Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Jeff – Jev-compatible 0.8B decision models, trained at home, ~30 ms (github.com/firelex)
    144comments
  2. 1996 chat room simulator connected to Win95 and System 7 web desktops (lolchat.rip)
    33comments
  3. Pirating the Pirates (mubi.com)
    237comments
  4. MicroLLM Lab – Try 7 tiny LLM's in the browser (stateofutopia.com)
    68comments
  5. 12,000-year-old Göbeklitepe burials explain scattered bones (archaeologymag.com)
    27comments
  6. Tank Body Problem (jimsitu.com)
    9comments
  7. California farmers are struggling to sell grapes as demand for wine drops (kqed.org)
    248comments
  8. ESP32S3 cluster running 1.58-bit (BitNet) Language model (github.com/low-zi-hong)
    7comments
  9. Show HN: Pac-Bench – How well can models one-shot a Pac-Man game? (jonclegg.github.io)
    5comments
  10. Sonnet 5.5 (anthropic.com)
    439comments
  11. Scientists solve 1840s space weather mystery (arstechnica.com)
    39comments
  12. Hijacking the PS5's RTMP stream (yashgarg.dev)
    69comments
  13. Phyllotaxis: An audio-reactive LED display (jagi.studio)
    —discuss
  14. World Labs Is Joining AMD (worldlabs.ai)
    89comments
  15. Who Killed Paulina Borsook's Career? (wired.com)
    —discuss
  16. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    194comments
  17. How to win a beer with high-dimensional statistics (jamiesimon.io)
    4comments
  18. Bluegraph – Explore NOAA buoy data, rebuilt in 3D from measured spectra (bluegraph.io)
    2comments
  19. What is the best shape of a city? Modelling effect of urban form on distance (sagepub.com)
    12comments
  20. Updated Google Maps shows destruction of the city of Rafah (twitter.com/aliabunimah)
    170comments
  21. Does Reddit have an astroturfing problem? What the data suggests (petervijeh.com)
    177comments
  22. The Art Forger Who Became a National Hero (priceonomics.com)
    4comments
  23. U.S. Strategic Petroleum Reserve Falls to Lowest Level Since 1982 (oilprice.com)
    110comments
  24. Nvidia wants to put a watchdog chip next to every AI agent (cnbc.com)
    160comments
  25. It's Time to Investigate the AI Labs (calnewport.com)
    133comments
  26. Show HN: HN.watch – Videos of all Hacker News posts (hn.watch)
    86comments
  27. Profit Margins of the Largest Companies (visualcapitalist.com)
    2comments
  28. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    58comments
  29. What reversing, modernising old games tells us about the economic impact of AI (isfine.org)
    37comments
  30. Behold the pawpaw (cbc.ca)
    26comments

How to own an airline in 3 easy steps and grab the TSA nofly list along the way

1028 pointsby 3y agomaia.crimew.gay
478 comments
3y agoHN ↗

Also seems to have gotten a crew list from the CommutAir’s CASS or possibly from other airlines as part of the shared deadheading crew list, which includes crew addresses and employment information.

There were also prod AWS credentials in the files exposed in Jenkins.

3y agoHN ↗

I wonder which no-fly list it is. Is it a government no-fly list that would contain suspected international criminals and terrorists, or an airline's private no-fly list that would contain people who cause a ruckus on flights, drunks, anti-maskers, and so on. Maybe one shared between airlines? I would imagine that second list has grown substantially since 2020 given all the craziness airlines have had to deal with since then.

3y agoHN ↗

The Daily Dot article specifies that it's the United States' (the Terrorist Screening Center's).

3y agoHN ↗

https://www.fbi.gov/investigate/terrorism/tsc

[...] the vast majority of people who have disputed travel and appeal to the Department of Homeland Security’s Traveler Redress Inquiry Program are not on the terrorist watchlist. Most people on the terrorist watchlist are still able to fly within the U.S. A very small subset of people on this list are on the “No Fly” list.

[...]

The No Fly List is a small subset of the U.S. government Terrorist Screening Database (also known as the terrorist watchlist) that contains the identity information of known or suspected terrorists. This database is maintained by the FBI’s Terrorist Screening Center.

So, shouldn't this list be public information anyway? It's not even suspicious people they're watching, by the sound of it the no fly list is only for people they have concrete evidence of terrorist activity for. Imo the public has a right to know those identities.

3y agoHN ↗

the nofly csv is almost 80mb in size and contains over 1.56 million rows of data. this HAS to be the real deal (we later get confirmation that it is indeed a copy of the nofly list from 2019).

3y agoHN ↗

CSV you say? Let's hope Bobby Droptable's cousin Bobby Double Quote Comma-Semicolon don't get in it...

3y agoHN ↗

1.5 million rows you say? Better hope nobody opens it in Excel and overwrites it…

3y agoHN ↗

Oh don’t. I spent several hours last week unfucking one of those.

3y agoHN ↗

I have. All I'm saying is this plus someone who left 10 years ago who can't and shouldn't have written a CSV parser using regular expressions. Input row:

  A,B,Alice "Mallory" Bob,123
3y agoHN ↗

Thank you, I'm considering adopting this as job title, like "senior unfucker".

3y agoHN ↗

Intermediate Fucker reporting for duty.

3y agoHN ↗

I just had one today that had the last char of a field as '\', which escaped the closing quote and then munged the column count from there.

3y agoHN ↗

Isn't that your parser's problem? I don't think true CSV has any special characters other than comma, quote, and CRLF.

3y agoHN ↗

I thought it strange too. I saw what the issue was, and just "fixed" it be correcting the data in the CSV. For the lulz, I guess I could have played with the parser's options on deciding what is needed to be escaped. However, the data would have still been incorrect as the '\' is definitely not part of the desired content, so ultimately it was better to correct the input. i would kind of rather the import die than having the potential foot gun of '\' in a field for later sabotage.

3y agoHN ↗

Unless it's a CSV file exported from a Nordic locale Excel, in which case your CSV exports will use semi-colon as column separators and commas as decimal points. And yes the filename will still end with ".csv"

So the following Excel export I just did will parse perfect fine with your CSV parser but give you completely the wrong thing:

  1;2,3;3,3
  2;7,3;9,3
  3;4,5;7,5
3y agoHN ↗

That has nothing to do with the Nordics, but with the decimal separator. In locales that use a comma as the decimal separator (i.e., most European locales), Excel uses a semicolon as CSV separator.

3y agoHN ↗

There is no “true CSV”. https://en.wikipedia.org/wiki/Comma-separated_values:

“The CSV file format is not fully standardized. Separating fields with commas is the foundation, but commas in the data or embedded line breaks have to be handled specially. Some implementations disallow such content while others surround the field with quotation marks, which yet again creates the need for escaping if quotation marks are present in the data.

The term "CSV" also denotes several closely-related delimiter-separated formats that use other field delimiters such as semicolons.[2] These include tab-separated values and space-separated values. A delimiter guaranteed not to be part of the data greatly simplifies parsing.

Alternative delimiter-separated files are often given a ".csv" extension despite the use of a non-comma field separator. This loose terminology can cause problems in data exchange. Many applications that accept CSV files have options to select the delimiter character and the quotation character. Semicolons are often used instead of commas in many European locales in order to use the comma as the decimal separator and, possibly, the period as a decimal grouping character.”

https://en.wikipedia.org/wiki/Comma-separated_values#Standar... mentions a few standards for csv, one of which is the MIME type text/csv, standardized in RFC 4180.

3y agoHN ↗

If I’m not mistaken RFC 4180 says that quotes should be escaped by prepending them with another quote, so “” and not \” (these are not double quotes but my phone won’t let me type normal quotes), but yeah I guess it is a rather perverse value to put in a csv.

3y agoHN ↗

Note that virtually no one implements that RFC. CSV is merely a style of file, not a true file format.

3y agoHN ↗

read the article before speculating? it answers that question

3y agoHN ↗

You can follow their steps to find this data it’s not that hard. Then do whatever you want with it. Shodan isn’t some mythical tool.

3y agoHN ↗

They say the access got closed before publication.

3y agoHN ↗

Yeah I was just pretending I knew what was going on.

3y agoHN ↗

Basically any air charter service (no matter how small) will have access to the no fly list. It's honestly surprising that it's not up to date online within minutes.

3y agoHN ↗

If I was the US government, I would add some fake but legitimate-looking IDs in such lists, different ones for every airline I send the list to, so I can identify who leaked the list ex post facto, and come down with God's Wrath on any airline that leaked theirs.

But then, I am not a Bond-esque criminal organization bent for world domination.

3y agoHN ↗

This is called “seeding” a list and is standard practice for data brokers. But maybe that’s a sign they’re Bond-esque criminal organizations…

3y agoHN ↗

Yup - they're the people ACTUALLY selling your data (and often for pennies)

3y agoHN ↗

And as always... Never use production data in the test pipeline.

At the very least, I don't think the company was operating like every random developer should have full-access to the no-fly list, which is what they de-facto gave them when they dumped an old copy into the test pipeline.

3y agoHN ↗

with pretty much no skill required

Seriously? I know like none of the tools or terms they used, like wtf is shodan?

In general the author doesn't seem to follow the white hat guidelines, and I'd be worried what they've done is quite illegal (possibly on a federal level if the nofly list is so secret)

3y agoHN ↗

US law is neither a universal law nor an international one.

Accessing computer systems owned by a US company based in the US might constitute a violation of US law, but the hacker is based in Switzerland - where US law does not apply.

As you can see in the linked Wikipedia article, accessing these systems is probably not illegal in Switzerland, thus, for all intents and purposes, no crime was committed.

3y agoHN ↗

The jurisdiction is quite questionable. If someone in north Korea would decide I'm guilty of breaking some bizarre law, I couldn't care less. Why would a Swiss citizen care about what the united states think is a crime?

3y agoHN ↗

It's easier to get extradited to the US than to North Korea

In fact I don't think any countries will extradite you to North Korea. There's plenty (including many in the neighborhood of Switzerland) that extradite to the US for at least some crimes.

3y agoHN ↗

Switzerland has assisted the USA in going after them, unless I'm missing something.

(I am open to missing something here)

3y agoHN ↗

And also it's been confined to Switzerland for at least a couple years now; committing US federal crimes isn't a new circumstance for it.

3y agoHN ↗

- where US law does not apply.

Us law applies wherever they want. Very, very few governments will refuse a request....it's too expensive in the long run.

