HN user

FungalRaincloud

259 karma

[ my public key: https://keybase.io/fungalraincloud; my proof: https://keybase.io/fungalraincloud/sigs/F0GfFi5Eh9qqFmMyAfwaSyexRLoXI0hCqxQe_ODWjPY ]

Posts0
Comments102
View on HN
No posts found.

A lovely thing in math is that a counterexample, especially if it leads to infinitely more counterexamples in a particular class, can teach you more about the problem. I find this article hopeful. It made me excited about knot theory for the first time in a while.

I'm a bit surprised that you put PHP in that list. My current workload is in it, and a relatively modern version of it, so maybe that surprise will turn around soon, but I've always felt that PHP was more obnoxious than even C to read and write.

Granted, I started out on LISP. My version of "easy to read and write" might be slightly masochistic. But I love Perl and Python and Javascript are definitely "you can jump in and get shit done if you have worked in most languages. It might not be idiomatic, but it'll work"...

The Hedgehog Review? Yes, they've been around since 1999, and publish a few times a year. But I'm not sure where you're leaping to a strong political leaning. They're an academic journal published by the University of Virginia. I don't religiously follow them, but I've been cursorily aware of them for a while. I don't think I've ever considered them to lean one way or another when reading their publications.

I had something similar set up on my second to last work laptop. I had done some heavy customization that was mostly focused on common workflows for that job, but I have learned that I should still keep a backup even if most of it won't work elsewhere. I should have learned this lesson almost a couple decades ago when I lost all my emacs customizations on a personal computer. But instead, I decided to learn vim.

I think it's important to consider audience. If I'm working with the intent that what I write is legible to folks who only have a basic understanding of math, I'll usually use the multiplication symbol (NOT the letter x, but ×, intentionally in the middle). Someone with more advanced knowledge of math, who may be more inclined to think it's an x, because my handwriting is shit, I will typically use the dot operator. But then there's the whole other audience where I need to define what the dot operator does. At that point, I'm probably pulling up something like LaTeX, because, again, my handwriting sucks.

Funnily enough, when I write for the purpose of math, my numbers are more legible than when I just write down a number. For some reason, I code switch in my handwriting. Kinda obnoxious when I'm filling out forms.

I was advised by a few recruiters to remove all PII from my resume but my email, both for privacy reasons and because it's better to funnel all offers to the same location. I still keep my phone number on there, but if someone really wants my data, it's remarkably easy to find, so I am not really doing much by just removing it from my resume. Oddly, I've had a few people actually try to find more PII on me and fail miserably. They claimed to be good at it, and should have known enough to find at least my legal name with ease. Used to be able to find old AIM conversations of mine if you knew what to search for (or got lucky).

Trust, to me, is not the problem. You can build trust. Known-good certificates can be distributed physically, and require signed messages for replacement. Or, we can develop schemes for distribution digitally via validated channels. For example, each worker at a company has a particular known-good digital presence, verified by their own public key, and distribution happens with them as the source, essentially creating an expanding ring of trust to the key being distributed. Violating such a ring of trust is not going to be easy, if it is well enough built.

There are two issues I do see, though, and they're kind of the same issue. Right now, we have this concept of a central store of public certificates. It makes it easy for you to get a certificate for a particular entity, but it also makes the central store a target. If you can compromise a central store (or a machine that is attempting to access said central store), you probably have the resources to at least redirect the user to your own site and leave them none-the-wiser, and you probably have the resources to man-in-the-middle their connection entirely and just snoop your heart out. So central stores of trust are a bit of an issue, and the ways around that are non-trivial to set up. A good example is probably KeyBase, who allow you to certify your various online presences with your private key. So if someone wants to replace your information on KeyBase with their own one, and they have the resources to do so, now they also have to compromise all the places you've distributed that key to. Or, they have to compromise one of those centralized stores of trust....

The big issue with centralized stores of trust is that they build blind trust. That's the big issue with humans in general, though. We don't want to question what we're watching. And we probably don't want to be bothered with validating that the "trusted source" of the certificate used to sign this content is actually _trusted_. It's just too much mental overhead. We want it to be automatic. We want central stores of trust, because it's just _easier_. The work is going to be convincing people that _easier_ is dangerous, in this case. Or, it's going to be to convince software companies to build in inconvenient technology and not make it trivial to turn off.

Something that does concern me about WhatsApp is that backups of messages (by default, it seems, put on Google Drive on Android) are not encrypted. I'm not really sure why. There's not a compelling reason that I can think of.

