HNHacker News
TopNewBestAskShowJobs

notzorbo3

584 karma · joined February 4, 2016

submissionscomments
notzorbo3··on Cloudflare's new DNS attracting 'gigabits per second' of rubbish
The beauty of it is cases like Google's. They have this bizarre 2FA security-theater Google Authenticator thing, but then nearly force everyone to have their phonenumber as a "backup device".

Guess what the send you when you forget your 2FA or password? Yep, an SMS. So out the door goes the whole point of 2FA. Your three factors (account name / email address + password + Google Authenticator) have now been reduced to one factor: your email address.

I can rent a mobile tower in Malaysia or some other asian country, advertise your phonenumber as roaming there for about €10/h and start intercepting all your shit. Or just get your telco's inept service dept to forward your number somewhere else.

Lessons here:

1. Even the giants get it wrong. 2. There is no security anywhere in the tech world. Literally everything is broken. Your electronic car locks / starter system, your phone, your internet, everything is horribly horribly horribly broken beyond any imagining, even for hyper-tech savvy people. 3. Remove your phonenumber as a backup device from your google account and never use it as a backup device every again.

notzorbo3··on The Boys Are Not All Right
Those numbers are from 2009 through 2015. That's just cherry picking, because those years just happen to include Anders Breivik. I think its well established that the US is the market leader in mass shootings.

Edit: Also, the president of Crime Prevention Research Center is John Lott, who's a known gun rights advocate. Your source does not seem to be very impartial.

notzorbo3··on The Boys Are Not All Right
I agree with everything you said, however

> The more likely cause is the legal structure around gun ownership in the United States.

Gun ownership may be an enabler in mass shootings, but I don't believe it's the cause. Merely having a gun doesn't automatically make you a mass murderer. There are other underlying issues there. Not that that means the U.S. shouldn't do something about the legal structure around gun ownership. It's probably going to be much much harder to actually address the underlying cause.

notzorbo3··on The Fields Medal should return to its roots
> If you accept the idea that a penchant for math is randomly distributed among all people

That would seem rather detached from reality.

notzorbo3··on How did Google Talk change from a dream to a nightmare?
> A smartphone isnt required

It is for Whatsapp. Not only for sign-up, but actually all communication on the web version goes through the app running on your phone. The web "session" times out constantly, so I'd have to re-pair it with my phone all the time. If I still decided to use whatsapp.

notzorbo3··on The Kubernetes Effect
Because NATting encapsulates while routing doesn't? And encapsulation is the whole idea behind containers. Until everything is ready for IPv6 (lol, yeah right), NATting seems the only way to me.
notzorbo3··on GitHub giveth; Wikipedia taketh away
Does the author have any evidence that's it's typically white males?

Is the author implying that white males are to blame for draconic / legalistic Wikipedia?

Has the author proven that draconic wikipedia editting is a bad thing?

Does the author show, in a mere three words) that they're both racist and sexist? (answer: yes).

I like how the author negates the entire point of their article just by casually mentioning thier unproven, unfounded bias. This person's thoughts are not worth anybody's time.

notzorbo3··on Zerg: Boot a VM instance per request, all in under 250 ms
> Obviously no one would ever run something like this 1 vm per request thing irl.

I can see plenty of use-cases for doing just that. Large uploads, time-consuming request/responses such as server-side data processing, RPC, as a backend behind a caching front-end so that it only has to respond to invalidated cache entries, etc.

I don't see many people using this to actually serve general website requests though. It'd probably be modified to serve multiple requests until nothing is left to do and then exit.

notzorbo3··on Personal observations on the reliability of the Shuttle – R.P. Feynman
> Feynman argues for unit tests

I'm not sure that would be my takeaway from that quote. In the analogy of Unit testing, the test would have found the cracks in the turbine blades. It seems to me that Feynman continuously argues for deep investigation into any problems encountered, rather than (seemingly) ignoring them or making up excuses for why they're not problems.

He regards independent code verifications and testing highly, it seems:

> The software is checked very carefully in a bottom-up fashion. First, each new line of code is checked, then sections of code or modules with special functions are verified. The scope is increased step by step until the new changes are incorporated into a complete system and checked. This complete output is considered the final product, newly released. But completely independently there is an independent verification group, that takes an adversary attitude to the software development group, and tests and verifies the software as if it were a customer of the delivered product. There is additional verification in using the new programs in simulators, etc. A discovery of an error during verification testing is considered very serious, and its origin studied very carefully to avoid such mistakes in the future.

