HNHacker News
TopNewBestAskShowJobs

ailideex

828 karma · joined December 29, 2016

submissionscomments
ailideex··on Privacy critique of WhatsApp
matrix.org is almost unusable as it stands. I really would love to recommend it to people but as it stands it just is not an option.
ailideex··on Privacy critique of WhatsApp
I know many people that are well aware that google has access to their emails, all of them still use gmail. not sure who these people who usually choose privacy but I have yet to meet them.
ailideex··on Privacy critique of WhatsApp
WhatsApp is certainly not the least tolerable of all the dumpster fires that are the IM apps that exist today.

I really like the ideas behind matrix.org but that is a dumpster fire of epic proportion.

ailideex··on The boss who put everyone on 70K
> In some ways, that mindset comes from a place of privilege.

Would be hard pressed to do that as I don't come from a place of privilege. Check your assumptions.

ailideex··on The boss who put everyone on 70K
> I can confirm from my own experience that when you worry about not being able to pay rent and all the bills, it's very difficult to be productive, much less in a job that requires any kind of focus or creative thinking.

Who was paying you and could you not go do something else for money?

ailideex··on Programmers generate every possible melody in MIDI to prevent lawsuits
And yet this will prevent exactly 0 lawsuits.
ailideex··on Some unique aspects in US which make risks of COVID19 higher than Europe
Twitter is basically like a digital swewer outlet right into your computer and phone, getting that raw digital sewage from the source. Brilliant invention.
ailideex··on Some unique aspects in US which make risks of COVID19 higher than Europe
What do you think the US government would have to demand from private industry to do build in the time frame that Thunder God Mountain was built?
ailideex··on Some unique aspects in US which make risks of COVID19 higher than Europe
True even in Norway and China.
ailideex··on Some unique aspects in US which make risks of COVID19 higher than Europe
Kills 50+ what?
ailideex··on Some unique aspects in US which make risks of COVID19 higher than Europe
> Thunder God Mountain may not have been possible in the US

What would you say would be the biggest impediment here? I would think actually that just government regulation in and of itself would prevent any private company from achieving this feat. And even Federal and State governments are similarly encumbered by regulation.

ailideex··on We need to take CO2 out of the sky – an overview of climate tech
Good luck convincing China to impose a carbon tax.
ailideex··on “We found PayPal vulnerabilities and PayPal punished us for it”
I'm not sure that you being convinced by someone who doesn't even understand that it was not hackerone that found the vulnerabilities says much about PCI-DSS
ailideex··on “We found PayPal vulnerabilities and PayPal punished us for it”
Can you remind me again why hackerone is relevant here? Who claimed where that they performed a PCI DSS external scan that failed?
ailideex··on “We found PayPal vulnerabilities and PayPal punished us for it”
We read the page, and even if your claim holds, it is still irrelevant because whatever you quoted is not the same as being a PCI-DSS approved scanning vendor. And even if it was, HackerOne did not perform any scans.

HackerOne offering PCI-DSS approved auditor approved challenges gets you nowhere towards the claims you made in your first comment.

To review:

1. HackerOne would have to be a PCI DSS Approved Scanning Vendor - they are not AFAICT, neither is the CyberNews research team that did the scan AFAICT.

2. HackerOne would have to have conducted the scan - they did not. The CyberNews research team did.

3. The scan that HackerOne did would have to qualify as a PCI-DSS external scan - which ... do you get the part that HackerOne did not do the scan here or not? And nowhere did the CyberNews research team claim they performed a PCI-DSS external scan.

Please at least try to make an argument for your claims

ailideex··on “We found PayPal vulnerabilities and PayPal punished us for it”
What is their certificate number?
ailideex··on “We found PayPal vulnerabilities and PayPal punished us for it”
> HackerOne states they are a PCI-DSS auditor approved organization

Not anywhere on the page you linked. And a "PCI-DSS auditor approved organization" is not a "PCI-DSS approved scanning vendor" which if they were you could just quote the certificate number instead of link to HackerOne.

----

EDIT: I guess you are referring to this:

> Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report.

This in no way is the same as claiming "we are a PCI-DSS auditor approved organization". Which again, would be irrelevant if it was the case.

----

Further, if you read the article, it is clear the "We" does not refer to "HackerOne".

> When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level.

As far as I can tell "We" refers to cybernews.com

And again even if cybernews was a PCI-DSS approved scanning vendor it would still have to qualify as an official external scan within the PCI-DSS framework.

ailideex··on “We found PayPal vulnerabilities and PayPal punished us for it”
> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed.

Quote from your source:

> If your scan fails, you must schedule a rescan within 30 days to prove that the critical, high-risk or medium-risk vulnerabilities have been patched.

Scan in this sentence refers to "a PCI DSS external scan".

The list of approved vendors that can conduct PCI DSS external scans can be found here: https://www.pcisecuritystandards.org/assessors_and_solutions...

Please find cybernews' certificate number there and quote it for us, I have looked and can't find it.

I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong.

And even if they were an approved scanning vendor, from what little I know about PCI-DSS, these scans are part of larger process - so even if they were an approved scanning vendor the scan failure would still have had to be part of the larger process for this 30 day limit to apply.

I could go on and on about how much I hate PayPal and random other things, but just because I don't like something does not quite justify making false claims about it.

ailideex··on Developer Experience: Fundamentally harder than normal UX
I also use it, but it is quite buggy and not quite enough. Luckily xfce is now available for RHEL8 via EPEL.
ailideex··on Developer Experience: Fundamentally harder than normal UX
VS is decent at debugging if it does not fall apart in the process - which for me happens more often than not. So not really useful.
ailideex··on Developer Experience: Fundamentally harder than normal UX
I would think there is a lot less to learn with vi than with Visual Studio.
ailideex··on Developer Experience: Fundamentally harder than normal UX
I googled it. I did not know vi before that, and now I use vim as my main editor for code.
ailideex··on Developer Experience: Fundamentally harder than normal UX
> It's simply not possible to learn vi by just using vi.

I did. I learnt vi when I was told go fix this file on that computer, you have ssh, x forwarding won't work because you have 3 hops (embedded devices that won't allow forwarding of any kind), there is only vi on the box.

So I figured out how to use vi. It is not rocket science, there is not that much to learn, vi muscle memory takes time but also not even that long I think.

ailideex··on Developer Experience: Fundamentally harder than normal UX
Maybe a bit unrelated, I got used to Windows 2000, then window XP, then Gnome 2, then Gnome 3 came. So I stuck with Gnome 2, then moved to XFCE, and now with RHEL 8 I had to use Gnome 3 because there were no other options. Gnome 3 is an absolute horror show. I don't know who made it, for who, and what the theory behind it is but I don't see how it would be easier to use for someone non technical, my parents both understood how to use Windows 2000. It is just weird. It is harder to multitask as efficiently as I did in XFCE and Gnome 2. Gnome 3 is not simpler - it is just more convoluted.

And I feel this is a very similar situation with other tools. I edit code with vim, in a terminal. This is simple as dirt. I do it because it is simple as dirt. Visual Studio is incredibly complicated to me because to do the creating code part my job I need to understand the following:

- How code is built.

- How to build the code without using any graphical front end.

- But now when you bring VS into the mix I need to also understand visual studio. It does not remove complexity, it adds it.

Similar thing with debugging, I need to understand all the ins and outs of debugging but now bring VS into the mix and I need to understand it's stupid UI.

I like simple, my mind is simple. I can learn things, if there are rules and patterns it makes it easier to learn, but the less things I have to learn the happier I am. I don't have an option to not learn some things, like how to do build automation, how to debug code, how computers work, etc. But I do have an option to not learn something entirely useless like VS.

I think the lie being sold is that somehow you can be a programmer without actually knowing how to use a computer. And to know how to use a computer is not the same thing as knowing how to click on things in the UI with a mouse. To know how to use a computer you need to understand how to use it to do automation - and once you need to do this VS is just a nuisance.

Just a rant I guess.

ailideex··on Microsoft apparently removing ‘Offline Accounts’ for international Windows users
I think it would be wonderful if people abandon Windows for alternatives but that won't happen. People are somehow utterly enthralled by that crapware.
ailideex··on Samsung accidentally sends 'Find My Mobile' notifications to Galaxy phones
I think any AndroidOne phone should. A major issue for me is that there is almost no Android phone that is not quite bad. I had a Nokia 7 Plus which ran AnroidOne and it was probably one of the worst phones I ever had. I bought a Samsung afterwards because the Nokia was not usable and while the Samsung was also quite horrible it was at least usable. Motorola also offers the Motorola One Vision but I can't vouch for their quality and I would guess it is also rather bad.
ailideex··on South Korea switching their 3.3M PCs to Linux
Wish this was true, but I doubt it.
ailideex··on Married co-founders are a startup’s secret weapon
The only time I ever saw this it was a dumpster fire. Don't mix family, friends and business. Sure you can get lucky but if you don't get lucky, which you most likely won't, you are screwed.
ailideex··on Apple engineer killed in Tesla crash had previously complained about autopilot
Maybe there is something wrong with the coffee I have had today but I utterly fail to see the novelty or notoriety in the title as a whole or any subset of it. Can someone maybe point it out to me?

People complain a lot. Engineers are people. People still do things they complain about. People die in crashes. Cars crash. Teslas are cars. What am I missing?

ailideex··on Mozilla’s plan to fix internet privacy
Not sure how, it is not exactly a bug, just ... a thing.
← PreviousPage 3 of 15Next →