HNHacker News
TopNewBestAskShowJobs

Latty

5,328 karma · joined October 6, 2014

Software Developer

https://www.lattyware.co.uk

[ my public key: https://keybase.io/latty; my proof: https://keybase.io/latty/sigs/W8a_MqlArh7H9p_JWUWnXFGx94t6slLire3_2Z9_ECM ]

submissionscomments
Latty··on Newgrounds.com – A community of games, music, and art
I'm aware of the definition of censorship, but the context is you saying:

> One of the worst cultural developments of this century has been creative people becoming censorship-hungry prudes.

This is not the same as a dictionary definition of censorship generally.

Presenting people changing their views over time as they learn as some evidence of some new trend of "censorship-hungry prudes" is silly. It's hysteria and a false narrative trying to paint something normal and healthy as equivalent to something dangerous.

The much bigger media preservation issue is actually represented by Scrubs: the fact that all the streaming services now have the show with all the music cut out and replaced with generic royalty-free stuff because the licenses ran out.

Latty··on Newgrounds.com – A community of games, music, and art
Bill Lawrence removed episodes because he and the cast hated that for years after they'd see people at halloween dressing as the characters in blackface, and realised that people were taking the wrong message from the episodes they'd made which were meant to mock the idea of people thinking it was OK to do blackface.

That isn't self-censorship, it's accepting that your work didn't read the way you wanted it to and deciding it's not worth having it out there under your name any more.

Freedom of speech also includes the freedom not to speak, and people should be allowed to say "I don't like this work of mine any more, I'm not continuing to publish it". If you advocate for enforced speech, you are the censor, just using a different tool.

Latty··on When did Google get so weird?
It's not a "skill issue", the product got worse.

If I wanted a chatbot, I'd go to a chatbot, I want a search. Making me frame my query as a question rather than just assuming it's a query by default is just bad.

Latty··on There are no "rogue" AI agents
Huh? It's extremely common for businesses to decide that breaking the law is a cost of doing business and just do it because they figure they'll end up net positive from it, or even just to cash out in the short term.

Uber made no attempt to cover up that they were operating without licenses, and just ate it and fought it betting they'd get established before the law could catch up, and they won that bet, paying some fines and stuff but ultimately taking the market.

These LLMs are literally trained by these companies pirating literally every bit of media humanity has ever made, they made very little attempt to cover it up.

Of course they'd be willing to break the law for some PR? With a thin layer of plausible deniability "oh no, we didn't mean for it to hack stuff!" they know they'll get a slap on the wrists at worst, all while generating hype to prop up the AI bubble further by presenting the models as hypercapable.

The mindset is probably: either a) the models become capable of what we are claiming and so the companies become so huge and valuable the cost is irrelevant and we'll be to big to punish meaningfully, or b) it's a bubble and might as well push it up as big as it can go while I can make money, then by the time consequences come around I'll be long gone and who cares.

Latty··on There are no "rogue" AI agents
I don't think they intentionally set it up to hack stuff with a prompt saying "hack this site".

I do think it's highly likely they knew this would happen with the lack of safeguards and number of instances of this stuff they were setting up, and that it's PR they want to make the models seem "powerful". Stochastic "unexpected" events they can advertise.

I suspect it was probably set up with the official internal goal of just trying a ton of arbitrary tasks that seem hard so that when any of them succeed they can publicise it and pretend the models do that routinely, but a "failure" where they hack stuff works just as well, if not better, for their goals.

Latty··on PipePipe: NewPipe hard fork implementing SponsorBlock
Have you tried disabling the Page Visibility API? Web apps will sometimes use that to try and mess with background playing, IIRC.
Latty··on I don't like passkeys
Why would it be that is the only recovery method? The most convenient one is just more passkeys on other devices of course, but you can have any other recovery methods you want. Magic link emails are the most common, but there is nothing about passkeys stopping you from implementing anything you want.
Latty··on I don't like passkeys
Right, I haven't seen that particular flaw in baked-into-the-browser ones (probably because they already having secure domain matching code ready to use), but the distinction is that doing the domain check is a part of the spec and standard, so e.g: sites aren't going to break it by changing the log-in subdomain routinely, as has been common historically.

Password managers have had to be permissive enough to work with most websites, and there is no standard for it. There have been sites that blocked the autofilling of passwords and so on as well.

My point wasn't this one particular flaw in some password managers is the reason to use passkeys (the copy/paste point is the much bigger issue anyway), just that it's an example of how relatively brittle the password manager process is. Having it a core part of the spec gives stronger guarantees.

Latty··on I don't like passkeys
If the user just has a username/password fallback and that's it, then yes, but the aim of passkeys is that won't be the norm, rather users will only have passkeys and the fallback would be to, e.g: magic link email log in where the phishing attack is still broken. I've seen some sites explicitly disallow plain username/password login after you enable passkeys for this reason (you can still put them in, but then it just does a magic link flow afterwards as a second factor).
Latty··on I don't like passkeys
It should be a big red flag for sure, but the reality is most users aren't going to understand that. They got told to use a password manager by someone or find it convenient, but they don't understand the security flow enough to catch that it's a potential attack, or how to resolve it safely.

Historically I've seen lots of sites do a subdomain shuffle for login pages every now and then which routinely breaks domain matching, introducing false positives that users have to deal with, making them numb to the threat too. Passkeys baking in the domain check with no workaround means that sites can't do that, which is a benefit.

Latty··on I don't like passkeys
You don't. The browser handles the passkey matching to the domain which is obviously a better place to do it. There could obviously still be bugs as with all things, but it's much more intentionally integrated into the flow which makes it much harder to bypass.
Latty··on I don't like passkeys
Which is a trade-off that makes sense for a lot of people. If you have multiple devices, many of which are portable and one you have on you all the time, the need for that is just way lower, so being more secure against commonplace automated widespread attacks is worth it to them.
Latty··on I don't like passkeys
The offer a strong protection against phishing attacks that would still get plenty of password manager users: fake websites. A passkey is strongly linked to a domain, so a fake site can't get that credential.

Some password managers will only fill if a domain matches, but IRL the response I've seen from most users when it doesn't match is to assume the integration broke and manually copy/paste it in. I've also seen lots of them do stuff like happily autofill on any prefix of the domain, so your credential for `something.example.com` will autofill into `fake-something.example.com`.

Latty··on The CSS Zen Garden dream, finally shipped
People say stuff like this and just... do you never think about accessibility? Have you never experienced stuff changing the UI under your feet and how incredibly annoying and flow-breaking it is?

It reminds me of people wanting Hollywood UIs that would obviously suck to actually use. Just completely ignoring the reality of using what you are suggesting.

Latty··on I stopped trusting USB-C cable labels and started testing them
Do people really not remember the hell of every device having it's own cable which was incompatible with all the others? Going around to a friend's house and finding out, no, they don't have the cable that can charge your phone.

It is a strict improvement to be able to transfer data or charge at degraded speeds, compared to not being able to plug it in at all. Wanting all your cables to end up entirely incompatible just because you don't want to bother checking labels (modern cables come with clear ones, I have ones that clearly say 40Gbps/240w on them) is, frankly, silly.

Latty··on Postgres LISTEN/NOTIFY actually scales
It was diffs in state that got sent to the client, so recomputing them from the current state would have required having the previous state.
Latty··on Postgres LISTEN/NOTIFY actually scales
One way it explicitly doesn't scale (unless something has changed since I last checked and my quick search failed me) is the hard limit on 8000 bytes of data in a notification. If your notification doesn't make sense to exist as a row (where you can just give an ID), then that makes it hard to use. I had a web game and the events were transient descriptions of changes in state that didn't make sense to store in the database, and could be bigger than that, so it didn't work for that use case.
Latty··on Firefox 153 available with support for Vulkan video decoding, JPEG-XL
"All" really isn't true, most AM4 Ryzen chips don't have iGPU (unless they are specificly APUs), and a lot of Intel chips have popular 'F' SKUs without an iGPU.
Latty··on Should DayQuil Be Legal?
“Incredibly”? The US does exactly the same thing in another case: denatured alcohol.
Latty··on There is minimal downside to switching to open models
They literally arrested people for quoting Charlie Kirk in tweets after his death.
Latty··on Leaving Mozilla
Look, I absolutely agree it sucks they didn't deliver the opt-out/in interface day one, it was obvious people would want it, and yes, it's not the first time they've blundered.

At the same time, they did listen to the feedback and deliver. It now has a genuinely good interface for it where you don't have to opt out of everything, but can opt-in where you want it. It's not just a big off button, it's a general out-out including new features, but that then exposes individual opt-ins if you want for each feature. Most other browsers won't respond at all. Firefox is still by far the best browser out there for people who care about their privacy.

Especially on HN, Firefox just gets so much more hate than software that is way more user hostile for much less bad behaviour. I'm not saying we shouldn't hold it to a higher standard when that is what it's selling itself on: clearly we can't allow "not as bad" to let it slip into worse and worse, but at the same time, I don't understand how the narrative seems to trend towards "they are essentially the same as google" when that is so clearly not true (to be clear, not saying you are saying that in this post, just that's the vibe of HN's commentary as a whole).

Latty··on The Website Specification
"Agent Readiness" will likely age as well as "Web 4.0 Blockchain Integration" has.

(To be entirely clear, not because agents won't be a relevant thing, although certainly I have my doubts, but because I believe even if they are a relevant thing, requiring special allowances from sites undermines the whole point, and such things will only end up used by bad actors to mismatch what agents see to what humans see, and so will be intentionally ignored.)

Latty··on Security through obscurity is not bad
Well, my issue is that "one layer" implies you can just stack it on others, especially if you say "as many layers as one is able to manage", it implies the best option is to add obscurity on top.

As my comment made the case: it's not a simple addition, it's a trade-off, and I'm saying it should be thought about in those terms. I didn't find that was evident from what you said, I guess the "push back" framing was more negative than I intended.

Latty··on Security through obscurity is not bad
I'll push back on this: obscurity isn't a "free" layer of security, it has both security benefits and security costs.

By having obscurity you lose anther layer of security: public scrutiny. It's harder for security issues to remain if people can see them and point them out, more eyes mean more chances to catch problems.

There is also a cultural component: having to lay out what you are doing publicly means you can't just think "no one will know", and let something slide, which pushes you towards better security practices.

Of course, this doesn't mean obscurity is always going to be the worse choice, there are times it will offer more than it costs and it's particularly evident that in, for example, open source projects, a lot of the time the number of eyes on most code is low enough that "many eyes" is a bit misleading, but I think presenting it as a pure positive is wrong, obscurity has cost, even if you think it's worth it in some cases.

Latty··on Can I disable all data collection from my vehicle?
Firefox also has a setting like this, although I think it's even nicer in that it makes everything (current and future) AI default to opt-out, but still lets you opt in to specific use cases if you want.
Latty··on GitHub Copilot is moving to usage-based billing
I expect in the future we'll find out that someone in the industry was juicing the numbers with fake thinking tokens or something. The whole pricing model of charging you for the tokens it generates while not knowing how much it is going to generate going in has always been pretty crazy.
Latty··on Pgbackrest is no longer being maintained
To me it reads as being worried that someone malicious could step in and use the project's name to do harm. If you don't have someone within the project with trust built ready-to-go, establishing that trust enough to hand over the project is a big task.
Latty··on New 10 GbE USB adapters are cooler, smaller, cheaper
> That's why Thunderbolt eGPU setups don't perform as well as plugging the GPU directly into a PCIe slot.

The bigger factor is probably that PCI-e tunnelling at most a ×4 link, while when you plug a GPU in you are generally doing so into a ×16 or at least ×8 slot, and very few GPUs target ×4.

Latty··on Firefox Has Integrated Brave's Adblock Engine
There is an obvious difference between someone who is still actively involved in running something and working on it, profiting from it's success in the market, and using something someone invented but is no longer leading development of or profiting from.

It's normal and reasonable to discover someone who makes bad decisions is running something and decide that makes using it a higher risk for you. Sometimes you don't have a choice, but sometimes you do.

Latty··on Firefox Has Integrated Brave's Adblock Engine
And people treat Mozilla like the devil when while they make mistakes, they routinely fix them too. E.g: when people had concerns about the AI stuff, they added a general opt out with a feature-by-feature opt-in.

To make an obviously unproven and not universal observation: I feel like it's people who just like the google integration in Chrome and want an excuse to run it, even though they feel like they should use Firefox because it's more compatible with their world view, so they latch onto any issues Firefox has to go "see, they are all the same anyway", and then just repeat vague "Mozilla sucks" stuff.

Page 1 of 34Next →