Readit News logoReadit News
gnyman commented on Tunnl.gg   tunnl.gg... · Posted by u/klipitkas
gnyman · 14 days ago
This is nice and for those who's asking, it's different from ngrok and the others in that you don't need a separate client, (almost) everyone has ssh installed.

To the author, I wish you best of luck with this but be aware (if you aren't) this will attract all kind of bad and malicious users who want nothing more than a "clean" IP to funnel their badness through.

serveo.net [2] tried it 8 years ago, but when I wanted to use it I at some point I found it was no longer working, as I remember the author said there was too much abuse for him to maintain it as a free service

I ended up self-hosting sish https://docs.ssi.sh instead.

Even the the ones where you have to register like cloudflare tunnels and ngrok are full of malware, which is not a risk to you as a user but means they are often blocked.

Also a little rant, tailscale has their own one also called funnel. It has the benefit of being end-to-end encrypted (in theory) but the downside that you are announcing your service to the world through the certificate transparency logs. So your little dev project will have bots hammering on it (and trying to take your .git folder) within seconds from you activating the funnel. So make sure your little project is ready for the internet with auth and has nothing sensitive at guessable paths.

[2] https://news.ycombinator.com/item?id=14842951

gnyman commented on Roc Camera   roc.camera/... · Posted by u/martialg
donaldihunter · 2 months ago
I don't think ZK proofs help to establish trust in a photo's authenticity at all. C2PA is a well thought out solution to this problem.

https://spec.c2pa.org/specifications/specifications/2.2/spec...

> The C2PA information comprises a series of statements that cover areas such as asset creation, edit actions, capture device details, bindings to content and many other subjects. These statements, called assertions, make up the provenance of a given asset and represent a series of trust signals that can be used by a human to improve their view of trustworthiness concerning the asset. Assertions are wrapped up with additional information into a digitally signed entity called a claim.

gnyman · 2 months ago
Neal Krawetz of fotoforensics (and others probably) disagree that C2PA "is a well thought out solution"

https://www.hackerfactor.com/blog/index.php?%2Farchives%2F10... (search his blog if you want more of his thoughts on it)

I don't have a know enough bout this but I've been reading his blog for other topics a while and he does seem to know a lot about photo authenticity.

gnyman commented on Ask HN: 10-Year Reddit Account Hacked Despite 2FA [updated]    · Posted by u/guilamu
guilamu · 2 months ago
Hello, thank you very much for your very insightful comment!

The cookie theft is also IMHO the most probable scenario. The malicious extension is the only thing that make sense to me.

log out all devices: done

rotate password and 2FA: done

switch to a hardware key/WebAuthn: not done yet

audit browser extensions: done (I'm using only what I think are very "secure" ones: Bypass Paywalls Clean, Control Panel for Twitter , Correcteur d'orthographe et reformulateur — LanguageTool , Google Images Restored, I still don't care about cookies, Keepa - Amazon Price Tracker, Reddit Enhancement Suite, SingleFile , uBlock Origin , Voir image (https://github.com/bijij/ViewImage)

scan the box: done

revoke any third‑party app access tied to Reddit: there are none

Anyhow, thank again!

gnyman · 2 months ago
Even if none of these extensions were malicious, they might have some vulnerability that would allow and attacker to get your cookie? Or the developers of those might have unknowingly been phished like what happened last December.

Sorry for just offering speculation, hopefully you figure it out. Even if it was "only" a Reddit account, the feeling of not knowing how it happened and if other things are at risk must be horrible.

https://crxplorer.com/ might help you to inspect your extensions a bit deeper if you are interested and have the knowledge.

And finally, just a comment, passkeys/webauthn/fido keys would not protect against a session cookie theft. They only prevent the login stage from being phished.

gnyman commented on Stripe Launches L1 Blockchain: Tempo   tempo.xyz... · Posted by u/_nvs
Illniyar · 3 months ago
I guess domains might not mean as much as they used to, but xyz? To me that's something you get for experiments and one-offs, not something you use for a serious enterprise you want to get people onboard for.

