HN user

Kadin

3,257 karma
Posts0
Comments933
View on HN
No posts found.

The US has never allowed unfettered foreign competition in its domestic market, and neither do most other nations (including, very notably, China).

The US has always done what every other nation seeks to do, which is to try to obtain favorable trade terms for exports while restricting imports that would harm domestic business.

This particular bill is idiotic, likely because it was spawned by an idiot. But the general concept of protecting domestic enterprises from foreign competition who are not subject to the same rules has always been part of trade policy.

This is all true, but just to set expectations: the open source ecosystem seems to be lagging the proprietary world pretty significantly, unless there's some corner where development is really chugging along that's not making it out to the rest of the hobbyist market.

Though there have been incremental improvements in flight control software, and video subsystems have moved (mostly) from analog to 2.4/5.8 GHz and digital, the overall architecture is pretty similar to what it was 5+ years ago. You have a hobby R/C transmitter and receiver driving PWM outputs (through the flight controller, typically an STM32) to hobby-type ESCs which control the motors. The ESCs are microcontroller-driven and can be reflashed, but painstakingly and annoyingly. Telemetry is typically separate from control, which is separate from video. Everything is very short-range and non-IP.

In comparison, a COTS quadcopter from DJI has a single backhaul from the airframe to the controller which does control, video, and and telemetry. And the video is impressively low-latency. (I'm pretty sure they use a WiFi-type chipset and just spew raw vendor frames, and the receiver picks up what it can, best effort. You could do this with an ESP32 in ESP-NOW mode, I suspect?) I've seen some efforts to reverse-engineer the DJI protocol but I'm not aware of a fully compatible implementation or equivalent in the OSS world.

And at the upper end of the commercial/proprietary space you have systems with out-of-the-box autonomy, multiple backhauls over IP -- so they can use LOS/BLOS radio, LTE, SATCOM, whatever you want -- integration with navigation beacon systems to reduce GPS dependence, hybrid motor/generators, redundant power systems, the whole shebang.

There's no real reason aside from developer interest that this situation exists, as far as I can see. The components are mostly all available. A Raspberry Pi running a decent RTOS would have orders of magnitude more processing capacity than an STM32 and could easily do the sort of multi-sensor fusion that the commercial systems do. LTE modems are cheap. A bigger hexacopter or fixed-wing could easily loft one of the small Starlink dishes, if someone wanted to. Stuff like "perching" (landing and recharging from solar panels) is entirely possible.

But from what I can tell, the cutting edge of open source drones is happening behind closed doors in Ukraine and Iran.

Happy to be corrected if there's new stuff that I'm not tracking, but the gap between the "art of the possible" and current practice seems large.

Lots of opportunity though, is the other way to view it.

It doesn't seem that weird precisely because so many people here are in software, rather than hardware. My suspicion is that the median HN reader probably knows a few JS developers, but PCB designers are few and far between in software shops.

Some of the responses surprised me -- I would never have thought about using Fiverr, for instance. I've gone there for graphic design, HTML/CSS/JS, and even some full-stack work, but it never occurred to me to hire a PCB eng there. No reason, just not something I'd looked for before.

In many products, there are different firmware or software loads for the PRC market (specifically PRC -- until recently not the HK versions) and the rest of the world. In some devices it's possible to lock satellite positioning to only Chinese constellation (BeiDou), or introduce error, or just not include positioning by default.

Of course, some of those devices get through, or are carried in by tourists, or are enabled by enthusiasts who load the non-China firmware. This seems to be understood. The Chinese are smart enough, one presumes, to know that actual state-level competitors can get accurate (in the chosen geodetic system) location data without relying on tourists' geotagged Google Photos uploads.

But that does lead to the question, "why, then?" -- if your adversaries know your secret, it's probably not worth the effort of protecting, anymore. (And why, in the US, we know about stuff like VENONA now.) The Chinese seem focused on a different threat: they don't care if a few people have good location data, even if some of them work for the US NGA, they just don't want everyone to have that data.

Which is interesting, because it suggests that that they're less concerned about a foreign government with strategic intelligence, than they are their own domestic population.

This isn't about state secrets vs other states; it's about denying their own population a capability that they find valuable, and thus threatening.

That's only interesting to the extent that an organization has operations in China. Google was mostly ejected from the Chinese market years ago, I thought -- hence Baidu largely taking its place there.

It would be telling if despite that rejection, they were still open to taking direction from Beijing. Google at one point was fairly friendly with US DoD. Clearly the national loyalty of multinationals isn't guaranteed.

