<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: NotPractical</title><link>https://news.ycombinator.com/user?id=NotPractical</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 27 Jul 2026 01:02:55 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=NotPractical" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by NotPractical in "GDID Windows – Cut the tracker that follows you even under VPN"]]></title><description><![CDATA[
<p>> Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place<p>What they did was the opposite: ask Microsoft for GDIDs used by attacker-associated IPs within several 24-hour time periods during which attack-related activity took place. Windows pings Microsoft regularly with the GDID, establishing links between your GDID and any IP addresses you use. The IP logs from Microsoft and the VPS provider showed at least 10 instances where a single VPN IP accessed the attacker's VPS and also pinged Microsoft with at least one GDID within a 24-hour period. They found a constant GDID that all instances shared. This seems to have been the most damning GDID-related evidence in the DOJ complaint [1] and yet it wasn't mentioned in the article you linked (or any other articles about this I've seen pop up on HN). It includes the diagram from the complaint (page 18) that outlines this, but devoid of context. The ngrok stuff that the article focuses on was just the cherry on top and was discussed later in the complaint.<p>What also becomes clear when you read the complaint is that the GDID was just one piece of the puzzle and that they had plenty of other evidence. Attacker-associated IPs were used to access the suspect's Apple, Snapchat, and Facebook accounts, at least one of which was his actual residential IP, not a VPN IP. Once they had revealed the identity of the person who owned these accounts, they were able to all-but-confirm that this was in fact the attacker.<p>What remains unclear even after reading the complaint is how they were so sure that the GDID they obtained visited specific websites, but honestly, at that point, they were already drowning in evidence, so I don't know if it matters that much. It could be as simple as "he was signed into Edge with his Microsoft account and had sync enabled".<p>[1] <a href="https://www.justice.gov/usao-ndil/media/1450651/dl?inline" rel="nofollow">https://www.justice.gov/usao-ndil/media/1450651/dl?inline</a></p>
]]></description><pubDate>Sat, 25 Jul 2026 20:31:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49051258</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=49051258</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49051258</guid></item><item><title><![CDATA[New comment by NotPractical in "GDID Windows – Cut the tracker that follows you even under VPN"]]></title><description><![CDATA[
<p>I think the difference is that, on Windows, there are background services that constantly ping Microsoft with the device ID. A device ID on its own is not really harmful if it's not exposed to the internet.</p>
]]></description><pubDate>Sat, 25 Jul 2026 17:28:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=49049619</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=49049619</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49049619</guid></item><item><title><![CDATA[New comment by NotPractical in "Android May Soon Restrict On-Device ADB"]]></title><description><![CDATA[
<p>I have bad news for you if you think GrapheneOS isn't going to accept this patch from upstream if it lands.</p>
]]></description><pubDate>Sat, 25 Jul 2026 16:41:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=49049085</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=49049085</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49049085</guid></item><item><title><![CDATA[New comment by NotPractical in "Introducing selfie for sign-in: a new way to access your Google Account"]]></title><description><![CDATA[
<p>There is no information about the author of this article, and it has the "AI smell". It's safer to operate under the assumption that it is AI generated unless and until the author reveals themself or at least anonymously confirms that it is not AI generated. This saves you from having made a fool of yourself by spreading it around, if it later becomes apparent that AI wrote it.</p>
]]></description><pubDate>Fri, 24 Jul 2026 18:56:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49040163</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=49040163</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49040163</guid></item><item><title><![CDATA[New comment by NotPractical in "What's wrong with EU age verification? (Nothing)"]]></title><description><![CDATA[
<p>> A next version of the Technical Specifications for Age Verification Solutions will include as an experimental feature the Zero-Knowledge Proof (ZKP) solution<p>From: <a href="https://ageverification.dev/av-doc-technical-specification/docs/architecture-and-technical-specifications/#71-zero-knowledge-proofs" rel="nofollow">https://ageverification.dev/av-doc-technical-specification/d...</a><p>The EU reference implementation is adding ZKP.</p>
]]></description><pubDate>Wed, 01 Jul 2026 15:49:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48748808</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48748808</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48748808</guid></item><item><title><![CDATA[New comment by NotPractical in "What's wrong with EU age verification? (Nothing)"]]></title><description><![CDATA[
<p>Except that within days of this service going live there's going to be a freeageverification.com that instantly generates an attestation proof for anyone for free. I fail to see how this is not untenable. You can compare it to geoblocks that can be circumvented using VPNs, but at least VPNs are costly to run and are usually paid services. With the implementation of verification (ZKP) described in the article, there is no cost to generate attestation proofs nor any limit on the number of proofs nor any way to stop a known-but-anonymous abuser from generating new proofs.<p>Maybe the EU knows it's untenable and is still moving forward because they will be able to demonstrate to the public that privacy enables abuse, creating pretext to make the system not private anymore after it's already been implemented.</p>
