<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ds</title><link>https://news.ycombinator.com/user?id=ds</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 21 Apr 2026 10:12:19 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ds" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[4chan has been hacked, Database exposed]]></title><description><![CDATA[
<p>Seems to be a full database access hack as well.<p>As expected, Lots of bad words on the site currently, album link below is not safe for work :<p>https://imgur.(NSFW)com/a/qa-won-R7c6EBw</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43689484">https://news.ycombinator.com/item?id=43689484</a></p>
<p>Points: 39</p>
<p># Comments: 2</p>
]]></description><pubDate>Tue, 15 Apr 2025 06:08:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=43689484</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=43689484</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43689484</guid></item><item><title><![CDATA[New comment by ds in "Google’s OAuth login doesn’t protect against purchasing a failed startup domain"]]></title><description><![CDATA[
<p>Nearly a decade ago, there was a website called thehunt.com that basically ran out of money and some employees were acqui-hired by pinterest.<p>All of the assets were left to rot and at the time the company was a good match for another startup of mine. So I reached out to the investors I found on crunchbase and asked if I could acquire everything. We worked out a deal and I did. The issue was the complete lack of people from the old company willing to assist and the complete lack of data for alot of things. There was 1 or 2 people who we could ping from the old company to ping who were super helpful, but the big thing was many things were just lost to time- passwords, history, code repos, etc..<p>Simply creating a new google apps account allowed us to get full access back to <i>everything</i> - We could even read old slack messages (even DMs!) by resetting each accounts password. The whole thing was shocking to say the least, but with that access we got back into literally every service they used and managed to get it up and running again within a week, which was a good thing because nearly every service it was using was threatening to shut it down every day for lack of payment.<p>I think the solution here is actually way simpler than most make it out to be and could easily be a startup for someone:<p>Create a startup that lets customers simply enter in domains. If the domain EVER goes into the "pendingDelete" status, inform the customer. The customer would be random SAAS's that want to protect against this type of attack and could simply choose to disallow access to any account that has had their domain go into that status.</p>
]]></description><pubDate>Tue, 14 Jan 2025 19:00:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=42702076</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=42702076</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42702076</guid></item><item><title><![CDATA[New comment by ds in "ACF has been hijacked"]]></title><description><![CDATA[
<p>I talked at length with theo about this here if anyone wants a catch up from the very start
<a href="https://youtu.be/u-KCKEWMt-Q?t=774" rel="nofollow">https://youtu.be/u-KCKEWMt-Q?t=774</a><p>Cliffnotes- This is a absolutely insane situation but matt has come out looking insanely bad imo.</p>
]]></description><pubDate>Sun, 13 Oct 2024 05:11:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=41825322</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=41825322</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41825322</guid></item><item><title><![CDATA[New comment by ds in "Hezbollah pager explosions kill several people in Lebanon"]]></title><description><![CDATA[
<p>> "One shot attack"<p>>> This is the second time israel has done this <a href="https://en.wikipedia.org/wiki/Yahya_Ayyash" rel="nofollow">https://en.wikipedia.org/wiki/Yahya_Ayyash</a></p>
]]></description><pubDate>Tue, 17 Sep 2024 16:30:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=41569462</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=41569462</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41569462</guid></item><item><title><![CDATA[New comment by ds in "AMD's Ryzen CPUs might be slower in PC games due to a weird Windows 11 bug"]]></title><description><![CDATA[
<p>I believe that disabling core isolation and bitlocker will also give a 2-3% gain as well. Not worth it though for the security loss.</p>
]]></description><pubDate>Sun, 18 Aug 2024 01:39:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=41279487</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=41279487</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41279487</guid></item><item><title><![CDATA[New comment by ds in "Google-Wiz deal fizzles out, company will pursue IPO"]]></title><description><![CDATA[
