HN user

aimazon

799 karma
Posts1
Comments122
View on HN

Some people are protesting against this law by threatening to shut down their websites or by deleting content. The founder of lfgss explicitly said they’re against the law on principle.

I think historic content is very valuable which is why I am offended by this absurd response on hacker news where people are conflating the actions of a protest with the consequence of a law.

If someone chooses to protest this law by deleting their website then more power to them but we must be honest about what it is: protest.

People should be considerate about the consequence of the services they release onto the internet. We can debate the specifics of whether certain requirements are reasonable/fair/beneficial but it’s patently absurd to label choices these website owners are making as being caused by this law. The law has zero to do with historic content, there’s not a single risk to anyone who leaves a website online in read only mode as an archive.

You’re falling for the big numbers that do not stand up to scrutiny. There’s no such forum shutting down. Are you referring to lfgss? First, it’s not shutting down, second, the user numbers are completely wrong. As is the claim that the platform supports over 300 forums. You’re an order of magnitude off. Go and visit it and look at the activity, it’s clinging to life. 275k active users? Pure fiction.

The forum has had less than 100k posts in the last 10 years.

Forums and small websites have been killed off by changing consumer behaviour, the shift to big social media platforms. Using big numbers to suggest that the UK Online Safety Act is responsible for killing off these smaller independent websites is disingenuous.

If you do the same exercise for the other forums, you’ll find they’re all long dead too.

Headline: 2.6M posts

Reality: the forum has negative 358 posts in the last month. The forum has negative ~2k posts over the last 12 months. The forum is so inactive that they’re deleting posts faster than creating them. 8 people have created accounts in the last year.

The forum has been long dead.

obviously some government employees are not providing value for money to the people because that’s just what happens in big organizations (public or private). The point being made by critics of DOGE is not “there’s no waste in the government” it’s that the DOGE goal is to gut government services, whether they’re wasteful or not is immaterial.

I was wondering what happened to micro recently (loved the m3o domain). Sorry to hear it’s over. Have you written a post-mortem? I’d love to hear more about it — if you don’t feel too downbeat about it.

(is the domain for sale?)

In memoriam 1 year ago

There has been new information since that blog post which has reaffirmed the "this is much ado about nothing" takes because Ofcom have said that they do not want to be a burden on smaller sites.

https://www.ofcom.org.uk/online-safety/illegal-and-harmful-c...

"We’ve heard concerns from some smaller services that the new rules will be too burdensome for them. Some of them believe they don’t have the resources to dedicate to assessing risk on their platforms, and to making sure they have measures in place to help them comply with the rules. As a result, some smaller services feel they might need to shut down completely.

So, we wanted to reassure those smaller services that this is unlikely to be the case."

In memoriam 1 year ago

You're right. Plus, the overreactions have been walked back or solved in some cases, e.g: LFGSS is going to continue on as a community ran effort which will comply with the risk assessment requirements. Most of the shutdowns are on long-dead forums that have been in need of an excuse to shutter. The number of active users impacted by these shutdowns probably doesn't break 100.

I am glad to see you renamed to forms from blocks :) I am not saying that your work is bad but even if your work is bad you can make money hand over fist so questions of "good" or "bad" are immaterial[1].

As a solo developer walking a well-worn path you're in a fortunate position. You can poach customers from competitors and differentiate based on customer's having direct engagement with you, the founder, and price, because you don't have expensive developers to pay.

Identify a single use-case that your software is good for today, and then spend some time identifying prospective customers based on companies using your competitors for that use-case, then reach out and undercut your competitors based on your values. A competitor's case study / customer stories page is the classic poachers first port of call.

Persistence will pay off. Most of your outreach will fail, most of your ideas will fall flat, most of what you think matters won't matter and most of what you think doesn't matter will matter. That's okay.

Anything can be made into a company. Can you make this into a company? Nobody really knows until you've tried, but the idea has potential and you have the necessary skills to pull it off so there's no reason it shouldn't be possible.

The biggest difference between developers who write software and founders of software companies is a focus on customers. If you're struggling to see a clear path forward, it's a sign that you are probably spending too much time writing code and not enough time thinking about / talking to customers. You'll know you're doing enough business things when you start to feel like you're letting the software slip.

[1] I think it's great but that would undercut my point that it doesn't matter

Travel can be as easy as you want it to be if you are willing to spend money and/or plan. Stay at hotels that are part of a hotel group (e.g: Marriott) and check-in will be seamless. Use airport transfers and someone will be waiting at the airport with a sign and take you straight to the hotel (any reputable hotel will arrange it for you at a fair price). Use a global e-sim that you can activate when your plane lands. The pain you're describing is a choice (a completely reasonable choice to make for many people, but a choice nonetheless).

