HNHacker News
TopNewBestAskShowJobs

tetrep

2,031 karma · joined June 26, 2013

I probably have not been served an NSL.

paul at blacksheepwall dot com

submissionscomments
tetrep··on It’s Time to Reaffirm Our First Amendment Right to Boycott
> The court of appeals reasoned that because one can’t know the meaning of a decision not to purchase from a business unless it is accompanied by speech, the boycott itself is not protected, and the state is free to single out and penalize the boycotts it disfavors.

Wow. Using the same logic as that ruling, donating to politicians is not protected by the 1st Amendment unless you also include a memo making clear your intent...

This feels like more "I'll know it when I see it" but with intent instead of porn.

tetrep··on Westinghouse sees a tech disrupter in its eVinci microreactor
I read an article about this recently and there's at least one company working on exactly such a process:

> Swedish green-tech firm SaltX Technology demonstrated that it can produce clinker with its Electric Arc Calciner: a proprietary system similar to the plasma torches widely used by automakers and other manufacturers for cutting metal. Plasma torches pass an electric current through a jet of inert gas, typically nitrogen or argon, which ionizes the gas and heats it to temperatures over 20,000 degrees Celsius. In June, SaltX announced a partnership with the Swedish limestone supplier SMA Mineral to accelerate commercialization of its technology.

Article: https://arstechnica.com/science/2022/11/the-road-to-low-carb...

tetrep··on Libraries – how companies do not understand open spaces
Librariarch?

Library + https://en.wiktionary.org/wiki/-arch

tetrep··on Skin exposure to UVB light induces a skin-brain-gonad axis and sexual behavior
There's similar issues with computer security and having projects reviewed before being shipped, with the classic story of people avoiding review because they didn't think they needed it at the start of their project (not that they're qualified to determine that) and by the time someone told them about it, it was "too late" and they'd miss important deadlines by going through the requisite review.

The only sane solution I've seen to that is to make everything go through security review, even if the review is a simple "we don't need to review this." If everyone knows everything needs review, it makes it very hard to forget about it and incentivizes people to involve security folks with their projects ASAP in the hopes of getting review done early on / avoiding being blocked by it.

You'll always need exceptions to the rule, so you can have some sufficiently high up VP or similar sign off on releasing things without review (and with the caveat that it's still going to get reviewed, it just won't block release), but that's a lot easier to manage than dealing with random developers deciding it for themselves.

It also helps a lot to have a culture where developers learn about security too, but just like researchers and ethics, they'll have perverse incentives to downplay/ignore risks so you still need other, differently incentivized people, to enforce "checks and balances."

It sounds like IRBs are not designed to review all or even most (animal?) experiments and I think that's unfortunate. It seems like a win for everyone if we get better ethics coverage.

tetrep··on Classes vs. Data Structures
Haskell does address it exactly as you say. Functions and values both being expressions is much less complex. As an example, imagine if you couldn't freely substitute 2+2 and 4. Functional languages say those are the same, imperative languages say one is a value and one is a function call.

It's not particularly intuitive if you're not used to high level math or functional programming, but it really is a lot simpler (not that it doesn't have downsides/leaks in the abstraction, but that's another discussion).

tetrep··on We launched an app with $500k annual revenue, and then Apple copied it
But patents wouldn't protect them in this instance. Patents are explicitly for implementations, not abstractions/ideas. I highly doubt they could get a patent on an implementation sufficiently abstract that would block any statistical tracking/monitoring of app usage, or at least one that wouldn't run into prior art issues.

Apple isn't tunneling everything through a VPN to track it.

tetrep··on Mazda is purging touchscreens from its vehicles
It is. Car conversations are a serious issue with respect to distracted driving. I personally can't handle thinking about driving safely and thinking about a conversation. Humans are famously bad at multi-tasking and I don't see how being in a car gives us magical powers.

I thought I had read a study about talking to people in your car versus drinking, but here's a similar one with talking on a phone versus being drunk: https://www.ncbi.nlm.nih.gov/m/pubmed/16884056/

tetrep··on Salesforce is buying Tableau for $15.7B
Is this somewhat common? It makes intuitive sense, but the big 3 or 4 or whatever number it is (IBM, P&Y, etc) consultancies have "use us for everything" as their explicit strategy / part of their sales pitch.

