HN user

compbio

1,012 karma
Posts6
Comments123
View on HN

No need to apologize for giving your opinion. I have strong feelings on accessibility and security, perhaps a bit too strong. Others may rank design or "a fast development pipeline" higher than me.

I expect content websites to function without requiring JavaScript. I'll settle for a much poorer experience, as long as I can access the content.

Put more strongly: Nothing is gained (from a user perspective) by requiring JavaScript, but security is lost (Tor disabled NoScript because too much of the web would break, leading to disclosure of user data [1])

[1] http://www.wired.com/2014/08/operation_torpedo/

Visit http://1.2.3.50 to disable this image compression for your device.

Add "Cache-Control: no-transform" to your headers to disable image compression for all your site's visitors.

Web devs should make sites that work without javascript, so that turning on NoScript is also a solution.

The bmi.js injection may look a bit nasty, but it is there to save bandwidth for users who are on a bandwidth budget. Vodafone would profit from higher bandwidth usage.

Interesting. The "new terrorist tool used in the Paris attacks, encryption" is far from new, and that story has revolved around the Playstation network (which the media told us was used by the Paris terrorists, despite the originators of that rumor retracting their story about Jambon).

The "problem" here is not secure communication. It is media propaganda / information warfare. Facebook and Twitter being used to instill hate and spread conspiracies. It is all in the open: Facebook images stating that Israel is behind ISIS, or Twitter accounts that post nothing but Anwar al-Awlaki videos. Could you imagine that happening 10 years ago, on your own homepage, without being raided? If Twitter can block porn, surely they can block terrorist propaganda too. But the law enforcement probably want to use these for fishing. Instead Clinton wants to build another nuke.

"Dad, what happens if Donald Trump wins and we have to move out of our homes?"

These are propaganda tactics close to character assassination. In the next sentence he says that "freedom of expression" unites us, but when Trump uses this freedom of expression he is suddenly scaring Muslim kids. Very recognizable.

especially from someone as untried and as incompetent as Donald Trump.

You just know that they made this a talking point, a hook. And O'Malley wrestled it in his answer, because that is what he prepared.

where do you draw the line between national security and personal security?

Donald Trump is incompetent. Next question! Next!

I think this kind of research is rather unethical and farcical. Like the previous research, where they came to the conclusion that Putin was an autist, based solely on Youtube video's.

http://www.theguardian.com/science/head-quarters/2015/feb/07...

  it seems like a clumsy attempt to discredit Putin, so
  that people don’t take him seriously.

  we’re just being given pure conjecture, dressed up as 
  convincing scientific knowledge. This sort of practice
  doesn’t offer any useful scientific insight into, well,
  anything, and it misrepresents how science works, and
  what good quality scientific research looks like.
I do understand that as a public figure one attracts more scrutiny. But I also thought that medical professionals, like neurologists, fall under Hippocratic Oath:
  Whatever, in the course of my practice, I may see or 
  hear (even when not invited), whatever I may happen to
  obtain knowledge of, if it be not proper to repeat it,
  I will keep sacred and secret within my own breast.
If a neurologist is allowed to dig up old KGB manuals to classify heads of state as gunslingers, I am allowed to say this has nothing to do with fast gun access, but everything with signalling stature through body language: People will pass you by at your swinging arm and not bump into you when you employ this gate. Either that or old habits really do die hard, and Putin carries a gun to summits.

Absolute and utter FUD article, with zero basis in science and all the markings of another self-fulfilling social research trick.

Of to Google "Are all The New York Times articles shitty journalism?" Our research shows that in the months after these searches, the number of shitty articles on The New York Times seems to rise. We know this before the FBI does so, because we wield the power of Google Trends.

Do note that this is the most basic of SEO: Actually having the search engine access your content, so it can index it.

It is, and has been, a far cry from actual optimization: Giving your content the best possible ranking it deserves.

Want to be able to rank for an exact sentence match? Sure, use Angular. Want to actually compete for rankings? Do not build a single-page Angular application.

Solid SEO is about optimizing for users, thinking: "would I do this if search engines did not exist?". SEO for Angular apps has become: "Detect and redirect one of the major search engines to a text alternative".

Not serious, or maybe ha-ha-only-serious. See:

http://philip.greenspun.com/humor/ai.text

  The AI field has been a prolific source of hokey new
  terminology
  ...
  AI is about the same age as the rest of computing.
  ...
  If DOD spending on AI drops far enough, universities   
  like Stanford, MIT and CMU may even find the integrity
  to rid themselves of scientifically embarassing, but 
  formerly profitable, AI programs. The quality of CS 
  faculties and budgets at universities across the  
  country will continue to be diluted by the presence of
  large numbers of AI meatballs. 
  -- Gary Martins (former RAND manager)

citing unidentified “European officials”

That was the Belgium minister.

It was not clear whether the encryption was part of widely used communications tools, like WhatsApp, which the authorities have a hard time monitoring, or something more elaborate.

"PlayStation 4 is even more difficult to keep track of than WhatsApp," Jambon [Belgium minister] said at a debate in Brussels. "The most difficult communication between these terrorists is via PlayStation 4," he said. "It’s very, very difficult for our services — not only Belgian services but international services — to decrypt the communication that is done via PlayStation 4." http://www.telegraph.co.uk/technology/video-games/playstatio...

So: It is less about encryption (PGP, Tor) than it is about companies running their own communication networks with encryption, and the intelligence agencies have increasingly more trouble tracking extremists using games or phone apps to plan their attacks.

Is that Snowden's fault? No. Did Snowden's leaks contribute to companies making their networks harder to tap? Definitely.

Another tidbit that is coming out is that nearly all terrorists were already on the radar of the intelligence services and had documents tracking their radicalization. http://www.theguardian.com/world/2015/nov/16/french-and-belg...

Apparently there was a failure to share and to make actionable sense of this information.

Is that Snowden's fault? No. Did Snowden's broad indiscriminate leaks cause less willingness to share information between intelligence agencies? Definitely.

This is, in my view, a side-effect of these revelations, but a real effect too. I don't want to weigh up these two on a scale, as that will be difficult and everyone will have different priorities anyway.

BTW: This gaffe/Chinese whispers started with a Forbes article and New York Times fell for it: http://www.forbes.com/sites/insertcoin/2015/11/14/why-the-pa...

"Correction: It has not been confirmed, as originally written, that a console was found as a result of specific Belgian terror raids. Minister Jambon was speaking about tactics he knows ISIS to be using generally. "

I am sorry for all posts in this thread (including this one). Imagine being PG and reading 200+ negative replies to a blog post you did. I could have reasoned in line with Graham and learned a lot more than when resisting and attacking a viewpoint different than yours.

I feel that a different number of darts is salvageable for this logic, but having thought about this blog post some more, I feel bias is inherently non-compute-able. Our decision on how to compute influences our results.

What PG did for me was show that there is no Pascal's wager in statistics: All outcomes/data/measurements/views are equally likely. The view that the female variable alone is able to divide skill/start-up success is weak. The assumption of non-uniform points is weak. The assumption of no variance/unequal rankings is weak. The assumption that a non-random sample is significant is weak. The assumption that VC's are unbiased in their selection procedure is weak. The assumption that nature/environment favors skilled women is weak. The assumption that decisions of who to fund does not influence future applicants. The assumption that women are still selected for capability is weak. The assumption that women ignore nature/environment and keep focusing on start-up capability is weak. It is much more likely that any other thing happens. PG's alternative is certainly a sane one, but one of many.

Perhaps women perform better because, while VC offers the same chance to men and women, they are better at picking capable women than capable men. Bias in favor of capable women.

Perhaps women perform better because, they are naturally better than men.

Perhaps women perform better because, VC is biased against women, and only the strong survive.

Perhaps women perform better because, affirmative actions to remove the inequality in performance (perceived bias) actually increased our objective bias.

Perhaps women perform better because, VC is bad at picking capable women, so they pick incapable women, of which there happen to be a lot more.

