HN user

tonywebster

501 karma
Posts5
Comments61
View on HN

I think bringing attention to common practices putting people in jeopardy is a good thing, because it’s likely website operators and the general public don’t think about these risks. If data is collected, it can be used by police and prosecutors. Ignoring the problem because everyone knows about analytics does not start necessary conversations. Google has increasingly been a target for law enforcement investigations, and the search warrants Google receives can be as broad as compelling Google to turn over data on the accounts or IP addresses of anyone who Googled someone’s name.[1]

[1] https://www.techdirt.com/2017/03/17/judge-grants-search-warr...

After a Minnesota lawyer reported his neighbor for allegedly sexually assaulting his son, that neighbor cracked the lawyer's wi-fi WEP encryption and proceeded to attempt to frame him for CSAM crimes, sexual harassment, and threatening of politicians. The lawyer's employer hired an outside firm to investigate, the Secret Service showed up, and ultimately a search warrant at the neighbor's home found evidence that he was the true culprit. He was given 18 years in prison.

[1] https://www.wired.com/2011/07/hacking-neighbor-from-hell/

My house was blurred many years ago and I wish it wasn't. It almost draws more attention when you look at Street View, which is probably contrary to privacy interests. I've also had odd reactions from companies I've called out to do maintenance or yard work. Some of them never show up, and I suspect it is at least in part because they draw some negative inference from the blurred house. I'm also thinking about selling the house soon, and I just know it's going to be problematic. I've tried to get it unblurred several times, but have failed to get a response from Google.

For travel, I'm happy with the Peak Design 45L Travel Backpack. It's optimized for photographers, with separate packing cubes that clip into the bag. https://www.peakdesign.com/products/travel-backpack

Their Tech Pouch in particular is an amazing design, and has organized all of my random cables and adapters. https://www.peakdesign.com/products/tech-pouch/

For just around town, I like Timbuk2 messenger bags. Sadly, they stopped making the Especial messenger bag, which was the best product they've ever made.

I'm excited about this (and all things Sketch-related), but I thought this was a product release from the makers of Sketch until I saw the disclaimer at the bottom.

$39 seems fair, though I'd rather see this as an open-source project that the community could contribute back to. According to the changelog, this is a v1 release and the website contains no statements about the $39 buying future updates for new features or updated versions of Sketch, which is disappointing.

Aside from a few screenshots, it would be nice to have a YouTube video demonstrating how it works in practice, in real-time, especially considering the terms stating: "As a customer you are responsible for understanding this upon purchasing any item from Sketch Design System".

I wouldn't buy it without more information, and knowing who is behind it. There's no "about" section on the website with a real person identified. The domain WHOIS data is a proxy service.

Here are some random observations and opinions.

1. The screenshot at the top of the page seems to show some features, but I have to infer what they are. It would be good to automatically cycle through annotations to show what the little "Expert" badge and all the other features mean. Sell your product in a captivating way. The headline "Become a PROFESSIONAL freelancer" is a good thing to A/B test, or to have rotate through words, e.g. "Become a SUCCESSFUL freelancer," etc.

2. The demo video is way too small. Make it much bigger so users don't have to squint. It's also too long. There's a time and place for a nearly five-minute demo video, but not this soon in the process. 30-45 seconds max.

3. The NDA feature is overhyped. I care much more about defining the scope of work and getting my clients to agree to my master services agreement or other contract. Does the product generate an agreement? Can I make a template for my agreement? More detail would be helpful.

4. I don't find value in the personal assistant feature, personally. I want to maintain direct contact with my clients once we make contact. It actually freaks me out to have someone else talking to a client and potentially making promises I don't agree to, or not behaving the way I'd expect.

5. As I scroll down the page, I'm not actually presented with a big call-to-action to start the signup process until I reach the bottom. This adds way too much resistance. Also, make the signup button green, or consider A/B testing signup button color.

6. The signup process is difficult. Instead of just asking for a couple quick details (e.g. email address and name), it opens a modal window that presents huge resistance. There's a splash screen adding yet another step to the process (you have to click TWICE to reach any form inputs).

