HN user

btasker

70 karma
Posts0
Comments34
View on HN
No posts found.

they should have stood firm or offer up the 'Oh no we couldn't possibly figure out how to do that, it's entirely too complicated, you wouldn't understand.' excuse all other tech companies put out whenever they are told to do something trivial.

Here in the UK, that's basically what BT said back in the early days of rights holders trying to block this stuff.

The rights holders took them to court and managed to get the court to order them to use Cleanfeed (a system that was only used, at the time, to block Child Sexual Abuse Material) to block Newzbin.

Not only did it help kick all this off but, overnight, it meant there was a socially acceptable reason for people to share knowledge on how to circumvent Cleanfeed.

The rights-holders give zero shits about the collateral damage they create with stuff like this

than you are to find any EU-based product used widely in the United States.

Spotify?

If you don't mind including companies that offer multiple things: Accenture, Amadeus, Capgemini, Mistral, SAP

I'm also assuming there that you're only referring to tech products and services, otherwise you probably want to look at the long, long, long list of pharmaceuticals, cars and other products.

I think the issue is more that you don't have a good understanding of which products and services aren't American.

There is far more leverage with the country exporting goods

True leverage comes from import, not export of goods and materials. The thing that grows GDP is buying materials cheaper from elsewhere, turning them into something and selling on at a healthy margin (whether domestic or as an export).

then nanny-stating them into a form they think is better.

I'm no fan of nanny-stating, but I don't think that that's the case here.

There certainly are examples of that, but then the ones that I can think of (age verification in particular) are also getting pushed hard in the US. In fact, by all accounts, a lot of that pushing is being driven/funded by Meta

Personally, I think this is the answer too - rather than mandating it across all platforms, they could have created a service which provides scanning so that there was an additional app people could choose to install (and would, presumably, present as an accessibility addon so it could access content in other apps).

That's not without its own issues though - creating external deps is more or less what they did the first time they tried to mandate age verification.

Although their plans fell through, they created an industry who'd expected a captive market and started lobbying heavily. Eventually, it worked and we've ended up with mandatory age verification.

All of what you said could be true and it'd *still* be wrong for Grok to be allowed to generate it.

All Musk actually needed to say was "oh fuck, we'll fix that". Instead, he responded with laughing emojiis and nothing's changed.

is not technically illegal in the US

Bully for you.

X is operating in the UK and it *is* illegal here (and not just here). X can either comply with our laws (and the associated moral standards) or it can cease operating here.

There's weird nerd diving in front of Musk to defend him and then there's defending his AI generating CSAM. Neither's a good look, but one is much worse than the other

We have small claims courts in every jurisdiction in the US. It costs $50 to file, and you do not need an attorney.

This particular example is in the UK though.

It's even easier here!

You can issue a Statutory Demand (https://www.gov.uk/statutory-demands) which gives the receiver 21 days to either pay or reach an agreement to pay. Failing to do that can lead to them being wound up.

If, for some reason, you wanted to go the small claims route instead, there's an (ageing) online service (https://www.moneyclaim.gov.uk/web/mcol/welcome).

Unlike the US, the fee isn't a flat fee, and is tiered depending on the amount being claimed (still cheap though).

I've had to use both in the past.

The developer in this case really has no excuse for airing dirty laundry in public. If they're hosting and not being paid, by all means suspend the site, but don't deface it so there's a message about not being paid carrying the customer's branding.

His "don't move off 22 for ssh" is also just opinion. He argues "you will be found"

Worse than that, that post misunderstands it's own statement:

"Sure, you will see fewer attacks than before, but most of the attackers are no longer just stupid bots"

That's a *good* thing, because the move has reduced the signal to noise ratio. By getting rid of most of the crufty noise of the internet, you now know that anything hitting your logs now is more likely to be an actual threat than the poorly automated dictionary attack bots.

Moving SSH to a different port doesn't make the system much more secure (and definitely shouldn't be the only thing you do), but it does generally enable you to be more responsive.

The author also make it feel like the only option is to use cloudflare DoH on Firefox

In fairness, the date on the post is 2018 - when Firefox first launched this, Cloudflare was the only option

Yes.

DoH requests go to /dns-query so you only need that path to proxy onto your DoH handler.

