HN user

dsukhin

343 karma
Posts8
Comments40
View on HN
Botanical Sexism 3 years ago

This causes some interesting knock on effects on society:

1. more pollen (as mentioned in the article), leading to more more allergies, leading to more allergy med sales

2. no free fruit growing in the streets for kids/others to eat healthy snacks (visitors to some “old world” towns admire this about them). The fruit “littering the landscape” being the stated reason for not planting female trees, means non biodegradable trash from chip bags and other disposable wrappers litter our cities instead

This is an amazing educational experience for students but it is also such a great way to crowd source hyper realistic 3D world replicas - it reminds me of the Minecraft replica of MIT that cropped up at the start of COVID. I really hope they open source and preserve all the work of these students on a combined server anyone can browse.

It would be even more amazing if we ended up in a world where we basically open source public infrastructure projects so that anyone could contribute ideas and/or solicit public comment on new concepts before we invest billions of dollars of public money.

It also immediately comes to mind that Microsoft develops MS flight simulator - could proposed airport innovations be paired with it to test how pilots feel about changes to layouts or e.g. how new runways may affect air traffic and other patterns?

Very cool.

There is a discussion on that thread about the bounty being rather small compared to the damage it could have caused the crypto market and/or Coinbase’s stock/reputation. It’s low relative value is even being cited as a risk to future bugs not being responsibly disclosed.

It is however important to consider the technical complexity, effort, and exploitability when valuing an exploit. This was a very, VERY simple bug to find and with KYC very obvious and unlikely truly monetizable without consequences if exploited (unlike say getting access to the private key of a hot wallet). The biggest damage would have been reputational (though a rational person should consider the fact this kind of missing condition check bug made it to production a major issue already). The market would have recovered from whatever flash crash ensued and the attacker wouldn’t be likely to keep their winnings.

Kudos to tree_of_alpha for being the first to look at the API, spotting this, and reporting responsibly - $250k for what appears to be under an hour of work that was driven by curiosity is not a bad deal at all. I know Brian Armstrong frequents HN so it will indeed be interesting to get his take on this as well if he was involved in it.

You are doing exactly the right thing by reaching out and asking for advice in communities you are a part of that may be able to offer you a job or a connection to one. One piece of advice however would be to include a link to a resume or personal website showing off your independent projects and skills. It’s these projects that will show what technologies you are proficient in and prove to others that you know what you are doing even at a younger age.

I also started coding very early and used my time choose a project and dive very deep into the full stack. Web technology is the easiest thing to “show off” to others since it’s ubiquitous and easy to distribute. Even if you consider yourself a “back end” type of person, learn some web dev to be able to show and tell.

This is a time in your life that you can work on a piece of software that’s just for fun and to learn and do something cool. If you are lucky and commercial, that project might become a job of its own that provides you a passive income. Otherwise, it’s a part of your portfolio to help you secure another opportunity. I routinely look to give part time/internship opportunities to folks in your position precisely because others may overlook your talents and passion to develop them and because I was one of them :)

The email domain where the messages originate is from some sort of federated identity management system that was created in 2010 (here is a proposal deck [0] with technical details). Found this program simply by searching Google for the sending domain.

Based on the guide for using this system [1] (see step 15) looks like this specific email address is the one that sends automated confirmation emails upon registration. Perhaps someone was able to inject a message instead of the regular canned text through some sort of reflection attack? This explains why replies to the message result in a canned response. The system also now appears to be temporarily down. So it’s getting some sort of attention (internally taken down (most likely) or maybe denial of service from the abuse).

The Reddit thread suggests the recipients’ emails are likely ARIN IP range contacts. Those are very available from tools like this [2] so nothing interesting with that, but the real question is WHY someone would do this at all? This was clearly given some thought (on who to send this to who would actually take the time to verify the headers) but given the sloppiness of everything else, is this just a script kiddie flex? Whoever it is pissed off the FBI and gained absolutely nothing.

[0] https://bja.ojp.gov/sites/g/files/xyckuh186/files/media/docu...

[1] https://www.justice.gov/tribal/page/file/1260671/download

[2] http://itools.com/tool/arin-whois-domain-search

I can speak using MIT as an example and I assume Harvard is the same way for the same reasons.

Big research institutions that were present when IP addresses were being allocated got A LOT of IPs by simply asking for them. Apple has the entire 17.0.0.0/8 range. Ford Motor Company has one, the US Gov has a lot [0]. Up until recently MIT had all of 18. (they sold something like half to AWS for a hefty sum not too long ago).

As a student (or visitor), when you joined the network (wired or Wi-Fi) you weren’t allocated some internal IP behind a router but a PUBLIC 18.something that was in the global address space because they had so many IPs available. This meant you could literally host something on the public internet from your dorm room because every device on the network was publicly routable by a unique public IP address.

[0] https://en.m.wikipedia.org/wiki/List_of_assigned_/8_IPv4_add... (see the last section on the original allocation)

Yes, they get enough donations to cover their costs, just like Uber has enough VC cash and loans to continue its operations. It's non profit tax status is not strictly relevant to the fact that you typically need at least as much as money as it takes to run your entity rather than less. In my opinion, this doesn't change the spirit of the point that Wikipedia doesn't make money from its free, high-traffic service but rather from favorable financing for its goodwill and assets similar to a not profitable startup.

I've considered this question a number of ways. The fact that capital holders are gatekeepers to innovation is unequivocally worse for federated innovation, but it has created an interesting class of companies which may never need to turn a profit yet still have a positive (and growing) net present value.

Take Wikipedia for example. They lose money running a high traffic service (edit: see below reply for clarification), but it's plain to see they hold a huge asset in terms of goodwill, usage, knowledge base, and their contribution to research and knowledge growth. Despite its operating losses, its capital value (which may be in the form of social capital) is huge and will likely remain well financed into the foreseeable future.

The fact that the service is free is not relevant: a startup offering an invaluable service that is based on years of user research, development and testing has developed an asset which helps other companies and companies pay what they think it is worth (or at the beginning a subsidized rate to take a risk to try it). Operating losses at most start ups are from continued R&D; but if they were to just declare the product as "done" and have a sufficient moat/network, they could rent seek on the asset for years - yet in many cases that's not what is best for anyone (company, clients or shareholders) - we continue to want them to innovate for the good of the product and there will be stakeholders that would rather finance this research in perpetuity to grow the underlying asset and thus the value of the product and company.

Inductively, that's a company with negative NOL but positive NPV. In the physical world this might be the same as an apartment complex that's expanding (forever). They may currently collect $1M in rent, but they are spending $2M on new construction. The new construction may bring in $5M over its 30 year lifespan but it will never be enough to outpace the immediate outlay of continued construction cost. As long as the time value of money is correctly attributed, this isn't a new idea - just one that's been pulled to an extreme.

It's worth comparing Bitcoin's proof of work to other schemes of maintaining currency value to understand this in a relative sense. The Military Industrial Complex which arguably is the mechanism by which the dollar maintains its position as the global reserve currency puts out 152MtCO2/yr [1].

Without making any judgement on if this ratio is reasonable: this is 3-5x more than BTC POW but arguably also contains other negative externalities like loss of life, etc.

[1] https://earther.gizmodo.com/groundbreaking-report-gives-us-a...

A DNS record lookup points to ddos-guard.net which provides both hosting and DDOS protection (like cloudflare) and is based in the Netherlands.

I don't think they care much about Parler or free speech for that matter. They might not care much beyond the likely big hosting bill they are being paid. Free market at work, nothing to see here.

This is fascinating, I didn't realize there was a spec for this for the web.

But this begs the question: Apple Privacy Labels "caught on" because Apple has unilateral control to enforce them in the App Store. If ostensibly the same idea for the WWW did not catch on, is the problem (1) the lack of enforcement/economic incentive mechanisms on the decentralized web or (2) that consumers really didn't care/know enough to create/enforce such free market incentives?

The most insidious part of mega bills is the surprises that get snuck into them that I'd like to believe would have been adequately thought about and debated if someone actually had a chance to read them. The article suggests the CARES act itself is to blame and the 14k charges are "fees on these facilities to fund the FDA's regulatory activities". It wasn't meant to attack distillers but that didn't stop them from getting swept up in a provision that didn't belong in this bill in the first place.

How is a logical person supposed to reconcile a bill that was meant to help the country deal with an emergency is actually penalizing the companies that stepped up to help and charging them for the extra red tape?

This appears to be a two part question. Part one is how space efficient the language representation is (words, sounds) and part two is how much mental RAM is needed to extract meaning. In a traditional CS setting this would be an example of a time-space tradeoff (decompression), but given hefty evidence of special structures in the brain that are adapted for language processing, the processing aspect has really been abstracted away by "special hardware" which places a lower bound on how dense the representation can be to take advantage of it in a real-time streaming context. I find it hard to imagine any popular language system evolving to make itself harder by not using the embedded hardware for processing, so I'll turn the rest of my answer to examining the representational efficiency.

If you look at language efficiency from the information theoretic sense (i.e. most meaning conveyed with least amount of "bits" of data), you can approximate the efficiency of a language by looking at the branching factor and probability of words in its language model. The more branches there are, the more meanining a single word can have in a stream of text (especially a low probability word). However, the more words you have in your language, the more "bits"/letters/memory/etc. It takes to represent the word even if you use a probability informed encoding like Huffman.

If you think of a Markov language model as simply bitstream guided state machine, you can approximate the expected length of output for equivalent length inputs and get an information density approximation of the language model itself.

