HNHacker News
TopNewBestAskShowJobs

tcd

214 karma · joined August 29, 2017

submissionscomments
tcd··on Windows 10 could start bullying people into using a Microsoft account to install
> but is it really so terrible?

We don't know what the future has in store for us. To me, the level of control China has over its population is scary.

Data can be misused in many different ways, and one day, I suspect we'll see a catastrophic situation occur as a result of all this connectivity and mass surveillance.

Only then, people might take note and realize it's a terrible idea.

tcd··on Windows 10 could start bullying people into using a Microsoft account to install
They're not "crazy", which is pretty disrespectful. Anyone paying attention has seen the writing on the wall for a while. Snowden just confirmed what they've been saying all along.

Data is the new arms race, those who collect the most have the most to gain, especially financially where data is being a core asset to a business.

Dumb is going to be the new gold, at least for those "crazies" you speak of.

tcd··on Stop Using Encrypted Email
I generally can agree with this. Encryption is a distraction from the real issue: the weakest chain in the link.

We've recently seen recordings of meeting with Trump and associates. No one is safe.

You must assume your every tap on a smartphone, you every keystroke and interaction with a computer is being logged in some way. You interact with computers by proxy - people entering information on your behalf, perhaps other devices are listening to you, or logging your movements/interactions within the world, perhaps taking videos and pictures of yourself. Profiling who you are, who you talk to, what your financial situation is like, who you care most about, who you align with, your network; colleagues, close and distant friends, those you once interacted with but not so much. A brain capable of recording every minute detail that you may want to forget. Details can be recalled within seconds and just a few keystrokes, a second by second recording in ultra high quality and the density of information being stored is unmatched to any other time in history.

If somebody wants to get your information, they will get it, one way or another. This much has been proven true again and again.

So sure, use your fancy tools and gadgets, but be clear, one day, it's highly likely what you wanted to keep private may become public.

When, not if.

tcd··on Request Node lib used by 48k modules is now deprecated
I have a question:

Is it the responsibility of the package manager to keep users safe? By that, I mean, if there was a security vulnerability that the maintainers refused to fix, what would the process be?

Should NPM refuse to install packages marked as deprecated, perhaps after a certain age of deprecation (say, 6 months)?

Comparing this to the browser where I believe it is the expectation Firefox, Chrome, Safari et al to keep users safe, by updating automatically if an issue is discovered.

tcd··on Coding Flaw Exposes Voter Details for 6.5M Israelis
I often wonder if we, as humans during this era, are really at the primitive end of the introduction of computers and big data.

We're still incredibly new to the concept of storing PB's of easily searchable and accessible data, and can be accessed at the speed of light.

At the same time, exposing this can do real human harm, depending on the motives (for example, Cambridge Analytica).

I wonder what the next 100, 500 years will look like, after all this has 'settled' down.

We're seeing this today with facial recognition and machine learning - new concepts today that will grow old with time.

I wish I was capable of seeing all of this 'big tech' in that time to see how it matures. To say we have a long way to go is an understatement.

Breaches like this should be impossible as there should be designs against it.

tcd··on Dangerous domain corp.com goes up for sale
Except what's the human cost of this? If there is a stream of sensitive info, real people will be impacted.

Big corps are not usually the ones that are affected the most.

tcd··on Apple wants to standardize the format of SMS OTPs (one-time passcodes)
I'm honestly tempted to tell my bank I no longer have a SMS capable device and will not be getting one (and that my number on their file is no longer under my control and as such is a security risk).

I want 0 to do with SMS security, I am happy to use 2FA via an app, and backup codes, that I have to manually enter, with an insanely long 50 char password that's unique for each site.

Sim jacking is a real issue, and it's possible and sometimes easy to assume control of somebody's phone number.

SMS is also not a secure protocol in any way, shape or form. No security or privacy is built in, similar to emails.

Now if we go about adding something like private public key pair authentication that would be a good start, and a standardized "build your own security" where you can add as many layers to each site rather than relying on them to keep you secure which they often fail at.

tcd··on Congrats! Web scraping is legal! (US precedent)
If I decide to change the class names, or HTML structure of the page, is that no longer allowed?

How far does this go?

tcd··on 250M Microsoft customer service and support records exposed on the web
I find it really intriguing hearing about all these data breaches - never before in human history have we been able to store so much information about ourselves and our world and how readily accessible that information is, just sitting on hard disks around the world.

Which makes me wonder, is there information that's leaked so much it's no longer "private"? Names, addresses, phone numbers, contacts lists, photos, emails, cloud documents, IP address logs, search history...It's all there, waiting to be leaked...

And why the insistence on storing information for an unlimited period of time - it should be illegal to store data above 5+ years without explicit consent from the user (after reviewing the data and clicking "I am okay with this data continuing to be stored").

tcd··on Cloudflare is turning off the internet for me
Because their regex is crap and if you have @twitterHandle or something with a legitimate "@" you just see the obfuscated version.

It's laughably adorable to think it's actually solving a problem or helping in any way, the 'bad actors' it's trying to prevent probably have a work around anyway.

tcd··on LastPass stores passwords so securely, not even its users can access them
Keepass - choose your own way of syncing, can never go down, works without the internet etc etc.

Cloud services...lol

tcd··on Smart homes will turn dumb overnight as Charter kills security service
Let's assume product uses domain.com to get updates.

domain.com one day might be owned by $badDude - that's a huge risk

domain.com might return 404's - that's pretty terrible.

What happens to domain.com once $business is now $noLongerBusiness?

You can provide a method of flashing firmware onto the device itself (possible security risk?), but where do you get the files from? How do you verify they're safe?

Then, you need to host the server software itself (depending on how it's coded, that ranges from quite simple to your worst nightmare), and you expect someone to keep that secure? The EU dictates GDPR compliance, which adds additional cost to maintenance.

It's just easier and cheaper to just not bother with servers if the company can't keep them online.

tcd··on Smart homes will turn dumb overnight as Charter kills security service
That's a very idealistic but unrealistic perspective. Often times the source code can't or won't be released - it could put further customers at risk if a vulnerability is found and the update servers have gone away.

Some devices might not be possible to update due to hardware/software configuration (perhaps certain variables are hard coded?).

Whilst what you're saying is right it just doesn't work that way. I'd love for all the Android devices to get years of OS and security patches, but it simply doesn't happen.

Any IoT device is pretty much the same. It's not going to change any time soon.

Only invest in products you can be sure of (which is hard these days). Expect them to break, expect nobody to care, and be prepared to lose money or get a terrible ROI - it's why phones don't get updates, the OEM doesn't make money from providing updates which are a direct cost VS selling a new phone.

This is capitalism, produce crap, sell many units, offer no support, rinse and repeat.

tcd··on FBI unlocked iPhone 11 Pro via GrayKey, raising more doubts about Pensacola case
It's not possible to generate a computer system that will remain secure for the rest of time. All encryption can be decrypted.

Every phone ever sold can have its internal data read, it's not a case of if but when. This also applies to every HDD, SDD and any encryption software you may be using, it will be cracked eventually.

tcd··on The new Microsoft Edge is out of preview
They probably can't, especially if the engine interfaces with proprietary code or is deeply linked to the kernel for example. It's likely part of the reason why they never got it updating as frequently as the Chromeium counterpart can, as this is entirely userspace.
tcd··on Google's new website speed badge
"Slow unless you're using our AMP".
tcd··on Google collects face data now. What it means and how to opt out
Your face already exists in a plethora of databases anyway if you've existed the last 10+ years. I'm not saying you shouldn't be concerned but don't be mis-guided this is a recent development.

It's not. You as a human generate an immense amount of JSON data as you interact with the world until you die (and, possibly still after).

We're all just one big JSON object now :)

Cheers and happy new year, be tracked some more.

tcd··on How to stay private when using Android
Android is awful regardless of device you buy. Google's control is an absolute disaster for an OS.

If Google is involved, expect 0 privacy.

tcd··on Smartphones and the location data marketplace
The irony as this page blocks many attempts to send my information to known data rapers.

You're part of the problem nytimes, how about you start setting the gold standard and show the world you're better than others?

Oh wait, that data is too valuable to your business isn't it?

Can't wait to hear their so called "solutions".

tcd··on LogMeIn Acquired by Private Equity
Keepass; open source, can store the file wherever you wish, isn't liable to be acquired by a private entity since you can just build your own copy.

Use open source software wherever possible, it's just better that way.

tcd··on LocalStorage or WebSQL unexpectedly cleared
You should apply a rule similar to 3-2-1:

3 copies of the data

2 copies on different storage mediums

1 backup in a separate location.

Ideally, a backup solution on the OS would target the browser profile itself at regular intervals, and you could allow the user to export the data into a file that can be downloaded by the browser (or copy/pasted).

It should be obvious that any form of browser storage is unreliable, and MUST be treated as such, and it should be EXPECTED to be deleted at a moments notice - setting such expectations encourages good practice at backing up your data incase of a failure.

Don't rely on others to ensure business critical data is stored and accessible - that's partially on the users/application to offer what they can.

tcd··on A Thread about Internet Archive's “Silent Killer”
I'm inclined to agree with this position. Does every Youtube, Reddit, Twitter, Hackernews, Facebook comment need to be archived and stored for the next thousand years?

I'd argue no, and there's a huge amount of waste in there - so many bot posts, or just spam.

But here we are, people want to archive every byte of information that traverses through the internet.

These days you have to approach cautiously, as every thing you do or post may be archived.

tcd··on Verizon/Yahoo Blocking Attempts to Archive Yahoo Groups – Deletion: Dec. 14
And this is the dangers of relying on a private, corporate, for-profit law-bound organization. They're susceptible to abiding by the laws and of course, there is a cost attached to all of this.

Exploiting a free resource, as we all do these days (reddit, youtube, facebook, hackernews itself etc) is all well and good but maintaining history is expensive (content needs moderating, you are required to abide by the GDPR and DMCA, there may be disputes about content on the platform).

I mean, Google+, MySpace, Bebo, IMDB comments is now dead and gone, how useful was the data really? I'm sure some people might go to archives but I would imagine 95% of the data is just "rot" that has no value or substance.

History is lost all the time, we barely know what we've been up to the last few thousand years only now can we so extensively document our world with the precision and quality afforded to us.

But in the end, time moves on and some of that history is lost, it hurts, but whose to say any archived history will be preserved anyhow? We're still relying on our storage technology being readable years/decades/centuries from now, which is not a given.

tcd··on Verizon/Yahoo Blocking Attempts to Archive Yahoo Groups – Deletion: Dec. 14
I can imagine it's easier and safer (from a legal perspective) to just delete the data and therefore no longer be responsible for the content. Twitter wants to delete older Twitter accounts because they're required to by law under the GDPR.

I mean, the GDPR makes things kind of difficult in this regard, and I suspect even archives are liable if somebody takes an issue with content they are hosting.

tcd··on Privacy analysis of Tiktok’s app and website
The GDPR IS the legislation, at least, I thought so.

If you're serious about this, the network shouldn't be making these requests unless you've explicitly allowed it (meaning the request is blocked at the network/OS level).

tcd··on Privacy analysis of Tiktok’s app and website
As more time passes I begin to fundamentally believe the modern Internet isn't compatible with the GDPR or privacy as a whole.

Simply the act of enabling JS within the browser is enough to have your privacy violated in thousands of different ways and data sucked up by everyone who wants it.

Simply by installing an app on your smart phone you invite SDK's that are happy to report back all the information the OS freely allows access to because why not? Data storage is cheap and collecting that data is free of charge.

But yes, data about children is collected in the millions, and the truth is there is no possible law that can prevent this from happening because it will happen anyway. One example: If FB detects a baby photo you upload, should it be deleted? I mean that baby cannot possibly consent, and you'd have thought the GDPR or some law meant uploading baby photos is impossible, but that's not the case, FB/Google WILL perform facial recognition on that baby.

Your data will be processed, used, sold and manipulated for as long as you generate it.

The GDPR helps, a little, in some ways, but it's really had very very little effect overall (apart from some damn annoying "we respect your privacy" pop-ups on websites).

If the GDPR was serious, it wouldn't be possible to collect this data at the OS level, like, at all, JS would return nothing, Android apps would return nothing (or fake data, at least).

But the GDPR is not serious, at least in some ways.

tcd··on Fractured Forests Are Endangering Wildlife, Scientists Find
Why do WE need forests? All WE need is roads, and houses and buildings for businesses and transportation networks covering air, land and sea to ensure capitalism can reach every corner of earth. How else will Amazon Prime thrive and make boatloads of cash?

Fauna and Flora, aside from humans, are not relevant, we are the superior species and can cut down entire forests, bleach the coral reefs and decimate habitats so we have our nice luxurious houses because THAT is what is really important.

So these "scientists" are clearly not too caring of how important capitalism is and how it must take priority over anything else. Masses of species will likely go extinct but as long as we can keep buying stuff it'll all be okay.

/s

tcd··on PIA VPN to be acquired by malware company founded by former Israeli spy
PIA also claimed they were going to release the code of their new Windows desktop client.

They did not. They have not.

They lied.

They cannot be trusted.

tcd··on PIA VPN to be acquired by malware company founded by former Israeli spy
Yet PIA has LIED about making their desktop source code public.

Where's the link to the GitHub repo?

You are proven liars.

(Thanks for the flag, doesn't change the facts, prove me wrong ;) )

tcd··on The world needs more search engines
It is if you're using Chrome or got any Google related properties installed on your PC.
← PreviousPage 2 of 6Next →