HNHacker News
TopNewBestAskShowJobs

tcd

214 karma · joined August 29, 2017

submissionscomments
tcd··on Facebook uses 1.5B Reddit posts to create chatbot
I get the reasoning, but I don't see this applied to some platforms. Reddit and Discord allow you to both delete and edit older comments, and there's no limits on how far back you can go (so you can, if you wanted, edit or delete your entire history).

Under the GDPR a subject is allowed full erasure rights. If I say I want you to delete my content from x date to y date, or a particular post, or everything entirely then that shouldn't be an issue. A request may be bothersome, but that's what happens when you don't offer that functionality natively.

I noticed a few days back you didn't like it when a user made a new account, except with the internet these days and how everything is archived for all time, throwaway's are the only option. Building a comment history is extremely dangerous, especially when you might forget what details you may have posted or how meta-data can leak through (such as what subs you post in, any details you posted that could identify you etc).

You can't have it both ways: no to multiple accounts and also no to control over your data. I might have 50 accounts, dislike it? Give me proper control over my comments. (to be honest, it may just be worth making a new account for every comment for maximum privacy, it's extreme, but it's a viable option).

If I want to delete them, that's my choice to freely make. Your thoughts or concerns are not relevant to me, thankfully, the GDPR agrees.

tcd··on A look at modern PHP
> As the businesses still using it either mature, evolve, or fail, the need for PHP will begin to dry up.

People have been calling for PHP's death, or saying PHP is a dying language, for as long as the internet has been around.

It's always the same arguments, that $newHipLanguage will replace it.

Then you actually do some research and understand just how much of the internet is still powered by PHP and will continue to do so for the forseeable future.

So, I'm still waiting for PHP's death. Or for this same predictable comment in 2030.

tcd··on 9M logs of Brits' road journeys spill from number-plate camera dashboard
> nobody came to any harm or suffered any detrimental effects as a result of this breach

Who gets to decide what "harm" is or whether anyone suffered "detrimental effects"? Surveillance is so common and normalized they don't consider the act of collecting so much information itself as a "detrimental harm".

What if that harm only presented itself years down the line? Maybe a creepy stalker who can synthesize mulitple data sets to reconstruct a person's movements or possibly use it against them some way (scammers and fraudsters are increasingly using all these leaked datasets to create a more accurate profile of an individual for more sophisticated attacks/targeting. Your name/address/mobile number must not and can not be considered PII since it's already been leaked probably ten's of times by now).

That's an incredibly shortsighted comment to try and justify developing a system with not even the most basic of security considerations.

I honestly just wish those same people were jailed for 50 years as a result, we'd see a LOT more consideration in the future if they were held personally liable.

tcd··on 9M logs of Brits' road journeys spill from number-plate camera dashboard
You can once the inevitable database leak of driver information details leaks from the DVLA/insurance companies.

It might take a few years, but you can use this dataset in the future to understand who owned the vehicle at this time and reconstruct their movements.

Using collected information it's possible a computer can remember every journey you've ever taken; this car with this reg plate was here at this time at this place, and they did not have a valid tax/insurance at this time, or it could be useful during investigations

tcd··on Google Apple Contact Tracing (GACT): a wolf in sheep’s clothes?
What does opt-out mean anyway? I've had examples where Google Fit has reenabled itself without my due consent in the settings of my phone (and I have screenshots to prove it).

We've seen opt-out abused before so it is down to whether you feel you can use a platform known for not respecting your choices.

Often times, it's a simple boolean value, do you want to trust that bool will stay the same, always?

tcd··on Privacy Not Included
HAHA! What an absolutely trash service, in that page it says:

> Facebook says that it does not listen to, view or keep the contents of any video or audio calls on your Portal.

No mentions about on their servers though, which we know they do!

How do I report articles on HN for misleading trash? This needs to be deleted from the internet.

How dare they give 5* to a fucking FB property.

tcd··on Privacy Not Included
Is Mozilla's new browser on Android not included on that list?