<p>Far more likely is Google was not willing to complete the deal and was pulling the plug after looking at internal data. Wiz, fearing the bad press of Google backing out rushes to tell journalists that THEY are walking away because they are worth more.<p>Wiz's valuation is insane. Most people havent even heard of them. I think it was a > 60x ARR multiple on this deal. Id actually be kinda pissed if I was a google shareholder and they went through with it.<p>Something very strange is going on with Wiz. My gut tells me if they ever IPO to go big on puts.</p>
]]></description><pubDate>Tue, 23 Jul 2024 03:41:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=41042313</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=41042313</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41042313</guid></item><item><title><![CDATA[New comment by ds in "Synapse's collapse could spell trouble for nearly 100 fintech startups [video]"]]></title><description><![CDATA[
<p>The destruction of synapse is because of one thing: They were way, way too reliant on mercury, who was there far and away largest client. Mercury woke up one day, chose violence and left synapse to work directly with evolve.<p>The whole thing came down like a house of cards.</p>
]]></description><pubDate>Tue, 04 Jun 2024 02:11:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=40570025</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=40570025</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40570025</guid></item><item><title><![CDATA[New comment by ds in "Slack AI Training with Customer Data"]]></title><description><![CDATA[
<p>Just another read to mass delete your Slack DM's before you quit your job/move to another job.<p><a href="https://redact.dev" rel="nofollow">https://redact.dev</a> (my startup) makes this easy.</p>
]]></description><pubDate>Fri, 17 May 2024 01:29:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=40385403</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=40385403</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40385403</guid></item><item><title><![CDATA[New comment by ds in "Mozilla Drops Onerep After CEO Admits to Running People-Search Networks"]]></title><description><![CDATA[
<p>All the existing databroker remover tools are flawed because they make use of manual labor to remove you from sites, primarily done by people in third world countries.<p>We @ <a href="https://redact.dev" rel="nofollow">https://redact.dev</a> are working on a pure software mechanism for doing these optouts directly from your own device. We already have full mass deletions for over 40 social media and utilitys.</p>
]]></description><pubDate>Fri, 22 Mar 2024 21:32:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=39795082</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=39795082</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39795082</guid></item><item><title><![CDATA[A Twitter privacy change would make glassdoors look insignificant]]></title><description><![CDATA[
<p>Article URL: <a href="https://redact.dev/blog/glassdoors-trust-violation-is-just-the-start/">https://redact.dev/blog/glassdoors-trust-violation-is-just-the-start/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=39792019">https://news.ycombinator.com/item?id=39792019</a></p>
<p>Points: 3</p>
<p># Comments: 3</p>
]]></description><pubDate>Fri, 22 Mar 2024 16:03:56 +0000</pubDate><link>https://redact.dev/blog/glassdoors-trust-violation-is-just-the-start/</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=39792019</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39792019</guid></item><item><title><![CDATA[Ask HN: Why does stripe not let you accept crypto payments?]]></title><description><![CDATA[
<p>Stripe itself just gives corporate non-speak answers. When I say "accept crypto" I mean if I am on some random website that uses stripe for payments, the ability to select crypto and have it all process inside stripe.<p>I could understand if stripe was worried about regulations or KYC, but they already do (imo) way more frisky crypto implementations like powering exchanges fiat to crypto. ( see https://stripe.com/use-cases/crypto )<p>Why not let my users pay in crypto all through the existing stripe interface? Do I really have to go build ANOTHER implementation for bitpay? (Already had to do one for paypal). Stripe is becoming less and less of the "payments for developers" and more and more of the "godaddy walled garden" every year.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=39734712">https://news.ycombinator.com/item?id=39734712</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Sun, 17 Mar 2024 14:29:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=39734712</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=39734712</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39734712</guid></item><item><title><![CDATA[New comment by ds in "Mozilla Monitor Plus: automatically remove your personal info from data brokers"]]></title><description><![CDATA[
