HNHacker News
TopNewBestAskShowJobs

schlowmo

1,012 karma · joined March 29, 2015

submissionscomments
schlowmo··on German woman uses an AirTag to find a government arm that doesn't exist
There's a newer post on medium by her which mentions the AirTag [0]. Sorry I didn't spot that myself when I linked to the older medium post in an earlier comment.

[0] https://lilithwittmann.medium.com/bundesservice-telekommunik...

schlowmo··on German woman uses an AirTag to find a government arm that doesn't exist
A longer article by Lilith Wittmann (the "German woman") herself can be found here [0] or you could listen to the detailed and entertaining interview on the podcast Logbuch:Netzpolitik [1], unfortunately both only in German language.

[0] https://lilithwittmann.medium.com/bundesservice-telekommunik...

[1] https://logbuch-netzpolitik.de/lnp419-und-aehnlich-verschwor...

schlowmo··on An update on AirTag and unwanted tracking
I don't think that the timing of this has much to do with the following, but I find it an amusing coincidence:

Just a month ago the German activist Lilith Wittmann used an airtag to corroborate the suspicion that a branch of the German government she (or anyone else who should) never heard about before called "Bundesservice Telekommunikation" (Federal service of telecommunication) is just a front for the Bundesamt für Verfassungsschutz (Federal Office for the Protection of the Constitution, the federal domestic intelligence agency). Unfortunately I only found this [0] article in english quickly, a longer piece by herself in German can be found at [1].

[0] https://www.imore.com/german-woman-uses-airtag-find-governme...

[1] https://lilithwittmann.medium.com/bundesservice-telekommunik...

schlowmo··on Enom still has DNS issues
Afer a scheduled datacenter migration enom has still issues with their DNS services. It's now more than 3 days and counting. It took them more than 2 days to even acknowledge the issues. For those two days DNS wasn't resolving for some domains using their DNS servers. For some customers it wasn't possible to login to their DNS management console to change the primary DNS servers.

I would never do business with them voluntary but I got an domain registered with them through Google Workspace (back then called Google Apps) almost ten years ago. My guess would be that the affected Google customers alone may be in the thousands. It took them more than two days to get the DNS resolving again, which meant not even email was working since the MX records just vanished.

It's just a total shitshow. I'm now waiting for getting an Auth Code to transfer my domain to another registrar.

schlowmo··on Asking nicely for root command execution and getting it
> It's worse when working with vendors

Well this works the other way around too. I found this especially true when delivering software which is considered an interim solution.

More than once I got root privileges on customer machines or seen my software run as root because the project owner found it too cumbersome to deal with his own employers security regulations. Or just wasn't given the budget to deal with it properly. Sometimes it's easier to get an exception than to follow protocol.

This is coming back to haunt you if something goes wrong or an interim solution wasn't so interim after all. If someone responsible for auditing permissions asks at this later stage it was always the vendors fault.

schlowmo··on Temporal Tables PostgreSQL Extension
For everyone using MariaDB instead of PostgreSQL, a similiar feature called "System-Versioned Tables" exists since MariaDB 10.3 [0].

We're using this feature in production as part of a financial forecast application. This makes it possible to forecast spendings/revenues based on data from different points in time. For example the users can generate a forecast in december based on data as valid as in june and can compare how good their forecast model predicted the reality at the end of the year.

This works quite well but there are some pain points:

1. System-period (transaction time) data is immutable and can't be changed with queries. If "faulty" (in the sense of "technically correct" but not reflecting reality) data is imported to the database, the database will return this faulty data for this "as of" date no matter what and there is no easy way to drop this data later.

2. This is the main reason why logical backups (mysqldump) for historical data are not possible, since there is no way to write that data back with queries. This should be possible in the future but the correpondig (critical) bug ticket wasn't solved in almost 3 years.[1] You can use mariabackup (physical backups of the underlying file-system storage) instead but this requires console-access to the database server which isn't always allowed in corporate environments.

3. I'm not aware of any ORM framework which supports System-versioned tables (neither MariaDB nor PostgreSQL) so you have to write your own solution on top of an existing ORM or use raw queries.

[0] https://mariadb.com/kb/en/system-versioned-tables/ [1] https://jira.mariadb.org/browse/MDEV-16029

schlowmo··on Temporal Tables PostgreSQL Extension
(Disclaimer: I'm coming from MariaDBs temporal table feature but this is basically the same in PostgreSQL)

Temporal tables adding an additional "time axis" to SQL databases. A "valid from" and "valid to" field is added to each row and the SQL syntax is extended for allowing two new types of queries:

1. Query the data as of a specific point in time. E.g. "show all customers as of April 9th 2021". This not only limits WHICH customers you see, but also select the exact state of each customer as valid at this point in time. For example if the adress of a customer changed on April 10th, you will get the old address.

