Hacker Newsnew | past | comments | ask | show | jobs | submit | bagder's commentslogin

vodafone has been blocking my site daniel.haxx.se for several years.

Discussed on this very site for example back in 2022: https://news.ycombinator.com/item?id=31248250



So it's been "on review" for more than a year now?! So the filter is basically unidirectional since they apparently don't care about false positives. I wonder who else uses that filter database provider


Oh, and Microsoft includes that adult software in their operating system. Can someone report to Vodafone that all Windows PCs must be blocked because they run adult content. Except for those who have deleted curl.exe of course...



The author (me) did get a visa, after a mere 937 days: https://daniel.haxx.se/blog/2020/11/09/a-us-visa-in-937-days...


Roughly the same thing happened to me, although it only took 11 months to get the visa. It happened to so many people at the company I work for (IBM / Red Hat) that they eventually gathered together testimonials from everyone and sent them to one of the senators where Red Hat is based in North Carolina, and magically everyone's visa "problem" was resolved within 2 weeks. The root cause is that Trump defunded the relevant sections of the State Department: https://www.economist.com/united-states/2022/07/28/americas-...


Do you have your process of how to handle bug reports written down? I'd love to see it, especially if it includes what data you gather, like the commit that introduced a bug.

I guess it's probably in everything curl or will be?


I only record the introduction commit for security flaws as they are rare and important enough to give that level of attention. And that's not a mandatory or required step in our process, I do it mostly as a service for users and to satisfy my own curiosity.

Our process for handling security problems in curl is documented here: https://curl.se/dev/secprocess.html


Love you man great software


That's fairly inaccurate. QuicTLS is pretty much exactly what we're all waiting for. That is OpenSSL + PR8797.


Daniel here.

Thanks everyone for the positiveness and expression of appreciation I've sensed here. The threat has been reported to the police and I'll move on. I love you all. Now I'll go back and continue working on curl.


Thank you for your useful project and sorry you have to deal with this. Consider reporting to US authorities as well if you have not done so, (or wherever you think the threat may have originated from).


You have done great work and I appreciate it.


I use curl daily and just want to thank you for your great work!


As someone who uses curl on a daily basis, thank you.


We love you too. Thanks for everything!


<3


Account restored!


While I am disconnected from twitter, you can always reach me at:

Mastodon: @bagder@mastodon.social

Keybase: https://keybase.io/bagder

IRC: #curl on freenode

Email: daniel@haxx.se

website: https://daniel.haxx.se/


Do you have / did you have 2FA enabled? And, if not, why not?


I doubt it. If it is enabled, I don't see how the hacker could've circumvented it. I wonder if @bagder uses 1Password or something similar for 2FAs. Would love to know once this gets resolved.


can I just mention that my twitter handle is 'bagder' - as in a dyslexic animal! =)


Care to elaborate on how it might have been compromised?


I rather refrain from speculating as I truly have no idea! As I describe in my blog post, I just got an email saying "someone" had logged into my account from a new device and then I was kicked out (as that user then changed password and email presumably).


You still have access to your phone number? So not been sim-swapped hacked?

I guess we will find out (I hope) how it happened.

But surely there should be some automatic red flags with Twitter if an account changes name, email and starts spamming... Especially if verified!


Tadaa: curl already supports --parallel to download many URLs simultaneously...


"For some years" sure, but that's ancient history.

curl has verified the server certificates by default since version 7.10, shipped in October 2002.


I'm actually just very old. But thanks for the effort put into Curl over all this time.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: