The Web MiniDisc App (2020)
stefano.brilli.me
stefano.brilli.me
As a side note - I recently found my old MiniDisc player in an old shoebox. Popped in a new AA battery, and it still worked perfectly! Some funny notes... I can't believe it lasts for ages on a single AA battery. And, I had forgotten how noisy they are, with constant whirring and spinning noises coming from the player as it seeks tracks.
Sorry.
We're humans, here's HN. We're just chatting, and misremembering things is alright.
Have a nice and safe weekend. :)
No more devices turning into landfill fodder once their iOS and Android apps stop being updated.
The problem with these technologies are not their utility, but their potential for being abused.
Who on this blue dot ever uses battery percentage meter as another input for browser fingerprinting. That's insane.
I've gotten really tired of this browser fingerprinting FUD. Removing features like WebUSB, WebBluetooth, etc, is not going to make users less fingerprintable. You're 100% fingerprintable from just your browsing activity. Preventing fingerprinting is not just "hard", it's impossible.
But we still get people complaining about it enough that browser vendors implement these security theater mitigations like when Google unilaterally decided WebAudio needed to be hobbled. Are users any less fingerprintable because WebAudio now requires a user activation to run, and timing information needed to have artificial noise added? No, users are still 100% fingerprintable. But now we have to jump through hoops to get it to work, the API as a whole is unusable for timing-critical applications, and old demos and apps are broken.
I'd be fine with a permissions prompt. We have the web app manifest format. Let's use it. It's not like the app stores are doing anywhere near a good job at preventing abuse, anyway. But no, is so often not even an option.
That is what is insane.
I'm sick of fingerprinting itself actually. Coming the office and seeing the ads of stuff my family browsed at home is really getting old now.
> Removing features like WebUSB, WebBluetooth, etc, is not going to make users less fingerprintable.
No, but I think it'll reduce attack surface considerably for boty wired and wireless devices. Just being able to abuse webbt to listen my wireless keyboard or abuse my information stored on an external drive via webusb or just being able to poke around via an untrusted medium by design is perfectly safe as blindly poking a positive coefficient nuclear reactor (we know how well it went in Chernobyl).
> Are users any less fingerprintable because WebAudio now requires a user activation to run? No, users are still 100% fingerprintable.
Again, microphone access?
I think there's a lot of insanity going on the web right now. Exclusion of extremely cool technologies because of a real and big potential for abuse is probably the leading one.
Edit: I also use technologies for their intended purposes, but not everyone is doing that, AFAWCS
Crypto-*: it might be used by criminals!
Anonymous content sharing: it might be used be poedophiles!
Free speech: it might be used by yucky people!
UBI: it might be used as an excuse to not work!
Consumer-grade GPUs: they might be used by cryptominers trying to burn the world!
Paternalism and prior-restraint are anti-democratic. Other people using a tool for bad purposes should have no bearing on my usage.
Let's dig deeper, with your examples:
Crypto: If you're a normal user, you can be private. If you're criminal, you'll get to cover some of your tracks. The other effects are secondary and indirect.
Anonymous content sharing: If you're a normal user, you can share stuff. I personally share stuff this way in HN. It keeps my cloud accounts tidy. It can be used for other nefarious purposes, but it's effects are again secondary.
Free Speech: It shall also be used by yucky people, so we can improve our civilization, systems and ourselves further. It causes a lot of pain I know, but alas, humans probably need it sometimes to evolve. We're lazy otherwise.
UBI: I think it's a neat idea. I can't think any bad examples, sorry.
Consumer Grade GPUs: I don't think using a country's worth of energy to speculate on something's value is hardly efficient, so I'll pass. However, again its effects are secondary.
In all your examples, the receiving party is narrow. The receiving party's number grows because of secondary effect. However, web technologies bring everything to your home, including exploits and abuse.
It's a big can of worms for 1-click and 0-click exploits. "Oh, the web browser was not on the foreground, how my data is exfiltrated?" yeah, webusb/webbt/webaudio.
Crypto cannot directly harm you, neither GPUs. But I can get into your home and violate your with every privacy right with a couple of little, neat technologies.
Maybe you're right. We shall let these technologies loose and allow everyone to snoop into everyone's devices. That'd be equal and democratic. Maybe exploited people will like it and allow more of it. Like the most recent Facebook breach...
While we're at it, I really like the glow of Cherenkov Radiation. I'd like to build a small, fish-tank sized reactor with lead-glass sides. I won't use the material for any other reasons. If only they let me...
Yes, it will.
I don't know of anyone who would seriously argue that less variation between client data doesn't also offer less uniquely identifiable variation between users.
Less remotely-viewable variables, less rolls of chance to be unique.
>Are users any less fingerprintable because WebAudio now requires a user activation to run, and timing information needed to have artificial noise added? No, users are still 100% fingerprintable.
Less fingerprint-able doesn't mean completely un-fingerprintable.
These very edge cases and seemingly unnecessary inclusions into the spec are the very things that allow you to keep the technology in place while reducing possible privacy concerns.
These changes and inclusions are designed as a compromise between the two goals of technological innovation and privacy infringement.
And why, in this sisiphian effort, is the answer to hobble Web APIs, rather than request permissions, as native mobile apps do? Why should there be a functional difference between native mobile apps and web apps? The app stores don't vet submissions, so malicious apps are apparently quite trivial to get into the stores. Users don't really think twice about installing apps. Why do web apps need to be uniquely hobbled in comparison?
I just wish there was a way to automatically turn all this off when I'm just reading an article or filling a form, browsers should have a special app mode.
HTTP Referer header is so unreliable and so frequently used to spam server logs that it would break nothing to remove it completely, yet it's still there and we've got people complaining about the `navigator.hardwareConcurrency` value "leaking information".
Why does WebAudio need a user activation, but WebGL can run straight away, maybe even in a Worker where you'll never even see it?
The userAgent string alone tells you tons of information about a user, especially when you consider how frequently browsers bump version numbers versus how much user upgrade patterns can lag behind. But Ambient Light Events, man, they might be used to capture the user's face, one pixel at a time, over the course of a year, so that's clearly evil, too!
Because it's not really about security. It's all about pushing developers off of the Web and into app stores. Mozilla goes along because they're locked in an abusive relationship with their misinformed users, the 5% of the world that is so-called "privacy conscious" people who comprise their only user base.
If you create an app that makes good use of advanced features, then it has a higher likelihood of being something people are willing to pay for. So what does an app developer do, if they need this functionality? They make a native app instead. The user is still giving up the information (not to mention their email address at the point of purchase), but the app now has to give up 30% of revenue and be at the whims of a group of unelected technocrats' ever-changing, unspecified censorship criteria.
I love the idea of accessing USB devices from JavaScript but I don't want my browser anywhere near them.
Both are great ideas and share technologies, but can (and should) be separate products.
Chrome have stated that they won't do anything to prevent fingerprinting for example.
Flashing a Pixel phone with GrapheneOS.org with nothing but a single page webapp is absolutely magical.
This is a couple of days of work!? I should just quit trying. Dude is a machine.
But then my fingers hurt from typing so much code in such a short timespan. And then all that media attention, it was exhausting.
Maybe, but certainly dude doesn't have the same direction as you. Don't compare yourself to others. Well, unless you're trying to do exactly the same thing.
I wouldn't take this as a reason to quit trying: take it as an inspiration to which to aspire.
Still impressive either way!
There are two implementations in our organization project, one in Python which supports NetMD only and the more complete one written in C/C++.
It‘s still on Github and I should probably get back to working on it again.
Can anyone in the know give a quick explanation why that is the case? I appreciate it's a moot point now with the extreme price of MD-RWs, but every now and then I'm reminded of them and get upset. It's probably out of the question now that there's an MD resurgence like cassettes are enjoying.
I think it's a real shame that there is no way (as far as I know) to use re-writable MiniDiscs in the same way that CR-RWs, for storing generic files.
HiMD does exactly that. It’s a FAT-formatted mass-storage device.
Also, it's good for a relatively high quality recording device when paired with the output stage of a make-shift studio mixer.
Anyone who wants to read about the sound quality, a relevant discussion is here: https://news.ycombinator.com/item?id=26440967
The form link is still open. I'd do what I've said there if a couple of people applies.
I only say that ATRAC3, while being lossy and old, can provide very enjoyable sound. I argue that sound is transparent in SP mode and very high quality in LP2.
I further argue that when combined with Sony's DSP and electronics magic, its sound still holds very well and provides a very rich, detailed and enjoyable listening experience, and can rival today's mid-high end portable devices very, very well.
I tell this as a former orchestra player, btw.
* better battery life (supposedly up to 40 hours on a single AA, but I haven't benchmarked this independently)
* consequentially from the above, your phone's battery is saved for when it _really_ matters, like when you are in the middle of nowhere and need a map to navigate the environment
* a more tactile experience compared to a touchscreen
* works offline, and even without mobile signal coverage
* no adverts
* no interruptions, constant bings and bops and notifications from other apps
* no need for updates - it's already a "dead" platform and was never updatable in the first place
* can still download music from a PC, albeit it takes longer and is slightly harder than loading something onto a micro SD card
* no need to fight stubborn mobile UIs, just the buttons to play, stop and control playback
* some players come with a dedicated remote controller, which is also much more convenient than unlocking your screen to change tracks
* you can focus on just the music or audiobook that you took with you, no temptation to shop for new listens while out and about and no temptation to doomscroll your multimedia feed of choice (Instagram, YouTube, Spotify)
* content never "disappears" from your streaming service until you erase it on purpose
* as long as the laser module works, this device will be usable into ~eternity if your model runs on AA batteries. Your battery life never degrades, and your device will never be artificially obsolesced by its own battery disintegrating.
* the discs are very light and quite small, so it's still possible to get a couple of albums or several hours of speech-quality audio to choose from on the go.
* and of course retro coolness
That said, there are downsides:
* you could mostly get all of these advantages with a single mid-end MP3 player
* cables are a pain once one experiences the wireless life
* download from a PC is a thing, but it's undeniably burdensome because of how long it takes, and until Web MiniDisc, because of the antiquated formats and runtime environments supported by the official software.
* shock-proof, not so much. I don't recommend this for heavy workout in a gym
* the proprietary nature of everything chafes. Downloading music back from the player is impossible, remotes are proprietary, DRM is still a problem when the rest of the world moved on.
All in all, it's an aesthetic choice. An art project, if you will. It's not for everything, but in some ways, on certain days, the coolness makes up for it.
Too bad my MiniDisc players are pre-NetMD devices.
I'm tempted to use this and see if it still works.
I remember using TOSLINK to write tones to a MiniDisc to use on the old Jupiter or Saturn Bells with the unmuted receivers back before MP3 and other digital audio players existed. I want to say we moved to a Creative Nomad, but it didn't have the same cyberpunk feel as discreetly swapping discs into a MD player.
Does anyone know if the masters used were unique MDs or the same as for CDs of the era? I've been wanting to create a FLAC library of MD rips, or at least recreate the playlists to burn onto some blanks if they're the same.
Sony likely made millions off MiniDisc even if it didn't win in the end.