HN user

bramhaag

1,336 karma

https://bramh.me

You can find me on any of these platforms: https://keyoxide.org/0F5C4286BFB0837F2F9DA590499DE67900B12A11

[proof: openpgp4fpr:0F5C4286BFB0837F2F9DA590499DE67900B12A11]

Posts7
Comments153
View on HN

Although a majority of voting Members of the European Parliament (MEPs) actually opposed the regulation (314 against, 276 in favor, 17 abstentions), the motion to reject it failed to secure the required absolute majority of 361 votes.

This vote was urgently scheduled for today, the last day of parliament before the summer break. 113 MEPs were not present for this vote, likely having taken vacation days to extend their break. It's hard to believe choosing to do the vote today was done accidentally.

Signal is one example. Their values are simply not compatible with what the Chinese government wants (local data storage, key access, etc.). Instead of complying and putting their users' privacy at risk, they accepted the ban.

Google, out of all companies, also decided to partially walk away from the Chinese market in 2010 over censorship concerns [1].

Nobody is forcing Apple to do business in China, or the UK. They actively choose to do so, and because of that also put themselves in a position where they have to comply with these laws, presumably because it makes them more money.

[1] https://www.nytimes.com/2010/03/23/technology/23google.html

Im pretty sure Google wouldn’t intentionally cut marginalized people like this off from the entire internet, would they?

Why wouldn't they? Google is notorious for making marginalized people's lives harder if it can make them money. Some examples:

- Hosting Palantir's ImmigrationOS, used by ICE to track immigrants

- Actively removing tools marginalized people use to protect themselves against ICE, such as ICE-tracking apps on the play store

- Intentionally aided Israel in committing genocide as part of Project Nimbus

- LGBTQ creator censorship on YouTube

Cutting off a small group of people they've repeatedly shown not to care about in the first place is a small price to pay to further cement their position as gatekeeper of the internet.

https://beyondfossilfuels.org/europes-coal-exit/ keeps track of coal phase-out commitments. 24 European countries still use coal generators, and 6 have not even planned to phase them out (Serbia, Moldova, Turkey, Poland, Kosovo, Bosnia).

Never used coal power:

  Albania, Cyprus, Estonia, Latvia, Lithuania, Luxembourg, Malta, Switzerland, Norway
Phased out:
  2016: Belgium
  2020: Sweden, Austria
  2021: Portugal
  2024: United Kingdom
  2025: Ireland
Phase-out planned:
  2026: Slovakia, Greece
  2027: France
  2028: Italy, Denmark
  2029: The Netherlands, Hungary, Finland
  2030: Spain, North Macedonia
  2032: Romania
  2033: Slovenia, Czechia, Croatia
  2035: Ukraine
  2038: Germany
  2040: Bulgaria
  2041: Montenegro
[dead] 5 months ago

Spammers won't pay even $0.08 per message because their whole model depends on sending millions for free.

Your LLM forgot that SMS exists. Even a 0.01% success rate on tens of thousands of messages can be lucrative.

GPT-5.4 5 months ago

What makes you think that they see bombing civilians as a bug, not a feature?

Yes, sent*, not sends. Before they got called out, it was opt-out. No consent dialog, warning, or any other sort of confirmation before sending audio to OpenAI. The keyboard is auto-enabled.

Almost half a year after the controversy started, they added a consent dialog (https://gitlab.e.foundation/e/os/murena-voice-to-text/-/comm...). A few months later, they actually made the consent dialog function as intended (https://gitlab.e.foundation/e/os/murena-voice-to-text/-/comm...). Mistakes happen, but initially Murena:

1. sent voice messages to OpenAI

2. did not anonymise said voice messages, only their origin

3. did not ask the user for consent

4. ignored the user's consent after they started asking for it

That is not a good look for a privacy-focused OS. There is now a working consent dialog before using this feature, and audio is actually anonymised (random pitch shifting + filtering + noise), but it took them nearly 8 months to address all of this after getting called out.

open-source means auditable privacy

This is what that auditing actually reveals:

* /e/OS sends user speech data to OpenAI without consent [1], and thought this was ok until they got caught [2].

* /e/OS massively delays security patches, and calls this a "standard industry practice" [3]. Meanwhile, GrapheneOS' opt-in security preview releases provide early access to security updates prior to official disclosure [4]. Also see [0] (Security update speed) and [7] (WebView being 40 security updates behind).

* microG downloads and executes proprietary Google binaries in a privileged environment [5] [6]. You can obviously not audit these, nor should this count as "degoogled".

* microG still phones home to Google by default (android.clients.google.com for device registration check-in, mtalk.google.com for FCM push, firebaseinstallations.googleapis.com for SIM activations) [7].

[0] has a comparison of popular privacy and security-focused Android-based OS, which paints the whole picture. Privacy-friendly does not necessarily mean secure, but in this case "privacy-friendly" is quite a stretch already.

