HN user

tombrossman

3,859 karma

Bailiwick of Jersey

tom at tom brossman dot com

Posts27
Comments722
View on HN
www.thebureauinvestigates.com 5y ago

Spy companies using Channel Islands to track phones around the world

tombrossman
3pts0
themarkup.org 6y ago

Swinging the Vote?

tombrossman
20pts8
www.nytimes.com 6y ago

Mark Zuckerberg: Facebook Can Help the News Business

tombrossman
18pts6
news.ycombinator.com 6y ago

Ask HN: Interesting RSS Feeds to Subscribe To?

tombrossman
5pts1
community.letsencrypt.org 7y ago

Action required: Let’s Encrypt certificate renewals

tombrossman
3pts0
arxiv.org 7y ago

Tracking Users Across the Web via TLS Session Resumption

tombrossman
145pts24
www.economist.com 7y ago

Bitcoin and other cryptocurrencies are useless

tombrossman
76pts151
apnews.com 7y ago

Google tracks your movements, like it or not

tombrossman
515pts259
22-8miles.com 8y ago

Public by Default – What Venmo (and the Whole World) Knows About You

tombrossman
1pts0
www.tombrossman.com 8y ago

Apple’s Adware Problem

tombrossman
1pts0
privacyinternational.org 8y ago

Connected Cars: What Happens to Our Data on Rental Cars?

tombrossman
2pts0
www.expressvpn.com 8y ago

Apple Removes VPN Apps from China App Store

tombrossman
97pts1
www.dmagazine.com 9y ago

Barrett Brown Arrested for the Most Ridiculous Reason Ever

tombrossman
3pts0
www.tombrossman.com 9y ago

Faster and More Accurate Analytics with GoAccess

tombrossman
1pts0
ma.ttias.be 9y ago

Despite revoked CA’s, StartCom and WoSign continue to sell certificates

tombrossman
83pts26
www.businessinsider.com 9y ago

Amazon is secretly building an 'Uber for trucking' app

tombrossman
1pts0
news.softpedia.com 9y ago

Weebly Confirms Data Breach Affecting Over 43M Users

tombrossman
4pts0
www.ovh.com 9y ago

The DDoS that didn't break the camel's VAC

tombrossman
4pts0
www.dailydot.com 9y ago

Meet Ahmed Mansoor, the world's most spied-on man: Layer 8 Podcast

tombrossman
1pts0
certsimple.com 9y ago

Chrome is warning users about insecure pages

tombrossman
185pts203
www.percya.com 9y ago

Chinese CA WoSign faces revocation after possibly issuing fake certificates

tombrossman
272pts110
www.theregister.co.uk 10y ago

US standards lab says SMS is no good for authentication

tombrossman
3pts0
www.phoronix.com 10y ago

An Apparent Exodus Continues at OwnCloud

tombrossman
4pts0
news.ycombinator.com 12y ago

Ask HN: How to bandwidth test a gigabit connection?

tombrossman
2pts9
www.weeklystandard.com 12y ago

Through a Google Glass, Darkly

tombrossman
2pts0
arstechnica.com 12y ago

Feds drop most charges against former Anon spokesman

tombrossman
1pts0
webmasters.stackexchange.com 13y ago

Should Google Analytics be used on a 'Report anonymously' police website?

tombrossman
2pts0

You know, now that you point it out that seems obvious. I think maybe I was experimenting with rotation and left that in, unused. I did this years ago. The loop works OK though. Thanks for the feedback (and now I have to finish editing that script ...)

GNOME Desktop users can put this in a Bash script in ~/.local/share/nautilus/ for more convincing looking fake PDF scans, accessible from your right-click menu. I do not recall where I copied it from originally to give credit so thanks, random internet person (probably on Stack Exchange). It works perfectly.

  ROTATION=$(shuf -n 1 -e '-' '')$(shuf -n 1 -e $(seq 0.05 .5))

  for pdf in "$@";
    do magick  -density 150 $pdf \
              -linear-stretch '1.5%x2%' \
              -rotate 0.4 \
              -attenuate '0.01' \
              +noise  Multiplicative \
              -colorspace 'gray' \
              "${pdf%.*}-fakescan.${pdf##*.}"
  done

I was taught to use a little cornstarch sprinkled over freshly grated cheese, and to me it is undetectable (served hot or cold) and works amazingly well. The shreds never clump together and are easy to scatter evenly.

Strange that someone down-voted you, as this is a fair question.

Curious how you found this number, have a source?

I don't have the source handy but have seen the estimated 10 million figure cited repeatedly. But maybe it is about a million too high, as the US Department of State estimates nine million in this 2020 publication: https://travel.state.gov/content/dam/travel/CA-By-the-Number...

This Wikipedia page has a lot more info for those interested: https://en.wikipedia.org/wiki/Emigration_from_the_United_Sta...

Using FVAP stats to me seems problematic, because just like the general population, many US citizens do not bother registering to vote (though they do acknowledge this on the page you linked to and try to control for it).

State likely have a more accurate estimate from knowing how many passport renewals originate from overseas addresses. I am sure some Americans renew or replace their passports while merely travelling overseas, but I cannot imagine this is a routine practice.

