HNHacker News
TopNewBestAskShowJobs

nullfield

265 karma · joined April 8, 2022

submissionscomments
nullfield··on Ask HN: Should you reply STOP to unwanted texts?
Which is why i just report (to Verizon) every piece of shit political spam text as junk as I delete it.

The “do not call” registry had a purpose, and it’d have been so easy to add an additional “and also no political anything” to it. Let them burn.

nullfield··on [dead]
No such thing. You’re paying or you’re the product.
nullfield··on Tell HN: Vercel flags accounts using protonmail
Quite unlikely.

This doesn’t differentiate between paid and non-paid PM users, or those just hosting their domain email with PM, either, but if a company wants to cut off its face to spite some users for the communications provider they user, then yeah.

Don’t use Vercel.

nullfield··on Docker Joins Movement to Dump Passwords for Security
“Passkeys, developed by the FIDO Alliance, with support from major tech companies like Apple, Google, and Microsoft, offer a more secure and user-friendly alternative to traditional passwords“

is a lying, surreptitious statement.

Yes, “passkeys” are public-private key pairs, but no different in theory from, say, ssh public/private keys. Whoever is pushing passkeys today though, at this point, is just trying to improve your security (good) while simultaneously locking you into their stuff, Forever (Very Bad).

Passkeys are not “user-friendly” because they take control away from users, promote lock-in that prevents users from switching platforms, and remain something that could be improved… but the powers that be have no intention of doing so because their only goal is to fuck you.

Without an open storage protocol and transfer method, not involving any third party “letting” you do so or collaborating to force you to store cryptographic material in their place or format, this is just another attempt to control you and screw you over.

FAFO at your own risk.

nullfield··on Evolving our self-hosted offering and license model
The forced telemetry on the unpaid version is a good enough reason to opt out of ever considering their product, if there’s an option to do so.

If they don’t respect me before I pay them, why would I believe they’ll respect me more after I pay them? (Yes, I know that telemetry “isn’t required” on a paid product-which, conveniently, they won’t even provide an idea of a price for but instead just ask you to “contact them”)

nullfield··on So the Department of Energy emailed me
As a US taxpayer, charge them.

Charge them, and make sure they understand why - they’re benefiting, and have been benefiting, from software developed at no cost to them. If they want anything, it needs to cost them; otherwise, …

nullfield··on Google pulls the plug on uBlock Origin
Seriously, if there’s any security risk here it’s Chrome.

Ffs, even the FBI recommends using an ad blocker.

nullfield··on Texas sues GM for unlaw­ful­ly collecting and selling dri­vers' pri­vate data [pdf]
And what else does it break-break, even if you do kill the antenna, more that just the annoyance of a light? Integrated GPS, because it uses cellular to “enhance” that?

What other risks are there? Haven’t we seen CAN bus “hacked” over the air to shut down vehicles before? (Even ignoring the intentional ability to do so by the OEM, granted to law enforcement)

nullfield··on The end of Patreon? Google is implementing micro-payments into Chrome
Google can die in the biggest, best fire before I’ll pay—or willingly let anyone I know pay—a cent through them.

They’ve been declared monopolists, abusing everyone else. They destroy web standards, crush other browsers using their influence, and need broken up.

nullfield··on Some subreddits could be paywalled, hints Reddit CEO
Reddit already shot itself in the head shortly before its IPO.

The sycophants at the top have cashed out, and the corpse is just still falling towards the ground.

nullfield··on NASA says Boeing Starliner astronauts may fly home on SpaceX in 2025
I admit I didn’t think of this, but… without another science mission or something, what do they do up there?

This said, yeah, I wouldn’t want to come back on Boeing hardware with Dragon available.

nullfield··on GitButler is now fair source
I don’t get the blanket ban on AGPL-am I misunderstanding how attach-y it is?

For example, people seem to have the impression that if you host something like an AGPL email validation service that just has an API to request a check for an email and then connects via SMTP, which another service calls, that you “infect” your product that even uses that API.

