HNHacker News
TopNewBestAskShowJobs

o8r3oFTZPE

171 karma · joined June 9, 2021

submissionscomments
o8r3oFTZPE··on FOIA requests show Apple’s emails pitching state agencies on IDs and Wallet app
Who invented "clickbait". What is the purpose of "clickbait".

Non-profits supporting investigative journalism like MuckRock are to blame. MuckRock is not selling advertising, but don't be fooled. Investigative journalism will just create more clickbait.

Whereas Big Tech companies have nothing to do with clickbait nor advertising. They are not spreading clickbait like non-profits that submit FOIA requests. Tech companies do not make money from clickbait nor eyeballs. Tech companies have sources of non-advertising revenue and legitimate business purposes that benefit society.

In 2012, EFF filed over 200 FOIA requests through MuckRock, for information about drone usage. EFF should stop participating in these clickbait campaigns. EFF should be protecting Apple from low hanging clickbait.

We should be thanking Big Tech companies not scrutinising them. They mind their own business, they do not try to learn what their users/customers are doing. They respect user/customer privacy. OTOH, these non-profits submitting FOIA requests do not respect the privacy of Apple and governments, who deserve to be left alone, to do their work in private. This is a basic human right.

Why don't people trust Big Tech. Tech companies have done nothing wrong.

o8r3oFTZPE··on Show HN: Age 1.0 – Simple, modern and secure file encryption
Fair question. Im not the author so can only make a guess (other readers of HN surely know far more than I about these subjects). However I suspect the rationale is related to whats been called "Bernstein chaining".

https://cr.yp.to/proto/ucspi.txt

http://www.catb.org/~esr/writings/taoup/html/ch06s06.html

https://skarnet.org/software/execline/grammar.html

https://www.oilshell.org/blog/2017/01/13.html

o8r3oFTZPE··on Clarifications regarding arrest of climate activist
Heres the issue with Proton's marketing that no one is mentioning. The CEO keeps making claims about "Swiss law" as if it is something to be desired. However he never adds any citations to the relevant laws or their interpretation. This seems strange because #1 How many Proton customers know anything about Swiss law (how many can even read German or French^1) and #2 The CEO is not a lawyer, he is a physicist.

It seems prudent that Proton customers would want to have a look at those "Swiss laws" (a) to see what sort of protection they offer and (b) to make sure they dont violate one. In the case of (b) the customer will potentially lose all privacy protections, as emphasized in this announcement.

1 It appears that Swiss law is conveniently published in English however the English translation is not what Swiss courts use.

o8r3oFTZPE··on Show HN: Age 1.0 – Simple, modern and secure file encryption
"An extremely simple CLI that composes well with UNIX pipes"

Just for fun, I occasionally experiment with proposed "post-quantum" encryption solutions and one in particular called Classic McEliece, from the same author (more or less) as the encryption used in age. Its small and compiles quickly. The interface is elegant and seems impossible to screw up. I have rarely seen anyone outside of the author and his followers use file descriptors in compiled programs in this way. I like it.

Three programs, each only does one thing

     usage: cmkeypair 5>publickey 9>secretkey

     usage: cmencrypt <message 4<publickey >ciphertext

     usage: cmdecrypt <ciphertext 8<secretkey >message
To be fair, I should probably add that McEliece arguably fails the "small, copy-pasteable keys" criteria. :)
o8r3oFTZPE··on Rumble, an open source, offline, censorship resistant microblog (2017)
"Unfortunately they're solving the wrong problem."

Heres the description of Rumble:

"Rumble enables the spread of messages in an epidemic fashion using automatically formed and opportunistic local ad-hoc network. Every message sent or received with are stored on the local database and pushed to every other device it meets. By doing so, messages naturally propagates throughout the network using social links as the underlying infrastructure. Because it doesn't rely on any fixed infrastructure like the Internet, it is naturally resistant against censorship."

"About

Rumble allows the sharing of messages and pictures without relying on the Internet, in a Delay Tolerant Fashion following the Store-Carry and Forward paradigm"

Question: What problem is Rumble solving.

Option #1

Answer: Requirement for fixed infrastructure in order to exchange messages. Censorship resistance is just an incidental benefit.

Option #2

Answer: Censorship. Formation of ad hoc network infrastructure is just implementation detail.

The problem with #2, the parent's interpretation, is that formation of ad hoc infrastructure, i.e., non-reliance on fixed infrastructure, has multiple benefits besides censorship resistance. Its quite possible someone could use Rumble to solve a problem other than censorship.

o8r3oFTZPE··on Clarifications regarding arrest of climate activist
"No matter what Apple and ProtoMail and similar companies tell you, you cannot buy privacy off-the-shelf."

