HNHacker News
TopNewBestAskShowJobs

shortsunblack

300 karma · joined November 10, 2023

submissionscomments
shortsunblack··on Anthropic officially bans using subscription auth for third party use
Anthropic has no authority to do as such. Users and third apps are protected by interoperability exceptions found in copyright case law.

Trying to prevent competitors from interoperating with the service also may be construed as anticompetitive behaviour.

The implementation details of an authentication process do not beget legal privileges to be a monopolist. What an absurd thought.

shortsunblack··on What has Docker become?
Open source community detests dilettante attempts at rent seeking by building mediocre wrappers over commodity software.

Docker did not invent Linux containers. They did not invent namespaces or chroots.

You'll be hard pressed to name the things they did invent and those things have long ago left Docker to hang dry (OCI imagespec).

OrbStack is built by a single person and it provides an objectively better experience than Docker Desktop, built presumably by dozens of full time engineers.

People detest incompetence and rent seeking. That they do.

The lack of important contributions of Docker can be best summarized by all the alternatives that popped up in no time. With Kubernetes now defaulting to CRI-O, modern container stack has precisely zero Dockerisms.

shortsunblack··on Anthropic Explicitly Blocking OpenCode
OpenCode is doing nothing wrong and adversarial interoperability is the cornerstone of hacker ethos.

As such, the sentiment in this thread is chilling.

shortsunblack··on Passkeys: They're not perfect but they're getting better
Yes. HMAC extension allows for this use case.
shortsunblack··on Passkeys: They're not perfect but they're getting better
Android to this day does not support CTAP 2.1, hence it does not support hardware-bound passkeys with PIN via NFC as transport. You can only do PIN via USB.

Google does not care about FIDO or standards compliance. They care about vendor lock-in their proprietary passkey offerings allow.

shortsunblack··on VMScape and why Xen dodged it
KVM was made because Citrix made moves against Xen that spooked Linux community, hence KVM. Then Red Hat ran with it and based its virtualization platform on it.

Citrix involvement has subsided in meantime and the ecosystem is much healthier (governance is actually under Linux Foundation), but the damage was done.

Xen to this day lacks in features, also.

shortsunblack··on EU age verification app not planning desktop support
The current reference design is not compatible with existing law. eIDAS regulation that is the legal basis for digital wallet mandates unlinkability. GDPR has a general requirement for technical controls to be state of the art. Inherent reliance on American monopolies is incompatible with Digital Markets Act.

The current design and usage of cryptographic primitives does not allow for unlikability (it is actually quite easy to for verifiers and relying parties to collude) and it certainly is not state-of-the-art. BBS signatures would achieve actual unlinkability, but those have been outright rejected by the designers.

Current implementation is poised to not comply with the regulation that established the mandate for the wallet and it violates GDPR. The best one could hope for is for CJEU to strike down the whole project.

The GitHub organization of the OP's post has various issues that discuss these ills. Here is a position of several cryptographers against the current design: https://github.com/eu-digital-identity-wallet/eudi-doc-archi...

shortsunblack··on OpenAI slams court order to save all ChatGPT logs, including deleted chats
The legal obligation has to come from relevant member state or EU law. Not third party countries' laws.

This at best is force majeure that prohibits OpenAI with satisfying its contractual obligations that are there to comply with EU law. But contractual obligations are not the only control organizations have to ensure compliance with EU law, so this is not a defense.

shortsunblack··on OpenAI slams court order to save all ChatGPT logs, including deleted chats
OpenAI is breaching relevant laws that regulate data protection. Being compelled by a foreign power, for instance, are not grounds for data processing under GDPR.

OpenAI has not started to "be incompliant" with GDPR with this order, yes. More like OpenAI was always incompliant because it does not have relevant controls installed that mitigates extraterritorial tendencies of US law.

Regardless of legality of retention this order brings, them not notifying their users (the court did not compel them to hide this from their users (no gag order is in place) about this material change of data processing, could be constituted as breach of various consumer protection laws, misrepresentation, unfair dealing, false advertising and related.

shortsunblack··on OpenAI slams court order to save all ChatGPT logs, including deleted chats
The order mandates retention of all user data, even of non-Americans. This is a massive extraterritorial overreach and a highlight of how US law has zero regard to data protection as a fundamental human right. As if there were not enough concerns about US cloud providers already.
shortsunblack··on Docs – Open source alternative to Notion or Outline
And United States still has regulations. Chevron doctrine is not a thing in Europe and European institutions do not get captured by NIMBYs when industry wants to build a railroad, a house or an apartment complex. There are no hundreds of governmental organizations demanding you impact assessments and environmental studies.

For crying out loud, as an American you cannot work on your own house, since a lot of labour is licensed (electrical work, etc) and taped in red.

The regulation Americans talk of in disparaging way is always the regulation that shifts and allows consumer/user surplus.

shortsunblack··on Deploy from local to production (self-hosted)
Cloud init/Cloud config is a standard way to provision Linux hosts. It is slowly being outcompeted by Ignition and the friends, though.
shortsunblack··on AI systems with 'unacceptable risk' are now banned in the EU
EU law largely does not regulate national security matters of the states. Though that justification is limited per international law (such as ECHR, which is the basis of many anti-government surveillance rulings by CJEU). All European Union members are part of ECHR because that is a pre-requisite for EU membership.