So while they might lose customers like you, there is clearly ridiculously large piles of money up for grabs if they diversify their products, rather than remain specialized. And, of course, any sufficiently good specialist is at risk of being acquired by one of these behemoth generalists.

tetrep··on Blender Is Free Software
I don't have any additional context, but the overall style of the post makes it sound to me like it could be talking about a change in the add-on API license or something (in addition to a general pro GPL post). This is the strongest evidence I have:

> I expect that all add-on developers recognize and respect this concept.

tetrep··on Salesforce enables ‘modify all’ in user profiles
it'd be nice if we could get the hn link pointing to that instead, since it's actually got a bit more details than the reddit post and the reddit post doesn't seem to be getting updated, so it's only going to get more "stale"
tetrep··on Utah Bans Police from Searching Digital Data Without a Warrant, Closes Loophole
I'd rather the camera always record and make the "off" button a "private" button that encrypts the footage (but not metadata) when pressed. If the "private" footage is relevant to something police can get a warrant for a specific time range.
tetrep··on Saudi Aramco Is World’s Most Profitable Company, Far Exceeding Apple
I don't think the latter is true. Crude oil is still a great source of fuel and even in the worst case society collapse people will still need fire.
tetrep··on Tumblr has lost 30 percent of web traffic since December
What you want sounds within Reddit's normal use case. If it's not a site feature, it's a feature of automod: https://www.reddit.com/r/AutoModerator/

There's a lot of subreddits configured to only allow text posts, one of the subreddits I frequent is configired to delete your post if it is an image post that doesn't have a top level comment by the poster, as the subreddit rules require all image posts to have text descriptions (to guide conversation/mitigate low quality posts).

I don't Tumblr so I don't know the full use case for tags, but from what you've described it sounds like flair: https://mods.reddithelp.com/hc/en-us/articles/360010513191-P...

tetrep··on Amazon Personalize: Real-Time Recommendation
To take it a bit further, you'd probably want to mark down the checkout suggestion to not only make it look better, but also because you're only suggesting a very limited amount of options, once customers are used to trusting the checkout suggestions for a good deal, you introduce higher-margin and/or promoted products.

More or less the same tactic Amazon used for search results: Return useful/functional results for a few years to train you users to trust what is near the top, then start putting promoted products at or near the top and generally ordering the search by what increases your revenue the most, rather than for any user-oriented goal, AKA "sort by relevance".

Also the same thing Amazon did with prices in general, get people used to thinking you're the market with the best price/deal, etc.

tetrep··on This Startup Does Not Exist
Reminds me of the startup generator: http://tiffzhang.com/startup

HN discussion (2015): https://news.ycombinator.com/item?id=9427856

tetrep··on DOJ: Hackers broke into an SEC database and made millions from inside info
> This is easy to solve; simply make it illegal to use the identification number so capriciously.

Hmmmmm, that sounds familiar... https://en.wikipedia.org/wiki/Social_Security_number#/media/...

While it wasn't law, I don't see why legislature wouldn't renege on their promise to not use a unique identifier, already conveniently assigned to all people, for identification purposes.

tetrep··on Congress just voted to legalize hemp
Wikipedia is usually a good place to start: https://en.wikipedia.org/wiki/Terpene
tetrep··on Two images of the miners' strike, an instant apart: so which is the classic?
Looking at the links of the photos from other commenters, is the gun actually pointed at man being given water? There's 3 US soldiers in frame, the one holding the guy and the one giving him water are both next to the guy, and the 3rd seems a few feet away, and could easily be holding his gun in a neutral position, pointed at the ground, giving a optical illusion similar to what tourists try to do with the Leaning Tower of Pisa.

Edit: Looked at it a bit more, the non-water giving adjacent US soldier is not holding the guy (I think his hands are bound behind his back by cuffs/rope/zip ties/whatever).

tetrep··on A well-known URL for changing passwords
That's effectively what U2F provides. You can "nop" the password by using a bad password that you can trivially remember, and then your U2F token is, effectively, your only authentication.

I don't know what features U2F tokens support, but if they can be password protected I don't see why U2F being the only auth factor would be bad. You could even have the token itself attest to being password protected so you could require that of users before allowing them to disable non-U2F passwords.

tetrep··on Type inference
If types are specified in function definitions, then you'll find them in the docs, which you need to be reading in order to properly use a function in the first place.

Finding out type definitions is made massively easier with an IDE, but even without one there's an extremely high chance any library you're using is going to at least have autogenerated docs sitting on disk somewhere or mirrored on a crappy website. Maybe you need to clone their repo and build the docs yourself, but even that's pretty unlikely as most language ecosystems have a package manager + docs website or man pages.

I don't really develop anything without at least a third of my screen real estate dedicated to documentation and I don't see "RTFM" as a meaningful or undesirable barrier to programming correctly.

> Now you don't need to know or care about how "uniqBy" works, or the exact details of how you should or shouldn't use it...

I don't follow you. What if "uniqBy" only works properly on sorted lists? You'd never know that based on the type (unless you've got dependent types) and if you're not reading docs on how the function works (the types check/it compiles!) you're going to be in a world of hurt at runtime. Intuitive programming may be easier but it's a heck of a lot more dangerous unless your compiler is intuitive too (i.e. makes the same intuitive assumptions that you do).

> ... and if you try to pass 2 arrays with different items, it will yell at you because that's not right, something that type inference can't determine (at least not with Flow's typesystem)

That's entirely Flow's fault. There's no reason a "proper" type system couldn't deduce that the same type would be needed for both arrays, the `oldItems.concat()` call should have a type definition something like (functional for brevity): concat(Array<T>, Array<T>). Nothing ambiguous about T being the same type.

tetrep··on Fallout 76 Day One Patch Is Larger Than the Game Itself
I thought disk I/O was a major blocker for loading in games, which would imply you'd want to keep things compressed on disk.

Additionally, as another commenter pointed out, the majority of assets are in formats that support native compression (textures and audio) and thus won't compress too well a 2nd time.

tetrep··on Apple T2 Security Chip: Security Overview [pdf]
> As I understand it, Apple claims that by simply changing its online service to deny signing certain boot loaders, it can prevent many OS downgrades to versions with known vulnerabilities.

That seems like a very reasonable ability considering that "Full Security" mode says, "This mode requires a network connection at software installation time."

I'd guess it's a challenge/response deal with the T2 in your Mac issuing a challenge to Apple. The response could be as simple as Apple signing the signature of its software with the challenge, i.e. response = sign(challenge + sign(MacOS))

Presumably it's whatever Apple currently does for iOS, as my understanding is that it has the same downgrade protection feature and that is part of what makes jailbreaking so precious, you need to be on the vulnerable version of iOS in the relatively short window it's still being served by Apple (aka before Apple patches some or all of your exploit chain).

tetrep··on Copyright Office Ruling Imposes Sweeping Right to Repair Reforms
I think this ruling would apply to anyone who wanted to bypass controls Cisco might have in place to prevent other software from running, e.g. a custom non-Cisco OS. I don't think it would give you the right to run Cisco's software.
tetrep··on Building a Titan: Better security through a tiny chip
> Finally, in the interest of transparency, the Titan M firmware source code will be publicly available soon. While Google holds the root keys necessary to sign Titan M firmware, it will be possible to reproduce binary builds based on the public source for the purpose of binary transparency.

and

> Transparency around every step of the design process — from logic gates to boot code to the applications — gives us confidence in the defenses we're providing for our users. We know what's inside, how it got there, how it works, and who can make changes.

This should be a boon for security researchers! I'm really looking forward to what comes out of fuzzing that whole subsystem. I imagine attacks against the secure enclave would be a lot easier to perform (and ideally, report to Apple) if it was feasible to attack it with pure software.

tetrep··on Survey of YC female founders on sexual harassment, coercion by angels and VCs
It sounds like you'd need to lie to a lawyer, which (I assume has) legal implications:

Users of this product will be able to enter the identity of their perpetrator into the escrow. This data can only be decrypted by the Callisto Options Counselor (a lawyer), when another user enters the identity of the same perpetrator. If the perpetrator identities match, both users will be put in touch independently with the Options Counselor, who will connect them to each other (if appropriate) and help them determine their best path towards justice. The client relationships with the Op- tions Counselors are structured so that any client-counselor communications would be privileged.

edit: from https://www.projectcallisto.org/callisto-cryptographic-appro...

tetrep··on EFF to Texas AG: Epson Tricked Its Customers with a Dangerous Fake Update
I don't think regular updates are abused to remind you because it's pretty trivial for the application to pester you with notifications itself. I think the updates are a combination of wanting to keep the app fresh and "normal" bug fixes/features that, especially since "nobody" cares about details, developers never bother writing details for.

If you're on Android, you can disable update notifications from the app store settings.

tetrep··on New Evidence of Hacked Supermicro Hardware Found in U.S. Telecom
Couldn't it be done on-demand? Apple orders X hundred boards, motherboard manufacturer makes their small modification(s) to a line that is currently producing the same models of motherboard as Apple ordered, they produce a handful, then they revert and mix in a few of those modified boards into the real order. I don't really know the exact scale, so maybe they make a few hundred / the entire order with chips in them, but economic cost isn't a big deal for things like this, so even losing money making the modified boards wouldn't be the end of the world (and presumably they get a hefty sum of money for whoever is paying them to do this).

I thought China was famous for extremely short turnarounds for industrial engineering edits, so it seems plausible that they could manufacture the boards in a reactionary way and not need to do much in the way of logistics to get them to their targets.

tetrep··on Abstract of the NTSB Report on Air Canada flight 759's taxiway overflight at SFO [pdf]
> Cockpit voice recorder (CVR) information was not available for this incident because the data were overwritten before senior Air Canada officials became aware of the severity of this incident.

How long are recordings normally kept? I would assume at least a few days for mundane flights (storage is cheap, isn't it?) but any sort of incident similar to this I would assume they keep recordings for much longer, if only for internal purposes.

tetrep··on Pioneering study finds more than 200,000 rats in Barcelona’s sewers
How do you know it's deceit? It seems like you could get similar behavior if you filled two trays, one with food and the other with trash, and never provided food unless the trash tray was empty. You're training the rat to empty the tray.
tetrep··on Chrome 69 will keep Google Cookies when you tell it to delete all cookies
you can use the same argument to tell people not to vote. it's not a good one.
← PreviousPage 4 of 14Next →