Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mhils
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
mhils
4y ago
mitmproxy would not really be helpful for what you describe, this sounds like she is confusing it with some other software/stalkerware.
32.
▲
by
mhils
4y ago
WireGuard mode does not help with interception, it helps with getting traffic into mitmproxy. Put differently, it's a user-friendly alternative to 1. configuring an explicit HTTP proxy in your system settings, or 2. fiddling with
33.
▲
by
mhils
4y ago
I don't think I'm aware of any. If possible I would recommend using a browser extension like uBlock Origin instead, being in the browser context makes adblocking more efficient. (I realize not every client is a browser, I simply d
34.
▲
by
mhils
4y ago
We can definitely intercept DTLS now, there are no specific contentviews (pretty-printers) for WebRTC yet. I don't know how much of a binary protocol WebRTC is that would make pretty-printing necessary. :)
35.
▲
by
mhils
4y ago
The recommended way to install mitmproxy on Linux is to download new standalone binaries. They are self-contained and can just be dropped into /usr/local/bin. If you want some way to update automatically, use our Docker image
36.
▲
by
mhils
4y ago
Hard to say without more details. Once you reach that limited connectivity state, do you see anything that stands out in the mitmproxy event log? Feel free to open a thread at https://github.com/mitmproxy/mitmproxy/
37.
▲
by
mhils
4y ago
I haven't played around with this myself yet, but basically: 1. Configure your device to use mitmproxy. 2. Visit our magic mitm.it domain on the device. 3. Click on "Show Instructions" for Android.
38.
▲
by
mhils
4y ago
Are you looking for mitmproxy-on-linux maintainers, or Linux kernel maintainers? You have found the former I suppose, but I'm the wrong person to ask for the latter. :)
39.
▲
by
mhils
4y ago
If you can run mitmproxy on another device, then our new WireGuard mode does exactly fix that problem. At least as long as WireGuard is able to capture all traffic. :) Transparent same-device interception is something where we still need to
40.
▲
by
mhils
4y ago
mitmproxy dev here, happy to answer questions once I'm back home later! :)
41.
▲
by
mhils
4y ago
Yes, the UDP parts are preparation for QUIC/HTTP/3! We will be there soon. :-)
42.
▲
Mitmproxy 9: WireGuard Mode
(mitmproxy.org)
158 points
by
mhils
4y ago
|
46 comments
43.
▲
by
mhils
4y ago
Thank you! :) You are absolutely right on pre-commit hooks. My experience with FOSS projects is that it's quite hard to get contributors to follow your style guides and/or opt-in to pre-commit hooks. In this case it's much ea
44.
▲
by
mhils
4y ago
Author here, happy to answer any questions! :)
45.
▲
Show HN: Automatically fix linting/code formatting issues in pull requests
(autofix.ci)
5 points
by
mhils
4y ago
|
3 comments
46.
▲
by
mhils
4y ago
Anecdata: Copilot has been net-negative for me when writing Python, but the Rust completions are fantastic .
47.
▲
by
mhils
4y ago
Not yet, but you might be lucky soon. We have an RSS feed on mitmproxy.org and a Twitter account. :-)
48.
▲
by
mhils
4y ago
AdTech increasingly uses CNAME cloaking-style tricks to evade DNS blocking. Some of those tricks are detectable, but DNS blocking will inevitably fail once ads are served from the first party domain. It's still rare, but simple CNAME c
49.
▲
by
mhils
4y ago
I wouldn't write it off - one possible trick here is to also MITM the DoH/DoQ server and disable ECH by removing the relevant records from the DNS response. We've just added DNS support to mitmproxy and this is a natural foll
50.
▲
by
mhils
4y ago
This approach is a natural escalation step as DNS-based blocking is getting increasingly difficult. But it's not without its drawbacks. For example, browsers tend to have by far the best TLS implementations. By MITMing yourself, you es
51.
▲
by
mhils
4y ago
FWIW, if your PyInstaller experience is from several years ago, I'd strongly recommend checking it out again. I used to dread its updates because they usually broke something, but everything has been super smooth in the last 1-2 years.
52.
▲
by
mhils
4y ago
mitmproxy dev here, very awesome! :) This seems to be particularly useful to quickly generate clients for reverse-engineered APIs.
53.
▲
by
mhils
4y ago
Technically possible, but I don't think that works with code signing (more accurately: every developer using it needs to re-sign).
54.
▲
by
mhils
4y ago
I think there are other, more effective, mitigations in place against the threats you are describing. First, there's no automated way to install CAs on Android. Users must do this step manually (the articles you linked are about Window
55.
▲
by
mhils
4y ago
Enforcing CT is good, but that doesn't excuse the treatment of user-added CAs. On all platforms but Android, user-added CAs are considered particularly trustworthy . For example, Chrome Desktop, Firefox, and IE did not enforce HPKP if
56.
▲
by
mhils
4y ago
Thank you - that explanation makes sense, apology accepted. :)
57.
▲
by
mhils
4y ago
We've been one of 666 repos, and I'm not too happy of having our repo used as advertising space. Some thoughts: - I'm happy to receive fix-a-typo PRs from human users. In this case the other side demonstrated that they care b
58.
▲
by
mhils
4y ago
In our case OPs bot did not open a PR which could have been merged quickly, but filed an issue instead.
59.
▲
by
mhils
4y ago
We've blocked the bot after their script malfunctioned and they opened a second issue with exactly the same text ( https://github.com/mitmproxy/mitmproxy/issues/5286 ).
60.
▲
by
mhils
5y ago
mitmproxy dev here! Happy to answer any questions. Answers may take a while as I'm on a remote mountain hut, but please shoot. :)
More ›