As someone who only has a cursory knowledge of Postgres backup systems, how does this compare to something like pgBackRest? When would someone reach for one over the other?
If you're running pg yourself I recommend pgbackrest. It doesn't run as a daemon, & it forks multiple processes for concurrency. But it's simple to run as archive_command & is light on resources outside concurrency
It could be the other way round too. ;) We just limited the number of Postgres providers in the first batch. May add you in the next and might ping you before sharing it in public, just to make you sure you are aligned and like them.
It wasn’t left out on purpose, it was just prioritization, we chose 5 that most commonly came up. Please feel free to submit a PR, it should be pretty straightforward.
A lot of people have been very vocal about this. I use uBlock Origin Lite and haven't noticed a difference between it and uBlock Origin. Am I missing something?
> For uBlock Origin users on Chrome, there’s uBlock Origin Lite. However, the Lite version “allows some tracking, its blocklist is a fraction of what the original blocked, and it can't perform the dynamic filtering that made the original effective,”
I guess that's what the GP and I are both saying we didn't feel. I have no idea what benefit "dynamic filtering" provides. It sounds good on paper but having tried both versions, I can't tell the experiences apart. I don't see ads, pages load fast, and that seems like enough?
Actually, I'll take that back. I used to see far more stuff get blocked (e.g., when clicking links) than with Lite. Which is to say, Lite feels like it has fewer false positives.
When sites attempt to block users who use ad blocking extensions, dynamic filtering allows well written ad blockers to continue to work.
For instance:
> Last year, Google/YouTube ramped up its efforts against ad-blockers, preventing playback for users with the software installed on their devices, coercing them to disable it.
Users continued to exploit loopholes in browsers and third-party extensions, such as Firefox, that allowed them to bypass YouTube's ads while watching videos. However, the tech giant has seemingly doubled down on its efforts against ad-blockers, closing the few remaining loopholes
I've realized over time that people on the internet love finding things to be mad about, because raging against evil is fun. They'll make up an injustice if they can't find one today.
They’re not “making up an injustice.” Google is actively trying to stop ad blocking, this is a fact. You can argue whether or not it’s as severe as some people make it sound or whether people should be upset at all (I think we should be), but let’s not act like this was made up whole cloth.
Manifest v3 doesn't stop ad blockers. In fact the chromium team worked together with ad block developers to adjust the design of Manifest v3 to better allow for them to be implemented.
+1, Lite is mostly fine. The main difference seems to be that YouTube videos sometimes start a couple seconds late. Not quite annoying enough yet to switch browsers (tbh though, Firefox is totally fine these days, main downside for me is that the WebGPU implementation lags quite a bit behind Chrome and Safari).
it's not nearly as complete: You only get filter list updates when the extension updates, there's no custom element picker, no per-site switches, no strict-site blocking, no dynamic filtering and you can't import block lists. It's better than nothing (which is pretty much unbearable IME) but not as good.
Origin Lite _can_ be beat by advertisers rotating the URLs they serve ads from. That doesn't mean advertisers are actively bypassing Lite, but they could
OTOH it's not out of the question that some open source non-extension Chrome mod emerges that will then block those kinds of ads. Brave is already shipping this anyway.
Hiding elements on the page should be the last goal. A lot of the traffic uBO-proper blocks, has nothing to do with what you see. "Ad blocker" is a lame name, it's not even the important part.
Just because it's working today doesn't mean it will work as well in the future.
It's not about the small technical change with deprecating mv2, it's about the direction they are taking Chrome.
The Spectacle Factory recommends, in order, (1) warm water and a microfiber cloth, (2) Zeiss lens wipes, or (3) an ultrasonic bath: https://www.youtube.com/watch?v=m4lJ_5Tg9Ms
They recommend (v=5FUUgO95sb4) against both detergent for the sake of the lens coatings and against sprays which may cause grease to accumulate around the lens rim.
If you're the kind of person who has bought a dozen pairs of cheap Zenni's... the lens coating gets visibly damaged every time I've used hand soap on them. I now just blast them with hot water and wipe dry with a lens cloth. I don't know whether hand soap is a problem for more expensive brands, but it definitely is for Zenni's.
