HN user

B1FIDO

32 karma
Posts0
Comments74
View on HN
No posts found.

A funny thing about the "stages of grief" is that they are a total myth and the originator of the hypothesis never intended them to be abused this way.

Elisabeth Kübler-Ross did her research solely on people who were dying: people with terminal illnesses, and she studied how they coped with facing their own mortality. Not how other people did.

https://en.wikipedia.org/wiki/Elisabeth_K%C3%BCbler-Ross

And of course, even for a dying person, this may be total bunk. It is not like some programmed flowchart that people go through five stages of emotional stuff. This is just, like, a framework for further therapy.

I'm actually studying this stuff right now. In the 1980s and 1990s, "The Five Stages of Grief" were basically a household phrase, and everybody talked about them like they were real and true and invariable. But everyone doing the talking had never actually studied the research or even knew who proposed it. They were just parroting headlines.

I rented a car last July, and I specifically picked out a small one because I wouldn't need to carry any cargo or passengers around.

As soon as I drove off the lot, 3 warning indicator lamps lit up, including "Tire Pressure" so I stopped at a service station, thought for a moment, then drove back to the rental lot.

The other indicator had something to do with crash protection, and I think we worked out how to disable the system. After putting air into my tires, I was good to go.

So I'm thankful that those lamps indicated some actual conditions. I always kind of make a point of taking out the Owner's Manual and leafing through it, however briefly, just to see that it covers everything. They're still fairly comprehensive. I really appreciate that.

You may be surprised to learn that there are many types of botnets out there, and many use DNS queries for the C&C.

Although the GP wrote "53/tcp" that is a weird situation, because most (not all) DNS is over UDP.

One day I suddenly found my DNS resolver logs were very active with veritable gibberish. And it seems that my router had been pwned and joined some sort of nefarious botnet.

I only found this out because I was using NextDNS at the time, and my router's own resolver was pointed there, and NextDNS was keeping meticulous, detailed logs of every query.

So I nipped it in the bud, by determining which device it was, by ruling out other devices, and by replacing the infected demon router with a safe one.

But yeah, if your 53/udp or 25/tcp is open, you can pretty much expect to join a botnet of the DNS or SMTP-spam varieties.

"installing software" sometimes still consists of

  curl | bash
So if you want to have a conversation about trusting curl and bash and random gists...

Like I said, I installed software in many ways back in the day. I typed it in; I loaded off cassette tape; I loaded off disk. One common denominator was loading from trusted sources. My Atari cartridges were store-bought and not homebrew. I went to B.Dalton mostly for the software, and got it shrinkwrapped from the publisher.

I had a number of classmates and colleagues who caught viruses and malware from loading and installing cracked software or untrusted programs... or even alleged porn, from shady sources. This is still a good way to get infected.

When I get on a friend's computer, I often have occasion to congratulate them for being uninfected, and it's nearly always because they "practiced good hygiene" in terms of loading only trusted software from trusted sources.

So you're correct, in that really nothing has changed. Back in 1983 you could certainly "sideload" crap from a pirate BBS and then suffer the consequences. And we all had choice words for people like that.

Look we are talking about computers here. Computers don't understand or exercise actual trust as you describe it. Actual trust doesn't make computers work at all, because it doesn't exist in their world. So you need a proxy for it.

The security vetting, the authentication, the scans that are done, whether by Google Play or by F-Droid, are a process that tries to eliminate egregious abuses and basically curate the collection so that the users have something to actually trust. Now you understand that actual trust comes in degrees, right? I don't trust everything on Play equally. There are plenty of different types of trust relationships between me and the Play Store and the devs who put their apps on it.

But cryptographically, cybersecurity-wise, we need that CIA triad, and we need to authenticate that developers are who they say they are. And that authentication is the crux of cryptographic code signing. That we can trust that updates came from the source, and not a 3rd party injection or supply-chain attack. If Google or F-Droid countersigns it, then it's been through their vetting process as well. That's how cryptographic signing establishes trust relationships for computers.

If your computer doesn't trust an app or a driver, it won't download, install or run it. Since you cannot teach a computer "actual trust" there must be an analogue to this. And it's working fine. I don't know what you're on about "opposite to actual trust". If you don't trust Google Play, that's a you problem.

The US Civil War was along territorial lines, of course, and "Electric Boogaloo" will defy those clear delineations.

I believe we are seeing more of a https://en.wikipedia.org/wiki/Partisan_(military) type situation.

In rural areas, it may be the case that small towns and regions could be "on one side" or another, but obviously we see that in major urban centers, all different sides are mixed together, territorially speaking, and so the conflicts and "front lines" just sort of spill into the streets without a lot of uniforms or phalanxes or "us vs. them" delineation.

While it is true that Silicon Graphics eventually acquired Cray Computer, they did it after the novel, and the film's release, but I would suppose that even before the 1996 acquisition that SGI and Cray machines were very good partners, like peas in a pod.

It is important to remember that nobody who operated a Cray did it in isolation. The supercomputers always require some extra workstations arrayed around it in order to get stuff done. Of course, there were remote connections too, but often there would be at least one sort of "dedicated user console" that was closely coupled to the supercomputer itself. I believe that some supercomputers of that era were poorly equipped to actually handle interactive user sessions, and that's why.

Once, back around 2011 or 2012, I was using Google Translate for a speech I was to deliver in church. It was shorter than one page printed out.

I only needed the Spanish translation. Now I am proficient in spoken and written Spanish, and I can perfectly understand what is said, and yet I still ran the English through Google Translate and printed it out without really checking through it.

I got to the podium and there was a line where I said "electricity is in the air" (a metaphor, obviously) and the Spanish translation said "electricidad no está en el aire" and I was able to correct that on-the-fly, but I was pissed at Translate, and I badmouthed it for months. And sure, it was my fault for not proofing and vetting the entire output, but come on!

Well there is no "European military" per se and there will be no "Russia invades Europe" scenario, because "Europe" is a continent and not a sovereign nation.

What would happen is that Russia invades Poland, or Russia invades Romania or Bulgaria or something. Those are Eastern European countries. (I mean they all used to be Soviet bloc anyway.) Or Russia would invade Germany like the good ol' days. So whatever nation they invaded would sic their own armed forces on them, and their allies' too. NATO could jump into the fray.

Americans (and perhaps Russians too) often misunderstand how terribly small European nations are, really. They're mostly smaller than individual United States. So, less population, less time to transport stuff, fewer natural resources available in a sovereign context, etc. But lots of national borders.

So Russia won't invade "Europe" but they could go into one or more nations on the list.

I mean actually the FSV that you refer to is a clone of the SGI IRIX utility, fsn, that was actually depicted on a live computer in the film.

SGI was well-known to the film industry, because their IRIX systems were basically the sine qua non of graphics workstations and powerhouses. SGI invested heavily in the graphical capabilities, including 3D rendering, and therefore when the industry graduated from Amigas with the "Video Toaster" they slid into SGI systems quite nicely.

So it stood to reason that a couple of them would show up in an actual film. How plausible it was to have SGI systems on-site at a Jurassic Park type lab? I don't know, but seems reasonable, if they were also crunching DNA numbers.

What I'm talking about is actual trust. Like, there are cryptographic measures taken, certificates involved, code signing, that kind of thing.

You claim that you "can install anything" on Windows, but that is simply false. The system's Driver Signature Enforcement will prohibit the install of unsigned or invalid signatures on device drivers. Windows SmartScreen will also give you trouble by blocking unsigned apps.

So yeah, you can bypass these protective measures and "install whatever you want" ultimately, but it is basically the same process as sideloading on Android, isn't it? Disabling a bunch of protections that are there for your safety?

Your trust, honestly, doesn't mean jack shit. There is cryptographic signing, and certificate authorities, and processes to approve the certificates that authorized developers use. You don't got jack shit with your "trust" of Termux and Kodi. It means nothing to the end-user.

We do not work in "trust me bro" territory when it comes to signing software, anymore. I am sorry/not-sorry to say. It is very important to have a chain of trust that goes up somewhere above "goldenarm @ HN".

No, that is not how you change search engines.

In Chrome on Android (and yeah, on desktop too) you just go into "Settings" and change your default search engine. I can choose between Google, Yahoo!, Bing, Yandex, or DuckDuckGo.

There are also custom searches through Wikipedia and other resources. You can use little shortcuts to get to almost any custom search you set up in advance.

This has been configurable by the user for a long, long, long time. This is not a surprise or a concession. This is built-in stuff by Google for Chrome. (Edge too, of course.)

Changing your browser, you can do, but it won't be comfortable. I have Edge installed on my Android, but it is not possible to run natively on Chromebook and the Android emulation is bad. I will not set Edge to my Default Browser because it messes things up. It is not a great experience to change your Default Browser on Android. I just go with Chrome and use Edge for specific tasks and topics.