<p>We are working on a fully local version of this @ <a href="https://redact.dev" rel="nofollow">https://redact.dev</a> - Beta should be out within a month or so. Huge (obvious) advantages for doing it locally</p>
]]></description><pubDate>Wed, 07 Feb 2024 14:31:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=39288993</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=39288993</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39288993</guid></item><item><title><![CDATA[New comment by ds in "How to delete your data from data brokers"]]></title><description><![CDATA[
<p>Id get into this debate, but its been done a million times before.<p>Heres the cliffnotes of how it goes though, roughly:<p>* So is minimum wage ok then?<p>* Why cant a minimum wage person invest all their money into a startup? Why do they have to be a accredited investor?!?<p>* Why cant I just open up a payday loan place that charges 900% interest? Theres no other payday loan places around and poor people willingly will use it!<p>* What about prostitution, nobody is forcing them to do it?<p>* Alright then, Should we let poor people sell their organs? Again, nobody is forcing them to do it!<p>Cliffnotes: Just because someone will 'willingly' do something, or doesnt have any better options, doesnt make it just or moral. You setting up a 'consulting' company in bangladesh that pays people x$ a day to do something is exploiting those people, plain and simple.<p>Also, as to your phillipine cost- You are completely wrong. The average wage across the majority of regions in the country is under $10 per day. This is where (see my first link below) most shops get setup, obviously.<p><a href="https://www.outsourceaccelerator.com/articles/average-salary-in-the-philippines/" rel="nofollow">https://www.outsourceaccelerator.com/articles/average-salary...</a><p><a href="https://www.statista.com/statistics/1048636/philippines-monthly-average-salary/" rel="nofollow">https://www.statista.com/statistics/1048636/philippines-mont...</a><p><a href="https://en.wikipedia.org/wiki/List_of_Asian_countries_by_average_wage" rel="nofollow">https://en.wikipedia.org/wiki/List_of_Asian_countries_by_ave...</a></p>
]]></description><pubDate>Sun, 14 Jan 2024 16:22:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=38991771</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=38991771</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38991771</guid></item><item><title><![CDATA[New comment by ds in "How to delete your data from data brokers"]]></title><description><![CDATA[
<p>You can trust them only as much as you think they have self interest in not being sued for doing something nefarious.<p>That said, they could very easily have a data breach and every customers full info would then be out in the wild. 
Were not talking about ordinary payment details either, just full on dox - every address you have lived at, your license scan, all emails, phone numbers, its crazy. Id be willing to bet all these services are targeted quite alot as well because the people who would be willing to pay for this stuff are likely the ones with the most to lose.<p>I made a post lower in this thread but in general this entire model is flawed. Deletions should happen directly between your device and the service in question.<p>Also, its just as important to wipe the data YOU create as the data other people create about you. Just like databrokers, you can either do it manually or automated.<p>Check out <a href="https://redact.dev" rel="nofollow">https://redact.dev</a> if you want to automate that part at least (I'm on the team)</p>
]]></description><pubDate>Sun, 14 Jan 2024 16:14:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=38991711</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=38991711</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38991711</guid></item><item><title><![CDATA[New comment by ds in "How to delete your data from data brokers"]]></title><description><![CDATA[
<p>I am not OK with supporting someone getting paid 2-3 dollars a day for this labor and would prefer to not support that business model if I can.<p>I also dont trust those workers not to misuse or sell my information on the side because of the unfortunate financial situation they are in financially.<p>Its acutally a similar answer for why I dont pirate games or software. I dont want to support the behavior and I dont trust that something bad wont happen as a result (virus/malware/etc.)</p>
]]></description><pubDate>Sun, 14 Jan 2024 15:42:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=38991396</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=38991396</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38991396</guid></item><item><title><![CDATA[New comment by ds in "How to delete your data from data brokers"]]></title><description><![CDATA[
