HN user

brianpgordon

3,290 karma

[ my public key: https://keybase.io/brian; my proof: https://keybase.io/brian/sigs/pOrpc9JT66_CJmX_oqQuOqqrcN8TB3Iv6Qsu-Ev_pFg ]

Posts7
Comments983
View on HN

I find it very much unsettling that you're portraying as capricious or arbitrary things that I would consider basic human decency. We're not talking about Facebook's font choice here, we're talking about intolerable content that foments racial hatred.

Also, it seems like many people in HN politics threads over the last couple of months are in such a rush to talk about everything in terms of a clash over speech and censorship that they seem to forget about the actual clash over racial equality. There's a ton of important and complicated context around why norms for acceptable speech should change. That context is why the Facebook moderation concerns are able to come from a place of universal values, and not arbitrary zero-sum disagreement.

All these high-minded ideals you're appealing to sound wonderful. Who would be opposed to individual rights? The idea of suppressing opposing viewpoints seems insane. And nobody likes people who act like they're morally superior.

But hang on. What rights, and which viewpoints, and what are people acting morally superior about? Your appeal to those ideals is not as universally applicable as you make it sound. I mean, this is pretty self-evident - one can easily pick examples of completely reprehensible beliefs that almost no one would tolerate.

Let's make this concrete. Someone who supports a policy of the government killing all American Jews could make an impassioned argument about the injustice done when a tyrannical moral orthodoxy imposes its views on a free man and vilifies him for daring to think differently, and about the tragedy of the fact that in its zeal to stamp out the dissenter it would betray its own cherished value of free thought. But it wouldn't be a very convincing argument.

And similarly the left is increasingly unconvinced by people who say that their reasonable disagreements are being demonized and complain that the usual framework of liberal democracy should protect them from that kind of treatment. When someone - anyone - finds a position monstrous enough, they're no longer going to be willing to tolerate it. That's what's happening. The human costs of our current status quo are so emotionally and ethically explosive that people come to see these issues as non-negotiable. Your appeal to those norms of civil disagreement and compromise is just not convincing if you're no longer willing to accept the consequences of playing by those rules.

I'm a Photo (and Designer) user too, just for casual use. The only features I really miss from GIMP are animated gif editing, a "crop to selection" function, and to a lesser extent a click-and-drag perspective transform. The Affinity forums have helpful information for working around missing features, but it seems like some people there have a weirdly defensive attitude about how there are good reasons for every missing thing...

Designer was a bigger win for me because I've always found the Inkscape UI baffling.

It may be a technically superior API but even so I'm not thrilled that if I want to stay current with MacOS updates past the phase-out period then I have to pay for a Little Snitch 5 license. v4 works fine for me and without this API deprecation issue I almost certainly wouldn't be interested in upgrading.

One Word Broke C 6 years ago

The point of a compiler is not to try to show off that who ever implemented it knows more loop holes in the C standard, then the user, but to help the programmer write a program that does that the programmer wants.

The author makes it sound like the people working on optimizing compilers are deliberately seeking out these weird corner cases and selecting some random surprising behavior for them out of a hat, gleefully imagining how confusing it will be for end users. That's not how it works. Optimizers can be extraordinarily complex and need to maximize this ill-defined thing called "performance" in a highly multi-dimensional solution space. They ping-pong around inside this space constrained only by the specific requirements of the standard, and it's not surprising that some of the techniques used would produce some counter-intuitive results if the programmer is breaking the rules and relying on undefined behavior. It's kind of like if you trained a neural network to classify cat and dog pictures, and then you showed it a picture of a fire truck and expected it to give you a useful result.

The idea of a new version of the C standard that defines some of the most surprising undefined behavior is an interesting one though, and I'd be interested to see how much that really impacts the ability of the optimizer to do its work.

The Fed's move to cut to zero has been expected by everybody over the last few sessions. This is not new information.

As for why they're doing this, well, monetary stimulus is really all the Fed can do, ineffective as it is, and in the vacuum of fiscal intervention from Washington I guess they feel that someone has to do something. By cutting all the way to zero they also put the ball in the government's/congress's court so the focus is on their inaction, where it should be.

I see the point you're making from an epidemiological perspective but, because it's so important to people from an individual perspective to avoid contracting the virus, I have to take issue with your claim that it is likely possible to contract the virus from a surface after a period of a week or even weeks. I haven't seen evidence that would substantiate such a claim. According to that preprint linked above, even a period of one week on a steel door handle is more than six half-lives past the "death" of the last detectable viable COVID-19 virus. The science is not all in yet, and it may indeed turn out that COVID-19 is much hardier than we thought, but until then I don't see how you can say that it "probably can" survive for weeks in some cases.

I apologize if this is coming off as pedantic but the damage being done by misinformation and speculation about the coronavirus is significant, and I don't think it's possible to be too zealous about precision here. Trump's claims that fears were overblown and a "hoax" have been amplified into widespread and potentially deadly skepticism that coronavirus is even a danger. People have suggested various quack cures that at best drain the resources of vulnerable people. Even saying something as seemingly-innocuous as "wear a face mask to reduce your risk" ends up having a devastating impact on healthcare providers who really need the masks but can't source them. We should be listening to public health authorities and mainstream health experts, and taking reasonable precautions, but absolutely refraining from speculation that might have unforeseeable consequences.

The relevant part of the CDC quote was "because of poor survivability of these coronaviruses on surfaces, there is likely very low risk of spread from food products or packaging that are shipped over a period of days or weeks" and the study preprint you linked showed that in the worst case (polypropylene surfaces) no live virus at all was detected after 72 hours while on cardboard it was more like a third of that time (with large error bars).

I'm just going to quote the CDC again, because public health authorities are really the best sources of information we have and I don't want to participate in the "telephone" effect that paraphrasing begets:

The virus is thought to spread mainly from person-to-person.

* Between people who are in close contact with one another (within about 6 feet).

* Through respiratory droplets produced when an infected person coughs or sneezes.

These droplets can land in the mouths or noses of people who are nearby or possibly be inhaled into the lungs.

https://www.cdc.gov/coronavirus/2019-ncov/about/transmission...

No. From the CDC:

It may be possible that a person can get COVID-19 by touching a surface or object that has the virus on it and then touching their own mouth, nose, or possibly their eyes, but this is not thought to be the main way the virus spreads.

In general, because of poor survivability of these coronaviruses on surfaces, there is likely very low risk of spread from food products or packaging that are shipped over a period of days or weeks at ambient, refrigerated, or frozen temperatures.

Usually the point is the account balance and gains at the top above the chart. It's been a few months since I used RH but I believe you have to touch and drag to see the point you're touching be labeled. The real problem with the screenshot is the lack of labels on the X-axis. It might at least be interesting to see what dates the spikes corresponded to.

I'm excited to be starting in Mountain View soon but I'm pretty apprehensive about having an effective orientation and getting up to speed if everyone's working from home. I've read that orientation is supposed to be a big event where you meet tons of people from around the world and learn together about internal Google tech and culture. I would hate to miss out on that experience because of the coronavirus fears.

Anyone who still keeps a balance there is insane.

Robinhood accounts are protected by the SIPC. Although with other discount brokers introducing free trading, I would tend to agree with you that continuing to use RH with its simplistic interface and appalling execution is pretty silly.

A couple more really odious offenders in MacOS-

1. Needing to hold the option key when right-clicking in order to even see an option for moving a copied item. I don't mind the use of copy->move instead of Windows's cut->paste but why does it have to be hidden? This is surely one of the basic operations you want to perform in a file manager!

2. Needing to right click and select "open" in order to run an unsigned app for the first time. This is a counter-intuitive and pointless ritual - there should be no difference between double-clicking and selecting "open" from the context menu. If Apple wants to ban unsigned apps they should just do it, instead of hiding a workaround behind a trivial trick that the unsophisticated users Apple is ostensibly trying to protect can easily discover by accident.

That doesn't seem like a non-serious criticism to me. They're trying to build something huge that's of immense strategic importance looking forward potentially decades. It seems appropriate to adopt the utmost caution about incorporating a language that's promising but for which widespread traction might not materialize as expected. Though to be fair, the same (and more) might be said of Dart...

I suppose if someone successfully created an ML-powered optimizer, powerful enough to level the playing field with C++ as the author suggests, in a higher-level language then they could run it on itself and there would be no need for C++ in the loop. Training the first unoptimized version of the model might be expensive, but if Google can throw $1.4 million of capacity (https://twitter.com/eturner303/status/1223976313544773634) at training a chatbot...

It should, I hope, go without saying that nobody is required to run a bounty in the first place, and most companies probably shouldn't.

Really? Most companies? That seems like an extraordinary claim.

I'm not a security researcher but if I stumbled on some security issue in something that's not open-source and not owned by my employer, the only way I'd consider reporting it is if they have a bug bounty / responsible disclosure program. Otherwise I'd expect it would be about as likely for me to receive a "thank you" as a knock on the door from law enforcement.

I feel like this is over my head, but if the problem is that sorting a vector produces non-differentiable kinks in the output then why not just run a simple polynomial regression over it and differentiate that?

I'm a data hoarder and I organize meticulously, so I get where you're coming from. But I often need to do searches along different dimensions than the "primary keys" I chose for organizing the directory structure. Search is indispensable for this.

As an example, say I have records related to my taxes - a bunch of documents and images - organized into directories by year, and I want to copy all of the images for the last 5 years out into a temporary directory so that I can flip through them easily. I can browse to my taxes directory, do a search for "kind:picture" then sort the results by modified date and drag the relevant items into the destination directory.

For some types of tasks this is so convenient that sometimes when I'm ssh'd into a server on my home network I'll move files into a mounted network share so that I can manipulate them from Windows Explorer. Clicking around a graphical file explorer is just way less cognitive overhead than stringing together a big command on the command line. Windows Explorer in the Windows 10 era isn't great, but it's much better than e.g. Finder or Thunar, which are my other options on my home computers.

If the index isn't updated instantly then they should account for that by first searching the index (for speed) and then manually trawling through the Start Menu folders for results which are missing from the index.

Anyone that can talk to the apiserver that injects certificates can probably convince the system to give you a certificate for your rogue container.

This is pretty infrastructure-heavy but I think my ideal solution would be to have a trusted orchestrator service on every machine which has its own certificate and accepts human-signed build artifacts to be run in a new container on that machine. It could verify the signature of each uploaded artifact and send CSRs for them to a hardened signing server, which returns the certs to be mounted (or sent over a standard initialization API) into the new containers.

Your options for compromising this are:

1. Get a malicious build artifact signed and submit it to a machine for execution. This shouldn't be possible without compromising an actual developer's credentials to sign the artifact.

2. Send your own custom CSR to the signing server to get a signed certificate. This shouldn't be possible without compromising the certificate from one of the orchestrator services to sign the CSR.

I think this should work as long as you can guarantee that services can't break out of their containers and as long as there's some hardware root of trust ensuring that your orchestrator service is genuine and the only thing that can read its CSR-signing certificate.

If you take protecting your users seriously then any of their personal info counts as a "valuable" so yes, you should secure everything. And it strains credulity that you might be running any kind of actual business where it would be appropriate not to take protecting your users' data seriously. Even if you're doing something as mundane as hosting cat pictures, you have email addresses and password hashes and analytics data.