<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ev1</title><link>https://news.ycombinator.com/user?id=ev1</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 15 Jun 2026 14:18:18 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ev1" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ev1 in "New two-factor authenticator: Commodore 64"]]></title><description><![CDATA[
<p>So far I haven't seen a single major company doing phone based (insecure) 2fa not use the number for marketing, data abuse, etc.<p>Non-standards based "authenticator" dedicated apps phone home and spy on you. Intentionally trying to break or block actual TOTP.</p>
]]></description><pubDate>Sat, 26 Nov 2022 01:35:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=33748955</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33748955</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33748955</guid></item><item><title><![CDATA[New comment by ev1 in "“Invalid Username or Password”: a useless security measure (2014)"]]></title><description><![CDATA[
<p>> Side note: the McDonald's app is nice in not requiring (or apparently even allowing) passwords to log in. However, there's a problem with its state transition, where the user needs to exit from the dialog that sends the sign-in link before they go to their email and click on the sign-in link, otherwise the user gets dumped to the next step without having actually signed in.<p>The mcdonalds app loads several dozen data collection sdks, pihole practically had a meltdown when it launched</p>
]]></description><pubDate>Wed, 23 Nov 2022 18:40:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=33722972</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33722972</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33722972</guid></item><item><title><![CDATA[New comment by ev1 in "Barclays using TeamViewer font to warn customers"]]></title><description><![CDATA[
<p>I have encountered numerous sites that port scan localhost via websocket/img onerror/etc.</p>
]]></description><pubDate>Tue, 22 Nov 2022 21:13:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=33711600</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33711600</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33711600</guid></item><item><title><![CDATA[New comment by ev1 in "Ask HN: Maximize Uber/Lyft Driver Profits"]]></title><description><![CDATA[
<p>The answer is generally "move" unfortunately. Surge pricing for things like club  and concert nights runs orders of magnitude higher than normal rides for the same wear and tear. These don't really happen in small towns, and in larger places it's multiple times a night nearly every night.</p>
]]></description><pubDate>Tue, 22 Nov 2022 21:10:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=33711574</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33711574</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33711574</guid></item><item><title><![CDATA[New comment by ev1 in "Why Twitter didn’t go down: From a real Twitter SRE"]]></title><description><![CDATA[
<p>> children with his executives,<p>Why do people do this? I mean in any industry. Just why? Is there something I don't understand about executives or C-levels or something?</p>
]]></description><pubDate>Tue, 22 Nov 2022 18:44:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=33709371</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33709371</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33709371</guid></item><item><title><![CDATA[New comment by ev1 in "CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows"]]></title><description><![CDATA[
<p>The biggest shock to me here is "aarch64 Windows doesn't have calc.exe"</p>
]]></description><pubDate>Mon, 21 Nov 2022 20:10:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=33697286</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33697286</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33697286</guid></item><item><title><![CDATA[New comment by ev1 in "How does Windows decide whether your computer has full Internet access?"]]></title><description><![CDATA[
<p>No, your browser converts it before access</p>
]]></description><pubDate>Sat, 19 Nov 2022 08:13:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=33668168</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33668168</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33668168</guid></item><item><title><![CDATA[New comment by ev1 in "Infosys leaked FullAdminAccess AWS keys on PyPI for over a year"]]></title><description><![CDATA[
<p>> Infosys will ban all OSS contributions from their developers.<p>Sounds... good to me?</p>
]]></description><pubDate>Thu, 17 Nov 2022 05:22:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=33635300</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33635300</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33635300</guid></item><item><title><![CDATA[New comment by ev1 in "Europe faces ‘cancer epidemic’ 1M cases missed during Covid Lockdowns"]]></title><description><![CDATA[
<p>To be entirely neutral on this reply, it's not part of the title on the linked article and against  guidelines to add it like that.</p>
]]></description><pubDate>Wed, 16 Nov 2022 18:23:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=33627947</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33627947</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33627947</guid></item><item><title><![CDATA[New comment by ev1 in "“When we all have pocket telephones”"]]></title><description><![CDATA[
<p>I have not installed the TM app - you can add a ticket to Apple Wallet from the website, and every order I've seen has "don't have a phone? go to the box office for tickets when you arrive" somewhere</p>
]]></description><pubDate>Tue, 15 Nov 2022 22:10:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=33615774</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33615774</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33615774</guid></item><item><title><![CDATA[New comment by ev1 in "Amazon Clinic"]]></title><description><![CDATA[
<p>Why are the 5 star reviews all for a nonstick frying pan?</p>
]]></description><pubDate>Tue, 15 Nov 2022 19:44:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=33613998</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33613998</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33613998</guid></item><item><title><![CDATA[New comment by ev1 in "Elon Musk doesn't understand GraphQL & blames 1000s of poorly-batched RPCs"]]></title><description><![CDATA[
<p>I see entire massive threads requested and responded in a single compressed call to /api/graphql/xxx/TweetDetail<p>Loading an entire next page is also a single call to the same endpoint. There is nowhere remotely that I see the mobile client even making a hundred gql calls for tweets.<p>Is there something I'm missing or is he misusing "app" when he means backend service to service GQL calls?</p>
