HN user

Deregibus

285 karma
Posts2
Comments56
View on HN

Putting aside that these claims are presented without any evidence, “most” of 50% of the US population is a minimum of 82M people. ~31M have contracted COVID so far. That we’re going to see almost 3x the number of cases, concentrated in half the population, as we enter summer, and with 3-4M vaccines administered per day, is a pretty bold claim.

In a hypothetical world where our competent president and his competent staff made an occasional error, it would be reasonable to give the benefit of the doubt.

This is one of three or four errors just in this address alone. An address that may literally be the most important of his presidency. It wasn't just some George W. tripping over his words, he said literally the exact opposite of what the policy actually was and just kept rolling.

This is too important to be grading on a curve.

edit: To be clear I'm not suggesting he misread the teleprompter intentionally. I am saying that he and his administration have a level of incompetence and neglect that would result in jail time in many private industries.

That's a good broad description of both.

I loved their previous game TRS-100, but Opus Magnum didn't really do it for me for whatever reason. I'm completely hooked on Into the Breach.

The sites aren’t linking to a tweet, they’re embedding them. There’s a difference of intent between a plain old <a> link to a tweet’s URL, and the full set of tags, scripts, and configuration used to embed a tweet inline with your page. It would be unreasonable to hold you accountable for a simple link if I had a browser plugin that automatically converted them into embeds, but if you used the twitter markup such that they would be rendered as embeds on any standards compliant browser that’s a different story.

Yeah, to be clear when I said “makes sense” I was referring to what allows for a functional ecosystem of Twitter, users, media, etc. and not a legal evaluation. IANAL and all that.

In this case wouldn’t your innocent infringement example apply? As I understand it there’s an implicit license to use the content of tweets via an official Twitter embed. That would mean it would be fine to show the image via an embedded tweet from the copyright holder, as they agreed to that by posting the tweet in the first place and presumably could revoke that right by deleting the tweet. So the argument would be that the media sites had the rights to republish the tweet and thus believed that the author of the tweet had the rights to the contents of the tweet (which they didn’t). Is that logic not applicable here or is it that a media company should know better and thus it’s not a reasonable mistake?

Also wouldn’t the DMCA be applicable here as the method by which the photographer could get the photo removed from Twitter?

The photographer didn’t post the image on Twitter, someone else who presumably didn’t have a license to do so did. The sites then embedded that other person’s tweet.

If it had be the photographer that posted the tweet then the media companies would have been in the clear AFAIK since part of Twitter’s TOS allows for embeds.

This ruling doesn’t make a ton of sense assuming the media companies were acting in good faith. If they knew that the image was copyrighted and the Twitter user didn’t have the rights to post the image but embedded it anyway in an attempt To get around the copyright on a technicality then this seems more reasonable.

As far as whether or not Spotify is good to musicians, or takes too big of a cut, or distributes revenue fairly, I don't know. It's certainly possible that there's a better payment structure that would be better for musicians that results in no difference to the consumer.

But as a long-time paying user of Spotify I disagree with the premise of the article: Spotify is the product, the music is not.

For a fixed amount of money each month I can just play almost any song, whenever I want, regardless of whether I even know I want to, with zero friction. I don't have to decide whether or not a song is worth the money, I don't have to decide exactly which songs I will play, I can have shared playlists with friends where we can listen to music from our various overlapping tastes.

The extensive collection of music is a key aspect of the platform, but short of a massive dropoff in what's available, if an album isn't on Spotify the most likely outcome isn't that I'll go somewhere else to listen to the album, it's that I'll just listen to something else on Spotify.

This is like complaining that the rates at the airport currency exchange are worse than in your FX trading account.

Coinbase isn't a brokerage, it's more akin to a bank, and like a bank you're not going to get the market rate if you want to exchange currency. If you want to use a brokerage, use GDAX.

You are assuming the value of time spent on these activities is inherently positive.

If you like cooking or cleaning or taking out the trash then by all means you should do those things. But, if you don't like doing those things then the threshold for when it makes sense to pay someone else to do them is lower than most would think.

Yeah, I think that's pretty much the case. The first 320 bytes of the two PDFs released by Google result in the same SHA-1 state. Once you're at that point as long as you append identical data to each of the files you're going to get identical hashes. This is just taking those same 320 bytes and appending the combined images of your choice.

edit: as versteegen points out it's 320 bytes, not 304.

This was a good explanation of what's happening here from a previous thread: https://news.ycombinator.com/item?id=13715761

The key is that essentially all of the data for both images are in both PDFs, so the PDFs are almost identical except for a ~128 byte block that "selects" the image and provides the necessary bytes to cause a collision.

Here's an diff of the 2 PDFs from when I tried it earlier: https://imgur.com/a/8O58Q

Not to say that there isn't still something exploitable here, but I don't think it means that you can just create collisions from arbitrary PDFs.

edit: Here's a diff of shattered-1.pdf released by Google vs. one of the PDFs from this tool. The first ~550 bytes are identical.

https://imgur.com/a/vVrrQ

Funny how all the proponents of a Universal 'Basic' Income aren't proposing instead to make every 'Basic' item 'Free'.

After all, if you believe their rhetoric, giving someone $500/mo should be the same as giving them free bread, eggs, milk, some clothes and some movie tickets.

It's not "funny", it's the core part of basic income that separates it from state-run socialism. Not making a determination about what is or isn't basic is one of the key points. You give a person their $500 each month and let them determine what it should be spent on. What is basic for one person may not be for another.

That would require the client to be compromised though right? My understanding is that the client is making the decision whether to retransmit with the new key.

Now it's fair to question whether you can trust the client, but if you can't then there's no limit to what they could do.

I believe that you get a key change notification, but by default it doesn't require any sort of confirmation and will just continue to work with the new key.

I did read the article, and yes, his points are largely due to technological and environmental constraints. He presents a combination of current and past VR tech (with a healthy dose of strawman mixed in) and uses that to make the claim that VR will never work. It's not going to live up to the current hype, but you can say that about almost everything.

Nausea from VR is not some sort of intrinsic property, it's due to a number of physical factors, many of which can be solved technically by better hardware or by the design of VR experiences. It's not going to be easy, but it's not an intractable problem.

The difference between the VR we have now and the VR we had in the past is that now there is momentum towards moving the technology forward. You have multiple companies competing to develop hardware. You have many developers working on VR experiences and learning what does and does not work. You actually have people buying these things and using that software.

I think that there is overoptimism in VR right now where the technology is going to progress slower than people think, there will be more difficult roadblocks than people think, and the best practices around VR software will take a while to develop. It will happen, it's just not going to be easy.

This article strikes me as saying something akin to "Cellular phones are a stupid idea and will never take off. They're heavy, the size of a brick, and you can only use them in the few areas where there are towers nearby." Well yeah, if we were perpetually stuck in 1985 sure, but fortunately we're not.

I'd argue that the current generation of VR (Rift/Vive/Gear/PS4/etc) is already multiple orders of magnitude more successful than past attempts, and, to continue the cell phone analogy, we're essentially in 1985 right now.

Born to Rest 10 years ago

The coercion is to ensure that everyone at least tries something. I would bet that there is a significant percentage of people that would go in being unhappy about having to meet the requirement and come out being really happy that they did it. A well designed program will present a wide enough range of options that most people will find something of interest. And if it doesn't, then I'd say stopping as soon as the course is over is still better than not starting in the first place.

I was thinking the same thing. Assuming it's technically feasible I don't see this as being a huge problem. If your site is important enough that you can't have any downtime due to a CA revocation then you spend the extra time/money up front to get get cross-signed certs. If you don't care, then you just fix the problem when it comes up. If CAs start getting revoked more often then this will just become standard practice.

We used to play a game like this at my last company using a 4'x6' foamboard map that someone had pulled out of the trash. We would stand far enough back that you couldn't read the text on the map, use a generator to select a random country, then throw darts. Closest dart wins the point. It worked surprisingly well since even if you really knew your geography you still had the challenge of actually getting the dart there.

I feel that at its core programming is about taking a conceptual idea (e.g. pac-man moving around a maze) and determining the unambiguous logic that describes it. The language used to express that description has a significant effect on the end result, but it's the ability to develop the logic in the first place that really separates "programmers" from "non-programmers".

"Non-programmer" isn't meant as a slight. This style of problem solving works great a significant portion of the time. Natural languages can describe a solution to a lot of problems very concisely because a) there's a lot of implicit context that clears up many of the potential ambiguities, and b) you're typically present and available to handle any unexpected situations that may arise. For many problems, the best solution is one that can be specified quickly, will work 90% of the time, and can be easily adjusted for most of the other 10% of the time. Natural languages and fuzzier thinking work great for this.

But this approach doesn't work well for problems where the solution is either too complex too be easily described using natural language, or situations where data sizes or time constraints make it unfeasible for you to be available to handle unexpected situations. In this case the solution requires all of the logic to be precise, unambiguous, and developed up front. It's a different way of thinking than what has typically been asked of humanity, and natural languages are pretty poor at expressing that logic.

I think the paper has some good points, but I'm not sure how much you can really draw from it other than verification that natural-style problem solving doesn't work well for the type of problems that are typically solved by programming. If you asked a bunch of experienced programmers to write programs that will tell you how to "go to the store and buy me some milk", you'd probably get similar results about how the programs didn't handle the many different unexpected situations that might occur in such a simple task.

The checksum is only telling you when the value is probably incorrect, it doesn't show that it's correct or meaningful.

For example (on a completely hypothetical filesystem/disk), lets say you want to open a file. You read the entry in the filesystem metadata that tells you on what sector that file begins and it gives you a value of 5005. Even if the checksum is correct, the filesystem code still needs to check that a) 5005 is actually within the range of valid sectors, b) that it actually makes sense as a sector value (maybe files must always start on a multiple of 4), c) that the data at that sector actually looks like a file, d) etc.

If you don't update the checksum as well when generating the test data then you limit the amount of depth in the testing since most errors would get caught immediately at the checksum validation stage.

No one ever said "off".

It's 20% of the time you're paid to work on things that aren't necessarily part of your core responsibilities but still have a plausible positive impact to the company, even if it's just goodwill and team building.

It was never claimed to be a 4 day work week.

You would use techniques that are conceptually similar to responsive web design to deliver a UI that is appropriate for each of the supported devices. I assume this kind of thing has already been done for years for phone/tablet apps, this is just adding desktop as well.