HNHacker News
TopNewBestAskShowJobs

nobodyorother

311 karma · joined February 23, 2017

submissionscomments
nobodyorother··on Fearless Concurrency in Firefox Quantum
My kingdom for Tab Groups! https://addons.mozilla.org/en-US/firefox/addon/tab-groups-pa...
nobodyorother··on Equifax CEO to Congress: Not Sure We Are Encrypting Data
I just use double-ROT-13 as my TPM, that way I can invoke the DMCA too!
nobodyorother··on Everyone will have 5 years to get their car off the road or sell it for scrap
> The end state will be the fully autonomous module with no capability for the driver to exercise command. You will call for it, it will arrive at your location, you'll get in, input your destination and go to the freeway.

Except it won't. You'll go to three Sponsored Locations that offer similar, but not quite the same, services as the destination you selected, while the windows are used as projection screens for advertisements related to your destination and locations you're passing.

- Me: "Take me to Central Park."

- Car: "I'm sorry Tom, I can't let you do that. Going to MOMA, the New Museum, and Battery Park."

- Car: "We'll be passing a Wendy's restaurant momentarily. Did you want to stop to pick up some chicken nuggets or a tasty hamburger? I can offer you a 2 for 1 deal expiring in 5... 4... 3..."

- Me: "We were just planning on pizza, thanks."

- Car: "A $2 non-subsidized convenience fee will be added to your total."

This is my hell.

nobodyorother··on Paradise Papers: Dear Tim Cook
But they aren't, not even in Delaware. That's a common misconception that greedy folks love to spread.
nobodyorother··on Paradise Papers: Dear Tim Cook
What is Apple's effective tax-rate, world-wide (for, e.g., 2016)? I've not seen this spelled out anywhere, yet.
nobodyorother··on AntiX 17, a Linux Distribution Without Systemd, Is Released
Found the bug! Seems like the new behavior is non-compromisable, but keszybz and pottering both put forward potential solutions that leave everybody happy(?), but that haven't been acted on since July. So, there was some compromise between the requestors and developers, just not in the places I expected to find it in the bug report.

https://github.com/systemd/systemd/issues/5755

nobodyorother··on Exploring Previously Unknown Remote Kernel Bugs Affecting Android Phones
I hope it's Google's bug bounty program that's paying off.
nobodyorother··on AntiX 17, a Linux Distribution Without Systemd, Is Released
Essentially: https://xkcd.com/1172/

It's great that they're making systemd, but if it doesn't work for you, it won't. (Rephrasing a Github bug I read a while back) systemd seems set on replacing the existing software stack with software that works for its creators, without regard to established historical standards of behavior.

For example (in the GH bug), folks using systemd for networking can't necessarily connect to intranet sites, because systemd doesn't keep historical behavior: it doesn't try all the DNS servers you've provided for each request. Instead, it always connects to whichever DNS server hasn't failed most recently. That's faster, that's good.

If you needed systemd to connect to your local DNS server to resolve intranet names like http://myreports/, and 8.8.8.8 to resolve external names, that would work fine... Until the local server took too long to respond to one request. Then, all future DNS requests would go to 8.8.8.8, effectively blackholing your intranet. That's broken, that's bad.

The resolution supplied in that bug, IIRC, was users shouldn't do it that way. So, the resolution appeared to be that the user should've been hired as the network administrator instead of their current job. Maybe it's been fixed some other way since then? Please correct me if so!

Sure, systemd might be faster, but faster isn't better than working-as-expected.

nobodyorother··on Appeals court rejects petition for rehearing in podcast patent case
Incinerate, rupture, enervate, deconstitute, liquefy, melt, vaporize, expurgate (maybe), evanesce, squidify, particulate (particulize?), atomize, gluonification, skeletonize, exsanguinate, devertibraification, and maybe even defenestrate.

