HNHacker News
TopNewBestAskShowJobs

hda2

1,151 karma · joined September 28, 2020

submissionscomments
hda2··on Apple says they're removing my game because it's more than 2 years old
According to Google, that's changing soon (probably in an attempt to ward off pending app store regulation).
hda2··on Apple says they're removing my game because it's more than 2 years old
No, just ban software stores from removing working apps for no good reason.
hda2··on Regular blood donations can reduce “forever chemicals” in the bloodstream: study
This, but unironically.

Science is, and has always been, about adjusting our flawed, incomplete models as new evidence emerge. We shouldn't let our ill-informed preconceptions prevent humanity from moving forward.

If removing blood from the body takes forever chemicals with it and we have no practical way of filtering those chemicals out, then discarding the blood (yes, bloodletting) is the moral way to do it. Irrational and uneducated biases need not apply.

hda2··on Git security vulnerability announced
> but then what if you need hooks? then you'll have to somehow manually enable it on a repo-by-repo basis, which also doesn't seem very convenient.

What's wrong with that? Git hooks are inherently dangerous (i.e. running arbitrary code) and should be something you opt into manually.

hda2··on Git security vulnerability announced
Nitpick: This isn't an RCE. An attacker would need 1) write access to a /local/ directory that the target will navigate to in his shell, and 2) convince the target to execute arbitrary git hooks in every directory (or parent directory) he visits by adding git to his shell's PS prompt.

Besides, now that this security issue is patched, git devs should seek a proper solution to that doesn't break git and decrease security for everyone else.

hda2··on Git security vulnerability announced
Then don't run commands in PS1 that blindly execute arbitrary code in that directory.

Honestly, people haven't learned a single thing from Window's autorun days.

hda2··on Git security vulnerability announced
Wait, I thought git hooks aren't pulled from remote.

Wouldn't untrusted git hooks mean that git verify-* are useless since you're already running untrusted code?

hda2··on Git security vulnerability announced
Was this change discussed publicly prior to merge?

I think this is a big mistake. Build environments use separate users for security purposes. It's insane to decrease security for everyone by requiring a single user to do everything because some of your users want to have fancy terminal prompts.

At the very least, let users configure this at a per-user level.

hda2··on iFixit and Google Are Launching a Genuine Pixel Parts Program
The pessimist in me is inclined to believe that this is just another empty gesture to ward off the specter of right-to-repair legislation that's looming over tech giants. Louis Rossmann made a grate video about why these programs are almost useless (samsung) to downright harmful (apple).

I think the only reason Google and their friends are doing this is to remain in control (how, when, if). They don't want to end up like the car industry.

I hope regulators don't fall for this trap.

hda2··on NPM package event-source-polyfill compromised by political activists
> Why should I trust open source today? Packages are routinely hacked, political message or not.

Correction: NPM packages are routinely hacked.

I've been using linux packages for two decades, and not once have they been hacked (to my knowledge). I consider those packages to be infinity more secure than proprietary packages where I and others can't check what's running under the hood.

OSS being safe and secure is one of the primary reasons why I prefer open source to closed source software.

hda2··on Twitter is using its embedded JavaScript to hide tweets that have been deleted
> Twitter is under no obligation to retain this kind of stuff on your behalf.

They declared something worked one way then silently changed how that thing works without properly announcing the change first and giving people enough time to adapt. Would you still be willing to make these excuses if your emails provider decided to do the same thing?

Even if it's their system, there's a limit where people would rightfully start to object.

hda2··on What happens if you try to download and install Firefox on Windows
My bad. I meant full proper desktop-grade support for addons and devtools like what kiwi does for chromium on android. From your comment, it seems that proper full is still disabled on both stable Firefox and Fennec.

Since I'm not really interested in using nightly or jumping through hoops, I'll just continue using kiwi which is able to support both my requirements just fine.

Thanks for the clarification though.

hda2··on What happens if you try to download and install Firefox on Windows
> Well just tried it. Edge > opened Bing > "Firefox" > Click on first Firefox hit > Download. And nothing like that happened. No pop up or nothing. And I'm using a Windows 10 PC with an MS account logged in for Office365 + Gamepass

Mozilla was caught "studying" (read, spying) on a tiny portion of its user-base who have explicitly opted out of telemetry. The fact that most weren't spied upon doesn't mean that it didn't happen.

This is what I don't like about people who make misinformed statements on HN.

hda2··on What happens if you try to download and install Firefox on Windows
If I may ask: How are you using addons on mobile?

Firefox for android doesn't allow addons and F-droid Fennec doesn't seem to support them either.

The only browser on android that gives me full devtools and addon support is kiwi browser which has it's own skeletons to contend with: https://www.reddit.com/r/uBlockOrigin/comments/ppygw1/can_i_...

hda2··on What happens if you try to download and install Firefox on Windows
Like other abusive software, if I need to use windows, I use it in a sandbox (a VM in this case) or in its own dedicated device.

