HN user

Nadya

4,139 karma

nadyanay.me - U+26A5

Democracy is totalitarianism. Freedom is oppression. Censorship is freedom.

[ my public key: https://keybase.io/nadya; my proof: https://keybase.io/nadya/si gs/lklP5B4B7JREUYCzdbw60w0u3esviheCxECPU0D9TgU ]

Posts12
Comments2,477
View on HN

Yeah, I have a never ending need of things I could easily make myself I I could set aside 7-10 hours to plan it out, develop and troubleshoot but are also low priority enough that they sit on the back burner perpetually.

Now these things are being made. I can justify spending 5-10 minutes on something without being upset if AI can't solve the problem yet.

And if not, I'll try again in 6 months. These aren't time sensitive problems to begin with or they wouldn't be rotting on the back burner in the first place.

In the story the engineers weren't designing a tool well-suited for the customers, but for whatever abstract scenarios they had in their head.

A joke exists about how developers will never be displaced by AI because that would require clients and/or project managers to accurately describe what they want the AI to build. On one hand that is extremely egotistical of developers. On the other it is also factual.

To my understanding of the story the developers had designed what was being communicated to them by someone who described what customers asked for and not what the customers actually wanted or needed. Nothing to do with what the engineers thought customers wanted and everything to do with what project managers had expressed to the engineers about what customers wanted. Speaking with the customers directly gave them a better idea of what was actually being asked for. So they built that instead.

My takeaway from the story is to fire the project manager. Not to make devs call clients.

If a user holds an ice cream cone upside-down and their ice cream falls to the floor, do you blame the user for not holding their ice cream cone upright or the creator of the ice cream cone for a stupid design that allows the ice cream to so easily fall out of the ice cream holding device and onto the floor?

I find far more often that bad UX is the result of someone trying to use a tool for something it wasn't designed for. They might even clob several different tools together in an unholy abomination to get it to do what they actually want instead of having a tool built to do precisely what they want (and once that tool has been built - people will inevitably misuse it to do things other than what it was designed for and then complain about its poor UX for doing those things).

Yes, but none of that is truly unique. The odds of a doppleganger sharing my name are astronomically slim but my looks, voice, interests, personality, etc. are not truly unique to me.

For an example, what of voice impersonators? Sounding like Morgan Freeman is not unique to Morgan Freeman. What if a soundalike legally changes their name to Morgan Freeman? What if a lookalike changes their name?

I'm familiar with the existence of such laws but less so with how they are enforced or how they can even be enforced at all. The laws have never made that much sense to me.

The argument of likeness seems odd to me because there are at least a dozen people who might look almost exactly like you who are alive somewhere in the world.

What if I give explicit permission to use my likeness but my lookalike demands it can't be used? We're both dead. Do my wishes not get respected because someone who looks like they could be my identical twin had other wishes? Whoever's estate has the deeper pockets?

See photography by François Brunelle. The similarities went past appearances too. Many of the stranger dopplegangers had similar hobbies and even similar personalities. So if an AI recreation looks like me, acts like me, and has the same hobbies as me that means nothing unless someone is trying to claim it is me (rather my likeness).

Very useful for flagging any O(n^2) that make assumptions about the size of N because N is not expected to exceed a certain size. Especially for when N inevitably exceeds that size.

Documenting it saves the poor dev doing profiling in the future a bit of effort so they can come up with the better solution that you failed to come up with when writing the code.

Often times code has to be written and committed and I don't have the time nor the brains to come up with a novel solution that solves a future performance issue that is not yet and is not expected to ever become a performance issue.

Rust is like walking across a mine field with all the mines flagged for you. You can dig up the mine and remove the flags over time. Or at least know to avoid stepping carelessly around them.

In C you only see the flags people know of or remembered to plant. There's an awful lot of mines left unflagged and sometimes you step on them.

It's very obvious to me which would be more safe and I find myself questioning why it is isn't so obvious to others.

I'm a Memrise beta member w/ lifetime premium access for my contributions to the site in its early days. I cannot recommend anyone use Memrise for anything nowadays it has been so heavily enshittified. In fact, I recommend against using it in favor of Anki (Memrise's biggest strength over Anki in the early days was the community mnemonics and courses (Anki equivalent "community decks") - none of which really exist in any way today).

I tried following the modern Japanese track on Memrise and was appalled at how bad it is nowadays.

I would greatly appreciate if you engaged with what I wrote and not what you think I wrote if you're going to make the bold claim that I'm not engaging in good faith.

Absolutely nowhere did I equate writing a book to grooming. I equated selling the book in the greater context that "providing children with potentially harmful/dangerous information should be illegal because it grooms them to commit harmful actions to themselves or others" and this context would carry the implications that by "selling" I am referring particularly to "selling it to children" since "providing children with potentially harmful/dangerous information should be illegal because it grooms them to commit harmful actions to themselves or others". With my argument being would it be criminal for an AI but not for a human?

