HNHacker News
TopNewBestAskShowJobs

soziawa

415 karma · joined November 28, 2017

submissionscomments
soziawa··on AltStore. The first Apple approved alternative App Store
It is available for me in Switzerland. In fact, it's the number one app.
soziawa··on The App Store, Spotify, and Europe's thriving digital music market
The market share of iOS in the EU is only around 35% though. The market this is about isn't the market for music streaming apps but the market for iOS apps.
soziawa··on Ente: Open-Source, E2E Encrypted, Google Photos Alternative
> There are so many alternatives to Apple Photos, all with this handicap.

Apple doesn't allow background execution for third party apps. Can't increase service revenue if you allow competition.

soziawa··on The failure of self-checkout technology
In Switzerland the two major grocery stores have this system. You need to establish trust first, for the first few months you'll get more inspections. But I haven't been checked in years now.
soziawa··on The failure of self-checkout technology
In Switzerland it's similar for one of the two major retailers. For the other one you can pay in the app without every going to a POS.
soziawa··on Lenovo ThinkPad T14s G4 review: Business laptop is better with AMD Zen4
Can you put linux on one of these without any issues?
soziawa··on Spotify looked to ban white noise podcasts to become more profitable
You can exclude certain playlists from the list of stuff that is considered when creating the recommendations. Tap the three dots on a playlist and tap "Exclude from taste profile".
soziawa··on Show HN: StackOverflow.gg – AI-generated answers to every coding question
It very much depends on the tags you use. Swift and iOS is absolutely abysmal and questions will be closed as duplicates of questions that have been irrelevant for years. Go and Haskell are great though.
soziawa··on Recent Apple updates leading to WiFi issues?
It also resets custom DNS settings for all networks.
soziawa··on Apple introduces end-to-end encryption for backups
But most importantly the whole OS and all of the integrated apps do use pinning.
soziawa··on iPhone app receives notification for another app
> Someone replied to his tweet by saying he should let Apple know there is a problem. His response was, "I don’t get paid to do free QA."

The reply says that he should file a radar. Radar is Apple's bug reporting platform and famously unpopular among many developers due to slow and often useless replies.

soziawa··on Twilio incident: What Signal users need to know
So that means for the duration of the attack active contacts and groups were exposed?
soziawa··on Twilio incident: What Signal users need to know
Threema seems to manage just well. I guess payment is the natural limiter for spam there.
soziawa··on Telegram reportedly surrendered user data to authorities
> Terrible advice. If you want e2e you can choose to enable it. It is not enabled because many users choose to receive their messages across multiple personal devices simultaneously. This is not possible with e2e, which is why it is an option.

Signal, WhatsApp, iMessage and Threema seem to do just fine.

soziawa··on Telegram reportedly surrendered user data to authorities
> Look no further than Signal's supboenas and how they respond to them. With all the information they hold about an account. Which is just the creation date and last connection date. https://signal.org/bigbrother/eastern-virginia-grand-jury/

Signal's subpoenas have always left a sour taste in my mouth. I just can't believe that they are getting so few, at least some cases they'll just send the standard letter out and will try to get something. Having no list of how many they have rejected would at least increase my confidence in them a bit.

But the bigger issue is, that they data they provide is just too good to be true for the majority of users. Signal has a push token for the vast majority of accounts otherwise they wouldn't be able to send out push notifications on iOS and would waste at least some battery on devices with Google Play services installed. The subpoenas always seem to affect people who have an Android phone without Google Play services installed. In my eyes is too strange of a coincidence to be true.

Signal does at least a bad job of explaining what kind of data they keep on an average user.

soziawa··on Swiss army knifes WhatsApp at work
Only a few years ago the Norwegian army was played by their soldiers using Tinder (https://old.reddit.com/r/Tinder/comments/9uos8g/norweigian_m...) during a maneuver. This is a great and long overdue move even though it is somewhat strange that they didn't go for their OnPrem offering.
soziawa··on Session Encrypted Messenger
Session is a cool fork from Signal. They adress the two biggest privacy issues, push tokens and IP addresses.

