<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: upofadown</title><link>https://news.ycombinator.com/user?id=upofadown</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 14 Aug 2026 01:10:48 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=upofadown" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by upofadown in "Bluesky's active user base is shrinking as its focus expands beyond the app"]]></title><description><![CDATA[
<p>Wait, Mastodon has 10 million users and 8000 servers? That's way more than I would of guessed. So Mastodon is a real thing in the world now.<p>Twitter has something like a half a billion users. So it wins I guess...</p>
]]></description><pubDate>Wed, 12 Aug 2026 15:55:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=49274418</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=49274418</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49274418</guid></item><item><title><![CDATA[(ADVANCED) Guide to not fucking up QR codes]]></title><description><![CDATA[
<p>Article URL: <a href="https://infosec.exchange/@rebane2001/117078420917152774">https://infosec.exchange/@rebane2001/117078420917152774</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49270632">https://news.ycombinator.com/item?id=49270632</a></p>
<p>Points: 16</p>
<p># Comments: 5</p>
]]></description><pubDate>Wed, 12 Aug 2026 11:15:19 +0000</pubDate><link>https://infosec.exchange/@rebane2001/117078420917152774</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=49270632</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49270632</guid></item><item><title><![CDATA[Cellebrite zero-day exploit used to target phone of Serbian student activist]]></title><description><![CDATA[
<p>Article URL: <a href="https://securitylab.amnesty.org/latest/2025/02/cellebrite-zero-day-exploit-used-to-target-phone-of-serbian-student-activist/">https://securitylab.amnesty.org/latest/2025/02/cellebrite-zero-day-exploit-used-to-target-phone-of-serbian-student-activist/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49270498">https://news.ycombinator.com/item?id=49270498</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 12 Aug 2026 11:01:38 +0000</pubDate><link>https://securitylab.amnesty.org/latest/2025/02/cellebrite-zero-day-exploit-used-to-target-phone-of-serbian-student-activist/</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=49270498</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49270498</guid></item><item><title><![CDATA[New comment by upofadown in "CSS: The bomb inside your inbox"]]></title><description><![CDATA[
<p>It was never allowed. Microsoft just started doing it in their email client and obnoxiously made it default. There was no standards process where anyone spent time considering the potential downsides with the aim of making HTML email practical and secure.<p>HTML email is just something that people semi-randomly do. It should be rejected/ignored if you are at all concerned about privacy and/or security.</p>
]]></description><pubDate>Sun, 09 Aug 2026 14:18:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=49231663</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=49231663</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49231663</guid></item><item><title><![CDATA[New comment by upofadown in "Decimen Optical Transfer: fountain-coded QR file transfer"]]></title><description><![CDATA[
<p>>Neither mode is encrypted: whatever is on the sending screen is readable by any camera pointed at it.<p>Something like this would be good for transferring the public key(s) associated with some cryptographic messaging identity. This would allow that to happen entirely offline. The optical nature of the transfer would prevent a potential MITM. The idea that an identity is being transferred would be fairly easy to impart to the user.<p>So the lack of encryption would be a feature and not a bug. This would enable later encryption which could then use any medium for the transfer in a completely secure way.</p>
]]></description><pubDate>Thu, 06 Aug 2026 15:47:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49198270</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=49198270</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49198270</guid></item><item><title><![CDATA[New comment by upofadown in "Civilian plane crash in New Mexico tied to military GPS blocking"]]></title><description><![CDATA[
<p>GPS is direct sequence spread spectrum. You might be thinking of frequency hopping, jamming that is harder, but you are only working against super weak signals from satellites. It would still be quite possible.</p>
]]></description><pubDate>Wed, 05 Aug 2026 15:37:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=49184400</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=49184400</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49184400</guid></item><item><title><![CDATA[New comment by upofadown in "Civilian plane crash in New Mexico tied to military GPS blocking"]]></title><description><![CDATA[
<p>A rehash of the paywalled Wired article:<p>* <a href="https://futurism.com/science-energy/us-military-gps-jamming-signal-medical-flight" rel="nofollow">https://futurism.com/science-energy/us-military-gps-jamming-...</a></p>
]]></description><pubDate>Wed, 05 Aug 2026 11:26:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49181300</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=49181300</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49181300</guid></item><item><title><![CDATA[New comment by upofadown in "GrapheneOS protections against data extraction from locked devices"]]></title><description><![CDATA[
