HNHacker News
TopNewBestAskShowJobs

ehhthing

421 karma · joined February 26, 2022

submissionscomments
ehhthing··on Roblox Accused of Concocting Illegal Gambling Ring for Minors
I don't play Roblox, but I'm aware of their history of exploiting children.

Based on my preliminary research it appears as if these websites actually just ask you for either your Roblox username/password or ask you for your Roblox cookie to authenticate.

I really doubt they would actually be apathetic to removing these, since even though they do get richer off of it... If discovery finds evidence they're trying to cover this up the damages will be endless...

ehhthing··on Google ordered to identify who watched certain YouTube videos
You're delusional if you think the landscape 10 years ago is the same now. Companies are much less likely to simply capitulate to governments now. In fact, the references you make here are why they're less likely to allow these kinds of things.

It looks really bad for them, and it affects their bottom line when these things come out. When public trust in your service is crucial to its existence, you can spend more on lawyers to fight the government about it.

ehhthing··on Google ordered to identify who watched certain YouTube videos
This is your choice obviously, you get to choose how much data you give to them. You can also choose not to give any data at all if you wish.
ehhthing··on Cloud Egress Costs
If you're on GCP because you want v6 support you're probably in the wrong place :^)
ehhthing··on Cloud Egress Costs
> It is very simple. If you move your data off cloud provider X, cloud provider X is losing revenue because you are doing things with your data off their platform.

Right but if this were the case then why does the Bandwidth Alliance allow you to move data at a much lower cost for 2/3 of the major cloud providers? If they _really_ cared so much about not allowing you to do processing with a third party, the Bandwidth Alliance wouldn't exist!

AWS is the sole hold-out here, and I think the way that Cloudflare worded this makes it pretty clear that the Bandwidth Alliance is basically a middle finger to AWS than anything else, but it also seems clear that the cloud companies aren't actively trying to make it costly to do data processing on a third party.

In fact if you want to move off GCP right now, Google will waive all egress fees to do so: https://cloud.google.com/blog/products/networking/eliminatin...

ehhthing··on Cloud Egress Costs
> That isn't how business works. Companies maximize their profits and "balance" isn't a profit center. If it didn't benefit them in some customer leveraging way, they would charge for ingress.

What I'm referring to is the practice of balancing peering ratios. That is, when you make transit/peering arrangements with other ISPs, some ISPs will charge more if the amount of data you're sending to them vs the amount of data you're receiving from them is not balanced. It is in Google's best financial interest to at least try to balance their pipes in this way.

ehhthing··on Cloud Egress Costs
This is also a fair take, but not a very compelling reason why bandwidth costs are vendor lock in...
ehhthing··on Cloud Egress Costs
> Some cloud providers charge nothing, others only start charging after hitting a high threshold from a single instance. Do they not operate infrastructure?

Yes you do pay for the rest of their infrastructure when you rent servers from them...

I'm not saying that the fees aren't extremely overpriced. I know what a gigabit port costs. But saying it's to keep vendor locking is just not true, and nobody has suggested any actual proof of it being true.

ehhthing··on Cloud Egress Costs
Ingress is free because it helps them balance their pipes, and it would be really shitty to charge for DDoS attacks. As far as I can tell, with the exception of some really expensive network environments (e.g. China), nobody has ever charged for ingress.

With an exception to OVH, none of the cheap providers the article has listed have any kind of backbone network. They all rely fully on transit providers. Turns out backbone networks are expensive to operate!

OVH is the sole example of a provider that has a backbone network, and admittedly, it's pretty good. However, nowhere near expansive as the big three, and it falls flat in Asia (which is the hardest to route traffic in). Also OVH has to build datacenters so cheaply that one of them burnt to the ground in recent years...

(Cloudflare has a backbone too, but you have to pay a lot extra to use it. Linode uses the Akamai backbone now but that's a very recent acquisition and it's expected that Akamai will eventually raise costs significantly)

Yes, bandwidth is way too expensive on cloud providers. AWS Lightsail is proof of that. However, I see no reason to believe that this is purely for vendor locking, and nobody has been able to give any evidence of causation between the two beyond "well it's so expensive!!!"

ehhthing··on Cloud Egress Costs
> They charge an arm and a leg because they want to keep you and your data on their platform. When you move it you are breaking free.

This isn't remotely true.

The bandwidth alliance exists, and a lot of cloud companies are on the list: https://www.cloudflare.com/en-gb/bandwidth-alliance/

The actual answer is much more complicated. For example, Google Cloud offers two different bandwidth tiers: premium and standard. The calculation on the OP assumes premium since that's the default option, but obviously it's much more expensive.

Google cloud's "premium" bandwidth is much akin to AWS Global Accelerator since it utilizes Google's own backbone network for as long as possible before exiting at the nearest peering point between Google and whatever ISP your end user is at. AWS Global Accelerator has some other options available, that make it fundamentally a different product, but the routing characteristics are much more similar to GCP Premium bandwidth than anything else AWS offers.

ehhthing··on Deno in 2023
Deno wasn't originally designed to be node compatible, but I think they realized nobody would want to switch to it because node is so prevalent already...
ehhthing··on Don't use NameCheap for the .fr TLD
CloudFlare domains is a bit of an underbaked product, it's not bad but you should be aware that you cannot change your root nameservers . They must be CloudFlare. The only way to change them is to switch registrars.
ehhthing··on Attack of the Week: Airdrop Tracing
UU Booster, which is the service I currently use for gaming is operated by NetEase, which is a giant in the Chinese online gaming space. It's fully legal, no issues whatsoever.

Also you can get roaming SIM cards or even eSIMs, which connect to APNs overseas.

You can also get Alibaba Cloud private networking connection between a region inside of China and a region outside. They use private lines so there's no GFW involved. My understanding is that you need an international real name verified account to do this, but after that you basically have an uncensored line that's also much more stable than connections that have to go through the GFW. I know of a US company that uses this to connect their Chinese workers to their central office, and again it's fully legal once you get an ICP license.

ehhthing··on [dead]
I was searching mostly under the News section of google although this seems to just be a Tiktok feature "restricted mode" that Tiktok may have accidentally enabled for some users?

Regardless the article is pretty misleading...

ehhthing··on [dead]
I'm sorry but this article is BS and it's associated "source" seems to be a SEO stuffing website and smells very much like it was written by AI.

Is there any actual evidence that this is happening? This NYPost article and their "source" material seems to be the only things that reference such a practice.

ehhthing··on When a postdoc in my lab committed fraud, I had to face my own culpability
Don't you think its funny that we pay academics a fraction of how much we pay tech workers and yet we expect so much more from them?
ehhthing··on When a postdoc in my lab committed fraud, I had to face my own culpability
Nobody wants to assume fraud in science, unless you have unassailable evidence that someone has committed fraud you really cannot risk your own reputation by dishing out allegations. The solution to this is trust but verify, but verifying data would require twice the amount of work, which not every lab has the funding to do, even if it was breakthrough research.

The sad truth about a lot of science is that science is built on trust. The psychology replication crisis is proof of that, there are so many ways to manipulate data to make it look like you have a result and also so much pressure to get a result that people resort to the former to get the latter.

There are plenty of historical scandals about how scientific fraud has taken way too long to investigate, people like Victor Ninov and Hwang Woo-Suk are two examples of just how far fraud can go before it's found.

The article here is comparatively tame compared to how far Huang and Ninov got.

ehhthing··on Flare, a video sharing site built on Nostr
The internet isn't really decentralized and realistically it cannot be.

Submarine cables are owned by companies, T1 ISPs provide the majority of routing and you really cannot prevent any of this.

Centralized control is somewhat required because submarine cables cost money and transit costs money and small companies simply do not have the capital to do that.

ehhthing··on An Empirical Study and Evaluation of Modern CAPTCHAs
Theoretically you don't need to reveal your identity to prove that you're human. You can use a zero knowledge proof instead, likely attached to something like an EU Digital ID, which would allow you to remain anonymous and also prove that you're human.
ehhthing··on A decade of Have I Been Pwned
I can't tell whether this is a joke or not.

I would bet you that over 99.99 percent of HIBP's users do not pay for the service. Troy's time has value, so working on a service that provides no income is not really something you can expect a person to do. Troy decided to create an enterprise subscription service to get a bit of revenue from something he's created. It's not cheap, but it's not something you're meant to buy unless you're a company looking to monitor your employee email addresses. This service is pretty cheap in that regard, actually.

I really do not understand why you feel that you're being ripped off here. This is just a lack of product-user fit, his pricing structure simply doesn't work for you because you use email canaries. But for a company with 100 people, this pricing is entirely reasonable, if not something incredibly cheap.

What you're paying for is everyone who doesn't pay for the service, the time he takes to add new breaches to the service and the time he takes to develop the service.

Just because their pricing model doesn't fit you doesn't mean it's a cash grab. Is this too hard to understand?

EDIT: Also, I assumed this was a common understanding, but product pricing is based on the value it gives to the person buying. For a company of 100 people, do you think paying $160/yr is worth breach monitoring? I think for any IT department, this would be a no-brainer.

ehhthing··on Signal says there is no evidence rumored zero-day bug is real
Sounds like a version of the WebP bug that abuses link previews to display the image maybe?
ehhthing··on Apple Bricked my AirPods and now wants me to buy new ones
Did you gasp go to the apple store and tell them what happened?

Seems like you should do that before complaining on Twitter. Mistakes happen, it's about how they handle them that matters.

ehhthing··on Hired by Google as L4 but rejected by top colleges
So having applied to Google multiple times on different referrals and gotten exactly 0 interviews, I can say that it probably doesn't affect your application to have "connections" nearly as much as you'd think. In any case, he did competitive programming on the side and he was certainly very good at it, which makes the interview portion trivial to pass.

> Moreover, some have pointed out that the Stanley Zhong's primary background in the case was founding a startup that utilized services from a major tech company, like Amazon Web Services (AWS). This situation has led to discussions about the potential overlap between the teenager's career development and the parent's professional connections, as Nan Zhong happens to be previously software engineer manager at AWS.

This is BS. Every web app runs on some cloud infrastructure (or I guess on-prem is an option if you have a lot of money), but as a high school student your budget will be determined based on how much free credit you'll get. Google Cloud and AWS both have generous amounts of free credits for startups, so realistically these were the two best options. I think it's slightly easier to get AWS credits than Google, but regardless, they're pretty easy to get (I have a friend who has gotten tens of thousands of dollars worth of free credits for simply having registered an LLC and getting a Mercury account).

ehhthing··on Privacy washing: Google claims to support privacy while lobbying against it
But I'm not a judge and this isn't court.

The adversarial system has a time and a place, but in this case it's not like Google ever publishes blog posts on why ProtonMail may or may not be bad, and it would be quite impossible for them to debunk every accusation against them.

This isn't the adversarial system as much as it is just one company making marketing material for themselves by attacking another company.

ehhthing··on Privacy washing: Google claims to support privacy while lobbying against it
Regardless of who wrote this, I find it hard to trust an article written by a direct competitor to the company being scrutinized -- there is a clear conflict of interest here.
ehhthing··on We have successfully completed our migration to RAM-only VPN infrastructure
You know at that point why not just hack Level3, Cogent, Telia, Zayo or some other T1 provider?

Frankly VPNs don't protect you from anything other than the most monitoring systems and the occasional public wifi connection. They're really just glorified Netflix region proxies and nothing more to most people

ehhthing··on I Tracked an NYC Subway Rider's Movements with an MTA ‘Feature’
Sorry I'm not American, I don't just hand my card to random strangers. Kinda forgot that was a thing at restaurants there.

My perspective comes purely from a person that exclusively uses Google Pay and occasionally Chip + PIN when my purchases go over the limit for that.

ehhthing··on I Tracked an NYC Subway Rider's Movements with an MTA ‘Feature’
I'm confused, these are completely different situations. But also, yes?

If a random stranger has my credit card info, I feel like I have much bigger problems than people knowing my Amazon purchase history.

ehhthing··on I Tracked an NYC Subway Rider's Movements with an MTA ‘Feature’
I think the issue has been rather overblown. Realistically I think the solution to this problem is to make riders more aware of the existence of this website, so if they feel that they may be tracked by an abusive partner they'll know how it's happening.

It is not a security issue in itself.

ehhthing··on Film Review: BlackBerry
Definitely the best Canadian movie I've seen. Hits close to home as a UWaterloo student.
← PreviousPage 2 of 4Next →