HNHacker News
TopNewBestAskShowJobs

tristador

56 karma · joined January 22, 2020

submissionscomments
tristador··on New Cryptographic Tools on Keybase
> When she someday establishes keys, and cryptographically proves her Twitter account, the Keybase servers will ping my apps and ask for me to make available the decryption key to her. My app will check the signed statement from myself, check her tweet, make sure the proof is valid, and then send the decryption keys to her, encrypted for her device keys.

> Keybase is not a trusted man-in-the-middle here, and no one else has keys. The only weak link here is Twitter: my assertion is like this, in English: “once someone who owns the @billieeilish Twitter account publicly proves a Keybase connection, I'll unlock it.” If Twitter gives that account to someone else or takes control of it, I'll be trusting Twitter's answer. @billieeilish is not yet a human. She's a Twitter account.

That seems decent at first pass. Keybase could maliciously not notify about her joining keybase, but everything after that seems like it follows a cryptographic path.

Is your concern that their code is improperly implemented (which seems the concern cited for triplesec)? I'm not seeing the abuse risk. Any pointers?

tristador··on Monoliths Are the Future
I'm not following. How do things work better for the non-microservice approach?

Re. teams: For any project above a certain size, you'll have teams. If that's a network boundary, a process boundary, or a library boundary doesn't change that you'll have multiple teams for a large project.

I'm not sure I get the resiliency point. I worked on a project where the dependent data service was offline painfully frequently. We used async tasks and caching to keep things running and were able to let the users do many tasks. For us our tool was still fairly useful when dependencies went down. If we used monolith then everything would be down, right? That doesn't sound better.

tristador··on Boeing reports a $410M charge in case NASA decides Starliner needs another test
> 2000 extra hours during a 12 month period

11.5 hour days, 7 days a week for a year?

> I almost burned out

No kidding. Seems like a recipe for much worse than burn out.

tristador··on Python community request to postpone breaking changes in Python 3.9 to 3.10
> So in 3.8, they kept code that had deprecation warnings so that they could be compatible with 2.7. They'd like to now drop that code and be 3.9-only compatible, but they don't have enough time to do that because they couldn't start that work as long as they were supporting 2.7.

> So the dilemma is essentially how hard we push users to abandon 2.7 -- how much tax we incur on them for keeping its support.

Its fascinating to see how the details of Python 2.7 EOL are still being figured out, and nuisance of the decision are still being debated.

tristador··on Facebook to Pay $550M to Settle Facial Recognition Suit
I think a favorable reading is that he described the category. Facebook tracked that fine under "general and administrative".
tristador··on Off-Facebook activity
I thought Google Analytics had a decent privacy policy that would prevent Google from doing anything with GA data. But I remember some fuzzy wording like "your data" which could simply mean that Google considers GA data to be their data.

Has anyone done a good deep dive on what Google actually does with GA data?

tristador··on Ask HN: Why is there no built-in authenticator app in iOS or Android?
Looking at play store quickly:

Facebook, which I've seen preinstalled on phones, has 5B+ downloads.

Google authenticator has 10M+ downloads. It's not that popular relative.

tristador··on Ask HN: Why is there no built-in authenticator app in iOS or Android?
For Android, preinstalled apps are set by the phone manufacturer. I suppose each manufacturer could pick their favorite 2fa app and install it. There is some pressure not to install apps that the user doesn't need as it's bloatware. I'm not sure what percentage of users currently use an authenticator app.
tristador··on Patents Do Not a Product Make
The economics on that look terribly bad. Keyboard is too high or screen is too low. Keyboard is too close to the screen.

I suppose you'd adjust those but for a single piece of glass product, your sort of stuck with placement.

Honestly, what's wrong with a wireless keyboard? Or a wired one?

tristador··on An ad free, mentally healthier alternative to social media
I like the idea of a paid social network, that removes tracking and ads, focusing on quality engagement versus quantity.

There are a few of these already, what makes this one unique?

tristador··on Why Your Static Website Needs HTTPS (2018)
CF is undoubtedly good for DDoS protection, but that doesn't negate the fact that it does other things poorly.

FWIW I've found more websites that prompt for Cloudflare captcha than I've seen websites offline due to DDoS. I've seen lots of websites offline because they get too popular though. Many websites that I've known were currently under DDoS attack stayed online while I used them (like GitHub using Akamai).

At the risk of Troy writing a blog post proving me wrong... does the average static website need DDoS protection? I'd guess they don't.

tristador··on Wealth is what you don't spend
> However you can’t just choose to not pay for things.

Sure you can. The article even has examples.

> In the 1950s camping was an acceptable vacation. Hand-me-downs were acceptable clothes. A 983 square foot house was an acceptable size. Kids sharing a room was an acceptable arrangement. A tire swing was acceptable entertainment. Few of those things are acceptable baselines for most households today. The average new home now has more bathrooms than occupants.

> most poor people I know

I think this is the disconnect. The article is about the 50% of Americans that have nothing saved for retirement. Not Americans who are poor. It's specifically about how you can make lots of money but have nothing saved.

If we talk about poor people, then I agree with most of your comment. It's just not what the article is talking about.

tristador··on Wealth is what you don't spend
> Diet without exercise however can work just fine.

