HNHacker News
TopNewBestAskShowJobs

fweespee_ch

607 karma · joined March 8, 2016

submissionscomments
fweespee_ch··on The Burden of Policing Walmart
> What, exactly, should Walmart's response to shoplifting be? The article seems to make a point of the low dollar-value of some of the items stolen vs. how much the police spend arresting the subjects. I fail to see why the value of the stolen goods matters from a illegality perspective; it's not like Walmart can punish the shoplifters themselves.

Honestly, shoplifting and other small scale financial crime committed by individuals who are not conspiring, should be largely considered in financial terms.

fweespee_ch··on Venture capitalist says a $28 minimum wage would create a more robust economy
This is sadly one of those situations where the guy's heart is in the right place but he is simply wrong on the number.

$11-15[1] by 2020 is a reasonable national range for a minimum wage with certain states/localities raising it higher. The simple fact is, the peach picker in rural Georgia has a lower cost of living than the Subway "sandwhich artist" in NYC.

[1] 2016 Dollars, permanently adjusting for inflation against 2016 USD indefinitely. This whole "random correct every so often" is simply disruptive to both businesses and workers since it makes projection difficult compared to small, annual raises linked to inflation.

fweespee_ch··on Microsoft no longer allows admins to block Windows Store access in Win10 Pro
> Microsoft has retroactively removed the ability of companies to turn off access to the Windows Store in its Windows 10 Pro version.

Yes but by "upsell" you mean "extort by way of feature removal after the product was purchased".

fweespee_ch··on Google AI has access to huge haul of NHS patient data
> It's trivially easy for Google to do this already without the NHS data, and they don't face prison time for doing it. See all the pregnant teens outed by supermarket loyalty cards for other examples.

And how many members of the general population do you think are aware of this?

> I understand "the" NHS is complex, but it's pretty frustrating talking to someone who has very strong opinions and who clearly doesn't know what they're talking about.

It probably has something to do with the fact you are completely missing the point I'm discussing rather than the strength of my opinions.

fweespee_ch··on Two-factor paper passwords
Well, they'd also need the codebook where you store the passphrase to get the other half of the password.

So if you change the master password regularly, they'd need to hack a database in that time window and steal your codebook. I highly doubt anyone would put that level of effort in.

fweespee_ch··on Google AI has access to huge haul of NHS patient data
1) I have a disagreement with bait and switch data privacy laws that are publicly sold as anonymous when everyone can tell from the implementation details that they are not.

2) You asked why they were astonished. Well, #1 is why. Most people don't have the time/energy/desire to study the implementation details on every facet of their lives.

fweespee_ch··on Google AI has access to huge haul of NHS patient data
Its psuedononymous data the NHS has previously admitted can be deanonymized given sufficient effort but such deanonymization carries criminal and civil penalties.
fweespee_ch··on Google AI has access to huge haul of NHS patient data
http://www.bbc.com/news/uk-16021240

> "All necessary safeguards would be in place to ensure protection of patients' details - the data will be anonymised and the process will be carefully and robustly regulated.

> "Proper regulation and essential safeguards need to be in place when it comes to patients data," he said. "It cannot be done in a way where essential rules are threatened."

The legality of these data sharing laws start off with public promises of anonymization, robust regulation, safeguards, and privacy.

https://www.england.nhs.uk/2014/01/geraint-lewis/

> Amber data are where we remove each patient’s identifiers (their date of birth, postcode, and so on) and replace them with a meaningless pseudonym that bears no relationship to their “real world” identity. Amber data are essential for tracking how individuals interact with the different parts of the NHS and social care over time. For example, using amber data we can see how the NHS cares for cohorts of patients who are admitted repeatedly to hospital but who seldom visit their GP. In theory, a determined analyst could attempt to re-identify individuals within amber data by linking them to other data sets. For this reason, we never publish amber data. Instead, amber data are only made available under a legal contract to approved analysts for approved purposes. The contract stipulates how the data must be stored and protected, and how the data must be destroyed afterwards. Any attempt to re-identify an individual is strictly prohibited and there is a range of criminal and civil penalties for any infringements.

The problem with psuedonymous data is the NHS basically admits it can be used to identify people given sufficient effort.

---

That is why people are "astonished" by these decisions. The politician provides the initial promises that imply anonymity, the implementation doesn't provide true anonymity but provides criminal penalties for pulling off the mask, and then the data is handed to enough 3rd parties if such data is leaked its likely impossible to know by whom unless the data was tampered with to provide a per-contract identifier.

I understand this specific decision did not involve a politician but the conversation was why people are surprised. How many people do you think really know the anonymity originally promised became a permeable pseudonym?

fweespee_ch··on Google AI has access to huge haul of NHS patient data
> Why are people astonished?

Because politicians keep making promises in regards to privacy that they don't keep in regards to "confidential" information.

Similarly, most of the medical value from such information [e.g. Frequency of X within a given population fitting certain characteristics] would likely deanonymize people.

fweespee_ch··on Craig Wright's signature is worthless
> To me that's just bizarre. It's like Trump saying he'd be a great president and Obama meeting with him and saying he's the real deal, it'd just wouldn't happen.

It would happen if Gavin was Satoshi. Gavin attempts to permanently deflect things on to a smooth talking conman with liquidity problems to maintain his privacy.

Hell, he could even give Wright some of the bitcoins as payment for the cover.

fweespee_ch··on Why is Amazon all of a sudden not re-investing all its profits?
Massive capex.
fweespee_ch··on Unmasking the Men Behind Zero Hedge
> About 2 years ago the tenor of the publications shifted from libertarian to more and more reactionary (bordering on proto-fascist). When I skip the articles nowdays, I think that the authors have no problem with authoritarianism, as long as taxes are reduced and social welfare is gutted (it is obviously not stated as such, but most opinion-pieces speak for themself).

I think the problem with this is their ideological goals are to starve the beast and play at being antiestablishment. They were always unscrupulous about the how and have been since at least 2011 when I first noticed they existed.

I honestly don't think the tone has changed substantially.

fweespee_ch··on Unmasking the Men Behind Zero Hedge
> (Bloomberg LP competes with Zero Hedge in providing financial news and information.)

Does anyone else feel this is particularly generous?

ZeroHedge is borderline conspiracy theorist nonsense surrounded by occasionally correct financial analysis with a level of accuracy on par with a dart board.

fweespee_ch··on U.S. high court approves rule change to expand FBI hacking power
There is a different between "legal to do" and "within one's jurisdiction".

They are clearly lying through indirection unfortunately. :P

fweespee_ch··on Why is Amazon all of a sudden not re-investing all its profits?
http://www.nytimes.com/2014/04/26/business/amazons-shrinking...

I think a couple years ago they got tired of their stock tanking every time they reported a lower profit than previous quarters.

fweespee_ch··on How Cheap Can Electric Vehicles Get?
> You assume a constant price for gasoline, which is a bold assumption, given that the oil markets are currently gyrating wildly, and have been for some time - we're likely to see prices at the pump go up by orders of magnitude over a relatively short timescale, which will provide a big push towards EV adoption, and will drive people away from older vehicles which guzzle gas.

Sorry, that isn't likely. We have basically "infinite" (50+ years worth) of Oil @ $100 [1] [2] [3] a barrel which is why all those shale wells came online when oil was priced higher. We've already been ~$100 for years at a time. Similarly, the shift to greener technologies is going to put downward pressure on it once it is back to the ~$100 baseline from years past.

[1] http://www.bloomberg.com/news/articles/2016-02-03/texas-toug...

[2] http://www.forbes.com/sites/rrapier/2016/02/29/the-break-eve...

[3] http://www.cnbc.com/2015/08/20/us-crude-oils-break-even-cost...

fweespee_ch··on Suspect jailed indefinitely for refusing to decrypt hard drives
Yep. I use encrypted drives for my financial information and other sensitive information I store on behalf of family (e.g. legal docs), etc.

I wouldn't have a desire to reveal that either.

fweespee_ch··on Hiring Is Broken – My interview experience in the tech industry
> Hiring in CS / IT is massively more objective compared to most of other fields.

That is the illusion many people have convinced themselves of but literally 0 of my coworkers could answer the questions I was asked simply because don't have similar responsibilities despite us applying for literally word-for-word identical job ads.

The reality is, unless you do X regularly, you simply aren't going to be able to impress people with your answer to X.

fweespee_ch··on We’re not the “good guys”: American drone warfare is terrorizing the Middle East
Employed properly, drone strikes against legitimate targets [e.g. Military bases, arms shipments] are perfectly reasonable and effective.

Really the only problem we have is the fact the US keeps using it as a tool of assassination which results in too much collateral damage:

http://www.theguardian.com/us-news/2014/nov/24/-sp-us-drone-...

fweespee_ch··on Empty DDoS Threats: Meet the Armada Collective
> Do I want to see booters online? Of course not. > But if CloudFlare were to shut them down without due process, that would damage their credibility - to the point where I would feel uncomfortable doing business with them.

The problem with this stance is it appears to be a conflict of interest. The easier it is to access a booter site, the more people who need Cloudflare's services.

I'm not saying that is the reason they do it. I'm just saying that is a conflict of interest that can really only be resolved by removing clearly labeled booter sites.

> Think also from the customer standpoint: people who need DDoS protection are people who are having their site shutdown without due process (by criminals who launch DoS attacks). When the company you hire to fix the problem becomes part of the problem, it's not good - and they would be part of the problem if they offered a 'send us an email and we shut down our users' denial of service attack vector.

Hosting booters makes them part of the problem is the flaw in that logic.

fweespee_ch··on Bangladesh Bank hackers compromised SWIFT software, warning issued
https://www.schneier.com/blog/archives/2011/06/yet_another_p...

> Computer disks and USB sticks were dropped in parking lots of government buildings and private contractors, and 60% of the people who picked them up plugged the devices into office computers. And if the drive or CD had an official logo on it, 90% were installed.

It sounds more like someone left usb sticks with logos on them in the parking lot.

fweespee_ch··on The Heart of Deterrence (2012)
Honestly, large scale nuclear weapon deployment is going to kill alot of "us" so symbolically killing one of us is a better representation of reality.

There is never going to be a one-sided nuclear exchange when a substantial number of powerful, ideologically opposed countries have access to ICBMs.

fweespee_ch··on Fingerprints are Usernames, not Passwords (2013)
Did you bother to read the posts where I offered old accounts and/or the fact I cycle through accounts?

https://news.ycombinator.com/item?id=11440951

https://news.ycombinator.com/item?id=11377425

I mean if you are going to accuse me of being a liar, you may want to at least check to see if I mentioned having other accounts first.

Also, you may want to consider the OP was posted in 2013 to HN and I've said publicly I've been around on and off since 2010.

fweespee_ch··on Fingerprints are Usernames, not Passwords (2013)
I'm glad to see this post getting upvoted because I've had to argue with people repeatedly on HN who claim its private / a valid authentication factor.

Look folks, maybe as part of some second or third factor it might be okay...but you still need a password.

fweespee_ch··on Ubuntu 16.04's new Snap format is a security risk
https://insights.ubuntu.com/2016/04/13/snaps-for-classic-ubu...

> The security mechanisms in snap packages allow us to open up the platform for much faster iteration across all of our flavours as snap applications are isolated from the rest of the system. Users can install a snap without having to worry whether it will have an impact on their other apps or their system. Similarly, developers have a much better handle on the update cycle as they can decide to bundle specific versions of a library with their app. Transactional updates make deployments of snap packages more robust and reliable.

> By bringing snap packages to Ubuntu 16.04 LTS we are unifying the experience for Ubuntu developers, whether they are creating software for PC, Server, Mobile, and IoT Devices. Snapcraft, a tool available for snap development, makes it easy for developers to package their apps and dependencies. Developers targeting snap packages get a great environment to write and test their applications – directly on their desktop, rather than being forced to use a device or a virtual machine.

I think it is just a poorly worded announcement that implied security isolation on Ubuntu 16.04 LTS when that was not the intention.

Similarly, they are just as secure as apt so there is no loss of security so the claim of the OP's title is misleading.

fweespee_ch··on FBI Paid More Than $1M to Hack San Bernardino iPhone
> Was there something on the phone what made it worth it?

It doesn't matter to me tbh. They want to investigate, they can.

I just don't want them to be able to "scale" their investigations like they seem to want so they can get into all encrypted communications without a serious financial hurdle because they'll abuse it.

> I don't know if I understand the hypocrisy of hn. We cry "oh humanity" when Ford pays $50k over sticker for a new Tesla car for reverse engineering but of course if the FBI does something then surely they were judicious with their purse strings.

I didn't. Generalizing like that is unhealthy because it causes you to make some silly assumptions.

fweespee_ch··on FBI Paid More Than $1M to Hack San Bernardino iPhone
https://www.eff.org/deeplinks/2015/06/damn-equities-sell-you...

> Noted eagle eye and EFF Investigative Researcher Dave Maass happened on an interesting item from earlier this week on FedBizOpps, the site for government agencies to post contracting opportunities. The Navy put up a solicitation explaining that the government wants “access to vulnerability intelligence, exploit reports and operational exploit binaries affecting widely used and relied upon commercial software,” including Microsoft, Adobe, Android, Apple, “and all others.” If that weren’t clear enough, the solicitation explains that “the vendor shall provide the government with a proposed list of available vulnerabilities, 0-day or N-day (no older than 6 months old). . . .The government will select from the supplied list and direct development of exploit binaries.”

http://www.zdnet.com/article/nsa-purchased-zero-day-exploits...

> The National Security Agency bought hacking tools from a security firm, based on documents unearthed by a FOI request.

The US is doing it. The GCHQ likely does it too and I bet at least some of this list was built via information purchased from others:

https://www.schneier.com/blog/archives/2014/07/gchq_catalog_...

fweespee_ch··on FBI Paid More Than $1M to Hack San Bernardino iPhone
> James Comey, director of the FBI, said on Thursday that the cost was “worth it”, but added that an accommodation needed to be made with Apple and other technology companies in the future, as paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.”

That is exactly what we want. If its clearly in the public interest to expended substantial effort as part of a criminal investigation, they absolutely should do so.

The problem is they want scalable access to everything.

fweespee_ch··on Kite: Thoughts on Security
Contractual agreements, NDAs, etc. might make it impossible to disclose work product and/or source code to a 3rd party which would include Kite.

> If you're a contract developer, or a developer working full-time for a consulting firm, you might not have the authority to determine for yourself whether it's contractually allowable to upload code to Kite's servers. But if you're working for a pro shop, you can bet every dollar in your pocket that the contracts your firm has with its clients technically prohibit it.

As tptacek said, you might be prohibited and/or not have the authority to do so.

> Why does the device need to be on-premise? Would a Github Enterprise-like setup, where you have a dedicated Kite instance/VPS at their datacenter, work for you?

We run GitLab on-premise so I'm not familiar enough to answer. However, if by "their" you mean Kite? Yeah, that won't work as its essentially the same thing. [e.g. Disclosing it to a 3rd party outside of my control]

fweespee_ch··on Kite: Thoughts on Security
The only way to truly solve this problem is on-premise devices that do not push data to Kite, honestly.

I'd need to ignore every file I have.

Page 1 of 8Next →