HN user

hunter2_

3,616 karma

web and audio

Posts12
Comments1,908
View on HN

just read an extra second [...] accidentally trigger watchdogs

Well, this seems to touch heavily on the concern: if your job normally takes 0.1s and costs $100, it could accidentally be considered to have taken 1.1s and therefore cost $1100. This is quite contrived, but if you consider that some people put very infrequent cron jobs at the top of the hour (which isn't typically the best idea, but I digress) and it might start just ahead of what the billing system considers to be the top of the hour, theoretically there's something to this concern.

Yes, but a mitigation suggestion like "keep using it, except don't do X specific sequence" (for example, send to a Yahoo address via the Reply button, or whatever the case may be) could be helpful as well, since it seems that bad actors (and/or good actors spilling the beans) will figure it out sooner than later anyway.

As someone who doesn't rely on this feature, I'd love to know now as well, but perhaps the etiquette in public would be to align ourselves with:

we will not discuss or disclose the details of the exploits until they're fixed.

But if there's a public forum where the cat's already out of the bag, then game on. Perhaps this:

https://www.reddit.com/r/apple/comments/1ukilw1/apple_hide_m...

...which makes it seem like perhaps the attack surface is limited to scenarios involving a Yahoo/Sonic address (assuming that Apple only sends X-Sonic-* headers when talking to those providers that want to see it), which might be a small percentage of users.

When you're already going 10 mph and you're about to add another 10 mph, you can only "call that zero" (i.e., go from 0 mph to 10 mph again) if your point of reference (i.e., the ground) also begins moving with you at that point. Since the ground is stationary, you're definitely about to increase from 10 mph to 20 mph relative to the ground, not from 0 mph to 10 mph, and that's harder to do. But if you're on a treadmill that was stationary for the first change, and then suddenly starts moving at 10 mph right before the second change without affecting your speed relative to the ground, then you can "call that zero" and you'll be able to add another 10 mph (ending up at 10 mph relative to the treadmill and 20 mph relative to the ground) with the same ease as the first go.

I'll admit, many maneuvers can be described as cutting someone off. One so crazy that it would likely cause a collision should never be performed, but I was talking about the low-speed "bumper to bumper traffic" scenario common in lanes dedicated to making a left turn: the reason the gaps are too small for a non-cutoff lane change is a direct consequence of the low speeds involved, say 0-10mph. Imagine cars are nearly stopped for a red light, with gaps varying between 0.2 car length and 0.5 car length (this is much tighter than other parts of the US where gaps while stopped for a red light are typically 1-3 car lengths). I would line the nose of my car to the very front of the 0.5 gap (taking the majority of the risk), signal, cross the lane line within a flash or two, forcing the gap to expand to just over the length of my car, all at just a few mph. This is the type of cutting off I was referring to. And the driver who was cut off has no opportunity to fight; they would if I signaled too early!

Indeed, the extremely minor inconvenience of creating a gap in that scenario is very common even in the northeast US. It's the other half of the spectrum, where it's a more severe inconvenience, that it's uncommon for a northeastern driver to accommodate, from which the perception arises that we fight people who are signaling. The signaler is the one picking the fight, and we simply don't entertain it.

I wouldn't turn on my signal until after they had passed. If I did it before they pass, they might think my intent is to merge in front of them, and slam on their brakes

This is precisely the point I'm making, which I perceive as more typical in the northeastern US than other parts of the US where people use the turn signal to beg for an opportunity to be created that doesn't yet exist (at which point declining to create is seen as actively fighting when it's really not).

Also really strange to me to be prioritizing fuel economy over safety.

If I see that someone is actually changing lanes (in terms of lateral position changing within their lane) then of course I would get out of their way, as it would be unsafe not to. But if they're postponing their lane change (despite their signal already being on) because I'm about to be in their way, that's the scenario I'm talking about when I say I'm going to continue on my way rather than lose momentum/fuel: they are waiting for me to not be in their way, they will continue waiting until I'm gone, and they should've waited until I'm gone before signaling (by "should" I simply mean if they want to assimilate into this driving style). The example scenario in my other recent comment will help illustrate this.

leave a big enough buffer with the car in front of you [...] leaving a healthy gap

I realize that my original comment wasn't clear on this, but the "gap" I'm talking about is between cars in different lanes (again, see the example scenario in my other comment). We can assume no lead car at all.

I also can't comprehend how if you're "scared" by someone signaling when you are in their blind spot, the best course of action could be to put yourself directly in their path vs giving a little extra space to safely merge.

I won't say it's the best, it's just what I've noticed. But it's not "their path" if they're just hoping to be let in without actually moving. When they start moving, it's a whole different story, and I would get out of there (ideally lane change, but brake if needed). I guess "stealing my attention" would've been a better way to say it than "scare."

How do you handle an upcoming left turn (assuming right hand driving) during heavy traffic?

If I am in the middle lane (lane 2), and I realize I need to get into the leftmost lane (lane 1) to make a turn, but lane 1 is too full for me to simply move into it without affecting others, then I would have no choice but to cut someone off. I would minimize the effect in two ways: by trying to cut off whoever has left the largest gap in front of them (hunting for a gap that might not be the largest now, but will be the largest when I actually use it), and by assuming as much of the rear-end-collision risk as possible until the lane change is complete. Only once my position is optimized to begin the lane change would I signal, because signaling from a suboptimal position could scare people (or give them an opportunity to fight my ability to change lanes). If I can remain in the optimal position for a couple of blinks without any downside, I absolutely will, but in the very heavy traffic we're discussing, typically the tires hit the lane line between first and second blink -- very much not an "ask."

