HN user

itdaniher

122 karma

[ my public key: https://keybase.io/itdaniher; my proof: https://keybase.io/itdaniher/sigs/O6Ujs0zaHiJA9-xEyjQrJs3fzISi38caiU4X367nmtA ]

Posts3
Comments30
View on HN

True diversity means listening to qualified and civil voices...

Referring to the leadership of Heritage as "civil" is a stretch from the point of view of individuals in categories repeatedly demeaned and dehumanized by the members of the organization acting in their official capacities.

All of these are true! Except maybe the first one, which is a gross oversimplification.

"The dose makes the poison" is not something I expect an average Google user to have modeled accurately.

Edit: after reviewing other examples in this thread, my opinion of an average Google user has fallen drastically. Was mostly having a laugh at the fact fluoride salts are generally a thing I avoid, which seems to be the intuition represented by your example.

I don't understand why, but I believe I've observed similar. Possible hypotheses include:

DHT Sybil attack? Hash ring bloat? Bad peers distributing exclusively irrelevant content?

Wonder if this is a common observation, and if so, what kind of research might elucidate the underlying change.

Maybe once upon a time, but with blobless mainline Linux kernel support for almost all features on almost all SOCs[1], including video codecs on many parts[2], anyone claiming Allwinner to be "the devil" or variants on a theme is unambiguously incorrect. Broadcomm and the raspi foundation are evil. [3][4]

[1] https://linux-sunxi.org/Linux_mainlining_effort

[2] https://www.kickstarter.com/projects/bootlin/allwinner-vpu-s...

[3] https://twitter.com/marcan42/status/1088472549715918848

[4] https://github.com/raspberrypi/firmware/blob/master/boot/LIC...

Running a build of Ayufan's 4.19 patches on a rock64 with latest dev device tree from the Armbian project. Eth runs close to theoretical, finally, and I've not observed any issues with USB3 either. Months of uptime, TB of traffic.

Here with the rock64 it was just a matter of time till hardware support settled in mainline, and it seems like we're there!

Proprietary - Can't patch out the autoupdate, which I might be tempted to do if something else in my toolchain did things at someone else's leisure.

DRM/monetisation - the product as of my comment didn't seem to acknowledge the open source works compiled into the binary, and I didn't think that was a good look for someone with the authority to push out malicious code.

I don't think a DRM solution that is both robust against an adversary and inspectable by a stakeholder can be engineered. Software can't look out for both the person running it and the person selling it simultaneously when their needs are mutually exclusive. Cory Doctorow has some eloquent content on the topic, ie at [0].

In this particular case, the use of TLS (good!) makes it relatively challenging to inspect. Assuming the author isn't shipping a cert in his binary (doesn't look like it) - I'd have to spinup a new VM, load a custom root cert, and mess with a TLS terminating proxy / forwarding solution, and hope he's not using a secondary stream cipher on top of TLS. Maybe I get lucky and https://mitmproxy.org/ or something just works out of the box. In any case, lots of effort to know he's not siphoning up all the source code on the local machine and using it to train v2 of his project. And the more robust the DRM solution, the less feasible it is to inspect.

[0] https://github.com/jwise/28c3-doctorow/blob/master/transcrip...

...as risky as installing a proprietary editor plugin which updates automatically, yes.

Also, AFAIK most understandings of MIT, BSD, and Apache 2.0 licenses require you to acknowledge the copyright holders of the source code you compile into your binary, even if the licenses permit binary distribution. I can't find your "Copyright (c) 2018 Tokio Contributors" or "Copyright (c) 2014 The Rust Project Developers" that I'd expect based on `strings TabNine | grep github`. Maybe you've got a lawyer that suggests otherwise? Your plea of "trust me, I have good hygiene" carries less weight when I have to `strings` your stuff to know what shoulders of which giants you're standing on.

your software will automatically update to the full released version at no additional charge.

So, give your proprietary software both network access and access to all my source code?

I have very few complaints about the Jedi autocomplete library, which is neither proprietary nor requires network access.

I welcome innovation in dev tools, but I wish you had found a monetization strategy that didn't require us to trust you so completely.

I'm astonished that there are folks in this thread who believe vaping to be as harmful as smoking cigarettes. Are there any peer reviewed papers supporting this assertion? I've kept an eye on literature as it's been released and everything indicates orders of magnitude less cell death and disruption from nicotine and flavor carrying PG/VG vape juice than cigarette smoke. Linked a DOI supporting this understanding elsewhere, but wondering if folks have papers supporting the opposite?