3y agoHN ↗

Legalities aside, it's morally wrong to hack a server, disregard reasonable disclosure, and publish (even to a selected group) an in-depth list of personal information; all for political reasons! (at least going off what their Wikipedia page describes as their motivations).

3y agoHN ↗

"Look at you, hacker. A pathetic creature of meat and bone. Panting and sweating as you run through my corridors. How can you challenge a perfect immortal machine?" — Shodan

3y agoHN ↗

You actually have most likely come across mentions of shodan if you use HN often. It is that search engine for insecure systems like exposed/insecure webcams.

3y agoHN ↗

Anyone even tangentially involved in infosec knows shodan though... so in that context everything done in the article was trivial.

3y agoHN ↗

As a nontechnical person who enjoys this stuff, also wasn't familiar. Anyone have a good rec for a starter guide for a nontechnical person to be able to do similar research (albeit in ideally more of a white hat approach)?

3y agoHN ↗

Hosting public facing Jenkins should be illegal tbh

3y agoHN ↗

I think she used publicly available common tools in this regard without specific knowledge of the airline industry. Even searching the internet is a special skill for those never used a computer or held a smartphone but is a no brainer for those never created a search engine algorithm.

3y agoHN ↗

I know those tools and i agree. There's no skill required to use a search engine for compromised/misconducted servers to find a compromised/misconfigured server and then pile around on it. I don't think it's so good to publish it instead of reporting to the airline but I'm pretty sure that is for political reasons considering the author's political views.

3y agoHN ↗

so are there any repercussions for hacking US entities from switzerland ? Not that I think there ought to be.

3y agoHN ↗

The Swiss tend to make your life vaguely difficult by confiscating your computers every now and then at the request of the US.

You won't be extradited though.

The Swiss could maybe prosecute domestically, but its not (currently) in the public interest to do so.

3y agoHN ↗

Even then the sentences are reasonable while in the US you go to jail for just as long as if you killed someone in some cases.

The ATT "hacker" got 41 month for guessing URLs. US sentences are insane.

3y agoHN ↗

Isn't weev hiding in Transnistria after he got released on a technicality that allows them to go back after him in another district court or something?

I was thinking the courts ruled he got tried in the wrong jurisdiction so prison had to release him. He basically GTFO'd before they had a chance to refile and is hiding in an unrecognized territory inside Moldova.

3y agoHN ↗

This is clearly on the darker side of gray-hat. Hate to be preachy but anyone seeking to emulate this sort of attack-finding should consider their ethical obligations as a computer scientist and follow best practices for responsible disclosure. It appears this was completely ignored here, including sharing stolen sensitive data of normal people with whoever can plead a case.

3y agoHN ↗

Yeah cause we should totally have a top secret no fly list

3y agoHN ↗

Maybe we should or shouldn't, but the potential victims of this aren't just some greedy corporation. Leaking the no fly list could cause irreparable harm to individuals whose names are on it or even similar, causing discrimination by employers and other organizations.

3y agoHN ↗

Top secret stazi lists should absolutely be shared. It's why we have 'we have right to know' laws, so the government can't just lock people up in a jail and disappear them.

3y agoHN ↗

While this is true, it is also true that many people think "where there's smoke, there's fire".

Or, to put it another way, governments can make people disappear by publishing such lists and having the police be busy somewhere else when a mob happens.

3y agoHN ↗

If someone was on a no fly list and they wanted the general public to know, they could just put it out there themselves. No? This seems more likely to be used as a form of public shaming than a way to expose injustice.

3y agoHN ↗

If someone was on a no fly list and they wanted the general public to know, they could just put it out there themselves. No?

How would they know? How would they prove it?

There's a known case a few years ago where a woman was trapped away from the US for 3 years - her estranged husband put her on the list when she went to visit her parents, and boom, she's not allowed into the US and no-one will tell her why, making it easy for him to get divorced and keep the house.

(If she'd known what had happened, and been able to put her hands on enough money, she could maybe have flown to Canada/Mexico and entered overland; all she knew was she was denied boarding)

3y agoHN ↗

There's a known case a few years ago where a woman was trapped away from the US for 3 years - her estranged husband put her on the list when she went to visit her parents, and boom, she's not allowed into the US and no-one will tell her why, making it easy for him to get divorced and keep the house.

How does one "put her on the list"? It's not that easy.

3y agoHN ↗

Apparently if you happen to be working in the right government department then it is. It was only discovered when he applied for a promotion and they did an extended background check.

3y agoHN ↗

Just because things should work a certain way doesn't mean they do.

3y agoHN ↗

You can almost certainly get anyone put on this list by simply creating an email account like firstname.lastname@protonmail.com and sending out a few threatening emails to the right places.

3y agoHN ↗

It's not like the federal government sends you a letter to tell you about it and what to do if you have an issue with it. While you raise a valid concern, I think it's a lot more likely to function as the basis of a class action suit - a sufficiently plausible and timely piece of evidence that would move a court to compel proper discovery.

3y agoHN ↗

That's actually exactly what they do.

If you are a U.S. citizen or lawful permanent resident, and the TSC determines that you are on the No Fly List, DHS TRIP will send you a letter informing you of your status on the No Fly List and providing the option to submit and receive additional information.

https://www.aclu.org/know-your-rights/what-do-if-you-think-y...

3y agoHN ↗

I think you may not be reading the parent comment correctly. They're saying that those on the list have a right to privacy, therefore outright leaking the list is wrong. Being able to find out whether or not you are on the list is not incompatible with maintaining others' right to privacy.

3y agoHN ↗

I am reading it correctly. They do not have a right to privacy, because we all have the right to know who the government is keeping on lists. Regardless the line of thinking reeks with hypocrisy - the government of the United States has been doing nothing but trampling privacy, yet when it comes to top secret government surveillance state programmes they hold it close to their chests

3y agoHN ↗

I don't understand your reasoning. To me, you seem to be saying that since the state violated everyone's privacy, the general public now has the right to violate these individuals' privacy even further to get back at the state.

Publishing the list as-is would also imply that you believe the state is infallible and can't err when putting people on this list. There are thousands of people out there who have redress numbers because they have the same name as someone on the list. Can you imagine if getting a redress number is necessary for employment? Leaking the list would ironically increase the state's control.

(edit: Again, I'm not disagreeing with letting individuals find out if they themselves are on the list, just disagreeing with the method)

3y agoHN ↗

They do not have a right to privacy

What the fuck is wrong with you? Do you understand the repercussions of it being found someone is on a no-fly list (because we all know the US government makes mistakes).

3y agoHN ↗

those on the list have a right to privacy, therefore outright leaking

Those Americans on list have a right to question their accuser in court before a right (to travel) is restricted. When did we agree to suspend due process, 14th amendment?

3y agoHN ↗

And then, what, some hapless person on there gets doxxed and some red neck asshole rolls up on their house and shoots them cause ‘Merica? After 9/11 we had these idiots killing brown people left and right just because “they could be terrorists.”

Don’t be so naive. Lists of people are almost inherently dangerous things. I don’t like that a no-fly list exists in the first place but it would be completely irresponsible to just publish it and wash your hands of it.

3y agoHN ↗

I think the intention here is to leak the list to a journalist, that will report on it's contents, but still not leak the list publicly.

3y agoHN ↗

What are you talking about? The list is literally designed to harm those people. It's a no-fly-list. If anything, having it public could provide public pressure to get them off the list.

3y agoHN ↗

It also provides proof to the victims that they were on it. It may not bring justice from the same government that put them there in the first place, but spreading their stories may (hopefully) reduce its legitimacy and revoke the consent of the governed.

3y agoHN ↗

Though I don’t like the idea of it, I’m also not certain that I know better than people whose careers are in national defence. I’m not convinced that it’s a black and white thing. There are bad actors out there, and sometimes it’s clearly advantageous to hide information from them, which means hiding it from everyone.

Maybe there are reasons this is short sighted or I’m missing a greater point. I’d be interested to hear ideas in any case.

3y agoHN ↗

Am I missing something? It seems Maia didn't share the data at all, and only offers to if someone can demonstrate they will use it responsibly.

Moreover, depending on the contents of the list, this likely offers proof of what is generally suspected, that the no fly list is a form of discrimination and authoritarian overreach, targeting people that haven't been convicted of a crime but are "suspected" due to race, religion, etc. The whole thing is probably unconstitutional/illegal, but it's hard to prove that since it's been secret.

This seems like a clear case of hacktivism- trying to expose an unethical government program for what it is, so that it can be stopped.

3y agoHN ↗

>demonstrate they will use it responsibly.

The problem is to define "demonstrate" and the criteria. Remember the gatekeeper is now an unemployed gal who "know lot's of things about cyber security" according to her main page. Seems likely a competent bad actor could easily impersonate a well-meaning reporter...

Yes, security through obscurity isn't security, but this also seems incredibly irresponsible for any "security researcher". AFAIK, just basic standard good practice is to report the flaws and allow a reasonable interval before publishing, and there seems to be no hint of this.

Modern society really is held together with duct tape, baling twine, and a few pieces of bubble gum...

[EDIT: pronouns]

3y agoHN ↗

>Remember the gatekeeper is now [...] unemployed [...] who "know lot's of things about cyber security" according to [its] main page. Seems likely a competent bad actor could easily impersonate a well-meaning reporter...

...and it has a Wikipedia article (https://en.wikipedia.org/wiki/maia_arson_crimew), and has demonstrated in other cases (cf. https://www.dailydot.com/debug/feelyou-mental-health-app-dat...) that it has at least a reasonable grasp on what to leak and what not to leak.

3y agoHN ↗

Good to see that; thanks for digging deeper. I hope he has done this behind the scenes and the holes are patched, because I'm sure that by now, someone with worse intent has already followed those footsteps...

3y agoHN ↗

In the aforementioned Daily Dot article:

CommuteAir added that the server, which was taken offline prior to publication after being flagged by the Daily Dot, did not expose any customer information based on an initial investigation.

As a side note, maia uses it/its pronouns.

3y agoHN ↗

If TFA (may not be accessible right now) is to be believed, “the” server is a very generous understatement of the size of the exposed infrastructure, and customer information was very much accessible if not accessed per maia’s words. So seeing a statement like this from the CommuteAir PR people actually makes me feel less reassured, not more. (The attacking side looks better so far—maia itself is not a “watch the world burn” type, judging from its breach history, even if its writing makes you wonder whether the absurdist parody is deliberate or the author is in fact slightly manic. Kind of like Justine Tunney.)

3y agoHN ↗

According to wikipedia maia has used both it/its and she/her at various times, so it seems either is appropriate.

