HN user

sickmate

143 karma
Posts2
Comments30
View on HN

This is not correct. ISPs cannot see the actual URL being requested. Your DNS provider can see the hostname. The ISP may be able to see the hostname unless encrypted SNI is in place. The ISP can see the IP address you are connecting to.

It might have been called something else like cloud hosting, but it was definitely equivalent to a shared hosting model. We didn't manage the web servers, no root access etc and the database server was shared between 300+ of their customers.

Highly trained people handled the company’s incoming telephone and online inquiries

Not sure I can agree with this. Almost a decade ago we had some shared hosting accounts at Rackspace for some very legacy clients (ones that even accounting had forgotten about and not billed them for years). We had an issue with accessing one of the databases to export for handover, and so I got in touch with their online support. They gave me full admin access to their database server which had several hundred other clients on there. I could also see the historical metrics for the server which were interesting. I told them immediately but it took them almost a day to revoke my access.

I've never shorted or taken out crypto loans, but you could theoretically:

- Take out a loan of USDT, using a stablecoin you trust as collateral

- Immediately trade all USDT into your stablecoin

- If the USDT price crashes, buy it up to repay the loan.

e.g. Binance lets you borrow 800k USDT with 1.23m collateral. Over 180 days, interest paid would be 36k.

Say USDT crashes and you repay your loan at 10c/USDT - you would pay at most 84k to settle the loan. You then end up with 1.94m, a 58% return on investment.

It's probably not that simple however.

You could also open restricted system preference panes by searching for a relevant term in Spotlight and going to a User Guide article. Often they would have a link to open the preference pane which would bypass any restrictions.

This blog post[1] has a good explanation of ConfigData updates. The flag would appear to force the install of new Gatekeeper configuration updates.

To help distinguish Gatekeeper and XProtect updates from other updates in the software update feed, Apple marks them as being ConfigData updates.

Marking these updates as ConfigData cues the App Store to not display these as available software updates in the App Store’s list of software updates. These updates are meant to be under Apple’s control and to be as invisible as possible.

[1] https://derflounder.wordpress.com/2014/12/27/managing-automa...

For Android: XPrivacy will alert you when apps attempt any type of network access and allows you to whitelist or blacklist specific hostnames or wildcards.

That isn't it's main/only function though. From their github page: "XPrivacy can prevent applications from leaking privacy-sensitive data by restricting the categories of data an application can access."

It is a module for the Xposed framework, and requires root.

http://repo.xposed.info/module/biz.bokhorst.xprivacy

https://github.com/M66B/XPrivacy

It's not completely fixed. My guess is that only certain Airport Express cards are affected, as I have some machines that fail to reconnect and others that are fine.

With regards to Joomla, it really is terrible when it comes to security. Versions 1.5-2.5 have major vulnerabilities that allows anyone to create an admin user unless you disable account registration. Popular plugins like TinyMCE allowed unauthorised users to upload arbitrary files with a specially crafted request.

There are also plenty of bots that scan for vulnerable Joomla installs as they do with Wordpress.