<p>The point of the comic is pretty obviously to make fun of the expectations of cryptography geeks; you know, the sort of people who use 4096 bit RSA keys for the coolness factor. It is a stretch to imply it is suggesting that encryption is somehow futile.</p>
]]></description><pubDate>Sun, 26 Jul 2026 13:28:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=49058015</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=49058015</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49058015</guid></item><item><title><![CDATA[New comment by upofadown in "Government orders GitHub to remove Bluetooth-based chat app Bitchat: Jack Dorsey"]]></title><description><![CDATA[
<p>To avoid a potential misunderstanding, the maintenance mode is intended to continue indefinitely. Briar project is not shutting down.<p>* <a href="https://briarproject.org/news/2026-maintenance-mode/" rel="nofollow">https://briarproject.org/news/2026-maintenance-mode/</a></p>
]]></description><pubDate>Sat, 25 Jul 2026 11:05:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=49046529</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=49046529</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49046529</guid></item><item><title><![CDATA[New comment by upofadown in "Aluminum foil (2021)"]]></title><description><![CDATA[
<p>>...and conductive, rivaling copper.<p>That isn't true for either thermal or electrical conductivity. So I don't know what is meant here.</p>
]]></description><pubDate>Mon, 06 Jul 2026 18:01:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48808223</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=48808223</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48808223</guid></item><item><title><![CDATA[New comment by upofadown in "Web-based cryptography is always snake oil"]]></title><description><![CDATA[
<p>But claiming that your system is end to end encrypted means that you are claiming protection from you and your system. This is mainly a truth in advertising issue.</p>
]]></description><pubDate>Sun, 05 Jul 2026 11:26:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48793275</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=48793275</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48793275</guid></item><item><title><![CDATA[New comment by upofadown in "Web-based cryptography is always snake oil"]]></title><description><![CDATA[
<p>>...pretty much any E2E system is falling under this definition.<p>The definition is quite clear. It does not apply when the implementation is not distributed by the same entity that creates it for example. There are other related issues but the message here is that web based cryptography has a particular weakness when it comes to things like end to end encrypted messaging which makes it so bad as to be worthless.</p>
]]></description><pubDate>Sun, 05 Jul 2026 11:22:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=48793255</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=48793255</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48793255</guid></item><item><title><![CDATA[New comment by upofadown in "Web-based cryptography is always snake oil"]]></title><description><![CDATA[
<p>If, say, Signal <i>was</i> completely controlled by the CIA[1] and was thus evil, then having incoherent cryptography as described in the article would be a feature, not a bug. Being able to reject law enforcement requests would produce a false sense of security for the people the CIA was interested in surveilling. Responding effectively to law enforcement requests would reduce the value to the CIA of the ability to secretly backdoor Signal.<p>This effect was seen in the Apple vs FBI incident described in the article. The public perception of Apple as a brave defender of user privacy was greatly increased due to that dispute. For all we know, the FBI was in on the conspiracy. In return they might receive the fruits of such surveillance with the only limitation that they would have to disguise the source with parallel construction[2].<p>[1] <a href="https://en.wikipedia.org/wiki/Crypto_AG" rel="nofollow">https://en.wikipedia.org/wiki/Crypto_AG</a><p>[2] <a href="https://en.wikipedia.org/wiki/Parallel_construction" rel="nofollow">https://en.wikipedia.org/wiki/Parallel_construction</a></p>
]]></description><pubDate>Sun, 05 Jul 2026 11:17:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48793225</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=48793225</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48793225</guid></item><item><title><![CDATA[New comment by upofadown in "Web-based cryptography is always snake oil"]]></title><description><![CDATA[
<p>How about GPG distributed with a Linux distribution like Debian as a counterexample? It would be fairly difficult to backdoor GPG in that case without getting caught. Everything happens in the open both at the GPG level and the Linux distribution level. The binaries are signed by the distribution and are distributed by a bunch of mirrors. An evil Debian maintainer would have to make a change that was well enough disguised as something else to evade scrutiny.</p>
]]></description><pubDate>Sun, 05 Jul 2026 10:56:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48793101</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=48793101</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48793101</guid></item><item><title><![CDATA[New comment by upofadown in "“Beyond the limit”: Satellites and mirrors in space pose threat to the night sky"]]></title><description><![CDATA[
