Hacker Newsnew | past | comments | ask | show | jobs | submit | lschueller's commentslogin

Firstly, very cool to stay curious and to aks around publicly. I think, starting with ARP spoofing is a great way to dive into the topic. There are a bunch of youtube videos, explaining this and I made the experience, that there are channels I like way more than others in terms of how they present those concepts. David Bombal, and in this case, Certbros is always worth a visit. Than get a package tool like wireshark or for a more easy-to-start-with-alternative Sniffnet and undetstand how traffic flows and how the things explained in videos and article actually happen in real life. Then level up and get your hands on the actual tools for arp poisoning. But be aware, stuff like that is very easy to track back, if used on people or devices, who would call the cops. Like wifi hacking in general. Easy to do, tempting to try it at your neighbors, but almost certain to get very fast in real trouble with your isp and the police. So, stick to experiments at home.


Thanks a lot, will check them out ;)


Seems to be a 404 now.


Nicely put together. As mentioned in the article, HR might not be a help at all. I for myself would even make the stronger point, that hr in almost every case doea not have any interest in getting involved in such things.

My experience is in general, sooner or later there is an opportunity to talk with the problematic colleague and this is very often the moment, where relationships change to a better. Avoidance looks easy, but often makes things worse in the long run.


HR isn’t neutral, and it’s definitely not an advocate for employees. It exists to protect the business (potentially from lawsuits). Their job is to resolve the situation in a way that protects the organization, which sometimes overlaps with helping employees and sometimes doesn’t


If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.

Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)



Among these runbox is quite good and my friend has used migadu for a few years and likes it even though he says the "soft" limits still make him uncomfortable even though so far he has never hit them; so I guess that should be fine. Posteo doesn't support custom domains (I've used them and otherwise they are good). I wouldn't go with Proton ever. Mailo seems new - never heard of them. Would love to get a review.

mailbox.org can be avoided if you need to send and receive emails from domains where the mail admins might not be email admin savants and/or privacy activists (sometimes that's not a choice in case of Govt services etc and you may not live in a country when you can get those changes done). Also, if you ever face an issue and send them an email, expect the reply to come in weeks (if you are lucky) and that too a flippant (sometimes even terse) nothing-mail and then if you respond the cycle repeats until you give up.


What do you use now?


Splendid, thank you. the european-alternatives.eu is exactly what helped! Appreciate it!


Depends on the definition and your threat model but to make a very large story short; it’s email, others have copies (your gmail friends?). Metadata is public by default the body can be encrypted and encrypted at rest (comes with many limitations) and that’s the highest level of security you can realistically achieve.

If that works fine if not, use another method of comm. Email wasn’t designed to be secure.


Thank you. Sure. In Europe the "euro stack" approach becomes more and more relevant. So, the issue is more a compliance topic in the way of making use of service provides, who are best-case "eu-headquartered", but at least with a guarantee that processing on my side stays within the european realm. Doesn't mean very little in a technical understanding of security, I agree.


I do not know any EU-only, but ProtonMail is in Switzerland.


Proton is leaving Switzerland because of surveillance and privacy issues.

> Because of legal uncertainty around Swiss government proposals to introduce mass surveillance — proposals that have been outlawed in the EU — Proton is moving most of its physical infrastructure out of Switzerland.

https://proton.me/blog/lumo-ai

They are moving to Germany, but will quickly find that they are going to face the same surveillance and privacy issues since the EU is in the process of negotiating a data sharing agreement under the US Cloud Act.

https://www.justice.gov/archives/opa/pr/justice-department-a...


That was 2023 before the 2nd Trump Admin and before the Privacy and Civil Liberties Oversight Board that was supposed to be independent and protect against abuse has resigned.


Some cool ideas. But do you have actual numbers by any chance? Like, wp login attempts per month, ssh connects etc. Just curious, what actually worked and how the measures compare


I've looked at how to characterize the ssh tarpitting, and I'm not sure how to do it. I haven't put serious thought into characterizing WordPress logins at all.


Wouldn't be super surprised if their ip lawyers already sent a legal title about trademark violations... Some big companies are very fast in tracking such similarities and enforce 800 to 2000 in restitution per violation.


I'd guess someone in the us fat-fingered ip ranges and mixed up 2.144.0.0/14 (Iran) with 2.148.0.0/14 (Norway)


Or someone entered 2.144.0.0/14 but on a machine without ECC and a bit-flip happened, turning it into 2.148.0.0/14.


Or they tasked a frontier AI with it.


and it hallucinated


I do think, there is. But just software, which is only used by the person who vibed it. And which never gets out to a broader public.

Beyond that, you are right.


An API for reporting would be nice. Besides that: hope this page came to stay. It's nicely done. Couple of years ago there was a very similar project here on hn, which came to a halt after only a couple of days it got posted


I'm afraid not. My impression is, most are just prompting for the tool they need right now, accept bugs and maybe even security gaps, but save time and pain not searching for an established tool. Which is fine and understandable for private things. But I wonder, how often this happens in professional environments. But maybe I'm just wrong... I have not seen any resarch or evaluation for this claims. Would be interesting, though


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: