HN user

jonchang

2,188 karma

https://jonathanchang.org

Posts46
Comments207
View on HN
attackanddefense.dev 7mo ago

Attempting Cross Translation Unit Taint Analysis for Firefox

jonchang
1pts0
www.ntsb.gov 9mo ago

Hull Failure and Implosion of Submersible Titan

jonchang
5pts0
jalopnik.com 4y ago

What I Mean When I Say 'Ban Cars'

jonchang
2pts0
www.sfgate.com 4y ago

'Buy now, pay later' is sending the TikTok generation spiraling into debt

jonchang
33pts45
blog.mozilla.org 5y ago

Privacy Analysis of FLoC

jonchang
288pts164
www.matuzo.at 5y ago

Accessible to Some

jonchang
2pts1
www.facebook.com 8y ago

Certificate Transparency Update for Developers

jonchang
1pts0
robert.ocallahan.org 8y ago

Maintaining an Independent Browser Is Expensive

jonchang
441pts300
rachelbythebay.com 10y ago

HTTP/HTTPS not working inside your VM? Wait for it

jonchang
364pts78
www.scotusblog.com 10y ago

Apple loses case on its e-book selling tactics

jonchang
2pts0
www.wired.com 10y ago

A Long, Bizarre Scientific Feud

jonchang
5pts0
sethgodin.typepad.com 10y ago

Empathy

jonchang
1pts0
www.wired.com 10y ago

Pilots Who Fly Drones into Wildfires Are Idiots. Punish Them

jonchang
4pts0
rachelbythebay.com 11y ago

Filter all ICMP and watch the world burn

jonchang
292pts57
www.latimes.com 11y ago

USC MFA class of 2016 withdraws in protest

jonchang
4pts0
www.slate.com 11y ago

Forbidden Data: Wyoming just criminalized citizen science

jonchang
13pts1
benjaminkerensa.com 11y ago

Google trying to win Firefox users back

jonchang
6pts3
www.marcozehe.de 11y ago

Social networks and accessibility: A not so sad picture

jonchang
1pts0
www.theatlantic.com 11y ago

Clocks Are Too Precise

jonchang
6pts3
blogs.msdn.com 11y ago

How did that program manage to pin itself to my taskbar when I installed it?

jonchang
31pts15
arstechnica.com 11y ago

T-Mobile to offer LTE over 5GHz Wi-Fi airwaves to boost data rates

jonchang
3pts0
blog.mozilla.org 11y ago

Getting Tiles Data from Firefox

jonchang
4pts0
blogs.msdn.com 11y ago

Counting array elements which are below a particular limit value using SSE

jonchang
5pts0
www.facebook.com 11y ago

Helping You Understand How Facebook Works and How to Control Your Information

jonchang
10pts0
www.latimes.com 11y ago

AT&T to refund $80M in settlement of mobile cramming case

jonchang
1pts0
monica-at-mozilla.blogspot.com 11y ago

Firefox 32 Supports Public Key Pinning

jonchang
188pts100
pistondevelopers.github.io 12y ago

Piston: a user friendly open source game engine written in Rust

jonchang
8pts0
www.janbambas.cz 12y ago

New Firefox HTTP cache now enabled on Nightly builds

jonchang
16pts0
leomca.github.io 12y ago

Mozilla and DRM

jonchang
2pts0
www.scotusblog.com 12y ago

Aereo – Just the middleman, or a scofflaw?

jonchang
2pts0

Developing media literacy is an important skill!

One way to approach this work is to understand the genre of the work you are reading! We can determine genre in a few ways, but in this case, we see that the publication is the New Yorker, which tells us to expect magazine-style writing, specifically longer form feature pieces.

Another important clue is that this is published in the New Yorker's "Books" section, suggesting that this is a book review. And, if you know much about the New Yorker's book reviews, they often include things such as history of the field the book addresses, compares the book to other related books, and what the book's thesis might imply about our world today.

This longer form book review can introduce important context and enrich your understanding of the world! I encourage you to keep an open mind and continue to read pieces that are outside of your usual genre.

Firefox 125 2 years ago

You'll be interested to know that Safe Browsing was introduced in Firefox 2 in 2006, and the malware check feature was introduced in 2014! I suggest you search using your favorite search engine to see how this feature works while also preserving the privacy of your URLs and downloads. It uses hashing! Here's a good link, I suggest you scroll down to the Privacy section and read carefully: https://feeding.cloud.geek.nz/posts/how-safe-browsing-works-...

CZI and CZF are structured as a for-profit LLC and a non-profit arm, respectively. Depending on where the money came from, it might not be a problem at all, though it could potentially jeopardize Harvard's nonprofit status. I'll leave it up to you to figure the odds of the IRS revoking that designation.

Firefox and other browsers use an optimization called the bfcache (back-forward cache) that is intended to do exactly that. However, lots of web developers write their pages in a way that defeats the bfcache optimization. Moreover, bloated large page sizes (including JS objects) will make the bfcache more likely to evict entries.

Compare using back/forward on a boring HTML site like Hacker News, and to something like say, the Google Search results page. What's funny is that Google itself has a page on how to optimize your website for bfcache implementations, with some Chromium-specific tweaks, but the left hand doesn't talk to the right at Google, so we're stuck with lots of full page refreshes on Google properties.

https://web.dev/bfcache/

Our solution to the infinite-backtracking pip dependency resolver was to instead rely on poetry to do dependency management via lockfiles. This way dependency resolution only needs to happen once, and oftentimes on CI through dependabot version bumps. This also has the advantage of ensuring that the exact dependency tree is mirrored on developer machines and on production servers.

I also helped work on python app dependency resolution in Homebrew. For apps (i.e. not libraries) written in python, Homebrew vendors the full dependency tree as formula resources. However this was a fully manual process for a while and relied on maintainers laboriously copy and pasting URLs from pyPI, checking requirements.txt and so on. We instead transitioned to a system that used pipgrip to do dependency resolution (and helped report a few bugs) so that all of this could happen automatically instead.

It's kind of sad that all of these are built outside of the pip team, but I imagine in a few years pip will be good enough to replace both of these use cases.

I think that what this means in the long-run is that this small number of very highly resourced private colleges (Ivies, a lot of the small New England liberal arts schools, Duke, MIT, etc.) will be able to sustain "normal" people going there on the need-blind aid, and lower-ranked private institutions (out of the top 50-100 schools) will probably close if they can't afford to offer that level of aid.

The term here to look for is "tuition discount rate" which is how many students actually pay the full price. You are correct in suggesting that high discount rates mean that only the extremely well-resourced schools will be able to compete for students who aren't able to afford the full price of college. Here's IHE's summary of a study about 2020's numbers:

https://www.insidehighered.com/news/2021/05/20/private-colle...

“Tuition discounting strategies come at a heavy cost for many colleges and universities, especially those that forgo a significant amount of tuition revenue to expand educational affordability for students and/or to meet enrollment goals,” the study said.

These are the first paragraphs of the email I got:

On December 13th 2021, the Firefox browser will be officially "resorbing" Firefox Lockwise. Don't worry, all your saved Lockwise passwords will still be available through the Firefox browser using a Firefox account.

The Firefox Lockwise app will no longer be updated and supported by Mozilla and will not be available in the Apple App and Google Play Stores. After that date, current Lockwise users can continue to access their saved passwords and their password management in the Firefox desktop and mobile browsers.

It seems pretty clear-cut to me.

This article appears to be focused on laptops, desktops, and servers, and the author uses the term "system" to collectively refer to these. If this really is "infurating" (and you're not just using the term to be hyperbolic) then I think recognizing that sometimes blog authors write about topics that are more specific or have a different focus than you'd prefer would help calm you down a bit.

Quote:

Why go after hotel or airline rewards? Because these accounts can all be cleaned out and deposited onto a gift card number that can be resold quickly online for 80 percent of its value.

“These guys want that hard digital asset — the cash that is sitting there in your inbox,” Bill said. “You literally just pull cash out of peoples’ inboxes, and then you have all these secondary markets where you can sell this stuff.”

It's important even when it's an iPhone or Android device. As the FTC report details, many households lack internet access outside of their mobile phones, so having to send off your only way to get online to the original manufacturer can mean days or weeks of not being able to access government services or apply for jobs or whatever.

Note that this hasn't been a problem for Apple hardware released after 2008, according to an Apple engineer:

All cameras after that one were different: The hardware team tied the LED to a hardware signal from the sensor: If the (I believe) vertical sync was active, the LED would light up. There is NO firmware control to disable/enable the LED. The actual firmware is indeed flashable, but the part is not a generic part and there are mechanisms in place to verify the image being flashed. […]

Scroll about halfway down, there's more detail that I haven't quoted.

https://daringfireball.net/2019/02/on_covering_webcams

Looks like the maintainer just didn't have time and there weren't enough people in the community willing to step up and do issue triage or contribute code.

What would actually help is that people help to completely investigate existing issues instead of keep asking me to add yet more features. Turns out people willing to step in the code to investigate and pinpoint exactly where is an issue (or that there is no issue) is incredibly rare.