Perhaps women perform better because, now the smart and capable women start to act like the mediocre ones (bad funding decisions influence actors looking for reward)

Perhaps women perform better because, nature is "biased" against older risk-averse, but available, men and, older, unavailable women who have children, and nature favors both young males (who have to compete with the old males) and females (who compete only among themselves).

Perhaps women perform better because, our sampling method was biased.

Perhaps women perform better because, our measurements were 5 years old and we are seeing an old static state of a highly complex dynamic system.

Perhaps women perform better because, they are more variant. The good ones are really good and the bad ones are really bad, making it easier on VC's to pick the cream of the crop.

All I know is how little I know. That (algorithmic) bias is an important subject, worth thinking about, and that we need very smart people working on this subject. I would never have gotten away with upvotes on my posts in this thread if the subject was cryptography. I clearly know very little about both subjects (and only now I know that, which I hope is at least a start).

PG showed that we (I), perhaps too easily, go along with the status quo: Our measurements are all correct, our conclusions are all correct. While, if you think about it.. objectively I agree that women and men are equal in capability. If you believe this to be so, then you may have a selection bias, if you observe that men and women perform differently.

I think the least all views could do is to make sure the environment for female founders to flourish is healthy and in line with skill/capability. Then let nature do its thing.

P.S.: If we know that females actually perform better than males, what is the ethical thing to do? Fund even more female founders and make it harder for men? It would make you richer. Affirmative action? It would not remove a bias, it would introduce one.

If feel the addition:

    "C" the applicants you're looking at have roughly 
    equal distribution of ability.
	
makes the reasoning more tautological/weak.

If we take two dart boards (one for female -, one for male founders) as a visual, where hitting near the bull's eye counts as "startup success".

If we take "C" to be true, then the darts would be thrown at random.

Now we draw a circle around the bull's eye. Anything landing in this circle we fund. If this circle has a smaller radius on the female dartboard, than on the male dartboard, then evidently the smaller female circle will contain more darts closer to the target (better average performance) than the larger radius male circle.

But then we do not even need performance numbers: Smaller radius circles will have less darts in them. Using "C" we only need to know that the male-female accept ratio is not 50%-50% for us to have found a bias.

In short: If you see a roughly equal distribution of ability, and (for simplicity) a roughly equal number of female to male fundraisers, then you should always have a roughly equal distribution of female to male founders in your portfolio, performance be damned.

The technique is still useful for when you do not have these female vs. male accept ratio's, and a VC publishes only success rates, but this information on ratio's is often more public than success rates/estimates.

PG:

Assumption: There is no fundamental difference between a female and a male founder for achieving start-up success (average rates and variance/distribution of rates is the same)

Observation: VC funded start-ups with female founders are (on average) 60% more successful than start-ups with male founders

Hypothesis: VC funding is biased against female founders. The ones that do receive funding are better vetted, less risky, and have higher individual qualities.

Experiment: Start funding more female founders.

If we then observe: The numbers start to even out, then there is no fundamental difference. VC funding bias may have been the cause of the difference in success rate.

If we then observe: The numbers stay the same, then there is a fundamental difference and our assumption is flawed.

Rational choice: Start funding more female founders. This either removes a bias (levels the playing field), or increases your profit (funding more potentially successful founders).

PG should of course not use an hypothesis to prove an assumption (experiment/probing is needed for verification). But also: The possibility of an uneven distribution should not invalidate such an experiment (or PG's line of reasoning), it will merely bring it to light (the numbers would stay the same, thus we have shown that the difference is fundamental and not caused by a sampling bias).

Ok, that's solved. Now let's speculate on the current cultural weapons, that the Russians can't keep up with, but that the Americans use to keep cultural dominance:

- The entire entertainment industry.

- The LGBT-movement / Pussy Riot.

- Social networks, the internet, email providers and search engines.

- Quantum computing and advanced NLP.

Clearly they wanted to keep "the (perpetual) fight against terrorism" on this list, but Russia did not listen.

I think you got downvoted not so much because HN believes in conspiracy theories, but because the lizard people remark was a bit of a rude put-down.