I'd consider this quote a clear argument for unit testing though:

> There is additional verification in using the new programs in simulators, etc.

In the end, it seems to come down to the simple concept of: spending more time on verifying code results in better code. Whether it is through automated testing, code reviews, independent (and competent) user acceptance testing, etc.

notzorbo3··on How the US Pushed Sweden to Take Down the Pirate Bay
I used to run an abandoned warez site when I was young. I received a lot of cease and desist letters from "lawyers". They usually failed to identify the infringing material, failed to show they had the right to act on the copywriters behalf and a staggering amount of them confused trademark infringement with copyright infringement. Also, every last one I received via email. Yeah, right, like that's going to hold up. I ignored all of them and never got even so much as a follow up.

In other words, such things are considered low-hanging fruit by these companies. Just throw it out there and see what sticks.

notzorbo3··on High-Level Problems with Git and How to Fix Them
> A well designed ui should be learnable while being used

Strongly disagree with that one. A UI that lets you work in the most efficient way (e.g. vi) can also be well designed, even if it's incredibly difficult to learn.

> creating a fresh learning repo for dedicated learning for fear of losing data while using the tool in your "real" repo is the ultimate red flag in terms of usability.

Again, strongly disagree. Git is a powertool. You don't let loose a powertool if you don't understand how it works. Creating a fresh learning repo is merely acknowledging that you don't know the tool well enough yet. There's nothing wrong with that.

There's a big difference between being noob-friendly and being user-friendly. Personally, I hate noob-friendly tools, because they tend to just get in the way.

notzorbo3··on Universal Basic Income Explained – Free Money for Everybody? [video]
It seems everybody has different goals for UBI. Getting unemployed people to work is not one I've encountered before I think. I fail to see how giving everybody free money is going to get unemployed people to work. For them, nothing changes.

> The taxes will come from the same places they are expected to: automation increasingly taking over the creation of most of the wealth in society.

I think this is the "lets tax automation!" argument? That's another one I haven't seen convincing arguments for. Why do you think companies would stand for such a thing and not oursource their automation to a country that doesn't do UBI?

> that's the theory.

I think there's a lot lacking in the theory, and I'm not hearing any convincing solutions for the problems UBI presents from anyone. It all seems to be built on hopes and dreams and best wishes, with little accounting for actual real-world considerations.

notzorbo3··on Universal Basic Income Explained – Free Money for Everybody? [video]
Traditional social programs are a safety net for single people like those going through divorce and such. Under UBI, it just puts a lot more pressure on those people, while at the same time alleviating the pressure on multi-income households. It's might force people to stay together in unhappy marriages, etc. I see that as a problem.
notzorbo3··on Universal Basic Income Explained – Free Money for Everybody? [video]
> If UBI = $1 / person, then the difference in pressure is small.

The pressure might be small, but it's still there. The €1 still has to come from somewhere.

> Also, you presume that people only work for money. I think with UBI, you'd see a revitalization of community oriented, but low profit pursuits.

How are low-profit pursuits going to pay for everybody's UBI? You can't heavily tax low-profit pursuits.

notzorbo3··on Universal Basic Income Explained – Free Money for Everybody? [video]
I still haven't found an solution anywhere for the following problem: Living (not just housing, but everything) expenses are a lot less for dual, or even triple, income households than for single people. So there's going to be a lot less pressure on dual income households to work beyond their basic income. Logically, this would put double (or even triple) the additional pressure on single income households. Under UBI, they'd have to provide enough in taxes to provide the UBI for themselves AND dual income households.

How do UBI proponents solve that problem?

notzorbo3··on Hundreds of web firms record 'every keystroke'
By "focus" i mean the current window on your desktop that has the focus, as in, the one that's going to receive the input you give through your keyboard. I've seen plenty of people (and it's happened to me too) fumble and accidentally type or paste things in the wrong window. If that window happens to be your browser on a website that does this kind of tracking, that information goes to some random third party instead of the window you thought it was going to.
notzorbo3··on America’s flat-Earth movement appears to be growing
> there was a study that said the most effective way to fight stupidity is by ridicule

Unless people are just trolling, in which case both trying to ridicule or educate them is not gonna work. Just ignore them. Don't feed the trolls.

notzorbo3··on Hundreds of web firms record 'every keystroke'
> These sites already have access to all of your data (stored in their databases!)