3y agoHN ↗

Sure but "he" isn't, which is what OP used.

3y agoHN ↗

Please give maia the respect she deserves and use the correct pronouns.

3y agoHN ↗

Apparently the pronouns to use are it/its? According to other people which makes your comment even better.

3y agoHN ↗

She goes by it, so go look in the mirror. We're all trying our best here.

3y agoHN ↗

Maia uses both she and it pronouns. The poster before me misgendered it though, which absolutely isn't okay.

3y agoHN ↗

I try and use a person's preferred pronoun. Sometimes I fail, and that absolutely OK.

3y agoHN ↗

after your comment, I looked at her main page more closely and found that she mentioned "it/she" in a superscript the middle of a paragraph, so that's what I corrected it to.

I do have to say that, while it's polite to use people's preferences, when just reading an article and posting a quick comment, it's pretty casual, and (almost always) no offense is meant, so none should be taken. Note that the bulk of the comments here are all over the map, and I'm sure no one means to be offensive.

3y agoHN ↗

I think the point here is to expose the nofly list as an unethical and/or illegal government program by leaking it to journalists that can evaluate and summarize it's contents, not to help them secure it better.

White hat hacking assumes that the hacked party is doing normal or ethical business, and that helping them secure it would be generally beneficial.

Also, I'm pretty confident that Maia, as a famous hacker and cybersecurity expert, isn't going to be easily duped by someone impersonating a journalist, and knows how to verify such things.

3y agoHN ↗

I get the impression that she's/it's doing this from a place of pain and desire to lash out, and "the system" is an easy target for her to fix onto. Not out of any sense of morality.

3y agoHN ↗

That's an odd take but I'm getting old. Once you cross 30 its incredibly to spot when someone is an NPC laundering hate in the guise of reading minds. They're clearly young or angry, so you let it go.

3y agoHN ↗

The adjective is missing from your comment so I mean not sure whether you meant to write that it's incredibly easy or hard. I certainly do not presume to be a mind-reader, but I do have experience with gender dysphoria. Self-hatred is a hell of a drug.

She appears to have talent in connecting these data sources, but she's also in way over her head when it comes to motivation. On the world chessboard, she's a pawn. I can easily imagine that she's being egged on to do harm to the quasi-neutral but not isolated society that is now her life raft.

3y agoHN ↗

As I understand it, self hatred arises not from gender dysphoria but rather how others treat the person experiencing that.

3y agoHN ↗

Maia didn't share the data at all

You literally immediately falsified that assertion:

and only offers to if someone can demonstrate they will use it responsibly.

And nobody ever lies of course.

3y agoHN ↗

Offering to share it privately, if specific conditions are met is very different from having already shared it, or publicly releasing it.

3y agoHN ↗

She had only shared it with known journalists that she had a relationship at time of writing, and seems pretty bright.

Hypothetically she might get scammed by someone and irresponsibly disclose but let's not condemn her for it yet.

3y agoHN ↗

You have an incredibly naive understanding of the propensity for people to divulge secrets.

"Three can keep a secret if two of them are dead"

3y agoHN ↗

We're talking about a no fly list which every airline in the world has a copy of. There's at the very least hundreds, if not 10s of thousands, of employees of airlines alone that have access to this list.

If people had such an innate propensity to divulge secrets, surely the employees who setup that faulty jenkins server would have already sent you a copy of the no fly list, right?

3y agoHN ↗

And I would agree that it has been leaked, probably a lot, and that any halfway competent government intelligence agency in the world has copies if they feel they need them.

That isn't really a counter-example to my point which is just that it is stupidly naive to suggest that Maia is somehow exempt from these concerns.

If you want to argue that its all pointless secrecy theater, then I'd agree with that entirely.

3y agoHN ↗

Three can keep a secret if two of them are dead

Probably thousands of airline and US government employees have had access to this list over the years. Yet neither you nor me can see anything on it, here in January 2023.

3y agoHN ↗

Depends what exactly they mean with "demonstrate". It can mean email from J. Random Person with "pinky promise I will use this list for good", or it can mean "well-known journalist with a clear public track record".

3y agoHN ↗

including sharing stolen sensitive data of normal people with whoever can plead a case

Wait, I thought Maia was offering to share who was on the no-fly list, not this stolen sensitive data this comment is claiming

3y agoHN ↗

This is why such a list should be public. You don't trust random grey hat hacker at .gay TLD to distribute the list to people who won't do harm with it. I don't trust the government to not distribute it, accidentally or otherwise, to people who want to do harm with it.

In fact, the government does do harm with it, by putting people on it without telling them (they might send a letter, that's not guaranteed), and you only get to find out a few hours before your flight when you get rejected at security.

Furthermore, this particular government fails to properly secure info all the time. Seems the last two presidents have been just leaving classified papers strewn all over the place.

No, I'll trust the gay hackers over the government, thank you very much.

3y agoHN ↗

Sure. But that isn't the naive position that just because someone is Good(tm) that they will be careful with secrets. That's just the position that keeping secrets and having Kafkaesque bullshit is itself bad, so it doesn't matter, and the right thing to do is just post it on a pastebin hosted in Russia and call it a day.

3y agoHN ↗

And incidentally some of it is entirely illegal but sense she is already facing extradition for a federal indictment - in for a penny, in for a pound.

3y agoHN ↗

Seems to making it's prosecutors jobs really easy, by incriminating itself.

3y agoHN ↗

Perhaps this is just my autism speaking, but am I the only one who gets completely freaked out by sentences like the above? "It" refers to inanimate objects, things which can't have free will, do crimes, or be prosecuted.

It's almost like you're talking about how a lawnmower decided to run a child over and then incriminate itself by boasting about it on social media. It makes no sense!

I know she picked that pronoun herself, but I really wish she didn't. It just makes communication difficult.

3y agoHN ↗

I wonder what the motivation was. Anarchism is mentioned elsewhere, so if I wonder if that’s a motivating factor here. At any rate, I appreciate that people are trying their best to be respectful. Personally, I’d also prefer to use “she” if that’s alright with her (it?). This becomes confusing quickly when we’re also trying to use it abstractly to refer to arguments and concepts.

3y agoHN ↗

Sure, but that’s not what the page says. The Wikipedia article says that. The page says “it/she”. From what I’m familiar with, the order is usually “singular/plural” and when multiple are preferred I’m used to seeing it written as you notated it here as pairs in a list e.g. she/her, him/his, they/them, it/its, xe/xim, etc, in a list. I guess I can infer that’s the intention, however, which is fair enough.

But that really didn’t have much to do with what I was discussing. That was a separate argument about how we use “it” to refer to objects as a rule. Humans are objects, but we also generally prefer to think of them as objects of a higher order variety. In conversation, we take advantage of this to parse and interpret context more quickly. Choosing to do otherwise makes it more difficult to know if the “it” I just used in this sentence is Maia, some other object, or an abstract point I’m making in this discussion. Anyway, that’s why I prefer she/her.

3y agoHN ↗

I totally understand wanting to be respectful, but respect goes both ways. She needs to respect the fact that her odd pronouns are literally breaking the English language for people who want to use them.

3y agoHN ↗

I personally think that the ultimate end game for pronouns in English will be creations of new ones with no connotations (so easy to apply like names) that get incorporated into the language or more likely an eventual move to a single pronoun that applies to everyone. Chinese, for example, only differentiates in written form so would be an easy adjustment. They is every high schoolers preferred choice in essays before English teachers complain.

I'm not sure how the under 20 is adjusting but in my groups of mid 20 to late 30 nobody is trying to disrespect anyone by not using preferred pronouns, but it just slips out from decades of usage, and people just end up replacing pronouns with the person's actual name after multiple times apologizing. The having to remember multiple names when meeting someone just doesn't seem tenable long term.

3y agoHN ↗

more likely an eventual move to a single pronoun that applies to everyone

Oh god i hope. As a german, we have pronouns for all nouns. So far no societal backlash against those, but they just seem totally useless to me (beside maybe a teeny tiny bit of "forward error correction"). You just have to learn them. Surest way to spot an immigrant. Then there is job titles. In the US, "nurse" seems to be used for both genders, but the words origin is female. Yeah, we have that as well for many jobs. Others usually have suffixes. Ofc we want to be welcoming to all. You can imagine the job listings...

3y agoHN ↗

That's more or less what singular they is, surely?

3y agoHN ↗

That's a problem with the English language though. There's not a singular only version of "they" and there probably should be.

3y agoHN ↗

The singular only version of "they" is "they", just like the singular only version of "you" is "you". "You" was formerly plural, with "thou" as singular, but "thou" has since fallen into disuse.

3y agoHN ↗

"You" was formerly plural, with "thou" as singular, but "thou" has since fallen into disuse.

Sadly. Overloading "you" and "they" feels rather clunky. I wish it got rid of "he" and "she" instead - gendering pronouns is completely useless, and that's coming from someone whose native tongue genders much more than just pronouns...

3y agoHN ↗

After Miner49er went to the store, they went the bank.

After Foo and Bar went to the store, they went to the bank.

If we don’t need a singular-only you, why would we need a singular-only they?

3y agoHN ↗

Have you considered that someone who chooses "it/its" as its pronouns is intentionally trying to break the English language with said choice? In this case, it is Swiss, and therefore it is likely not a native English speaker which could be a factor as well.

3y agoHN ↗

German has similar singular pronouns to English, with "he", "she" and it corresponding directly to "er", "sie" und "es".

(Not trying to make any point here, just thought it might be useful for context.)

3y agoHN ↗

Swiss though, so the evil twin of German :P

3y agoHN ↗

Possibly, but that just makes me more interested in simply ignoring her wishes.

3y agoHN ↗

Really not. Most sentences can be easily rewritten without pronouns. I know a bunch of trans people and have trouble remembering who likes to be called what, so I just reduced the number of direct references. It's not that hard to do, because most conversations don't involve so many subjects that it becomes complex.

3y agoHN ↗

I'm sorry to hear about that. Sounds difficult.

3y agoHN ↗

That's the reply I should have given to your complaint about 'breaking the English language'.

3y agoHN ↗

You can't 'break' a language. You either just follow its rules or flaunt them. If your output is still comprehensible - which 'it' as a pronoun is - it's still language. Back in the day English used to have two pronouns for 'you'. Was merging them both into one pronoun also literally breaking the language?

3y agoHN ↗

She's actively making the language less comprehensible by breaking the rules. Multiple times in this thread, people have said "it" and I've been confused as to what - or who - they're referring to.

I'm not a language historian, so I don't have an opinion on your last question.

3y agoHN ↗

People seem to be assuming that this request for certain pronoun usage is made in good faith. Asking to be called "it" is probably just trolling on "its" part. "It" would probably laugh at the people bending over backwards to accommodate.

3y agoHN ↗

This is the result of most of progressive society saying that it is socially acceptable for a person's preference of expression to mean more than grammar and clearness of communication.

3y agoHN ↗

Perhaps this is just my autism speaking, but am I the only one who gets completely freaked out by sentences like the above?

Hi, fellow autist here.

Yes, it feels like my brain hits some speedbumps with that particular pronoun. I wouldn't say I get "freaked out" though; it's just unfamiliar yet.

Despite what other comments claim, I doubt this is agrammatical. "It" is part of the same grammatical class (the class of pronouns!!) and so fits anywhere "he" or "she" does.

"It" refers to inanimate objects, things which can't have free will

Could you bring yourself to see the choice of "it/its" pronouns exactly as a self-identification with things that feel no agency of their own? I don't know why Maia claims those pronouns, but I'd get this motivation for sure.

3y agoHN ↗

Fairly neurotypical person here. I tripped up on the ‘it’ pronoun, too.

3y agoHN ↗

Competing access needs: autists need regularity, ??s ("the category of people who go by it/its") need ... creativity? chaos? uniqueness? Those goals are at direct odds.

(I'm going to presume here that crimew doesn't actually want to be considered an object, because we don't generally respect objects' pronoun choices. So calling them an "it" in the grammatical way would be paradoxically self-defeating; we call objects he/she all the time and they usually don't complain.)

This is also why I will always defend the use of "they" as valid. There has to be at least one universal pronoun.

3y agoHN ↗

Yes, it's likely that I am more challenged by the grammatically incorrect pronouns than most neurotypicals in this thread, thanks for pointing that out.

A lot of people who like to cry 'transphobic!' may wish to understand that there are people who need accommodation in our society other than trans people, and that heralding chosen pronouns as truly inviolable will sometimes make other people less comfortable.

That said, I have so far managed to avoid any such accusations in this thread, thankfully.

3y agoHN ↗

I fail to see how any of the mentioned pronouns are ungrammatical.

As for competing needs and such, in this case it’s as easy as using she/her (as maia lists that as one of its pronouns), in other cases it’s usually acceptable to use they/them or no pronouns at all. The only thing that is generally absolutely unacceptable is (knowingly) using the wrong gendered pronouns or using gendered pronouns when the person only uses non-gendered pronouns.

3y agoHN ↗

It's not that it's hard in any absolute sense, it's that imposes an ongoing overhead cost on people who may already pay a high cost to interact at all. (Also, of course, a cost on reading discussion about it. (Does that 'it' refer to the discussion or the author? You don't know! Have fun investing effort to work it out, every single time it's used.)

3y agoHN ↗

"It" refers to inanimate objects

It may do so in English, but it is Swiss, so probably also speaks German, where 'it' - 'es' is Genus Neutrum, exactly meaning neutral gender. For example 'the child' - 'das Kind' is neutrally gendered. Hope this makes sense.

3y agoHN ↗

Makes sense, but we aren't speaking German here.

3y agoHN ↗

In English, animals are routinely referred to as "it", and they're obviously animate.

So, at most it could be said that "it" doesn't normally refer to persons... but even that's not true if you include sci-fi in your definition of "English language". When dealing with topics such as non-standard biological sex and/or gender fluidity, older sci-fi works would often use "it" for such people without any implication of non-personhood.

3y agoHN ↗

You have it backwards. Ethical obligations mean unethical things like government blacklists should be leaked in their entirety.

3y agoHN ↗

Maybe I missed it, but what data of normal people was stolen?

3y agoHN ↗

full names, addresses, phone numbers, passport numbers, pilot's license numbers, when their next linecheck is due and much more

3y agoHN ↗

Hacker is anti-capitalist (cool), so I’m not sure they’re concerned with what hat they’re wearing in the endeavor.

Graciously, though, they’re at least feigning caution with handing out the no-fly list.

3y agoHN ↗

Hard agree here, with a qualifier.

Breaking into private S3 buckets because you are bored is not considered an appropriate “Step 1” by the _professional community_ (people who get paid to do this for a living) at large.

Among people who plan to be financially rewarded for their work and also not be in handcuffs, Step 1 is usually to “Get written permission”.

3y agoHN ↗

From the accompanying (and linked) Daily Dot article[1]:

On the list were several notable figures, including the recently freed Russian arms dealer Viktor Bout, alongside over 16 potential aliases for him.

[...]

Numerous names included aliases that were common misspellings or slightly altered versions of their names.

For non-natively-Latin names, the US government is thorough to the point of hilarity in including every possible romanization and misspelling of one, and they list full names not their individual parts so combinatorics ahoy, as well. For example, if you know a bit of any Slavic language written in Cyrillic, browse the Russian sanction lists, it’s going to give you a chuckle.

In all seriousness, this actually makes perfect sense given the prospective consumers of the lists may not have any clue about the languages the targeted people speak. It’s just that the article makes 16 aliases sound vaguely sinister, whereas if you’re a Russian—or, for that matter, a Ukrainian or a Belarusian—that’s just a reasonably low estimate for how many romanizations of your name people may think up. (Not that Bout isn’t sinister as hell.)

[1] https://www.dailydot.com/debug/no-fly-list-us-tsa-unprotecte...

3y agoHN ↗

"On Wednesday, Public Safety Minister Bill Blair said in the coming days, certain travellers, like Sebastian Khan, will be able to apply for a Canadian Travel Number, a unique number they will be able to use when they book a flight to distinguish them from people on the list."

Soon they'll give everyone a number so they can travel. And print it out in physical form too. And call it a passport.

That "solution" seems a bit backwards.

3y agoHN ↗

Shouldn't take much for this to overflow beyond 2**whatever names, which is probably going to be all sorts of fun for the 1970s software probably involved in processing this data.

3y agoHN ↗

... nah, it has error catching, it just won't process beyond that much.

3y agoHN ↗

Relatively off-topic, but I absolutely love the 90s/early 2000s vibes I get from this. I can't remember the last time I saw a webring, much less one with animated logos.

3y agoHN ↗

I spent like 30 mins clicking links lol. brings back old memories of a web long gone. oatmealine's site also convinced me to install cowsay

3y agoHN ↗

This whole thing has made me incredibly happy to see that somewhere, someone out there on the internet is pwning people for stupid vulnerabilities and posting about it on a site that looks like this one. I admit the flashing ACAB really did it for me.

3y agoHN ↗

It's even more entertaining when the people who make it weren't even alive or old enough to understand or have memory of it. It's a bit of a trip for me.

Made me realize that 'vintage' basically means to many people 'things that are before my living memory' and it can literally only be 0 to 5 years back before they were born.

3y agoHN ↗

Anything post WW2 and pre 1995 feels pretty much the same to me.

3y agoHN ↗

I got 1983 vibes of Matthew Broderick owning an airline in 3 easy steps to grab tickets to Paris.

3y agoHN ↗

I love the implication that this random person should be the authority on whether or not I can see the no-fly list.

3y agoHN ↗

I mean she pretty much explains the whole process of getting it. If you're willing to get prosecuted just go get it yourself.

3y agoHN ↗

In the Daily Dot article above:

CommuteAir added that the server, which was taken offline prior to publication after being flagged by the Daily Dot, did not expose any customer information based on an initial investigation.

3y agoHN ↗

I wouldn't be surprised if he gets added to the list as well after pulling this stunt.

3y agoHN ↗

Reading that wiki page, it sounds like he's on his way to a long stint in prison, or worse. Wouldn't be surprised if he gets black-bagged now that he's attacking critical national infrastructure and encouraging others to do so.

3y agoHN ↗

Why do you keep saying "he"? It's pretty easy to respect people's pronouns...

3y agoHN ↗

Someone who continues to deliberately misgender after being told about it - especially using "he" when the person's name (Maia) is traditionally a woman's name - seems to care quite a bit.

3y agoHN ↗

So the fact that she has gained access to this restricted list, has somehow granted you entitlement to it? Or are you implying that every person on that list should be doxed to satisfy your curiosity?

3y agoHN ↗

Wow, actual hacker news.

For once.

Meanwhile, another front page article is some genius asking why there aren’t any cars in 1984.

3y agoHN ↗

They should just send the list to the New York Times and Fox News.

3y agoHN ↗

Maia should try proton mail, it’s fine

3y agoHN ↗

Suspected members of the IRA, the Irish paramilitary organization, were also on the list.

Oof the international politics always come out in things like this. Twitter also publicizes all of its suspensions and bans. There's a Wikipedia article with a list of all the notable suspensions since 2010. It's interesting to see that, contrary to popular narratives, many of the international groups banned were actually far-left aligned.

The list gets really boring the more you scroll down however. The last notable ban was Paul Graham for simply sharing their Mastodon handle. A boring dystopia indeed

https://en.wikipedia.org/wiki/Twitter_suspensions

3y agoHN ↗

The last notable ban was Paul Graham for simply sharing their Mastodon handle.

Paul Graham is a man, not a plural entity.

3y agoHN ↗

Singular they predates singular you in the English language by about three hundred years.

3y agoHN ↗

That doesn’t mean the “they” here isn’t unclear. I wasn’t sure whose Mastodon handle Paul Graham shared. I certainly didn’t think OP meant he shared his own handle.

3y agoHN ↗

To be perfectly pedantic, this should only be confusing if referring to the Mastadon employees. Otherwise, if referring to the non-person entity, singular or plural appropriate syntax would be “it”.

3y agoHN ↗

How do you know that? I know singular they goes a long way back, but this is an extreme claim that I've never heard before.

3y agoHN ↗

They originated around the same time, but singular you was initially only used for addressing superiors/showing respect (using the plural second person pronoun as a singular for this purpose is still a thing in a bunch of languages), a few hundred years later “you” became the standard second person singular pronoun while “thou” fell out of favour.

3y agoHN ↗

A very modern convention is now using “they/their” when a person may not be aware of someone’s preferred pronoun. And even still, I have also seen people abandon gendered pronouns entirely.

3y agoHN ↗

It’s also just far easier to use a plural pronoun to refer to a singular person to reflect the idea that you’re talking about their whole persona, brand, work, etc… and not just specifically the human being, IMO.

3y agoHN ↗

It's also a very old method. In fact, he/she is a later evolution of the English language. "He/his" used to be more equivalent to "it/its". It wasn't until ~15th century that the modern "he/him" and "she/her" fully evolved. "They/them" meanwhile was in full use by the 14th century

3y agoHN ↗

No one speaks in middle english. Dead language rules and customs are irrelevant to modern language norms.

