HNHacker News
TopNewBestAskShowJobs

tgsovlerkhgsel

17,079 karma · joined December 26, 2015

all opinions are my own
submissionscomments
tgsovlerkhgsel··on Extreme Heat conference cancelled due to extreme heat warning
I get rage when I hear those "5 clever tips to stay cool without A/C".

Many buildings already have shades, but please tell me more how those shades and "properly ventilating during the night" (aka not getting sleep half the night due to outside noise) will keep my apartment at a livable temperature when the air temperature outside never drops below 23 degrees for more than an hour.

You can't effectively remove the heat that has pooled in the apartment with a 2-3 degree temperature difference, let alone in the few hours where you actually have that difference.

So because of thinking like the one in your post, we can't have real AC's (because to "protect the environment" we'd first need to install every other system that doesn't help then prove that with a mountain of paperwork), so my only option is to open the well-insulated window so I can stick the coolant hose of a portable unit through it.

I think the "properly installed AC bad" mentality will only change once the entire population of renters has those inefficient portable units (that are de facto impossible to regulate) and even the anti-AC group realizes that encouraging "real" ACs is much better than the workarounds that the status quo forces.

tgsovlerkhgsel··on Extreme Heat conference cancelled due to extreme heat warning
"Simply cannot have AC" is a problem we did to ourselves, or rather, the "its not so bad just suffer a bit" people are doing to the rest of the population.

What are the reasons "most of us simply cannot have AC"? Either laws/regulations banning it or making it prohibitive, or living in rentals without proper protection.

There is no reason why heat protection couldn't be mandated for rental units just like heating is required in winter. Or why tenants couldn't have a right to install AC at their own expense.

Meanwhile, because permanent AC units are de facto impossible, the portable Mideas sell out as soon as the heat wave hits, and we're forced to run air conditioners with literally open windows just so we can run the hose through.

(You should get one for next year, by the way. You probably missed the opportunity for this year unless you want to pay a scalper 2-3x the normal price, but they can be installed in essentially any window or balcony, are reasonably quiet, much better than the 'air hose out the window' monoblock units, and they fucking work)

tgsovlerkhgsel··on Extreme Heat conference cancelled due to extreme heat warning
How do you suggest to keep buildings livable during the decades that it takes to (as you suggest) essentially rebuild cities?
tgsovlerkhgsel··on WhatsApp's "End-to-End Encryption" Is the Biggest Lie in Tech History
Feels AI generated ("linkedin-style" short sentences, blob of malformated text towards the bottom), so I'll give myself the permission to skim and take shortcuts.

The most interesting claim is the weakness of groups (the article claims the server controls who is a group member, without cryptographically secured authorization by an existing member).

The other key points are correct to my knowledge but unsurprising to anyone knowledgeable and partially apply to Signal too (backups are a weak point, you securing/disabling them properly doesn't protect you, metadata is unprotected and sensitive, participants in the conversation might upload the chat to Meta's AI, endpoints are attackable either through WhatsApp or other apps, the general trust issue - which isn't really resolved by being open source unless someone actually checks the reproducible builds AND someone reviews the code).

I thought that claim about the backup password hash was wrong, but https://www.nccgroup.com/media/fzwdxklh/_ncc_group_whatsapp_... suggests that Meta thought that 100k iterations of PBKDF2 are a reasonable choice for the key derivation, so it might actually be accurate.

AFAIK WhatsApp backups are, by default, encrypted with a key escrowed to WhatsApp (which means that an attacker using warrants now has to subpoena both the cloud provider and whatsapp - probably the best you can get while keeping backups usable for the 99% of people who can't be expected to write down a passphrase and still have it when asked).

But IMO the reality is that WhatsApp is the most secure messenger that you can expect normal people to actually use (mostly due to market share/network effect), and the only secure-ish messenger aside from Signal, so I'd be careful with the messaging towards "normies": "Signal is a much better choice, but out of the other options, Whatsapp is by far the least bad".