7. The form is a Typeform full-screen modal form with a "0% completed" label. I hate Typeform forms, and I've found them to perform poorly in my own experience. For a signup process, seeing "0% completed" is a huge mental barrier. I immediately think "ugh, this is gonna take forever, I'll do this later" and I might not come back.

8. I'm not told before or during this signup process whether I have to pay any money or what I get for free versus for pay. Use the signup process as an opportunity to reinforce features and benefits. Is there a trial period? I have no interest in filling out this complex form if I'm going to have to pay right away. I need to be able to take it for a test drive.

9. You force users to provide a LinkedIn URL. Not everyone uses LinkedIn, for good reason. If you don't have a LinkedIn, you cannot proceed. You're killing signups.

10. The signup process doesn't actually work. It appears all it does is email you. So, it's actually a "contact" form and not a "signup" form. Upon submission, it says "Thank you! We'll get back soon. If you have any questions reach out to [email]." You've now dead-ended your user that is interested in your service. I doubt many will come back when you "get back soon" to them. Make sure you always give users a path forward, without manual intervention from you. Your post says, in all caps, "NO ONE PAID" -- well yes, you literally do not collect payment information or give users a path forward to payment.

11. Footer says "Use of this site constitutes acceptance of our User Agreement and Privacy Policy". But you have neither. There are no links to a user agreement or privacy policy. This suggests to me that maybe I need to be concerned about how good the onboarding process is. This might seem like a small detail, but the site is marketing itself to web developers and engineers, who will notice these details.

12. Show success stories somewhere. Seeing an HBO Silicon Valley character screams "we don't have any users." Use real stories of people who have enjoyed using the service.

13. You mention in your post an "Elite 100" program where you give people shares. I don't think this is compelling for most users, but perhaps it's worth testing and experimenting with. Currently you appear to not advertise this anywhere. Your ProductHunt appears to include a link to it (/100), but that redirects to the homepage. If the program isn't detailed, it doesn't exist.

14. Site needs proofreading throughout.

15. Pricing says $29 per month and then right below that says $10 per month. Which is it?

The author used `tcpdump -i lo0 -s 65535 -w info.pcap` which, as a non-root user without sudo, successfully captures loopback traffic in OS X 10.11.3.

I just tried it, and with Chrome and 1Password, I was able to see my auto-filled bank password in the pcap. So, I presume any process on my system, without root privileges, would be able to sniff loopback.

I don't see why 1Password wouldn't use TLS here. This is not good.

Don't be so quick to dismiss this one. This is notable for several reasons, including (1) it wasn't his mistake, but rather that of a Visual Studio bug not following his instructions to make a private repo on GitHub; (2) the speed in which this happened (minutes), and (3) it has useful analysis into some sorely lacking functionality in AWS that lets this continue to happen.

I love this concept, and it is sorely needed. I read in your Medium post[1] that “Data is wiped from the phone as soon as it’s securely moved to the Witness servers.” I'm curious what the reasoning for this is. Of course, I get that the data is streamed/copied to Witness in the event that the device is destroyed or confiscated, but it's hard for me to think of a use case where having a local version on the device would would do any harm.

In fact, I think it would be valuable for evidentiary purposes to have the original on the device. I'm assuming that the streamed/copied version is probably lossy in some regard, while the local version might be higher resolution or frame rate, also.

[1] https://medium.com/@marinosbern/witness-livestreaming-for-em...

There's another strong reason not to trust Evernote: nothing is encrypted at rest on your system or their servers, unless you manually go encrypt selected text in a specific note in the desktop application, where you have to make a new passphrase for each note you want this on. Even this was only recently upgraded from RC2 64-bit to AES 128-bit.

They claim they can't perform searches over encrypted data, but that doesn't seem too difficult to solve with an index file that's also encrypted.

Evernote does have some detailed security policies and 2FA, but without encryption at rest where only the user has the key, what's the point?

