HNHacker News
TopNewBestAskShowJobs

written

69 karma · joined April 1, 2018

submissionscomments
written··on US and allies launch strikes on Syria chemical weapons sites
Hmm, I never thought my informative post would get flagged, while baseless speculation is upvoted.

The parent is pretty much 9/11 inside job conspiracy level stuff. I just stated a few facts about what happened, and how that contradicts the parent's speculation.

Anyway, whatever. Evidently HN is not a forum for reasonable discussion around this topic, because people don't follow what's happening wrt Syria closely.

EDIT: Let's just say, that this reaction is pretty typical. Almost universally, whenever a chemical attack happens and is reported, we're told that rebels are doing it to themselves as a false flag, to inspire western intervention.

After 40th case of rebels successfully throwing canisters with chlorine upon themselves from helicopters they don't have, to inspire intervention that never happened in the last 7 years or didn't bring anything good,... it gets ridiculous...

The problem is that anyone who doesn't watch closely, only sees this one medialized case in MSM, and thinks that false flag somehow may make sense. And "why would Assad use chlorine?" pops up, when it's docummented he uses it regularly.

written··on Google is testing expiring emails in the new Gmail
Most of the big providers are shit, I wish I could shame them, but alas, I can not.

If I'm responding to e-mail from their users, I expect at least my initial response will get through. You really don't need any fancy crap like DKIM/SPF/nice IP addresses database/AI/bayes/etc. in this case to make the decision if e-mail is legitimate.

All my responses contain randomly generated ID of the message I'm responding to that nobody else than the sender and the intended recipient (me) can know. If it matches one of the e-mails their user sent me, say within a reasonable timeframe, and it's a first response or so, it is almost certainly genuine.

It just shows how little they give a crap about their own users, if they don't make such a simple check to make sure that their users can get responses to all sent emails.

Instead of making e-mail work, they're inventing bullshit like this new "expiring email" thing and making redesigns nobody asks for.

written··on U.S. Launches Attacks on Syria
Have you looked around? :)
written··on US and allies launch strikes on Syria chemical weapons sites
They will get there on weekend. OPCW was allowed in. Unless the strikes will change that.
written··on U.S. Launches Attacks on Syria
Probably too early for anyone to have any substantial comments anyway.
written··on U.S. Launches Attacks on Syria
All I hope is that the regime didn't do the same shitty thing it did in anticipation of Obama's response in 2013, when they moved prisoners into evacuated air bases, in hopes that the US will kill them.
written··on U.S. Launches Attacks on Syria
Just take the info with a grain of salt. Counterattack on whom? US forces in the east? US/French ships in the west?
written··on Bulgaria played a vital role in introducing yogurt to the West
Thank you Bulgaria. Hopefully the real thing without thickeners will always be available. A lot of crap is being sold as yogurt by the usual multinational culprits.

I guess we can make it at home if need be.

written··on Photo of Zuck's notes
Oh, I understood that posting the photo was propaganda, not the actual content of the notes. I guess the meaning of the parent post was ambiguous.
written··on Backpage.com Pleads Guilty to Human Trafficking in Texas
Everyone's repeating the 73% number, like it's some shocking statistic.

It's meaningless number in isolation. For example if backpage.com captured 70% of the sex ads market, I'd expect it to also capture the sex ads related crime at the similar rate.

If craigslist has 90% of ads for selling beanie babies, it will also have a hand in significant majority of beanie babies selling related crime.

So the question should be how big backapage was when it came to sex work ads, to make sense of this number.

written··on Photo of Zuck's notes
Perhaps a breach of privacy, but propaganda?
written··on YouTube Face is clickbait, attaining human form
Just make the algorithm select a random frame, and it will be solved.
written··on AV1 beats x264 and libvpx-vp9 in practical use case
x264 is a software codec.
written··on Mark Zuckerberg testifies before Congress
That's probably why he seems to enjoy it so much.
written··on Don't just shorten your URL, make it suspicious and frightening (2010)
Even random clicking on these "select X" captchas works. You'll just get a longer run around, until AI gets bored and lets you in.