40+ year glasses wearer here who learned this perhaps only 10 years ago, I think this is the correct way. The one annoying part is the difference that the glass coating makes. The water just falls off some of my glasses with barely as much as a light tap. Others length tend to hang onto the water in beads, so I have to actually wait for it to dry (or walk around with water spots, which I also do when impatient...)
I’ve been wearing glasses for just under 30 years, and only last month I decided to actually try and clean my glasses with the tiny microfibres cloth they give you when you buy a pair of glasses rather than throwing it out because it gets annoying in your case because you just use your t-shirt… I’m not a 100% microfibre guy
>Cleaning your glasses properly – what to do —
Use this method for both for [sic] thorough cleaning of your glasses at home, and fast, effective cleaning when you are out and about: rub a microfiber cloth or a folded lens cleaning wipe gently over the lens surface to remove coarse dirt particles.
Use a clean microfiber cloth. ANYTHING ELSE will scratch your lenses up. (This is probably the most common no-no I see. People will clean their glasses with anything on them and smudge/scratch them instead.)
Two cloths are ideal: one for cleaning and another for polishing.
If you're using soap and water, apply a tiny amount of soap onto both sides of the lens --- less than a grain of rice --- then apply water and rub with your fingers until clean. Skip to polish step.
If using cleaner, spray cleaner onto the cloth, NOT onto the lens. Spray onto one side of the cloth so that you have a wet side and a dry side.
(You can use water instead of cleaner in a pinch.)
Three passes.
First pass: with wet side, wipe lens in lines from top of frame to bottom. NOT in circles. (You'll spread the dirt around this way, making the cleaning process take way longer and potentially introducing scratches.)
Second pass: Repeat first pass with dry side of cloth.
Repeat first and second passes until lenses look mostly clear.
Third pass, if you have a polishing cloth: Wipe polishing clothes in circles until lenses are clear.
Your lenses will last forever if cleaned this way.
The cleaner steps above also work on any glass surface, like laptop screens or car windows.
>Use a clean microfiber cloth. ANYTHING ELSE will scratch your lenses up.
No, it wont. I'm cleaning mine for decades with anything at hand (cotton shirts, napkins, etc) and not a scratch.
And of course there's the little fact that microfiber cloth is a recent synthetic thing. People used cotton and linen squares, or chamois leather ones if they felt fancy, to clean their glasses.
yes they do. it's not so much the cotton fabric that will scratch your lenses; it's the dirt on them. cotton weaves leave bigger holes for dirt to get caught in; much much bigger than microfiber, which is why it's best for the job.
I don't know why people say this. When I wore glasses I cleaned them with my cotton shirts for over a decade and they didn't get scratched up, at all. I don't see how cotton would scratch glass to begin with.
Very few people wear actual glass lenses. They are something like 1-2% of the market from what I can tell. Everyone else wears plastic lenses, which are much lighter and thus more comfortable to wear. Also slightly safer due to much reduced risk of shattering with plastic lenses. I've never even had an optometrist offer glass lenses. I think you'd have to specifically ask for them.
But yeah, dust can also definitely scratch the coatings on glass lenses, too.
Are we still talking about glasses, not contacts right? Because everyone over here (Norway) gets glass lenses in glasses on prescription. They are much better optical quality and not uncomfortable in the slightest, and can be customized to individual vision. Mine have glass from Rodenstock, a long time camera lens supplier but other vendors like Zeiss or Swarowski are common too.
You can always tell if it's glass by tint of PVD coating. Polycarbonate or acrylic lenses can't be coated. Plastic's only advantage is low manufacturing cost.
> You can always tell if it's glass by tint of PVD coating. Polycarbonate or acrylic lenses can't be coated.
This not true. Plastic can absolutely be PVD coated. You can buy cheap sunglasses with PVD mirror coatings on plastic lenses. I’m pretty sure Rodenstock’s own plastic coatings (e.g. “Rodenstock technology Solitaire® Protect Plus 2”) are also a PVD process.
> Plastic's only advantage is low manufacturing cost.
