HNHacker News
TopNewBestAskShowJobs

handsclean

988 karma · joined March 29, 2022

submissionscomments
handsclean··on Cloudflare API Down
I know git claims to be decentralized, but has anybody ever actually managed to use it in a decentralized manner? Not even the git or Linux projects themselves are without a centralized sync point.
handsclean··on Germany's terrible trains are no joke for a nation built on efficiency
https://en.wikipedia.org/wiki/List_of_bridge_failures#2000–p...

I admit it’s not great data, but I think it’s a step better than drawing conclusions from a single event.

handsclean··on Anything longer ago than yesterday should just say the actual date
Even more fun: everybody rounds differently. “1 year ago” may mean 365 to 729 days ago to YouTube, but another website thinks it means 183 to 548 days ago (nearest whole number of years), and another website 350 to 548 days ago (nearest whole number of months up to 11, then years), and another anywhere from 1-365 to 364-729 days ago (within the last calendar year).
handsclean··on Germany's terrible trains are no joke for a nation built on efficiency
Wikipedia lists 282 bridge failures between 2000 and present, 4 of which occurred in the UK, 7 in Italy, and 35 in the US.
handsclean··on Not setting up Find My bricked my MacBook
Stockholm Syndrome was invented by a man who didn’t even talk to the people he accused of it, but simply asserted it as explanation for why former hostages were criticizing the police, while those former hostages were clearly stating that it was because the police were aggressive and irrational, escalating with acts like unnecessarily pointing guns, and generally disregarding the safety of the hostages. The only other famous case turned out to be acting under duress. It is to this date not a real psychological diagnosis.

Similarly, if you’d like to understand why people put up with Apple’s moderate abuse, maybe ask not how one might write them off as insane, but instead what their alternatives are.

handsclean··on 'This Is a False Advertisement': X Ads Are Being Challenged by Reader Context
Facilitating discussion of arbitrary webpages, though, has been stupendously successful, in the form of social media. I think that’s the problem with the extension idea, it’s social media that doesn’t realize it’s social media, so doesn’t pay enough attention to the make-or-breaks of social media like content quality, drawing people good for content quality, spam prevention, moderation, and circles of shared interest. Getting HN-like commentary on every webpage is interesting, what you get if you just turn on WordPress comments then do nothing, isn’t.
handsclean··on Issues with 1.1.1.1 public resolver and WARP
There are two missing facts here that change the story quite a bit:

- In addition to not supporting EDNS, Cloudflare sends DNS requests from effectively random PoPs, so the recipient doesn’t know even the visitor’s nationality.

- The reason archive.is doesn’t like this is it makes them vulnerable to DoS attack.

Source and details: https://news.ycombinator.com/item?id=36971650

handsclean··on H&R Block, Meta, and Google allegedly schemed to scrape taxpayer data: lawsuit
Sure, and price fixing scandals are “just using email”. It’s not what they used, it’s what they did with it. In this case, what they did with it is share with Google a huge amount of extremely private, legally protected information.
handsclean··on Why Japanese Websites Look So Different
It seems to me that all WEBP’s problems stem from extremely delayed or still nonexistent support from various programs and platforms. Does anybody know if there’s a good reason for this?
handsclean··on DKIM: Rotate and publish your keys
That’s just impersonation, framing is when it’s about how you make the real party look, not yourself. Which would be weird, not implausible, but you get to implausible when you assert not just that somebody framed you, but that you were framed by some specific trusted party like the police or Google, and also you have zero evidence.
handsclean··on DKIM: Rotate and publish your keys
Here’s the thing about deniability: even if you successfully remove all cryptographic proof of provenance, actually denying it is still asserting a frame job. That’s useless if the party you’re trying to mislead either is or trusts the data source, like, say, in the case of police surveillance, hackers, nation-state attackers…

I think the real solution to future breaches is ephemerality, which is why it’s critical for any secure messaging service to not only implement all-participant auto-delete, but to also make it easy to opt in to only for specific messages, since that brings the cost:benefit down to a point that it’s actually used.

handsclean··on Raspberry Pi 5
How else would you define how much a dollar is?
handsclean··on macOS Sonoma is available today
This release does add AV1 support, just only for devices with hardware decoding support [1]. I’m not entirely sure that restriction applies to desktop as well as mobile, it doesn’t work on my Mac without hardware support even after enabling the disabled feature flags, but I only upgraded Safari, not macOS.

Hardware-only is the right move IMO. Literally earlier today I was dealing with stuttering video that turned out to be caused by Chrome putting me on a software implementation of a “better” codec. These new codecs are only better on devices that can run them without stuttering, heating up, and chewing through battery.

[1]: https://webkit.org/blog/14445/webkit-features-in-safari-17-0...

handsclean··on LastPass: ‘Horse Gone Barn Bolted’ Is Strong Password
The first paragraph very nearly lost me – irrational, rage bait, directly contradicts later stated facts – but there’s some good content later. The chief complaint seems to be that LastPass is not forcing this upgrade, they are just blast emailing unaffected people that they “forced” it while not actually doing so. And they’ve pulled similar stunts in the past, and in current communication seem to clearly be blaming users for their weak settings and passwords while erasing the fact that LastPass chose the settings, ok’d the passwords, botched the upgrade, and still hasn’t fixed most of their mistakes.