2. Query all versions of a specific entity. This makes tracking of changes or time series analysis possible.

This feature is transparent, so if you use "normal" SQL queries, you keep getting the current state of the data. I don't know if this is true for this PostgreSQL extension, but MariaDB even hides the "valid from" and "valid to" columns and only show them when you explicitly select them.

Additionally there a two types of "valid from"/"valid to" data, which can exist at the same time:

1. Application period: Those validity dates represent a period in the real world. If we stay at the customer address example, they can express "a customer informed me, that their addess will change on April 15th, so the current address is valid until then and the new address is valid from then".

2. System period (also called transaction time): Those validity dates are a kind of technical period. They represent when data changed in the database, e.g. the exact point in time when an UPDATE query was executed.

schlowmo··on Audacity 3.0
You're right. I didn't meant to say that Audacity isn't for professionals. But in my experience most audio professional (like audio engineers) pick (or get picked by their educational institution) a tool early in their career and stick to it. Most of the times this tool is a full-fledged DAW in which they acquire quite a muscle memory. So switching tools later (even for simple tasks, which don't require a DAW) comes with a big "performance hit".
schlowmo··on Audacity 3.0
Very pleased that Audacity is still actively developed. I said it before but I think this can't be overstated:

Audacity may had some quirks over the years but it's still one of the most (if not the most) accessible tool for audio editing by non-professionals with an adequate feature set. It's used by community radio stations all over the world since it's easy to teach and cross-platform while being free.

schlowmo··on Woice.me – async voice communication for teams: work, at your own pace
> Voice messages are easier for the producer, but are always more work for the consumer.

This is so true especially for long voice messages. I really don't like listening to people thinking aloud about what they want to tell me. I mean...this isn't a suprised-by-voicemail moment, they intentionally decided they wanted to send this voice message in the first place.

But it gets even worse if you (like me) don't like sending voice messages. Maybe it's just me, but to reply to a lengthy voice message via text I have to listen to it in parts multiple times to adress every question/topic which was raised in it.

I'm totally fine with people calling me, if they prefer voice. But please don't send me voice messages as long you're not in a car or otherwise unable to text and have a real important message.

> I very much do not want to be bombarded with voice messages in a professional context.

I had one client who started sending me voice messages and it drove me nuts. I realised that most people tend to forget what they said in a voice message faster then via other means.

schlowmo··on US doctor forgives $650k in medical bills for cancer patients
I was commenting on a specific point made by the parent comment. It's pretty far fetched I'm in denial of the root issue when I even mentioned the real solution which you're agreeing with.

So while I get your sentiment you're really arguing against the wrong person here.

Besides that in my opinion there is a significant difference between "falling through the cracks" and making wrong decisions poorer people aren't even allowed to make - and then wanting those poorer people pay for your errors.

schlowmo··on US doctor forgives $650k in medical bills for cancer patients
> The problem is you can´t easily opt back into the public system once you´re out (especially once you´re old), so there are tens of thousands (if not hundreds), that get stuck in the private system without being able to pay the fees because they´ve become poor (possibly because of health reasons), and then they get denied coverage and thus access to medical services.

Although I recognize the personal hardship this can cause, I fail to accept this as a general injustice. In the German healthcare system nobody is forced to choose a private insurance instead of the public one. Choosing a private insurance when you're allowed to (which often means because you're in a higher income bracket) is usually only cheaper if you're young and healthy. It's basically a gamble on your own health for wealthy people.

And if the wealthy young and healthy population don't contribute to the public health insurance system which also pays for the not-so-wealthy and not-so-healthy (older) population, the public insurance system isn't sustainable.

The real problem with this system is its division in public and private insurance. Mandatory public insurance would mean lower insurance fees for public insurance and the problem of being stuck in private insurance would no longer exist.

schlowmo··on Banning facial recognition is missing the point
Unfortunately this is already illegal in some other western countries for quite some time. In Germany for example since 1985 (one year late though). It's often used as legitimation when the police is using violence against otherwise peaceful protests.

