HNHacker News
TopNewBestAskShowJobs

cmg

1,061 karma · joined September 14, 2010

Personal & small-org security, Rails/PHP/JS development.

Former Technology Director @ Trans Lifeline. they/them

@cmg on the bird site

submissionscomments
cmg··on Minify and Gzip (2022)
Because 1 !== true and 0 !== false in JavaScript:

  const index = "Hello HN".indexOf("H")
  console.log(index);
  >> 0
  index == false
  >> TRUE
  index === false
  >> FALSE
cmg··on Apple plans a slow, appointment-only rollout of Vision Pro
For me, the "magic word" is my WWDC 2007 bag. Pretty much the only reason I keep it around these days.
cmg··on Should you remove duplicate files?
If you're not rebuilding the desktop every other day you're really missing out!
cmg··on Infinite Mac: Infinitemac.org
Before anyone looks up and emails that relative, please note that it's been attempted already:

https://www.emaculation.com/forum/viewtopic.php?p=75314#p753...

cmg··on The Disappearance of the Ashtray
I took the Shinkansen on my last trip to Japan in 2016 and I didn't see any smoking cars, but there were closed-off smoking rooms available on the train with really good ventilation systems.
cmg··on Ncdu – NCurses Disk Usage
One of the first things I did in my new position was to add ncdu (and mysqltuner) to our Ansible playbooks. It's that useful for me - I probably use it every other day at least.
cmg··on Never use a warning when you mean undo (2007)
[2007] but also timeless advice, at least while our UIs still follow the same general paradigms.

It's important to note that Aza Raskin is the son of Jef Raskin, who wrote a lot about interfaces (including a book called The Humane Interface), and worked on the original Macintosh at Apple, on the interface.

Aza Raskin has continued that work at Mozilla and elsewhere and I'm glad he has. Though I miss the original Songza interface https://signalvnoise.com/posts/1117-fresh-ui-ideas-from-song...

cmg··on Why is Rosetta 2 fast?
For what it's worth, I use Mailplane on an M1 MacBook Air (8GB) with 2 Gmail tabs and a calendar tab without noticeable issues.

Unfortunately the developers weren't able to get Google to work with them on a policy change that impacted the app [0] [1] and so gave up and have moved on to a new and completely different customer support service.

[0] https://developers.googleblog.com/2020/08/guidance-for-our-e... [1] https://mailplaneapp.com/blog/entry/mailplane_stopped_sellin...

So unfortunately

cmg··on Linode Outage in Dallas, Fremont, Atlanta, Newark, and Toronto Data Centers
I had 6 servers out of about 50 go down, all in Dallas/Atlanta even though most servers are in Newark. IPv6 connectivity seemed to remain up for all of them, though.
cmg··on Integrating with Fastmail
This is fine if you're not concerned about metadata (date, recipients, subject).
cmg··on AppleScript: Graphic User Interface (GUI) Scripting
Remote Apple Events are pretty fantastic. Back in 2002/2003, I wrote an AppleScript Studio application (with a little bit of Objective-C) that let you control iTunes on another machine.

It seemed like absolute magic at the time to me and my friends - from my PowerBook on the couch, we could change the song playing on the iMac on the other side of the room! Wish I still had that source code to look at.

cmg··on Removal of Heroku free product plans
> Starting October 26, 2022, we will begin deleting inactive accounts and associated storage for accounts that have been inactive for over a year. Starting November 28, 2022, we plan to stop offering free product plans and plan to start shutting down free dynos and data services. We will be sending out a series of email communications to affected users.

Sad to see this, but not surprised after the Salesforce purchase. Heroku was a great place for hobbyists and tiny one-off projects. What's a good alternative?

cmg··on Ask HN: Can I see your scripts?
I have this one aliased to mkcd, but yours saves an extra character. I like it!
cmg··on U.S. transition to 988 suicide and crisis lifeline begins Saturday
It was very much performative anti racism. All the right words, none of the actions.
cmg··on U.S. transition to 988 suicide and crisis lifeline begins Saturday
I explained a little elsewhere in this thread: https://news.ycombinator.com/item?id=32121332
cmg··on U.S. transition to 988 suicide and crisis lifeline begins Saturday
Hi Zhama, I’m not able to fully respond to your comments right now but I read and appreciate them even if I don’t fully agree. And thank you for what you do at CTL.

My post was general, not specific to CTL.

cmg··on U.S. transition to 988 suicide and crisis lifeline begins Saturday
I’m glad to hear that. There is a place for these hotlines and I have a lot of respect for the folks who volunteer at them - I hope it didn’t come off differently. My comments weren’t meant to be blanket “everything is like this” but rather pointing out trends & common experiences.
cmg··on U.S. transition to 988 suicide and crisis lifeline begins Saturday
I’m not particularly interested in having to defend myself on this forum, on a completely unrelated post. heartbreak will likely respond, and that’s fine, but it’s very interesting that they decided to look into my (public) associations here.
cmg··on U.S. transition to 988 suicide and crisis lifeline begins Saturday
I'm on the EB but I don't get paid for that. Why?
cmg··on U.S. transition to 988 suicide and crisis lifeline begins Saturday
I'm so sorry to hear about your brother, Jamie. I hope he can find the support he needs. This is too common of a story.
cmg··on U.S. transition to 988 suicide and crisis lifeline begins Saturday
I'm hesitant to answer this because a lot of what I'd have to say can't be corroborated except for people who work or worked there. I'll summarize, with the understanding that I left a month after the 2020 election (I gave my notice in October 2020 and stayed on to get the organization through potential security issues around the election).

- A culture of internal anti-Blackness. During the uprising of 2020, staff and volunteers wanted the leadership team to address real issues with race inside the organization. As a member of the leadership team at the Director level, I pushed for many of the staff-led changes, but most of the team wanted to just talk about things instead of implementing policies.

- I had a bug in some software I wrote - applications for a service were supposed to be distributed based on race. A few more white people than they wanted got through. I fixed the bug immediately (it was a concurrency issue), explained it, and was met with absolute hostility - shouted at in meetings, labeled a white supremacist and removed from leadership. A plan was developed to have mediation, but after months nothing happened.

- From what I understand, they have basically gotten rid of their QA program that would review calls to make sure operators are properly trained and handling calls appropriately.

- A former staff member went missing during a mental health crisis. They said they were going to provide FMLA but fired her instead, leaving her partner and children without any financial support.

- Piss-poor answer rate. After they fired their Hotline Program Director last year, basically no one stepped up to run the hotline. Folks I've heard from have reported that many volunteers (the backbone of the hotline department) left, new volunteers weren't being processed properly.

cmg··on U.S. transition to 988 suicide and crisis lifeline begins Saturday
I have experience in this field: I ran technology for one of the only hotlines in the US that didn't engage in non-consensual active rescue [0] [1]. I've written about this a little on this site in the past, when Crisis Text Line was caught sharing data.

Many, if not most, of these places give the operator full access to your phone number and whatever geolocation data they can get based on that. They also have policies where the operator is allowed/encouraged to call emergency services on you without your ongoing consent, or even without telling you. In my experience talking with others who have been affected by those kinds of policies, this can lead to police breaking down your door while you're naked and crying, or worse. A person in deep crisis is not likely to respond well to armed officers showing up, as the police are more likely to come into the situation looking for conflict.

Sometimes, you can call a local dispatch and just get medical services, or maybe a fire department sent first. But that's entirely up to the discretion of the dispatcher and local protocol.

There's also a relatively common experience I've heard where people who aren't actively suicidal call these lines, and the operator (I won't say counselor) is completely dismissive: "if you're not going to hurt yourself, what do you want me to do?"

Not to mention the stories I've heard where call centers just have passwords for their internal systems on sticky notes laying around on monitors...

The general field is so bleak that some other folks with peer support experience and I have started a nonprofit where one of the things we're doing is building open-source software that will let anyone create their own support line. Security and privacy are our primary concerns, ensuring that operators and callers never see each other's numbers or any kind of information.

[0] non-consensual active rescue is the practice of calling emergency services on someone without their OK

[1] The line was Trans Lifeline, which I cannot recommend supporting for other reasons at this point

cmg··on Ask HN: What is with the new URLs on facebook.com?
Along these lines, someone else mentioned that Tiktok embeds direct tracking into URLs already.

Twitter recently started adding a 't=' param to their share links [0] as well, and I can only guess that it's some kind of similar tracking scheme. From watching browser traffic it appears to be generated when you click the share button, but I might be wrong about that.

[0] https://twitter.com/NanoRaptor/status/1548301612246249474?s=... - the first thing in my feed. Link works fine without any of the query params, of course.

cmg··on Ask HN: What is with the new URLs on facebook.com?
> try to expire old pbfids (and risk breaking "legitimate" links)

Or encode some versioning scheme, and keep trying various versions until one comes up with a valid link. If we can think of these things in seconds, so can the engineers at FB.

cmg··on The Art of Mac Malware: Volume I: Analysis
In November of 2020, Apple's OCSP responder became slow/unavailable for a bit. As a result, Mac apps were either not loading or taking a very long time to load because trustd was trying to connect on app launches and connecting but not getting a quick response.

https://blog.jacopo.io/en/post/apple-ocsp/

cmg··on It's quite hard to lose a Duolingo streak
I'm using Duolingo to learn Russian because my spouse is Russian and I want to communicate better with his family (especially his grandmother, who speaks less English than I do Russian).

After nearly a year, I can help set up for dinner ("Where are the plates?" "There is bread on the table already" "Do you want tea?") and similar things.

Now I'm getting into genitives and such, and that's where Duolingo really seems to not do well. It doesn't explain why a word appears a certain way in a tense, it just makes you memorize that it does. Sometimes I'll ask my husband why, and he just says "Well, because that's the way it is". Of course I'll use the same explanation when my MIL asks me something about English.

cmg··on What's the deal with all those weird wrong-number texts?
Nope. It’s some kind of restaurant. She’s drinking a tea or juice or something like that from a glass with a straw
cmg··on What's the deal with all those weird wrong-number texts?
It was an 802 area code in this case, but I think it’s pretty clear now that these scammers have multiple personas and numbers to work with.
cmg··on What's the deal with all those weird wrong-number texts?
I've gotten a few in the last couple months, with a US cellular number that I've had for over 20 years. At least two are "I missed you at the gym today!" via text and another was from a Vermont area code via WhatsApp to a "Dr. Jack":

> Hi Dr. Jack! My cat is very slow and does not eat cat food. Can you make an appointment for me?

> Sorry, you have the wrong number

> Sorry, I just checked, I entered a wrong number, please don't mind. hope I did not disturb you.

> Best of luck with your cat!

> thank you for understanding. You are a kind person. where do you come from.

And then I just moved on with my day, because as nice as that sounded I wasn't looking for a conversation.

The contact profile image is of a young, attractive Asian woman, I think at a restaurant. No reverse image results on Tineye or Google.

[Edit: I’ve had this number for over 20 years (not “nearly 20”) and now I feel old.]

cmg··on Apple’s macOS Ventura – New Security Changes
Exactly. Technical measures are important, but if someone wants to play a game or do something that's been banned on Apple's stores and finds a site that claims to have an installer (which is actually malware) with instructions to disable Gatekeeper or SIP or what not, social engineering can work. Their goal is to do the thing they wanted to do, probably not thinking of security in the meanwhile. Popup alerts are going to be interpreted as something to get rid of so they can do the thing.

It's a difficult balance. Power users, engineers, developers - we can (usually) tell when warnings need to be heeded. People who use their devices to achieve a goal without really understanding or caring about what's happening usually won't.

← PreviousPage 2 of 9Next →