HN user

plausibility

84 karma

Contact: chris@gibsonsec.org

Posts2
Comments41
View on HN

I’ve been wondering for a while if these ludicrously high numbers are just MAU and count people running 16 free accounts load balanced for more access without paying.

No way 1/7 people globally use ChatGPT?

Mythical Man Month 3 months ago

I feel like that’s tied to the hardware the companies are using. All the banks I’ve worked at run z/OS mainframes, can they even deploy modern run of the mill Go/Python/Rust code or is getting off COBOL reliant on hardware changes?

Meow.camera 4 months ago

If you have a premium Shodan[0] account, they have an ‘Images’ view which is filtered VNC and other Remote Desktop screenshots and links to view them directly with the IP. Lots of security cameras, some SCADA industrial access control screens, and lately seemingly people who I guess are hacking vulnerable Windows boxes and changing the wallpapers to anti Israel stuff.

[0] https://shodan.io

When you’re trying to type a URL there’s a period next to the space bar where your right thumb usually hits space, but if you’re just texting iOS won’t show that. That’s my theory, just muscle memory.

The thing they’re describing is people hand holding lapel mics right up to their mouth, rather than clipping them to their lapel or shirt or anything (where I assume they’re designed to go still). Seems more ‘indie filmmaker’ where actually clipping it on seems too polished, and why would you trust someone who’s from Big Lapel Mic on TikTok.

This lead to other people clipping them onto random objects to make fun of the trend for a while.

Tech Independence 5 months ago

At the lower or easier end, there’s your standard containerisation tools like Docker Compose or the Podman equivalents. Just move your compose files and zip the mount folders and you can move stuff easily enough.

Middle ground you’ve got stuff like Ansible for if you want to install things without containers, but still want it to be scripted. I don’t use these much since they feel like the worst of both worlds.

Higher end in terms of effort is using something like NixOS, where you get basically Terraform for everything in your distro.

It’s pretty much table stakes to block or restrict or just investigate more closely if requests come from an IP address in a data centre provider or VPN provider ASN though.

I worked at a cloud company a while ago, and if free tier user requests came from another cloud providers IPs we’d have to double check it wasn’t fraud since that happened more often than residential ranges.

This is kind of the confusion I mean. Sometimes YouTube Music has audio tracks that you are seemingly different to the "X Artist - Topic" videos you can find on YouTube proper. I'll have to revisit this again to see if it's all the same now, because the last time I was looking into it a few years ago not everything I had organised in playlists on YTM was available via regular YouTube playlists I could rip with yt-dlp.

Tidal has lots of downloader clients you can install due to its often technical but niche user base. May I suggest Tidal-Media-Downloader[0]?

Now if only there was a way to download things from YouTube Music with a Premium subscription. It's practically impossible to search for "YouTube Music download" without falling into the 'youtube-dl YouTube mp3 audio tracks!' SEO hole. Vague naming on Google's part.

[0] https://github.com/yaronzz/Tidal-Media-Downloader

There was something similar shown here on HN a few months back (but for current Googlers) [0]. Apparently this counts as commercial bribery. I guess ex Google Ads folk giving their market expertise to another company as an SEO Consultant might not be a problem, unless somehow they're breaking an NDA about divulging company secrets or special sauce?

[0] https://news.ycombinator.com/item?id=40431126 "Show HN: Pls Fix – Hire big tech employees to appeal account suspensions (plsfix.co)"

Look no further for evidence than New Zealand. There are two major grocery store chains (Foodstuffs, who own New World, Four Square, and Pak n Save) and Woolworths Group -- obviously we have the smaller Asian marts and produce stores too, but most people only have one of the big stores nearby to their towns.

There are two major building materials suppliers (Carters and Fletchers). There's one manufacturer of drywall (Gib) that is easier to get council plan approval for than any other cheaper manufacturers of drywall because they provide some material strength documents that saves the councils some engineering review time and effort.

We technically have 4 major banks, but 3 of them are just offshoots of big Australian banks and siphon the insane profits offshore.

The government keeps making investigation commissions into breaking these up, but doesn't do anything. The companies just point fingers back and forth at each other blaming "the competition" for price gouging. Meanwhile the recommendation from the politicians is we cut back on avocado toast, lattes, and our Netflix subscription.

One thing I learned from using Little Snitch is that a lot of Apple apps are seemingly immune from these types of firewalls, due to Apple shenanigans around k-ext signing etc [0].

Ref also [1]: > In Big Sur Apple decided to exempt many of its apps from being routed thru the frameworks they now require 3rd-party firewalls to use (LuLu, Little Snitch, etc.) > Q: Could this be (ab)used by malware to also bypass such firewalls? > A: Apparently yes, and trivially so

[0] https://x.com/patrickwardle/status/1318437929497235457 [1] https://x.com/patrickwardle/status/1327726496203476992

I think it's just because he had no illusions as to the good and bad uses it would bring. I've used Palantir Foundry heavily at work, and it is good for remotely viewing events and communicating mind-to-mind to executives with pretty dashboards. Definitely nicer optics than their Gotham platform used by USA law enforcement since e.g. it helps Airbus identify issues on their plane fleets before they occur.

Plus from talking to the Palantir engineers, the CEO and Thiel are both weirdo nerds, so it's fitting.

The WiFi spec has something called "active scanning" [0] for clients (as opposed to passive scanning, where the client listens for the periodic AP beacons). There's something called a "directed probe request" [1] that a client can send during active scanning which will contain the AP's SSID it's directed towards. Whether or not your particular device sends these direct probe requests is probably configurable and different per client. According to this [2] post, Android devices will sometimes send SSIDs in a scan, but not all of them and not always. Might be possible to find the logic here in the Android source code, I assume it's there somewhere.

[0] https://www.wi-fi.org/knowledge-center/faq/what-are-passive-... [1]: https://dot11ap.wordpress.com/active-scanning-probes/ [2]: https://stackoverflow.com/questions/36264440/phone-doesnt-se...

Something I've noticed a lot with tech products is that they "cost the same" (in number value) in USD as well as Euros or GBP, which actually makes them cheaper in the US. Take for example, the Awair Element air quality meter:

- Ordering in the US: USD$299[0] (~£224) - Ordering in the UK: GBP£299[1] (~$360 USD at the time of writing)

Even including 20% VAT in UK it should only cost around £270 by my calculations. Is shipping really that expensive? I find similar issues buying things online in Australia (and that's before expensive shipping, duty, import GST, etc.)

[0] https://store.getawair.com/products/awair-element [1]: https://ukstore.getawair.com/products/awair-element

Was this perhaps LA Hacks [0] in 2014, or Hacktech [1]? Evan Spiegel attended LA Hacks, but I had someone who was attending Hacktech email me for help with the Snapchat API for their project. (I was part of Gibson Security, and published some early Snapchat API research [2] online in 2013)

[0] https://en.wikipedia.org/wiki/LA_Hacks

[1] https://medium.com/hacktech-2014/everyones-watching-hacktech...

[2] https://gibsonsec.org/snapchat/fulldisclosure/

Fuck Microsoft 11 years ago
    $ dig +short foo.meme
    127.0.53.53
    $ 
It's the same for .meme, which is owned by Google if I'm not mistaken.