Avatar

A Mouse

mouse@midwest.social
Joined
7 posts • 89 comments
Direct message

It’s a relatively low performance hit and it benefits me when having to replace a failing/old disk. I can just toss the drive without having to erase the data first, that is as long as the key is a secure length.

permalink
report
reply

Not that it helps but the CEO claims they forgive for this type of attack/event. https://news.ycombinator.com/item?id=39521986

Netlify CEO here.

Our support team has reached out to the user from the thread to let them know they’re not getting charged for this.

It’s currently our policy to not shut down free sites during traffic spikes that doesn’t match attack patterns, but instead forgiving any bills from legitimate mistakes after the fact.

Apologies that this didn’t come through in the initial support reply.

And later they were asked if they would have responded if it didn’t go viral. https://news.ycombinator.com/item?id=39522029

Question:

There are only two questions everyone have:

  1. Would Netlify forgive the bill if this didn’t go viral?

  2. How do you plan to address this issue so that it never happens again?

Everyone here knew someone from Netlify would come and say OP wouldn’t have to pay. That was a given. Now we want to know the important answers.

Answer by CEO:

  1. Yes. We’ve forgiven lots and lots of bills over the last 9 years and they haven’t gone viral

  2. While I’ve always favored erring towards keeping people’s sites up we are currently working on changing the default behavior to never let free sites incur overages

permalink
report
parent
reply

Quickly skimming the readme, it states:

  • OAuth token spoofing: To circumvent rate limits imposed by Reddit, OAuth token spoofing is used to mimick the most common iOS and Android clients. While spoofing both iOS and Android clients was explored, only the Android client was chosen due to content restrictions when using an anonymous iOS client.
  • Token refreshing: The authentication token is refreshed every 24 hours, emulating the behavior of the official Android app.
  • HTTP header mimicking: Efforts are made to send along as many of the official app’s headers as possible to reduce the likelihood of Reddit’s crackdown on Redlib’s requests.
permalink
report
parent
reply

Unless I missed something, the article states as follows

Another method of bypassing the account lockdown still exists. You simply have to enter OOBE\BYPASSNRO in the command prompt during the Windows 11 setup process, which allows you to skip the connection to the Internet and thus also the link to a Microsoft account.

permalink
report
parent
reply

We all make mistakes, thank you for being transparent. 💖

permalink
report
reply

Firefox 130 adds an opt-in feature for LLM sidebar to use Anthropic’s Claude, ChatGPT, Google’s Gemini, HuggingChat, and Mistral. https://ostechnix.com/firefox-integrating-ai-chatbots/

permalink
report
parent
reply

You’re right, there is no hack involved. I probably should have mentioned that it’s not. I was just referencing what I thought OP was trying to discuss.

permalink
report
parent
reply

I agree. I am someone who values their privacy and often does not like opt-out style analytics however I also know opt-in skews analytics. The way the searches are only categorized, and they are using Oblivious HTTP keeping IP addresses private makes me A-OK with this.

permalink
report
parent
reply

As an adult, we do too, and it also negatively impacts us. When I left the other social platforms I took the time to uninstall or disable many notifications, I now receive a total of 5 a day on average. It’s good to see these conversations happening though, whether we react and change though only time will tell.

permalink
report
reply