Checkout passage: https://github.com/FiloSottile/passage which has done part of this by using age instead of pgp. I used it for a while, and last I checked there was sadly no android app (the pass android app hardcoded too much PGP to be a useful base, so I was told), but the work is def there.
HN user
faeranne
Not even curl can connect... seems whatever this is on about isn't important enough for them to let people even try to read.
It appears that the public side of X is sent as the first part of the handshake, without any login info yet, and can be verified as part of B, thus a varying X would be easy to detect... I think.
looking at it from a high level, it doesn't appear the final token ever leaves the client till it's being redeemed. There's a middle step that does get signed, but this part is not what is sent.
Assuming the cryptography does what they say it does (am not a cryptography expert, so I can't verify that part), this would completely disjoin a search request from any account info. The account generates several "search tokens", and for each search request, one of those tokens is spent. The tokens are generated on-device, and until spent, never leave the device, so in theory there's no way for Kagi to know which account generated the token just from the token alone. This doesn't fix fingerprinting or IP associations (though the plugin for Firefox and Chrome supposedly takes efforts to try and limit fingerprinting too), but this isn't any better/worse than simply using Google or Duckduckgo, and functions on Tor if you really want some privacy.
Again, not sure on how the tokens are proven legit without ever sharing them, but there's probably some ~~zero-knowledge proof~~ stuff going on that covers that.
Edit: Not zero-knowledge proof. Seems to be Blind Signature?
Part of a library's primary purposes is the preservation of history and culture. In the modern cycle, one of a company's largest competitors is their own history and back catalog. Destruction of historical artifacts is becoming necessary to ensure customers keep coming back, as we have reached a point of diminishing returns at most corporate scales. If a corporation's motive is to destroy history, and a library's goal is to preserve, there is no compromise.
As I mentioned in a sibling comment, the entirety of IA's existence is a "critical failure of risk assessment" now. Their existence forces companies to deal with the one competitor they can't beat, their past selves. The question we begin to ask here is "This is the only place that was able and ready to accept and preserve these otherwise permanently lost works. Do we let copyright ensure the destruction of itself, or is culture and history more important?"
Probably they're thinking "This person brought us something that is about to be extinct, our job is to keep things from going extinct."
The entirety of IA is the idea that culture and history are to be preserved for future generations. The job of these big companies like UMG is to make as much money as possible, and destroying history eliminates a core competitor, themselves. IA's existence is poking the bear (just look at how often the Web Archive's existence is used by others to show off back actors in companies). Compromise left a long time ago.
The sought damages is $621 Million. Internet Archive reported having about $7 Million in assets and $30 Million in revenue (for those who accidentally read over that, revenue is before factoring in costs, which for IA budgets around $37 Million annually as well.) (EDIT: in 2022. I've been rewriting this a few times and forgot to re-add that part in the final comment)
If the suit is found in favor of UGM and enforced at full effect (not impossible, but Hachette v. Internet Archive was not either), then IA will be on the hook for the full $621 Million. You can guess how that ends.
But even if they don't enforce at full effect (and given Web Archive has been successfully used to provide evidence against UMG and Sony multiple times now, they have a pretty strong incentive to get it burned down), a sizable portion of the 400,000 recordings are from disks that quite literally broke down after capture. Those disks are the last copies of those recordings. Ever. Should UMG and Sony succeed, it is a very safe assumption, given they already confirmed they don't have those recordings (and based on that, don't want them), that those recordings immediately become lost media.
why don't we see HN crying about the need to show a national ID ... when buying a mobile phone?
Mmm, very possibly because there are at least a few ways to get a phone without using any ID. I picked up a used phone about a year ago, and use Tello. Tello had 0 info on me for years, only an old UPS box that I got the card delivered to. I eventually gave them my first name so Caller ID was correct, but short of that or putting in a correct address if you want 911 support, there's no reason to need any valid info with them. They don't do credit checks, just prepay.
The solution is secure boot plus attestation That's the second option they presented "Closing the platform". The issue with all these options is that it consolidates power, and thanks to already partially consolidated power, any option selected will, by necessity, obligate everyone to partake, whether or not they are ok with it.
The average normie user does not care about anonymity, nor privacy, on the Internet.
It's true that often "normies" don't care (or at least think they don't care, but that's a completely different point I don't feel like trying to make), and it's also true that often "normies" don't want the status quo changed. But often "normies" also ignore when people are kidnapped due to their heritage being revealed. Is it acceptable to actively create a hostile environment for people already disadvantaged? Do we gain something worth their safety? Who gains from this higher level of scrutiny?
If we look at the smaller web, most sites never get enough traffic to be under active threat, and passive threat is easy enough to quell using honeypot forms and questions. Maybe the "normie" internet is the problem. Passive people passively consuming. "Normies" love watching stolen content, and praise thieves for harassing anyone who points out that what their doing is wrong. "Normies" enjoy watching someone livestream themselves flying down a highway at 100 mph over the speed limit.
I think maybe we should acknowledge that what we're defending with things like hCaptcha is not actually worth defending. Maybe the "normal" internet does need to be deprecated over "small" internet? We did pretty good before with things like Wikipedia. The "small" internet from before had a lot of chaff, but good things have grown from it, and a lot of it still exists as a "small" internet. Maybe it's ok that we have a lot of "crap content", so long as the internet can keep changing?
I think maybe it's easier to realize you don't care when working apart from a company structure. I suspect most people don't care nearly as much about the company as the company would like. There's a constant push for "Corporate Family" and what not, which at large scales stops being a two way street and def becomes more indoctrination. Being separated def allows one to start viewing their relationship with work from a third party perspective, and often can show the unhealthy lines.
But of course companies that implement these indoctrination practices really don't want that, and will do whatever it takes to keep that control in place.
they affect less than a hundredth of a percent of Android devices, and do not matter.
2 reasons I can confidently disagree: 1. Unlike desktop platforms, most android devices cease receiving "official" updates long before the chipset stops receiving updates, thus maintaining them requires an alternative rom. While most people will just buy a new phone, the percent usually on the fence about something like switching from Windows to Linux are gonna be pushed harder into looking into alternatives. 2. Well over 1% of desktop users use Linux. Even if you debate the methods to get the current 4%, there's simply no debate on at least 1%.
The two combine to suggest that, on android, there's a very good change that more than 1% of android users are using some rom, and all roms help each other.
Don't screw up your otherwise valid argument by trying to "put tech nerds in their place" like that. These roms do matter, even if the judge 100% didn't "screw up". Everything else you said is both true and important, and probably matters more than what parent wanted, but it doesn't diminish the value of the roms, just suggests that parent was misguided.
I'd argue the line gets drawn when the driver is barred from stopping the distracting element themselves. Everything else can be stopped, disabled,refused, or removed by the driver. If an element is designed to be another source for focus (the entire infotainment system is this) it must be able to be turned off by the driver. In theory simply disabling the infotainment system should cover this, but now you have to argue if removing things like modern navigation is an acceptable option, and frankly, these ads only serve to line pockets. This isn't a radio situation where the feed is free, the car is (in theory) already paid for. (and don't try to argue that the car is cheaper because of the ads. TV manufacturers already turned that argument into swiss cheese when they stopped bothering to sell TVs without preloaded ads.)
Why is digital scarcity a good thing? Why is scarcity at all a good thing? Is there any reason for this, outside of trying to sell them at an ever higher price? And how does sharing a read-only e-ink card benefit over a regular card, or a card with an NFC tag in it?
I get the feeling people think because things are scarce already, scarcity is good. but... it really isn't. outside of a store-of-value, there is no real benefit to it, is there?
You're not entirely wrong, but often these AI systems need some pretty clear audio to work. It's kinda shocking how good we are at working around bad audio when it comes to conversation, and I'm certain most people know how bad these intercom systems get. The issue isn't that they need to be fixed at all, it's how far they can go before they must be fixed. And the one thing we can do that AI can't is have face-to-face conversations. If the speaker simply doesn't work, it's a bit of a drag, but you can just pull up to the window directly and skip the entire audio system. Or just walk inside. Both options eliminate the problem hardware, where as AI would need additional hardware to do those jobs.
Oh it definitely is, it's just also a requirement for reasonable living in most of the US too. It's not a good combo.
Someone want to setup a wiki for this? Seems like a good place for things like replacing the head unit correctly or other "make it my own" instructions.
Thing is, we do have that "document API". CAN bus has been a thing for a long time (and is still in use even today), and has documented ways of communicating with everything modern Body Control Units and Engine Control Units do. For everything else, we have the ever valid DIN size standard. Both of these together make for an easy to upgrade system, including options to use Open Source head units. Just looking for a radio and nothing else? Go for it. Want all the fancy bells and whistles that Android Auto or Car Play provides? You got it. Even the steering wheel controls have a standard.
So the question is, why do they keep re-designing the head unit as a monolithic brick, and make it non-replaceable? I can't say for sure why, but my guess is that they've since added their own team for "Smart this" and "subscription that", and removing those sources of revenue is far more expensive than rebuilding the head unit each year.
Ignoring the problematic details of this specific implementation (Seriously? they didn't make encryption the first thing to implement?), I think the biggest thing to remember is that, while the only sure-fire way to prevent this data from being stolen is to not record it, the likelihood some 2-bit hacker is gonna access this data goes way up when it's easy to expect it to be there.
CoPilot Recall is a massive target because if you break into a system, there would be a good chance that data is there since it was opt-out by default. open-source recall implementations are not only opt-in, but require additional overhead to install, so the likelihood that one would find this data on the drive is such a low target as to be not worth including in an automated scanner.
Remember that surface-area does matter in things like this. If you believe you're a large enough target for some amount of focus (and you might be if your involved in mid-scale open-source projects, like XZ apparently), then it's good to be cautious. If you're not that kind of target, then just remember you only need to be more complex than the average person, and something like this absolutely qualifies as "more complex".
Exact source is a bit convoluted, because most US law is convoluted, but is covered in multiple subsections of section 1201 of Public Law 105–304 (the technical name for DMCA). There are exceptions for things like making things interoperable and security research (kinda), but beyond that simply glancing at one of these locks can be a violation of DMCA. Sadly the document is excessivly long (60 pages plus references to other laws), and the available source PDF is so poorly formatted as to be nearly impossible to follow (nothing is aligned correctly, and subsections regularly form a very confusing pattern)
FreeCAD has some pretty hefty backing from the likes of Opulo, and a history (like KiCAD) of working with CERN and other groups like them. Fusion def has a larger laundry list of features, but if the question is "What open source cad tools exist" (and given the question is explicitly asking about open source electronics design, so I'd assume they want to stick with open source for model design too), then the answer is gonna likely be either FreeCAD or OpenSCAD. And given that most popular cad and edm software has repeated pushed back on the open source community (and given they are profit driven companies, they eventually have to), I don't blame a person for seeking exclusively open source tools. It's the same reason I decided FreeCAD's flaws are worth working through. I already had both Eagle and Fusion force me to scramble to recreate projects before, I wouldn't wish that upon anyone else who is doing this under- or at-cost.
Good news on that front, FreeCAD is working on adding an official Assembly workbench as we speak. They added OndselSolver as the core back in november, and seem to be working to add the workbench by the next major version. https://blog.freecad.org is a great place to keep an eye on things.
This reads paranoid and hyperbolic.
It does read paranoid, because the whole things should be ridiculous in a sane world. That's part of the problem. This shouldn't even be a concern, but it is.
I'm gonna needs source...
Unfortunately the source is to read through Oklahoma Statute 40-142, since it's a fairly interwoven and long document that establishes what Alternate Fuel Technicians must do to be certified, what vehicles must be serviced by said technicians, and what the consequences are for violating those requirements. Of note, the statute calls out EVs as falling under the statue requirements, and what your allowed to modify is a (short) list of exceptions, rather than a list of restrictions. There's no single line to point to, as is true for a lot of law stuff.
Also, nobody is bricking anyone's car. If you're that paranoid about remote access, it's possible to just remove the cell access.
First, please read the last 3 references of my previous comment. There is a clear and present pattern of increased removal of access via remote updates. Furthermore, removing that cell access hampers the car significantly, with no allowed alternative. The option is to let them listen, or watch your infotainment system be effectively paralyzed. I would be happy with an option to simply swap out the infotainment with something else, like I did with my 2002 Honda Civic, but it's their system or nothing. Plus, it takes one trip to the repair shop, which must be a first-party repair shop, since no one else is allowed access to the needed codes to reset the computers, for something to be updated without my consent, and a feature (or the whole car) to be bricked "for your safety". It need not even be that involved. Again, the above train example used geo-fencing to decide when to brick the train. no remote connection needed.
This isn't just a matter of can I hobble a car enough to not abuse me. It's about what part of the car do I really own. Am I allowed to modify it? Are enough of the systems cryptographically secured to, in-practice, prevent me from changing something like a break-pad? Will I need to completely replace the engine computer to swap out the music app?
Right now the answer is that the car isn't mine, and I'm not allowed to make changes. Not in practice, and not in principle.
