HNHacker News
TopNewBestAskShowJobs

throwawayReply

787 karma · joined July 5, 2016

submissionscomments
throwawayReply··on Why it took a long time to build the tiny link preview on Wikipedia
You're very much not alone, this comes up frequently here at hn, because other sites also frustratingly block this behaviour often by popping up "tweet this" links after highlighting.
throwawayReply··on How North Korea’s Hackers Became Dangerously Good
> a nation where 99% of people shit in simple holes in the ground

Now that is propaganda.

throwawayReply··on Viability of unpopular programming languages
The index is clearly not credible:

https://www.tiobe.com/tiobe-index/visual-basic-dotnet/

There is no way that in reality visual basic is surging up the charts and more popular than most other languages, instead I would guess they are attributing some .Net results to VB instead of C#.

for comparison, this is the google trends chart of visual basic: https://trends.google.com/trends/explore?date=all&q=visual%2...

throwawayReply··on Singing road strikes wrong chord with Dutch villagers
It's interesting how you still observe the doppler effect even though the road isn't moving.
throwawayReply··on Exit scammers run off with $660M in ICO earnings
Did it actually raise 660m or was that the size of the "market cap" when it collapsed?

if I sell 100 tokens for a dollar then convince someone to buy 1 token for 10 dollars, if I run off with the money I've not run off with $1000 even if it feels like it for the people left with tokens.

throwawayReply··on Kafka, GDPR and Event Sourcing
Right, and what if those connections are burned into an immutable data source through the connection event in your event sourcing?

That is what this article is about, and methods to deal with that.

throwawayReply··on GDPR and automated email marketing
The UK has had data protection laws for years, people aren't scared of GDPR because it finally provides laws, they're scared because they actually look enforceable.
throwawayReply··on Web Authentication: Proposed API for accessing Public Key Credentials
1. A fingerprint is something you cannot change, cannot revoke if leaked and cannot be unique across different sites.

2. A fingerprint hash isn't a cryptographic hash because you need to be able to match to nearby matches. A small variation in input needs to have a small variation in the hash so a distance function can be applied.

Those are terrible properties for a password.

throwawayReply··on Web Authentication: Proposed API for accessing Public Key Credentials
Fingerprints are usernames, not passwords (2013): http://blog.dustinkirkland.com/2013/10/fingerprints-are-user...

edit: The original headline before being changed, "Web standard brings password-free sign-ins to virtually any site", and contained a paragraph espousing fingerprints in place of passwords.

throwawayReply··on Common Mistakes in Firebase Security Rules
I'm not familiar with firebase, but am I reading correctly that rules cascade but without specificity rules?

How does cascading make sense at all if lower-down rules don't supersede higher rules?

throwawayReply··on Probabilistic Filters By Example
I was trying out the javascript example, but managed to get a case where there is a negative conclusion but this goes against the introduction where it says negative conclusions are always definite.

My multiset was:

   a, b, c, d, e, f, g, h, j, abc, def, asd, asds, 3g46stb6vy6vsyosyvosfsdfsdsah, oooooooooooooooo
Then trying oooooooooooooooo a second time, the bloom filter correctly says it might be in the set. The cuckoo filter says it is not.

I assume this is just a javascript bug in implementation, because previously the filter said it might be in the set, actually adding it to the set then gave a false negative when trying it again.

throwawayReply··on Facebook Container Extension: Take control of how you’re being tracked
There's a "Same-Site" cookie flag that helps prevent CSRF by preventing cookies being sent in that scenario. Can the browser be made to treat all cookies as "same-site" for a quick 'fix' to this issue?

Obviously this would need a white-list (and a pair<from,to> whitelist, not just "this domain is OK list) to allow SSO scenarios.

throwawayReply··on Facebook's Zuckerberg will not appear before British MPs
That makes it sound like people are upset about an isolated incident, trying to play this off as an isolated incident is going to blow up very badly as people "discover" just how much of their data is everywhere, whether they gave permission or not this isn't about a single breach.
throwawayReply··on You probably don't want to run Firefox Nightly any more
You should be using Aurora not Nightly for those features.
throwawayReply··on Ask HN: Why is PayPal's password length limit still a thing?
Note that bcrypt has a maximum length well below some of the lengths mentioned in this thread:

https://security.stackexchange.com/questions/39849/does-bcry...

Given this, it seems reasonable to restrict input below a length where the password will become (effectively) truncated by blowfish.

That length is also well above 10 characters however.

throwawayReply··on Google and LG creates VR AMOLED 120 Hz at 5500 x 3000
Not just GPU but display bandwidth too, 5500x3000x120Hz requires a monstrous 59.40 Gbps according to this calculator: https://k.kramerav.com/support/bwcalculator.asp

For that you'd need multiple displayport cables.

throwawayReply··on What Works and Why: Opus Magnum
The Steam integration is nice if you have a couple of other people who also play these games because you get to compare your best with their best.

Personally I managed to keep up with the global optimums early on in the shenzhen campaign but as it went on my solutions were progressively worse than the population. (Or least the portion of it left still completing those puzzles.)

The personal satisfaction is still the main driver of course, I think having the base binary "solved or not" solution is a good way to gate progression as you can choose to optimize as you go through or do a success pass and then revisit for optimisations which suits different play styles. (Personally I like to optimize as I go).

throwawayReply··on Eve Online Chat Is Moving to Ejabberd
I doubt it, EVE typically has ~10-20k concurrents players, that's actually relatively small to other xmpp-based services.
throwawayReply··on Securing your Linux web server
Back in the day we used to call that "Shared hosting" and it was looked down on by the in-crowd.
throwawayReply··on CRPG Book Released
I'm happy to see it covers Legend, a game of which I have many fond memories, it was the first RPG I played and sadly highlighted the difference between my (parents') 386 with PC speaker beeping out the music in off-colour cga and my friend's 486 full music and good looking VGA.

The game itself is was fun, more than tricky (almost impossible for the 9 or 10 we were at the time) and there aren't many games which combine all it's best elements. As the book says, the custom spell rune system was a treat. Creating a spell which shot a missle which exploded and also fired other missles around it was really fun.

throwawayReply··on A Shrinking Pie? The IPv4 Transfer Market in 2017
~10% to ~20% is closer to 100% gain than 10% gain. From 1 in 10 to 2 in 10 people is a doubling of people!

This is why percentage is a bad measure when it can represent two things (percentage or percentage-points).

I like log-odds as a scale to use to represent adoption, going from negative infinity with no adoption through zero (at 50%) to positive infinity at full adoption, but with a typical range of -2 (~1%) to +2 (~99%) when using base e. (Although you can use any base).

By that scale it went from -0.95 to -0.65.

throwawayReply··on [dead]
There are dozens of earthquakes of this strength every year. I understand that this one is in the backyard of many of you but it's ridiculously CA-centric to be upvoting this.
throwawayReply··on Ask HN: How can I learn computer security?
This is bad advice.

There's a reason that cyber is used, because you need something to disambiguate it from all the other kinds of security.

Imagine you're a policy person at the pentagon (or equivalent), if someone talks about security then that doesn't narrow it down to all the other kinds of security going on there.

You could use "info sec" but there are agencies who deal with a lot of information which doesn't necessarily mean this space either. They've been dealing with information security since their inception most of which I suspect is focused around people and not machines.

Cyber security makes it clear to those people what you're talking about.

To someone who works in SV and spends all day with developers the context is other way around, and in that context cyber sounds asinine and if you talk about security someone immediately knows it's security in your space.

That's my guess at why you tend to see 'info-sec' in the private space and 'cyber security' in the public space.

throwawayReply··on How we use big data can reinforce our worst biases, or help fix them
> Correlation is not causation

That's particularly ironic, since a lot of ML can treat it that way.

throwawayReply··on Long Island Iced Tea Soars 500% After Changing Its Name to Long Blockchain
"It's different this time!" - Someone in every bubble.
throwawayReply··on Uber is officially a cab firm, says European court
Banning companies which subvert or break laws or regulations to gain competitive edge over those who follow laws and regulations is not and should not be controversial.
throwawayReply··on Bitcoin exchange Youbit shuts after second hack attack
It's not visible at all, because you can sell coins which never existed because exchange transactions don't happen on the blockchain.

You start off selling maybe 100 bitcoins which you've 'created', so the value of bitcoins on your exchange is 100 higher than in your 'wallet'. No-one can audit that and no one will notice because it's a tiny amount compared to the total volume. The more you do this, the more popular your exchange looks and the more you can repeat it and get away with it.

Eventually you be holding only a tiny fraction of the exchange book in actual bitcoin having cashed out 90% of it generating large amounts of money for yourself in the process.

If it ever looks like there's a run and you can't provide people with their bitcoin you claim "hack".

By the time you exit scam and claim "hack" the missing coins are gone but really they didn't exist so there's nothing to trace.

throwawayReply··on Bitcoin exchange Youbit shuts after second hack attack
Yes, if people accept fractional reserve banking for bitcoin. I'd actually assume that's how most exchanges operate under the hood but many people who buy into bitcoin for ideological reasons won't accept that.

A consequence of making that formal is that the total owned amount of bitcoin would be more than 21m, because the hacker would own bitcoin and the users would own bitcoin on the exchange.

As long as there isn't a bank run, that discrepancy would not be a problem, but it would deflate the currency, also seen as unacceptable to bitcoin purists.

edit: access -> accept.

throwawayReply··on Bitcoin exchange Youbit shuts after second hack attack
If the consequence of my account being compromised is the bank adjusting the numbers in the ledger back then the bank are welcome to enforce such rules.

If a bank said that customers were responsible for the money stored in the bank and that the bank could not undo transactions (from the POV of the genuine client) then we'd be demanding much stronger banking passwords.

throwawayReply··on Don't tell people to turn off Windows Update
Windows is far more painful.

Firstly, it'll keep prompting even if you choose "restart later".

Secondly, unlike most linux environments, it doesn't perform the updates which take effect next restart, it actually performs the update next restart.

That means if you find yourself needing to restart forgetting you've updated, you can find yourself suddenly having to wait a very long time before your computer is usable again.

They often take multiple 'restarts' to apply, typically you might have to wait the first shutdown, then when it boots back up it'll be "applying updates", then it'll restart again having done those updates. Occasionally you'll even get a third restart.

That's compared to 'nix applying the updates but them not having taken effect until a restart which isn't normally noticeably slower than any other restart.

Page 1 of 6Next →