HN user

lucastx

237 karma

[ my public key: https://keybase.io/charlieaik; my proof: https://keybase.io/charlieaik/sigs/Y269TsORtLSVUwX4p2I9nFx0ekt52-u5yBZugUyYOhU ]

Posts15
Comments63
View on HN

Fluid Concepts and Creative Analogies is a wonderful book. I wouldn't call the systems they build upon (such as lMetacat [1] and Tabletop [2]) "machine learning"...

[1] http://science.slc.edu/jmarshall/metacat/

[2] https://deepblue.lib.umich.edu/handle/2027.42/105891

I'd also like to see FARGonauts / Center for Research on Concepts and Cognition style software implementations around... I have run with success this python implementation of Copycat:

https://github.com/ajhager/copycat

From the news article:

Boelter said: “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which users might not notice. Using the retransmission vulnerability, the WhatsApp server can then later get a transcript of the whole conversation, not just a single message.”

I frankly didn't understand what was said here.

Signal and Giphy 10 years ago

People underestimate a lot the power of "useless" features, if well designed, to attract new users.

Telegram's Stickers are probably one of the features that most people feel other messengers lack to make people enjoy using it. Lots of friends are actually communicating daily through GIF's.

Sure it is not the best tool -- but depending on what means "critical" in your context it provides great security. Not against the NSA targeted attacks, sure, but if you're not so concerned about your adversary using exploits and more sophisticated tools (versus just demanding data from the provider or something like that) ProtonMail goes a long way.

Anyway it is, for most cases I can think of, much better than Gmail.

Google is supposedly hiding a direct competitor to one of its main product from its search engine, the main entry of the Internet for millions of people that aren't very proficient with computers.

Google's product, Gmail offer considerably lower security and privacy than this competitor and using it instead of ProtonMail may very realistically get someone (a journalist, whistleblower, LGBT activist...) in deep trouble or even killed in lots of places and contexts.

I think this is a pretty evil move. Not only for this but what it represents when, again, millions of people were educated for years to enter the Internet through this search engine and don't have any clue that it may not only tamper with the order of the results but also hide websites.

For a much more gentle (and illustrated) introduction do public-key encryption, GnuPG and how to use it with email (Thunderbird + Enigmail), see FSF's Email Self-Defense:

https://emailselfdefense.fsf.org/

Tactical Tech's Security in-a-Box has more detailed, step-by-step, multiple platform guides for the same tools:

https://securityinabox.org/en/guide/thunderbird/windows

https://securityinabox.org/en/guide/thunderbird/linux

https://securityinabox.org/en/guide/thunderbird/os-x

I guess there is no point in arguing if you think this way. Paraphrasing Edward Snowden, if you don't work to protect privacy because the threat to YOU is not clear, you shouldn't work to protect free speech if you're not the one being silenced.

A big problem is that the threat to you exists, but is subtle: society gets worse when we allow this to happen to all those people that we would consider heroes years in the future but are deemed (sometimes by the letter of the law, sometimes not) criminals right now. Conformity for the forest by pruning the trees.

I'll work on a quick article today to explain this and adapt the page to reflect that. Thanks for the tips. Answering you quickly (I'm preparing dinner :-)):

- Tomorrow, the CPI decides their final report (after three drafts and a couple separate patches) on all the inquiries the commission made the last months. This report includes "recommendations" to some existing draft bills and proposes a number of other bills.

- Parliamentaries presented "destaques" that will be voted separately and may supress the "IP blocking for illegal content" and "notification-based removal of illegal content" bills.

- The final report as of now is the first link with a small patch on the Projeto de Lei 1.6 made by the second link.

http://www.camara.gov.br/proposicoesWeb/prop_mostrarintegra?...

http://www2.camara.leg.br/atividade-legislativa/comissoes/co...

EDIT TO APPEND:

TL;DR: The two bills that we may realistically remove through the help of friendly parliamentaries tomorrow are the ones about illegal website blocking (ISP blacklisting) and content removal through notification; both open the door for criminalizing remixes and using copyright infringement for censorship.

We dodged this bullet but here in Brazil but RIGHT NOW there is a much more dangerous risk: with the Parliamentary Commission on Cybercrimes (CPI dos Crimes Cibernéticos / CPICIBER) report a "combo" of bills will get "fast track" on Congress and, to list some things, expand data retention, allow access to IP addresses without warrant and allow judges to block "illegal" content, including copyright violations much like DMCA does (they use the "notice-and-staydown" terminology).

More details here:

https://www.eff.org/deeplinks/2016/04/battery-dangerous-cybe...

https://www.accessnow.org/access-now-delivers-petition-brazi...

https://theintercept.com/2016/04/26/brazilian-cybercrime-bil...

The final voting will happen TOMORROW, 9 a.m. Brasilia time (GMT-3), 5am in California I guess. If you can help raise awareness and use EFF's Action Center to message the parliamentaries through Twitter and Facebook around that time, it would help a lot.

https://act.eff.org/action/fight-back-against-brazil-s-draco...

In portuguese, this is the best starting point on the debate (disclaimer: I work on antivigilancia.org):

https://antivigilancia.org/pt/cpiciber/

It has many tactics or tricks to cover or change the topics when facing difficulties.

This at start sounded like cheating for me, but thinking about it, developing these tactics to change the course of conversation seems like an important skill that all social people develop, especially with bigger groups of people in which the subset of topics that everyone understands and is more or less interested to is not very big.

I like how the Panopticon concept is complemented by the Synopticon one, as in "many watches few". It's close to the "sousveillance" concept.

What may save us from a dystopic totalitarism is the freedom and agency we get through our devices and networks. Certainly software freedom, use of cryptography and uncensored, inclusive basic communications infrastructures are needed.

Google is a known collaborator with three letter agencies (remember that famous "SSL added and removed here :)" diagram?)

The SSL diagram indicates not Google's participation; it shows that NSA was wiretapping their datacenters without their knowledge. PRISM indicates Google collaboration, though.

But see, the presence of Google Play in your phone does not magically allow Google or NSA to listen to Signal conversations.

The easiest way for them to do this would be sending a fake update with a backdoor. This is way more intrusive, targeted and detectable than tapping cables or getting access to Google data.

The Obsproxy and Pluggable Transports are kinda this, aren't?

https://www.torproject.org/projects/obfsproxy.html.en

obfsproxy is a tool that attempts to circumvent censorship, by transforming the Tor traffic between the client and the bridge. This way, censors, who usually monitor traffic between the client and the bridge, will see innocent-looking transformed traffic instead of the actual Tor traffic.

https://www.torproject.org/docs/bridges.html.en

It's not "typing stuff", it's exercing forced, unasked control of your computer (plus unknown behavior on other operating systems), isn't it?

If the user's expectation when handed a thumb drive looking USB device from a big company is that it will display files, and instead it just pretends to be him and controls his computer interface, for me it is at least a gray area regarding computer abuse. But I am not a lawyer.

I'm a GNU/Linux user for almost a decade now, sysadmin, programmer. I still double click things everytime I'm using a Windows desktop (not on the web of course), as does everyone I know here in Brazil.

I think that framing this around "consumers" is not the main point here. If you think that those that benefit are only in a buy-and-sell negotiation, a free market is very appealing.

What we are doing here in Brazil regarding the upcoming regulations on the Internet and data protection [0] is to frame it around human rights issues -- freedom of expression and press freedom are the main ones.

The existence and action of governments is only justifiable for me to keep people from hurting each other too much, and preventing abusive power relationships. I believe current net neutrality issues are one of those situations.

[0] http://www.internetlab.org.br/en/news/internet-brazil-debate...

The title of this Wired article is somewhat over the top. It is about a (then) upcoming Gareth Owen's presentation on 31C3.

I just watched it [1] yesterday, and Gareth Owen himself says that this number is the count of a certain kind of hidden service request that should not be confused with "visits" or "visitors", for a number of reasons. The main ones I remember are:

- The specific kind of request measured is the first step towards connecting to the service, but may not always represent a complete connection that can be mapped to a individual

- Various anti-childporn organizations crawl the dark web constantly searching and indexing child pornography hidden services

[1] http://media.ccc.de/browse/congress/2014/31c3_-_6112_-_en_-_...