Live data from Hacker News

BugMeNot Is Gone?

bugmenot.com

31–40 of 54 posts

Re: BugMeNot Is Gone?

#31
post #27
post #24

Earlier quoted context omitted.

Which browser from this decade ignores HSTS completely?

Safari on iPadOS 16 loads that just fine for me. I’d forgotten all about this site, don’t remember ever using it but I certainly heard of it.

Haven’t managed to find a site (apart from HN) that it does allow yet!

Re: BugMeNot Is Gone?

#32

It got less and less useful in the last years a lot of sites killed a login as soon as it hit bugmenot understandable to shut it down.

Still worked for ~75% of sites I visited. Especially smaller sites and those annoying forums that required a login to download attachments.

Re: BugMeNot Is Gone?

#33

Earlier quoted context omitted.

Looks like that's gone too

Hsts?

HTTP Strict Transport Security

It allows servers to specify that browsers should never even attempt to make an unencrypted request to the site and instead silently convert any such requests to encrypted requests.

This header is good for security but it’s also convenient for old sites that don’t want to update their existing links. They can upgrade the whole site to HTTPS without any content changes.

https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/St...

Re: BugMeNot Is Gone?

#34
post #24

Earlier quoted context omitted.

It's probably your browser trying to protect you from yourself, re: HTTPS. It works in non-user hostile browsers.

Which browser from this decade ignores HSTS completely?

It works for me in firefox, but I've got it locked down pretty hard.

I have the following all set to false in about:config

  network.stricttransportsecurity.preloadlist
  dom.security.https_first
  dom.security.https_first_pbm
  browser.fixup.fallback-to-https

Re: BugMeNot Is Gone?

#35

Never understood why people use it seems to be too risky. You can end up sharing an account with someone associated with some unsavory activity and end up having to explain it. Plus many sites allow users to view their login and download activity logs which means your private information can leak that way. Sure VPNs and TORs can help mitigate some of that risk but BMN isn’t for opsec it’s for continence if you alread…

I only ever used it to access things that should not have been behind a user account in the first place. It was really just an opt out for the forced "sign up for our newsletter/spam to download our app" type paths. The only thing it'd really leak is that someone with a particular IP had used bugmenot... Which many would likely consider an advantage over going through creating an account and potentially getting spamm…

I rely on email proxy for most stuff nowadays, so when I register an account I can at least temporarily disable the address used for this particular service if it gets too spammy.

Combined with a password manager it's mostly the only way to stay sane online.

Re: BugMeNot Is Gone?

#37

BugMeNot was a good example of a pivot - RetailMeNot https://en.wikipedia.org/wiki/RetailMeNot ($90 million for the founders) Which is why they let BugMeNot start slipping over a decade ago removing domains when requested, they didn't want to risk the cash cow.

It wasn't a pivot - the founders were great bootstrapped hackers who wanted to try out different models.

They promoted RMN to BMN users which gave it a meaningful early boost.

Re: BugMeNot Is Gone?

#38
Still works via HTTP

Used it recently for ABC iview because now they require a fucking account, even though I'm paying for this through my taxes.

Used it about 2 months ago for a download off some random forum which required an account.

Great site!

Re: BugMeNot Is Gone?

#39

Never understood why people use it seems to be too risky. You can end up sharing an account with someone associated with some unsavory activity and end up having to explain it. Plus many sites allow users to view their login and download activity logs which means your private information can leak that way. Sure VPNs and TORs can help mitigate some of that risk but BMN isn’t for opsec it’s for continence if you alread…

I only ever used it to access things that should not have been behind a user account in the first place. It was really just an opt out for the forced "sign up for our newsletter/spam to download our app" type paths. The only thing it'd really leak is that someone with a particular IP had used bugmenot... Which many would likely consider an advantage over going through creating an account and potentially getting spamm…

It doesn’t matter you use it to access a news article someone else uses it to issue a death threat as a joke or do something worse your IP is tagged on the same account and someone might come knocking.

Law enforcement isn’t even likely to know that the account is on BMN or even what it is. And what’s worse is if the rest of the IPs are foreign but you are local well congrats you’ve now become the focus simply for being within reach.

Re: BugMeNot Is Gone?

#40

It got less and less useful in the last years a lot of sites killed a login as soon as it hit bugmenot understandable to shut it down.

Still worked for ~75% of sites I visited. Especially smaller sites and those annoying forums that required a login to download attachments.

Web-browsers are a lot better at auto-filling registration forms correctly thesedays, and now that even Office 365 supports disposable e-mail addresses means that registering for online services is far less of a chore than it was before. Also, many sites support federated identity (OIDC, Sign-in-with-Google, etc) which also takes a lot of the pain away.

I remember in years gone-by, before data/privacy-laws were either introduced or widely understood by web-devs that sites would have all manner of required fields just because someone from marketing or management thinks they need to collect everyones' home address, age, home, work, and mobile phone numbers, and sex/gender - now that they legally can't (without a good reason) things are a lot smoother.

So in summary, BugMeNot is gone because the severity of the problem it aimed to solve (online registration tedium) has been reduced below the threshold of action.

Post reply on HN