<p>>SpaceX plans to send one million more satellites into orbit, for space-based data centres, ...<p>I think we should wait to see how the first satellite data centre works out. It seems fairly unlikely that it could be practical. It seems kind of nuts...<p>>Reflect Orbital, a US start-up, aims to launch a constellation of very large mirror-like satellites to provide sunlight at night, with reflected beams that span at least five kilometres on Earth's surface.<p>Straight up nuts with no practical value, even if it did work out.</p>
]]></description><pubDate>Sat, 04 Jul 2026 19:02:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48787930</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=48787930</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48787930</guid></item><item><title><![CDATA[New comment by upofadown in "FFmpeg 9.1's new AAC encoder"]]></title><description><![CDATA[
<p>The linked article makes the argument that looking at the BSD licensed example code in the RFC that defines Opus would mean that code written based on that understanding would be a derivative work and would have to be BSD licensed. This seems to have something to do with the fact that "clean-room design"[1] is a thing. But as the Wikipedia article points out:<p>>Clean-room design is usually employed as best practice, but not strictly required by law.<p>As the article points out, if this was actually true then we could change the licensing on code examples found in RFCs to fix the issue, but there doesn't seem to be any actual issue here. Imagine a world where simply reading some code   caused licensing issues...<p>[1] <a href="https://en.wikipedia.org/wiki/Clean-room_design" rel="nofollow">https://en.wikipedia.org/wiki/Clean-room_design</a></p>
]]></description><pubDate>Thu, 02 Jul 2026 15:58:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=48763463</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=48763463</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48763463</guid></item><item><title><![CDATA[New comment by upofadown in "The Future of Email"]]></title><description><![CDATA[
<p>A signature is not authentication in itself. It is only such if the signing entity is in some way restricting what it is willing to sign. The domain part of the email address in the "From" field is so restricted. The signing MTA will only sign domains that it controls. Otherwise it would suffer a loss of reputation. The user part of the address is not so restricted.<p>The name part of the email address is also part of the same signature but is not being authenticated either.</p>
]]></description><pubDate>Sat, 13 Jun 2026 11:25:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48516132</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=48516132</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48516132</guid></item><item><title><![CDATA[New comment by upofadown in "The Future of Email"]]></title><description><![CDATA[
<p>The article makes a reference to the failed ARC (Authenticated Received Chain) proposal which was intended to help DKIM not break email forwarding:<p><a href="https://www.ietf.org/archive/id/draft-adams-arc-experiment-conclusion-00.html" rel="nofollow">https://www.ietf.org/archive/id/draft-adams-arc-experiment-c...</a><p>It will be interesting to see if Google can be convinced to move away from ARC to something else. Gmail is all about email server reputation these days so they can reliably treat email servers they don't like badly.</p>
]]></description><pubDate>Fri, 12 Jun 2026 11:41:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48502847</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=48502847</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48502847</guid></item><item><title><![CDATA[New comment by upofadown in "The Future of Email"]]></title><description><![CDATA[
<p>>Anyone can put anything in the “From” field of an email.<p>... and then the article goes on to talk about SPF, DKIM and DMARC which authenticates only the domain part of the "From" field. So just the reputation of the email server, not the entity that sent you the email. If things get as bad with AI generated deception as suggested by the article this wouldn't be good enough, we would have to start signing our emails again. Emails from entities we don't know would have to be treated with a high level of suspicion.<p>I am not convinced that things will for sure really get that bad. How can a AI figure out the email addresses of our correspondents? They are not magic.</p>
]]></description><pubDate>Fri, 12 Jun 2026 11:33:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48502780</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=48502780</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48502780</guid></item><item><title><![CDATA[New comment by upofadown in "A Post-Quantum Future for Let's Encrypt"]]></title><description><![CDATA[
<p>If you specifically mean something that can embody Shor's algorithm, it is fairly clear these days that a fundamental breakthrough is required. So the timeline extends from tomorrow to never.</p>
]]></description><pubDate>Thu, 04 Jun 2026 10:52:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48396817</link><dc:creator>upofadown</dc:creator><comments>https://news.ycombinator.com/item?id=48396817</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48396817</guid></item></channel></rss>