HN user

Reelin

2,258 karma
Posts2
Comments1,007
View on HN

Turned out a lot of people were running unstable, overclocked hardware sold to them by vendors who had fraudulently misrepresented the hardware.

The original devblog from 2005 is (https://devblogs.microsoft.com/oldnewthing/20050412-47/?p=35...). Aside: Upon pulling that up, I recognized the author as the one who wrote my favorite article about undefined behavior (https://devblogs.microsoft.com/oldnewthing/20140627-00/?p=63...).

My car is governed at 110 mph. Why?

Most likely due to some physical (not legal) issue that would make it mechanically unsafe to operate the vehicle above that speed even in an otherwise appropriate location. (Or perhaps it's due to some obscure state law, or the manufacturer is just out to spoil your fun, or ... who knows?)

More generally, I agree with the point you make here about the responsibility to configure things correctly. However, it seems to me that Microsoft is also on the hook for failing to include the necessary context when an MFA request is sent. It's a bit like selling a car with seat belts that superficially appear to work but fail at the slightest provocation, no?

I thought the way you wrote it was clear but these comments got me curious what the various conventions might be so I took a quick look at :help in Vim (since it lists an awful lot of key bindings). I'm now officially confused and don't think you can go too far wrong.

In some contexts :help notates things as characters (ex zh, zH, and z<CR>). In other cases I'm seeing things written as <S-F11> and <C-G>. There's also CTRL-H (instead of <C-H>) but I'm not seeing shift written out like that for whatever reason. Sometimes they get mixed (I'm not sure what the rules are) such as for hh<Space> and hh<C-]>. Amusingly enough, :help appears to treat Meta-{char} as case sensitive but CTRL-{char} as case insensitive (I assume there's a reason). I also spotted a <kPlus> (for the keypad).

What an amusingly pointless distraction!

Who spends that much time just in the command line these days?

Just stop using GUI utilities. It really is that simple. If you just don't use them you'll end up in a shell out of necessity because you still need to get things done.

Of course, the majority of my time is spent in my web browser reading documentation followed closely by vim for writing things. Actual time spent interacting with CLIs is a small minority at the end of the day.

No. Those are the very definition of publishers, not communications providers masquerading as publishers when it's politically convenient for them (recall the dance around Section 230 protections).

If a local newspaper ever somehow became the central point of communication for a significant fraction of the population, posting nearly everything they received by default with very little to no curation, then it would be reasonable to reexamine the expectations placed upon them by society.

Nobody is claiming this.

The person I responded to did, in fact, directly imply this. Recall that I had compared the impact of modern mainstream social media to that of the printing press historically. Directly ignoring my central point clearly places your comment in bad faith.

"Freedom of reach" is nothing more than a thinly veiled attack on (cultural, not legal) freedom of speech (and liberalism more generally) for the reasons I've already articulated in this and nearby threads.

Freedom of speech is not the same thing as a (nonexistent) right to post whatever you want on a private platform

Again with a non sequitur - I never claimed that it was. I said:

> Censorship reduces freedom to speak. That statement remains true whether or not the speech happens to be legally protected

It's really hard to have a good faith discussion about the pros and cons of a nuanced issue when one of the parties repeatedly fails to make good faith interpretations of claims which appear to challenge their worldview.

YouTube, Twitter, Facebook, Reddit, etc (and to a lesser extent search engines) are the modern equivalent of the printing press in terms of the effect they've had on how we communicate. A domain and VPS are simply not a viable substitute for access to mainstream social networks; to claim otherwise is disingenuous.

They are not at all similar to publishing. There's no editor. There's no approval process for the typical use case, only a retroactive removal process. They don't have an audience in the traditional sense of people paying someone to curate information for them but rather depend on network effects to maintain a monopoly on their segment of the market. To that end, they have more in common with a dating app than they do with the New York Times. The presence of advertising revenue is the only legitimate similarity I see to a traditional publishing model.

In spite of your claim that YouTube isn't infrastructure, it appears to me to have far more commonalities than differences with it. That it isn't (yet) regulated as such is merely a legal peculiarity from my perspective.

(And the above doesn't even begin to consider the effects that dumping VC and megacorp funded free product has had on the market. Good luck starting a competing platform when there's no viable way to operate a subscription model and your direct competitor has a monopoly on the relevant advertising market.)

I suspect you're being rhetorical, but the algorithm and specific metrics to use are selected by the developer. The data is entirely user generated - it's the result of collecting the metrics over some period of time. The trained model is the result of feeding the collected data into the chosen algorithm.

The point is that the algorithm is, for all practical purposes, tuning itself. The developer has essentially selected a black box to feed the data into, told it what to optimize for, and given it the ability to wiggle a bunch of unlabeled knobs. Which knobs it should tweak and in precisely what way is never specified by the developer. Instead of "show the following things to the following users", the developer just says "maximize number of videos viewed per visit" and the algorithm tweaks whatever parameters have been made available to it until it finds something that works.

Unfortunately, "something that works" is often not what we might have liked. ML is a bit like a Djinn, fulfilling wishes in an unpredictable and borderline malicious manner.

Not if it's built into the communication platform you happen to be using. Just one or a few basic indicators to give you even the slightest bit of information about who wrote what you're reading. Just a simple "p = 0.03 US resident" or an aggregate trust score based on a combination of social graph connectivity and spam reports or something. Sure, people could intentionally ignore it, but right now there's no indicator to be had even if you want it!

To be clear, I'm not talking about present day clunky GPG web of trust with key signing parties and all that. I'm talking about a hypothetical (ie as yet nonexistent) magical web of trust that somehow doesn't destroy your privacy in the process of being used. (It's not as crazy as it sounds - we already have zero knowledge proofs, blinded encryption, and various other privacy preserving cryptographic schemes.)

These aren't singular global quantities. Such censorship reduces spammers' freedom to speak in order to preserve that of the other participants. Spamming closely resembles a tragedy of the commons (overuse of the system to solicit sales) and anti-spam an associated regulatory action.

The problem with such an analogy is that spam is inherently off topic - approximately none of the other participants actually want to see it. That's fundamentally different from this case. Whether you deem it misinformation or political speech, many of the participants clearly do want to see it. In fact, they want to see it so much that such information is consistently selected by the automated algorithms that are designed specifically to maximize engagement metrics.

We limit speech already, you can't advocate for the killing of other people, races, etc...

Actually, not that I support such behavior but (at least in the US) you can generally advocate for it. People usually don't (thankfully) so I don't have any examples immediately to hand, but my understanding is that the legal test is "imminent lawless action". (https://en.wikipedia.org/wiki/Brandenburg_v._Ohio)

free speech is the solution to all democratic problems, it's not an absolute good

Rather than an absolute good, I would argue that it ought to be viewed as an absolute right. I would also argue that, whether used for good or ill, free political speech is a functional necessity of any democracy. (Necessary but not sufficient and all that.)

in a way censorship might be already happening. In this case non-arousing messages are being suppressed

Agreed, but it's a separate issue and I've no idea what anyone is actually supposed to do about it.

Those aren't mutually exclusive. The government can simultaneously regulate specific behaviors of large entities where there is reason for concern while otherwise largely leaving them to do whatever they want.

I don't think GP is necessarily suggesting that Trump will address their objections or that they personally support him. Rather, I read it as suggesting that much of his support may in fact be due to backlash against such cultural trends on the left.

This mirrors my experience perfectly. Conduct on HN is uncommonly civil (for the internet) across the board - props to Dang and whoever else moderates things. Insightful discussion, however, is almost entirely limited to the extremely technical submissions. From biochemistry to compilers to machine learning, they consistently attract participation at a truly impressive caliber.

Sometimes I wonder what HN would be like if it were somehow possible to preemptively block the majority of the "fluff" articles that make it to the front page. I guess there's no way to automate such a determination though, and even if there were any such action would probably anger the majority of the user base.

They're private platforms. You can send those links via many other routes ...

That is a complete non sequitur. You say it's not about freedom of speech. Someone responds that, in fact, blatant censorship is occurring. You don't even attempt to refute this point, instead falling back to pointing out that the censorship isn't illegal!

Censorship reduces freedom to speak. That statement remains true whether or not the speech happens to be legally protected, and regardless of how wide spread the censorship might be.

It's about freedom of Reach, not freedom of speech.

What a snappy cliche. If you prohibit certain people from using the printing press but allow others to do so, then in practice you are limiting their freedom to speak relative to other people. To imply otherwise is either disingenuous or profoundly misinformed.

foreign governments and other actors actively seeking to polarize society

What are some better alternatives?

I have no idea if it's mathematically possible but I'd be optimistic about the potential of a (hypothetical) privacy preserving web of trust metric. It would be really nice to have at least some limited indication of how the person behind the account fits into the world at large. Right now you can't reliably determine (arbitrary examples) country or even continent of residence, paid posts by an organized campaign (PR, propaganda, etc) versus organic occurrences, etc.

Of course, Facebook is the ever present counterexample where people proudly attach their full legal name to hate filled streams. But at least I personally know for certain that they're local people who actually exist and aren't being paid for their posts! Silver linings and all that.

Qt 6.0 6 years ago

You will just write a mobile app and that will be backwards compatible with desktop automatically.

A PWA? Sure. But a native app with seamless integration? No way.

Instead of Windows, macOS, and various Linux flavors, now you've got Windows, iOS, still macOS (for now), various Android versions, and various Linux flavors (including Chrome OS). Good luck!

(Depending on the type of app, you might also want or need to support various embedded devices or game consoles. I guess QT doesn't help there though.)

Qt 6.0 6 years ago

Just do your linking in a final build step that 1: Only reads in object files and resources (ie rejects source code); 2: Bundles up all the object files into an archive; 3: Outputs the final executable alongside the archive.

You mentioned LTO. Don't the LLVM and GCC LTO implementations currently involve outputting compiler IR to object files, then running the optimization passes against the full collection of object files prior to linking? So they inherently collect all the object files together in a linkable form.

(Of course, it's probably more efficient to just dynamically link Qt and pay for a license if you want to publish for iOS.)

Thanks for spelling it out like that - I think I might see the bigger picture here now. DoH (which incorporates DNSSEC under the hood) to protect the name lookup. IPv6 to provide unique addresses for every single service you connect to. The complete removal of SNI (as a security threat) and ESNI (as unnecessary complexity).

Pi-hole type filtering is then implemented based on IP blocks instead of DNS queries. Any unrecognizable IP address is default denied. Tracking, analytics, and ads could still be proxied by a remote host, but that can already happen anyway.

Of course, your ISP (or VPN, or anyone else along the network path) could employ the exact same approach to determine the services you connect to. Which leads me right back to DoH being largely pointless and Tor or similar being a hard requirement for actual privacy. Unless I'm missing something?

there continue to be threads full of arguments that amount to "It should be possible for 'good' network admins to intercept traffic from devices that don't trust them, but 'bad' network admins shouldn't be able to intercept traffic from devices that don't trust them"

That's not what I see at all.

I see people pointing out that DoH hurts privacy and reduces control for end users by providing a convenient turnkey solution for device vendors to bypass filtering at the network level.

I also see it pointed out that DoH could have been specified in a way that facilitated filtering for the local network. Given that it's so obviously possible, the fact that it wasn't speaks volumes.

Note that (IIUC) your ISP can still see which sites you visit because TLS still transmits the FQDN in plaintext (https://security.stackexchange.com/questions/86723). Even if that stopped happening tomorrow, the destination IP would still be visible (not quite as bad but still reveals a huge amount of information). On top of all that, DNSSEC already exists which allows you to verify the authenticity of the query result. As such, the argument in favor of DoH would seem to be limited to preventing your DNS resolver (but not your ISP or VPN!) from tracking which sites you visit. I don't find that to be very compelling in light of the immediate downsides.

I thought that iptables was the easy way to do it? (Both for IPv4 and IPv6.)

NAT66 is an experimental (10 years old IIUC!) RFC for one-to-one IPv6 mapping. While there's no RFC specifying an official method of masquerading behind a single address, AFAIK iptables "just works" (as long as you aren't running FreeBSD).

It is about protecting the consumer

Nonsense. Protected origin status is protectionism plain and simple. That's not to say whether it's bad or good, just to call it what it is.

Proliferation of confusing low quality lookalikes is prevented by having an enforced criteria and associated labeling requirements. (If the text is too small as in your example then either the labeling requirements aren't sufficient or they aren't being enforced.)