Hacker News new | past | comments | ask | show | jobs | submit | karma20's comments login

Firefox for iOS and macOS. I have strict tracking protection [1] enabled on the former, and NoScript + uBlock Origin set up on the latter. I also use Little Snitch on the Mac.

[1] https://support.mozilla.org/en-US/kb/tracking-protection-ios


I like the concept but share some of the blockchain concerns here. In particular, I'm interested in how the Gaia "driver model" [1] is actually architected, and how this compares to local storage:

> Gaia enables applications to access [it] via a uniform API.

[1] https://gekri.com/privacy


I have been told that the privacy page [1] is reads poorly. I will rewrite the copy ^^'

You can learn more about Gaia storage here: [2]

[1] https://gekri.com/privacy

[2] https://github.com/blockstack/gaia


HN's policy on paywalls is outlined in the FAQ [1]. Private Browsing mode is generally a good workaround:

> It's ok to post stories from sites with paywalls that have workarounds.

> In comments, it's ok to ask how to read an article and to help other users do so. But please don't post complaints about paywalls. Those are off topic.

The rationale explained by dang in a 2015 post [2] makes sense:

> Publications like NYT, WSJ, the Economist, and the New Yorker have paywalls that leave ways for readers to work around them. Such stories are OK to post to Hacker News. Yes, this sucks, but the loss of many substantive articles would suck worse.

[1] https://news.ycombinator.com/newsfaq.html

[2] https://news.ycombinator.com/item?id=13434938


Aside from: clearing cookies, having to reopen news articles you've already half read in incognito, or adding an additional '.' (like "nytimes.com./blah"); what are some of the other ways people are getting around paywalls?


Personally, I do just clear cookies, but I've found a good Firefox extension that does it well for me.

https://addons.mozilla.org/en-US/firefox/addon/remove-cookie...

It has a convenient button that clears all the storage for the page in the current window. It remove the cookies, local storage and session storage. Then I just reload the pay-walled page and it thinks I'm a new visitor.


Adding "outline.com/" before the url sometimes works.


At least wsj.com does not work anymore on outline. Maybe HN can bundle all those paywalled sites and sell a subscription.


Use a WSJ link from Bitly into Outline and it works again...



archive.is is fairly foolproof for me


I have this trick where I just pay for high quality, well researched news because I'm an adult and I realize that not everything should be free and maybe we should pay for some things.

People on HN like to complain about paying in data to use Google and Facebook and yet also consider it an affront that they have to pay money to journalists.


True, i would agree.

If only paying for high quality news and articles guaranteed me that i won't see ads, well at least non-js ads.

Sadly that won't happen because people who can pay for such news have higher disposable income and are better target for advertisers.


Which one do you pay for? All of them? How do you determine high quality? How do you reconcile the fact that you need to pay before you can read it, thus not being able to evaluate the quality properly? How do you reconcile saying a large news publication produces quality with the amount of errors that are frequently and egregiously present in articles with any sort of depth?


I agree with the opening question but I find latter part of the argument unreasonable. You will encounter many, many services in life that require an initial payment. Pay once and then decide whether you want to keep on paying for more. This applies to restaurants, movies, hotels, taxis, etc. The initial payment for pay-walled articles is usually quite small. If you don't know where to start you can always ask a friend, read a review, or join an online community.


I opened and closed with the questions what were to me most relevant, which is my mistake as I should have front-loaded both. Your answer is reasonable, except it glosses over the fact that the quality is bad and this is a pervasive issue.


Yup this


HackerOne is a platform on which Valve runs a public program [1] that awards monetary bounties. I'm confused as to why Valve is allowed to forbid disclosure of "out-of-scope" reports and will only "generally" disclose reports in any case:

> Please note that we will not consent to disclose reports if they have been marked out-of-scope or inapplicable, or where Valve has not taken a specific corrective action / mitigation.

> Valve embraces transparency in our security. We will generally disclose the details of vulnerabilities found, upon request.

[1] https://hackerone.com/valve


Also of interest is the follow-on discussion [1] taking place on the electron/asar repo.

[1] https://github.com/electron/asar/issues/123


Qihoo has also employed dark patterns to push deceptive security practices around its own browser [1]:

> When you attempt to install other browsers, the 360 Safe Guards will allow the browser to be installed but will then popup saying not to let it become the default browser.

> When users of 360 Safe Guards run a check of their system, if they don't have the 360 browser installed it will give them a failing grade. If the user chooses another security software to protect their failing grade browser, the Safe Guards say no.

Also interesting is a statement by Opera on the 2016 acquisition [2]:

> The transaction would give Opera access to the extensive internet user base of Kunlun and Qihoo in China as well as the financing and other support of the Consortium that would allow for the full potential of the Company to be realized. At the same time, Kunlun and Qihoo would be able to cross-sell their products and services to the Opera user base, and benefit from Opera’s leading mobile advertising platform.

[1] https://web.archive.org/web/20150723081728/http://www.digita...

[2] https://arstechnica.com/information-technology/2016/02/chine... (can't find a direct link)


TL;DR: Microsoft bumps Azure max bug bounty to $40k, introduces Azure segregated hosts for researchers to test against, and formalizes their Safe Harbor terms [1].

[1] https://www.microsoft.com/en-us/msrc/bounty-safe-harbor


Interesting concept. From the FAQ [1]:

> Login into Hero Trainer when you go for a run (gym check-ins will come in the future)

How would you calculate points earned for each run or gym visit? For the former, does the app rely on step count during the "tracked" period or does it incorporate outdoor GPS?

[1] https://hero-trainer.com/faq/


You are correct. For now, we're focusing on tracking only outdoor runs utilizing GPS and accelerometer. In the future, we're evaluating different ways to quantify the intensity of work outs at the gym.


TIL. I should check out Rectangle:

> Spectacle used it's own keyboard shortcut recorder, while Rectangle uses MASShortcut [1], a well maintained open source library for shortcut recording in macOS apps. This cuts down dramatically on the number of bugs that were only in Spectacle because of the custom shortcut recorder.

[1] https://github.com/shpakovski/MASShortcut


Interesting. From the source article [1]:

> [...] they would essentially be "dev devices." Think of them as iPhones that allow the user to do a lot more than they could on a traditionally locked-down iPhone.

It sounds like Apple might provide vetted researchers with development-fused devices [2]. In an official capacity, these have only been mentioned once - during a Black Hat talk by Ivan Krstić [3].

[1] https://www.forbes.com/sites/thomasbrewster/2019/08/05/apple...

[2] https://www.theverge.com/2019/3/7/18255509/apple-iphone-dev-...

[3] https://www.blackhat.com/docs/us-16/materials/us-16-Krstic.p...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: