HN user

eksith

5,196 karma

I should have been a carpenter

Twitter: @eksith

Email: reksith at google's email thingy.

Web: eksith.com | eksith.neocities.org

When engaging in a pointless argument on HN, please heed the following advice: https://news.ycombinator.com/item?id=5976026

Posts148
Comments1,423
View on HN
www.snipe.net 11y ago

The Hardest Part of Running a Startup Isn't What I Thought It Would Be

eksith
1pts0
www.moma.org 11y ago

Welcoming New Humble Masterpieces into MoMA’s Collection

eksith
6pts0
www.wired.com 11y ago

How Ebola Healthcare Workers Get Dressed

eksith
2pts0
www.ncl.ac.uk 11y ago

Contactless cards fail to recognise foreign currency

eksith
37pts30
www.wired.com 11y ago

Communication between brain networks in people given psilocybin

eksith
189pts97
www.wired.com 11y ago

America’s Polling Places Desperately Need a Redesign

eksith
1pts0
www.washingtonpost.com 11y ago

A day buying (and returning) things with Apple Pay

eksith
1pts0
www.wired.com 11y ago

A Full-Body Mouse: Click with Your Leg, Scroll with Your Hips

eksith
5pts0
www.sciencemag.org 11y ago

Detection of a branched alkyl molecule in the interstellar medium

eksith
2pts0
www.plosone.org 11y ago

Olfactory Dysfunction Predicts 5-Year Mortality in Older Adults

eksith
3pts0
arstechnica.com 11y ago

Spyware executive arrested, allegedly marketed mobile app for “stalkers”

eksith
3pts0
qz.com 11y ago

iOS8 will predict your passwords

eksith
4pts0
arstechnica.com 11y ago

Fake fingerprint fools iPhone 6 Touch ID

eksith
2pts0
arstechnica.com 11y ago

Ashkenazi Jewish population has distinctive, yet similar genomes

eksith
2pts0
medium.com 11y ago

Musings on Deep Learning

eksith
2pts0
www.gov.uk 11y ago

End User Devices Security and Configuration Guidance

eksith
1pts0
www.plosone.org 11y ago

An Efficient and Provable Secure Revocable Identity-Based Encryption Scheme

eksith
6pts0
en.wikipedia.org 11y ago

Joan Pujol Garcia

eksith
1pts0
arstechnica.com 12y ago

One man’s journey to restore Star Trek’s bridge

eksith
6pts0
arstechnica.com 12y ago

Researchers ID genetic switch that controls muscle repair system

eksith
1pts0
www.npr.org 12y ago

Sniper Attack On Calif. Power Station Raises Terrorism Fears

eksith
2pts1
www.computerworld.com 12y ago

3D printing, now in living color

eksith
1pts0
arstechnica.com 12y ago

Did life start with a replicating molecule or a metabolism?

eksith
3pts1
www.wired.com 12y ago

Did Brain Scans Just Save a Convicted Murderer From the Death Penalty?

eksith
2pts0
www.itworld.com 12y ago

The Moore's Law blowout sale is ending

eksith
47pts41
isitsnowingyet.org 12y ago

Is It Snowing Yet?

eksith
3pts1
www.gutenberg.org 12y ago

The Hitchhiker's Guide to the Internet (1987)

eksith
20pts3
duckduckgo.com 12y ago

Generate QR codes with DuckDuckGo

eksith
37pts16
duckduckgo.com 12y ago

A QR code that means...

eksith
1pts0
www.logothief.com 12y ago

LogoThief

eksith
58pts35
  If a woman blogged unkind and sexist behavior at a tech company, but 
  hid her name to avoid the backlash (like Michael), that would be 
  unethical. I guess she'd be an "asshat", right? Same thing for a 
  journalist using an anonymous source?
Did you just compare a woman blogging about a legitimate grievance that makes her work environment intolerable to someone suggesting "Fair game" practices a la Scientology for criticizing his company?

That was a fantastic article! Thanks for linking that. It certainly gave me a lot of food for thought.

My honest hope when I first heard of Uber was that it would give a huge wakeup call to the industry. Let's face it, America is a service industry and many of its services suck. The attitude is marginal at best, horrifying at worst. I hoped this level of customer scrutiny on performance would bring it up to the same level as in Japan.

I'm still hoping someone will make it happen. Or rather, perhaps an entire army of services will make it happen as we've seen, a de facto monopoly, yields terrible results.

And this, folks, is why taxi regulation is a thing. Of course, there is crime and corruption and they have their own variety of scams[1]. But what you won't see is a sweeping sense of impunity because if you go out of bounds to this degree so blatantly (and at regular intervals, it seems), a rather large hammer will come down on you and your union. Taxi drivers in general are well aware of this.

But a bunch of broexecs, who answer to no one, setting the tone for everyone else is unlikely to feel any need to change any time soon.

[1] http://www.nydailynews.com/new-york/tlc-22-000-cab-drivers-p...

This is why PBKDF2 would have made more sense then. They can centrally authenticate, derive a secondary token from the original pass while specifying the max limit for each of those services. Best of all, this means the mail, UNIX login etc... need not have the same login token.

  The McGill Password length has also been increased from exactly eight 
  characters to a variable length of eight to 18 characters.
So they're not using bcrypt (usable length 72). Even PBKDF2 would have been acceptable, but my guess is that they were sold a "layer over" on their stack with this. I can already tell this is a hacky patch.
  Every year, about 1,200 to 1,500 McGill accounts are compromised in 
  one way or another.
Phishing + guessing. I know someone who gets about 2-3 emails a week asking to enter their login info into some site in Brazil or the Czech Republic.

If every site properly salted and hashed passwords, reuse isn't even a problem. But as we know :

  - Most people choose crappy passwords.
  - Most sites use crappy hashing schemes (if they hash at all)
When other sites are compromised, there's an easy list of ready passwords to try against other potential targets.

McGill's problem isn't Heartbleed.

If the popularity of GoDaddy has taught me anything, it's that people use what they know; not what's good. The list of companies that should have gone out of business is as long as the number of years since commerce began.

The fact that they still stay means (and this is relevant to the EFF project as well), creating alternatives is just as hard as making enough people know and care about them.

The registrar check per domain is probably the biggest plus in having it act as CA. Of course, that adds overhead to the registrar which they may not be willing to accept (margins and all that).

The registrar issuing cert solution would certainly speed up HTTPS adoption; you're dealing with one less org to secure your site. The down-side is that if you decide to move registrars, that still complicates things. What if the new registrar refuses to issue a new cert without a hefty fee? Or what about revoking the previous cert? Now the registrar is functioning as a de facto CA so it doesn't completely eliminate the middle-man factor.

I'm hoping the EFF project will smooth over these hiccups, which is why I'm looking forward to it.

  Privatoria.net is a service which provides secure communication, anonymous 
  surf and secure file sharing for individuals and business. All security 
  services are united together in Privatoria. It includes Secure VPN and 
  Anonymous Proxy, that enable surf anonymously, change IP, unblock sites, 
  Anonymous E-mail, Secure Chat, Secure Call, Secure Video Chat for secure 
  communications and Secure file sharing via FTP and Secure Data Storage.
No conflict of interest there at all in your badmouthing of Tor, with no corroborating evidence at all to boot.

That's extreme. This is just a swing toward turning internet access into utilities like electricity and water which are available without being tied to your residence. You still have public street lights and public water fountains outside your home. Likewise, internet is slowly moving away form this "thing" you always have to pay for to stay connected.

Verizon, TWC, Optimum, Comcast et al require that you have an account with them to use their hotspots. But you don't need an account with ConEd to be able to read your newspaper or book out on the street. This is where internet is headed.

You can view something like 20 stories a month

10 stories a month. Also, even though you may only post one or two as you say from these sites, others do the same adding to that total E.G. wsj.com Which doesn't allow viewing at all unless you browse in from a search engine or subscribe.

There are many reasons not to freely give out your address, or name for that matter. The validity of ideas need not be tied to an identity. If an idea can stand on its own, then so be it. If not, you can just move on.

"...being accountable for an opinion is probably bad for them in this case." Same for you as well, it seems.

Amen. Actually that would have been the better outcome anyway since it adds entropy to the gene pool. Cross pollination of ideas could have benefitted both parties. And even if your side doesn't take the cake, enough people would have flocked to the source that we could have fixed some bugs and resolved potential security issues due to the addition of more eyes.

Looking from afar, you'd think this was some tiff over imaginary lines on a map or something. Now that would be silly.

"While these death threats and the like are in no doubt horrible..." Then let's stop there.

No bridge is sacred enough to warrant physical threats when burned. No attitude poor enough to elicit the response that this did. It's bloody software.

Extremely difficult. There is plenty of technical expertise in networking, laying fiber, trenching, construction, equipment etc... around. Even with the local terrain. The problem is with the legal landscape.

Take Google for instance. The biggest hurdles they had to deployment are the protective hurdles put in place by ISP friendly politicians. Some states have regulation in place that new deployments must reach last mile to virtually every resident, which is cost and time prohibitive when there's no profit initially. You have to bite the bullet and do the deployment as necessary, bend to the legal winds and bear the full cost (which, even for Google may be a bit high) with no guarantee of profit until years after deployment.

4G is a bit tricky as well since there are areas where you'll have little choice but to rent existing towers or build your own. In some places, the terrain gets in the way, so towers are fairly limited in what they can do. Then there are the issues with maintenance and safety for crews working on these towers, which cell providers don't seem to care much about http://www.propublica.org/article/cell-tower-fatalities

In an ideal world, any traffic entering and leaving a private network would be encrypted, but the issue is with near-realtime services like VoIP and remote presence where latency isn't acceptable. When you add the large number of users that use these networks, the amount of hardware for both redundancy and performance load balancing becomes a problem.

The Myth of AI 12 years ago

Bachelor’s degrees in physics and economics. Experience in engineering, consultancy and management while working at Tesla and Space X (particularly their engine design). Has a history of literally thinking outside the box.

The Myth of AI 12 years ago

Because the foundations upon which AI shall be built aren't exotic. They're still programs. They still need an architecture to run on and they need electricity.

Even if new architectures that are specifically designed to leverage neural nets[1] or some other variety of processing are developed, the fundamental realities of computing, programs, physics and economics are not immune from being sufficiently underwhelming as far as AI is concerned.

Of course, this is precluding cloning technology where actual biological brains and therefore legitimate "life" and therefore intelligence can emerge.

[1] http://www.nytimes.com/2014/08/08/science/new-computer-chip-...

That's awful! You should never even insinuate physical threats like that. You're putting yourself and others at risk by doing so and permanently harming your own reputation.

Look, I'm not hopelessly naïve (most of the time) and understand very well about standing up to what's right, but there's a way to do that without acting like this. Even if the person you're dealing with is a sociopath, even if they're terrible human beings, there are ways around them that don't rely to threats, real or implied.

Negotiation takes a lot of nuances, verbal and physical, but you can achieve a lot diplomatically without being intimidating physically.

I understand where you're coming from, but I disagree completely.

Edit: Also, I didn't downvote you because what you brought up was still interesting and allowed me to voice my opinion.

It was actually a credit union. And yes it is crazy, but then so are a lot of their other practices. Also, I was calling them internationally so even though the private questions they asked me verified my identity, it was still an arduous process. The number of times I called to finally get the card cancelled actually made my long distance charges greater than the stolen value ($25).

Like I said, I don't know if they still do this.

I had a discussion with a friend about The Thing[1], an invention by Léon Theremin and how ingenious it was that it required no external power source and can be turned on/off at will by transmitting at a certain frequency. The trouble with this is that it's still possible to identify the retransmission. In fact, this was how it was discovered.

What if the room had a length of surgical or other type of long tubing embedded into the wall so that the detector was a fair distance away? Essentially, a very crude stethoscope originating in a wall outlet or other place in the room that already has an orifice(s) and terminating at another location with a passive resonator.

By decoupling the transmitter from the audio source by using a non-electronic medium, it's possible to still eavesdrop on keystrokes even in an em-shielded room.

[1] https://en.wikipedia.org/wiki/Thing_(listening_device)

It's a nightmare sometimes to cancel credit cards, especially if you're travelling.

There are some banks that simply won't cancel the card until you visit your local branch. A tricky maneuver when it's 2000 miles away (I don't know if they've changed this now). Likewise, there are things that are hard to find if you use your cards a lot and don't keep detailed receipts on everything you buy. This happened to me when I discovered someone's been deducting a small sum from my card for several months without me noticing as I was overseas. Of course they could only take care of the last charge before cancelling my card.

It will look like every other book... intended to hold private information so they'll never suspect anything! ;)

I once had the bright idea to put passwords written on a small piece of paper and place it inside a 3.5" floppy. If it's in a pack of other unlabeled disks, that's going to be a nice fishing trip.

The laughter was nearly deafening when this product was introduced http://arstechnica.com/gadgets/2013/05/password-minder-the-b...

I wonder whether its time has finally come.

Edit: It's worth noting that each typewriter is unique and will leave a telltale signature subject to identification https://en.wikipedia.org/wiki/Typewriter#Forensic_examinatio...

Of course, modern printers aren't immune to this and many models incorporate identifiers by the manufacturers to aid forensic investigation https://en.wikipedia.org/wiki/Printer_steganography