HN user

yoo1I

790 karma
Posts6
Comments187
View on HN

Hmm, not quite what I thought it would be. It's just a javascript widget that let's users report content to your own team.

I know that Facebook (and I assume the other big players) run teams (from what I read not excellently paid and without enough psychological support ) that actually review/filter objectionable content and I am guessing they're throwing their automatic detection systems at it as well.

Anyone aware of a company offering the actual filtering system AAS ?

I don't have a lot of skin in the game, but I am genuinely curious as to what you mean. How else other than "lump[ing] them in together", would you comprehensively criticize it?

I mean, two things good about Signal is that it let's you chat with friends and family in a secure manner.

There are these following issues though: I doesn't federate, it relies on Google Push, it doesn't support SMS. Also, I don't like how Signal does [...]"

Is that already an invalid way to make an argument ?

This sounds like you might need to define your threat model in a little more detail. I don't think the threat such that you might catch ME sending out data while you're looking for it in this way.

But let's say I was your attacker, I would simply encode some data in the timing between each individual packet that I am sending out on behalf of the kernel: imagine a sort of morse code where that are long pauses between packets for dashes and short pauses between dots.

So now all I have to do is convince your ISP to let me look at your packages timing.

First off, as pointed out below, making copies of national IDs is illegal in some jurisdictions, but there are many other IDs which according to the issuers may not be copied. Think drivers licenses, library cards, and so on.

That being said, all IDs that I own are issued for a particular service, any app/webservice asking me to upload a copy of them, would most likely re-use some aspect of value that these IDs provide for a different purpose, and I can't think of an actual, compelling reason why I would give someone else access to it.

And that's before even thinking about security and the possibility of a breach.

Would you mind sharing why you are asking ?

TL;DR

Journalist tries to grow up; succeeds;

Select quotes:

give up spending on all but the essentials

As a personal finance journalist people assumed I was good with money but while I wrote a lot about the merits of saving, I wasn’t practising what I preached.

I hope I have encouraged other people to reconsider their spending patterns too.

My Verdict:

Experience logs that explain things like "de-clutter", "minimalize", "de-tox", "live a frugal life in which a missing tile on a roof (see article) is an unnecessary expense" and recommend the lifestyle, serve more to explain their authors problems with themselves than being useful life advice.

There, now you don't have to read the article. Do something fun in moderation with that time.

It's not quite that simple. The sample of 900000 customers includes some knowledgeable people, and the attack/outage has been going on for long enough to investigate a little bit.

If what they write is to be believed, and many people have posted evidence, this is a mirari-style attack on people's home routers via a hole in the TR-069 remote management protocol.

The malware then closed off the management port, locking out the Telekom ISP from performing remote maintenance to fix it. Their advice to "shut off" the devices, seems to be based on the fact that at least some variants of mirari do not persist to the device and only exist in memory.

Can anyone explain to me how this could be used against someone? I'm asking completely seriously as I don't see any harm in this no matter how hard I try.

This is called the "nothing to hide" argument. If you currently have no foes and are generally closer to the elite of a society than to the margins, then these few little data points collected on you (pseudo-anonymously or not) cannot really hurt your.

But as your digital shadow grows (and with google analytics et al being used to extensively, it certainly is) and you drift to the margins of society, possibly developing some foes in the elites in the process, the information about you that is now available to people in power becomes more threatening for you.

Say, you're now a black, female, delivery driver in Detroit instead of a Silicon Valley software engineer. Once you give cause for scrutiny, say, a conflict with your employer, the digital shadow of data-points can be searched to find anything that, taken out of context or not, can be used against you.

Or, put differently in famous exaggeration by Cardinal Richelieu:

  If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him.

You're pretending there is an inconsistency in their argument when there is none. Let me give you a slightly (ever so slightly) exaggerated explanation of why you're incorrect in your analogies.

* A phone is a communications device. We know it transmits information. Unwanted tracking that exceeds the metadata strictly necessary for the execution of it's purpose and usage of this metadata for any other purpose needs to be opt-in.

* The browser is a communications application. We know it transmits information. Unwanted tracking that exceeds the metadata strictly necessary for the execution of it's purpose and usage of this metadata for any other purpose needs to be opt-in.

* An internet-enabled TV. We know it transmits information. Unwanted tracking that exceeds the metadata strictly necessary for the execution of it's purpose and usage of this metadata for any other purpose needs to be opt-in.