People once walketh befide their mules, but now we gots lambos

3y agoHN ↗

And yet, pronoun ragers cleave to Olde Anglishe in an attempte to rectifye Ye langge. Sadge.

3y agoHN ↗

This train of thought makes no sense. The fact that something originated in Old English doesn't at all mean it's dead. He/She also originated in Old English, just a little later. Should I make fun of people using he/him, she/her pronouns because they're "clinging to Olde Anglishe"? lol

3y agoHN ↗

No one made that claim.

Your comment is non sequitor

3y agoHN ↗

Using they/them as a neutral pronoun is not dead and never died...

3y agoHN ↗

Non-binary people tend to prefer the they/their pronoun too.

3y agoHN ↗

"the suspect jumped in their car and fled the scene"

In English the word can be used as a singular pronoun

3y agoHN ↗

John jumped in their car...

Right, so if you change it, then it's changed and it's different.

Appreciate the clarification

3y agoHN ↗

Yes, I suppose changing things changes them. Appreciate the redundancy.

3y agoHN ↗

Good observation! Hope this wasn't an attempted, and failed, grammar 'correction'?

3y agoHN ↗

It's interesting to see that, contrary to popular narratives, many of the international groups banned were actually far-left aligned.

The list that Wikipedia determines "notable suspensions" is probably not the best gauge to counter "popular narratives". What Wikipedia chooses to highlight is often the sum of actual popular narratives - not simply popular protests [1]- which is sourced almost entirely from the media and then filtered through the culture found among Wikipedia power users.

A raw database of suspensions and their rationale [2] would probably be the only useful analysis.

[1] The people most often protesting bans aren't always the people getting the most media-sourceable attention for their bans

[2] Recent leaks show that that the US state/federal gov employees (and other well connected power players) often sent lists of tens/hundreds of accounts to be banned and Twitter employees often retroactively found reasons to do so when the given reason wasn't justified. So both the rationale and "notable" part both have questionable value for general analysis

3y agoHN ↗

It's also possible that wikipedia (and the editors there of) are more likely to be far-left aligned / knowledgeable -- thus leaving the far-right unaccounted for.

That said, I also see bans of accounts with few followers regularly being far-right (white supremacist jokes for instance). They may just not be able to gather large followings at this point and / or be on alternative platforms.

3y agoHN ↗

he didn't share his mastodon handle, since that had been prohibited; he just said he had one and you could look on his site for it

3y agoHN ↗

contrary to popular narratives, many of the international groups banned were actually far-left aligned.

Massachusetts state police posted a photo on twitter from inside one of the emergency management command post whatever facilities.

In the background was a projector screen showing a web browser and in the toolbar was at least one link to a facebook group for one of the occupy movements.

Of course, no visible bookmarks to any of the state's numerous white supremacist or far right groups.

Those polo-shirt-and-khaki wearing clowns? From numerous accounts by witnesses, reporters, and photos on twitter they received what amounted to a police escort from the public transit station where they all parked, all the way into the city...and then from the transit station to their protest site. And then back again.

See: FBI report from a decade or two ago citing the huge problem with white supremacist groups infiltrating law enforcement.

3y agoHN ↗

I looked at the 2022 ban list and didn't see anything I recognized as "far left" until Elon took over.

3y agoHN ↗

I think it was just that the subthread was mostly veering off topic.

Offtopicness is fine when it's fresh and whimsical but not when a thread gets sucked into old/repetitive arguments.

3y agoHN ↗

????? I just went through the entire table of suspended people and there were almost no far left groups besides Antifa. Most of the suspended were either far-right/alt-right, trump related, doxing related or spreading miss-information.

3y agoHN ↗

Suspected members of the IRA, the Irish paramilitary organization, were also on the list.

A list that details primarily terrorists having terrorists listed on it. Colour me surprised.

3y agoHN ↗

Interesting to see ASCII SOH/STX/ETX in the wild! (^A, ^B, ^C in the .RCV files.)

3y agoHN ↗

Those are pretty standard ACARS messages. It's the only time I've seen SOH/STX/ETX used, probably because originally in the 70s they were designed to be typed used with Telex machines.

3y agoHN ↗

This guy is a (hobbyist?) security researcher who responsibly alerts companies of vulnerabilities.

However are his actions of downloading the no fly list and offering to share with journalists legal? Or does that cross into overreach and criminal activity?

3y agoHN ↗

The fact that they can do it so casually means there's a problem journalists need to know about.

3y agoHN ↗

it isn't a guy and it uses it/its pronouns.

3y agoHN ↗

What? "It" identifies as an inanimate object? This neopronoun thing really is getting absurd.

3y agoHN ↗

Absurd? Maybe, but I’d hate a life without any absurdity.

3y agoHN ↗

I agree with you on this, but I feel a need to note that "it" refers to non-persons, not just inanimate objects. It's perfectly normal to refer to animals as "it", and it is also quite common to use it for babies (and even more common for fetuses). Not that this makes it any less weird to ask to be referred as "it", mind you.

3y agoHN ↗

Thanks for the correction, you're quite correct.

3y agoHN ↗

I've also seen it being used to refer to aliens. What's wrong with letting people choose their pronouns?

3y agoHN ↗

Letting people choose whether to be referred to as men, women, or neutral (perhaps using neo-pronouns or singular them/they) is perfectly fine. But re-purposing existing words with other meanings is not. And "it" has a very specific meaning, one that just doesn't apply to conscious adult people. If I asked to be called "the object" that would not be a reasonable request, anymore than asking to be referred to as "it".

And particularly for "it" and other objectifying language, it has the huge problem that it makes other people uncomfortable. Especially those who overhear without being aware of your preference (imagine sending an email to a new client with text like "in my absence, contact my colleague X, it will assist you, it is an expert").

3y agoHN ↗

This is downvoted, but the homepage really does say "hello i am maia arson crimew (it/she)".

I'd feel uncomfortable referring to anyone as "it" though, as there are some connotations with that :-/

3y agoHN ↗

If they ask for it :shrug: also their tld is literally .gay so I think they’re pretty aware of what they’re asking for with their pronoun preference.

3y agoHN ↗

The page literally says the pronouns are "it/she" so you can call her "she" and no one should be offended, correct?

3y agoHN ↗

Doesn't sound right to me. A normal clause of that form would look like "she/her" and indicate that the pronoun is "she" as the subject of a clause and "her" otherwise.

This would indicate that maia wants to be referred to as "it" as the subject of a clause and "she" otherwise.

3y agoHN ↗

No, you misunderstand. You need to apply some common sense, not rigorous logic.

“they/he” and “it/she” indicate alternatives, whereas “she/her” indicates different cases.

3y agoHN ↗

Both preferred multiple alternatives for nominative case (“it/she”) and preferred single alternatives for nominative and accusative case (“she/her”) are commonly used. When at least one of the pronouns involved are traditional pronouns rather than neopronouns this is pretty clear as to which is being used (though unless they are both standard pronouns, its ambiguous as to the accusative case to use with the neopronoun, but of course it indicates that the standard pronoun and its corresponding accusative form are acceptable, so that’s not really a problem), though if they are both neopronouns it might be ambiguous in theory (in practice, if they are both neopronouns, its always the second nominative/accusative form, not the multiple alterantives form.) Occasionally, you’ll find neopronouns presented in a triplet where the third is possessive case (which really should always be the case with neopronouns, since otherwise you’re left to conjure up your own possessive if one is needed.)

3y agoHN ↗

Isn't "they" wholly inclusive? It is a genderless pronoun.

3y agoHN ↗

It's not good that you are uncomfortable when it asks you to talk about it with its preferred pronouns. It's 2023, it's about time you try to do what it ask you to do. When it tells you its preferred pronouns, try as hard as you can to follow it.

3y agoHN ↗

How dare you call it not good. It did a really neat hack here.

3y agoHN ↗

There's a difference, though, between

This person is female and I'm not comfortable referring to her as 'it' because females are 'she'

and

This person is a human being, and 'it' is used to refer to objects. It's demeaning to call a human being 'it' and makes me uncomfortable

The later is, at least imo, much more defensible.

3y agoHN ↗

In the absolutely fantastic novel Too Like Lightning there was a character that is famous for the life-like dolls made of it. Eventually it comes to term with the fact that its preferred identifier is "it" because it feels more comfortable being referred to as a doll, or inhuman, i.e. literally objectified, than it does with being considered traditionally human.

I also feel uncomfortable using "it" as a pronoun, luckily this person seems comfortable with "she/her" as well so we can just use those instead.

3y agoHN ↗

If someone tells me they are happy and comfortable being referred to as "it", and that situation makes me uncomfortable, isn't that a "ME" problem?

3y agoHN ↗

Why is the discomfort of it not being called it (morally >) than the discomfort of someone who finds it demeaning to use it on people.

3y agoHN ↗

"It" has a pretty clear meaning in English, and it is not as a pronoun for people.

You seem eager to reduce this to "just" a pronoun issue, but it's not the same as calling someone "he" or "she", whatever they might prefer.

No one gets to single-handedly (re)define the English language for everyone else. "It" in this usage does not fall in to normal English usage, other than to mock people. That they want to use it nonetheless or whatever reason, that's fine with me. I will always listen to that and do my best to oblige with that within reason. However, radically different meanings for words in common grammatical structures, for me, falls outside of "within reason". Other people may choose different, and that is fine too.

3y agoHN ↗

It seemed serious, but at this point, who knows any more?

3y agoHN ↗

Knock Knock

Who's There?

It's me, Bill Gates!

"It" has a pretty clear meaning in English, and it is not as a pronoun for people. Therefore you're not Bill Gates or a person.

3y agoHN ↗

Maybe it’s something well know in the us/ gay sphere, but what does it refer to? I get to call the person he/she backwards so she/he feels acknowledged, I get calling one’s/they instead of he because it may be a woman and they will feel discriminated. But it referring to a person?

3y agoHN ↗

My pronouns are you/your.

Whatever you have to say, say it to my face, and not in third person behind my back.

3y agoHN ↗

We are a first person singular we user, to celebrate our freedom from the aristocratic yoke.

3y agoHN ↗

No one is obliged to endure morally sane discomfort for the sake of someone else’s comfort.

This isn’t “I don’t want to call her him because he’s a she.” The person you’re replying to has a very valid discomfort with reducing a person to an object’s pronoun. Completely understandable and defensible and beyond the apparent needs of the author.