I am no fan of the UK but "worst weather on the planet"? The UK's greatest fault is that it is mediocre, it is uninspired, it is neither good nor bad, it is a place with so much potential that realises so little of it.

If economic opportunity is your motivation then the U.S. is a much better place to be than the UK, but if you'd just like to live a normal life with healthcare and a house, the UK is a far better place to be than the U.S for most people. "Economic opportunity" as a motivator is itself a U.S. mindset.

Major YouTube channels are typically managed by multiple people through the channel management features and brand accounts. I don't think it's possible to even log in to the brand account (which has a generated email address like channel-000000000000000000000@pages.plusgoogle.com) instead it can only be accessed through an authorized user's account (which are distinct from the channel, i.e: it's not the email address that would be surfaced by this attack). Granted, things have changed over the years, so there may be old channels lingering with Google account linked email addresses, but from what I can tell, all channels were converted a while back.

https://support.google.com/youtube/answer/7001996?hl=en-GB

edit: My hunch is that the channels the OP's attack was able to target are not actual channels but rather YouTube users (who have a "channel" because that's how YouTube represents users): so "YouTube User" is the correct description of this attack, which is distinct from what you're thinking of as a channel.

Fair Pricing 1 year ago

I think this is a vast overestimation. The majority of people notice every payment they make every month, a Netflix subscription is a choice that they would not continue to make if they were not using Netflix. Those of us who can afford to pay Netflix whether we watch it or not are the minority of wealthy people. I think you would be surprised to learn how many normal people juggle different subscriptions by cancelling/subscribing each month.

Yes, you need to get better at filtering. Yes, it has always been like this. Public job listings have always attracted mostly junk.

The typical good candidate becomes a good candidate through years of experience. The years of a good candidate's experience has exposed them to many people, many people who would love to work with the good candidate again. And so when the good candidate is looking for a new opportunity, or even when they're not looking, there's a bunch of people waiting in the wings, longing for the opportunity to hire them. A good candidate is probably not going to end up trawling job listings. A bad candidate probably is.

Public job listings aren't all bad as they can bring in candidates that you might not have otherwise encountered... and these can be very influential and beneficial hires, but in general, public job listings are for the people who couldn't find a job otherwise. You're looking for a diamond in the rough.

Your company is doing the right thing by pausing the search, it is a very bad use of time. Find people through the founder's and employee's personal networks. A vouched-for candidate in the hand is worth 1,000 applications in the bush. If personal networks aren't an option, the alternative is to do what candidates hate: keep your applications open without the goal to fill a specific role by a specific date but rather to wait for the right candidate to come along.

Some companies are just very selective, i.e: they're hiring the right people not the best candidate. Most of us get jobs because companies need to fill a role and we're the best candidate of a bad bunch... most of us (whether we have 22 years and a fancy title or not) would not get a job at a company that hires carefully because we're probably not a good fit for their very niche view of what a good hire is.

I think that's just a quirk of HackerOne's username system. The username daniel was previously owned by another account (now known as daniel-hamid) which submitted a bug to Adobe. If you go through @hackermondev's tweets (starting in 2018) they are without question a kid (making games in Roblox and Minecraft) and then started to show an interest in hacking in 2020 (which lines up with when they created their HackerOne account). The claim of being 15 years old is plausible (presumably with parents / guardians who are accomplished in technology).

The counter point is that anyone who cares about being anonymous is using methods to disguise their identity that cannot be compromised by this attack, e.g: a VPN. Plus, there are much more effective versions of this attack, like sending a link to an endpoint that you control -- getting someone to click a link isn't hard if you're considered trustworthy enough to send them notifications. And less technical versions, like correlating when the user is online vs. offline with timezones around the world.

The method that both Apple and Cloudflare use in their own privacy software (iCloud Private Relay for apple, WARP for Cloudflare) is specifically based on the idea that your region is not information that reveals your identity. If you enable Apple Private Relay, your origin IP will be obscured but the IP your traffic is routed through will be in the same country -- same principle.

https://www.apple.com/icloud/docs/iCloud_Private_Relay_Overv...

This attack is academically interesting and novel but it's not "deanonymization".

If I have troubles receiving SMSs from Germany to German number while in US, would wifi calling icrease the chances of receiving the said SMSs?

I'm not up to date on the state of messaging infrastructure but it used to be the case that some providers would offer non-standard methods for sending messages over their network to intermediary providers. Rather than sending an SMS to a number, a business would ask the intermediary to send a message and the intermediary would use the non-standard method provided by the network provider. The non-standard methods work fine if you're connected to the network directly but if you're overseas that will not be the case and so you can't receive these non-standard messages. Don't quote me on any of that, though.