I get that if you change the service and/or expose it publicly you have to make the changes available, but it seems misunderstood.

nullfield··on What Visa earnings tell us about the state of the payments industry
Also from Bits About Money: https://www.bitsaboutmoney.com/archive/anatomy-of-credit-car...

The operative quote in support of this from the link, in support of subsidizing those who don’t and almost more damning because even cash users are subsidizing it as the overall price gets raised to roll in the cost of all the people who do use CCs: “Credit card issuers explicitly and directly charge the rest of the economy for the work involved in recruiting the most desirable customers.”

nullfield··on What Visa earnings tell us about the state of the payments industry
Amex and Discover, as someone else pointed out, are their own banks too-so they are both running the payment network layer for their cards. Or they are at least at the final point; I have no idea whether there’s some blended payment layer/network that can also handle their cards, but since the article says that sometimes Visa cards aren’t processed over their network it stands to reason.

It’s still the “bank” (or credit union-a better choice, but I digress) issuing you a credit line; they’re also the ones on the hook if you don’t pay. Visa pretty much has nothing to gain by securitization, unless they want into the reinsurance industry. They just want to be paid any time their payment processing network is used or when a card with their logo on it is used.

nullfield··on What Visa earnings tell us about the state of the payments industry
After looking at it, the “uses a different number” would seem to imply that the side-channel thing is right. Pace-participating entities load your cards to their system, you get access via your email address, Paze acts as an interface whereby issuers associate a new unique ID with your account while still showing you your “Visa” account number or whatever and “validating possession” with CVC.

That said, my level of trust in Early Warning Systems, who runs it, is pretty low-Zelle looks like a hot mess with EWS/banks ignoring Reg E as much as they can get away with:

https://www.bankingdive.com/news/zelle-scam-reimbursement-we...

nullfield··on What Visa earnings tell us about the state of the payments industry
They probably won’t give us the concrete numbers.

They definitely don’t want to get sued if they facilitate what turns out to be not just distasteful to them but potentially illegal-see the PornHub lockout by all the CC companies after it was discovered that not all the things they hosted were legal/consenting/etc.

That said, “the optimal amount of fraud is non-zero”: https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...

nullfield··on Taking a Radio Camping
Packet doesn’t have to be in any particular frequency band, e.g. not in ELF-MF (3Hz-3000kHz).

It just implies packet switching instead of circuit switching or message switching, and can be done at any frequency.

APRS is packet; anything that hears a position report can decode the data and decide what to do with it, as a unit. This is versus circuit switching or message switching-circuit switching being a dedicated channel (e.g. a phone call, regardless of what the underlying protocol is, since I know we can do things like VoLTE where the underlying network packetizes and multiplexes traffic) and message switching being like email-routed all together somewhere, perhaps via multiple hops.

nullfield··on Proton Mail goes AI, security-focused userbase goes 'what on Earth'
Well, if you’re not happy about it, as a paying customer, you should let them know. I did.
nullfield··on 7 out of 10 hiring mangers say its ok to post a fake job
Why this isn’t criminal,with the companies engaging in it prosecuted for fraud, I don’t understand.
nullfield··on Organize Links with Precision and Speed
I’d probably never pay for this, even though I want something like it conceptually-tab hell is a real thing.

$12/mo is too much, and to be honest I just don’t trust that, with the state of the enshittification-of-everything (doubly so when it comes to a new player to the market with a $144/yr for a product like this), it won’t end poorly. Too many things like this just get shut down, or sell out, or whatever, and I’m not interested in ever dealing with that kind of thing again.

nullfield··on Microsoft Research chief scientist has no issue with Recall
https://learn.microsoft.com/en-us/windows/privacy/manage-con...

is about as close as we get.

nullfield··on Ask HN: I'm getting overwhelmed by AI. How to cope?
There seem, to me, really two bifurcating paths ahead. Maybe 2.5.

In both of them, AI is Not My Problem.

In A, we get a technological singularity, and AI is beneficial and benevolent; life is radically improved. In A.5, we don’t quite get to that technological singularity immediately, but get vast improvements in domain-specific systems from individually optimized models. Life is still significantly improved, so much that the edges of post-scarcity start to hit. This is the only one with a maybe caveat, but if anything it’d be leveling disparities.

