HNHacker News
TopNewBestAskShowJobs

atomwaffel

499 karma · joined March 31, 2015

submissionscomments
atomwaffel··on A bot that tweets any time devs swear on GitHub
Probably often enough to be used to it, although it's still bad design and needs to be fixed. (I'm not sure why a non-public-facing system needed a profanity filter in the first place.) https://en.wikipedia.org/wiki/Scunthorpe_problem

I find it interesting that this Twitter bot seems to have the same problem in reverse: it can't reliably filter out things that aren't offensive.

Edit: Thinking about it, it's really still the same problem, i.e. false positives when trying to automatically determine whether or not a given string contains swearwords.

atomwaffel··on Post a boarding pass on Facebook, get your account stolen
Detecting if the embedded data is from a boarding pass is not difficult, nor is parsing it[0] and displaying it in a human-friendly format to "prove" that it's probably sensitive ("The boarding pass you posted belongs to John Smith and contains their American Airlines frequent flyer number. Are you sure you want to share this?")

[0] https://www.iata.org/whatwedo/stb/Documents/BCBP-Implementat...

atomwaffel··on Airport lounges will let anyone in, provided you can fake a QR code (2016)
Almost, but not quite. It does apply on all flights departing from the EU, but only on flights arriving in the EU if they are operated by a carrier from an EU country. It's a small but important distinction.

For example, if you were travelling from London to New York, it would always apply regardless of the airline. In the other direction, however, it would apply on BA but not on AA.

atomwaffel··on Japan Pictures Likely Show Melted Fukushima Fuel for First Time
Good point, those are definitely easier to read, although in this age of clickbait I give them credit for admitting a degree of uncertainty right in the headline.
atomwaffel··on Japan Pictures Likely Show Melted Fukushima Fuel for First Time
That's exactly what I did. I think my brain even went on to read "show" as a noun, and "may" would have prevented that. Title Case Didn't Help Much Either.

Besides that, I'm not sure either "Japan" or "Japanese" is really necessary, because "Fukushima" makes it clear that the pictures are from Japan.

atomwaffel··on Japan Pictures Likely Show Melted Fukushima Fuel for First Time
As I feel incompetent to comment on the article's content, I'll be glad to start a thread on the linguistics of that car crash of a headline. It took me three or four fresh starts to parse it correctly. The linguistic term for this is garden path sentence[1][2] and it's such a good one that it makes me wonder if it's deliberate.

Even just some small adjustments would make it more readable: "Japanese pictures may show melted fuel from Fukushima for the first time."

[1] https://en.wikipedia.org/wiki/Garden_path_sentence [2] https://www.youtube.com/watch?v=ldT2g2qDQNQ

atomwaffel··on Every total solar eclipse happening in our lifetime
D3 (https://d3js.org). It's actually not terribly hard to do: https://bl.ocks.org/mbostock/7ea1dde508cec6d2d95306f92642bc4...
atomwaffel··on Auto-Play Policy Changes for macOS
Although one might argue that there's something seriously wrong with your website already if it doesn't work without video playing in the background.

According to the article, blacklisting (or lack of whitelisting) is also easy to detect by handling the Promise rejection, which means you can easily provide a static fallback for video that's used purely decoratively.

atomwaffel··on Auto-Play Policy Changes for macOS
Oh, absolutely. I'd even expect them to be whitelisted by default (although that would pose the interesting problem of deciding which sites deserve the privilege of being whitelisted out of the box).
atomwaffel··on Auto-Play Policy Changes for macOS
YouTube. Netflix.
atomwaffel··on Arturo Di Modica has a point
It depends on the reasons for your dislike, as the article explains beautifully. If you don't like the statue because you disagree that women should have the same entitlements as men, then you may need to open yourself to the possibility of being called sexist.
atomwaffel··on Five world map styles
Yes, you're very clever. https://xkcd.com/977/
atomwaffel··on Five world map styles
It's used in what's arguably the most used map of our time, Google Maps (as well as most other interactive maps).
atomwaffel··on Brexit's Tech Brain Drain
Not quite:

> the UK will be able to revoke its notification of article 50 but this must be “subject to conditions set by all EU27 so they cannot be used as a procedural device or abused in an attempt to improve the actual terms of the United Kingdom’s membership”. [1]

So in short, remaining is less likely than ever but still possible.

[1] https://www.theguardian.com/politics/2017/mar/29/first-eu-re...

atomwaffel··on The Gig Economy Celebrates Working To Excess
The form factor. My national ID is the size of a credit card, so I always keep it in my wallet. For something that lets me visit a good thirty countries, that's good enough value for me.
atomwaffel··on Amsterdam Airport Launches API Platform
Or written by people whose native language isn't English, which is a possibility.
atomwaffel··on Most Electronics Being Banned on Certain US-Bound Flights
Yes, they can be refused at Heathrow. I did so just a few weeks ago. The alternative process wasn't unpleasant but did feel deliberately inefficient.
atomwaffel··on All I Possess
You're wrong: https://allipossess.com/products/macbook

He does, however, only seem to possess one pair of boxer shorts.

atomwaffel··on Death by Tactile Paving
On the contrary: it's not naïve, it's far too advanced. This isn't a problem that needs to be solved with technology and by forcing people to wear a beeping device on their heads. You can just install a railing and make the environment safe for everyone.

I suppose your solution would work as a stopgap, but it seems like poor design to make people adapt to human-made environments rather than building the environments in a way that works for everyone.

atomwaffel··on Stop Using Arial and Helvetica (2013)
That's a great idea in theory, but bear in mind that (in most target audiences) few people will know how to change the default typeface and even fewer will bother. I'd be willing to bet that 95 percent of your visitors will be seeing Arial, Helvetica or Roboto.

I'm not trying to dissuade you, just make you aware (if you weren't already) that you're making a choice by not making a choice.

atomwaffel··on Tripling Down Against USA Conference Hosting
I was thinking of Spain too. I went to a conference in Madrid last year and was pleasantly surprised by how many people there were from Spanish-speaking Latin America, far more than I usually see at conferences. At the same time, it's easy enough to get to for most of Europe and not too far from North America either.

Then again, I'm sure it's a nightmare for people from Oceania. Our planet is really inconvenient in that regard, what with being round and all…

atomwaffel··on Show HN: The Quibbler aggregates “fake news”
Here's the solution to the substitution cipher on the "contact us" page, in case you were wondering.

    Hom ckxpt faji yfsrxa ukqlb fgmw hom rzvj edzwn. Hf bmae qm za mrmphwfaxp qzxr kbm hoxb zeewmbb: medxaomwm zh yqzxr efh pfq.
    The quick onyx goblin jumps over the lazy dwarf. To send me an electronic mail use this address: ......... at gmail dot com.
(I left out the username part of the email because I won't post other people's email addresses, but it's easy enough to decode.)
atomwaffel··on Naughty Strings: A list of strings likely to cause issues as user-input data
From what I remember (can't test right now), a zero-width space is okay as long as there are other (printable) characters in there too. This seems reasonable, because allowing a tweet to be a single zero-width space would make it appear be empty and probably lead to some confusing display issues.

I'm pretty sure I've used it to "end" a hashtag early, like in this made-up example:

    I've eaten two #banana<ZWS>s today!
In my language, the possessive form doesn't take an apostrophe ("Alices Adventures" instead of "Alice's"), so for hashtags and user names it can be desirable to use the ZWS as an invisible apostrophe.
atomwaffel··on Is this plane landing or departing?
Exactly, that's why I think this is a great pictogram: it makes it clear what it's supposed to represent, even though it has nothing to do with what a healthy landing looks like. A pictogram's job is to fit most people's conceptual model of what it represents while being simple and distinguishable, not to be an accurate representation of whatever it stands for.

This pictogram is simple (just a few shapes), it's easy to distinguish (e.g. from the pictogram for "departure"), and it fits most people's conceptual model of a landing (plane comes down from sky to earth).

atomwaffel··on NeverSSL
It also depends on where you are. Getting high-speed, low-latency internet to a shopping centre in the middle of a metropolitan area is probably a bit easier and cheaper than getting it to a plane flying 40000 feet above the Atlantic. And while I probably wouldn't pay $20 for eight hours of internet on a plane (unless I really needed it), I don't find the price tag entirely unjustified.
atomwaffel··on Where in the World Is Carmen Sandiego? Becoming a Secret Travel Agent [video]
> They also made some pretty ridiculous suggestions that simply wont work, like the proposed scheme with adding your FF# to other peoples tickets. The name on the ticket has to match yours for you to get the miles, this is the worst imaginable way of stealing them.

You must have missed the bit in the Q&A session when they addressed this very issue. They suggested creating a new frequent flyer account in the name of the person travelling and transferring the stolen miles to your own account – or simply changing the name attached to your own account if the system permits. They also claimed to know of people who were doing this as they spoke, and their talk gives little reason to doubt them.

> I watched the entire talk days ago as it was happening and didn't see anything new or interesting in it. Record locators are short and you can scan bar codes on boarding passes was basically all of it.

I disagree. The (in)security of travel agency systems was something I suspected but had no evidence of, and they presented some novel, fairly clever and disturbingly feasible ways of exploiting the bruteforceability of sequential PNRs, like sending highly targetted credit card phishing emails to people with recent bookings.

atomwaffel··on Where in the World Is Carmen Sandiego? Becoming a Secret Travel Agent [video]
> I get that he was saying that the system is unsafe but a lot of it is only in relation to the web interfaces.

I think that was the point though: when these systems were being built in the 70s (i.e. pre-internet), the security measures they had – many of them based on trust – were perfectly reasonable. You'd need to have physical access to a machine connected to this closed network to even do so much as look at a reservation. And then the internet comes along and these companies (with no experience in web security) hook up their closed, tightly controlled network to an open, not-at-all controlled network with virtually no additional security. I guess it's fair to say that trust alone doesn't work too well on the internet.

> You can't get direct GDS access unless you're working directly for an airline or travel agency. Those people definitely need to see most of the information on the record.

Yes, but the researchers addressed this in their talk about 14 minutes in. The authentication isn't hard to crack: it consists of an agent ID and a password, often in a format like WS<DDMMYY> (where <DDMMYY> is the date of first access to the system). These credentials are shared by the same office at the very least, and I have a sneaky feeling that I might find a conspicuous post-it note on a computer screen if I visit a few of my local travel agents.

atomwaffel··on Deep Learning Enables You to Hide Screen When Your Boss Is Approaching
But I can mentally snooze a Slack notification for three minutes or so, enough to neatly tuck away everything in my head and reach a state where I can more easily resume what I was doing. That doesn't work as well when I have someone breathing down my neck who "just wants a really quick word".
atomwaffel··on Japan issues tsunami warning after magnitude 7.3 earthquake
Interesting, thanks! I had a quick peek at the developer tools but didn't delve more deeply. I assume (from the fact that it was live TV) that all of this can be done just in time as well and that the stream of captions is sent along with the video stream.

> Also, this video is in Flash

Not for me. I was watching in Safari on my phone.

atomwaffel··on Japan issues tsunami warning after magnitude 7.3 earthquake
I was also quite amazed to see that they have closed captions for the simultaneous translation of their live domestic broadcast. Besides the sheer logistics of it, I didn't even know that you could do that with HTML video.
← PreviousPage 3 of 5Next →