HNHacker News
TopNewBestAskShowJobs

wtbob

6,614 karma · joined May 14, 2013

submissionscomments
wtbob··on Internet firms’ legal immunity is under threat
In 2016 the NRA spent $3,188,000 (source: https://www.opensecrets.org/lobby/clientsum.php?id=d00000008... that doesn't even make the top 20 (it's #156).

Perhaps you meant campaign donations? It donated $1,092,750, making it #427.

It is #8 in outside spending, but its $53 million is nowhere near Priorities USA's $133 million.

wtbob··on Meshbird – Distributed private networking
Seriously, I'd advise that you implement an HMAC today, and implement GCM tomorrow — using raw CTR mode really is that dangerous. And make sure that you never ever ever reuse IVs, ever.

This sort of thing is incredibly dangerous. Props to you for coming up with a great UX, but crypto is very, very difficult to get right.

wtbob··on The Fastest Blog in the World (2015)
> except for adding just enough JS to do Medium-like lazy image loading to save bandwidth for visitors.

Please, please don't do that: it means that visitors without JavaScript enabled simply cannot view your page.

If a visitor wishes to configure his browser not to download images until he scrolls near them, that's certainly within his power. But if you break your page and only unbreak it for those with JavaScript, then your visitors have no choice.

wtbob··on Encrypted email is still a pain
> at best you're attempting to tunnel encrypted messaging over an unencrypted transport.

That covers pretty much all communication encryption: ultimately, encrypted data goes out over an unencrypted link.

> A protocol that leaks metadata, including some message content, at the envelope layer.

That is indeed the major problem I have with it.

> Hundreds of millions of users that primarily access messages through browser clients that can't meaningfully implement crypto.

The solution IMNSHO is to get off of the browser. Browsers are great for what they were designed for, but they're a terrible general-purpose computing platform.

> End user demands for things like search that can only be delivered efficiently at scale by databases of plaintext (most likely at centralized servers).

I think that one's home computers can probably handle the load of searching all of one's own data. If that's not the case, encrypted search protocols may be of use.

In general, though, your last point argues against any encryption or other user-privacy measure: if users are right when they demand centralised search, then encryption is a bad thing. I don't agree that encryption is a bad thing, thus I refuse to believe that users are right to demand centralised search.

> But: why bother? Email is just one of dozens of messaging systems available to Internet users.

It's the only decentralised one atop which a trustworthy system could be built. Signal, WhatsApp & Wire all have critical flaws which prevent their widespread use (Signal is centralised, tied to a phone number, leaks contact information to OWS; WhatsApp is centralised, owned by Facebook & default insecure; Wire looks appealing, but it too is centralised and controlled by a single company).

I tend to agree with your conclusion that email encryption is not worth the trouble; I disagree that it cannot be used securely.

wtbob··on Lisping at JPL (2002)
> I can't even say the word Lisp without cementing my reputation as a crazy lunatic who thinks Lisp is the Answer to Everything. So I keep my mouth shut (mostly) and watch helplessly as millions of tax dollars get wasted.

I've been there too, only in the commercial world watching corporate profit be wasted. It's really disheartening to see the computing world re-invent S-expressions badly (first as XML, then as JSON) and reinvent Lisp badly (e.g. JavaScript). Lisp really is awesome, and it really is the best language of which I'm aware, if for no other reason that if one wants to do enough programming in the language, then one can implement any other language, seamlessly.

wtbob··on Raymond Smullyan has died
> trying to shift Catholicism back to its roots of faith and charity rather than being hypocritical morality enforcers.

How are faith & charity different from any other moral issue? Why do you (apparently) think encouraging faith & charity is okay, but (apparently) not humility, chastity, temperance, prudence &c.?

wtbob··on The horror of blimps (2003)
All I can say is: if you've not read this yet do so. It's a quick read, and it's completely worth the time. Best thing I've read on the Internet today, honestly.
wtbob··on Designing a Business Card in LaTeX
> They use it because certain journals require it, or their advisor makes them use it.

I think that's one of the jobs of an advisor: to encourage his students to strive to be better and do better.

wtbob··on Designing a Business Card in LaTeX
Well, this was in academia and it was a long time ago, but when I was in college at the turn of the century I used it. Once I noticed that the exact same paper got a whole extra grade in LaTeX, I never went back to word processors.
wtbob··on Designing a Business Card in LaTeX
> You need to get 1 out of 100 applications from the app store, that competes for the one who can shows the most ads and be the least effective at decoding the picture.

The ZXing Barcode Scanner doesn't show any ads. IIRC, they give it away for free because they want people to use their (open source, natch) barcode library. I've been very happy with it.

This of course demonstrates a problem with the App Store model: neither Google nor Apple has a strong incentive or interest in directing users to the best, most secure, most privacy-preserving apps (particularly Google, who would prefer that privacy become a thing of the past): they would much rather that you buy something, or use some ad-ridden piece of nearly malware.

wtbob··on Designing a Business Card in LaTeX
One of the first apps I install on my phone is ZXing's Barcode Scanner, specifically so I can scan QR codes. On Android, it's hands-down the easiest way to post WiFi details for a LAN party or similar (no idea how to do it with iPhones — maybe Apple sells some $99 AirWiFiScanner thing?).

I'll scan 'em to see if there's useful info there. I'm a little concerned that there may be some way to do something malicious with a QR code, but I don't believe I've ever seen a POC.

I'll also use them to set up TOTP. Incredibly easy.

Honestly, I wish that they were used more often. In my experience they work flawlessly.

wtbob··on Designing a Business Card in LaTeX
FWIW, my $BOSS-2 had a PhD, loved LaTeX and even set one of our lower-level guys on writing all our company-internal docs in LaTeX. It actually worked out pretty well.

I imagine that an obviously-LaTeX resume (look for the ligatures, the correct spacing between sentences vice after periods, the clean, consistent grey across the page, the bold, clean margins) would play especially well with him. As you might guess from the preceding sentence, it'd probably play pretty well with me, too!

wtbob··on Yale will rename Calhoun College to honor Grace Hopper
One wonders how long before Yale changes its name altogether: Elihu Yale was a slave trader.
wtbob··on Oracle refuses to accept pro-Google “fair use” verdict in API battle
Not understanding is fine: assuming that something one doesn't understand must be a slur is not fine.
wtbob··on Thousands of deadly U.S. military airstrikes have gone unreported
The aircraft was 11 nautical miles away, which is over the horizon.
wtbob··on Grappling with Go
> There's a significant amount of code you can lose from a large C project just by getting rid of ifdefs that nobody uses, so the +/- line count isn't a great metric either.

Can't 'ifdefs that nobody uses' hide security flaws? Removing them helps the overall security of the codebase, preventing folks from accidentally enabling a long-dormant codepath, no?

> The true metric for success for something like ntpsec is the number of meaningful security problems ntpd has been vulnerable to since ntpsec's inception that ntpsec hasn't been.

True enough. Are there any numbers on that?

wtbob··on Thousands of deadly U.S. military airstrikes have gone unreported
> The military also didn't go out of its way to punish recklessly shooting down a civilian aircraft.

It wasn't reckless: it was the right call based on the data Vincennes had, which showed that an Iranian fighter was able to kill it.

wtbob··on Thousands of deadly U.S. military airstrikes have gone unreported
> Our guy shot down a passenger flight, murdering 290 human beings, we gave him a medal but we then paid USD$213,000 in blood money per passenger to Iran without ever admitting fault.

Vincennes believed it was shooting down an attacking Iranian fighter, not a passenger jet. It wasn't murder; it was an accident (due to faulty electronic data). We didn't give the skipper a medal for shooting down the plane; we gave him an end-of-tour award. And I don't know what the big deal with paying weregild is: that's what you do.

Has Russia paid anything to the families of the Malaysian airliner shoot-down?

wtbob··on Thousands of deadly U.S. military airstrikes have gone unreported
> In 1953, we overthrew their democratically-elected government in favor of the opposition

No, we didn't: the rightful government (the Shah's) overthrew an attempted dictator. Mossadegh lived out the rest of his life in peace, and died in bed.

> Or you've probably never heard of Iran Flight 655, where in 1988 a reckless US cruiser drifted into Iranian waters and shot down an Iranian commercial airplane in Iranian airspace.

No, it wasn't reckless: the electronic data gave Vincennes good reason to believe that it was being attacked by an Iranian fighter.

> Our "defense" of Vietnam.

The 2 million South Vietnamese who fled their country after North Vietnam conquered sure seemed to have appreciated our defence: while we were there, they didn't take to the sea in boats, fleeing for their lives.

wtbob··on The open-office trend is destroying the workplace (2014)
> I'll have headphones on all day, instead of 10-20% of the day.

I worry about the damage that my office headphones have on my hearing. I wonder if there's some sort of OSHA regulation regarding it, and if I have recourse against my employer because I am forced to don headphones are be distracted.

wtbob··on Building a Lisp from scratch with Swift
You're right, of course. Still, 'everything is a boolean' is close enough for government work:-)
wtbob··on The open-office trend is destroying the workplace (2014)
> I was even asked to meet with my company's architects and designers about a new space we were building out. I basically spent an hour telling them in every different form I could that what I wanted was a place I could go where people could find me, but they would have to knock on a door and open it to talk to me, and these people looked at me like I was from fucking Mars.

I had to check your username to see if a) you're me or b) you're one of my co-workers. This exact same thing happened to me. I'll admit that our new office looks quite nice, but it is more-or-less impossible to actually get any work done there. Every conversation destroys the entire focus of the entire team; every personal tic annoys dozens of people and destroys their focus. There's no peace, no quiet and precious little productivity.

I honestly don't know why they bothered having those meetings. Did other folks say, 'I'd love something pretty, but I don't want to ever complete any actual work'? Did someone request an office which looks great in a brochure? Did someone say, 'I want something which makes an awesome gallery — don't worry about making it an office'? Enquiring minds want to know.

wtbob··on What Killed the Linux Desktop (2012)
> Linux (as in the kernel) succeeds because it's free, flexible, stable and secure. But none of those words are "pretty", "aesthetic" or "powerful".

I think that StumpWM, i3 & dwm are all powerful, æsthetically-pleasing environments. I think that emacs is a powerful, æsthetically-pleasing environment.

> OSX became the uber tech junkie's OS of choice, but with Apple's recent shenanigans these savvy enthusiasts and devs are also starting to use Windows again.

I think anyone who chooses to use Apple doesn't care about his freedom, and anyone who chooses to use Windows doesn't care about æsthetics. With Linux, I have both.

wtbob··on What Killed the Linux Desktop (2012)
> I would take Windows 95's window manager over Ubuntu's Unity every day of the week.

And I'd take StumpWM over Windows 10. Honestly, I'd take Windows 95's UI over Windows 10.

I don't actually mind what the Unity guys are trying to do — it's definitely not for me, and is part of why I left Ubuntu for Debian, but I can see that they are trying to do something good.

wtbob··on What Killed the Linux Desktop (2012)
I personally find that movable-window designs are a UI failure, requiring too much user interaction. A tiling WM, OTOH, enables me to do what I want: work with one tool or another, and work with multiple tools when that's what I want (which, frankly, is rarely — other than consulting a browser or info window, it's not often that I need more than one window on my screen at a time.
wtbob··on The State of Go
This slideshow doesn't work on narrow browsers: a narrow browser window clips the text, despite there being more than enough window space to display all the information on the slide.

Remember when the Web was automatically adaptive? Remember when we preferred HTML to PDF because it adapted?

wtbob··on How the NSA obtains and uses airline reservations (2013)
> One of their 'crazy, batshit insane,' conspiracy theories was that the government was recording all of our phone calls.

> think of all of the circumstances we've become used to now that were the territory of conspiracy theorists 25 years ago.

There may be many such circumstances, but certainly not the one you mention: the government doesn't record all of our phone calls.

wtbob··on Building a Lisp from scratch with Swift
> Is there a boolean predicate?

Nope, because everything is a Boolean: NIL is false, and everything else is true.

wtbob··on Using tmux properly
I did that as well, and it was Great and Good and obviously the Right Thing — right up until I pasted in a some shell code which used `` instead of $(). Never again.

These days I use C-z for tmux. It works, and C-z z is easy enough to type when I want to put something in the background.

wtbob··on Using tmux properly
You're not wrong about the problem, but there is an issue: sometimes the defaults are really, really bad — e.g. C-a as a prefix character, when anyone who uses emacs keybindings is used to that keystroke taking him to the beginning of the line.

The solution, of course, is to improve the defaults, but that's not always practically possible. Sometimes the maintainers refuse to do the right thing, and sometimes there is no right thing (e.g. should be use C-{b,f,p,n} or hlkj?).

I'd rather have a system which enables me to mold it to myself — even at the risk of being unable to use the same system configured differently — then have a system which forces me to do the wrong thing.

← PreviousPage 5 of 34Next →