So to clarify the argument: Writing the book is fine. Selling the book to adults is fine. Adults reading the book is fine. But if providing dangerous information to children should be made illegal - how would selling such a book to a child not be considered illegal? Because it was written by a human and not an AI?

After wasting the better part of a decade on speed reading as a teen and using speed reading tools I can only find myself to agree with them. Remove multiple-choice questions and ask questions about the material and speed readers comprehension crumbles apart to such a degree it is difficult to call what they do to be "reading".

There are quite a number of studies on this, but I'll reference a blog that does all the referencing for me [0] since their experience and thirst for knowledge that led them to later be an advocate against - rather than an advocate for - speed reading is basically a 1:1 match of my own.

500-600 WPM is the upper limits, 99.99% of people claiming otherwise are bullshitting, I always leave that 0.01% because some people are literally just built different and are truly one-of-a-kind (or one-of-maybe-a-dozen people on Earth). Anyone claiming such speeds is going to be under a lot of scrutiny the same way I'd be skeptical of anyone else claiming to be in the top 0.01% of anything. If someone tells me they're a Top 10 Challenger ranked League of Legends player I'm not just going to take their word for it without some solid evidence.

[0] https://www.scotthyoung.com/blog/2015/01/19/speed-reading-re...

So selling the Anarchists Cookbook is illegal? Being a YouTuber targeting teens for <extreme political positions> is illegal? This is honestly news to me given how many political YouTubers there are who are apparently criminals?

Given some of the examples I'm not so sure a human would be charged for saying the same exact things the AI has said. Without an actual push to suggest violence and even that's difficult to prove in cases where it does happen (eg. The cases where people pressured others into suicide or convinced them to murder)

People can give children terrible information too and steer/groom them in harmful directions. So why stop there at "AI" or poorly defined "algorithms"?

The only content children should see is state-approved content to ensure they are only ever steered in the correct, beneficial manner to society instead of a harmful one. Anyone found trying to show minors unapproved content should be imprisoned as they are harmful to a safe society.

History of Hangul 2 years ago

It's such a common aspect of languages too that many people don't even realize when they're doing it in their native language!

People get lazy - especially natives who don't get confused because it's how most natives will talk. For example, every word ending in "ing" in your comment could drop the "g" sound when spoken. Plenty of English speakers do that when speakin' and not many people would think anythin' of it until a frustrated person learnin' English asks why nobody is pronouncin' the endin' "g". Droppin', changin', and blendin' sounds is why learning a language by listenin' to natives speakin' is so important instead of crammin' textbooks all day.

Some might consider this a regional thing/accent and I'd argue that it both is and isn't. To the extent I tried to illustrate it would likely get seen as an accent but the occasional droppin' of it is somethin' I've heard across so many different English accents that I'd argue it isn't only an accent thing.

In the US it's mostly associated with a Southern accent and in England it would be the English Midlands like Brummie or Mancunian.

History of Hangul 2 years ago

Every now and again a site exists that has a massive community, tons of resources, ways to speak with other learners, ways to meet language exchange partners, and are greatly successful. Then all of that gets gutted for what is essentially a worse version of Anki but for the web when the company runs out of funding and has to start turning a profit somehow. This burns the community and the people providing most of the value move elsewhere.

It's happened to italki (now iKnow), Memrise, DuoLingo, and a few sites that were so short-lived I no longer remember what they were called.

My takeaway is that language learning apps are a lot like dating apps. They profit less if people actually learn a language and so can't be too good at their job because they'll bleed users faster than they can gain them - similar to dating apps. It needs to work just well enough that users are tricked into believing it is working but not so well that it actually works for most people.

It seems like the ETA before enshittification begins is about 2~3 years. If you're an early enough adopter you might actually benefit from it but you have to be willing to jump ship and not fall for the engagement/gamification tactics that keep you sticking around after it has stopped providing any value.

I spent way too long 'watering my garden' on Memrise before I looked around and noticed all of the once useful community-providing mnemonics were gone, you couldn't correct bad definitions anymore, it was difficult to actually speak to anyone else in the community (unless you could find them on the forums), and eventually I stopped using it altogether. The community I had signed up for and was a huge part of Memrise's success no longer existed.

History of Hangul 2 years ago

Anki for vocabulary building, Ryan Estrada's comic for learning to read Hangul (https://www.ryanestrada.com/learntoreadkoreanin15minutes/) as it sticks true to its promise. Over 8 years ago I spent 15 minutes learning how to 'read' Hangul. To this day I can still slowly sound things out and, at the least, read people's names. It truly is a fantastic writing system although I do sometimes struggle with which vowel is which that's 100% an issue of only having spent 15 minutes learning.