I very much like Microsoft too, but I also get the hate. Even this move of nagging you to update to Win10 seems to come out of the brain of marketeers, not engineers. When companies get big enough, they often lose some of their engineering/academic spirit to commercial thinking. Understandable, but annoying, as it becomes less about building a great product, but more about building great profits.

I do not think the US gov had anything to do with 9/11. I think they just didn't share information correctly and it could have been avoided (dropped the ball). I am always a bit mystified when Americans say that 9/11 was an inside job. If true, their government would be directly responsible for the deaths of 1000s. That should cause riots, not conspiracy theory forums. I think 9/11 conspiracy theories are interesting, because I have a conspiracy theory that most of these theories are propagated by the Middle East (shift the blame) and Russia (destabilize US politics, comparable to Operation INFEKTION, where they tried to paint the US as creating AIDS).

I think the lizard people are the product of a troubled mind and plain old antisemitism. In an allegorical sense it may hold some truths though. The crack cocaine flights of the CIA are no theory anymore, these have been pretty much confirmed, culminating in the "suicide" of Gary Webb by two(!) bullets to the head.

I like Robert Anton Wilson when he says that belief in the Illuminati is driven by our current information overload: The brain wants to make sense of it all, and that is easier when you picture an evil force behind the curtains pulling the strings. But also that there simply are a lot of people conspiring to do evil things (for instance the P2 lodge). So it is a balance between reality and psychology.

My favorite thing about conspiracy theories is that it allows you to draw all sorts of connections. It's a form of data analysis to occupy the mind with, only bounded by your imagination.

I think the China-themed conspiracy theories are very US-centric. Europe seems less afraid of China as a competitor, decreasing the popularity and adoption of such theories.

You may be interested in this older documentary: https://youtu.be/DfsK6DuNhnc?t=2208 about the psychology of conspiracy theorists. The psychologists claim that they can predict who will believe in conspiracy theories, and they use as a dividing test the following question to separate conspiracy theorists from healthy trustful people:

"The government is using mobile phone technology to track people all the time. Yes/No."

Also includes an interview with David Icke.

I don't think that question is decisive anymore...

Most users will (rightly so) view this as an OS upgrade, not as an update. You already gave MS permission to provide you with security updates. You did not give MS permission to upgrade your OS. I feel the difference is of importance as updates are often necessary, while upgrades are not.

  This update installs the Get Windows 10 app, which
  helps users understand their Windows 10 upgrade options
  and device readiness.
https://support.microsoft.com/en-us/kb/3035583

This would run afoul of the European 'cookie law' (the name is a bit of a misnomer as it applies to more than just cookies). In short: Microsoft needs express permission to store/modify files on my computer.

It will probably be spun like Windows 10 is a security update to old OS's, but that is simply not sincere. Given the problematic privacy/sharing/phone-home settings on Windows 10 one can hardly call it a security improvement.

  You must tell people if you set cookies, and clearly 
  explain what the cookies do and why. You must also get
  the user’s consent. Consent can be implied, but must be
  knowingly given.

  The same rules also apply if you use any other type of
  technology to store or gain access to information on
  someone’s device.
https://ico.org.uk/for-organisations/guide-to-pecr/cookies-a...
  [Under the cookie law permission is needed to] store 
  or gain access to data on the peripherals of a user 
  through an electronic communication network.
http://www.justitia.nl/cookiewet.html
  Article 5.3) Member States shall ensure that the use 
  of electronic communications networks to store 
  information or to gain access to information stored in
  the terminal equipment of a subscriber or user is only
  allowed on condition that the subscriber or user
  concerned is provided with clear and comprehensive
  information in accordance with Directive 95/46/EC,
  inter alia about the purposes of the processing, and 
  is offered the right to refuse such processing by the
  data controller.
http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:...

That is a major difference between these two languages.

Python: There should be one, and only one, preferable way to do things. Though this may not be obvious at first.

R: Every author has a different style of doing things, reflecting in the code.

As for the comparison in general: You can call R from within Python. So Python is at least as powerful as R. The rest (BeautifulSoup, Compression, Game development etc.) is icing on the cake.

