<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: banger180</title><link>https://news.ycombinator.com/user?id=banger180</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 21 Apr 2026 13:48:54 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=banger180" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by banger180 in "Millions of Accounts Vulnerable Due to Google's OAuth Flaw"]]></title><description><![CDATA[
<p>> I wonder what action is causing the sub to change like the author suggests is happening.<p>Indeed this would be very interesting.<p>This issue is also very similar to CVE-2024-25618.<p>What we did to mitigate this is the following:
- Federated login with OIDC
- Look for a user based on the sub claim
- If they are found: authenticate that user and optionally update their profile (email, name, ...) based on then new id claims.
- Else look for a user matching on the `email` claim and link the `sub` to that user
- If no user is found create a new one</p>
]]></description><pubDate>Tue, 14 Jan 2025 18:01:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=42701127</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=42701127</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42701127</guid></item><item><title><![CDATA[New comment by banger180 in "Google’s OAuth login doesn’t protect against purchasing a failed startup domain"]]></title><description><![CDATA[
<p>> “The sub claim changes in about 0.04% of logins from Log in with Google. For us, that's hundreds of users last week”.<p>What I don't understand is why the `sub` claim is not consistent for those users at Google. To my understanding of the OIDC protocol the `sub` should be unique for a specific user.<p>Additionally as far as I understand if you take over a defunct domain and create a new google workspace with new users those new user account should get assigned a new `sub`.</p>
]]></description><pubDate>Tue, 14 Jan 2025 17:29:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=42700570</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=42700570</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42700570</guid></item><item><title><![CDATA[40 Years of European Digital Policies. Forgotten Lessons [video]]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.youtube.com/watch?v=kXefs6tmTgo">https://www.youtube.com/watch?v=kXefs6tmTgo</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=40884676">https://news.ycombinator.com/item?id=40884676</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 05 Jul 2024 17:52:52 +0000</pubDate><link>https://www.youtube.com/watch?v=kXefs6tmTgo</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=40884676</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40884676</guid></item><item><title><![CDATA[New comment by banger180 in "Flathub: One million active users and growing"]]></title><description><![CDATA[
<p>I really like flatpaks, easy to install and work with. Definitely superior over Ubutnu's snaps. As a user you do have to be somewhat aware that the application is running in a sandbox and won't behave exactly like one running without a container. For example the Belgian digital ID card software does not work in a sanboxed browser. At least not by default a the moment.</p>
]]></description><pubDate>Mon, 29 Jan 2024 19:46:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=39181437</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=39181437</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39181437</guid></item><item><title><![CDATA[New comment by banger180 in "USB-C is about to go from 100W to 240W, enough to power beefier laptops"]]></title><description><![CDATA[
<p>USB-c Power Delivery does not require an intel CPU, so I don't see a problem.</p>
]]></description><pubDate>Wed, 26 May 2021 11:06:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=27288912</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=27288912</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27288912</guid></item><item><title><![CDATA[New comment by banger180 in "Response to Flatkill.org"]]></title><description><![CDATA[
<p>And what if i do not use a debian based distro for which the ppa works?<p>Maintaining one package that works on all distros is a lot easier.</p>
]]></description><pubDate>Mon, 22 Mar 2021 16:49:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=26543327</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=26543327</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26543327</guid></item><item><title><![CDATA[New comment by banger180 in "The Signal Server repository has not been updated since April 2020"]]></title><description><![CDATA[
<p>I honestly believe matrix will become the go to for (federated) messaging everywhere. The element client has much improved and matrix is continuing to get better.</p>
]]></description><pubDate>Thu, 04 Mar 2021 18:30:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=26346196</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=26346196</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26346196</guid></item><item><title><![CDATA[New comment by banger180 in "This Week in Matrix 2021-01-08"]]></title><description><![CDATA[
<p>> This might not be the right place to ask but I've been looking into matrix and am I right that if you don't want to rely on a central authority then you need to run your own homeserver, which at minimum requires a publicly accessibly HTTPS server?<p>If you run your own homeserver you are completely independent and don't rely on anyone else.<p>If you want to join the federation and talk to people on other homeservers you do need a publicly accessible web server with a valid TLS certificate (which you can get for free from let's encrypt).<p>If you only want to chat with people on the same server you can choose not to join the federation, but this is not what matrix was designed for.<p>> those homeservers seem very public by default if you just want one for your personal use.<p>You can disallow public user creation in the homeserver config. Then only users you have created can access your homeserver. Of course anyon in the federation can invite your users to a room etc.<p>> Which makes it seem a bit risky<p>I don't think there is a very large risk to running your own homeserver (not more than running other services).<p>A matrix homeserver can require quite some resources depending on how many users you host and how large the rooms are. Also there is some normal administration required (updating, making sure the cert is valid, ...).</p>