And weight. And shatter resistance. And higher refractive index options.
In USA I've been told by multiple glasses sellers (wrongly, but they believed it) that no companies sell glass lenses anymore. It's apparently rare enough that a lot of stores think it doesn't exist.
They live in an imaginary world where no one ever cleaned glasses until microfiber cloths were widely available.
To clean glasses safely you basically need a soft, clean cloth. Cotton is totally fine. You could get away with a soft clean sponge, too. Or even a soft-ish piece of paper (which is what most disposable lens words are.)
There is lens-cleaning paper (I used to use this in photgraphy), and facial tissue-grade paper.
The latter does tend to scratch over time, if perhaps only slighly, but the damage can accumulate.
I'm on team soft-cotton, with a very-well-worn bandana serving as my usual cleaning material, plastic lenses, no scratches.
Another sin, for glasses, is laying them lens-down, or face-up, on surfaces when not in use. Lens-down of course grinds the lens into whatever is on the surface. Face-up, as you'd wear them, is vulnerable to flipping over (most glasses are top-heavy), so upside down is preferable. Or folded, with the earpieces down and lenses up. In a case is of course preferable to either.
Leaving glasses randomly on chairs, sofas, beds, etc., is also an invitation to catastrophe.
I've lived with people doing many of the above, and their glasses were perpetually scratched and damaged. Given the high cost of a new pair for many of them, this was ... curious.
Most believe whatever marketing material or sponsored "expert" advice is presented to them for "proper care", without actually checking. At least glasses clenaning is a harmless area - people do the same for supplements, diets, and all kinds of health advice too.
Yea, this reads very meticulous to me.
I clean my glasses under running hot water and the micro fibre cloth.
I wash the micro fibre cloth with dish soap from time to time.
In a bind I clean the glass with any clean fabric that feels soft.
Not op, but I bought quite some noo.ma home furniture half a year ago. Not sure if they manufacture it all in Poland, but the design is refreshing, at least.
I'd like to switch to Bitwarden, but my singular focus is on security. I trust 1P because of its reputation in the security community. Does Bitwarden have any drawbacks when compared to 1P, security-wise?
My iOS devices have been repeatedly breached over the last few years, even with Lockdown mode and restrictive (no iCloud, Siri, Facetime, AirDrop ) MDM policy via Apple Configurator. Since moving to 2025 iPad Pro with MIE/eMTE and Apple (not Broadcom & Qualcomm) radio basebands, it has been relatively peaceful. Until the last couple of weeks, maybe due to leakage of this zero day and PoC as iOS 26.3 was being tested.
> restrictive (no iCloud, Siri, Facetime, AirDrop ) MDM policy via Apple Configurator
MDM? That doesn't surprise me. Do you want to know how _utterly_ trivial MDM is to bypass on Apple Silicon? This is the way I've done it multiple times (and I suspect there are others):
Monterey USB installer (or Configurator + IPSW)
Begin installation.
At the point of the reboot mid-installation, remove Internet access, or, more specifically, make sure the Mac cannot DNS resolve: iprofiles.apple.com, mdmenrollment.apple.com, deviceenrollment.apple.com.
Continue installation and complete.
Add 0.0.0.0 entries for these three hostnames to /etc/hosts (or just keep the above "null routed" at your DNS server/router.
Tada. That's it. I wish there was more to it.
You can now upgrade your Mac all the way to Tahoe 26.3 without complaint, problem, or it ever phoning home. Everything works. iCloud. Find My. It seems that the MDM enrollment check is only ever done at one point during install and then forgotten about.
Caveat: I didn't experiment too much, but it seems that some newer versions of macOS require some internet access to complete installation, for this reason or others, but I didn't even bother to validate, since I had a repeatable and tested solution.
I would happily pay Apple an annual subscription fee to run iOS N-1 with backported security fixes from iOS N, along with the ability to restore local data backups to supervised devices (which currently requires at least 2 devices, one for golden image capture and one for restore, i.e. "enterprise" use case). I accept that Apple devices will be compromised (keep valuable data elsewhere), but I want fast detection and restore for availability.
