HNHacker News
TopNewBestAskShowJobs

127361

507 karma · joined October 30, 2023

I think nobody should be going to prison for looking at or storing any image on their computer. Or reading any book or text as well (some countries prosecute possession of certain written material).

Such actions are part of the private sphere, which the state has absolutely no business policing, unless e.g. you commit some violent crime or are diagnosed with a severe mental illness.

The state's policing of what we are allowed to read is a modern day witch hunt.

submissionscomments
127361··on Post Office lied and threatened BBC over Fujitsu dev whistleblower
They had Operation Ore in the early 2000s, thousands of innocent people were arrested and it resulted in 44 suicides.

https://www.theguardian.com/technology/2007/apr/26/comment.s...

https://insidetime.org/newsround/massive-miscarriage-of-just...

127361··on Timeline to remove DSA support in OpenSSH
Sorry, I likely screwed up my reasoning in that comment, I was under a lot of pressure at the time. The option to delete my post is gone, so I can't remove it.
127361··on Timeline to remove DSA support in OpenSSH
Instead we'll have the company going bust for constantly having to replace critical machinery in the name of "security". Sometimes it is necessary to keep old equipment around and it can be secured using physical methods (an air-gap).
127361··on Timeline to remove DSA support in OpenSSH
Or just not upgrading the entire operating system, say for example in an industrial control system. Because we find that this old version of SSH no longer compiles on modern operating systems. Thus making the whole system more vulnerable, so that it can keep communicating with some 10-year old device that cannot be easily replaced.

Again, air-gapping and limiting the physical extent of the network to the room or building would provide significant protection against attacks here.

127361··on Timeline to remove DSA support in OpenSSH
> If you can't update a system, you have no business exposing it to a network. Full stop.

What about isolated networks, a single Ethernet switch for example, used for industrial automation? We can't keep replacing equipment every 5 years because they keep changing crypto protocols.

Many industrial networking protocols have no security at all. No encryption. Not even a password. They achieve their security by being disconnected from the outside world, constrained to a single room or building. If an attacker can get physical access to the wires, then we have a lot more to worry about than network security.

127361··on Cancer Is Striking More Young People, and Doctors Are Alarmed and Baffled
When sucralose is heated above 120C (e.g. baked in an oven) it breaks down into harmful organochlorene compounds, such as Polychlorinated Biphenyls similar in toxicity to 2,3,7,8-TCDD.

2,3,7,8-TCDD is one of the most toxic dioxins known.

https://www.bfr.bund.de/cm/349/harmful-compounds-might-be-fo...

127361··on Cancer Is Striking More Young People, and Doctors Are Alarmed and Baffled
Sucralose is an organochlorine compound, in the same class as PVC, pesticides and nerve agents.
127361··on Cancer Is Striking More Young People, and Doctors Are Alarmed and Baffled
This and all the other food additives combined together, in our modern Western diet. Yes, discovered while trying to make an insecticide.

https://www.medicalnewstoday.com/articles/a-chemical-found-i...

https://www.tandfonline.com/doi/full/10.1080/10937404.2023.2...

Article about Sucralose:

https://www.newyorker.com/culture/goings-on/sweet-nothings

"Over the next year, Hough and Phadnis worked with the British sugar company Tate & Lyle to make more than a hundred chlorinated sugars, finally settling on one that had three chlorine atoms and was about six hundred times as sweet as sugar. “It isn’t of any use as an insecticide,” Hough told me recently. “That was tested.” But it has proved useful as a food. In its pure form, it is known as sucralose. When mixed with fillers and sold in bright-yellow sachets, it’s known as Splenda, the best-selling artificial sweetener in America."

127361··on Why Would I Buy This Useless, Evil Thing?
The market will decide. If nobody likes it then it will flop. If it takes off, then well done to them.

Good to see some form of innovation. Maybe they will create a new category of device, as dozens of Chinese imitators come up with clones? Either way this is all positive.

A device like this with the battery capacity and processing power for running local AI would be very good for privacy.

I could see some people buying it, if someone advertised it as totally private, with no logs or sensitive data stored on even the device itself (i.e. in RAM and gone on power off). So you can ask it anything, it will answer, and there is no trace at all once it's switched off.

127361··on Timeline to remove DSA support in OpenSSH
It would have to be on a small isolated LAN, e.g. within a machine or section of a plant.

Many buses used in industrial control equipment such as CAN bus and Modbus do not use encryption. I suppose there's more risk if you're using TCP/IP and connect laptops that have been online to the LAN, because it's such a common protocol.

But again sophisticated malware could just wait until you have your USB CAN dongle connected to the laptop, and still attack the CAN bus. Heck, CAN bus and Modbus don't even have any password protection at all.

127361··on Timeline to remove DSA support in OpenSSH
Telnet will still work. So if you're developing an embedded device that will keep functioning after 20 years, it's best to not use any crypto at all. I'm half joking here.
127361··on Show HN: Annie – An Uncensored AI Girlfriend
Minimizing all software phoning home as much as possible, and then watching for suspicious network activity.

Also dumping the flash* contents out with JTAG. And even better than that, physically disabling the network interfaces completely and not ever connecting the device to the Internet at all.