Everybody with a clue knows LastPass is a lost cause, but what’s more interesting to me is how we can generalize the lessons we’re learning here. I’d propose that user blaming in general is evidence of bad tech and magical thinking around it, and that points a finger at some very interesting targets.

handsclean··on Signal: The Pqxdh Key Agreement Protocol
They definitely can and do scrape Signal logs and use them in court. The protocol doesn’t help them prove the validity of the log, but they don’t need it to: it’s already not plausible to claim that you and your contact falsified your logs, something few people know how to do, in sync, in order to frame yourselves. I think Signal’s approach to deniability is just not making it even more hopeless, while the real protection against future compromise of a currently trusted contact or your own device lies in a different strategy that does work, ephemerality.
handsclean··on Global Google Kubernetes Engine Outage
And grocery stores are just selling somebody else’s corn, but it’s that or become a farmer.
handsclean··on Chrome now tracks users and shares a “topic” list with advertisers
We’re in agreement on the relative privacy, too. My point was just to challenge this “protection” / “prevention” framing. If somebody regularly mugs you then announces they’re going to start taking half as much when they mug you, and that only in response to people increasingly fighting back, framing that as “mugging protection” or “mugging prevention” is not just inaccurate, but pushes an assumption that this person is actually helping us and that demands of no mugging at all are unreasonable.
handsclean··on Chrome now tracks users and shares a “topic” list with advertisers
They’re planning on turning off one tracking system they use on us and turning on another, that’s not “tracking prevention”. Every other browser just turned off the old and didn’t replace it, and users are better off for it.
handsclean··on Chrome now tracks users and shares a “topic” list with advertisers
> Technically they’re correct: the privacy offered by this new system is superior to that which is offered by the web with no tracking protection.

That’s not true, this new system is a tracker, not tracking protection. Simply turning it off improves privacy.

handsclean··on Ask HN: Why hasn't the cloud killed the mainframe?
I’m not GP, but I found it funny because the term is misusing the word legacy. It doesn’t fit other usage of the word or the dictionary definition of the word. I didn’t look it up because I didn’t think to, it looks like a normal use of an adjective, not a term.
handsclean··on Redesigning Chrome Downloads
It seems like it often happens that a company makes a bad decision, everybody begs them to fix it, the company sticks to their guns until the complaints die down, then years later the company finally does what everybody was begging for, claiming it as their own idea.

Cynically, this looks like a PR strategy: “Our course corrections are always about us improving on our past selves, not anybody else knowing better than us.”

I wonder, though, if it either really took them this long to reimplement it, or this long for some political change to enable it, and meanwhile a disconnected PR department was just spinning whatever they had at the time.

handsclean··on Apple’s strict on App Store rules but gives WeChat a free pass (2020)
Google’s “web integrity API” is a system to prevent use of software not authorized by a centralized, unelected authority. Even Google’s deceitful claims about it aren’t about copyright, but auth and anti-cheat.
handsclean··on Show HN: Blogs.hn – tiny blog directory
Because I was curious, frequency counts:

    256 - own domain, original tld
        208 - .com
        29 - .net
        19 - .org
    95 - own domain, cctld
        38 - other, <5 each
        20 - .io
        19 - .me
        9 - .ca
        9 - .in
    85 - own domain, new tld
        41 - other, <5 each
        31 - .dev
        7 - .blog
        6 - .xyz
    73 - platform’s domain
        36 - .substack.com
        20 - .github.io
        9 - .medium.com
        8 - other
handsclean··on The Titan Submersible Was “An Accident Waiting to Happen”
Readable link: https://web.archive.org/web/20190505114631/https://twitter.c...
handsclean··on TabDB: Using browser tabs as a database like only a maniac would
This is the database that shows up when I’m trying to pitch PostgreSQL, but the boss read a blog post and now has Strong Opinions, and now my job depends on writing a comparative analysis of PostgreSQL and TabDB that reaches the right conclusion while also making anybody who advocated TabDB look smart and feel like they contributed. I literally just wanted to code.
handsclean··on Site claims to sell upvotes on Hacker News
It’s hard to attribute Reddit’s rot to voting when it’s had so many years of administration alternating between absentee and inept, and when HN gets such dramatically different results. I generally agree that the trivialization of sentiment is probably a bad thing, but there’s also a lot that works here and one should be careful not to break. I’d certainly be curious to see how it plays out. I wonder if one couldn’t disable voting for only some threads…
handsclean··on Microwaved plastic containers release microplastics into food
I believe the new material isn’t less food safe, it just trades some thermal shock resistance for impact resistance.
handsclean··on Welcome Lemmy.world
4% usage doesn’t mean only 4% prefer it. It’s a buried setting that’s default off, that alone makes the choice for ballpark 80%. It doesn’t support mobile, which drops another huge segment, and it doesn’t support “new” features like images and tags, and Reddit spent years aggressively pushing everybody to switch. I wouldn’t be surprised if 4% is the vast majority of Redditors who actually tried both and had the opportunity to choose.
handsclean··on “But the SEC let us go public” and other flawed arguments in Coinbase's defense
I think I’ve run into this misunderstanding in my own conversations. The problem is that there are two different lines of reasoning that can look very similar:

A: You say “Z is true of X”, and I respond “Z is false for thing-like-X”, implying “Z is likely false for X”.

B: You say “Z is true”, and I respond “Z is false for Y”, implying not “Y is like X therefore Z is likely false”, but “Z is sometimes false, so we need to actually evaluate whether it’s true of X”.

I think people who use this reasoning would do well to make it more explicit.

(Here, Z is “there must be a path to compliance”, X is Coinbase, and Y – not, I believe, thing-like-X – is heroin.)

handsclean··on Intel is all-in on backside power delivery
https://www.cpubenchmark.net/cpu_value_available.html#xy_sca...

It looks like Intel still has a solid lead in single core perf, which is frankly the biggest factor for me for a general purpose desktop CPU. Of course, other uses have other priorities. The charts are missing one important measure, power efficiency.

← PreviousPage 6 of 8Next →