As this is framed more as the results of a policy change, there are some things to consider when banning weed:

- Street sales to tourists and foreigners exploded. Small-time dealers reported weekly income of 2k Euros during the prohibition.

- Dutch teenagers use less weed than German, UK and Belgian teens. Legal availability seems inversely correlated with actual use.

- In France there is no clear distinction between hard drugs and soft drugs. A dealer will sell you pot, but also heroin.

- There are other ways to get weed, without using a weed pass. Home growers will not check the age of the person they are selling to.

Smoking weed in Holland has a social stigma attached to it. It is not cool, it is for chumps. Policy changes like these may make it dangerous, hidden and cool again, actually raising our usage to the levels of neighboring countries.

As to the results, I shudder and think: Imagine what Feynman would have been able to achieve, if he had no access to weed or bongos for seven months...

It's a game of numbers. Even if the response rate to spam email is like 0.00001%, it is still economically viable to send out 10 million spam emails.

Scammer groups that have survived for this long got to hone their skills of manipulation and persuasion (and have the money to continue operations). We are all to a degree vulnerable to persuasion, and it used by scammers, but also businesses: "Temporarily free version of Microsoft 10. Get yours now! It's easy. 10 million people have already upgraded."

Older people have trusted phones for all their lives. They are more vulnerable to these than email scams. Locally there is now a scam involving people who dress up as home care, visit one hour before the real home care person, tell them they are the new replacement, then proceed to ransack the place for valuables. I could see myself falling victim to that.

They played on this old man's hope and financial worries ("greed" in less positive terms). Stories like these gravely sadden me. Hits close to home too: Both my father and mother were targeted, one over email (cloud backup scam), the other over the phone (helpdesk scam). I hope to build a product in the future to help combat these online and offline scams.

It is not racism. Racism is the attitude/belief that one race is superior to another race. Also military veteran is not a race.

It is discrimination. Discrimination is having applicants use 23andMe to prove that they are more black than white, so you can give them a different preferential treatment.

Next to making the world a better place through more black startup founders, this is a PR move. Paul Graham stopped posting on YC around the time of those terrible threads on females in tech. Hackernews became renowned for their toxic response to these issues. You can still see some of that in the rest of this thread and in my comment.

What followed was Female Founders and this initiative. This discriminatory trend will only continue. YC thinks it can make their startup portfolio more diverse, by adding more black startup founders. In this lies the hidden assumption that black founders act or think differently than white founders. The terrible alternative being that YC judges the diversity of their portfolio on the skin color of their founders.

I think a US asset could have been targeted by their software. Or Hacking Team sold to a country with a bad standing in Israel.

Then the software becomes a direct threat to their agents/allies overseas and it needed to be neutralized. That is the kind of competition you do not want as a state actor.

I also think Gamma International was the victim of a foreign intelligence agency. I don't believe the privacy-minded hacker Robin Hood stories anymore.

Web design and development is also an art. Good artists look beyond business value.

You actually should bend over backwards to cater to as many users as possible, especially if you are getting paid to build websites for users.

Some countries require sites to be accessible to the disabled. If you design sites for the US government, they should also be accessible to 0.1% of blind or no-script users.

Sure, IE6 as a baseline is very progressive, but it is certainly doable. Less so, if you start with an inaccessible website and catering to as many users as possible is an annoying time-consuming afterthought.

If you can not muster an accessible progressive enhanced website, then you can not muster a js-only ARIA compliant website either. Your only hope is to make something profitable. That's being a marketeer or business man with a little HTML skills, not being a solid web dev.

Progressive enhancement for JavaScript is not only a accessibility and usability issue, it has become a security issue. Tor enabled JavaScript by default, because the web would break without JavaScript support, and that hampered adoption rates of Tor.

We already had a programmable web. If anything we are moving away from machine-readable code.

If progressive enhancement does not fit your development style, and takes too much time to build, well... fine. I see this not as a fault of progressive enhancement, but in your approach. To me it is akin to saying that writing unit tests takes you too much time, and hence, testing makes no sense.

I understand the meme: "Never ever roll your own encryption", but I am stubborn enough to ask: "Why?".