Does "momentum towards closing the gap" just mean that you're keeping a higher speed than the car in front of you?

No, I was referring to the gap between the car signaling for a lane change and the car that ends up preventing the lane change, which are in two different lanes. Suppose I'm in lane 2, and a car is in lane 1 a few car-lengths ahead of me. Suppose the car in lane 1 is going slower because they just merged from a left-side entrance ramp. Due to our speed difference, after a moment they're now only 2 car-length ahead of me. Their right turn signal comes on. Now they're 1 car-length ahead of me but they haven't yet changed lanes. Now they're 0 car-lengths ahead of me (i.e., the gap is closed) and cannot change lanes. I did not "let them in" upon seeing their signal, because that would ruin my momentum.

As a northeasterner, I can explain:

In some other places, a turn signal before a lane change is an ask, to which others respond by creating more of a gap than there originally was. Here, it's not an ask but a statement that you've got enough of a gap already so you're going for it. As such, others don't find a need to react at all, which could mean the gap continues shrinking if it was already shrinking prior.

The signaler needs to have anticipated it and not signaled until this problem doesn't exist, in fact it's scary when someone signals despite this problem because the other driver is led to believe they're unseen. When there's already a lot of momentum toward closing the gap, continuing to do so is a more fuel-efficient way out of the blind spot than using the brake pedal.

Aside: turn signals that automatically flash 3 times with no reasonable way to cancel the remaining flashes when you discover a need to abort a lane change exacerbates the aforementioned scare, so I recommend disabling it.

Stop Ruining It 2 months ago

Presumably that's to keep hardware sales up, e-waste be damned. You won't notice it taking 8 times longer when you have 8 times as many cores, or whatever.

Not being able to ignore the speech/writing/transmission of a passenger is reasonable. Not being able to ignore the speech/writing/transmission of the manufacturer of a device on the plane is unreasonable.

Wifi SSID? Passenger speech, since those are typically changed by the user. Bluetooth GAP/GATT device name? Manufacturer speech, since those are often not changeable by the user.

I can imagine an evolution like:

1. Introduce passwords

2. Introduce email-based reset flow

3. Introduce 2FA (optional)

4. Someone says "take the password reset flow, trigger it automatically when a user tries to log in and has only given their email, hide the password field during login, and after the email is validated drop the user back to their previous journey instead of having them set a new password"

5. You see #4 as #3 failing, but when #3 was never applied it's not quite that. Aside: making #3 mandatory would be smart.

I had been thinking someone with a similar address made a typo. But now I'm thinking Microsoft already considers this a known incident depending on whether a bazillion attempts were made in a detectable manner. I hope a successful launch at least demands a botnet and random delays/backoff.

You have a point, but as a musician and programmer, I'm far more fond of AI generating things of a "no wrong answers" nature than things that are ostensibly correct.

Music does have certain notions of correctness (e.g., [0]) but with a very forgiving "know the rules, then break the rules" aspect. Code has bugs or it doesn't, and it's probably easier to debug human-written code (certainly easier to grok every line of a human-written PR, IMHO).

The real problem is with the domains that aren't at the far ends of this spectrum.

[0] https://en.wikipedia.org/wiki/Counterpoint#Species_counterpo...

I recently got an unsolicited OTP email from Microsoft, which led me to fear that someone had entered my password, but no: I eventually was able to confirm that the arrival of an OTP does not, in fact, require that someone enter anything beyond my email address. This is rather insane (I should not be having a blood pressure event due to Microsoft) but on the other hand I do understand the passwordless concept which is just a password-reset flow sans password-change. Perhaps a nice middle ground would be if the OTP email explicitly stated that my password was not entered.

Thanks! As I think about terminals in quite different contexts (credit card terminal, battery terminal, train terminal, etc.) I'm realizing that it's really just any kind of endpoint at all, so pretty much any human interface device (HID) should probably be called a terminal. But when taken to that level, using the acronym TUI (in the "terminal" sense) to mean "not a GUI/CLI" (as if big old consoles or emulators/PTYs thereof are the only type of terminals) seems questionable.

The tricky bit is that while it's impossible to deprive someone of their idea (i.e., commit theft of an idea), it's possible to steal someone's idea (i.e., copy it and use it illicitly), because only the word theft, but not the word steal, has that "deprive others" stipulation.

So with that in mind, circling back to whether possession occurs in such a way to make possessive language appropriate (being able to say "my data" after stealing data but not depriving the author of the data), my opinion is that the copy of the data that the author still controls is the author's data, and the copy of the data that the stealer controls is the stealer's data. It's the author's idea, but both parties separately possess the data (the data is a record of the idea).

Stealing has a much looser definition than theft; notably, it can include ideas unlike theft. You deprived me of my accounts, but not of my now-obsolete passwords, therefore it's a theft of my accounts, but not theft of my now-obsolete passwords; I suppose you stole both. I'd be upset despite lack of password theft because I'd be the victim of your CFAA violation for example.