Traditional Chinese which is not phonemic will have a much larger "word" space but a much smaller branching factor. Each symbol conveys more meaning, but highly constrains the space of symbols which can follow. Where it falls on the tradeoff curve relative to say, English is not obvious ex ante, but we can use this framework to test it.

This answer might be a little dense, but is meant to provide some intuition and a thought framework to evaluate your question.

Really any cheap VPS provider with cPanel should do what you are asking to provide unlimthed domains, aliases, users, mailboxes, catch alls, forwarding, etc. if you are not looking for anything more complex than IMAP support. Just be sure to set all your DNS/DKIM/SPF up correctly and you should be good to go.

Off topic: the consent dialog on this page was hilarious and simultaneously a great social commentary on the typical dark patterns.

In order to offer an "ad-filled experience" and maximize our profits, LinuxReviews would very much like you to allow our Google AdSense ad-partner to use tracking and cookies so we can show ads from them on our website.

Options: Resist, Approve (2x bigger)

As a web developer, this was refreshing, but as a user didn't immediately make me want to accept. I wonder what their opt in rate is like compared to the "best" practice

Interestingly, newer version Fitbit devices also sport an SpO2 sensor, but they have dragged their feet on enabling direct readings or the expected sleep apnea detection features.

The delay seems to have come from the worry of the perception that it was being used for "diagnosis" of sleep apnea as that would put them in a different category with the FDA. You can imagine how direct access to the SpO2 sensor was a hot topic during the height of the pandemic of a repository illness. In short, the hardware is there, but corporate conservarivism kept it from being used or even exposed to the user.

I've bought a Withings Smart Scale (at that point they were briefly owned by Nokia). The scale is simple, clean, durable, featureful; the companion health app is one of the cleanest/effective specimins of UI I've seen in a while and has tons of integrations. I expect great things here and hopefully less fear about exposing the hardware readings of highly useful sensors.

Not to disagree with your premise, but if you scrolled back to the top, the cookie consent box reappears. It just hides so you can read the article when you scroll which by itself isn't bad. It's not clear it assumes consent but it's also not clear it doesn't.

IMHO the cookie consent box is a flawed premise from the start, it's annoying to the user (especially on mobile where it takes half the screen) and there is no way to verify it is actually implemented correctly and doesn't just track you anyway regardless of what you do - hence your comment above.

If one really decides a first party cookie is a privilege rather than a simple data storage primitive on the web because it's been abused by google analytics etc, this is something you can set your browser to ask for permission each time or a content blocker to avoid from sources like Google. Keep in mind, that does affect the site's ability to understand which of it's content is most popular which is not bad on its own - but yes there are workarounds to this too like server logs which are probably more reliable anyway.

This cookie box is the most annoying side effect of GDPR with almost no benefit as it's riddled with dark patterns and "compliant" sites that don't respect the spirit of the law, just the letter.

I clicked, pleasantly surprised and expecting a post-mortem. Instead it's a corporate PR admission of guilt and non-apology. If your audience is developers who implement the SDK, a more detailed explanation is the only respectful option.

Moreover, the actionable advice to upgrade the SDK is a complete non-technical non-sequter seemingly put as a distraction:

- They admit it was a server side change that caused the crashes. SDK version doesn't change that.

- No breakdown of which versions were affected (or was it everything?).

- Is a newer release safer? Were changes made that we would get by upgrading?

Did anyone by chance MITM the server payload to understand the bad code/bug?

It's always strange to see the "orthodox" macro realtionship take precedent over emperical results (see article and figure 1 scatter plot: https://www.stlouisfed.org/publications/regional-economist/j...). In the short term, the orthodox thinking might be correct and an effective lever for the economy, but long term, it's clear that high interest leads to higher inflation AND less innovation which are bad outcomes IMHO.

I agree with your observation for the demand to keep money "safe". We should define what that means. Historically, if you choose to keep wealth in a stable cash with real interest rate (nominal interest rate minus inflation rate) that is positive or zero, it's safe as it retains or grows its buying power. The "or zero" part is important as it allows for a zero interest environment if that also means low inflation.

Some may even argue that a reasonable negative interest rate is "safe" and it's just like a "wealth tax" which is the cost of service for keeping large sums of money at the bank. Shouid safety be free (no negative rates)? I would say maybe yes, but safety shouldn't also reward you... and positive interest rates do exactly that.

Perhaps an unorthodox way of looking at things, but it's very intersting take a step back to consider what 0 to low interest rates might accomplish for society:

- Low interest rates mean it makes no sense to simply keep cash, it's better to invest in something productive. For companies that's new projects/ideas which create jobs, for individuals that might be spending on goods to stimulate the economy or buying a house.