GrapheneOS on Pixel and Pixel Tablet have been anomaly free, but Android tablet usability is << Apple iPad Pro.
USB with custom Debian Live ISO booted into RAM is useful for generic terminal or web browsing.
could you please elaborate on how you determine that your devices have been breached? e.g. referring to "anomaly free" makes it sound like you might witnessing non-security related unexpected behaviour? sorry for the doubt, i'm curious
Explained at length below: after subjective indicator of possible breach, by monitoring, allowlisting and then deleting outbound network traffic sources (i.e. apps) on the device, then look closely at any remaining, non-allowlisted traffic, which should be zero.
By definition you will have access to things Apple wont publish or support at subsidized rates below the fully loaded hourly cost of a senior engineer.
Because you will be paying the full unsubsidized rate for any support needed for features not available to the mass market.
Its like how IBM will gladly send a team of senior engineers to help enterprise clients resolve every last possible request.
Edit: As compared to mass market features, where the economics dont work unless they’re close to 100% certain most users wont require any costly support.
- Signup for Apple Enterprise account with direct billing
- Buy one hardware device direct via Enterprise account
- Buy one MDM license for the hardware device
- Sign contract for support at $500/hr, no minimum commitment
- Get access to docs & tools for iOS 18 on new hardware (don't need support)
Apple Enterprise Developer account requires 100 employees minimum, but Apple Enterprise does not.
> By definition you will have access to things Apple wont publish or support at subsidized rates below the fully loaded hourly cost of a senior engineer.
If you're an Apple Enterprise customer, can you install iOS 18 on a new device today? It appears that enterprises can delay upgrade to iOS 18 post-enrollment, but cannot roll back to or provision iOS 18 on new hardware.
First idea if great honestly - lots of vendors do this. I use Firefox long term stable and Chrome offers this for enterprise customers. Windows even offers multiple options of this (LTSC being the best by far).
Would also make a great corporate / government product - I doubt they care about charging the average consumer for such a subscription (not enough revenue) but I can see risk averse businesses and especially government sectors being interested.
Just to save everyone the read, reading through the replies, this person is very clearly paranoid and has no clear evidence of an actual breach. I have zero idea why people are actually engaging with this.
This thread (on a story about 10 year old 0-day that exposed 2 billion devices to potential breach!) has many comments questioning the mere possibility of repeated breach, yet not a single comment engaging the point of my original post -- that Apple's 2025 introduction of MIE/eMTE changed the observable device behavior vs. Apple devices of the previous five years. On the new iPad Pro, MIE was shipped alongside Apple's $1B investment in modem technology to replace Qualcomm cellular and Broadcom WiFi/BT radios used on billions of existing devices.
Memory Integrity Enforcement (MIE) is the culmination of an unprecedented design and engineering effort, spanning half a decade, that combines the unique strengths of Apple silicon hardware with our advanced operating system security to provide industry-first, always-on memory safety protection across our devices — without compromising our best-in-class device performance. We believe Memory Integrity Enforcement represents the most significant upgrade to memory safety in the history of consumer operating systems.
> has no clear evidence of an actual breach
If the perceived breaches during 5 years of using multiple generations of Apple devices were due to methodology errors leading to false positives, why did they stop after moving to 2025 Apple hardware with MIE and Apple-only radio basebands?
16e still uses a Broadcom chip for WiFi + Bluetooth, though. iPhone Air is currently the only iPhone that uses both Apple-designed baseband + WiFi/BT chips.
Presence of one or more: unexpected outbound traffic observed via Ethernet, increased battery consumption, interactive response glitching, display anomalies ... and their absence after hard reset key sequence to evict non-persistent malware. Then log review.
What are examples of logs that you're considering IOCs? The picture you are painting is basically that most everyone is already compromised most of the time, which is ... hard to swallow.
By minimizing apps on device, blocking all traffic to Apple 17.x, using Charles Proxy (and NetGuard on Android) to allowlist IP/port for the remaining apps at the router level, and then manually inspecting all other network activity from the device. Also the disappearance of said traffic after hard-reset.
Sometimes there were anomalies in app logs (iOS Settings - Analytics) or sysdiagnose logs. Sadly iOS 26 started deleting logs that have been used in the past to look for IOCs.
How did you determine that a connection was malicious? Modern apps are noisy with all of the telemetry and ad traffic, and that includes a fair amount of background activity. If all you’re seeing are connections to AWS, GCP, etc. it’s highly unlikely that it’s a compromise.
Similarly, when you talk about it going away after a reset that seems more like normal app activity stopping until you restart the app.
That doesn’t have any details supporting the belief that this traffic was malicious or a sign of compromise. I’d easily believe that it’s picking up developer telemetry or ad networks but without some hard evidence this sounds like misinterpretation rather than a compromise.
Traffic was monitored on a physical ethernet cable via USB ethernet adapter to iOS device.
Charles Proxy was only used to time-associate manual application launch with attempts to reach destination hostnames and ports, to allowlist those on the separate physical router. If there was an open question about an app being a potential source of unexpected packets, the app was offloaded (data stayed on device, but app cannot be started).
MDM was not used to redirect DNS, only toggling features off in Apple Configurator.
Surely you used several USB Ethernet adapters to rule them out as being the source as well right? Those types of dongles are well known for calling home.
Good observation :) Multiple ethernet adapters: Apple original (ancient USB2 10/100), Tier 1 PC OEM, plus a few random ones. Some USB adapters emit more RF than others.
It excluded the published hostnames for services and CDNs (some of which resolved to GCP, Akamai, etc) published by Apple for sysadmins of enterprise networks, https://news.ycombinator.com/item?id=46994394. It's indeed possible that one of the unknown destination IPs could have been an undocumented Apple service, but some (e.g. OVH) seem unlikely.
So how did you identify this as a breach? I'm struggling to find this credible, and you've yet to provide specifics.
Right now it comes across as "just enough knowledge to be dangerous"-levels, meaning: you've seen things, don't understand those things, and draw an unfounded conclusion.
Feel free to provide specifics, like log entry lines, that show this breach.
Please feel free to ignore this sub-thread. I'm merely happy that Apple finally shipped an iPad that would last (for me! no claims about anyone else!) more than a few weeks without falling over.
To learn iOS forensics, try Corellium iPhone emulated VMs that are available to security researchers, the open-source QEMU emulation of iPhone 11 [1] where iOS behavior can be observed directly, paid training [2] on iOS forensics, or enter keywords from that course outline into web search/LLM for a crash course.
I worked at Corellium tracking sophisticated threats. Nothing you’ve posted is indicative of a compromise. If you’re convinced I’d be happy to go through your IOCs and try to explain them to you.
Thanks. In this thread, I was trying to share a positive story about the recent iPad Pro _NOT_ exhibiting the many issues I observed over 5 years and multiple generations of iPhones and iPad Pros. If any new issues surface, I'll archive immutable logs for others to review.
With the link I provided, a hacker can use iOS emulated in QEMU for:
• Restore / Boot
• Software rendering
• Kernel and userspace debugging
• Pairing with the host
• Serial / SSH access
• Multitouch
• Network
• Install and run any arbitrary IPA
Unlike a locked-down physical Apple device. It's a good starting point.
I'm much more convinced that you're competent in the field of forensics. But I still don't think suspicious network traffic can be categorically defined as a 'device breach.'
For all you know, the traffic you've observed and deem malicious could just as well have been destined for Apple servers.
Apple traffic goes to 17.0.0.0/8 + CDNs aliased to .apple.com, which my egress router blocks except for Apple-documented endpoints for notifications and software update, https://support.apple.com/en-us/101555
They said upthread that they had blocked 17.0.0.0/8 ("Apple"), but maybe there are teams inside Apple that are somehow operating services outside of Apple's /8 in the name of Velocity? I kind of doubt it, though, because they don't seem like the kind of company that would allow for that kind of cowboying.
I don't doubt it in the slightest. Every corporate surveillance firm—I mean, third-party CDN in existence ostensibly operates in the name of 'velocity'.
There’s no hard evidence that you’ve put forward that you’ve been breached.
