HNHacker News
TopNewBestAskShowJobs

prance

142 karma · joined April 13, 2016

submissionscomments
prance··on Zcoin implementation bug enabled attacker to create over 500K Zcoins
> You still run afoul of countless computer security laws

Only if you're citizen of/doing it in a country with such laws.

prance··on PGP needs to be retired in honor
My point is that as long as I have to choose non-mainstream OSs for secure communication, the tradeoff will not be worth it for me. As will be the case for 99% of "normal" users (most of whom don't even know that they can install alternative OSs, let alone on a USB stick). Things like QubesOs (which I had to Google) are interesting, but I think the general failure of Linux to become a mainstream desktop OS alternative proves that the chances of something like that gaining any relevant degree of popularity are minimal.

So yes I accept the risk that this will come back to me one day, because there's no other practical choice. Just as I decide to go out of the house and take part in normal life, even though there's a high chance of getting into a traffic accident one day.

prance··on PGP needs to be retired in honor
This attitude of "either you really need the security, so make do with whatever inconvenient method is necessary, or just forget about it" is what keeps secure methods out of the mainstream, and thereby from widespread usage. This in turn means that anyone actually using those methods is immediately suspicious. Carrying multiple devices at the airport, or is there a Tails on that USB stick? Let's interrogate!

Also the notion that only journalists/whistleblowers by today's definition need this level of security is wrong. Your "normal", politically active person of today may be the whistleblower of tomorrow. E.g. after a regime change, or just by voting some crazy people into government. I'm living in a country where bloggers are sometimes arrested because of some alleged nonsense. But even in the West, it's nowadays all too easy to just be labelled "terrorist".

So the only sensical way forward is to popularize secure communication methods so that they are normally used by everyday people (including "professionals") with their everyday systems. This increased user base would likely increase the demand to close the existing holes and insecurities of the rest of the system, thereby creating a market force in this direction. And for this purpose, I agree with the author that PGP is not the way forward.

prance··on AI learns to write its own code by stealing from other programs
This discussion reminds of this question/answer on quora: https://www.quora.com/Since-programming-can-be-self-taught-w...
prance··on LibreTaxi – A free and open source alternative to Uber and Lyft
"at least in much of the USA, and certainly in NYC"

Here in Kenya, and much of the developing world, things are quite different. Traditionally, people would save known and trusted drivers in their phonebook, and call them when needing a taxi. If you're somewhere far from your drivers, you might call a friend who lives there and ask them.

That's how we got started on our own app (http://maramoja.co.ke): we let people favourite drivers, and let them choose the driver for their ride. We show them who's their favourite, who's their friend's (e.g. from Facebook, phonebook, referrals) favourite etc.

Although other apps have now made an inroad here (Nairobi), particularly Uber, whose marketing budget we of course cannot match, there's still quite a number of people who won't use their "just any driver" approach.

prance··on Experts, True Believers and Test-Driven Development: how advice becomes a religion
I agree, but even Uncle Bob advocated TDD not as a religion of itself, but as a means to achieve the underlying goal - test your code.

In one of his articles he mentioned that there are very few cases where he deems it acceptable to not write unit tests immediately, but one such scenario is where you develop your code interactively using a REPL. Of course it's still better to then create the unit tests for regression testing, refactoring etc.

But the point is that the most important thing is simply that the code is tested somehow. Basically what agentultra said above.

prance··on Is Model-View-Controller dead on the front end?
I agree to almost every point, but note that in the MVC definition, each of the M, V and C are components, not classes. A component may be composed of several classes. So there's nothing inherently wrong with Rails' approach.

I just think that as opposed to the original idea, people started to stuff way too much into their controllers, which is what makes things messy. I agree that Flux helps enforce the way it was supposed to be.

prance··on Turns websites into Markdown
Personally I also find such domain names just childish (and therefore will be slightly negatively biased when first looking at them).

However I would never share them on FB, Twitter etc., as here locally (Kenya), swear words are much less accepted than in the West.

prance··on Some bad Git situations and how I got myself out of them
At this point I think we need to define what it means to "learn git properly". The assumption in this discussion is that it is more than learn a few concrete commands for specific tasks in a few minutes. You say 3 hours is sufficient, but is it?

For example, something as simple as "Changing the Last Commit" (as in "git commit --amend") is found in chapter 7.6 in the git book which is given as main documentation on git-scm.org. The first 6 chapter mainly deal with introducing the model, architecture and high level workflows. Even if you skip the chapter on github, that's still 5 chapters on mostly theory to read before you get to some often-used tool commands. I would argue that is more than 3 hours for most people if you don't just skim it but try to also understand it.

Apart from that, to answer the question: indeed, often I don't have 3 hours for something to be considered "nice to know" as opposed to "absolutely necessary". And if the manual is a "fsckin'" one, I'm unlikely to read it at all.

prance··on Some bad Git situations and how I got myself out of them
I agree that it's worth it learning git properly, but sometimes you're thrown into the deep end and don't have the time to get up to speed the "right way". I think git is complicated enough to warrant some simplified descriptions for the most-required tasks.
prance··on In defence of Douglas Crockford
The reason would be that they announced a speakers list which they then changed. Of course this happens all the time at conferences without refunds offered, so I guess it's very fair from them to do this.
prance··on In defence of Douglas Crockford
Your arguments only make sense if you assume that the people refusing to speak if Crockford is there are the bullies, while they and the organisers seem to say that Crockford is the bully. Who is right? We cannot know from the available facts.

If you believe the organisers' reasons to disinvite him were not "good enough" (whatever that is), well, then just don't go there or get a refund.

prance··on In defence of Douglas Crockford
I meant "owe" more like as in "you owe me one". If contractual obligations for ticket holders exist, I guess they'd have to offer a refund.

Regarding the other meaning, I could only repeat myself: they state that some other speakers have big problems with Crockford, and that they chose them over him. I think it's totally ok for them to do that, even without providing more information.

In fact, it's totally conceivable that revealing more information could hurt more people, or the same people more, or Crockford himself, or all of this. I fail to see how it would "advance humanity" if they did such a thing.

prance··on In defence of Douglas Crockford
This article is based on the assumption that those two statements from Rockford were the actual reason for his disinvitation - because that's "everything [the author's] been able to find". Which is not the case according to nodevember's statement[1].

Besides, the fact that the author is criticising people for calling for a disinvite of a white supremacist speaker from LamdaConf[2] doesn't quite increase my trust in his opinions.

[1] http://nodevember.org/statement.html [2] https://modelviewculture.com/news/lambda-conf-fuckery-white-...

prance··on In defence of Douglas Crockford
No, absolutely reasonable. They say that multiple other speakers have stated that Crockford's "presence would make some speakers uncomfortable to the point where they refused to attend or speak." So they chose to prioritise them over him, something which they can totally do as organisers. Do they owe everyone a detailed explanation for that? I think not.
prance··on Republic – Now everyone can invest in startups
pmen is right. We considered crowd investments for our own startup, and concluded it's too much work, hassle and inflexibility. Republic's model seems to mitigate this somewhat, but (probably?) only works in the US and even they state on their site:

"The tradeoff for the benefits of investment crowdfunding is the complex regulatory requirements that companies must follow. The general spirit of the law is simple: companies should provide complete and accurate information so that the public can make informed investment decisions. Incorrect or misleading information comes with severe legal consequences. In addition to the following, you should also consult your attorneys and accountants to ensure full compliance with all legal and accounting requirements. Republic as a funding portal is not authorized to and does not provide legal, accounting or investment advice."

Sounds like it could very well still be too much for us.

prance··on Republic – Now everyone can invest in startups
Actually, both Apple and Orange are public companies :D
prance··on Thousands of adoptees thought they were US citizens but learned they are not
Why is this down voted? It is the truth.
prance··on Why bad scientific code beats code following “best practices” (2014)
Actually it's not exactly the same: he added a README.
prance··on “Baffling” “signal” “from HD 164595” is probably none of the above
I want to believe!
prance··on Show HN: Carbide – A New Programming Environment
LightTable started as a clojure/-script IDE which are not imperative but functional languages.
prance··on Show HN: Carbide – A New Programming Environment
I was pretty excited about LightTable (which has some similar ideas) when it started out, but then Chris Granger went on to another project and LightTable was left hanging. They open-sourced it, but developer uptake was slow initially and there wasn't much progress. Commits/pull requests seem to be better now (2 years on), but e.g. the blog is still very much inactive, and the last release is more than half a year ago.