]]></description><pubDate>Sat, 09 Jan 2021 08:40:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=25698690</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=25698690</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=25698690</guid></item><item><title><![CDATA[New comment by banger180 in "How Discord (somewhat accidentally) invented the future of the internet"]]></title><description><![CDATA[
<p>Too bad it is a completely proprietary walled garden and that they do not care about privacy or security.<p>I would love for matrix to eventually replace discord, but ATM discord is still a better user experience.</p>
]]></description><pubDate>Sun, 01 Nov 2020 19:46:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=24961943</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=24961943</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24961943</guid></item><item><title><![CDATA[New comment by banger180 in "Huawei’s HarmonyOS is now open source"]]></title><description><![CDATA[
<p>Yep, The largest threat to the international FOSS collaboration is the US bullying other countries.</p>
]]></description><pubDate>Fri, 11 Sep 2020 09:18:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=24440649</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=24440649</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=24440649</guid></item><item><title><![CDATA[New comment by banger180 in "The Day AppGet Died"]]></title><description><![CDATA[
<p>> "apt-get" is the classic tool for Windows Subsystem for Linux<p>APT is the classic tool for debian-like Linux distributions. FTFY</p>
]]></description><pubDate>Thu, 28 May 2020 08:48:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=23334980</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=23334980</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=23334980</guid></item><item><title><![CDATA[New comment by banger180 in "Ubuntu 20.04 LTS’ snap obsession has snapped me off of it"]]></title><description><![CDATA[
<p>There are many kinds of linux users, just like there are many kinds of windows users.</p>
]]></description><pubDate>Sat, 02 May 2020 16:47:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=23052978</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=23052978</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=23052978</guid></item><item><title><![CDATA[New comment by banger180 in "Zoom 5.0"]]></title><description><![CDATA[
<p>My Guess is that it is mostly a security through obscurity thing for now, we do not know exactly how they mark the audio. When someone figures this out I believe that it should be possible to filter this out.<p>It would be interesting if they found a way to watermark the audio in such a way that removing the mark makes the audio unusable.</p>
]]></description><pubDate>Tue, 28 Apr 2020 21:33:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=23012364</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=23012364</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=23012364</guid></item><item><title><![CDATA[New comment by banger180 in "Ask HN: Best current mailing list manager?"]]></title><description><![CDATA[
<p>Fedora usses mailman 3 and hyperkitty at <a href="https://lists.fedoraproject.org/archives/" rel="nofollow">https://lists.fedoraproject.org/archives/</a><p>It is infidelity inspired by the layout of a forum, but looks great IMO.</p>
]]></description><pubDate>Mon, 27 Apr 2020 19:40:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=22999183</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=22999183</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22999183</guid></item><item><title><![CDATA[New comment by banger180 in "ICANN delays .org selloff after California’s attorney general intervenes"]]></title><description><![CDATA[
<p>Except that centralization will eventually give rise to corruption =p. It's and endless debate I guess. But for an organization like ICANN my vote goes to decentralization.</p>
]]></description><pubDate>Fri, 17 Apr 2020 20:48:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=22902836</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=22902836</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22902836</guid></item><item><title><![CDATA[New comment by banger180 in "Curl will now output JSON"]]></title><description><![CDATA[
<p>Yep this would be really great.</p>
]]></description><pubDate>Tue, 17 Mar 2020 20:30:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=22609981</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=22609981</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22609981</guid></item><item><title><![CDATA[New comment by banger180 in "Share Now, formerly Car2Go, is leaving North America"]]></title><description><![CDATA[
<p>and sad...</p>
]]></description><pubDate>Thu, 19 Dec 2019 03:17:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=21831758</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=21831758</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=21831758</guid></item><item><title><![CDATA[New comment by banger180 in "Websites can change content inside a selection"]]></title><description><![CDATA[
<p>An alert that you did not copy what you think you copied would not be out of place in my opinion.</p>
]]></description><pubDate>Mon, 28 Oct 2019 16:45:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=21378611</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=21378611</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=21378611</guid></item><item><title><![CDATA[New comment by banger180 in "Guess I'm Done with Discord"]]></title><description><![CDATA[
<p>Yep, I wished matrix would replace discord and all other proprietary crap. Unfortunately the UX is still a bit lacking, but if you somewhat know what you are doing it's great.</p>
]]></description><pubDate>Sun, 25 Aug 2019 04:48:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=20791415</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=20791415</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=20791415</guid></item><item><title><![CDATA[New comment by banger180 in "Google's Quantum Processor May Achieve Quantum Supremacy in Months"]]></title><description><![CDATA[
<p>Do you have a reference to these theories? Seems interesting</p>
]]></description><pubDate>Mon, 24 Jun 2019 08:24:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=20261491</link><dc:creator>banger180</dc:creator><comments>https://news.ycombinator.com/item?id=20261491</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=20261491</guid></item></channel></rss>