Hacker Newsnew | past | comments | ask | show | jobs | submit | Habgdnv's commentslogin

Just a quick note for the unsuspecting: I run two local DNSes, one recursive and one forwarding. The forwarding one uses few services, like 1.1.1.1, 8.8.8.8, 9.9.9.9, etc. One day I noticed inconsistent responses and started investigating. Turns out that by default 9.9.9.9 have "protection" and for your safety will lie and return NXDOMAIN or something else, for some dangerous domains, taking into account their definition of "dangerous". I am not saying that this is bad, probably lots of non-HN people don't want to run their DNS or anything related and just want a tablet that works because they don't even have laptop. It just hit me hard because I did not expected filtering on these servers.

Instead of CloudFlare's 1.1.1.1 I like CloudFlare's 1.1.1.3: it filters known porn and known malware sites.

By now I expect many sites to be filtered out: too much crap out there.

Then I also run my own DNS (unbound) and after seeing a warning from one of my banks about a phishing site where one letter differed in the domain name from the real bank's site, I went ballistic: I did generate hundreds of thousands (maybe millions by now) of variations of the names of banks/brokers domains I use, with every single variation of one character and many variations of up to two characters and I nullroute those too (in addition to known porn and known malware sites).

And I nullroute every single Unicode domain name. I don't care. I don't care if you disagree with this: too many homoglyph attacks. Too risky. And the Web Just Works [TM] without accessing any Unicode domain.

I null route tens if not hundreds of TLDs.

Filtering out every single domain name using any Unicode char is a bit more involved but it's doable (I do it since years, but today you can ask LLMs if you want to do it or patch a DNS software to do it).

I know some go further and by default disallow everything and then only allow domains they want to use but I find that a bit too tricky.

Now... Should there be something I really want, say I want a shady torrent tracker to download some dubious file, I can always use a VM/container with a more lenient DNS.

I'm using such a setup since years. My unbound DNS runs on a Pi 3 that's on 24/7.

Works flawlessly.

P.S: on another subject I also blocklist entire IP blocks, including entire countries. Same thing: the Web still works totally fine.


I ended up getting rid of unbound, stubby, and a technitium instance and just moving to numa.rs everywhere i needed dns. It simplified my life a lot. Now laptops run it with forward*ng that makes sense for their use case (ie home dns to my home dns vms running numa, work dns forwarded to work dns servers, everything else was recursive resolving but i swi5ched it to their odoh and it worked great while probably being more private

>works flawlessly.

Obviously. You’re continually tinkering with it.

The vast majority of people do not share the same hobby of troubleshooting and tweaking home DNS of all things.


To be thorough, you should check your domain names for any characters that can be changed by a single bit flip. It probably will not look right as far as spelling, but the idea is that eventually something like a cosmic ray will pass through a memory chip and flip that single bit for a connection, and they get redirected to another site set up to handle the request. It's a thing. It takes patience, but but does work. People were doing this to fbcdn.com and other large targets years back.

You can use 9.9.9.10, which is unfiltered, or 9.9.9.12, which is unfiltered and passes ECS.

That is the point and business of Quad9. It's not their fault for you not knowing what Quad9 is.

I don't want my family to get malware from sketchy websites. Quad9 offers a simple solution for these usecases. I'll take the false positive anyday over unfiltered DNS.


Not really. Quad9 also provides an unfiltered version of itself, which I'm currently using. Cloudflare I believe has the same option too.

I noticed few commenters mention something like a rule: If you say your domain is for sale, they will take it from you because..... And was wondering, few years back, twitter was sold to mr Elon. I will just say it like this: Did they lose all their trademarks and rights to all domains, if someone register twitter.cc or twitter.it or similar, because twitter is for sale and they did not need the trademark for business anymore?


The concern is if you own a domain that you don’t own the trademark for.

Twitter owned both the domain and all trademarks so it’s a non issue.

Basically in fairly limited circumstances you can have your domain taken off you if someone else holds a matching trademark. Saying you are selling it can go some way to demonstrating you are not holding it in good faith.


I had registered trademark, and when you register one they ask you what are you doing. I was selling clothes, shoes, fashion stuff. I wanted to get the domain with that name, and it was already taken by someone who sells industrial manufacturing machines. Heavy equipment. They also had registered trademark with the exact same name. The idea is that you as a customer won't be confused who is selling something when you enter a shop and see that name.

I now get what you're saying, but then this can be turned against everyday people. Imagine you have a domain that is your personal blog, vacation photos, stuff like that. No ads, nothing to sell there. Then you receive a message "We from Microsoft/Sony/IBM/Amazon are willing to give you 10Mil for this domain, because we have plans for it, if you won't use it for something bigger ofc" And then show your reply in court saying "He want to sell it". Even if you run a successful business, they can troll you and say "We offer 1bil - you and your family will not have to work for the rest of your life", and then say "His business is fake, he is selling the domain". I don't know if this is possible but if it is, then the whole system is wrong I guess.


Being willing to sell isn’t the only test, otherwise domain squatting would be very difficult. You can generally accept these offers without much risk if done via a lawyer (I’m sure a lawyer isn’t strictly necessary but beyond 5 figures is likely worth it!)


<sarcasm> Today I sat down on my PC determined to finally go and file that bug report with debian - when I open their site in order to download the new .iso I am moving my mouse to the bottom of the screen and waiting to click that I accept the cookies in order to continue but I cannot see the banner. It is really frustrating. </sarcasm>

The internet is still kind of the same. Yes - some IRC networks changed but people think that facebook/discord/reddit/tiktok are the center of internet. No - just go to the real web - it still exists out there. IRC is still here, and they do not ask about your age/id in order to enter and chat. BTW HN is one of these places where you are free too. Probably when Paul starts demanding my ID in order to post my dull sarcasm here I will move, but for now it is a pretty nice place to be.


