Let's say I sent up a key "foo" to get the value "bar", and I did this again and again. Will either "foo" or "bar" be encrypted to the same ciphertext again and again? Or is there some kind of nonce or salt or other mechanism that will make the ciphertext always different? Congrats on launching and thank you for any answer.
HN user
dougk16
My most recent project: https://aytwit.com/thoughter
Hello, my name is Doug. You probably just read a witty yet insightful comment of mine and want more...
BLOG: https://aytwit.com/blog
I also make cool educational Engineering/DIY videos...
YOUTUBE: https://www.youtube.com/channel/UCBgtpu1QDRAAA8QvsL68E1A
Here's a crazy personal portfolio site I made. The engine is reusable for other sites if you're interested...
PORTFOLIO: https://dougkoellmer.com
Contact me anytime about anything, but especially to be of service...
EMAIL: doug@aytwit.com
nttjbxmv9trm
I'm adding to your comment and not trying to argue (unless you want to!): There's no distinction between the public and the government. The government is made up by the public. And corporations are usually first in line anyway. Much more "public" in the cake mix right there alone.
It's hard for me to think in terms of rights. I don't know what the word even means. Legal rights? Moral rights? God-given rights? You can say I have a right not to be murdered, but that doesn't matter very much if in fact I just got murdered. All I know is that some people feel they have a "duty" for lack of a better word, to keep all their dealings as private as possible. If I were such a person, this would mean using cash, metals, and cryptocurrencies like Monero as much as possible through decentralized services. It would even mean using things like credit/debit cards to maintain a "good person" public persona. Going grey so to speak.
Really great list. Thank you. Some of these I wasn't even aware of. I've been using Session for about a year. A year ago it definitely had some missed messages and I was about to ditch it but I held strong and haven't experienced that issue in a while. Been flawless for about half a year. The Oxen/Loki network overall https://oxen.io/ is a really interesting alternative to Monero and Tor. It's interesting how it can be both!
Capitalized, yes. It should also have air quotes.
"Effective Altruism" is more appropriate in this case.
One solution to this is to become an oracle at your company. Any time someone (namely someone higher in the company who is responsible for your pay) has a question, no matter how many times it's been asked, how recently it's been asked, how obvious and repeated it is in the documentation, you answer quickly and thoroughly, like a machine. After a year or two of this, you'll be able to ask for any raise, or to work remote, or to even switch to contracting. They won't want to lose you.
For all the bigger companies I've worked with that have infinite war chests and rely heavily on user data and analytics, the question is always why shouldn't a specific metric be tracked, not why should it. Even if they have absolutely no reason to track how fast you're reading, it's safe to say they're tracking it anyway. At a certain point you stop reading privacy policies or listening to what a company says it's doing or not. You even stop looking at code or inspecting network traffic. You simply assume you're being tracked in every technical way it's possible for "them" to do so, and you either accept it or change it.
Well, yea. Living things and organizations have incentives. The implication I gleaned from your original comment was that Google's incentive to avoid bad press on HN for its App Store policies is enough that it should use its static analysis abilities "for good". We're not debating the existence of incentives. We're debating the existence of consistent/unified motivation/ability/will to satisfy those incentives. Or are we debating? After your second comment I'm not even sure the point you are trying to make.
Besides, I repeat that Google is big enough that different factions have contradictory incentives. There are people in Google that want bad Play Store press on HN. I'll leave that as a thought exercise as to how that could be true.
Google is a vast, schizophrenic organization. They're big enough that they have different teams and internal politics fighting each other all the time. It's not a unified consciousness with consistent incentives. Even if that's a bad take, Google is constantly seen in a negative light on Hacker News. The Google hive-mind doesn't care too much.
Google does some pretty surprising levels of static analysis of compiled source, particularly surrounding their API usage. There's a few examples I've run into but the first that pops to mind is when they started requiring a yes/no confirmation dialog before allowing a user to access a non-https resource through the WebView. There was no way a human was running into that on the particular app I was working on. We're not talking advanced static analysis but it's not a simple decompile and grep either.
In another case I had accidentally left some dead/debug AWS access credentials in a build and they sniffed those out too. Notable since that's not even Google-related. They had to have been looking for a particular AWS library method signature and how it was fed. I would bet on their static analysis getting more advanced, in which case it could also be used to prove that OP is using APIs/permissions in a safe manner. But of course they're not incentivized to do that.
