HN user

kinsomo

498 karma
Posts2
Comments160
View on HN

Underdogs with nuclear weapons?

For most of their existence their much larger Arab neighbors (who had the backing of a superpower) had the explicit and oft-stated goal of destroying Israel. Those weren't idle threats: several wars were fought under that banner, one of which was almost successful.

While they currently have a somewhat more secure position, due to peace treaties. They remain unpopular, and a governmental change or revolution could easily put them under intense threat again.

You should only be buying from an American supplier, even though we just spent 30 years shutting them all down

Factories won’t be growing up out of the grown churning out parts in 6 mos because of this

If you wanted to reverse the trend of all the American suppliers getting shut down, and re-build the American manufacturing base, what actions would you take to accomplish that?

(a) does not harm China, as intended, as they are still the only viable place to purchase these items, yet (b) actively harms business in the United States, as we are paying the additional cost ourselves.

There's an important qualification: that's probably only true in the short or medium term. I believe the goal is that the higher cost would produce economic space for competitors to enter the market.

Ironically, I believe the WTO rules allow for countries classified as "developing" (like China) to maintain high tariffs to develop local industry for precisely this reason.

What I don't understand is the response. The burden of this cost has entirely been placed upon US businesses

I don't think that's true, which is proven by the fact that China is strongly opposed to the tariffs and plans to retaliate with their own. China's exports will go down, so it will cost them too.

Developers are the only people Apple really needs to make Macs for and that's a pretty small market in the grand scheme. Creatives doing photography, 3D, video, etc. have long left for other platforms. I don't expect things to get much better.

Apple alienated the creatives and it seems like they've started alienating the developers, too.

If the Mac platform becomes nothing more than part of a development kit for iOS apps (sort of like developer version of a video game console [1]), it will be a sad day.

[1] https://en.wikipedia.org/wiki/Game_development_kit

let me piggy-back, is Apple going to have proper HDMI ports in future? Im going surface book the moment my current macbook stops working.

Unlikely. That would require a 180 degree change of direction. Apple has decided that fewer ports in kind and number is what they're going to do, and I don't really see them responding to external feedback (and basically admitting to a mistake). They're too insular. Case in point: there have been loads complaints for half a decade about the current Mac Pro, and all we've seen so far is a souped up iMac and vague promises.

Hopefully they're laying conduit with new road construction. I read somewhere that there are proposals to mandate that (can't remember if it was state or federal level).

Edit: seems like it's both:

https://arstechnica.com/information-technology/2017/03/natio...

https://arstechnica.com/information-technology/2014/10/fed-u...

https://www.csg.org/pubs/capitolideas/enews/cs41_1.aspx

https://www.azleg.gov/legtext/50leg/2r/bills/sb1402s.htm

So... two of the routers affected by the recent VPNFilter malware? Interesting choice.

If you're looking for a router that's never had a documented security flaw, you're probably going to buy a no-name brand that's full of them (because no one's looked yet, so it has a "clean" record).

The factors that you really need to look for are 1) good engineering practices for security, and 2) prompt and effective response to flaws. 1) can hard to verify completely, but you can get a sense of 2) based on patch cycles.

I have a Mikrotik router at home, and I chose it because their products are inexpensive and aimed at professionals, which means the software support is much better than consumer routers. Mine is quite old, but it still gets patches.

Maybe SWAT can use this to validate that it's actually the right house when serving a no-knock warrant.

How would a stick figure images help a SWAT team validate that they're at the right house?

This could only help them by giving them a clue about where to point their guns once they bust down the door.

Because people rely on reviews and ratings to buy stuff?

There are people who try to make a living on YouTube. Demonetization hurt them and they have a ready-made audience to vent to.

But legitimate reviewers won't really care if Amazon implements stricter checks, because their livelihood doesn't rely on Amazon reviews. People won't have much sympathy for the people pushing crappy products using sketchy reviews who might get hurt, and they don't really have a high-profile forum to complain.

If Amazon wants to implement a stricter review check you can rest assured that it will not be like YouTube demonitization all over again.

This seems like it's probably unhelpful and out-of-date. Any such how-to guide really should cover some kind of obfuscation to avoid the anti-VPN blocks. For instance, apparently the great firewall will let SSH terminal traffic through, but it uses heuristics to detect and block SSH tunneling.

This guide, is really more like "step 0" of a multi step process. All it does in orient a novice toward the services he will need to expend effort to try to access.

It is a matter of record that some local politicians made speeches about how the new freeway would benefit the original city it runs through. I think they use the phrase "tortured truth" to express how these statements reflect what actually happened.