3y agoHN ↗

As an older trans person who's been subjected to targeted hate speech in public, I used to be pretty uncomfortable with younger trans people using it/its pronouns. It's understandable, let's give people some grace.

3y agoHN ↗

I can understand that feeling.

When English got rid of ‘thou’ and “thine” those were replaced by referring to everyone with the more polite “you“, that surly helped adoption.

3y agoHN ↗

the homepage really does say "hello i am maia arson crimew (it/she)".

I'd feel uncomfortable referring to anyone as "it" though

In Five Children and It (published in 1902), the "It" of the title is a magical creature. However, one of the characters is a human baby who is always referred to with the pronoun "it". I glossed right over that reading the book as a child, but I found it pretty disturbing rereading as an adult.

However, once rereading the book had called the phenomenon to my attention, I noticed that it's not uncommon for me to want to refer to a generic child as "it". I wouldn't refer to a specific child that way.

So referring to a person as "it" is sometimes the normal thing to do. (And, of course, intensely inappropriate at other times.) On the other hand, the intro appears to specify that maia arson crimew wants people to use "she", an exclusively subject pronoun, as the object pronoun for she. That is deeply unnatural and virtually nobody will be able to comply; it's much worse than using "it" for a person.

3y agoHN ↗

"Child" is gender neutral and was historically neuter when English had genders.

I guess calling a child "it" is impersonal. Calling it "it" to its face is just strange since "it" is 3rd person.

3y agoHN ↗

"Child" is gender neutral and was historically neuter when English had genders.

By 1902, that time was several hundred years in the past.

Calling [a child] "it" to its face is just strange since "it" is 3rd person.

Sure, but I haven't mentioned any such usage.

3y agoHN ↗

However, one of the characters is a human baby who is always referred to with the pronoun "it". I glossed right over that reading the book as a child, but I found it pretty disturbing rereading as an adult.

While it's uncommon today (and I think uncommon even by the time that book was written), use of 'it' for babies was definitely A Thing at one point.

3y agoHN ↗

‘-tsu’ in Japan was used to refer to low caste/outcaste people

Claudette Colvin was called it by the police when she was arrested

But I do have a trans friend who prefers it pronouns so that’s a sample size of one in the opposite direction

3y agoHN ↗

I think a similar case would be if someone black asked you to call them an n word. They may be comfortable with that, but I am afraid others probably won't.

3y agoHN ↗

Why do we only get to choose our pronouns?

I want to choose my prepositions: in, up and above.

Also, my conjunctions are: however, moreover, and whereupon.

3y agoHN ↗

Because we already arbitrarily assign different pronouns to different people, usually based solely on their appearance, and there is no harm in letting people pick which type of gendered (or less gendered, in the binary sense) association they'd rather have.

3y agoHN ↗

There's an easier fix for that, instead of having to memorize everyone's "unique" preference (xy/xor/xeps), change the language to avoid the issue. "They" for everyone is the only logical evolution.

My native language doesn't have a he/she differentiation..

3y agoHN ↗

You don't have to memorize shit. When you refer to someone and they tell you "I prefer pronoun X" just use that pronoun for the rest of the interaction. If you interact with them regularly or they are important to you somehow, you will remember, the same as you remember a pet name or nickname or screenname. If you forget and interact with them again they will remind you. They will likely not be angry if you forget occasionally, and using their chosen pronouns will please them and endear them to you. They only get hurt if you obviously do it on purpose.

It's literally identical to the concept of learning someone's name, yet humans largely don't have a problem with that.

3y agoHN ↗

I don't know about you but I mostly refer to people with they/him/her/his/hers when they are not present.

3y agoHN ↗

What? When you're interacting with a person, you don't need to know their pronouns. They are the first person in front of you, so the pronouns are "you" and "yours".

The third person pronouns kick in when talking about them, to someone else, almost certainly in their absence.

That may happen in writing.

3y agoHN ↗

We also hurl prepositions at people based on their appearance.

"He doesn't look with it": preposition and pronoun.

Oh, and don't get me started on adjectives. If a 5-foot-tall Douglas wants to be called Giant Doug, just oblige.

3y agoHN ↗

I know someone who says... it's pronouns are "it"... and using that really does make me uncomfortable, I agree. I _think_ (it hasn't necessarily told me this directly) that the choice may be intentionally to make people uncomfortable... like, why shouldn't you be uncomfortable thinking about gender? Lots of people are uncomfortable with gender, why shouldn't you be too? I think of it as a sort of art project... I'm not sure if it would be comfortable with that characterization or not. It also understands that some people can't handle this and will accept "they" without being offended, but really prefers "it", so if you're its friend and want to make them comfortable.... (I still don't love writing it even here with anonymous referent!)

I thought it was the right that accused the left of being precious snowflakes who aren't able to handle being uncomfortable ever? Why should you being uncomfortable be a blocker to referring to someone as they prefer, right? Being uncomfortable is part of life.

3y agoHN ↗

Guys doesn't refer to men anymore, it's now a neutral word that can refer to both genders.

3y agoHN ↗

So how many guys have you slept with?

It's not neutral but guys like to pretend it is.

3y agoHN ↗

This is a genuinely clever reply.

I do wonder what a linguist would suggest about these two uses, though. English is a language in which context often changes outcomes.

3y agoHN ↗

It’s clever if you’ve never heard of context.

3y agoHN ↗

It's not clever if you've never heard a joke.

3y agoHN ↗

It's neutral referring to groups, not individuals.

If you approach a group and say "How are you guys?" it doesn't imply an all-male group.

3y agoHN ↗

Depends which register of english.

If I'm in a mixed group down the pub I won't at all be surprised if somebody (usually female) walks up to the table and says "hey guys" as a greeting, intending to include male, female and enby members of said group.

If I'm on the internet I'm not going to try and use "guys" as gender neutral because I fully expect I'd be misunderstood by a decent percentage of people reading if I did.

So I wouldn't say people are necessarily pretending, it's entirely possible they're just used to it being neutral and forgetting that for a bunch of people it very much isn't.

That's socially though - when talking about people I've slept with, I acknowledge I'd expect people to read 'guys' as only referencing the male-identified ones. Though I'm more likely to use 'dudes' for that purpose myself, because confusion around 'guys' can go in both directions.

3y agoHN ↗

Point taken.

There's a difference though between "guys" as an address (which is used by plenty of female-only groups as well) and "guys" as a noun.

3y agoHN ↗

A lot of people say this, and I WANT this to be true because I don't know of a similar term that really works. I don't think most women agree.

When my best friend came out as trans, I struggled to come up with a good way to refer to everyone as a group in a "hey everyone" kind of way. I eventually realized it's a stupid concept all together and walked into the room of my now mixed gendered friends while shouting "SUP CHODES!".

Went over very well. I recommend it.

3y agoHN ↗

As I regularly remind people, "assholes" is a perfectly good gender neutral collective pronoun.

3y agoHN ↗

Interesting to see in which prison "it" will land

3y agoHN ↗

I think you're confused. The main person in the OP is crimew. The Daily Dot article talks about her in the first few paragraphs but towards the end they talk about a different security researcher that came across the same-ish list from a different source

3y agoHN ↗

The laws around digital access to networks are archaic and very broad, they were mostly defined in the 80s and 90s. I believe any unauthorized access (i.e. not having consent from the owner/operator) to a private network is technically a crime. Even if the Jenkins server was open, I bet finding and using the S3 credentials would have crossed the line of the law. Those S3 buckets are private and if you didn't have permission to access them, even if you have the credentials because you found them elsewhere, you could be breaking the law.

3y agoHN ↗

Regards the archaic laws I'm not convinced, they tend to just parallel real world crimes. For example if you parallel it to the real world then the crime of trespass covers the Jenkins server situation (you can trespass on land that is open and easy to access) and you still commit a crime if you enter a house where you found the key on the floor outside the door, which covers the S3 situation.

3y agoHN ↗

Trespass doesn't get you bent over in the shower of a federal prison. CFAA violations do.

3y agoHN ↗

Yes there's clearly a discrepancy regarding punishments but the point I was making was about the initial crimes. I'm also not saying I agree either; certainly a lot of the punishments for crimes in America seem disproportionate to the offences commited.

3y agoHN ↗

Just accessing could also be seen as just looking through the window. And the lack of safety as a lack of curtain.

Trespassing implies a presence, this could be seen as installing some software or code to maintain access on a system.

Now let's imagine the OP went to the airline office and found that the door was open, on a desk there was a printed version of the nofly list, he takes a picture of each page and leaves. He would face 20 times less prison time.

3y agoHN ↗

Yeah as I've said I'm not commenting on the sentencing/punishments, I'm commenting on the offences.

3y agoHN ↗

downloading the no fly list and offering to share

(This is a genuine question) but where's the actual value in having this list?

I'm afraid I regard it as yet another piece of security theatre.

Full disclosure: my passport always fails to scan at the UK Border automated gates.

I had a discussion this week with yet another border agent after getting another "seek assistance" message and having to queue for a manual check.

I pushed for more information on why, for the last couple of years, it refuses to scan.

He suggested it's because I have very common first and middle names (although my surname is not common at all), so let's say I'm called Alice Bob MacQuaffle, someone called Alice and/or Bob is "on a list" somewhere. I would bet a substantial sum there is no-one on any terrorist watch list called MacQuaffle.

This sounds like someone approved a ridiculously broad match, meaning anyone called Alice and/or Bob is inconvenienced every single time they go near a border.

I would prefer to be safe when travelling just like the next guy, but matching watch lists using common first names ... only .... really?

3y agoHN ↗

It’s trivial to change your name in the UK so this is bonkers.

3y agoHN ↗

We can be pretty sure it's not to protect anyone. Anybody too dangerous to allow on an airplane should probably be behind bars. What it does accomplish is letting the government punish people without justification let alone a trial and with pretty much no transparency or consequences when innocent people end up being hurt by it. I imagine that's a power which is hard to surrender, and 'we the people' haven't exactly been insisting that they give it up either.

3y agoHN ↗

Anybody too dangerous to allow on an airplane should probably be behind bars.

Someone who the US deems a danger but isn't in the US would fit this criteria.

3y agoHN ↗

Someone who the US deems a danger but isn't in the US would fit this criteria.

If the bad person isn't in the US there's no need for US airlines to maintain a list of them which prevents them from getting on a plane, but then just sends them on their way to arrange other travel plans. What we want for really bad people outside of the US who should be arrested on sight at airports are warrants. Signed by judges. Not secret lists with no oversight or transparency, and not sending dangerous people back out into the American population.

