<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: sloshnmosh</title><link>https://news.ycombinator.com/user?id=sloshnmosh</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 06 Apr 2026 06:05:40 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=sloshnmosh" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by sloshnmosh in "A Guide to Push Notifications for Developers"]]></title><description><![CDATA[
<p>Just say No to push notifications!<p>There is a huge problem with spammy push notifications that trick users into accepting push notifications by using fake media players and fake CAPTHAs that if accepted will push all manner of SPAM on victims devices that say they have multiple viruses that pull up Google play store app to some bogus Cleaner/antivirus apps.<p>The push notifications are hosted on Cloudfront using AdMaven and AdFly and AppNexxus.<p>I have been trying to report these criminals for a couple of years now with no luck.<p>Cloudfront refuses to take down the script that AdMaven uses and AdMaven, AdFly, AppNexxus and Proppelerads all ignore multiple attempts to contact.</p>
]]></description><pubDate>Thu, 26 May 2022 14:12:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=31518548</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=31518548</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31518548</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Launch HN: Helio Sleep (YC S21) – One-stop portal for sleep apnea"]]></title><description><![CDATA[
<p>Have you gone to the VA?<p>I know our local Vetrans hospital has a small sleep study room for diagnosis and will supply CPAP to those in need.</p>
]]></description><pubDate>Tue, 22 Mar 2022 18:36:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=30769751</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=30769751</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30769751</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Walgreens replaced some fridge doors with screens, and some shoppers hate it"]]></title><description><![CDATA[
<p>Walgreens has always tried to harvest every single penny they could squeeze from their customers, mainly by selling the customers PII to anyone and everyone, so this is no big surprise to me.<p>It reminds me of the obnoxious talking gas pumps that play ads while you’re filling your car.<p>At first there used to be a “mute” button to where you could silence the crap and all the plastic was worn away from everyone mashing it trying to shut it up.<p>Now I no longer see any option to mute the ads.<p>I hate ads with a passion and won’t allow them to run on my devices. 
Mainly for security and privacy but the aggravation they cause is palpable.<p>Whenever I work on someone else’s computer and open a web browser I am in shock that people can even concentrate with all the garbage on the screen.</p>
]]></description><pubDate>Sun, 13 Mar 2022 01:45:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=30657053</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=30657053</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30657053</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Newer TP-Link Routers send large volumes of requests to Avira servers"]]></title><description><![CDATA[
<p>I heard that ads were able to circumvent DNS by using canonical names.<p>But uBlock origin and PiHole both do CNAME inspection to block this.<p>Is there other ways that ads are circumventing DNS ad-blockers such as PiHole?</p>
]]></description><pubDate>Sat, 12 Mar 2022 14:47:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=30651719</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=30651719</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30651719</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Newer TP-Link Routers send large volumes of requests to Avira servers"]]></title><description><![CDATA[
<p>I came here to say the same. 
I even purchased a LAN throwing star to look to see if my Asus router was sending anything to TrendMicro but never did get around to it.<p>But I will now for sure.</p>
]]></description><pubDate>Sat, 12 Mar 2022 13:44:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=30651279</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=30651279</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30651279</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Malicious app on Google Play drops banking malware on users’ devices"]]></title><description><![CDATA[
<p>Google is complicit in this by their refusal to ban larger app developers that create malicious apps. 
Google may kick the malicious app off the play store for a couple weeks and make the developer remove the malware (or obfuscate it better) but then allows the app(s) back to the play store.</p>
]]></description><pubDate>Sat, 29 Jan 2022 17:10:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=30128040</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=30128040</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30128040</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Web Push Notifications in WebKit"]]></title><description><![CDATA[
<p>The software being used to push this malware is from Propeller ads and more recently AdMaven but is protected by Russian DDoS services.</p>
]]></description><pubDate>Wed, 08 Dec 2021 20:43:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=29490224</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=29490224</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29490224</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Web Push Notifications in WebKit"]]></title><description><![CDATA[
<p>Be VERY careful on accepting push notifications!<p>There is a huge malvertising campaign targeting mobile users (especially Android) that tricks users into accepting push notifications with fake CAPTCHAs or fake media player buttons that push malicious ads and mobile malware and can even lead to botnet activity.<p>The risk versus value is too high.</p>
]]></description><pubDate>Wed, 08 Dec 2021 20:40:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=29490196</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=29490196</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29490196</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Xfinity outage leaves tens of thousands in the Bay Area without internet"]]></title><description><![CDATA[
<p>Hmmm. 