]]></description><pubDate>Sun, 13 Nov 2022 22:42:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=33588139</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33588139</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33588139</guid></item><item><title><![CDATA[New comment by ev1 in "Tell HN: GitHub banned me permanently"]]></title><description><![CDATA[
<p>Reddit fingerprints you very aggressively. Cookies are not used here. Every single pageload, they scan all your fonts, plugins, etc.<p>They also exfiltrate this data back in ways to prevent blocking, by completely randomizing the API endpoint used to submit it and also not use a dedicated endpoint. For example on each pageload it might send to /submit, or /register, or /friend, it'll just pick a random valid endpoint and "front" that<p>They also continue to do this while you are logged out to tie your IP to the fingerprint.<p><pre><code>    hxxps://www.redditstatic.com/reddit-init.en.4-tSxFR4sOk.js


</code></pre>
^F "Arial"<p>Commonly spoofed fingerprints will result in a permanent ban automatically.</p>
]]></description><pubDate>Sun, 13 Nov 2022 08:10:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=33581054</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33581054</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33581054</guid></item><item><title><![CDATA[New comment by ev1 in "The Lie That Facebook Sold You"]]></title><description><![CDATA[
<p>Amusingly, some of my friends that use it for Marketplace express a desire for Craigslist to be popular again, if not only for the absolutely insane people on Marketplace that demand to pay $20 for an item listed at $300 and then start spamming you and making public posts about how you're a thief and scammer for trying to rip off a single parent who just wanted to get their kid a present for $20, linking your profile the entire time.</p>
]]></description><pubDate>Tue, 08 Nov 2022 18:27:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=33522428</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33522428</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33522428</guid></item><item><title><![CDATA[New comment by ev1 in "The most unethical thing I was asked to build while working at Twitter in 2015"]]></title><description><![CDATA[
<p>CFA app loads a bunch of rather fucked up surveillance SDKs under the guise of anti coupon fraud or something. Probably related to that.</p>
]]></description><pubDate>Mon, 07 Nov 2022 23:23:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=33513976</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33513976</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33513976</guid></item><item><title><![CDATA[New comment by ev1 in "Ask HN: Ideas to have fun poisoning data collection by trackers/data brokers?"]]></title><description><![CDATA[
<p>Yeah all of these listed still require an equivalent to SSN.</p>
]]></description><pubDate>Fri, 04 Nov 2022 03:40:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=33461846</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33461846</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33461846</guid></item><item><title><![CDATA[New comment by ev1 in "Ask HN: Ideas to have fun poisoning data collection by trackers/data brokers?"]]></title><description><![CDATA[
<p>Reloadables require SSN verification, afaik.</p>
]]></description><pubDate>Thu, 03 Nov 2022 20:31:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=33457080</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33457080</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33457080</guid></item><item><title><![CDATA[New comment by ev1 in "Ask HN: Have you noticed any side-effects from 100% work-from-home?"]]></title><description><![CDATA[
<p>> It makes the days going back to the office feel more refreshing, like I have more oxygen<p>For some reason, every time I'm in a conference room I inevitably pass out. Even if I'm not tired and perfectly energetic on the way in, I can count on one hand the number of times I haven't just mentally gone while in one. Wonder why.</p>
]]></description><pubDate>Wed, 02 Nov 2022 18:54:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=33441108</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33441108</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33441108</guid></item><item><title><![CDATA[New comment by ev1 in "Ask HN: Why are ringtones not interesting anymore?"]]></title><description><![CDATA[
<p>For younger group, you don't generally know or give out your number in the first place for person to person communication, which means that for the rare chances you are expecting, say, a medical call once a quarter or less, it's a scam. I don't know my best friend of 10+ years phone number but I can reach them in multiple ways.<p>If you're older the ratio probably tips it further into the "likely to be a valid call" I'm guessing.<p>I receive something on the order of one legitimate call every 5-8 months, everything else is spam/scam. There is absolutely no point in me accepting a  call.<p>A formal phone call is generally synchronous, not asynchronous. It is extremely blocking behaviour and I hate it.  Joining a group call with a few friends or even just 1-2 other people on discord or whatever else that you can drop out at any time without notice is a different type of "mood" and completely different set of standards. You can drop in and out in seconds, pop in to say hi and leave while you have your airpods in on while riding bart, , or spend hours just discussing dumb shit, etc.</p>
]]></description><pubDate>Tue, 01 Nov 2022 22:38:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=33428657</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33428657</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33428657</guid></item><item><title><![CDATA[New comment by ev1 in "Ask HN: Why are ringtones not interesting anymore?"]]></title><description><![CDATA[
<p>I don't know how well this generalises, but in my sample size most people including myself don't even know our own phone number if asked. You don't exchange phone numbers. You might hold out your phone for the other person to scan your Snapchat QR or tell them @hn2022 and a platform like instagram. If you say hn#2022 people know automatically which platform that is. A sizable amount don't even have phone numbers and opt for data plan only for cost savings if paying for their own plan.</p>
]]></description><pubDate>Tue, 01 Nov 2022 21:54:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=33428112</link><dc:creator>ev1</dc:creator><comments>https://news.ycombinator.com/item?id=33428112</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33428112</guid></item></channel></rss>