HNHacker News
TopNewBestAskShowJobs

ehhthing

421 karma · joined February 26, 2022

submissionscomments
ehhthing··on Griffin – A fully-regulated, API-driven bank, with Clojure
This is true for basically everything powered by an API.

I mean if you want to start your own bank and deal with compliance then sure do that! I don't see your point here, there is no sensible alternative to this problem.

ehhthing··on ISPs should not police online speech no matter how awful it is
I don't think this is true. Phone companies (which are legislated to be utilities) can block malicious/spam calls without legal issues.
ehhthing··on ISPs should not police online speech no matter how awful it is
I'm not entirely sure about this but I believe that HE may have been null routing rather than just dropping routes.
ehhthing··on Griffin – A fully-regulated, API-driven bank, with Clojure
I'm confused by this statement. fintechs aren't just proxies for banks, they're financial products that people want to use. There are plenty of cool and innovative things you can do with just a banking API beyond just creating another bank

Sure the costs for any fintech using these products are the same, but they can offer a million different types of products which make them unique.

ehhthing··on Speed Test
> then that puts cloudflare in a very strong negotiating position for peering agreements etc.

Ideally settlement peering would exist for everyone. Cloudflare, like every other sane provider prefers IX routes over PNI since it's less expensive for everyone involved. There really shouldn't be a discussion about whether peering should be settlement free or not.

ehhthing··on Speed Test
Netflix and Google both have servers colocated within ISPs' networks so this is probably why. Also SEA is a routing cesspool, many providers don't do settlement free peering and actively throttle IX routes, which is probably why your Internet was so slow.
ehhthing··on Tunnel Vision: CloudflareD AbuseD in the Wild
I don't understand why this is news for anybody. This is just the cloudflare version of ngrok...
ehhthing··on Microsoft Owns the Trademark for “X”
Not talking about Meta's X, talking about Microsoft's X
ehhthing··on Apple already shipped attestation on the web, and we barely noticed
Also Google Trust Services has free certificates although you need a Google Cloud project for it.
ehhthing··on Apple already shipped attestation on the web, and we barely noticed
> If no company running a CA will give you a cert you'll simply be unvisitable (on HTTP/3).

This isn't technically correct. I believe on the security warning page you can type "thisisunsafe" (just blindly do it) and it'll let you through.

At the very least this works for bypassing HSTS.

ehhthing··on Microsoft Owns the Trademark for “X”
https://trademarkgarden.com/2018/03/09/amazon-and-you/

The two are equivalent.

ehhthing··on Microsoft Owns the Trademark for “X”
They owned the trademark for X scoped to banking and financial services. Meta owns the trademark scoped to social media.
ehhthing··on How the great firewall of China detects and blocks fully encrypted traffic [pdf]
Assuming what you mean is over mobile data (and not over wifi), mobile data works differently than typical internet. You can think of it like when you connect to a mobile network what you're actually doing is making an IPsec connection to your carrier, with all data flowing over that IPsec connection. As such any carrier with a roaming agreement in China will bypass the GFW entirely -- and this is by design, Chinese carriers have to whitelist the APNs of western companies they do business with.
ehhthing··on How the great firewall of China detects and blocks fully encrypted traffic [pdf]
GFW only looks at connections with destination IPs outside of China, the private fibre line bypasses it entirely.
ehhthing··on We can ID people from DNA that shows up in environmental studies
We're a small step right now from the police getting access to genetic databases like 23andMe, so if anyone in your family tree has gotten a genetic test it may be possible for them to identify you based on ancestry.
ehhthing··on Google will add E2E encryption to Authenticator backups
Yes, this is an option (that you definitely should turn on).

I think Google shipped another underbaked product here. They have E2EE implemented for Chrome sync data already. They should have just used that rather than going with whatever system they decided. Adding Google Authenticator to the Chrome Password Manager is probably much more useful than having it as a standalone app.

ehhthing··on Go port of SQLite without CGo
Beware: This library seems to have bugs that cause it to break on some writes. Recently held an event that heavily used this library and it broke on us half way through, had to wipe the database and switch it back to the cgo version (the data inside was mostly ephemeral, which was quite a relief).
ehhthing··on The TikTok ban is a betrayal of the open internet
Funnily enough, spinning a cloud VM is quite easy actually. You can do it in seconds on Alibaba Cloud. Getting port 80 unblocked on the other hand...

Arguing that the relationship is inherently completely asymmetric isn't really true either. Chinese companies can't really just create a single website that serves both western and Chinese customers. While nothing legally is stopping them, doing this is just going give your western customers a bad time overall, since content delivery across the Chinese border is all but impossible at any reasonable speed. TikTok is an American company, fully owned by Bytedance yes, but they went through incorporating in America and complying with all local laws to do so.

How many Chinese made websites do you use? Unless you're a Chinese immigrant, TikTok is almost certainly the only one. You might use e-commerce websites like AliExpress, but, again, AliExpress is a specially made website that was designed to follow foreign regulation. Chinese companies don't generally operate in other countries. The only reason TikTok is so popular is because they bought their way into the western market with millions of dollars with the acquisition of musical.ly. You have not shown any empirical evidence of any Chinese tech company actually being successful in the west, that hasn't just bought out some American competitor.

Also, nothing is requiring you to setup servers in China to serve your Chinese audience, and in fact it's almost certainly much more expensive to do that, not just for an ICP license but for bandwidth as well. You can serve your Chinese audience well with servers in Japan, Korea, Hong Kong (for now), or other East Asian countries and as long as you follow Chinese laws, the GFW won't block you.

Sure, following Chinese laws is hard and goes against a lot of free speech principles, but at the end of the day the laws are enforced reasonably uniformly. Banning TikTok or Chinese companies in general just shows that Americans can't handle foreign competition. Instead I believe that a better solution would be to simply create uniformly enforced laws that create federal data processing regulation ... like Europe has already done with the GDPR ...

ehhthing··on The TikTok ban is a betrayal of the open internet
I'm sorry, but what? You haven't cited anything that shows China cares about using TikTok as a means of influencing foreign countries? You're just spouting rhetoric that is made to fearmonger.

China bans western websites because they don't follow China's censorship requirements. Apple services exist in China, why isn't Apple a national security threat? They're the richest tech company on the planet, and based in the US.

ehhthing··on FDIC Takes over Silicon Valley Bank
Except in this case, when SVB fails their customers will get the vast majority of their money back as the FDIC liquidates all of SVB's assets. When FTX fell, nobody got squat.
ehhthing··on Google Fi seemingly affected by latest T-Mobile data breach
VPNs still have massive problems with network diversity. They often rely on a tiny subset of transit providers, usually just Cogent/HE/Telia and some straight up all run on the same network, usually M247. While a carrier like Comcast has thousands of peering agreements and much more diverse routing. This means all traffic coming out of a VPN is viewable by a tiny group of network providers.

Sure, I would probably trust Cogent over Comcast, but the current state of the VPN market seems very stagnant in actually diverse network routing.

It's really hard to recommend a VPN for people who are actually privacy conscious simply because you're moving your data to a handful of transit providers that aren't put under nearly as much scrutiny as a normal consumer ISP.

ehhthing··on Rails on Docker
For what it's worth, the vast majority of vulns in a web app are in its code or dependencies rather than in the base OS. I haven't actually seen any real-world cases of getting hacked because your docker base OS image was out of date. The only exception I would give would be for like language runtime version, which can occasionally be an attack vector. Switching runtime version usually requires manual testing regardless, so I wouldn't really consider it a docker-only problem.

If you're really concerned, just have a CI job that rebuilds and tests with newer base image versions.

ehhthing··on Hackers demand $10M from Riot Games to stop leak of ‘League of Legends’ code
You're quoting something from Valorant, not League of Legends. They use two different anti-cheat systems.

As a person who actually plays the game on a M1 Pro MacBook running in x86 emulation, which is not supported by kernel mode drivers, I can tell you with absolute certainty (unless of course Riot has found an exploit that allows installation of unsigned system drivers), that my computer has no non-apple drivers installed.

ehhthing··on Hackers demand $10M from Riot Games to stop leak of ‘League of Legends’ code
League of Legends does not use a Kernel-level anti-cheat. If you had actually read the article in question, this would have been made clear.
ehhthing··on Websites selling abortion pills are sharing sensitive data with Google
Shouldn't this be a discussion about how law enforcement search powers are getting out of control, then?
ehhthing··on [dead]
Your clickbait title doesn't match up with what you're saying.

> So why fool around pretending to maintain it? All they do is merge drivers.

Why aren't they maintaining it? All they're doing is maintaining it!

ehhthing··on Seattle Public Schools sues TikTok, YouTube, Instagram over youth mental health
I assumed this lawsuit was a negligence one. It's not, it's under public nuisance laws. I still don't understand how the school board should get damages paid given they aren't "the public", and they didn't have any of their rights violated.

> Those aren't analogous companies at all. Social media companies don't just deliver content, they promote specific content and optimize thier platforms to increase engagement.

A school investigates all threats equally regardless of how they are communicated. Whether they are mailed, sent via SMS, called in or sent on social media should not matter.

ehhthing··on Seattle Public Schools sues TikTok, YouTube, Instagram over youth mental health
I am not a lawyer, but this seems like the school board have no standing (in the legal sense) to be filing this lawsuit. I do not believe that social media companies have the duty of care to the school boards to maintain kids' mental health.

Some of the things in the lawsuit are just stupid like arguing that social media causes them to need to do investigations into threats and such. You wouldn't be suing the USPS or AT&T for allowing the same thing, would you? Sure these aren't the same thing as social media, but whether a duty of care exists should be a relatively similar analysis.

ehhthing··on Leaked Slack all-hands meeting reveals a ‘strong culture clash’ with Salesforce
This isn't entirely true. Even at the most surface level, "buying" a company can mean almost a dozen things.

For example, a holding company can buy your company and do ... absolutely nothing, just treating it as an investment. This happens a lot too. Off the top of my head, AMC was once owned by Wanda Group based out of Dalian, Liaoning, China. Yet I'm sure that nobody who worked for AMC could tell, or even knew this was the case.

ehhthing··on Apple Lightning (2020)
iPad Pros also use USB C, so they already have the requite support on the portable electronics side. Right now it seems mostly a transition for the phone accessories.

Personally, I think apple has wanted to switch to USB-C for a while on iPhone. They waited until the EU actually passed legislation so they could find a person to point fingers at when their customers complained about accessories breaking compatibility.

← PreviousPage 3 of 4Next →