HN user

jk700

53 karma
Posts0
Comments45
View on HN
No posts found.

We have lots of RCTs on mask wearing (mostly in healthcare professionals) and they struggle to find a benefit.

This is false. If you look around and read actual studies, not demand other people to do it for you and not cherry pick garbage studies, you'll find even real life "experiments" of healthcare workers in the US during COVID-19 not wearing masks with rapidly rising number of COVID-19 cases then mandated to wear masks with subsequent rapid drop of cases.

What you won't find though is studies supporting the assertion that sick person wearing a mask protects others, not the wearer. Those are the studies that show little to no benefit and always did actually. You protect others with a mask by not catching the virus yourself, it's a second order effect.

It is a common human tendency and the US is merely a vanguard of what will eventually be a global reality.

No, it's not. The US is the one pushing other countries to implement US-like copyright laws, as it has a huge music and television entertainment industry and exports entertainment and propaganda to other countries. For most countries if they implement everything the US wants it will only hurt them economically, as they would have to pay more for disproportionally imported entertainment, and politically, as with that much control more propaganda will come from the US and generally forcing people to pay more for something is unpopular. Probably the only countries where local entertainment industries can potentially increase profits from such copyright laws are the countries that have huge music and tv entertainment industries to begin with, i.e. huge countries with large middle class. But those are few.

Too bad, because there was no false information. Plenty of countries don't have not just anti-circumvention laws for copyright, but also DMCA-like laws and may even require you to obtain a court order before you can get something taken down. Except for a couple of countries, most countries could make it significantly harder to take down youtube-dl under such obviously false pretenses. Some countries are even particularly hostile and ignorant towards copyright-related demands from other countries.

As someone who uses youtube-dl for all the videos online, it's presence in any repos isn't as important as it may seem, because it breaks from time to time for some websites and you need to update it in order to keep using it, which is only easy if you keep it in your home directory so you can just run youtube-dl -U once it breaks.

Luckily they don't need to consider what some rich capitalist CEO thinks and don't need to return to MicrosoftHub and hopefully they won't. Especially given there are plenty of easy options available: self host gitlab outside of US, use something non-US, like gitea, etc.

But in case they do something that stupid, there will be forks. I will probably even make one fork myself with removed code reinstated.

EDIT: what the downvotes are for? Do you really want youtube-dl to appease Microsoft, RIAA or something?

Could you please stop with this ideological political activism? There is no inherent sexism in any language, ancient historical origin of the words isn't carried over to modern meaning, semantics of the words and doesn't create any bias against women or men. Meaning is created by mass media, people, world around you through propagandistic rhetorics. If you hang out with someone expressing "sexist" attitude or exposed to them through media, it really doesn't matter what words they use to call things they want to be for men or for women, you will still develop "sexist" associations, for example, you still won't consider babysitting a manly task, no matter how politically correct gender-neutral it is called.

So whether you can legally use WWW browsers is not the point at issue. It is whether youtube-dl is a tool that enables access to YouTube contents by circumventing a "cipher".

But by that logic if youtube-dl circumvents a "cipher", so does Chrome and all the WWW browsers. There is no legal difference between them, YouTube provides code to circumvent a "cipher" for such software itself.

That’s not so clear, but YouTube does obfuscate its code to make the task of tools like youtube-dl harder.

Not for tools like youtube-dl, but for tools that let user manually extract links, such as viewing the source code of the document. Because YouTube also provides an algorithm to deobfuscate it, which humans can't run in their heads, but tools, browsers can.

But in that wording they do allow downloading. Features of the Youtube service accessed thought the Chrome browser don't have to be exactly the same as accessed though other browsers and tools, other tools are not prohibited to provide features they can extract and interpret from the received source code and data, they are not obligated to run the code at all or as is.

you circumvented the technical copy protection mechanism (no matter how ridiculously trivial it was)

They can't do ridiculously trivial copy protection legally, depending on the country they might be required to do at least authentication and authorization with disabled access to the sources and maybe even hardware DRM garbage, which neither Google nor publishers want to do because it will significantly reduce ad views. Basically there is no copy protection mechanism at all in this case.

The fact that copyrighted works were included in the readme shows it was intended for that use

It's an alternative web browser for videos, of course it was intended for copyrighted works, just like Chrome is. I don't understand your argument, is creating alternative web browsers illegal in the US somehow?

No one can sincerely follow those rules, because they are too subjective. The only reason people tolerate them is because they are not enforced. But when you do enforce something from them, it's always unjust and unfair, like in this case.

When someone is routinely dropping lit matches in a dry forest, "he only started one wildfire" is obviously no defense.

He has lots and lots of comments of which only a couple that you didn't like. Absolutely nothing like "routinely dropping lit matches".

No, dang is purposely vague in all of his warnings, as if he wants to make sure people won't be able to follow them and it will be up to him to decide whether they did or didn't.

If somehow he slips and they manage to do it, he will rephrase them next time, make them more vague and more subjective to make sure they don't. Like I saw a warning he gave someone to stop creating new accounts every couple of comments, but then in other warnings he stretched his definition farther and farther to include more comments and more time.

