← Back to context

Comment by HackerThemAll

12 hours ago

> appearance-wise it looks very noisy/distorted with some crooked elements (especially window buttons) and missing visual parts (mainly bevel edges).

Nitpicking. Let me reflect - runtimeterror.com has no https which is available for free, so I'm not entering it.

> runtimeterror.com has no https which is available for free, so I'm not entering it

I think your threat model needs some work here. What exactly does https guard against when downloading a jpeg? A intermediary swapping it out for a different jpeg?

Downloading things from an unknown domain over https still carries the risk of the site itself vending you malware...

  • Perhaps a compromised device on the local network can MiTM a javascript payload that exploits three zero days on HackerThemAll's browser stack, pwning his computer and finally enabling his super advanced, persistent adversaries to get exfiltrate his super important data.

    And all that for what, for a VB6 screenshot on a hn comment threat while procrastinating on top secret work ?

    Nah, not worth it.

> runtimeterror.com has no https which is available for free, so I'm not entering it.

It is a direct image link, it wont ask your password.

Also, https is not available for free even if some solutions are available without asking money for it. In this case: the site is on a shared host so the only option is the paid one from the host (so it isn't free-as-in-money) while the alternative is having a VPS and installing something like let's encrypt (which is more expensive than the shared host and requires me to play sysadmin for it, so not only it isn't free-as-in-money but also free-as-in-time).