It contains 3 trackers [1]:

Adjust

Google Firebase Analytics

LeanPlum

It also has telemetry selected by default and is NOT opt-in. So yeah, whether it's hardware or software, you're being spied on any time you use an internet connected device.

[1]: https://reports.exodus-privacy.eu.org/en/reports/org.mozilla...

tcd··on Valve and HackerOne: how not to handle vulnerability reports
Just drop a line on twitter saying you've discovered a vulnerability in $popularSoftware and mention $company. Say you'll be disclosing in 90 days if $company doesn't issue a reply publicly.

Make sure to deal with an actual human and that everything is done according to best practice. You may even get publicity this way and even if it's unethical it can be sold or used to your advantage.

If they care, trust me when I say they will make an effort. Most places (like Google) have effective systems in place for dealing with such queries.

tcd··on Contact Tracing in the Real World
Not trying to be cynical, but to me this seems to be a way to get the mass public "okay" with contact tracing. Then somehow they "mysteriously" manage to get more accurate information from other sources (location, wifi beacons, data sharing etc).

But they'll just say "the information is only from this source, we pinky promise!".

tcd··on First look at Apple/Google contact tracing framework
> they could make having this app a legal requirement to go in any shop if they wanted

If they can legally mandate an "app" they can mandate me having a device to run said "app".

It'd be absolutely absurd to mandate you having a spy with you at all times to exist in society.

"Sorry, don't have a phone, kthx", "Sorry, my phone doesn't use gapps, it's using a custom ROM", and what about these Linux phones?

Yeah, that's not going to work.

tcd··on First look at Apple/Google contact tracing framework
None. If you're concerned, do not carry a spy around with you.

I know, it's a scary thought compared to 30 years ago, but it's possible.

tcd··on Privacy-Preserving Contact Tracing: Apple and Google draft specification
No disrespect but it's pretty useless. My "location" is where my browser "thinks" I am, no ability to correct it, and I was able to report myself as 'sick' which leads to your dataset being polluted.

Data which isn't verifiable is useless, wrong and potentially dangerous. IMO it's important that those who claim they are sick are actually sick.

If they're not, the data point isn't useful especially on a larger scale.

tcd··on Apple and Google partner on Covid-19 contact tracing technology
Right. But it's not like they're going to "just" announce that.

"Hey everyone - so yeah, we're using all your data you're willingly providing all these apps on your phone, like location, contacts, camera...So thanks for helping...Okay, bye!".

But you're right. Every day there is so much information from the spies we carry around with us as they communicate that it'd be unfathomable they're just "ignoring" all of this information.

The chances are in some privacy policy it says they can share that data with their "partners" which silently gets back to the government.

Just use what you already have, what we already know you have, and if it saves lives then at least it was put to good use.

tcd··on Apple and Google partner on Covid-19 contact tracing technology
This is why it'd be nice for the APK/installable file to have a hash that can be verified against an open source version. In theory someone should spot anything that doesn't look right.

But that can't/won't undo the effects of something being called "private" being exposed not to be afterall...

tcd··on Moving from reCAPTCHA to hCaptcha
I would love to see the raw data on how many transactions have been abandoned because of ReCaptcha; if I had to solve a test to purchase my shopping, I'd go elsewhere (and there are places that are not as hostile out there).

I cannot understand the stupidity of putting your entire business in the hands of an advertisement company who gives no shits about you as a business or a person, apart from your data.

I can say for certain ReCaptcha has made me reconsider a purchase and is a major factor in my purchasing decision. If I can't use all my privacy tools (including noscript, and I only whitelist a few times to get the right scripts), then I don't care about what you're selling.

Hopefully in the near future ReCaptcha breaks altogether due to enhanced privacy protection.

tcd··on Moving from reCAPTCHA to hCaptcha
I'm amazed Mozilla hasn't sued Google for discriminating against their browser - I also use Firefox and suffer endlessly using privacy tools. I can prove there are no more busses and I'm 100% right, but I can predict 100% of the time it'll say "please try again".

