HNHacker News
TopNewBestAskShowJobs

alexmuller

112 karma · joined April 12, 2011

http://alex.mullr.net/ is me.

[ my public key: https://keybase.io/alexmuller; my proof: https://keybase.io/alexmuller/sigs/s_BlKMRbxGFToVG8Scftf8W8BdDLk7m3r0PLR_V0Nj4 ]

submissionscomments
alexmuller··on OpenBenches – A map of memorial benches
There's some recent good news about this in a GitHub issue: https://github.com/openbenches/openbenches.org/issues/232
alexmuller··on Why we use progressive enhancement to build Gov.uk
> it'd be great if GDS would stop with the ridiculous forced password recipes across gov.uk sites.

GDS isn't enforcing weird password policies across government.

This is the advice GDS publishes on passwords: https://www.gov.uk/service-manual/user-centred-design/resour...

alexmuller··on A Fighter Pilot’s Guide to Surviving on the Roads (2012) [pdf]
Rules for cyclists in the UK:

At night your cycle MUST have white front and red rear lights lit. It MUST also be fitted with a red rear reflector (and amber pedal reflectors, if manufactured after 1/10/85). White front reflectors and spoke reflectors will also help you to be seen. Flashing lights are permitted but it is recommended that cyclists who are riding in areas without street lighting use a steady front lamp.

https://www.gov.uk/guidance/the-highway-code/rules-for-cycli...

alexmuller··on Whither print.css? A Rallying Cry for a Web That’s Fit to Print (2013)
I couldn't disagree more with the author about appended URLs being a problem. A print stylesheet is exactly when you want URLs to be displayed in the text of the page, because there's no other way to find out where that underlined text is supposed to be pointing.
alexmuller··on OpenSSL.org hacked?
Content-Security-Policy is doing something vaguely similar with <script> tags, where you add a nonce in the HTTP header and then only <script nonce='foo'> tags with those nonces are executed.

script-src at http://www.w3.org/TR/CSP11/

alexmuller··on Expunging Google
The new Fastmail webmail interface is actually massively on-par with Gmail. It's very slick and I'd encourage everyone to give it a(nother) go.
alexmuller··on Desktop App for All Your Email
Right, but they also store the decryption key -- your Inky password. Which is (presumably?) encrypted… somehow? Maybe?
alexmuller··on Show HN: a tiny Instagram projector
The cost of the product seems ok ($20 on Kickstarter, probably a little more later), but the lack of information on film pricing is a bit concerning. Especially after you include shipping from the US to the UK (in my case).
alexmuller··on Spotify loses $59.1 million on $244.5 million in revenue
Ah, dead on! Those user figures are from August this year but the revenue is listed as 2011. Thanks.
alexmuller··on Spotify loses $59.1 million on $244.5 million in revenue
I must be missing something here with regards to revenue. Spotify has 15 million users, 4 million of whom are paid subscribers. So 11 million free users.

They have two paid plans: $60/year and $120/year.

If we assume the following structure:

    11000000 free users @ $0.50 ad revenue per year = $  5,500,000
     4000000 mid users @ $60/year                   = $240,000,000
           0 top users @ $120/year                  = $          0
For a total of $245.5 million in revenue, already more than reported here. And those proportions for their two paid plans are clearly ridiculous. But even if their free users provide $0 in revenue _total_, they still only have 2% of paid users on their top plan.
alexmuller··on Facebook Users Report Seeing Old Private Messages Showing Up On Timelines
This is exactly what I'm seeing. I just spent half an hour on the phone with my friend going over public posts from 2007 saying "WOAH, did we _really_ say that in public?". Every one was public. There were no examples of private messages showing up.
alexmuller··on How Apple and Amazon Security Flaws Led to My Epic Hacking
As far as I can tell, this offers no way to use Google Authenticator. Only the Facebook for Android app.
alexmuller··on Lessons in website security anti-patterns by Tesco
While nice, it would be trivial to send you to prison for doing that: https://en.wikipedia.org/wiki/Computer_Misuse_Act_1990#The_C...
alexmuller··on Cool URIs don't change.
> For example, is there any harm in changing where that contact us form points to?

The point could more be made: "Why not keep that URL the same?"

It's trivial to do technically, and there's no advantage to be had from moving back and forth between foo.com/contact and foo.com/contact-us. If the URL of your company's contact form gets published in a book, would that change your mind?

alexmuller··on One way to fix your rubbish password database
Theoretically, sure. But I can't think of a nice way to authorise users on something like [1]. They'd then need a computer with the radio to provide some kind of access code, I guess?

[1] http://www.robertsradio.co.uk/Products/Internet_radios/STREA...

alexmuller··on Ubuntu Releases 12.04 LTS Precise Pangolin
Desktop release notes are at https://wiki.ubuntu.com/PrecisePangolin/ReleaseNotes/UbuntuD...
alexmuller··on 500px Terms of Service
They've got that covered:

> The column on the right provides a short explanation of the terms of use and is not legally binding.

alexmuller··on We’re hiring a Lead Visual Designer
Yep, I thought exactly the same thing. Didn't notice the strikethrough (it's almost invisible on iPad) before reading the other comments here.
alexmuller··on Show HN: Using a color pattern to let a user 'recognise' their password
I tested using the login form on huffduffer.com, which does exactly that.
alexmuller··on Show HN: Using a color pattern to let a user 'recognise' their password
Tested Firefox and Chrome, they both clear the password field but leave the username. I'd be interested to hear if there is a browser that leaves the password field intact.
alexmuller··on GitHub for Mac 1.2: Snow Octocat
The GitHub app never felt amazing before. I don't know if anyone else had the same experience I did, but it was forever doing weird things when redrawing the window. All gone.

I'm always surprised by how software can feel so, so much better with no new features but just a lot of effort under the hood.

alexmuller··on The YouPorn Chat leak revealed a lot more than email addresses and passwords
And I guess this is why established brands are so uptight about other companies or services using their names. I had no idea this was a 3rd party until seeing this article.
alexmuller··on Twitter to move away from Hashbangs
And to expand a little on what mbreese said, the basic, fundamental idea behind the URL is for a client to indicate to a server what resource it's trying to access. So it's totally broken by that #!.

http://isolani.co.uk/blog/javascript/BreakingTheWebWithHashB... is a great article.

alexmuller··on O2 statement on the mobile number issue
> A Freedom of Information request to get the full list,

Although (as far as I know) the FOI Act only applied to public bodies (government and organisations like universities). So O2 wouldn't need to comply with a request under that act. Not sure if the ICO could force them to disclose that info, but I doubt it.

http://en.wikipedia.org/wiki/Freedom_of_Information_Act_2000...

alexmuller··on UK network o2 send your number to every site you visit
Let's not forget Vodafone, who released an update for Android at about the same time 2.2 was arriving. Only it wasn't 2.2, it was a whole load of Vodafone-branded cruft for 2.1 that couldn't be removed.

http://www.itpro.co.uk/625774/vodafone-no-froyo-android-upda...

alexmuller··on Google, what were you thinking?
From the PDF transcript, page nine:

Caller: No, it’s absolutely free, free of charge. Ok, there’s a small fee for hosting of Ksh. 200 per month.

This seems like an incredibly simple scam, and it looks like blhack's nailed it.

There is nothing connecting this to Google apart from that one IP address. I could phone up half a dozen companies and claim to be from Google, too. Hell, I get phone calls from "Windows Security Centre" every few weeks telling me to do something to my non-existant XP install.

alexmuller··on Google's Kenyan ripoff?
Having just checked, it's not Google App Engine. GAE appends the string "AppEngine-Google; (+http://code.google.com/appengine) " to the user agent regardless of what it's set to. But still, I agree there may well be another explanation.

http://code.google.com/p/googleappengine/issues/detail?id=34...

alexmuller··on Google, what were you thinking?
Thanks for clarifying - ok, so there was lots of traffic from a Kenyan IP resulting in phone calls from a "Google employee", followed by traffic from a Google IP resulting in the same.

Perhaps I'm trying too hard to find a way out for Google, but this doesn't add up for me. Things like the Google callers giving out gmail.com addresses rather than their google.com addresses (transcript page 8).

alexmuller··on Google, what were you thinking?
I left this comment on the original post, but it's been caught by the spam filter there:

Hi Stefan – apologies if I’ve missed something, but the only solid proof I can see that this is actually run by Google is that the IP address some calls came from was assigned to Google.

Last year Mark Turner was concerned that the Department of Defense was listening in on his phone calls because of an IP address that later turned out to not belong to them at all, but (I believe) was being squatted on by Sprint. Couldn’t the same thing be happening here? http://www.markturner.net/2011/11/08/why-is-the-defense-depa...

I wonder whether the scammers aren’t actually employed by Google and are simply out to make a quick buck by pretending they are.

Can anyone speak to the technical aspects of his analysis? I'm not seeing any truly compelling proof that this is run by Google. Just the one IP address that's registered to Mountain View.

alexmuller··on Netflix live in the UK
I was wondering if this was happening to just me, but it would appear not.
Page 1 of 2Next →