But I can't see it gaining too much main stream traction any time soon. Too me it feels like WhatsApp has hit the sweet spot for people who can't get themselfes to care about security and privacy.

soziawa··on Session Encrypted Messenger
It's actually forked from Signal.
soziawa··on Signal is experiencing technical difficulties
> Most people I know that started using Signal a few months ago are now back to using Whatsapp. Privacy is a nice feature to advertise, but when both your UX and your reliability suck, it's not a good combo.

Fully agree on the UX but not the reliability. WhatsApp used to be famous in Switzerland for its unreliability. On big European football games and Christmas / New Year WhatsApp was regularely down for 3 hours and more.

soziawa··on EFF Joins Global Coalition Asking Apple CEO Tim Cook to Stop Phone-Scanning
This is based on pure speculation, but could it be that Apple believes the covid tracking functionality has shifted power from governments to Apple?

Many governments (e.g. Germany) wanted location instead of token based tracking with central storage of location pretty much up until the point where Apple and Google said that it won't happen .

This is based on my perception of Germany tech media coverage of the issue.

soziawa··on Hash collision in Apple NeuralHash model
> 6. Apple's CSAM detection then flags these, and they're manually reviewed

Is the process actually documented anywhere? Afaik they are just saying that they are verifying a match. This could of course just be a person looking at the hash itself.

soziawa··on Apple says photos in iCloud will be checked by child abuse detection system
There is some previous discussion about this regarding Facebook here: https://news.ycombinator.com/item?id=28119372

The false positive rate does not look great.

soziawa··on Apple says photos in iCloud will be checked by child abuse detection system
> Hash collisions would not pass the human review. About the only consequence I can think of for hash collisions is that the person at Apple who performs the human review step has a slightly nicer day because they were about to look at an image... and then it wasn't CSAM.

The whitepapers provided by Apple do not say what the human reviews consists of. They could just look at the hashes to make sure there isn‘t a bug in their system.

soziawa··on Apple’s Mistake
> Were there 20.3 million arrests of offenders?

I don't know of any data from the US but in Switzerland the Federal Police pre sorts all reports from the NCEMC and around 90% are unusable [1] and cannot be acted upon. The remaining 10% are then forwarded to local authorities. There is no data I know of what the final conviction rate looks like. But from what I have gathered from local news paper these departments are usually short staffed.

I suspect that the situation is similar in the US.

[1]: https://fedpol.report/en/fedpol-in-figures/fight-against-pae...

Edit: Fix typo: persorts to pre sorts.

soziawa··on 1password is considering a self-hosted option to store vaults
A direct link to the announcement post and the survey / announcement signup: https://1password.community/discussion/comment/604038/#Comme...

After hiding the standalone license this would put a lot of trust back into 1Password.

soziawa··on 1password is considering a self-hosted option to store vaults
What does Electron in name only mean? Either electron is included or it isn't. Whether you are using Rust through native bindings or through WebAssembly does not really matter does it?
soziawa··on Signal on Android: Images sent to wrong contacts
The protocol has been reviewed plenty of times. The rest of the app has not. At least according to your list.
soziawa··on Signal on Android: Images sent to wrong contacts
I‘ve been on Threema ever since I learned that WhatsApp did not even use TLS. It‘s a great chat app and nothing else (which is a feature in my book).
soziawa··on Cryptographic Weaknesses in Telegram's MTProto
Kinda

> We also show how an attacker can mount an “attacker-in-the-middle” attack on the initial key negotiation between the client and the server. This allows an attacker to impersonate the server to the client, allowing to break confidentiality and integrity of the communication. Luckily, this attack is also quite difficult to carry out, as it requires sending billions of messages to a Telegram server within minutes.

soziawa··on European Parliament approves mass surveillance of private communication
> Isn’t Signal FOSS? I don’t know how they’d police that when everyone can just fork it and remove the back door.

If the goal is large scale surveillance, it can be combatted fairly effectively as has been shown with e.g. kino.to and other streaming sites which have gone practivally extinct. The same would happen to websites hosting illegal apps.

If the goal is to go after real criminals this is of course useless. But EncroChat [1] has shown that at least large parts of the criminal world don't seem to have great operation security practices.

[1]: https://en.wikipedia.org/wiki/EncroChat

Page 1 of 6Next →