HN user

OkayPhysicist

5,525 karma
Posts0
Comments2,227
View on HN
No posts found.

Here's KeePassXC being threatened with blacklisting over granting users control over their own data:

https://github.com/keepassxreboot/keepassxc/issues/10407#iss...

Here's the most readable reference to playing favorites on passkey vaults I could find from the FIDO Alliance (the previously mentioned 'cabal of evil').

See Section 2.2: "Validating FIDO UAF authenticator attestations against the configured authenticator metadata to ensure only trusted authenticators are registered for use. "

And Section 2.3: "Verify attestation assertions made by the FIDO UAF Authenticators to ensure the authenticator is authentic and trusted. Verification occurs using the attestation public key certificates distributed via authenticator metadata. "

https://fidoalliance.org/specs/fido-uaf-v1.2-ps-20201020/fid...

Basically, Relying Parties (the sites you are logging in to) are expected to allow/disallow certain passkey authenticators (the devices or software that hold your passkeys), based on registration and trusted lists. The FIDO Alliance can use entry into those trusted lists as a cudgel to force compliance with the standard. Effectively, the standard is that users must be locked into to proprietary ecosystems, unable to escape.

The cabal of evil behind the passkey project actively have KeePassXC on their naughty list fore deigning to allow users to access their keys, and specifically included in the standard the means to discriminate between different passkey vault providers. It is the opposite of an open system, and cannot, under any circumstances, be trusted. Do not use passkeys, tell other people not to use passkeys, and make sure to not let shills astroturf conversations about passkeys unopposed.

I've taken up the strategy of telling any less-technical person who asks me about passkeys that they are the mark of the beast, intrinsically evil, and should be avoided at all costs, and I encourage all y'all to do the same.

Maybe, at some distant point in the past, there was a plan for a whole system of intercommunicating implementations of passkeys. That is no longer the case. The moment that they decided to include the information necessary to only allow the use of certain passkey vaults in the protocol, and then use that capability to threaten to lock out certain vaults that dared to let users actually be in control of THEIR OWN DAMN CREDENTIALS, it invalidated the entire project in my eyes. Passkeys cannot be trusted, they are designed to let entrenched powers hold your authentication hostage, and should under no circumstances be allowed to take root in the computing ecosystem.

That's how my friends and I play Civ. We had an issue in the beginning with players getting knocked out in the first day of a game that might go for 5 or more play sessions, so we devised a scheme where a player could be forced into vassalage. They can no longer win outright, they merely exist to support the conqueror. The conqueror gets to overrule any decisions made by the vassal, but there's a bit of a gentleman's agreement that this power should be used sparingly, since it's annoying to be micromanaged, and it slows the game to a crawl. In particularly aggro games, the same vassal might be handed back and forth between two players still in the fight several times, because as a relatively underdeveloped nation, they represent a fair peace settlement.

Another nifty maze solving trick: Using flood-fill in Paint or some such, starting at the entrance, paint the wall on one side of the entrance red, and the other blue. You'll find that the border between the red and blue sections (the path where one wall is red and the other is blue) is the path to the exit. If there are loops, then you'll end up with uncolored squares, but you can just treat those as blue if you follow the red edge.

That seems like all the more reason it's worthwhile. If they're going to invest in the tools for 1% of their users, why wouldn't they invest in tools for 50% of their users?

The key observation missing from the conversation here is that you're being judged by Americans, where damn near everybody (save ~1% Native Americans) belongs to "an entire family tree" of immigrants. Race relations are one of those things that the US catches a lot of shit for because we've had to deal with it for the entirety of our nation's history, which lets us look at the attitudes alarmingly prevalent in Europe and go, "hey, that's like when my granddaddy was burning crosses in his neighbor's lawn. That's fucked up".

Congrats on falling for hundred year old propaganda. Fascism loves dancing around in the flayed skin of the socialism it violently represses. Go look into what they did to trade unions if you think the Nazis were some Worker's Party.

There is a very, very, very large gap between "open borders" and "keep all those disgusting foreigners out". I guarantee if you ask the average "immigration control activist" in most countries what the acceptable number of brown people to let into their country is, the answer is zero. Because the most active members of these movements are motivated by racism.

That's because they are wrong, immoral, and stupid. They're grovelling in the crumbs left over by the rich, and then getting pissed that there are other people groveling for the same crumbs.

Blaming immigrants is easy because you get an immediate base amongst racists (the immoral). They'll perk up at the sound of your dog whistles, and immediately start barking shit like "finally someone had the bravery to say what we're all thinking". That amplification of your message then reaches the reactionaries, who accurately look around at the world that is hell bent on destroying them, but are a little too dense to understand the web of systems that make up that world, and thus are eager for a simple explanation (the stupid). And once your message gets embedded in the zeitgeist from that lot, normal, relatively detached from politics people start hearing all this talk about immigration being a problem, and believe it (the wrong).

The same way you can't be frugal to make up for making poverty wages, you can't shrink the pool of disadvantaged workers to make them advantaged.