I think that's the point. Earning more is hard, you need to get a raise or find a new job. That's "exercise". It's the obvious fix, but it doesn't really work.

Instead the workout makes you hungry. The raise in pay tempts you into buying a new car. So you stay over weight, or fail to save money.

Cutting your spending or going on a diet can work on their own.

I think the math works better for people earning lots of money and spending it all. Being poor is hard and unexpectedly expensive.

tristador··on Linode launches free DDoS protection
Instead the price would just go down more slowly. So the price drop that you'd otherwise expect is paying for the new features.
tristador··on Show HN: Userbase – Add user accounts and persistence to your static site
FWIW the current pricing page shows only a starter plan that caps you to 1GB, with no info about what happens after 1GB. Predictable pricing is a good feature, but you don't have that yet.

Really cool otherwise, I may use this for something. Great work!

tristador··on Why Your Static Website Needs HTTPS (2018)
Here are those IP addresses. Just know that the list can change over time, so you'll want to update your IAM policy.

https://www.cloudflare.com/ips/

tristador··on Why Your Static Website Needs HTTPS (2018)
How do you secure the link between Cloudflare and your HTTP only site?
tristador··on Why Your Static Website Needs HTTPS (2018)
I think you'll find a number of people who have seen issues (myself included). Things like adding Cloudflare on top of an API, breaking clients when CF decides their IP needs verification. Besides, other than DDoS, how do you abuse a static site?
tristador··on Why Your Static Website Needs HTTPS (2018)
The recommendation of Cloudflare here seems poor. Using CF to make an HTTP only site support HTTPS will only prevent MITM between CF and the end user. MITM between my server and CF is not improved as it's still HTTP. Yes, you can add a self signed cert and tell CF not to check the cert validity, but that doesn't prevent MITM.

Worse, Cloudflare can inject JavaScript into your site. The default settings will show Captchas to users if CF thinks they are not trustworthy. So you end up with MITM anyway if you aren't careful. For a static site, does a captcha really make sense? Cloudflare makes the internet worse with insane defaults like this.

https://community.cloudflare.com/t/getting-cloudflare-captch... https://www.techrez.com/remove-cloudflare-challange-page/

tristador··on Why Your Static Website Needs HTTPS (2018)
> In one of many robust internet debates (as is prone to happen on Twitter)

Maybe I just don't get Twitter. Every time I look at a thread it starts with some coherent conversation, but then devolves into a bunch of tangents that don't coherently follow each other.

HN and similar seem much better suited.

tristador··on Why Your Static Website Needs HTTPS (2018)
Note: 2018.

Troy talks about a tipping point, which was Jan 2017.

tristador··on Google backtracks on search results design
So my bid just drives up the prices advertisers need to bid to show me ads? Sounds like a win for a company that sells ads.

Asking for your "long term value" is interesting, although for users who run ad blockers and therefore never click an ad, isn't their value super low anyway? Imagine Google asking for $50/yr to not show ads, installing an ad blocker, then a year later seeing Google ask $5/yr as your value plummets.

tristador··on The Throw Keyword Was a Mistake
> Hit Ctrl-S every few seconds or you deserve to lose it.

Huh, I remember years ago I had this habit. At some point I stopped, I don't think I do that any more. Maybe with the rise of web apps? My switch to Linux as daily driver? With those I've been logged out when writing a long message (especially if I take a break while writing), so for some apps I know to copy the text out to notepad or something. Although I'm not sure the last time that's happened either.

tristador··on Household Manager/Cook/Nanny Needed, Menlo Park
Same error. Using Firefox for Android.
tristador··on 12 year old issue tracker entry returns from the dead
Google issue tracker requires login just to view issues? Strange choice.
tristador··on Household Manager/Cook/Nanny Needed, Menlo Park
> Oops, your browser, device, and/or location is not yet supported.
tristador··on Carbn.app – Passively manage your carbon footprint
It's a browser extension that monitors my purchases (like plane tickets) to compute a carbon footprint, then sells me the ability to purchase offsets, or recommends behavior changes?

Really interesting idea, I could see this doing well.

I'd personally need a ton of detail about how it collects data. If anything is sent back to a server then I'm out, the industry lost my trust by misleading about data sharing/usage. Also need a ton of data about the offset I'm buying, and what sort of cut the app takes from that purchase.

tristador··on “This is why I use ad blockers and a pi-hole server”
Is there a good example of a large company that blatantly ignores DNT? I'd guess its hard to know as a lot of the tracking could be server side only.
tristador··on “This is why I use ad blockers and a pi-hole server”
> The news will be expensive, so only the wealthy will have access.

I think this is correct, although HN readers may have some bias to disagree. I think the HN crowd is generally fairly well off financially (but not rich) and cares more about privacy than other groups.

tristador··on I've given up on using a CMS for my personal website
Yes, I've been moving in this direction as well for personal blogging. Markdown is nicer to write than HTML, especially for lists, but HTML feels workable. Just copy a template to start a new post so you only need to write the content.

I don't think the "edit on GitHub" experience is that great, you can't preview changes in any efficient way. That works ok if you are just writing text, instead of tweaking format.

Page 1 of 2Next →