In B, we get a technological singularity (or closeish) but fail to get the alignment problem down. The Terminator movies are so far from how badly we’d lose it won’t matter.

nullfield··on Ask HN: What's the best way to contact Tim Cook?
To quote from Reddit: “tcook@apple.com is a legitimate account, but monitored and managed by admins.”

To answer your question, you don’t, mostly. He might answer sometimes, as Jobs did, but it’s not normal or expected.

This also depends on the “why” that goes with your question:

If you just want to talk to him, good luck. If you want to serve legal papers, there are other methods that aren’t so much “contacting” him. For nearly anything that one can expect you might want, emailing that address or sending a message via the FAX number you were given is the closest to “executive customer service” you’re likely to be able to get.

nullfield··on Beginner's guide to the Shenandoah garbage collector
How does this manage to say that ZGC and genZGC are not production ready - “not that ZGC and genZGC are production-ready” - then later reference JEP 439 and note that Generational ZGC is production ready with, “At the time of writing, Shenandoah Generational is experimental, whereas Generational ZGC is production-ready” (production-ready is a link to the JEP)… then go back to “On a side note, Oracle's ZGC Generational—GenZGC—is not supported in production yet.”

Is this a separation between RH OpenJDK (which, being OpenJDK, has all of the JDK 21 features including JEP 439 in it) and something special Oracle is doing, or?

The presentation of the two and difference discussion is quite confusing, even knowing something about the JVM, for something styled as a beginner’s guide. If making comparisons it’d help if they were clear, especially when promising a “straightforward” look at the start and directing people who want detail off to “upstream documentation”.

nullfield··on Why do the Japanese love CDs?
There is something to be said for owning things you like, instead of those things being “available to stream” on service X. For now.
nullfield··on Don't Lie in Interviews
Game theory has some things to say about this, and the expected long term outcomes for everyone aren’t good. Employers could use some study in the subject, but I’m firmly convinced this is past the capability of HR departments in general. I mean, they call themselves “HR”, which tells you about all you need to know about how they think about you.
nullfield··on Ask HN: Did you switch off "allow your content to train our model" in ChatGPT?
In the iPadOS app, it’s under Settings then Data Controls; I presume it’d be similar for other interfaces.
nullfield··on Passkeys: A shattered dream
But not the same ssh key on multiple accounts.
nullfield··on Passkeys: A shattered dream
Except they ignore subdomains. Unless you fix that on a per-item basis, in their desktop application.

I think, finally, that the reason this feels so dirty-apart from companies and lock-in and all-is that it’s taking the “something you know” as one auth factor and turning it into something that, not only do you not know, the big goal of is to make sure you can’t know but something you have.

nullfield··on Passkeys: A shattered dream
No, you’re smart to feel this. See the previously linked comment from someone upset that KeyPassXC lets users export:

https://github.com/keepassxreboot/keepassxc/issues/10407

When it comes to Apple, or Google, remember that people keep their accounts (and therefore access to their keys) at Apple or Google’s pleasure; people’s lives can and do get upended when Google decides you’ve done “The Bad” and they revoke your account-and there’s no learning what you did. For your, and everyone else’s, security of course.

The desire for better metadata is good, because you don’t want to hand your password for microsoft.com to microsolt.com when you’re in a hurry and a sophisticated phishing email arrived. Still, as an example, I’m trusting 1Password less and less. They just helped me autofill credentials somewhere they shouldn’t have (thankfully to no ill effect) when the password was correctly set up with website information, basically where something was site1.example.com instead of othersite.example.com. Because they ignored the subdomain.

Their response from support? “By default 1Password doesn’t take into account subdomains when suggesting an item…” and if you’re using their desktop product, there you can go change - per-item (wtf?) - whether it requires exact domain match to fill.

As so many other people here are saying, it feels like a mass lock-in attempt. If it’s not FIDO is doing a really good job making it look that way, especially with “attestation” (which could just be Web Integrity 2.0 if misused).

← PreviousPage 3 of 9Next →