Hacker formerly know as doxx. Builder. Artist.

Joined July 2006
42 Photos and videos
This is only going to get worse. Adults should be allowed to use their devices anyway they want. Parents should control their kids content not old men with no tech background writing laws!
Ha llegado el día: mi teléfono Apple, de más de 1.000 €, ha dejado de ser mío y de obedecer mis intereses. Un teléfono inteligente que se ha revelado en contra de su dueño y se ha convertido en un pisapapeles por voluntad propia. Espero que más gente se oponga a esta vigilancia masiva. No habrá más oportunidades.
58
I’ve seen their storage arrays in the United States and it’s unreal. They have full city block sized disk arrays saving what appears to be everything. It’s insane.
Reminder: Telegram is not a secure messaging app. It is a plaintext database.
1
104
The current internet is a mess due to NAT and CGNAT; the idea is the Internet can be both open and private at the same time. The best part of the Internet is there is no privacy and the best part of the future is there can be both at the same time.
1
68
I've started multiple companies around global traffic: DDoS mitigation, large-scale video streaming, network visibility. When I say the current internet wasn't built for privacy, it's because I've spent 20 years staring at its guts.
4
227
From a threat-model perspective, a random VPN exit node is often worse than your ISP: less regulated, less accountable, and more incentivized to quietly monetize whatever they see. Exit nodes that are not network controlled by the VPN provider are honey pots.
1
76
The industry loves to point at one or two heavily audited providers as proof the model is fine. Meanwhile the long tail of "no-log" services ranges from sloppy to outright hostile. Continuous audit by AI will show the true extent of their depravity.
1
102
Researchers found most mobile VPN apps leaked traffic, and a chunk didn't encrypt at all. Leaking is easy because most VPNs don't support IPv6 properly. That leaks real quick on mobile networks. Their behavior is gross. It's clear NordVPN leaks everything because they allow CloudFlare to decrypt their traffic between you and their origin servers. It's all just a bunch of words, no actions. gist.github.com/herwy/040f7a…

1
5
366
Re the situation in Russia, most VPNs get blocked because they were never designed to be unblockable. They either use basic tech and don't support hardcore covert communications or they get blocked in the app stores. However, there are ways around all of that. More to come soon..
1
215
Even though your VPN says they don't track anything, that doesn't mean the follow through with it. VPNs like NordVPN or Mullvad use 3rd party services that often have flow monitoring.... really the SNI requests, DNS requests, everything you do leaves a trace. Do they monitor it? Who knows. Is it there? Yes.
1
119
Your VPN can see EVERYTHING about you: IPs, timestamps, servers, session lengths, and more. What devices you have, what time you wake up, what sites you go to, what you're doing, all your unencrypted stuff, the job you have. It knows more about you than you know about yourself. Even more... they see all your dns, what you request, what you download, even if encrypted. SNI requests are not, which means every site you visit they see. Do they log? Who knows? Can they deploy anti-log software when they're audited? Yes. Can that change after? Also yes.
1
90
Why would you trust NordVPN more than your ISP with your bits? Moving your data to a shady VPN isn't the way to go, VPN tech is good but the players behind them may not be.
2
95
"End-to-end encryption" from an app like WhatsApp, Telegram,etc doesn't mean peer-to-peer. It means they have servers in the middle and use E2E (who knows what kind of encryption) to make you feel special. It's all your #$%^& on our servers, eat it human.
1
74
"No-log" VPNs have been caught leaking user data or keeping connection logs that were handed to investigators. What's worse is they lie about where their servers are, and their GEO location is pay-for-play to save costs gist.github.com/herwy/040f7a…

1
62
A lot of ‘privacy’ services like VPNs totally expose their customers’ data by sending it to CDNs for full description. How the hell can they say they care about customer privacy when their APIs are proxied via a 3rd party?
4
88
"We don't log" is BS. VPNs allow 3rd party tools all over their products, which means they allow everyone else to log you. They give zero fucks about your privacy. The only safe assumption: every VPN provider logs something.
1
95
Big win for ISPs, but more importantly for privacy-focused networks. SC just confirmed neutral internet providers aren't on the hook for users' piracy w/o clear proof of inducement. If this had gone the other way it would have been like road owners being sued for getaway cars. Huge validation of what we're thinking about. latimes.com/politics/story/2…
2
103
A commercial VPN is just a proxy with better UX. All your traffic still terminates on someone else's box. They see everything your ISP would see, and more, if they feel like it. gist.github.com/herwy/040f7a…

3
7
406
You can’t switch your DNS to your backup/recovery plan to switch off of @CloudFlare if you can’t reach the DNS panel also hosted by CloudFlare. #outage #cloudflare #baddesign #oops
1
142
Microsoft Windows is a crime against humanity. Every design decision is shackled by 30 years of legacy code and the expectation that an old .exe from 1995 will still run today is an extremely flawed and stupid concept.
1
1
1
427
Wow… so Windows 11 doesn’t support a /31 prefix? What? #fail
1
211