HNHacker News
TopNewBestAskShowJobs

j_san

221 karma · joined December 30, 2020

submissionscomments
j_san··on How I influence tech company politics as a staff software engineer
What does it mean to make your 1 pagers and technical documents "float around" in your case?
j_san··on Overengineered Anchor Links
Hey, another overengineer! :D

My solution was to just highlight the last anchor if the user scrolled to the very bottom. Although this might skip the second last heading if its too close to the bottom.

See here: https://sharezone.net/privacy-policy (most visible on desktop, on mobile you have to open the "Inhaltsverzeichnis" at the bottom)

j_san··on Show HN: Psychedelic animation generator; (p)art of your next trip
Is there a way to make it loop? (So that one only needs to record e.g. 20 seconds, after which it loops to save space)
j_san··on GSA Eliminates 18F
I don't think that far-left was primarily only written because of the tax returns. I followed some links in the article and came to this twitter thread which might explain where that notion comes from: https://x.com/lukerosiak/status/1885523747425399247

(Disclaimer: I don't live in the US and don't want to take any political stance with this)

j_san··on Clean Code vs. A Philosophy Of Software Design
Biased against the approach of your former coworker and thus the "Clean Code" way? I assume it did not work out well, because you needed to move fast to build an MVP before trying to do it right?
j_san··on Show HN: InstantDB – A Modern Firebase
Is there a plan to make it self-hostable?
j_san··on 25 Years of Krita
The text in the "Choose your membership" column at https://fund.krita.org/ is broken for me, it's not visible.
j_san··on Dangers of “decentralized” ID systems
Do you have any links where one can read about the removal of DIDs?
j_san··on Ask HN: How is the Spotify app so bad?
For me the Android mobile app is sometimes skipping songs or not switching to the next one when swiping or tapping the next icon. Often recognizing another device as playing doesn't work. If it recognizes it then editing the song queue doesn't work more often than not (especially removing songs from the queue). I hate it. It is so bad, I'd be ashamed having so many users, so much money but such an bad app.
j_san··on Show HN: Flox 1.0 – Open-source dev env as code with Nix
flox.dev/terms leads to a 404
j_san··on eSignature Beta for Google Docs and Google Drive
Thanks for your answer, I appreciate it.

Although strictly speaking if they would only want to do AdES and not QES, they wouldn't have to be in the EU Trusted List, would they?

j_san··on eSignature Beta for Google Docs and Google Drive
Is this targeted for the US market or also the EU? Does this qualify as a an advanced electronic signature (AdES) under the eIDAS regulation?
j_san··on PSA: Intel Graphics Drivers Now Collect Telemetry by Default
Can some EU citizen please make a complaint to a DPA (Data Protection Authority)? It's gathering so much stuff, I don't think that this would hold up to scrutiny.
j_san··on Show HN: Invoice Dragon – An open source app to create PDF invoices
Is it open-source by any chance? I would be very interested to see all the logic that is necessary to handle all the different jurisdictions. Sounds complicated!:)
j_san··on IRIS²: The EU’s Response to Musk’s Starlink
I'm european and dont like thousands of satelites swirrling around in the sky as well but I'd rather have government-founded satelites for the public benefit than from some way-too-rich sociopath's private company.

Of course - this project would probably not exist without Starlink, so credit where credit is due.

Personally I find it quite sad that we're destroying the night sky in the sense that before these projects people could look in the sky and know that all humans before them had more or less the same sight. Now there are just so many satellites swirling around in your sight. I find that quite sad.

j_san··on Own Your Data
Under GDPR they'll still have to comply.

If they have a data protection officer then send him an email. Else if you're in the EU get the Data Protection Authority (DPA) of your country in the loop.

j_san··on Meta prohibited from using personal data for advertisement
I don't think this is true, many news sites either offer the option to accept cookies and show ads or offer a subscription without ads and tracking cookies.

This has been ruled as being valid by courts.

j_san··on Codeberg: A GitHub alternative from Europe
I just wrote them an email:)
j_san··on Codeberg: A GitHub alternative from Europe
The privacy policy is not compliant from what I see. I still love the mission but it just leaves a bad taste in my mouth - if one makes privacy a marketing point then at least the privacy policy should be compliant.

One example missing in the privacy policy is information regarding "the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;" There is more stuff that should be included, see: https://gdpr-info.eu/art-13-gdpr/.

(Technically it doesn't have to be in the privacy policy document but could be provided in some other kind of document. I guess thats not done though.)

j_san··on German judges visit Peru glacial lake in unprecedented climate crisis lawsuit
Some more information about this case and overall context: https://verfassungsblog.de/travelling-courts-and-strategic-v...
j_san··on European Commission prefers breaking privacy to protecting kids
I very opposed to the proposal of the commission - in fact I even went to a demonstration today against it. It's a horrible privacy invasion and very bad in many different ways, but...

But I think your take is not true. I can imagine that it might just be a really misinformed proposal to actually go against child abuse. I hope.

j_san··on Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
Depending on how it's implemented it could still use the same mechanism, couldn't it? (genuine question)

For me the question is if this is a webauthn thing in general or a security key thing (to include the domain in the challenge to prevent phishing)

j_san··on Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
But isn't the "thing" about FIDO (or maybe just security keys?) that the domain is also integrated into the challenge the client/key has to solve?

So from what I understand a attacker couldn't as easily fish me by pretending e.g. to be Google. With a password or even a TOTP code the attacker could just pose as Google and forward the credentials to the actual site.

j_san··on Considered "18+"
> As they were a US company, many of the "violations" that they picked up just weren't considered problematic for a UK / EU audience.

Just out of curiosity: could you provide some examples?

j_san··on Google gives Europe a ‘reject all’ button for tracking cookies
You know thats the funny thing - actually this would be pretty close on how one could do it right now. Nobody actually forces sites to show a big cookie banner, they choose to do it. The user could have a small button on the side to open a dialog and to activate more cookies than just the necessary ones if one really wants to (I think).

It's of course not how you describe it on a technical level but from a UX standpoint.

j_san··on Ask HN: What are the next internet infra problems?
I don't know if this is in the category that you're asking for but right now there is tons of experimentation with "Content centric networking" e.g. "Named data networking" to better optimise how we load content inside the web. Instead of using an IP to connect to some server of e.g. Google to get content we just say what data we want and load it from where ever (with better prospects of caching).
j_san··on Show HN: Bionic Reading – Formats text to make it faster to read
Props for the GDPR compliant Cookie decline button! :)
j_san··on Is Google Analytics illegal in your country?
I don't think the imprint is really hindering.

Not using SASS services (e.g. Firebase) just really sucks though.

We still use it (started with it before privacy shield was demolished) but we will have to migrate eventually. Don't know what we'll use exactly, maybe managed kubernetes with some platform for an easier workflow running on it? Idk yet.

j_san··on Fixing the Unfixable: Story of a Google Cloud SSRF
Nah also just the principle of data minimisation - if there is no good reason to save it (this long) then it shouldn't be saved. A DPA would probably have Google pay for that if it would come that far.
j_san··on Grindr €6.5M fined for not collecting users’ valid consent for sharing data
The Norwegian Data Protection Authority imposed a fine of €6,500,000 on Grindr for not collecting users' valid consent for sharing data with third parties for profiling and advertising purposes from the Grindr App.

Particularly interesting is that it is not allowed under GDPR to have a free version of an app with the condition that it shares personal data (in this case for targeting and profiling for ads) as the consent of the user is not freely given in this case - in a "Take it or leave it" situation, consent cannot be seen as freely given.

Link to the section "Consent as a condition to access the service ": https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)_-_2...

Page 1 of 2Next →