HN user

alpos

303 karma
Posts0
Comments129
View on HN
No posts found.

More like a different kind of sharing app/company as the potential starting point to people figuring out how to live the way they want to. I am indeed wondering out loud about whether anyone would participate in such a system.

To me, it could look like a bunch of people join a company through an app or something and receive voting shares they keep as long as they are participating.

Members would contribute various kinds of property and only members can vote on who gets to use what, for how long, and what, if anything gets sold to fund the company. At least initially, it would probably also have to be funded by members working regular jobs and contributing cash to the company but pretty shortly afterwards the idea would be to have the business making money on it's own by selling things the members make and want to sell.

The cash would then be used to buy anything the members vote to buy. Which then becomes part of the property pool people can vote on using.

As long as the members are geographically distributed, the company would also need to pay for shipping stuff around when it's time to change who is using what.

If it is profitable enough, then it might be able to provide most or all of what the members need to live their best lives. Short of that, it may at least be able to create a micro version of UBI or something.

There are a lot more details to work out than those of course. I do actually want to see if this approach can do something to help people live they way they want to. However, it's hard to imagine any communists or socialists wanting to join such a company if it is run by someone with a capitalist mindset. Even if that person's motives are pure and clear. Naturally, even if I was administrating such a system, I wouldn't allow myself voting powers in it but I suspect still that wouldn't be enough.

That's fine. The corrective for it is to name the bad conversational behavior where you see it, don't get too bothered about it, and demonstrate the kind of conversations you wish to have instead.

It's not terribly taxing to just say, "that's not the kind of conversation we want to have here" and go on to continue engaging with any specific points being made. And that's doable even when you suspect the post you are responding to might just be trolling. If there is an identifiable point, engage with that if you will, gently and patiently correct or ignore the rest. Kind of similar to being patient with a rowdy kid. Trolls don't get much out of it if they can't get your goat.

The sub-thread below still managed to take on a few people who just wanted to virtue signal with argumentative sniping but others showed up with good points and information, that part was good to see.

Agreed, Nixon was a moron, basically everything his administration did was truly awful. The war on drugs must end, the people put in jail for having or consuming the wrong plants must be released, and the US government should make amends with those people. Anyone still alive who provably participated in that should go to jail for the rest of their lives, ideally occupying the same cells as the people they unjustly locked away.

The process of repairing the damage that was done should include large payouts for unjustly taking away years of those people's lives, if nothing else. I'm not exactly holding my breath on these points, but if we take seriously the idea that the world should become more fair and just over time, we're going to have to square with the wrongs that were committed in the name of unjust laws.

In the post you are responding to, what you see is me acknowledging that, in order to answer the specific questions: "Is the US just as bad as China on this?" or "Is what China does to it's citizens in order to suppress wrong-think being unfairly criticized in light of what the US does to it's citizens in order to suppress drug use and generally be racist about it?"; one would require good data on just how many citizens are sent to jail for what should be trivial acts of speaking their mind or consuming weird plants, and that data is unlikely to be available or good data if it exists since both countries have rather large incentives to make sure it doesn't.

Please also note that I fully granted Akiselev's point that selective enforcement happens in the US even now. There should be genuine outrage over this until it is changed. However, I understand why people can't even keep up with the sheer scale of the bullshit modern governments get up to.

wrong think 99% of time gets you an invite to the police station to "drink tea" and sign a paperwork not to do it again. Maybe occasionally a write self criticism letter.

That is good to know. And genuinely new information for me. Thank you for contributing it.

And the details you offer do help calibrate something of an answer to the question you are responding to. Thank you also for being a great participant in that conversation!

Ask PRC citizen how many people they know has been formally punished, even mildly, for wrong think vs Americans who know someone jailed for drug offense and the numbers will be revealing.

We should definitely like to have real data on that for both countries. It seems difficult to find though. In the mean time I take your seemingly first hand experience as insightful. Thanks again!

