Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ultramancool
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
ultramancool
10y ago
This seems trivial to me. Heck, you could practically make it full out remote exec and grab output from airgapped machines if USB keys were moved between them frequently enough. Serialize and encrypt tiny blob with command, do the same for
92.
▲
by
ultramancool
10y ago
I can't see that working out well, it'd just be way too easy to cheat, you could fake any IP you wanted, pretend to be connecting from the regular consumer ISPs and generate fake hits, fake clicks and otherwise easily steal from t
93.
▲
by
ultramancool
10y ago
Yeah, or visual, anything with this CSS attributes applied (so even if they randomize names it can still be blocked) to it or something. Maybe even the element at this rendered location, which would pretty much guaranteed kill them unless t
94.
▲
by
ultramancool
10y ago
It'd also be a big risk in that it'd be easier to cheat the ads as they'd all come from the same connecting IP. I doubt advertisers would appreciate that much.
95.
▲
by
ultramancool
10y ago
> If FB decided to shut down some features to ad-blocking users, do you think that would be unfair? I think "they're welcome to try" is exactly the right response here. Nothing is "fair" or "unfair", at
96.
▲
by
ultramancool
10y ago
> If you do modify your device in a way that it can't be guaranteed that the updates will secure the device anymore (which shouldn't be an issue for the vast majority of user modifications), then you simply lose that "warr
97.
▲
by
ultramancool
10y ago
> How about a simple "devices selling in excess of 500 units must have security devices updates provided for four years from the first date of sale"? Legislation doesn't have to be onerous. Even this is problematic, you st
98.
▲
by
ultramancool
10y ago
Be careful what you wish for, this type of legislation may unintentionally prevent consumer level device modifications like rooting and custom roms which allow security researchers the ability to find these issues and basically restrict thi
99.
▲
by
ultramancool
10y ago
SuperSU is simply a tool which allows apps to gain root access with user permission via an API. Apps that use exploits like this can still gain root with no need for user permission. However, exploits like this can also be used for users to
100.
▲
by
ultramancool
10y ago
I just don't understand where the difficulty some people have in mind comes from so I'm trying to understand it better. You don't have to be bleeding edge to be secure against remote attacks, most of the configuration is triv
101.
▲
by
ultramancool
10y ago
Why do you think they'll respect your privacy any more than gmail? I think that's a serious misconception. They have no way to guarantee that to you, so believing it is a rather bad idea. They could be sitting back and reading the
102.
▲
by
ultramancool
10y ago
Updating the OS... usually a fairly rare occurence again, kernel vulnerabilities that affect you with minimal services exposed are quite rare, most vulnerabilities are local escalations and such which wouldn't affect just a mail server
103.
▲
by
ultramancool
10y ago
Updated is usually barely a problem, there hasn't been a serious postfix vulnerability since 2011 or a dovecot one since 2013 (and even the 2013 one wouldn't necessarily affect you as an individual user). One update every 3-5 year
104.
▲
by
ultramancool
10y ago
> That, and all the complications that running your own email server brings with it. If you read the article, the author explains it very well. I have to disagree, it sounds like he just had a crappy provider, avoiding blacklists is pret
105.
▲
by
ultramancool
10y ago
Maintenance is minimal, it's pretty much set and forget, add a cron job to update spamassassin, I get maybe 1 piece of spam in my inbox a week. Configuration (at least using dovecot and postfix) is easy too once you get started.
106.
▲
by
ultramancool
10y ago
I bought a house and run all my bills from my own mail server, so that certainly hasn't been my experience. You just need to configure it correctly and make sure your IP doesn't have a bad rep.
107.
▲
by
ultramancool
10y ago
> FastMail is a cheap and easy option to email. So is spinning up a docker container with this all already configured... I just don't see the argument I guess, it's just too easy to do yourself. Instead you're getting ripp
108.
▲
by
ultramancool
10y ago
Why would you use FastMail when hosting your own mail server has a much higher privacy level? It seems no better than gmail in this respect.
109.
▲
by
ultramancool
10y ago
> Buying copywritten works usually buys license yo use, not distribute (share) Under this definition loaning a book or movie to a friend is sketchy. The sharing model is rampant as individuals, it only became a problem when the internet
110.
▲
by
ultramancool
10y ago
Hello used to be some kind of picture messaging app related to Picasa if I remember correctly.
111.
▲
by
ultramancool
10y ago
Even with good tooling the current restrictions on Let's Encrypt make it impossible, you can batch many subdomains into 1 request however if you're requesting subdomains by customer username or similar, you can't exactly wait
112.
▲
by
ultramancool
10y ago
In this case a distribution site which hosts both the hash and the file was hacked. This test is only good for "is the integrity of the download good" not for "is this created by the original developer". An authenticode
113.
▲
by
ultramancool
10y ago
It also verifies signatures before it will execute the update, so even if that source were hacked it wouldn't have been affected.
114.
▲
by
ultramancool
10y ago
Someone have a copy of the infected version? I'd like to take a look.
115.
▲
by
ultramancool
10y ago
Yeah, but many apps for Windows still aren't signed so many users are trained to just click through.
116.
▲
by
ultramancool
10y ago
Pretty much true. As these attackers stated on their own twitter "You ran it as admin, just be glad we didn't steal everything". All it takes is user access to dump all your stored passwords and run, which is what most attack
117.
▲
by
ultramancool
10y ago
> I wonder what kind of programmer works for companies that produce this spyware... Googling around there's several similar tools available on GitHub... so I guess the answer to your question is lots of people would do it mostly for
118.
▲
by
ultramancool
10y ago
> If there's some other use case that dominates "mobile phone" for mobile phones, let's hear it. The use case is a lot larger than just "mobile phone". I'm an Android guy, but I rarely use my phone to m
119.
▲
by
ultramancool
10y ago
That's only to sell though - I mean buying there and selling on Amazon or similar.
120.
▲
by
ultramancool
10y ago
I'd aim more for Aliexpress to Amazon arbitrage. I've seen people selling stuff with 3-10x markup, Realtek SDR dongles, bluetooth speakers, etc. It's nuts. And I've seen people who know that still pay for it because they
More ›