HN user

arubania2

46 karma
Posts2
Comments32
View on HN

they didn't have antibiotics, anesthesia or life-saving surgeries. They didn't have access to a grocery store a short drive away, or a fire department.

They wouldn't even dream about these things, so they weren't unhappy because of it.

You can't feel like you need something if it doesn't exist (in your era at least).

Today we still don't have casual space travel, time travel, the elixir of life or the wonder drug, but it's not the lack of these things that is making us unhappy.

No it’s not.

Maybe to _you_, don’t assume other people are the same way.

Along my whole career path (I’m a senior now) I’ve always been curious about the high-level technical stuff and took every opportunity to listen to knowledgeable people.

I think there’s a term for it: incidental knowledge transfer.

You might be stripping that person of the opportunity to grow, or maybe just to hear about something interesting for them to follow up on later.

iPhone = Privacy? 4 years ago

I think they probably mean that this switch is software-based, so turning it on does not physically disconnect the underlying hardware.

I doubt there is any proof that some kind of system activity is still taking place while in airplane mode, but that might be irrelevant.

For some people, depending on their threat model and personal preference, what's important is that it's impossible to prove beyond any doubt that this is _not_ the case.

That is a fair point, indeed this would probably make the configuration page extremely complex. I guess my suggestion would only work for cases where you don’t really care much about other kinds of notifications.

this is a commercial relationship

100% agreed, therefore, we should keep emotions out of it.

People going there... could complain. Or take no sugar. Or choose a different coffee shop. Honestly, it's up to them. It's pretty reasonable to feel a bit upset though, I think, in that situation.

Exactly, they can just leave, pick an alternative. Why do they take to social media and cry about it? What do they expect to gain this way?

You have costs to cover? Well, I'm sure you'll figure something out. You'll probably lose some customers and gain some others. Maybe it'll work out; maybe it won't.

Indeed they have just figured it out - they started charging for sugar. They will lose customers, most likely, but I don't believe they haven't seen that. I'd wager that it's the customers who got caught by surprise, and our now making a big deal out of it.

In short, I agree that we shouldn't have any sympathy for the companies in this case - it's just that I'd extend that to the users as well.

That is also true for every password-based account without 2FA by means of password reset.

Plus, having someone access your email account means you're pwned anyway - they can see your sensitive documents that were received / sent as attachments, they can read recent conversations and phish information, maybe even ask for a downpayment, etc.

So the basic rule should be: don't lose access to your email.

That doesn't mean that email-based login is good, just that IMO this point is kind of moot.

Also, do email-based login flows allow 2FA?

"Don't do X, don't break the rule, you're doing it wrong"... that's why people don't write tests

I think that's why people don't read blog posts like this - such wording is rude and patronizing.

and never use your passwords on the phone you are using as 2FA

Notably, this also involves not logging into the same email account that you use for signups - it would allow the attacker to bypass the password manager completely by requesting a password reset.

I guess you could solve this by having one email address for signups and another to communicate with people, but you would still be giving up email notifications (such as “your order has been shipped”) delivered to your phone.

swapping out login pages

Hmm you’re right, I didn’t think of the scenario when they would give you the machine back in a tampered state.

I was gonna reply “well just wipe it once you get it back” but that assumes that I know it happened, so I’m still susceptible to the evil maid attack and such.

Also fully agreed with the last paragraph.

bigger things to worry about

Do you mean things like seeing your photos?

If your 2FA is not stored on the same machine then the attacker won’t be able to log into your bank / brokerage account, and that’s something I consider the main thing to worry about.

Well isn’t that a problem in itself then?

The way I understand it, the password database should only contain the passwords; then if someone got access to it (or your email app, same thing, as they would just do a password reset) 2FA would still protect you.

I tend to agree; I don’t really follow news myself. If there’s anything big going on, I’d know anyway.

But IMO there are two blind spots in that philosophy:

- If everybody did that, even the big things would not propagate. You’d only know there is a war going on if you heard the bombs.

- Voting becomes a problem. Since everything you hear is from people around you, it is most likely an opinion, which you will then echo. Also you might miss stuff which would affect your opinion, but which your friends didn’t care for.

I don’t think outlawing gold would stop the trading. Drugs are also illegal. Also in a crisis such as the one being discussed the laws and the concept of legality doesn’t mean much.

Btw it is estimated that the last time gold was declared illegal, only about 5% of gold owners gave it up.

I don’t think the parent was suggesting that companies stay remote _because_ the employees don’t need interaction.

(IMO companies stay this way because it’s simply cheaper and the hiring pool is bigger, but that’s not important in this discussion)

It just happens to benefit those whose prefer to stay at home.

One idea: use `—-no-install-recommends`.

Also in some cases (not necessarily this one) there may be multiple packages fulfilling the same dependency, so installing a specific dependency package explicitly may also reduce the total number of dependencies - otherwise you could end up accidentally pulling the whole KDE runtime if you’re not careful.

No reasonable scientist has ever claimed that their theory is 100% correct and that it is an objective truth.

Scientific theories are merely our best approximations of how the world works.

Usually it is the anti-scientific drivel that is full of assertions and absolute statements, which is also what makes it so popular, especially among the less educated crowd.

I agree that making progress is of utmost importance, but the concept of truth is much more nuanced and, imo, difficult to define in objective terms.

Stating virtually anything in the form of “but the truth is X” or “I know X to be true” is very arrogant IMO.

“The fundamental cause of the trouble is that in the modern world the stupid are cocksure while the intelligent are full of doubt.” - Bertrand Russell

That said I do realize his goal is to find people thinking outside the box and not afraid to speak their mind, it’s just that he could have phrased it better.

What are browsers doing about it?

I really hate this narrative. Why should the browsers give a damn? There should be nothing required of the browsers, the only ones to worry are the idiots writing faulty UA parsers and baking in their assumptions.