HN user

ksala_

225 karma

hn AT mail.ksala.eu

Posts0
Comments59
View on HN
No posts found.

Damned if you do, damned if you don’t. You can’t be expected to get a subscription, but you also can’t be expected to charge for an upgrade.

Now, I hate subscriptions as much as the next person, but I can’t leave this blog without feeling that the op is a bit entitled.

For what it matters, my opinion is that GoodNotes is doing everything correctly. If you bought a 5 lifetime, you can still use it. It’s the same app (that’s interesting, there is a toggle to go between 5 and 6) so I’m assuming it’s still getting bug fixes for new os releases and similar. 5 was a free update to 4, and 6 was released in 2023 (!) so that license was good for a while. They offer discounts if you bought 5, so op point of it being cheaper on a subscription might be wrong. And according to their website they still offer lifetime licenses for 6, bar the AI stuff (which is probably an ongoing cost for them? No idea if it’s local or not).

Plenty of scammy apps and it would be nice to go back to owning things, but this is the same experience if not better to when you could buy software on a cd and keep it a couple decades ago.

I'd argue the second one was not followed either. Maybe I'm misunderstanding the article, but I would not take a random "your password has changed" as proof. I would need the caller to send me an actual email from their personal work email address (or ticket system?) with some actual, human communications in it.

You can have 2 automation, one which enable grayscale when certain apps are open and one that disable it when the apps are closed. It’s under shortcuts > automation > app > is closed.

That is a terrible explanation to be honest. 10pm PT is 6am UTC, which is not a great time for Europeans. Both COTA and Miami started around noon PT, which is 8pm UTC and a much more reasonable time in Europe if you ask me.

Unless they are trying to appeal to Australian fan, my money on the real reason is that they wanted the glamour of a night race in Vegas.

If you limit yourself to the recommended ones they're supposed to be reviewed by a human and subject to some amount of guidelines - https://support.mozilla.org/en-US/kb/recommended-extensions-... and https://extensionworkshop.com/documentation/develop/build-a-...

Personally I do try to limit the amount of them I run, stick with recommended and take at least a glance at the source from time to time, but it would not defend against version updates or good efforts to obfuscate bad code. I do feel at least somewhat confident that for recommended extensions with substantial usage the internet would surface funny business quite quickly.

But yes, I would love for some independent third party to have some review program! Unfortunately it's not clear how it would be funded.

I still have to see a single webapp that is as performant and feels the same as a native one. We might get there, and lots of companies are happy to release a half-backed webapp today, but that is definitely not the experience today.

Both of them still exists, but of course in some situations it doesn't make sense, so there is a lot of leeway depending on the reviewers. My experience is positive here, I can't remember the last time an app did not allow me to not have an account or manually provide data when it made sense.

https://developer.apple.com/app-store/review/guidelines/#dat...

  (iv) Access [...] Where possible, provide alternative solutions for users who don’t grant consent. For example, if a user declines to share Location, offer the ability to manually enter an address.  
  
  (v) Account Sign-In: If your app doesn’t include significant account-based features, let people use it without a login [...]

Just different. I hate hangovers but love a good buzz. Unfortunately, alcohol is quite addictive to me. While I never got to the level I would define myself and alcoholic (I have definitely tip-toed that line in my life) just going out for one pint or having one beer is almost impossible - once I start drinking, all common sense goes out of the window and I keep going. A normal night to the pub might end up easily at 5 or 8 pints. At least it doesn't really alter my character :)

It's interesting because I don't tend to get addicted to things. I've never tried hard drugs, but I can quit coffee cold-turkey (and have done, several times. Just because I was feeling like switching to tea or oat milk in the morning) and never really got into weed.

(anyway, stopped drinking a couple months ago. Alcohol free beer is great for that to be honest. I do miss a nice whiskey from time to time. Let's see if I keep it up)

But with a teacher, I can get a feel of their qualifications after a while (or cross-reference whatever they tell me) and if they're wrong, I can go somewhere else. Also, a teacher is less likely to gaslight me and hopefully will research the topic in case they're not sure about something. With AI, it's always a coin toss.

I don't know, maybe I'm just a old person yelling at clouds, but I just find it crazy to use AI for learning anything. Maybe one day.

Either Reddit is happy about the caching as you cost them less, or they're not happy about it and they just block your app if you do that. Now, people could scrape the website or allow users to bring their own API keys, but then it becomes a cat and mouse game. And if you're trying to sell your app on any of the app stores, Reddit could likely get it taken down/take legal actions.

They're just checking the user agent

    $ curl -s -I 'https://www.sfgate.com/' -H 'User-Agent: curl/7.54.1' | head -1
    HTTP/2 403
    
    $curl -s -I 'https://www.sfgate.com/' -H 'User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/113.0' | head -1   
    HTTP/2 200  
One "trick" is that Firefox (and I assume Chrome?) allow you to copy a request as curl - then you can just see if that works in the terminal, and if it does you can binary search for the required headers.

That's usually where those things fail for me. Still, I don't really consider them worthless - the goal is not to prevent you from wasting your time, but to make you aware you're wasting your time and turning a muscle memory action into something you actually have to think about.

In my experience phisical separation is the best for when you don't want to use your phone (for example, when going to bed or if you want to focus on discussions when having lunch) but that is not always possible - then apps like one sec or other tricks like setting your phone to gray scale, moving icons around, focus mode, screen time... All serve to nudge your brain into thinking if you really want to waste time.

For making better use of your time... Eh. Everyone struggles differently of course, but I'm unlikely to go out and run, or do focus work, when I would waste 30 minutes scrolling through Instagram. But if you make sure to have better alternatives (reading a curated feed, listening to a audiobook/podcast) then they can nudge you that way. Finding a better alternative is entirely up to you. I do find that writing down things you want to do, no matter how silly it sounds ("of course I want to read more books!") helps, especially as you can always reference to that list later when you're bored.

It seems to be just parsing Google News, and displaying the articles in publication order instead of whatever smart order Google News is doing. I do like the design (or lack of) quite a bit.

That's a neat idea OP - I usually give https://www.economist.com/the-world-in-brief give a quick scroll, but I quite like sourcing from several news sites, and the summaries are good.

Where and how are you getting the ~1000 news articles you feed to GPT4? I think it would go a long way for transparency to list that somewhere on the website. Also, are you using international news agencies? Quite a lot of them publish an English feed too.

I would also love to see the difference it would make given a different geographical prompt ("in the context of China/India/Asia/Europe... How would you are this article") and political ideology prompt ("how would you rate this article for a Republican/Democrat/Libertarian/Socialist...")

They send the hash of the master key password after it's been encrypted to the server. They then encrypt the hash on the sever side to auth you. They don't send the password itself.

What that article is saying (rightfully, mind you) is that an attacker can mostly ignore the server side round of encryption, because if they have a copy of your local vault, they can just perform the client side rounds and then see if they can decrypt the vault.

This is a problem mostly if you see their claims of 100000 rounds server side, and decide "oh that's fast enough, I'll drop the client side rounds to 5 so my vault is fast to open)"

That page is weirdly interesting to me. It's hosted on sites.google.com which was probably one of the worst ideas google ever had, security wise (yes mom, always make sure the page says Google.com - but not sites.google.com). It's clearly one of those blog spam page types, with the same 3 bits of information repeated over and over again. It does not have any clear phishing links, in fact it tells you to open support.google.com in your browser without a link. One of the number it links it's the official adwords support number (https://support.google.com/google-ads/answer/7218750).

Only after all of this it links to another number, which from what I can tell is a scam phone center which will offer to help you with your account for some money. I really wonder if they're betting on everything else being so hopeless that a person will eventually try to call this other number after trying all the other options before.

It does tell you something about Google support if scammers can do that...