Expanding the foreign ownership rule to include social media platform companies (and, frankly, any strategically-important technology company in general) seems like a no-brainer.

Other countries should logically do the same. If Burma/Myanmar doesn't like what Facebook is doing there, they have demonstrated the capability to shut it down on multiple occasions. Setting aside that their government is a basically-illegitimate military junta, if I was them, I sure as fuck wouldn't let a US tech company operate within my country without a significant local presence that I could exert influence on.

"Dictatorships are bad" is not the game-over argument that it once was, maybe 20 years ago.

The Chinese aren't just competing against the US for control of some islands and sea lanes here and there, they are putting their political system -- which is de facto a dictatorship selected periodically by a small ruling clique -- as an alternative model to democracy. One that can compete with and defeat democracy, in fact.

And to be blunt, it's not clear to me that they are losing. We in the US have put ourselves at a disadvantage w/r/t China over and over again, relying ostensibly on the magical power of democracy to always win the day. As far as I can tell, it's straight-up magical thinking.

If we do not take China seriously as a threat to democracy, not just internally to Asia but as an aspirational model of society and the basis for legitimate government, I think we risk losing.

Why we would allow a propaganda outlet of what is effectively an enemy state to operate in the US, and why we would allow technology transfers and other advantageous trade arrangements, is mind boggling to me. Sure, the 'marketplace of ideas' sounds great on paper, but not when the other people don't believe in the same things. That sort of treatment -- access to the US market, both economically and that of ideas -- should be reserved for polities that at least have signed-on to the basic concepts that the US is built on.

That's only true if only a small percentage of users actually use that particular ad-blocking strategy. If a significant number of users did, then it would be a real concern.

Although I think YouTube et al see an increasing amount of revenue and viewership coming from apps... and if they could, I suspect they would kill their web sites in favor of apps where they have much more control.

I don't mind PiHole, but it doesn't do nearly as good a job of ad blocking as a "real" browser plugin does.

The amount of crap that still comes through when I turn off uBlock -- but am still using PiHole DNS, which is always active on my home network -- is a lot.

Honestly I don't think DNS-based adblocking is really viable, long-term. It's just too easy for advertisers and dirtbag website operators to get around it. There's just no substitute for controlling the retrieval of content elements and their presentation from the application where the user is doing the interaction.

This is why keeping browsers out of the hands of adtech corporations is pretty important; once they control that presentation layer it's largely game over. They can just tunnel all the traffic through a single connection to a relay server, if they want to, and there won't be shit a user can do about it once they've decided that's the only browser they can use.

I get that the WSJ needs to run these sort of pieces every so often to sell papers, but "No One Wants [Whatever]" think-pieces should be treated the same way as the overly-speculative question headlines that led to "Betteridge's Law" in the early 2000s.

Office culture, like the rest of culture, is cyclical. People are reactive, and tend to move in herds. Given an intense external stimulus like the pandemic, we should expect to see waves of behaviors propagating out through time for at least the next few years.

During the pandemic, nobody was in the office, so right after the pandemic, there was a boom in office socialization (in some quarters). Now, apparently according to WSJ, the pendulum is swinging back. This isn't indicative of very much, except that there was a big shock to the office-work social system and it's still not stabilized.

In particular, it's not especially suggestive of what the steady state will be, once these perturbations diminish.

I think we probably have several more back-and-forth cycles around everyone-works-from-home! vs. 40-hours-in-office-or-bust!, before the market works out what the relative value is (to the employer and the employee) of having people in the office and paying for a physical office for them, vs. the flexibility of working from home and of having a potentially international hiring pool. There are benefits and hazards for both parties in either arrangement.

My personal feeling, just based on how the job market has tended to stratify in the past, is that we'll see multiple approaches within each industry/sector, based on how fundamentally creative the work is.

The organizations in a particular sector who are really pushing the boundaries of that industry, who are actually advancing the state of the art, will likely be in-office cultures, because nobody has yet found a substitute for in-person communication particularly as it applies to creative problem solving. But those will represent a small tip of the workplace iceberg, sitting atop (and demanding higher rates than) a larger volume of companies whose work simply isn't that fundamentally creative or challenging, and have to compensate by offering flexible / WFH arrangements, and actively court the employees who are more interested in work-life balance than in working in their industry's version of the Manhattan Project.

That explains why the K8S defaults are bad, but why use K8S at all here?

Personally it seems like a lot of shade-tree server admins are way too eager to bust out much more tooling than is actually necessary for many tasks, just because it's the way that $BIGNAME company does it.