I can go with the general feeling here, but to use that to put the US's behavior on par with China's, specifically with regard to each country's own citizens, that is definitely a point that would need some data to back it up. Data that is likely hard to get on both the US and China.

It seems that line of argument would get much deeper into how, how fairly, and on which groups, the various countries have tended to apply their laws.

For now I can fully grant that selective enforcement has and still does happen in the US. The legal system here definitely does leave that possibility open and prosecutors are elected officials, some of whom have provably gone after certain groups or individuals, hunting for a reason to put them in jail.

The specific people referenced in the post I was responding to were not US citizens and should not be expected to be granted legal rights equal to US citizens.

Hicks was captured in Afghanistan in December 2001 by the Afghan Northern Alliance

https://en.wikipedia.org/wiki/David_Hicks

He was captured in March 2002 by Pakistani forces during a raid at Faisalabad, Pakistan. He was held in Islamabad for two months before being turned over the United States forces.

https://en.wikipedia.org/wiki/Ghassan_al-Sharbi

As I said, they were captured as enemy combatants, in a warzone. The circumstances of Sharbi's capture are much more questionable. But from the US's perspective, an ally turned him over as a captured enemy combatant.

It's all questionable and stupid, of course. But the question of their status at the time is relevant to the question of whether the US "vanishes" it's own citizens. These two were not citizens, so what happened to them does not support the case that the US is just as bad as China on that point.

No nation on Earth has a history of treating such captives as full citizens entitled to the same legal rights as it's own people. But maybe that's what we all would want. That's a fair point to argue, separately.

However, that is not the point the person I was responding to was making. Which is part of why I say the examples they offered were ineffective as support for their point.

You may find it helpful to practice re-reading and making sure you understand the case a post is making before responding to it.

You and I clearly agree that what the US did in Guantanamo was bad. You and I also agree that the US can, has, and may yet still violate the rights of it's own citizens as well as the rights of people who are not it's citizens, even in situations where it has signed treaties with those people's nations. And the US government should definitely be held accountable whenever it does something like that.

None of that changes the observation that the US's failure to give full citizen legal rights to Ghassan al Sharbi and David Matthew Hicks, people who were not US citizens, does not make a good supporting example to the case for the US being just as bad as China about "vanishing" it's own citizens.

You are, of course, free to offer concrete examples which would better make that case. That is essentially what I was opening the door for. But here you seem to be responding more to an emotion evoked by how I said something rather than the point I was actually making.

I think people find it insincere because pointing out that both parties in question have a problem doesn't change anything about the situation or the problems.

It is most often used as an attempt at a defense by calling out other guilty parties. Yes, we should like to live in a world where anyone calling out a problem or injustice only does so from a place of unimpeachable moral authority. But we do not live in such a world so we are still left with the need to address problems where and when we can get the social and political will to do so. Using finger pointing as a defense has the effect of making the problem seem insurmountable and therefore sapping the will to fix it.

The more genuine admission might be to simply say, "I admit I have shit on my shoe, and it does stink; however, if you are to hold me to account for that, then I demand you also be held to account".

With that approach people have a much harder time seeing the complaint as merely a self-defense by way of finger pointing and it's much more likely to be taken seriously.

This is where many people in the US are probably at on, say, the Trump indictment. Can't really say it shouldn't happen, he has almost certainly broken a long list of laws for his whole career. But that also shouldn't be the end of it, more like "Great start getting a corrupt and lawless politician in jail! Who's next on that list? When does their indictment begin?".

They may indeed like to disagree, as I'm sure anyone who has broken the law would and is entitled to. Hence the existence of a fair trial and the possibility of a "not guilty" plea along with the opportunity to present a defense before a jury.

One could argue about the fairness of any trial or set of trials, of course, and we should definitely do that and work out what we the people think of those trials as well as what we want to see in a fair trial.

However, if you are trying to say that what those people did was just a protest or just speech, you will need to address the actual crimes the people going to jail were charged with and convicted of. Otherwise, your argument there is not convincing at all.

