HNHacker News
TopNewBestAskShowJobs

KeepFlying

562 karma · joined January 31, 2014

submissionscomments
KeepFlying··on You Don't Need a GUI
"can't handle" is super subjective. Sure a GUI can have every feature available and be super capable. But it can also lead to it taking 10+ clicks to do something, and another 10+ clicks to do it again. Super painful.

So just because companies have proven that GUI is successful and capable, it's still possible that it "can't handle" a lot of things nearly as effectively as CLI in some cases.

KeepFlying··on WhatsApp gives users an ultimatum: Share data with Facebook or stop using app
Most users don't search for extra info screens and extra information in apps. ESPECIALLY not the older generations. I'd argue that the majority of people may understand the blue tick, but that _very_ few understand the difference between a single check and a double check.

Even the ones who do understand a little about the checks probably don't bother thinking about the difference between "sent" and "delivered". They'd understand it if it was pointed out to them, they aren't stupid. But they don't care enough to realize it because they shouldn't _need_ to understand it most of the time.

And even so, the checkmarks are very subtle and easy to not notice if you don't expect to need to look at them. A user is more likely to say "well it didn't give me an error so it must have sent, I wonder why nindalf is ghosting me" rather than "huh, I wonder if WhatsApp actually _delivered_ the message to nindalf, let me check"

KeepFlying··on Simple Opt Out – Links to opt out of data sharing by companies
Agreed. Though unfortunately the way we have it now is technically opt in, just through dark patterns or extortion.

Make an account? You are opting in via those T&C

Have an account and the T&C change to allow data sharing? Delete your account and deal with that pain and frustration or accept it.

Forgot you made an account? Well you agreed to be bound by the T&C that they changed to allow sharing even though you didn't know it happened.

They've made it so that legally you opted in in those dang documents that they make impossible to read. Super frustrating.

KeepFlying··on GHunt – An OSINT tool to extract information about a Google account
This won't stick around for long
KeepFlying··on Hacking Grindr Accounts with Copy and Paste
"Eh that required too much work, no one will try that in real life"

"Oh you were smart enough to open the dev tools and see that, that won't happen irl"

"oh users don't have important enough info stored on this account so it won't hurt to have someone access it" (<- literally a reasoning used by a site I used in defense of poor security. "the attacker only gets access to your last name and the last 4 digits of your credit card, that's not bad enough to need more security")

Don't put it past an incompetent/lazy/underfunded tech lead to dismiss even a one-click account takeover script.

KeepFlying··on Say goodbye to hold music
The company wants problems to go away. Fixing them or making it so people don't bother the company about it are both ways to accomplish that goal. And as long as the lack of support doesn't impact sales, it doesn't hurt the company and saves them money in not having to pay for more/better call center staff.

Also in more benevolent companies, providing support over the phone is the most expensive way to provide support. So as much of that that can be shifted to automated systems, better products, etc the better because it avoids the high cost of a call center.

While a call center employee may be paid by minutes on the line (though I think that is rare), they would be penalized for taking too long on a single call or helping too few customers. There's little incentive to spend time on longer more difficult calls when you could just focus your effort on solving many of the simple calls instead.

KeepFlying··on Changes to Fusion 360 for Personal Use
While not as capable and well supported as Fusion, the two top alternatives that I am aware of are: https://www.openscad.org/ and https://www.freecadweb.org/

With FreeCAD being closer to Fusion than OpenSCAD.

KeepFlying··on How Big Oil Misled the Public into Believing Plastic Would Be Recycled
That may have been the intent, but that wasn't the result.

Even though recycling is supposed to be the last resort, it was treated as an effective solution on its own instead. Less attention was paid to "reduce" and "reuse" and most of the attention was focused on "recycle"

KeepFlying··on Restream: Stream live to many social platforms at once
I'm sure there are use cases for this, but I see two issues I'd be worried about when using it.

First of all, any exclusivity requirements on any platform. Something like this must get you in trouble with the TOS of any of these sites.

Second, the culture of streaming on each platform is unique. Not to mention the form factor and expected behavior of any chats on each system. Or even things as simple as vertical vs horizontal video formats. Sure there are areas where this doesn't matter, there always are, but it shouldn't be ignored when trying to spread your reach.

KeepFlying··on Can't you just right click?
A system setting risks allowing you to make more mistakes.

Imagine I install some app from a trusted third party and am walked through the steps to toggle the system setting to allow installs. Then a year later when I am installing some untrustworthy tool, I am no longer warned (at least not to the same severity) that this tool is unsigned. It leaves me more likely to install that software and end up putting myself at risk in the future.

Take for example the Android settings for installing third party apps. I can enable it on a per-app basis, but that permission persists for the lifetime of my device. If I allow Chrome to install apps for me, that enables apps from ANY site from now until the EOL of my device, to more easily make their way onto my phone.

If I am asked every time (or even periodically) I am given a moment to consider if I know what I am doing.

KeepFlying··on Can't you just right click?
Exactly. I'm sure they do basic vetting of tools in their store, and I suspect they will remove the most eggregious offenders. But that doesn't make all of the tools in their store safe, and all of the tools OUTSIDE of their store unsafe.

Especially when it comes to privacy protections, where every user's standard for privacy is going to be unique.

KeepFlying··on Can't you just right click?
I appreciate this view except for the last point. As a hobbyist programmer, I am not "just releasing a program". I am usually "helping solve user's problems". And if my solution requires users to go through even more problems before they can use my tools, that's problematic.

I don't need to many money on my side projects. I do, however, want to help people. If I can't help people on a Mac because of the install friction, then it isn't worth my effort to create a MacOS port of my software at all.

KeepFlying··on The Billionaire Behind Efforts to Kill the U.S. Postal Service [pdf]
You have hit on the EXACT reason that the USPS is so critical. There are huge areas of the US which are not serviced by other private delivery services. And even in areas where those services do reach, I imagine the cost is extremely high.

People in Barrow, Alaska deserve access to mailing services as much as people in NYC. Without that, there is no reliable way to contact everyone in the US for the purpose of the Census, Voting (where mail-in voting is available), Jury Duty notifications, Selective Service, etc.

There are critical government services that still must be run over "snail mail" and to pass that off to a private institution which will not be able to service all areas equally will lead to more inequality.

KeepFlying··on Dixie cups became the breakout startup of the 1918 pandemic
I've never understood this about public bathrooms. I don't need my soap dispenser to be automatic since I only use it when I'm going to be washing my hands already.

It's weird to see automatic soap dispensers but manual "hand pump" paper towel dispensers.

KeepFlying··on Dixie cups became the breakout startup of the 1918 pandemic
Right, but will the worries about sanitation fade quickly enough or will we just accept that disposables are cleaner despite the environmental impact?

In the short term I'd say it makes sense to me, but long term I really hope we find other solutions.

KeepFlying··on Twitter hack has profound national security implications
The last 4 years have been a terrible example of how to interact on Twitter as a politician, but in general the idea of a politician being able to connect directly with their citizens is still a great dream. I'm not sure if social media is the right approach, but right now I don't think there is a great alternative.

Especially when during campaigning it is necessary to grow that kind of following organically and to leverage social media. Saying that the day you get elected that you must disable your online presence feels like the wrong solution.

I do think there should be some higher standard though. I just am not sure what it is. The same threats exist in Email that exist on Twitter in a lot of ways. I can register "JoeBidden.com" and email you about "my" campaign all day. There's no official registration of your "official" domain anywhere. And even if there were, that can be hacked too.

KeepFlying··on Don't close your MacBook with a cover over the camera
But in those few moments between when I notice the light and when I close the app/lid, my data has been stolen already.

If I'm in a compromising position, I don't want ANY footage of it to be created. If it is a so how frame or multiple seconds, I'm not okay with it. So being told that the notification light is equivalent to covering the camera entirely doesn't line up for me.

KeepFlying··on The science of mask-wearing hasn’t changed, so why have our expectations?
Yeah this is the part of the issue that my social media feed seems to attach to. They post comments from politicians and public figures (and medial professionals) saying early on that we shouldn't wear masks.

I'm sad that the original messages didn't come across as the nuanced issue that it is. Hospitals need the N95 stuff because they are exposed at high rates for a long time. Hospitals also educate their staff on proper protocol when wearing a mask so that people don't negate the effectiveness by wearing it wrong or touching their face after removing it.

The public isn't educated on proper mask wearing procedure. We don't know how to test that a mask fits properly. We don't have the same training to avoid cross contamination and poor mask hygiene. We don't understand the marginal benefits of masks and how it creates a false sense of security causing us to take more risks and spread the disease more quickly.

So at first, it makes perfect sense to funnel the best masks to the highest risk people and encourage "stay at home" (instead of "go outside with a mask") because it limits disease spread the most and protects the community.

I'm sad that it has turned in to "but they said masks did nothing" as an excuse to not wear them. It was never that they did nothing, it's that masks ALONE is not enough. Masks and proper behavior are necessary together.

KeepFlying··on Why we won’t be supporting Sign in with Apple
This is where their article lost credibility with me. Their decision to base their sharing and addressing system on email was their mistake, and Apple is just the first to force them to face their mistake.

I don't want to share my spam email with all my friends to get them to share with me. And I don't want to give my primary email to an app that will spam me.

If I want to share something, I'll send a link and the recipient can connect to me that way. I don't need to search them within the app to get in contact, that's useless.

> so when they enter your email address, our systems will believe that you don’t have an account. At that point, you’ll get an email from us asking you to create an account.

This is a trivial part of the problem to solve. Why am I being asked to create an account in an invite email? Why not "log in or create account" and having the link itself be the piece that connects the share to me.

KeepFlying··on Why we won’t be supporting Sign in with Apple
I think it would come down to user hostility here.

If I sign in with Apple and opt out of giving my email only to be faced with a prompt demanding I give up my email address, I'll be upset. I JUST told the app (via checking the box in Apple) that I don't want to give my mail, so why is it now suddenly required?

However if the app allows me to sign in and only asks for my email when I try to interact with a feature that would be more usable had I given my email, then I would be more accepting of it. Though I would still fully expect to be able to use the app in its entirety even if I opt out.

Now what Apple will say to this, I have no idea. But as a privacy conscious user, I would be happier with this.

As for having to come up with silly names, I don't understand why I need to be discoverable within an app. We have established social media and communication platforms, use them. Let me send a link to a friend to connect with them in your random app. I don't need to be able to add them within the dang app.

KeepFlying··on Why we won’t be supporting Sign in with Apple
I like this approach. And giving users that progresive consent is smart. If I open your app and am greeted with "You need to give us your email to get the most out of our app" then I'll be upset as that is user hostile. But If I click a share button and am told "In order to make it easier for people to send you things, would you provide your email" and being able to dismiss that and continue to use the app and all of its features, I'll be significantly happier.

That said though, I don't see why the app couldnt just change their sharing model to an "invite link" based pattern. If I want to share something with a friend, why do I need to provide their private information to the app to do it? Why can't I generate an invite link and send that through my already established channels of communication? I don't think the "but your friends don't know your Apple privacy email" reason is very compelling. That might not work in their current system, but it is definitely not an insurmountable problem.

KeepFlying··on United States wants HTTPS for all government sites, all the time
I regret reading this article. Damn, its just constantly "But by site doesn't need HTTPS". So many of the responses to criticism don't address the response at all and just parrot "but I don't need it".

Make a valid argument and I'll listen to you, but parroting "but I don't need it" does nothing to add to the conversation at all.

Is adding HTTPS a 100% required critical sev0 ship-blocking bug on every site in the world? No. Is it a valuable improvement to add HTTPS? I'd argue that it is.

KeepFlying··on United States wants HTTPS for all government sites, all the time
If I understand things like EARNIT correctly, they want to limit end-to-end encryption. I don't think they have a problem with HTTPS or any of the other transport encryption schemes.

I know its a bit of a nitpick, but its important that they know we understand the laws they want to push through and STILL disagree with them.

KeepFlying··on United States wants HTTPS for all government sites, all the time
What is the reasoning for the pushback? Can you talk about some of the reasons they give for that?
KeepFlying··on Organ donation in England has moved to an opt-out system
The article you linked is a truly horrifying thought.

I wonder though if a change like this would reduce those cases in the long term though. If there are more organs available, wouldn't there be less pressure to harvest from any particular person?

KeepFlying··on Ask HN: Is there still a place for native desktop apps?
And many of those apps end up with terrible performance. I'm sure it's possible to write a performant electron app, but I don't see it happen often and it's disappointing.
KeepFlying··on A small restaurant owner on Google, DoorDash, and Grubhub
True. But that is still going to a Doordash "employee" and not to an employee of the restaurant itself. So DoorDash is still diverting money that I would normally give to the restaurant.
KeepFlying··on We Chat, They Watch
Same. I'm more inclined to trust apple on privacy than most of the other big companies.
KeepFlying··on We Chat, They Watch
There's a whitepaper on iMessage's security as it was at a single point in time. It may be possible to verify this on a recent build with enough effort, but the average user will never be able to make that validation. So we can't be completely secure there.

More secure than WeChat? ABSA-FREAKING-LUTELY. And do I trust Apple to remain secure? Yes.

I'm mostly putting this here because I've heard people talking about security guarantees without considering tweaks in the supply chain or binary deliveries. Even Signal could get breached with enough effort from Google to push new bits and bypass certificate validation. (Though practically that is not going to happen.)

KeepFlying··on Now Is the Perfect Time to Memorize a Poem
Please make this happen, even if you can't fully do it justice yet. I just read it aloud to myself and I love it. I might have to memorize this one myself while I'm stuck at home.
← PreviousPage 4 of 5Next →