- High interest rates are a considered a way to reduce "risky" investments. But in reality, interest is rent seeking on capital which benefits (1) lenders/banks (2) capital holders. Cheap capital enables more projects with positive ROI (above cost of capital) to be persued. And this is good for society as it drives innovation and allocates capital to innovators instead of locking it under stagnant rent seeking. Lest you worry, this doesn't hurt capital holders, as they can instead proactively invest in companies and make the same or larger returns, but now capital is allocated by merit of the project being invested in instead of by simply who can afford it because it meets some threshold. This unlocks the "long tail" of innovation. This is what is referenced in the article: 1970s Hertz took a risky bet using debt which paid off to record profits.

- Higher interest really means higher long run inflation. If you can just let money sit in a bank, doing nothing directly productive for society, and there is suddenly more of it, prices will adjust accordingly. With low interest rates, money supply will adjust with GDP growth from innovation and prices might even be reduced by higher competition and discovery of efficiencies. As long as innovation (enabled by access to capital) stays on pace with money supply, inflation stays low.

This is of course a very optimistic way of looking at things which doesn't consider the effect of things like wage growth which has all but stopped. One could argue in a non-inflationary environment that might be ok, but this is a larger topic having to do with social mobility goals rather than just the economics.

The irony is palpable:

I would rather this be read by a few people motivated to take action than by a broad audience who will find it merely interesting. In that vein, if you find yourself wanting to share this on Twitter or Hacker News, consider instead sharing it with one or two friends who will take action on it. Thank you for indulging me!

I'm glad of course it was shared here. As a distillation - I think the author's theme lies with enabling more _researchers_ rather than business people to take moonshots and do foundational knowledge building and discovery that redefines a field and then focus on commercialization from a birds eye view by technically capable visionaries.

This is the SBIR [1] model (also a US Gov requirement to fund small business research for any federal agency with >$100M in funding), the Bell Labs model (which yeilded amazing foundational work like UNIX and the transistor and was a direct result of AT&T's monopoly and excess resources), and perhaps even the YC model (though that one is obviously focused on a shorter horizon and more on commercializing existing tech and more rarely on foundational research).

I've personally thought about this problem a lot and done this at a small scale and would love to expand upon it. https://augmentedlabs.org Would love to hear others experiences and thoughts.

[1] https://en.m.wikipedia.org/wiki/Small_Business_Innovation_Re...

Shortest Domain 6 years ago

If you are on an iPhone, type: "ai." to get to the site.

The trailing dot denotes the root of the DNS hierarchy and makes the domain "fully qualified". Otherwise it appears to fail a local integrity check if you try for just "ai"

The idea of React is good - declarative, stateful, reusable components, etc. While the bloat of React and it's toolchain (and npm plugins) has become a mess. When you have 2^100 different plugin combos to do something, you have 2^100 imperfect solutions and no experts in any of them, rather than one elegant and simple standard that can be optimized.

This repo is great proof that React is over engineered. Vanilla JS has WebComponents[1] and Templates, and a vDOM is easy to support (it existed long before React) and the DOM was the original place to store state in custom properties that you could manipulate internally with 'this'. What's missing is the ecosystem of Reusable WebComponents (primatives) based around this simple approach.

That's why this is so great to see. As more of a purist, I would try to make this a Vanilla JS lib instead of TS and remove one more build step. But the idea of 60 lines of code that use primatives (thus making this hyper extendable) is perfect.

[1] https://developer.mozilla.org/en-US/docs/Web/Web_Components

Great looking site. For those who don't know/realize - this is the work of Kevin Systrom, Mike Krieger (and team?) - co-founders of Instagram.

Statistically speaking - love that it has error bars and timeseries. Makes it infinitely more informative to track relative to news, events, and mitigation strategies and have a sense of the confidence of the estimate. The provided Jupyter notebook is a great resource.

Alphabetically speaking - I enjoyed the puzzle of figuring out how the states were sorted in the timeseries list (e.g. why was Alaska before Alabama, Iowa before Idaho, etc.). Turns out it's alphabetical by the two letter state abbreviation which is not shown - just a fun observation :)

Great work here. Are you using the legacy AppleScript interface [0] provided to Messages? I built an iMessage bot a long time ago that would respond automatically to messages you sent it and save notes for me using that and found it to be pretty reliable and easy to script but with a number of quirks and gotchas. I even bridged it out to Python to make it easier to work with.

The only limitation of course was that a Mac had to be always on, logged into the relevant account, connected to the internet, and running AppleScript to run it so there was no dream to scale it reliably/economically (as you are) much less even use it privately since the Mac was also a primary laptop. How are you getting past one device, one account scalability problem? Mac in cloud on the roadmap?

How do you consider you will scale this and at what cost? Have you checked into Apple's viewpoint and policies on this given they offer a business API [1] for a similar solution?

[0] https://stackoverflow.com/questions/11812184/how-to-send-an-...

[1] https://www.apple.com/ios/business-chat/