HN user

iwillbenice

64 karma
Posts0
Comments38
View on HN
No posts found.

Yep, not a monopoly, just a market bully applying mafia-like extortionary tactics.

Yeah that's totally it. It couldn't be that people like to have a phone that gets security updates for more than 2 years. Or having an AppStore that is policed in any meaningful way that keeps blatant spam and data-slurping apps out. Or any other numerous things that the Android ecosystem is totally fucked up on.

I love Apple haters- They rarely ever make sense and just come off as bitter.

(Sorry to ramble, I'm doing what I started sarcastically referring to as my "executive time" during the Trump administration -- if the signal is sometimes useful you can't complain it's also sometimes weird as hell.)

"Executive time", a/k/a fuck off time, is perhaps one of the few great things Trump gave us. I'm legitimately not kidding. More people need to engage in fuck off time on a regular basis. It is refreshing for the mind.

That line from Fight Club really needs a whole lotta asterisks and qualifications. There are plenty of forced-recall scenarios where the manufacturer would prefer to use the ABC<=X approach but are not allowed or simply over-ruled by government. Safety of life being the primary over-riding concern, for good reason.

I'm pretty surprised this issue has gotten as long in the tooth time wise as it has. I remember seeing a story about this ticking-timebomb power connector like 1.5 months ago and then heard nothing. I'm guessing there is scurrying behind the scenes between then and now, but you never know.

Imagine if the situation was flipped, and your CEO went "sales reps need to understand engineering complexity, so from now on they will each have to fix 10 bugs a month."

Picking up the telephone and debugging areas of expertise YOU created or are already responsible for is much easier than making a sales guy into a pseudo-engineer.

Also, paradoxically, some of the best product features I've come across literally started as a ghetto-coded-idea by a Technical Account Manager (sales engineer). Said features were later formalized and picked up officially by engineering, but the nexus of the product feature started with a non-dev.

Sorry for the ramble/rant. My point is this: Don't get so married to job titles. It can be limiting in my humble opinion.

I think privacy-first is the the correct mental model to have. I've had to explain to some people that the usage of a certain platform by drug dealers, pedophiles, and organized violent crime isn't a defect, but really a feature in theory. If the tech or platform sucked/was-compromised, they wouldn't gravitate towards it. It is a weird conversation, but most people do seem to grok it in that sense.

Nothing of what you said changes my original point: We live in a mixed-market economy. The government manages some buffers (food, oil).

And I'd really like to understand how the government "takes half" of your salary. Either you're super rich (probably not), or you're exaggerating.

edit: and for the record if your messages on a dating app are not E2E encrypted then you are making a terrible mistake. I can't believe anyone would voluntarily make this decision.

Reality goes something like this: You roll out your E2EE dating app, it gets successful, you're winning bigly. Then cops show up with an order from a judge demanding you hand over information regarding user #890202 because they are suspected of using your platform to entice minors into sexual activity. This is usually where the E2EE worship falls flat, for legitimate societal reason.

If you want E2EE you need to use a dedicated app specifically ONLY for that (Signal, WhatsApp, etc). Any time you bolt on other business or incentives and then use E2EE as the messaging platform you will discover a world of pain in my opinion.

(Aside: why do you even think the president is in that convoy? They may well be elsewhere, moved into the third suburban at the last possible invisible moment.)

Unless they are actively repelling an attack, I can guarantee you that the President is absolutely not anywhere except the Beast. All of the other vehicles in the motorcade are less armored, and do not carry the critical items the President may need, namely his blood. The standard operating procedure if the President's motorcade is attacked is to exfil the President while the CAT (Counter Assault Team) lays down massive amounts of suppressing fire. To that goal, the Beast is the safest vehicle for the President to be riding in.

I really wish people would stop conflating reducing the attack surface with safe software default configurations. They are not the same. There is value in hiding your listening sockets/ports from the world. Anyone who does not believe so frankly has never been responsible for security beyond their laptop and maybe some random VM in AWS they SSH into.

Have you ever been responsible for security in a professional sense? Hiding attack surfaces is standard operating procedure. No one with a triple digit IQ seriously thinks any piece of software is going to be secure to infinity.

While I am sure you are competent like most folks on here, I will say this: I have met a good number of people who claim they can "get in and get out un-noticed". In retrospect, I think rarely did they consider the possibilities of observation beyond the actual target system.

My point is this: There is no defense against 0-day/X-day exploits in the wild. But the second best thing against being patched is logging and properly tuned alerting. In my 20-ish years of working in this field I've caught half a dozen attackers/intruders via logs and anomaly alerts. Without those 2nd best things in place the entire network(s) would probably have been compromised.

Cheers.

The one note I will mention about SpaceX and caring about HW/terminal security is the subsidized cost. SpaceX is retailing the terminal I bought for $500, while I understand the hardware all-in is north of $2000.

In these scenarios you will usually see the vendor default to locking down the platform/hardware, if for nothing else to prevent people from buying it and re-purposing it due to subsidized components included.

Regarding the security clearance, while you are not technically wrong in theory, in practice things are heavily compartmentalized at an individual human level by "need to know" practices.

It kind of opened my eyes to how much a maze the IC is regarding classifications and data restrictions. We may both have TS clearances, but I may have access to wayyyy more crazy stuff than you do, based on what I am officially working on. However, on paper we may have the same levels of "trust" from the system's perspective.

After promising "no new taxes" during his campaign, he later agreed to do the fiscally responsible thing and raise taxes in order to offset spending increases.

That is an extremely charitable parsing of the events. The more accurate (realpolitik) version is Bush said the no new taxes quip, and Democrats subsequently laser-focused on making him (slightly) raise taxes, showing he is a "liar".

My take away is to learn not to promise overly optimistic outcomes when your political rivals have a significant stake in seeing you either be a success or a failure.

Edit: Not sure why this was flagged. Did not mean to come off as hostile or aggressive. Anyways, cheers.

I'm not purposely trying to be adversarial with you, but you listed 3 technology subreddits as examples, when my original comment was referencing non-technology subreddits.

To the point of bickering - that's human nature. I expect humans to argue over the shade of blue, sneakers of the month, or whatever. What I don't expect humans to do is regress mentally to some child-like viewpoint of erasing and censoring any opposing viewpoints.

Reddit is radically different than it was 10 years, and not in a healthy, engaging way. Browse some non-technology subreddits and you will quickly spot the echo-chamber effect and group think in action.

My grandfather was a WWII B-29 pilot. For a very long time he didn't talk in much detail about the horrors. It was only in his later years before he passed did he talk openly about some of the real nasty aspects. One time I asked him what the most unpleasant thing he experienced was during his time in the military. His answer was the stench of burning humans. When they started low level firebombing, his initial spot was the center-rear wave. So when he flew in to drop his stuff... the smell was horrendous.

I suspect he shared that with us younger folks to illustrate that war is not glamorous, even if you win. Yes they won, but it was a disgustingly ugly affair for all parties involved.

I'm glad he shared that, because I have a very healthy aversion to unnecessary conflict, in part due to a few stories shared by him.

Yeah, there's a lot of objects being rendered on screen. My GPU (3090 Ti) was running at about 41% while I was playing with the site. Amazing site, but definitely GPU intensive.

Agree completely with your concerns with regards to lost/stolen keys.

Most of the places where I've been able to use my Yubikeys (FIDO2) also offer a very clear list of enrolled/registered keys, along with either a hash or serial number of the key. It makes revoking a key pretty easy in my experience.

I'm less keen on the idea of centralized repo for dead keys - each key is unique to the site in question, so there will be no need to share the existence of that revoked key's identifer with other providers - the data is meaningless to anyone else.