I dismissed it all very early on but for other reasons. I took one look at the BTC whitepaper way back, saw that every transaction and wallet was completely public, and immediately wrote it off based on that, along with everything to do with the cryptocurrency space, until I found Monero then some other related currencies about 4 years ago.
You have different standards than me as far as what constitutes a "successful" currency. And that's cool! For example you generally can't buy breakfast with the currencies of silver or gold or British Pounds (in America) either. All throughout history there has been different currencies for different situations and crypto is just another one on the pile. I wish salt would make a comeback myself. ;)
I use cryptocurrencies as private replacements for bank wires. If your standard is that you must be able to buy breakfast in a city with it, then I agree with you it is not a currency by that definition and probably never will be.
As for me I get paid for my professional services in crypto and turn around and sometimes pay other people for goods and services without any conversion in between. Sometimes I convert it to precious metal directly. Sometimes I convert it to a fiat currency or another crypto. Sometimes I hold. It's all good!
Thanks for the conversation and good luck with everything you're working on.
I would continue easily dismantling your points but you're like a boomer railing against the Internet in the early 90s. It's bad according to your value system so other people shouldn't use it either. You don't understand it or want it or whatever. Which is totally fine. I'm not saying your position is a bad thing. In fact you have my respect. My Dad was like this with the Internet in the early 90's, and still is. He STILL doesn't use the Internet and his construction business is just fine without it. He has my respect. Both he and I ended up being "right". My only advice is to stick to your guns going forward, be like my Dad and NEVER use cryptocurrencies or metal or barter. Only use military-backed currencies and have them tracked and traced as much as possible. In fact don't even use physical cash. For your safety.
As for me, I'll continue to use Monero and precious metals and barter, and use fiat and the coming CBDCs as little as possible. If that's alright with you of course!
It takes all kinds. Though if you don't know what the Metaverse or CBDCs are you got some surprises coming!
Ah c'mon gimme something better to chew on, this argument is cake to dismantle. (1) You don't use Monero to buy breakfast. It's for large money transfers so at least compare it to bank wires. (2) Very few people know about Monero yet. Credit cards were at 20K transactions per day at some point. If you know how to look at the chart you linked, you can see the TX count growing sustainably over several years. This is healthy growth, not some SV venture-capital juiced unicorn. (3) There will be very few ultimate winners in the crypto game as far as fungible currencies. It's a more honest comparison to include transaction counts of non-fungible cryptocurrencies like BTC and ETH that people are unfortunately using as a currency for now. (4) Monero is just one of a few other legitimate private cryptocurrencies, so include those transaction counts too.
Well I could go on laughing at the "nobody cares" take, but you don't care so I'll leave it there. Enjoy your CBDCs in the metaverse.
Monero and other less well-known currencies solve all of that. You can say it's bad or useless for other reasons. But my direct experience with dozens of P2P transfers, outside exchanges, both paying people for products and services and being paid myself, is enough for me to know that the future involves private cryptocurrencies one way or another. It may be akin to the taboo nature of torrenting movies at some point, but it's not going anywhere. CBDCs, traditional fiat, crypto, and even precious metals (yea we used to use those too!) will all have their use cases over the next decade. Paying people (and being paid) with precious metals and private crypto feels so amazing, so freeing, I recommend everyone give it a try.
Money is the goal of the individual Cogs in the machine. Control is the goal of the machine itself, which uses money to incentivize (power) its Cogs. If you're a Big Tech company you essentially have endless free money to leverage compared to your Cogs. The machine itself doesn't care about money. That free money train is coming to an end though over the next decade. Or at least that's the reality I'm planning for. :)
Yup. My hypothesis is unambiguously verifiable, and I've verified it to my own satisfaction through my personal experiences. Your hypothesis is not unambiguously verifiable, only statistically so (whatever that means). At least it's falsifiable, but there's a deep challenge there because falsification would unveil aspects of our society that most people don't want to know about.
Again, you're assuming they don't have surrogates. This is still an assumption. The miscommunication here is that you think I'm a conspiracy theorist or something, and I think you're naive. But so what? Sure, maybe I'm seeing phantoms where they don't exist. We've clearly had different life experiences though. To me the basic calculus of a multi-trillion dollar company perhaps throwing out a few million bucks a year to pay "surrogates" to influence opinion on popular online forums is not the claim that carries the burden of proof. I'd be absolutely shocked if they weren't doing this. But again, there's no way we can even argue if you think the burden of proof goes in the opposite direction. But at least understand that neither of our claims are "simpler" than the other. My original comment saying "more simpler" was a bit of sarcasm in case that didn't come through.
