HNHacker News
TopNewBestAskShowJobs

fulldecent2

199 karma · joined February 4, 2019

submissionscomments
fulldecent2··on A radio frequency exposure test finds an iPhone 11 Pro exceeds the FCC's limit
I'm following along in this thread here and double checking everybody's math.

So... does this mean I will die from radiation or not?

fulldecent2··on US says it can prove Huawei has backdoor access to mobile-phone networks
Original source.

Will somebody with access to WSJ please corroborate this quote in OP which is attributed to WSJ?

> Telecom-equipment makers who sell products to carriers "are required by law to build into their hardware ways for authorities to access the networks for lawful purposes," but they "are also required to build equipment in such a way that the manufacturer can't get access without the consent of the network operator," the Journal wrote.

fulldecent2··on Microsoft begins showing an anti-Firefox ad in the Windows 10 start menu
You can't delete Apple's Music app in the same simple way that you can delete the Spotify music app.

Same thing. Abuse of monopoly.

fulldecent2··on Ask HN: What are good solo developer blogs that you enjoy reading?
Here is my list of solo developer blogs. Usually they are on topic. This does not include personal blogs I follow that happen to be developers.

@mdo (Bootstrop) - http://markdotto.com/

Keith Cirkel - https://www.keithcirkel.co.uk/

Coding – Corbin's Treehouse - https://www.corbinstreehouse.com/blog

Aaditya Purani – Ethical Hacker - https://aadityapurani.com/

Ben Balter - http://ben.balter.com/

fulldecent - https://privacylog.blogspot.com

Orange - http://blog.orange.tw/

Cocoa with Love - http://www.cocoawithlove.com/

Mark Otto - http://markdotto.com/

Moxie Marlinspike's Blog - http://www.thoughtcrime.org/blog/

hueniverse - http://hueniverse.com/

fulldecent2··on macOS Kernel Extensions are officially deprecated
How do people feel about Apple making these kinds of deals with Panic and others?
fulldecent2··on Honk more, wait more: Mumbai traffic police introduce the ‘punishing signal’
Parabolic dish from hotel room directly to sound sensor will DOS the intersection. And be difficult to detect.
fulldecent2··on Disk Prices on Amazon
The solution is Amazon Transparency. This is offered through their Brand Services division.

And the solution for the whole industry is the same thing with some distributed ledger or some very light centralized authority (like MAC or UPC vendor assignments) plus vendor-specific databases.

fulldecent2··on The iPad Awkwardly Turns 10
The main design theory of Apple is simple: come up with a great usability feature and deploy it on one model. Then spend the next 5 to 10 years spreading this out to their other models. When people stop buying, just swap in a higher specced component from Intel and talk about how it is 2x faster.
fulldecent2··on New coronavirus can spread between humans, but started in a wildlife market
The official name for this is 2019-nCoV.

And for Twitter that is #2019nCoV.

Using the correct name (or including it in parenthesis somewhere) is a way to help your publications stay connected to the wider discussion.

fulldecent2··on Google backtracks on search results design
You think that's bad, see AMP
fulldecent2··on What happened to Mint?
The addressable market for Mint is people that want to track their budget. They maxed out. Their only revenue model is giving you leads for credit cards based on broad categories.

---

With a little more data it would be amazing. Just forward your Gmail to it and it would line up all your receipts with all your credit card purchases. Now its revenue model is Honey and giving you targeted adds for competitors to specific SKUs it knows you are buying.

---

Who would be dumb enough to give all their emails to this type of company? I don't know, but there are piles of people that give out their bank passwords to "validate their accounts" with Plaid. So maybe it is not too low.

fulldecent2··on Wine 5.0
I just checked out Bitwig. Apparently it is a for-money app which is not available in the Mac App Store.

So far, every not-free-open-source app I have seen which is not on the Mac App Store has caused problems:

- Spotify: does weird things to start at login and hide it from your system's start-at-login settings - Dropbox: phishes you to get your root password - Panic Transmit and Coda: exfiltrates your ~/.ssh/id_rsa file while not clearly documenting this

For 399 USD, I had hoped Bitwig could manage to get its app set up with sandboxing and into the store.

fulldecent2··on Apple dropped plan for encrypting backups after FBI complained
Was this previously called iFunBox or something else?
fulldecent2··on Apple dropped plan for encrypting backups after FBI complained
Even if you want nothing to do with iCould, you must still enable it for these features:

- Mac-to-Mac copy/paste (shared clipboard, continuity) - iPad sidecar

Once you enable it, it immediately begins uploading your contacts, photos and passwords to Apple. Then you need to disable those specific things. Even after you delete those things, every app on your phone can silently and without your explicit permission, start loading data into iCloud.

fulldecent2··on Apple dropped plan for encrypting backups after FBI complained
"Encrypted" is a weasel word. There are many examples of "it's encrypted" even when encrypted refers to 8192-bit keys, where the system is not secure. Examples abound.

So claims of "encryption" are meaningless.

Instead, claims of "only X, Y and Z could access to this" are meaningful.

"Could" is a strong word because it includes unforeseen circumstances such as writs and court orders.

fulldecent2··on Apple dropped plan for encrypting backups after FBI complained
Who cares about this?

Yes, Apple has private APIs that it uses for its monopoly abuse benefit. That is why Apple's "Music" app can't be deleted from your computer ("'Music.app' can’t be modified or deleted because it’s required by macOS.") but Spotify can be deleted.

The solution is for Spotify to sue them on this specific issue and for other people to sue them similarly.

fulldecent2··on Apple dropped plan for encrypting backups after FBI complained
The small bit of iCloud E2EE which Apple allows (for health data, passwords and Mac-to-Mac clipboard sharing) is using your iPhone's 6-digit passcode and your Mac's admin password.

That means that Apple can also now perform an offline brute-force attack against your file vault password.

This makes even your offline devices less secure.

fulldecent2··on Why build this blog, or anything, on IPFS?
The long-term solution for web is:

- Use more static HTML - Since your assets are versioned and static, start calculating hashes for everything you publish - When you link to something, include the URL and the integrity <a href="URL" integrity="sha256:...">...</a>

In the immediate future this will fix broken links. Things that are important will be cached and accessible via content addressing. In the long-term future this will fix other problems like linking to a page and then it being changed to something you don't endorse.

fulldecent2··on What DoorDash pays, after expenses, and what’s happening with tips
Regarding IRS Standard Mileage Rates.

There are different costs to insure a vehicle based on whether it is "personal" use or "business" use. The IRS rate does not distinguish these. Is there any documentation on which scenario IRS is assuming this applies to?

fulldecent2··on What DoorDash pays, after expenses, and what’s happening with tips
How can companies be incentivized to WANT to hire employees rather than having contractors be the default choice?
fulldecent2··on Show HN: ESQLate – Build minimum viable admin panels with just SQL
Metabase?
fulldecent2··on Visa Buys Plaid
2D chess is actually quite complicated.

Buying a company to get its most valuable assets is less complicated than that.

fulldecent2··on Visa Buys Plaid
Simple. Just imagine that everybody is incredibly stupid and wants to be robbed and have their identity stolen. That's the target market.
fulldecent2··on Visa Buys Plaid
Worst of all, is their privacy policy.

> We retain information we collect about you for as long as necessary to fulfill the purposes for which we collected it, unless a longer retention period is required OR PERMITTED under applicable law.

It is not necessary to "hack" Plaid.

fulldecent2··on Visa Buys Plaid
No issues with customers linking Plaid.

If your company is ONLY supporting Plaid then your issue is that your smarter customers are leaving.

fulldecent2··on Visa Buys Plaid
I support this big time.

Plaid is a complete joke -- "give us your bank passwords and we'll validate your account". Banks are an even worse joke -- "20,000 logins today from one IP address, nope that's not a scam".

Plaid customers are the worst. Like Transferwise, you cannot setup a business account with them without giving Plaid your business banking passwords. What company treasurer would allow that?

Now that Visa is holding the bag this fixes two problems:

1. For customers, there is less risk that Visa will steal all your money than some "fintech" startup 2. For Plaid customers, they may realize Visa is buying this for the data and they may think of Visa as a competitor and not want to support them.

---

Because "just give us your sudo password to install software" and "just give us your bank password" to send money is a thing... the obvious dumber people in the future will have to do "just sign this power of attorney to create an account with us."

fulldecent2··on The Second SHA-1 Hash Collision
Now 1000x smaller than the original Shattered attack from Google! And 1000000x less expensive!!! Buy now
fulldecent2··on ProtonMail takes aim at Google with an encrypted calendar
Sure you can. Apple does not run its image classification on your images using its cloud servers. You can test this by stepping inside a microwave or other cage and seeing that image classification and search still works on the iPhone.

---

On the other hand, what Apple does with your photos that you allow to be exfiltrated through iCloud... that's your own stupid fault.

fulldecent2··on Encoding your WiFi access point password into a QR code
Which devices support this?
fulldecent2··on Encoding your WiFi access point password into a QR code
When I see it spelled wrong (like in the title of the OP here) my mind pronounces it "whiffy"
← PreviousPage 3 of 5Next →