HNHacker News
TopNewBestAskShowJobs

lawfulcactus

53 karma · joined April 25, 2019

[ my public key: https://keybase.io/lawabidingcactus; my proof: https://keybase.io/lawabidingcactus/sigs/1lvRvLit7ABIq-tFsrzUjGL-8SWHzBecaWpLwMHfUqE ]

PGP fingerprint: 09396E67CCFD945008A4C4B491403AC0BF58F1C6

submissionscomments
lawfulcactus··on [dead]
Statuspage isn't currently up-to-date; see downdetector[0].

[0] https://downdetector.com/status/shopify

lawfulcactus··on Intel accused by workers of prioritizing chip output over safety
Do you have any data to back this up? I should hope people would be embarrassed to post wildly unsubstantiated nonsense under a username linked to them.
lawfulcactus··on U.S. Postal Workers Were on the Front Lines Before. They Were Ignored
It's a random individual's approximation of the value added by their status as a government agency; and no, we patently /don't/ pay for it through taxes (unless you count subsidized borrowing, but that wasn't the original claim and it's more than a little nitpick-y).
lawfulcactus··on U.S. Postal Workers Were on the Front Lines Before. They Were Ignored
> Laws that bar any other shipping service from delivering mail and packages directly to residential and business mailboxes. Shapiro estimates that this gives the Post Office a $14 billion annual boost, more than three times what the Postal Regulatory Commission estimates it to be.

> Tax breaks. The Post Office is exempt from state and local property and real estate taxes, along with other burdens like tolls, vehicle registration fees, and parking tickets. These exemptions save the USPS $2.18 billion per year.

> Cheap borrowing. [...] It currently borrows the legal limit of $15.2 billion at a rate of 1.2%. Without this access, it would be paying somewhere between $415 million and $490 million per year more in interest.

> Finally, Shapiro points out that the USPS pays its workers salaries and benefits far above the rates paid to similar workers in the private sector.

From the article; it's not a /literal/ taxpayer-funded subsidy.

Also, since that link is paywalled: https://web.archive.org/web/20200411145708/https://fortune.c...

lawfulcactus··on The SeL4 Foundation: What and Why
So, I think what you're missing here is that the 'verification' is a formal specification about the behavior of the kernel, along with a set of proofs about that specification. This is vastly simplified (there are multiple levels of specification, last I checked), but that's the general idea. It's possible to have your compiler automatically derive the specification from your code (and, indeed, the seL4 people have written a Rust-like language called Cogent that does this), but formal verification inherently involves an understanding of what your code is /intended/ to do, and proving that it /does/. The compiler only has information about what it /does/, so it can only generate a specification that describes this. Information about your high-level intentions for the code has to be concretized somewhere, while ensuring that the spec conforms to it-- that's the job of the proof engineers.
lawfulcactus··on ISH: An Alpine Linux Shell on iOS
...why? If you don't like it, just don't install it. Not sure why you feel the need to ruin it for everyone else.
lawfulcactus··on One man lost his life savings in a SIM hack, you can try to protect yourself
From Wikipedia[0]:

> A medallion signature guarantee is a guarantee by the transferring financial institution that the signature is genuine and the financial institution accepts liability for any forgery.

[0] https://en.m.wikipedia.org/wiki/Medallion_signature_guarante...

lawfulcactus··on The 'Race to 5G' Is Lobbyist Nonsense
You're effectively talking about APRS[1].

[1] http://www.aprs.org

lawfulcactus··on Dark Horse Discord
I use a weechat relay over websockets (via nginx). It's a pretty convenient solution to the whole "my corporate firewall thinks I'm part of a botnet" issue (in addition to giving you channel history persistence).
lawfulcactus··on Brave Isn't Bad
> they put a Tor client in the default distribution

Something that Mozilla is also doing[0], albeit with significantly more attention paid to the privacy-minded patches to Firefox made by the Tor Project. The end goal is to mainline these patches, such that Firefox gains the same privacy properties as the former-- they're working with the Tor team on this. If I wanted to use Firefox to access the Tor network, I'd just start a client locally and have the browser proxy traffic through it. Tor Browser's anti-fingerprinting measures are half the reason it's useful.

It's half-baked "features" like this that turn me away from Brave; there's this feeling that it's marketed towards the sort of well-meaning crowd that won't know the difference between "Tor tabs" and Tor Browser. This isn't a bad thing; rather, it's the misleading material surrounding such features published by the developers. Just look at the relevant page[1]; there's just a vague mention near the end of the article about using Tor Browser if you need "leakproof privacy", and the rest of the page carefully tiptoes around the fact that this really only prevents websites from knowing your IP address (and likely not even that, considering the similar fingerprinting properties of normal tabs and Tor tabs).