I have PTCD. Post traumatic cookie disorder. Seriously. If I see one more of those I am going to throw my PC out the window

Apparently you can hide these with a ublock (origin) filter but I haven't found it and I know people have made separate extensions for this


It's the "annoyances" filter lists. Takes a few seconds to turn on in the settings, works like a charm.


I have them all enabled yet still get them


That's odd! They're practically gone for me. AdGuard works well on iOS too.


"the company’s whole shtick is supposedly verifying human identities" - that as PR means that from the next year forward you can expect official government services to require you to use that company. This is just observation from how the tech world works.


Actually that is what they want you to believe. Behind the scenes, secretly Chrome is mostly "a tool to upload files to Google's servers" but because it does not require any actions from the user to do that, many people miss that part.


Oops we accidentally stole, indexed and resold all your data. Sorry.


Or even better, open the on-prem AI portal and type something like "I just got a suspicious call from client X, but I am on a lunch break. Call him and use a fake video of me. Ask him if what he said is true..."


Just my personal thoughts:

Section 230 is the reason for the current situation. It allows youtube to host many videos and the internet became centralized. Then they decide that they will censor someone or some topic they don't like.

If tomorrow they remove section 230, and youtube cease to exist as is right now and everyone starts to self-host it will become quite impossible to deplatform anyone.


Without Section 230, self-hosters have to choose between screaming into the void or playing Russian roulette. You'd either have just your own content that you'd have to self police, or have a comment section where anybody could post something "objectional" that you would be responsible for. Online conversations would effectively be over, right down to email providers once a chain letter gets going that says something the authorities don't like. Section 230 might enable some bad things, but then again, so does free speech. The cost is worth it.


Yeah, social media would also have to decentralize.


My point is that it couldn't. Comments, regardless of where hosted, would be radioactive without S230. At best, we could vote on links, but there could effectively be no conversation because hosting it would be too risky.


I remember with nostalgia the mp3blaster. I spent years listening to it in my terminal. At one point I used only cli without graphical desktop on slackware and one of my TTYs was dedicated to it.

Turns out these times are forever gone - never to come back. The huge disappointment when I tried this on the first run to play a mp3 file from my local disk and it initiated outbound connection. Why a local CLI player needs outbound TCP connection to play a local file from my local disk?!?! The answer was in the source. It is called telemetry. Back then when I used mp3blaster we used to call this spyware, but the times had changed since then.


The times haven't changed. It's still spyware, it's just been normalised.


Back in the day I used to use mpg123. It's still available, but most of the time today I use mpv (successor to "mplayer", handles video too, opens a separate window, zero chrome) or ffplay, since they have wider format support.

No playlist or even file management - they do show id3tags, that's about it. No telemetry, SaaS chicanery or "improvement" upgrades every few days, either.


OIC: https://github.com/bjarneo/cliamp/blob/main/telemetry/teleme...

Should be easy to nerf, but the build instructions are kinda vague. Clone, and then what? Something like "go build" or something I guess.

Looks cool though



I just woke up this morning and I am amazed. I am taking all my nasty words back and I starred the project and followed the author who reacted so fast to my dull negative feedback and this reaction shows how much he cares about the project.


Thanks for pointing this out, to me it seems quite a good response.

I wouldn't mind opt-in telemetry, but possibly the participation rate would be too low to make use of it.


My issue with telemetry is that 99% of software ends up not using it. Why have it? And definitely don't have it by default. Your users will come tell you what they want, making telemetry useless, especially when it's an OSS project you're mostly building for yourself.


Except that telemetry can give you more complete (and foolproof) information than what users report. But yeah, that could also be solved by having debug info that users can attach to their report, the app doesn't have to "call home" for that...


I agree, but it's a cost/benefit thing. Most OSS projects aren't big enough to do anything with the telemetry, so you're just paying in goodwill for no reason.


Opt-in via extension, fine. Opt-in via flag, unreliable. The spyware code should never be anywhere near the main codebase.


Yay! Also, I hadn't noticed an entire section about building from source. Sorry about that. Good work!


Woo, good on them


No personal data is collected

IP address (which can be geolocated) along with a unique identifier is not considered "personal data"? This is basically a tracking cookie. It also seems to use HTTP, which is itself widely fingerprintable based on what request headers it sends.


There's a config variable and a cli flag to disable.

That seems reasonable to me.


to disable

All such surveillance behaviour should strictly be OPT IN.


I saw it, it is NOT spyware. It just sends a random UUID. It is just a personal disappointment for the fact that it is something so simple as a console player and yet connects somewhere. But that's just me. I grew up in other times.

Also I just compiled mp3blaster and I am listening to it again. So cool!


If it phones home without explicitly asking the user for permission in advance, it's spyware.


You can still set up an mpd server: https://www.musicpd.org/ that runs on your local files.


I used to use mocp under Unix but nowadays it's just audio/zuke in 9front with plumber settings for playlists.


Few years ago a huge NRA database was left public with admin/1234 or similar by the Bulgarian NRA. They government fined itself some non-trivial amount, then in the source/destination IBAN they put the same value and paid the fine. They managed to find someone to blame and it was not the person who left the database but the person who found it. Turns out that if you leave the PII of a whole country open to the public it is not your fault and you get to keep your cozy job. It is already unlawful to access that, so if someone access it - it is his fault - he broke the law.

Edit, i checked the facts: The Bulgarian government said that the it should pay too much to itself, and appealed the fine for few years until it somehow expired. And the guy (20 year at that time) they accused was later acquitted after they tried to ruin his life.


At least you think that this is satire, until the author receives a DMCA from one of the big corps saying that he leaked the transcript of their last meeting


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: