26.xhtml 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140
  1. <?xml version="1.0" encoding="utf-8"?>
  2. <!--
  3. h t t :: / / t /
  4. h t t :: // // t //
  5. h ttttt ttttt ppppp sssss // // y y sssss ttttt //
  6. hhhh t t p p s // // y y s t //
  7. h hh t t ppppp sssss // // yyyyy sssss t //
  8. h h t t p s :: / / y .. s t .. /
  9. h h t t p sssss :: / / yyyyy .. sssss t .. /
  10. <https://y.st./>
  11. Copyright © 2016 Alex Yst <mailto:copyright@y.st>
  12. This program is free software: you can redistribute it and/or modify
  13. it under the terms of the GNU General Public License as published by
  14. the Free Software Foundation, either version 3 of the License, or
  15. (at your option) any later version.
  16. This program is distributed in the hope that it will be useful,
  17. but WITHOUT ANY WARRANTY; without even the implied warranty of
  18. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  19. GNU General Public License for more details.
  20. You should have received a copy of the GNU General Public License
  21. along with this program. If not, see <https://www.gnu.org./licenses/>.
  22. -->
  23. <!DOCTYPE html>
  24. <html xmlns="http://www.w3.org/1999/xhtml">
  25. <head>
  26. <base href="https://y.st./en/weblog/2016/03-March/26.xhtml" />
  27. <title>Proof that Patreon is preventing Tor-users from logging in &lt;https://y.st./en/weblog/2016/03-March/26.xhtml&gt;</title>
  28. <link rel="icon" type="image/png" href="/link/CC_BY-SA_4.0/y.st./icon.png" />
  29. <link rel="stylesheet" type="text/css" href="/link/basic.css" />
  30. <link rel="stylesheet" type="text/css" href="/link/site-specific.css" />
  31. <script type="text/javascript" src="/script/javascript.js" />
  32. <meta name="viewport" content="width=device-width" />
  33. </head>
  34. <body>
  35. <nav>
  36. <p>
  37. <a href="/en/">Home</a> |
  38. <a href="/en/a/about.xhtml">About</a> |
  39. <a href="/en/a/contact.xhtml">Contact</a> |
  40. <a href="/a/canary.txt">Canary</a> |
  41. <a href="/en/URI_research/"><abbr title="Uniform Resource Identifier">URI</abbr> research</a> |
  42. <a href="/en/opinion/">Opinions</a> |
  43. <a href="/en/coursework/">Coursework</a> |
  44. <a href="/en/law/">Law</a> |
  45. <a href="/en/a/links.xhtml">Links</a> |
  46. <a href="/en/weblog/2016/03-March/26.xhtml.asc">{this page}.asc</a>
  47. </p>
  48. <hr/>
  49. <p>
  50. Weblog index:
  51. <a href="/en/weblog/"><abbr title="American Standard Code for Information Interchange">ASCII</abbr> calendars</a> |
  52. <a href="/en/weblog/index_ol_ascending.xhtml">Ascending list</a> |
  53. <a href="/en/weblog/index_ol_descending.xhtml">Descending list</a>
  54. </p>
  55. <hr/>
  56. <p>
  57. Jump to entry:
  58. <a href="/en/weblog/2015/03-March/07.xhtml">&lt;&lt;First</a>
  59. <a rel="prev" href="/en/weblog/2016/03-March/25.xhtml">&lt;Previous</a>
  60. <a rel="next" href="/en/weblog/2016/03-March/27.xhtml">Next&gt;</a>
  61. <a href="/en/weblog/latest.xhtml">Latest&gt;&gt;</a>
  62. </p>
  63. <hr/>
  64. </nav>
  65. <header>
  66. <h1>Proof that Patreon is preventing <abbr title="The Onion Router">Tor</abbr>-users from logging in</h1>
  67. <p>Day 00385: Saturday, 2016 March 26</p>
  68. </header>
  69. <p>
  70. It seems that the cause of the error when retrieving the file on Patreon for logging in is due to Patreon using a second CloudFlare-blocked domain for their scripts.
  71. I fill out their moronic <abbr title="The Onion Router">Tor</abbr>-discriminating <abbr title="Completely Automated Public Turing test to tell Computers and Humans Apart">CAPTCHA</abbr> for their main domain, but I&apos;m never presented with the second one, as it&apos;s not at a Web page.
  72. Basically, their JavaScript is behind a <abbr title="Completely Automated Public Turing test to tell Computers and Humans Apart">CAPTCHA</abbr> wall.
  73. CloudFlare is screwy and JavaScript logins are screwy, so when you combine them, you get something even more screwy.
  74. I&apos;m not sure if I should report this finding or not.
  75. If I do, they may just tell me to pay a visit to the second domain to fill out the <abbr title="Completely Automated Public Turing test to tell Computers and Humans Apart">CAPTCHA</abbr> every time.
  76. This is not an acceptable solution.
  77. While the <abbr title="Completely Automated Public Turing test to tell Computers and Humans Apart">CAPTCHA</abbr> on the main domain is not acceptable, at least it&apos;s visible.
  78. This secondary <abbr title="Completely Automated Public Turing test to tell Computers and Humans Apart">CAPTCHA</abbr> that an ordinary user would never find is in even more need of fixing.
  79. </p>
  80. <p>
  81. We went to the emergency rescue training to pretend to be victims of a disaster.
  82. It mostly went well, and though I was asked for my name twice, my mother was out of earshot both times and didn&apos;t suspect a thing.
  83. I ended up playing the dead victim, while everyone else had various injuries.
  84. Two injuries were fatal, though the victims didn&apos;t die until during treatment.
  85. When we were finished, they brought in pizza.
  86. I assumed that I wouldn&apos;t be eating, but it turns out that they also had salad, so there was something that I could eat after all.
  87. </p>
  88. <p>
  89. I received a postal letter from Discover today asking if I&apos;d like to open up a savings account.
  90. I don&apos;t currently have enough money to open the account, but it does sound like a good idea for the future.
  91. Discover has mostly been good to me, and I wouldn&apos;t mind doing all my banking online.
  92. I need to know if that&apos;s even possible though.
  93. How would I deposit paychecks? I&apos;ve never seen a Discover branch, and I assume that they are online only.
  94. I don&apos;t use proprietary software, so if a sourceless mobile application is required, I&apos;d have no way to deposit checks.
  95. How would I withdraw cash? I love having a card for online purchases, but in-person, I pay in cash.
  96. This isn&apos;t going to change any time soon.
  97. If having a secondary account at another institution is required for either of these tasks (for example, to deposit into the secondary account and wire it to my Discover account), it would severely limit the usefulness of having a Discover savings account.
  98. After all, what&apos;s the point of setting up an account with an online bank when an account with an in-person bank is still required? I wrote to Discover asking about these things, and they say that they&apos;ll get back to me in twenty-four hours.
  99. </p>
  100. <p>
  101. I finished my documentation of <a href="https://notabug.org./y.st./include.d">include.d</a>.
  102. (Volatile Git seems to be down right now, otherwise I would have linked to it there.) There&apos;s still much to do though.
  103. I&apos;ve added several @deprecated tags in places where the proper ways of doing things haven&apos;t even been coded yet, as well as added several @todo tags.
  104. I think that this documentation in the comments should help me get more organized.
  105. I now have a very unified way of keeping track of what still needs to be done.
  106. I also now have a few different tasks that need to be completed in include.d, and I might even work on them concurrently in different branches.
  107. The most urgent task is probably getting a documentation comment parser built.
  108. phpDocumentor is ironically not documented well enough to figure out how to use, so I&apos;ll need to build my own way to build documentation from comments to get my documentation online in the mean time.
  109. Once phpDocumentor is well-documented, I&apos;ll probably switch to it.
  110. The task I&apos;m most interested in though is cleaning up my <abbr title="Uniform Resource Identifier">URI</abbr> class, extending it with scheme-specific classes needed for Gopher page interpretation, and fixing up my <code>gopher()</code> function.
  111. Last and admittedly least, several smaller cleanup and optimization tasks need to be performed, including adding more inline comments and fixing minor function input/output issues.
  112. </p>
  113. <p>
  114. I received an email today about a job opening at a grocery store, so I&apos;ll probably apply for that tomorrow.
  115. I should have applied today, but I was quite eager to finish my documentation comments.
  116. Without those done, I wasn&apos;t really free to take my code in any direction.
  117. Likewise, spring break seems to have ended yesterday, so this Monday, I&apos;ll be more able to focus on job hunting, as there&apos;ll be less people around the house during the day to distract me.
  118. </p>
  119. <hr/>
  120. <p>
  121. Copyright © 2016 Alex Yst;
  122. You may modify and/or redistribute this document under the terms of the <a rel="license" href="/license/gpl-3.0-standalone.xhtml"><abbr title="GNU&apos;s Not Unix">GNU</abbr> <abbr title="General Public License version Three or later">GPLv3+</abbr></a>.
  123. If for some reason you would prefer to modify and/or distribute this document under other free copyleft terms, please ask me via email.
  124. My address is in the source comments near the top of this document.
  125. This license also applies to embedded content such as images.
  126. For more information on that, see <a href="/en/a/licensing.xhtml">licensing</a>.
  127. </p>
  128. <p>
  129. <abbr title="World Wide Web Consortium">W3C</abbr> standards are important.
  130. This document conforms to the <a href="https://validator.w3.org./nu/?doc=https%3A%2F%2Fy.st.%2Fen%2Fweblog%2F2016%2F03-March%2F26.xhtml"><abbr title="Extensible Hypertext Markup Language">XHTML</abbr> 5.1</a> specification and uses style sheets that conform to the <a href="http://jigsaw.w3.org./css-validator/validator?uri=https%3A%2F%2Fy.st.%2Fen%2Fweblog%2F2016%2F03-March%2F26.xhtml"><abbr title="Cascading Style Sheets">CSS</abbr>3</a> specification.
  131. </p>
  132. </body>
  133. </html>