HNHacker News
TopNewBestAskShowJobs

larma

422 karma · joined May 29, 2015

submissionscomments
larma··on Inside continues to bet on email, the “largest social network”
Just to be precise: Google and Facebook did not shut down their xmpp servers, they just disabled the ability to connect to them via xmpp clients, to make sure everyone uses their web clients, so they don't loose any data they could've collected otherwise...

The original Google Talk ifnrastructure is still up and running and clients can connect to it using a protocol derived from XMPP (basically a subset XMPP converted to protobuf) and use it to message devices (Android uses it push messaging, but technically you can also send messages directly between devices). It's not directly used for text messaging though.

larma··on Why OpenBazaar Token Doesn’t Exist
-> http://doyouneedablockchain.com
larma··on Ligatures in programming fonts
*Unless all people that might ever look at my screen are used to them.

If you work with people over the internet, it doesn't matter because they can disable ligatures and still read your code. And obviously it's not a problem if people know them and are looking on your screen.

But yeah, if you're doing pair programming and first dev is used to them and the second dev is not, that's a problem. The question is, is the solution that the second dev learns them or that the first dev stops using them - both will obviously dislike changing the way they like to code...

larma··on Ligatures in programming fonts
Correct syntax highlighting is subjective, because color selection is a matter of taste.
larma··on European Commission fines Google €2.42B for abusing dominance
I think it really depends on the product (e.g. having Google Maps integrated is not a bad idea, because that's what you usually want to access if you enter a address in Google).

But honestly, I don't know anyone that is happy with the Google Products service in Germany. They don't even show links to Amazon here, although they often have the best total price (because of free shipping). I even know a lot of people that go directly to Amazon or a price comparison site because the results presented by Google are so crappy.

As results might be different based on country, region and cookie, here is a screenshot comparing idealo (a large price comparison site) with Google Product search (I just picked this specific product randomly): http://imgur.com/a/MByay

larma··on Google's response to the European Commission fine
> our data show that people usually prefer links that take them directly to the products they want, not to websites where they have to repeat their searches.

If you would link them correctly, there wouldn't need to search again, but would be on the search results of that other site with their (usually better) results.

Also, considering that product search results are sponsored, usually the top results at product search are crap. There are three things that people usually prefer links to when they search for a product: 1. High quality product information - that's usually the website of the manufacturer. Amazon is not too bad in some cases but smaller retailers usually lack a lot of useful information. 2. Best offer - when you pay for being a top result on Google product search, then it's hard to claim you will be able to provide the best price. 3. Buyers feedback - sites that are larger usually have more prior buyers and thus more feedback. Google's very own ratings (which the scrape from other sites that allow them I guess) is usually crap compared to what you find on Amazon.

So basically, if Google would want to provide actual useful search results, this would just be a link to the manufacturers marketing site, a link to the best offer and/or the result page of a price-comparison site, and a link to Amazon and/or comparably large local retailers. Results based on who payed most is not what people usually want, don't try to argue that this is true.

larma··on Ask HN: Has Duckduckgo gotten worse recently?
I guess the problem only occurs with the lite version? At least for me, removing the /lite/ part in the URL results in far more results.
larma··on Show HN: A Browser-based Blockchain
re PoW: https://github.com/nimiq-network/core/issues/38
larma··on Show HN: A Browser-based Blockchain
On the bottom of the website it says: "Nimiq is an Inuit word used for an object or a force which binds things together."
larma··on Show HN: A Browser-based Blockchain
This is related to your local network. You will only be able to use Websockets for connections (which most nodes do not support) and not WebRTC. Go and fix your network, you likely have some UDP or NAT configuration issue (or a terrible ISP).
larma··on Show HN: A Browser-based Blockchain
I think the disclaimer was pretty obvious with this.
larma··on Show HN: A Browser-based Blockchain
Coins are out.
larma··on Show HN: A Browser-based Blockchain
Your Transaction is on the way.
larma··on Show HN: A Browser-based Blockchain
Done.
larma··on Show HN: A Browser-based Blockchain
11.11 is pending.
larma··on Show HN: A Browser-based Blockchain
13.37 sent from 0F25D122922E466F6A412DD0DC5E092DF13FF037
larma··on Show HN: A Browser-based Blockchain
Just ask here if you need some test coins. I already mined a first block.
larma··on Cloak and dagger – a new kind of attacks for Android
Everything but the info about apps becoming the permission granted automatically by Play Store was already used by malware over a year ago.