Unfortunately I can't help much with learning grammar as I never dove into actually learning Korean due to a dislike of how it sounds. There's the "Tae Kim Japanese Grammar"-like approach for a Korean grammar guide at: https://www.howtostudykorean.com/ although I'm not a big fan of how overly simplified (and sometimes wrong due to the simplification) Tae Kim's approach for Japanese was. So I can't attest as to whether How To Study Korean makes the same mistakes or not.

As for writing - Korean is simple enough to read/write that you can simply find any Korean news source and practice writing the sentences as you read them.

You could also try checking the Korean-learning subreddit out as they have a lot of resources in one of their pinned threads: https://www.reddit.com/r/Korean/comments/hw4gy0/the_ultimate...

And this is how you end up with rewriting the world and spending more time rewriting dozens of existing libraries to avoid adding them as dependencies and less time working on the problem you're actually trying to solve because you're fixing the same dozen bugs that the first person already went through the trouble of fixing for you had you simply used their library instead of eschewing it and having to learn everything that they had already learned for you. Often times because the problem space is deeper than you could have known before getting into the weeds and hopefully you don't get bit by sunk cost and decide to do yourself a favor and just use a library instead of continuing to work on solving problems that aren't related to what you set out to do.

There's a balance to be struck between LeftPad scenarios and "Now there are 37 competing libraries".

The site was taken down earlier today. Mail service remained up for some time. Sent myself a test email - seems I managed to migrate most of my emails over just in time as I'm no longer getting mail.

I used cock.li since about a few months after its initial opening. It was reliable enough and I trusted Vincent had his heart in the right place.

Even if it comes back up - I have no plans to migrate anything back. I've been self-hosting my email for a few years now but never took the time to reset my email everywhere until today. I wish I started about an hour sooner than I did as there are 2 accounts now stuck in potential limbo assuming the domain doesn't get moved elsewhere or temporarily hosted so people have time to migrate away from it.

So long and thanks for all the fish.

There are literally hundreds if not thousands of studies about precisely how to navigate people in aggregate and take advantage of every little bit of human psychology to maximize profits. It's not about people being mentally weak but about corporations and marketers knowing how to best break past people's mental barriers.

You are not unique among the millions of people. Advertising works - and it also works on people who adamantly believe that it doesn't work on them. Often because people think of themselves are more intelligent than the average person.

Almost nobody claims to like advertising. They might prefer advertising over subscriptions as a form of payment - but not because they like ads but because it doesn't take money from them directly but rather indirectly. Yet despite the almost universal hatred of advertisements its the worlds largest business.

Advertising would not be in the top 10 of worlds largest businesses if it didn't work on hundreds of millions of people. It bears repeating. You are not special. Neither am I. Despite my best attempts at avoiding advertising I can nearly guarantee it affects my purchasing decisions perhaps without my awareness of it at all. Subconsciously there like a parasite. Because that's how advertising actually works.

Nobody sees an ad and goes "I want <ad product>". That's not how advertising actually works but it's how people think it works. 3 months down the line you're buying beer for a party and buy a pack of Heineken without thinking too much about it. And that is when they have won.

There are very few forms of advertisement that I don't have a major problem with. Public space bulletin boards, word of mouth (non-sponsored), dedicated infomercial spaces (no videomercials w/ the comedy-like over the top failing at life to try and sell the product).

Price, product/service, why you need it and why yours over any competitors. Non-targeted ads by default unless the user opts in for targeted ads.

Mom & pop shops are totally capable of emotion-targeted advertising and it's a problem when they do it too. Corporations just use it more.

For example - how does one advertise perfume over television? A product that requires you to smell it? Emotional manipulation and promise of fantasy. Nothing to do with perfume. A proper commercial would at least try to explain the smell - maybe mention the high/low note fragrances used. Nope. Beautiful models. Lavish party. Brand name.

Fixing advertising will never happen. Advertising runs the world because it already won the war.

Most forms of advertisement should be considered criminal, as most modern ads are borderline psychological warfare against a population that doesn't even understand they're at war and losing because the effects aren't immediately noticeable and are very rarely directly physical.

Tear down someone mentally until you can get them to agree to part with their money. Call them ugly, call them fat, call them depressed. Show them how boring and miserable their life is before <product> is a part of their life. But only ever indirectly - if you're too direct the negative emotions they're feeling will be associated with your product instead of themselves. Tease them with beautiful people having fun and enjoying life. This could be you if you buy <product>. Happy and successful. Surrounded by friends laughing and smiling. Remember - ending on a happy emotion makes people associate those feelings with <product> which will increase sales of <product>. Cute polar bears. Drink coke.

It's a form of assault and I refuse to pretend otherwise.