Does anyone have any more info on the meaning and usage of the term "tortured truth."

I've been looking for new, concise ways to refer to a dishonest use of selectively chosen truth to mislead.

I'm pretty sure freedom and democracy are a really good match for Chinese culture (probably a better match than American culture? hard to say). It works well here. But that's just my two cents.

Would you care to elaborate on your point that "freedom and democracy are a really good match for Chinese culture"? I ask because that directly contradicts one of the points that the CCP (probably Self-servingly) hammers on. It would nice to get other perspectives on that.

I'd say it's not irrational to consider the possibility that these firms either are directly or via the Taiwanese government cooperating with US cyberattacks.

But to be totally clear: that's no more than speculation.

It's also not irrational to consider the possibility that there's been no cooperation but that the certificates were stolen.

It's also possible that unicorns exist. Considering that certificates have been "stolen" from Taiwanese firms multiple times [2]

Malware that uses stolen certificates is less unique than once thought. If a group building a bank trojan can steal certs, I'm sure state intelligence agencies can too.

https://arstechnica.com/information-technology/2017/11/evasi...

There is also some reason to think their certificates would be targeted for theft, because code signed by those firms would be some of the least conspicuous. There are a lot of Taiwanese firms that make a lot of low-profile specialized support silicon that's literally everywhere (Sound, USB, Wifi, etc), and a driver signed by one will arouse less suspicion. Inconspicuousness would be a high priority for a nation-state hacker trying to avoid detection.

The possibility that the Stuxnet and Duqu certs were stolen is speculation too, but it's less inflammatory and more likely in my judgement.

It's also worth noting that getting explicit cooperation from a company to use their certificate would be risky for clandestine nation-state operation, since the more organizations that know about aspects of it, the more likely it will fail. If word got out that a particular code signing cert was shared, a rival actor could focus attention on suspicious code signed by that cert and be more likely to detect it.

> The implication is that American silicon itself is backdoored.

There was no such implication. Compromising hardware never makes sense unless you can intercept the hardware en route (something the NSA has been known to do [1]).

That's wrong. If the silicon is comprised from the get-go, there's no need for an interception step.

The actual attack vector relies upon drivers signed by Taiwanese chip makers.

But that's not a hardware attack. IIRC, Stuxnet used driver signing certificates to bypass some OS-level safeguards. It's quite possible that the needed certificates were stolen from a manufacturer that poorly protected them.

When you said:

> Their dependence on American silicon may in fact be their greatest security risk. [emphasis mine]

The implication is that American silicon itself is backdoored. That may be true, but I don't think Stuxnet is in any way an example.

Their dependence on American silicon may in fact be their greatest security risk. It's clear that the US and its allies will weaponize this advantage (see Stuxnet)

Please elaborate on this point, my understanding is Stuxnet relied purely on software vulnerabilities (to spread and to take control of the centrifuges). I don't think it used any hardware backdoors or anything. If it did, I'd have expected the roar to be enormous, probably several times what we just had with Spectre/Meltdown.

Does the api support creating old posts and back dating them?

FB is really good at hiding old activity and being utterly worthless at searching your feed, so if you can just put all the fake stuff in the past you'd be fine with your real friends.

They allow you to back date, but if you're goal is to avoid annoying your friends, you could use the privacy settings for a similar effect. Just post your garbage as visible to "only me," let it age for a week or two until the algorithm will ignore it, then make it "public," "friends only," or whatever you want.

I actually had the strategy on fb to just like very random stuff like movies, groups etc. I’m not sure whether it has helped but it makes me feel better

I've done similar, and afterwards nearly all advertising categorizations of me eventually dropped off my profile (after a period where they were schizophrenic and contradictory). I can't be certain I caused that, because this was contemporaneous with Zuck's congressional testimony and the run up to the GDPR (both of which probably motivated many changes).

But it would make sense that mountains of bad data would make it hard for them to confidently place me in advertising demographic and interest categories, do to all the contradictions.

You rested your argument on the fact that we should take away someone’s right because they got annoyed. So no, I am not being unreasonable.

You are being unreasonable. You seem to be unable to imagine things except from the POV of a person who wants to rent out an apartment as an AirB&B, which may be the root of your unreason.

Anyway, this thread is dead and you seem immune to the insight that what you seem see as an "inalienable right" (turning an apartment into a dedicated AirB&B) might actually be an oppression on others. It's pointless to continue.

I'm glad you're not my neighbor, and I'm glad there's government to keep you from being too much of an inconsiderate asshole if you were.