https://www.skycure.com/blog/accessibility-clickjacking/

larma··on Cloak and dagger – a new kind of attacks for Android
You can use onTouchEvent even when not receiving taps.
larma··on 21 XMPP use-cases and the best ways to achieve them
Is GNU compatible and thus can run on all platforms (e.g. Windows via MinGW). Some features might require special handling for Windows / OS X (GPG, Audio/Video) and Linux is for now the "official" target platform...
larma··on White House Open Data Unavailable
Apparently they changed the software used to store the data, in the bottom on https://open.obamawhitehouse.archives.gov/ it says "powered by dkan", on https://open.whitehouse.gov/ it says "powered by socrata". Maybe it was not easily possible to migrate the data and/or it is planned to be done later.
larma··on About backdoors in crypto messengers
> someone controlled by Google

Manufacturers that ship GMS are not controlled by Google. I think you don't know a lot about how to apply for GMS integration, it's as easy as filling a form and passing the CTS (compatibility test suite).

Google is providing some non-free files (basically apps and libraries, all sandboxed) and configuration files to manufacturers that they apply on top of AOSP (or possible extensions they did). The only way for Google to break out of the sandbox is to make a backdoor in the AOSP code, that is openly available for review.

To repeat what I said to the other guy here: If you are not on a Nexus or Pixel device, Google is UNABLE to look into private app data of third-party apps (if they correctly configure the backup feature). This is possible with Signal only due to the mentioned "backdoor", making this an important issue.

You are however right that the manufacturer(s) might be able to look into app's private data, but that's another issue (especially as most manufacturers are non-US companies).

larma··on About backdoors in crypto messengers
Signal is told to be a secure crypto messenger everyone can use. This means that people are installing it on a usual Android device and assume that nobody is able to read their messages without physical access.

Of course you are right, there are many black boxes in most mobile devices. But does this mean we shouldn't care about any of them? Most of these black boxes are not updated on a regular basis or the update requires user consent. This means that, if they don't allow arbitrary code execution now, it is hard to make them do evil things.

The mentioned issue with Google Maps integration (leave the GCM problems aside) however is a real possibility to silently drive targeted attacks on Signal - it's actually damn easy for Google to do this. If we'd be doing a proper analysis on all other black boxes (processor, modem, manufacturer extensions, etc), I doubt we'll find such kind of backdoors in most of them. And if I will find such a thing, be sure I'll be writing about it as well.

This backdoor is important for those that want to securely communicate and their adversary is for example the US gov. e.g. the next Snowden. Google can be forced by US agencies to use this backdoor and this renders Signal unusable for them. These people should know about the backdoor. If you know and don't care, that's your problem...

larma··on About backdoors in crypto messengers
On Pixel and Nexus, yes. for every other device it would require coop with the device manufacturer: they build the open-source code (+ their own proprietary extensions), add google apps and libraries (that are sandboxed) and sign the build. Only they have the private keys to provide updates, Google does not have full device access.
larma··on About backdoors in crypto messengers
No, see https://news.ycombinator.com/item?id=13435152
larma··on About backdoors in crypto messengers
Even with stock Android, on devices != Pixel or Nexus, Google parts are sandboxed in a way making it hard for them to access private app data. The only way would be to deliver a different app through play store which is easy to discover as it breaks the cryptographic signature and must be done on first install (android uses TOFU).

So without the mentioned issues through Play Services and Gboard, Google would not be able to access your Signal messages. On Stock Nexus/Pixel builds they can of course push updates that change this...

larma··on About backdoors in crypto messengers
http://webcache.googleusercontent.com/search?q=cache:OSLZXIu... works for me (better use text only version as Google tries to load css from the server apparently)
larma··on Ask HN: With the death of Cyanogen, what options exist for a Free phone?
Cyanogen OS was not free, neither was CyanogenMod.

The Fairphone 2 has an official, monthly updated system that is mostly (beside firmware and other Qualcomm shit) free software. You can install it optionally, search for Fairphone Open OS.

larma··on WikiLeaks and NSA committee: document could reveal informants
The document package contained a document not available to the NSA commission but to some foreign affairs commission. Only very few people have access to documents of both commissions.

The more interesting part is: this leak was completely useless. Although the documents are not for the public, they're also not rated as a secret. This means that every politician with access is allowed to tell the press about it, only publishing is not allowed. As we have a useful opposition in Germany there was nothing new in the documents...

larma··on MicroG Project: A re-implementation of Google's Android apps and libraries
already there and heavily relying on EU software directive 2009/24/EC :)
← PreviousPage 2 of 3Next →