]]></description><pubDate>Wed, 01 Jul 2026 14:15:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48747201</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48747201</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48747201</guid></item><item><title><![CDATA[New comment by NotPractical in "European digital ID wallets rely on safety services of Google and Apple"]]></title><description><![CDATA[
<p>Not to mention self-signed custom builds of GrapheneOS.</p>
]]></description><pubDate>Tue, 30 Jun 2026 16:31:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=48735157</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48735157</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48735157</guid></item><item><title><![CDATA[New comment by NotPractical in "macOS 27 Beta breaks the ability to boot Asahi Linux"]]></title><description><![CDATA[
<p>> I think it would be nice if we could run unsigned apps on iOS<p>Apple enforces those restrictions via the permanently locked bootloader. The main benefit of unlocking the bootloader on an iPhone would be to run a modified version <i>of iOS</i> that allows for the installation of unsigned apps. Apple wouldn't like it and might even get litigious over it, but still.<p>> (in the US)<p>Apps intended for release onto alternative app stores in the EU, Japan, and Brazil still need to be approved and signed by Apple. These laws were nearly useless.</p>
]]></description><pubDate>Fri, 12 Jun 2026 15:34:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48505476</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48505476</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48505476</guid></item><item><title><![CDATA[New comment by NotPractical in "Sweet Jeebus, macOS 27 Golden Gate Removes the Dumb Icons from Menu Items"]]></title><description><![CDATA[
<p>...it's still large enough to comfortably read without zooming in, which is not the case for Gruber's website.</p>
]]></description><pubDate>Fri, 12 Jun 2026 02:46:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48499259</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48499259</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48499259</guid></item><item><title><![CDATA[New comment by NotPractical in "Sweet Jeebus, macOS 27 Golden Gate Removes the Dumb Icons from Menu Items"]]></title><description><![CDATA[
<p>Nope, HN's CSS accommodates smaller screen sizes [1]:<p><pre><code>    /* mobile device */
    @media only screen
    and (min-width : 300px)
    and (max-width : 750px) {
      #hnmain { width: 100%; min-width: 0; }
      body { padding: 0; margin: 0; width: 100%; }
      td { height: inherit !important; }
      .title, .comment { font-size: inherit;  }
      span.pagetop { display: block; margin: 3px 5px; font-size: 12px; line-height: normal }
</code></pre>
Not perfect by any means but at least there's an attempt.<p>[1] <a href="https://news.ycombinator.com/news.css">https://news.ycombinator.com/news.css</a></p>
]]></description><pubDate>Thu, 11 Jun 2026 15:48:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48492002</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48492002</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48492002</guid></item><item><title><![CDATA[New comment by NotPractical in "Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable"]]></title><description><![CDATA[
<p>Was this program available to independent security researchers or just established organizations? The docs you linked aren't very clear on this.</p>
]]></description><pubDate>Wed, 10 Jun 2026 22:51:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=48483886</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48483886</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48483886</guid></item><item><title><![CDATA[New comment by NotPractical in "Anthropic, please ship an official Claude Desktop for Linux"]]></title><description><![CDATA[
<p>> No upstream open source developer takes that on<p>The key words here are "open source", right? Some problems can't be solved without cooperation with the developer.</p>
]]></description><pubDate>Mon, 08 Jun 2026 14:20:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48445768</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48445768</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48445768</guid></item><item><title><![CDATA[New comment by NotPractical in "Anthropic, please ship an official Claude Desktop for Linux"]]></title><description><![CDATA[
<p>There is a difference between mandating that your customers use one specific Linux distro which is maintained by a controversial company, and supporting all Linux distros through an imperfect-but-fully-working method.<p>Sure, you'll still get a few complaints from ideological purists, but there's no avoiding that regardless of what you do.</p>
]]></description><pubDate>Sun, 07 Jun 2026 18:59:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48437596</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48437596</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48437596</guid></item><item><title><![CDATA[New comment by NotPractical in "Anthropic's open-source framework for AI-powered vulnerability discovery"]]></title><description><![CDATA[
<p>Won't they just ban your account for using this?</p>
]]></description><pubDate>Fri, 05 Jun 2026 22:19:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48419093</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48419093</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48419093</guid></item><item><title><![CDATA[New comment by NotPractical in "Codex just found a "workaround" of not having sudo on my PC"]]></title><description><![CDATA[
<p>No, because a malicious AI agent could just replace the sudo binary in your path with one that collects your password and uses it to execute arbitrary code as root. Nothing short of sandboxing everything or just never using AI agents or proprietary software will prevent this.</p>