Those are just the ones off the top of my head, I'm sure we can come up with more. Regardless of the verbage, the EFF deserves a pat on the back (and my recurring donation).

nobodyorother··on What Are the Most Disliked Programming Languages?
The ":" implies bidirectionality (or at least, non-directionality), you could clarify it in the graph by replacing ":" with "dislikes" or "->".
nobodyorother··on The New York Times Is Now Available as a Tor Onion Service
As of last weekend, NYT-over-onion serves ads like their other entry points do.
nobodyorother··on The New York Times Is Now Available as a Tor Onion Service
%6EY YcfI Yu0` *lAS B4k< GonA 9ZZ+ 02(#
nobodyorother··on The New York Times Is Now Available as a Tor Onion Service
Could you thank the folks involved in this? The TOS is great news.
nobodyorother··on The New York Times Is Now Available as a Tor Onion Service
Nope, I got promoted to Wall St., 5th floor! Just leave it unattended in the Blue Room, by the donuts, and I'll pick it up in a few.
nobodyorother··on The New York Times Is Now Available as a Tor Onion Service
You don't need anything that isn't already publicly available: see every security bug reported on the mailing list, and reliable hop tracing via coordinated parties recording traffic (Tor's version of Bitcoin's 51% problem).

That said, it's still the most reliable limited-anonymity provider I know of.

nobodyorother··on The New York Times Is Now Available as a Tor Onion Service
That's a clever question and the answer has a few parts, mostly due to the slipperiness of "trust" as a concept: I wasn't specific enough in my description of my own threat model (which makes sense, as my aim wasn't to explain the threat model but to cultivate answers from other folks). In short, I currently only have access to systems that are too costly to replace, if the site is under active attack. That's not to say that HN's comment section isn't also a risk, but it seems less of one.

I considered these actors before deciding to ask the question instead of immediately connecting directly: available computer systems, internet pipes, the NYT website, and the bevy of third party ad-services hosted through the website.

nobodyorother··on The New York Times Is Now Available as a Tor Onion Service
I was asking because I'm currently nowhere near a system that I'd trust for this purpose. I'll be near one later and, if you're interested, I'll update the question with my findings.
nobodyorother··on The New York Times Is Now Available as a Tor Onion Service
Not all entry points do the most paranoid thing, and not options are even available on all entry points.

The Tor Browser Bundle (desktop) has different defaults than Orfox (phone), and I think both will connect to non-onion URLs when connecting to an onion site. Same for JS, ad-block, etc.

nobodyorother··on Suicide Linux
Nuke-practice is why I only use tar these days.
nobodyorother··on The New York Times Is Now Available as a Tor Onion Service
Does the onion service still serve the same advertisements their website and mobile app do?

If so, they're leaving their users-who-want-to-stay-relatively-anonymous open to attack via the advertisement vector. Members of that group would be considered high-value targets simply due to their anonymity desires.

I can't see the number of daily users being large enough that they'd lose significant profit by closing that attack vector. Hell, if there was a way to pay NYT enough to disable ads on all their services, I'd do it.

nobodyorother··on Catalan parliament declares independence from Spain
Hey, that sounds like the sort of thing an indoctrinated othersider would say...
nobodyorother··on Monsanto Attacks Scientists After Studies Show Trouble for Its New Weedkiller
Arbitration clauses?
nobodyorother··on Managify – Content Management Platform for Projects, Notes, Bookmarks, Passwords
I actually like Magnify a lot better: focus on the things that matter.
nobodyorother··on Stealing Sensitive Browser Data with the W3C Ambient Light Sensor API
The obvious solution is not having an ambient light sensor API, or a much more granular one, like the battery API should've been.
nobodyorother··on The Mars company has sponsored hundreds of studies to show cocoa is good
What does 70 calories of chocolate weigh, and what's chocolate's LD50?

...What's the maximum number of heart-healthy flavanol doses?

nobodyorother··on It Takes Just $1k to Track Someone's Location with Mobile Ads
Is this an inevitable consequence of our society, or is there a way to actually do marketing ethically? What negative feedback loops actually apply strongly and over the long term to this behavior and creating these sorts of systems?

This is a pretty horrifying society we've built.

nobodyorother··on Infineon RSA Key Generation Issue
The next obvious question is "whose signature is worth more than €5k a month (until the Smartcard is updated and the old sig is revoked)?"
nobodyorother··on The /bin/true Command and Copyright (1990)
Imagine what a wonderful world it would be if someone took lawyers to task for every absurdity!
nobodyorother··on The /bin/true Command and Copyright (1990)
It's provided on the shirt itself (self-evident), so it should be fine to distribute copies of the shirt.
nobodyorother··on Symantec CEO says source code reviews by foreign states pose unacceptable risk
So they're basically admitting that their antivirus tools aren't secure enough to handle a basic code review?

Yup, totally makes me want to buy copies.

"No, guys, security by obscurity totally works in this one case! Because it's us! Come on, you trust us right?"

Page 1 of 4Next →