3y agoHN ↗

Someone who the US deems a danger

Someone who is apparently so bad they can't be allowed through airport security into an aircraft, but only if that aircraft is travelling to or within the US?

Yet someone who is apparently so innocent they can't be arrested/detained/charged with anything, anywhere, and so are free to travel the rest of the world.

It sounds ridiculous even just typing that out.

3y agoHN ↗

No passport in my family of 4 successfully scans at those gates, fwiw.

3y agoHN ↗

I digged a little into this and to my understanding did she never actually 'hack' but just used publicy open data in a smart way which apparently is not illegal under swiss law.

3y agoHN ↗

Interesting hack, but this seems quite the brazen confession to a fair number of computer crimes. If I were the author, I'd be worried about getting arrested and potentially extradited for this. Especially as he deliberately downloaded a load of confidential information after gaining access, and then shared it around. He'd be looking at years in prison for this, in the US.

3y agoHN ↗

She’s already potentially facing US extradition from Switzerland for unrelated computers crimes. No idea why she would publicize this exploit.

3y agoHN ↗

Switzerland's federal constitution prohibits extradition of swiss citizens to foreign powers. Now technically, this one amendment can be overriden by a mere act of Parliement, so unless there is a special act I'm not aware of, they are safe.

3y agoHN ↗

She's Swiss and the US already tried to extradite her for posting stuff on git.rip

3y agoHN ↗

I expected to read an article about actually owning an airline in 3 easy steps. :(

3y agoHN ↗

I too was at first annoyed by a bit of an overhyping in the title and the overall style as well, until I remembered how it felt when you discovered something yourself, or even just read a good clever report from someone else. You get this rush that this is the coolest craftiest thing in the world.

3y agoHN ↗

Indeed, the de-editorializing of the title made the interpretation more ambiguous. I'd actually prefer the real title ("how to completely own an airline...") or a more clear adjustment ("how to hack an airline...").

3y agoHN ↗

I was disappointed too. I wouldn't know what to do with an airline, I never had one, I wouldn't even know which one I'd like, perhaps Virgin Airlines?, but the thought of having one was exciting still.

3y agoHN ↗

I guess we do need the verb 'pwn' after all :D

3y agoHN ↗

you're....actually right. I totally misread this headline. There were no context clues to help with the reading.

3y agoHN ↗

I imagine it's something like Richard Bransons How to become a millionaire:

1) Be a billionaire

2) Start an Airline

3y agoHN ↗

I actually expected this to be "buy a bankrupt airline for ~nothing, and, oops, look, it still has a copy of the no fly list", to be honest...

3y agoHN ↗

Yep, that's exactly what I thought on first opening the article.

3y agoHN ↗

For Musk's $44B Twitter bid, he could theoretically have purchased Delta, United, and American airlines.

3y agoHN ↗

As a software engineer even I sometimes can't help romanticising hacking in my imagination. But so many times it turns out to be just like some company left the front gate wide open and the "hacker" walked in and took a look around.

Eg when an airline had a public API where you could get someone's passport number and details just from their boarding pass https://mango.pdf.zone/finding-former-australian-prime-minis...

3y agoHN ↗

Private keys checked into code?

Password salts that were identical for the entire set?

"Random" initialization vectors always created from the same prng seed?

Without coders like these, hackers would really have to work for it.

(And, yes, I've encountered all of these in my career.)

3y agoHN ↗

Since when are passport numbers supposed to be sensitive information? This isn't something you could use for identity fraud in any normal circumstances.

3y agoHN ↗

Don't all sorts of person-related details come in handy to stage a social engineering hack? Maybe a caller could demonstrate legitimacy by coughing up a passport number. At this point, it may impress me more than someone having found my SSN (_love you for that, Equifax_). Yet, SSN is still by many institutions considered something that should be stored in the vault.

3y agoHN ↗

Don't all sorts of person-related details come in handy to stage a social engineering hack?

Maybe? But also maybe not really?

Passport numbers change very frequently, nobody uses them to identify people.

3y agoHN ↗

I don't know if you are joking or I need to break it to you that in most cases passports are the de facto identification for foreigners and passport S/Ns are being used as part of identification procedures.

3y agoHN ↗

I don't know if you are joking or I need to break it to you that in most cases passports are the de facto identification for foreigners

As a perpetual foreigner I've never had to use my passport number for identification.

passport S/Ns are being used as part of identification procedures.

Where?

3y agoHN ↗

In the US there are basically 2 forms of ID cards currently, one says “Federal Limits Apply”, the other does not. The one that says “Federal Limits Apply” requires a backup identity document to verify in some cases like buying a gun, or flying. Passports are often used, and while the TSA is going to verify the info on the passport, others likely will just verify if it looks real enough or check that the number actually exists and go no further.

3y agoHN ↗

They change frequently? My passport is the longest-lifetime form of ID I'm offered, the absurdity of using Social Security Number as an ID aside. Most passports last for 5-10 years in my experience, and I'm not sure the number changes when you renew it.

3y agoHN ↗

I'm not sure the number changes when you renew it.

Of course it does. Numbers used to identify people generally don't. Passport number identifies the individual document, mostly so it can be checked against INTERPOL's SLTD database.

3y agoHN ↗

Ha! Loved the linked story. Thanks for posting.

3y agoHN ↗

Eg when an airline had a public API where you could get someone's passport number and details just from their boarding pass https://mango.pdf.zone/finding-former-australian-prime-minis...

Underneath all the garbage, good story. But Holy Hell, why do bloggers write so terribly and self-indulgently? That's a half hour of my life I'll never get back that shouldn't have been more than 10 minutes. Don't they have Ritalin in Australia? They really should.

3y agoHN ↗

Aussie, can confirm. They have Vyvanse, Dexamfetamine, Adderal and Ritalin. I didn't mind reading this one though, was a novel change to see sentences starting without capital letters.

3y agoHN ↗

You could just say you don't prefer the writing style.

3y agoHN ↗

They did, in their own writing style that you don't prefer!

3y agoHN ↗

I had always assumed that the “no fly” list was a phrase and that it didn’t refer to an actual list, but rather a database with more detailed information than a “can they fly?” Column with a Y/N entry. In pharmacy we have a database we have to access when we suspect there is abuse, fraud, or diversion of controlled substances. The database is regularly updated with current information about prescriptions that were dispensed including location, prescribing physician, etc. I had always assumed the “no fly” list would be something similar. Now that I think about it though, that wouldn’t be efficient or useful at all. It would make sense for it to be much more simple.

3y agoHN ↗

yeah, surprised as well. In finance, there is ofac for people forbidden from moving money, but it's also typically used as a service/db instead of passing around csv files to everyone. Very bizarre.

3y agoHN ↗

Could this have been an export given to someone upon request? Or maybe served as backup?

3y agoHN ↗

There are various aggregators who combine this list and a bunch of other sanctions/related lists like the BIS Entity List which is probably what he was referring to.

3y agoHN ↗

Have you ever witnessed this file being used by companies moving money stored in S3 as "shitlist2019.txt" for screening incoming transactions in production? Because that's what the article is alluding to.

3y agoHN ↗

No, but I have seen it being ingested and turned into some horrendous XML on a weekly basis.

3y agoHN ↗

I naively thought a secret list (file) with secret data is not distributed among random developers of random organizations in full but having a private access point where specific persons could be checked for no fly list by those with right for it, audited, with measures to avoid abusing the service. Potentially with training set available for developers separately. There are services where the accuracy of certain data can be validated (i.e. for cars by license plate and other data) so those who query should already possess the data of a particular person when using it and not just browse everyone in the secret list they please.

3y agoHN ↗

Every company keeps its list or it´s a USA government list?

3y agoHN ↗

Network connectivity in airports can be patchy at best, and connectivity from the airport internal network to the internet even worse. All the check-in and boarding systems are designed to be able to work offline (with semi-automatic reconciliation afterwards). You have to query the no-fly list at check-in and boarding, so it's more resilient to have a list that can be loaded airport-side every morning

3y agoHN ↗

Why can't the TSA run an onsite cache in a secure IT closet?

3y agoHN ↗

I had a friend with a common Indian name get bounced off a flight and then be unable to book flights after it turned out he shared his name with someone on the no-fly. He had to petition his senator/congress person to get off it. TSA had no easy way to prove innocence. It was very clear the list was just a list of names with no useful or distinguishing unique fields with it.

This was roughly 10 years ago, so things might have changed, but at the time it seemed like federal agencies could easily append to the list, but there was no standard process to get off it. I'd guess there are obvious incentive for agencies to add ("hey look, we've found terrorists", even if nothing was actually done about it), and none to remove people from it.

3y agoHN ↗

`cat` aliased to `bat`, nice. :) I really like bat.

3y agoHN ↗

After seeing the title but before clicking on the article, I thought this would be about a legal hack rather than a security hole. More specifically, creating the minimum possible corporation that qualifies as an airline (so that you literally own an airline), and then saying to the government, "hey, we need the nofly list, we're an airline, see?". The actual hack sounds way easier, to be sure, but I still like my version the best.

3y agoHN ↗

I came here to make the same comment. Also, I now know that .gay is a tld and I'm trying to figure out how to take advantage, registration isn't terribly cheap, but the only restrictions are ones that don't apply to any of my ideas.

3y agoHN ↗

Apropos of nothing, I also just really appreciate crimew.gay's aesthetic.

This website is what me from 1993 thought a hacker's website would look like. A nod of respect to them for kickin' it old-school.

3y agoHN ↗

And they were born in 1999. We are dealing with a unique mind here.

3y agoHN ↗

In reality it’s like a kid listening to the beatles, but with computers. I’m a younger millennial that grew up entrenched in ‘hacker culture’ and even then there was a clear fetishisation of the good ol’ days.

3y agoHN ↗

Like people using eMacs or vim these days

3y agoHN ↗

Not to start a flame war, but no, people use vim and Emacs because they're productive with them. I've certainly tried alternatives like vscode seriously and find I prefer vim.

3y agoHN ↗

Arguably you need a bit of fetishization to get started with them though.

3y agoHN ↗

Or just start early. I learned vi in Uni as part of our course and it's always there so I keep using it (but not solely).

3y agoHN ↗

In my case, it was using Linux distros pre-vscode that got me into emacs. In that era, your choices for general-purpose developer-oriented file editor were (a) emacs, (b) vim, (c) something that was ported from another OS and either running in an emulator or running atop a library stack that barely worked on your architecture and would take like thirty seconds to boot up.

