Live data from Hacker News

Mail a Letter Online

mailaletter.com

21–30 of 117 posts

Re: Mail a Letter Online

#22
post #12

This is similar. I've never used it but it looks fun: https://handwriting.io/

this is pretty cool. I would love to see a service takes writing samples in your own handwriting and produces a letter that looks like you wrote it.

> this is pretty cool. I would love to see a service takes writing samples in your own handwriting and produces a letter that looks like you wrote it.

That would personally be horrifying to me. Imagine, someone can make it look like you said _anything_.

Re: Mail a Letter Online

#23
post #7
post #2

Too bad there's not a postcard option...

https://lob.com probably has what you're looking for. I've used their service for awhile and it's amazing.

Yeah I use Lob for a lot of my "write up a letter, print, and mail it with a written record of what I sent and when" correspondence. They make it super easy to send letters about as easily as an e-mail.

I am very clearly not the intended customer and appreciate that they're willing to take my business anyway.

I also used them for holiday cards two years back, which was

* Fantastic -- super straightforward to write up a small script to call their API and send 1 card to each person on our holiday-card list

* A little weird -- sending 70 holiday cards involved instructing their API to download an identical .pdf holiday card template from a remote server where I hosted that one file 70 times

* Cheap -- they printed and mailed glossy postcards at a very affordable price

* Ever so slightly disappointing -- we got to see maybe 10 of the actual mailed postcards from this run (on family's fridges, in the test copy we sent ourselves, and in the 3 or 4 postcards that we thought were addressed correctly but which were returned to us with an invalid address) and every single one of them had the same printing defect, what looked like a big scuff across a photo. Not sure what the deal was or why it was so consistent on every image. We didn't write in to support because I am pretty sure we are not the target audience.

Great service, A+, huge time saver vs. manually writing so many addresses, still a big fan.

Re: Mail a Letter Online

#25
post #17

Earlier quoted context omitted.

Why? Also there is https on the more sensitive parts of the site (login etc).

pretty meaningless when you can MITM the page and remove https from all the links

Can you? Please demonstrate.

This is one of the silliest arguments that comes up every time "SSL All The Things!" is discussed. The "you" in your story has to be both a Bad Guy and your ISP, and needs to come up with a way to sabotage a site that shows you cat pictures in such a way that it shows malicious cat pictures that somehow do anybody any harm.

So yeah, please MITM this site for us real quick so we can see all the Bad Stuff you're talking about.

Re: Mail a Letter Online

#26
post #12

This is similar. I've never used it but it looks fun: https://handwriting.io/

this is pretty cool. I would love to see a service takes writing samples in your own handwriting and produces a letter that looks like you wrote it.

There are services that will take samples and make a ttf font. Here's one: https://www.calligraphr.com/en/

Re: Mail a Letter Online

#27

Earlier quoted context omitted.

pretty meaningless when you can MITM the page and remove https from all the links

Can you? Please demonstrate. This is one of the silliest arguments that comes up every time "SSL All The Things!" is discussed. The "you" in your story has to be both a Bad Guy and your ISP, and needs to come up with a way to sabotage a site that shows you cat pictures in such a way that it shows malicious cat pictures that somehow do anybody any harm. So yeah, please MITM this site for us real quick so we can see al…

https://moxie.org/software/sslstrip/

The attitude of "it's cool, only use SSL for the sensitive parts" hasn't been true for a decade.

Re: Mail a Letter Online

#28

Earlier quoted context omitted.

Can you? Please demonstrate. This is one of the silliest arguments that comes up every time "SSL All The Things!" is discussed. The "you" in your story has to be both a Bad Guy and your ISP, and needs to come up with a way to sabotage a site that shows you cat pictures in such a way that it shows malicious cat pictures that somehow do anybody any harm. So yeah, please MITM this site for us real quick so we can see al…

https://moxie.org/software/sslstrip/ The attitude of "it's cool, only use SSL for the sensitive parts" hasn't been true for a decade.

Again, that looks like it needs to be sitting somewhere between the end user and the webserver.

I don't disagree that it is possible to mess with http traffic in flight if it's not encrypted. I do disagree that a) there are bad guys between me and the http://catpictures.com right now and b) They have targeted me with malicious cat pictures that will cause damage somehow.

My sites that allow logins are all https only. My "cat picture" site is not. Because it doesn't need https.

Re: Mail a Letter Online

#29

Earlier quoted context omitted.

https://moxie.org/software/sslstrip/ The attitude of "it's cool, only use SSL for the sensitive parts" hasn't been true for a decade.

Again, that looks like it needs to be sitting somewhere between the end user and the webserver. I don't disagree that it is possible to mess with http traffic in flight if it's not encrypted. I do disagree that a) there are bad guys between me and the http://catpictures.com right now and b) They have targeted me with malicious cat pictures that will cause damage somehow. My sites that allow logins are all https only.…

Can you give a reason for not using https in the age of LetsEncrypt?

And yes, the point of MITM is that there has to be a malicious actor in the middle. This is mainly a threat when using public WiFi, like at an airport or a coffee shop. It's absolutely trivial for some bored individual to run SSLstrip for funsies and distribute malware through any HTTP connections.

Also, an attacker doesn't need to somehow create malware-infested versions of the cat pictures on your site. They only need to append some javascript at the end of your site's body tag, which again, is trivial for a script to do. And maybe a transparent image with the malicious payload should they have JS disabled.

To those wondering how they might protect themselves from these sorts of attacks when using non-SSL sites on public WiFi, this is where a VPN comes in handy. All of your connections will be encrypted and no longer vulnerable to MITM attacks.

Re: Mail a Letter Online

#30
post #8

This makes it look like there are some unresolved challenges with fulfillment: https://www.bbb.org/us/wa/seattle/profile/international-mail...

I've been using it for many years with no problems with fulfillment. I like that there is a record the letter was sent.

The biggest annoyance is the horrible UX for entering recipient's address. I'd like to type the two lines on the envelope. Instead, I need to go through this form adding them as a contact, with fields for e.g. city and state. Most of my letters are one-offs, and it's a bunch of cut-and-paste work. Still beats doing my own mailing, though.

Post reply on HN