Viewing profile — vitalipom
vitalipom
HN member- Joined
- Wed, Mar 23, 2022, 9:44 AM UTC
- HN karma
- 247
- Public activity
- 85 items
- HN profile
- View on Hacker News ↗
About vitalipom
No profile information was provided.
Recent public activity
-
story
Show HN: This App Is My Lifelong Labor of Love
This App Is My Lifelong Labor of Love When was the last time that after an update you felt yourself as if being exposed to something amazing, having as if a radioactive feeling acr…
-
comment
Comment #48532781
https://play.google.com/store/apps/details?id=com.vitali.pom...
-
story
Show HN: I built a keyboard with typing effects
The name of the app is Effected Keyboard 2 on Android Play Store. So far it supports: * Tens of languages * Truly immersive effects as you type * Undo/Redo * Copy/Paste clipboard *…
-
story
Show HN: A demo video of Effected Keyboard 2
Effected Keyboard 2 is the number one keyboard that pops up effects as you type from the keyboard to the screen. The keyboard is underrated, hence unpopular, but those who’ve tried…
-
story
Show HN: Effected Keyboard 2 – Effects as You Type
Have you ever heard of Cafe keyboard from Samsung’s app store? It’s very similar to it, but here there are effects that… Make you feel like your phone is on steroids, and in a good…
-
story
The Phishing Campaign Targeting Gmail Users from April 2025
In April 2025 a phishing campaign, targeting Gmail users has launched in a massive attack, making a malicious email look legitimate. Foreseeing a probability of such circumstances …
-
comment
Comment #42845517
I TL;DR-ed it here in the edits of the root post above.
-
comment
Comment #42845423
You’re right! Editing.
-
story
I Found a Security Bug in Way Too Many Websites
I found a security bug that allows a phishing website to pretend to be the real website and sniff user’s credentials. It exists almost EVERYWHERE. I did my own research, experiment…
-
comment
Comment #42784335
Again, I haven’t yet tested it. But I’d like to hear what community has to say with relevance to that about my direction with the solution I’d been working on.
-
comment
Comment #42784004
Yes, but more smart people that visit a clear phishing website later on understand their mistake and change their password. If you could perform actual actions on a letsencrypt cer…
-
comment
Comment #42783961
A bit loss of context. Angular was mentioned in the context of how servers serve Angular apps: if instead of server index.html server would serve a different whole url. And my worr…
-
comment
Comment #42783310
Thank you for the reference! Would you mind to see if you can reflect on my solution idea which I’m questioning myself about? I filed a patent for it and mentioned it in a comment …
-
comment
Comment #42783254
The thing is that I claimed to have a solution and I even filed a patent for it. Some time later I understood I need many iterations to even understand if I’m right or wrong. The d…
-
comment
Comment #42773950
Okay, I’ll give it a try by mocking up an attack on a secure app of mine I’m making. Thanks!!!
-
comment
Comment #42773829
Not claiming it to be novel or new at all. Just trying to understand. I'll think about CORS. Meanwhile my thought - correct me if I'm wrong, is that CORS would be irrelevant since …
-
comment
Comment #42773740
Isn't CSP controlling what you can fetch FROM your website? The proxy in the example I mentioned can act as a simple web browser behind the scenes. Unless I'm missing something.
-
story
Ask HN: What prevents the following vulnerability I found from being exploited?
I've now consulted ChatGPT on a solution for a vulnerability which I even filed a patent for long time ago and I feel less stupid right now. Say bank.com has SSL. Cool! Now how doe…
-
story
A Better Way of Defense with Csurf
Csurf might be deprecated in the npm main repository, but it does not cancel the fact that this is still a great lib for CSRF Tokens in NodeJS. While striving to find and provide a…
-
story
Ask HN: A Clickjacking Defense Suggestion?
The problem: when website has a post comments section that allows including html, attacker can post a link that utilizes clickjacking attack by posting a button that says i.e. clic…
-
comment
Comment #39049889
I will update when everything will be in the air
-
comment
Comment #38983933
I will create a demo how I hijack my own account using session hijecktion and and a simple laptop and it to you to get convinced in the nature of purity of the provided signmeonly.…
-
comment
Comment #38983907
I will make a demo hijecking myself account and how do I do it and show with example yo you guys how all of us are vulnerable.
-
comment
Comment #38980228
I described it: on Tik Tok, on YouTube, on dev.to, here in another posts. But somehow people don’t say anything. As if in the only tech places I know people don’t want to talk abou…
-
story
Am I doing this right?
I developed a cool piece of software that helps potential users a lot and I want to expose it and bring a lot of traffic and acknowledgement before I launch it in order to stay mot…