HNHacker News
TopNewBestAskShowJobs

traceroute66

5,864 karma · joined September 24, 2019

submissionscomments
traceroute66··on European Commission Revives Push for Encryption Backdoors in ProtectEU Strategy
This is from 2025. I don't know why someone has seen fit to repost it again in 2026.... I'm guessing they didn't look at the date.

And lots of people here are spouting FUD.

In the ensuing period, the EU took expert advice later in 2025, and as they say in an update a few months later in June 2025[1]:

    The High-Level Group recommended taking a cautious approach to designing solutions for lawful access to systems, whereby industry should not be asked to integrate systems that are likely to weaken encryption in a generalised or systemic way for all users of a service. Lawful access to data must remain targeted and limited to specific communications on a case-by-case basis.

   As a general rule, any solutions should be implemented based on clear standards that are developed with input from all stakeholders, including industry representatives, data protection, privacy and cybersecurity experts, and law enforcement practitioners. However, caution is warranted when dealing with encryption, as underlined by the High-Level Group.
So there is ZERO EVIDENCE that the EU are "pushing for encryption backdoor".

It is instead quite clear from the above that the experts are on "our" side AND the EU are listening to them.

Instead, all these publications are just a reflection of a democratic process of discussing modern threats. The documents clearly mention "terrorism, organised crime, online fraud, drug trafficking, child sexual abuse, online sexual extortion, ransomware".

So it is only fair and reasonable that politicians should be discussing ways to counter these threats. And quite honestly they would not be doing their job if someone did not MENTION "encryption" and ask "the question" to the experts and other stakeholders.

The fact they are DISCUSSING "encryption" does not automatically mean they want to backdoor it.

I know it is alien to people in the US under the present administration, but this is how proper politics works. You openly discuss issues of the day, you seek opinions from stakeholders and experts, rinse and repeat until you make a decision (or not). The present US administration could do with learning a thing or two. ;)

People here need to rein in the FUD.

[1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...

traceroute66··on Woman stranded in Spain after UK's eVisa system mistakes her for twin sister
> If a person off on holiday just had their face burned off

I suggest you actually read my post, because its clear you did not.

If you had read it, you would have seen the phrase "Of course, if you have a temporary mismatch due to being injured on holiday that's different.".

I quite clearly excluded holiday injury.

traceroute66··on Woman stranded in Spain after UK's eVisa system mistakes her for twin sister
I don't follow.

You cite three meaningful changes in biometrics: disfigured, loss of fingerprint and retinal issues.

In all three cases surely the right and proper thing do to is to get your details updated on the system ? It may even be a legal requirement for you to do so in the case of official ID documents.

Of course, if you have a temporary mismatch due to being injured on holiday that's different.

But for a permanent thing I just don't see why you would not just get stuff re-issued or updated.

traceroute66··on I dream of quieter computing
Please do not attempt to move goalposts.

My original comment was quite clearly about businesses, I wrote company/companies three times.

I was unaware German Impressum applied to a natural person who is not running a business. If that is true, then I agree that is unfair. But I was never seeking to comment on that anyway.

traceroute66··on I Dream of Quieter Computing
> I live in the Czech Republic ....build a website without identifying yourself

I am not familiar with Czech Republic law but out of curiosity I asked an LLM:

     § 435 of the Civil Code (Act no. 89/2012 Coll.)
     The law explicitly says every podnikatel (entrepreneur/business) must include on all business documents and on information made publicly available through remote access (i.e. their website):
     - the company's name (firma),
     - its registered seat (sídlo) or place of business,
     - its identification number (IČO) — the Czech equivalent of a company registration number,
     - and if registered in the Commercial Register (obchodní rejstřík), the registration details including the file reference and section/insert (spisová značka, oddíl, vložka).
    This is the summary provisions that was previously found in § 13a of the old Commercial Code (obchodní zákoník) and is now codified in the Civil Code.
    Consumer Protection Act (Act no. 634/1992 Coll.) — adds requirements when you sell to consumers online: business's name and address, ADR (out-of-court dispute resolution) body information, delivery/payment terms, and — for online marketplaces — how offers are ranked, etc.

I then did a quick Google to attempt to validate the LLM and it seems this is indeed true, I found https://www.zakonyprolidi.cz/cs/2012-89 and putting it through Google Translate, §435 is pretty clear that publication of name and address is required.
traceroute66··on I dream of quieter computing
> it's a very naive thing to think that it's just "customers/suppliers" looking at who they're dealing with

Its still no excuse.

Nobody forces anybody to start a business.

If somebody chooses to start a business then they should do grown-up things like having insurance and complying with the law – which includes publishing their business's contact details.

The legal and good manners reasons for publishing a business's contact details far out-weigh any negative ones.

I am sure I am not the only person on this planet who associates alarm bells with small/medium businesses that try to hide their contact details on their website. As a customer it rings alarm bells that they are going to be a pain the neck to deal with if something goes wrong – if a business is trying to bypass such fundamental requirements, then it makes you think about how they feel about e.g. consumer rights law in relation to handling returns.

traceroute66··on I Dream of Quieter Computing
> Some countries like Germany also require legal contact information (an Impressum). Technically it even applies to sites outside Germany that Germans can visit

I don't understand people bitching about Impressum like its some sort of German-only thing.

I am sure if you looked at the legislation of many countries, you would find similar requirements for companies to identify themselves. Off the top of my head you have Austria, France, Italy, Spain, Switzerland, UK ... and probably the rest of the EU/EEA states as well. IIRC it is also a requirement in a number of Asian countries.

In reality requiring an Impressum (or equivalent in other countries) is no different to having to put identification information on a company's old-school letterhead. Its just good manners so that your customers/suppliers can know who they are dealing with.

Personally I dislike the US attitude of trying your damnest to hide any trace of your company's identifying or contact information from your website. ;)

traceroute66··on Tell HN: Cloudflare silently injects its analytics when you switch nameservers
Yeah, I was trying to get hold of the list from Github myself before posting the edit. It is unfortunate strict isn't truly strict, but at least now I know. Thanks for that.

Pending Github fixing itself, could you confirm if `browser.events.data.microsoft.com` is on your local copy ?

traceroute66··on Tell HN: Cloudflare silently injects its analytics when you switch nameservers
> I wonder if this is necessary for Firefox users to get past Cloudflare's various bot/scraping protections?

I also daily-drive Brave and Mullvad browsers, both of which correctly block `static.cloudflareinsights.com` and I never have issues with Cloudflare sites.

traceroute66··on Tell HN: Cloudflare silently injects its analytics when you switch nameservers
I just double checked `about:preferences#privacy` is "Enhanced Tracking Protection: Strict" and clicking "Advanced Settings" confirms the radio button is indeed under "Strict".

Firefox 153.0.4

traceroute66··on Tell HN: Cloudflare silently injects its analytics when you switch nameservers
I have "Enhanced Tracking Protection" strict mode enabled in Firefox and surprise surprise it is allowing `static.cloudflareinsights.com` not blocking it.

So much for "Firefox shields you as you browse, blocking trackers automatically so you’re in control of your digital trail" Mozilla.....

Edit to add:

I have been doing a little experimenting, it looks like there might be some sort of hardcoded whitelist somewhere in Firefox ?

When I first wanted to check, I visited `cloudflare.com` as it seemed the obvious place to find `static.cloudflareinsights.com` and Firefox shield blocks nothing there (hence I made this post)

However, then I tried to find a different site, and after a bit of random searching/clicking around I found `www.tenforums.com` and `static.cloudflareinsights.com` is blocked on there.

Its not a first-party domain thing, since cloudflare.com != cloudflareinsights.com.

Surely `static.cloudflareinsights.com` should be blocked everywhere in strict mode, no exceptions ?

Interestingly, when testing other sites, I have also been discovering other things Firefox shield is failing to block, e.g. `browser.events.data.microsoft.com` (tested on a non microsoft.com site)

traceroute66··on On AI regulation and messaging
> It's like saying "we'll cure infectious diseases"

Don't worry, I'm sure that's his next blog post. Right after Claude has finished solving famine and poverty. ;)

traceroute66··on On AI regulation and messaging
> The thing that will work is actually curing cancer.

This is honestly hilarious. Dario must think people are stupid.

