HNHacker News
TopNewBestAskShowJobs

aapeli

289 karma · joined June 1, 2018

https://www.aapelivuorinen.com
submissionscomments
aapeli··on Couchers is officially out of beta
Thanks, will look into it. Get in touch if you want to help out on it too!
aapeli··on Couchers is officially out of beta
Send a bug report and we'll add them!
aapeli··on Couchers is officially out of beta
(I'm the Couchers co-founder who wrote this blog post.)

Yes I agree, CouchSurfing.com went to shit through a slow process of enshittification that ended up looking like this. That's exactly why we founded Couchers.org when CouchSurfing.com put up a paywall (it was the last straw for us). We're trying to take what Couchsurfing was at its best and go further. We're solving these issues you're talking about with better moderation, better safety tools, and nudging users to behave in a way that's best for the community, etc.

I think it comes down to setting clear expectations and educating users about what it is and what it's not. We try to make it very clear and then enforce those rules very carefully. Once this happens, it's surprising how quickly the community roots out that behavior.

aapeli··on Couchers is officially out of beta
Part of it is the better UI and new tech, but there's a lot more too.

Just on that point though: there's actually another open-source platform called Trustroots. They initally started as a rewrite of the BeWelcome frontend, but because of politics and such, BW never let them merge those big changes, so they spun off. Trustroots is a cool project but I think they swung too far into the realm of anarchism in their vibe both as a platform (they are very hitchhikey, so their moderation model is extremely hands off) and as a project (they have this things called a "do-ocracy"). We think there needs to be some planning and roadmapping and a healthy mix of dev + non-dev, as well as serious moderation to keep the platform safe.

aapeli··on Couchers is officially out of beta
Couchers founder and wrote the article.

I don't think so: it just takes thoughtful moderation, setting clear rules, and then enforcing them. When you make it socially unacceptable on the platform, people do a good job reporting inappropriate behavior.

I think the reason that CouchSurfing.com turned into a low-key hookup app is that it was actually a profitable strat for them. They used to monetize verification (something like $60 per verification), and my hypothesis is that a large proportion of people who ever verified paid for verification soon after signing up. By being a hookup site, it actually increased the perceived value to a certain subset of people signing up, which increased signups, verification numbers, and revenue. Of course this made the experience worse on the platform itself once people tried to use it, but they could milk that "easy way to hook up" concept for a long time (basically until the pandemic killed it).

aapeli··on Couchers is officially out of beta
I'm one of the Couchers founders and wrote this blog post (and incidentally spend way too much time on HN), awesome to see this show up here!

This launch is the culmination of a huge push from our volunteer team to clean up a bunch of core features and make the platform easier to use. We are also launching a new branding strategy and new landing page.

Quick plug: we are looking for senior React Native devs to join us and help us get a mobile app out, as well as React/Python devs for frontend/backend. Everything we do is open source (under MIT): https://github.com/Couchers-org/couchers/

Happy to answer any questions folks might have!

aapeli··on My experiment living in a tent in Hong Kong's jungle
> This turns into a surprisingly intense experience. I get to meet people in their most intimate space and bond over late-night conversations in ways that never would have happened otherwise.

This is much like the couch surfing experience: staying with people for a few days and sharing their space, which often ends in these deep, late-night conversations. It's an incredible experience.

There are a few platforms for that, I recommend Couchers.org. It's free & open source (and I'm one of the core maintainers).

aapeli··on Buying a single character domain – and 3 character FQDN – for £15
Also http://ai./ which doesn't redirect you anywhere.
aapeli··on Lossless compression of English messages using GPT-2
So if you end up being famous and talked about a lot on Wikipedia, your name will compress better?

The impact of bias in training data is interesting in general here. What's the impact on Wikipedia's article biases? That's probably one of the main corpuses used.

aapeli··on AWS Snowcone
I wonder if AWS are shooting themselves in the foot (if these things become very popular), by making the "Cloud" a physical, tangible thing. I think part of the lustre for some customers is that they don't know what they're paying for when they start a 2 vCPU EC2 instance and must think it's something crazy complex and special. Now having it on your desk in a tiny little box will make them wonder what they pay so much for.

The other thought I have is that maybe there's a market for shipping around bytes in mail boxes not just between a business and AWS, but just any people and businesses. I've seen B2 and Dropbox (I think) also have these "we'll ship you a drive" things, but maybe they'd outsource that for example to a third party who just did it really well and cheaply.

aapeli··on Pgsodium: Modern cryptography for PostgreSQL using libsodium
Correctly hashed (with salt and a memory+time hard hash) passwords are taken to be brute-force hard to crack.

In that sense it's as safe to publish such hashed passwords on the internet, in the same way a website's public key is published on the internet. In fact, it's good practice to set hash parameters such that it's slower to brute-force passwords than asymmetric keys (e.g. TLS certs).

However, the big difference is that TLS private keys are randomly generated, and of a fixed length, whereas passwords are user chosen. So an attacker could do a dictionary attack and probably uncover a number of passwords using that (e.g. just try out "password" on all the hashed passwords). Hashed passwords are only as hard to crack as the passwords themselves.

aapeli··on Dissection of COVIDSafe (Android): Australian government's contact tracing app
Don't have a public source, sorry.
aapeli··on Dissection of COVIDSafe (Android): Australian government's contact tracing app
It's called dual licensing.

The Au Gov got the code for TraceTogether (what OpenTrace, the open source implementation of BlueTrace is based on) weeks before the source was publicly released as GPL.

aapeli··on Nototo – Build a unified mental map of notes
I quite like this idea. It seems for now to be fairly simple: I think more "decorations" and higher detail on trees, or whatever, might be important.

It seems that it's only 2.5D though. Have you considered making it truly 3D somehow? There's a surprisingly large amount of extra space you gain with that third dimension.

Also, fun idea: what if the island evolved over time? Like every time you visit, trees grow a bit and some new trees grow next to them, so eventually you get a forest, etc. I wonder what the implications of this would be to remembering things? Would the constant change help, or no?

aapeli··on People who tend to be optimistic are likelier to live to 85 or more: study
This is a hidden case of confounding. In particular, you would expect a question such as "in uncertain times I usually expect the best" to be very heavily confounded with your chance of making it through uncertain times (in the past and in the future).

Yes, they controlled for basic things like some generic concept of health, diet and smoking, but there's so many things that are hard to control for.

As a simple example: what if you have some rare genetic disease that's not controlled for but will likely kill you?

aapeli··on An HTML attribute potentially worth $4.4M to Chipotle
Yes, most browsers treat password boxes as sensitive input which has implications to a lot of things. For instance if a blind person types in their CVV using assistive tools on Firefox on macOS, making it a password stops it from being read out loud like other input (it's probably the same on an iPhone, and in some cases this would be annoying if you're in public, etc).
aapeli··on Statistics with Julia [pdf]
Accompanying code here: https://github.com/h-Klok/StatsWithJuliaBook
aapeli··on Tell HN: I came up with an interesting way to do decentralized account recovery
There's some more subtlety to this "what if you're too poor to initiate a recovery" idea. Suppose I know a person with $10k of crypto lost their key which requires a 50% escrow for recovery, but they haven't yet initiated a recovery. What stops me (a well funded adversary) from sending over another $490k of my own funds so that the recovery escrow amount is now $250k, well outside what the original owner can put down?

Other than that, I generally think it's a really bad idea to have a decentralised currency require constant checking in in order to keep your funds. I could imagine situations where users are being monitored by an adversary, and having to quickly intervene with a recovery action would compromise their privacy or anonymity. For me it to be even remotely sensible, the escrow time should probably be several years.

Also, it's much easier to make someone loose access to their keys than it is to make them tell you their keys. What if I just steal their laptop that I know contains keys? That's much lower risk thing than beating someone up for private keys. It's much easier to "accidentally" make someone lose their keys while making it look like it wasn't about crypto at all anyway. What if the person holding the crypto doesn't want to go to the authorities or the authorities don't feel that protecting crypto is important. This is a much, much lower bar than kidnapping.

aapeli··on The Chalk Market: Where Mathematicians Go to Get the Good Stuf
I was first introduced to Hagoromo about four years ago when the word had just come out that they were closing shop. A colleague of mine was in love with it, and ordered several boxes. I managed to get two sticks of the stuff and used it sparingly for quite a long time. It really is way better than the majority of chalks. It's coated in a thin film so your hands don't get dirty and it's extremely fine making it smooth to write with.

The article is a little comical about the effects of using the chalk, but due to its scarcity, I've certainly heard that some use it only for the most important theorems.

aapeli··on I Found the Best Burger Place in America, Then I Killed It
That's actually really interesting about TicketMaster. I can't find any info about it online; but if that's actually what's happening, it's genius—I never thought about that possibility.
aapeli··on Comodo CA rebrands as Sectigo
Yeah it'll probably take years before we start seeing Sectigo root certs. Maybe finally they can also stop capitalizing their name.
aapeli··on GitHub Status Generator
All done, I added multiple events. Let me know what you think.
aapeli··on Status.github.com: “We're failing over a data storage system”
https://github-status-generator.com/
aapeli··on 1/0 = 0
> I consider it infinity because the limit as the denominator goes to 0 is infinity.

Note that this only works if the denominator approaches 0 from a positive side. Otherwise it's 0. This is the idea behind the extended real numbers.