Live data from Hacker News

Uninstall the NightOwl app

robins.one

201–210 of 236 posts

Re: Uninstall the NightOwl app

#201
post #11

There's gotta be some law that could be passed about stuff like this. Software should have an implicit contract that it does what it says and not something wildly different than it, with harsh penalties for violations.

Common licenses specifically go out of their way not to imply such a contract. This is the start of the all-caps portion of the MIT License [0]: > THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO […] FITNESS FOR A PARTICULAR PURPOSE …and the GPL has nearly the same text in section 15. [1] [0]: https://opensource.org/license/mit/ [1]: https://www.gnu.org/…

It wouldn't be that hard to make free open-source software not subject to the same rules.

Re: Uninstall the NightOwl app

#202
post #180

Earlier quoted context omitted.

Given https://eclecticlight.co/2023/08/08/apple-has-just-released-... it does look like it was revoked in response to the original article, and not the other way around.

> Given https://eclecticlight.co/2023/08/08/apple-has-just-released- ... XProtect is separate from Developer ID certifcate revocation. In many cases, malware is not even code signed, so certificate revocation would do nothing. > it does look like it was revoked in response to the original article, and not the other way around. I'm not sure what you mean?

I was trying to figure out how long I had possibly been running the infected code. I was certainly in a state today where binaries were running with revoked signatures. What I couldn’t tell is if this state was only for a few minutes or hours, or if it was days or weeks.

If Apple only revoked the dev certificate (and possibly XProtect) today, that would make sense. But if it was revoked a ways back, then it would be concerning that it would require a reboot (with no prompting) for a regular user to fully kill the running background processes.

Actually, thinking about this further, if Apple had revoked the certificates before today, others would probably have noticed it and investigated given the “Move to trash” dialog and the strong assertion of “this is malware” in it.

Re: Uninstall the NightOwl app

#203

Earlier quoted context omitted.

Do you have a link to more information somewhere? I'd like to know more about what NordVPN is doing, if true. It's certainly not what their customers expect.

https://nordvpn.com/blog/residential-proxies/

That blog post does not say that NordVPN uses customer VPN endpoints as proxy servers without the customer's consent. It talks about the possibility of setting them up, but the implementation is left to the customer.

Re: Uninstall the NightOwl app

#204
post #79

>> It is an alternative to the built in macOS automatic mode which only switches when the user steps away from the computer. Huh? Setting a schedule/location for nightshift and setting the dark mode setting to auto will always change instantly. If you use a launcher or spotlight then a simple one line applescript can change the setting as well. (tell application "System Events" to tell appearance preferences to set d…

> Huh? Setting a schedule/location for nightshift and setting the dark mode setting to auto will always change instantly Not in my case?! I’d say there’s a 25% chance that Dark Mode enables at sunset. It’s been this way for years — even up til Ventura. Has it worked flawlessly for everyone else the whole time?

I have never had any issues. Every single day I get the jarring shift as all the dynamically dark-mode-aware apps shift color schemes and realize that the sun must be setting.

Re: Uninstall the NightOwl app

#206
post #132

Earlier quoted context omitted.

Seems like a developer that is getting literally nothing for his app or plugin is more likely to sell it than a developer that's getting some income from it. At the least, the buyer would need to match the current value that the app provides its author.

I don't know. A developer who didn't charge anything from the beginning has more likely other motives releasing his software than making money. But if you already make a little money you may easily fall for a lot of money.

Look at Red Shell for example:

https://www.polygon.com/2018/6/20/17485762/red-shell-spyware...

I don't have a link handy but I distinctly remember Take Two, a giant corporation with billions in revenue, saying when they removed it from Kerbal Space Program that they promised to wait a while and be more subtle next time they did that.

Re: Uninstall the NightOwl app

#207
post #20

I know this happens with some frequency, I wonder how frequently the companies update the TOS with language like this. The very idea of a self-updating TOS that will govern all usage into perpetuity feels like it should have been legally stuck down years ago. This company's current language on indistinct modification rights: > We reserve our right to alter the terms in this Agreement and/or the pricing information an…

“In case the Agreement is amended as described, we will post an updated version of it in our website, at which time it becomes active and binding”

Several years ago, a friend entered into a contract with Comcast for business internet and phone service that had similar wording and no actual URL for the site. My instinct was that would be unenforceable and unconscionable, but you’d think Comcast legal would have thought it through.

Any lawyers out there familiar with this type of wording related to contract changes being posted on a website, particularly where no notice is given?

Re: Uninstall the NightOwl app

#210
post #191

Earlier quoted context omitted.

> NordVPN does this as well. Do they? Last time I looked into this drama, it seems like the botnet accusations were just scurrilous slander. https://www.comparitech.com/blog/vpn-privacy/nord-vpn-botnet...

Almost certain. NordVPN owns Oxylabs if I'm not mistaken

Seems like it https://news.ycombinator.com/item?id=29285988
Post reply on HN