frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

ZoomInfo CEO blocks researcher after documenting pre-consent biometric tracking

https://github.com/clark-prog/blackout-public
88•SignalDr•2h ago

Comments

SignalDr•2h ago
I just got blocked by the CEO of ZoomInfo for documenting surveillance infrastructure on their GTM Studio landing page.

Timeline: 1. CEO posts product demo on LinkedIn 2. I analyze the landing page with Chrome DevTools 3. I post findings in comments (40+ cookies pre-consent, biometrics, etc.) 4. CEO blocks me within minutes

So I'm releasing the full evidence pack publicly: https://github.com/clark-prog/blackout-public

What I found: - Sardine.ai behavioral biometrics (mouse/typing patterns) firing before consent - PerimeterX device fingerprinting pre-consent - 118 unique tracking domains on a single page load - Base64-encoded config showing "enableBiometrics: true" - Formal partnership with Sardine (partnerId: "zoominfo")

The irony: ZoomInfo sells visitor identification tools but uses 3 external fingerprinting vendors on their own site.

All evidence is reproducible. HAR files, deobfuscated code, legal analysis included.

AMA about findings or methodology.

globalnode•1h ago
A lot of orgs operate under the "ask forgiveness later" principle. They were probably hoping the "later" would be much later...
SignalDr•43m ago
Considering that sales/marketing are basically the only business functions that have never been held to a compliance standard, they're betting it never comes.
ethin•41m ago
They're hoping the word "later" is synonymous for "never".
snihalani•40m ago
I wish america was customer first but its always going to be business first
snihalani•40m ago
sorry, investor first*
linkjuice4all•30m ago
Sorry - had to flag this ad posting. Future tip - just release this stuff under one of your employee's or founder's name so it's not as obvious of an ad for the platform you're launching.
Aeglaecia•20m ago
what exactly is being advertised ?
ChrisMarshallNY•11m ago
Looks like deployblackout -dot- com.

Looks like a service to do the kinds of scans mentioned. Note the punchlist of laws being broken.

altairprime•1m ago
[delayed]
helloericsf•26m ago
Thanks for sharing. I bet their DPO and EU customers are super interested in the findings. The CEO should have handled it better, IMO.
chzblck•9m ago
You do know that lots of software is just meshing a few things together and selling that as a service right?

Whos to say that they are making it so those 3 vendors work better together?

edit - Also I just know this is a EU dev who thinks if I build a really good product people will just buy.

mike_d•50m ago
User opens DevTools and loads pretty much any website on the internet, film at 11.
jgalt212•19m ago
> The question to consider: could this data become actionable in litigation?

That's sort of a silly question to pose. That risk always there. It's just a question of estimating that risk. EU is rolling back GDPR, so I'd estimate that risk is getting lower every day.

To play devil's advocate, why should FANG be the only ones allowed to crap all over the public internet's privacy?

superkuh•19m ago
Automatic execution of javascript from arbitrary random domains is the biggest mistake the web ever made. A completely 180 from the old "Don't run programs you don't know where they're from." We're doing this to ourselves. I know it's too late to save the corporate, institutional, etc environments, but in your personal life you should set your primary browser to not auto-execute random programs. It'd solve this.

A new bridge links the math of infinity to computer science

https://www.quantamagazine.org/a-new-bridge-links-the-strange-math-of-infinity-to-computer-scienc...
89•digital55•3h ago•12 comments

Show HN: We built an open source, zero webhooks payment processor

https://github.com/flowglad/flowglad
194•agreeahmed•5h ago•131 comments

Google Antigravity exfiltrates data via indirect prompt injection attack

https://www.promptarmor.com/resources/google-antigravity-exfiltrates-data
505•jjmaxwell4•5h ago•143 comments

ZoomInfo CEO blocks researcher after documenting pre-consent biometric tracking

https://github.com/clark-prog/blackout-public
88•SignalDr•2h ago•14 comments

How to repurpose your old phone into a web server

https://far.computer/how-to/
147•louismerlin•3d ago•63 comments

Ilya Sutskever: We're moving from the age of scaling to the age of research

https://www.dwarkesh.com/p/ilya-sutskever-2
133•piotrgrabowski•6h ago•110 comments

