HN user

__MatrixMan__

9,075 karma
Posts2
Comments4,253
View on HN

Instead, the password managers each have their own finicky app-to-app mechanism for transferring passkeys from one password manager to another. (I think all the password managers kinda like that lock in.)

It's a nice simplifying step to talk about password managers here, but in the majority of the cases this won't be handled by a password manager, but rather by the device operating system, and the device manufacturers really like that lock in.

They're also in an especially good position to abuse it, because they now know every service that you authenticate and the webauthn "attestation object" field lets them set up a side channel with those services such that they can sell additional information about you.

Some people will tell you that the attestation object is not used in the consumer passkey system, so there's no way for this abuse to occur, but since it's usually going to be the device manufacturer who controls the password-manager-like component here, and they're the ones who stand to profit most from this kind of abuse, I think we need stronger guarantees than "the spec says you shouldn't do this unless the user is your employee and you paid for their device".

Until they fix this, I'm sticking with my mess of TOTP authenticators and yubikeys.

It brings to mind satellites assembling themselves in space. Send up a tightly packed box of spaghetti and extrude it into the desired physical shape upon arrival in orbit. For increased rigidity, paint with a solar pumped laser to weld the links together.

I'm reminded of the mountains of blogspam not intended for human consumption but rather to influence the google page rank algorithm.

This will go about as well as that did unless the models can be smart enough to identify when their training data is trying to coach them into being misleading at prompt time.

That's better than nothing, but if you're expecting people to be looking at something before you use it, you should be waiting for a thumbs up from them, not waiting some arbitrary timespan for the absence of a thumbs down.

You should probably also be paying them directly.

Using the prints themselves as glue rather than buying glue for them would make this a more interesting form of recycling.

I wonder if you could make a large hand-driven low-resolution 3d printer which, rather than running on filament, had a hopper that you fill with failed prints. Really just a giant hot glue gun.

Nothing to do with poisoning the non-AI parts of the economy to drive investment in AI? Its not like this bubble was gonna blow itself.

It's clear that there's plenty of money to go around. It's just that none of it is being spent on things that improve people's lives, mostly due to corruption.

What it is to you depends on if you want to sell a screwdriver or if you want to drive a screw.

If you're looking for somebody to design a screwdriver for you, you're better off with the guy who wants to drive a screw.

If the outputs are independently verifiable at low cost, and the US models refuse to even try because somebody sneezed nearby and it sounded like "antigen" and not "achoo"... yeah sure. Whatever works to get the job done.

The hope is that AI will open up whole new sectors of economic activity. If you have to chose between exploring that space while potentially being exposed to Chinese tampering, versus just sitting on your hands and doing nothing... well then you take that risk.

Products tend to be someone else's tool

I like this. The question is really whether you're facing the "business end of the stick" or not (although stick isn't quite right here, because not all software has both ends).

There are good reasons to dislike outcomes that involve a single entity pulling well ahead of the pack here. Whether or not it continues to be American labs in the crosshairs and Chinese operators doing the aiming, perhaps it's reasonable to plan for continued efforts of this sort.

When I think of software that is minimally tainted by productism, these come to mind:

- linux

- nix

- nushell

- helix

Are these products... at all? Do the open me up to new scams? I don't think so.

I'm not in a position to demand anything from the people who make these things. If they were subject to demands, their craft would be tainted by compromises made in acquiescence to those demands, and I'd probably be less enthusiastic about their software (because presumably, my tastes don't align with whichever others are also in a position to be making demands).

Supply and demand are well and good if what you're after is barley. But when you compare what there's demand for with what's being supplied re: software, there appears to be no correlation.

We gotta stop selling picks and shovels and start learning to be miners who have good taste in picks and shovels and the ability to make and remake our tools as needed. The disconnect is creating a hell for our users.

I'm all for pushing back against "let's not make perfect the enemy of good." I hear that all the time in reference to software that is usually quite bad, and often a little evil to boot--nothing good anywhere in sight except some poor schmuck trying to find a way to make their job something worth taking pride in.

I'm not sure I agree that systems are products though. The product mindset is toxic. It means that you've got goals which are independent of the user's goals (typically to make money, which sometimes means doing something dastardly to the users on behalf of the shareholders).

All the best software is more in the "tool" category and less in the "product" category. Usually it's made by the users, only bothers with solving problems they have, and has no ulterior motives.

LSD has risks, especially if you're already prone to certain kinds of mental illness (you might not know it), but addiction isn't really one of them.

Going for a walk can also rewire your brain, but doing so on LSD will probably rewire it more quickly. Whether that's good or bad depends on whether you do a good job with the rewiring. It comes down to how well you trust yourself.

I've been attempting to build something similar and every time I take an honest look at the state of affairs on mobile phones I'm end up leaning towards running the way meshtastic users do: either strictly on dedicated hardware, or over a bluetooth link from my phone to dedicated hardware which I'll keep in my backpack or glovebox.

I recently discovered you can get a usb-C travel bidet, in case you're looking for a way to be even more maximal. Recommended.

So it's not propagandists that are the problem, but rather the people they target? That's an odd take.

Maybe we should've shown a little more spine when they asked us to build a medium for the strong would use to prey on the weak. Maybe we're the problem.

The city can buy cameras and install them an operate them, but I don't think there's really space for an ethical SAAS play here.

Companies are either out of the loop, or they're in the loop and the only way to do right by their shareholders is to exploit that data in every way they can.