[0] https://eylenburg.github.io/android_comparison.htm

[1] https://grapheneos.social/@GrapheneOS/114880528716479708

[2] https://community.e.foundation/t/clarification-about-voice-t...

[3] https://community.e.foundation/t/e-os-and-security-updates/7...

[4] https://discuss.grapheneos.org/d/27068-grapheneos-security-p...

[5] https://github.com/microg/GmsCore/blob/e19a9985204ec8329c1d9...

[6] https://github.com/microg/GmsCore/blob/e19a9985204ec8329c1d9...

[7] https://www.kuketz-blog.de/e-datenschutzfreundlich-bedeutet-...

I wonder how this compares to GrapheneOS in practice.

https://eylenburg.github.io/android_comparison.htm is a fairly complete comparison. One of GrapheneOS' biggest features is that they sandbox Google services (if you choose to install them), whereas e/OS gives them privileged access by default (via microG). Calling it a "degoogled" OS while microG uses Google's proprietary blobs is... a choice.

The GrapheneOS developers are very sceptical of e/OS (https://xcancel.com/GrapheneOS/search?f=tweets&q=e/os), but you should obviously take biases into account here. Murena's CEO occasionally participates too: https://xcancel.com/gael_duval/search?f=tweets&q=grapheneos

Facebook is cooked 5 months ago

People can curate their profiles, but not search results. Their posts and comments will still show up if you just search on their user page.

Facebook is cooked 5 months ago

My feed has devolved into AI generated propaganda with a scary amount of genuine support. Police brutality against minorities and other politically relevant groups; all fake but with hundreds of seemingly real replies cheering them on.

A split keyboard might still bring you some relief. Modifiers/enter/backspace/etc are usually moved away from your weakest fingers (pinkies) to your strongest (thumbs). I have Ctrl, Alt, backspace, delete, space, enter and shift all on my thumb clusters.

Here's an example of what that might look like: https://kinesis-ergo.com/wp-content/uploads/KB360-GBR_FRONT-... (though in the default configuration, shift is still on your pinky; you can customize this on most keyboards, or on OS level).

The rabbit hole goes very deep. Another option is home row mods: https://precondition.github.io/home-row-mods. A combination of thumb clusters and home row mods can reduce your finger strain a lot.

Gentoo on Codeberg 5 months ago

I really enjoy using Codeberg (as well as my own self-hosted Forgejo instance). It's fast and responsive, and if something is broken or inconsistent, it's trivial to create a PR and get it merged with minimal friction. It's a breath of fresh air after having dealt with GitHub's bs for many years.

Some other FOSS apps I use daily:

Aegis - 2FA (https://github.com/beemdevelopment/Aegis)

Breezy Weather - A very good looking weather app (https://github.com/breezy-weather/breezy-weather)

OnlyOffice Documents - MS Office suite replacement (https://github.com/ONLYOFFICE/documents-app-android)

Fossify Calendar (https://github.com/FossifyOrg/Calendar)

Fossify Messages (https://github.com/FossifyOrg/Messages)

Aves - Local gallery with great organization (https://github.com/deckerst/aves)

Termux - Terminal emulator (https://github.com/termux/termux-app/)

Unexpected Keyboard - A unique keyboard that pairs nicely with Termux (https://github.com/Julow/Unexpected-Keyboard)

WG Tunnel - WireGuard client (https://github.com/wgtunnel/wgtunnel)

These are all easily installed through Obtainium: https://obtainium.imranr.dev/

Claude Composer 6 months ago

These songs sound like royalty-free stock music at best. Bland and inoffensive, with the same uncanny and compressed quality that AI-generated images have too.

Borderline acceptable for elevator music is a long way from the paradigm shift you claim it is.

OpenAI Frontier 6 months ago

They've already changed the wording to

  > At a major manufacturer, agents reduced production optimization work from six weeks to one day.
Make of that what you will.
  > all classic signs of centralisation.
No, these are classic signs of decentralization.
  >  I lost my Mastodon account history because I moved once
Your posts still exist on every server that federated with you, there's just no central authority to coordinate reclaiming them.
  > couldn't interact with half the network or apps because I was on a non-Mastodon codebase instance
Independent implementations having compatibility issues is what happens when there's no central authority enforcing conformance. Frustrating, yes, but it's a symptom of decentralization.
  > lost my account again because I stopped paying for access to the instance I was on
That's just how paying for services works. You could host your own instance, and nobody but yourself can revoke your access.

On Mastodon, if something goes wrong, nobody can cut you off the network entirely. On Bluesky, the author deleted an empty test account and is now blacklisted network-wide until Bluesky support decides to help. That is a classic sign of centralization.

I Like GitLab 6 months ago

Codeberg _wants_ to host open source projects; it isn't leeching any more than adding articles to Wikipedia.

If you feel guilty, you can self-host Forgejo, contribute to Forgejo, or become a Codeberg member and pay them a yearly fee of your choosing (https://join.codeberg.org/).