Hacker News .hnnew | past | comments | ask | show | jobs | submit | qot's commentslogin

Thank you for writing this. I use it routinely to back up my phone by mounting it and then simply running rsync.


Are you rooted? Have you ever tried restoring a backup in this way?

Backup on android (without Google Services' online) is awful, SeedVault exists but has issues.


Am I missing something? Your phone isn’t using encrypted storage?


Encrypted storage is an implementation detail of the filesystem. Once you're at the point of connecting an unlocked phone to a computer running ADB, you can just transfer files and not care about whether or not the underlying data is encrypted at rest.


Can someone please upload the .apk somewhere? It's not available in my country (Canada).


Thank you for being so willing to try it, I hope to release it to Canada on Tuesday. If you are interested, I have an email list on the website, I will be sure to notify you.


No, put another way this is Nike getting punished for creating a shoe that was used to kick puppies.


The purpose of kicking puppies is not embedded in the concept of a Nike sneaker.


No, in this analogy the punishment is aimed at Nike employees who after creating a shoe for kicking puppies also operated puppy-kicking-as-a-service with that shoe.

The people charged are the subset of the Tornado Cash devs who ran the service, not for solely developing some code.


Creating a shoe specifically designed for kicking puppies with enhanced puppy kicking features and instructions on how to kick puppies with said shoe


Which is, and certainly should be, entirely legal.


In the EU I get an EU cell plan because it's orders of magnitude cheaper than roaming from North America when travelling for a month.

So to log into my bank I have to load the website on my device, enter my username / password, have it send the SMS 2FA, switch to my home SIM card, wait to receive the text message, switch back to my EU SIM card, ensure internet works, then submit the 2FA code to finally log in.

That assumes I haven't forgotten something to poke the SIM card out with. I couldn't find eSIM last time I went to Portugal.


I don't recommend ClickUp because of the amount of marketing emails / spam they send you. Every minor version update gets an email in your inbox.

Their "unsubscribe" link at the bottom of the emails also doesn't work which is unacceptable.


Did you use a brainwallet (ie, the hash of the password as the private key)?

It looks like the funds were drained within an hour of you loading the bounty. People have made giant lookup tables of brainwallet passwords and monitor the corresponding addresses for transactions. Reddit user u/btcrobinhood is known for doing this and returning the funds.


Interesting! I suspected the attack vector was my poor use of BTC rather than someone cracking AES so quickly, I'll look into this.

I created the wallet using a popular opensource wallet app, and just moved some funds there. Don't know more than that...

Thank you for the pointers!


Update: funds were not stolen. PortableSecret wasn't cracked (yet)!

What happened is: the wallet app I'm using automatically performs CoinJoin[1] when funds are received (In fact, this is their business model! They take 0.3% of the amount to automatically anonymize all inbound coin).

CoinJoin is a protocol that breaks up the sum received in tiny pieces and scatters them across a large number of "sub-wallets".

So my wallet still has the funds. Bt the 'receive' address I used looks drained, that's because it was only a temporary address to share with the sender. Funds were soon after scrambled/tumbled/anonymized.

This was an interesting experience. I spent all day thinking about what could have happened, researched and learned a bunch of stuff in the process.

[1] https://en.bitcoin.it/Privacy#CoinJoin


Why bother with BTC? Monero implements such protections (plus many stronger ones) with TX fees in the order of a single cent, and obviously without any fees for laundering your entire balance every time you're given money.


Not your keys, not your coins.


Did your failed log-in attempt reactivate your account? Can your friends see your old facebook account now?

Please check for me, because I'm in a similar situation but have been hesitant to try logging back in.


That's a good question! I didn't think to look until you asked. It looks like it didn't, which is a bummer because then I could have asked my friends to get my photos...


Please review the site guidelines:

https://hackernews.hn/newsguidelines.html


Yes you are. We are talking about a tool, so you are asking why someone would "find it be useful".


I agree with you, it doesn't make any sense. AGPLv3 says it plain as day:

"you [the licensee] may remove that term."

The licensee, meaning me, or the defendants in this case, can remove any terms which impose further restrictions. The licensor (Neo4j) has given written consent to do so.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: