HNHacker News
TopNewBestAskShowJobs

handity

462 karma · joined January 21, 2022

submissionscomments
handity··on FastSpring Risk Screening
Both. KYC, as justified by antiterrorism laws, is out of proportion for a small one-person business earning roughly a living wage.

In the eventuality that KYC could be justified, it should be in the manner of Estonia and other European countries, who have managed to implement digital signatures without the insanity of validating infinitely reproducible pictures of paper ID documents from the last century, and relying on data-hungry third parties to process biometric data through "AI" black boxes.

handity··on FastSpring Risk Screening
After ten years using fastspring with no issues and decent sales volume, I received the same email. I categorically refuse to KYC by uploading a picture of my passport and allowing some algorithm to scan my face, and being asked to pay for the privilege is especially insulting. I allows my account to terminate. It remains to be seen whether they will keep my last two weeks of revenue also.

I switched to Stripe for billing, where apparently I do not need to undergo such KYC. I expect that won't last forever, and don't know how long I can go on hopping services without uploading a passport photo.

Modern KYC is an insanely invasive process carried out through insane methods, and I wish I saw it getting more pushback. Online ID verification should be done through zero knowledge proofs, if at all.

handity··on The new Paris métro
Anonymity cannot be guaranteed, but between the two options, the phone or reusable card based version is guaranteed to invade your privacy to a much larger extent.

At worst, a paper ticket can reveal your location when you buy it, when you start a journey, and possibly when you transfer or end a journey. It's already a close to ideal system: it provides proof of the right to travel in the event of a ticket control, without needing to reveal your identity, destination, past or future journeys, home address, phone number, banking details, or any other extra info. Out of band info exists in either case.

A phone app, which is what everything trends towards and seemingly what most people want to use, almost certainly has access to enough information from your device to uniquely identify you. The default will be to ask for your location, and most will grant it. Now the app knows who you are, where you live, exactly when you travel, who with, to what destinations, etc.

The trend is always towards more surveillance. Regardless of what is technically possible, digital will always struggle to achieve the levels of privacy and anonymity that are trivial with century old technology.

I grew up with the paper tickets, and remember being jealous of people with a Navigo. They could go through the gates so fast, and the contactless tech and little "bling" sound the gate makes when they touch in seemed so futuristic and cool! I never thought I'd come to see the paper tickets as almost too good to be true. That they have survived this long feels like a glitch in history, and in a rapidly evolving world they're a strong reminder of what's being lost.

handity··on Show HN: YouTube banned adblockers so I built an extension to skip their ads
Sure, I should have said "P2P based video sharing like PeerTube". The point is that for videos with no expectation of making money, P2P is a better model than YouTube, as it is both free and ad-free.

I am not saying that PeerTube is better and that people should be using it. I am saying that it is worse, because of the way YouTube developed and made competition impossible.

handity··on Show HN: YouTube banned adblockers so I built an extension to skip their ads
There is no mandate that YouTube must exist in its current state. YouTube serves two roles, one as a free service to host videos, one as a roulette machine that might pay out money if your "content" is favored by "the algorithm".

A huge amount of videos on YouTube are created for their own sake, with no expectation of going viral or making money off them. PeerTube fulfills the "free video host" role while also being ad-free. I might be naive, but I believe this is how most people saw YouTube around 2012.

The "seeking to make money on YouTube" role is artificially created as a result of a massive corporation running a loss-leader for a decade, dictating what content gets popular through recommendation algorithms, and literally paying people to encourage them to produce more of the desired addicting content.

Who knows what would have happened if YouTube had not been bought out and been allowed to compete fairly with P2P technologies as they emerged.

handity··on Using extra Firefox profiles to make my life better
Animations and eyecandy don't require arbitrary code execution and should be handled by css, if at all. Almost all websites can be served as data, with the client free to render it how it chooses, which enables far more elegant and unified UIs than anything we have now.

Windows Phone 7 was a brilliant example of this. It was one last attempt by a large player to unite social media sites and messengers into one UI and interaction framework, and it was the most fluid, beautiful and pleasant OS I've used. Now that kind of interoperability would be borderline illegal. When you strip control away from devs about how their data is rendered, the results are generally more beautiful, not less.

I'm guessing that interaction reminders are those modals that appear when you go to close the tab, or prompt you to subscribe when scrolling down further. I would classify both as totally unnecessary and making the experience worse for users. They also do not require arbitrary code execution.

Cookie popups are a result of the ad-centered, panopticon-enabling web.

I know what I'm describing is far and above nojs. What I'm trying to get at is the motivation for disabling js, and what the web would look that if that principle were followed to it's logical conclusion.

handity··on Using extra Firefox profiles to make my life better
JavaScript cannot be safe, at least if your threat model involves avoiding a global surveillance panopticon.

Allowing arbitrary code execution by default cannot be safe.

90% of what JavaScript is used for is totally unnecessary and only makes sense in an ad-based web.

handity··on Populating the page: how browsers work (2020)
I have been looking for exactly this sort of thing for ages, I'm so glad to have found your comment!
handity··on I'm fed up with it, so I'm writing a browser
Thank you, you've encouraged to make some mockups to try to bring this idea a little closer to reality.
handity··on I'm fed up with it, so I'm writing a browser
I really want to experience a happy medium between the barebones minimalism of Gemini and the insane free-for-all of the mainstream web. In my mind, there is no reason for every website to dictate its own layout and appearance when 99% of sites could be broken down into procedural elements that could be rendered however the client preferred.

I recently bought a Kobo ereader, and the gorgeous, text-focused, crisp design of the OS is what got me thinking in this direction.

The existence of Reader Mode in Firefox and Chrome points to a common understanding that, for articles anyway, most of the web fluff is totally unnecessary. Imagine Reader Mode, but maintaining navigation and slightly more complex layouts. There are plenty of extensions that allow you to theme specific sites, but I haven't found any that try to create a unified, pleasant experience from the current chaos.

As usual, the ad-based web can be blamed. The argument that it is of utmost importance to preserve the ability to make this button 5px bigger than the other, rounded, and blue, only makes sense if you're an ad-based company trying to manipulate people into specific behaviors. By leaving the design client-side we would enable experiences tailored to providing the best experience for the user.

I don't know if or how we could ever get there, but it seems to me that mass adoption of css and Javascript in the majority of websites was a mistake, when most sites could easily be built of a much simpler set of standard widgets. This need is currently filled by pages hosted with hostile third parties like Facebook, or middleware editors like squarespace.

This kind of framework would also give online privacy to all in one fell swoop. There is no reason browsers need to be finger-printable. The reason they still are is because the company for which this state of affairs is highly lucrative is also the company making the leading rendering engine.

Perhaps what I'm actually asking for is a splinter net, or maybe something like this is still achievable by just parsing html.

While I relate to OP's fed-uppness, building a browser seems to me like trying to play catch up to a system that will never have your interests at heart. Not that I think the project isn't worthwhile, it just triggered the above thoughts.

handity··on First U.S. ban on sale of cellphone location data might be coming
If he is extradited, 100% guaranteed he will not get a fair trial by any common definition of that term.
handity··on First U.S. ban on sale of cellphone location data might be coming
I had a second part to my comment about how web3 was the answer, but the public have been largely convinced that it's synonymous with get rich quick schemes or a worse version of Twitter. Where is the next WikiLeaks?
handity··on First U.S. ban on sale of cellphone location data might be coming
WikiLeaks tried that, Assange is still in Belmarsh and the MSM is still largely allowing him to rot there.
handity··on A weed is swallowing the Sonoran Desert
No, that's a bit like being happy that locusts are bringing so much life to your field. A single plant growing explosively over a large area with scarce resources should be worrying.
handity··on Pixel phones are sold with bootloader unlocking disabled
Counterintuitively, Pixels are great for "serious privacy phobia" people, as they are one of few phones that can be flashed with a custom OS and have the bootloader locked. GrapheneOS only supports Pixels for this reason.
handity··on Manipulative Consent Requests
"Consent requests" will never work.

Until all web browsers present identical fingerprints and reveal no identifying data about the user, tracking will take place, whether laws mandate consent or not.

Opt-in, opt-out, none of it matters as long as we're browsing the internet with our unique identities on full display to every site we visit. Thinking that the solution is to ask companies nicely to please not use that information is delusional.

handity··on Microsoft plugging more ads into Windows 11 Start Menu
Users should learn to say "no" to companies. The surveillance advertising economy is not some hapless mistake that companies will suddenly wake up to one day and realize the error of their ways. Whatever Microsoft "should" do is just wishful thinking. Change will come from users or regulation, and regulation seems unlikely.
handity··on Facebook engineers: we have no idea where we keep all your personal data
Agreed, Facebook definitely has the ability to provide timestamped interaction events as part of "Download my Data". Maybe legislation will force them to provide that information at some point, but that won't really have any effect on user privacy.

The hearing seems to want to get more to the heart of the issue, but is inept to do so. The stored data isn't the concern, it's the predictive capability of models built on it. The decision of a predictive model isn't any more traceable to a single piece of data than a brick in a road is traceable to a given taxpayer, which is what I was trying to get at with the analogy.

After reading some of the transcript, the special masters seem very on the ball, and it's more the spin of the article I take issue with.

handity··on Facebook engineers: we have no idea where we keep all your personal data
After reading some more of the transcript, I think the article does such a bad job of describing what was being asked for that it makes the court seem incompetent and Facebook actually rather reasonable. My original comment is below:

Government contracted construction workers: We Have No Idea Where Your Tax Money Goes

When tasked with answering the simple question "Which specific bricks did my tax money buy this year", the two veteran construction workers looked confused and tried to explain that that's not really how taxes work.

The special master at times seemed in disbelief, as when he questioned the engineers over whether any invoices existed for a particular road building contract. “Someone must have a receipt that says this is who the money came from that bought these bricks”

I'm not sure the analogy fits 100%, but it's the closest I could think of. This reads like the author thinks the Facebook algorithm is a human-readable decision tree that only takes into account the data of a single user at a time.

As usual, the problem is not data "collection" or "retention" or "privacy", but "creation". Regulation will always remain woefully inadequate to control such organizations, and the only solution is to adopt systems that don't spew user data everywhere in the first place.

handity··on Kagi/Orion status update: First three months
I much prefer to trust an implementation over someone's word. I use Signal because I agree with their stated goals, and their implementation seems to align with those goals. I don't use Facebook because their policy is awful in the first place, and implementation is nonexistent. Kagi is in between. I am happy with their policy, but their implementation is lacking. This wouldn't be a problem, but they don't seem to admit that their goals are fundamentally in conflict with their mode of operation.

This is the first item on their FAQ:

"Our goal is amplify the web of human knowledge, creativity and self-expression and provide the user tools to fight against the web of greed, ad-tech and user tracking."

To pretend that company policy is the best way to achieve that goal is insulting. We will never have an ad-tech and tracking-free future without technological measures. Offering a service on the basis of "Pay with your money, not your data" is a fantastic step in the right direction, but obviously not enough.

handity··on Kagi/Orion status update: First three months
While I am a happy paying Kagi customer, their stance on privacy is nonsensical and amounts to saying "We super duper pinky promise that we won't use your data"

From the Anonymity section: "For example your parents can know everything about you and still fully respect your privacy."

Ok, but if anyone thinks I trust a company the way I trust my parents they are sorely mistaken, and I certainly wouldn't want my parents to have an easily searchable record of everything I've ever searched for online, the same way a search engine provider does.

The complexity of accepting crypto payments is totally understandable. If that's the reason Kagi does not prioritize anonymity then that is understandable, but the justification that "you don't really want privacy anyway" is unnecessary.

"We do not log searches or associate them with an account, by design. This is a software architecture decision (we simply don’t need this) and there is no simple switch one can flip to enable this in case of a court order."

"Software architecture decision" is meaningless. The only guarantee that data will not be collected and stored is a technological, probably cryptographic one.

If an organization is in a position to gain intimate knowledge of your life and habits, they have the ability to influence your life and that of others. Pinky swearing not to do so is a lot like following someone around with a camera while repeating "it's just for a video". https://www.youtube.com/watch?v=-R5WjfL2ZAg

I don't expect Kagi to accept crypto, and I'll keep paying just because I'll jump at an opportunity to pay with my money rather than with my data. However, given that they decouple their service from the need to track users, I would have expected them to prioritize anonymity wherever possible as the next logical step.

If the justification was technological it would be understandable, but their reassurance that there is nothing to be concerned about is itself concerning.

handity··on Things not available when someone blocks all cookies
Cookie AutoDelete
handity··on Audible feedback on just how much your browsing feeds into Google
Paranoid was maybe the wrong word. I am not worried about anything in particular happening to me, but I know that mass surveillance is bad in principal, so I oppose it.
handity··on Audible feedback on just how much your browsing feeds into Google
I consider myself very privacy conscious, bordering on the paranoid. I use FOSS as much as possible, avoid FAANG, and remove surveillance from my life wherever I can.

This tool shocked me. It exposes in a visceral way just how prevalent Google is, and does a better job getting that idea across than every video, article, post or comment I've consumed on the topic.

← PreviousPage 2 of 2