Some DoH clients will also allow you to specify a custom path, so you can also obfuscate the path by configuring client and server to use /foobar instead.

But, re-using an existing site does come at the cost of generating a bunch of extra log noise (fine if it's just you, not so fine if it isn't). If you don't have some kind of auth in place, you might also find that you suddenly come under a lot of load (when I ran a public DoH service, I eventually started getting a lot of traffic from users in an authoritarian country)

They all default to ISO sizes for me.

If I format the page size, Libreoffice does offer "Letter" and "Legal". GIMP shows them as "US Letter" and "US Legal" but again they're not the default.

It wouldn't surprise me if most non-US users hadn't seen them at all, and certainly not that they don't realise the US uses a different size.

At some point people know if you don't care about them. If you cannot care about them why would they "follow you into battle?"

That's true, but it also works both ways.

If the "problem" person is impacting others on your team, you owe it to them to address rather than ignore the issue. After all, why would _they_ follow you into the trenches if you've shown that you don't care enough to deal with an issue that they're saying is making their lives difficult.

(Good) management is about striking a balance - between the business's needs (otherwise you're all out of a job anyway) and the welfare of everyone on the team (which IMO, should always benefit from a bit of priority over the other).

Sometimes that does mean making a hard decision about someone who's very technically capable, but damages the wellbeing or efficiency of the rest of the team.

As an extreme example - I once worked with someone who was a pretty good engineer and knew where a lot of the bodies were buried in the codebase (i.e. keeping him around would be beneficial), but one day he started regularly talking, quite inappropriately about schoolgirls in the team skype group (and even defended doing so). Good engineer or not, sometimes things have to change.

All of that being said, I think the article is too hardline, at least if those are intended to be the opening gambit. There's a ton of people engineering that you can do before you need to reach the point of making it sound like a PIP.

GDPR (including the UK GDPR) is extra-territorial by design.

It applies _by design_ to anyone or anywhere processing the data of an EU or UK citizen.

I suspect that you and I would agree about the wrongs of any law being extra-territorial, but it's where things on both sides of the pond have landed us.

You already linked to the relevant part of the ICO's guidance but *appear* to have misunderstood it: you've inserted an extra requirement - that it requires taking payment.

That's not the case, it applies just as much to free services.

Wordpress.org (and more so the associated services - slack etc) being available and (more importantly) *collecting and processing data* is offering a service.

Fun fact, in the UK data protection laws will still cover cameras and whatnot taken from a household

They do indeed. In fact, it's not just cameras: as soon as you publicly share information you can't rely on the exemption because it doesn't cover it.

Yea, but there is no standing for the UK to apply its laws on Matt.

You keep using the word standing, which is very much as US-centric term. I'm not, for a second, suggesting that anyone would try and enforce this in a US court.

Being able to enforce is (as I've already said) an entirely different kettle of fish.

Their entire claim would be to apply UK law to someone not operating within the country.

Yes. Welcome to the intended design of GDPR.

Although you're right that EU GDPR and UK GDPR are now two seperate things, they're not actually particularly different things: we didn't really amend it after leaving the EU - the two are seperate since Brexit, but the way that they work is the same, albeit absent a few years of caselaw.

In fact, it's not GDPR that's extra-territorial (or intended to be). Have you seen the stuff they've been trying to bring it to make the internet "safe"? That's extra-territorial in nature too.

Ever since the US passed the CLOUD act, politicians on this side of the pond seem to have decided that what's good for the goose is good for the gander.

dotorg being run by a private citizen who receives no payments does not exempt it from GDPR, because GDPR doesn't make that distinction.

There _is_ an exemption for household processing (recital 18) - which means that I don't need to worry about taking a neighbour's contact number etc - but wordpress.org wouldn't fall under that.

Given Matt's actions (and statements made by his own team so far in the case), I think he'd struggle to claim that wordpress.org is not linked to "professional or commercial activity".

It might be quite difficult to enforce against a private citizen, but that's not the same as it not applying.

I don't think

No, you just act and screw everyone else.

There's no justification for this whatsoever - it was your actions which meant that the ACF team couldn't manage the plugin on dotorg, and the issue you fixed was unbelievably minor.

IF you even had a point in the beginning, you've fatally undermined it. Hell, WPE's motion for a preliminary injunction even now notes that your actions here have potentially fallen into CFAA territory - https://storage.courtlistener.com/recap/gov.uscourts.cand.43...

Given you've been banning dissenters from Slack, I wonder "why" people might not be reporting issues where you can see them?

I can't say for sure that it directly led to jobs, but my website has been brought up in a positive light during the recruitment process more than a few times.

Because I write about technical things a lot, it's often been viewed as "evidence" that I'm an experienced technical writer as well as an engineer.

But, it (and my github account) have also been flagged as "risks" by a recruitment agency though: I can be a bit sweary at times and they felt that having a project called F*ckAMP might put off potential employers. No-one else has cared though.

But, to echo the advice that others are giving you - the "power" of my blog lies more in it being stuff that I want to write, rather than stuff that I'm writing because I think that it'll help my career.

Deciding what to write about can be hard, and sometimes you'll find you hit a block and don't write about anything at all. Those are both fine, just write about stuff when you want to and don't pressure yourself to write "just because".

Much earlier in my career, I was in the UK public sector.

Internal interviews within the department were conducted using something that mixed STAR with a set of core competencies (external candidates were given a bit more leeway).

So as the interviewee, you had to reply in the style of STAR but also ensure that your answers tied back into those competences. To have a chance of success, you'd need to demonstrate as many competences as possible.

As a methodology it makes it extremely easy for the interviewer to assess suitability (especially for candidates trying to move up the chain - there used to be a qualification assessment for that too) and to do so in a way that can easily be explained/defended if a decision is challenged.

As an interviewee, though, it really was the most awful experience. The questions themselves weren't codified, so the interviewer could ask whatever they liked and you had to find a way to tie it back to a relevant competence in order for your answer to "count" and then explain using STAR.

The problem, in my view, is that there's a huge difference between what works for interviewers and what's likely to work for an interviewee. STAR makes it easy for an interviewer, but it's not the way that engineers normally communicate - just as coding challenges are often quite unnatural (like everyone else, I've had some awful technical interviews).

First, let's be fair, Germany really is an awful example if you're going to then try to apply it to the rest of Europe.

It’s impossible to fire an employee for performance reason after the probation period in Germany.

This is untrue.

It's true that Kündigungsschutzgesetz does set a really high bar.

You can get rid of them if they aren't delivering on assigned tasks, but you need to show that they are able (and are therefore simply unwilling). There's also the possibility of doing it if there are personal reasons (i.e. something in their life has impacted their suitability for the role) but that's more complex.

That's why you see people get assigned easier tasks - they're being given tasks that are so noddy that anyone could do them (a failure to do so showing that they're not really trying).

But it's hard. The level they have to achieve is really low - something like 65% of a "normal" employee.

But Germany is just one country in Europe. Have a look at France, Italy, Belgium or even the UK - it's *nothing* like the level of stringency that Germany applies.

Having an employment contract is more common over here, but that's not the same as what we'd call being a contractor.

As a full-time employee of the company you're working for (i.e. not simply contracted in), you still have an employment contract (it's a right/required) which'll lay out the employment expectations (salary, hours per week, whether you can be required to work additional hours etc).

We do also have contractors - i.e. those who work for an external company who are brought in for a specific project (or to provide easy-to-get-rid-of headcount).

In my experience, working as a contractor isn't all that much more common than in the US. But people having some form of contract is, because basically all employees have one.

No, it's the result of that poster's mindset - there's absolutely no need to do any of that. In fact, that type of behavior is against the law in a lot of countries and will leave the employer likely liable.

If someone's under-performing whilst in their probation period getting rid of them is incredibly easy. Outside of the probation period there's a bit more of a process, but it's still not particularly hard - all you actually need to be doing is documenting.

I'm not sure that using a browser integration rather than having credentials pass through the clipboard really counts as an edge-case.

In fact, I'd go further and say it's exactly the use-case that should be being encouraged. As well as avoiding the issue of clip-board watchers, it also reduces friction and increases the likelihood of ordinary users being willing and able to use it.

Using a hardware key to unlock the database arguably is more of an edge-case, but conversely I'd argue that it's not acceptable to simply break that workflow.

