HNHacker News
TopNewBestAskShowJobs

koolhaas

122 karma · joined March 7, 2021

submissionscomments
koolhaas··on Poka Yoke
Sure, some Linux distros (or is it MacOS?) ask for confirmation before executing `rm -rf /`, which breaks the typical UX of the command but prevents bad mistakes.
koolhaas··on A catalog of naturally occurring images whose Apple NeuralHash is identical
The Technical Summary uses "visual derivative" without clarification, but their Threat Model PDF clarifies it further as thumbnails:

>The decrypted vouchers allow Apple servers to access a visual derivative – such as a low-resolution version – of each matching image.

https://www.apple.com/child-safety/pdf/Security_Threat_Model...

koolhaas··on A catalog of naturally occurring images whose Apple NeuralHash is identical
Fascinating, thanks for clarifying.
koolhaas··on A catalog of naturally occurring images whose Apple NeuralHash is identical
Of course, but it's a kind of last resort thing to support a valid legal process they cannot (and probably don't want to) skirt around. They also publish data on warrant requests.

To me it's pretty clear they are doing the absolute minimum possible to keep congress from regulating them into a corner, where they lose decision making control around their own privacy standards. The system they came up with is their answer for doing it in the most privacy conscious way (e.g. not decrypting user data in icloud) while balancing a lot of other threat model details, like what if CSAM-hash-providing organizations provide img hashes for a burning American flag, and lots of other scenarios outlined in the white paper.

koolhaas··on A catalog of naturally occurring images whose Apple NeuralHash is identical
Yes I agree, bit of a stretch. Based on their whitepaper, it's a smaller version of the original image, I guess just large enough to support the human verification step.

But I'm unsure that the thumbnail is included with every CSAM "voucher" -- it's likely only included when you pass the 30 image limit. Need to read that section more clearly.

koolhaas··on A catalog of naturally occurring images whose Apple NeuralHash is identical
Presumably, it’s done this way so they can say computers other than your personal device do not scan photos and “look” at decrypted and potentially innocent photos. And technically the original image is never decrypted in iCloud by Apple - if 30 images are flagged they are then able to decrypt the CSAM scan meta data which contains resized thumbnails, for confirmation.

In summary, I’m guessing they tried to invent a way where their server software never has to decrypt and analyze original photos, so they stay encrypted at rest.

koolhaas··on Man steals 620k photos from iCloud accounts from home without Apple noticing
I think it’s context dependent, just like other uses of the word steal. With copyright infringement, internet communities have come to agreement that it is not stealing, so avoiding the use of the word in that context is important. In baseball it’s not, and neither with identity theft. With illegally obtained private photos, never intended to be shared or released to the world, is there a better word? It’s such a different scenario, the only similarity I see is both involve files on a computer.
koolhaas··on Man steals 620k photos from iCloud accounts from home without Apple noticing
What word do you use when someone unrightfully gains possession of something that isn’t theirs?

Btw a lot of words in English have multiple meanings, and transform meaning over time, which can be confusing sometimes. For example, in baseball you steal a base, which was being protected by the other team, but you don’t remove the base from the field and run off with it.

I think steal works better than copy here, more accurately conveying meaning and intention, and unjust access.

koolhaas··on Apple’s crackdown on multicast
2023 Q1: each TLD you make web requests to will need individual human moderated entitlements.
koolhaas··on Apple’s crackdown on multicast
Wait, even to develop/test on your own device, without releasing, you need to fill out the form?
koolhaas··on The only skin care that works? science video response (2020)
Science supports that the sun really damages your skin, so you should absolutely use a sunscreen or SPF 30 moisturizer every morning.

Digging deeper into types of ingredients that block sun, things get a bit more tricky. In general I’ve read dermatologists say “physical” sun screen ingredients are best, like zinc oxide, because they aren’t absorbed through your skin like a “chemical” ingredient. But they also leave your skin looking more white.

And beyond that, just wash your face in the morning and night with a face wash product, not bar soap. Something simple from Neutrogena (Liquid Neutrogena).

koolhaas··on Deno on MDN
Thanks for the response. And thank you for clarifying that there is a larger ecosystem of package repositories, and that Deno does not give preferential treatment to any. In theory npm can do the same, but of course there is official support and community gravitational pull around a single service.

I agree there is nothing fundamentally less secure in general, but what you don’t get is being able to standardize around security for dev account protection, policies around immutability, DNS stuff, and some other centralized security measures. Neither are bullet proof, but there are some things you can’t protect against with random URLs.

I’d argue URLs are fine until you get massive use of a single package and it weaves itself into a complex dependency tree across multiple other critical projects. Then you worry about the what if’s.

koolhaas··on Deno on MDN
I would say, it doesn’t really fix npm. It has its own centralized npm repo, called deno land, and it’s own package.json, called deps.ts.