But ECHR is not part of EU law, especially it is not binding on the European Commission (in the context of it being a federal or seemingly federal political executive). This creates a catch-22 where member states might be violating ECHR but are mandated by EU law, though this is a very fringe consequence arising out of legal fiction and failed plans to federalize EU. Most recently, this legal fiction has become relevant in Chat Control discourse.

Great Britain and Poland have explicit opt-outs out of some European law.

shortsunblack··on AI systems with 'unacceptable risk' are now banned in the EU
You cannot barter with fundamental human rights, which right to data protection is (as per Charter of Fundamental Rights of the European Union), the same way you cannot barter yourself into slavery, even if you insist you are willing and consenting. By what precedent? By the precedent of the state being sovereign in enacting law.
shortsunblack··on AI systems with 'unacceptable risk' are now banned in the EU
Free as in free from coercion. And GDPR has clear language of 'no detriment'.
shortsunblack··on AI systems with 'unacceptable risk' are now banned in the EU
It's called dark patterns and malicious compliance . The annoying banners in particular, were designed by IAB Tech Lab, which is an industry front for adtech/martech companies.
shortsunblack··on AI systems with 'unacceptable risk' are now banned in the EU
Consent is never "needed". Consent is one of many legal bases that allows for data processing to take place. If other legal bases than consent do not apply, the industry can use "consent" as a get out of jail card. Consent as a legal basis was heavily lobbied by Big Tech.

If even consent does not apply, then the data shall not be processed. That's the end of it.

shortsunblack··on AI systems with 'unacceptable risk' are now banned in the EU
By which data is that clear? If anything, GDPR has lead to greater investment in areas that actually matter. Zero knowledge proofs, pseudonymization techniques, user friendly open-source SaaS products such as NextCloud.
shortsunblack··on Sigstore: Making sure your software is what it claims to be
See Keylime for this.
shortsunblack··on Supreme Court upholds TikTok ban, but Trump might offer lifeline
The ban is nothing more than an attempt to abridge speech and deny the youth voice in politics. TikTok increasingly has become refuge from censorship occurring on other platforms (see the recent issues). The lawmakers indicated that is the reason for the ban.

If United States was honestly concerned about data protection and privacy, it would devise a federal privacy law that models GDPR. They are trying to pass a federal law now, but it is seriously flawed and they are trying to preempt more user-centric privacy laws of the states.

Finally, such partisan, targeted and unprincipled bans reenforce that EU's approach on issues such as data transfers abroad (see Schrems 1 and Schrems 2) is perfectly valid. EU has a principled regulation, which gets evaluated by free and democratic courts. The outcomes are what they are. Not partisan and discriminatory, as they are here.

shortsunblack··on Windows BitLocker – Screwed Without a Screwdriver
Local security authority protection changes this.
shortsunblack··on Dumping Memory to Bypass BitLocker on Windows 11
See the talk "Recent TPM Security Enhancements to the Linux Kernel" by a Microsoft engineer (I find this ironic) for recent Linux TPM security enhancements. New features add some transport security.

https://youtu.be/WK7NERQXh4I

shortsunblack··on Why we use our own hardware
You can over-provision your own baremetal resources 20x and it will be still cheaper than cloud. The capex talking point is just that, a talking point.
shortsunblack··on Firefox removes "do not track" feature support
GPC does not meet GDPR's requirements and cannot be used for gaining consent under GDPR. There already has been a browser signal in design that meets GDPR requirements for consent, but it was ignored. The industry instead rallied behind GPC.

See: https://www.dataprotectioncontrol.org/

shortsunblack··on Firefox removes "do not track" feature support
The relevant context is that Mozilla is now an adtech company. Reuter's coverage over noyb complaint over illegal "PET" adtech: https://www.reuters.com/technology/mozilla-hit-with-privacy-...

Mozilla buying out an adtech company: https://blog.mozilla.org/en/mozilla/mozilla-anonym-raising-t...

Mozilla has also been lending its credibility and whitewashing Meta's "PET" measuring standards at W3C. More on this, from Mozilla: https://blog.mozilla.org/en/mozilla/privacy-preserving-attri...

shortsunblack··on Qualcomm Wants to Buy Intel
To the poster, Europe does not exercise outsized antitrust influence in the US. Many of these companies have their tax residency in the EU. There is no need to "deny" anything. If the company gets fined and it refuses to pay the fine, EU seizes the money in one of many bank accounts in Europe.
shortsunblack··on How de-Googled is Lineage OS?
Google gladly will broadcast you OpenRTB data (which includes meter accuracy location data) with shitty enterprise XML APIs if you are in the lists.
shortsunblack··on Appeals court finds California’s “Age Appropriate Design Code” unconstitutional
Children do not belong on the internet. Full stop. And trying to change that with regulation is in itself problematic from safety perspective.
shortsunblack··on Why toilet paper keeps getting smaller and smaller
Producers should be required to make disclosures in officially recognized boards/gazettes before substantially changing quality/composition/recipe/materials/function of any good. Make it 3 to 6 months. A consumer should not be screwed for buying an inferior product for the same price because a producer decided to reduce quality to increase margins. It's a form of information asymmetry that leads to inefficiency in markets.

This works even more easily if the product already needs to be registered in some gov't registry. For example books and with the case of substituting good quality paper with worse quality paper (less gsm or such).

shortsunblack··on Canarytokens: Honeypot for critical credentials, get notified when they are used (2015)
I wonder whether eBPF allows for increased deception capabilities.
Page 1 of 5Next →