I've spent 1% of my remaining life under lockdown so far, and expect to spend an approximately equal amount before a vaccine. At what point is it not worth it?

If you understand that vaccine won't solve anything, i.e. it'll be less effective and more dangerous than the crappiest mask. Then it's pretty easy to just accept that you have to wear a mask around people for a long time, the rest of your life if you prefer, and live a normal life. We had lockdown only for two months in april and may, after that it's back to normal, but in masks.

Except maybe for current comment (not really, HN just has more replies on anything these days), nothing actually turned into flamewars, most out of his few "flamewar" comments over many months barely had any replies at all and were just flagged. It seems you are labeling them as flamewar just so you could justify banning him. Possibly because he expressed opinions you consider "politically incorrect" today and you want to suppress such opinions on HN.

Also you can't claim he ignored your many requests to stop, because you never made a single request to stop what can be interpreted the same way by both of you, he probably thought he followed them. Again, you were using this as manufactured justification to ban him.

But if an attacker can intercept domain validation to issue a certificate, there is little reason not to protect his own certificate from revocation by preventing subsequent validations until it is used on a target, if he can't hide this fact in some way of course. A report of that will look like someone is trying to revoke a certificate for a domain they don't control and won't actually solve the problem even if a human can be convinced by other method that you do control the domain.

Maybe DNSSEC could be used here to help if ACME added a way to force DNSSEC-only domain validation.

It doesn't. Pretty much no one monitors CT logs and for those who do there is no way to prove misissuance of domain-validated certificate and revoke it, they don't have private keys.

That's the thing, they don't seem to bother actually addressing the problem and assume no other interception capability than hacking BGP. But we are talking here about exactly that, i.e. if you can intercept traffic in any other way somewhere close to a website or its nameservers - you can get a valid certificate and use it to MITM its visitors anywhere in the world where you can intercept traffic too. And in case of using big cloud providers for validation to "improve" security, this still likely pushes traffic from all of them through some big IX before reaching a datacenter with a website and at worst only adds a couple more points an attacker has to intercept traffic at to get the certificate.

This is where all that centralization is really bad for security. It basically makes https a protection only against low effort MITM of last mile ISPs.

MITM like that still works for most https websites because of the automatic domain validation by ACME-based certificate authorities. The only caveat is that now an attacker has to get a valid certificate, so first he has to do MITM on the route from the datacenters where CAs run validators to the datacenter where the website is hosted, which for most websites today is likely a long route crossing many countries, after that an attacker gets the exact capabilities as with MITMing http.

Maybe. Although switching wifi router into something like 802.11b-only or a-only mode and selecting a fixed least busy channel might be a better long term solution, as USB3 isn't the only source of EMI.

Bad hardware compliance is only part of the problem. With higher speeds all the user facing stuff, like cables, connectors, power without noise - all start to matter too. You know how 100 mbit ethernet works well even with crappy connectors and crappy wires, you literally don't need even a twisted pair for it, but pushing gigabit ethernet over that doesn't work reliably anymore or even at all. It's very much a universal problem with higher speeds. And the notion that "you can make any speed reliable and fool proof" is just absurd denying physics.

A typical FTTB ISP providing services to people living in apartment buildings isn't doing a "carrier ethernet", I guess it's more like a datacenter. It just has a media converter connected to a switch or these days a switch with an SFP port per building and from there it's all regular copper and RJ45. In the end of 90s and early 2000s ISPs haven't yet figured out how to do it properly, how to isolate and authenticate customers, at the time there were plenty of hubs and dumb switches with plenty of sniffing going on, plenty of vulnerabilities in switches, a single customer was able to cause problems for the whole network.

Privacy became a reason when ISPs started providing internet access over Ethernet. As hubs and unmanaged switches are vulnerable to sniffing, ISPs had to either give everyone separate VLANs or use managed switches with protections from sniffing.

It can't possibly be economically competitive if it is driving a steam turbine

What do you mean by "economic competition"? Generally speaking with current technology there is no power cheaper than nuclear power. In that sense it is the most competitive power there is.

But not for private investment funds looking to own power generation and secure huge returns in relatively short term. They'd rather see more expensive inferior dirtier climate-changing power generation they can profit from, not government owned nuclear they can't ever compete with. And in that sense no project with long term investments in science, education, infrastructure will ever be competitive for capitalists. So does it really matter then?

Luckily not everyone is fond of capitalists. Ukraine, for example, recently decided to go against certain capitalist run countries pushing it to limit nuclear and finish building new reactors, because other power is not actually economically competitive. If Ukraine can, surely most of the world can do it too.

Right, it's even more complicated. Such breakers also don't trigger at specified current exactly. They have two breakers inside of them, one for overload protection triggering once it heats up, could be an hour for 2x current if starts cold, and one for short circuit protection triggering in less than a second, but on 3x+, 5x+ currents, etc. So a 15A breaker, a 15A outlet and a cable for 15A all could easily see 30A of current for some periods of time and heat up.