HNHacker News
TopNewBestAskShowJobs

intherdfield

297 karma · joined December 16, 2013

submissionscomments
intherdfield··on Show HN: Tabstack – Browser infrastructure for AI agents (by Mozilla)
https://hg-edge.mozilla.org/mozilla-central/shortlog
intherdfield··on Platform Tilt
Apple already takes this approach to limit some entitlements to web browsers on macOS. See the Passkey entitlement as an example:

com.apple.developer.web-browser.public-key-credential

https://developer.apple.com/documentation/bundleresources/en...

intherdfield··on I Lost $150K in a Day
He didn't mean that literally. It's a tongue in cheek way of saying "when you're a 23 year old and you think you've mastered the markets, you don't think about wealth preservation."

Original quote: "When you have mastered the market at 23 years old, and you're up 6000% in less than a year, you don't think about wealth preservation."

intherdfield··on Ask HN: Can Firefox be revived?
Donations go to the Mozilla foundation which does "internet advocacy". Donations do not go towards Firefox development, not towards the CEO's salary or Firefox engineers' salary.

What does the foundation do? https://foundation.mozilla.org/en/what-we-do/

intherdfield··on Firefox usage is down despite Mozilla's top exec pay going up
This narrative ignores the fact that many of the executives have been replaced whether voluntarily or involuntarily.
intherdfield··on Dangerzone: Convert potentially dangerous PDFs, documents, or images to safe PDF
On macOS, the PDF reader Preview.app runs sandboxed by default.

The Preview.app sandbox is not quite as secure as what is used by browsers such as Firefox or Chrome on macOS for web content, so there is probably still a benefit to viewing PDFs in the browser, depending on whether the browser or PDF viewer is more hardened against these attacks.

intherdfield··on Lambda School’s Misleading Promises
That seems really disingenuous. Can't you update the article with this important detail?
intherdfield··on Lambda School’s Misleading Promises
I don't think you mentioned that the student doesn't have to pay back Lambda after 60 months of deferred payments. That seems important. From the Lambda site:

"The income share agreement has no interest. It's a flat percentage that goes away once you've reached the $30k payment cap, you've made 24 payments, or after 60 months of deferred payments (even if you haven't paid us anything)."

But you wrote in the article:

"Students with no safety nets experience real financial pain from the nine-month hiatus from work, in addition to the looming dread of possibly having to pay Lambda $30K one day."

intherdfield··on Drinking hot tea linked with risk of 1 type of oesophageal cancer
> FTFA "People who drank hot tea daily but didn't smoke or drink alcohol every day had no increased risk of oesophageal cancer."

Actually, it's the opposite.

From the article, "Some studies have suggested that only people who drink alcohol or smoke are at risk of cancer from drinking hot tea. This study suggests that is not the case."

The conclusion section of the article addresses some of the questions raised here. I would say the conclusion was a refreshingly well written summary of what the results mean and some outstanding questions.

intherdfield··on Firefox enables deprecated Fido U2F Support for Google Accounts
Apparently, the two are related. From the post,

"We’ve recently learned that Google Accounts has slipped their schedule for using Web Authentication to register new credentials. This delay is attributed to security key support on Android being, for most devices, non-upgradable."

intherdfield··on Serious Chrome zero-day
"The second vulnerability was in Microsoft Windows. It is a local privilege escalation in the Windows win32k.sys kernel driver that can be used as a security sandbox escape."

https://security.googleblog.com/2019/03/disclosing-vulnerabi...

intherdfield··on NTSB: Autopilot steered Tesla car toward traffic barrier before deadly crash
This came up last month and a Tesla driver had this to say.

https://news.ycombinator.com/item?id=16822623

intherdfield··on Tesla Model 3 Gets CR Recommendation After Braking Update
> What prevents a new update to revert this or cause other safety problem?

One would hope it's a culture of safety first at Tesla where all software changes are extensively reviewed, heavily tested in the real world and using whatever kind of simulations are possible, deployed in a reasonable manner to a small set of cars and only deployed to the main population of cars after a satisfactory amount of time.

> Pushing updates in a rush is not a good sigh for critical software.

Yeah, it's pretty scary to know the braking software in your car was tested for less than a week.

intherdfield··on Uber Self-Driving Car That Struck Pedestrian Wasn’t Set to Stop in an Emergency
Which simply means it is because the car's AI isn't good enough to classify that object as something it should slow down for versus something it can ignore (like an empty plastic bag drifting across the road.)
intherdfield··on Tesla Was Kicked Off Fatal Crash Probe by NTSB
That is very significant!

Your comment suggests that Tesla's claims about the driver having his hands off the wheel for x seconds before a crash could be wrong. If the sensors detect the drivers hands are not on the wheel when they actually are on the wheel, then data logged about how long the driver's hands were off the wheel should be considered suspect.

I hope that's being investigated.

Personally, I'm having trouble believing the driver who died in the recent accident ignored the warnings for six seconds before the head-on collision, especially when he knew Autopilot didn't work well at that section of road.

I'm not familiar with how the system works. If the warning engages, is there a guarantee that the driver will have to take over shortly? Or are there scenarios when the warning turns off by itself and so the driver could have been waiting to see if the car would correct?

[Edit: lolc and Vik1ng pointed out that the warning isn't related to unsafe conditions as I implied. It's used whenever the sensors think the driver's hands are off the wheel.]

intherdfield··on Ask HN: How can we stop the plan to end net neutrality?
No, they can still see the IP address of the site you visit.
intherdfield··on Ask HN: How can we stop the plan to end net neutrality?
Hi, I'm your ISP. Now that I'm not limited by net neutrality over-regulation, life is going to be better for you.

Hacker news and those other niche new sites you visit are niche sites and as such have a lower routing priority. If you would like to prioritize them with full enhanced speed, please upgrade to niche news site plan. An additional $9.99 per month. Sorry, they're so slow right now.

You've noticed all your https traffic is slow now? Easy fix: install this software which proxies all your HTTPS traffic through our fast and secure gateway. This lets us add "supercookies" to all your web requests. We then sell your name and address to operators of sites you visit.

And what's great is that this software also allows us to insert our own advertisements into the websites you visit. Now we can finally take revenue from Google and Facebook and become our own advertising empire. We've wanted Google-money for a long time, but we've never had a way to force ads on users because we don't offer compelling services.

With the recent increases in Netflix and YouTube prices, we recommend you subscribe to ISPFlix. It's an additional $24.99 per month which is half the price of Netflix. We've wanted Netflix money for a long time, but we've never had a way to force users to use our services over Netflix. Now we love cord cutters.

Oh, you've noticed the decreased traffic to the website you operate? That might be due to your site being so much slower for users. If you'd like your site to be fast again, please pay an additional expedited content service fee. It's an additional $299 per month.

Oh, it looks like you have a smart thermostat installed. That's an extra $9.99 per month for the home automation service plan. We'll block packets that look like they're from your thermostat for now. We should let you know we offer a full home automation and security product. It's a terrible product that is not competitive.

See? Regulation to make sure we won't block or slow down sites or alter your traffic just doesn't make sense. It's totally not important to anyone, but we are going to promise we won't block or slow down sites. Our terms and conditions may change at any time.

intherdfield··on Firefox Send: Private, Encrypted File Sharing
It's pretty close to being the same thing. You're downloading Firefox at some point and not verifying the binaries you get match the source.

Unless Firefox provides fully reproducible builds on your platform from an open source compiler, you have no guarantee that the binary you have is built from the public source code. You have to trust Mozilla.

Without reproducible builds, compiling the source yourself would be the way to go.

Anyway, I agree that it should be clear that this file sharing service, while convenient, essentially requires you to trust Mozilla with your data. The claim "Mozilla does not have the ability to access the content of your encrypted file..." is fragile.

intherdfield··on Firefox Send: Private, Encrypted File Sharing
>> one has to trust Mozilla not to do that. > > Exactly. One has to trust Mozilla every time one visits > the page. They could easily configure it to be malicious > one time out of a million (say); what are the odds that > they would be caught?

Bear in mind they also make the web browser.

intherdfield··on Google Sued by 3 Female Ex-Employees Who Say It Pays Women Less Than Men
From the article,

"a University of San Francisco study of data from 1988 to 2008, extended to 2013, demonstrated male nurses made an adjusted $5,148 per year more than female nurses. This inequality has persisted over 20 years with no discernible trend toward resolution in the future."

"The percentage of men in nursing has slowly risen from about 2% in 1975 when I entered nursing to almost 12% (or 330,300 nurses) now."

And I'm not trying to imply anything. I just thought it was noteworthy.

intherdfield··on Man charged after media storage site Dropbox finds child porn in his account
> Nope. Dropbox has never claimed they don't have access to your files

I don't mean to nitpick and it's been a while, but Dropbox used to claim that "even our employees can't access your files". People called them out on the misleading language and they changed it.

https://www.cbsnews.com/news/at-dropbox-even-we-cant-see-you...

intherdfield··on The New Firefox and Ridiculous Numbers of Tabs
> Hard to love when the broken extension ecosystem prevents the use of vertical tabs for these scenarios.

Here's an in-development vertical tabs extension using their new extensions API.

  https://addons.mozilla.org/en-US/firefox/addon/tab-center-redux/
Apparently the tabs still show up at the top because the API to disable that isn't available yet. But you get vertical tabs and it should get better over time. I've been using this and it isn't 100% perfect, but getting better and better.
intherdfield··on John Carmack on expert witnesses and 'non literal' copying
> Publishing it after the fact for review by > the public doesn't make sense, and calling for it is > petty.

Carmack isn't calling for it to be published. He only said he thinks the system should work that way.

intherdfield··on John Carmack on expert witnesses and 'non literal' copying
> You could say the same thing about anything people do in secret.

I don't think that makes sense. There is no attempt to generalize this to things people do in secret. There is no claim that if something could risk your reputation then it follows that it should be made public.

Carmack's assertion is only that this particular work (for which the witness does voluntarily and is paid for) should be made public so that these witnesses use the same level of rigor they would for their other published work. And letting the public review it would have benefits too. (I am not agreeing or disagreeing with this.)

Ultimately, if we take Carmack's statements as true, it sounds to me like Facebook/Occulus' defense did not do an adequate job of instilling doubt in the report. He wrote that the defense did a technical tear down. I think if I was a juror, I would need to see this report completely destroyed. I'd need to see the same methodology applied to works where we know there was no copying and have it find false positives.

intherdfield··on John Carmack on expert witnesses and 'non literal' copying
Could you explain why you think this is a threat aimed at the expert witness in this trial?

Any time someone publishes a work, they are putting their reputation at risk. If the work is bad, the whole world will know they did it. Carmack is saying he thinks this should be the case for reports and analyses given by expert witnesses.

intherdfield··on Trump Fires Acting Attorney General
You're both right, but when it plays out in public, someone has to get fired.
intherdfield··on Fired IT employee offered to unlock data for $200,000
The article describes how a college with 2000 student email accounts couldn't get Google to unlock their administrator account. And it wasn't resolved by Google until the legal situation with the fired IT employee made the news. The college switched to another cloud provider. It sounds one-sided, but also believable.

From the article,

<quote>

School officials asked Google for help. Google, the college said, refused to grant access to anyone other than Williams, who was listed as the account's sole administrator.

...

About 12 hours after an IndyStar reporter contacted Google representatives on Friday, the college's attorney, Scott Preston, said the internet company unlocked the account and returned control of the emails and data to the school.

Before that resolution, Preston told IndyStar: "The college has done all it can to resolve this short of police intervention or suing Google."

</quote>

intherdfield··on Tesla Flips the Switch on the Gigafactory
It's reasonable to want to know the answer rather than to be content that Elon Musk must know the answer. Asking the question isn't an attack. I found a few reports online.
intherdfield··on Apple’s 2016 in review
Apple has a large enough hardware footprint.

They now need to compete on AI. I imagine a lot of their resources are being put in the catch-up-to-Google bucket.

There have been a lot of blog posts saying Apple doesn't know who their customers are. But their products are already accepted by everyone (every group). Their customers are everyone.

intherdfield··on UK bulk surveillance review is ‘fiction’, claims former NSA technical director
I don't see anything about "with fury" in the wikipedia article you mentioned, but it does say he was with the agency for 30 years.

Not that we'll ever know what really happens over there (nor do I claim to know anything about these things), but in interviews, his argument was that his project was more sensitive to the privacy of American citizens, but the agency instead instead went with an approach that violated the constitution. Leading him to resign.

And aren't there other sources from the British government that essentially agree that the UK "review" doesn't exist?

Page 1 of 2Next →