YMMV indeed.

Since moving overseas 15 years ago, I tried numerous times and it simply is not possible. All the forms require a U.S. mailing address to register. Same for online access to your Social Security account.

There are an estimated 10 million Americans living overseas. Taken together, we are the equivalent of the 11th largest state. All of us completely blind to what is happening with our credit record and Social Security account.

At this point I think the only way this gets fixed is massive fraud/exploitation by organized crime, so these organizations finally address the problem.

You don't have to turn tracking protection off globally. You can leave it enabled in "strict" mode, and add the x.com domain as an exception (click the Manage Exceptions... button above the mode selection).

If you also use Privacy Badger, you'll have to center the slider for twitter.com when on the x.com login page.

You may not be happy with these compromises, but the above steps are tested and working for me. I have my primary Firefox profile set to delete all cookies on close but I do not log in to Twitter using that profile. I use Twitter in a second Firefox profile which keeps twitter.com/x.com cookies on close. If I want to open a third-party link someone tweeted, I just click and drag it from the Twitter profile window to my primary Firefox instance window. This is good enough privacy for me.

To make using multiple profiles at the same time easier, create custom desktop launchers for secondary profiles and give them a different theme. This is simple on GNOME and most likely possible on other desktop environments and OSs as well.

In Firefox you can change the "network.IDN_show_punycode" value to true, and you will no longer see lookalike UDN domains. It's a good point about using a browser password manager though, since they won't function on a lookalike domain and that should force you to stop and reassess, at which time you (hopefully) notice the scam.

Yes, +1 for Recoll. It can also OCR those PDFs that are just an image of a page of text, and not 'live' text. Read the install notes and install the helper applications.

When searching I'll first try the application or system's native search utility, but most of the time I end up opening Recoll to actually find the thing or snippet of text I want, and it has never failed me.

https://www.lesbonscomptes.com/recoll/pages/features.html#do...

For years I had a custom script sync my ~/.ssh directory on my primary workstation to my laptop, to pick up new keys and config changes. It failed after I switched from Ubuntu to Fedora, and I was surprised to discover --xattrs fixed it.

tl;dr try this if rsync fails in unexpected ways:

  echo "Syncing ~/.ssh directory"
  rsync --archive --delete --xattrs ~/.ssh/ laptop:.ssh/
Stupid Patterns 5 years ago

Try switching to an email service that supports custom Sieve scripts, which you can use to permanently reject messages based on variables you configure.

These are handled differently than message user agent filtering. Incoming messages are immediately rejected and the sending server is notified.

It's much easier than trying to contact some company that doesn't bother validating email addresses. You already know they are technically deficient so just bounce everything. Problem's at their end, let them work it out.

Fastmail do this, as do a few other hosted email providers. Highly recommended. I also use Sieve filters to reject attachment types beyond the default set, such as Microsoft Office files (.docx, .doc, etc.).

Here's some documentation to get started. No affiliation, just a happy customer. https://www.fastmail.help/hc/en-us/articles/1500000280481-Si...

I don't know if this is still the case, but in California the DMV form has a box asking for "Apartment or box number". I had a PMB (private mail box, like a PO Box but at a third-party business) so used my PMB number & street address.

DMV mailed me a licence with street name and "Apartment <my-PMB-number>" even though it wasn't an apartment and I lived elsewhere. That address worked perfectly for years - banks, passport application, etc, everyone accepted it. Online ordering from sites that specifically said "we don't ship to PO Boxes" also worked no problem.

If I ever move back to California I'll definitely do that again. I was 100% truthful on the DMV license application, it's just that they chose to interpret my mailing address as a residential apartment.

Firefox users can set "network.IDN_show_punycode" to "true" in about:config (or your user.js preferences), which will help you identify phishing attacks using lookalike domain names.

I believe Chrome users can do this as well, however it requires an extension.

The HTML reports are my preferred way of looking at stats, but to make them more useful it's worth taking some additional steps to filter all the garbage traffic.

What works for me is:

- Use ipset to drop all traffic from certain countries (you pick which works best for you)

- Configure fail2ban to 'automagically' drop all IPs requesting .php and wp-admin URLs for a few days

- Integrate Piwik/Matomo's 'referrer spam' blocklist into your list of ignored referrers.

- Use per-site logging and only log .html hits with a static site to see page views.

This approach won't work for everyone and it takes extra sysadmin & Bash scripting skills to achieve, but it works really well with my Jekyll site.

I don't receive much traffic on my personal website but my stats page is public and updates hourly with a cronjob. https://www.tombrossman.com/stats/

It is great but it increments ports each time it connects/reconnects which means you will have quite a few unwanted entries in your known_hosts file. Minor problem, but if you like to keep it organized you should check it from time to time and delete all the obsolete connections.

"A friend" drove a (non-UK reg) car from Glasgow to Southampton last year, significantly exceeding the speed limit most of the way and maintaining >90mph for multiple hours, and wondered if speeding tickets would later arrive in the post. Nothing ever happened. I can only guess that speed camera tickets are only sent to UK registered vehicles? That's a pretty big loophole.

