Notes

These are all of my posts made on various platforms which are then automatically accumulated here for posterity.

joshua stein via @jcs.org (Bluesky) - Dec 20 2024 09:47:09
Apparently they are going to a random address at a domain hosted by Gmail and there is a forward setup at Gmail to redirect it to an Outlook\.com address, which then forwards to my actual address. This way DKIM/SPF validate and they can probably bypass rate limits on PayPal->Gmail->Outlook. \
joshua stein via @jcs.org (Bluesky) - Dec 20 2024 09:47:09
They can change the forwarding address at Gmail/Outlook fast enough that for every e-mail that comes in, they just forward the last hop to a new victim.

Seems easy to stop, just rate-limit forwarding address changes at Gmail/Outlook. Or require validation from the address being forwarded to?
joshua stein via @jcs.org (Bluesky) - Dec 15 2024 09:22:14
I wouldn't mind paying for Kagi but I don't want to have to log into an account every time I want to search. All of my iPhone browsing is in Private Mode because I can't have a default-deny cookie policy with a whitelist.

Maybe I need to resurrect Endless and convert it to WKWebView.
joshua stein via @jcs.org (Bluesky) - Dec 15 2024 09:16:03
I used DuckDuckGo most of this year and I had to "!g" on almost half of all queries. The more specific the query, the worse and more generic the results got.

But I can barely use Google search on my iPhone now because they send me into CAPTCHA hell on every request due to iCloud Private Relay.
joshua stein via @jcs.org (Bluesky) - Dec 13 2024 17:13:30
Every security researcher's website:

- Hosted on github\.io
- Dark color scheme with awful contrast
- Has 1-5 weblog articles and then never updates again
- Numbers articles in hexadecimal

Bonus points for the first article being about how they switched to a different static site generator