HNHacker News
TopNewBestAskShowJobs

sseneca

157 karma · joined November 4, 2018

https://ssene.ca
submissionscomments
sseneca··on Google cancels Google Play publisher account and ends family’s source of income
F-Droid?
sseneca··on Google could have updated the Pixel 3 until Android 13, it just didn't want to
I use a 6s on iOS 15. It runs well.
sseneca··on Firefox is the alternative to a Chrome hegemony
Weird, I've been using `toolkit.legacyUserProfileCustomizations.stylesheets` for a lot more than three versions.
sseneca··on Revolt: Open-source alternative to Discord
Dendrite is written in Go, Conduit is written in Rust
sseneca··on Use Alacritty instead of Termite
Yeah, this was my take away as well. Also, iirc their claims of Alacritty being the "fastest" are dubious at best.

I used Kitty for a while instead, which is very similar. More recently I've been trying out Foot: https://codeberg.org/dnkl/foot

sseneca··on Proposal: Treat FLoC as a security concern
They've said they're going to disable FLoC. Still, this is one of the benefits of Firefox, it's not based on Chromium at all so it's out of the question.
sseneca··on ‘Counter Strike’ Bug Allows Hackers to Take over a PC with a Steam Invite
I agree, this is essentially what I was getting at in my original comment. Counter Strike is not Valve's game. They picked it up when it got popular and since then have done less than the minimum. And despite this they generate hundreds of millions each year off of it? Perfect.
sseneca··on ‘Counter Strike’ Bug Allows Hackers to Take over a PC with a Steam Invite
Yes, top players really are leaving CS for Valorant, though this is mainly limited to the NA scene afaik (two examples who were on top teams: Ethan[0] and nitr0[1]).

Other than that, it is mainly those washed players leaving, yes. Which still isn't healthy for the scene, and means the NA CS scene effectively doesn't exist any more (this isn't hyperbole, there are only two good NA teams right now and both were flown out to Europe by their orgs to compete there instead).

[0]: https://www.hltv.org/player/10671/ethan

[1]: https://www.hltv.org/player/7687/nitr0

sseneca··on ‘Counter Strike’ Bug Allows Hackers to Take over a PC with a Steam Invite
I think Valve's ineptitude in regards to CS:GO becomes easier to explain when considering their history with Counter Strike.

The game that became 1.6 wasn't even their game. It was a mod for the original Half Life and they hired the modders after it got popular.

Then CS:Source came around the same time HL2 did. That is to say it exists only because HL2 did, and Source is just HL2 with guns (lol). It was very divisive in the pro scene and the majority of professional players rejected it.

GO's history is even worse. It wasn't even meant to exist at first; Hidden Path were porting CS:Source to consoles and Valve decided that it could live as its own game. They release it in 2012 and, by all accounts, it sucks. Nobody plays it. Things begin to change when they create a virtual economy (skins) and admittedly do actually improve the game a fair bit. It's only when the game sees those improvements (2013-14?) that the pro scene finally moves from 1.6 to GO.

So the situation in 2021: The most popular game on Steam is a game which, according to Valve themselves, shares 75-85% of its code with a game released almost 20 years ago (Half Life 2), and which everybody knows is a complete and utter mess under the hood (thanks in part due to the source code getting leaked, also thanks to ex-devs sharing their stories of their time working on CS:GO). This along with Valve being notorious for just not having the internal incentive structures to get bugs fixed (hence GO's spaghetti code)... it's easier to understand (but not excuse!) Valve's attitude for serious security flaws like these.

I am similar to you in that I have about 1000 hours in CS:GO, and I've spent many 1000s of hours watching the pro scene. I love Counter Strike, but with Valve the way it is, I don't see how these fundamental flaws will ever get fixed. Look at how they're allowing Valorant to decimate the North American CS scene, just like they allowed Overwatch to take from TF2's player base back in 2016.

sseneca··on Update on beta testing payments in Signal
They have https://dendrite.matrix.org, and they use Dendrite to test new features (like Spaces). But its issue is it's not feature complete so I don't think it sees that much usage.
sseneca··on Update on beta testing payments in Signal
I'm excited for Dendrite, their new homeserver written in Go which will hopefully solve at least some of these performance issues. I've hosted a Dendrite server for a couple months now, but haven't had the chance to use it much.

With that said, it's been disappointing to see how slow development has been on it. Hopefully it picks up and they can get it out of beta this year.

sseneca··on Valve accused of ignoring existing RCE vulnerability in Source games for 2 years
As the other user said, BattleEye now bans for this. I used a VFIO set up for a number of years but had to switch because of it.
sseneca··on Valve accused of ignoring existing RCE vulnerability in Source games for 2 years
Ah. So, if a Windows application runs in ring 0, it can put malware in a place such that it can then interact with the Linux install?

Is there _any_ way to bypass this, apart from separate machines? I didn't know this was possible.

sseneca··on Valve accused of ignoring existing RCE vulnerability in Source games for 2 years
> Some game companies (riot games) even install their anti-cheat software so that is loads in the ring 0 space.

Why are separate machines required, rather than dual-booting? (i.e. Windows for games, Linux for everything else)

sseneca··on Valve accused of ignoring existing RCE vulnerability in Source games for 2 years
The outrageous profit Valve make from skins and the like is only half the story imo, their internal structure is the rest. Some of the stories ex-devs share from that place are just... idk, they explain the company’s apparent ineptitude
sseneca··on Mozilla plans to remove the Compact Density option from Firefox's Customize menu
Yes, they removed PWAs from desktop FF.

More information: https://bugzilla.mozilla.org/show_bug.cgi?id=1682593

Not only did they remove PWA support, they currently have "no plan for PWA support in Firefox" at all.

sseneca··on Mozilla plans to remove the Compact Density option from Firefox's Customize menu
PWAs, Compact Density, what's the next useful feature they'll remove?
sseneca··on UK to depart from GDPR
Huh. I guess this'll be what pushes me to finally figure out a proper backup system for my server, so I can trust it with all my photos etc, and remove them from "The Cloud"
sseneca··on Signal Appears to Have Abandoned Their AGPL-Licensed Server Sourcecode
Their silence has been so frustrating. Not even any acknowledgment from the team -- they just keep releasing updates and posting to the forums as if nothing happened.

It would be a lot easier to believe this was due to a court order if Signal's attitude wasn't always like this. I call them "the Apple of open source" because they rarely (if ever?) accept PRs from outside Signal, don't have a public roadmap they share, and the development process is all done behind closed doors (commits are made public only when the associated build has been released). These are all unique to Signal afaik versus its competitors (Matrix and the like), and it's made me grow to hate it.

Keeping the server's source closed is probably the final straw for me, a long time Signal-apologist.

sseneca··on Grindr to be fined almost €10M over GDPR complaint
I’ve already seen websites which I (cynically) assume exploit this new-found aversion I and many others have to green buttons in cookie pop-ups by using differing colour schemes, e.g. https://hltv.org, whose “Allow all cookies” button is actually blue, whilst “Allow selection” is green.

“TrustArc” is a funny name considering it and its pals have obliterated any trust I had in this stuff.

sseneca··on Grindr to be fined almost €10M over GDPR complaint
Is it TrustArc? I remember having a similar experience with their pop-up, for example on Oracle's website when I'm looking for Java docs: https://docs.oracle.com/en/java/

That example doesn't have the long loading times for me any more, but I'm almost certain it was the TrustArc pop-up.

sseneca··on Grindr to be fined almost €10M over GDPR complaint
It’s almost impressive what these people have created. Now, when I stumble across the rare “Reject All” button on one of those pop ups, I don’t know if they even really mean “all” or if it keeps the trackers under “legitimate interests” enabled because they’re... “legitimate”. So the only safe option ends up being disabling all of them manually, which is absurd when these websites list hundreds and hundreds of trackers.

It’s as if they used decades of HCI research precisely to make the user experience as horrible as possible. No wait, I’m sure they did exactly that.

sseneca··on Kitty – A fast, featureful, GPU based terminal emulator
I've used both. I have no figures but kitty feels at least as fast as st with infinitely more features and a proper configuration system.
sseneca··on Emacs is special regarding UIs
The release model is a mess. Most people tend to stick with using Spacemacs on the `develop` branch, which means updating via `git pull --rebase` every so often as well as the inbuilt `SPC f e U`.

I've been using Spacemacs for around a year on the `develop` branch. For me it's fine, but for those who want a very stable experience I don't recommend it -- it does break sometimes.

sseneca··on Apple II and Apple IIe emulators written in JavaScript and HTML5
People can be weird about this sort of thing, especially with Apple. I remember when the iPhone XR came out some people would insist on always writing "iPhone Xʀ", for example.
sseneca··on GDPR Violation: Scribd acquires PII on 500M users in a deal with LinkedIn
My experience is that when I sign up to a service with a previous account, the previous account tells me what data the new service will have access to, and then the new service has a couple of more steps to fully create a new account.

In this example it was "Log in with LinkedIn" -> immediately to the front page. I've never had that before.

sseneca··on GDPR Violation: Scribd acquires PII on 500M users in a deal with LinkedIn
Yes I didn't get a popup either time so I'm assuming that LinkedIn, in their infinite benevolence, automatically created an account for me.
sseneca··on GDPR Violation: Scribd acquires PII on 500M users in a deal with LinkedIn
This is what I think is happening.

Pressing "Sign in with LinkedIn" is deceitfully vague, and will create a new account if you don't have one already. So I actually created an account and then immediately deleted it afterwards, but their welcome email was delayed for whatever reason.

Just to be sure, I pressed the "Sign in with LinkedIn" button again and it made me an account again. I waited for the welcome email to come in, and then deleted it once more. I hope that's enough.

sseneca··on GDPR Violation: Scribd acquires PII on 500M users in a deal with LinkedIn
So, I just deleted my account.

15 minutes after I got confirmation of the deletion, I got a "sseneca, welcome to SlideShare!" email, lol.

sseneca··on Why I link to Wayback Machine instead of original web content
Yes, this makes the most sense in my opinion:

Check out [this link](https://...) ([archived](https://...))

This can also help in the event of a "hug of death"

Page 1 of 2Next →