HN user

jeeeeb

66 karma
Posts0
Comments21
View on HN
No posts found.

I cannot imagine it will ever happen but I'd like to see the spec precisely defined in terms of core "axiomatic" functionality (JS, layout engine, core CSS rules), and peripheral functionality built on the core functionality.

The core functionality would have a precise (as possible) and extensive definition with an agreed test suite encoding the expected behaviour (as much as possible).

This would allow development of a shared implementation of the peripheral layer, while browser innovation could continue on the core functionality (JS and rendering performance, battery usage etc), and on innovations in the UI.

In this pandemic, democratic nations are suffering more than authoritarian regimes purely by choice

South Korea, Taiwan, New Zealand, Australia, Finland, Norway and Malaysia all look to have handled the crisis very well. India is as well - as far as their figures are to be believed. We'll also find out if Japan's handling of the crisis has been effective in the coming weeks.

I'm not really seeing a pattern in democracies handling this badly. Meanwhile while the Chinese figures probably aren't completely made up, it's also extremely doubtful how reliable they are.

FWIW. My wife is Japanese and I lived in Japan through Fukushima as well.

A lot of people seem to think that Japan must somehow have a higher infection rate but I haven't seen any evidence that this is true.

For all the docileness of the mainstream media and the lame-duck politics it is a free and democratic society. The government couldn't hide a mass outbreak of corona virus anymore than it has been able to hide any other scandal. In fact almost certainly less given the levels of public interest.

The Ministry of Health and Welfare publishes updated statistics daily (https://www.mhlw.go.jp/stf/seisakunitsuite/bunya/0000164708_... -- in Japanese). looking at the current stats published there's not really any obvious problems. They're seeing about an 8% positive rate on corona virus tests and 1.8% of those with confirmed infections have died. This is well below the rates seen in Iran, Italy, America and China suggesting they've been relatively thorough in catching infections, although less so than South Korea.

In truth the Japanese healthcare system is probably the best in the world at providing population level care. Since long before Corona virus standards of hygiene have been very high. Masks and hand sanitizer bottles have been a common site for a long time, hand washing and gargling is heavily encouraged, and direct contact (hand shakes, hugs, back pats .etc.) is very restrained.

Whats more for all the criticism it copped the Japanese government has been pretty decisive in responding to corona virus. It's shut down schools. It's shut down public spaces (museums, libraries .etc.). It's discouraged crowds. It's encourage working from home. It's restricted travel from hot spots. It's isolated those with infections. Also most age homes seem to have gone into lock down weeks ago.

Facebook Is Dying 7 years ago

I imagine that even if Facebook goes the data will be bundled up and sold to third parties - a somewhat scary thought. Not that Facebook has been a good steward of the data so far but its hard to imagine vulturous third parties being better.

Facebook Is Dying 7 years ago

Without more context it seems hard to make conclusions from the data presented.

In terms of the raw figures both Daily Active Users and Monthly Active Users are up. However Monthly Active Users has increased at a faster rate than Daily Active Users, therefore user engagement which is defined as the ratio of daily active users to monthly active users has fallen.

Is this because existing users have reduced engagement with the platform, while Facebook continues to signup new users, or is it because the new users Facebook is signing up are not as engaged in the platform, or a combination of both?

For example maybe Facebook is 'hacking' its user growth figures by signing up marginal users at the cost of engagement.

Interesting anecdote about FastMail, I was previously C++ dev lead at a company with a large (1~2 mloc) legacy code base. Most of the C++ code was layers of mess but there was also a very well engineered core. One name consistently appeared in comments on these well engineered sections. Out of curiosity one day I decided to search LinkedIn and see if I could find the guy behind this shining light of engineering competence. Turns out he went on to found (/cofound -- not particularly sure of the details) Fastmail.

I find it very satisfying that a good engineer went on to succeed and would definitely trust the engineering competence of Fastmail.

Not to talk down the Dutch achievement too much but the quality of statistics used in this article is terrible.

Total monetary value of agricultural exports is a terrible way to measure output. It doesn't take into account: 1. Re-exports (Rotterdam is the largest port in Europe) 2. Specialisation in the production of certain goods (i.e. high imports and exports) 3. The high price of agricultural goods in Europe, driven by high trade barriers. 4. Low domestic consumption compared to more populous nations.

For a better analysis of the monetary value of Dutch agricultural exports see here: https://www.cbs.nl/en-gb/news/2018/03/dutch-agricultural-exp...

Note for example the 22.5 billion Euros in re-exports of agricultural goods.

90% reduction in water usage is also hard to judge without looking at changes in other advanced agricultural nations.

It would be more interesting to see the yields per-hectare the Dutch are achieving compared to other advanced agricultural nations.

Just to add to this, it is also a requirement to give consideration to the privacy expectations of the Australian community and the legitimate interests of the communications provider.

However, there is no guidelines on how these judgements should be made and what is / isn't acceptable. Effectively it will be left to the courts to decide through legal disputes.

I'm obviously not an expert on US law but I find it very hard to believe that it is legal for an employee of a US company, without the permission of that company to put up a fake login page for particular users and then provide that information to a foreign government.

Now if the TAN/TCN was issued to a US based company that would be a different issue but then you as an individual would not be in violation of it.

Not that that makes it a better law, but I think for people not physically in Australia the risk of being issued an enforceable (under Australian law) TAN/TCN is quite low.

As I said before: it is a defence for non-compliance if a TAN/TCN would compel you to commit a crime in a foreign country

That has nothing to do with whether you are an Australian citizen or not. If you are a resident in Austria, these laws do not allow the government to compel you to commit a crime in Austria.

I'd recommend reading the actual law, as passed by parliament. Knowing your rights and legal options under the law and based on that approaching your MP (if you are still registered to vote in Australia) with your concerns to encourage them to address them.

To do that you really need to know what the law actually says and requires. Here is a start: TCN/TAN are not limited to Australian citizens. Revoking your citizenship will not shield you from being issued a TCN/TAN, but will lessen the value of your voice in engineering change.

Realistically, I don't think the majority of the Australian community is particularly aware of, let alone opposed to this legislation. The idea that law enforcement should be able to gain access to encrypted communications if they have a warrant doesn't seem particularly controversial in the wider community either.

Given this, I'd assume the law is here to stay. The question we need to ask is how can we constructively engage politicians to minimise the flaws in the law. On that front Labor has been much more open and were instrumental in addressing some of the deeper flaws in the original legislation.

So to be clear:

1. The law specifically forbids the government requiring weakening of encryption / authentication / authorisation mechanisms.

2. The law specifically forbids the government requiring systemic vulnerabilities be introduced.

3. The law defines a consultation, review and appeal process.

4. The law prevents the government requiring someone commit a crime in a foreign jurisdiction

5. The law allows publishing the number of aggregate TAN/TCN/TAR received in aggregate in a 6 month period.

The question is where should the law be fixed and how do we engage Labor / Liberals to fix those aspects.

Personally I would like to see:

1. Better protection for software exported for use outside Australia

2. Better definition of what defines a 'systemic' vulnerability

3. Greater protection for individuals. For if a TCN/TAN could be otherwise issued to a company, then the law should not allow a notice to be issued to an individual.

I was worried about this as well which is why I read the law and commented above.

The short answer is: 1. Non-compliance with a TAN/TCN is a civil not a criminal mater 2. As I stated above the law clearly says that it is a defence for non-compliance if a TAN/TCN would compel you to commit a crime in a foreign country. The issue is whether you can be compelled to commit an act in Australia, which would be a crime in a foreign country. 3. Consideration must be given to your legitimate interests.

In short, if you get a TAN/TCN then seek legal advice.

I think that section 317ZH specifies that a TAN/TRN/TCN is invalid if a warrant would be required to access the information.

Specifically:

A technical assistance request that relates to an agency, or a technical assistance notice that relates to an agency, or a technical capability notice that relates to an agency, has no effect to the extent (if any) to which it would request or require a designated communications provider to do an act or thing for which the agency, or an officer of the agency, would be required to have or obtain a warrant or authorisation under any of the following laws:

                     (a)  the Telecommunications (Interception and Access) Act 1979 ;

                     (b)  the Surveillance Devices Act 2004 ;

                     (c)  the Crimes Act 1914 ;

                     (d)  the Australian Security Intelligence Organisation Act 1979 ;

                      (f)  a law of the Commonwealth (other than this Part) that is not covered by paragraph (a), (b), (c) or (d);

                     (g)  a law of a State or Territory.*

Personally I've been reading the text and trying to grasp the implications of this.

There appears to be two limitations on this power: 1. You cannot be compelled to do something in a foreign country that would be a crime in that country 2. In issuing the notice the relevant oversight authority must give weight to your 'legitimate' interests.

I think 1 is a huge point as it effectively constrains the jurisdiction of the law to Australia.

However, there is still significant ambiguity. For example, can I be compelled to commit a crime against a foreign country while in Australia, if I have a legitimate interest in not committing a crime against that country?

Would a company's legitimate interest in not compromising customer trust (more than the existence of this legislation doesn't already), act as a significant constraint on the issuing of TANs/TCNs?

There's also ambiguity as to whether I can reveal the existence of a TAN/TCN to my employer. The law makes certain exceptions, including the ability to publish the aggregate total of TAN/TCN received in a 6 month period and seek legal advice. So in order to seek legal advice or reasonably execute a TAN/TCN can I let my employer know?