Two years ago I spend nearly a month hunting for a decent electric vehicle. I had plenty of funds, and could theoretically afford a lower-end tesla. I was, at the time, driving a 2002 Honda Civic Hybrid, because to me, going electric makes sense. I was aware of the range limitations, and even had an agreement with my landlord to get a 220v outlet installed in the garage.
I ultimately abandoned my endeavor because none of the vehicles provided 2 key things older cars continue to provide: Ownership, and Privacy. And key to this is that this isn't just electric cars, it's pretty much all modern cars. My Civic had a replaceable stereo headunit. How many modern cars have the infotainment system so embedded that functions of the cars depend on it? And we know car manufactures take advantage of that. Hell, even judges seem ok with them doing that [1]. Then you have the fact that repairing anything in the car is made not only intentinally obtuse, but illegal is some states. As it stands right now in oklahoma, you can do any work you want on your gas vehicle, but move to electric and you better have a $5,000 yearly certificate to touch that. Simply opening the hood can land you in jail. And we know the car manufacturers can tattle on you [2]. Then there's the fact that these cars are more than capable of moving themselves. And that system is tied to a remote service. Absolutly nothing stops a manufacturer from deciding that your car's "drive train control system" is no longer licensed, and simply shut it down. Permanently. If companies are willing and able to steal your media [3], the next step is easily to just brick your appliances. Hell, microwaves are already doing that [4]. Trains do that if you decide a third party repair station is reasonable [5]. Where does this end?
Point being, till I can truly own my vehicle again, I'm sticking with older cars. I would much rather own an electric vehicle, but so far none of them are even remotely close to being something I can actually own. Price has nothing to do with it. [1] https://www.malwarebytes.com/blog/news/2023/11/judge-rules-i... [2] https://www.theguardian.com/technology/2023/apr/07/tesla-int... [3] https://www.forbes.com/sites/paultassi/2023/12/02/playstatio... [4] https://hackaday.com/2022/03/18/welcome-to-the-future-where-... [5] https://hackaday.com/2023/12/06/the-deere-disease-spreads-to...
I don't think Twitch fits the other definitions, 22675(e)(2)(b) probably could be argued to not fit with Twitch.
I was about to type up a message about how this affects private services too, buuuuut... section 22680 pretty summarily removes self hosted instances. I doubt any of them are making $100,000,000 profit per year.
https://github.com/noiszy/noiszy There's no direct link to the source, but it's out there.... and very, very broken.
Given it can run on other engines as well as self-hosted or local models, I don't think "calling someone elses API" is a major issue in relation to the reddit situation. If anything I'd argue this being both open choice and open source negates the concern of losing access to the software. As for continued development, it's about the same as any self-funded project: It's free, so don't expect the world, and if you end up relying on it as a company, it might make sense to forward some effort back to the project to keep it stable.
Exactly. Steam can, and honestly must, block them. People don't seem to realize that, of most of the large tech companies out there, Nintendo has figured out that they can easily outspend anyone in legal fees, and no one will care. Just look at their financials. Their lawyers make more than their board. They don't care what is legal or not, they can simply sue anything they don't like into oblivion. They don't have to win the suit to make it disappear.
Having started with Joplin, the three things that took me away were the (at the time) lacking mobile support, periodic syncing collisions, and probably most importantly, their non-standard file format. There was a tool that could extract files into standard markdown format, then repack them, but the overhead was tiring, and meant a few key environments lacked access, namely when I was accessing a server from the rack, and when the mobile app acted up. I actually moved to just using vimwiki style setup with markdown and a markdown editor app on my phone for several years, before I stumbled across Obsidian. I've since been using obsidian for about 9 months now, which is longer than my time with Joplin, and I will say that, once I got a stable sync going (I'm using the simple sync plugin and my own s3 compatible server), the plugin support, decent mobile app, and native markdown files have won me over. Though I'm still eyeing open source options with Logseq, just waiting on their mobile app to pick up and properly support plugins. I'll be more than happy to port everything as soon as it supports that.
As an additional note, I will add that despite Obsidian being closed-source, I actually feel more comfortable with my data there than with Joplin, primarily because all my data is just common markdown. With Joplin, if I archive content, I have no guarantee the notes on the file format will exist in 10 years (they probably will, but it's still a real possibility). With Obsidian, it's plaintext. There's nothing to need to rediscover, no file format to decode, just good old plain-text. In 40 years I'll still be able to read those files (though the storage media is a very different story). Sure Obsidian can change plans mid-stream, and I don't trust they wont, but all I gotta do is go back to my markdown editor and vim. No sweat.