I honestly thought this was fake and not from stripe the first time I saw it. (I kinda still do with that domain.)

gnyman · 3 months ago
tld's mean nothing anymore, but they still signal something, and to me .xyz is not a trust-inspiring tld

According to this Krebs article https://krebsonsecurity.com/2024/12/why-phishers-love-new-tl... 13% of the xyz domains was related to phishing, not as bad as .top which ahd 30% but still bad.

gnyman commented on A deep dive into Debian 13 /tmp: What's new, and what to do if you don't like it   lowendbox.com/blog/a-deep... · Posted by u/shaunpud
buckle8017 · 4 months ago
Which is a great reason to have a big swap file now.
gnyman · 4 months ago
Note though that if you don't have swap now, and enable it, you introduce the risk of thrashing [1]

If you have swap already it doesn't matter, but I've encountered enough thrashing that I now disable swap on almost all servers I work with.

It's rare but when it happens the server usually becomes completely unresponsive, so you have to hard reset it. I'd rather that the application trying to use too much memory is killed by the oom manager and I can ssh in and fix that.

[1] https://docs.redhat.com/en/documentation/red_hat_enterprise_...

gnyman commented on Show HN: Sping – An HTTP/TCP latency tool that's easy on the eye   dseltzer.gitlab.io/sping/... · Posted by u/zorlack
gnyman · 4 months ago
Looks nice.

I would add a link to the gitlab to the page also, clicking the LICENCE brings me to the source code but other than that there did not seem to be a link .

Out of curiosity, did you use LLM's to code this? My gut feeling tells me at minimum the readme was written by one, or maybe it's normal to use emojis everywhere :-) Also I am not meaning to judge it as good or bad, I'm just curious.

I think one thing that LLM's and coding agents enables, is creating these customised solution which solve a specific problem, in a specific way. Some might consider it wasteful. I bet many thinks your effort would have been better spent contributing to one of the existing ones instead of doing yet another tool, but I find fascinating that we can finally tell our computers what we need and the will do it.

If you hand-wrote everything, then apologies for the unrelated rant :-)

gnyman commented on How Not to Buy a SSD   andrei.xyz/post/how-not-t... · Posted by u/speckx
gnyman · 4 months ago
Tom's had a good article on this problem recently.

https://www.tomshardware.com/pc-components/hdds/seagate-spin...

(the title is also ~p~fun)

gnyman commented on Is anybody using this private key?   isanybodyusingthisprivate... · Posted by u/black6
gnyman · 5 months ago
I'm confused by this one. It says it's a joke but it still submits the key to a server.

These joke pages have been around since http://ismycreditcardstolen.com/

And I even made my own version https://hasmypasswordbeenstolen.net/

The difference is that neither the original nor mine actually submits the secret to the server. I went to great lengths to avoid actually doing it, it's still a bad idea to send a password to my page but at least you can check the source and network traffic and see that it's only checked with JavaScript and a hash is checked against the HIPB password site.

This supposed joke site sends and processes the key on their backend. At least it looks like that, I have not tried with a real key.

gnyman commented on Microsoft opens a free tier for Windows 10 extended updates   theregister.com/2025/06/2... · Posted by u/LorenDB
gnyman · 6 months ago
In case you want or need security fixes for older windows machines, there is a company/product called https://0patch.com/ which provides "micropatches" all the way back to Windows 7 and Windows Server 2008 R2.

There is a free tier but it only includes some patches. They have prices listed on the website for the paid tiers.

I have no experience with using them, but just sharing in case it's useful those who doesn't want to or can't throw away their old systems.

gnyman commented on Show HN: CoPlay – Enabling In-Room Xbox Gaming for Children's Hospitals   coplay.io/introducing-cop... · Posted by u/bradyriddle
gnyman · 10 months ago
Fantastic. Thanks for making this.

I would immediately recommend this to our local hospital, but they have PlayStations (five or four don’t remember). Do you know of anything similar is possible for PS?

u/gnyman

KarmaCake day651September 1, 2011View Original