Otherwise, you end up with people picking something like Telegram because "it's all bad anyways" or "I've heard Telegram is secure".

tgsovlerkhgsel··on Identity verification on Claude
Most importantly, they state "We [Antrhopic] are not using your identity data to train our models" but "Persona [...] can use your data [...] to improve their ability to prevent fraud." -- in other words, Persona can (and will) use your data to train their models.
tgsovlerkhgsel··on Telescope Ranchers
Customer support. Don't forget customer support.
tgsovlerkhgsel··on Many Let's Encrypt renewals had errors today
A warning with a clear clickthrough button would work for alerting - the default TLS warnings are designed to be somewhat hard to bypass to make people think twice.
tgsovlerkhgsel··on Many Let's Encrypt renewals had errors today
Revocation information may not be available for expired certificates. Not that it matters much because the last time I checked revocation didn't really work for non-expired certificates either, but I think that (+ the risk of people treating expired certificates as worthless and thus increasing the risk of exposure) is the main reason.

Also of course domains changing owners, but again... I don't think we have good monitoring for that during the current long lifetime, so maybe a grace period where a warning is shown but it's easier to click through would be a good idea. Perhaps combined with a requirement to keep revocation information (and keep revoking expired certificates) X days past expiry.

tgsovlerkhgsel··on Windows 11 users are tired of MS account requirements creeping into everything
An old Spartan response applies here:

If.

tgsovlerkhgsel··on Midjourney Medical
Or only consider it a positive once the confidence is high enough that false positives are not a problem anymore.

Getting a test good enough to still make it useful (detect enough of the true positives) would of course be a challenge, but the more data is available, the more feasible that might be.

tgsovlerkhgsel··on Midjourney Medical
I think it's (at least partly) about the psychological impact of finding something unusual. Even if you know that it's probably nothing and understand the Bayes theorem, there will be a "what if" that might be strong enough to do actual harm (nocebo effect).

Compare: The placebo effect works (at a reduced rate) even if you tell people they're getting a placebo!

tgsovlerkhgsel··on Midjourney Medical
We could test symptomatic people.
tgsovlerkhgsel··on Midjourney Medical
That sounds like a problem with applying the wrong threshold for a positive finding, possibly due to liability concerns or wrong goals.

To work, it would have to be incredibly accurate (specifically, have an incredibly low false positive rate).

tgsovlerkhgsel··on Midjourney Medical
I think a lot of medical diagnosis could be solved with mass data collection if it was cheap enough. Right now, blood draws are somewhat routinely done because they provide a lot of human-interpretable indicators from a small number of values, and there is some evidence that e.g. "dogs can smell cancer" etc. (i.e. some diseases cause detectable odors).

With a big enough data set of [all kinds of bio values, including ones considered irrelevant for that disease] labeled with diagnoses, I suspect we could get very fast and accurate automatic diagnoses, even from a limited data set currently considered uncorrelated. Rather than going to your primary care physician, you'd go into the standardized, mass-produced and thus reasonably cheap everything-scanner, and you could likely get a more accurate diagnosis (or at least "things to check") than the average doctor would be able to give you under the practical constraints they typically operate under (time, available information/diagnostics).

This goes in that direction, and I'm really excited to see where it goes. I could imagine that given enough training data, ML models will be able to pick up on minute details that make it possible to diagnose diseases that weren't historically considered ultrasound-diagnoseable from this kind of detailed ultrasound.

I think combining it with gas chromatography/mass spectrometry of e.g. breath or blood/sweat/urine samples would also have the potential to be a cost-effective diagnosis method - lots of data, probably not all too useful for human interpretation, but would open the potential to walk up to a machine, breathe into it, spit into it, pee into it, give it a swab, and have it come up with an accurate diagnosis without invasive testing. If mass produced, the cost of something like this could easily drop below the cost of a typical doctor's visit. (I googled it and it seems like GCMS is already used for some diagnoses, but screening only for a few specific diseases rather than "throw ML at it and try to diagnose everything").

tgsovlerkhgsel··on Windows 11 users are tired of MS account requirements creeping into everything
Because when I want to play a game, I want to play a game, not debug someone's hacky attempt to make it work on Linux.

Implementing a strict "no fiddly shit on my game machine" policy was one of the best choices for my mental health that I've made: It's a dedicated machine for gaming, with nothing really sensitive on it aside from gaming related accounts, and its only purpose is to play games with the least amount of immediate hassle. In other words, if the choice is installing something ugly or fiddling, that launcher, kernel level anticheat or whatever it is gets installed.

tgsovlerkhgsel··on Pirates, a naval warfare game inspired by Sid Meier's Pirates
That link doesn't work, so I'll respond here: My impression is that my ship always has a better turn rate than the other ship, so if I ever manage to get into the enemy ship's e.g. 4'oclock position, I can keep turning towards it, it will (slowly) turn towards me while consistently shooting behind me, and I can consistently hit it.
tgsovlerkhgsel··on The RCE that AMD wouldn't fix
This is a pretty common behavior that I've seen from bug bounty programs:

> a blog post discussing this issue has already been published, which does not appear to be in accordance with the program’s terms.

Companies reject bugs as out of scope and/or sit on them forever, then use the bug bounty ToS as intimidation to keep people from disclosing them. And sadly, it works.

I'm adding AMD to my list of companies that prefer their bug reports to be a public full disclosure rather than attempting to go through their bug bounty program.

tgsovlerkhgsel··on Google to pay SpaceX $920M a month for compute capacity at xAI data centers
To be overvalued by an order of magnitude, it'd have to have a fair valuation of under $180 B.

At ~5 billion per year in profit, Starlink alone would justify a 100 B valuation at a P/E ratio of 20 (i.e. assuming a non-growth company). If you account for the fact that this is very much a growth company, the valuation of the space part alone is well above these $180B.

And they do happen to have the launch and AI businesses on top of it, which (as usual for growth companies) may not be obscenely profitable but aren't worthless.

If 90% of the value is from the AI business, it's grossly undervalued.

tgsovlerkhgsel··on Google to pay SpaceX $920M a month for compute capacity at xAI data centers
But building a Starlink competitor is essentially impossible without also building a space company, and the main competitor doing that just turned their only launchpad into a crater and is out of the game for a year or so.
tgsovlerkhgsel··on Debug Project
I'm hoping that at some point someone just disregards all the "safety" debate, does it, and succeeds. There is something deeply upsetting about being in the position humanity is on earth and still being expected to tolerate being eaten alive.

I wonder why we don't just try it on some remote island that has had mosquitoes introduced to it, but is otherwise considered isolated from the rest of the ecosystem (at least as far as mosquitoes are concerned).

tgsovlerkhgsel··on Alphabet announces $80B equity capital raise to expand AI infra and compute
My guess: The company culture means that the best people went to other companies.
tgsovlerkhgsel··on GitHub bans security researcher who posted zero-day Windows exploits
You don't need to be thinking of any specific vulnerability to realize that putting the decryption key next to the data you're trying to protect is a dumb idea.

If for example a laptop like that gets lost or stolen, the attacker has the data and the key, in a box they physically hold, with no attempt limit, and unless they actively mess with the boot process, it will happily load the key into memory for them. If it's a discrete TPM the attacker can likely sniff the key on the wire. If that doesn't work, they just need to find a vuln anywhere in the secure boot process, or in Windows, and again, they have the key. And if that doesn't work, they could sniff the memory bus, or do a cold boot attack (again, with unlimited attempts unless they irreparably damage the mainboard/TPM in the process).

tgsovlerkhgsel··on CBP Directive 3340-049B: Border Search of Electronic Devices
Nothing works on Android. Not even for basic app data. The biggest problem is keystore keys and e.g. bank authenticator apps tied to them.

AFAIK iPhone backups, if restored on the exact same device (i.e. a CPU with the correct decryption key embedded in it) will restore almost everything, including authenticator apps.

The only realistic option for Android is a separate "burner" device.

tgsovlerkhgsel··on Why We've Filed a Referendum
Aside from "moral outrage" style concerns ("AI is bad for the environment", power consumption, water consumption, or "datacenters benefit rich people, rich people bad, so datacenters bad"), I've heard of specific bad examples how datacenters (allegedly) negatively impacted the surrounding population:

- Noise (from fans to generators to possible infrasound concerns)

- Air pollution (from data centers semi-permanently running on generators)

- Electricity prices (although I don't understand how this is supposed to work)

- Water consumption affecting the population (water restrictions, price increases, water table dropping)

Many of these are one-sided stories told from the perspective of the residents that I didn't try to verify, but I suspect some of these concerns are legit.

The company building the datacenter has a lot of incentives to cut corners and/or cause some of these impacts, externalizing its costs (e.g. by saving money at the expense of noise emissions, running the DC on unpermitted gas turbines to be able to build a DC where there isn't enough grid, negotiating clever deals that benefit the company but screw over the utility forcing it to raise prices for others, using groundwater for evaporative cooling to make cooling cheaper, etc.)

The company building the datacenter also likely has a lot more experience while the people of the town and the town itself are doing this once, so there is an inbalance in experience that makes it easy for the company to get away with some of these.

There is very little benefit that the people of the area can expect from a data center - as I understand it, there are very few jobs in one past the construction phase, even the construction jobs are often filled with experienced travelling workers, and given the negotiation imbalance, a town seems likely to get screwed on any contributions that the data center promises.

Maybe the solution would be some kind of framework/organization that guarantees (ideally with binding, well tested contracts) that the datacenter won't be a nuisance, builds a reputation for being reliable, and in exchange, companies that work under that framework can expect quick approvals and less pushback.

Until that exists, or companies start offering guarantees up front (e.g. guaranteeing a certain power price or noise level), I'm not surprised that people push back (especially if the company building the data center has screwed up in the past).

tgsovlerkhgsel··on Where to buy a non-Apple, non-Google smartphone
You're essentially blaming the robbery victim for handing over their wallet rather than fighting the knife-wielding robber.
tgsovlerkhgsel··on Where to buy a non-Apple, non-Google smartphone
Interesting that you mention Europe, because if I remember correctly, at least in Germany, all banks that I'm aware of dropped SMS support when PSD2 was introduced.
tgsovlerkhgsel··on Where to buy a non-Apple, non-Google smartphone
That doesn't solve for services that by definition need to be accessed on the go, e.g. public transit, parcel pickup, luggage lockers, rental bikes, restaurant menus, paying for parking, etc. (some of these may not mandate phones in your area yet or may allow mobile web alternatives, these are just examples where I've seen strong pushes towards apps or at leas in many places).
tgsovlerkhgsel··on Where to buy a non-Apple, non-Google smartphone
> can and should fight

I disagree, because the impact on my quality of life from fighting the fight is just not a level of sacrifice that is sensible.

> There are now and there always will be alternatives

The problem is that those "alternatives" often come with serious downsides, from higher cost, to massive inconvenience, to having to work around simply not having a service. And while most of the time it's possible to work around it, most people quickly hit the limit where the cost isn't bearable.

tgsovlerkhgsel··on Where to buy a non-Apple, non-Google smartphone
No, but you will likely be inconvenienced to a similar level as losing your house keys, and lose access to important services. You won't immediately die, because most people can survive for quite some time on nothing but questionable river water and a piece of cardboard under a bridge, but there is a difference between survival and existing in society.
tgsovlerkhgsel··on Where to buy a non-Apple, non-Google smartphone
> as inconvenient as it was in the 1990s

That's not true, because in the 1990s there was no presumption that everyone has a major-vendor smartphone. Now, the ways to do things without a smartphone are often disappearing, so things are more inconvenient. For example, ticket machines and printed schedules for public transit are going away in many places.

← PreviousPage 5 of 34Next →