While it's honorable to want to keep things on a handshake-and-honor level, when things go wrong, none of that matters. In my experience, clients are impressed and more comfortable with proceeding when a written agreement is in place. The only time I've had trouble negotiating an agreement is when dealing with large mega-corporations, where I'm still able to add in notable definitions and exceptions to the work that I'm performing.

"the client can afford more expensive lawyers than I can, so regardless of the truth they would be able to wipe me out"

Just like lines of code are not a measure of quality of software, hourly rates of attorneys are not a measure of the quality or effectiveness of their legal representation. The only time that you are on equal legal footing with a large corporation is when you're both entering the relationship. If you and a client sign an agreement defining and limiting the work and your liability, a more expensive attorney isn't magically able to rip that contract up.

"if the client has to read the detail of the contract, it's probably too late to save the relationship anyway"

I couldn't possibly disagree more. If a client isn't willing to work with me on defining the scope of the work to be done for both of our benefits, then I have no faith that they're going to work well with me at all, on anything. For a software developer, a scope of work is also just another piece of documentation: here's what I'm building, and what it does and does not do. A client should be as eager to define that as you.

Case in point: a bank recently suffered a data breach and had to spend more than $150k to comply with its notification obligations, and the bank's insurance company sued the bank's web design firm for, as they allege, failing to do proper servicing, security updates, etc[1].

Web design firms doing ongoing security, monitoring, and maintenance is totally not the norm. Usually the design firm designs the site, either has a couple developers in-house or contracted to another company to build out the front-end and do any integration with the bank's back-end, and when it launches, all is over. But here, this small midwestern design firm with a few employees is on the hook for damages and their reputation will be destroyed.

There are many details lacking in the civil complaint in terms of what their actual responsibility was, or if there even was an agreement in place. But if the design firm had a master services agreement that (a) disclaimed responsibility for doing security monitoring, updates, malware fixes, backups, contingency planning, and any costs or lost business as a result; and (b) limited liability to the amount of money the bank paid the design firm (a common business practice); and (c) indemnified the design agency against any claims by third-parties; the complaint probably would have never been filed.

None of this is legal advice, but don't risk having your reputation destroyed and being personally bankrupted simply because you're desperate for work, lazy, or unrealistically optimistic about people having good faith in all situations.

[1] Article with linked PDF civil complaint: http://www.scmagazine.com/travelers-accuses-web-firm-of-shod...

HTTP Shamer here. I absolutely practice 'responsible disclosure' when it is appropriate.

In the case of TripIt, they've known about this issue for a VERY LONG TIME and chose not to address it. I'm incredibly sad about this because I absolutely love TripIt.

There's several sites and apps I've either found out about myself or have been submitted to the Tumblr that I do think warrant responsible disclosure, and I've either done that or am working on that. Sadly, only one of those vendors even has a security e-mail address with a responsible disclosure policy.

In the case of Scribd, if you're using HTTP for all of your account activity, it's not going to be encrypted, period. I'm not going to responsibly disclose that passwords are sent cleartext over HTTP because that's obviously what happens with HTTP. If the vendor made any attempt to use SSL that appears broken, I would stop and responsibly disclose.

In the case of apps going out and checking for updates insecurely, I think that behavior is prevalent enough to see, and obscure enough to exploit, that responsible disclosure doesn't really apply. It's just that HTTPS is something I'd like to see on developer roadmaps. There's been good discussions about this on Twitter, including the VLC team closing a ticket about it.

If I saw personally-identifiable information being sent from an app, I would stop and responsibly disclose.

USPS Redesign 12 years ago

The two main typefaces are Knockout and Gotham, both being fonts from Hoefler & Co. — formerly Hoefler & Frere-Jones (H&FJ), until Jonathan Hoefler allegedly never gave Tobias Frere-Jones the equity stake he promised, eventually calling him just an employee[1].

Not only do I think is Hoefler & Co. a terrible company under Hoefler's leadership for that unethical move, the company has refused for the longest time to support web fonts using @font-face — now they partially support it, but only using their proprietary hosting platform, which is just setting a bad precedent for the open web.

There are plenty of small foundries producing high-quality typefaces, with @font-face friendly licensing for webfonts. Can we please stop using Hoefler fonts and supporting this guy?!

