycast network, reporting, access policies, all that good stuff. We do content classification and threat protection, and use a combination of AI, external data feeds, and human review to classify domains.

We have a few of positions open right now, but the two I want to post about are:

Threat Intelligence Researcher (https://apply.workable.com/dnsfilter/j/D64DD718AE/) Business Analytics Specialist (for DNS data) (https://apply.workable.com/dnsfilter/j/2AF95F2892/)

These roles are both on the Domain Intelligence team, and will be dealing with our existing data and threat intelligence, as well as looking at other sources.

Feel free to contact me with any questions - peter@dnsfilter.com. Or just straight up apply for a job!

ClickHouse, Inc. 5 years ago

Someone just reported this to me and I've removed the entry from my blocklist.

This was a very old entry - it was added on Fri, 06 Jun 2003 19:53:00. Back then it was a marketing company that served ads.

I pride myself on knowing the entries in my list very well, but I have to admit I forgot about this one, which is ironic because I use Clickhouse at my job these days.