Sign in

Karan Saini

@karansaini.com
302 followers 386 following 52 posts

hacker, researcher. blog at karansaini.com New Delhi

PostsRepliesMedia
Karan Saini @karansaini.com · 02/03/2026
The report, list of 43,083 blocked domains, raw DNS measurements, and code, are released publicly. dnsblocks.in
dnsblocks.in
Poisoned Wells - Examining the scale of DNS censorship in India
A survey of the entire visible domain name space across 6 Indian ISPs, producing the largest known list of blocked domains (43,083) and revealing previously undocumented instances of overblocking.
1157
Karan Saini @karansaini.com · 02/03/2026
Except for terrorism-related content, there is little consensus among ISPs on which domains to block.
171
Karan Saini @karansaini.com · 02/03/2026
MTNL’s consumer blocklist appears to derive from filtering policies meant for government offices. Services such as Telegram, Dropbox, Discord, and even Slack, are blocked.
151
Karan Saini @karansaini.com · 02/03/2026
Airtel, the second-largest ISP, is blocking an entire top-level-domain (.yokohama), likely due to a regex misconfiguration. This is unprecedented. The TLD currently has around 5,000 domains, all blocked.
181
Karan Saini @karansaini.com · 02/03/2026
Highlights: 43,083 domains blocked in India using DNS filtering, though this number likely represents a lower bound, owing to methodological and protocol limitations.
181
Karan Saini @karansaini.com · 02/03/2026
Excited to share “Poisoned Wells,” which presents the largest point-in-time study of website blocking in India to date. I tested the blocking of 294 million apex domains across six Indian ISPs, sending 1.76 billion DNS queries in total.
5289
Reposted by Karan Saini
Bob Lord @boblord.bsky.social · 20/12/2024
VPN vendors have huge budgets to advertise on your favorite podcasts. We don't have marketing for the IETF, browser and OS security teams, CAs (Let's Encrypt), CDNs, researchers, open source authors, website builders, digital rights activists... We made the web secure and didn't tell anyone.
10814177
Reposted by Karan Saini
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 20/12/2024
NEW: Cybersecurity experts, who work with human rights defenders and journalists, agree that Apple is doing the right thing by sending notifications to victims of mercenary spyware — and at the same time refusing to forensically analyze the devices. “These notifications have been a game changer."
techcrunch.com
Why Apple sends spyware victims to this nonprofit security lab | TechCrunch
Cybersecurity experts, who work with human rights defenders and journalists, agree that Apple is doing the right thing by sending notifications to victims of mercenary spyware — and at the same time r...
310338
Reposted by Karan Saini
netspooky @vacci.ne · 18/12/2024
The @phrack.org 72 CFP horny emojipasta has hit the chats
Screenshot of a copypasta that is in the replies
34921
Reposted by Karan Saini
—>realhackhistory.org @bsky.realhackhistory.org · 19/12/2024
It took quite a while hunting through newspaper archives, but this is what Joseph Popp actually looked like when he was arrested. Weird that someone considered the grandfather of ransomware is so poorly documented. Sources online get the date of his death wrong & the spelling of his middle name too.
Poor quality scan of a black and white image from a newspaper from March of 1990 called The Vindicator, a photo of a man with receding hair and a bushy beard and moustache who may be handcuffed. Caption reads "Joseph Popp is led from federal court in Cleveland. The suburban Cleveland man us accused of distributing computer disks with a virus that locked up machines in England and Africa."
121
Reposted by Karan Saini
Rebecca R Helm @rebeccarhelm.bsky.social · 12/12/2024
Holy crap
109837
Reposted by Karan Saini
Sean Lyngaas @snlyngaas.bsky.social · 04/12/2024
White House official: 8 US telecom providers hacked by Chinese www.cnn.com/2024/12/04/p...
cnn.com
White House official: 8 US telecom providers hacked by Chinese | CNN Politics
US officials believe Chinese hackers breached at least eight US telecommunications providers in their quest to spy on top US political figures as part of a hacking campaign that has affected dozens of...
098
Karan Saini @karansaini.com · 02/12/2024
first name + .forsale 🫨
000
Karan Saini @karansaini.com · 02/12/2024
I found in 2019 that DMs were soft deleted, you could even fetch both deleted DMs and DMs exchanged with deactivated accounts from the Twitter API and the account archive. www.theverge.com/2019/2/15/18...
theverge.com
Twitter has been storing your ‘deleted’ DMs for years
Including those sent to and from deactivated or suspended accounts
020
Reposted by Karan Saini
—>realhackhistory.org @bsky.realhackhistory.org · 30/11/2024
I wrote a series of blogs (that I’ll be adding to as I go) that document times in the #history of #hacking that journalists found themselves becoming part of the story that they were writing about #hackers. I labeled the blogs “Hackers & Reporters”.