[1] http://www.theverge.com/2014/1/17/5318206/hoefler-and-frere-...

"...which did that because there was no communication from No-IP ... The court ordered No-IP to send a response and looks like there was no response."

That's absolutely false. Microsoft explicitly asked the court to allow them to file the entire case under seal, and to obtain ex parte emergency relief without notifying the defendants.

The TRO states: “...good cause and the interest of justice require that this Order be Granted without prior notice to Defendants, and accordingly, Microsoft is relieved of the duty to provide Defendants with prior notice of Microsoft’s motion.”

The judge signed that. No-IP did not receive any advance warning or service by Microsoft's own admission, and No-IP's blog post confirms they weren't served until today.

That's not true. On June 19, Microsoft filed the Complaint, Motion to Seal, and Ex Parte TRO Application all at the same time.

The TRO actually says: “...good cause and the interest of justice require that this Order be Granted without prior notice to Defendants, and accordingly, Microsoft is relieved of the duty to provide Defendants with prior notice of Microsoft’s motion.”

It says that because Microsoft wanted it to say that; Microsoft used that language in their proposed TRO for the judge to sign, and the judge apparently agreed.

The Summons has nothing to do with this. The court issued the Summons, but the court doesn't do anything with it. It's the plaintiff's obligation to serve a summons on a defendant, and they have 120 days to do so before the Court would require the plaintiff dismiss the case without prejudice. The plaintiff could serve them the same day, or they could take their time. Corporations with registered agents are much easier to serve than an individual that dodges a process server.

There's often a good chance a defendant will receive a solicitation from an attorney (who searches court records for new cases) to represent them before they actually get served with the summons and complaint. However, nothing would come up in court records in this case because the entire docket is sealed.

There's no way Vitalwerks/No-IP would have known about this, and it sounds like they weren't served until today, after Microsoft's action.

I think it's pretty clear that Microsoft wanted to ensure that nobody, including No-IP, knew about the case until they were able to strike.

I hate pay-walls and even login-walls, so I genuinely disagree with Scribd's payment model. However, I do think the service provides value in that users are able to upload a PDF and it renders in a pretty widely-compatible viewer format (in HTML5). Embedding PDFs across multiple platforms are still a terrible native experience, and on some systems it launches tons of painful Acrobat toolbars or just doesn't show up at all.

I have yet to find a free or open source solution that's incredibly easy to implement and embed (for bloggers). To get PDF content showing nicely inside of a scrollable iframe, you need to convert the PDF to HTML, and host images somewhere. That's not easy for people who just want to jump right into publishing blog content. DocumentCloud seems totally awesome, but their hosted platform is restricted to journalists; specifically, "newsrooms."

I use Scribd for legal research; there's a lot of attorneys who post PDFs of case pleadings, since (a) PACER is expensive to use, and (b) RECAP has terrible searching. To that end, it really is the YouTube of PDFs, and I love it for that. Of course, YouTube is ad-supported, so perhaps that'd be a better option for Scribd, but that tends to draw ire too.

For what it's worth, you don't need to pay for a Scribd account if you regularly upload content. I haven't uploaded anything in a few months and I was able to download, for free, the Declaration of Independence link that the author highlighted. Of course, you wouldn't know that unless you stared at the little text on the bottom of the page, so that should change.

I actually appreciate the humor, but I'm in the same boat where there's a good portion I'm just not wrapping my head around clearly. I'd love if someone made an annotated version with technical descriptions.

I wish they were more transparent about the components used for the site, specifically for licensing purposes.

Example: The demo site uses Proxima Nova, which is loaded via Typekit. That's not an open source font, there's nothing documenting that they have a sublicensing/resale license, which means it's an added cost to someone to either license each weight of the typeface ($29 per weight, and I think I count 8 weights = $232). Alternatively, that font is only available in the Typekit $49.99/year plan, which imposes pageview limits. The typeface really seals the deal and adds to the emotion of the page, and could be a big disappointment or added cost to someone. Certainly, startups don't need the drama of being accused of copyright infringement.