The assumption for most people is going to be that they have the data that you explicitly sent them. Implicitly gathering and sending data is equivalent to snooping on people without consent. It's all about expectations.

notzorbo3··on Hundreds of web firms record 'every keystroke'
> Could a website that has a keylogger in it potentially pick up these keystrokes

Yes of course. All it takes is misclicking and having the focus on a wrong window, and you're toast.

notzorbo3··on Hundreds of web firms record 'every keystroke'
Whenever someone complains about a website not working without javascript enabled, someone inevitably responds "it's 2017, you can expect javascript to be enabled". I think that piece of knowledge is outdated:

- Late 1990's: static html documents + forms - early 2000's: shitty DHTML scripts that added nothing - early 2010's: javascript + gracefully downgrading sites - 2015/16: required useful javascript everywhere - early 2017: trackers everywhere, html5 popups, trackers, spywhere, trackers, bitcoin miners, trackers, etc, etc.

2017 is the year where you NEED a javascript blocker. What's the use of having any security at all if you're going to leave the biggest attack vector in modern times completely unprotected?

Plus, the web has become completely unusable without a script blocker.

notzorbo3··on Why we never thank open source maintainers
You're welcome!

I think I should stress the point that people will pay more for stupid things such as lessons than they will for actually useful things. For example, you can charge twice as much for teaching people how to use Git than you can for actually implementing the frontend and backend for them.

People are really, really insecure about their own abilities. If you can position yourself in the market as someone who can help them with their insecurities, you're basically golden. It sounds a little .. dickish, but really ,you're doing everyone a favor. So many people get hung up in merely(?) having to make a decision. Making it for them it usually a big help.

notzorbo3··on Why we never thank open source maintainers
Not being in the US, not trusting PayPal and wanting absolutely nothing to do with any kind of blockchain currency.

It's interesting that we have much simpler payment methods available in the EU, but apparently EU people don't like to pay for things.

notzorbo3··on Why we never thank open source maintainers
All kinds really. From transitioning companies to modern CI/CD practices to security counseling to integration work to helping out with automation and such. It's about 50% low level tech stuff and %50 advisements.
notzorbo3··on Why we never thank open source maintainers
The higher you charge, the more horrible your consultancy job will be generally ;-) I've found €200 to be the sweet spot between actually doing useful tech work and being in nonsense meetings all day.
notzorbo3··on Why we never thank open source maintainers
True, but expectations are sometimes also higher. Documentation etc has to be of good quality. Packaging. Stuff like that. There's really no comparing it with a paid job IMHO. It's more fun i'd say.
notzorbo3··on Why we never thank open source maintainers
Thats the fee for my part-time freelance consulting. 200 is on the low end.
notzorbo3··on Why we never thank open source maintainers
That's an awesome way to reward people! I've gotten offers for money, but actually getting to money to me is more of a hassle than it's worth, so I just decline.
notzorbo3··on Why we never thank open source maintainers
Ways I deal with this as an open source maintainer of various projects:

1. Severely restrict the scope of the project (i.e. do one thing and do it well) 2. Don't feel guilty about saying "no" 3. Realize that people have no malicious intent or are lazy when they request <feature X that takes two months>. It's just like a normal customer in a business: they often have no idea of the cost and difficulties in implementing things. That's okay, it's my duty to inform them of that. 4. Refuse pull requests for features that I don't feel like maintaining. I always try to keep people from wasting their time and ask them to confer before implementing a feature.

I don't feel animosity towards people who (even rudely) request such things. But they can expect a short reply in the form of "I'm sorry, that feature is outside the scope of the project / is going to take too much of my time."

notzorbo3··on Why we never thank open source maintainers
> It is true that some of you guys can build a tool in a hackathon

I've kept some data on how much time I've spent on a somewhat popular open source project (+/-1000 stars on github, if that means anything).

Time to implement to scratch my own itch: +/- 24 hours

Time to write documentation, package, etc: +/- 70 hours

Time to handle bug and feature requests, support: +560 hours

So that's an overhead of around 2500%. If I was paid to do that, it would have cost around €130,000.- (and would have netted me around €5, because dutch taxes ;-) )

The emails and other forms of thank-you's from users make it more than worth it. Plus, I get to give back to the community.

notzorbo3··on Extensions in Firefox 58
Is there uMatrix for the new Firefox? Are there even plans? Because I refuse to use a browser without uMatrix.

edit: I see it's there. Released yesterday. Yay! Now if only Firefox could add a "Add to desktop" option, I could really switch!

Page 1 of 5Next →