It's plausible that they could just compromise the security, intentionally, without telling anyone (and without anyone being able to easily tell).

I think what's more likely, at least in the case of WhatsApp, is that they would just not make an announcement when they remove E2E encryption entirely. The security community would certainly complain, and long-term, the traffic they are currently getting from parties of any interest would move somewhere else. But in the short term, it would compromise the security of a substantial number of their target users. It's plausible that, without a public announcement, many 'nefarious' users would continue to use it for a few months.

Like I said, it's the belief that it's a niche language that's kind of making it a niche language - that is, fewer people know it (because of the perceived niche-ness), but more people want it, meaning the pay is good. I'm not at all surprised to hear there are quite a few shops using it.

Granted, in my area, there are exactly none, but I don't live in the best location for the use of modern tool/language/technology stacks. If I were to move an hour or two north, I'd probably find many.

I don't know about others, but I personally have always seen Go as an internal language for Google. This made me feel like it was appropriate for projects that I personally control, but unlikely to be useful in a career. That's really just a feeling, though, and I recognize that if everyone felt like I do, it would make Go a niche language that was actually probably pretty lucrative to know. So I wouldn't say I'm put off by it, so much as the balance of factors hasn't tipped in favor of learning it yet.

What Facebook has that Youtube does not is that you can share with the click of a single button (without any prior setup) to friends and family. For a not-insignificant-portion of internet users, Facebook is how we communicate with others, so shareability to Facebook matters quite a lot.

I don't disagree that youtube is just as easy to use, but that doesn't change what Facebook has that youtube doesn't.

I don't think there's any reason one could not lace heroin with AIDS, it just would not reflect well on a dealer. That said, it would likely require intent (or really bizarre circumstances). With blood, it could much more easily happen, you're right.

Many young people already do give up their blood for a pretty cheap price, so I don't think there's any reason for this to become a black market thing.

I'm inclined to agree just from my own reading of this. I just don't see how sale could do anything but harm trust in the brands further, which makes sale only appealing to those who either don't care about trust, or have enough trust on their side to think they can rebuild it. Both of those groups are not going to want to pay much. Why sell a division of your company for peanuts?

I don't really like the argument that something is 'secure' because it is not vulnerable in the same ways that an alternative is. I think this is why I like talking about encryption so much. It's possible to mathematically prove the security of encryption algorithms, and all that's really left to pick apart is the implementation, politics and impact.

Counterpoint here: I went on a ketogenic, high fat, medium protein, low carb diet this past year, and managed to lose roughly the same amount in probably the same amount of time (if not less), doing basically the same thing. I ate what I wanted. I got full a lot faster, though. I also felt like I had more energy and suffered less brain fog while on the diet. I'll likely go back on it pretty soon here.

EOs cannot violate the law, or compel someone to violate the law. Could the president issue such an executive order? Potentially. But that does not mean it gets carried out, or is legal.

Do you think this president would? I don't think it terribly likely, and if I heard that he was about to, I'd probably start booting Linux for a few months, because I would wholeheartedly suspect that it did more than just patch effected systems.

In a brushless DC motor, the rotor is a magnet, and the stator is a series of electromagnets that can be powered independently, yes. But the rotor is still usually at the center. You're dead right on why it can be brushless - the bit that moves is the permanent magnet. One other important difference is that the coils need to be controlled by a computer of some sort to get the timing right to make a rotating magnetic field and keep the magnet spinning.

That's a matter of perspective, and I agree that that's what it will very rapidly become. However, right now, I would say it really is a discount - you get a rate that is lower than what you would otherwise have gotten before the technology was introduced. That's partially a reward for you being part of the early adopter group that will make it ubiquitous enough that they can justify raising the prices back up to the level the market can bear.

The trouble I see coming is, right now it's "a discount" for sharing the data. Once these sorts of services become ubiquitous and well tested, it'll be "a surcharge" for not sharing the data. Explicit opt out, versus explicit opt in. Right now, it feels like you're getting value out of sharing your data, but in the future, you may have to pay more (relative to others) to keep your data private.

What I'm interested in is something that takes hand drawn input and converts it to expressions that can be evaluated. A dedicated keyboard for math has been immensely helpful to me, as well, because it speeds up the input more than any software only solution I've tried. But there are always things which require some thought about how to enter them in. Not having to do that conversion myself would be pretty nice. I think there's some potential there.