Hacker Newsnew | past | comments | ask | show | jobs | submit | okso's commentslogin

A few observations:

- Registrar: HOSTINGER operations, UAB, Lithuania. Hostinger-branded authoritative DNS servers run on Cloudflare’s network. This creates a dependency on a US company.

- IPv6 is not supported by the public website/Git endpoint.

- DNSSEC would be a great addition for security, especially due to the use of US-based Cloudflare and Let's Encrypt.


Lack of IPv6 is especially disappointing. Means you'll need IPv4 connectivity for your CI servers and other such infrastructure. :(


The Pebble Index 01 is being sold as "Customizable and #OpenSource" on https://repebble.com/index

Apparently this was never the intention, as Core Device's founder Eric Migicovsky wrote in a GitHub issue that unlike all advertised, the firmware is closed source.

Official website: "Like all Pebble products, it’s extremely customizable and built with open source software."

Eric Migicovsky: "oh right, that's also closed source (friend's repo). sorry!"

This is deceptive advertising and dishonest.


Found about this new window compositor on Phoronix, could be a revolution in the field.

Project site: https://nourish.snowies.com/ GitHub: https://github.com/y5-snowies/nourish


The Mullbad Browser? https://mullvad.net/en/browser


Or tor browser, where all the features came from. You can also enable it on firefox with privacy.resistFingerprinting enabled.


> You can also enable it on firefox with privacy.resistFingerprinting enabled.

Not the same thing.

I use both Firefox and Mulllvad Browser side-by-side on a regular basis and in practice Mullvad Browser is far more aggressive in its privacy preserving measures to the extent that you do sometimes stumble across websites that are "broken" in Mullvad Browser but work fine in Firefox, for example the animated map features on the Ventusky website (which, IIRC, breaks because Mullvad is more aggressive at blocking JS graphics functions).


FYI here are the listed differences between Firefox-/Tor-/Mullvad Browser: https://mullvad.net/en/browser/hard-facts


LLMs are getting very good at packaging software using Nix.


Then you're committing to maintaining a package for that software.

Like all LLM boosters, you've ignored the fact that the largest time sink in many kinds of software is not initial development, but perpetual maintenance.


It's not materially any different from maintaining lines in a Dockerfile.


It is mateirially different compared to "maintaining" the line 'RUN apt-get -y install foobar'


Is it though? If the way that I’m going to edit those files is by typing the same natural language command into Claude code, and the edit operation to maintain it takes 20 seconds instead of 10, to me that seems pretty materially the same


Yes, it is


How so?


This. I wouldn't have touched Nix when you needed someone who was really good at Nix to keep it working, but agents make it viable to use in a number of place.


Would a transparent OLED display not provide a better visual quality ?


I would expect that to break the "visible from any angle" feature, as you would see the image in reverse from the other side of the circle?


macOS only (uses Apple Vision framework)


I've used SikuliX[0] in the past for similar purposes. Unfortunately the author hasn't had much time to maintain it recently.

[0] https://github.com/RaiMan/SikuliX1


I am dreaming of an open-source app that adds Wireguard capabilities to NetGuard or vice-versa.

Having to switch from one to the other is very annoying.


There's no need to dream about it, it already exists: https://f-droid.org/packages/com.celzero.bravedns/

I used to use it when I wasn't on grapheneOS and needed to block internet access.


That only uses wg for DNS queries. Everything else remains untunneled.


From what I see running the test on my phone, there's an option to tunnel DNS through Rethink here, which you can change to the VPN's DNS. Everything else is tunneled by default through wireguard. Maybe there's a configuration issue on your end?


The only place I see where wireguard can be set up is as a proxy for DNS. Perhaps that would still allow changing the default gateway?


It's annoying to see so much RethinkDNS propaganda on every Netguard or Invizible Pro thread on the internet.

That gives me a bad feeling, and it's the reason I started to consider RethinkDNS scummy.


Was the above post propaganda? Or was it just a user recommendation?

Perhaps the reason it gets mentioned often is simply because it's a good piece of software. Then again, perhaps not!

In any case, I'd be careful about using 3rd party DNS (and other) services, but that's for the user to decide, depending on the situation one is in.

Using one's own resolver is always a good practice, even in countries where ISPs are not selling customer's private data to anyone that comes along and where governments don't monitor and repress their citizens on every step...

We live in strange times where even EU countries misuse resolvers to censor certain web pages, while, for example, independent Balkan countries do not. Go figure...


I didn't intend for this to be propaganda, I don't even use it anymore since I'm on grapheneOS now. But I have tried all three. I need to use a VPN in split mode for certain apps, and since using Tor with apps wasn't part of my threat model, I ended up using RethinkDNS (the app only). I don't necessarily like their upstream DNS servers, but considering that I can use my own server (and do), I don't consider that to be an issue.


especially that Wireguard silently disables NetGuard, and then the communication undergoes (at least in my case) silent


Installing NetGuard was revelation regarding the amount of tracking in most Android apps.

You can configure it to block access by default and notify you every time an app attempts a new connection. And it rings all the time.

Some software call home at 4am every day, other every hour, some send data to a dozen "analytics" services - services that I never opted-in for, which shows how few apps respect the RGPD.

At least most apps still work when those are blocked, and NetGuard allows you to block connections to Google servers except for Google Apps, which network firewalls and DNS solutions can't.


> NetGuard allows you to block connections to Google servers except for Google Apps, which network firewalls and DNS solutions can't.

How do you know those connections are blocked and not merely bypassing Netguard?


I am using GrapheneOS. GrapheneOS has a compatibility layer providing the option to install and use the official releases of Google Play in the standard app sandbox.

See https://grapheneos.org/features#sandboxed-google-play

NetGuard also shows network requests from GrapheneOS itself, all proxied by the GrapheneOS project, as described here: https://grapheneos.org/faq#default-connections


I could see how they are blocked on your system, using GrapheneOS, but that doesn't tell us if Netguard blocks them on Android systems. One reason for GrapheneOS is to close that kind of hole.


> Some software call home at 4am every day

Which app?


Not sure anymore since I removed them, it may have been BlaBlaCar and/or Tricount.


[flagged]


I'm curious, how would looking at the Microsoft MFA app convince me that android apps aren't spying on me?


[flagged]


You did the same thing above but in the opposite direction.


F-Droid only packages open-source software and rebuilds it from source, while installing from Accrescent would move all trust to the developer, even if the license changes to proprietary.

I understand that the author trusts itself more than F-Droid, but as a user the opposite seems more relevant.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: