HNHacker News
TopNewBestAskShowJobs

cataflam

788 karma · joined January 19, 2012

submissionscomments
cataflam··on Tracking Coronavirus by Smell Test
I don't have a source handy, I think it was Prof. Drosten, but I've read that in Germany, there were many such anecdotal stories as well. The blood serum of these people got tested, and there was no indication that any of them had already had covid-19.

Of course, that's Germany, not London or the US, but at least there, the evidence currently points to a bad flu or something else for all these people from November to February.

cataflam··on Does your video call have End-to-End Encryption? Probably not
> I find it fascinating how committed everyone now is to Zoom when, at least in my circle, almost nobody had used it before two weeks ago.

Anecdotally, almost every startup/VC/etc. in my circle has been using Zoom for the past 2+ years (Paris and London). So there was probably a seed ready to take root not far from you. I've had the occasional Hangouts, and the rare WebEx or Teams meeting with some larger orgs, but that's it. I haven't even logged in to Skype in that time period.

Even my parents have been able to use zoom seamlessly from their phones. I think it helps that you don't even have to login or have an account if it's always someone else creating the meetings.

Zoom was not the first mover in chat/video apps, far from it. But over the past few years, it has overtaken all the other, older ones for the early adopters in the technology adoption cycle, at least in my anecdotal experience. The last few weeks have accelerated the mass adoption that could have taken much longer or never happened to an instant.

cataflam··on The Impact of Coronavirus on Global Activity
I'm going to make a wild bet that active FitBit users are not representative of the population on that matter, and will try to maintain a higher level of activity.
cataflam··on Italy is extending its coronavirus quarantine measures to the entire country
You can read this report from a doctor there (translated in English on reddit): https://www.reddit.com/r/medicine/comments/ff8hns/testimony_...

(the original links in Italian are at the bottom of the post if you prefer that)

cataflam··on Ask HN: A major USA bank is storing passwords in cleartext – what to do?
Blizzard battle.net used to do that, and probably still does: transform to lower or upper case (then hash because I'm giving them the benefit of the doubt), instead of dealing with customer support at a large scale of people messing up capitalisation of their passwords.
cataflam··on Mercurial’s journey to and reflections on Python 3
Isn't this a fairly recent change?
cataflam··on John Carmack and Amazon's $30 1TB thumb drives
On that topic, a tool named f3 exists to test the capacity of that flash drive/card you just bought from Amazon.

https://github.com/AltraMayor/f3/

cataflam··on Ask HN: Could EU residents comment on how the GDPR has improved their privacy?
All marketing email has an unsubscribe link if it didn't before, and you know it actually works now to stop the emails, not just confirm your email address works.

You also know you can get all the information a company has on you, and get them to delete it if you need to. I haven't made use of it yet, but I've read of people who have.

From inside the business side, I see most companies thinking about GDPR compliance when developing new products and features. What was never the case before and you notice now is they try to minimize PII collected to avoid headaches, and they are very careful about how data is shared with 3rd parties, asking for consent before doing it, etc.

cataflam··on [dead]
Oh right, my bad.

I've since realized it's a duplicate of https://news.ycombinator.com/item?id=19963640

cataflam··on [dead]
I think the author is https://twitter.com/PavelDoGreat

And the source is https://github.com/PavelDoGreat/WebGL-Fluid-Simulation

cataflam··on Caviar was a free bar snack
That was only true in coastal North America (and even there, the tales of disgust have probably also been exaggerated), not Europe. There are traces of it being appreciated going back to the Romans and Greeks. http://www.foodtimeline.org/foodlobster.html
cataflam··on Git reset vs. Git revert
The explanation that made me understand git reset the best is "Git Tools – Reset Demystified" from the Pro Git book [0].

Everything has been crystal clear since. I highly recommend it if you use git.

[0] https://git-scm.com/book/en/v2/Git-Tools-Reset-Demystified

cataflam··on 7-zip broken password random number generator
Not exactly the same, but the EU has commissioned audits and just started a bug bounty program on some important open source projects.

https://juliareda.eu/2018/12/eu-fossa-bug-bounties/

cataflam··on Backblaze Hard Drive Stats for 2018
Not the parent, but probably because

1. It's notorious that hard drives have a higher failure rate at the beginning of their lives than in the middle (see bathtub curve [0]). So it's not absurd to test them hard early on before writing any useful data and to do an early RMA.

2. The failure rate on drives is low enough that his methodology may be right but he still never has any failure in his life. Doesn't it make insane.

[0] https://en.wikipedia.org/wiki/Bathtub_curve

cataflam··on VLC developers refuse to consider updates over HTTPS
Mirror as the bugtracker seems to be taking a beating from the post: https://archive.fo/Dmtwo
cataflam··on Remotely compromise devices by using bugs in Marvell Avastar Wi-Fi
WiFi chips and baseband processors are particularly attractive targets for exploitation, since they are network entry point for devices, and running systems that have probably been less investigated (at least publicly).

Very nice research and writeup. For those who haven't seen it a couple of years ago, Project Zero also had a series of articles about exploiting Broadcom's WiFi stack [0].

[0] https://googleprojectzero.blogspot.com/2017/04/over-air-expl...

cataflam··on Remotely compromise devices by using bugs in Marvell Avastar Wi-Fi
> not really an OS, just a super-fast way of dealing with I/O streams

Saying this without any animosity, but you would probably be interested in reading about the history of operating systems. Desktop OSes are a (very visible) minority, and it's the opposite way in my opinion: a desktop OS is an OS + a large suite of tools + a shell.

It's literally something that operates the system so that every program written doesn't have to handle all the low level IO, that enables task management, etc.

https://en.wikipedia.org/wiki/History_of_operating_systems

cataflam··on Lessons Learned from Writing Over 300k Lines of Infrastructure Code
> hope he didn't write 300K lines of Terraform code.

If you look at the company, their product is providing infrastructure code, it was not a byproduct.

cataflam··on Comparison of the Best NSFW Image Moderation APIs 2018
There is (at least) one company providing this kind of services. They tag in the movie all the content with timestamps, and can provide it to a player to skip or not depending on the tag (nudity, violence, etc.).

As far as I know, it was manual, but that was already a few years ago.

I don't remember the name of the company, but surely it can be found and there are probably multiple such providers. The service was provided to TV operators (satellite, cable or pay-TV) to include in their set-top boxes.

PS: of course, as sjcsjc mentioned in a sibling comment, it immediately gives the idea to many people to only show those parts :)

cataflam··on Ask HN: What are some of the best technical talks you've heard?
It's We Really Don't Know How To Compute! by Gerald Jay Sussman
cataflam··on How I hacked modern vending machines
Fun stuff!

The article has an old vibe of hacking articles published in the '90s/'00s (in a good way).

> obviously, it was password protected

Not obvious at all. Last time I checked, WhatsApp or Telegram didn't password protect their database (that was a while ago admittedly). And obviously, it doesn't actually provide that much protection if the key is on the phone, as the article demonstrates.

cataflam··on Listen to a SIM-Jacking, Account-Stealing Ransom
That's not for your benefit, that's for them to verify you're a human / not a spammer / collect information (at least that seems like the most reasonable explanation to me).
cataflam··on Microsoft suspends Windows 10 update, citing data loss reports
Interesting.

They do have Mark Russinovich of colossal SysInternals fame as Azure CTO though.

cataflam··on Ask HN: Why did your startup fail and what did you learn?
I'm curious, how much would you have paid to be protected from this kind of risk and make sure you'd get your money?
cataflam··on Apple Maps vs. Google Maps vs. Waze
Great article, but the sample size is too small to draw strong conclusions from those time differences.
cataflam··on Tesla posts big loss, cuts production of Models X and S to catch up on Model 3
Indeed, if you click "expand" next to "About this article" at the bottom you will read :

>Author payment: $35 + $0.01/page view. Authors of PRO articles receive a minimum guaranteed payment of $150-500.

cataflam··on Ask HN: Who is hiring? (November 2017)
EHDA | Software Engineer, QA, Devops | Paris, France | ONSITE, REMOTE | Full-time

Euler Hermes Digital Agency (EHDA) https://ehda.co

We are a small innovation team, backed by Euler Hermes, the world leader in trade credit insurance. We try to bring together its expertise and extensive database with the mindset of a software company to develop new products in a digital world. We think there is currently a massive untapped opportunity to seize, in a vast but complex and strongly regulated market, and we believe we are uniquely positioned to capture it.

Our main product at the moment is a REST(-ish) API, allowing other platforms to include our insurance product. Think travel insurance tickbox, but for the risk of not getting your invoice paid on time. It is developed in C#/.NET and hosted on Azure. We also have some systems on AWS, and upcoming products, tools or test suites developed in Python and JavaScript.

We already have multiple customers in production and are scaling up. The team working on these products is still quite small (around 10 people), so your exact role will depend more on your abilities than a rigid description. Overall, we need software, QA and devops engineers.

We try our best to maintain a fantastic team in a diverse, welcoming and relaxed work environment. We offer competitive salaries, depending on profile, education, experience.

If you are interested, please reach out to sami (at) ehda.co (CTO) with your resume.

cataflam··on Opera Neon concept browser
That's from Opera. See http://help.opera.com/opera/Windows/1781/en/private.html

"If you are browsing on an encrypted connection (https://), Opera checks to ensure that all parts of the site are encrypted. If Opera detects that any live elements of the page, for example scripts, plugins, or frames, are being served by an open connection (http://), it will block the insecure content. This means parts of the page may not display properly.

Opera advises against allowing insecure content to load into an encrypted connection. The best way to protect your sensitive information is to interact only with secure content. When Opera detects insecure content and blocks it, a warning will appear in the right side of the combined address and search bar.

If you do not care about the security of your connection with the site, you can click the warning to show an Unblock button. This button will allow the blocked content to be loaded onto the page, and the security badge will change to show an open padlock, reminding you that you've allowed insecure content to display on an encrypted connection."

cataflam··on Opera Neon concept browser
Probably just an oversight or a typo. They've now changed the link to https.
cataflam··on Opera Neon concept browser
They changed the download link to https. The warning and block is from Opera itself. See http://help.opera.com/opera/Windows/1781/en/private.html

"If you are browsing on an encrypted connection (https://), Opera checks to ensure that all parts of the site are encrypted. If Opera detects that any live elements of the page, for example scripts, plugins, or frames, are being served by an open connection (http://), it will block the insecure content. This means parts of the page may not display properly. Opera advises against allowing insecure content to load into an encrypted connection. The best way to protect your sensitive information is to interact only with secure content. When Opera detects insecure content and blocks it, a warning will appear in the right side of the combined address and search bar. If you do not care about the security of your connection with the site, you can click the warning to show an Unblock button. This button will allow the blocked content to be loaded onto the page, and the security badge will change to show an open padlock, reminding you that you've allowed insecure content to display on an encrypted connection."

← PreviousPage 3 of 5Next →