Without getting on a soapbox about how the criminal justice system only guarantees repeat customers...

I'd definitely retain a lawyer to pursue expungement, but I'd ask them about what new records seeking an expungement can create. For example, ten years ago when you were convicted, the records probably weren't as likely to be digitized and searchable. Now, practically every state uses e-filing, has public access tools, and sells filings to third parties who SEO it up, guaranteeing it to be more public than it is now (just like shady mugshot websites).

In reading your other comments, it sounds like you start a conversation with volunteer work, talking about your testimony about it in front of your legislative body... I think that's the right approach. Possibly you could broaden the topic of your legislative involvement to other areas beyond criminal expungement, though.

This sort of thing is infuriating. Nowhere on this page does it say "we will charge you every month." http://i.imgur.com/ctMDiCJ.png

I just went through the whole checkout process to see how bad it really is. There were upsell interstitials at least four times, they did the 20-minute countdown clock thing to add a little pressure, and the checkout page looked like I was getting boots for $19.95. If you look on the right side in pretty small grey text it says that you're activating your VIP membership. You have to read down several paragraphs to figure out what they're trying to get away with, and nowhere does it actually say in clear terms "we will charge you every month." Entering in your shipping and payment information and it again completely fails to indicate there's a monthly fee — just a little checkbox "I accept the terms..."

All the state attorney generals should join together to sue them and get their victims' money back. At least we know they have the cash to pay the settlement now thanks to RHO, Matrix, and TCV.

If I was the participant with the stolen laptop, I'd first of all be really bummed out over not having the opportunity to participate in the hackathon because of stolen gear. I'd try to find them a computer they can use to hack on, and hopefully they didn't lose any work.

I don't know what to say about the stolen gear itself. People should take responsibility for protecting their own stuff, but that's a real challenge over a weekend non-stop sort of event, especially of that size. People need to eat, sleep, etc. I guess it's a lesson learned to have clear disclaimers of responsibility for future ones, and I'm not sure what to say about replacing that participant's computer. Not a fun situation, and it's hard to find fault on anyone (except the thief, of course).

In the perspective of an American, the primary concern is authenticity, and there's a high probability of that when you have to show up in person or request an absentee ballot. Not that I support more government programs to identify citizens, but I'd think should be some sort of PIN number or password issuance process during the issuance of things like driver's licenses, state IDs, passport numbers, Social Security cards, IRS filings, etc.

Government cannot run a program that elects a new government behind the walls of a datacenter. It's a major conflict of interest. The way things work now, the government really only handles the voter registration process, which is exposed enough so you know they're not messing with it. County employees and poll workers on-site are far enough removed from the people in power that there's little concern of major corruption. When recounts happen, staff from both campaigns are physically present to look at each ballot. When we get ballot counting machines from companies like Diebold, there's concern that a big corporation could be influencing a vote or that the system wouldn't be secure.

But I look at some of the things happening with health insurance marketplaces and health data exchanges as proof that government can tackle big tech problems in cool ways. The State of New York is building a health information network (Google: NYeC SHIN-NY) where all medical providers in the state have their electronic health records connected in a statewide network. It's not the government itself running the program, but a collaborative of government and healthcare people. The service doesn't store or transmit private health information, it just handles the secure handshakes, authorization, and authenticity. That is, a patient can grant/deny access to medical records from their phone -- or in an emergency situation, an EMT can bypass that and get the records directly. I think this is genius.

If we looked at something like this on a local or state level, a collaborative of sorts could include the Secretary of State, various government and non-profit representatives, and open source and security folks. I think that would be the first step toward moving to an online voting system: setup an entity that people can trust.

Obviously, it'd have to be optional. There were a lot of elderly folks at my polling place last November, proudly wearing their 'I Voted' sticker. No way they'd go online, even if it did support IE 5.5.

There is no state law limiting retention to 48 hours. The Minnesota State Patrol -- one single statewide agency -- has voluntarily chosen to limit to 48 hours. Any local police department or county sheriff's department can retain for whatever they want under state law. Or the State Patrol could be lying.