Floss is often / typically Nylon, which will take decades. If you accidentally wound up with PTFE floss (which is apparently a thing) I'd expect millennia unless it's in direct sun. Tampons should biodegrade at home, but I'm willing to bet there are large swaths of the US where composting anything with human fluids is illegal.

In any case, hat-tip for empiricism! Very pro composting, wish it was safer, smaller, and easier to do at home.

I have a rescue Cockatiel I inherited from my late grandfather. He's a poor excuse for a parrot, but a great pet and 10/10 work-from-home friend. Flies from his house, sits on my monitor, bows his head expecting headpats.

Don't rule out feathered friends - there's a continuum of intelligence and dependency ranging from finches (simple lil robots, a'la fish) to African Grays (3yo intelligence as discussed) - I've found my 'tiel to be in the sweet spot - intelligent enough to have his favorite people, not so smart as to constantly demand attention.

Thanks for the link, which presumably contains the OC I'm about to reference.

We've seen several classified documents claiming (pick a three letter USG agency) have minimal operational ability to deanonymize a particular Tor user, and even less-so in real-time.

Fortunately, the FBI has proven it doesn't need to break Tor to interfere with the most egregious of the malactors who call it home. They've hijacked servers hosting objectionable content and used them to deliver Firefox exploits to leak real IP addresses.[1] They've done "good old fashioned police work" and exploited human trust [2] to bring down well coordinated teams of international players.

[1] https://www.eff.org/deeplinks/2016/09/playpen-story-fbis-unp... [2] https://www.wired.com/story/alphabay-takedown-dark-web-chaos...

Posted on a duplicate:

Good old Yasha! If you've been paying attention to his works, you'll be underwhelmed by this particular post. He repeats his claims, many of which are easily verifiable and simultaneously without significance. Yes, Tor updates fiscal sponsors with regards to project status.

Yes, Tor is USG funded. No, it's not a Honeypot. It's also not a panacea.

As a technical project based in Cambridge, MA, Tor doesn't exist in a political vacuum.

If Tor was more of a pain to the USG than a benefit, it likely would not have been able to grow to the extent it has, but this by no means is indicative of a comprehensive system failure or any significant subterfuge on the part of Tor developers. I do not believe Yasha or anyone else has evidence to the contrary.

To be clear, I dislike Yasha as a self-aggrandizing spinlord shipping a conspiracy theory laden set of tenuous hypothesis, but I've gone out of my way to read the documents he's released to date

He posted the FOIAd docs here: https://surveillancevalley.com/the-tor-files/master-list

He and I discussed them a bit on Twitter: https://twitter.com/itdaniher/status/961307347950940161

I was not impressed by his response.

The "bunch of emails" seemed remarkably banal. I've written similar emails about sponsored open-source work myself.

edit:

email stack 1: https://www.documentcloud.org/documents/4367176-Tor-BBG-corr...

email stack 2: https://www.documentcloud.org/documents/4367193-Tor-BBG-corr...

Recovering olpc volunteer here. Happy to hear of your labors!

One of the concepts a related project explored was using live / persistent USB disks to preserve student ownership and facilitate unscheduled explorations.

Multiplexes hardware across students at different times, facilitating students using a consistent environment at home on old P4 desktops and at school on whatever's available.

Even large (32+GB) portable storage devices are available under $50.

Check out "sugar on a stick" and "open1to1" for related trains of thought.

eMMC via the ZIF connector on the Rock64 is a bit of a pain to get setup, involving a serial console and uboot commands, but I see better than 20MBps on an A1 class uSD. I use a USB3 SSD for my /home, it's even faster.

I have had a decent experience with the 4GB ROCK64. Armbian provides a reproducible build that I've found to be perfectly stable in practice, and while I have yet to try booting the image, I was able to build the 4.4.x kernel version I'm running, on the device at that.

There's mainline kernel support in 4.14, but I'm unclear as to whether it supports USB3, which, behind the price point and the 4GB of RAM, is the main draw.

I only run the device headless, so I can't speak to the behavior or interactions associated with the graphics engine.

The situation's gotten much better since Armbian started building images[1], but it's still running a stranded kernel for now. This is expected[2] to change within the next few months. I've heard on IRC of people successfully running mainline Linux on the A64 SOC, but I don't believe it's recommended.

As far as China single-board computers go, I'm pretty pleased with Pine's build quality and attention to detail with regards to electrical design that's reflected in their schematics. Community-provided Linux support has come a long way in the last year+, it's worth checking out.

[1] http://linux-sunxi.org/Linux_mainlining_effort [2] https://www.armbian.com/pine64