* Open source project collecting usage metrics? Downloading software packaged generates metadata. We understand that, and use the software on that basis. Any usage of that metadata and tracking my usage habits of said Open Source project needs to be opt-in.

not to leave you hanging there; this is what I found in my .zshrc to enable the functionality.

  autoload edit-command-line
  zle -N edit-command-line
  bindkey -M vicmd v edit-command-line
... could've sworn that was included more default-y

This fails to mention the most vi-in-a-shell-yness:

Press "v" and launch your currently typed command into a vim (or whatever $EDITOR is set to) editing buffer.

Very useful for adhoc-but-long if or while statements.

This was highly illegal and frowned upon in polite society, but doctors needed the body parts to study anatomy and paid for them.

By chance I've recently read Dicken's "A Tale of Two Cities", which uses the banker's messenger secretly moonlighting as such a resurrectionist digging up bodies at night, as a plot device. Quite a fun read.

No.

Yesterday my friends Mac crashed hard while they were working on a foolishly unsaved one-and-a-half page document in LibreOffice.

At the next start LibreOffice gives a big warning of "Oh shit things are really wrong, should I fix them for you? [Continue | Cancel]" .

Thank you LibreOffice team for making it so that within the time of a phone call to me plus the time it took to press "Continue" they were able to recover the their document and continue working.

This "attempt to rectify" the problem, could only have made things better not worse, so that's reasonable to implement.

I am not saying that every problem needs a solution like this. But blanket statements like "crash whenever there is a problem with your environment", while certainly the correct way to do it in some cases, leads to software that's really shitty use if that's all the software does.

Because while

Almost all of these are the wrong numbers.

is correct from a programmers point of view, we aren't talking about the numbers a user put in, but rather numbers that the user has no control about.

And not many things are more annoying than computers doing unexpected things for reasons that are incomprehensible to you.

Yes, I am well aware of the enormous, almost insurmountable chicken and egg problem of Oh By Codes not being useful until everyone knows what they are.

I fail to see how what an "oh by" code achieves that cannot be achieved by an URL, save for the subjective beauty of the format looking like 0xffffff.

Plus, if this became a thing, everybody would have to put their total trust in "PERFECT PRIVACY, LLC" or "Oh By, Inc.", which seems a step backwards from the distributed nature of DNS.

Would you mind expanding a bit and explaining how this system can be used to log into services? That doesn't seem to be so obvious.

they already remove sites that are hosting phishing attacks and malware.

If only...

Let me quote [0]:

CloudFlare will forward all abuse reports that appear to be legitimate to the responsible hosting provider and to the website owner. In response to a legitimate abuse report CloudFlare will provide the complainant with the contact information for the responsible hosting provider so they can be contacted directly.

So, if I report a scammer CloudFlare will forward my information to that criminal, putting me at risk. Gee, thanks!

and

Since CloudFlare is not a hosting provider we do not have the capability to remove content from a website.

Or to put it in the words that they answer every abuse request with:

Please be aware CloudFlare is a network provider offering a reverse proxy, pass-through security service. We are not a hosting provider.

Which basically translates to "We don't care, we want to pretend that we are not responsible for our actions."

[0] https://www.cloudflare.com/abuse/

Because one would think that it would be in CloudFlare's interest not to harbour criminals on their network. This logic seems to work almost everywhere else on the internet, including privacy friendly hosters in iceland. It's mostly just CloudFlare who replies to every abuse report with the same "WE R A REVERSE PROXY", no matter what the actual issue that was raised with them was.

If they were any smaller, their IP ranges would just go into the rogue-isp-blocklist, and that would be the end of that. But because they're mixing in the criminals with their normal customers, that's not really possible.

And since I am unlikely to be in any jurisdiction that CloudFlare is in, nor do I have any chance of finding out who these criminals are because CloudFlare is protecting them, going to the police here wouldn't really achieve much.

How Tor Works 10 years ago

that won't be hidden by https anyway

The only thing that's not hidden are the domain names in the certificate that the server presents.

The rest of the URL is encrypted, along with all data and headers.

It's super useful though. If someone forget's the htaccess login credentials that are shared with a customer, and it's too embarrassing to ask if they remember, you can just run john-the-ripper on it, and seconds later: crisis averted.

twitches