Perhaps it recognizes that being annoyed and a willful breaking of rules are also human qualities.

written··on How to keep your ISP’s nose out of your browser history with encrypted DNS
I just realized I'm obfuscating my internet usage inadverently. Here's how:

Good source of reasonable randomness is twitter. I've set up a scrapper for various twitter accounts and I'm downloading every page that is linked by those accounts automatically.

With this approach you can even select what you want to look like based on your browsing data by selecting proper accounts. Gold bug? Bitcoin fool? Knitting expert? No problemo. ;)

written··on The dots do matter: how to scam a Gmail user
That's pretty good. It would require some serious gullibility to defeat. If it's active attack, attacker may send the second mail with the passcode and instruct the user to enter it.

Though people are forwarding their second factor SMS confirmation codes for their banking accounts to attackers upon request, so it's not too far fetched someone would find a way to trick some users to enter it.

Here's one study about the phenomenon (the N is basically zero, but this happens and banks are warning people against doing this):

https://engineering.nyu.edu/files/VCFA_PasswordsCon15.pdf

written··on Publishers Haven't Realized How Big a Deal GDPR Is
Many state run organizations have to be compliant too.
written··on Publishers Haven't Realized How Big a Deal GDPR Is
Also user can require the service to remove his personal information and that means that service provider has to notify services he uses to stop using and remove that PI.

How will this work with Google Analytics and things like that? Will random e-shop be required to notify Google to stop using/delete PI for random persons upon request?

written··on The dots do matter: how to scam a Gmail user
You have no guarantee that the domain part case is preserved from what the user wrote, if it's not defined to be case-sensitive. So you can do what you want, but the input data are not reliable.
written··on The dots do matter: how to scam a Gmail user
Depends on the service. I've seen verification e-mails that just contain a link with no other text. Or with texts like "Continue here: [link]".
written··on The dots do matter: how to scam a Gmail user
You don't click because you're educated in these matters. Most people are not.
written··on The dots do matter: how to scam a Gmail user
It's a user's problem. If user is willing to click through some unsolicited email and pay, he will probably click on the verification link too if the service would send those.

It's still a statistics game. Not everyone would pay without verification and not everyone would click the big green button in the verification mail, but some people will without realizing what's up, just like people fall for Nigerian scams mails.

There's no technical solution, only education can help.

written··on The dots do matter: how to scam a Gmail user
Not true, domain part is case insensitive by the standard.

Server can decide for non-standard behavior, but that would be foolish.

written··on Molyneux's problem
I hoped it was not.
written··on Raspberry Pi microSD card performance comparison
Sounds too cheap, are you sure it's not a fake?
written··on Raspberry Pi microSD card performance comparison
It works surprisingly well and it makes many operations faster than ext4. I noticed it especially when doing system updates.

And I've just read yesterday, that F2FS in Linux 4.17 will have further optimizations for low end systems. Yay.

written··on Comcast, AT&T and Verizon pose a greater surveillance risk than Facebook
Google doesn't need to break encryption for other reasons too. It has JavaScript execution access and thus access to all the client side data on at least the half of the top 1mil. websites on the internet.

It's easily blockable for people who care, but still many don't, and for those people it makes all the pretty transport encrytpion a sham.

Seriously, companies afford third parties JavaScript execution on pages where they expect me to enter CC or other sensitive info. Half of the web at this point is a joke when it comes to security and privacy.

written··on Raspberry Pi microSD card performance comparison
I have similar experience with SanDisk and Samsung EVO+. 9 Pi's (not raspberry) running continuously for ~2 years. No kernel panics/PostgreSQL failures. I run with data checksuming enabled. I also disabled options in PostgreSQL that cause periodic and unnecessary write activity.

Frequent regular updates, periodic database activity (web scraping, environment monitoring, ...). Running on F2FS.

I have logical replication setup in PostgreSQL, because I don't trust the SD cards anyway, but I have had no issues so far.

written··on Raspberry Pi microSD card performance comparison
Host side interface limitation.
Page 1 of 2Next →