HN user

johnmarcus

174 karma
Posts4
Comments305
View on HN

when i download the release, chrome gives me a nasty releasxe that Teapodo...zip is not commonly downloaded and may be dangerous.

It may be, may not be. Either way, I'm not opening on my work mac. Do you have a release for Linux, since it's written in rust?

Also, I think if you make it a .app with a developer license from apple, the creepy message goes away.

I love how they say "We used to do X on some non-Google sight, it was so fun; but I can't do that on Google - so GoOgLe hAs FaIlEd anD iS BaD."

Why not just use another site, that you know, isn't Google? Like they suggested, you can search Reddit, or you can search Tumbler, or you can find a Facebook group, or where we found this article: Hacker news.

I miss the yesteryear when people didn't expect Google to somehow be the answer to everything on the web. Here's an idea: your fan sights can co-exist as well as Google.

And the irony is, the authors own blog home page uses a dark pattern to try and convince you to subscribe to their newsletter! Talk about ruining the web for commercial purposes!

Web 3 is Flawed 4 years ago

What do you mean he didn't give examples? Just throw a dart at any web3 project, and there is your example.

Web 3 is Flawed 4 years ago

Skiff.org charges $8 USD/month for it's premium service, and it's just an implementation of PGP encryption. I have no idea what this as to do with crypto.

ens.domains is a privately owned and managed DNS provider. It's litterally the exact opposite of what web3 claims to be. Having a "constitution" is just re-wording "Terms of Service". I love how it sells hard covers versions of it's Terms of Service for fiat at Blurb.com. And no, Blurb does not accept cryptocurrency payments even, lol.

Signal.org existed well before they added crypto, and quite frankly, yes I did just about completely stop using it - and so did many others. The introduction of cryptocurrency in that app litterally chased away users rather than improve adoption.

Gawd, could go on forever here.

Web 3 is Flawed 4 years ago

Ok, I looked. And now I will tell you with great ease.....it is not of a "real productive use".

I'm litterally about to jump from 8 to 17 this week, so that's good to hear. It seemed seamless on my local setup and was wondering if it was just too good to be true. It's a great piece of software.

You are correct about the documentation. I find the tragedy of open source documentation is that the people who need it most - the novices - are the ones whom could write it best - if they only knew if what they were saying was accurate. And then by the time you become an old-timer, and know thy ways, you just want to wipe your hands and walk away, because your tired....and still not sure if all your knowledge is accurate.

But anyway, once it's all figured out, it runs very reliably.

No, there are blatantly obvious things about packaging software that you are missing.

- you will need a copy of each platform running in order to build the binary - it's X-times++ as much work to package for X number of platforms. - The code you chose might not compile well on all platforms without code changes. - Dependency conflicts can be a pain.

oh boy, i could go on.

You want to collect usage data from my terminal? I'ma nope right outta there.

And I don't want to tie my github to this thing, i have all sorts of github accounts for legitimate reasons.

I would be glad pay a lifetime licence fee (maybe with a 30 day money back guarantee?) to check it out, but no way am i going to do a subscription model for my terminal.

The CEO backs them up. lulz. More likely, the CEO says "as long is it doesn't get in the way of our quarterly sales goals, then i really don't give a sh#* and you can do whatever you want."

But sure, we can all dream.

I wish the effect smoking has on the heart was advertised more.

People are terrified of cancer and that's all they think about with smoking, but actually far more people die from heart and stroke related illness after smoking than from cancer. I don't know the exact number, but it's a multitude.

once it becomes a $1000 product, the number you can sell dramatically decreases. Hence, these existing products that do this are $10,000 and up.

The price has little to do with the R&D and manufacturing cost, it really has to do with how small the market is. Once you have a customer that is willing to pay $1,000 for this novelty, they will likely also pay $10k for the novelty.

Also....I seriously doubt artificially extending daylight hours is good for anyones health.

The data is read by more than one person, so this likely wouldn't work.

Also, I'm not sure this is an actual breach. I think they accidentally published the data themselves, that's the vibe I'm getting from reading between the lines. It's like the code maybe missed checking a flag that would exclude private records from showing.

Ngrok Alternatives 4 years ago

i'll need to open a pull request for [tolocal](https://github.com/nelsonenzo/tolocal) :). It's clunky because it requires node and terraform and AWS, but all your stuff is self hosted and can be e2e encrypted, costs almost nothing, can be used with real domain names, etc. I would like to make it all JS at some point (the actual terraform is minimal), but it's hard to see why when Cloudflare Tunnel is a thing now.

What i love most about this is that if these clowns didn't stupidly store their keys in a decrypt-able file in cloud storage, then ~.01% of BTC could have been lost forever.

We are just 10,000 hacks away from bitcoin being gone forever! A boy can dream.

the file was encrypted, but the fbi hacked it after already having gained access to the account (via warrent).

Which is to say, this isn't how they actually got cought, it's just how the nail will go in the coffin (and thankfully for those impacted, some funds recovered).

FWIW, if you ever find yourself in this position of owning a large amount of stolen crypto, I believe the best way to wash it would be to "robin hood it out" to a bunch of random wallets. You just happen to own 10-20% of the wallets, but the feds now have to try and track thousands of different people over years to try and identify the true thief, and there will always be plausible deniability.

I keep my old phones as backup for either myself, or that poor soul you come across whom just smashed their screen and do not have money for a new one.

Or sometimes I just keep it in my car as a an emergency phone / for pandora / for maps. It almost never goes to waste that way.

are we pretending that they didn't say that exclusively in hopes the deal would go through?

They will turn around that statement on a dime and not a single investor will blink with "...but you said to the regulators...". No risk in making such a silly statement.

They probably will get a change of leadership though. Often they chose the best-man-for-the-merger, and when it doesn't work out, they then actually search for the best-person-for-the-job.

aaaalllllllll the way down at the bottom is this gem: >Some core Roblox services are using Consul’s KV store directly as a convenient place to store data, even though we have other storage systems that are likely more appropriate.

Yeah, don't use consul as redis, they are not the same.

Yup, so true. People think redundant == 100% uptime, or that when they advertise 99.9% uptime, it's the same thing as 100% minus a tiny bit for "glitches".

It's not. .1% of 36524 = 87.6 hours of downtime - that's over 3 days of complete downtime every year!

For a more complete list of their SLA's for every service: https://aws.amazon.com/legal/service-level-agreements/?aws-s...

They only refund 100% when they fall below 95% of availability! 95-99= 30%. I believe the real target is above 99.9% though, as that results in 0 refund to the customer. What that means is, 3 days of downtime is acceptable!

Alternatively, you can return to your own datacenter and find out first hand that it's not particularly as easy to deliver that as you may think. You too will have power outages, network provider disruptions, and the occasional "oh shit, did someone just kick that power cord out?" or complete disk array meltdowns.

Anywho, they have a lot more room in their published SLA's than you think.

Edit: as someone correctly pointed out i did a typo in my math. it is only ~9 hours of aloted downtime. Keeping in mind that this is per service though - meaning each service can have a different 9 hours of downtime before they need to pay out 10% of that one service. I still stand by my statement thier SLA's have a lot of wiggle room that people should take more seriously.

A Microsoft product with blatant and egregious security holes? How could anyone have ever known?

It's a good thing these guys were late to the cloud. I shutter how lousy my life would be as a sysadmin if I was forced on-prem because of how untrustworthy the reputation of cloud computing would have been.