HNHacker News
TopNewBestAskShowJobs

ac4tw

78 karma · joined March 15, 2016

Currently: www.simpleid.xyz, www.referenda.io
submissionscomments
ac4tw··on Ask HN: Why can't we have an open android and apple store
That's terrible. The opacity of app store developer interactions frustrates me greatly.

I was actually thinking something similar to your suggestion the other day for an entirely different reason. Specifically, trust based integrations to SCM so that users could be more certain their devices were running the same code published as open source (it stemmed from a discussion on HN where some folks mentioned that the only real way to know what's running on your device is to rev. engineer it / decompile it). It would be great if we could have more confidence that an open source app is indeed running the code published to it's production branch.

ac4tw··on Atari 7800 Source Code
Folks like yourself are one of the big draws of HN for me. It's awesome to hear the perspective of people who created aspects of the things I was in awe at growing up (in this case I'm thinking of the Jaguar).
ac4tw··on How to Tell Us a Secret
"It not being open source is a political argument, not a technical one."

If I can compare the open source to the reverse engineered code to see what I'm really using/getting, that seems like a technical advantage. Also, all of the reverse engineered code I've worked with has been difficult and time consuming to digest (missing var names, comments etc); open source gives me a technical advantage in analyzing and understanding the code. Lastly, looking at a companies open source lets me assess their technical sophistication and practices which also seems like a technical advantage.

I haven't spent much time thinking on this subject, but the political aspect seems to be the line of thinking that says: you will engender trust by making a project open source.

Is your reasoning similar?

Also are there good tools for reverse engineering iOS deployments?

ac4tw··on How to Tell Us a Secret
myth_buster, lisper, & newscracker make interesting points.

In researching WhatsApp a while ago, I came across this in a Quora post "But one more point I want to stress here is that, though whatsapp is allowing end to end communication , it does not necessarily mean they can not analyse the encrypted data. in cryptography we call it Searchable Encryption." (https://www.quora.com/Now-that-WhatsApp-can-no-longer-read-y...)

I don't know whether it is accurate to WhatsApp, but it's certainly food for thought and also made me wonder how many other end-end encrypted systems use it.

I personally don't trust FB. WhatsApp is not open source, so I have to trust what FB says. I don't.

There are many important considerations in secure messaging and the EFF has done a reasonable job of trying to cover the subject in their series on messaging (https://www.eff.org/deeplinks/2018/03/secure-messaging-more-...)

ac4tw··on Atari 7800 Source Code
After reading through the src for Dig Dug, I have to confess that I'm jealous of the awesome variable names in gaming.

Didn't see a lot of things like 'DETHWISH', 'FLEE', 'ROCKDETH', or 'VICTIMX' writing FPGA SW.

ac4tw··on Full-Size Lego Bugatti Chiron Powered with Power Functions S Motors
My bad--I got so excited when I saw this, my brain forgot to check if it already made it here first. I also learned that the delete submission feature is not a thing. (Clearly I should spend more time on HN).
ac4tw··on Full-Size Lego Bugatti Chiron Powered with Power Functions S Motors
While I love software, I was a LEGO head first. Seeing this today just shows what an awesome era we live in. Here's the URL where I found the video--it has more details on the car:

https://www.lego.com/en-us/aboutus/news-room/2018/august/tec...

From the article: "The model is the first large scale movable construction developed using over 1,000,000 LEGO Technic elements and powered exclusively using motors from the LEGO Power Function platform. Packed with 2,304 motors and 4,032 LEGO Technic gear wheels, the engine of this 1.5 tonnes car is generating 5.3 horse power and an estimated torque of 92 Nm."

ac4tw··on GitLab is now running on GCP
It seems like a good solution to CryoLogic and your discussion might be for services to allow you to choose what you would like censored. For instance 'yzmtf2008' could simply say, don't show me content like this.

Obviously there are some challenges in the 'like this' part, but it seems like it might scale better and be less prone to centralized censorship problems than the current mechanism.

The sad part is that 'yzmtf2008' will exist inside of a vacuum and will miss out on things that appear crazy and may actually be true, but perhaps the upside is that this person may be more productive in other areas of life by defocusing on distractions.

ac4tw··on Google Boots Open-Source Anti-Censorship Tool "Ahoy" from Chrome Store
I prefer projects that strive for "can't be evil".
ac4tw··on Someone Uploaded What Look to Be Apple’s Internal iPhone Repair Videos
"It's got to be about the worst cost to utilization ration of any feature on the iPhone."

I can't speak to whether you're correct or not, but that feature is a massive time saver for me. It's one of the most compelling features that keeps me on their platform. I have large fingers and selecting text with 3D touch is incredibly easy compared to using the twin cursors offered by iOS/Android for that purpose.

I run into quite a number of folks who have no idea they have 3D touch though. Surprises them even more than me when I show them.

I don't use 3D touch for much else though, which sort of supports your assertion.

ac4tw··on Show HN: imwith (YC S17), a messaging app that memes everything you say
Enjoyed your buttonless UX.

The NLP engine worked well too.

Your premise about improving meme search is inline with some of the comments I was reading about Line this morning (though their users mentioned problems with sticker suggestion).

The only problem I encountered was that my phone became a space heater while the App was in the foreground--it's not often that I see an App exceed the incineration capabilities of Waze.

ac4tw··on WebRTC Chat on IPFS
I don't think there are any 3 that are exactly what you ask about ("chat-on-blockchain thing").

However, from my understanding of Telegram's ICO and "leaked" roadmap, they appear to be doing a decentralized chat the may leverage their own blockchain for some features (identity, tokens etc.).

I think Status.im is another example, but it's currently early access I believe.

My own product, stealthy.im could be another example. The web product is in production. It builds upon blockstack, storing identity and storage pointers in the blockchain.

So that's 3. I could probably list a few more, but again they wouldn't strictly satisfy your precise criteria in one or major ways. I think @jerf's response is really good--for us the "why" of blockchain is in identity and providing a verifiable decentralized storage network through blockstack. The underlying bitcoin blockchain wouldn't be suitable for message storage or sdp handshaking due to latency as another person pointed out.

ac4tw··on WebRTC Chat on IPFS
I think @detaro says 'regrettably' because of the distaste many have about ICOs and the hype related to them. However, I too would like to hear from @detaro on this.
ac4tw··on Van Jacobson Denies Averting Internet Meltdown in 1980s (2012)
Comments like yours are what keep me coming back to hacker news. Thanks for the perspective.

Especially interesting about TP4 & traffic shaping. The even-numbered hour bug sounds like a nightmare--kind of like cold temperature timer issues I've encountered on micros.

ac4tw··on Show HN: Decentralized P2P Messaging with Blockchain Verified Identities
Absolutely agree with you. Transparency in a messaging platform is important (it's sort of captured in EFFs criteria for a messenger too as regards open sourcing and inspection--not sure if you saw their recent 4 part series on messaging or earlier piece on all available messaging tools).

Your comments and 18pfsmts got me thinking about metadata from a different angle than I had been considering prior--that of a state actor's capability to observe the entire network. Your comments never came across as negative.

ac4tw··on Show HN: Decentralized P2P Messaging with Blockchain Verified Identities
Indeed if one was observing the entire network, they might be able to piece together useful metadata as you both suggest. The kind of thing you might do with a NarusInsight. Tox and Zerocoin have done some interesting work towards this end and it's definitely something for us to consider going forward.

Thank you lawl & 18pfsmt for highlighting protection of metadata vs. content. At this time protecting content seems like the minimum bar by which one should measure, with metadata protection being the ultimate goal without sacrificing performance or convenience.

ac4tw··on Show HN: Decentralized P2P Messaging with Blockchain Verified Identities
18pfsmt, that's an interesting question. Do you have any specific examples you can point us to? When I think about a network drawn atop of say WebRTC connections, it's possible for a message to travel realtime via hops from person A to person B via persons C, D & E even though persons A & B have no direct connection, obfuscating the path and connection information that lawl alluded to with STUN/TURN/ICE servers. A similar situation exists for offline messaging polling between data storage where we could obfuscate that transaction via another user's client (i.e get person C to poll for messages from Person B to Person A offline). I'm not sure if this is what you had imagined or if you were thinking of something else?
ac4tw··on Show HN: Decentralized P2P Messaging with Blockchain Verified Identities
Good questions lawl. I'll try to address them in order:

1. "A blockchain, implemented using virtualchains [6], is used to bind digital property, like domain names, to public keys. Blockstack’s blockchain solves the problem of bootstrapping trust in a decentralized way i.e., a new node on the network can independently verify all data bindings." [https://blockstack.org/whitepaper.pdf]

2. I believe collecting an email is required in case you need to recover your 12 word pass phrase.

3. The default storage that comes with a Blockstack account is a Microsoft Azure Blob. If you implement your own GAIA hub, you can circumvent that with a number of other options, but conventionally you would refer to the other options as 'centralized' too. Consider this though: "We decentralize data storage with relationship to trusted 3rd parties - remove control from app developers, cloud storage providers, etc and give it to users." [https://forum.blockstack.org/t/gaia-decentralisation/4275/2].

Anyway, each user's storage is used for the following things: - contact lists - conversations - offline messaging - initiating WebRTC connections

It is all encrypted client side.