So, IMO, Klode was very much the "computer says no" part of the analogy. He changed the process so the default was to turn away live use-cases.

I’ll admit it is not in the UK, but I doubt they have a significantly less professional police force.

Ah, that explains a point that I'd didn't bother to pull you up on.

Carrying ID is not a routine thing here in the way that it is in some other countries (there have previously been attempts to introduce a national ID but they were staunchly opposed). So, it's not a given that you'll have ID on you to show them.

Drivers probably have their driving license in their wallet, but even that's not guaranteed (because you don't have to have it on you when driving).

The "quality" of police varies by force (and, of course, by officer).

The Met, though, have had some pretty serious issues with misconduct (including sexual assault and murder) and are still working through the processes of identifying personnel who shouldn't be in uniform at all (the Met themselves found there were hundreds of officers who should have been sacked previously).

They're working to fix things (or claim to be), but you probably don't want a force that's been described as "institutionally racist, sexist and homophobic" to be entrusted with something like this.

For anything where failure means death, sure. For situations where failure means a minor inconvenience, maybe not so much.

I would still say the failure rate is too high given that the outcome of interactions with the Police varies quite significantly (par.

To me, the only relevant point of comparison here is the rate of misidentification by officers while _not_ relying on the face id tech.

I'd also be interested to know this. But, I don't think it'll go quite the way you expect.

I'd expect there'd be _fewer_ overall stops: coppers simply won't (mis)recognise as broad a range of people. If they're only stopping people they recognise (or based on stuff that's been radioed through), their success rate is probably better

Easy answer: yes it'd be better.

TFA says that it has a failure rate of 1:33,000. That's a "do not ship" rating for almost anything else.

immediately stopping you the only thing you have to do is pull out your ID?

Someone I know was detained on the side of the M25 for an hour sorting things out after being pulled over.

He presented the police with his ID and they decided it was a fake. His name was almost identical to someone who was wanted - his middle name and date-of-birth were different.

The Police said that was common on fake IDs - just change a few small bits of information - and that they'd have to take him to the station where he could sort it.

The only reason he didn't get taken in in the end is because the description of the wanted person noted that he had tattoos on his chest. On the side of the M25, at night, the only thing that stopped my mate being hauled into a London police station was taking his top off.

Anecdotes don't make data, but the idea that a copper will simply accept ID despite a system saying "this is your guy" is incredibly naive and suggests you've not had to interact with them much.

Telling someone wrongly that they are a thief, in public, seems like libel

Slander.

Libel is published, Slander is spoken. If they put a picture of her on a sheet that said "shoplifter" and posted in on the wall (or the net), it'd be libel.

But, I don't think you'd win a case based on Slander either:

* you'd still need to show it was published to a third party (though as you say, maybe you had friends present) * They can show that they reasonably believed it to be true (the system told them so). Their wording then becomes incredibly important - did they say "you're a shoplifter" or "you've been identified by our shoplifter recognition system"

They might also try to argue that stopping shoplifting is in the public interest and that this was a statement of opinion related tot hat.

I agree though, if this happened to me, I'd definitely be sending a letter or two to dissuade them from making a similar mistake in future (I think I'd also be trying my luck with Facewatch given that their system disseminated that "information")

I didn't have the same luck.

I gave it a photo from inside a house, you can see a person on the bed, and the white wall behind - that's it.

Obviously I wasn't expecting an accurate location, but

This photo was taken in Los Angeles, California. We can tell this from the architecture of the buildings in the background, as well as the vegetation. The palm trees are a dead giveaway that this is Los Angeles.

There are no palm trees, the photo wasn't taken in the US and palm trees exist outside of LA.

I also fed a photo of some quite distinctive castle ruins. It mislocated that by 100s of miles.

most CDNs will send every single request in that period through.

I don't think this is true. It certainly isn't for any CDN that I've worked for or on.

Cloudflare don't do this either - they use a cache lock - the first request basically acts as a blocker for all the others, leaving the other requests waiting for the response (if it's cacheable they serve that response, if not then they proceed to origin).

It's normally configurable, but most sane CDNs do have it enabled by default, precisely because big bursts tend to be sharp in nature and a cache miss can be origin breaking at that point.