<p>The big thing to know is the following:<p>Google yourself - See what shows up that shouldnt. Go through those sites and manually opt out. Its not too hard and you get the biggest offenders.<p>Yes, you can use a automated service to do this for you but I think its a really bad idea based on how most of them work.<p>First of all- Most of the big ones make use of extensive labor in thie phillipines and malaysia to manually type your data into opt out forms. They also have to make use of extensive proxy networks that I can only suspect are not always on the up and up. This is because the databrokers will block IP's from submitting more than a few opt outs per date. So you are supporting both shady practices for the proxys and third world labor thats semi exploited<p>Second of all- You are trusting yet another company with your data. When you sign up to one of these services, they obviously know everything about you. When one of these services inevitably has a data breach in the future, its going to be a disaster.<p>The reason that the big services have difficult with the biggest services that are listed in this article is because they: Use captchas, use cloudflare and do email confirmations. They also do things where they show you multiple pieces of data and you have to pick which one is yours, but some of the data is blurred and presented as a image. ( ie- Is this email yours? tee***@gmail.com )<p>So, what to do if you want to stay on this? Well- Im creating a solution with my team to do what all the big players should have done- Do the optouts from your own device. They of course want you to do it from their servers because its a nice zero friction experience where you just type your info in and they handle most stuff. But as we see, the biggest offenders for databrokers are NOT handled because they are tricky.<p>So, at our startup <a href="https://redact.dev" rel="nofollow">https://redact.dev</a> we already built out a ton of tech for this, but targeting social media and messengers. We are now building all of that out for data brokers. And because its ran directly on your own machine there are a TON of advantages:<p>1: No limit to how often you can scan for new databroker leaks. Most of the players now limit you to once every 30-45 days<p>2: No limit to adding friends/family to scan/opt them out also.<p>3: No use of third partys to process your removals. This one is self explanatory. The deletions happen direclty between your device and the databroker- no third world workers involved.<p>4: Handles the 'hard to delete from' sites listed in the article. Our built in IMAP system can handle email confirmations no problem. Because its running from your own IP, you have no issues with getting blocked there either. Cloudflare/captchas are also no issue<p>5: Most importantly, you dont have to trust another company with your most personal information. All your data like address/names/phone stay on your device and are only sent to the sites you need to opt out from. Believe it or not, a bunch of these databroker remover sites will just bulk email a bunch of databrokers right now saying "hey, if joe smith @ 123 main street is in your DB, remove him!"<p>The big drawback is that you need to have a device open that can do the work for you. With other services you can just pay and shut off your PC or phone. You need to keep our solution open for 5 minutes while it does its work. I think thats a definitely good tradeoff for the security you get AND the fact that it instantly removes you from many of these sites. Alot of the players as I mentioned just do emails so it could take weeks or months before they remove you. If you use the databroker sites automated forms, it can be removed instantly or within days or hours.</p>
]]></description><pubDate>Sun, 14 Jan 2024 15:21:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=38991176</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=38991176</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38991176</guid></item><item><title><![CDATA[New comment by ds in "Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead"]]></title><description><![CDATA[
<p>Technically speaking, Beeper can keep working for a long time. That is, Until apple starts checking if the client is on a official apple device. This may or may not be feasible for Apple to implement, mostly depending on if they even have the resources/method to know if every device is legitimate or not (they may not- especially for older devices)<p>If they do have a way to enforce 'authentic' devices, the only step after that for beeper to take will be to ask users to purchase the cheapest iphone that still works for imessage and to extract its serial/key/whatever to import into the android client.</p>
]]></description><pubDate>Fri, 15 Dec 2023 12:25:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=38653459</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=38653459</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38653459</guid></item><item><title><![CDATA[New comment by ds in "YouTube may face criminal complaints in EU for using ad-block detection scripts"]]></title><description><![CDATA[
<p>This is a 1 dimensional view of things.<p>Maybe I can simplify it for you with this question:<p>Does Google have the ability to legally compel you to only use chrome?<p>Im guessing you would say no- Antitrust and whatnot. So the next followup is, Does Google have the ability to tell blind people they cannot use screen readers? Or that people on linux cant browse the site in lynx?<p>Again, I am guessing the answer is no- Theres anti competitive, antitrust and 230c reasons why. Legally, ad blocking is fine to do. Heres a great article going over it : <a href="https://scholarlycommons.law.wlu.edu/cgi/viewcontent.cgi?article=1552&context=wlufac" rel="nofollow noreferrer">https://scholarlycommons.law.wlu.edu/cgi/viewcontent.cgi?art...</a><p>HOWEVER- I disagree with the premise that Youtube cant try to stop adblockers- They just need to do so in a way that doesnt target specifically target a user. Twitch did a system where they would not send the video stream to you until the advertisement was done playing (which was embedded in the feed itself)- So if you blocked the ad somehow, you would just look at a black screen for 15-30 seconds. This, in my opinion would be completely compliant.</p>
]]></description><pubDate>Mon, 13 Nov 2023 13:46:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=38250047</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=38250047</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38250047</guid></item><item><title><![CDATA[New comment by ds in "Mint is shutting down, and it's pushing users toward Credit Karma"]]></title><description><![CDATA[
<p>Its great that Microsoft has teams- but nothing to do with skype as a consumer front-facing product.<p>Years ago, Skype was the de-facto solution for video calls and video meetings. There was no zoom, there was no google meet. Skype was so known for video chat that it was a verb. 'Skype me'<p>Skype absolutely and completely fell asleep at the wheel and wholesale abandoned the public market to Zoom, Discord and Google. Its not like it happened overnight either. Skype had the ability to respond to these guys but instead did almost nothing after a redesign to 'skype 8' in 2018.<p>I cant exclaim how astronomical a failure it is to go from being the defacto verb for video calls and instant messaging to not even having 5% of the end-user consumer market anymore. It would be like if people stopped using google for search, or youtube for videos. You dont get to say "Yeah well google got reworked into gsuite which has 300m users" - Its still a failure of biblical proportions.<p>They should have been capable of creating a enterprise product and keeping their consumer offering going.<p>--<p>Just to be clear, I understand teams is large and doing well. Its also a enterprise product and it has nothing to do with what im talking about above. Discord (~20b valuation) only exists because Skype did zero updates or innovation for years.</p>
]]></description><pubDate>Thu, 02 Nov 2023 21:15:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=38120259</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=38120259</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38120259</guid></item><item><title><![CDATA[New comment by ds in "Mint is shutting down, and it's pushing users toward Credit Karma"]]></title><description><![CDATA[
<p>How much they paid for Mint vs CK has little bearing. Google bought youtube for 1.6b and Motorola for 12b (later sold for 3b) - Which would you rather focus on today?<p>I dont disagree Mints revenue is not enough currently, but thats the issue. Mint has 3.6 million MAU. Maybe I need to be more explicit, but the value of a financial services user is high, not just in immediate revenue but also in referred revenue. Mint has never done a good job at pricing their product. Ive used it for 15 years and have never paid them a dollar. Thats a failure on their part, as I would have gladly paid monthly or yearly for the past 15 years. Even if I didnt, there were tons of products I would have IAP'd for that could have been seamlessly integrated into mint. Instead they seem entirely focused on trying to get me to sign up for credit cards or to switch bank accounts. What a lost opportunity.<p>As for the how much it costs to operate mint, thats true we dont know exactly what it is. But I am not a ostrich with my head in the sand. I can infer that the cost is going to be magnitudes less than the revenue it brings in, even in its current sad state. This isnt a chatgpt startup thats using insane resources on metal or developers to offer a product. Its a application suite that processes and coorelates data provided by plaid.com - Mint doesnt even do any of the heavy lifting anymore.</p>
]]></description><pubDate>Thu, 02 Nov 2023 16:35:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=38116122</link><dc:creator>ds</dc:creator><comments>https://news.ycombinator.com/item?id=38116122</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38116122</guid></item></channel></rss>