Why use bcrypt over scrypt over pbkdf2? Because crypto experts told you? How could you know it is correct, if you are not able to inspect it? By the amount of people yelling "Use bcrypt"?

I know that in crypto you should expect an attacker to be able to read your source code. If you can keep secrets, while your source is out in the open, then it is good crypto. But does that mean you do not need a script-based salt? An attacker which can get into your database, should be able to get code-read access too right? I don't think so... Databases are leaked on forums without any trace of the source code/app logic. When these people did not roll their own encryption, any attack which is able to beat modern crypto (you will never hear of this, as you are not an expert), could now attack you. They fingerprint the hashes, try to find out which expert roll you used, open their suitcase of crypto breaking tools written by the same expert when she was working for the NSA, under cover of doing a PhD at MIT, and go to town.

Don't listen to me, because I am not an crypto authority, but do roll your own encryption: Give your own twist to it. That is security by obfuscation, and would not put all eggs in the same basket. An attacker has to be able to break your custom scheme now, for every different site/database attacked. It could be simple, it could be near perfect, but it won't be as simple as pressing a button on the "break modern crypto"-toolkits.

If you are one of the few doing this: People will move to less arcane targets in the never-roll-your-own-basket. If you are one of the many doing this, breaking crypto would become an unmanageable field of eggs.

If I was a state actor in charge of keeping secrets and breaking crypto, these two memes: "Never roll your own encryption" and "just use bcrypt" are exactly the memes I would propagate to the tech crowd. Even moreso when you can already break bcrypt (or expect to in 5 years and just store everything that looks encrypted with bcrypt) and want to keep your task manageable.

AM would be harder to crack if they'd ROT-13'd the hashes in the source code.

There are many links, but no conclusive proof: The long-term effects are unknown, research without commercial funding is slow, and you can not test on humans directly.

Herbicide residues are found in the main foods of the Western diet.

Atrazine is used in Hawaii to test effect. It is the most commonly used herbicide in the US after glyphosate. It is banned in Europe.

"In 2007, the U.S. EPA said, "studies thus far suggest that atrazine is an endocrine disruptor". The implications for children’s health are related to effects during pregnancy and during sexual development, though few studies are available. In people, risks for preterm delivery and intrauterine growth retardation have been associated with exposure. Atrazine exposure has been shown to result in delays or changes in pubertal development in female rats"

Then there is paraquat dichloride. "Paraquat causes fetal losses in high-dose reproductive studies of animals. In studies of Mallard embryos, it causes birth defects."

How do you suggest we remove or strengthen links with research? If injecting embryos with herbicide is not a valid study for birth defects, then what is? Farmers telling us they see lots of disease when switching to herbicides? Simulations? AFAIK, we came to know these herbicides act as endocrine disruptors from embryo research, so is that conclusion ridiculous too?

Fifty 11 years ago

Thanks Jacques. I first read about you almost 15 years ago. I think you did an interview about the creation of webcams and starting the first webcam community. What struck me was the typical Dutch resentment for success and those that dare to stick their necks out. Commentators would say you were lying or embellishing or try to downplay your successes. That typical envy. I hope you are now totally over that.

A few years back you took a few hours to just chat with me, in a period when I was really depressed and did not believe in myself. Thank for you that. It really helped and you demanded nothing in return. A very approachable, commendable spirit -- I hope there are people around you who do the same for you.

Jacques. Thanks man! Congrats, and here is to many more years!

Yes. Check out adaptive design. Instead of responsive, start talking in a way that specific user wants. No one-for-all design, which has to cater to both the power user and grandma, but a design that adapts itself to your (or similar) behavior. For example: count the times that users use 2-3 steps to perform the same task, then automatically make it a one-click process for them. Being able to change the top bar color on HN is also a form of adaptive design, just one requiring manual action.

Some weird alignment with the "l" in Google. It's 2 pixels off the baseline: http://i.imgur.com/BeSYG3a.png

It also does not work with the country subtitle. These are touching the letter "e", perhaps showing they forgot to test this with different country names and x-height.