HNHacker News
TopNewBestAskShowJobs

jsnathan

2,096 karma · joined December 18, 2014

submissionscomments
jsnathan··on How I Became HackerRank 1 in Two Hours
The code snippet shows a bug, p is an uninitialized pointer. The behavior is undefined. Theoretically it could point to some valid memory, but saying that it points to dynamically allocated memory definitely implies a misunderstanding.
jsnathan··on 1177 BC – The Year Civilization Collapsed [video]
It's funny you say that because the author addresses this at the start of the talk. He says that when it was suggested to him by a friend that he write a book about the Collapse, he agreed only on the condition that he could distinguish himself from previous publications on the same topic precisely by talking more about what the Late Bronze Age was actually like, and what was lost.

He also says if he had to choose any period of history to live in he would choose that period.

I don't think he should be blamed for writing what he wants to write about, but maybe the marketing of the book is a bit misleading.

jsnathan··on What $50 buys you at the Huaqiangbei electronics market in Shenzhen, China
Wired did a 1-hour feature recently called 'Shenzhen: The Silicon Valley of Hardware' [1]. They also visit the markets.

[1]: https://www.youtube.com/watch?v=SGJ5cZnoodY

jsnathan··on Yahoo scanned customer emails for US intelligence
There are many ways to categorize and define argumentational fallacies, and so it is often difficult and disingenuous to argue over exactly which fallacy is violated by a particular utterance.

But since this is blown up since I last looked at it, why not take a moment to try to diagnose this.

It is not in fact an 'ad hominem', as you said, since an ad hominem attacks an argument by attacking a person (or group). Though it is, to me, perfectly fine to call it that, since that is the result, the second quote does not in fact attack any argument directly.

It is a response to the act of quoting Rand, rather than to anything specific that Rand was quoted as saying.

Secondly it is also not an 'appeal to emotion', since an appeal to emotion is again directed at making a particular argument, in this case by making people feel instead of think. This again does not fit the second quote, because it does not make any specific argument at all.

From what I can tell, the most descriptive term we can find for what makes this quote by 'John Rogers' so upsetting, as evidenced by the amount of discussion below and above, is that it is a 'smear'.

Its nature is that it does not attack the argument made by the quote it is posted in reply to, but instead attacks anyone who might believe, and quote, anything from that book, presumably including the OP.

To quote Wikipedia [1]:

> A [smear] is an intentional, premeditated effort to undermine an individual's or group's reputation, credibility, and character.

...

> Smear tactics differ from normal discourse or debate in that they do not bear upon the issues or arguments in question. A smear is a simple attempt to malign a group or an individual with the aim of undermining their credibility.

> Smears often consist of ad hominem attacks in the form of unverifiable rumors and distortions, half-truths, or even outright lies; smear campaigns are often propagated by gossip magazines. Even when the facts behind a smear campaign are demonstrated to lack proper foundation, the tactic is often effective because the target's reputation is tarnished before the truth is known.

> Smears are also effective in diverting attention away from the matter in question and onto the a specific individual or group. The target of the smear typically must focus on correcting the false information rather than on the original issue.

> Smear tactics are considered by many to be a low, disingenuous form of discourse; they are nevertheless very common.

So, while this is not strictly one of the traditional logical fallacies, I think it is nevertheless clearly a bad form of discourse, and frankly inappropriate.

[1]: https://en.wikipedia.org/wiki/Smear_campaign

jsnathan··on How many lines of code is Candy Japan?
I'm glad he mentioned it cause I wouldn't have noticed otherwise. I submitted it [1].

[1]: https://news.ycombinator.com/item?id=12612574

jsnathan··on The FBI’s Approach to the Cyber Threat
Just a brief note for those coming late to this thread that this originally pointed to (and made it to the frontpage as) [1], which is a discussion of only the part of this speech by Comey which pertains to encryption and privacy, and which starts with "A brief word, because I can’t resist, to talk about encryption", which you can grep for.

A basic summary, not using the same words: They want backdoors, and they propose that still counts as 'strong encryption', only, well, with a backdoor. Also, they intend to make a push for this next year.

[1]: https://www.wsws.org/en/articles/2016/09/05/encr-s05.html

jsnathan··on EmDrive: Nasa paper has finally passed peer review
I've been doing some reading on this recently, and as far as I understand it, this paper is not going to settle the matter one way or the other. IANAP so take these notes with a grain of salt.

There was an experiment done by a Chinese lab a few years ago, which seemed to support the effect, but when they re-did the experiment using an on-board battery instead of a power cable, the effect disappeared.

So far noone has publically replicated this condition (i.e. battery instead of power cable), and either confirmed or disconfirmed this null-result, and I do not think this new paper will report any experiments using this condition either.

There are however efforts underway to actually put one of these things into space in the form of a tiny satellite, and see if any thrust is produced there, which seems like the perfect experimental setup.

All in all I think it is going to be years before we know what is what in regards to this technology.

jsnathan··on Uber's Failure in Japan
The article basically states that Uber's cavalier attitude towards the law was the wrong approach to use in Japan, because the Japanese public does not respect this attitude, and that they should have worked it out with regulators before they started operations.