You can set up all kinds of email services in the Gmail app, or you can install a native app. I use Outlook in both of those ways, and it's fine.

SMS is very widespread in the United States.

All the B2C services I work with are sending SMS to my phone. Not RCS, not iMessage: they are sending SMS messages.

All the MFA providers, such as Twilio and Okta, are sending SMS.

All the political campaign spammers are sending SMS.

All the reminders for appointments and bills are sending SMS.

All the notifications for apps where Push isn't good enough: they're sending SMS.

If user-to-user communication is using iMessage then that is fine. I have noticed that only about 2 of my human contacts use RCS, and at least 2 of them are using iPhones and not Androids for it. So that's some anecdata for ya!

It was hilarious when I checked the movie listings for this week and found Greenland 2 in its opening run.

So I went to YouTube and rented Greenland (2010). It was a hoot! https://en.wikipedia.org/wiki/Greenland_(film)

I wrote "it's the second funniest rom-com I've ever seen". But seriously, it was filmed in close collaboration with the United States Air Force. (Much like Mission: Impossible was a collab between US Gov and US Mil units.)

It is kind of a fun ride if you're willing to suspend that much disbelief.

But I just found it hilarious that a pair of films named and set in Greenland should be produced in this way, while the actual country is in our news cycle now. I almost feel like it's a "PR buzz campaign".

The term you're looking for is "demarc" or: https://en.wikipedia.org/wiki/Demarcation_point

This is the physical boundary of a network, in telecommunications. This is the junction where the service provider can point and say "that's our equipment on this side". So it helps to narrow down the troubleshooting.

Often, if you have a telephone landline, you will see your demarc take the form of a gray RJ11 box with a small self-plug in it. It would be common practice to plug a phone into that box directly, then you've eliminated the "inside wiring" in the house.

God destroyed it

Where does it say that? I have never read any Book of Genesis that says "God destroyed the tower".

Also it doesn't say "God was afraid". God doesn't have negative emotions like that. God plans out everything, so He is not "afraid" in the human sense.

In fact, I am fairly certain that the mythical "Tower" for the Jews was sort of a parody of the Pyramids of Egypt and the Ziggurats of Mesopotamia. They were essentially mocking their ancient neighbors in the Levant for such a frivolous project that they believed really didn't honor God, but increased their arrogance and hubris.

In fact, the Sumerians worshipped a god named "Sin" https://en.wikipedia.org/wiki/Sin_(mythology) and it is believed that the "plain of Shinar" and the "wilderness of Sin" are cognate with this term, and therefore represents the ancient deity that was worshipped in that particular case.

For Egypt, the pyramids were funerary monuments, i.e. they invariably honored some dead Pharaoh. The Jews invested their engineering progress in building a temple of the Living God instead.

So it stands to reason, in the Hebrews' account of the foreign projects, that immigrants would come in, mess up the project enough, and they would kinda abandon them in progress. But they weren't destroyed.

It is not really though.

"Sideloading" refers to data transfer between two local, peer devices. Really, that is it. It is not "something scary" or something forbidden. It is not even really installing. It's data transfer.

So "before walled-gardens" people would install software in many many ways. I originally typed it in from scratch, or from a magazine. I loaded it from tape. Or diskette. That's not really "sideloading" if you think about it, because it's just "loading" from peripheral storage.

Later, when people dialed up on a PC, they could "download" software and then install it or do whatever with other data or media. They could also upload it. They could transfer it among devices locally. This was not, at the time, called "sideloading" but just transfer, or "null modem", or "sneakernet", or "a station wagon full of backup tapes".

If we're going to use "sideloading" in the strictest sense, then we cannot actually refer to the process of downloading APK files separately and then installing them, because that's literally downloading. But that is the colloquial meaning now.

Hey, if you want to coin a new term or neologism for it, by all means do so. But it seems absurd to downplay "sideloading" as having "scary" or "negative" connotations, when it really doesn't. You've got to look past the hype and F.U.D.

Remember, there was a time when people considered FTP and torrenting to be dangerous or subversive. Perhaps they still do.

I do not own a vehicle, and most of my life I've depended on public transit. Lately, I take Waymos or I ride scooters, or use public transit as usual.

Sometimes, for special errands, I rent a car. For example, I intended to move across town last year, so I rented a car for 3-4 days.

It was the most excruciating pain I could have. I chose a little Mitsubishi Mirage, and firstly, it was the middle of July in the Sonoran Desert, and the A/C hardly worked, so I was sweating, and the car would heat up real good in parking lots. No sun shades, dark upholstery. Also, the USB connection was flaky, so sometimes my phone didn't charge, and whether or not, it was directly exposed to the Sun and overheating.

By the second day, my legs hurt a lot. I had spent an unexpected amount of time on my feet and walking around, despite the vehicle. Do you know how big parking lots are these days?!

I tried sitting down at every opportunity. I have a running gag/dispute at my bank to see whether they will allow me to "sit down" at the "ADA/Disabled" teller window.

Driving home at night on the last night, my leg cramped up really bad. I was in such pain, I nearly pulled over because it was my accelerator/brake leg and I was going to lose control of the car.

Thankfully I was able to hold it together, and returned the car the next day, but boy I did not want such a vehicle ever again. And it was not a stick-shift; it was an automatic transmission.

Next time I'm going to be really sure that the USB and A/C work. And that my legs are super-comfortable and has cruise control.

"Installing" has the connotation of doing it directly from the Play Store. This is also known as "Downloading" (because the data is on a server, in the cloud, and you're fetching it "downstream" to a local device.)

"Sideloading" doesn't refer to the installation process, but to the file transfer process. You're sideloading when you transfer, e.g. APKs from your notebook to your Android. Or, from a USB stick into your phone or something.

In general, though, "sideloading" also refers to any "non-app-store" installation. It's a kind of colloquial shorthand. It's not really a technical term. But it's adequate for getting the point across.

If you just called it "installing" without qualifying it, how would anyone know that it's a different process, or that it's accomplished not by navigating to the app store? It seems that you would invite ambiguity here!

Once, long ago, I was a fledgling C programmer working on the TinyMUCK game server. My mentor had released the 2.0 version with MUF, and I had implemented the port to SunOS (where a dereferenced NULL pointer does not return 0, but SIGSEGV: that was a lot of fun to debug!)

Later on I was working with another fellow to kind of bring the codebase up-to-date, and we found it necessary to implement a new database dump format (the database was normally 100% in RAM and then "dumped out" to a flat file for checkpoints and shutdowns.)

So I made the database changes, and then I christened the format "Christina Applegate TinyMUCK Dump Format" because she was the girl/woman of my dreams at that point in time (prior to Melissa Joan Hart taking over).

It is unclear if she ever found out about this particular usage. But last time I checked, this codebase was still extant, and so, someone somewhere may still be running a TinyMUCK server that utilizes a unique format dedicated to Christina Applegate herself.

Multimedia "texts" are actually MMS. In fact, if you send more than 160 characters, those are also MMS because it's an extension of the SMS standard.

https://en.wikipedia.org/wiki/Multimedia_Messaging_Service

It is not unusual for there to be hosting or intermediate storage of images and other files, and from the phone you may tap a link or something to download/access that file, instead of having it automatically download and appear immediately, due to bandwidth and resource constraints.

The smart projects that are going for L10N will collect all the UI strings into a file or set of files, separate from the code, and indexed so that the app can just switch language and then begin using a new set of localized strings. This also makes for easy translation where you don't need to rebuild the app, just expand the data files that it's using. Is this not the only way to build apps today, or are "localized strings" still being hardcoded??

A really bad platitude can be "let me know if I can help, somehow!" and then leaving it at that.

Well, your friend/acquaintance may not know how you can best help. Yes, if it's a widower who lost a home-maker wife, he may need help fixing meals or cleaning house or doing laundry. Vice versa for a woman who's lost her husband.

But if you don't fill them in on how you can help and the things you are good at doing they will not know how or when to ask you. And then you will not end up helping.

Be concrete and specific when you offer help. You could make a list of three things to do. Then present your list as a menu of choices. Or "D", something different.

Be concrete about your boundaries and schedules. Don't let them get carried away with using your services. Tell them you can give them a ride once a week to essential errands, for example. It is sometimes most helpful if there are multiple people pitching in.

Really, long-term, if I were in need, I'd want to go to a professional agency for most things. A professional meal-prep service, housekeeping agency, home care agency that sends licensed and bonded pros. My volunteering friends and neighbors are well-intentioned, but this can be fraught with difficulty if they are not good, or not-so-well-intentioned after all.

Many people will swoop in to take advantage of people who are perceived to be vulnerable, grieving, and willing to accept help. That's why some of us are skeptical.