HNHacker News
TopNewBestAskShowJobs

DoctorNick

815 karma · joined October 28, 2016

submissionscomments
DoctorNick··on Jeffrey Epsteins Little Black-Book Unredacted [pdf]
Clearly you have not heard of the all-powerful Floridian Massage Parlor lobby.
DoctorNick··on The M1 MacBook Air is the best computer I've ever owned
Unfortunately, you don't actually "own" it. https://sneak.berlin/20201112/your-computer-isnt-yours/
DoctorNick··on Voice of America CEO Accused of Fraud, Misuse of Office All in One Week
An employee of Voice of America is accused of propagandizing it?! Say it isn't so!
DoctorNick··on AWS Session Manager: A better way to SSH
HTTPS is broken on this website.
DoctorNick··on IntelliJ Idea 2020.3.1 Is Out with Apple Silicon Support
yeah, stop using python
DoctorNick··on When free software isn't practically superior (2015)
...why wouldn't you name any of them?
DoctorNick··on A leak containing a register with the details of nearly two million CCP members
McCarthyism is back, baby! This time with extra racism!
DoctorNick··on I accidentally built a spying app
well, stop doing that.
DoctorNick··on Colombia is considering legalizing its cocaine industry
CIA: "What's that? You want ANOTHER coup? Ok..."
DoctorNick··on ‘Extremely aggressive’ internet censorship spreads in the world’s democracies
>I found quite surprising that Japan censored The Washington Post and the Wall Street Journal for G20. What would be the reason for that? It's not like they would provoke disturbances.

No, but they would have covered the protests against it.

DoctorNick··on Bypassing Firewalls in macOS Big Sur
Well, this basically confirms my decision to not purchase a macbook for my next laptop.
DoctorNick··on Voters overwhelmingly back community broadband in Chicago and Denver
Maybe they could take some money from the police budget. I recall some protests to that effect.
DoctorNick··on Zero-Days in Desktop Web Browsers
this is basically an advertisement for an IE spin-off.
DoctorNick··on TeXmacs 1.99.14 released. Take a look at this research paper exported to HTML
Heh, I thought that David Harvey had switched fields for a second there.
DoctorNick··on Bizarre Design Choices in Zoom’s End-to-End Encryption
Because it fuckin' rocks, that's why.
DoctorNick··on YouTube-dl is now part of GitHub/dmca.git
The people who are responsible for this SHOULD have their lives made as difficult as possible.
DoctorNick··on Uber Wasted $2.5B on Self-Driving Cars
They rushed headlong into this, knowingly stealing IP from Google in the process, because their business model is currently unsustainable with human labor and this is the only way to make it work. It's unsurprising that they're struggling.
DoctorNick··on How I bypassed Cloudflare's SQL Injection filter
All you got was a lousy t-shirt? You could have easily sold that on the black market for tens of thousands of dollars.
DoctorNick··on Post-Open Source
people who aren't self-absorbed enough to think that their preferred newssite is the center of all activity in their industry?
DoctorNick··on Post-Open Source
>Either way, LLVM's license is still Free Software, still Open Source. And LLVM's permissive license is actually proof that you don't necessarily need a copyleft license to get companies to contribute. And we've got a whole ecosystem of such projects built with permissive licenses, hello BSD/OS.

It's also enables proprietary extensions, easily enabling companies to make compilers for their proprietary languages, see CUDA. That seems pretty contrary to the mission of free software.

Also, just curious, how many patches have FreeBSD and co. actually received back from Sony and Apple in the past few years? They still seem to be struggling to add features to the point of begging for 802.11ac support.

DoctorNick··on Ubuntu 20.04 LTS’ snap obsession has snapped me off of it
Flatpak's sandboxing is an absolute joke and entirely voluntary.
DoctorNick··on Google: Open Letter to Australians
nope, Google doesn't give a shit about that. They just hate having to pay for displaying content from news media.
DoctorNick··on How long since Google said a Google Drive Linux client is coming?
Hope you've properly secured it, because if not, everyone will have access to your data and metadata.
DoctorNick··on Why is there only one Snap Store?
Yeah, but Linux Mint still has snapd removed by default and refuses to support it; so do most of the other popular downstream distros (PopOS, elementaryOS) for desktops. Together, they have way more desktop share than Ubuntu does.

Sure, there are other distros not based on Ubuntu that technically support snapd, but I have yet to encounter one that does it well; Manjaro's still breaks on many snaps, Fedora's snapd stopped working completely for over 3 months and nobody noticed. Pretty much nobody but Ubuntu users actually care about snaps; Flatpak has way, way more support and penetration than snaps do, and it looks as if that isn't going to change any time soon due to Canonical's refusal to open-source the snap store. I don't think snaps have much of a future as a widely-supported method of package distribution if this doesn't change.

DoctorNick··on I Tried to Live Without the Tech Giants. It Was Impossible
Absolutely. The material interests of the shareholders ultimately drive the decisions that these companies make. If you invest in them, you are complicit.
DoctorNick··on I Tried to Live Without the Tech Giants. It Was Impossible
As Snowden says, tech workers are complicit in how their companies hurt society: https://www.vice.com/en_us/article/wxqx8q/snowden-tech-worke...
DoctorNick··on Why is there only one Snap Store?
>You can have very secure deb packages by having default-deny apparmor rules.

Nobody would do this on a desktop because it is massively inconvenient to go through every single app you want to run and debug which app armor rule that it's violating. Even when running a service with a pre-written app-armor profile you usually have to spend a while to figure out what the hell went wrong.

Flatpak's sandboxing is a complete joke and is entirely voluntary. Snaps have sane and granular permissions interfaces that you can easily toggle on and off. Canonical is actually enforcing auto-connect rules for the more potentially dangerous ones in their store. If you want to get a classic confined app in the store, it actually has to be approved by their security team.

These things are GREAT for security, which, to be quite frank, is a complete fucking disaster on Linux desktop. X11 is a massive security hole, no real mandatory access control, no sandboxing for apps, local privilege escalations out the wazoo, a quadrillion open security bugs in the kernel. Sure, you can try and set these things yourself, but that relies on the USER to properly configure these things, and if you don't know exactly what you're doing and screw it up (and there are no reliable, consistent guides on how to do these things), then you're just as insecure as you were before.

We're just fortunate that Linux on desktops aren't popular enough to be targeted, because we'd just be getting constantly owned thanks to this massively outdated security model. Windows is actually doing the security model a whole lot better these days, but their popularity and their tendency to implement them poorly and with bypasses to preserve backwards compatibility kind of cancels that benefit out.

It's a real shame that snaps have not taken off. If flatpak wins, and they don't massively overhaul the damned thing to actually add some semblance of sandboxing with permissions controlled by the user, then we're doomed.

DoctorNick··on Show HN: EventNative – An open-source, user event collection service
Understood, I'm just wondering if you offer the ability to detect it and report it, not mitigate it.
DoctorNick··on Show HN: EventNative – An open-source, user event collection service
Just curious, do you also detect if content in the web page is changed or if content is blocked by adblock?
DoctorNick··on Mozilla lays off 250 employees while it refocuses on commercial products
I don't hold Mozilla to higher standards. I just expect Mozilla to make a decent browser. Firefox is not a decent browser anymore compared to its competition. Its performance and security is lagging severely behind Chrome, and it doesn't really respect privacy any more than Chrome does in its default configuration. Pretty much the only two advantages it has right now are containers, and the fact that it's not Chrome. The former matters a lot less now that the newest version of Cookie AutoDelete can remove cache and indexedDB per-domain.

The one thing that could save it, Servo, doesn't seem to be a priority. Instead, Mozilla seems to be focusing on offering cloud services that nobody wants or cares about, which also don't really respect privacy any more than other cloud services. The only significant revenue stream Mozilla has is through Firefox, which keeps steadily losing users and market share.

And even that is almost entirely dependent on people using Google search with the browser. Given that Google is Mozilla's primary competitor who has intentionally broken their apps on Firefox and is pushing them down in search results, and that Firefox is marketing itself to privacy-conscious people who wouldn't use Google anyway, it doesn't seem wise or sustainable at all.

Unless things seriously change, I have no faith that they'll be able to turn this situation around. We may just have to live with a Blink/WebKit web monoculture until we get some serious anti-trust legislation.

← PreviousPage 4 of 6Next →