It's not just free speech when you destroy property, break into government buildings, assault cops and government employees, actually invade and interrupt a session of congress, trespass in government offices, and actually try to locate the vice-president with the loudly declared intent to hang him.

Note that this does not apply to US citizens. US citizens, even those accused of terrorism, still retain their legal rights under US law. That is what citizenship in any country, is.

Can those rights be violated? Yes, governments do bad things all the time. But that is not the same as a foreign national participating in Al-Qaeda training camps and meeting with Osama bin Laden. No nation on Earth has a strong history of giving full citizenship legal rights to foreign nationals and/or enemy combatants captured in a warzone.

Hicks was also returned to Australia to be dealt with by his own government, where presumably he then did retain his legal rights as a citizen of Australia. And at that point it would indeed be a violation on part of Australia if they did not treat him as any citizen of their nation should be treated.

All of that said, Guantanamo has still been a completely broken and messed up situation. We the people of the US owe it to ourselves and the rest of the world to hold our government accountable for that and not allow it to happen again.

It's just if you are wanting to say that the US treatment of it's citizens has been on par with China's treatment of it's citizens, your case may be better served by finding a more direct example.

You are completely dodging the other poster's central point.

The US locks up more people, but not for wrong-think. Instead our country does it for consuming the wrong plants at the wrong time, because our systems are still racist in various ways, and because we have somehow allowed prison to become a for-profit institution.

Those are different problems and they need to be addressed. The war on drugs must end, policing culture and policies must be corrected, the US prison system must be corrected. Other options for dealing more effectively with various social and mental health problems must be instituted.

And none of that is the same as what China is doing to their people, nor does it absolve China of the wrongs it has committed. And it doesn't take the edge off of it either. Going to China can still get you locked up for reasons you don't understand because you said the wrong thing one time and forgot you even said it.

That actually is a more risky situation for most people than making sure they are not buying or carrying around the wrong plants. That is what comments such as the one you are responding to are actually worried about. It's not a raw numbers game for the individual, it's a question of "how easy is it for me or people I know to go to jail for what should be trivial actions?"

That makes your email box effectively a password vault. Might as well use a service designed for that such as LastPass, or 1Password.

Or better still, use a password calculator app such as https://spectre.app/

This kind of approach generates your passwords for different sites based on login information and a single password only you know. No other passwords are stored on any devices or services, not even within the app on the device you are using it on.

Which enables you to have different passwords for each service and solves the problem of "too many passwords to remember" without just having to write them all down in a dozen ways that can also be compromised.

a secret word for phrase that both you and the service you want to sign into know

That would not be a password, that would be something you share. An actual password must be possible to verify without it being stored on any device. On the service side, it's the same as for certificates, as you describe. The service can't store the password because that would invalidate it's usefulness as a way to prove someone is who they say they are. This is why we store a cryptographically secure hash code instead. It is also why the password hash code must be generated on the user's end, not on the service side. You never want to "transmit" passwords in plain text because transmission across the internet is an act of making copies of the data transmitted in the memory and storage of all the devices it transmits across. The moment you send a password across the internet, it is compromised.

So as the service, you don't know the password, you only know that the hash code you received matches the one for that user, and you are reasonably certain that there is no known way for someone to generate that hash code without knowing the real password. Therefore the person trying to login in must be who they say they are.

Passwords and private keys only work as authentication if no one else knows it, has possession of it, or can get access to it. If there is a flaw in any one of those aspects, then the system doesn't actually prove a person is who they claim to be. It only proves that a person is someone who knows, possesses, or has access to that thing. That might still count as evidence that they are authentic, but more will still be needed to actually prove they are authentic.

You never get "realtime" in data processing. Actual realtime systems are a totally different animal. Mostly done in the embedded space, the design of a realtime processing system involves setting up fixed time windows for each task that needs compute time and optimizing the code for each task until it fits into the time window for it, on every execution, every time. This is done in order to provide hard guarantees on how fast a system can respond to new data flowing in. It's usually only safety critical systems that actually have such responsiveness and delivery time constraints.