First, cancer research charities are some of the most well funded on this planet. They all obtain donations on the basis of "together, we will cure cancer" messaging. They all fund the best science they can.

Second, the human body is a complicated thing. You can feed your fancy LLM as many textbooks and academic papers as you like, but the reality on the hospital ward will always be different. Why do you think student doctors have to spend so many years "doing the rounds" Dario ? They are all academically smart, they are all capable of memorizing text books ... but there is no substitute for seeing and doing the reality.

I barely trust Claude to write code, let alone find a cure to cancer.

traceroute66··on WhatCable: Know what your USB-C cable can do
> You are hell-bent on pushing this viewpoint

Its not a viewpoint "man", it is a FACT.

There are people here actively using the term "it verifies" in relation to their $40 toy they bought on Amazon, they absolutely need to be corrected firmly.

A $40 toy DOES NOT "verify" anything it (a) Does a DC continuity test (b) Reads the chips on the cable. NOTHING ELSE.

People here trying to pretend it does more than a+b need a reality check.

traceroute66··on Google is making private AI practical with homomorphic encryption
> Wouldn’t a zero data retention agreement be pretty close to this?

1. A ZDR clause is "trust me bro". You have zero way of verifying their pinky-promise.

2. A ZDR clause is still subject to the old-classic "government, court or administrative order" catch-all clause. :)

3. "Even with ZDR enabled, Anthropic may retain data where required by law or to address Usage Policy violations. If a session is flagged for a policy violation, Anthropic may retain the associated inputs and outputs for up to 2 years, consistent with Anthropic’s standard ZDR policy." (I quoted Anthropic, I'm sure all the others have similar).

traceroute66··on WhatCable: Know what your USB-C cable can do
> If I want to tell a cable that can do only USB 2 from one that can do 3 from one that is actually thunderbolt

And if the marker chips in your "some unknown usb cable" are fake / counterfeit ? Then what ?

Your $40 toy won't help with that scenario and you will be back at square one. That's what.

traceroute66··on WhatCable: Know what your USB-C cable can do
> Buying my cables from decent manufacturers does not tell me what specific version of USB a cable purports to support

A $40 toy won't tell you if the marker chips it has just read are fake / counterfeit.

You need the expensive kit for that.

traceroute66··on WhatCable: Know what your USB-C cable can do
> Then I am kidding myself, because I'm convinced it does a lot more.

Good luck spotting those counterfeit / phony markers with your $40 toy.

Just one of many examples of basic things your $40 toy won't tell you.

traceroute66··on Count Binface receives over a quarter of votes in Clacton by-election
> What are campaign finance laws like in the UK? Can he crowdsource this to offset his cost?

Anybody can donate to a political party in the UK so that's how you would do it.

There's no citizenship/residency requirement AFAIK.

Here is his official entry on the register: https://search.electoralcommission.org.uk/English/Registrati...

traceroute66··on Google is making private AI practical with homomorphic encryption
Quoted from the blog post:

> user-data can be protected from data breaches, but then the service provider cannot provide features that depend on the data, such as spam or virus detection

I think they forgot "or advertising" at the end.

I don't trust Google. I would much prefer to use on-prem or - at most - one of the secure-enclave providers like Tinfoil[1] or Private Mode[2]

[1] https://tinfoil.sh/ [2] https://www.privatemode.ai/

traceroute66··on WhatCable: Know what your USB-C cable can do
> You need a six figure wallet to want to spend $20k on a tester :)

Heh. I'll give you a +1 for that one.

Reminded me of the old joke...

What's the quickest way to become a millionaire ? Be a billionaire and buy an airline.

traceroute66··on WhatCable: Know what your USB-C cable can do
> What would be really interesting is if I could connect a cable to two ports on a Mac and have the Mac test the cable.

Not reproducible and introduces all sorts of other random variables to your test (buffering etc.).

traceroute66··on WhatCable: Know what your USB-C cable can do
> verify what's actually in the cable (not blindly trusting the marker) the latter is sufficient

But as was repeated 101 times on that thread ....

All that those cheap $40 boxes are doing IS reading the marker.