Just for completeness's sake, Nginx's HTTP proxy module can do it too (the setting's proxy_cache_lock) though it is off by default there.

I see forced purchases of insurance for people with nothing to insure as similar to debtor's prison

That's probably because you're looking at it entirely wrong.

The third-party cover in insurance is not for you (the driver), it's for the poor sod that you turn into a pavement stain.

If you kill them, their family has had someone taken away from them - would you be happy with $50K for the loss of a spouse?

If you don't kill them, but inflict life-changing injuries, the resulting lifetime healthcare costs could easily be more than $50K.

When you take to the road, you do incur some risk, but on average you pose more of a risk to others, particularly if you've chosen to drive a car that you can't see in front of properly.

The UK introduced compulsory third-party cover in 1988. Even back then, the cap was £250,000 - it's not led to any societal problems (although, the accident rate in the UK is far, far lower than in the US so policies probably are going to be cheaper).

I do agree, though, that 10 mil is definitely pushing it a bit far.

Apple reported 30bn net sales in Europe in the last quarter: the second biggest region after the US. Although some of that'll be driven by non iOS stuff, we know that's the main earnings driver.

In a future where Apple have withdrawn the app store, who in the EU is going to buy an iOS device?

Sorry, but the idea that they'd be able to justify pulling out to shareholders over this is pure fantasy.

edit: source - https://www.apple.com/newsroom/pdfs/fy2024-q1/FY24_Q1_Consol...

And finally, tests enable new contributors to work confidently from day one.

Exactly this.

If I run into an issue when using OSS, I tend to try and look at contributing a fix back.

The projects where this is most successful are those with a good range of tests - I don't have the time to sit and learn the workings of a project inside out for the sake of a single fix, a good test suite helps reassure me (and them) that I've not inadvertently broken something.

That same benefit exists for new starters working on closed source codebases - they can hit the ground running much faster, confident that tests will help make sure they don't accidentally blow things up.

But, the OP is also right that tests need to be written in the correct way - built based upon the intent, rather than the code that was actually written (where I can, I tend to try and write a test first - even if I might later need to go back and tweak it)

Hey, OP here.

Figured I'd reply once, at the current bottom of the thread.

Since I have over the decades made several insurance claims that were paid out

I assume that either wasn't for this situation, or you are not in the UK.

House insurance *might* cover a package that was stolen after being left on the front doorstep, but it certainly doesn't cover items that never actually arrived at the insured property.

When purchasing with a credit (rather than debit) card, the "insurance" we have is provided by Section 75 of the Consumer Credit Act. For purchases over £100, the card provider (Amex in my case) effectively indemnifies the purchaser against anything that the retailer would be liable for under the Sale of Goods Act.

That's not a "provider being nice" thing either, s75 means that the contract for purchase of goods is with them.

they’ve allowed themselves to be subordinate to Amazon and Amex corporate internal processes. I struggle not to label that as vassal thinking.

Or, perhaps, you know, understood how the law works where I am.

When this happens, you call the police

Here, I'm definitely assuming that you're not in the UK. If you were, you'd be well aware of just how stretched and underfunded the Police currently are. They're not turning up for this.

I laid out in the post why I don't believe it's me who needs to, but as we're here lets take it one step further.

If I were to report it to the Police, Amazon may well try to use that as an argument that it's my problem to solve, not theirs. They would, almost certainly, pull "we can't do anything whilst there's an ongoing investigation".

That, by the way, isn't something I've pulled out of the air. Since publishing the post, I've been contacted by a lot of people - a lot of them have been told by Amazon that they "must" get a crime number: if they can't get the crime number, Amazon refuse to proceed. Those that did get a number... their cases are still stalled.

Reporting it to the Police not only wastes Police resources, it gives Amazon a means to try and drag this out further.

The correct procedure is:

- Raise it with Amazon - If Amazon do not/can not resolve, invoke section 75

I've no idea how the Police in your area would handle it, but here we'd be lucky if we were given a crime number.

thought of reasonable reasons why the driver would act that way.

I completely agree, it could equally have been someone in the warehouse. That doesn't change my gut feel that it was the driver though and, really, it doesn't matter what my gut says: ultimately it's for Amazon to investigate and root the problem out.