]]></description><pubDate>Mon, 01 Jun 2026 03:25:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48352289</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48352289</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48352289</guid></item><item><title><![CDATA[New comment by NotPractical in "Colorado Amended SB051 (Age Verification Bill) to Exclude Open Source Projects"]]></title><description><![CDATA[
<p>Does anyone have a citation for this that wasn't written by Claude? It wouldn't surprise me, but I refuse to look through AI slop to check the accuracy of the report.</p>
]]></description><pubDate>Thu, 21 May 2026 02:26:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48217062</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48217062</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48217062</guid></item><item><title><![CDATA[New comment by NotPractical in "Hardware Attestation as Monopoly Enabler"]]></title><description><![CDATA[
<p>> Other than enriching apple, there’s been no direct or apparent harm to the end user from the walled garden.<p><a href="https://www.reuters.com/sustainability/society-equity/apple-removes-ice-tracking-apps-after-pressure-by-trump-administration-2025-10-03/" rel="nofollow">https://www.reuters.com/sustainability/society-equity/apple-...</a><p>I don't want to hear about how this isn't Apple's fault. This isn't the big bad orange man forcing Apple to act against its will; it's a business arrangement between Apple and the president. He gets censorship, they get a weaker EU.<p><a href="https://www.whitehouse.gov/presidential-actions/2025/02/defending-american-companies-and-innovators-from-overseas-extortion-and-unfair-fines-and-penalties/" rel="nofollow">https://www.whitehouse.gov/presidential-actions/2025/02/defe...</a></p>
]]></description><pubDate>Tue, 12 May 2026 19:00:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=48112796</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48112796</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48112796</guid></item><item><title><![CDATA[New comment by NotPractical in "Google Cloud fraud defense, the next evolution of reCAPTCHA"]]></title><description><![CDATA[
<p>No, they were correct in their understanding of what I meant. I should've said "capable of passing Play Integrity's device attestation checks". I replied to them with more context.</p>
]]></description><pubDate>Fri, 08 May 2026 18:33:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48066990</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48066990</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48066990</guid></item><item><title><![CDATA[New comment by NotPractical in "Google Cloud fraud defense, the next evolution of reCAPTCHA"]]></title><description><![CDATA[
<p>It indeed runs on modified versions of Android, but this is not supported by Google and never has been.<p>When Apple says "Apple Pay is supported on iOS >= $VERSION" they don't explicitly mention that it won't work on jailbroken iPhones, because they don't expect you to make modifications to your device and then try and use their services as normal. This is unsupported and discouraged, just like trying to manually install Google Play services on an OS that didn't ship with it.<p>The only way to get Google Mobile Services officially is to buy an Android device with it pre-installed while leaving the stock OS untouched. And the only way for an OEM to ship GMS with their device is to certify it with Google. And one of the requirements for certification is to use device attestation keys signed by the Google Hardware Attestation Root certificate [1], thus Play Integrity will pass on all such devices.<p>[1] <a href="https://developer.android.com/privacy-and-security/security-key-attestation#root_certificate" rel="nofollow">https://developer.android.com/privacy-and-security/security-...</a></p>
]]></description><pubDate>Fri, 08 May 2026 18:32:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=48066977</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48066977</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48066977</guid></item><item><title><![CDATA[New comment by NotPractical in "Google Cloud fraud defense, the next evolution of reCAPTCHA"]]></title><description><![CDATA[
<p>> No mention of device integrity verification yet<p>If Google Play services is listed as a requirement, that implies that a "certified Android" device capable of Play Integrity attestation is required, since that's the only officially supported way to obtain Google Play services. On consumer-facing support articles like this, they don't tend to get into the nitty gritty details like what APIs are being used. If MEETS_DEVICE_INTEGRITY is required, that would probably not be explicitly listed here.<p>E.g. the consumer documentation for Google Pay just says you need a "certified" Android device and a screen lock set up: <a href="https://support.google.com/wallet/answer/12200245" rel="nofollow">https://support.google.com/wallet/answer/12200245</a><p>(Yes, if you go deep into the FAQ at the end it eventually states that if you rooted your phone, you can't use tap to pay, but that requirement is implied by the certification requirement [1].)<p>In Google's eyes, and in the eyes of the law due to trademarks filed by Google, Android == Google Android.<p>This feature would make little sense if it's <i>not</i> using device attestation because otherwise it would be easy to spoof. I expect that it will initially not use it, and they will start A/B testing device attestation in the coming years.<p>[1] Expand "What to do if you see device is not certified" -> "Reset device to fix issue" <a href="https://support.google.com/android/answer/7165974" rel="nofollow">https://support.google.com/android/answer/7165974</a></p>
]]></description><pubDate>Wed, 06 May 2026 19:36:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48040663</link><dc:creator>NotPractical</dc:creator><comments>https://news.ycombinator.com/item?id=48040663</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48040663</guid></item></channel></rss>