Sadly you are kidding yourself if you think a $40 box off Amazon is doing any sort of "verification". Let alone in any sort of calibrated, reproducible sense free of random unknown variables.

traceroute66··on WhatCable: Know what your USB-C cable can do
> Are you suggesting there is no middle ground

Sadly yes.

Like many people on that thread concluded:

The best "middle ground" thing you can do is pay a premium to buy your cables from reputable manufacturers.

traceroute66··on WhatCable: Know what your USB-C cable can do
> For practical use you only care if it carries a certain amount of packets per second without excessive retries

The $40 black-boxes do two things:

    1. Basic electrical continuity test
    2. Read the marker chips (if present)

There is zero chance that a $40 black-box, even if it did a naïve packet pushing test, would deliver you reproducible results and introduces all sorts of other random variables.

"Excessive retries" sounds like exactly the sort of intermittent, hard-to-diagnose cable issues that you will not find unless you test the USB cable on a 6-figure rig. :)

traceroute66··on WhatCable: Know what your USB-C cable can do
> Decent quality cable testers can be had for like $20,000.

See the discusison linked to.

Trust me, my interest was piqued by that thread and I went down the rabbit warren with Mr Google and spent far too much time on the subject. I looked at the various manufacturers and the setups required.

TL;DR: To start with, you need fancy harness assemblies. Then you need to plug those harnesses into very, very expensive equipment.

You're not going to find anything for $20k. High-throughput USB-cable testing simply can't be done the same way copper CAT6 certification can with a 20k Fluke.

For those who want to play with Mr Google, some manufacturers from my notes: Wilder Technologies, Allion, Keysight, Tektronix, Teledyne LeCroy

Here's one blog post I uncovered during my researches: https://www.keysight.com/blogs/en/tech/bench/2023/02/17/powe...

traceroute66··on WhatCable: Know what your USB-C cable can do
> I'm using the hardware tester from $INSERT_NAME_HERE

Oh god not again... before everyone starts naming their favourite brand, here's a 265 comment HN thread[1] (from last week !) on why these cheap USB-cable "testers" are not worth anything.

TL;DR You need a six-figure wallet to seriously call anything a "hardware tester" for USB cables. User ChrisMarshallNY has a one-liner summary buried in that thread:

    Think about it. You need to generate a precise, calibrated, 40GHz signal, transmit it, then precisely measure the returned signal for phase, amplitude, and waveform integrity -at that speed. Oscilloscopes and logic analyzers that run at that speed, are damn expensive.
If you only paid $40 for a black-box on your favourite online marketplace, then what you've got is definitively NOT a USB-cable tester.

[1] https://news.ycombinator.com/item?id=49152255

traceroute66··on Gloomberb
> They're paying for the data source

Yup.

If you want fixed-income data, Bloomberg is the only shop on the street data-wise.

If you want other financial data, Bloomberg's fixed entry-point pricing tends to make more sense in terms of bang for buck than its competitors modular price sheets.

People saying Bloomberg is just about the chat are simply embarrassing themselves.

Look at the price sheets of Eikon, Factset, CapIQ etc. There is no such thing as a cheap "Bloomberg killer".

Quality data is expensive. So are the leased-lines it arrives at Bloomberg on. So is the data wrangling architecture.

traceroute66··on Italian Bank Stores 400K Wheels of Cheese as Collateral for Farmer Loans
The blog post is written by someone who has never heard of a Lombard loans.

TL;DR: No surprise to anybody .... loans involve two parties, and shockingly (/s) its up to the bank what they take as collateral !

Lombard loans have been a thing ever since banks have existed and – ironically in the case of this blog post – the term originates from the Lombards who conquered the northern region of Italy now known as Lombardy.

In the case of this blog its cheese. But it is incredibly common - for example - for the loan collateral to be an investment portfolio.

As long as there is an accepted way to value it, correctly manage it and it has a good chance of holding or increasing its value, banks can consider it as collateral. Doesn't mean they will (that is a decision for the risk committee), but they can.

traceroute66··on Automatic Key Verification
If they wanted to build trust, they could have at least made an effort to find minimum of one non-US company !

Also the ties to phone numbers is not cool in 2026. :(

← PreviousPage 3 of 34Next →