HNHacker News
TopNewBestAskShowJobs

smeehee

30 karma · joined September 2, 2015

submissionscomments
smeehee··on Show HN: Make cursed fonts like Times New Bastard
Fun though the idea is, assistive technologies such as TTS will also have problems with it.
smeehee··on Thinking out loud about 2nd-gen email
Fifth group here: HTML mail should never have been implemented. Better, never thought of in the first place.
smeehee··on Thinking out loud about 2nd-gen email
And require that if any colours are set, both foreground and background are set. (I've seen too much breakage with assumptions about one or the other.)
smeehee··on Thinking out loud about 2nd-gen email
MX records don't send messages. Assuming that “sent to them via SMTP” is meant… well, moving all messages to ‘junk’ isn't a good idea: it needs to be restricted to messages sent on or after that time. But why not just respond with “554 No SMTP service here” on opening the connection?
smeehee··on Backdoor in upstream xz/liblzma leading to SSH server compromise
Debian have reverted xz-utils (in unstable) to 5.4.5 – actual version string is “5.6.1+really5.4.5-1”. So presumably that version's safe; we shall see…
smeehee··on Chrome Widevine DRM can no longer be disabled
Hmm… I'd look but there don't seem to be any builds since late November on mozilla.debian.net.
smeehee··on Chrome Widevine DRM can no longer be disabled
I recently switched from Firefox to Vivaldi due to the upcoming dependency on PulseAudio. Depending on what happens, I may end up switching back; but if I do, I expect support for ALSA either by default, a run-time option or a compile-time switch.
smeehee··on The closest I've ever come to falling for a Gmail phishing attack
Google can prompt you to confirm the login via your phone. It appears to work well: there's a time-out, and this time-out is also triggered if a second login attempt is made in parallel (and reaches the confirmation stage).

So… whichever login attempt gets to confirmation stage last wins (not relevant in this situation), and the confirmation screen on (at least) my phone does not indicate anything regarding location (which is highly relevant).

This looks a little weaker than TOTP (you're basically trading a little security for the convenience of not entering a code while keeping the second factor) and a lot weaker than U2F.

smeehee··on The Chrome Distortion: how Chrome negatively alters our expectations
Sometimes, it's clear what minimum window size they've assumed. I know of one (bank login) which doesn't work well on a netbook due to this.

I tried to report the problem via the site feedback link which they helpfully provide in most of their page footers. It fails in Firefox but works fine in Chromium; I ended up reporting two problems reported instead of one.

smeehee··on The Chrome Distortion: how Chrome negatively alters our expectations
I think that the IE11 one, of those, is best. I would have said that Firefox's rendering matched it but it's doing that broken kind of anti-aliasing which adds colour fringing.
smeehee··on The Chrome Distortion: how Chrome negatively alters our expectations
Oops. Somebody forgot to set the background colour on that page. As I've changed the default to light grey (white's too bright), that makes it rather less readable...
smeehee··on Updates Make Windows 7 and 8 Spy on You Like Windows 10
This seems loosely equivalent to Google's account activity mail, but with invade-by-default. I can see it being useful, though, despite the flaws which you describe.

Also – potentially – incredibly dangerous, as other posters mention. I don't think that we can have the possibility of one without the possibility of the other here.