HN user

ZoFreX

4,860 karma

I like giving advice out and helping people, but I'm not always the best at communicating my intent. So, unless otherwise explicitly stated, if I offer my services on HN, I am not trying to make money, but just want to help people out for free because I'm such a nice person.

The best way to contact me if you want to is via Twitter.

Posts27
Comments1,707
View on HN
www.zofrex.com 5y ago

Bundler Is Still Vulnerable to Dependency Confusion Attacks

ZoFreX
3pts0
www.revk.uk 9y ago

The TOTP seed storage dilemma

ZoFreX
1pts0
conference.hitb.org 11y ago

Infecting BIOSes Is a LOT Easier Than You May Have Realised [pdf]

ZoFreX
2pts0
martin.swende.se 11y ago

Inside Secure threatens security researcher who demonstrated product flaws

ZoFreX
3pts0
boingboing.net 11y ago

Death threats for sceptic who leafleted at Sally Morgan “psychic” show

ZoFreX
2pts0
www.bbc.co.uk 12y ago

Cyber-theft hits eBay's Stubhub

ZoFreX
1pts0
ansuz.sooke.bc.ca 12y ago

What Colour Are Your Bits? (2004)

ZoFreX
1pts0
twitter.com 12y ago

Valve bans developer from Steam for revealing security vulnerability

ZoFreX
11pts0
news.ycombinator.com 12y ago

Ask HN: Would I be crazy to learn Objective C now?

ZoFreX
12pts10
www.artlebedev.com 12y ago

Idea worth minus a million

ZoFreX
1pts0
www.ft.com 12y ago

Cyber Snake plagues Ukraine networks

ZoFreX
1pts0
blog.8thlight.com 12y ago

The Transformation Priority Premise

ZoFreX
1pts0
www.youtube.com 12y ago

The Moto X's interactive print advert

ZoFreX
1pts0
delyan.me 12y ago

Samsung agency is buying off StackOverflow users

ZoFreX
447pts155
www.eurekalert.org 13y ago

Custom bots for Unreal Tournament 2004 pass Turing test

ZoFreX
67pts31
marketingland.com 13y ago

Android Owners "More Complacent" Than iOS Users When It Comes To Browser Choice

ZoFreX
1pts0
www.lukew.com 13y ago

Why server-side browser detection belongs in your web design toolkit

ZoFreX
2pts0
www.technologyreview.com 13y ago

Room Temperature Superconductivity Found in Graphite Grains

ZoFreX
177pts68
www.guardian.co.uk 14y ago

Professional graffiti artist banned from Olympics games venus and owning paint

ZoFreX
1pts0
mattjackrob.com 14y ago

Why you should not be building a minimum first version

ZoFreX
1pts0
news.ycombinator.com 15y ago

Ask HN: Should I specialise?

ZoFreX
12pts6
news.bbc.co.uk 15y ago

Musical sweet spot for 3D sound

ZoFreX
3pts1
www.bbc.co.uk 15y ago

PS3 imports banned in patent row

ZoFreX
1pts0
www.chrononsystems.com 15y ago

Chronon "time-travelling Java debugger" beta now available for download

ZoFreX
28pts6
www.bbc.co.uk 15y ago

Microsoft says Yahoo is 'phantom data' phone bug source

ZoFreX
3pts0
www.bbc.co.uk 15y ago

T-Mobile: "There will be no change to the data packages for existing customers"

ZoFreX
1pts0
news.ycombinator.com 15y ago

Ask HN: Presentation on giving presentations?

ZoFreX
2pts3

This seems to be an internet meme, because it's repeated in every discussion on this topic but I never see any citation for it.

It also doesn't seem to hold up to scrutiny - even if the initial packing of the vehicle holds everything in place, what happens once a few packages are removed?

Largely yes. Or at least a lot less of a problem.

The biggest risk from space garbage is that the small stuff is not trackable, so at any point it could slam into satellites or, god forbid, people or space stations. It's going fast enough that despite being small this would have dreadful consequences.

Larger items can be tracked, and therefore can be avoided, so they don't pose a risk any more than non-junk large items like other satellites and so on. There's quite a lot of room so if you know where things are it's not hard to avoid them.

Some amount of garbage is sadly unavoidable at this point in our development of space travel. For example many rockets are multi stage and jettison those stages, farings to protect satellites are jettisoned, and so on. That all falls into the "large and trackable" category so it's not a terrible problem, at least not yet. So the main current strategy for avoiding creating problems is to avoid creating small garbage, and people work very hard at that - being careful not to lose tools or even a single nut or bolt.

And yes, before you mention it, "lots of room" is a relative statement and this is not an infinitely sustainable strategy. But people are working on methods to capture and clean up garbage, and as those get more feasible we'll be able to go and clean up all this large garbage that we are tracking. So even with a long-term perspective, the large stuff is less of a problem.

Also, to prove a rocket you need to have a dummy payload of some kind. Whatever you think about the stunt of using a Tesla as that dummy payload, there was going to be a payload of some kind however that decision went. The fact it was a car doesn't change the collision risk or debris amount compared to using a mass simulator.

Windows doesn't have fine-grained permissions for adding to or changing certificate stores, though. When you run "mkcert -install" you'll get a generic prompt for mkcert requiring admin permissions, not a prompt for it changing certificate stores.

I believe the point is that any software asking for admin could fiddle with your certificate stores, so there's no sense in asking for a higher standard of integrity from software that tells you it will do so.

It's not, necessarily.

It's a tradeoff between usability and security, and each site should make their own decision about what is right for them.

It obviously makes attacks like the one in the article easier, but there are other ways to mitigate that.

An example often given for when revealing an email is registered would definitely be bad is dating website and pornography websites - where identifying someone is a member alone could be embarrassing or compromising.

Outside of such scenarios, websites may decide the increased conversion from a more streamlined registration process and lower numbers of support requests for login issues outweigh the marginal security gains from hiding that information.

If people are using it, not paying attention, with the expectation that it will beep to tell you to take over that's a big problem. In situations like this divider issue it won't beep, it thinks everything is fine right up until it rams you into a stationary object. I think people may not be fully aware of all the potential failure modes of this tech?

This should help you to have a backup next time you get locked out!

The official authenticator also displays a backup code which it tells you to keep a copy of somewhere safe...

The difference is (according to the article) that there is an abundance of objects at 0mph - signs, litter, barriers - so the system filters all of these out to avoid constantly braking. There is no such abundance of ignorable items going at 20mph.

NatWest are particularly terrible. Last time I checked, in-branch they were still using Internet Explorer to visit an http (not https) site on their intranet to launch via Java Web Start a thin client to log in to their (I assume) mainframe to actually do things.

There's a number of places in that chain of events that something could go nastily wrong, despite them owning every part of that chain.

Being a jerk and disagreeing are orthogonal. You can be a jerk while agreeing with someone, and be a not-jerk while disagreeing.

I'm curious, in reference to the post, how you would have no problem working with a "Bob"? Is there really no behaviour there that would bother you in a coworker?

with a reputation as huge and important as Google's

Not trolling: What reputation?

Among non-techies, their reputation is one of creepy and spying.

Among techies, it's that company that keeps killing loved products.

Among developers, it's one of terrible support and awful job interviews.

Common to everyone is they are impossible to get hold of, a faceless and heartless machine that makes decisions you can't argue with.

None of this matters because they have the best products on the market in a few key areas and everyone keeps using those regardless of their reputation.

So what reputation do they have to lose? Their reputation is already bad, and it doesn't matter anyway, and they presumably know this as well as everyone else does.

Why do they need to do this?

This is explained in detail here:

http://content.tfl.gov.uk/review-tfl-wifi-pilot.pdf

If you would rather buy a paper ticket with cash you can still do that, and you won't be tracked if you put your phone into wireless mode. Personally I'm happy for them to collect limited amounts of data, with restraint, if that means they can improve the effectiveness of the network. But if you're not, that's understandable, and it's not that difficult to avoid it.

Yup, I'm happy with it. Can't see how else you would get this amazing data which is obviously going to be extremely helpful for managing an increasingly overcrowded train system.

Even the article says they're using this to assess the value of advertising spots, rather than some of the more nefarious things that _could_ be done with this technology.

In the circles I hang in (as in, both people I talk to, and articles I read) the term "emotional labour" is used like it is in this article.

Sometimes terms mean different things in different circles or groups or contexts, it doesn't mean either usage is "wrong" necessarily.

The "power" to ban people isn't up for debate, though. Reddit have that power, whether they exercise it or not. If they did not exercise it today, it could still be inherited and abused by a future actor tomorrow. There may be arguments about how to change that, but arguing Reddit should not ban users for their speech would not be one of them.

Further, it's hard to imagine a world where websites cannot ban users. Reddit's "power" extends over their own property and who they admit to it, I can't imagine it being possible to run a website without that "power" - how would you deal with spammers and so on? How could you possibly compel a website to admit all people whether they want to or not?

Epistle 3 9 years ago

If HL would have been a EA game

It was! I know EA are the go-to bad guy in these comparisons, but EA is the distributing publisher for physical copies of Valve games, and Valve are on record as loving working with EA.

Epistle 3 9 years ago

it's amazing that Valve continues to ignore it

Valve isn't a monolithic entity nor a top-down controlled company though. This argument doesn't reflect how they make decisions.

They have spoken on a few related points in the past:

* Their projects often change dramatically during development, even being scrapped or started over again from scratch (Half-Life is a rework of a scrapped project, Team Fortress 2 was completely rebooted)

* They prefer not to talk at all about things that are very hyped because they believe it's more painful to the community to go through those twists and turns than have radio silence

* If they aren't happy with the quality of something they produce it doesn't see the light of day, rather than release something that isn't great

* For it to happen requires enough people within the company to decide to work on it, and see it through

I would have to read their source code to answer that question (I know almost nothing about 1Password). Some password managers just call a PGP executable. Others are assembling crypto primitives into larger pieces and making choices like "let's use CBC mode" themselves.