Hacker Newsnew | past | comments | ask | show | jobs | submit | captn3m0's commentslogin

Namecheap also suspended my primary domain because of a bug at their end: https://captnemo.in/blog/2026/05/05/namecheap-whois/

tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.

I know a few other people that were impacted.


I reversed Super Hexagon these last few weeks and ported it to the Playdate (the yellow console from Panic with a crank): https://old.reddit.com/r/PlaydateConsole/comments/1v1zxmt/i_...

The multiplier comes from being able to design arbitrary fast feedback loops - Claude wrote Python scripts to do decompilation matching for itself, and then use Frida traces from the original as a verification harness.


There are a lot of other implementations of this idea that don't necessarily rely on trust-on-first-use. The securedrop team explicitly includes malicious JS served by the primary-domain in the threat-model and made WEBCAT[0] as an outcome of that research. Their article on webcrypto is much better than this one.

The solution obviously is to go out-of-band:

> When a user visits a website that has enrolled in WEBCAT, before the site can load the content is checked against a signed manifest to ensure that it has not been tampered with (more on enrollment later). If everything checks out, the page loads normally. If, however, any content does not match what’s expected, the page load is aborted and a warning is displayed, protecting the user from potentially malicious content before it can execute.

[0]: https://securedrop.org/news/introducing-webcat-web-based-cod...

[1]: https://securedrop.org/news/browser-based-cryptography/


This is a OS port (iOS) of an existing functional and maintained fork (MacOS) of the official release (Windows).

Most of these low-hanging bugs would have been caught upstream by now.


upstream is a MacOS+linux build. https://github.com/fbraz3/GeneralsX.


Do we know how Apple sends these? Is it just a notification, or also email?


https://support.apple.com/en-us/102174

>A Threat Notification is displayed at the top of the page after the user signs into account.apple.com.

>Apple sends an email and iMessage notification to the email addresses and phone numbers associated with the user’s Apple Account.

You can see what it looks like in https://reddit.com/r/iphone/comments/1c10jai/i_have_received...

I wonder how they detect it, is it for known IOCs that they've already found elsewhere, or do they have heuristic detection that flags things that might need further investigation.


There are 2 complete folds in the Isaac 0 video around 0:40, but speeded up: https://m.youtube.com/watch?v=KhImSR8GuCE

The about page claims 1000+ lbs of laundry folded every week.


That's fine. Like a robot lawnmower - if it does it every day, it doesn't need to be as fast as a person.


10% apparently for .tk. I also remember .tv windfall, which is 8-9% of their GDP.


The .ai TLD is some tiny island with a few thousand people


.io is (British) Indian Ocean (Territory).


I always thought these TLDs were a flight risk to be used in any serious capacity. What if the random state decides you/your business are in violation of [whatever] and kick you off?


I seem to remember bit.ly had some issues when turmoil happened in Libya


My latest domain (five chars!) that I am actually using recently went down because my registrar is (was?) in Gaza.

The registry thankfully was able to sort it out and I was able to get it back and registered with a regisrar not currently being actively genocided.

I felt like a real dick, emailing people in Gaza in 2026 how to renew my domain.


Notion just migrated from their Somali domain to a normal .com


What if they sent out a hit squad to your house?


What if an elephant steps on the power cable to the server room?


The owners of `queer.af` thought that AF only meant “as f*ck”, without realizing that AF also happens to the be the ISO 3166 code for a country controlled by the Taliban, who didn’t like their domain name [1].

Brits that had `.eu` domains lost their domains due to Brexit [2] (unless they had some other EEA ties).

And if the Chagos deal goes ahead [3] and the British Indian Ocean Territory ceases to exist, then all `.io` domains might disappear too (although considering that `.su`/Soviet Union domains are still a thing, they probably would have stayed around).

[1]: https://www.404media.co/taliban-shuts-down-queer-af-domain-b...

[2]: https://www.gov.uk/guidance/registering-and-renewing-eu-doma...

[3]: https://www.bbc.com/news/articles/ce9m47y1ez2o


>Brits that had `.eu` domains lost their domains due to Brexit

Ouch, that must've hurt. Brexit is the most stupid thing that Britain has ever imposed on itself.


After the restoration of the monarchy of course


Assuming the British/American air base remains on some agreement with the Mauritian government, then the Chagos Islands may remain as a special territory of Mauritius, justifying the continual existence of an ISO 3166 code for it.


Actually, Diego Garcia (the British/American military base) already has it's own ISO 3166-1 alpha-2 code, DG: [1]

It's "Exceptionally reserved" "at the request of International Telecommunication Union (ITU)".

Although my gut feeling is that if the deal happens, Mauritius would probably ask to exceptionally reserve `IO` as well. Still, I'm not sure if I'd risk using a `.io` domain since it's not guaranteed.

[1]: https://www.iso.org/obp/ui/#iso:code:3166:DG


haha yeah I've bet the last 12 months of my career on a .io


Anguilla


And the .sy boom until startups got enough heat for, you know, funding the Assad regime.


Apparently nobody cares that .af is now funding the Taliban


The terms of using that tld say it must comply with Sharia law

pretty strict and apparently the Minister of that agency doesnt care that .af is a domain hack for “as fuck” in the west


In other words, he doesn't give a fuck


Perhaps he does - dontgive.af does not resolve.


1. Be Sharia law

2. Sell domain name that's against Sharia law

3. Retake it back when someone buys it, because it's against the law

4. Repeat and profit


yeah it was right there


What website/service actually uses that?



I thought that ended up being because the registrar didn't pay it's bill to the Afghan government?


During Pride Month?!?


I wrote superbright to be able to force it: https://github.com/captn3m0/superbright (fork of BrightIntosh). The display does get hit after 10-15 minutes of this though.


Yeah, that's one of those third-party apps, though not one that I've seen before -- but it has the same issue of just plain feeling weird. At the end of the day, a hacky solution is a hacky solution, but I honestly can't wait until OLED makes the backlight obsolete.


When I read the title, I thought it would be for research papers.


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: