HN user

jasode

34,669 karma
Posts0
Comments4,073
View on HN
No posts found.

This is much, much simpler than you think it is. Passkeys are just passwords that require a password manager.

The issue isn't what passkeys _are_ (e.g. explaining they are like public/private "ssh keys" and hoping that type of explanation ends the confusion).

Instead, it's the workflow around passkeys. The websites show very confusing dialog popups and choices that a lot of normal people will not understand. This is a good article with screenshots showing the confusion: https://arstechnica.com/security/2024/12/passkey-technology-...

I have senior citizens asking me about passkeys because their bank and medical websites keep reminding them about switching to passkeys every time they login into their accounts. My recommendation to them is not to do it unless they have a simplistic single vendor setup such as only Apple iPhone and MacBook with iCloud Passwords app. If instead they have a mixed Windows + Apple setup with 3rd-party password manager, they could accidentally put a new passkey into the os or browser instead of their external password manager and not realize what has happened. This happens because the different parties implementing passkeys all have different agendas that suits their interests and that's what makes the workflow confusing for normal people.

Literally who cares what language a JS toolset is written in?

Maybe you're being coy by asking a rhetorical question you already know the answer to but I'll answer as if you asked sincerely...

There are 2 different groups interacting with software products:

(1) end-users : this is where the "Who cares what language it's written in?!?" is usually applicable. E.g. The finance guys using MS Excel don't care whether it's written in assembly, BASIC, or C Language.

(2) code contributors and/or programming language enthusiasts who see other projects as "validation" of the whatever language they've invested in: these people definitely care.

For all the decades that computer languages have been debated, Group (2) will always discuss projects language choices. E.g. reddit.com switching from Lisp to Python, the Linux kernel fiercely debating future Rust contributions , the Typescript compiler switching from Javascript to Go, Bun switching from Zig to Rust, etc.

People try to lecture others in Group 2 about "don't make a programming language your identity" ... but people are human and they can't look at all the above language choices as totally detached observers. They like to talk about it!

If one is a Zig coder that contributed to the previous Bun Zig codebase, we can't expect them to be neutral observers.

assembly driver

Way too easy to strip out the threads.

An "assembly driver" or "installation driver" is meant to describe low-torque powered screwdrivers. They don't strip threads especially when used on the lowest torque settings that can barely turn a screw before the clutch-release mechanism clicks. On the other hand, the high-torque powered screwdrivers that can turn drywall and deck screws and the impact drivers that can spin the lugs on car wheels are a different beast.

The bigger risk with IKEA furniture is hammering in the metal dowel pins (that interlock with the rotating cams) at a perpendicular angle to the flat board. You have to gently tap them with a hammer because it's too easy to puncture through the particle board.

Actually, the majority of "screws" to turn in a lot of IKEA furniture (e.g. bookshelves) are the cams instead of typical threaded screws. The cams only rotate 180 degrees so there's no time savings in trying to use a powered screwdriver.

Does Apple actually have a winnable case

Based on the previous thread, Apple seems to have damning evidence of wrongdoing by the (ex)employees before-and-after they left their positions at Apple: https://news.ycombinator.com/item?id=48865019

Seems very similar to Google/Waymo winning its case against Uber (ex-Googler Anthony Levandowski) stealing corporate data.

Apple has the employees' emails history, the server access logs, etc. Really don't see Apple pursuing this unless they had a mountain of evidence against them.

Of the 1980s 8-bit computing era, the Commodore 64 was the "best value" for getting a lot of functionality for the price. It had 64k of RAM when some others only had 16k. It had a really good built-in sound chip with polyphonic sounds (makes it richer sounding for programming video games music and sound effects). Some other computers had cheaper chips with monophonic sound which makes simplistic beeps and tones. It outsold all the other computers like Apple II, Atari 400/800, Texas Instruments TI-99, etc. This meant it had a big ecosystem of 3rd-party add-ons.

The article talks about COMPUTE! magazine. They often had free games where they listed the source code in the magazine pages. The reader would then manually type in the code by hand into the computer and save it to floppy or tape drive. The magazine would have the same game ported to different computers so there would be separate source code listings for Commodore, Atari, etc. The Commodore 64 versions of the game would always end up being the best version to run because of the hardware advantages mentioned above.

https://www.google.com/search?q=compute%21+magazine+program+...

More pertinently "the term is purely descriptive and therefore lacks the distinctiveness required for trademark protection."

As I wrote in my other comment, "open systems" also can be purely descriptive and yet Open Systems seems to be a valid trademark in Europe.

I'm not defending OpenAI. I'm just confused that the rules for allowing trademarks for ordinary words and phrases don't look consistent at the surface level.

Open AI has an independent descriptive meaning as composite term.

See my edit. "Open Systems" also had an independent descriptive meaning. The phrase "open systems" was a very common generic phrase in 1990s when companies talking about POSIX compliance was a big deal. (E.g. Microsoft touted POSIX in Windows NT.)

The story about the ruling really doesn't explain why another company called OpenText that's been around since 1991 and has a valid trademark registration in EU but OpenAI would be invalid. OpenText also has its Europe headquarters in Germany: https://www.opentext.com/about/office-locations

Any legal guesses as to why those 2 companies are treated differently with regards to the very generic words : "open", "text", "AI" ?

EDIT add another example is Open Systems that has a office in Switzerland. https://www.open-systems.com/

The trademark registrations search results: https://www.tmdn.org/tmview/#/tmview/results?page=1&pageSize...

We can assume the OpenAI lawyers brought up these and other similar examples and the court rejected the past examples as a valid argument.

Iroh 1.0 1 month ago

I don't understand why HN seems so concerned about nailing down its "value proposition".

You're getting sidetracked because of the particular phrase "value proposition" but a lot of people just use it as a stock meme to simply understand something even without any commercial product perspective.

You can read through this entire thread where people are having a hard time wrapping their head around what _it_ _is_ because the blog article doesn't explain it well.

The following various stock phrases use different words but are basically asking the same thing:

- "This is the solution to what problem?"

- "How's this different from Tailscale/Wireguard/QUIC/etc?"

- "What is the raison d'être ?"

- "ELI5?"

- "What's the value proposition?"

- "Why should I care about this?"

- "What's the use case for this?"

- "What's the motivation / rationale for this?"

- "What does this do?"

And then different commenters try different explanations and hopefully one will finally click for readers.

Running Windows 10 Enterprise IoT LTSC [...] have yet to encounter any issues.

It depends on the type of software a user runs. I installed Windows 10 LTSC on a friend's computer last year thinking she could run it for at least 5 more years and just ignore the newer Windows 11/12/whatever.

But she needed Intuit TurboTax 2025 and it requires Windows 11 and it's a hard requirement. The installer aborts on Windows 10. It's not a soft requirement like Adobe where they only support Windows 11 but their installer still runs on Windows 10. Autodesk Fusion 360 is another example that requires Windows 11.

I'm guessing if there's a future Windows 12, Intuit TurboTax will be aggressive about making it a requirement that forces the issue even though nobody wants to upgrade to it.

pg is or was the owner of a very influential venture capital fund, that created projects such as Uber

Uber was not a YCombinator company. For some unexplained reason, many mistakenly think it was a YC startup but it's not correct.

(The gp's comment is an example of how chatbots hallucinate because they train on the text of people unintentionally hallucinating.)

The gp isn't talking about spam using "secure message" as bait to open unwanted email.

Instead, legitimate companies like banks, healthcare, etc tell users to click on a url link to their "Secure Message Center" to read or submit some critical information. It's often the only way to get the info the users need.

E.g. if I open a payment dispute with the bank, the workflow they use is the Secure Message area. I can't just use my normal email client and upload some pdf attachments. Instead, I have to log into my bank website, navigate to their Secure Message area, and then upload the docs there to submit the claim. They also don't send followup status or final resolution in an email. Instead, you log back into the Secure Message area to read the case resolution. Similar for insurance claims.

Similar situation for asking a medical imaging center for some mammograms. They will not send those as PDF or JPG attachments directly to your email address. Instead, you log into a secure message area on a healthcare website and download it from there.

With all the hate Ticketmaster has gotten [...], I'm surprised Ticketmaster still has a hold of pretty much the entire market. How are they doing this?

This question is a common mystery because you're using the perspective of the fans. E.g. "I hate Tickemaster ridiculous fees because it's price gouging, etc"

But the mystery of Ticketmaster being dominant is solved once you understand it from the perspective of the venues, promoters, and the artists. They are the true customers of Ticketaster. Ticketmaster's various "convenience fees, surcharges, etc" are just creative financial tricks to funnel more money back to venues+promoters+artists but still keep the ticket's face price artificially lower.

The alternative arrangement would be the ticket's face price being much higher to reflect the "true market price" but that means the artists would be the ones perceived as price gouging. Instead, just charge the higher price via convenience fees and let Ticketmaster take the public relations hit. The psychological manipulation of fans is working exactly as designed.

When the fans wish that there was another true competitor to Ticketmaster, what they're saying is they want "a service that charges less money". But that idea conflicts with the venues/promoters/artists that want to charge more money.

Therefore, if you really want to disrupt Ticketmaster, you need to charge even higher fees and more expensive ticket prices so that the greedy venues & artists will get more money from you and thus choose your service over Ticketmaster. I don't think that's the type of competitive disruption fans have in mind.

And the common cited reasons of vertical integration of LiveNation and owning the venues doesn't explain Ticketmaster's advantage. They were already dominant in the 1980s and 1990s before LiveNation acquired venues. Taylor Swift's tour promotor was AEG (not LiveNation) and she played at many stadiums owned by the cities (not owned by LiveNation) and she still chose Ticketmaster to be the selling agent for those locations. One of the reasons is she negotiated 110% of ticket's face price from Ticketmaster. How is extracting that type of money even mathematically even possible?!? The add-on "convenience fees".

Also see: https://en.wikipedia.org/wiki/Drip_pricing

We need to establish measures of accountability for data holders. Not securing customer data appropriately needs to be persecutable, and the affected parties need to be given a right for compensation.

The ultimate entity that could hold businesses accountable is the government but the government itself is careless with citizens' private data.

I underwent a government required background check to get a security clearance and my data was stolen: https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...

My "compensation" for my data being leaked was 1 year of free credit monitoring. But obviously, criminals interested in identity theft will continue their attacks after 1 year.

As far as persecution/prosecution, I suppose Katherine Archuleta, the director of OPM, and the CIO, Donna Seymour ... could have been put in prison as punishment instead of just resigning. I don't think that would change anything. There will still be future scenarios where governments want more collection of private data. Flock cameras, TSA airport scans, internet access age-verification face scans, etc.

, SQL teaches you [...] Without any wrapper masking low-level logic.

I understand the point you're trying to make, and yes, it does seem like SQL is "low-level" from the perspective a wrapper like ORMs or a GUI db browser tool with menus for filtering data.

But it's also worth remembering that SQL itself is a high-level wrapper that hides the lower-level C/C++ code of the db engine that has the loops that iterate through b-trees, 8k data pages, memory blocks of the buffer cache, etc.

And C/C++ itself is a high-level wrapper that hides the logic in lower-level Linux o/s system calls that manages RAM and disk i/o.

And Linux itself is a high-level wrapper that hides low-level device drivers like SATA/SSD memory-mapped IO ... and so on and so on.

Depending on the type of app, you can ignore all the lower levels and just work at the abstraction level of higher-level wrappers.

Raymond Chen of Microsoft explained why they go through the effort of coding a lot of special-case compatibility shims for other's misbehaving apps. It's to remove obstacles that prevent customers from upgrading Windows.

(The urls from microsoft.com load very slowly for some reason so may have to use Wayback Machine instead.)

https://devblogs.microsoft.com/oldnewthing/20050824-11/?p=34...

https://devblogs.microsoft.com/oldnewthing/20031224-00/?p=41...

https://web.archive.org/web/20190315130516/https://devblogs....

https://web.archive.org/web/20190315121601/https://devblogs....

3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse

There seems to be a misunderstanding of how typical cloud password vaults work. The 3rd parties like Bitwarden, 1Password, Apple iCloud Keychain, etc don't have access to the users' passwords. The scheme is based on Zero-Knowledge End-2-End-Encryption. The 3rd-party cloud is just a mechanism to store an encrypted blob and sync them to various devices. The client devices (users' desktop, users' smartphone) are the only ones that can decrypt the passwords. There are still only 2 parties with knowledge of the actual passwords.

In contrast, the type of 3rd parties that do have knowledge/access to unencrypted plain text passwords would be Amazon storing users' wi-fi passwords, and Plaid storing users' bank account credentials & passwords. Gmail and MS Outlook.com would also be a 3rd party having a copy of users' passwords when they act as web clients to fetch email from other IMAP servers.

, my dad and his printed out sheet of password next to his desk is still beating every company out there.

That doesn't work for users when they're not sitting at their desk and need passwords. Printing out a hardcopy sheet of passwords and carrying it the wallet or purse is a massive security risk.

macOS/iOS Safari and Brave browsers have "Reader mode" . Chrome has a "Reading mode" but it's more cumbersome to use because it's buried in a side menu.

For desktop browsers, I also have a bookmarklet on the bookmarks bar with the following Javascript:

  javascript: document.querySelectorAll('p, td, tr, ul, ol').forEach(elem =>  {elem.style.color = '#000'})
It doesn't darken the text on every webpage but it does work on this thread's article. (The Javascript code can probably be enhanced with more HTML heuristics to work on more webpages.)

"democratization" doesn't mean more people have access to it.

I just don't like it and think it is relatively new usage and a change in the older meaning of the word.

People have been using "democratize" to describe "more accessible to the masses" for a long time. Here's an example from 106 years ago in 1920 :

https://www.google.com/books/edition/Soviet_Russia/qflaAAAAM...

And 40 years ago a 1986 article of "microchip democratizing computing" : https://www.google.com/books/edition/Procom_s_1986_1987_Dent...

The additional meanings of democratize to describe "more accessible" are also documented in Oxford and Merriam-Webster dictionaries:

https://www.encyclopedia.com/humanities/dictionaries-thesaur...

https://www.merriam-webster.com/dictionary/democratic#:~:tex...

Just use the Ask button on YouTube videos to summarize,

For anyone confused because they don't see the "Ask" button between the Share and Bookmark buttons...

It looks like you have to be signed-in to Youtube to see it. I always browse Youtube in incognito mode so I never saw the Ask button.

Another source of confusion is that some channels may not have it or some other unexplained reason: https://old.reddit.com/r/youtube/comments/1qaudqd/youtube_as...

The rule is: If the bank, or paypal, or your landlord, or anyone else really emails you that you have to complete some information to your account or pay the latest bill or whatever, you GO TO THEIR WEBSITE and login normally.

Yes, that is a "best practice" and good internet hygiene is to never click on email and text message urls but the reason they like clicking on legitimate email urls is convenience and usability. A helpful email link directly lands them on the relevant website page to do whatever they need to do. That's because the email url has a long string query parameters (id, etc) that automatically navigates to the correct webpage.

On the other hand, to do it the "best practice" way, it requires clicking around a confusing website menus and drilling several layers deep to find whatever issue the email is talking about.

A helpful email url link bypasses the hassle of learning whatever flavor-of-the-month confusing UI the website designer happened to to use.

Hang around old people and watch over the shoulder how they use computers and you become sympathetic to how the make it work for them.

E.g. An order status email has a URL link of a UPS tracking number to monitor shipping status. But don't click on that! Instead, copy the 1Z... number to the buffer. Then open a web browser and type in the ups.com url. Then paste the number into the text box. Those copy&paste mechanics not too difficult on desktop (Ctrl+C Ctrl-V) but it is much more difficult on mobile phones (double taps or long press and hold).

That was a simple example. The more complicated one is email from health and medical companies with confusing websites. They'd rather just click on the email url.

When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else.

That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls.

  https://getsupport.apple.com/customer?cvid=8c11bcc71f684b6ab405d4fa1e86c146
  https://getsupport.apple.com.phish.xyz/customer?cvid=8c11bcc71f684b6ab405d4fa1e86c146
People just pattern match on the substring "apple.com" because they don't understand that the DNS system works right-to-left. Therefore, the 2nd url looks just as "legitimate" as the first one.

I work with senior citizens and tried to explain how to parse the domain in the URL by looking for the first forward "/" after the "https://" and then scan backwards but they find that mental algorithm confusing and those instructions don't stick. (This is actually an area where some AI on phones/desktops could assist people decipher urls or mark them as suspicious.)

The other problem with that advice is people can't "whitelist" the legitimate domains to look for because they don't know ahead-of-time what they are. E.g.:

- An Amazon verification email will be sent from "account-update@amazon.com". It's intuitive to predict something coming from "@amazon.com" so a mental whitelist filter works in that case.

- However, State Farm Insurance legitimate login verification codes are actually sent from "noreply@sfauthentication.com" instead of the expected "@statefarm.com"

Flighty Airports 4 months ago

Why does everything have to make money? People like to built things as a hobby.

The gp asked a reasonable question. Your admonition about making money is misplaced because your assumption about it being a hobby is incorrect.

The website was developed by Flighty LLC. To answer the gp's question: Although the website itself doesn't have direct monetization, it acts as "inbound marketing" for the paid iOS app. Clicking on "Download Flighty" takes the user to the Apple App Store:

  In-App Purchases
  Week-to-Week Flighty Pro         $4.99
  Annual Savings Flighty Pro      $59.99
  Month-to-Month Flighty Pro       $9.99
  Annual Savings (Family Plan)   $119.00
  Lifetime Flighty Pro           $299.00
  Flexible Monthly (Family Plan)  $15.99
  Week-to-Week Flighty Pro         $4.99
  Week-to-Week Flighty Pro         $7.99
  Pro Family Lifetime            $449.00
  Annual Savings Flighty Pro      $59.99
The website's hyperlink url to the App Store page also has a tracking id so the company can attribute downloads/sales back to the webpage. This lets them see how well the "free website" is converting to paid customers. As a vehicle to generate sales leads, it seems to work very well. To wit... Wikipedia says the company has been in business for 7 years and it's been upvoted to the HN front page and we're discussing it. (The Flighty website is an example of the old saying, "The best advertising is free advertising.")

It's not just a $5/month VPS. Some cursory googling says Flighty gets data from the FlightAware Firehose api which costs a lot of money. The cost would exceed the financial resources of most people to make an equivalent free hobby website. (https://www.flightaware.com/commercial/firehose/documentatio...)

mpv to achieve a similar effect? Not sure if you can cover a specific part of the image but you sure can crop the video

mpv doesn't run on iPad so it's better for my situation to just burn the blackout into a new video. I actually do a lot more stuff than drawvg (also rescale, pts, framerate,etc) in filter_complex but left the rest of it out for the HN comment so the example is more readable.

I suppose it might be possible to use mpv with a custom shader mask glsl code to blackout circular areas of the screen.

you sure can crop the video

Cropping the video is straightforward with no information loss when the geometry of presentation and the speaker is laid out like these: https://www.youtube.com/@MeetingCPP/videos

But cropping the following video by shrinking the boundaries of the rectangle until the circle overlay is not visible would result in too much of the text being cut off: https://www.youtube.com/watch?v=nUxuCoqJzlA

Scrub that video timeline to see the information that would be chopped off. For that, it's better to cover up only the circle overlay with a blacked out disc.

drawvg is very useful. Before drawvg, I was always fine using the stable FFmpeg releases such as 8.0.1 but when I saw drawvg added to the master branch[1], I didn't want to wait for the next stable release and immediately re-built ffmpeg from master to start using it.

My main use case is modifying youtube videos of tech tutorials where the speaker overlays a video of themselves in a corner of the video. drawvg is used to blackout that area of the video. I'm sure some viewers like having a visible talking head shown on the same screen as the code but I find the constant motion of someone's lips moving and eyes blinking in my peripheral vision extremely distracting. Our vision is very tuned into paying attention to faces so the brain constantly fighting that urge so it can concentrate on the code. (A low-tech solution is to just put a yellow sticky know on the monitor to cover up the speaker but that means you can't easily resize/move the window playing the video ... so ffmpeg to the rescue.)

If the overlay was a rectangle, you can use the older drawbox filter and don't need drawvg. However, some content creaters use circles and that's where drawvg works better. Instead of creating a separate .vgs file, I just use the inline syntax like this:

  ffmpeg -i input.webm -filter_complex "[0:v]drawvg='circle 3388 1670 400 setcolor black fill'[v2];[0:a]atempo=1.5[a2]" -map "[v2]" -map "[a2]" output.mp4
That puts a black filled circle on the bottom right corner of a 4k vid to cover up the speaker. Different vids from different creators will require different x,y,radius coordinates.

(The author of the drawvg code in the git log appears to be the same as the author of this thread's article.)

[1] https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/016d767c8e9d...