HNHacker News
TopNewBestAskShowJobs

KeepFlying

562 karma · joined January 31, 2014

submissionscomments
KeepFlying··on Climate activist arrested after ProtonMail provided his IP address
Why not? It would just mean that the NSA needs to own more routers than it would to break TOR->Public internet routing.

From what I understand, connecting to an onion address 'just' involves 6 routers, not the typical 3. (Of course an oversimplification.)

Or am I misunderstanding your threat model here?

KeepFlying··on Why can an ad break the Windows 11 desktop and taskbar?
That's probably the case but then windows should just force webview2 to be its own package independent from Edge's main browser UI.

Or better yet, build the Edge browser so that it's actually an app using webview2 to help ensure that webview2 has a great API experience and is actually easy to use.

KeepFlying··on How I re–over-engineered my home network for privacy and security
Still better than sending them to his ISP (or keeping them visible to his ISP no matter the destination). Sure it's not ideal but really very few things are when it comes to home network DNS requests.

I'd love suggestions for better solutions though, I'm sure there's something I haven't considered.

KeepFlying··on T-Mobile investigating claims of 100M customer data breach
People with stable living situations can more easily keep track of all their official paperwork and spend the time needed to understand the application process. They also have more access to the internet to do things remotely.

Poor people are more often in less stable living situations and it's easier to lose track of documentation. Not to mention unhoused people who don't have a safe place to keep track of things either and often don't have up to date identification in the first place. Also, with less access to the internet to do things remotely it's more common to need to take time off work to go to a physical branch which may be very far away, requiring taking multiple busses just to prove their identity.

Of course adding more security is important, but it has tradeoffs like this that harm the poor that need to be considered.

KeepFlying··on Apple's child protection features spark concern within its own ranks: sources
I'm not a fan of this either but at least it doesn't call the police on me. It places a marker so that a human could track it back to be, sure, but that still requires me to actually try to do something illegal with something I've printed.

I still think it's BS that you can't scan money though and it very much an overreach. Your home printer isn't gonna make a convincing fake anyway.

KeepFlying··on Amazon.com product pages are down
It could be that all global systems happen to rely on some kind of single point of failure that the team never really realized before. Or if they did realize it they didn't realize the potential impact.

Or it was a code change that was able to be validated and rolled out to all regions but then some totally independent interaction caused it to fail afterward in a unique way.

I'm banking on surprising singe point of failure though. I really hope we get a detailed post mortem here.

KeepFlying··on A call to minimize distraction and respect users’ attention (2013)
I get what you're saying but that's only because teenagers in their bedroom are unlikely to get enough attention, not because they don't have enough influence.

It's totally possible for a bedroom-made startup to grow to the point where the lack of GDPR enforcement could be directly harmful to customers, for example. True it's unlike they'd get noticed, but I don't think that's a strong argument here.

I want reasonable widespread application of GDPR, ADA, etc with explicitly carved out safeguards for small operations like this teenager.

They shouldn't have to rely on getting lucky

KeepFlying··on Another 0-day looms for many Western Digital users
Sadly they probably will. At least the ones who didn't have their shit totally deleted.

So many "average" users just want consistency and will go with WD again because they don't need to relearn as much (even if the relearning is minimal it's still a mental barrier for anyone who does not feel totally technically competent).

I think of my parents who, despite being very smart people, are frustrated by tech because it doesn't come easy to them. Any extra step isn't beneficial, it's stressful.

KeepFlying··on Pinterest bans all weight loss ads
A better analogy would be if wheelchair companies were causing people to be ashamed of using their legs and preying on a societal hatred of "walking people" and making everyone feel like they need a wheelchair to be accepted in society at all.

If weight loss things were FDA approved, effective, and didn't carry the weight of a society that tells people that being overweight (or even just feeling overweight) makes you less respected as a human being, then I'd totally agree with you that they shouldn't be banned outright. But unfortunately with how we currently look at weight loss it's not as simple.

KeepFlying··on Mumble: Open-Source, Low Latency, High Quality Voice Chat
It's probably from ReCaptcha, but Discord is the one deciding to use that service to protect their logins so they are ultimately responsible.
KeepFlying··on Reddit’s disrespectful design
As a dev who works with telemetry in my day job I HATE when "better metrics" gets in the way of a feature or product improving.

(I also hate the pervasiveness of identifiable tracking but that's a whole different rant.)

You don't need to perfectly A:B test your two different offerings if that means preventing users from using the product in a way that best suits them. Stop putting shit behind "read more" buttons just because you want to see if people are actually reading your articles. Stop breaking things into multiple screens just so you can track your damn funnels. Better MAU _tracking_ (not even better MAU) does nothing for user experience and pursuing that at the expense of everything else is just plain foolish.

KeepFlying··on Don’t Cancel Plans Anymore
Yes.

At home I am limited in my skills and in the quality and variety of ingredients. In a restaurant (one where the chef actually makes food, not a place where it's microwaved, cooked from frozen, or just repackaged restaurant supply food), I get a skilled chef using many high quality ingredients which I cant get my hands on for any reasonable price to use at home.

I'll still avoid getting certain things at restaurants that I could make at home (many pasta dishes for example), but there are so many things I'd have a lot of trouble making myself.

KeepFlying··on Amazon US customers given one week to opt out of mass wireless sharing
Maybe someday I'll write a rewrite rule to pass google DNS through my PiHole...maybe.

All of this hardcoded DNS server BS in iot devices is a pain.

KeepFlying··on Rethinking the computer ‘desktop’ as a concept
Better software doesn't always exist and when it does exist is not always possible to switch (or has other downsides).

But for example Steam updates on boot, which is a (albeit minor) pain when I want to use it. Similar with Spotify. There aren't really any great alternatives to either of them that have equivalent libraries of content.

Or going right to the core, Windows and it's annoyingly frequent updates. Sure I could use Linux (and I do on a few machines), but that isn't possible on my work machines, and introduces incompatibilities on my personal machines.

KeepFlying··on Rethinking the computer ‘desktop’ as a concept
For security updates it still depends on risk though.

A flaw in my browser is extremely high risk and I require it fixed and updated quickly. But a flaw in my SSH server that is only accessible from behind a VPN is lower. And the risk is lower still if it's a flaw in a feature which I do not use.

I don't see an easy solution of course, it's a hard problem. But I wish that I had more granular control over what and when I update, and was given a clearer way to see the impacts of the update so I could weigh risk.

KeepFlying··on Rethinking the computer ‘desktop’ as a concept
I 100% feel this pain. And for security updates and major fixes, I see the need for frequent updates.

Though setting aside practicality for a bit I wish we would design software to be more backwards compatible so old versions of things could continue to work for longer. I shouldn't have to buy a new phone every three years, for example.

Also for a tool like Audacity, I rarely need to update it. It doesn't depend on a service, so I don't need to worry about an API falling out of support and he security risks are much lower. I wish we could design more of our software to work this way.

Obviously for internet connected things like browsers this isn't possible as the security impacts are significantly higher, but why should I need to update Word every month if I don't plan to use the online components, for example.

KeepFlying··on Rethinking the computer ‘desktop’ as a concept
I generally agree. And Chromes method is definitely better than Steam's where you have to wait 30 seconds on boot every few days for it to load.

But that introduces issues where if Google adds some shitty new feature to Chrome I sorta get forced into it instead of having an opportunity to choose, so there's definitely a tradeoff and also a responsibility on the part of the vendor to make sure they aren't abusing their ability to install things on my computer.

KeepFlying··on Rethinking the computer ‘desktop’ as a concept
I'm generally in favor of more control too. Though that control extends to wanting to be able to control when my software updates and when I get to have new features, settings,etc.

My comment above is more of a rant than a recommendation.

KeepFlying··on Rethinking the computer ‘desktop’ as a concept
That dialog also invokes so many issues with computers today.

When I open a program, I want to use that program. I don't want to update it, I don't want to see all the new features, I want to USE it. I opened it because I had a task to complete and all this junk is getting in my way.

And same when I close a program, as the author hits on very well.

Basically, the computer/program/etc always wants me to do something for it, but it never asks for those things at an opportune time.

No, I don't want to update my computer right now, and no, updating overnight tonight isn't good either because I need to keep this program running until tomorrow. I understand that your new UX is better for me, and I'm sure I'll love it, but forcing that on me right now is preventing me from doing what I need to do. I see your error dialog describing some odd issue, but I don't have time to triage that right now and decide to take the time to fix it.

I wish software would respect the human element more. My time and attention is valuable, please don't interrupt it carelessly.

KeepFlying··on Amazon devices will soon automatically share your Internet with neighbors
I can disable it this time because I got lucky and heard about it happening.

There's no assurance that I'll hear about the next invasive feature, which is yet another security risk in my network that I need to be aware of.

KeepFlying··on Amazon devices will soon automatically share your Internet with neighbors
It may go through an Amazon device, but that fact is stripped away as soon as the packet leaves your network. Your router may know it came from your Echo, but your ISP won't have a clue.

And even if Amazon is tunneling all traffic now, that may change or someone may find a way to break out of it.

And even if law enforcement sees that the traffic is from Sidewalk, our legal system is pretty shit regarding the internet and I bet a dedicated prosecutor would try to get you for aiding a criminal because you technically allowed that access to your network. Look at the legal issues around running TOR exit nodes and the uncertainty there, in a lot of ways this is an opt-out version of that. (though I admit this might be a stretch, but I don't trust the legal system enough to handle this well).

KeepFlying··on US Soldiers Expose Nuclear Weapons Secrets via Flashcard Apps
I'd still encrypt my B2 upload though, just to be safe. Just because it's a trustworthy service doesn't make it immune to hacks
KeepFlying··on What’s your API’s “Time To 200”?
True and if this API handled user data or anything substantially private that would be a HUGE deal and super dangerous.

But it seems like in this case it's mostly a rate limiting and identification exercise and not a secure protection of user data so the impact of exposure is substantially lower. So it does seem reasonable here.

Though I hope that OP has documented all over the place "do as I say not as I do" so people don't copy this pattern.

KeepFlying··on What’s your API’s “Time To 200”?
But you could give a short lived highly limited API key out for testing to allow the potential user to test the API for their needs before bothering to make an account and providing their personal information.
KeepFlying··on Ad block shouldn't break your checkout
What I buy from you is your business. The information I give you to complete my transaction is your business.

Who I am is not.

You don't need to know if I have kids, have a disease, my age, my race, my gender. You don't need to know anything. Sure that information would help you make a better experience for me, I get that. But that's up to me. If I want a better experience, allow me to provide that information in exchange for the benefits that information gains me. But peeking over my shoulder as I walk through your store so that you can overanalyze everything I do isn't okay.

KeepFlying··on Ad block shouldn't break your checkout
That's on the site for requiring tracking to be successful in order to take my money.

They shouldn't require tracking to succeed in order for me to buy the product. If they want tracking, sure. But be resistant to it erroring out. Don't let errors in 3rd party tools prevent your user from getting their core goals completed.

The same goes for client apps. Don't crash the app if it fails to log to a file. Don't crash the app if it can't sync your cache. Etc, etc. Don't let these unnecessary conveniences get in the users way.

KeepFlying··on Microsoft says mandatory password changing is “ancient and obsolete” (2019)
I'm with you on this. I know very few people who generate passwords like that and most people I know use some simple "special word with special number" pattern. Often it's kids names, a random word they picked as a password years ago and have been reusing, and some part of their pin number.
KeepFlying··on Microsoft says mandatory password changing is “ancient and obsolete” (2019)
Writing passwords down on paper is fine.

Writing passwords down on paper and leaving that paper in an insecure area isn't.

Your little address book full of passwords is the same as a password manager, and for a lot of people it's easier for them to manage the security of a booklet than it is to handle a password manager properly. And for those people, it's definitely worth using a book for the sake reasons we say using a password manager is a good idea

KeepFlying··on Higher quality audio makes people sound smarter
I assume it also depends on if they are using the laptop speakers or some standalone ones. I'm guessing the cancelation tech is tuned for the onboard speakers
KeepFlying··on Court rules grocery store’s inaccessible website isn’t an ADA violation
Totally. Especially if you design correctly from the start. Adding accessibility to a site/app/etc that was designed for years without it in mind is a pain in the ASS, but doing it from the start is simple.

The contrast issues sometimes make design a bit harder, but it's totally worth it I believe.

← PreviousPage 3 of 5Next →