HNHacker News
TopNewBestAskShowJobs

tcd

214 karma · joined August 29, 2017

submissionscomments
tcd··on EU antitrust regulators say they are investigating Google's data collection
Fines are the cost of doing business, you need to do more than that to see meaningful change.
tcd··on Go master Lee Se-dol says he quits, unable to win over AI Go players
I mean, computers are vastly better than humans at many things, I think you need to accept that and find the fun in sharing a game with a computer involved or with another human whose playing with another human in a like-for-like match with witt and skill being determining factors in the result, not a super advanced AI/algorithm.
tcd··on Facebook Portal – Privacy review
People have purchased - and installed - Google Home (and Mini's) and Alexa's in their homes. They think they're "cute", and offer a valuable service to them. They are a microphone controlled by data raping giants.

People use "Assistants" and enable full tracking technologies on their devices ("See how great it is Google has your every location on a map for the last decade").

People have not only accepted but embraced a full surveillance and tracking society; even if YOU don't accept it, you're part of it, people may add your contact to their phone that will be gobbled up in seconds by Facebook/Google/et al.

People don't care. End of story.

tcd··on Twitter prepares for cull of inactive users
Twitter et al IS a historical archive of information however - Imagine if Donald Trump's handle was to EVER be recycled, who'd get it? what would the consequences be? What about news pieces that embed or screenshot his tweets?

I feel context is vitally important here, usernames are an important identify in who said what at what time, and can be used "on the record".

tcd··on The trouble with VPN and privacy review sites
So is what Equifax did, but guess what, they're still in business. You can see the "settlement" at [1]. And guess what?

"Whether or not you choose to get free credit monitoring from Equifax, the company will continue to collect information about you."

In other words:

"Even though we got hacked, we're still going to collect your information so it can get leaked again, lolz".

Awesome FTC right there.

[1]: https://www.ftc.gov/enforcement/cases-proceedings/refunds/eq...

tcd··on The trouble with VPN and privacy review sites
The best approach I feel is how [1] does it.

A list, what features each provider has, and leave it to yourself to make the judgement. If you're being told why it's good there is bias involved somewhere along the line.

Of course, you need to understand whether the site has updated their information and presenting it truthfully, which should be easily verifiable.

[1]: https://thatoneprivacysite.net/

tcd··on Google to restrict political adverts worldwide
No media outlet is immune to posting what may be considered factually incorrect information, for example, earlier this year as highlighted in [1].

Deciding what is "true" or not these days is incredibly difficult if not impossible when we have a POTUS who wants to control the narrative and calls what could be considered factually correct as "fake news".

Even reporting the "facts" has become incredibly difficult, especially when digital data is so easily manipulated (for example, how can we verify the integrity of a 'tweet' as it was published at a particular second in history? Is there a hash that should be provided? Screenshots can be easily manipulated, as some articles embed the tweet itself and can be later modified, even Spez on Reddit admitted to editing the database).

[1]: https://www.bbc.com/news/world-us-canada-46935701

tcd··on Facebook: We don’t need your consent
The GDPR is a failure anyway. US tech giants are still globbling up masses of data even if the individual hasn't consented.

For example, the "contacts" permission should be disabled on OS's in the EU as it's impossible to prove the user has constend to sharing that information, yet Google launches an API in chrome to access the users contacts which totally won't be abused.

Alternatively you can gobble up data and "accidentally leak" it through an open MongoDB or AWS instance, will anyone go to jail? Unlikely, nobody really cares.

I doubt Facebook is going to change its ways any time soon, they're simply too big to fail at this point

tcd··on Intel's CIP wants to collect the “categories of websites you visit”
No surprise more and more entities want that delicious browsing history data, it's extremely valuable and profitable.

These days you need to really understand your threat model when it comes to using the internet and who might be able to record every keystroke and website you visit.

We used to call them "keyloggers" but now GBoard and Windows 10 have "clipboard sync" features.

I think there's going to be some genuine business in having scripts make random web searches, copy/paste random things with the cloud sync feature enabled etc to trick algorithms and what data can be harvested from what they collect.

If you poison the data they have on you then what use is it collecting it? Maybe I just am a raging furry, and adore Adolf Hitler and buy Nazi related materials.

tcd··on GitHub Archive Program
However, what's to say the archive will even be accessible in 10,000 years time? The entire archive may not be readable/usable due to fundemental changes in technology/language/society etc.
tcd··on GitHub Archive Program
I feel the term "deleting" is misleading.

It's more akin to "hiding" - to me, deleted means unrecoverable, by anyone, at any time.

Even your OS doesn't "delete" files, until the actual sector on the drive is overwritten (depending on media used, of course).

tcd··on I turned on every notification for a month
No. It's only encrypted "so only you can see it" if it never touches a remote server.

Anything that ever touches a server you must assume is done so in plain text (including passwords).

tcd··on Gitlab ‘rethinking’ third-party telemetry
I can't believe any organisation can be this tone deaf considering the awareness of privacy abuses that are practically in the news on a daily basis.

Respect your users and respect yourself, roll back the change, make an apology PR piece and move on.

tcd··on Open-source apps removed from Google Play Store due to donation links
It's amusing - I feel it's almost like causing a media "storm" is part of the whole "AI powered" process they've got going on. Create Reddit/Hackernews/tech blog outrage and maybe a human might step in and reverse the decision.

You can look at r/videos and see how many examples there are, the link in [1] provides quite a few...

So hey, go get people to repost across social media, maybe get a nice trendy hashtag going like #freewireguard and maybe their "AI" (or PR department) might actually do something useful.

Because to me, I've noticed more and more companies only reverse decisions or backpeddle once there's enough shit flying at them (See Blizzard recently, for example).

[1]: https://old.reddit.com/r/videos/search?q=flair%3AYouTube%2BD...

tcd··on Open-source apps removed from Google Play Store due to donation links
Unsurprising - Google obviously wants you to be within their walled garden. You could probably add an in-app purchase but this has been a known thing for a while now.
tcd··on The privacy trade-offs of cheap Android smartphones
Except even if you pay you're still the product. Data is a currency, they'll happily take it if you offer it :)
tcd··on Vulnerabilities exploited in VPN products used worldwide
Wireguard isn't even stable yet - it's not even been mainlined by the Kernel which is one of the main selling points that it will eventually be included.

It's alpha level software at this point and should not be relied upon or even trusted.

tcd··on EU brings in 'right to repair' rules for appliances
Links to the rules please? BBC didn't share a link to the legislation. Google yields nothing.
tcd··on The history and legacy of jQuery
> and as a professional you'll have to deal with it.

Yes, by not supporting those users. If you want to use IE 11 that's fine by me, doesn't mean I need to go out of my way to ensure it works for them.

tcd··on Sunsetting Python 2
Yeah, sorry buddy, but that's just not how modern software dev works. Platforms change, code gets outdated, and whilst older platforms "work", they're likely not taking advantage of all the features that have been added to platforms since that time.

It's much easier/better when you are forced into dealing with the change. At least people can laugh at how annoyed others get when they cry "but you broke everything!".

It's called progress. Get with the times or get outdated.

tcd··on Librem 5 Shipping Announcement
That still doesn't answer the question of the fact there _will_ be different models and how that affects software support.

For example, Chestnut says: "improved power management", will all previous models get that?

In Birch it says "Next run of board", are there changes that change the software in any way?

Evergreen is the "LTS" release, do the others not get "LTS"?

In Q4 2020 there's a new CPU, does that affect drivers or software in any way? Will they provide software updates for all devices for a number of years?

You'd hope opting for Model 1 2019 doesn't punish you but I can't see how they have the resources for testing every single model for every single software release.

It's not a good idea in the long run. Not even Google would do something like that and nor should a smaller company, it's idiotic.

tcd··on Librem 5 Shipping Announcement
One of my concerns about this is fragmentation. They've essentially announced 6 different phones released over a staggered time period.

Will all batches get updates for the same duration? Will they all get same day software releases? How about support? Will there be subtle differences that cause headaches? If you opt for one revision over another and that has issues, what's the process going to be to handle that case?

Rather than just having a single shipping device with a fixed design they're going to incrementally change it, and I fear it's going to be an absolute disaster.

I think if you visit this comment in exactly a year's time I'll probably be right, and it'd hardly be a surprise.

I absolutely agree with smacktoward, they're doing this to hide the fact they're simply not ready, but instead opening a can of worms that could devastate the entire project.

Not a fan of this, you can only hope this is the right move forward.

tcd··on Privacy Sandbox – Open standards to enhance privacy on the web
Yet they don't mention Android, where the security is so lax you can also be fingerprinted and data sent to a remote server without you ever knowing, where Chrome on Android doesn't even allow you to use ad blocking tools?

This is a weak attempt at showing how tracking Google has been a part of and enabled is not being accepted by certain vendors anymore.

Let's build a cross OS, cross browser and cross platform set of standards, not just for the web but computing as a whole.

Also, didn't Google propose cutting the web manifest to prevent tools like uBlock from working as well? Not sure what's going on with this...

tcd··on Google's software mistreats or harms the user
> but I feel very much more in control of my Microsoft box that I am of my Apple or Google one.

Hahaha, you haven't seen the data MS collects on Windows 10 users? Try enable full telemetry and download their tool, every damn URL gets logged and even some of the "basic" data might reveal trends when combined with other data sets.

NO "big tech" company is to be trusted. Cambridge Analytica and co taught us that.

Data and information is being weaponized, the 2016 election proved that, go read the Mueller report for more information on this.

tcd··on Google's software mistreats or harms the user
I mean, anyone who bothers to take the time to do a Google Takeout and actually looks at the data in the JSON files can see just how much information they are storing, and it is quite alarming.

Thing is, companies keep data about you even if you don't have an account, which is impossible to GDPR.

Some of the sources here are questionable; there's a sun.co.uk URL which is obviously tabloid trash, so please apply critical thought, the article presents what appears to be a convincing piece but some of the "sources" are not to be trusted.

But even on Linux you can't escape Google's web, even if you really really tried, some developers use Google's APIs for fonts, jQuery/scripts etc, so it's really hard to use the web without Google knowing about it and building up their knowledge graph.

tcd··on Netflix’s biggest bingers get hit with higher internet costs
Maybe 20 years ago we had the same comment "who needs 1gb? You can fit everything in a floppy!".

It's called innovation and progress, thank God you are able to be corrected and change your thoughts as with your approach we'll never get anywhere

Try streaming 4k and get back to me, or is 140p "good enough"?

tcd··on Disney Announces $12.99 Bundle for Disney+, Hulu, and ESPN+
Not many people will watch shows where D&D are involved I suspect
tcd··on MITM on HTTPS traffic in Kazakhstan
We need new measures to not allow these certificates to be installed unless they're verified, or at least the OS shows a massive giant warning "DO NOT DO THIS unless you accept this cert gives $identity access to all your data".

Seems a very solvable problem.

tcd··on How to Track Your Kids (and Other People's Kids) with the TicTocTrack Watch
Yup, people are cheap. Just go on Amazon and look at the cheap Smartwatches. I actually tore down an APK of one "WearHealth_v1.0.55_apkpure.com_source_from_JADX" and it contained some really dodgy URLs to Chinese servers.

Nothing you can do really, the platform (Android) should be responsible for protecting the individual to be honest.

tcd··on How to Track Your Kids (and Other People's Kids) with the TicTocTrack Watch
Yup. These days the law doesn't really factor in the consequences of code/programming as it's almost impossible to legislate that.

For example, you could run NPM update that installs a malicious package that is somehow able to connect to your MySQLD and access all the tables (that contain geolocation information on children) and execute a cronjob to perform a query to backup the .sql data and upload it to a remote server.

There would be 0 consequences legally for such an action (or development would cease to function entirely).

Besides, how is knowingly storing GPS information on children acceptable? They can't consent, so maybe it's time to apply that to things like geolocation as well.

Code has no consequences, because law makers likely don't "get" what that means. You may think it's just $GPSOfALLChildrenInTheDatabase but that variable can cause actual, real harm to humans.

There's totally a disconnect.

← PreviousPage 3 of 6Next →