The contexts of security by obscurity is usually in regards to data that would attract people who would specifically target you for being a mark that will make them a lot of money rather than opportunistically target you because you are an easy mark that will make them a quick & easy profit of unknown value.

If someone wants to rob you - a door lock isn't going to stop them. Likewise if someone wants to pwn you - a little obfuscation isn't going to stop them.

Security by obscurity only works in the case that you aren't known to be worth the effort to target specifically and so nobody bothers. Much like very few people bother to beat my CTF. I'm sure if I offered a $1,000 reward for beating it the number would increase tenfold because it is suddenly worth the effort to spend a bit of time attacking. But as it stands with no monetary incentive the vast majority (>99%) give up after a few days.

Can you cite an example where a company was sued over bad code? I want to agree with you and agree with your reasoning (which is why I upvoted you as I think it is a good argument) but cannot think of any example where this has been the case. Perhaps in medical/aviation/government niches but not in any niche I've worked in or can find an example of.

The publicly known lawsuits seem to come from data breeches and the large majority of those data breeches are due to non-code lapses in security. Leaked credentials, phished employee, social engineering, setting something Public that should be Internal-only, etc.

In fact, in many proprietary products they rely on FLOSS code which resulted in an exploit and the company owning the product may be sued for the resulting data breeches as a result. But that's an issue with their product contract and their use of FLOSS code without code review. As it turns out many proprietary products aren't code reviewing the FLOSS projects they rely on either despite their supposed potential legal liability to do so.

I say that because it's how safety and security work everywhere else - they're created and guaranteed through legal liability.

I don't think the legal enforcement or guarantees are anywhere near as strong as other fields, such as say... actual engineering or the medical field. If a doctor fucks up badly enough they can no longer practice medicine. If a SWE fucks up bad enough they might get fired? But they can certainly keep producing new code and may find a job elsewhere if they are let go. Software isn't a licensed field and so is missing a lot of safety and security checks that licensed fields have.

Reheating already cooked food to sell to the public requires a food handler's card which is already a higher bar than exists in the world of software development. Cybersecurity isn't taken all that serious by seemingly anyone. I wouldn't have nearly as many conversations with my coworkers or clients about potential HIPAA violations if it were.

Codebases outside of security-contexts are rarely audited, much less professionally so. The culture of code reviewing PR's from 14 years ago is a little different from today and is also why any "quick hacks to make things work" should always have some form of "//HACK: REVIEW OR REMOVE BY <DATE>" attached to it to make it easy to find.

From a security perspective there are only two kinds of code bases: open & closed. By deduction one of those will have more eyeballs on the codebase than the other even if "nobody looks".

Case in point: It may have taken 14 years but someone looked. Had the code base been closed source that may never have happened because it might not have been possible to ever happen. It's also very easy to point to the number of security issues that never made it into production because it was caught in an open source code review by passerbys and other contributors while the PR was waiting to be merged.

The fact it was caught at all is a point for open source security - not against it. Even if it took 14 years.

As opposed to the “security” of closed source software? Where severe vulns are left in as long as they aren't publicized because it would take too much development time to justify fixing and the company doesn't make money fixing vulns - it makes money creating new features. And since it isn't a security-related product any lapses in security are an "Oopsy woopsy we screwed up" and everyone moves on with their lives?

Even companies that are supposed to get security right have constant screw ups that are only fixed when someone goes poking around where they probably shouldn't and thankfully happens to not be malicious.

The issue you're missing is the scale of the cheating.

When it is some small percentage of games you might shrug, hope you don't run into the cheater again, and move on to the next game where nobody is cheating. A few matches of your day get ruined but you still get to enjoy >95% of them so it's overall still a good experience. It has a very small impact on your enjoyment but you can move on and still enjoy most of your time.

It becomes a problem when there are so many cheaters that you encounter one in nearly every single game you play. Making it nearly impossible to play or win because the aim botting, wall hacking, infinite ammo, one-hit-kill, teleporting, invincible hacker is mowing down you and your entire team and the round ends in a few minutes. Except now it is 5 out of every 6 games you play and you hardly get to enjoy playing.

Additionally, back in the day you could leave matches without really getting punished for it. If you encountered an obvious hacker you could just leave and rejoin a new game. Now you get punished for leaving matches and might have to sit out a 15-60 minute timer if you leave too many games. Mix that with some high percentage of cheaters and you might be sitting in lobby waiting to play the game more than you're actually playing the game.

Let's say you enjoy playing Chess. How long would you enjoy playing against Alpha Zero - especially when expecting to play against someone your own ELO? At what ratio of playing against people cheating with Alpha Zero would you stop bothering to try and play Chess? I could tolerate it occasionally but if every single person I was playing against was just using Alpha Zero I'd stop trying to play Chess at all. It's no fun to lose every single time because the other person is always cheating.