HNHacker News
TopNewBestAskShowJobs

hellojesus

849 karma · joined September 23, 2021

submissionscomments
hellojesus··on Illinois just passed a law that puts Linux on the hook for age verification
Perhaps I'm just too old and don't use mainstream socials outside of HN, but when I was growing up the very act of knowing I was on a "child" account was reason to break out of it alone. I broke a lot of operating systems that way but also got good at repairing them. Jailbreaking was normal. War driving was normal. Breaking WEP just because you could was normal. Later, watching your neighbors go crazy over the fence as you deauthed their devices from their network was normal. It was just part of being a kid and having fun learning about the world.
hellojesus··on eBay scammer took $600 from me; eBay suggests cotton-candy flavor energy drinks
What a bummer. Sorry to hear that.
hellojesus··on Illinois just passed a law that puts Linux on the hook for age verification
This is step one. The next step is to say that it's not working and we need hardware attlestation or some such nonsense.
hellojesus··on Illinois just passed a law that puts Linux on the hook for age verification
But wouldn't this type of law drive youth to using more exotic distributions to get around the issue? It's not far fetched to think that kids will just live boot from tails or another distro to visit socials and circumvent this rule. Plus with unlocked pixel bootloaders it would be trivial for them to petition their parents for a pixel, hard reset it, unlock the bootloader, install grapheneos via the web installer, and then be on their way. If parents don't know how to monitor their kids I doubt they'll notice grapheneos not being base android.
hellojesus··on eBay scammer took $600 from me; eBay suggests cotton-candy flavor energy drinks
Tl;dr: I solved my scam issue by emailing first.last@ebay.com of every executive listed on their website.

Anecdotal, but once I sold a GPU to a buyer (which I knew was working), who reported it as defective. He initiated a return and I accepted, as is part of the normal selling process. I then randomly received a toe ring from Amazon addressed to someone that was not me but at my address (luckily it was the name of my parents' dog, so I held onto the package). The buyer then called ebay and said the return was complete and provided the tracking to show it was delivered to me.

I was made aware of this when I got an email saying that the return was complete and the buyer had been refunded. I called ebay to dispute it, since I hadn't received a package. I looked up the posted tracking number, and it represented a shipment from FL to me (PNW) whereas I sent the gpu to NY. It also said the package was 1 lbs, which would have been impossible because the gpu was listed as over 2 lbs by the manufacturer. I explained this to the nice customer service rep. We agreed the buyer could have relocated in the past week but the weight was unexplainable. She couldn't undo the transaction but escalated my issue. A couple days later I got an email saying my case was closed and ebay was siding with the buyer, so I was out the $400 they paid for the gpu since ebay wouldn't release the funds. I was in shock, but I called usps because I thought I must have been missing something. Usps takes pictures of all mail, and the nice man on the phone that called me back looked up the package and described it to me. I then realized it was the nose ring Amazon shipped to me that I thought was a weird Halloween joke from my parents related to their dog. I then emailed every first.last@ebay.com explaining my issue, stating that I, as a seller, could no longer take on the risk of selling on ebay because I had no protection in the case of an obvious scam. The next day I got a call from a secretary, and I explained everything to her, including that, had this been my work, my president would have called me and others into her office and played the recording of this phone call, concluding with, "Go fix this and make sure it can't happen again."

I got lucky and was given the payout. Ymmv.

hellojesus··on EU Age Verification Project Mandates Hardware-Bound Attestation
I was recommended by my psychiatrist to go get tested for autism recently. I suppose I should take that more seriously than I first did...
hellojesus··on EU Age Verification Project Mandates Hardware-Bound Attestation
I still contest that I should be able to solder together a basic computer in my garage and communicate with the internet so long as I follow the communication standards. There is never a reason to outlaw general purpose computing.
hellojesus··on EU Age Verification Project Mandates Hardware-Bound Attestation
Even so, they likely aren't recording everything your eyes see and for how long they linger. They likely aren't recording your entire traversal through the venue, what you do, what you say, what times you go there, from where you connect, etc. Simply being at a public place is one data point. A full history of your entire interaction is a magnitude different.
hellojesus··on EU Age Verification Project Mandates Hardware-Bound Attestation
I'll take the bait.

Can't you just enroll your kid's devices in your home corporate and leverage MDM to force the network to call through your proxy, which denies or downgrades all ECH and then can actively filter to an allowlist or screen the material through your personal or contracted LLM?

This seems relatively solved to me.

hellojesus··on GrapheneOS recommended for domestic abuse victims
It took me about an hour. I sat down, read the docs, installed it via the web installer, then spent the next 45 min deciding how I wanted to segment separate profiles for play services.

Nowadays it seems a lot easier because there seems to be a separate profile isolater you can run in the main profile, which I would choose if I was installing today.

The only hiccup I've had is that sometimes group messages don't send correctly and send individual messages to everyone, but I think that's because I'm on a secondary profile, and it only happens when the phone is receiving a bunch of messages all at once while I try to send to the same group. But I deny network access to my installed swype keyboard, so it may have something to do with that too.

I've been running this for years, since the Pixel 7 came out, which I'm still using.

I love it. I can confidently go through customs knowing that if they yank my phone during some weird checkpoint and try to celbrite it, I'm as secure as can be.

hellojesus··on Age verification is just a precursor to automated attribution of speech
But shouldn't the extension of logic be the same in either case, even if there is some premature convergence criteria? I have yet to see someone say age verification is okay because the gov ensure X is the maximum use of the tech. If anything, Public Choice Theory compels the grant that the gov will misuse the data given enough time.
hellojesus··on Age verification is just a precursor to automated attribution of speech
I was asking the Google llm search about why iterative games don't reach their competitive equilibrium the round after revealing the theory. In my example, it was the "guess 2/3 the average game", and I asked it why my class didn't immediately converge to zero after it was explained. The llm said people are lazy and I have autism because I couldn't identify or understand the stopping criteria used by my classmates. I'm still confused.
hellojesus··on The Australian Government to Require SMS/MMS Sender ID Registraion
> I vented to one of those call-center people trying to sell me a cheaper power utility for the Nth time, and told her to find another job or something like that

I threaten to kill and rape them all the time, but that usually doesn't do much.

I've found that politely asking them to kill themselves elicits much more engagement, and I hope it at least implants some lasting memory.

hellojesus··on Windows 11 users are tired of MS account requirements creeping into everything
Maybe I am the fool. :) I think about crime in the way I would do it, which is to grab the valuables police are unlikely to care about (hard drives) that allow me to quickly clone and encrypt myself, so I can destroy the tangible evidence, and then I have unlimited time to crack and review the information, and then even more time to execute my malicious attack against identities or whatever other I information I do find.

Only slightly better than this would be to break in, install a root kit, and then leave everything else untouched so as to try and minimize the knowledge that I was there, but I'd still be concerned that my c2 server would eventually point to me.

Maybe I should read about these actual crimes or get meds. The first couple years of my first kid's life were full of anxiety that someone would break in and steal my kid while I was sleeping at night.

hellojesus··on Windows 11 users are tired of MS account requirements creeping into everything
I'd argue the proper solution here is backup, as a hdd could die at anytime and leave you with approximately the same outcome. While encryption adds some overhead and increases the surface area for failure, it ultimately requires the same backup solution as anything else.
hellojesus··on Windows 11 users are tired of MS account requirements creeping into everything
> I roll my eyes at my friend when he explains the solutions for how to input the encryption password when his server restarts.

Isn't this rather trivial? You gen a keyfile, register it with luksAddKey, then update /etc/crypttab, no? The real concern is making sure that keyfile is stored securely, but you can simply symmetrically encrypt it and upload it to your favorite cloud storage provider.

hellojesus··on Windows 11 users are tired of MS account requirements creeping into everything
Agreed, specifically about the tax info concerns. All my drives are encrypted with either luks, veracrypt, or native zfs encryption if my server data.

My primary concern is a robbery while I'm not home. It's trivial to break in, steal hard drives, and then go pop them into another machine on your own time to scan the files looking for tax or other sensitive docs.

While encryption keys are a risk, you can always save the random key file or passphrase in cloud storage (using symmetric encryption) and/or in your password manager.

hellojesus··on Anthropic confidentially submits draft S-1 to the SEC
Agreed. Ben Felix has a video about this, I think he focused on SpaceX in it. The problem with the standard total market funds is they gobble it up right away. There are funds that do wait some period of time to purchase new ipos to let them smooth out, but I'm not sure those are typically available in 401k plans.

Hedge funds already know broad based mutuals will have to purchase these so can sneak in before them and then sell to them for a marginal gain. Mayhaps the newest strategy for exiting is generating so much hype that you're guaranteed an exit by retail retirement funds?

hellojesus··on Google employee charged with $1M Polymarket insider trading bet on search term
How is it fraud? Wouldnt it just be a tos violation?

In my view, anyone participating in these markets does so knowing that the outcomes are within the control of other participants. I can't think of any other reason individual account activity is public.

hellojesus··on Nobody cracks open a programming book anymore
Yahoo answers gave us MBMBAM. For that I will always be thankful.
hellojesus··on Google employee charged with $1M Polymarket insider trading bet on search term
If it's unregulated, how are people getting charged with insider trading?
hellojesus··on Green card seekers must leave U.S. to apply, Trump administration says
Agreed. I don't really know how the current process works, but I would assume there is some level of oversight, meaning that errant (unqualified) applicants shouldn't detract from a qualified h1b under the current system any more than a centralized one. Tying a profile to a human (gov can do this) should at least help with determining whether an applicant is qualified (not that they are an actual fit for the team) which could provide some proxy for fitness of the current pool.
hellojesus··on Green card seekers must leave U.S. to apply, Trump administration says
Isn't the correct response to the sham hirings to regulate that jobs are posted on a gov-run board for some period of time, ~30 days, before you can claim no qualified workers? That seems more reasonable than turning the spigot off entirely.
hellojesus··on Green card seekers must leave U.S. to apply, Trump administration says
It's shocking to me that the gov is allowed to claim "backlog" to defer one of the functions the gov is actually supposed to do. They print the money. They can hire enough to fulfill their obligation with almost zero effort.
hellojesus··on Green card seekers must leave U.S. to apply, Trump administration says
This is the part that is the wildest to me. The current system seems to generate a collection of second-class citizens: people we openly rely on for labor but that have no recourse if they're exploited and no regulatory protections such as minimum wage (even though I argue against min wage, if we're going to have it, have it!).

My personal preference would be to allow nearly unlimited legal immigration but strip welfare programs for all. In this way we allow anyone and everyone to become an economic participant, voting participant after the naturalization process, and mitigate those immigrating purely for handouts.

But I haven't thought through this policy well. Maybe there is something this seemingly solution is missing.

hellojesus··on Microsoft BitLocker – YellowKey zero-day exploit
Why not? Here are some scenarios where you may want protection:

- The feds show up

- A bugular breaks in and grabs your computer

- You're selling your house and host an open house

- You have curious children and want to keep them from live booting and reading your tax returns

hellojesus··on Kids can bypass some age checks with a drawn-on mustache
Sorry if I was unclear. My "race to the bottom" occurs because a privacy-preserving pass allows actors to hand out free passes to those the system is seeking to deny entry. E.g., An adult can generate valid keys and then publish them online for anyone to consume (or charge for them even).

My hypothesis is that this would lead to demands for policy changes to prevent that, which can realistically only be done via actual identification or hardware based attlestation (which is identification).

Does that seem wrong? If we didn't care if people could bypass the system, there is no reason to force even privacy preserving barriers, since parents literally have all the tools necessary to deal with this now, from router guards, to parental controls on computers, to device enrollment for iPhone and android systems.

hellojesus··on Software engineering may no longer be a lifetime career
Weird. I call myself a developer because I don't have an engineering degree from an abet certified engineering program.

I recognize, in some capacity, that this isn't the norm and in the US "professional engineer" is protected and not simply "engineer", but it feels akin to stolen valor to me.

hellojesus··on Gmail registration now requires scanning a QR code and sending a text message
You should just determine which carrier hosts the phone number and then go get a job there as a customer service agent or store employee. You'll get full permissions to change accounts, so you'll be able to make the change, fix your gmail, then change it back.

You probably risk some legal fallout though, so be cautious.

hellojesus··on Kids can bypass some age checks with a drawn-on mustache
Makes sense and apologies if I came off that way. I just skip to the logical conclusion, which is that there is no way this is going to happen without a race to the bottom, ending by forcing privacy violations. But maybe I'm wrong. I'll be a bit more cautious with my posts.
Page 1 of 34Next →