I guess the broader lesson implied is that you need to put in the effort to understand the local culture, and adapt your strategies accordingly, before you try to enter a new country.

jsnathan··on Sad Trombone Exoplanet Reality Check
> That seems way bogus to me.

I'm sorry, I'm not sure exactly which part you're objecting to?

jsnathan··on Sad Trombone Exoplanet Reality Check
You're probably right about Einstein not suggesting there was a hard physical limit preventing nuclear energy. But I don't think that hard physical limits are a good argument anyway.

There are FTL proposals that do not violate known physics, such as distorting spacetime using some perhaps yet unknown mechanism.

Saying that there are hard limits in physics here, as you did, suggests that research in this direction is not worth our time.

I believe that is misleading.

jsnathan··on Sad Trombone Exoplanet Reality Check
Google found me this [1].

"On 29 December 1934, Albert Einstein was quoted in the Pittsburgh Post-Gazette as saying, “There is not the slightest indication that [nuclear energy] will ever be obtainable. It would mean that the atom would have to be shattered at will.” This followed the discovery that year by Enrico Fermi that if you bombard uranium with neutrons, the uranium atoms split up into lighter elements, releasing energy."

This would be before the 1939 letter.

[1]: https://www.newscientist.com/article/dn13556-10-impossibilit...

jsnathan··on Lyft Is Said to Seek a Buyer, Without Success
It seems more like a rush to the finish to me [1], rather than a slow crawl. The goal doesn't seem to be to create a 'perfect' AI driver before deployment, just one that is good enough.

And after all, we only really need a statistical improvement over human drivers for it to be worth it, given that the software in these cars can be updated over time.

I guess it would be nice though, if we had a really tough standardized test course, involving various common situations with pedestrians, cyclists, etc.

On the other hand, we test human drivers on real roads too.

[1]: http://www.driverless-future.com/?page_id=384

jsnathan··on Measure the Real Size of Any Python Object

  >>> import pysize
  >>> import sys
  >>> pysize.get_size([])
  0
  >>> sys.getsizeof([])
  72
  >>> a = [[],{},()]
  >>> pysize.get_size(a)
  0
  >>> sys.getsizeof(a)
  96   # probably also wrong?
It's cool idea, but needs a bit more work I think.
jsnathan··on HyperTerm – JS/HTML/CSS Terminal
Anyone remember this?

> On February 20, 2004, the developers of wxWindows announced that the project was changing its name to wxWidgets, as a result of Microsoft requesting Julian Smart to respect Microsoft's United Kingdom trademark of the term Windows. [1]

That being said, I think if MS doesn't ask them to change it, there isn't much to worry about. "wxWindows" was originally started in 1992.

[1]: https://en.wikipedia.org/wiki/WxWidgets

jsnathan··on Rats free each other from cages (2011)
I believe that the development of synthetic meats that are both cheaper and of a more homogeneously high quality will supplant butchered meat, and eventually enable us to outlaw it.

The science is happening as we speak.

jsnathan··on UK votes to leave EU
He's not the only one who seems to think so: https://www.reddit.com/r/worldnews/comments/4pkt3k/bbc_forec...
jsnathan··on Why Aging Isn’t Inevitable
Going to try to summarize a bit.

The article explains that different organisms exhibit different patterns of aging, when we consider aging as either defined by increases in the probability of death, or decreases in the probability of reproduction.

Taken together with the evolution of species, this implies a plasticity in both the mechanisms and utility of aging - something which is otherwise considered to be a rather solid constant of life.

The takeaway then is that we must 1) widen our definition of aging to accommodate the variety of natural phenomena, and 2) reconsider the intuition that a specific pattern of aging, such as the one found in humans, is necessary for the survival of the organism and/or the species.

jsnathan··on The Difficulty of Private Contact Discovery
Really sorry about the edits! Thinking in real time :)

So about the size of the phone number space. Interestingly I guess you could at least limit it by country. But, unless you already know the mobile phone numbers of the target's acquaintances, (in which case there is no real danger of 'leaking' your social graph), you can't really limit it more, because mobile phone numbers are pretty random within each country's phone number space (I think).

So say the US has at least 0.5 billion assigned mobile numbers, and you don't know which are assigned, so the space could easily be 10^10 for just the US. (I can't find any quick numbers on Google right now).

But even if we go down to say, 100 million, we would still get (10^7 * 10^7)/3600 ~ 2.7e11 hours worth of hashing to get all contact pairs. Which is still secure.

Now as far as limiting one end point to a single phone number - that would be a special case. I'm not sure if this isn't moving the goal post a bit.

As long as the server does not have access to your own phone number, it, or anyone who has hacked into the server, cannot really use that to limit their computations. Unless they are already targeting you through other means (possibly you are a person of interest to someone), and so know your phone #.

In that case yes, they could reveal (part of) your social graph for a (maybe) affordable cost. But in that very special case, I think we are dealing with nation-state adversaries.

And in that case, the telcos probably already have a list of your phone # contacts. So it would probably be easier to simply get it from them.