I don't drive like this in France, they will stop you and my understanding is you must pay the fine on the spot or they arrest you and tow your car.

I considered filing a complaint with the police department, but I'm skeptical anything would have come of it.

Your instincts are correct, it is a waste of time. If the matter is serious enough, hire a lawyer and get a judgement against the officer or department. For everything else, let it go.

I had my car stolen a while ago. The police found it abandoned midweek, and had it towed to an impound lot. Then they waited until 4:45pm on Friday to tell me. The impound lot was an hour away, so I had to wait until Monday to get my car back. I also had to pay the tow lot for towing and storage of my stolen car for all the extra days.

I have heard that setting a very long MX TTL can be helpful if your domain registration is ever hijacked. The idea is that enough resolvers will have the original cached records so you can still receive email (and prove ownership). Anyone have any experience with this?

My "404-pests" fail2ban-client status, which drops everything making *.php requests (This machine has never had PHP installed...):

2a03:2880:10ff:14::face:b00c 2a03:2880:10ff:21::face:b00c 2a03:2880:11ff:1a::face:b00c 2a03:2880:11ff:1f::face:b00c 2a03:2880:11ff:2::face:b00c 2a03:2880:12ff:10::face:b00c 2a03:2880:12ff:1::face:b00c 2a03:2880:12ff:9::face:b00c 2a03:2880:12ff:d::face:b00c 2a03:2880:13ff:3::face:b00c 2a03:2880:13ff:4::face:b00c 2a03:2880:20ff:12::face:b00c 2a03:2880:20ff:1e::face:b00c 2a03:2880:20ff:4::face:b00c 2a03:2880:20ff:5::face:b00c 2a03:2880:20ff:75::face:b00c 2a03:2880:20ff:77::face:b00c 2a03:2880:20ff:e::face:b00c 2a03:2880:21ff:30::face:b00c 2a03:2880:22ff:11::face:b00c 2a03:2880:22ff:12::face:b00c 2a03:2880:22ff:14::face:b00c 2a03:2880:23ff:5::face:b00c 2a03:2880:23ff:b::face:b00c 2a03:2880:23ff:c::face:b00c 2a03:2880:30ff:10::face:b00c 2a03:2880:30ff:11::face:b00c 2a03:2880:30ff:17::face:b00c 2a03:2880:30ff:1::face:b00c 2a03:2880:30ff:71::face:b00c 2a03:2880:30ff:a::face:b00c 2a03:2880:30ff:b::face:b00c 2a03:2880:30ff:c::face:b00c 2a03:2880:30ff:d::face:b00c 2a03:2880:30ff:f::face:b00c 2a03:2880:31ff:10::face:b00c 2a03:2880:31ff:11::face:b00c 2a03:2880:31ff:12::face:b00c 2a03:2880:31ff:13::face:b00c 2a03:2880:31ff:17::face:b00c 2a03:2880:31ff:1::face:b00c 2a03:2880:31ff:2::face:b00c 2a03:2880:31ff:3::face:b00c 2a03:2880:31ff:4::face:b00c 2a03:2880:31ff:5::face:b00c 2a03:2880:31ff:6::face:b00c 2a03:2880:31ff:71::face:b00c 2a03:2880:31ff:7::face:b00c 2a03:2880:31ff:8::face:b00c 2a03:2880:31ff:c::face:b00c 2a03:2880:31ff:d::face:b00c 2a03:2880:31ff:e::face:b00c 2a03:2880:31ff:f::face:b00c 2a03:2880:32ff:4::face:b00c 2a03:2880:32ff:5::face:b00c 2a03:2880:32ff:70::face:b00c 2a03:2880:32ff:d::face:b00c 2a03:2880:ff:16::face:b00c 2a03:2880:ff:17::face:b00c 2a03:2880:ff:1a::face:b00c 2a03:2880:ff:1c::face:b00c 2a03:2880:ff:1d::face:b00c 2a03:2880:ff:25::face:b00c 2a03:2880:ff::face:b00c 2a03:2880:ff:b::face:b00c 2a03:2880:ff:c::face:b00c 2a03:2880:ff:d::face:b00c

I think op is saying, at the cost of an undetectable fraction of a second rounding error when you SSH somewhere, so what?

I tried switching from a 2048-bit to a 4096-bit key to control a modestly sized VPS (~4GB RAM, 2CPU) and scp file transfer speeds plummeted.

I have a symmetric 1GB FTTH connection and I'm used to everything being pretty quick. Using a longer key was like a return to dial-up speed. If you don't plan to transfer large files or directories you can safely ignore it, but I bet your patience will run out pretty quickly if you do.

Got my flu shot last year, still ended up with severe flu in February. The flu shot is not completely effective.

My understanding is that the 'flu shot' changes every year, in anticipation of the strains predicted to be the most prevalent that year.

In other words, flu shot producers say "we think flu strains A, B, and C will spread this year" and strains B, C, and D may be what actually spread.

It's still worth getting because even if you catch strain D, your immune system still easily defeated B and C when exposed and you didn't even notice.