3y agoHN ↗

Or nano/pico for the biggest, but there were other options available. Midnight commander has an editor, too.

3y agoHN ↗

vscode didn't exist when I learned vim, and Visual Studio was only on Windows, and I had seen demonstrated that people using vim seemed to be a lot faster manipulating and navigating code.

3y agoHN ↗

Amusingly, "they" is not one of the pronouns it prefers.

3y agoHN ↗

“They” is a perfectly acceptable pronoun when you don’t know somebody’s gender, or preferences.

3y agoHN ↗

Sure, but we do, half the thread is arguing about the validity of it(s) pronouns.

3y agoHN ↗

Feels like a passing of the generational torch as elsewhere in the thread there’s large arguments about pronouns while younger people who are way past that are out here getting into wide open Jenkins servers for active airlines lol

3y agoHN ↗

Didn't know you could tell someone's age by their comments.

3y agoHN ↗

I think you're misunderstanding a few things, particularly the nature of commentary.

People comment mostly when they think they have something topical to add that hasn't been said. And pronouns are something people feel much more able to have opinions on that doing scans for open servers.

The vast vast vast majority of people of any age won't comment at all.

Good rule of thumb: NEVER assume that the views of commentators are in any way representative.

3y agoHN ↗

Not sure if amusing but referring to someone as "it" makes it seem like an insult. I realize (per the bottom of the wiki article) that those are the chosen pronouns but still.

3y agoHN ↗

Consciously using retro design is very much a thing in industrial design, architecture, and so on; it only makes sense that it would come to websites, too (and indeed you'd expect younger people to be doing it; most retro _anything_ takes inspiration from a time period before the designer was around).

3y agoHN ↗

Oh hell yeah, I turned off my dark mode extension, much better now. Thanks!

3y agoHN ↗

I love the .gay TLD! Had no idea it existed and now I want to register some domains against it

3y agoHN ↗

I agree with you, but probably in the 90s would have been a bit darker/greener :D But nice website brought me back in time ^^

3y agoHN ↗

This site is part of the lavender.software webring!

A webring! I'd completely forgotten that these were a thing.

3y agoHN ↗

"An elegant social network, for a more civilized age."

3y agoHN ↗

And the s3 buckets/dynamodb/whatever other data you store should be vpc restricted. Ours are like this by default, for exceptions (like aws services that run in some internal vpc that's not exposed) you can make an exception per role.

3y agoHN ↗

Hey all im new. Didnt expect so many of yall to actively check & comment on this one app

3y agoHN ↗

TIL https://en.wikipedia.org/wiki/Maia_arson_crimew

In March 2021, crimew was indicted by a grand jury in the United States on criminal charges related to her alleged hacking activity between 2019 and 2021. The charges were unrelated to the hack of Verkada. Her home and her parents' home were raided by the Swiss police at the request of United States authorities, and her electronic devices were seized. People used the hashtag "#freetillie" to express support for her in the aftermath of the raid, and the Swiss magazine Republik compared her to Jeremy Hammond and Aaron Swartz.

3y agoHN ↗

What a Wally. What purpose did it serve doing this?

3y agoHN ↗

Are you asking, what purpose was there in bringing the hammer of the American Justice Department and down onto a random grey hat hacker? The same as always: enforce rigid authoritarianism and blind bureaucratic SOP.

Remember kids, clicking the "next page" button on court document websites is legal, doing it with javascript is a felony, off to jail with you, join the rapists and murderers!

3y agoHN ↗

They could also be talking about the Apple email leak caused by incrementing an UUID.

There's probably other notable cases with the same failure mode.

One of the things you learn working in computer security: history doesn't repeat itself, but it does rhyme.

3y agoHN ↗

history doesn't repeat itself, but it does rhyme.

I do like Mark Twain

3y agoHN ↗

Ah, yeah, that's where I heard it from first. Thanks!

3y agoHN ↗

Nah history in information security repeats daily. How many unsecured mongodb databases exposed to the internet and unsecured S3 buckets did we see? Credentials have been committed to github so often that Github chose to build an automated alert system on their own dime that you don't even have to sign up for. How many times have lastpass and Experian been breached? How often do we STILL see sql injection attacks, a problem that has been actually solved for decades?

3y agoHN ↗

How such supposedly talented hacker end up to be doxxed? It's not that hard to become 99.99% anonymous online...

3y agoHN ↗

Technically easy, operationally virtually impossible - everyone will slip up eventually.

Also, the need for recognition often drives any human endeavour - and that leads hackers, criminals, etc to boast of their exploits to at least someone … who might be under observation, or under pressure to give up information to escape severe punishment for their own activities.

3y agoHN ↗

Prolly the need for recognition because if you hack from public wifi with tails tor mullvad, brand new laptop with specific hardware and so on I don't see how you can get caught up

3y agoHN ↗

Don't forget the time machine to go back to warn past self about the one time they slip up just prior to when they decide to really go all in on the haxoring.

Some parts of the internet never forget, and the anonymous graph is only anonymous if all of it is anonymous. 99.999% isn't good enough.

3y agoHN ↗

No doxxing was necessary, Tillie did it all publically, publishing on a home server, making announcements on Telegram under their real name. I don't quite get it either, but they specifically didn't want to hide in (pseudo)anonymity.

3y agoHN ↗

Can Confirm. I was big into telegram communities at that time and joined when her group was public. I have nothing to prove because I delete all my stuff but the indictment shows screenshots and transcripts from the group. She literally posted selfies on Twitter sometimes.

I don't agree with most of her more radical views and find her methods to be too extreme, but she clearly stood behind them and didn't hide

3y agoHN ↗

crimew's stated viewpoint and goals are "radical transparency". Hiding her legal name would go against this goal. It has nothing to do with competency and everything to do with her worldview.

3y agoHN ↗

Laws are written to protect multibillion corporations and billionaires. Prove me wrong.

If we truly lived in a sane society, companies with lax security and god awful security policies would be punished.

3y agoHN ↗

Depends on the country.

Mine was founded by some overseas family that can still come over and start telling us what to do as they please.

So uhhh, yeah, can confirm, Canada’s laws basically revolve around keeping old money wealthy without providing any value to anyone.

3y agoHN ↗

The British Crown hasn't had real power since 1649, but please continue complaining about nothing.

3y agoHN ↗

No you just (by constitution) have to swear allegiance to the crown to become a lawmaker, which makes you a perjurer if you don't acknowledge their power.

Also is the monarch not commander in chief their armed forces? I thought being under the command of the queen / monarch was part of their oath. If your soldiers are sworn to do what the queen says that seems like a lot of potential power.

3y agoHN ↗

Yeah, it's crazy to me that the UK has no armed forces, the military are all personally bound to the monarch. The king has interfered in politics too, so arguments based on royalty not being active are off to a bad start.

3y agoHN ↗

It's hilarious that even though I think my comment was misread, it turns out I think we both are right.

You read it as me talking about the military in the UK.

No I was talking about the Canadian military. They are bound to the queen and swear an oath to such, you know the one that lives in the UK.

It really illustrates the absurdity of the situation.

3y agoHN ↗

Ah, I suspected you were talking about Canada, but wasn't sure if it might be Australia. I guess your situation is more absurd.

3y agoHN ↗

There's still a 10% difference in wealth on average between people with noble Norman family names and everyone else in UK.

3y agoHN ↗

So if I leave my front door unlocked, I should go to jail when someone steals from me? What nonsense.

3y agoHN ↗

Probably not. But if you owned a warehouse and you left it unlocked without security, and someone steels from it stuff that is owned by somebody else, then maybe you are liable somewhat.

3y agoHN ↗

Your front door and the items in your house are not analogous to having sensitive information on a machine connected to the internet.

3y agoHN ↗

Please don't complain that a submission is inappropriate. If a story is spam or off-topic, flag it. Don't feed egregious comments by replying; flag them instead. If you flag, please don't also comment that you did.

If you feel it's appropriate, flag the comment.

3y agoHN ↗

So it’s OK for individual vigilantes to punish them, am I right?

3y agoHN ↗

Yes, punish the victims is the best policy.

3y agoHN ↗

There is very little if anything similar between the subject and Aaron Swartz

3y agoHN ↗

Exactly. There is a whole infrastructure of sympathizer-nuts, similar to US politics.

3y agoHN ↗

Doubt it. The US would very much love it to fly pretty much anywhere outside Switzerland so it can be extradited.

3y agoHN ↗

Hah shodan, the title made me think this was about starting a dummy airline and getting the nofly list from the government.

3y agoHN ↗

I'm not confident that is it safe to link to the site operated by such hacktivist. I prefer to see link for news article on HN headline, rather than criminal hacker's website itself, but I don't know rules.

3y agoHN ↗

And this kids, is why you always need 2FA and you need to whitelist your build servers with ipranges. Yes Like the 90s.

3y agoHN ↗

Surprised to see this guy wasn't already in prison due to his previous antics, and it's too bad he didn't responsibly report this issue through the proper channels. Everyone's luck is bound to run out at some point.

3y agoHN ↗

Oh it must be nice to be able to do things like this, while only keeping an eye out for the laws of your own country, safe in the knowledge that your government won't extradite you for breaking the laws of another country.

3y agoHN ↗

The TSA no fly list is a blatant violation of the Constitution: for the government to be able to remove a right, you must be convicted at trial.

The fact it still exists at all is incredible, but a disturbing precedent.

3y agoHN ↗

Was there any penalty for CommuteAir or their employees for negligently distributing the list?

3y agoHN ↗

"That would be the gayest site I've ever seen" :D

Seriously, though, is the list on the github yet?

3y agoHN ↗

Hack aside, there's something poetic about leaking the no fly list from an email address called "nofly@crimew.gay"

3y agoHN ↗

The headline made me think this was about a scheme where you register as an airline, just to get access to the list. I mean, how many planes do you need to own to be an airline?

3y agoHN ↗

This would be a good candidate for a k-anonymous API where you can query if a specified full name, DoB, etc., is in the list without divulging the list or the request.

3y agoHN ↗

This is gonna be random but I love people just shamelessly being themselves on the Internet. This person is literally a kitty cat playing around and I find that adorable~

Oh, also secure your Jenkins servers.

3y agoHN ↗

Why is the no fly list sensitive information?

3y agoHN ↗

assuming i was willing to ever interact with a SOAP api in my life which i sure as hell am not

^^^ this killed me. i'm sure everyone who has ever interacted with a SOAP api feels the same. god bless this tiny kitten/person/hacktivist, the world needs more of this energy.