The only thing left to be revealed would be that you communicated with a specific acquaintance using that particular app, at some particular time.

So a targeted attack could leak that metadata.

It's not perfect.. but I think it might just be good enough for most users.

If we go off the deep end with an attack tailored to a single phone #, we also have to worry about a whole lot of other attack vectors that are probably more important.

Lastly, note that the user (if sufficiently paranoid) could simply opt out of the automatic contact search post-install.

jsnathan··on The Difficulty of Private Contact Discovery
OK hold on. Say the rotating salt thing doesn't work, for whatever reason.

But you yourself made a better suggestion! If we do hash (phone #) contact pairs, and every client publishes multiple hashes, one for each of its contacts, then a cheating server would need to compute (max) (10^10 * 10^10)/3600 ~ 2.7e17 hours worth of hashes.

That would actually be secure, no?

Edit: messed up the math myself this time; I think this is correct now though

jsnathan··on The Difficulty of Private Contact Discovery
See my sibling comment about the salt.

As long as hashes are computed client-side, I don't see why the size of the installed base matters?

jsnathan··on The Difficulty of Private Contact Discovery
> You can't use a salt, the contact you want to match has to be able to compute the same hash.

I think the misunderstanding here is that I meant one salt for all users at a time, instead of one salt for each hash.

And as long as stored hashes can be recomputed (by active users), the 'global salt' can be rotated over time.

We can pre-compute hashes with future salts in case apps are not constantly online. Then we could rotate salts, say, once every 2 hours.

The point being to make rainbow tables more expensive.

> You can hash the contact pair instead of one side of it, but even then an attacker can rent X instances of some hardware that is Y times faster than your phone, so if you target a difficulty of ~1 second per contact on your phone, you get a difficulty of 2700 hours / XY for the attacker to recover all of your contacts

> So if Y is 10 times faster than your phone, you only need X=10 to recover the contacts for a given number in a day. If the attacker is willing to set X=1000, Y isn't even relevant.

I think this should be (10^10/3600 ~ 2.7 million hours) / XY. Also, let's say we can make it Y seconds (perhaps the hash is memory hard, etc). Then to compute a single table (per salt) we need 2.7e6 hours, at say $0.01 per hour, so $27k per table.

Taken together that would mean to reveal the contacts of signups happening within a 2 hour window, would cost quite a sum.

It's not secure, of course - but it does give some measure of privacy.

If you think users are willing to wait more than an hour, you could 10x the cost too. But that's probably not practical anymore!

Edit: Oh. I see I made a mistake here! If the server computes a single rainbow table it will be able to retroactively de-anonymize all users that are already active at that time! :( Sorry.

jsnathan··on The Difficulty of Private Contact Discovery
There cannot be precomputed tables for every custom hash computation. Especially an expensive one. Even less so if you add a salt.

It could be made prohibitively costly for all but the most determined adversaries - and those could probably get your social graph much easier from other sources.

Only problem I can see is it would take a few minutes after the app is installed to find your contacts..

jsnathan··on The Difficulty of Private Contact Discovery
Can't you just make the hash more expensive?

Also, couldn't you regularly rotate salts?

jsnathan··on If you're alive in 30 years you might be in 1000 years too
> Ray Kurzweil and Aubrey De Grey are playing on the hopes and fears of people to make arguments about the fountain of youth that won't come to pass. I wish they would, but they won't.

Oh but they will. Most certainly. It's a question of when, not if.

The body is nothing but a very quirky, very complex bit of machinery. Our task is to scientifically probe that complexity until we have such a great understanding of it that we can manipulate and improve that machinery in vivo.

To say that we cannot do that is to say that Science itself is too weak a method to overcome the level of complexity presented by advanced biological organisms.

It is therefore to predict that scientific progress will come to an unexpected, screeching halt, some time in the next decades.

I find this an absurd scenario, and therefore believe to the contrary. Science will overcome the level of complexity of human biology, and continue onward even long after that.

Because, putting anthropocentric intuitions to the side, the human body is not the most complex phenomenon imaginable.

jsnathan··on Show HN: Transcrypt – Fast, small Python 3.5 to JavaScript transpiler
FWIW I prefer the same kind of spacing. So there's at least two of us.
jsnathan··on A letter to our daughter
That seems counterfactual to me, but that's just my opinion.
jsnathan··on A letter to our daughter
Sorry I was referring to the second part of your comment.

Even if you happen to be in majority with your progressive views, in this instance, there is no guarantee for that generally, especially if we consider the entire global populace.. is what I was trying to point out.

jsnathan··on A letter to our daughter
But would you be in the majority with that? :)
jsnathan··on 15B More Reasons to Worry About Facebook (2007)
It might power 20% of all domains, but that doesn't equate to 20% of mindshare. Individual Facebook pages should be counted individually in this context.

Wordpress also is not really a federated system, because the individual sites are not interconnected.

jsnathan··on A Decade-Old Gag Order, Lifted
IF this were the case, then the solution would be a whistleblower. Or someone hacking into the system, who makes the information collected public.

Of course this person would face even more risk than Snowden ever did.

← PreviousPage 3 of 5Next →