Hacker Newsnew | past | comments | ask | show | jobs | submit | pohuing's commentslogin

I'm getting a solid frame per second in FF android. It's quite nostalgic to have a navigation system this laggy.

It runs about as well in Chrome as in Firefox for me, so I don't think this will work particularly well on any phone at the moment.


And they're also easy to read. So if you find a wallet you can figure out where the owner lives for a visit/s

Was a bit shocked to find that I can just read my suica using my European Pixel. I had expected that part to be encrypted somehow.


I had an rx 5700xt where one version worked on bf4 but it didn't work on doom eternal. Meanwhile the version had unusable performance when streaming my game to friends. So any time I wanted to play games with friends I had to reinstall an older version. This stayed an issue for months with no communication from AMD.

My current rx6900xt meanwhile has quite a few other stalls and crashes, and doesn't get any of the cool rocm support the 7000series gets.

So my next gpu will be an nvidia. Paying over a thousand euros for a gpu, only to get your support dropped after 2(two!) years of shoddy drivers is just unbearable.

I understood shoddy drivers in the R series, Vega(another lemon i bought) as well, AMD was flat out broke. But by now they surely have some money left over from the ryzen success to make their gpus at least stable.


There's a couple avenues besides just stealing what's in your URL bar.

If you don't use wildcard certs all of your subdomains can be scraped from the certificate transparency logs. Additionally, any domain+cert using HSTS with preload enabled end up in a big list at Google to speed up the initial connection from browser to site.


CT logs just explain how they found the domain. T doesn't explain how they could have found unlinked content on the domain itself. If I put up secret-example.com/asdf-1234567.html, how does that page get found if there are no public links to it?


True. I just assumed imprecise phrasing.

Google misusing chrome browser history as a hitlist for indexing sounds wild to me, so I tried to see if there's another way.

It also felt unlikely because there's multiple subdomains of mine that aren't indexed, and wildcards+no preload are the only precautions I've made myself for my private sites.

This might also be an EU vs rest of World thing, or my stuff isn't interesting enough to index(in retrospect the most likely reason I suppose)


Don't underestimate people not knowing were they share stuff by accident.

Creating Sitemaps, sharing it somewere public, putting the url in some 3th party service, server logs, some indirect path in javascript.

But if you never mention that url, it will not be found if not leaked by your server.


> But if you never mention that url, it will not be found if not leaked by your server

That sounds like a claim that security through obscurity is infallible, which is dubious. Don't get me wrong, it can be a reasonable part of defense-in-depth strategy, but like, brute force attacks are kinda a well known thing, especially if your URLs aren't truly random...


For hosts, but not pages on the site.

But I think the other explanations take care of pages: cloudflare hints, chrome reporting addresses visited, etc.


> HSTS with preload enabled end up in a big list at Google to speed up the initial connection from browser to site.

HSTS preload is not for speed. It's to protect against SSL stripping on first connection. Modern browsers already try port 443 first or in parallel with 80.


The recommendation is to get your basic immunization of 1-3 pricks depending on how many you've already had, or if you've already had covid.

Certain at risk individuals, or ones that work with them are recommended to also get a prick every year around autumn ideally.

If you're not in that last category the insurance will only cover your initial innoculation.


They do. Good luck getting Firefox otherwise, so I don't mind it.

Similarly, they bundle Bing as the Web search in the start menu.


If you can convince a victim to install an app, you can probably convince them to enable screen overlays, accessibility features etc. Apparently these scams are quite common in South East Asia.

Nevertheless, scammers will just use stolen identities to sign their malware.

This is just a thinly veiled attempt to prevent apps such as ReVanced YouTube or others that ruffle IP holders, such as alphabet.


Stolen identities have the same problem as stolen Google Play publisher credentials. As soon as one scammer who has used an identity is found, the identity is burned, and all the scammers using that identity have to look for another. This is different from self signed certificates that you can create at will.

People like me who use Morphe aren't actually going to be inconvenienced much, so I doubt appeasing IP holders is the motivation.


I expect Google to ban the devs eventually. After all the app's sole purpose is breaking the TOS of YouTube.

Thank you for name dropping Morphe btw, I'll use that for as long as it still works.


Morphe can still self sign. Nothing has changed in that regard. The only thing developer verification adds is the ability to install an app outside a system app store without a warning, but Morphe has always been distributed outside system app stores with a warning.


Even sneakier. If you use an ad block(FF android with Privacy Badger and Block Origin) it'll tell you your connection doesn't support uniq yet. But if you then load the page in chrome without add-ons you can suddenly manage it, despite being on the same connection!

I guess I can't expect an advertising platform to work with adblockers on.


> We were able to watch some of the movements to Venezuela and Iran in advance of hostilities.

These were deliberately visible to show that the US is not messing around this time. A mass evacuation would never advertise in ads-b. But perhaps you could see a drop in activity as hidden planes get priority on the runway?


It does remove money from local economies. The drawdown of the British hurt my regional economy quite a bit.


That makes sense. It's like packing up a very small city of US influence abroad, just more embarrassing self-destructive petulance from Trump. He probably wants a headline that looks like he's hitting back more than anything.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: