<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: erros</title><link>https://news.ycombinator.com/user?id=erros</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 15 Sep 2026 09:53:47 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=erros" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by erros in "Why is Google still serving dodgy ads?"]]></title><description><![CDATA[
<p>So true!</p>
]]></description><pubDate>Tue, 15 Sep 2026 00:35:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49706188</link><dc:creator>erros</dc:creator><comments>https://news.ycombinator.com/item?id=49706188</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49706188</guid></item><item><title><![CDATA[New comment by erros in "Why is Google still serving dodgy ads?"]]></title><description><![CDATA[
<p>Money. They make so much money from malvertisement that it doesn't make sense to remediate them. It's corporate greed and they've known about this since the 2010s, various campaigns have sprung up and have caused untold X amount of dollars in damages in breaches, and nothing changes. I've heard at least one FBI agent who had investigated cases related to malvertisement put Google up there with some of the worst ad networks.</p>
]]></description><pubDate>Sun, 13 Sep 2026 19:55:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49687999</link><dc:creator>erros</dc:creator><comments>https://news.ycombinator.com/item?id=49687999</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49687999</guid></item><item><title><![CDATA[New comment by erros in "Why and how we’re migrating many of our servers from Linux to the BSDs"]]></title><description><![CDATA[
<p>Ladies and gentlemen, this person solves problems. Let it be known.</p>
]]></description><pubDate>Fri, 04 Oct 2024 12:01:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=41740515</link><dc:creator>erros</dc:creator><comments>https://news.ycombinator.com/item?id=41740515</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41740515</guid></item><item><title><![CDATA[New comment by erros in "Server Setup Basics for Self Hosting"]]></title><description><![CDATA[
<p>You may want to update this post to disable password authentication, and thus you'll no longer need to install fail2ban. An important goal is to tighten your attack surface, not expand it. At this point you will still have an exposed SSHd server, so I'd recommend throwing the server under tailscale. You can setup the SSHd listener to use your tailscale IP or setup tailscale for SSH via ACLs (<a href="https://tailscale.com/tailscale-ssh" rel="nofollow">https://tailscale.com/tailscale-ssh</a>).<p>Additionally you can further tighten controls of incoming logins with the use of AllowGroups to tighten your controls on which groups can log into the system. This would mitigate a scenario where an adversary is able to escalate enough privileges to write an .authorized_keys file to a non-privileged user which may have a shell still configured.<p>Finally, unless you're treating this server as a bastion host of sorts, you probably should disable forwarding for agents or X11 etc. We've seen a lot of adversaries move laterally due to this agent forwarding.</p>
]]></description><pubDate>Mon, 26 Aug 2024 04:21:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=41353995</link><dc:creator>erros</dc:creator><comments>https://news.ycombinator.com/item?id=41353995</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41353995</guid></item><item><title><![CDATA[New comment by erros in "Kim Dotcom's extradition to the U.S. given green light by New Zealand"]]></title><description><![CDATA[
<p>I'm sure we all could appreciate Mega for what it was, and we could also debate the charges and go back and forth on extradition laws. The reality is that according to the DoJ, US citizens were victimized by a service that used US assets (servers) within its territory. That opens the doors for litigation. This happens literally in every country that can enforce it.<p>Like Reddit, HN has a crowd of anti-US folks with terrible sentiment until, you know, when they need the US or need a job in the U.S. The hypocrisy is astounding.</p>
]]></description><pubDate>Fri, 16 Aug 2024 15:59:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=41267536</link><dc:creator>erros</dc:creator><comments>https://news.ycombinator.com/item?id=41267536</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41267536</guid></item><item><title><![CDATA[New comment by erros in "GRC SpinRite"]]></title><description><![CDATA[
<p>It is my opinion. What else? I mean, what was the point of your response? You didn't even offer an opinion on the topic. You offered an observation and lazily concluded whatever-it-was with a rhetorical question?<p>Is that normal for people like you?</p>
]]></description><pubDate>Sun, 02 Jun 2024 14:42:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=40554572</link><dc:creator>erros</dc:creator><comments>https://news.ycombinator.com/item?id=40554572</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40554572</guid></item><item><title><![CDATA[New comment by erros in "Cracking encrypted LastPass vaults"]]></title><description><![CDATA[
<p>Used vast.ai for this setup: $5.875/hr. Using their API you can likely find better deals and launch a series of different setups and optimize your spending. Hope that helps.</p>
]]></description><pubDate>Sun, 25 Dec 2022 14:02:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=34127295</link><dc:creator>erros</dc:creator><comments>https://news.ycombinator.com/item?id=34127295</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34127295</guid></item><item><title><![CDATA[New comment by erros in "Cracking encrypted LastPass vaults"]]></title><description><![CDATA[
<p>Just out of curiosity I booted up a box with 10x RTX A6000 @ 451.6 TFLOPS<p><pre><code>    Speed.#1.........:    38789 H/s (11.17ms) @ Accel:128 Loops:64 Thr:64 Vec:1
    Speed.#2.........:    39017 H/s (11.17ms) @ Accel:128 Loops:64 Thr:64 Vec:1
    Speed.#3.........:    38894 H/s (11.16ms) @ Accel:128 Loops:64 Thr:64 Vec:1
    Speed.#4.........:    39254 H/s (11.02ms) @ Accel:128 Loops:64 Thr:64 Vec:1
    Speed.#5.........:    38626 H/s (11.17ms) @ Accel:128 Loops:64 Thr:64 Vec:1
    Speed.#6.........:    39448 H/s (10.94ms) @ Accel:128 Loops:64 Thr:64 Vec:1
    Speed.#7.........:    39256 H/s (11.06ms) @ Accel:128 Loops:64 Thr:64 Vec:1
    Speed.#8.........:    38966 H/s (11.14ms) @ Accel:128 Loops:64 Thr:64 Vec:1
    Speed.#9.........:    38870 H/s (11.17ms) @ Accel:128 Loops:64 Thr:64 Vec:1
    Speed.#10.........:    39259 H/s (11.01ms) @ Accel:128 Loops:64 Thr:64 Vec:1
    Speed.#\*.........:   390.0 kH/s
</code></pre>
Used the same example as the author with 100500 iterations. I think with some good wordlists, I'd wager a ton of low hanging fruits will be wiped within a reasonable time. If we're talking a threat actor with $$, they'd do some serious damage on this dump.<p>*edit: just wanted to clarify that I think bruteforcing this dump wouldn't be as useful. It would still take a crapload of resources to be effective or useful in that scenario.</p>
]]></description><pubDate>Sun, 25 Dec 2022 12:44:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=34126755</link><dc:creator>erros</dc:creator><comments>https://news.ycombinator.com/item?id=34126755</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34126755</guid></item></channel></rss>