The pattern seems to be 2/3 'right' guesses. on sites like eBay, the captcha is broke on firefox. I complete it, and it says "you need to resubmit this form again", and reloads the entire page.

That's the cost of privacy; broken pages and refused access because Google says "NO!".

And businesses are okay with Google denying them money. I wonder if they did a cost/ben analysis if they find it worthwhile.

Thanks to Google, I've actually saved quite a bit of money, they lost out hundreds recently when their automated systems decided to refuse my transaction. Their loss and my gain.

tcd··on Moving from reCAPTCHA to hCaptcha
It's funny that we need to ensure humans are the ones performing certain actions like making a purchase or accessing a service, but we let machines make decisions over very important matters in our lives (credit/financial decisions).

It's intriguing they said Google will charge for reCaptcha, any information on that? I can't imagine all the small business owners will have to start paying, but perhaps if they did they'd just remove it altogether (a net win!).

tcd··on Bootstrap v5: drop Internet Explorer support
It seems IE11 has become the new Python 2.7. I can only hope one day MS decides to pull the plug entirely, it can't run any new JS features and is clinging onto life.

Eventually, the web will just break (for example, http/3), and IE will be forced to retire.

We just need the "right" pieces to break before it can retire in peace.

tcd··on Mast fire probe amid 5G coronavirus claims
Even the news outlets themselves are the ones spreading fear and non-substantiated claims. Just look into BBC's reporting of Molly Russell and how they use words like "Instagram helped kill my daughter", in quotes, to try and add substance to their piece.

They are willing to lay the blame squarely at Instagram's foot and yet offer no critical analysis of how her dad or teachers or society may have failed to help her - she may have tried reaching out, or showed signs of distress, but that's just glossed over because fuck instagram, they clearly have all the blame.

And that's a very dangerous narrative that people soak up - no critical thought, no attempt to try and offer thoughtful analysis whatsoever.

Those of us wise enough can see through their ploy, the agenda's they push, the propaganda they peddle. Just look into the BBC during the last election and you'll soon understand that disinformation, or out of context reporting is everywhere. Videos, quotes, images and basically all speech is being manipulated, to lure an unsuspecting reader into believing what they're ingesting, and has happened since civilization began.

YOU, as a human being, need to analyze and think about what you believe; are masks "ineffective" during this pandemic? News sources will tell you yes, others with experience will tell you no.

Stop relying on bots and algorithms to try and fill your world view, they're geared to feed you what you want to believe.

tcd··on Covid-19 Community Mobility Reports
No, instead they have armies of overzealous AI bots making decisions without any human oversight.

That's far more scary to me, but you know, you do you.

tcd··on Bringing 4K and HDR to Anime at Netflix with Sol Levante
The whole proposition by Netflix is hilarious. "Hey, everyone's at home now, so enjoy your SD kthx".

If I pay for HD I expect HD, if I pay for 4k, I expect 4k. I should be able to play 4K on any device I like, even if it doesn't work properly (as I can do by downloading the MKV).

Dumb Rights Management is and has always been a failure. I expect this anime to be on torrent sites shortly. All digital media goes onto torrents, and there's very little evidence to suggest DRM 'works', it only frustrates legitimate paying consumers (and makes consumers like me put off entirely).

Maybe in some decade we'll get an actual competitor to that offered elsewhere. Mean while, I'll enjoy all the 4k/HD content I desire, without any hassle or throttling, and BS management decisions at the cost of my internet connection.

Now that's a good deal - how close can Netflix get, so far, not close enough.

tcd··on 1.1.1.1 for Families
I feel that transparency would be key, to understand what cloudflare considers good/bad.

As we can see in this thread, there's already been a mistaken block - expect many, many more of these to come.

They will be chasing their tail between their legs for years to come, and they'll only get bad PR from this.

It'll be dead and buried in a year after a shit storm hits reddit

tcd··on Full third-party cookie blocking and more
The web shouldn't block ads, it should block JS entirely. There should be a 'global' permission system (similar to Android) that allows me to control exactly what information websites are allowed to access from my browser.

For example, I want to disable WebRTC as it can be used to collect my IP address, or disable WebGPU APIs or anything that can be used to finger print me.

JS has far, far, far too much broad access to information that might seem mundane but can be used to profile a user.

Android is the same - you can get the entire list of installed packages on the system and various other pieces of information to build a unique, persistable tracking ID.

There's also a lack of accountability: What information is being sent to what servers? I want a detailed JSON formatted breakdown of EVERY single piece of data that is being sent from my device.

I should be able to block anything that is outside my own determined comfort zone.

But most OS' just make requests to US IP's without much thought now - just turn on Windows 10 in a VM and watch as it sends so many requests with no insight into the data, which many companies (including Google) don't tell you about.

Ask me about a recent GDPR request to Google which I just got a generic response about (and they didn't action my request to delete information, so now I need to complain to the regulator because it was also late).

So yes, blocking ALL tracking by default is sensible.

tcd··on RFC: Adopt a modern JavaScript framework for use with MediaWiki
It's our collective responsibility to decide what user agents work with what platforms.

The beauty of the internet is that any website is free to decide as they see fit - if they don't want to support IE/Edge/etc then that is their choice.

No website is a 'public utility' bound by laws which dictate what browsers must be supported - that remains a free and open decision.

IE11 is a dead browser, and the sooner it breaks for good, the better.

tcd··on The reckless, infinite scope of web browsers
Is this a fundamental problem? I mean, all the code required to make your own browser is Open Source - Microsoft can customize the Chromium engine as much as they like, adding in their own patches and removing parts they dislike.

I mean, would you write your own networking stack? Probably not. You'd take an existing tool and, if you really want, make it your own.

Most of humanity and what we do is based on those who made our lives easier with tools they built, and that changed how the manufacturing process altogether.

tcd··on Google tracking a bike ride past a burglarized home made the rider a suspect
delete your google account.

don't use android (or iOS really).

don't carry a smartphone.

I mean, it may seem inconceivable but you're not forced to carry a spy in your pocket =).

tcd··on Europe sees warmest winter since records began
I think it's already too late - US is withdrawing from the Paris agreement. Australia is in complete denial it seems

We need to reduce emissions yesterday and reduce our plastic output considerably. We're not doing anything on a scale big/quick enough to matter.

We don't have until 2050 or the targets some governments have set.

We need it done by next year, 2021, but that's unlikely to happen. We need new laws enacting tomorrow and to give everyone a big kick up the ass to get their acts together.

That's not going to happen, no matter how desperate Greta, Attenborough make it seem.

tcd··on Apple now allows iOS developers to send ads using push notifications
That's....Not beneficial, at least in terms of what is going on behind the scenes.

1: App knows your location - most likely is profiting from that

2: App can see how often you visit $place, all for the cost of a few 'sale' items.

3: More extensive profiling can possibly occur, depending on what data the OS allows you to access.

As apposed to:

1: Walk to shop, no smartphone, see discounts inside shop.

There's 0 reason this information needs to be presented via any form of 'notification'. It could literally be done by $shop.com/discounteditems.txt.

tcd··on 8000 screenshots of my PC and phone over the past 365 days
I'm going to flag this (hopefully that's the same as report)?

It's pretty irresponsible to publish this if you haven't:

a) Checked ALL the screenshots yourself

b) got permission for all the PII (names, mobile numbers) of everyone in your screenshot.

Should be removed until such time as that's established.

tcd··on Google's ambitious push into gaming is floundering
It's hilarious. Many people commented on how long it would take before it ended up in killedbygoogle.com.

I don't trust a single product they launch these days. Usually it's best to wait 5 years and get a sense for its longevity.

What products do Google make that last longer these days? I feel the majority of new stuff ends up canned because it just doesn't hold up to the tech debt and costs for running the service at such huge scale.

Page 1 of 6Next →