Because it can accept any URL as a dep in the source files, you can in theory do some cuter, weirder things with it. But security wise I’d argue arbitrary URLs, for critical, high traffic deps, are harder to fix when bad things happen, without centralized control.

koolhaas··on A dubious writing style emerging in science
>“ant colony” -> ”underground creepy crawly settlement”

Wow, and it passed peer review.

koolhaas··on An Open Letter Against Apple's Privacy-Invasive Content Scanning Technology
> Apple has always been able to scan iCloud and send your data to police

I don’t see how the article you linked to explains how Apple can “scan iCloud” for the police. What do you mean? It seems like they just hand data over for a specific warrant related to individual users.

koolhaas··on Folk wisdom on visual programming
I’d be curious to hear you elaborate on the singular/many things point. Trying to understand which deficiency you are pointing out.
koolhaas··on Folk wisdom on visual programming
Flow paradigm doesn’t claim scale though. It’s about being a DSL for specific environments, often visually-oriented software like CAD or interactive art, which doesn’t have heavy 10K person team requirements.
koolhaas··on Folk wisdom on visual programming
> Data generated by a node "flows" to the other nodes it is connected to and when any node has data on all it's inputs, it executes and produces data which flows to whatever nodes it's connected to.

I think you just described flow programming. There are at least 10+ visual languages / environments that work like this.

koolhaas··on Folk wisdom on visual programming
Side note: interactive debugging is kinda inherent with the flow based programming paradigm. The program is continuously executing with every new action and immediately reflecting the current state. To program with it is to debug. If there’s an error with a component, it turns red and everything down stream breaks as well.
koolhaas··on Folk wisdom on visual programming
> But why did we bring it forward in the first place?

Speculation: visual programming is a bit more beginner friendly, and more compatible with the brains of people designing stuff in UE. I wish blueprint was around when I was 13, messing around in UT’s version of UE and having no idea what unreal script could do. Visual language can break out all possible components into UI menus, just like everything else in UE. Visual oriented people really click with tools like visual programming.

Personally I think it’s cynical / arbitrary to pin the decision to corporate power struggles. Sometimes people propose new things out of interest or as a side project and then it grows from there.

koolhaas··on GitHub Copilot
I would change your question from “does it have any real benefits” to “does it have a practical effect on the model”

Benefits to me are clear: giving a developer choice over how their source code is used with for-profit, opaque, next generation ML models.

But yes, drop in the ocean in terms of the full data set. But that shouldn’t be an excuse to remove user choice.

koolhaas··on Bring back menus, QR codes are terrible
My preferred combo: QR code at the table for menu browsing. Order with a human. Then QR code on the bill to (optionally) pay on your phone, ideally with Apple Pay. But you have the option still to leave out your CC for a more leisurely payment flow.
koolhaas··on Ask HN: What Are You Learning?
- car maintenance, via ChrisFix

- how to fix my xaomi m365 battery

- Japanese

- basics of koi ponds, for a gift to my mother in law

- cooking with a instant pot

- ayurveda

koolhaas··on Are the Rich Gaslighting Us When They Donate Billions to Charity?
Gaslighting has been collectively redefined to “when someone says or does something which evokes emotions inside me in the case where I generally dislike that person”
koolhaas··on Show HN: 3dasd – open-source DIY room-scale 3D scanner
Awesome work!

How long does it take to scan a room? And when scanning something like an apartment with multiple scans, how do you piece them together / automatically offset the points collected in the next scan?

koolhaas··on Reddit.com Service Unavailable
Even amazon.com homepage has no CSS right now!
koolhaas··on LOL just got kicked out of @ycombinator
Essentially yes. Once you get the first, you are scheduled for the 2nd, and aren’t questioned (and really, it’s all very honor system anyways).

Early in vaccination, I believe sites were reserving 2nd doses for everyone who got the first. Then production became predictable enough where cdc instructed sites to not reserve in favor of increasing vaccine rates. Then sites always prioritized people returning for 2nd doses (internally, or through scheduling systems)

koolhaas··on LOL just got kicked out of @ycombinator
> I’d feel guilty, but it’s hard for me to get upset about other people skipping the line

Same. I’m not upset, just wanted to walk through what goes through my head personally.

> And in public policy, the long game is always the important one

This is a key point. The policy did its job. Old and weakened people got their shots, line skippers are a blip on the radar. But maybe it worked because most people played their role and held back tiny personal infractions for the greater good.

> I mean, if politicians and VCs and the elite all want it ASAP, maybe it’s safe for almost everyone?

I think that is very theoretical psychoanalysis, but if it’s what people tell themselves to get that early jab, sure. In the end, this is an unprecedented global crisis and people are either going to fall in line or act in ways that help them cope with uncertainty and anxiety.

koolhaas··on LOL just got kicked out of @ycombinator
I would feel guilt if me waiting in line before becoming eligible resulted in another person being turned away at a busy vaccine site - even if I didn’t have to technically lie about my eligibility.

Even if I’m iffy on the morality now, I don’t want to look back 20 years later as a different person, thinking about how, as a healthy young person, I cut in front of the eligible.

Would that person who was turned away because of me get a shot the next day, or the next? Probably. It’s just principles for me, like a personal code. The morality is debatable, everyone is different.

There’s something nice too about working cooperatively with an entire country at a unique time in history, and helping the less fortunate by simply following the rules as best you can as a non-essential individual.

My 2 cents

koolhaas··on LOL just got kicked out of @ycombinator
Did the church site have to turn away elderly people, or other people who cleared CA guidelines, at the end of each day?
Page 1 of 2Next →