152
Reposted by Karan Saini
Taggart @taggart-tech.com · 22/11/2024
This is your reminder that DMs here are _not encrypted_. They're not even really part of ATProto. It's on the roadmap, but that's not the case now. DMs are centralized and unencrypted. Behave accordingly.
56127
Reposted by Karan Saini
hrbrmstr 🇺🇦 🇬🇱 🇨🇦 🏳️‍🌈 @hrbrmstr.dev · 20/11/2024
I know this is in the Drop I just posted, but y'all really need to try out ATFile — github.com/electricduck... It lets you upload & download arbitrary files to Bluesky's Blob storage (or any ATptodo PDS). The Blobs don't show up in your timeline, they just "exist". Store your MP3 collection! 1/2
github.com
GitHub - electricduck/atfile: 📦➔🦋 Store and retieve files on the ATmosphere
📦➔🦋 Store and retieve files on the ATmosphere. Contribute to electricduck/atfile development by creating an account on GitHub.
2232
Karan Saini @karansaini.com · 20/11/2024
come for the malware, stay for the posts
020
Reposted by Karan Saini
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 20/11/2024
NEW: The U.S. government has announced charges against five alleged hackers who targeted several companies stealing millions of dollars in crypto, and corporate data. DOJ says the hackers are part of the infamous Scattered Spider cybercrime group. techcrunch.com/2024/11/20/u...
techcrunch.com
US charges five accused of multi-year hacking spree targeting tech and crypto giants | TechCrunch
The five alleged hackers are accused of stealing millions of dollars in crypto, and corporate data from several victims all over the world.
0295
Reposted by Karan Saini
wint @dril.bsky.social · 14/11/2024
as a gamer ive eliminated thousands of moo deng like creatures for their various parts . Ive completed countless quests using their pain
205384303236
Karan Saini @karansaini.com · 10/11/2024
was just inviting people over!
010
Karan Saini @karansaini.com · 30/07/2024
It’s legal in the United States under the Truth in Caller ID Act, 2009, in certain circumstances. It’s unlawful when done with the intent of defrauding others. The rationale behind allowing it is that some businesses might want to advertise their pay-per-minute or toll-free number when they call.
110
Karan Saini @karansaini.com · 29/07/2024
what video? :)
100
Karan Saini @karansaini.com · 29/07/2024
Ha! I wouldn’t have thought, but that is great. They seem active too! And yes. They’re currently relying on reports from subscribers, which could indicate a lack of adequate automated detection at the telecom operator level. Thanks for reading!
010
Karan Saini @karansaini.com · 29/07/2024
What is being done about caller ID spoofing in India? My piece for the Text and Context section in The Hindu today.
363
Karan Saini @karansaini.com · 31/12/2023
This project now catalogues over 10,000 websites known to be blocked on the ACT Fibernet network. 4,226 new hostnames were added since the last update in June. github.com/qurbat/block...
github.com
GitHub - qurbat/blocked-hosts: A periodically updated list of websites known to be blocked in India
A periodically updated list of websites known to be blocked in India - GitHub - qurbat/blocked-hosts: A periodically updated list of websites known to be blocked in India
042
Karan Saini @karansaini.com · 20/10/2023
BharOS was touted as an indigenously developed secure and private mobile operating system. But is it? My piece for The News Minute from today. www.thenewsminute.com/news/what-bh...
thenewsminute.com
What BharOS, India’s ‘homegrown’ answer to Android, says about our credulity
In a development that has sparked outrage among India's free and open source software communities, it has come to light that India's much-hyped ‘indigenously de
097
Karan Saini @karansaini.com · 25/09/2023
The Supreme Court has dismissed a petition requesting for the source code of Electronic Voting Machines to be made public. The court stated that publishing the source code would make EVMs vulnerable. This line of reasoning is fallacious and ill-informed. m.thewire.in/article/law/...
m.thewire.in
SC Refuses to Hear Plea Seeking Audit into Source Code of Software Used in EVMs
A three-judge Bench, headed by Chief Justice D.Y. Chandrachud, disallowed the petition on the grounds that making the source code public would make the machines vulnerable to hacking.
041
Karan Saini @karansaini.com · 21/09/2023
You can create a post with an arbitrary date and time from the past if you call the Bluesky post creation API directly. bsky.app/profile/sain...
