HNHacker News
TopNewBestAskShowJobs

ust

413 karma · joined February 15, 2013

submissionscomments
ust··on Trump says he will ban TikTok through executive action
Explanation of the current legal structure that can be used to ban/force divestment of TikTok:

https://www.lawfareblog.com/tiktok-and-law-primer-case-you-n...

In short, a president has substantial powers (granted by Congress via IEEPA and CFIUS) to institute a ban or force a divestment of any company "engaged in interstate commerce in the United States", if "national emergency" or "national security" is involved. So, legally, it seems that president can ban TikTok, under certain conditions (that may not be so difficult to achieve). The link above only explains the current legal framework, not whether banning the TikTok is in itself a good or a bad thing. IANAL, so I can't judge the competence of the presented arguments, but it is written by a respected law professor.

ust··on 9th Circuit holds that scraping a public website does not violate the CFAA [pdf]
The post is now here:

https://reason.com/2019/09/09/scraping-a-public-website-does...

ust··on Ask HN: How are you implementing GDPR-compliant soft deletes?
Yeah, I agree with everything you said.

It would be interesting to know whether the big companies have addressed (at least partially) their GDPR compliance. Maybe they do just "play Russian roulette" like you said, and hope for the best.. Of course, implementation guidelines are not yet fully defined (like WP29 opinions, some of them will change, even then, those opinions are not legally binding).

ust··on Ask HN: How are you implementing GDPR-compliant soft deletes?
Not every company needs a DPO though, e.g. check here:

https://www.eugdpr.org/key-changes.html

Maybe his company doesn't need one. Of course, whether he has a DPO or not, still the question remains of how to "properly" delete the personal data.

ust··on My new favorite book of all time
I'm sorry, but your comment about Yugoslavia is extremely simplistic, if not outright wrong. While ethnic tensions certainly played a large role, the causes for the war were numerous, and also include outside influences (end of Cold War, geopolitical situation, etc.). BTW, Tito was dead for 11 years before the war started, and while he certainly was a dictator, albeit somewhat more lenient than other communist dictators, describing him as a "violent warlord" is a mischaracterization.
ust··on GDPR consent design: how granular must adtech opt-ins be?
Hi, I'm involved with GDPR for my work, although in academic context, i.e. the primary motive in processing of personal data is in security, provisioning services, accounting purposes, etc. Also, I'm not a lawyer, and this is just my personal opinion.

So, while I do work in academic environment, I do have contact with people from industry, and they are taking this seriously. (Of topic, this actually created a new business opportunity, for compliance with the GDPR). However, GDPR is not that different from the Directive, if you were compliant with the Directive, chances are, you're probably (mostly) compliant with the GDPR. Yes, the conditions for consent are strengthened, and since now we have a Regulation, it is valid in all countries. There are other differences, and it is more stringent now, but it is not drastically different from the Directive. BTW, this link[1] have a nice overview (I'm completely unaffiliated with that firm, I just like how they structured it...):

[1] https://www.whitecase.com/publications/article/gdpr-handbook...

One thing that people lost sight of, at least in my opinion, that GDPR is not just about punishment, or stopping the processing of personal data, it is also about transparency. People should not be coy/evasive/unclear about what kind of data one is collecting and for which purpose. This is one of the most important things (again, in my opinion). Processing of personal data has a valid and important purpose, and the GDPR is not there to stop it.

And for the question will the GDPR be enforced, I think it will. For the moment, though, all data protection authorities (DPAs) are a bit overloaded, and I suspect that will be the case in the near future. But obviously, EU and EC are taking GDPR quite seriously.

Hope this answers your question.

(Edited for grammar...)

ust··on How a Radio Shack Robbery Could Spur a New Era in Digital Privacy
There was an interesting discussion about 4A implications between Orin Kerr (who thinks, that according to 3rd party doctrine, there was no need for a warrant, and therefore no 4A protections of cell-cite data) and Alex Abdo (of ACLU, who argues that, since the collection was too excessive, it does trigger 4A protections).

Link: https://www.youtube.com/watch?v=hW32k7x7zE0

ust··on With a $1k Price, Apple’s iPhone Crosses a Threshold
I have Nexus 4, too, and changed stock OS to LineageOS (previosly I've used cyanogenmod) and it works great, and now I have Android 7.1.2. and I receive weekly updates...

I realize that "flashing" the ROM is not what normal user would do, but it has become very easy to do, and it does extend the (usable) life of the phone..

ust··on Man Who Refused to Decrypt Hard Drives Still in Prison After Two Years
Last time this story was here, I posted this link [1], from law prof. Orin Kerr. I find his reasoning about "foregone conclusion" and Fifth Amendment pretty interesting.

