HNHacker News
TopNewBestAskShowJobs

titaniczero

149 karma · joined September 27, 2018

submissionscomments
titaniczero··on Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
And don’t forget the battery. A mic recording 24/7 would drain the battery much faster and would not go unnoticed unless specialized hardware is used like the one for “hey siri” and “ok google”.
titaniczero··on Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
Yeah, that could be tested by reversing engineering and analyzing your network traffic to see if there are requests leaking keywords
titaniczero··on Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
Yeah, I recommended Pi-hole because it is easier to setup than a proxy, it is very easy to see if it works - just try to send messages. The last time I tried it you could block whatsapp traffic by just blocking the domain at DNS level.

Of course, if it does not work, use a proxy.

titaniczero··on Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
Another idea: test a null hypothesis. Block with your pi-hole or a proxy all the facebook traffic so the messages won't work. Then reproduce with the same exact behavior with your wife (it would be better if you both could get a clean identity and then repeat the exact same conversations and topics, but getting a clean identity is not that easy) so all the external factors are the same except the facebook connection itself. It could be even more granular by trying to block just enough so it won't send the messages, allowing facebook ad trackers, etc.

If you try this several times, the messages are not working and the corresponding ads show up you can be sure that it is not because they are reading your messages. Which does not rule out the possibility that they might read them, but at least you can be 100% sure that your ads are not showing up because of your messages in this case.

If they do show up you could then try discarding other factors like client-side keyword analysis e.g.: talking about very generic things which are not useful to ad trackers like "how you going?", etc (ie. awkward elevator conversations), but it is harder to test a null hypothesis for client-side keyword analysis.

titaniczero··on Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
By accessing the device. It is not only E2E encrypted, WhatsApp servers are only a middleman, as soon as they arrive (double-check) they will be deleted from the server. Undelivered messages are retained up to 30 days, according to their privacy policy:

<<Your Messages.

We do not retain your messages in the ordinary course of providing our Services to you. Instead, your messages are stored on your device and not typically stored on our servers. Once your messages are delivered, they are deleted from our servers. The following scenarios describe circumstances where we may store your messages in the course of delivering them:

Undelivered Messages. If a message cannot be delivered immediately (for example, if the recipient is offline), we keep it in encrypted form on our servers for up to 30 days as we try to deliver it. If a message is still undelivered after 30 days, we delete it.

Media Forwarding. When a user forwards media within a message, we store that media temporarily in encrypted form on our servers to aid in more efficient delivery of additional forwards.

We offer end-to-end encryption for our Services. End-to-end encryption means that your messages are encrypted to protect against us and third parties from reading them. Learn more about end-to-end encryption and how businesses communicate with you on WhatsApp.>>

https://www.whatsapp.com/legal/privacy-policy/?lang=en

Assuming they are compliant with their privacy policy, they don’t even have the messages.

titaniczero··on Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
They are E2E encrypted now in recent versions.
titaniczero··on Ask HN: Ads triggered by WhatsApp “end to end encrypted” messages?
An interesting experiment would be the same thing you are doing but isolated in a note taking app to discard the google keyboard you’re using. Also, it would be interesting if you can use e.g.: proxyman (available directly on iOS), or some proxy on your PC to intercept your network traffic and then try to reproduce while blocking/allowing some domains. Especially, blocking all google domains, then facebook domains, etc. If you have a Pi-hole set-up doing that at dns level may be easier.

I’ve never been able to reproduce these experiments. But keep in mind that I’m european and my WhatsApp app is slightly different - it is a version from WhatsApp Ireland (instead of WhatsApp Inc) which shares less data with third parties, the privacy policy is also slightly different for the european union.

Edit. Another idea: try to reproduce while disabling predictive text on your keyboard.

titaniczero··on “UBO Minus (MV3)” – An Experimental uBlock Origin Build for Manifest V3
> If any appreciable percentage of the population started using a browser that allowed adblockers, Google (and Facebook, and Twitter, and Reddit, and...) would do everything within their power to block that browser from all the web properties they control (this is not an exaggeration: everything within their power, because the alternative is the death of their entire business model and the end of the company)

Even easier, they would just sabotage their own web versions (like reddit with mobile.reddit.com) to force people to use the app versions where tracking/ads is harder to block.

The web is the best platform for us, the users, and the way to go - good sandbox, transparent, customizable. We should fight tooth and nail to preserve it.

titaniczero··on Difftastic, the fantastic diff
Embrace, extend, and extinguish [1]. This is the extend phase.

Microsoft has the resources and ability to make better language servers which could be closed source now, so people end up switching to those tools, owned by Microsoft, with better language servers, killing other editors if they are not able to catch up.

E.g.: Why would a C# programmer use Neovim if the language server is worse than the one that VSCode has? (Which is now proprietary and closed-source). The difference right now is insignificant, but the future tools and features that they are adding to the new proprietary C# language server will not be available for other editors.

[1] https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguis...

titaniczero··on Difftastic, the fantastic diff
My neovim is drooling over this!

> This IMO really highlights the power of having an ecosystem built around tools like tree-sitter because they allow for powerful dev UX tools to be more democratized

LSP is also an example of this and it is also an example of how dangerous it can be when these tools are backed by big companies: https://news.ycombinator.com/item?id=31760684

titaniczero··on Leon: Open-source, self-hosted personal assistant
English is his second language, I'd cut him some slack and create a PR to fix it and help him instead of criticizing.
titaniczero··on AdGuard publishes the first ad blocker built on Manifest V3
Does anyone know what is Edge's take on MV3? Will they just leave it untouched and obey or do they have alternative paths planned for adblockling like Brave (In addition to the native blocker, Brendan Eich also said that they will "put back the lost functionality for uBO, uMatrix and other legit extensions" [1]).

I have a feeling that Edge will become mainstream in the near future because it is the default browser on Windows (getting IE monopolistic vibes again!) and people is using and even loving it. I think both Edge and Chrome will decide the future for the web. Firefox and Brave, unfortunately, are not mainstream enough to make their decisions count.

[1] https://twitter.com/brendaneich/status/1134141335881912320

titaniczero··on Wizz Air now charging some travellers a strange extra fee (2020)
Yeah, that’s them being greedy lol
titaniczero··on Wizz Air now charging some travellers a strange extra fee (2020)
Sounds credible to me. Some adblockers and lists block bot detection scripts on purpose, in some cases it could lead the system to flag you as a bot.

What they should do in these cases is to fallback to a captcha or something like that.

titaniczero··on The coming tsunami of fakery
That's so sad and plausible. I already hate social networks because everything is so fake, I struggle to find genuine posts and interactions, I can't imagine what would happen when everything becomes [even] more and more fake. Will people become unsociable IRL?
titaniczero··on Botspam apocalypse
It looks great, as a suggestion: Instead of an easy mode and advanced one I would use a single mode with a calculator, that way it is more transparent to the user and it would make the process of learning the advance mode and concepts easier.

Also, here: https://mcaptcha.org/, under the "Defend like Castles" section, I think you meant "expensive", not "experience".

Keep up the good work!

titaniczero··on GitHub Copilot is generally available
Jetbrains costs $150/y. IMO, an autocomplete is not worth $100/y at all, let alone $200/y.
titaniczero··on Async Rust doesn't have to be hard
This is similar to Go’s sync.Pool to reuse buffers and prevent allocations when you want to optimize things, right?
titaniczero··on VSCodium – Free/Libre Open Source Software Binaries of VS Code
> vi/vim is nice but I find the convenience of VSCode - auto complete, show inf doc etc - very useful

You can have all of that on vim. On neovim, you can even setup LSP with the same LSP servers that VSCode uses [1]. The learning curve is steeper but if you like vim/neovim keyboard-centric features, it is worth it.

The only thing I miss from VSCode is maybe the debugger, not because you can't have one, but because it is a bit tedious to set it up and more error prone. So sometimes I use VSCode as a debugger, but I'm pretty happy with my config on neovim (imports, auto complete, docs info (or "hovering"), definitions, go to definition, rename a symbol, etc., you can have all of that with LSP).

[1] https://github.com/neovim/nvim-lspconfig

titaniczero··on Classified specs leaked on War Thunder forum for third time
It’s literally the military version of https://xkcd.com/386/. People can’t help it lol
titaniczero··on Show HN: Spanish Basic
I want to make crystal clear that my comments are 100% in a pragmatic way, as a project it is awesome and very enriching. Kudos to the OP.
titaniczero··on Show HN: Spanish Basic
Until someone comes along and translates 'heap_alloc' as 'asignacion_al_monton' or 'DatabaseDriver' as 'PilotoBaseDeDatos' (I wish I had made up the latter).
titaniczero··on Show HN: Spanish Basic
Yeah, that's a good one.

The terminology is well established and standardized in english, so if someone says things like bus, heap/stack allocation, driver, or even simple random things like timeout, tracker, to trim a string, to wrap an error, etc. everyone knows what you mean but when people write their docs in spanish and make up their own terms (let alone the mental effort required to translate every term), you can quite easily end up with a huge mess.

Por favor, programad en inglés y usando los términos conocidos y si tenéis un equipo a cargo forzad a hacerlo así, os lo agradecerán en el futuro!

titaniczero··on Show HN: Spanish Basic
Excel formulas are a perfect example of how horrible localized versions can be for coding.

I hate them, all the good guides and docs are in english but if the application is in spanish then all the function names are different. I have everything in english in my computer because of this and to avoid context switching, but when my gf asks for help I have to google every corresponding function name. Terrible design choice IMO.

titaniczero··on Show HN: Spanish Basic
Thanks, interesting project but I disagree with the proposal. Actually the project is more about using your own style for coding and then transpiling that, than the language itself. And both are terrible ideas IMHO.

In fact, what's popular now is to do just the opposite: linters and formatters which force the same coding style for everyone, which is way easier to implement for all the different languages and way more reliable.

And as far as the language itself is concerned, I'd say that it is a bad idea as well because of context switching, translating what you type into other languages (which is not a trivial task for both machines and humans) and because, as I said above, you still need a good english proficiency level if you want to be a good developer, so it makes sense to prepare your students for the real world by teaching programming in english and getting used to it.

titaniczero··on Show HN: Spanish Basic
As a spaniard, please don't.

I'm fine with programming in english, this only complicate things for everyone involved. Imagine if every popular language out there had their own adaptations or even their own programming languages.

Also, you must know english for coding. There is no way you can be a good developer without a good english knowledge - docs, specs, protocols, guides, tools, books, remote jobs with international teams... everything is in english.

titaniczero··on Mental illness, mass shootings, and the politics of American firearms (2015)
What about the european countries without "equalizers"?

https://www.nationmaster.com/country-info/compare/Spain/Unit... https://www.nationmaster.com/country-info/compare/Germany/Un... https://www.nationmaster.com/country-info/compare/Denmark/Un... https://www.nationmaster.com/country-info/compare/Italy/Unit... https://www.nationmaster.com/country-info/compare/France/Uni... https://www.nationmaster.com/country-info/compare/Austria/Un...

> You see an increase in crimes against people when the equalizing force of guns is removed: assaults, muggings, home invasions, rapes, etc. Guns can (and do) allow smaller men, women, and the elderly to defend themselves with lethal force — against stronger aggressors.

Sorry but to my european ears, this "equalizing force" theory sounds plain stupid. I get that it is not that easy to ban them because we have different traditions and background, and I get that it is really hard to ban something when people is used to it and that it could lead to unexpected consequences (black market, etc).

But defending guns as an "equalizing force" is just stupid, given the stats.

titaniczero··on Mental illness, mass shootings, and the politics of American firearms (2015)
What about banning new people (e.g.: born in 2016 and onwards) from using them like some countries are banning smoking?
titaniczero··on Statement on 4 Years of GDPR
GDPR is about personal data, not just cookies.

I agree they should have thought better of that cookie law, which is a different one. But GDPR really was and is on point.

titaniczero··on Rustdesk – Remote desktop software, an open source TeamViewer alternative
“explicit lifetime bound required“, you poor soul
← PreviousPage 2 of 3Next →