HNHacker News
TopNewBestAskShowJobs

kevinslashslash

94 karma · joined December 17, 2017

submissionscomments
kevinslashslash··on 2-in-1 calculator app adds up to surprise hit for retired engineer
It's just the iPad doesn't have a default calculator app https://www.howtogeek.com/820792/where-is-the-calculator-app...
kevinslashslash··on Google Play bans call-recording apps
> deny access to the App store if using the permission if you want, I don't care, as long as there is an option to do it for power user.

That's what the article is about. It's a policy change.

kevinslashslash··on Drastic DS Emulator Pulled from Google Play Store
> The greatest scam of Google and Apple is convincing millions of developers to learn Swift and Kotlin to make apps on their stores that can be swiftly (pun intended) removed from their stores

I certainly won't defend Apple and Google's app store monopolies and control. However, Kotlin was actually a case of Google listening to the developer community. Google could have, and wanted to, push Dart (see Flutter) on Android. But the Android development community was already adopting JetBrain's Kotlin. Google listened and embraced Kotlin instead of pushing their own thing. It was not a hostile act.

kevinslashslash··on Ask HN: Let's build an HN uBlacklist to improve our Google search results?
Ironically, when testing an example Google search from this thread, this thread came up. So HN doesn't block Google completely, but maybe has poor SEO so it rarely shows.

4th result is HN for me https://www.google.com/search?q=%22code+that+protects+users+...

kevinslashslash··on LastPass Login Attempted Activity Blocked – More Information
The original response was essentially blaming affected users, saying it was credential stuffing. Now they changed their story. If there is any credibility to the credential stuffing story, they should ask all users that received the email change password, not just say change it out of an abundance of caution.

Obviously something changed as the emails just started going out recently. Maybe it was a recent code change introducing a bug on their end, that's fine software has bugs, but they could explain it. Maybe attackers are doing something different, which is triggering an old bug causing incorrect emails. Or maybe LastPass still doesn't really know and is just giving a potential reason, like they did earlier saying it was credential stuffing.

I'd already stopped using LastPass years ago and deleted my account when this current mess started, so they weren't really going to win me back anyway. But the (current) response to this incident leaves plenty of unanswered questions.

kevinslashslash··on LastPass users warned their master passwords are compromised
I'm one of the people that replied yesterday.

I haven't used LastPass since, at the latest, 2017. I had actually deleted all my passwords from my LastPass vault, but originally kept the account because of LastPass's password sharing feature, though I stopped using that as well. I believe I had the LastPass extension installed on both Chrome and Firefox, on both Mac and Ubuntu. I primarily used Chrome on Mac. I did have uBlock Origin on those setups as well, but I really doubt that's the vector, it's likely just incredibly popular with all users of Hacker News. My LastPass password was globally unique and between 15 and 20 characters long (with some symbols and digits). This password shows no matches at https://haveibeenpwned.com/Passwords . I considered sharing the password here, but just in case an old version of my vault is out there somewhere somehow I'm not going to. My understanding is that such a password would be so incredibly impractical to brute force that it's not worth considering. Unless I'm outdated/wrong on that, that means the password leaked in clear text (or hashed with a broken hashing method). As I haven't typed that password since at least 2017 and I can't imagine LastPass is storing passwords in clear text, I'm inclined to believe the password was stolen in clear text from client machines (either LastPass extension exploit or malware) in or before 2017. It's weird they were not used earlier, but as LastPass doesn't allow new IPs by default, maybe the attackers knew this and were sitting hoping an additional exploit would allow their user. But now they're just trying in the off chance someone clicks the "That's me" link in the email. This doesn't explain the more recent claims, personally I'm inclined to disregard them as unrelated noise (user confusion, reused password, etc).

kevinslashslash··on Ask HN: How did my LastPass master password get leaked?
I got the "Someone just used your master password" email too

Time Monday, December 27, 2021 at 3:05 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.190.69

I haven't used LastPass since 2016 or 2017.

kevinslashslash··on Why are hyperlinks blue?
Excellent comment. For "constructive separation", if giving him benefit of the doubt, the relevant employment term seems to be Constructive Dismissal (or discharge or termination). https://en.wikipedia.org/wiki/Constructive_dismissal

"when an employee resigns as a result of the employer creating a hostile work environment. Since the resignation was not truly voluntary, it is, in effect, a termination. For example, when an employer places extraordinary and unreasonable work demands on an employee to obtain their resignation, this can constitute a constructive dismissal."

