HN user

ac4tw

78 karma

Currently: www.simpleid.xyz, www.referenda.io

Posts5
Comments54
View on HN

I did the Hackintosh thing for a friend on one of those 10” HP mini-laptop 5 years ago. It was delightful when it worked, however every macOS update (or OS-X back then) was a toothache—usually culminating in 2-7 hrs of googling/re-configuring etc. It wouldn’t have been so bad if the machine wasn’t this person’s main machine, or if I had waited longer before updating (so known procedures to make things work were available and not still being understood and developed by the community).

Might be a very different experience on a desktop, but definitely read up on the update experience and time-cost if you go this route.

I'm curious about how long you were using Mac and how much of the ecosystem you were taking advantage of. Specifically were you using Apple messaging, photos, and / or email?

Also, did you take advantage of handoff or airdrop?

I imagine if you were strictly using cloud services, it was a relatively painless transition.

Great article @prostoalex--gets excellent 1/2 way in with the details I was looking for.

Esp. interested in more on this:

'A major concern was that Russian spies with physical proximity to sensitive U.S. buildings might be exfiltrating pilfered data that had “jumped the air gap,” i.e., that the Russians were collecting information from a breach of computers not connected to the Internet, said former officials.

One factor behind U.S. intelligence officials’ fears was simple: The CIA had already figured out how to perform similar operations themselves, according to a former senior CIA officer directly familiar with the matter. “We felt it was pretty revolutionary stuff at the time,” the former CIA officer said. “It allowed us to do some extraordinary things.”'

Agreed--though much of the core code is shareable between both targets.

When I first discovered the prototyping capabilities for colors/themes/samples in the Chrome dev tools, my mind was blown away b/c of how fast I could iterate. A plug-in might take that to the next level. It's hard to say without me surveying more of what's out there and in use--I get the sense that at a certain level, teams rely more on tools like Sketch, inVision studio, Framer etc. for this.

I was looking at the website and trying to connect the dots--the thing I'm wondering is how 2020 madness knows about a donation.

Is 2020 madness a wrapper to a candidate's ActBlue landing page / site, collecting form data for it's purposes and re-transmitting it to ActBlue or is there a tie to the receipt or some other mechanism?

Interesting gamification idea btw.

Checked out the preview on htmlstream and really enjoyed how complete this is and all the items you've included.

One thing I saw was during my mobile litmus test (Chrome developer tools set to iPhone 5SE), it didn't render using the full screen width, being offset left. Checking the element dimensions confused me because they matched those given for the device. Perhaps an issue in Chrome I'm using (76.0.3809)--when I inspect I see that the root element width of 320x568 matches that stated for the device. Looks fine on other device emulations with more than 400 pixels of width.

Thanks @timqian--really like the look of this and the examples cracked me up--esp.: "Monthly income of an indie developer".

I'd 2nd the comments below on Safari & size--ultimately I'm excited about using this in some mobile projects we're planning.

I like this idea.

After reading the comments here and visiting your site, I decided to see if there was specialty information on developing software for silicon (i.e. FPGAs) as that is very different than software development at Facebook or Google--yet all might fall under the description Software Developer. I'm thinking some way to differentiate that so that people can figure out if they want to make horizontal moves or what a horizontal move might be like would be useful--especially when you get more reviews.

Another question I have is about the incentive for people to provide job descriptions--are you thinking karma or some other benefit?

This idea has a lot of really interesting crossover--for instance just confining it to the developer space, not only is it interesting to contrast being a developer at say NPM, Mozilla, Facebook, Google, Maxim, Xilinx and Qualcomm, but to also see those development environments and tools (i.e. Twitch style) is interesting. I know there was someone who was doing that and I followed it briefly a few years ago.

Interesting idea @longsangstan--I played around with it for a while and liked how the colors would change on reload or palette click. I often muck around with colors using the Chrome debug tools, but it would be interesting to have something like this pop up as a dev plug-in with assignable sections/classes/ids so I could tweak things on the fly and o/p CSS--if that doesn't exist already.

Indeed.

Sidenote, it behaves differently if you've enabled airplane mode (or at least so the UI would indicate). In airplane mode, it gives no message and the wifi/bt icon goes transparent. If you're not in airplane mode, the wifi/bt icon goes light gray and it says 'disconnecting <device type> devices until tomorrow' but the radio is still on as your article mentions.

Personally I miss the old behavior where it just turns it off, but I'm often in airplane mode so I get the old behavior anyway and great battery life :P

"Blockstack stores the content" -- today this is true in that you are provided with a default storage bucket by Blockstack that amounts to Microsoft Azure space. It's been Blockstack's vision that you could select your own cloud storage upon account configuration (i.e. your own S3/Dropbox/IPFS storage), thus decentralizing your data storage away from the App developer. If you're willing to get your hands dirty, you can theoretically spin up your own Blockstack GAIA node and store your data there instead of the provided defaults. More info here: https://github.com/blockstack/gaia

Have you tried using force touch to select text--I have big fingers and it's my fav. iPhone feature. You just put the cursor on a word and press hard--the word gets selected. Then press even harder and the surrounding words get selected--you can also press hard and drag one side of the selection cursor to select left or right of the datum. (You need a 6s or greater phone though--5se won't do it).

Interesting comparison Irvick. Enjoying the resuling conversation too. More detail on meanings and methodology would be helpful as some other HN folks suggest.

Stealthy.im isn't mentioned (I develop that presently).

Stealthy makes use of decentralized identity in the blockchain and a decentralized storage system called GAIA. Regular chat is E2E encrypted using ECIES. Currently released for Android and iOS.

I've had a conversation about something like this nearly every year that I worked in Corporate America. Interesting to see it get built (I can't speak to the history of other implementations). Those past discussions were around an MS Outlook add-on to disable/gate the send button if the email draft content was too egregious.

A few questions I had about your product:

  * How would you monetize? (If you're thinking of doing so?)
  * Have you considered integrating with other messaging?
[dead] 8 years ago

Hi everyone, I wanted to just address a few points that arise for decentralized and messaging apps:

How decentralized is Stealthy?

  * User identities are stored in the Bitcoin blockchain
  * User storage is decentralized away from Stealthy in the user’s own cloud storage
  * Stealthy doesn’t require a centralized signalling server for p2p communication (both parties must add each other as contacts, coordinating this outside of Stealthy)
  * Conveniently, Stealthy includes a signalling server that can be disabled.
  * Push notifications use centralized technology at present.
  * Our public discussion channels use centralized notifications to scale at present.
  * We build on Blockstack to get decentralized identity and storage (https://blockstack.org/faq/, https://blockstack.org/whitepaper.pdf)
  * We have plans to continue decentralizing Stealthy features as time permits and solutions become available, for instance migrating to GUN decentralized database for some features (https://gun.eco)
2. Protocol details?
  * We plan to publish more details near the end of this year.
  * All data is stored off chain for performance approaching centralized messengers.
  * Offline p2p communication is relatively simple and involves polling a contact’s cloud storage for messages.
  * Polling scales based on users presently and will see more intelligence in a future release.
  * Realtime p2p uses our offline p2p to establish a WebRTC connection (coming later this year to mobile).
  * All p2p messages are encrypted client side before transmission.
  * Our public channels use a hybrid version of our p2p protocol
    * Messages from users use the p2p protocol with a centralized notification for scaling.
    * Messages from the channel are written sequentially, unencrypted (it’s a public channel)
3. Encryption details?
  * Encryption keys are held by the user 
  * Stealthy uses Blockstack compatible ECIES for all p2p messaging (SECP256K1 curve, SHA512 MAC, AES 256 CBC cipher, SHA256 HMAC)
  * More information here: https://blockstack.org/faq/
4. Surveilling metadata?

Stealthy was not designed to conceal metadata from state-level actors, especially those with a capability of surveilling each node of a network concurrently. There are other protocols with that intent. However, we are looking to improve our protocol in this regard in the near term.

5. Why collect an email?

Stealthy uses Blockstack’s identity solution which collects email in the event that you need to recover your 12-word Blockstack pass phrase. Stealthy does not collect your email.

Actually a fellow on HN the other day demonstrated that you could decompile their APK and inspect the code, so you can make a pretty solid attempt to verify product statements if you have the skill and the time.

Also, I think we're cross talking about their statements--I can't divine anything specific from what they say, but their answers (esp. Sandbergs non-answer) seem supportive of other things I've seen claiming the encryption they're using is leaking business analytical information to FB on purpose (effectively undermining the lay understanding of end-end encryption).

BTW That situation in Australia is saddening.

I find the article interesting from a cryptographic perspective--specifically have they implemented searchable encryption or such a "encrypted environment" where they able to capture more than meta-data.

These quotes specifically:

The challenge was WhatsApp’s watertight end-to-end encryption, which stopped both WhatsApp and Facebook from reading messages. While Facebook didn’t plan to break the encryption, Acton says, its managers did question and “probe” ways to offer businesses analytical insights on WhatsApp users in an encrypted environment.

...

When Sandberg, Facebook’s COO, was asked by U.S. lawmakers in early September if WhatsApp still used end-to-end encryption, she avoided a straight yes or no, saying, “We are strong believers in encryption.” A WhatsApp spokesperson confirmed that WhatsApp would begin placing ads in its Status feature next year, but added that even as more businesses start chatting to people on the platform, “messages will remain end-to-end encrypted. There are no plan

I think this is my favorite quote for discussions that start out like yours:

“Arguing that you don't care about the right to privacy because you have nothing to hide is no different from saying you don't care about free speech because you have nothing to say. – Edward Snowden”

Maybe I'm foolish, but I have this hope that a shift from the "make money off of mining your data" business model to something else, perhaps like crypto/tokens enable, might just enable the convenience you speak of, without forcing me to sell my information because everyone else didn't care to value their data.