[1] https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...

ust··on It is easy to expose users' secret web habits, say researchers
I find this reasoning by prof. Orin Kerr pretty interesting, in respect to whether always collecting the full URLs of users (by IPS) is actually legal. His argument is that it might not be legally OK to do so, and that there already are restrictions, even with rescinding the privacy rules by the FCC:

https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...

ust··on Euro MPs back end-to-end encryption for all citizens
That is correct, user will have access to the data, e.g. the images/videos user uploaded to Facebook, and I presume the Facebook will have to delete (successfully) these data upon request. However, personal data are not just images, or similar. It is also IP addresses, logs containing user's actions, etc. everything and anything that may identify a person. So, e.g. if some logs somewhere may contain IPs of a user, or some actions of the user were recorded in logs that are scattered throughout the system, the controller may argue that it "reasonably" tried to remove also these data for the user, but it can't guarantee that. However, GDRP now stipulates Privacy by design, which means some of these scenarios might have to be taken into account before creating and providing a service, so the removal of (all) user data should be more feasible.
ust··on Euro MPs back end-to-end encryption for all citizens
For my work, I'm working on the impact of the GDPR on the research, and how will the GDPR work in scientific communities. I'm not a lawyer, of course, so my interpretation might be a bit off (so disclaimer, IANAL, this is not a legal advice, and etc.). Anyway, these are just some of my thoughts on the subject.

Well, GDPR is a big topic, and it not yet clear how all the provisions will be implemented. It is not that different from the (currently valid) Directive, but it does clarify certain points, and makes much more stringent penalties, as mentioned in parent post (the fine is actually 4% of the global revenue, or 20M Euro, whichever is greater). The changes in respect to the Directive are, in short:

  • GDPR applies to the processing of personal data by controllers and processors in the EU, regardless
    where it takes place

  • Penalties – up to 4% of annual global turnover or 20M€ (whichever is greater)

  • Consent – conditions are strengthened (clear and plain language, explicitly related to the
    processing, easy to withdraw)

  • Breach notification

  • Privacy by design

  • Right to be forgotten

  • Data Protection Officers

  • Right to access
Now, as mentioned in another comment, the right to be forgotten and erasure of data is not really wipeout, the data controller and data processor are supposed to do it using "industry standards" and "reasonable effort" (controller, e.g. should flag that the processing the data should be restricted). Also, there are exceptions (legal claims, public authorities, free speech, etc.).

Different comment points out that the Regulation, unlike Directive, makes GDPR valid in all EU countries, and this is true. However, the EU states are free to implement their own data privacy laws, which of course, need to be in line with the GDRP. This may potentially introduce legal inconsistencies across the EU for certain points.

Also, one should not underestimate the legitimate interest of the service provider, or controller, to retain the data, even if the user has asked for the data to be removed. The data may also be retained by the request of relevant public authorities, etc. One comment has suggested what will happen if the EU citizen requests the removal of it's data, while the US public authorities asks for access to this data. In this case, the relevant EU public authorities may request for the data to be kept (or not, I guess this will be decided on case by case, also the provider may have a legitimate reason to keep the data..).

And of course, the biggest problem, the transfer of data to non-EU countries. For this, there are several ways to do it, one is mentioned already, i.e. user consent (which must be clear and unambiguously given, and can be revoked at any time). Then, of course, there are contracts, binding corporate rules, etc. For EU-US transfer, there is Privacy Shield for transfer of data to US (which is a replacement for the Safe Harbor, stricken by EJC), but this is mostly for commercial services (so it does not work for academic environments..).

There are some other interesting aspects to GDPR, but this post is already getting a bit long. For more info, these links are interesting:

[1] https://aarc-project.eu/aarc-infoshare/ -- for academic environments..

[2] https://iapp.org/resources/article/top-10-operational-impact...

[3] https://www.whitecase.com/publications/article/unlocking-eu-...

There are multiple WP29 interpretations on various points (some of them are actually human readable, not just legal talk..), etc. In any case, it will be interesting to see all these developments in the future.

[Edited for mistakes..]

ust··on Man jailed 16 months, and counting, for refusing to decrypt hard drives
Professor Orin Kerr has wrote about this exact case extensively, and provides a good insight into all legal aspects. I think it is well worth a read, especially the part about the 'forgone conclusion'.

https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...

ust··on Hackers Have Stolen Millions of Dollars in Bitcoin Using Only Phone Numbers
Well, you can generate TOTP codes on your laptop, using oathtool, if someone has a "dumb" phone. One of the downsides is then you need to have your laptop always with you...
ust··on Google reveals its servers all contain custom security silicon
It seems a bit counterintuitive that open hardware results in less choice, so I disagree. I think that hardware is getting more and more open, also drivers for it. With FPGAs it is (relatively) straightforward for one to create it's own crypto processor and integrate it in the system. Also PCBs are getting easier and cheaper to make. I hope that also there will be some open PCB designs that incorporate some kind of crypto chips and functionalities outside of CPUs, so everyone can start creating their own servers, if desired.

Didn't also Facebook started some open server hardware initiative? I don't remember what happened with that...