The cost is personal time and effort, not money. The software needed is generally free of charge. The goal being not a physical product or a service, but a level of knowledge and proficiency. To put it another way, "tech-savviness" cannot be purchased, it has to be achieved.

The cultural problem we face is that the so-called "0.1%" are leveraging their "tech-savviness" against the rest of the population, working for so-called "tech" companies, websites that make money by exploiting the privacy of the "99.9%" in the service of online advertising.

If we take HN comments as true, in some cases, these employees do not even believe in the bottom line they are working to support.1 They are not adopting the behaviour of the "99.9%", i.e., the "expected" behaviour required to sustain their employer's bottom line. Not sure about you, but that would not give me much confidence they are going to work very hard to protect other users' privacy.

The term "dogfooding" is sometimes used amongst tech companies to describe the situation where employees themselves partake in what they offer to non-employees, i.e., "users".2 To persons outside the tech bubble this can be quite amusing. Does this suggest they view their relationship to users as more like "human-to-dog" than "human-to-human". There is nothing inherently wrong with someone peddling something she does not believe in, however we might consider what is/are the reason(s) for her lack of faith.

To be clear, I am not suggesting the cultural problem can be solved. I am attempting to provide further reasons that digital privacy is, like the parent suggested, generally not something you can "buy".

1 Evidence appears periodically in HN comments. For example, yesterday: "Disclaimer: I work at Google. In cloud, not on Android. I am privacy conscious so I though I would give a try at Graphene OS, it was brutal."

2 The term is alleged to have first appeared one the joelonsoftware.com website and to have originated at Microsoft.

o8r3oFTZPE··on Climate activist arrested after ProtonMail provided his IP address
Generally I use custom utilities for HTTP generation, URL extraction, chunked transfer decoding, URL encoding/decoding, GZIP/ZIP/PDF/MP4 extraction, etc. Thus I can use any TCP client I want to make HTTP requests from the command line. I do not need a browser to request content. Nor do I need projects like curl or projects that use libcurl like youtube-dl. For large downloads I use tnftp. The shell script I use to download YouTube videos is 424 bytes.

For reading HTML I prefer links. It has the best rendering of HTML tables, IMO, and is for me the easiest source code to work with. I did use lynx back in the late 90's but would never go back to it. Its bloated. Its slow. Im not sure why anyone interested in text-only browsers would use it other than they are unaware of or have not tried alternatives.

o8r3oFTZPE··on Climate activist arrested after ProtonMail provided his IP address
I wouldnt trust any of them to be honest. Privacy policies really arent worth anything.

I would look for websites that generally do not ask for data. Then send them the minimum data you can get away with. I would avoid "signing in" or "signing up" to any website. There is an immense amount of data and information available from free from the web, no "account" is necessary.

For example I dont send any extra HTTP headers like Cookies or User-Agent, I dont use Javascript. I dont request images, CSS. I dont automatically follow links in src tags. Yet I can still read and comment on HN and I can read every website posted to HN. Thats a lot of websites. I can read them just fine while not sending them any more data than is needed. Because I do not use a large, complex graphical browser sponsored by an online ad-supported vendor to make HTTP requests, I can easily control what I send. This is far better IMO than sending unknown amounts of data (letting the websites control what the browser sends via headers, Javascript and src tags) and then hoping the websites dont do things with the data that we dont like.

Privacy policies do not limit websites from collecting data nor do they limit how the data can be used. They are "policies" not agreements. If a website operator does things behind the scenes that violate privacy but that it does not disclose in a "privacy policy" what can a user do. How would the user even know. Or the website could clearly violate their own "privacy policy", but no one outside the website's operators would know. Even if users discover the violation, what would be the repurcussions. Its too late, because a violation means privacy has been blown.

Show me a case where a tech company got sued for violating a privacy policy. How can anyone prove a violation if the operations of the website are not open for public inspection.

o8r3oFTZPE··on Climate activist arrested after ProtonMail provided his IP address
Nothing is even defined. There is nothing in this policy that obligates the company to do, or restricts the company from doing, anything.

This is the way most tech company "Privacy Policies" are written.

There is a significant difference between a statement such as "We (Company) do not do X" versus a promise such as "Company shall not do X" or a statement such as "We do Y. We may do Z" versus a promise such as "Company shall do Y."

