HNHacker News
TopNewBestAskShowJobs

CapacitorSet

1,489 karma · joined July 27, 2016

[ my public key: https://keybase.io/capacitorset; my proof: https://keybase.io/capacitorset/sigs/3XQYiFYsETBVes6mFixMECaVoMYCJBjVFgwf6JikpeY ]
submissionscomments
CapacitorSet··on Netflix tweet raises privacy questions
>it's flaunting how much 'scary data' you have on the users to say that a file has been accessed 56 times when everyones grandma would be fine with a viewcounter on every video.

I think it's a different matter. A viewcounter is seen as a stateless counter, increasing for every view/user but not going beyond that; Netflix's analysis is seen as stateful tracking, one that tracks a user through his consumption of data. Also, the former is content-focused, whereas the latter is arguably user-focused.

CapacitorSet··on Ask HN: Is a P2P browser possible?
There's also IPFS which is a network of static, hash-addressed content. However, note that the official client comes with "blocklists" which may be used for censorship.
CapacitorSet··on Larry Ellison allegedly tried to have a professor fired for benchmarking Oracle
>this is the norm within the industry and is intended to ensure information accuracy

I like how even they understand that it's a bullshit clause, and try to justify it.

CapacitorSet··on A nefarious but incompetent spyware campaign targeting Ethiopian dissidents
>>A court has ruled that an American citizen born in Ethiopia can’t sue his birth country for hacking his computer and monitoring him with spyware.

I wonder what would happen if the individual in question was from the CIA/FBI/SS, and Ethiopia exfiltrated state secrets. I bet they will find a way to sue, since it's their privacy that was put at risk.

CapacitorSet··on Kata Containers – The speed of containers, the security of VMs
>I'm not sure I get the connection.

.io is the TLD for the British Indian Ocean Territory, technically speaking.

CapacitorSet··on Stanford University data glitch exposes truth about scholarships
The existence of castes - social classes - is in direct contrast with the definition of communism, which seeks a classless society.
CapacitorSet··on Maintaining an Independent Browser Is Expensive
I fail to see how north of 80k$/mo is a reasonable salary. Maybe things are more costly in America, with private insurance and whatnot, but where I live (Italy) few people earn more than €10k/mo after taxes.
CapacitorSet··on Stanford University data glitch exposes truth about scholarships
Castes are about as far from communism as it gets.
CapacitorSet··on Stanford University data glitch exposes truth about scholarships
Aristocracy and privilege are about as far from communism as it gets.
CapacitorSet··on Stanford University data glitch exposes truth about scholarships
A private university, especially privileging students from finance backgrounds, is about as far from communism as it gets.
CapacitorSet··on A Clever Line of JavaScript
That might be clever, but aside from possible performance gains it's worse than the trivial alternative arr.map(it => it.trim()).
CapacitorSet··on Bucket Stream: Finding S3 Buckets by watching certificate transparency logs
A is a realistic case of security by obscurity - there's a sizable amount of people who believe that to be secure.

B is in my opinion much less realistic: very few people believe a password two bytes long (or better, with two bytes of entropy) to be secure. Even a trivial password like "TelnetSucks" scores 31 bits of entropy with https://apps.cygnius.net/passtest/.

CapacitorSet··on Why I don't support Net Neutrality
The way some arguments are exposed is... weird.

Argument 1 ("Free speech will suffer without net neutrality”) boils down to "People say X will happen without net neutrality, X is happening, so we may as well let NN pass" [where X is "interruption of free speech"], while ignoring that free speech is not a binary and that circumventing net neutrality can be one way to deny free speech. Internet censorship is the most basic example of such a situation.

Argument 2 relies on the concept that not only should users pay for their bandwidth and services for theirs, but large services ought to pay once more for their bandwidth w.r.t. "interconnection fees" - but then again, the sentence being discussed ("These ISPs are monopolies, and they need to be regulated”) isn't relevant to NN.

Finally, when talking about Portugal he claims that "Portugal does have net neutrality", when the screenshot above is in direct violation of NN as defined in the link ("End-users should have the right to access and distribute information and content, and to use and provide applications and services without discrimination, via their internet access service.", Recital 6 of the "BEREC Guidelines on Net Neutrality"). At best, he is relying on a weird interpretation of this sentence, where "have the right to access" means "there is at least one plan which does that". Besides, the existence of a European regulation doesn't mean NN is enforced: the same regulation applies to Italy, but I can buy a plan boasting "free social&chat" and 10 GB towards select music services, through Telecom Italia no less (https://www.tim.it/ricarica-automatica).

CapacitorSet··on Super Tiny Website Logos in SVG
ImageMagick's `identify` claims it's a PNG:

    $ curl -OL https://i.imgur.com/dHIaRh1.png
    $ identify dHIaRh1.png
    dHIaRh1.png PNG 512x512 512x512+0+0 8-bit sRGB 3545B 0.000u 0:00.000
CapacitorSet··on Apple’s Secure Enclave Processor (SEP) Firmware Decrypted
Not on HN, where I expect most readers to understand what is firmware and what happens when you have its binaries and/or source code.
CapacitorSet··on Ciao, Chrome: Firefox Quantum Is the Browser Built for 2017
For starters, Google Translate has had a Chrome advert for as long as I remember.
CapacitorSet··on Looking at how many sites use vulnerable JavaScript libraries
I don't understand, what were the scammers trying to achieve?
CapacitorSet··on Net Neutrality will die, so let’s take the profit out of killing it
What makes you think that such a consortium would ensure open access rather than simply privileging its own services?
CapacitorSet··on Skype Vanishes from App Stores in China, Including Apple’s
>I want there to be CENTRALIZED COLLABORATION on a platform, and not competition (eg of browser makers)

>only one major browser

>nothing is RESTRICTED from people and they are free to try new things

What happens when one does a new attempt at a browser, that cannot be merged into the original major browser when it gets big enough?

For a simple example, suppose Google Chrome was the only major browser in such a model. One day, someone decides that C++ is too prone to vulnerabilities, and creates a new browser, called Firefox, based on Rust (on an entirely new codebase). What will happen when Firefox becomes sufficiently large to be considered major?

CapacitorSet··on How the BBC News website has changed over the past 20 years
Huh? It works for me, with a 301 redirect. Truncated output:

    $ curl -Lv http://bbc.co.uk
    > GET / HTTP/1.1
    > Host: bbc.co.uk
    > User-Agent: curl/7.56.1
    > Accept: */*
    > 
    < HTTP/1.1 301 Moved Permanently
    < Location: http://www.bbc.co.uk/
    < 
    > GET / HTTP/1.1
    > Host: www.bbc.co.uk
    > User-Agent: curl/7.56.1
    > Accept: */*
    > 
    < HTTP/1.1 301 Moved Permanently
    < Location: https://www.bbc.co.uk/
    < 
    > GET / HTTP/2
    > Host: www.bbc.co.uk
    > User-Agent: curl/7.56.1
    > Accept: */*
    > 
    < HTTP/2 200 
    < content-type: text/html; charset=utf-8
    < content-length: 270866
CapacitorSet··on Puffs: Parsing Untrusted File Formats Safely
I wouldn't be too sure about that. Rust gives more compile-time guarantees, allowing the compiler not to emit code for otherwise plausible conditions (see eg. pointer aliasing); on the other hand, C compilers typically rely on undefined behaviour to apply optimisations, whereas Rust may not have as much undefined behaviour due to its safety.
CapacitorSet··on Puffs: Parsing Untrusted File Formats Safely
>The aim is to produce software libraries that are as safe as Go or Rust, roughly speaking, but as fast as C, and that can be used anywhere C libraries are used.

I'm all for having different implementations of software, but does Rust not fulfill these requirements?

CapacitorSet··on How Discord Resizes 150M Images Every Day with Go and C++
For ease of reading, that's respectively 51 ms and 3 ms.
CapacitorSet··on 65 out of the 100 most cited papers are paywalled
My apologies, I googled "scihub" and picked the first result in English.
CapacitorSet··on 65 out of the 100 most cited papers are paywalled
Relevant:

[SciHub](https://scihub.org/) is a project to "provide free access to research articles and latest research information without any barrier". It can also be used via Telegram at @scihubot.

CapacitorSet··on How Firefox Got Fast Again
What stops you from launching Firefox with the profile manager twice (there's a flag for that), and selecting the two profiles? It takes a couple of seconds to select the profile.
CapacitorSet··on 8th – A secure, cross-platform, concatenative programming language
Honestly, it might even be the fastest language ever, but if the license prohibits something as basic as sharing benchmarks there is something quite fishy and dystopic.
CapacitorSet··on Show HN: HN Status Page in the style of HN with detailed metrics
I think you commented on the wrong post?
CapacitorSet··on LibHTTP: Open Source HTTP Library in C
>It removes a lot of complexity from your code.

Not to mention, Nginx implements quite a lot of features that are probably missing in LibHTTP, or implements them in a more performant way.

CapacitorSet··on WTF? Chromium (2016)
>the author is basically complaining that Chromium decided to update itself. Well, maybe it warrants complaint, but I fail to see what's such a big deal. (The alternative is millions using browsers ridden with last year's vulnerabilities.)

You're misrepresenting mandatory enrolment in A/B testing with plain software updates. Firefox is an example of a browser that does software updates, but does not force you to use potentially buggy features - and yet they do not have "millions using browsers ridden with last year's vulnerabilities", because their alternative is to give users a choice to enroll in experiments. I do participate in experiments since I wish to improve Firefox, but I could switch to any time to no experiments at all.

← PreviousPage 6 of 9Next →