Hacker Newsnew | past | comments | ask | show | jobs | submit | ectospheno's commentslogin

Or it is just regular ageism.

It is amazing to me that people still answer their phone. If it isn’t my wife or kids then my phone has a silent ringtone. If your voice mail doesn’t successfully transcribe to text then I delete it without listening. I check my postal mail since mail fraud is the only thing still taken seriously by anyone.

Is mail fraud really taken seriously? after I bought my house I got dozens of letters every few days that appeared (or tried to appear) from my lender warning of "FINAL NOTICE call this number about your mortgage!!!!!". The phenomenon is apparently so common and well known that my realtor, the seller's realtor, and my lender ALL warned me about these letters.

I feel like it should be easy for the postal inspectors or to go after these, if they cared. Just gather up some of these letters from someone who just bought a house (seems to be public record when someone buys a house, that's how the scammers know when to target someone). Then just call the number in the letter, trace the call and arrest whoever is there.


I can only imagine this passing their “QA” because every dev there uses AI for every commit and therefore saw no issue.

The Bleeping Computer link below mentions a potential remedy until a patch is ready.

https://www.bleepingcomputer.com/news/security/new-linux-cop...


This workaround only applies to kernels with the impacted code compiled as a module. RHEL, Fedora, and Gentoo (we use a modified Fedora config) all are configured to build this in directly. Without a patch or config change (as Sam from Gentoo was alluding to), those distributions remain vulnerable.

There was some discussion on the GitHub issues about workarounds to disable it, even though it is baked in.

https://github.com/theori-io/copy-fail-CVE-2026-31431/issues...

https://github.com/theori-io/copy-fail-CVE-2026-31431/issues...


This worked as a mitigation on distros with the module compiled into the kernel: https://gist.github.com/m3nu/c19269ef4fd6fa53b03eb388f77464d...

Basically: sudo grubby --update-kernel=ALL --args=initcall_blacklist=algif_aead_init

sudo reboot


For compiled-in kernels you can also work around it without rebooting via apparmor, seccomp or SELinux at the least, there may be eBPF or other methods too.

F44 is safe as the kernel is greater than 6.18.22

The potential remedy doesn't work on RedHat and derivatives because the affected code is not a module there but statically compiled in.

Owing tax each year instead of overpaying solves this problem. As long as it’s less than $1000 you won’t pay any interest or fees.

That doesn't solve anything when the fraudster is filing a fake return. They are under no obligation to include all of your carefully chosen income and deductions that get you to $1000 owed.

What? In order to get a refund, that means you have to overpaid what you owe. It's pretty simple. If you are not putting in enough, the fraudster cannot get a refund as you still owe. Like, where is the break down? They would have to know how much you have paid, and then file so many deductions that it'd probably trigger an audit. If you file that many audits not with an account signing off of them, I could only imagine that would trigger an audit as well. Then again, the IRS has been beaten so badly that they barely have enough employees to function.

The fraudster claims that you installed energy efficient home improvements that qualify for the max $3,200 tax credit. Now that $1,000 in tax owed is a $2,200 refund. Maybe you get audited, but the IRS is certainly not auditing everyone who claims a tax credit.

Isn't that pretty much how the solar installation business operates?

Why would a scammer be discouraged by the possibility that the person they have chosen to steal from might get audited?

An audit would mean the refund is not automatically sent.

Nope. Audits don't block refunds, they are an asynchronous process.

I did owe the IRS money. I jokingly told the representative that whoever wants to pay the government more can be the real abirch.

From what I can tell they claimed a lot of exemptions and got a refund.


Everyone is very, very wrong about something. By your logic we should ignore everyone about everything.


This but unironically!


Worked for me just now on mobile safari. You get the cloudflare human test but I just clicked the box and was in. This was despite accessing the site while vpn’d from home and using multiple adblockers.


You can change the priority.


The ipv8 one required all traffic on a network comprising 4 billion ips to go through one server. It was far from sensical.


I didn't say it was practical. But it definitely made more sense than this "meow" crap.


Don't worry, it actually called for 2 Zone Servers in an active-active pair!


> Also, notice how Android and iOS don't support turning off IPv4.

You can trivially connect an iOS device via IPv6 only.


Can you share details on how one trivially connects via IPv6 only? I see no option in iOS Wi-Fi settings to do this, and I think it's reasonable to expect not to have to turn off IPv4 on my access point to test IPv6-only networking.


Presumably thats with the network having a PLAT somewhere if you’re relying on CLAT for any v4-only connections when you use safari


I think they're saying you can't force disable ipv4 entirely.


I’m going to guess no one responding to me has actually tried connecting to an IPv6 only network because it works without incident. Will your apps? Who knows - apple hasn’t always been great at enforcing that.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: