HNHacker News
TopNewBestAskShowJobs

NotPractical

1,386 karma · joined May 19, 2020

submissionscomments
NotPractical··on And then the men with guns tell you to do it anyway
> The thing I admire most about Anglo-American culture is that people will jump off a bridge if you give them a court order that complies with all required procedural formalities.

The president of the United States routinely violates court orders and has little respect for the law or the Constitution. Also, nobody is going to willingly jump off a bridge because a judge told them to. You'll find that the death penalty isn't carried out by asking people politely to kill themselves.

NotPractical··on Guess which of these LLM outputs is watermarked
Could do with some context on how watermarking works. Objectively speaking it should be impossible to tell.
NotPractical··on Apple announces changes for apps in the European Union
> Apple's internal justification for this is that the iPhone and iPad are consumer devices designed for maximum comfort and safety, whereas the Mac is a device designed for developers and professionals.

Then why did they recently launch a MacBook that costs less than an iPhone and a marketing campaign targeted at existing iPhone users?

> If you love iPhone, you'll love Mac. Mac is designed to be just as easy to learn as iPhone.

https://www.apple.com/mac/mac-does-that/

https://www.tiktok.com/@apple

NotPractical··on GDID Windows – Cut the tracker that follows you even under VPN
> Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place

What they did was the opposite: ask Microsoft for GDIDs used by attacker-associated IPs within several 24-hour time periods during which attack-related activity took place. Windows pings Microsoft regularly with the GDID, establishing links between your GDID and any IP addresses you use. The IP logs from Microsoft and the VPS provider showed at least 10 instances where a single VPN IP accessed the attacker's VPS and also pinged Microsoft with at least one GDID within a 24-hour period. They found a constant GDID that all instances shared. This seems to have been the most damning GDID-related evidence in the DOJ complaint [1] and yet it wasn't mentioned in the article you linked (or any other articles about this I've seen pop up on HN). It includes the diagram from the complaint (page 18) that outlines this, but devoid of context. The ngrok stuff that the article focuses on was just the cherry on top and was discussed later in the complaint.

What also becomes clear when you read the complaint is that the GDID was just one piece of the puzzle and that they had plenty of other evidence. Attacker-associated IPs were used to access the suspect's Apple, Snapchat, and Facebook accounts, at least one of which was his actual residential IP, not a VPN IP. Once they had revealed the identity of the person who owned these accounts, they were able to all-but-confirm that this was in fact the attacker.

What remains unclear even after reading the complaint is how they were so sure that the GDID they obtained visited specific websites, but honestly, at that point, they were already drowning in evidence, so I don't know if it matters that much. It could be as simple as "he was signed into Edge with his Microsoft account and had sync enabled".

[1] https://www.justice.gov/usao-ndil/media/1450651/dl?inline

NotPractical··on GDID Windows – Cut the tracker that follows you even under VPN
I think the difference is that, on Windows, there are background services that constantly ping Microsoft with the device ID. A device ID on its own is not really harmful if it's not exposed to the internet.
NotPractical··on Android May Soon Restrict On-Device ADB
I have bad news for you if you think GrapheneOS isn't going to accept this patch from upstream if it lands.
NotPractical··on Introducing selfie for sign-in: a new way to access your Google Account
There is no information about the author of this article, and it has the "AI smell". It's safer to operate under the assumption that it is AI generated unless and until the author reveals themself or at least anonymously confirms that it is not AI generated. This saves you from having made a fool of yourself by spreading it around, if it later becomes apparent that AI wrote it.
NotPractical··on What's wrong with EU age verification? (Nothing)
> A next version of the Technical Specifications for Age Verification Solutions will include as an experimental feature the Zero-Knowledge Proof (ZKP) solution

From: https://ageverification.dev/av-doc-technical-specification/d...

The EU reference implementation is adding ZKP.

NotPractical··on What's wrong with EU age verification? (Nothing)
Except that within days of this service going live there's going to be a freeageverification.com that instantly generates an attestation proof for anyone for free. I fail to see how this is not untenable. You can compare it to geoblocks that can be circumvented using VPNs, but at least VPNs are costly to run and are usually paid services. With the implementation of verification (ZKP) described in the article, there is no cost to generate attestation proofs nor any limit on the number of proofs nor any way to stop a known-but-anonymous abuser from generating new proofs.

Maybe the EU knows it's untenable and is still moving forward because they will be able to demonstrate to the public that privacy enables abuse, creating pretext to make the system not private anymore after it's already been implemented.

NotPractical··on European digital ID wallets rely on safety services of Google and Apple
Not to mention self-signed custom builds of GrapheneOS.
NotPractical··on macOS 27 Beta breaks the ability to boot Asahi Linux
> I think it would be nice if we could run unsigned apps on iOS

Apple enforces those restrictions via the permanently locked bootloader. The main benefit of unlocking the bootloader on an iPhone would be to run a modified version of iOS that allows for the installation of unsigned apps. Apple wouldn't like it and might even get litigious over it, but still.

> (in the US)

Apps intended for release onto alternative app stores in the EU, Japan, and Brazil still need to be approved and signed by Apple. These laws were nearly useless.

NotPractical··on Sweet Jeebus, macOS 27 Golden Gate Removes the Dumb Icons from Menu Items
...it's still large enough to comfortably read without zooming in, which is not the case for Gruber's website.
NotPractical··on Sweet Jeebus, macOS 27 Golden Gate Removes the Dumb Icons from Menu Items
Nope, HN's CSS accommodates smaller screen sizes [1]:

    /* mobile device */
    @media only screen
    and (min-width : 300px)
    and (max-width : 750px) {
      #hnmain { width: 100%; min-width: 0; }
      body { padding: 0; margin: 0; width: 100%; }
      td { height: inherit !important; }
      .title, .comment { font-size: inherit;  }
      span.pagetop { display: block; margin: 3px 5px; font-size: 12px; line-height: normal }
Not perfect by any means but at least there's an attempt.

[1] https://news.ycombinator.com/news.css

NotPractical··on Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable
Was this program available to independent security researchers or just established organizations? The docs you linked aren't very clear on this.
NotPractical··on Anthropic, please ship an official Claude Desktop for Linux
> No upstream open source developer takes that on

The key words here are "open source", right? Some problems can't be solved without cooperation with the developer.

NotPractical··on Anthropic, please ship an official Claude Desktop for Linux
There is a difference between mandating that your customers use one specific Linux distro which is maintained by a controversial company, and supporting all Linux distros through an imperfect-but-fully-working method.

Sure, you'll still get a few complaints from ideological purists, but there's no avoiding that regardless of what you do.

NotPractical··on Anthropic's open-source framework for AI-powered vulnerability discovery
Won't they just ban your account for using this?
NotPractical··on Codex just found a "workaround" of not having sudo on my PC
No, because a malicious AI agent could just replace the sudo binary in your path with one that collects your password and uses it to execute arbitrary code as root. Nothing short of sandboxing everything or just never using AI agents or proprietary software will prevent this.
NotPractical··on Colorado Amended SB051 (Age Verification Bill) to Exclude Open Source Projects
Does anyone have a citation for this that wasn't written by Claude? It wouldn't surprise me, but I refuse to look through AI slop to check the accuracy of the report.
NotPractical··on Hardware Attestation as Monopoly Enabler
> Other than enriching apple, there’s been no direct or apparent harm to the end user from the walled garden.

https://www.reuters.com/sustainability/society-equity/apple-...

I don't want to hear about how this isn't Apple's fault. This isn't the big bad orange man forcing Apple to act against its will; it's a business arrangement between Apple and the president. He gets censorship, they get a weaker EU.

https://www.whitehouse.gov/presidential-actions/2025/02/defe...

NotPractical··on Google Cloud fraud defense, the next evolution of reCAPTCHA
No, they were correct in their understanding of what I meant. I should've said "capable of passing Play Integrity's device attestation checks". I replied to them with more context.
NotPractical··on Google Cloud fraud defense, the next evolution of reCAPTCHA
It indeed runs on modified versions of Android, but this is not supported by Google and never has been.

When Apple says "Apple Pay is supported on iOS >= $VERSION" they don't explicitly mention that it won't work on jailbroken iPhones, because they don't expect you to make modifications to your device and then try and use their services as normal. This is unsupported and discouraged, just like trying to manually install Google Play services on an OS that didn't ship with it.

The only way to get Google Mobile Services officially is to buy an Android device with it pre-installed while leaving the stock OS untouched. And the only way for an OEM to ship GMS with their device is to certify it with Google. And one of the requirements for certification is to use device attestation keys signed by the Google Hardware Attestation Root certificate [1], thus Play Integrity will pass on all such devices.

[1] https://developer.android.com/privacy-and-security/security-...

NotPractical··on Google Cloud fraud defense, the next evolution of reCAPTCHA
> No mention of device integrity verification yet

If Google Play services is listed as a requirement, that implies that a "certified Android" device capable of Play Integrity attestation is required, since that's the only officially supported way to obtain Google Play services. On consumer-facing support articles like this, they don't tend to get into the nitty gritty details like what APIs are being used. If MEETS_DEVICE_INTEGRITY is required, that would probably not be explicitly listed here.

E.g. the consumer documentation for Google Pay just says you need a "certified" Android device and a screen lock set up: https://support.google.com/wallet/answer/12200245

(Yes, if you go deep into the FAQ at the end it eventually states that if you rooted your phone, you can't use tap to pay, but that requirement is implied by the certification requirement [1].)

In Google's eyes, and in the eyes of the law due to trademarks filed by Google, Android == Google Android.

This feature would make little sense if it's not using device attestation because otherwise it would be easy to spoof. I expect that it will initially not use it, and they will start A/B testing device attestation in the coming years.

[1] Expand "What to do if you see device is not certified" -> "Reset device to fix issue" https://support.google.com/android/answer/7165974

NotPractical··on Metal Gear Solid 2's source code has been leaked on 4chan
Minecraft Legacy Console Edition apparently leaked on 4chan recently, too: https://github.com/MCLCE/MinecraftConsoles

Almost no coverage on HN or mainstream media though. Surprising, considering the popularity of this game.

NotPractical··on We found a stable Firefox identifier linking all your private Tor identities
Here's the technical measures that are being worked around: https://blog.mozilla.org/en/firefox/fingerprinting-protectio...

> IMO you need to actually work around a technical measure intended to stop you for it to qualify as an exploit.

Even well-known vulnerabilities like SQL injection don't qualify under this definition?

NotPractical··on The world in which IPv6 was a good design (2017)
Most tech businesses exist because problems exist. Tailscale delivers a solution that's available today. The only alternative is to sit and wait for IPv6. I don't imagine Tailscale is against IPv6 any more than security professionals are against memory-safe programming languages.
NotPractical··on Apple removes iPhone vibe coding app from app store
The entire rule is as follows:

Apps should be self-contained in their bundles, and may not read or write data outside the designated container area, nor may they download, install, or execute code which introduces or changes features or functionality of the app, including other apps. Educational apps designed to teach, develop, or allow students to test executable code may, in limited circumstances, download code provided that such code is not used for other purposes. Such apps must make the source code provided by the app completely viewable and editable by the user.

There are not "exceptions"; there is one exception, and that's educational apps. But it's unclear why Pythonista is educational while the apps mentioned in the article are not. In fact, Pythonista is even listed in the "Productivity" section in the App Store.

NotPractical··on Apple removes iPhone vibe coding app from app store
Apple's own Swift Playground app does the exact thing that supposedly violates the rules, abusing an inconsistently-applied exception for "educational" apps [1].

Recent regulation doesn't help here, by the way. iOS apps submitted for "notarization" to be distributed in alternative app stores in the EU, Japan, etc. still must comply with a subset of the guidelines, including 2.5.2. EU is probably not interested in strengthening the DMA so that Apple doesn't have to approve everything because then it makes other EU regulations easier to bypass (e.g. Chat Control).

Looks like YC wasted their money on this one, unless it's exempt because one of the founders used to work at Apple or something: https://news.ycombinator.com/item?id=45041185

[1] https://developer.apple.com/swift-playground/

NotPractical··on ChatGPT won't let you type until Cloudflare reads your React state
But do they do it whether you're logged in or not?

I noticed the ChatGPT app also checks Play Integrity on Android (because GrapheneOS snitches on apps when they do this), probably for the same reason. Claude's app doesn't, by the way, but it also requires a login.

NotPractical··on Apple Just Lost Me
> 1. Gatekeeping. OK, fine

Proceeds to explain why your opinion is not "fine" but rather invalid, because Apple boiled you like a frog...

Every time someone mentions here that they're concerned macOS is becoming more like iOS, Apple apologists show up to explain how that's not actually happening. I guess now you guys have just accepted it.

Page 1 of 13Next →