020
Karan Saini @karansaini.com · 20/09/2023
It turns out that you can pass an arbitrary datetime value for the 'createdAt' parameter when creating a new post. I've linked a post of mine below with a datetime value of 1970-01-01T00:00:00.000Z. The datetime value appears to have been offset to January 1, 1970, 5:30 AM, Indian Standard Time.
231
Karan Saini @karansaini.com · 19/09/2023
It's quite possible it is only happening in India. I was only able to confirm that the post in question was withheld in India at the request of the Government (users from other countries were able to access it), but I wasn't able to confirm whether the same notice is shown to non-Indian users.
120
Karan Saini @karansaini.com · 19/09/2023
Twitter (X) seems to no longer display a notice for when a given post has been blocked at the request of the Government. Instead, a nondescript notice is shown, simply reading "This Post is unavailable."
263
Reposted by Karan Saini
wint @dril.bsky.social · 13/08/2023
this site needs a badge i can pay $8 a month for to trick people into thinking I am a Mod
465046708
Karan Saini @karansaini.com · 04/09/2023
www.livelaw.in/high-court/t...
livelaw.in
Can't Deny A Citizen's Statutory Rights For Not Having Aadhar Card: Telangana High Court Reiterates
The Telangana High Court has reiterated that a citizen of India cannot be denied his/her statutory rights for not possessing an Aadhar Card.
051
Karan Saini @karansaini.com · 27/08/2023
starting something new
130
Reposted by Karan Saini
Mike Drucker @mikedrucker.bsky.social · 25/08/2023
more like a SMUGshot! siri please send when official headshot released. siri please dim lights and set alarm for 9:30 am.
1867
Karan Saini @karansaini.com · 23/08/2023
Also true
010
Karan Saini @karansaini.com · 23/08/2023
India is on the moon
1124
Reposted by Karan Saini
wint @dril.bsky.social · 16/08/2023
if you are a stupid ass reddit poster from fucking reddit me and my crazy friends will put you in a head lock
302227291
Karan Saini @karansaini.com · 16/08/2023
Indian movies vilifying Muslims spark fear ahead of polls tribune.com.pk/story/2431004/indian…
tribune.com.pk
Indian movies vilifying Muslims spark fear ahead of polls
Critics accuse recent movie releases of peddling lies and amplifying divisive narratives ahead of national elections
000
Reposted by Karan Saini
Vasabjit Banerjee @vasabjit.bsky.social · 16/08/2023
Zero statements from the Biden admin about India technically exporting* defense equipment to Russia. Quite disappointing. *Russia is calling it "re-importing".
122
Reposted by Karan Saini
they/them might be giants ☭ @babadookspinoza.bsky.social · 12/08/2023
You used to be able to complain to corporate accounts and get refunds but now they’ll just quote you with “this mfer does NOT have the meats 🤣“
427433
Reposted by Karan Saini
kilgore trout @kilgoretrout.bsky.social · 12/08/2023
I swear to god if you made a wallet inspector badge out of construction paper and showed it to these people it would work a hundred times in a row
221084193
Karan Saini @karansaini.com · 12/08/2023
just chilling wbu
110
Karan Saini @karansaini.com · 12/08/2023
у меня есть сабака
000
Karan Saini @karansaini.com · 10/08/2023
which site is this?
000
Reposted by Karan Saini
Spoo Keidick @donkeidick.bsky.social · 04/08/2023
“Stop the car. Stop the fucking car NOW”
301541411
Karan Saini @karansaini.com · 04/08/2023
Quick, someone jump on his head
000
Karan Saini @karansaini.com · 20/07/2023
In 2001, a year after Mitnick was released from prison, the documentary film "Freedom Downtime" was released. The film, directed by 2600 Magazine editor Emmanuel Goldstein, documented Mitnick's case and the "FREE KEVIN" campaign. www.youtube.com/watch?v=WN4fCK23Srk
youtube.com
FREEDOM DOWNTIME - Kevin Mitnick Hacking Documentary
Freedom Downtime is a 2001 documentary film sympathetic to the convicted computer hacker Kevin Mitnick, directed by Emmanuel Goldstein and produced by 2600 F...
040
Karan Saini @karansaini.com · 20/07/2023
Throughout 1998 & 1999, the 2600 Hacker Quarterly dedicated several of their magazine cover pages to bring attention to the "FREE KEVIN" campaign. The campaign played a significant role in helping Kevin Mitnick receive a more lenient sentence following his arrest in 1995.
181