Why not have our own "Policies" as users that we publish for tech companies to read. In them, we could describe what we do and what we do not do, and what we may or may not do. Tech companies could rely on these statements. You can see how silly that sounds. Yet users are expected to read and rely on hundreds of different "privacy policies", collection of non-binding statements like "We take privacy seriously".

o8r3oFTZPE··on Climate activist arrested after ProtonMail provided his IP address
Devils advocate: Why trust the policy. Can you enforce it. If yes, then how.
o8r3oFTZPE··on Climate activist arrested after ProtonMail provided his IP address
"Their homepage says..."

Is the parent suggesting that no one should bother to read the Terms and Privacy Policy, linked to from the homepage. https://protonmail.com/privacy-policy

Despite the parent's claim, the Privacy Policy says the company may log IP address. Temporarily. Irrespective of any request from local authorities regarding a specific user. IOW, they may log anyone's IP address temporarily regardless of whether the particular user is casuing trouble; they can log IP address for everyone. The policy says they log this data for the purposes of preventing fraud and abuse. The problem for privacy-conscious users is that if they log the data, then that entices authorities to try to successfully request it.

The policy, which imposes no obligations on the company BTW, reads as follows:

"IP Logging: By default, we do not keep permanent IP logs in relation with your use of the Services. However, IP logs may be kept temporarily to combat abuse and fraud, and your IP address may be retained permanently if you are engaged in activities that breach our terms and conditions (spamming, DDoS attacks against our infrastructure, brute force attacks, etc). The legal basis of this processing is our legitimate interest to protect our Services against nefarious activities."

There is nothing that says "By default we do not retain any logs". This clearly states they may be expected to retain IP logs. ("IP logs may be kept temporarily...")

But wait there's more.

"We will only disclose the limited user data we possess if we are instructed to do so by a fully binding request coming from the competent Swiss authorities (legal obligation)."

This clearly states the company may disclose the data they possess, e.g., IP logs collected to combat fraud and abuse, if in response to a request from competent local authorities.

Further down is a curious statement about decrypting messages.

"If a request is made for encrypted message content that we do not possess the ability to decrypt, the fully encrypted message content may be turned over."

Why include a statement such as this, specifically the part that says "that we do not possess the ability to decrypt". The company already specified it may disclose the data it possesses. This further statement suggests there could be some situation where they may have the ability to decrypt some messages. Besides their own communications with customers, why would they ever have encrypted messages that they can decrypt. They could state something like "If the request is made for encrypted communications addressed to us or sent by us, ...", but they do not. As such, their statement must include other messages, too.

o8r3oFTZPE··on How did American “wokeness” jump from elite schools to everyday life?
Referenced in the article

https://www.wsj.com/articles/can-vivek-ramaswamy-put-wokeism...

o8r3oFTZPE··on Ask HN: Why does validating a user require 14000 files?
Why do you need users to sign in. Do they really want to sign in. What do they get out of it versus what do you get out of it

Using Sign in with Google just encourages use of Google. Is that really the best thing for users. Google is a privacy disaster

If you and your users truly both need authentication of each other why not let your users use x509 client certificates

You are probably already using x509 server certificates

The term "SDK" is synonymous with "unnecessary fluff". Its been that way since the 1990s

o8r3oFTZPE··on Ask HN: Research on usage of text-only versions of websites?
If you make a test page, then post it to HN, perhaps we can provide some "demonstrable popularity" to give you some data to present for your business case. :)

I am a heavy text-only web user. In fact, I view all sites that way with a text-only browser. I do not use lynx or w3m. Its so easy to generate simple web pages for text-only viewing. I have the process automated. I do not understand why web developers argue "it's not worth it". The developer time needed to generate such pages is close to zero.

o8r3oFTZPE··on Ask HN: What cloud providers are suitable for running mail servers
But you cannot/will not name the offshore 3d party service
o8r3oFTZPE··on My MacBook Pro had over 10k USD in repairs
"I had Windows computers back in the day, late 90s, where I only upgraded the hardware, not the OS."

How would that be possible since Windows almost invariably came pre-installed by OEMs. New hardware would have the latest Windows version pre-installed. Downgrading would be extremely difficult if not impossible.

o8r3oFTZPE··on Firefox 91 introduces enhanced cookie clearing
Advertising targets1 trust Google. There is no reason for them not to trust this company. Google has the privacy of its advertising targets as its highest priority.

Mozilla gets 90+% of it operating budget via a deal with Google, but Firefox developement is not influenced at all by Chrome. Totally independent.

