584 karma · joined November 5, 2015
Edit: oh, no, you have a point about the UI blocking stuff, it's fine when apps are loaded and active but "cold booting" a UI component definitely has lags in stupid places, android UX feels like a web perform sometimes due to that.... Tap button, go on holiday for a week, come back and it's responded to the button press (while you were trying to do something completely different and now you've pressed something else and you're not sure what because this time the button you pressed closed the activity overlay 1ms after)
if the name bothers, it can be forked. looking forward to "yCont" messenger!
But I get that "strength" is a poor metric. It shouldn't allow "weak" passwords. It should be binary - pass or fail.
The nicest thing about strength indicators - and I reckon this is why they are copied a lot - is that they are usually real-time feedback to the user with a nice red/orange/green invalid/weak/strong indicator that updates as the user types. The best ones even go as far as show you the list of rules your password is failing to meet, again updating as you type. Much much nicer than the server-side validation form submission loop imo.
So, remove the middle concept of "weak but allowed" passwords from the strength indicator widget, I think then you get good UX that meets NIST recommendations..?
Either they are confident that the 0.25mm terminal difference is within tolerance enough that they consider 12VHPWR to be functionally equivalent to 12V-2x6, or they're getting themselves confused let alone the target audience of their article.
The mobile hotspot thing... I have to do that to do anything involving Okta.
For some frustrating reason my IPv4 address, which I pay extra to my ISP to have, has been blocklisted by Okta. A login flow failure in one of the apps work uses triggered my address getting banned indefinitely is my best guess. My works Okta admins don't really understand how to unblock me on their Okta tenancy, and Okta support just directs me back to my local admins (even though it's any okta-using org I'm banned from logging into).
I get that misuse/abuse detection has to do its thing but it's so frustrating when there's basically zero way of a legitimate user from an IP of undoing a ban. My only recourse is to do all my using of okta from another IP.... If I was a legit spammer I wouldn't think twice about switching to another IP from my big pool, probably.
> Until you know more, strongly consider suggesting the company just hires someone who knows that. Just because you're available to do it, doesn't mean you should just yet.
This is a fair point. We'd always find it difficult to hire someone who was 100% specialising in software security / crypto etc, but a software eng who has some experience would probably be palatable... But funding for new hires could be a couple of years out. That, or we find a way to turn it into a research proposal we can sic a PhD on.
Still, I think it benefits us to have a strong baseline knowledge of crypto systems as a team, "bus factor" and all that. Maybe one day we have a colleague that can teach us that, but until then we may as well crack on with self-teaching :-)
(Not TFA, which was published Jan 31 - OP, who posted it this afternoon shortly after a talk which included the Byzantine Generals problem)
I'm like 18 lectures in, two out of three semesters. And I still feel like I have only the vaguest ideas what the primitives are, how they work, what they're for, and their weaknesses. I'm having to follow all the mathematics as someone not mathematically inclined (Prof Paar did do a good job of making the mathematics fairly accessible though).
All of this so I can have a bit more confidence in proposing E2E for a project at some point in future (before somebody asks us to, too late).
And my use-case makes it difficult to follow the most trodden paths so I can't just plug in a handshake protocol and MACs and elliptic curves or "just use PGP" or whatever.
As a software dev, I have all these boxes I could use, that come with so many caveats "if you do this, but don't do this, no do that, don't do that"... It's very tricky trying to work out how to glue the pieces together without already being in the field of crypto. Feels like I'll always be missing some crucial piece of information I'd get if I pored over hundreds of textbooks and papers but I don't have the resources to do so!
I'd love if someone did like, a plain English recipe book for cryptography! Give the mathematical proof of stuff, but also explain the strengths/weaknesses/possible attacks to laypeople without the prerequisite that you need to understand ring modulus or Galois fields or whatever first. Or, like, flowcharts to follow!
Any old cheap plug tied to Home Assistant (or plain old Google Home in my case) for auto powering on my Cambridge Audio amp. (I'm not fancy enough to care about automated input switching between TV and music, I just get up and turn the knob, but turning off the hifi remotely I like)
Music Assistant supports streaming to Chromecast from TIDAL at the native (24 bit, 96khz, flac/m4a?) format. And TIDAL mobile app itself supports casting to Chromecast devices as you'd expect.
Those 3 things combined got me an old school hifi set up which I can include in my Chromecast groups of shitty sounding second-hand nest minis, so I get multi room audio where one room has the most audio :-) but I could swap out the shitty pucks for some more CC audios if I wanted to fork out for more amps and bookshelf speakers.
I trust Google to at least not intentionally brick their old devices and chromecast is built on mDNS and documented http endpoints enough that you can automate your own stuff in your LAN that you should be able to keep that stuff working in home assistant + music assistant should Google ever decide randomly they wanna sunset Google home (so, 50% chance of them announcing that in 2025).
Homebrew you can roll your own DIY multi room hifi audio using stuff like Hifiberry, too. Pipewire/PulseAudio/JACK on raspberry pi / NUCs should be able to get you surround sound over the network with minimal latency (although you probably want decent ethernet), since you can make a virtual sink that bridges the audio servers together.
You have one of those fancy hifis that has hdmi inputs and digital input selection and whatnot? Okay yeah you'd have to roll your own HDMI CEC automation again with a raspberry pi or whatever. Eminently doable.
There's definitely ways to get multi room audio of equivalent or better quality and at-least-equal user experience as long as you're willing to invest the time in doing loads of DIY shenanigans, but honestly it's pretty easy these days. For me, I think the "this is too complicated for me to implement" bar is not high enough to warrant buying Sonos
(Tyres from Spaced)
Edit: ironically my post in this thread about how ads are partially enshittifying the internet, reads a bit like a sponsored endorsement for FF :-) ah well. It's still good.
> Not everyone can achieve this level of communication in a productive manner.
Correct, and it sucks. I feel like it's ableist at times too. 9-to-5 days of small-talk are so strangely exhausting t me. It's very frustrating I feel it's a mandatory part of my career if I don't want to be forgotten about.
But? I don't disagree with the author. In my interpretation, they aren't saying "I'm an extrovert and I'm great", they're saying "hey, this is a thing you can choose to do or be, and you may find it benefits you, and the introvert/extrovert thing is a stupid distinction, but being extrovert in the right way is a means of making yourself visible".
Because, let's face it, it is. There is some entrenched ableism, in a way. Last I checked like 10-20% of western population is some form of neurodiverse and a proportion of that just do not click with the predominant communication styles used by the majority population. It sucks and we are left feeling like we are not accommodated for and can easily fall into that exhausted feeling of resentment.
But? So what? You can help make things incrementally better for yourself in the system whilst still "playing the game", if you consider it as something you are choosing to expend your energy on.
You could also add a ping with a client-requestable interval, e.g. 30 seconds (for foreground app) and 5 minutes or never (for backgrounded app), so the TCP connection is less frequently going to cause wake events when the device is idle. As client, you can close and reopen your connection when you choose, if you think the TCP connection is dead on the other side or you want to reopen it with a new ping interval.
Tradeoff of `?lastEventId=` - your SSE serving thing needs to keep a bit of state, like having a circular buffer of up to X hours worth of events. Depending on what you're doing, that may scale badly - like if your SSE endpoint is multiple processes behind a round-robin load balancer... But that's a problem outside of whether you're choosing to use SSE, websockets or something else.
To be honest, if you're worrying about mobile drain, the most battery efficient thing I think anyone can do is admit defeat and use one of the vendor locked-in things like firebase (GCM?) or apple's equivalent notification things: they are using protocols which are more lightweight than HTTP (last I checked they use XMPP same as whatsapp?), can punch through firewalls fairly reliably, batch notifications from many apps together so as to not wake devices too regularly, etc etc...
Having every app keep their own individual connections open to receive live events from their own APIs sucks battery in general, regardless of SSE or websockets being used.
That... Doesn't feel like a problem to me? First music I remember "owning" as a kid was mix tapes I listened to on a portable radio. Later I grew up listening to crappy MP3 rips of albums on tinny earbuds. I got better headphones. Blasted the same albums on vinyl on big speakers. Listened to stuff compressed as hell over FM radio. Listened to albums in my car with an aftermarket subwoofer. Listened to FLAC rips of remastered albums. And yeah, a few Atmos albums on Tidal recently.
I can have listened to like 10 different iterations on the same one album and just enjoyed hearing the differences and the nuances of each medium or production version / remaster. You listen obsessively to one variant of an album enough to know every intimate detail, every imperceptible flaw in the recording, it becomes very familiar and then hearing new sounds in new variants is novel.
Edit: to give a concrete example: Pink Floyd albums. Listening to dark side of the moon, I equally have enjoyed the different warbly qualities of gradually degrading tape and vinyl, the tiny hiccups of slightly scratched CD, the squishy high frequencies of old MP3 rips, and just how clear everything sounds in hi-fi formats, and the atmos version. And like, listening to it over different generations of speakers and headphones etc. It's not an evolution or a progression; it's just hearing stuff different.
Don't trust private repos to be private!
Text selection and getting it to bring up a keyboard is iffy on the canvas-based things you linked to (I'm looking at them on Firefox for Android on a Pixel 6). Sure, the VB one is a desktop app. But the original (non canvas) version of that app likely worked with windows screen readers, and that is lost in this reincarnation onto the web. Good old fashioned DOM already has pretty good native accessibility support for mobile phone UI.
There's a lot of things that have been thought about when it comes to usability and accessibility, in both the web, and traditional desktop/mobile UI frameworks.
Reimplementing those UI frameworks in canvas in a browser environment requires mapping the a11y bits too, not just keyboard+mouse input and rendering to screen.
Not to mention Qt and Gtk and the older Android framework apps all use forms of markup and styling which are inspired by XHTML and CSS and document object models......
https://thwaitesglacier.org/projects/tarsan
On the AUV front, as well as multibeam from the Hugin, seafloor imagery has been mapped with an AUV named Rán.
I work alongside the team who build Autosub Long Range, who were there in 2022, taking physical/chemical/biological measurements (CTD, microstructure, turbulence):
https://noc.ac.uk/news/boaty-mcboatface-returns-thwaites-gla...
Underwater Gliders have also been deployed under or near the ice sheet to do similar:
https://www.sciencedirect.com/science/article/pii/S096706451...
The "AUV under ice" thing is a fascinating challenge to me. You have to rely a lot on different and novel navigation techniques (like terrain aided/bathymetric navigation and acoustic beacons). And you have to work out how to get your very very expensive robot not stuck under an ice sheet, when its default failsafe is to become positively buoyant, and its primary method of communication (satellite comms) requires a clear view of the sky :-)
The results of the work are.... sobering? Worrying? But I'm glad we're doing them.
There's a lot of other things which are very GPU parallelizable which just aren't being talked about because they're not part of the AI language model boom, but to pick a few I've seen in passing just from my (quite removed from AI) job:
- Ocean weather forecasting / modelling - Satellite imagery and remote sensing processing / pre-processing - Processing of spatial data from non-optical sensors (Lidar, sonar) - Hydrodynamic and aerodynamic turbulent flow simulation - Mechanical stress simulation
Loads of "embarrassingly parallel" stuff in the realms of industrial R&D are benefitting from the slow migration from traditional CPU-heavy compute clusters to ones with GPUs available, because even before the recent push to "decarbonise" HPC, people were seeing the increase in "work done per watt" type cost efficiency is beneficial.
Probably "relatively tiny" right now compared to the AI boom, but that stuff has been there for years and will continue to grow at a slow and steady pace, imo. Adoption of GPGPU for lots of things is probably being bolstered by the LLM bros now, to be honest.
CUDA benefits from being early to market in those areas. Mature tools, mature docs, lots of extra bolt-ons, organizational inertia "we already started this using CUDA", etc.
Who knows, maybe I dreamed it.
Nonetheless, I disabled IPv6 again and that, somehow, was the smoking gun that solved the "my phone always runs out of charge overnight when I stay connected to your wi-fi" problem.
Something to do with Router Advertisement intervals being too short, though I don't get why that only affects her ~5yo android phone. And IPv6 is so complex, I haven't figured out if the RA interval is something I can or should tweak, whether that comes from the PiHole or whether I'd have to flash OpenWRT on my router, or whether my ISP ultimately controls that upstream. Like, I can't figure out as easily where the boundary between me and "the internet" ends with things like the /64 prefixes and SLAAC and RDNSS and all the other acronyms.
Yeah, yeah, I should RTFM, and eventually I might figure out what makes a "good" home IPv6 network. But I can't be arsed to do that in my free time yet, and neither can most software companies cough cough Google/Android and that one guy causing IPv6 drama in the android team
Like.... Ehhh... I'll come back to it in a few more years. "Are we IPv6 yet?"