We're both making the same number of assumptions. The difference is that yours is in the negative and mine is in the positive. Your example about the risk of someone leaking to the press shows we simply live in completely different realities, thus argument is impossible. Which is fine! In my reality people are leaking to the press all the time about such things and simply being ignored by most who don't want to confront how dark corporate and government PR and marketing has become.
The even more simpler explanation is that it's both.
Fellow DERO holder I see. ;)
Another possibility is they want to keep eyes off tech that people would go to in droves if they outright banned it. They want to avoid the Streisand effect. Part of that play is indeed making people think it's already backdoored. There is a big push to promote that narrative. Whether it's true or not, who knows!
They've coded for 10 or 20 years, and now just sit back and design interfaces, write specs, evaluate technologies, mentor juniors, do code review, and of course the ultimate mind blow when you're trying to figure out who to fire: they remove code instead of add it. Unfortunately for the company, these "imposters" do indeed get weeded out in preference to the recent college grad copy/pasting thousands of lines of StackOverflow answers. I usually escape before all that drama though!
Very nice! I hope to soon get to the point where I need this. I'm bookmarking this.
Cool idea, I can see how this would be useful once you're dealing with more than a few invoices per month. For those like me that do indeed only send out a few a month, I've found the Numbers app on Mac to have a very nice invoice template that you can customize, fill out, and generate a professional-looking invoice from.
Agreed with the vibe of other comments here. It's hard not to come off snobby, and the market won't allow such snobbery forever, but for now the reality is that a senior engineer is interviewing YOU, not the other way around. Anything longer than a few emails and maybe a one hour conversation and you risk them moving on. Technical assignment is definitely pushing it, unless perhaps it's paid.
Nice, quick implementation. It's cool that it's all client side. People have pointed out the weaknesses as far as non-crushes brute forcing the answer but still this is interesting. I'll have to digest the implications more. I created https://aytwit.com/thoughter which takes the basic idea here to a much more involved extreme. It got some good traction on hackers news a few years ago and I've improved it a lot since then. I still want to make some improvements as far as moving more of the cryptography client-side so people don't have to trust my server as much, yet not ALL client side like this for more convenience and privacy.
Thanks for the submission!
Your body stores a tremendous amount of energy. For example I've personally fasted for 7 days, no calories in, and know people who have gone a month, no problems. Normal daily routine, exercise, etc. In a way you have even more zip in your step cause you're not processing all that food.
So it's not like you're an inert lump out in the elements. You have the caloric equivalent of several gallons worth of gasoline in your body somewhat readily burnable (obviously at the tail end you'd start to look a little worn out). Systems like Wim Hof give you the ability to consciously tap into that energy reserve with enough practice.
Also think about tiny animals like squirrels out in the elements all winter. Yes natural insulation plays a small role, but let me give you a fur coat and some nuts and see how long you last. ;) Not to mention surface:volume ratio much worse than humans. They're natural Wim Hof masters.
Inversion is a complete redefining.
Under extreme socialism, think Orwellian levels, definitions of words are inverted. So the argument would be, if one believes we're already deep into Orwellian territory, that what most people think of as some kind of extreme capitalism because we have these large, unchecked corporations running around, is actually extreme socialism, aka fascism: the merger of corporation and state. And that's the reason these companies have gotten so large and unchecked. That we're not in a free market, but rather dealing with cartels that have grown like weeds and enforced their monopolies through violence through co-opting and/or cooperation with the state.
That's the idea, not trying to argue that's the case. Just giving a possible answer to your question. In reality we're all in a completely free, survival of the fittest-type situation. We're all gonna die someday and all that. It's just that society provides some nice illusions wherein we can debate about whether we're socialist or capitalist.
I generally only use private cryptocurrencies with low fees and fast transaction times, like Monero and PirateChain. If I have to use Bitcoin or any other surveillance coin, I am well-versed in "cleaning" my coins, but that's not desirable for a number of reasons. Perhaps you're focusing on co-opted surveillance coins, but privacy coins are amazing.
Is "purchase" some technical definition you're using? I've purchased many goods and services with cryptocurrency these past few years. Used physical silver a lot as well. Even paid rent. Also partially paid a contracting bill with one ounce of gold. It takes a bit more legwork and explanation but monetary systems don't change by magic. It takes an impassioned minority individually putting the work in.