* = also the eMMC controller internal firmware, this is where a sophisticated implant will likely reside

It's also very unlikely that the hardware would be compromised, the government doesn't want to waste a potentially high value exploit on ordinary people. If they do, they risk having their exploit captured and exposed, and thus wasting it.

127361··on British Post Office Scandal
Another horrendous scandal in the UK was Operation Ore, twenty years ago. Thousands of people were falsely accused of purchasing child pornography because their credit card numbers were stolen and used by fraudsters.

https://en.wikipedia.org/wiki/Operation_Ore#Controversies

127361··on Show HN: Annie – An Uncensored AI Girlfriend
Yes, I assume the hardware is not compromised, which is much easier to detect.
127361··on Ex Post Office CEO hands back award after IT failures lead to false convictions
All those people that ostracized or otherwise hurled abuse at the postmasters, they can go to hell.
127361··on Show HN: Annie – An Uncensored AI Girlfriend
It would be much nicer if this ran locally. That way you can say anything you want to it, without ever the possibility of someone policing it.
127361··on Gnome Mess Is Not an Accident
It keeps getting worse with each version, and they drag a big part of the open source community with them, because so many apps depend on GTK. Especially important ones like Firefox and Chromium. It absolutely sucks when Gnome controls such a large chunk of the open-source ecosystem.

In fact, it was Gnome that dragged Debian into the systemd debacle. Lennart Poettering managed to convince the Gnome developers to introduce a hard dependency [1] on systemd.

1. https://news.ycombinator.com/item?id=31993161

127361··on Gnome Mess Is Not an Accident
The "Cascade of Attention-Deficit Teenagers" model, or "CADT" for short.

https://archive.is/t5m32

127361··on Gnome Mess Is Not an Accident
Cargo-cult enshittification, where they blindly follow the corporate UX design trends, which are usually dictated by the marketing department, and done to maximize revenue instead of making a usable and productive interface.

Such as following trendy fashionable fads such as low contrast text, excessive whitespace and overuse of animations. Also to make the entire interface a part of the brand identity. In my opinion, these concepts have no place in open source software.

Also: if you don't like the new interface they will say you have problems accepting change, despite it objectively being inferior to the old versions.

KDE has done a lot better than Gnome in this area, by the way.

127361··on Gnome Mess Is Not an Accident
This article sums up what I have been complaining about for nearly a decade.

Yes, it's the GNOME mentality / disease, that has been metastasizing to other areas of the Linux ecosystem such as Freedesktop.org.

The same arrogance can be seen in systemd developers as well (another freedesktop.org / Red Hat project).

127361··on Irish State announce plan to build a porn preference register for most of the EU
Yes, the Internet has created a real life Orwellian nightmare.
127361··on Irish State announce plan to build a porn preference register for most of the EU
No. I support freedom of expression over safety in that case. As long as it's legal under the 1st Amendment, then anything goes. And of course we have the right to counter speech we disagree with.

It is up to the reader to validate whatever I'm saying in my posts and it's their responsibility to disregard them if they're inaccurate.

If I get censored on this forum, then it obviously doesn't align with my values and I will find another one that supports freedom of speech.

127361··on Irish State announce plan to build a porn preference register for most of the EU
I'm suspecting that certain Evangelical Christian groups might have something to do with it. They have front groups with names such "anti exploitation network", where nobody would suspect it's a religious organization behind it.
127361··on Terminal Smooth Scrolling
Blue flash completely destroyed, I confirm it.

This is my userChrome.css (I also have a megabar remover in there, that's not shown here):

* {

    transition-delay: 0ms !important;

    /* This is the magic to kill it 100% */
    transition-timing-function: steps(1, jump-start) !important;

    /* Animation Killer */
    animation-delay: 0ms !important;
    animation-duration: 0ms !important;
    animation-iteration-count: 1 !important;
    animation-timing-function: steps(1, jump-start) !important;
}

Also I have ui.PrefersReducedMotion=1 set in about:config.

127361··on Irish State announce plan to build a porn preference register for most of the EU
Maybe it is shit, maybe it isn't. I'll see if any studies were carried out on it.

I don't really care what you think about it, I'll carry on as usual, and try to correct my mistakes to the best of my ability.

I have rights under the 1st Amendment to express myself freely, including possible amateur psych diagnoses. That's my protected freedom of speech right there.

127361··on Irish State announce plan to build a porn preference register for most of the EU
These addictions are likely a symptom of another problem. It's not the porn itself that's the problem. It's likely childhood trauma or some other adversity that's caused the addiction.
127361··on Inverting PhotoDNA (2021)
Well said.
127361··on Terminal Smooth Scrolling
I eliminated Firefox animations with a custom userChrome.css file. They are all gone.
127361··on Terminal Smooth Scrolling
I personally hate anything that adds unnecessary latency, that's why I disable smooth scrolling and desktop effects. I even have a CSS hack to disable all transitions, animations and fades on the Web. It makes everything instantaneous, which I really like. I also use plain X11 without a compositor, so I have a super low latency desktop that feels really fast.
127361··on AMD proposes an FPGA subsystem user-space interface for Linux
There are existing reverse engineering efforts for AMD Xilinx devices:

https://f4pga.org/

https://f4pga.readthedocs.io/projects/prjxray/en/latest/arch...

https://github.com/f4pga/prjxray

https://github.com/epfl-vlsc/bitfiltrator

← PreviousPage 4 of 8Next →