HN user

_pghu

4,388 karma
Posts1
Comments18
View on HN

Everyone can't. You can adjust the privacy settings such that you have to add someone to your Telegram contacts before they can discover you are on Telegram. It's easily done in Telegram's privacy settings. This is a primary reason I prefer it to signal despite the screeching from armchair crypto experts on HN anytime Telegram is mentioned.

Users hate change 7 years ago

I imagine you’re being downvoted because your post comes across as another smug designer/product person saying “I know better than you, you uneducated philistine”, with a side of “you just haven’t seen it done right and your personal experience is wrong.”

I’m sure Reddit’s abortion of a redesign has went through hundreds of rounds of UX testing and has been signed off on by the masters of the field, but it’s still slow, unnecessary, and buggy. It does everything worse than the existing design, except perhaps for increasing some sort of pointless dashboard metric users don’t care about.

No, no, no, no.

I do not want Google to have any more fucking data about me than it already does! "Put this blob of JavaScript on every page of your site so that we can see how users are clicking, scrolling, and browsing around. Think of the children^W spam and abuse!"

I just cannot believe that Google somehow gets away with spinning this as some sort of "guardian of the Internet" thing when it is a transparent attempt to a) make adblocking more difficult and b) force people to accept being tracked by Google or get blacklisted from the web.

Getting banned from sites or treated as a subhuman because you don't want Big Brother to follow your actions around should not be something that we're okay with. It just shouldn't be.

Hopefully it isn't yet another case of smug Europeans preening and going "Oh, you stupid Americans, our regulators are different and would never levy gigantic fines. Instead, they come give you a hug and have a cup of tea and politely ask you to please stop, and they would never ever in a billion years abuse this extremely wide-ranging law for political ends!"

Hi Bemmu. I subscribe to TokyoTreat, and formerly subscribed to Japan Crate (and the 'umai crate' noodle box, until one of them got seized by customs because they shipped something with pork bits...)

I don't subscribe to CJ despite having seen it a million times here and almost definitely being the target audience (though this particular ad would have definitely repelled me) because your prices just aren't competitive. I mean, sure, the root price of $29 a month is, but when you consider the volume of candy you get, it's not even close. 7 items on your example image vs. the 14 I got in the February TokyoTreat (one of which was a heavy drink and another of which was a 30-piece share pack) just makes it clear.

Have you considered dropping the shipping to once a month like all the other boxes and making them bigger? I think that would help you compete more effectively, because you'd be paying less for shipping as a percentage of your subscription gross and the "unboxing" pictures of your boxes wouldn't look as sad.

$29 for 7 items is over $4 an item. You're going to have a hard time convincing people it's worth paying that if they look at any other subscription box.

From looking at the list of past boxes, I think you do a really good job hitting the right balance of "ooh, exclusive Japan thing" and balancing out the tastes of an average person. The candy you select is spot-on with what I considered some of the best stuff I got when I lived there.

Regular reminder that any time Telegram is mentioned on HN people pop out of the woodwork to launch a smear job against it because it isn't Signal.

From 1: "We stress that this is a theoretical attack on the definition of security and we do not see any way of turning the attack into a full plaintext-recovery attack."

The second paper is a huge wall of text that boils down to "the protocol is too hard to analyze and doesn't use what I have declared as crypto best practices, therefore I declare that it is insecure."

There isn't, in either of these, any actual attacks showing any actual problems with the protocol. I'm really sick of people jumping down the throat of anyone who tries to use Telegram by declaring it as insecure without even the first whit of evidence. "This isn't best practice" != "This is insecure and you should never use it."

I also very very very strongly do not want any hosted service requirement for using 1password. I am very proud user of 1P but a hosted requirement would kill it for me. No matter how much you (the generic 'you') tell me you're super secure, nothing will be as secure as owning my own data and using local Wi-Fi sync to put it on my phone.

"self-XSS" (the thing this malfeature is purportedly protecting people from) is a made-up concept. It's basically "don't run your own scripts to interfere with our site, and we'll use scary-sounding security words in an attempt to discourage you from doing it." I don't believe for a second this is about helping the user - more likely is that FB and Netflix want to prevent users running scripts that add features or do functions they find inconvenient, like exporting your address book or movie rating info.

I get to run code just as much as you do - it's MY computer, MY browser, and MY bandwidth. Making up a scare word (that just means "users running code I don't like") in an attempt to legitimize disabling access to development and exploration tools is beyond the pale. There is absolutely no reason to permit this kind of behavior, and I'm frankly a little appalled a community of startup founders and hackers would ever defend this kind of behavior, as some of the comments here have done. If you want to protect users from themselves and limit and restrict what they can do, write a mobile app. Don't try and put your shit on the web if you want it to be a walled garden.

And, of course, the "search for what I actually fucking typed" mode is completely undiscoverable, hidden behind another click, and which can't be defaulted into.

This is a good bandaid, but is still a bandaid. I have still switched away from Google to a search engine that will actually search for what I told it to, not one that thinks it can guess my meaning. (Not to mention one that doesn't wrap all the outgoing URLs in click-tracking garbage then uses JavaScript in an attempt to hide it, with no way to opt-out.)

1973 was almost 40 years ago. You should not have the right to profit from your work forever. 40 years is more than enough time. As such, I don't feel the least bit compelled by the second part of your argument. If Disney goes broke because Steamboat Willie has finally entered the public domain and is blatantly copied in Russia, I don't think anyone is going to shed a tear.