My tinfoil hat tells me that Comcast may be doing this to tie users Twitter accounts to their real names and addresses.</p>
]]></description><pubDate>Tue, 09 Nov 2021 17:40:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=29164716</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=29164716</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29164716</guid></item><item><title><![CDATA[New comment by sloshnmosh in "SSH Tunneling Explained"]]></title><description><![CDATA[
<p>Excellent article!<p>What’s also very interesting is that the article links to page from TrendMicro about malicious Android apps using Java’s version of SSH to infiltrate internal corporate networks.<p>TrendMicro’s own Android app ALSO contained the same Java SSH sdk.</p>
]]></description><pubDate>Sun, 10 Oct 2021 11:18:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=28817539</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=28817539</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28817539</guid></item><item><title><![CDATA[New comment by sloshnmosh in "How much information can a small image contain?"]]></title><description><![CDATA[
<p>I was hoping this was an article about packing different executables into images like I saw on Twitter.</p>
]]></description><pubDate>Mon, 04 Oct 2021 04:36:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=28743127</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=28743127</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28743127</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Facebook thrives on criticism of “disinformation”"]]></title><description><![CDATA[
<p>+1 for the zerohedge comment.<p>A few months ago something happened over at Zerohedge..
The site became unviewable with JavaScript disabled so I stopped going to the site. 
But it looks like they’ve had a change of heart and can now be viewed with JavaScript disabled.<p>But it also seems like the content has changed from what it used to be.<p>Did they change ownership or is it just my imagination from taking a break from their site when it became dependent upon JavaScript?</p>
]]></description><pubDate>Fri, 01 Oct 2021 04:21:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=28714503</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=28714503</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28714503</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Lithuania says throw away Chinese phones due to censorship concerns"]]></title><description><![CDATA[
<p>Fun fact..<p>The first 4 smartphones I  ever owned all came with preinstalled malware or malware was added after a “security update”</p>
]]></description><pubDate>Thu, 23 Sep 2021 00:44:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=28623950</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=28623950</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28623950</guid></item><item><title><![CDATA[New comment by sloshnmosh in "PalmOS on Raspberry Pi"]]></title><description><![CDATA[
<p>One of the people I follow on Twitter collects old electronics and I’ve seen him do some pretty interesting hacks to boot his vintage devices without using the long-dead original battery. 
I’ve seen him use 2 different rechargeable battery packs used for development boards attached to the battery terminals of an older laptop and even seen him using a screwdriver tip with leads attached to fit inside the female power port of an older device.<p>I don’t know his exact Twitter handle but you can find him under “foone”</p>
]]></description><pubDate>Sat, 11 Sep 2021 10:14:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=28490758</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=28490758</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28490758</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Apple’s Mistake"]]></title><description><![CDATA[
<p>As the recent NSO/Pegasus scandal has proved, there is no need to add backdoors into our cellphones.<p>If someone is suspected of a crime a warrant can be issued by a judge and the suspects phone compromised under lawful control of law enforcement.<p>What Apple is wanting to do is pre-crime where everyone is considered suspect until proven otherwise.</p>
]]></description><pubDate>Mon, 09 Aug 2021 17:49:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=28119939</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=28119939</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28119939</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Pitfalls of Data Anonymization"]]></title><description><![CDATA[
<p>Avast should be avoided completely. 
They have truly lost their way and have become more of a privacy/security risk than anything.<p>Did you know that Avast has a “confidential collaborator” known as Psafe that has an antivirus/cleaner app on Google Play called DFNDR that has been tricking users into installing their bogus app through scareware popunder fake virus warnings for over 8 years straight.<p>The DFNDR app was funded by the Chinese Qihoo and early versions of the app used to harvest users social media data and send data to Chinese servers. 