Realistically, most people running a personal or small community's IT system aren't going to need the sort of crazy scalability that container orchestration systems are designed to provide. And if you're not running them at significant scale, the containerization and orchestration-system overhead are often quite significant fractions of the overall resource footprint. Plus there's the unnecessary complexity due to all the levels of abstraction that just don't need to be there.

E.g. for a Mastodon instance, I wouldn't touch Kubernetes or complex orchestration unless I was out of other, more traditional options for scaling. The server side is already broken into a number of components (RoR app, PosgreSQL, Redis, Sidekiq, node.js) which you can separate out onto their own servers, and from there each component has preferred ways of scaling based on need. And while nothing is safe from failure, backing up a bog-standard PostgreSQL VPS is a lot more straightforward than K8S.

If you're doing deployments dozens of times a day, of course automation is desirable. But if you're doing it once, I suspect most people would be hard-pressed to make back the investment of time and additional testing required (well, should be required) of working through a complex container-management architecture.

Interesting, as I have had the opposite experience. There are lots of documents that I have to work with -- most created originally in Word 2007, I think -- with very intense formatting, forms, embedded charts and other crap, and Google Docs makes a total hash out of them.

LibreOffice, OTOH, pretty much looks just like they did on the original.

The one issue I've run into is font substitution. The fonts that LibreOffice uses by default if the actual Microsoft fonts aren't installed are not, at least IMO, very good substitutes. They don't look great to me, but worse they seem to be very different in terms of character/word width, so everything gets reflowed to hell and back. But assuming you install the actual MS fonts, the results seem quite good.

There's really no technical reason why imagery like that couldn't be contributed, and IIRC Google does use municipally-owned imagery in its products. A single city might not be a big enough source for them to bother, I don't know, but I know particularly in Europe I have seen copyright notices for national and regional governments when looking at imagery.

Though there are a lot of sources for satellite imagery right now; Google may not be that hard-up for new stuff. I suspect the commercial vendors they work with probably image the entire CONUS area every 12 months or so.

The imagery that would seem to be more in-demand would be the aerial photos used at very high zoom levels. I'm not a geospatial expert but I think these images are combined with some sort of LIDAR or multi-spectrum imagery to have height maps in tandem with the visuals. That strikes me as pretty expensive to obtain.

I agree with everything except I don't think I would have called out OrangePi as the worst of the lot -- at least not anymore.

They seem to have basically outsourced their software maintenance to Armbian, and if that relationship holds it's probably a win-win. Armbian's build system is really nice, IMO.

FriendlyElec are borderline; they make nice hardware but definitely seem to take a "here's a kernel we got to boot once, good luck!" attitude towards software support. Some of their boards are supported by Armbian but often without key features due to lack of documentation or binary blobs.

Below that is a vast sea of largely-anonymous Chinese-based hardware companies who drop a design (sometimes really neat) into the world, then disappear without a trace. Mostly I think these are designs whipped up quickly to use up spare parts, or originally designed for embedded use in a particular product and being sold on the side. (I've definitely seen 'development boards' that were clearly designed for security cameras or TV decoder boxes, f.ex.) But you are buying yourself a new hobby if you decide to get one.

Anybody not a pure hobbyist left the RPi space long ago.

I suspect a lot of hobbyists have left too, and that's why there's so many not-quite-knockoff SBCs on the market (ranging from the respectable OrangePis to weird fly-by-night stuff on AliExpress made by a company that's already out of business before your order arrives).

But I don't know how many people are using alternatives because they want to use alternatives. Raspberry Pis have been like hen's teeth for a couple of years now. If you have a NIB Pi4, until recently you could sell that sucker and probably by 3 OrangePis instead.

But if RPis were the same price? I think they'd sell like hotcakes just like they did a few years ago, and you'd see them in every random project on Youtube. I don't know of any SBC (other than very high-end industrial embedded modules) that are as well-documented as the Pis.

I'm not sure the Pico and Pico W are going to make as much of a splash as the original did (it's harder for people to get started with an overgrown microcontroller than it is a tiny PC), but I expect them to sell very well, too. Maybe they won't show up in every disposable pregnancy test and lightbulb like the ESPs and Nordics, but I suspect we'll see them in some commercial products too.

I guess... but if industrial is really their market, I think they need to up their game in terms of documentation. "Real" industrial embedded modules tend to come with reams of documentation covering almost down to the silicon. You pay for that, of course, because writing documentation costs money, but so is having your engineers spend time twiddling bits and poking at undocumented registers, trying to figure out why your sample code works and theirs doesn't.

That said, I've seen some neat shoestring-budget prototype projects done on BB hardware, so there's some market there. But it seems like their stuff is a bit expensive for low-end learners and hobbyists and missing some of the niceties you get if you convince your boss to buy a ComExpress-based industrial module, or (if you really twist their arm) something like the Arnouse BioDigital SBCs.

Having random people reverse-engineer your hardware in order to document it seems... a lot less ideal than having the people who actually built it in the first place reveal some of the information that they must already know and probably have written about it.

Yes, a hundred times yes.

I've been down this road and while it was certainly an interesting learning experience in some of the mechanics of the kernel build process, module dependencies, etc. etc., it was not necessarily productive in moving the projects forward that I wanted to do with the temptingly-cheap Chinese SBCs that I couldn't resist buying.

Having learned that lesson, now I won't order something unless it's formally supported by someone like the Armbian project (or Debian, or OpenWRT, etc.). And as interesting as some of the niche SBCs are, sticking to boards that have a broad userbase saves a lot of time when you run into weird errors.

you could probably put the obsidian vault directory inside of dropbox

I've done this and it seems to work fine.

In theory I guess you could end up with sync conflicts if you are literally editing the same note on two devices at the same time, in which case Dropbox will create a "Conflicted Copy" which will pop up in Obsidian so you can resolve it manually.

But in practice, because Obsidian saves pretty much constantly, and Dropbox syncs pretty much constantly, in a typical connected office use case you don't run into this much. If you work offline a lot, you might need to think about a more structured workflow (i.e. using Git). But for me it wasn't worth the hassle to commit/push every time I wanted to switch devices. Dropbox (and presumably the many Dropbox-like folder-sync tools) worked fine when I was testing it out.

Perhaps, but setting aside the philosophical point, Evernote was nowhere near "done".

Their 'new' client software (Electron-based, of course) never even achieved feature parity with their 'legacy' client software. The mobile app wasn't exactly screamingly performant, to put it nicely. Really basic core use cases, like creating a note, typing in a title and some content, tagging it with a keyword, and saving it, required a lot more clicks than it seemed to me like it should. Hierarchical tags, while technically supported, seemed like a weird add-on that never got full support. And Penultimate -- their tablet-centric app that stored data in your Evernote account -- hasn't been updated in several years; I'm actually impressed it continues to work.

There's plenty of room where they could have built new features, if they'd wanted to. Off the top of my head, I'd have liked to see Markdown support instead of their quasi-HTML WYSIWYG editor (some versions of the thick client had a subset of Markdown-like syntax but others didn't). Penultimate would have been great if it had on-device OCR / handwriting recognition, or even just a way of tagging specific pages or page-regions with keywords.

I think there's a lot of room in the notetaking space. I'm still waiting for an app that isn't a glorified text editor or a drawing program, but also doesn't lock your data into some unparsable binary format or obscure graph database behind the scenes. I want to take notes, using a pen, on a tablet, that might or might not be text, and then I want to annotate the shit out of those notes and keyword them and cross-reference them, and I want the whole thing to be searchable and I want the handwriting recognition to not suck, and I want all of this to be encrypted at rest and in transit, and I want native clients for all major desktop and mobile operating systems.

So, yeah, I don't think notetaking is done quite yet.

Yeeeah, no thanks. I don't want my hardware running automatic upgrades of any sort.

I'd probably trust an open source team like OpenWRT's more than a shitbag company like my telco, or only-slightly-less-shitbaggy cableco, but as others have noted an open source effort likely won't ever have the resources to do it anyway.

I deeply dislike the cableco's ability to push firmware files to my DOCSIS modem, and I'm certainly not letting them any further into my network than that.

Sure, having your router get security updates is nice, but as a tradeoff for that, you're effectively giving your ISP a complete view into your home network. They could install firmware that gives them MAC addresses and then tags packet traffic by device, giving them a device-by-device, and hence person-by-person, packet-level (or at least connection-level, in the case of properly encrypted traffic) view of who is looking at what, all the time. With a more sophisticated beam-forming AP, they could physically track your devices (and thus people) around inside the house.

That data would be phenomenally valuable, especially as ad-tracking systems get shut down. And they've realistically got at least a few years of absolutely bald-faced shut-up-and-bend-over abusive behavior before Congress would get around to regulating it, and that's given both the worst-case for their behavior and the best-case for regulators. Very likely they could do shit like that indefinitely, especially if they own the router hardware. Who knows -- maybe they already are? It's not like they'd have to tell anyone in the US if they were.

I think I'd rather take my chances with random ransomware gangs than the guarantee of allowing a hostile actor -- my ISP -- into my private network. Those fuckers can stay where they belong, on the untrusted side of the firewall, pushing packets and nothing else.

Not an interesting question at all, IMO. The government is not required to protect you or make you whole, if you invest in an enterprise that the government later decides to prohibit, or makes illegal, or decides to regulate in some other manner.

I mean, think that through for a second: if the government had to compensate everyone for the negative impact of legislation, it would be almost impossible to pass laws. If my town says I can't burn tires in my back yard, do they need to pay me to shut down my tire-burning operation? What if I don't even have a tire-burning operation, but I could have started one, except now I'm prohibited from doing so... did they impair the value of my property by prohibiting a potential use? What about all the other things I could have done with my property, absent any pesky zoning restrictions, Clean Water Act rules, or just centuries of common law precedent? Do they have to pay me for the impairment of each of them, each time a law is passed that eliminates a hypothetical option?

No, of course not, because that would paralyze government and be ridiculous.

The government has no responsibility to make anyone whole if they decide someone's business model is counter to the public good and make it illegal. It's on my investors to take into account the risk of legislation that might impact the business and factor that into their investment decisions and subsequent valuation of the business. If they do that poorly, or fail to recognize a legal risk, that's on them.

This is literally why sovereign immunity is a thing.

Not at consumer price levels, no.

There are companies that make security hardware here in the US, but the market is mostly very high-end government and military customers. And TBH mostly they are still using Chinese components, just assembling stuff here in the US and marking the price up enough that they can justify calling it 'made in USA' by virtue of the value-add. Sometimes the software is coded or at least audited, though.

You can avoid the worst Chinese-made hardware if you look for "NDAA compliant" rather than US domestic manufacture. NDAA compliance means that a product isn't made by a number of prohibited Chinese suppliers who are known to be very thoroughly compromised (as opposed to the average level of compromise that you should assume most companies in China have... but China is a big place, so that difference isn't nothing).

Axis and Bosch both have NDAA-compliant product lines.

Sure, and that's probably happening as well.

But it shows a level of not-giving-a-fuck if they're just leaving not-even-well-hidden "backdoors" in, so people in China can get access.

It suggests to me that the software engineers writing this stuff don't really think of ByteDance US or the US version of TikTok as being any different from ByteDance China. Because of course they don't: I don't think ByteDance itself, or its leadership, does. The whole idea of separating the company internally is a sham, and it's almost always a sham when companies claim to do internal firewalling or controls like that. (See also: pre-2008 financial companies that did both consulting and accounting/audit, and claimed they never talked across that line. Of course they did!)

TikTok is a shining example of both China being China (no real private/public sector separation, lying as standard practice, economic policy is just war by other means) and the US being the US (everything is for sale, everyone's loyalty can be rented, all laws are negotiable, workers / average people exist to be exploited rather than protected, if it's profitable it can't be that wrong)... and we wonder why it's a trainwreck for average users.

The US government is and has always been reactive, not proactive.

About the most forward-thinking the US gets is writing the occasional contingency plan. Everything else is done in haste once a serious problem becomes plainly obvious to everyone, and people (deep-pocketed ones especially) start screaming to their elected representatives to fucking do something about it. Then and only then do the gears start to turn.

We can still fix the issue now though, by creating a targeted law against them.

That's not a great idea, since it will invite a lawsuit on the (potentially valid) grounds that it's a de facto bill of attainder. Which the US has traditionally taken a dim view on for very good reasons.

Better would be if it prompted a more general law about foreign ownership of corporations which have access to large amounts of information on US persons, regardless of how it is obtained or who they are.

As a US citizen, I don't want any government that I don't have input into -- even the relatively indirect and less-than-satisfying input of casting one vote among millions -- compiling a dossier on me, and I expect my government to do what it can to make that at least somewhat difficult. (And yes, I am aware there is no way to stop it completely. If the Chinese government wants to task its intelligence service to compile a dossier on me, there's nothing much that can be done about it. But let's at least try to raise the bar on the difficulty and effort involved. The more difficult and expensive, the more illegal, and the more internationally frowned-upon the task becomes, the harder it is to do at scale to millions or billions of people at once.)

Forcing ByteDance to host the data in the US, on Oracle's servers or anyone else's, doesn't mean a lot if there are a bunch of people in China with the login to those servers. Who has access to the data and the various administrative controls over it are more important than where it physically resides.

ByteDance has claimed that their US operations were administratively firewalled from their Chinese ones, and then it's been repeatedly shown not to be the case. At this point they have lost all credibility about their ability to 'firewall' or internally control access to user data, probably because they (or certain parts of the company) don't really want to.