HNHacker News
TopNewBestAskShowJobs

cnst

3,678 karma · joined December 18, 2013

submissionscomments
cnst··on Synthetic Fragrance Is Dangerous. The New Second Hand Smoke
Honestly, I'd rather my 0.1% in rent would go to these lawyers than to the scent machine companies.

I'm very surprised it even took that long for this to happen. These laws have been on the books for decades, and the scent-free policies have been popping up like flowers ever since the 2009 CDC policy that went as far as prohibit using scented detergent for clothing worn to work (a little extreme, sure, but, at the very least, doing an extra rinse cycle does help a lot).

Many of these policies are more about awareness and civil rights than actual enforcement. If these policies are normalised and seen by everyone, it removes the friction from people for whose benefit these policies were created. So then if you actually need it enforced, it wouldn't be a surprise to anyone of your need for the policy to be enforced.

cnst··on Synthetic Fragrance Is Dangerous. The New Second Hand Smoke
They may be stretching a bit, but the statistics is still on their side, and their filings are very explicit that they actually demand compliance (sure, they probably had to add that for some legitimacy, but they did add that nonetheless).
cnst··on Synthetic Fragrance Is Dangerous. The New Second Hand Smoke
This filing is worth a read for the entire situation:

* https://colevannote.com/wp-content/uploads/CMP_Greystar.pdf

For those unaware, Greystar is a major property management company in the US for residential apartments:

* https://en.wikipedia.org/wiki/Greystar

It's a great summary of the issues. Some of the less talked about points is an outsized disparate impact of these scent machines on reportedly 85.4% of autistic individuals, as pointed in the opening statement of this lawsuit, which I'm sure many HN readers could certainly relate to.

cnst··on Plaintiffs allege the use of scents discriminates against them under the Ada
Found the non-paywall original:

https://news.ycombinator.com/item?id=48734824

cnst··on Plaintiffs allege the use of scents discriminates against them under the Ada
I recently learned that the CDC has adopted an "Indoor Environmental Quality Policy" in 2009 that has the following text:

> In addition, CDC encourages employees to be as fragrance-free as possible when they arrive in the workplace. Fragrance is not appropriate for a professional work environment, and the use of some products with fragrance may be detrimental to the health of workers with chemical sensitivities, allergies, asthma, and chronic headaches/migraines. Employees should avoid scented detergents and fabric softeners on clothes worn to the office. Many fragrance-free personal care and laundry products are easily available and provide safer alternatives.

The most interesting bits:

> Fragrance is not appropriate for a professional work environment

> Employees should avoid scented detergents and fabric softeners on clothes worn to the office.

cnst··on Mercedes-Benz commits to bringing back physical buttons
Resume Driven Development is why fundamentally people like Steve Jobs and Elon Musk are crucial to ensuring the enshitification is kept in check.

Elon Musk may be a bad example in this situation, because he's actually a fan of removing the extra controls and the physical buttons, but at least their UX is far-far better than any of the legacy manufacturers.

cnst··on Credit cards are vulnerable to brute force kind attacks
IIRC, MasterCard SecureCode and Visa's verified-by-visa were more of a thing in the US maybe like decade or two ago? I think NewEgg and B&H did support it at one point? Afterwards, everyone has simply disabled the thing, and you simply get a wave-through by most issuers when shopping on foreign sites, where you get redirected to issuer's website, then back to the online shop, without having to type or confirm anything.

Back when it was a thing, it was quite a nightmare, where you had to register for a 3ds account, often separate from your normal online account, and keep a separate password etc. Then those iframe windows look exactly like the phishing websites, too.

Honestly, it's much ado about nothing. If the transaction is suspicious or likely fraudulent, today, you already get an SMS or an alert within bank's app on your phone. All you have to do is confirm and retry the transaction a minute later. This works for both in-person transactions, as well as remote ones, with the same flow, unlike 3ds, which only works for online shopping.

cnst··on AWS stops billing Middle East cloud customers as repairs to war damage drag on
I think during the OVH fire, it was the smoke damage that was deemed to have damaged a lot of the servers.

Fans and cooling might be affected by all the debris. Spinning rust drives often have breathing holes, too.

cnst··on Your website is not for you
This doesn't even touch the entire resume-driven development issue.

The vast majority of all websites today, are designed in such a way as to tout the resumes of all the people responsible for the site with all the latest buzzwords. Content hidden under drop-down menus noone cares about and which makes things very hard to find, pointless animation here and there, pointless custom zoom logic that doesn't work properly on the big screens, all the latest frameworks to display a few tables of text, progressive loading and pagination for the simplest of data (like the banking transactions of a consumer credit card) that in the old days could have simply been displayed on a single page etc.

cnst··on City Learns Flock Accessed Cameras in Children's Gymnastics Room as a Sales Demo
An underrated comment. But sunlight is the best disinfectant.

I think it's the fundamental issue with these cameras, that it takes pictures of us, but we ourselves cannot access it. Even though it was us who has paid for it!

cnst··on Three men are facing charges in Toronto SMS Blaster arrests
These things just prove that the entire "security" industry is a sham.

At one point, every bank would ensure that your password COULD NOT be saved by your browser, because sEcUrItY.

Which is precisely the scenario where typing your password into a site like this is possible.

cnst··on An AI agent deleted our production database. The agent's confession is below
I think the problem here is that all of these services are optimising for the biggest "change-at-all-cost" that there could be.

If you have a service that does one thing, and does it good, and provides backwards compatibility, it cannot change every day. But if it doesn't change every day, then it's labelled as "obsolete" by those who go after the latest and greatest. If it just works and doesn't require adapting on every level, then those that are after the resume-driven-development, aren't "learning", and thus, again, those services are "old and obsolete".

But you can't have both the "change" and the "stability", something has got to give.

cnst··on GoDaddy gave a domain to a stranger without any documentation
They're so infamous that their infamy even has its own Wikipedia page!

https://en.wikipedia.org/wiki/Controversies_surrounding_GoDa...

And them blocking entire countries from their website and DNS isn't even mentioned in your list or the page!

cnst··on GoDaddy gave a domain to a stranger without any documentation
Apparently, GoDaddy is so infamous that their infamy has its own Wikipedia page!

https://en.wikipedia.org/wiki/Controversies_surrounding_GoDa...

cnst··on GoDaddy gave a domain to a stranger without any documentation
There's been a story a few years ago that GoDaddy was blacklisting entire countries not only from their own website, but also from the DNS provided to their customers.

So, at a minimum, your website and email may not work worldwide if you're using the DNS disservice of GoDaddy.

I would NEVER use GoDaddy as a registrar, but if somehow that was a necessity, I would 100% NEVER use their DNS.

cnst··on GoDaddy gave a domain to a stranger without any documentation
GoDaddy has also been blocking entire countries from being able to access all services.

And to make it far worse, IIRC, at a certain point, those blocks applied not only to GoDaddy's own website, but even to the DNS services that are provided for the customers, e.g., your own website wouldn't necessarily work from the "wrong" country, either.

Honestly, I dunno why anyone would use their services. High price, very low value.

cnst··on Wikipedia deprecates Archive.today, starts removing archive links
They've changed usernames they use to post under. That's the only "altered" allegation they've been accused of.

BTW, they also alter paywalls and other elements, because otherwise, many websites won't show the main content these days.

It kind of seems like "altered" is the new "hacker" today?

cnst··on Wikipedia deprecates Archive.today, starts removing archive links
> Change the original source to something that doesn't need an archive (e.g., a source that was printed on paper), or for which a link to an archive is only a matter of convenience.

They're basically recommending changing verifiable references that can easily be cross-checked and verified, to "printed on paper" sources that could likely never be verified by any other Wikipedian, and can easily be used to provide a falsification and bias that could go unnoticed for extended periods of time.

Honestly, that's all you need to know about Wikipedia.

The "altered" allegation is also disingenuous. The reason archive.org never works, is precisely because it doesn't alter the pages enough. There's no evidence that archive.today has altered any actual main content they've archived; altering the hidden fields, usernames and paywalls, as well as random presentation elements to make the page look properly, doesn't really count as "altered" in my book, yet that's precisely what the allegation amounts to.

cnst··on Wikipedia deprecates Archive.today, starts removing archive links
It's because it's actively maintained, and bypassing the paywalls is its whole selling point, thus, they do have to be good at it.

They bypass the rendering issues by "altering" the webpages. It's not uncommon to archive a page, and see nothing because of the paywalls; but then later on, the same page is silently fixed. They have a Tumblr where you can ask them questions; at one point, it's been quite common for everyone to ask them to fix random specific pages, which they did promptly.

Honestly, you cannot archive a modern page, unless you alter it. Yet they're now being attacked under the pretence of "altering" webpages, but that's never been a secret, and it's technologically impossible to archive without altering.

cnst··on SmartOS
Immutability and reproducibility is great. Depending on unreliable and antiquated hardware, like the USB key sticks, is not.

Who exactly has the environment where you can add, let alone promptly repair/replace, USB key sticks, on your server? Or run PXE when you have just a single server? How exactly do you do that in Hetzner or OVH? Let alone any other service where you get just a single dedicated server or two.

So, we're big enough to have our own quarter-rack in a collocation facility, let's do PXE. Now you have to have a whole separate infrastructure server, just for your other servers to be able to boot properly? (And how exactly does that server itself boot?) Plus, have an extra infra server for redundancy?

Sorry, but this is the reason noone would use SmartOS. You can't build a fortress on such a shaky foundation.

It's simply out of touch with the target market. At least with FreeBSD or OpenBSD, you known it'll just work™ on any single server, as long as serial console access is available, which is standard-enough. Going against the mainstream of Linux is already hard-enough, there's no reason to make it any harder.

SmartOS sounds like a lot of work, for negligible or even negative benefit.

There's zero good reasons why any machine with 450GB+ of zfs-backed redundant storage, needs to rely on USB keys or networking, in order to function properly. There's a reason Samsung's Joyent entirely abandoned and divested of SmartOS, because this sort of over-engineered mentality, simply doesn't compute. It prevents all sorts of usecases, and even with a growth mindset, still prevents the organic growth from a couple of servers to a rack and more.

cnst··on SmartOS
The biggest downside of running off of a USB key, is that it's super unreliable.

How exactly does it make any sense to use ECC memory and ZFS RAID for error correction and redundancy, but then rely on the modern floppy disk for the OS itself?

cnst··on Why use mailing lists?
I'm not disputing that assertion, yet it does go against the marketing materials we're all presented by all of these services, as for reasons to not run our own mailservers.

In other words, if all you want to do is run a personal mailserver, or even a corporate one, you'll probably not have to deal with this supposed IP reputation issue, unless the IP addresses you use, have already been added to the blacklists even before you start at it.

cnst··on Why use mailing lists?
But how would anyone know it's Gmail or Apple if the IP address is new?

That's exactly my point, that the reputation need is overstated by all those services that claim to solve a known problem that everyone has heard of, but noone has actually experienced, because, guess what, it might not actually exist.

I've seen plenty of cases where the emails sent out through Sendgrid et al, end up in the Spam folder, or these "professional" services don't even attempt to retry, thus, never getting through the greylisting, or other bugs which cause deliverability issues, which would never happen if you were to run your own real mail-server on your own hardware yourself.

cnst··on Why use mailing lists?
I'm pretty sure the reputation thing is overstated, else, how would all those providers be able to scale up their SMTP services themselves?
cnst··on Why use mailing lists?
Via http://www.mail-archive.com/nginx@nginx.org/msg25495.html.

Sadly, it's been announced yesterday that the nginx.org mailing lists are being shutdown by end of month (Sept 2025).

P.S. Probably one more reason to look into into the freenginx fork of nginx — https://news.ycombinator.com/item?id=39373327 — their mailing lists are at http://freenginx.org/en/support.html.

cnst··on Apple's Assault on Standards
I feel the same, I agree that the web has gone downhill with all the endless JavaScript wasting all the available CPU cycles. (With all the rest CPU cycles being wasted by the swap-in/out because of the memory bloat of web browsers, again.) This is why these days I ALWAYS enable Low Power Mode in any browser or system that provides such a functionality; macOS has finally added this a few years ago — better late than never.

But I feel like ALL browser vendors are not doing enough to combat this bloat. There have to be resource limits, warning messages/icons, and stop-gap measures to avoid pointless JavaScript wasting our electricity; but NONE of the browsers do this to an extent I'd wish they'd do; in fact, Chrome has actually been ahead of Firefox and Safari in reigning these sites, probably because it has to run in production on 4GB ChromeOS machines costing $99, whereas all the Firefox and Safari devs are probably using 48GB machines costing $2399 as their benchmarks. So, the reality, is that, ironically, Chrome is again the leader even in this area. Because Chrome on a $99 4GB ChromeOS machine feels snappier than Firefox on a $999 MacBook, given enough open tabs.

Your point about feature bloat sounds good in principle, but is not practical in reality. In reality, if things don't work in Safari, you're simply asked to install an app from the App Store. Or if you have to configure a keyboard on a Mac, you have to use a Windows machine with the native keyboard configuration tool, instead of VIA in Chrome WebHID or WebUSB. Why in your opinion are these alternatives not worse than having these sorts of things as web standards as written by Chrome?

cnst··on Apple's Assault on Standards
I never have to use Chrome on any device besides ChromeOS; how exactly is it a monopoly when I can uninstall it once, and never see it on the same device ever again, even on Android, which is made by Google? How is it a monopoly when I don't even lose anything by replacing it with another browser, even on Android?

How exactly is Chrome the same as Edge or Brave or Vivaldi or Yandex Browser or Opera?

Why are there no browsers on iOS besides Safari, and how is that not a monopoly?

The "Internet Explorer" issue culminated with Microsoft attaining a market share that allowed them to stop all innovation and investment into the product, where the browser became substantially lagging behind the competition, as well as lagging substantially in standards compliance. Something that's currently an issue with Safari, not Chrome. (Please enlighten me if that's not the case — which exact standards does Chrome NOT support today? Else, how is supporting EXTRA experimental standards a bad thing?) Chrome and Blink, on the other hand, became market leaders not because they couldn't be uninstalled, but because of superior engineering; Blink is the only browser engine today where you can configure your gaming keyboard, for example. How's that NOT innovation?

Why do you have to keep redefining words according to some laws some politicians wrote, or misplaced analogies that turn things upside down, in order to sustain your points? The only Internet Explorer of today is Safari — severely lagging behind in most modern features, without any ability to be uninstalled or replaced on the iPhones and iPads. Again, I'm actually typing this in Firefox on desktop. As I said, I don't use Chrome, it's not even installed on my machines; because it doesn't have a monopoly in any way, on any device besides ChromeOS. (If you're curious on why I don't use Chrome or Blink on any desktop, it's because I cannot stand blurry text, and there's no way to disable blurry text in Safari, WebKit, Chrome or Blink, which have mandatory antialiasing, making all text super blurry and ugly; that's the actual monoculture we should be talking about.)

cnst··on Apple's Assault on Standards
Can you kindly explain why Blink's monopoly is bad, but iOS Safari's monopoly is good?

Whilst at it, can you kindly explain how Blink is even a monopoly if it's actually separately distributed by 6+ distinct and unrelated/competing vendors, namely, Google, Microsoft, Brave, Vivaldi, Yandex, Opera, etc? Out of these 6 vendors, a total of at least 3 are running an entirely independent search engine, so, these aren't just "fronts", but real competitors.

Whilst at it, can you kindly explain why is it better than I have to use a Windows machine to configure my keyboard or mouse, or the Bluetooth headset, instead of using a web browser on any device with any OS? Or why do I have to download extra apps to get video conference access instead of using a Blink-based web browser from one of like half a dozen vendors?

cnst··on We should have the ability to run any code we want on hardware we own
As an Android user, although I'm not too happy about the Sept 2026 upcoming changes, but also the impact is far overstated in these comments over here.

First of all, it's simply a trial, a whole year from now, in Sept 2026, and only in 4 mid-sized countries around the world.

Second, they'll only be verifying developers, not users. They won't be reviewing the apps any more than they already do today. They already do scan all third-party apps, which is partly why people are upset about the needless doxxing of the devs.

Also, as far as I understand it, an app store like F-Droid already does app signing on behalf of other developers, to ensure funny stuff couldn't simply slip through undetected, so, as such, F-Droid probably already "owns" the Aurora Store and all the other apps you can download through the F-Droid app store, so, it would be my expectation that even in those 4 countries in Sept 2026 during the trial, you could still sideload the same apps the same way I do today.

In turn, the apps installed by Aurora Store are signed by the Play Store; this ensures that the private data cannot be hijacked through modified updates of the app, since the developer profile won't match. So, there's no concern there, either, since everything is signed.

Basically, it's not a good precedent, but at the same time, nothing will really change at least for my own workflow (as a non-publisher), where I don't install anything outside of F-Droid or Aurora Store anyways.

Keep in mind, it's still just a trial. And even if it goes worldwide in 2 years in 2027 (which is still a big if), it's still FAR more consumer-friendly than anything Apple has ever allowed on iOS in any jurisdiction I'm aware of.

cnst··on Apple's Assault on Standards
Google's support article is wrong/misleading. You can uninstall all app updates for Chrome. You can disable Chrome. Once disabled, it cannot run again, unless you expressly enable it. It's basically equivalent to an uninstall for most purposes.

The latest trend in OS design are an immutable system partition, so, obviously, you cannot modify the underlying system image, neither on macOS, nor iOS, nor Android, but what evidence do you have that doing an overlay disable isn't enough?

I've been using Android for years, and have not seen funny business after I disable Chrome. You can use Brave or Vivaldi or Yandex Browser or Opera in place of Chrome at all times. Or Firefox in many cases. I routinely have fully functioning test devices with stock Android without any Google Accounts or any Chrome. Everything just works the way it should. Including the banking apps installed through Aurora Store through F-Droid, as well as the streaming apps like Amazon Prime Video etc. Again, all of this works without a Google Account in any way on my side as an end-user, and it's expected to continue working even in 2027 even if the trial they've announced goes through worldwide. It works on any Pixel device, it works on any Motorola device, it even works on Samsung, too.

Page 1 of 26Next →