Big Tech exists for users, not advertisers. Privacy must come first and money must come second. Thats why we have more privacy than ever and Google does not make much money. Government regulation is totally unnecessary. All incentives are aligned toward greater privacy.

Google will "build a more private web" for its advertising targets. Sorry advertisers. :(

1. Also known as "users".

o8r3oFTZPE··on The Insecurity Industry
"For example, if you want to see Microsoft have a heart attack, talk about the idea of defining legal liability for bad code in a commercial product."

That sort of discussion is quickly dismissed on HN. And probably elsewhere on the web/over the internet.

Instead we frequently see discussion blaming users of the software, i.e., Microsoft's customers, or even suggestions to make the customer liable, or comments from "security experts" on how Microsoft has made such amazing strides in securing Windows (a tangent). In the real world, outside the Redmond/Silicon Valley monopoly space, how many mistakes does someone have to make before we start to suspect there might be problems with relying on that person's work. Even more, how many times do we hire someone knowing they have made 500+ mistakes in prior work leading up to their application.

If Microsoft products are so infallible when used as instructed by Microsoft, then why would Microsoft have a heart attack as Snowden suggests. What a remarkable state of affairs we have today where employers such as Microsoft can call their employees "engineers", and yet both the employer and employees are absconded from any liability for the so-called engineer's work. The number of "second chances" Microsoft gets is nothing short of astounding. A bit like the number of pardons we allow to Google or Facebook for privacy infractions. Infinite.

https://www.nspe.org/resources/professional-liability/liabil...

o8r3oFTZPE··on The Insecurity Industry
[accidental dupe. see above comment]
o8r3oFTZPE··on iDOS 2 will be gone soon
"innovation, competition and small business"

Not to mention the effect on intellectually curious users (and learning). These computers bundled with phones are crippled, tinker-proof, and there is no way to extend or improve them after purchase except as according to the seller's business model. Un-tethering from the seller and opting not to use their servers is effectively discouraged or prevented. "Protecting you" is a suspect justification for all the hoops one must jump through to "accept the risk". There is no anticipation of user autonomy. The world according to the seller is divided into "developers" and "users". Anyone in both categories is intended to pay Apple twice. First for the hardware, then again for the "developer certificate" and a percentage of any licensing revenue.

Maybe that is what the market is demanding. Or maybe the market does not have full information and thus does not understand the full spectrum of possible choices. As long as the cartel persists we will never know.

o8r3oFTZPE··on Google broke a conditional statement that verifies passwords on Chrome OS
Here is the original article from Android Police:

https://www.androidpolice.com/2021/07/20/a-new-chrome-os-91-...

The reason for the failed "update" was another Chrome 0-day that relies on the Google's Javascript engine:

https://www.androidpolice.com/2021/07/16/another-day-another...

Curious whether they release the details of how this 0-day works after it is fixed, so we can see the mistake they made putting users at risk.

o8r3oFTZPE··on A case against security nihilism
From the video: "Cloud computing is really a fancy name for someone else's computer."

He goes on to discuss the expansion of "trust boundaries".

Big Tech: Use our computers, please!

o8r3oFTZPE··on Even if you’re paying, you’re still the product
Never said "good old days". POP3 and IMAP were not part of the original design of email. The point of difference between then and now worth considering, IMO, is that the ISP's business plan was not personal data mining and online advertising services, it was internet service.

Perhaps it is a mistake to attribute improvements in syncing solely to the existence of a gigantic webmail service run by an online ad services company. There have been vast improvements in computers and networks since then.

What was arguably "good" about the "old days" was a relative absence of third party middlemen trying to make money from online advertising, and investing in surveillance as a "business model".

As for spam filtering, I agree. However I do not think "webmail" hosted by a third party is the final solution to the problems with email. The original SMTP-to-SMTP design used on a LAN overlay performs very well and attracts no spam, for example.

o8r3oFTZPE··on Even if you’re paying, you’re still the product
Before Gmail, it used to be common to have an email account through one's ISP. No need for Google.

IIRC, when Zuckerberg was testifying before Congress, one senator said his terms of service "sucked". Was he wrong.

o8r3oFTZPE··on New Aspects Related to Plant Processing Revealed at Çatalhöyük
You could just read the paper instead of the web page on archaelogy Google Blogspot blog about the paper, plus advertising.

https://journals.plos.org/plosone/article?id=10.1371/journal...

(No ads but they do use Google Tag Manager and Google APIs)

o8r3oFTZPE··on A case against security nihilism
"In contrast, even though you keep insisting otherwise, Security Keys don't give "escalating amounts of personal information to tech companies" but instead no information at all, just that useful answer to the question, "Are you still you?"."