4. We have two forms of discovering users.

The first is where the users coordinate outside of Stealthy to add eachother as contacts--at this point communication is established only between the two chat clients with no third party, consequently there is not traditional leakage that may occur in this mode.

The second (which can be disabled from options) uses a centralized DB and listeners to simply exchange the notion that someone wishes to talk to you. If that centralized DB were to be hacked, that request could theoretically be leaked. The invitation to talk only occurs initially when both parties are not within eachother's contact lists.

5. We do use WebRTC for P2P communication and it can be disabled from the options or during initial configuration. The STUN/TURN/ICE server could certainly acquire some of the information that you mention.

6. We agree with your notion of an architecture / protocol overview and are currently considering precisely how we will proceed with that. Earlier this month we spoke with a representative from the EFF and their advice was to publish a paper on the subject and then commence with formal review of our work, similar to Signal.

Hopefully this helps.

ac4tw··on Show HN: Decentralized P2P Messaging with Blockchain Verified Identities
When Prabhaav mentions it's encrypted client side, we should elaborate and also mention that it's encrypted such that we can't see it, so we have no way of knowing if you are transacting illegal content.

An interesting architectural point is that because you as the user choose your storage provider, you are essentially hosting bad content along with your storage provider. We and Blockstack simply provide you with a means of transporting your data to others without getting in the middle.

ac4tw··on Show HN: Decentralized P2P Messaging with Blockchain Verified Identities
Answering your question to my satisfaction is difficult from a single source, but here are some key points and source links that may help:

* "Can Blockstack control my data or ID when I use it? No. When you're using a Blockstack client you control your data and ID with a private key. This private key never leaves your device and is meant to stay on your laptop/phone. As long as no one gets access to your private key, no one can control your data or ID. When you use Blockstack, by design, your private keys are never sent to any remote servers." [https://blockstack.org/faq]

* "The main difference between blockchain identities and accounts on any other service is that blockchain-based systems have strong ownership. Blockchain identities can't be confiscated by any service because the system defines ownership according to ownership of public-private keypairs, just like ownership of coins on Bitcoin. This is in direct contrast to Twitter or Facebook usernames, which could be confiscated or censored at any time by the respective companies that they belong to." [https://blockstack.org/posts/blockchain-identity]

* "Identity is user-controlled and utilizes the blockchain for secure management of keys, devices and usernames. When users login with apps, they are anonymous by default and use an app-specific key, but their full identity can be revealed and proven at any time. Keys are for signing and encryption and can be changed as devices need to be added or removed." [https://blockstack.org/intro]

ac4tw··on Show HN: Decentralized P2P Messaging with Blockchain Verified Identities
The diagram at the bottom of this link, 'How Blockstack Works', has proven helpful to me for discussing and understanding Blockstack and dApps built upon it: https://blockstack.org/intro
ac4tw··on Show HN: Decentralized P2P Messaging with Blockchain Verified Identities
Thank you. I appreciate your concern. My understanding is that the Blockstack team has more development planned for GAIA, but to date have been focused more in other areas, as you discovered. We've been working on their platform since December of '2017 and so far their GAIA storage system has been reasonably reliable for us.

*Edit: Though recently I've been considering the system and Stealthy's use of it for scaling purposes and it's likely that we'll be looking into running our own hub(s). A brief discussion on throttling of the free hubs, best practices, and performance here: https://forum.blockstack.org/t/gaia-read-write-and-throttlin...

ac4tw··on Show HN: Decentralized P2P Messaging with Blockchain Verified Identities
Greetings, I develop Stealthy with the OP. After reading a lot of the HN dApp posts, I want to address two frequently occurring topics from the comments:

1. How decentralized is this dAPP? Stealthy is decentralized in two main ways. The first is that it does not require a centralized signaling server to establish connections, when two people have added each other as contacts. That of course requires that they initially co-ordinate outside of stealthy (though we do however have a convenience mode that does a one-time centralized introduction / discovery service if both users have that enabled). The second is our storage, which is built atop Blockstack's GAIA storage system (more info here: https://github.com/blockstack/gaia).

2. How secure is Clientside javascript crypto? In other HN posts, I've seen quotes like: 'Nobody who's serious about security is going to use an app that does crypto in javascript. Why not make browser plugins to avoid this complication?' and posted the classic Javascript cryptography being considered harmful article. Blockstack gets around this in a way similar to being a plug-in with their one-time browser download (which is essentially a node process that also has your crypto keys/generation capabilities so you're not transmitting those back and forth for acquisition purposes). You can find more information on that subject in this forum post: https://forum.blockstack.org/t/blockstack-vs-clientside-js-e...

ac4tw··on Show HN: Take a 1 min pre-diabetes test for a chance to win $20 Amazon Gift Card
Done
← PreviousPage 2 of 2