Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
fruitreunion1
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
fruitreunion1
3y ago
How does this affect old YouTube videos (and possibly other historical public content)? (obviously, save everything you love while you still can in case things get removed or difficult to archive due to attestation/DRM)
2.
▲
by
fruitreunion1
3y ago
The idea is you connect to the wireguard UDP port from one of the obfuscation tunnels. laptop -> obfuscation tunnel (udp2raw/iodine/ssh/tor/wstunnel/etc.) -> wireguard UDP port. Though some protocols like ssh
3.
▲
by
fruitreunion1
3y ago
Their point I think is that often (to varying degrees), 'power user' things are less convenient to do or behind configuration options or menus and so on nowadays.
4.
▲
by
fruitreunion1
3y ago
I think this is a good thing. Apply obfuscation on top of WireGuard, that way you can have the functionality and security of the WireGuard tunnel and swap between different obfuscation techniques as needed.
5.
▲
by
fruitreunion1
3y ago
No. https://www.wireguard.com/known-limitations/ >Deep Packet Inspection >WireGuard does not focus on obfuscation. Obfuscation, rather, should happen at a layer above WireGuard, with WireGuard focused on providin
6.
▲
by
fruitreunion1
3y ago
I disagree. I think it's good that implementing a secure network tunnel and obfuscation are separate. WireGuard can handle the secure tunnel functionality while I can apply any sort of obfuscation protocol on top of it without worrying
7.
▲
by
fruitreunion1
3y ago
I don't want to revoke a key to test but I'm pretty sure that just sets the port in the Endpoint part of the WireGuard config file. (the port you use to connect, for if the regular one is blocked). Are you sure your service behind
8.
▲
by
fruitreunion1
3y ago
You forget that some people like general purpose computing. Android and other mobile operating systems (as well as Chrome OS) do have great security, but that comes at the expense of functionality (arbitrary code execution is discouraged, p
9.
▲
by
fruitreunion1
3y ago
Another term I've seen used is "traditional Linux distributions" as opposed to locked-down/less general purpose like Android and Chrome OS.
10.
▲
by
fruitreunion1
3y ago
Well, Alpine wouldn't fit that definition but is still a user-controlled Linux.
11.
▲
by
fruitreunion1
3y ago
>We should not destroy the entire internet to protect/increase adtech profits. Yeah, ideally businesses wouldn't be built on this model (free service funded by ads at the expense of privacy and now user control). Then we might
12.
▲
by
fruitreunion1
3y ago
>To prevent ad fraud either you need to increase the fingerprintablity of users on the web, violating people's privacy, or implemented a form of remote attestation, which protects people's privacy. >If EFF cares no much abou
13.
▲
by
fruitreunion1
3y ago
When the alternative is sacrificing privacy or anonymity, I think it's at least useful, even if not ideal given the current energy situation.
14.
▲
by
fruitreunion1
3y ago
I think in internal environments like within a company it's fine. Just not in the public, user-facing web.
15.
▲
by
fruitreunion1
3y ago
>Can someone give a counter argument of how this might benefit the users themselves? Remote attestation might reduce the amount of cheaters in games and fraud in banks if implemented properly. So, through potential indirect means. I don&
16.
▲
by
fruitreunion1
3y ago
Is there really much browsers can do to actually effectively restrict fingerprinting without going all out like Tor Browser? WEI may disincentivize websites to not use fingerprinting, but if they really wanted to, they could use it for de
17.
▲
by
fruitreunion1
3y ago
Tor Browser defaults to JS enabled.
18.
▲
by
fruitreunion1
3y ago
Yeah, I think there's just a disconnect in culture. Making IRC more viable towards those who like Discord etc. would fundamentally change and ruin it for many who like IRC. And vice versa. So IRC will never resurrect and be used by the
19.
▲
by
fruitreunion1
3y ago
>Go ahead and create 1 account per 1 server, nothing prevents you. Doesn't having to give up a phone number for each account (and you can't use the same number on different accounts) make it difficult? (unless you haven't
20.
▲
by
fruitreunion1
3y ago
I use it for just about everything except for things tied to IRL identities. (short-lived usage like making a search request, to persistent identities like this) Some services block Tor. Sometimes they can be bypassed by pressing "New
21.
▲
by
fruitreunion1
3y ago
i2p is an alternative with its main focus on hidden services rather than outproxying to the regular net, that seems to be somewhat used with torrents.
22.
▲
by
fruitreunion1
3y ago
Yeah, I'm disappointed there's no permission toggle so that I could have javascript-based clipboard setting behind a prompt on most websites and have exceptions for others.
23.
▲
by
fruitreunion1
3y ago
Bash also buffers pasted content.
24.
▲
by
fruitreunion1
3y ago
>You can. It's just that no browser that supports HTTP/3 will accept it as a legit endpoint with a valid root. So they won't connect to the HTTP/3 endpoint at all and you won't be able to access the HTTP/3 s
25.
▲
by
fruitreunion1
3y ago
yeah, I liked being able to archive and scrape web content with yt-dlp, gallery-dl, and similar tools
26.
▲
by
fruitreunion1
3y ago
The captcha and fingerprinting methods are higher effort compared to attestation, so I think there is an incentive for most sites to get rid of it in favor of attestation.
27.
▲
by
fruitreunion1
3y ago
You can compartmentalize such activities to a dedicated device, much like one may need a Windows device for certain software or an Android device for features in banking apps that aren't available on the website.
28.
▲
by
fruitreunion1
3y ago
It's so silly that some sites block addresses that weren't exit nodes.
29.
▲
by
fruitreunion1
3y ago
I feel a bit similarly. I'm torn these having very cool and interesting security properties but this way of using computers, for a lack of a better description, is just not what I'm after.
30.
▲
by
fruitreunion1
3y ago
De-googled as in not tied to a Google account and its web services. Look at something like ungoogled-chromium.
More ›