HNHacker News
TopNewBestAskShowJobs

andrerm

167 karma · joined April 13, 2019

submissionscomments
andrerm··on Google bans fake 'cookie stuffing' Chrome ad blocking extensions
Almost 5 years after uBlock's fork and now that Google is ready to kill ad blockers as we know and like them. Well, good job
andrerm··on Content Detection Software Installed on Most Smart TVs
> Content Viewing Information includes things like the title of the content, actions taken while viewing the content, and the length of time you viewed it.

But may or may not include other "things" you will never know.

> we may recognize the content played through your TV. Please note, we are only able to recognize public content, such as certain shows and movies. We won’t know when you’re watching, for example, home videos.

But we will know that it's not a public content video because otherwise we can't know when it is.

> we may also obtain information from other sources and combine that with information we collect

By "may" you should know that we only don't when it's technically impossible or law forbidden (which is basically never)

> if we have your consent to do so, we will share information with companies, organizations or individuals outside of Samba TV.

By "consent" we mean that "would you help make our product better" checkbox that already was checked and you almost didn't notice.

andrerm··on New surveillance tech means you'll never be anonymous again
> we need to ask ourselves whether the future society we want to live in is one which constantly watches its citizens – or, more likely, one in which citizens are never totally sure when, how and by whom they’re being watched.

First, digital behavior is already being 24/7 surveiled. Authorities and corporations only need to extend this to when there is no digital device available with the subject.

But the real danger is that if nobody knows for sure when, how and by whom, then everyone will be forced to assume that it's every time, by every means and by everyone.

And in top of that there is the problem of never being able to truly be forgotten (soft delete). So you lose the motivation to commit mistakes, engage in theoric or philosophical conversations, criticise ahd inovate unless you're going the same direction of status quo. Which only accelerates the process.

andrerm··on Eu Guidelines on Ethics in Artificial Intelligence: Context and Implementation [pdf]
This is a step in the right direction but it is so generic that it basically corroborates everything that is being done today. Is basically says to big tech co: keep up with the good work.

What we need is laws like this: opt-in is mandatory and very well explained. Stop the "would you help to make XYZ better" and contractors listening private conversations, pictures videos calls and who knows what everywhere.

What we need is: people must have a way bypass all AI automated BS and talk to humans at any given time. Stop the click here, open there, press one, press two, press 99, please hold BS.

I shouldn't be commenting on privacy news because I beleave that by the time we get any real effective regulation for ordinary peoples (not CSS/JS pop-ups everywhere) all peoples PII will be out there in the wild and we will have lost control and ownership of names, SSNs, pictures, voice.

To kentye question is less yownto regulate surveillance economy and more how to live in a world where SIM swapping is everywhere.

andrerm··on Ex-Google worker fears 'killer robots' could cause mass atrocities
> The machine doesn’t have the discernment or common sense that the human touch has.

July 12, 2007, Baghdad airstrike (https://en.m.wikipedia.org/wiki/July_12,_2007,_Baghdad_airst...)

Edit: add title to link

andrerm··on Cloudflare's DoH Disabled by Default in Firefox on OpenBSD
> Applications should respect OS configured settings.

Why does everybody misses that part?

andrerm··on CEOs want America-wide privacy law
> i. Consumers should also have the opportunity to make choices with respect to the sale of personal data to non-affiliated third parties.

> ii. Consumers should understand under what circumstances their decision to opt-out (or not opt-in) may result in the organization no longer providing them certain goods and services (for example, free content).

Consent or die

andrerm··on What’s Next in Making Encrypted DNS-over-HTTPS the Default
Android + Chrome + DoH + AMP = ?

Edit: typo

andrerm··on What’s Next in Making Encrypted DNS-over-HTTPS the Default
Mozilla I don't know but Google is already doing it with AMP
andrerm··on You Can Now Tell Facebook to Delete Its Internal Record of Your Face
This is misleading to the point it's almost propaganda. From Facebooks announcement [1]

> ... if you’re in a photo and are part of the audience for that post, we’ll notify you, even if you haven’t been tagged. You’re in control of your image on Facebook and can make choices such as whether to tag yourself, leave yourself untagged, or reach out to the person who posted the photo if you have concerns about it.

[1] https://newsroom.fb.com/news/2017/12/managing-your-identity-...

andrerm··on Hong Kong protestors using Bridgefy's Bluetooth-based mesh network messaging app
Google knows and logs forever every app you start on your device doesn't matter if installed from Google Play or not.
andrerm··on The “mail is hard” myth
> We can’t let that happen: allowing e-mail to be fully controlled by a small set of cooperating multi-million users hosts is just accepting to be screwed.

I agree but don't say it isn't hard. It's hard and it's not for everyone but if you can the benefits are worth it.

Now I don't think having more small mail servers will stop big mail servers abusing their power but without a significant number not small servers better just give up.

For the record I do have my mail server on a vps

andrerm··on Is Apple’s Cloud Key Vault a Crypto Backdoor? (2017)
> This is probably the biggest weakness of the system, and the part that’s driving the “backdoor’ concerns above. You see, the HSMs Apple uses are programmable. This means that — as long as Apple still has the code signing keys — the company can potentially update the custom code it includes onto the HSM to do all sort sorts of things.

> To remove these keys as a concern, once Apple is done programming the HSM, they run these cards through a process that they call a “physical one-way hash function”

> To make sure all admin cards are destroyed, the company has developed a complex ceremony for controlling the cards prior to their destruction.

> This mostly involves people making assertions that they haven’t made copies of the code signing key — which isn’t quite foolproof. But overall it’s pretty impressive.

The problem is that with this kind of implementation governments can forbidden key destruction.

Now, I don't know how to protect users with encryption without users owning master/private key. But that's not my point.

My point is that saying that there is no backdoor is misleading because although there is no backdoor today it's not immune to backdoors

Edit: typing

andrerm··on The “mail is hard” myth
And Postifx is not just one thing, it's: smtp, smtps, submission, relay etc... And Dovecot: pop3, pop3s, imap, imaps, lmtp, passdb, userdb, sql, ldap, seive etc.

Look, I don't want Google changing this tomorrow because to something tied to and controlled by them because they don't do evel, isn't faster or people like it, but please, don't say it's not hard because you will be misleading people for sure

Edit: to be crystal clear, I agree with parent but don't agree with op

andrerm··on On-Device, Real-Time Hand Tracking with MediaPipe
> all on device and do not transmit out

Like Apple? Retorical question. My point is: this stays in device is just propaganda. It can be done but will never happen

andrerm··on Don't Play in Google's Privacy Sandbox
I have conserns about privacy pass protocol. Can't the server abuse the protocol? What if sT is always 2T? For the record, I don't like captcha.

About fingerprinting "budget", asking users for consent is useless to protect users that can't for any reason change to another app

andrerm··on DHS Launches Smart City Sensor Pilot in St. Louis – Nextgov
“I’m sensitive to it,” >Speicher said. “I don’t know the scale or scope at this point in time but I don’t see it as being fundamentally different than our other experiments in the sense of ensuring that we can evaluate the tech without any exposure or concerns with privacy-related data.”

He is "sensitive" to privacy but he doesn't even know the scale or the scope. In the big data (data harvesting) era privacy is never priority. Always comes in second or third place

andrerm··on Google moves closer to letting Chrome web apps edit your files
Great, a giant WebAssembly blob reading and writing my files. What could go wrong?
andrerm··on Google moves closer to letting Chrome web apps edit your files
> Consent by the user

Like Android permissions hell?

Why do Google do this kind of things? Can't they see it's not worth it? How could my 12 years old daughter understand that her farm, barbie or chicken whatever don't need access to read and write her files?

andrerm··on Improving Siri's Privacy Protection
> users will be able to opt in

Would you help make Siri better? Yes|No

andrerm··on Apple Apologizes over Siri Privacy and Will No Longer Retain Audio Recordings
> users will be able to opt in

Would you help make Siri better? Yes|No

andrerm··on Privacy Fundamentalism
> the widespread creation and spread of data is inherent to computers and the Internet

It is not. It is that way because we developed software to he that way

Edit: I don't beleave in absolute privacy, we never had that, but Ibdo think people get surprised and find things creepy for a reason: we are abusing the trust that people had put on us software developers and hardware manufacturers

andrerm··on U.S. tech companies are building a Chinese-style social credit system
Why do you think Google is indexing all your online purchases?

Look, online tracking inevitably leads to behavioral profiling. Put two behavioral profiles side by side and you have scoring, ranking. Add some weight on behaviors, age, income etc. and you have a social credit system.

Edit: the question is not if big tech already have social scores in us or not. The questions are when and how they will use it

andrerm··on Every web server is a dead drop
URL are limited to 1000 charactes
andrerm··on Apple Just Gave 1.4B iPad, iPhone Users a Reason to Leave
We, the ones who fully understans how technology works, must stand in favor of the ones who don't and can't make a truly informed decision when using technology. Tech companies must stop the dark patterns, information obfuscation and misleading and start informing all it's users in a exhaustively, clear and transparent manner.
andrerm··on Apple contractors listened to 1k Siri recordings per shift: former employee
It is not surprising and it is how it works today but people don't fully understand it and can't make a truly infirmed decision.

We, the ones who truly understand both sides if this, must stand in favor of the ones who don't.

andrerm··on Privacy by Design Foundation
But the IRMA QR code generator server is decentralized too?
andrerm··on Privacy by Design Foundation
First, thanks for all the work on the right direction. I have some questions.

Why won't we fall on the same problems we had with SSL certificate issuers until Let's Encrypt truly made HTTPS viable to everyone?

What will prevent requestors from requesting all or most users attributes like most apps do with permissions on Android platform?

Edit: add "with permissions"

andrerm··on Siri, Privacy, and Trust
Paying or not, you're the product.
andrerm··on Fewer Than Half of Google Searches Now Result in a Click
And with AMP, Google is trying to do the same with entire sites.

In the long run why will we continue to produce content for Google?

Google must stop trying to suck the hole world into itself. Google is becoming a big black hole.

And the "it is good for consumers" or "users like it" are just offensive. It's good for Google. It may be good for users today but it's bad for content producers and in the long run it's bad for everyone.

← PreviousPage 2 of 4Next →