The US funds (and used to even moreso) scientific endeavors that stand to bolster the entire country all the time. Medical research is the obvious one, DARPA is the defense based one (though oftentimes defense is just a post-hoc justification for a lot of those), the Department of Agriculture is constantly researching improvements to the farming industry, the Bureau of Weights and Measures and the NSA fund cryptography research.

Research and development of new technologies often is a "rising tides lifts all ships"-type deal, which it is absolutely in the government's best interest to support.

For China, the best case scenario would of course be to control a locked-down best-in-class frontier model that the rest of the world becomes reliant on. The US seems to be beating them at that, and "Everyone is reliant on the United States" is a pretty bad scenario. A middle ground, positive outcome is that no one is reliant on locked-down closed models, so they're supporting that outcome.

It's really not that nefarious.

Devtools are built-in on Firefox, and this one is probably useful to more people than want to be looking at the JS console. I can't imagine the maintenance burden is unreasonable, it's just a combination of features that Firefox already has.

Users absolutely can edit HTML/CSS/JS without any other tools. That's what the entire dev-tools section of the browser is about.

I quite like the 2 wavelength light that sodium lamps give out. When I was in school, my university gradually went from all sodium to all LED, and it was definitely a loss. The complete loss of hue, combined with the soft buzz of a dying sodium lamp had a certain otherworldly feel to it. I found it quite relaxing.

"Vapes leading to smoking" headlines are always WILDLY misleading. If you look at the surveys they use to create those responses, they always include exceptionally low-frequency cigarette use. (think, "have you smoked a cigarette in the last month"). This captures habitual vapers who, once in a while, can't get a hold of vape juice, and buy a pack of cigarettes.

Like, maybe my vape runs out of battery while I'm out for a night of clubbing with my friends. Nicotine and alcohol get along like a house on fire, and I've got a bit of a habit, so I pop into a gas station. They're not selling vapes, they're selling cigarettes. So I buy a pack of cigarettes, smoke a couple, and probably end up ditching the pack once I get a hold of a charger because vapes are better in every way.

I'm in an age bracket where a lot of people picked up a nicotine habit in college, and literally zero of couple dozen users I know stopped vaping and started smoking cigarettes. Vaping's cheaper, more comfortable (no burning your throat), safer (not to be confused with "healthy"), and doesn't make you stink. And the single biggest reason nobody switches from habitual vaping to habitual smoking is that smoking provides less nicotine. You need to be slurping down cigarettes to get a similar hit.

Sabotage works by introducing friction into your opponents activities. Sabotaging one piece of one data center doesn't do much, but the more you do, the more outsized the impact.

Imagine I'm a factory building widgets. If I buy materials, my default assumption is that I get the materials I asked for. If 5% of the time, or even 1% of the time, my vendor sends me junk that breaks my machines, now I have to introduce a step to verify that the vendor sent me the right ingredients to every widget. That's an asymmetric cost.

The messaging for something like this wants to be "we publicly announced and took credit for this this time", because it's good publicity, and the threat of future, clandestine attacks increases costs across the board. If you can include exactly how you did it, you might even inspire copycats.

Almost certainly. I can go out into the woods behind my house and get into the iron age in a few days (most of that time would be waiting for clay to dry and charcoal pits to cool). That cuts out ~300k years of anatomically modern human history. Whether or not it would be possible to bootstrap the industrial revolution without easily accessible coal and petroleum is a bigger question.

We might lose electricity for a while. There's not a lot of utility for electricity in pre-industrial society. Like, given enough copper, I could make a wind turbine, but I can't casually make a useful lightbulb. Maybe a ceiling fan, but it would almost certainly be easier to run that off of mechanical power directly via a series of gears and belts. Electrochemistry would be a neat party trick, but I don't think my shoddily built wind turbine would generate enough juice to process aluminum.

Firearms would probably continue to exist. I could make a musket, and its utility for hunting and defense would make it immediately worth it. Black powder's not terribly difficult to manufacture from base ingredients.

Are we including domesticated crops as "man-made"? Because that would complicate matters. A lot of knowledge could be lost in the time it takes to rebreed the kinds of grains that allow for stable settlement.

We wouldn't need to re-invent writing, since that's just knowledge, and that would give a pretty big leg up in not losing a bunch of knowledge every time someone dies.

On the whole, if we keep selectively bred crops, I'd say we'd be bumped back to about the Middle Ages at the most. If we're losing the crops, then it would come down to whether we could preserve our more advanced knowledge long enough for agriculture to redevelop.

IDK. I got a hand-me-down sporty car when I was in high school, which was initially white, then I had it painted orange as a birthday gift a year or two later. Comparing the before and after, there was a noticeable shift in how other drivers responded to me, and not universally for the better. I was less likely to go unnoticed (think people trying to merge into me, or jumping out in front of me when they have a yield), but a subset of people (mostly other young men, sometimes older men driving minivans) would act significantly more aggressively. No one ever tried to race me when my car was white. It'd happen like once a week once the car was orange. People actively speeding up to avoid me passing them also increased substantially.

In the context of competitive online games, ping is going to be ~10-60ms, depending on your connection to the particular server you're playing on, and not particularly noisy (and that's a roundtrip time. Client-Server latency would be 5-30ms). In order for one value to "dominate over" another in an adversarial context, the variance of the former must be much greater than the base rate of the latter.

Imagine a game that's just a pistol duel. When the kerchief hits the ground, players press a button, first person to press the button wins.

In an ideal world, with no delay whatsover, the probability P(A) of player A shooting no later than player B is 100 (because both players shoot at exactly the same time). If we add 5 ms of delay to player A, then P(A) = 0 (he will always lose). If then we add 50 ms of network latency to both players, P(A) = 0 still, because 55 > 50. If we instead make that 50ms delay 50ms +- 10ms (ignoring normal distribution for the moment, pretending every value in that range is equally likely), there's a 25% chance of player A experiencing an unwinnable delay (any network delay value > 55ms results in a value greater than player B's max of 60ms), resulting in a probability of P(A) = 75% * 50* = 38%.

If we make the network delay 50ms +- 5ms, then P(A) drops to 25%.

Honestly, they probably would have been perfectly happy with a bookmark on their home screen, but have you ever tried walking someone who doesn't know how to enter a url into their browser through the process of making a home page bookmark on their phone?

Ultimately I ended up making a PWA that does nothing except act as a bookmark. Which was way more of a PITA than it should have been.

Nobody here is talking about the fact that a significant number of users want apps, too.

I'm responsible for an internal tool at the company I work for, hosted as a website, that handles a bunch of miscellaneous tasks that other employees need. Think reimbursements, documentation and reporting, gathering and presenting business data. That sort of thing.

When I took it over, it was desktop only ( a lot of <table> formatted pages with fixed px sizes). I spruced it up, modernized it to work on screens of any size, and created a mobile version of any pages that just didn't translate well to small screens (think "large tables of information").

When I announced the update, the number of people who asked me variations of "how to get website on phone if website on computer" or requested I make the damn thing an app was outrageous.

We take tech literacy for granted, because it's like a dozen levels down fundamental to our entire field. But the tech illiterati exist, and they love apps.

I was definitely that kid. I remember discovering that my district's web filter had a default password (something like "changethis123"), by watching one substitute with exceptionally poor typing skills. Problem was, substitutes' accounts were disabled frequently, and any one account only really had a lifetime of a week or two, before someone in the IT department realized that 300 devices were connecting to the network with the same credentials.

But the staff lists were public, and I had the default password. So I set up a script to turn the lists of names of teachers, librarians, janitors, etc. into usernames, and then tried to login with all of them. Turns out, most support staff, especially custodians, hadn't changed their passwords. (I'm guessing their jobs didn't involve much computer use). With a list of a couple dozen working accounts, I'd mete out 1 or 2 at a time to my friends, and we had teacher-level access for the rest of our time there. Don't remember using it for much, maybe showing my friends a youtube video during lunch or something.

Why does a fitness tracker need continuous development? How on earth is something whose main competition is a $5 notebook and a $1 pen worth $50/yr?

A fitness tracker is exactly the sort of software I would expect to pay once for. It doesn't need some compute-heavy backend. It shouldn't need any backend at all. The entire application is window dressing for a SQLite database.

If you violently bust into someone's home in the United States, you're liable to, and absolutely deserve to, get shot. I do not care if you have a badge. If you want to execute a lawful search warrant, the best time to do it is when nobodies home. The second best time is during the day, when you can clearly state your legal mandate to be there, and allow the homeowner to comply.

The ATF in this instance (and frankly most instances) chose the most violent option available to them, because good people don't join the ATF. Violent thugs who get off on shooting dogs join the ATF. And when they get tired of shooting dogs, they decide to manufacture a scenario where they get to kill a more dangerous game.

In the US, most unions are majority unions, i.e., they unionize an entire workplace by majority vote, and then demand that the company allows them to require all hired employees to belong to the union. Hiring scabs is a breach of contract, with the added weight that unions have extra protections ( for example, you can't just fire anyone who talks about unionizing. That's big illegal).

Besides the legal protections, the primary leverage a union has is the fact that in manufacturing, agriculture, etc., companies start hemorrhaging money if work stops. So a relatively short strike (and thus more easily weathered by the members) can have a massive impact. This worked even before there were legal protections for unions, because the union can strike faster than the company can hire scabs. Of course, prior to the protections, companies could decide that taking the hit was acceptable, and then just hire a bunch of scabs to replace the workers. Or they could threaten the union leaders with violence. Which of course lead to the unions using threats of violence against management and the scabs.

After a couple decades of increasing hostilities, accelerated by the re-introduction of a bunch of combat trained WWI vets back into the workforce, the US established a robust set of worker protections to eliminate the necessity of violence.