HNHacker News
TopNewBestAskShowJobs

solstice

611 karma · joined June 26, 2013

submissionscomments
solstice··on Why webcams aren’t good enough
Are you sure that that won't have begun to change after one year of pandemic-related Home-Office?
solstice··on Why webcams aren’t good enough
Have two cams on the edges instead to avoid this and calculate an average image. (Or even use it for stereoscopy)
solstice··on Bitwarden releases “emergency access” feature
You could generate parity files to guard against this. There was some discussion recently here about tools to do it. One example that is decent is https://github.com/brenthuisman/par2deep
solstice··on Show HN: I built Multy – Generate a short URL to share a list of websites
Click on the train icon next to "www."
solstice··on Show HN: I built Multy – Generate a short URL to share a list of websites
I don't have the ability to downvote your comment but if I could I would.

This sort of suggestion of niche web sites (by different people) that I basically would have never comes across except through some recommendation is something that I highly value HN for.

solstice··on Tencent is acquiring a majority stake in Klei Entertainment
I think that you're wrong specifically and in what seems like an uncharitable insinuation about China.

对等 duì deng: equal status/treatment, parity (under the law), equity, reciprocity

在对等的基础上 Zài duì děng de jīchǔ shàng on the basis of reciprocity; on a reciprocal basis

Source: plecodict

solstice··on Three Mathematicians We Lost in 2020
Wear your seat belts, people...
solstice··on Par2cmdline is a PAR 2.0 compatible file verification and repair tool
I almost did but I tried something else and found the likely reason: the file name contained an "ä". Par2deep also fails when there's a CJK character in the filename. After removing these non-ascii characters it works. But this bug is going to cause problems for many people.

Edit: filed a bug report

solstice··on Ask HN: How/Where do you store/backup your photos safely?
Afaik that's exactly what these cryptolockers often do: after infecting a system they start encrypting things while sitting between the user and the OS to transparently forward file access. This also goes for any accessible network drives and external disks that are connected. Then, after a certain time has elapsed (or whatever other metric the malware author has chosen) the cryptolocker stops forwarding file access and holds you ransom.

In that scenario, if your backup drive is writeable from your infected machine, your backups are potentially fucked.

One way to guard against this would be for example a raspberry pi on your network that periodically connects to your (possibly infected) main machine and makes incremental copies over the network to an external HD connected to the Pi. (Meaning the Pi reads and determines what is new, what's is old and how to make the incremental backup.) This of course needs to be coupled to some sort of smart versioning scheme and regular inspection of the backups by the user.

solstice··on We can do better than Signal
See my other reply here: https://news.ycombinator.com/item?id=25812853
solstice··on We can do better than Signal
I'm not saying it's untrue. but that op is saying that something bad is happening at signal without saying what exactly they mean (hence my !!1!-ing) is what I find annoying and I would qualify that as FUD.
solstice··on We can do better than Signal
That's not true afaik. Signal days that they don't store phone numbers beyond the initial setup/verification. See here:

> Does Signal send my number to my contacts? Signal does not send your phone number to anyone unless you send them a message or make a call to them. The Signal service does not have any knowledge of your contacts. Data is all owned by your phone. Registration notifications are never transmitted by anyone in any direction at all; these notifications are created by your phone.

> How does Signal know my contact is using Signal? Signal periodically sends truncated cryptographically hashed phone numbers for contact discovery. Names are never transmitted, and the information is not stored on the servers. The server responds with the contacts that are Signal users and then immediately discards this information. Your phone now knows which of your contacts is a Signal user and notifies you if your contact just started using Signal.

https://support.signal.org/hc/en-us/articles/360007061452-Do...

(Btw, I think that first sentence is a bit confusing and should be classified/reworded.)

solstice··on We can do better than Signal
If all the interesting stuff happens on the client and the server "just" forwards encrypted messages, why would the server need frequent updates?
solstice··on We can do better than Signal
Severely limiting? Please... Signal Desktop can be improved but I use it daily and it works for me™. Also, in many other countries, many people don't even have a PC (outside of work) but they'll definitely have a smartphone. So prioritizing app development is smart imo.
solstice··on We can do better than Signal
Lots of FUD in the opening paragraphs ("no changes to server code since April!!1!"). I stopped reading after that
solstice··on Par2cmdline is a PAR 2.0 compatible file verification and repair tool
Hi. I tried it out with some random pictures and par2deep wasnt able to generate the par2 file for one of them. The error was createdfiles_err. I used the GUI on win10, the file names are of normal length, file permissions are the same as for the others. I can send it to you for testing if you want
solstice··on JingOS: Linux Distro Inspired by the iPad
No it isn't. See their About page
solstice··on Ask HN: How/Where do you store/backup your photos safely?
How do you guard against cryptolockers?
solstice··on Messenger Comparisons – Threema, Signal, Telegram and WhatsApp
Same question. Especially relating to Signal
solstice··on Why Isn’t Telegram End-to-End Encrypted by Default (2017)
The only thing missing from signal among the things you listed is news, no?
solstice··on Signal WhatsApp Chats Import
You imply that they don't understand this. Are you sure this is the case? It could be that their priorities are simply elsewhere. Things will take time, even with funding because any crypto/security mistake will be so incredibly more damaging for them than for any other software shop. This goes especially for conversation backups.
solstice··on Signal WhatsApp Chats Import
I totally understand what you mean and I also frequently look up older conversations to enjoy again the in-jokes, banter and actually useful information of my chats.

However to avoid 1) having to manually delete things and 2) accumulating hundreds of megabytes of messages and 3) to not be swamped by months and years of "can you call?", "alright, see you later" and other ultimately meaningless stuff, I have conversations in Signal with my frequent interlocutors set to expire after a month.

To save things, I currently simply screenshot the relevant parts of the conversation or forward them to my "Notes to myself" thingy for later. It's a bit manual, but at least it's simple to remember: what I don't actively save disappears. Screenshots leave out audio messages and gifs (to a certain extend) but it is at least something. (And I just realised that with Signal it's actually possible to download individual audio messages and video so that a later reconstitution is possible if tedious.)

However, what would be great is to indeed have a way to backup messages including stickers, audio, videos etc. in a more high-fidelity way to relive important converations.

solstice··on Donate to Signal
You can disable receiving calls on your desktop in settings, I believe
solstice··on My Google Traffic Has Fallen to Zero
Same here. I use Teddit.net for Reddit, Newpipe for Youtube and one of the nitter.net instances for Twitter. All the content without the clutter and fast, as well as a lower temptation to get into flamewars etc.

(In Newpipe you can subscribe to creators' channels, see the comments and their other videos. You just can't comment from there.)

solstice··on Obsidian Note Taking App Thoughts
Me too. I use Markor (Android) which also supports the internal links created by Obsidian.
solstice··on Jack Ma has not been seen in public for two months
Very unlikely indeed. The government/party bigwigs he recently antagonize are not going to let an entrepreneur shame them publicly and let him get away with that. He's keeping or being kept out of public view until things are settled. I don't think they care what other countries assume and therefore there's no way for pressure to build up
solstice··on Possible Radio Emission from Exoplanet Detected
> It’s a strange quirk of our culture that the word radio carries connotations of technology and thus connotes intelligence.

Counterpoint: "radio wave fart from exoplanet detected". No connotation of intelligence IMO

solstice··on Nuclear weapons agency breached amid massive cyber onslaught
Too late now but consider using a throwaway account next time.
solstice··on Twitter cut off the ability to read a tweet by fetching its URL with a HTTP GET
There are a bunch of different instances running the nitter software too, so please consider choosing another one to avoid hugging nitter.net too much. Here's the list: https://github.com/zedeus/nitter/wiki/Instances
solstice··on China suspected of spying on Americans via Caribbean phone networks
> China appears to have used mobile phone networks in the Caribbean to surveil US mobile phone subscribers as part of its espionage campaign against Americans, according to a mobile network security expert who has analysed sensitive signals data.

This is probably happening via SS7, right? Can someone explain how a non-telco third-party company like Mr Miller's can monitor these signalling messages? (or just point me in the right direction)

How likely is it that this can be independently verified? So far it's allegations reported as facts. I'm prepared to believe him, but it would be better to have solid facts.

← PreviousPage 4 of 11Next →