DFNDR also was not forthcoming with AV-test about it’s antivirus detectction engine.<p>It uses Avast’s detection engine and when AV-test found out the DFNDR app was no longer included in its testing.<p>The app itself is filled with trackers and several advertising SDK’s which take over the users device.<p>I have communicated with Psafe in private emails to show them the source of the fake virus warnings so that they could be stopped. 
Psafe requested I not go public with my findings for 30 days which I granted.<p>The fake virus warnings never stopped, not even on the sites I gave Psafe as examples.<p>Avast for it’s part banned me for life from their forums without warning.<p>Look at the user reviews of the DFNDR app on the Play Store to see for yourself.<p>Avast is nothing bat data harvesting ad agency at this point.</p>
]]></description><pubDate>Wed, 04 Aug 2021 17:00:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=28063434</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=28063434</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28063434</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Implement window.{alert, prompt, confirm} removal from cross-origin iframes"]]></title><description><![CDATA[
<p>I’ve been tracking a massive mobile malvertising and drive-by malware download operatition for the last several months.<p>The malvertising company is abusing a script found on GitHub called: “alerty”
hXXps://github.com/undead2/alerty#readme</p>
]]></description><pubDate>Wed, 04 Aug 2021 01:14:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=28056199</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=28056199</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28056199</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Facebook Wanted NSO Spyware to Monitor Users, NSO CEO Claims (2020)"]]></title><description><![CDATA[
<p>Are you sure about that?
Facebook has been caught several times doing shady surveillance type stuff on its users. 
The VPN app that is mentioned in the thread is one. 
There was another incident years ago when Facebook users were forced to download antivirus software from their “trusted partners” and scan their PC’s before they were allowed to login to their FB accounts.
People that had been flagged for scanning tested some theories and found that it had nothing to do with the users computer as their partner that shared the same device could login to their FB account on the same machine without having to run an AV scan.<p>There’s not a lot of information out there about that incident.</p>
]]></description><pubDate>Fri, 30 Jul 2021 10:33:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=28006493</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=28006493</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28006493</guid></item><item><title><![CDATA[New comment by sloshnmosh in "NYC mental health response teams show better results than police"]]></title><description><![CDATA[
<p>We have a Crisis Response Team in my city and it has been blessing.<p>I believe they are actually part of the fire department or under their leadership but I could be wrong.<p>The most important thing about the crisis response team is time and patience.<p>The team is trained in descalation and are able to spend hours with a person in crisis.<p>They will sit and listen to the person, give them rides if need be and also make contact with people even if they aren’t in crisis to build trust and reliability.<p>Most of the time that’s all that someone really needs is just someone that will take the time to really listen.<p>I will also add that there is a definite need for a police presence in my city as well.</p>
]]></description><pubDate>Sat, 24 Jul 2021 05:51:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=27938798</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=27938798</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27938798</guid></item><item><title><![CDATA[New comment by sloshnmosh in "Amazon Shuts Down NSO Group Infrastructure"]]></title><description><![CDATA[
<p>I contacted Amazon to report an advertiser out of Tel Aviv that was using JavaScript hosted on CloudFront to fingerprint user's devices and if an Android device was detected a fake media player or fake CAPTCHA would trick user's into accepting push notifications for fake virus warnings to install questionable apps from the Play Store.<p>This script also pushed ads for a fake AdBlock app that was a dropper for banking trojan apps.<p>Amazon refused to do anything about it.<p>More info:<p><a href="https://forum.xda-developers.com/t/massive-mobile-advertising-fraud-campaign-fake-virus-warnings-free-iphone-scams-surveys.4242181/" rel="nofollow">https://forum.xda-developers.com/t/massive-mobile-advertisin...</a></p>
]]></description><pubDate>Mon, 19 Jul 2021 14:40:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=27883146</link><dc:creator>sloshnmosh</dc:creator><comments>https://news.ycombinator.com/item?id=27883146</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27883146</guid></item></channel></rss>