Live data from Hacker News

Viewing profile — parable

parable

HN member
Joined
Thu, Jan 15, 2026, 7:13 AM UTC
HN karma
146
Public activity
61 items

About parable

No profile information was provided.

Recent public activity

  1. comment
    Comment #49207602

    This would be nice, and I hope I get to see a future like this, but I moreso meant that I don't see a solution for this issue given the current landscape of things. Ideally, yes, c…

  2. comment
    Comment #49207534

    Metabase can be self-hosted, but you cannot self-host Salesforce or Mixpanel or many of the other products I'm referring to. In an ideal world, every company would self-host their …

  3. comment
    Comment #49206576

    While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesfor…

  4. story
  5. comment
    Comment #48442914

    I've had a similar thought in the past. I was thinking about the feasibility of a law being introduced where each company making over a certain amount of money per year must begin …

  6. comment
    Comment #48442788

    Companies can and do get away with arguing that they have a "lawful basis" to collect whatever data they'd like. It's unfortunate. IANAL, but the law seems a bit vague to me, and i…

  7. comment
    Comment #48442593

    > Otherwise, just assume everything you do online is public and act accordingly. This is such a depressing reality. It's also what governments want you to believe. If you aren't ab…

  8. comment
    Comment #48442515

    I use Snusbase ( https://snusbase.com ). They've been around since around 2016 and haven't had any issues legally - they're the longest-standing data breach search engine besides H…

  9. comment
    Comment #48442502

    Hashes can be cracked, and end users won't understand how to create password hashes to check which one was leaked. Plus, salts exist. Passwords shouldn't matter anyways. Use a pass…

  10. comment
    Comment #48442304

    I wish that were the case, but because of there being barely any consequences for breaches, it's much more profitable to store everything you can and sell it to the highest bidder.…

  11. comment
    Comment #48442266

    I'd also add a third issue to this list: data retention. Too many companies I've dealt with have privacy policies that state something to the tune of "we'll hold onto your data for…

  12. comment
    Comment #48390515

    I find it very hard to trust any email service that claims to be E2EE without an audit by a reputable firm like Cure53 or Trail of Bits. I signed up to give it a brief test and imm…

  13. comment
  14. comment
    Comment #48380971

    I'm not sure how I haven't heard of this yet. There have been too many times I've wished I could convert a command-line script to a native application easily for me not to try this…

  15. comment
    Comment #48380934

    Kudos for the public disclosure. Too many people haven't been happy with MSRC and it's starting to boil over (see the Nightmare Eclipse situation, too). Maybe all of these disclosu…

  16. comment
    Comment #48378677

    It seems pretty trivial to just add a check in the agent's tool call to determine if the email is actually the one on file (or one that has previously been on file). I'm not sure w…

  17. comment
    Comment #48375800

    The bug still exists - two of my friends have lost access to their accounts as of an hour ago. They've partially recovered but are unable to change their passwords, so their accoun…

  18. comment
    Comment #48365428

    It appears the exploit hasn't been patched: https://x.com/vxunderground/status/2061636614267273332 I've heard the new "method" has to do with setting your location to Singapore or …

  19. comment
    Comment #48364666

    The original 2FA did not get thoroughly bypassed, because otherwise I would've lost my username, so that's false - at least, based on my experience. However, there are separate vul…

  20. comment
    Comment #48364638

    I suggest you try signing into your Instagram account via the app or website to check if you've been compromised. It could very well be a bot trying to obtain your recovery method …

  21. comment
    Comment #48364625

    If there's no recovery email address set, or that email has expired, there are no recovery methods to verify with. The account is locked "for good". I use quotes because in some ca…

  22. comment
    Comment #48364605

    This still happens. Meta doesn't do much to protect against this, they just fire more people and hire new agents when they find out one was bribed.

  23. comment
    Comment #48364590

    It's against Meta's terms to buy and sell accounts, thus the bank would never do such a deal unless you structured it a certain way: create a business, the account becomes property…

  24. comment
    Comment #48364088

    Meta's aware and tries their best to act on it, but the real solution is simply not hiring outsourced support workers. It's really that simple. They have the money to hire people i…

  25. comment
    Comment #48363131

    Correct, which is the problem here - they don't want to, and you can't force them to.