Excerpt:

"Also, web destinations can no longer easily identify or track a user arriving via Brave’s Private Tabs with Tor by means of their IP address."

To non-technical users, this reads more like "Brave (with Tor tabs) prevents websites from knowing who you are". It's lawyer-y, if that makes sense-- the whole thing just rubs me the wrong way. This is, of course, assuming said users even read the linked post; most will probably see 'Tor' and draw the relevant conclusions.

> even if the browser does not implement some of the anti-fingerprinting measures that Tor browser does

It's laughably easy to fingerprint Brave browser users, even compared to Firefox and its rather basic fingerprinting protections (at the moment). Though this is likely because Brave has a far smaller userbase.

[0] https://wiki.mozilla.org/Security/Tor_Uplift

[1] https://brave.com/tor-tabs-beta/

lawfulcactus··on Hard Problems in Cryptocurrency: Five Years Later
How are participants prevented from simply splitting up their stakes?
lawfulcactus··on We are making Sandboxie a free tool, with plans to transition it to open source
SELinux's sandbox[1] tool works pretty well for isolating GUI applications (with -X). [1] https://linux.die.net/man/8/sandbox
lawfulcactus··on A cartoon intro to DNS over HTTPS (2018)
Tor also gives you the option to use a variety of pluggable transports, which are purpose-built to circumvent DPI boxes and such. Pretty sure obfs4 (based on [1]) works against the GFW.

[1] https://www.cs.kau.se/philwint/scramblesuit/wpes2013.pdf

lawfulcactus··on Dear Stack Exchange, Inc.
The ratio of value (or entertainment) provided to oneself versus value provided to another entity clearly differs significantly between a user of a site and an (unpaid) moderator of it.
lawfulcactus··on Apple suspends Siri response grading in response to privacy concerns
while I might be an uninteresting target, this doesn’t mean others are not

And though you might be an uninteresting target now, there's no guarantee that will be the case in the future. The sorts of personal information people would like to keep private change with the society around them, and generally speaking, it's not possible to retroactively conceal information.

lawfulcactus··on My Last Macbook Pro
I've had a great experience with my 6th gen Thinkpad X1 Carbon. All its hardware is fairly standard and well-supported-- I haven't found anything it doesn't work with yet (I ran OpenBSD on it for a while). Keyboard is great, too, despite the thinness.
lawfulcactus··on The Backbone of VHF Amateur Radio May Be Under Threat
>JT8, etc, have reduced "contacts" to a few bytes

I think you mixed up FT8 and JS8 there. :)

FT8 is the (effectively) zero-interaction DX mode. JS8 exactly the opposite-- a weak signal mode based on FT8 tailored for ragchewing.

lawfulcactus··on Gmail confidential mode is not secure or private
It's worth mentioning that all these measures can be fairly trivially defeated by the analog loophole[1]. I suppose it's harder to prove authenticity in that case, however.

https://en.wikipedia.org/wiki/Analog_loophole

lawfulcactus··on Ask HN: Does anyone still use IRC?
##security and ##ibmthinkpad are my personal favorites. They don't take themselves too seriously (as in, you're allowed to get off-topic), but can be super helpful when needed. The wealth of knowledge combined with the general lightheartedness is refreshing.
lawfulcactus··on Launch HN: Termius (YC W19) – SSH client that works on desktop and mobile
If you're looking for a polished mobile SSH client without a subscription model, you might be interested in Blink[1]. It's worth mentioning that in addition to SSH, it also supports Mosh[2] (it's the official iOS client!), a remote access protocol tailored to handle spotty mobile connections. It's also open source[3] and gives you access to several Unix commands offline.

[1] https://www.blink.sh/

[2] https://mosh.org

[3] https://github.com/blinksh/blink

lawfulcactus··on “Apps intended for kids may not include third-party advertising or analytics”
Well, there's Youtube Kids: https://www.youtube.com/kids/

And on iOS, you can use Guided Access to keep them in the app. Not sure about Android.

lawfulcactus··on MuseNet
Can you explain? I'm not an expert on ML by any stretch of the imagination, but you'd think with the sort of stringent logical coherence required to construct useful programs, it'd be a pretty subpar use case. Or do you mean smaller-scope tools to aid programming, like linters and autocompleters?