No, I am responding to the above assertion that I have insisted security keys give esacalating amounts of personal information to "tech" companies.

This is incorrect. Most users do not have physical security tokens. But "tech" companies promote authentication without using physical tokens: 2FA using a mobile number.

What I am "insisting" is that "two-factor authentication" as promoted by tech campanies ("give us your mobile number because ...") has resulted in giving increasing amounts of personal information to tech companies. It has been misused; Facebook and Twitter were both caught using phone numbers for advertising purposes. There was recently a massive leak of something like 550 million Facebook accounts, many including telephone numbers. How many of those numbers were submitted to Facebook under the belief they were needed for "authentication" and "security". I am also suggesting that this "multi-factor authentication" could potentially increase to more than two factors. Thus, users would be giving increasing amounts of personal information to "tech" companies "for the purposes of authentication". That creates additional risk and, as we have seen, the information has in fact been misused. This is not an idea I came up with; others have stated it publicly.

o8r3oFTZPE··on A case against security nihilism
If you cannot write safe C and you need memory-safety, why not just use Ada.

Restricting who can write C is another "extreme" idea in line with "no one can write secure C". I will not call it hyperbole but I think its absurd.

What we can do is be more cognizant of who is writing the software we use. (For example, I use software written in C by Robert Dewar, co-founder of AdaCore, called spitbol. A big part of why I use it is because of who wrote it, the code itself and its history.)

Not caring how much space something occupies is not something to which I can relate. I always care. I do not have unconstrained computers. Each has a finite amount of resources and I try to use them in a controlled and efficient manner. That means avoiding lots of large, amorphous software programmers use without question. For me, this works quite well.

Intentionally ignoring who writes the software I use does not make sense to me either. I think in a previous comment you mentioned Heartbleed. It seems that countless people using OpenSSL were relying on it heavily without ever bothering to investigate anything about its source. That to me was strange. We read comments from people who were "shocked" to find out who was managing the project. Total lack of curiosity. They never bothered to look. Not a great recipe for learning.

o8r3oFTZPE··on Kubernetes is our generation's Multics
"Poeple like to ..."

Perhaps the reason people question these complicated things is because they are, whether intentionally or not, being marketed to an audience on HN that includes small scale non-enterprise users.

I shall quote thyself here: A problem does not exist for you simply because it exists for LARGE SCALE ENTERPRISE users.

o8r3oFTZPE··on A case against security nihilism
To clarify, I know you may not have said "no one can" but plenty of other HN commenters are saying exactly that on a regular basis. Thank you for refraining from repeating this absurd hyperbole.

C programs are not inherently smaller and faster but in practice this is usually the case. Can you guide me to some Rust programs that are smaller than their C counterparts. The thing that holds me back from experimenting more with Rust is the (apparently) enormous size of the development environment relative to a GCC toolchain.

The number of downlaods from crates.io is questionably large and some of the binaries I have produced were absolutely gigantic. Largest executables I have ever compiled. Crazy.

We do not "lose" if people keep writing in C as long as its the right people. The right programmer for the job. All programmers are not created equal no matter what languages they use. Absent professional certifications and enforceable quality standards, perhaps the world of writing software for use by others needs an ethos something along the lines of "code within your means". Memory-safe languages are great but it seems like they just enable people to become far too ambitious in what they think they can take on. This is no problem at all unless and until they start marketing their grand creation to undiscerning users who are none the wiser. (This is of course the general idea behind the "dont roll your own" meme. However, I do not think it should be limited to cryptography.)

o8r3oFTZPE··on Kubernetes is our generation's Multics
"People like to ..."

Perhaps the reason people question these complicated things is because they are, whether intentionally or not, being marketed to an audience on HN that includes small scale non-enterprise users.

I shall paraphrase others here: A problem does not exist for you simply because it exists for LARGE SCALE ENTERPRISE users.

What I would add to that is there is nothing particularly noteworthy about a large organisation's IT work simply because it is a large organisation or making billions in ad revenue, unless one is also working in a similar organisation. If some organisations are writing the next "Multics", it really should not be interesting to everyone. A single person who can do all the individual tasks you listed is likely to think critically when presented with "news" of organisations where no single individual can do those things. Its like how many Initech Corporation employees does it take to screw in a lightbulb.

I find some of the most interesting work is found in projects started by individual programmers working alone. luajit for example.

Page 1 of 3Next →