So for me, I'd only try yet another IDE if I have enough confidence that it will live long enough. The commitment of the original team is of course a big factor, but as was seen with LightTable and other projects, that can change quickly. So I would require that either - it is commercial and has enough investment/backing, - it is open-sourced and gets enough dev uptake quickly, or - I believe so much in the concept that I'd try it even if the other two points are not satisfied.

Speaking of functionality, however, there isn't any mention of refactoring capacities. To me, that's probably the #1 feature why I'd use an IDE instead of just an editor in the first place. I'd consider the in-place partial debugging display only as a nice add-on, but nothing I would throw out a mature IDE with proper refactoring, search (for definitions, references) and other typical IDE functionality for.

prance··on Power in the Age of the Feudal Internet
Yes, participation is a difficult thing to ensure in a democracy, and even more so when it's online. A few years ago, I was a member of the German pirate party. We tried to implement "liquid democracy", using Liquid Feedback. It allows every party member to vote on anything or delegate their votes (based on categories, subcategories or single initiatives) to any other voter, and change those delegations at any time.

Because of the known security problems with digital voting systems, the system was supposed to work only as a tool to form opinions. Initiatives were then put to final vote in real-life assemblies, where everyone was allowed to participate. We didn't have any "classical" delegates.

Both of these steps posed their challenges in participation:

- Liquid Feedback was not the easies tool to understand and use. For non-technical people, it was quite the challenge. And of course, a computer in the first place.

- Full member real-life assemblies, particularly on a national level, require time and money for travel, accommodation etc. Because we didn't have "real" delegates, if you couldn't afford to go, you were out.

There were some suggestions to overcome these issues (like a "permanent assembly" which would work by postal -snail mail- vote), but that never came to pass. (Or at least I think it didn't, I moved out of the country since then and don't follow that closely anymore.)

prance··on The Apple Goes Mushy Part I: OS X's Interface Decline
Sums it up. Most interesting is that more teenagers tend to know what an icon is used for on the computer than what it originally represented. Which makes total sense because they grew up with these icons.

So it might make more sense to ask "to what degree are people used to this icon?" rather than "how many know where this icon came from?".

In this sense, changing established icons (like I would argue the photo app's one) doesn't seem such a good idea.

prance··on With Launch of AU Passport, Africa Is Now Borderless
Well she didn't have to stand in line for the year ;) No seriously, at some of the bigger and more central places in Nairobi you can now pick a number (and take a guess how long that might take, maybe risk going about some business in the meantime).

But yes, new tech might help with the actual issuing/processing time. In the past, getting a new passport was a matter of a few weeks[1], but they installed various processes to supposedly enhance security. This is not unfounded, as there has been a lot of counterfeiting going on with IDs and passports, e.g. for elections, immigration (mostly from Somalia), or foreign workers. But as long as better/more efficient systems are in place, I doubt their effectiveness.

[1] Even though corruption is rampant in Kenya, it isn't too bad if you're steadfastly refusing to pay bribes.

prance··on With Launch of AU Passport, Africa Is Now Borderless
In 2014, it took 4 months for my wife's Kenyan passport to be renewed. Last year, she applied for a new ID card (to get her new family name on it), and she was able to collect it more than one year later.

At least here in Kenya, I'm not going to hold my breath for the AU passport...

prance··on The Untouchables – Why it’s getting harder to stop multinational corporations
This article tells some truths but is pretty confused. It headlines multinationals based in China, India, Russia etc. as the problem but then only mentions that these companies are not accountable in their home countries, allegedly. Apart from not providing any evidence towards this, it also doesn't give any reasons of why this is so or who could do what to change that.

Then, it gives an example at length that doesn't have anything to do with multinationals. Instead, it's a classic example of corruption and land-grabbing. But while these problems are prevalent in much of the developing world, there are certainly huge differences between different countries. E.g. here in Kenya, land-grabbing is rampant, but its usually smaller cases, and the public increasingly fights back (see e.g. https://www.standardmedia.co.ke/ureport/story/2000163954/lan...)

Nevertheless, the article chooses to present an example from Zimbabwe of all countries, one of the worst-governed countries on Earth, as representative.

There was another recent article on Foreign Policy which summed up the land-buying/grabbing situation across Africa much more balanced: http://foreignpolicy.com/2015/10/20/the-myth-of-the-african-...

← PreviousPage 2 of 2