I do agree that the current status is not great, and that we could all benefit from more open hardware design. I think that it would also benefit large companies as well.

ust··on Ask HN: Can you recommend some 33c3 talks?
I found this one very interesting, about using ultrasound for tracking

https://media.ccc.de/v/33c3-8336-talking_behind_your_back#vi...

I think it was also on HN a few days ago..

ust··on How to Enable Two-Factor Authentication on Amazon
Yes, there is oathtool that you can use on Linux (well, that's how it's called in Debian). I use the same, just type:

oathtool --totp -b "key value"

where your "key value" is your secret (same thing you would get if you scan QR code). And then you just need to keep the secret safe, and you can run it on as many devices you need.

EDIT: just realized that michaelt had much more substantial comment.

ust··on Florida court says iPhone passcode must be revealed
Just a small addition, the analysis was done by prof. Orin Kerr[1], who is writing for "Volokh Conspiracy". He writes a lot about the intersection of technology and 4th/5th amendment, etc. I don't agree with everything with him, but it is pretty interesting, and he writes clearly.

1. https://www.law.gwu.edu/orin-s-kerr?id=3568

ust··on Ransomware gives free decryption keys to victims who infect their friends
I do have a follow up question to this. If the ransomware encrypt the files, then it would also need to delete the original files. Unless the original files are overwritten, wouldn't it be possible to recover them? If the files are indeed overwritten, I would presume it would take a really long time, and, if I remember correctly, this wouldn't work on SSDs, unless you fill the SSD completely. Or am I missing something?
ust··on Joe Armstrong Interviews Alan Kay [video]
I've just seen the movie after your comments, it was interesting to see that they use emacs (without syntax highlighting, it appears..). OT, but how's vim for coding in erlang, anyone?
ust··on Warning: 2016 MacBook Pro is not compatible with Linux
That well may be (regarding the power management), but while SPI as standard is old, the use of SPI is not standard. I've implemented quite a few SPIs (mostly FPGA) to interface with various commercial devices and virtually all of them had a different protocol, i.e. 8bit vs 7bit words, different bits to denote write or read, etc. Some of them didn't even use SS signal. I wouldn't really called them standard, and I say that with regret. More hardware could be used in a more standard manner.
ust··on Ubuntu 16.04 proves even an LTS release can live at Linux’s bleeding edge
I have the same machine (t450s), and I've just upgraded from 15.10. No issues with docking, or even suspend for that matter.
ust··on HaxeDevelop: A Haxe IDE on Windows
Thanks for the link, I see that you're using deoplete, how good is it for python? For me it doesn't really work..
ust··on Germany's Unlikely Diplomatic Triumph: Inside Look at Reunification Negotiations
This is completely incorrect. All of these countries were monarchies leading to the WW2, and all of them, except Yugoslavia, had fascistic tendencies. While they did welcomed the Nazis (again, Yugoslavia is an exception, it was invaded, not just by the Nazis, but by the surrounding countries as well, who were by that time Nazi puppet states), that was not to "get rid of the soviets". I am not trying to absolve Stalinist regime of it's atrocities, or that these countries didn't see Soviets as a threat, but this is just wrong.

Also, they didn't "realized" that Nazis were "just as bad or worse", they were on the losing side of the war (again, exception is Yugoslavia, although there was a Nazi puppet state in Croatia), and their regimes were subsequently defeated by the USSR, which then included them in their sphere of influence (Warsaw pact, etc.), and yes, from that point on, effectively ruled them (Yugoslavia had it's on independent dictator, Tito). But to claim "welcoming the Nazis to rid of Soviets" is just factually wrong. What is puzzling for me, is that all of this is readily available on the wiki pages of these respective countries. It seems that relying on "common narrative" is all too great.

ust··on Write like you talk
On an unrelated note - orthography... https://en.m.wikipedia.org/wiki/Johann_Christoph_Adelung
ust··on Math puzzle for Vietnamese eight-year-olds
Would forcing the integer result fix this problem? Something like:

    def f(a, b, c, d, e, f, g, h, i):
        return a + int((13 * b * i + g * h * c) / (i * c)) + d + 12 * e - f - 11 - 10
If I try it like this, I still have the same number of solutions... Maybe I'm missing something..

EDIT: code formatting...

ust··on Math puzzle for Vietnamese eight-year-olds
I have the same number, do you think there is a reason why they are not all valid? EDIT: actually the number I calculate is 2796. Also using Python 2..
ust··on Why did disastrous floods in the Balkans fail to capture US attention?
You're right, it did received more coverage in Europe medias. Changed...
ust··on The Story Of Larry Page's Comeback
Agreed. One more factual error is mentioning Tesla as a Croatian immigrant, but actually he was born in then Austrian Empire (which today is Croatia). His parents were Serbian. http://en.wikipedia.org/wiki/Nikola_Tesla
ust··on They said this hack was impossible
This doesn't seem so impossible, if device can work as a wi-fi hotspot, instead of forwarding Internet connection, it can just send a file to other device, unlike AirDrop, which needs a router to establish communication between devices. Or maybe I'm wrong...
Page 1 of 2Next →