I point this out because how we talk about a problem determines what solutions we even acknowledge as being on the table here. Saying it's a realtime system when it isn't, or thinking we need realtime processing when we don't, makes people throw out solutions per-maturely, that the thrown out solutions are often right answers.

Once you acknowledge that your system will not be "realtime" and you actually don't have the time-boxing and specific time window delivery constraints that actual realtime problem spaces have, you can weigh all of your actual options with an eye for what will be fastest and most efficient given the budget and hardware you have to throw at this problem.

In the case of networked hardware, the stealing the device part is a relatively minor concern.

For the case of passkeys, expect the bad actors currently playing the phishing game to shift from getting you to enter your password on a fake site, to getting you to install an app that either triggers the push notification to send the passkey or has a way to lift the passkey off the device directly. And in order for this tech to be useful, it will have to be expanded to cover nearly all sites and services available on the internet. So phishing will still happen in the form of bogus sites and services getting past whatever app verification equivalent process Google tries to put in place for services that would like to integrate with their passkey provider.

My claim that the passkeys are strictly worse than passwords applies specifically in the sense that, as a form of authentication, passkeys do not prove that the person logging into the site is actually the person they say they are. Passwords prove that only in the case that no one, who is not you, knows your password. Passkeys only prove you are who you say you are in the case that no one, who is not you, can unlock or otherwise get access to your networked and only loosely secured smartphone. It is easier to hack or steal a phone than it is to read your mind.

Though I grant you the point that one doesn't always have to read the mind, only trick it into giving up the goods. Fair enough but that is still the owner of the password DOING something whereas phones can be broken into through the network, through something the user did (like downloading malware), or through something they didn't do or know to do (like downloading updates).

It can also be broken into by way of something the owner had no control over, like a supply chain attack on app or system updates, a compromised third party service for one of the legit apps you have installed, or a zero-day hack for an app or the system itself.

Those situations are exactly why password systems must be designed NOT to store the password on any devices, whether that's a file on a phone or laptop, or a cell in a database. Every time the password is written down, it is effectively already compromised as an authentication tool because it's no longer just something you know.

The phone unlocks with the bio-metrics but the passkey has no additional lock. Be careful to take note of what thing you are actually "unlocking".

For example, if your 2fa codes for a service are always sent to an email account that uses the same password as the site for that service, then you do not actually have 2FA in that case since any potential attacker just needs the one password to get into your email account and that automatically gives them access to the other service.

If the passkey is stored on the device, and the device unlocks by bio-metrics only, and there is nothing additional but to tap the yes button on a notification in order to get logged in. Then the site or service you are logging in to, has only one factor authentication. You can also notice this in the fact that the system here does not send the raw bio-metric data to the service, only the passkey. Therefore if someone copies your passkey or finds a way to man-in-the-middle the key exchange, they can unlock the the service without having your phone. Again one factor.

For it to be a true 2-FA system, you would have to send the evidence of what you are and actually hand over what you have. Both would be checked, and only then would you be logged in.

In the case of the usual password plus auth app codes. The codes, and the keys the are generated, from are in the auth app. That's not ideal either, it can still be messed with, but that's why we pair it with something you know, which is not stored anywhere (if it is written down anywhere, even as uncovered text in a database, or a file on your device, then the password is not a password any more, it's just something else you have).

IIRC, the code for at least some of those unlocks is available open source. And usually hacks or jailbreaks have a tendency to trend in that direction even when the hackers are charging for it initially. Someone eventually decides to share their code and methods, for the fame or to do a talk, if for no other reason.

The reason I think it will happen fairly quickly in cases like this is that hackers also tend to be more "challenge accepted" as culture whenever the offending restrictive software is particularly obviously stupid or egregious.

I've seen and read up on how some of the communes have gone, but I haven't seen any that made a serious attempt to run a company that way. By using the existing structures as a buffer, as I am proposing, a group could actually make the commune thing work without giving up any modern conveniences.

It's somewhat similar to what Amish people do, and they do quite well at it in terms of sustainably living as they wish even though no one else around them does. They pull that off by trading the things they do want to make for the things the surrounding society has that they actually want.

It's totally possible to do a socialist version of that where everyone lives in modern houses with modern conveniences, share whatever stuff you all actually want to be building yourselves, but when you have to buy or vote on something, do so through the company and as a block. Mormons have largely gotten away with block voting over the decades, and still do, so we also have existing evidence that that works too.

The details are, of course, up to whoever is trying this out, but the overall thing I'm pointing to, that I don't think anyone has given a real go at, is that using a company as a buffer against capitalism. No one has to live without, but individuals in the community also don't have to go play the capitalist game every day just to get what they want or need.

That sounds about right, I try to engage with people on this topic as much as I can without annoying any of them too much. That basically looks like asking them why they don't group up and prove their point instead of individually raging against the machine all the time.

IRL I know two or three people who like to lean this direction from time to time, but even those people seem to be just ranting against the remaining issues present under the version of capitalism we have now rather than truly wanting a completely different system.

Not totally opt out. That's a stupidly dismissive take on this idea. The point is that you would never get a wholesale light-switch style shift in any civilization anyway.

So just start now, incrementally, and see how far you can get before anyone stops you. You would ultimately be exiting the existing economy, but that's what you presumably wanted; to build a different kind of economy that you think will be more fair and equitable. And every single step you can take in that direction proves out whether your way is actually better.

All along the way, you have your collective company acting as a buffer against the capitalist system around you. You can't really exit totally without giving up modern life, so don't try to do that, as you point out, such a move wouldn't really be a desirable or viable way to get this job done. The next best move seems to me to be to just exit incrementally, as much as you like, one step at a time.

Why not do that?

I keep trying to tell the socialists and communists out there that they can totally implement the way they want to live within any democratic capitalist system.

Just make a corporation which all of your people are members of, give voting powers to all members to decide what stuff the corporation buys as well as how members get to use the things. Can even go as far as setting up an HOA or a town where the company is the landlord for everyone or has right of first refusal in every property in that area. Once you have enough people to make some stuff on your own, the company call sell that stuff and that's the only touch point you all have to have with the capitalist economy. With time the members you have, the more stuff you can make yourselves, and the less stuff you company has to sell or buy. Eventually you're totally self-sufficient, don't make transactions, and therefore don't really pay taxes either.

They usually don't go for it because they are not really bothered that they can't live the way they want to so much as they are bothered that other people might still live under capitalism.

Possibly the stupidest day-one DLC play we've ever seen.

"Customers might see that as “a bit of a cheat,”

Because it is a cheat.

There is exactly zero chance this doesn't get bypassed and unlocked for free with the quickness. Better still though, just don't buy stuff from people willing nickel and dime you like that.

Pay real money for real things that you actually own. You will be happier this way.

Just here to note that there are several huge problems with this approach from an actual security standpoint:

First is that this changes from 2-factor authentication (something you have plus something you know) to single-factor (just something you have).

Also be sure to notice in the article that they have changed their term there to 2-STEP authentication, not 2-FACTOR authentication, these are not the same thing, and they know that. It's important that you know the difference too if you want any kind of real security. If you use passkeys plus an authentication code app, then you have 2-steps (for whatever that's worth) but not 2-factors since they are both just a piece of code on your device, if they are both on the same device, that's even less secure since they can both be compromised at the same time, and in practice they will be.

Second is that the now single factor authenticator is strictly worse than a password because it is something that can be taken away from you and manipulated without your permission.

Third is that the keys are not private since the passkey provider is storing them for you and/or copying them around. This means they can be spied on, stolen, or demanded by the government, all without you even knowing someone else got access to your stuff.

The last glaring issue I can see for the time being is that it relies on a simple, easily cracked unlock pin, or worse still fingerprint/facial recognition bio-metrics as the only way to keep someone, other than Google, out.

One might be tempted to think facial recognition or fingerprints are pretty good security but it's already been demonstrated that people can break those mechanisms quickly and the cops can and will use your fingerprint and/or mug shot to unlock your phone if it's locked by biometrics only. They are not allowed to force you to give your real password, but the courts do allow them to use any means they like to break into your phone. Even if they damage it in the process, they just have to pay you back for it, they still get to take your data and use it against you.

Just some things to keep in mind before anyone gets too excited about this "new" invention. There's a reason we still have passwords even though we've had Smart ID Cards (such as DoD's CAC system https://www.cac.mil/) and other device driven access controls for decades now.

"We built a video stream processor by splitting every 1080p+, multi hour long, 30-60fps video into individual images and copying them across networks multiple times."

Not surprising that didn't go will. This strikes me as a punching bag example.

Anyone who has worked with images, video, 3d models, or even just really large blocks of text or numbers before (any kind of actually "big data") knows how much work goes into NOT copying the frames/files around unnecessarily, even in memory. Copying them across network is just a completely naive first pass at implementing something like this.

Video processing is very definitely a job you want to bring the functions to the data for. That is why graphics card APIs are built the way they are. You don't see OpenGL offering a ton of functions to copy the framebuffers into ram so you can work on them there only to copy them back to the video card. And if you did do that, you will quickly find out that you can be 10x to 100x more efficient by just learning compute shaders or OpenCL.

You could do this in a distributed fashion though, but it would have to look more like Hadoop jobs. I predict the final answer here, if they want to be reasonably fast as well, is going to be sending the videos to G4 instances and switching the detectors over to a shader language.

In general, if the data is much bigger than the code in bytes, move the code, not the data.

IO is almost always the most expensive part of any data processing job. If you're going to do highly scalable data processing, you need to be measuring how much time you spend on IO versus actually running your processing job, per record. That will make it dead obvious where you should spend your optimization efforts.

Which demonstrates the problem. When you have a market that only one or a few players can even operate in, that is bound to lead to this exact situation.

The regulations are so heavy and complicated that the best path to profit is to just capture and manipulate the regulators. Which only the biggest power players can do.

So there is effectively no competition allowed here. That doesn't serve the public well at all. We should like to see a market where many more new aircraft companies are popping up with new designs to prove out. Safety as a top concern, yes, but also a path to profit that doesn't have to involve cheating the system.

The overall point is that, even if Boeing can, they can't do it often. And they are basically the only ones who can.

That's not a healthy market and it is definitely suppressing advancement and discovery of new technology that we would all benefit from. What we should like to see is a market where safety is maximized AND it is possible to start a new aviation company with a reasonable chance of success.

The public is not well served by the current regulation environment. It looks like maximum safety concern, but we don't even get to know how safe and efficient flying could be if the tech was actually moving forward at a reasonable pace.

It took forever to even get winglets on most of the big aircraft. We knew about winglets in 1897.

That's the entry ticket price my friend. Beyond that you also have continuing currency requirements and that basic license pretty much only allows you to fly on clear weather days.

Which is also a problem because weather changes during flight. So if you actually want to travel with a plane you rented, you're going to need an instrument rating, which costs about as much as the initial license.

So you're out the price of a new mid-tier sedan, which you had to pay in cash upfront, and all you have to show for it is a card that says you can rent someone else's plane to go somewhere, AFTER they make you do a check ride with one of their local instructors anyway. You'll also then be renting the even more expensive IFR rated planes. And I hope you're doing this with aviation renter's insurance, which most places actually don't make you carry...but planes are expensive, remember? And you're borrowing one because you can't afford your own. And you're a low flight time pilot at this point, so enjoy those insurance premiums.

Software people are well paid enough to do all this, yes. So are lawyers and doctors. But that amounts to around 1% or less of the US population.