In the aftermath of the G20 summit in Hamburg there were some advancements to even tighten the law while at the same time the police was using illegal face recognition software.

schlowmo··on Show HN: Ananas – a hackable data tool for beginners
I really wanted to like Metabase but unfortunately it's way behind its promise. I made an attempt to use it in a customer project for creating very basic customizable dashboard-like statistics, with little to no success. Just to name a few pain points:

- using the docker image is easy; not so using the jar file especially due to very little documentation

- confusing UI paired with lack of extensive documentation

- this makes it far from "easy" to be used by "everyone in your company" (quotes from metabase marketing claim): you really have to know how to do things, even easy ones like changing labels

- the UI contains many minor bugs which sometimes lead to unsavable metrics and you have just start from scratch

- no build-in way to export dashboards, which makes it nearly impossible to test your new metrics on a different system before pushing it to production; if you really want to do this, you have to juggle with database dumps

There might be some valid use cases for metabase, but I don't think it's very usable for non-technical users. I strongly suggest to evaluate it thoroughly before counting on it.

Nevertheless thanks for making it open source and free to use, so don't get me wrong.

schlowmo··on Tenants win right to physical keys over smart locks from landlords
> "At least here in Germany, the apartment owner is allowed to enter your apartment using his key in emergency situations."

I am not a lawyer but I know that this is a common misunderstanding in Germany. The landlord is not allowed to keep a key to the apartment he rented out, unless you're explicitly consent to it.[0]

You have to grant him access in case of an emergency and if you don't do that, forced entry may be legal (like in the case of a pipe burst).

[0] https://www.mieterbund.de/index.php?id=566

schlowmo··on Tinfoil Chat – Onion-routed, endpoint secure messaging system
> (It's actually only sending computer that must not be compromised during installation, but in other respects you're right.)

Thanks for clarification, it slipped my attention that plaintext extraction isn't possible even with a compromised receiving endpoint as long as the data-diode is in place.

And thanks for your work. I'm currently experimenting with TFC on various hardware and considering it as topic of my (long due) bachelor thesis in Software Engineering.

schlowmo··on Tinfoil Chat – Onion-routed, endpoint secure messaging system
The part of the design which piqued my curiosity and distinguish Tinfoil Chat from other messengers is the endpoint-security aspect.

Besides the software it uses a very simple made data-diode[0] circuit especially to prevent key- and plaintext-extraction by limiting the data flow in only one direction. This is used to connect three distinct computers (sending/receiving/networked) from which only one is considered compromised (the networked one).

The rational behind that is as long as your (sending/encrypting and receiving/decrypting) endpoints aren't compromised during installation it's very hard to compromise them later.

That can't be said about Wire on an unsave endpoint like an android phone. On the other hand, Tinfoil Chat isn't the easy to use messenger which you want to recommend to any non tech-savvy person.

[0] https://en.wikipedia.org/wiki/Unidirectional_network

schlowmo··on Unveiling the first-ever image of a black hole [video]
> is currently eating something big

You mean: was eating something big 55 million years ago ;)

schlowmo··on The Gyllenhaal Experiment
Yes, I also had the same issue with Chrome 72 on Android. Probably saved myself some shame though.
schlowmo··on EU wants to require platforms to filter uploaded content, including code
> "Illegal content means any information which is not in compliance with Union law or the law of a Member State [...]"

The "law of a Member State" part is very concerning. If it's enough that content is illegal in one member state to have it taken down in the whole EU, very tough times lying ahead.

The first two things which came to my mind were the new Polish holocaust law and the current prosecution of various symbols of Kurdish groups (e.g. flags of YPG) in Germany.

Say goodbye to free speech.

schlowmo··on There's a Persistent Hum in Windsor, Ontario, and No One Knows Why
> Is a hum not more or less expected in the vicinity of busy harbors, even more so than in general industrial areas?

You're absolutely right, but there are different types of hums and many of them you can directly be linked to a source. Just to name the two loudest in my direct neighbourhood:

* Some kind of ships at slow speeds make very loud humming sounds. The loudest in my expirience are big car carriers (to be specific: Grimaldi carriers in Hamburg). The sound is very unsettling since it's at such a low frequency, that it's more "feeling" than "hearing". But the good thing is that it's over after the ship passes by.

* Some procedures in the nearby ship repair dock are very unsettling too. Especially sandblasting ship hulls is very annoying and for some reasons they mainly do it at night.

But the most distracting hum of which I was talking about in my parent comment has yet to be linked to a specific source. And it lasts much longer than my other examples, typically for days. So it has to be something which is produced only in specific conditions. This doesn't mean that this is ruling out all of your examples (e.g. large refrigerators could only be in use when the storage capacity is needed, it could be specific vessels etc.).

schlowmo··on There's a Persistent Hum in Windsor, Ontario, and No One Knows Why
We can put Hamburg (Germany) on the list of "humming cities" too. When I moved close to the harbour I started hearing a humming sound, espececially at night, almost exclusively indoors.

None of my flatmates heard that sound, so I started questioning my perception until I found another person living in the same building hearing that sound. Our bedrooms are located one below the other and the sound is most perceivable in that rooms, but we can hear that sound at other places inside the building too while others can not.

Some time later, articles in various local newspapers about that hum appeared (search for "Brummen Hamburg" if you're interested, unfortunately only articles in german), telling stories about various people along the river "Elbe" hearing that hum. I started reading about the Windsor and Bristol hum that time too.

A local politician started investigating that issue together with scientist from a technical university but - besides some theories (e.g. a big power plant) which couldn't be proven - with no success. The acousticians where cited that some of them could hear the hum at various places too, but in terms of sound level they couldn't measure it distincly from the "general" background noises of the city (with harbour, industry and much highway traffic).

In the last few years there wasn't much news about it but the hum is still there in varying intensity and duration.

schlowmo··on Self-Crashing Cars
Thanks for sharing your concerns. But regarding your last two sentences, I'm sorry that I've to tell you that I think we are already fucked. I don't think it's a good idea to speed up the process of being fucked even more.
schlowmo··on Self-Crashing Cars
While I agree with the author about the undervalued risks of autonomous vehicles in the light of careless security practices his proposed solution is just insane.

In my opinion the demand for a government controlled kill switch in every piece of hardware that is somehow able to harm people is much more threatening in so many ways than the insecurity the author is trying to reduce. Just a few:

1. Based on the asumption, that ones current government/state is for the good of all people, what gives him the confidence that this will stay that way? What if your beloved government goes rogue? That's a lot power for an autocratic regime.

2. Why even trust the government in the first place with that kill switch? They are the same people which are careless about infrastructure critical ITSec since decades.

3. An univervsal security module which is highly standardized is a very profitable target. While the author is aware that finding an attack vector of one particular vehicle can mean that all vehicles of that type can be compromised, he doesn't come to the conclusion that the same logic applies to his security module.

schlowmo··on Who the Hell Uses Onion Juice?
You poor one. My mother also gave me "onion juice" when I got a cold, but there was one big difference: The onions were cooked with tons of rocked candy. I have to admit that it was my favorite medicine.

Maybe you should try that recipe to cure your onion juice trauma ;)

schlowmo··on How Automakers Invented the Crime of “Jaywalking”
Those signs differ from country to country, but the design is very similar. In Germany this sign looks like this

https://de.wikipedia.org/wiki/Verkehrsberuhigter_Bereich#/me...

The official meaning is "begining of a traffic calming area" (verkehrsberuhigter Bereich) but most people call it "Spielstraße" (literal translation "street for playing"). I don't know if the sign was designed after the common term for those streets or vice versa.

schlowmo··on Announcing the OpenWrt/LEDE merge
> "just not from someone with their best interests at hear"

Oh dear...I really wish your kids have the best parents in the world. I really do, my parents probably believed that too, but unfortunately they were not - surprise!

But I'm really happy that I was born at least two decades too early for that shit. I hope kids can still outsmart their parents today. If not, we've lost.

schlowmo··on Quake on an oscilloscope (2014)
This is one of those Why would you even do that? followed by Oh well...sorry for asking, totally got it article.

I really applaud such curiosity.

schlowmo··on NSA Unlawfully Surveiled Kim Dotcom in New Zealand
> "In Germany, when intelligence agencies merge with ordinary law enforcement, we call it Gestapo."

Who is "we" in this context? At least in the Germany I know most people actually call this "Gefahrenabwehr" (literally: danger prevention) or "Staatsschutz" and can't remember any historic event which has shown that this is a bad idea.

If right-wing terrorist join the party people call it "Nationalsozialistischer Untergrund" (National Socialist Underground) [0]

[0] https://en.m.wikipedia.org/wiki/National_Socialist_Undergrou...

schlowmo··on Twitter is broken for some users but status page shows everything is fine
I can confirm issues myself, also there's discussion about ongoing issues on reddit[0] and people reporting issues to downdetector[1].

[0] https://www.reddit.com/r/Twitter/comments/6c1p1t/so_twitter_...

[1] http://downdetector.com/status/twitter

← PreviousPage 2 of 5Next →