Unifying our mobile and desktop domains

https://techblog.wikimedia.org/2025/11/21/unifying-mobile-and-desktop-domains/
42•todsacerdoti•6h ago•13 comments

FLUX.2: Frontier Visual Intelligence

https://bfl.ai/blog/flux-2
212•meetpateltech•7h ago•65 comments

Launch HN: Onyx (YC W24) – Open-source chat UI

157•Weves•9h ago•112 comments

Trillions spent and big software projects are still failing

https://spectrum.ieee.org/it-management-software-failures
267•pseudolus•11h ago•245 comments

Jakarta is now the biggest city in the world

https://www.axios.com/2025/11/24/jakarta-tokyo-worlds-biggest-city-population
195•skx001•17h ago•123 comments

The fall of Labubus and the mush of modern internet trends

https://www.michigandaily.com/arts/digital-culture/the-fall-of-labubus-and-the-mush-of-modern-int...
13•gnabgib•1d ago•4 comments

Reinventing How .NET Builds and Ships (Again)

https://devblogs.microsoft.com/dotnet/reinventing-how-dotnet-builds-and-ships-again/
4•IcyWindows•54m ago•0 comments

Constant-time support coming to LLVM: Protecting cryptographic code

https://blog.trailofbits.com/2025/11/25/constant-time-support-coming-to-llvm-protecting-cryptogra...
27•ahlCVA•10h ago•12 comments

The 101 of analog signal filtering (2024)

https://lcamtuf.substack.com/p/the-101-of-analog-signal-filtering
112•harperlee•4d ago•9 comments

Python is not a great language for data science

https://blog.genesmindsmachines.com/p/python-is-not-a-great-language-for
100•speckx•6h ago•100 comments

Human brains are preconfigured with instructions for understanding the world

https://news.ucsc.edu/2025/11/sharf-preconfigured-brain/
410•XzetaU8•17h ago•279 comments

Notes on the Troubleshooting and Repair of Computer and Video Monitors

https://www.repairfaq.org/sam/monfaq.htm
3•WorldPeas•51m ago•0 comments

Someone at YouTube Needs Glasses: The Prophecy Has Been Fulfilled

https://jayd.ml/2025/11/10/someone-at-youtube-needs-glasses-prophecy-fulfilled.html
6•jaydenmilne•1h ago•1 comments

Unison 1.0

https://www.unison-lang.org/unison-1-0/
167•pchiusano•3h ago•47 comments

Bad UX World Cup 2025

https://badux.lol/
110•CharlesW•4h ago•32 comments

Inflatable Space Stations

https://worksinprogress.co/issue/inflatable-space-stations/
54•bensouthwood•4d ago•19 comments

Making Crash Bandicoot (2011)

https://all-things-andy-gavin.com/video-games/making-crash/
185•davikr•11h ago•27 comments

A DOOM vector engine for rendering in KiCad, and over an audio jack

https://www.mikeayles.com/#kidoom
5•mikeayles•1h ago•1 comments

Orion 1.0

https://blog.kagi.com/orion
333•STRiDEX•7h ago•194 comments

What They Don't Tell You About Maintaining an Open Source Project

https://andrej.sh/blog/maintaining-open-source-project/
3•andrejsshell•1h ago•0 comments

Most Stable Raspberry Pi? Better NTP with Thermal Management

https://austinsnerdythings.com/2025/11/24/worlds-most-stable-raspberry-pi-81-better-ntp-with-ther...
277•todsacerdoti•16h ago•82 comments

Stop Putting Your Passwords into Random Websites (Yes, Seriously, You Are the PR

https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are...
18•Deeg9rie9usi•2h ago•6 comments

Google steers Americans looking for health care into "junk insurance"

https://pluralistic.net/2025/11/25/open-season/
24•hn_acker•1h ago•3 comments

This blog is now hosted on a GPS/LTE modem (2021)

https://blog.nns.ee/2021/04/01/modem-blog
45•xx_ns•3h ago•5 comments