Life it too short to deal with malicious vendors.

hda2··on Block a tweet, its author, and every single person who liked it
I agree that some very small subsets aren't worthy of attention, but I don't understand how any person would willingly isolate from the views of "vast subsets of humanity".

How can you be so sure you got it right? How do you check for blind spots if you don't regularly expose yourself to opposing viewpoints?

I ask this because some of the best decisions I ever made were only possible after I considered the "other" side. Most of the time their views fail apart when subjected to scrutiny, but sometimes my view is the one that is found lacking.

I think fuzzing viewpoints with honest dialog is crucial for a healthy society.

hda2··on Block a tweet, its author, and every single person who liked it
Precisely! Sure, block abrasive assholes, but blocking those who follow them or like their tweets will only serve to isolate YOU from those who might be able to present their view point in a more nuanced and respectable way. I think this can be a very harmful tool if misused.

I learned a lot of valuable things I wouldn't have otherwise had I used a tool like this.

hda2··on Nintendo Switch prevents downgrades by irreparably blowing its own fuses (2020)
I'm also one of the people who ultimately decided not to buy a switch (despite wanting to) because of nintendo's aggressive and misguided notion of ownership. There are other options that doesn't involve me betraying my principles and financially rewarding those who trample on my rights.

Now that the steam deck is out, I'm glad I did.

hda2··on Web3 is centralized and inefficient
> web 3 = own

1. How would this work for me as a user? Are web 3 "websites" (or whatever constitutes a service or company) not able to retain a copy of my data? Or phrased in another way, what prevents websites from also /owning/ my data?

2. How would this work for me as a service? Aside from my service's domain and internet address which are annoyingly hard to "own", what else is there to own that I don't already own?

I don't share hn's irrational hatred towards crypto so I'm not against joining whatever web3 is supposed to be (in principle) but I've yet to be shown a single benefit in doing so.

Give me a single clear benefit to using or offering a web3 service.

hda2··on On the Weaponisation of Open Source
> Me refusing to transact with you isn't a war crime.

You refusing to transact with me isn't a war crime, but your line of thinking where normal citizen activities are similar to conscripts shooting at you can certainly lead to one.

It's one thing to target citizens who work on applications for the military, and another to target open source devs because they happen to be Russian. If you can't acknowledge this distinction then I'm afraid we have to agree to disagree.

Also please don't put words in my mouth. Strawmen will get us nowhere.

hda2··on On the Weaponisation of Open Source
This line of thinking leads to bombing schools and hospitals. This is how we get war crimes. I'm glad most people don't think the way you do.
hda2··on On the Weaponisation of Open Source
> shoot at enemy conscripts

But most Russians affected by these aren't shooting back. They aren't conscripts or have anything to do with the war (doubly so now that sanctions are in effect).

Shooting at solders trying to hurt you is one thing, but that's not what's happening here.

hda2··on On the Weaponisation of Open Source
Unless your program is a black box that doesn't interact with the rest of the world in any way, sandboxing will not be enough. People still need to mitigate the effects of malicious supply chains.
hda2··on LibreWolf – A fork of Firefox, focused on privacy, security and freedom
> You can activate a developer mode and install any extensions you want to.

You mean a full feature-complete devtools like what you'd find in the desktop version of firefox?!

If so, then it's a life saver. The only other browser that I'm aware of that offers full devtools on android is kiwi, but that browser force-disables ublock origin and other extensions on some sites.

hda2··on I found a security issue on a competitor, got fired and served a summons
People got into trouble for reporting issues without any further digging. I'm not stupid enough to take the risk. Want good samaritans? Fix your laws first.
hda2··on I found a security issue on a competitor, got fired and served a summons
Seeing that we as a society haven't fixed this problem yet tells me that we deserve the countless security breaches we get. I will continue to let any vulnerability I discover go unreported until the government grants immunity to those who report them.

I want to help others, but not at the risk of destroying my life.

hda2··on Arti – An implementation of Tor in Rust
An enticing UVP for Arti would be that it allows rust services to easily have cheap built-in network redundancy via tor integration. This would make it trivial for administrators to set up alternative access to their services if their services can reach tor.

This would allow global access to services in case of DNS outages, superfluous takedown requests, or anything in between.

Onion service support seems to be TBD, unfortunately.

hda2··on Firefox removed Yandex search option
What's the status on allowing all addons and devtools on Brave for Android? I switched away from brave to another browser because those features were stripped out.
hda2··on Israel passes law denying naturalization to Palestinian spouses
Leaving what you consider Islamic imperialism aside, I'm curious to hear your thoughts on how dhimmi status compared to how jews were treated in other parts of the world at that time.
hda2··on Tinder’s pricing algorithm can charge users up to 5x more for same service
> The “crap” you’re talking about is the idea that fairness has a place in mating.

That "crap" is something you brought up on your own. We're discussing unfair discriminatory pricing, not mating.

← PreviousPage 4 of 13Next →