kevinslashslash··on GitHub no longer supports this web browser
There is an about:config setting called privacy.resistFingerprinting that does a handful of things, I believe including canvas fingerprinting. It also disables site specific zoom though (as that could be used for fingerprinting) which I find rather annoying.
kevinslashslash··on Firefox Preview Nightly with uBlock Origin Support Released
The non-nightly Firefox Preview for Android doesn't support add-ons. I imagine the title is just to emphasis that add-ons such as uBlock Origin work with this nightly.
kevinslashslash··on Google Kills Cloud Print
And Apple bought NeXT which is what macOS and iOS are based off of. A purity contest of "from scratch" isn't really relevant. Google clearly put, and continues to put, a lot of serious technical work into Chrome and Android which is reflected in their success.
kevinslashslash··on Google Announces .new Domain Availability
Well yes but also they forgot about gmail. It requires @google.com not @gmail.com
kevinslashslash··on Beyond Meat and KFC partner to test fried plant-based ‘chicken’
Because "red curry with tofu" is just called "red curry with tofu", not "vegan red curry with tofu". Same with chana masala, hummus and veggie sandwich, pasta marinara, etc. But a hamburger, "chicken nuggets", etc very much needs the "vegan" prefix to make it clear what it is, so you end up associating the word with the meat substitutes. But that doesn't mean American vegetarians only eat things that have the word vegan/vegetarian in the label.

Similarly, "gluten-free" is associated with breads, pastas, etc. Not rice or other non-imitation products.

kevinslashslash··on An oral history of the AIM away message
I had a similar experience. A friend gave me a free shell account so I built a little battle.net chat bot in Perl. Later I branched out into AIM bots, one had jokes/fortune but also a student directory (commandeered from a school server with lax security). The other would sign on like 60 different accounts and on my command mass message someone, it'd crash some versions of AOL and just be a real annoyance for AIM users.

The Perl library was `Net::AIM::TOC` and later `Net::OSCAR`

kevinslashslash··on An oral history of the AIM away message
I remember sending people a link to change their buddy icon
kevinslashslash··on Jony Ive to form independent design company with Apple as client
Not OP, but I believe he's talking about how the iPhone's large notch size is due to additional hardware used by face id. Having that size notch on the left/right side wouldn't be much better than in the center. Personally, I'd rather use my fingerprint anyway.
kevinslashslash··on iPadOS
Gingerbread, Android 2.3, was released December 2010 for phones.

Honeycomb, Android 3.0, was released Feb 2011 for tablets. It was a radical new UI and introduced several new APIs. It was the largest Android update ever, except that no devices were updated to it. Android tablets didn't sell very well and developers had little to no reason to support Honeycomb.

Ice Cream Sandwich, Android 4.0, October 2011. This refined the Honeycomb changes and was appropriate for use on phones. It did work on tablets but wasn't really optimized for them until 4.1/jellybean.

Honeycomb wasn't a fork or anything, but the strong divergence and poor sales of Android tablets meant that no one wanted to target Honeycomb until they were actually targeting Ice Cream Sandwich, and then at that point it was barely worth supporting Honeycomb tablets, but still work supporting Gingerbread phones.

I don't think it's particular relevant to the iPadOS situation.

kevinslashslash··on Public Sans – A strong, neutral typeface for text or display
It's a fork of https://github.com/impallari/Libre-Franklin so it'd be a bit against the spirit of things (if even legally permitted) to relicense it to a non-free license. It'd also limit the US taxpayers who wanted to use it in ways that required the full freedom to share with not US taxpayers.
kevinslashslash··on Meat-free 'Impossible Burger 2.0' tastes even closer to the real deal
Why don't animal eaters want to eat something that looks like an animal? Meat does not get a monopoly on being a blob of brown stuff
kevinslashslash··on The Chicago Express Loop
I really hope they change the name. Chicago already has a loop affectionally called "The Loop". This Boring system is really point to point anyway, it's just the skates don't stop or reverse at the stations, they make a u turn.
kevinslashslash··on A Milk Startup Takes on 300M Cows
Veal is a byproduct of dairy
kevinslashslash··on Rise of Kotlin: A Programming Language for the Next Generation
My guesses would be handling unsigned hex https://youtrack.jetbrains.com/issue/KT-4749

And bitwise operations https://discuss.kotlinlang.org/t/when-does-bit-fiddling-come...

And maybe handling generics. I haven't had any issues, but kotlin is a bit stricter which is generally a good thing, but I'd believe that for some edge case it makes things harder.

kevinslashslash··on A Stampede of Meatless Products Overrun Grocery Store Meat Cases
> produced by females of various mammalian species only.

Like coconuts

kevinslashslash··on Discussion if Google Fonts is GDPR compliant
https://support.google.com/accounts/answer/3118687?visit_id=...
kevinslashslash··on Susan Kare designed the suite of icons that made the Macintosh revolutionary
I got the impression that the dogcow was essentially a mistake, like stretching 4:3 to 16:9. The changes were intentionally (and manually) done to better fit with Page Setup, but it not intended to look like a cow or dogcow hybrid. I don't have any sources though, just something I think I read many years ago.
kevinslashslash··on Google thinks the sun is 15.81 light years from earth
My son likes to ask our Google Home the distance to different planets. The numbers, though generally technically correct (sun has worked in the past), are misleading as some are minimum, some average distance and some maximum.

For example "distance to mars" says 54.6 million km, which is the theoretical minimum. "distance to venus" says 261 million km which is maximum. I believe it was Jupiter that previously gave an average distance but now I'm seeing minimum.