Not understanding every bit of traffic from your device with hundreds of services and dozens of apps running is not evidence of a breach.
Have you found unsigned/unauthorized software? Have you traced traffic to a known malware collection endpoint? Have you recovered artifacts from malware?
Strong claims require strong evidence imo and this isn’t it.
As mentioned elsewhere in this thread, traffic from each iOS app was traced via Charles Proxy, the endpoints allowlisted for normal behavior, and finally the app was offloaded so it could not generate any traffic from the device. Over time, this provided a baseline of known outbound traffic from the device, e.g. after provisioning a new device with a small number of trusted apps.
I agree with other posters that you seem to be capable of network level forensics, but you have said nothing to back up what you consider a device breach other than 'some cloud destined network traffic which disapears after a hard reset'.
In my experience of forensic reports, this link is tenuous at best and would not be considered evidence or even suspected breach based on that alone.
I don't think that proves they've been breached. Are you sure your not just seeing keep alive traffic or something random you haven't taken into account ?
From another comment - I switched phone to Pixel and it has worked well, with a separate profile for apps that require Google Play Services.
> GrapheneOS on Pixel and Pixel Tablet have been anomaly free, but Android tablet usability is << Apple iPad Pro.
iPad Pro with Magic Keyboard and 4:3 screen is an engineering marvel. The UX overhead of Pixel Tablet and inconsistency of Android apps made workflows slow or even impractical, so I eventually went back to iPad and accepted the cost/pain of re-imaging periodically, plus having a hot-spare device,
Well many of them you may know in that they made their way into so many systems (though arguably without the refined UX of Heroku) but the two that come up the most and I am teaching others:
* The simpler the interface for the user, the more decisions you can make behind the scenes. A good example here is "git push heroku". Not only is that something every user (bot or human) can run, it is also easy to script, protect, and scale. It keeps the surface area small and the abstraction makes the most sense. The code that was behind that push lasted for quite some time, and it was effectively 1-2 Python classes as a service. But once we got the code into our systems, we could do anything with it... and we did. One of the things that blows my mind is that our "slug" (this is what we called the tarballs of code that we put on the runtimes) maker was itself a heroku app. It lived along side everyone else. We were able to reduce our platform down to a few simple pieces (what we called the kernel) and everything else was deployed on top. We benefited from the very things our customers were using.
* NOTE: This one is going to be hard to explain because it is so simple, but when you start thinking about system design in this way the possibilities start to open up right in front of you.
The idea is that everything we do is effectively explained as "input -> filter -> output". Even down to the CPU. But especially when it comes to a platform. With this design mentality we had a logging pipeline that I am still jealous of. We had metrics flowing into dashboards that were everywhere and informed us of our work. We had things like "integration testing" that ran continuously against the platform, all from the users perspective, that allowed us to test features long before they reached the public. All of these things were "input" that we "filtered" in some way to produce "output". When you start using that "output" as "input" and chaining these things together you get to a place where you can design a "kernel" (effectively an API service and a runtime) and start interacting with it to produce a platform.
I remember when we were pairing down services to get to our "kernel" one of the Operations engineers developed our Chef so that an internal engineer needed maybe 5-7 lines of Ruby to deploy their app and get everything they needed. Simple input, that produced a reliable application setup, that could now get us into production faster.
Given that A19 + M5 processors with MIE (EMTE) were only recently introduced, I wonder how extensively MacOS/iOS make use of the hardware features. Is it something that's going to take several years to see the benefit, or does MIE provide thorough protection today?
Apple’s implementation of MTE is relatively limited in scope compared to GrapheneOS (and even stock Android with advanced security enabled) as it’s hardware intensive and degrades performance. I imagine once things get fast enough we could see synchronous MTE enabled everywhere.
It is curious at the moment though that enabling something like Lockdown Mode doesn’t force MTE everywhere, which imo it should. I think the people who are willing to accept the compromises of enabling that would likely also be willing to tolerate the app crashes, worse performance etc that would come with globally enabled MTE.
I think all of the kernel allocators and most (?) system processes in iOS 26 have MIE enabled, as does libpas (the WebKit allocator), so it’s already doing quite a lot.