HN user

magic_haze

624 karma
Posts4
Comments181
View on HN

What happened to the Hydrogen option? A few years ago, everybody was talking about how it would be the best possible fuel and how much better than batteries it is, but I haven't heard much about it after.

From a distribution point of view, it seems like both batteries and hydrogen are pretty much equally bad. Is there something holding back the powertrain technology with hydrogen?

Aren't a lot of people who used to work at Microsoft during the 90s/early 2000s working at Google now? I'd be surprised if the people who implemented Embrace/Extend/Extinguish in the first place aren't one step ahead.

The best parts of Android are already closed sourced and patented: gapps, all the stuff Samsung, Motorola, HTC etc. add on, the baseband etc.

Showing modal dialogs on every new permission request is how XPrivacy works right now, and while I understand and deal with the process, I can easily see how most people would (rightly) see it as an annoyance. I'm just saying they could easily augment it with their crowdsourced data and reduce the number of prompts, which would mean people will actually pay attention to the prompts when something bad happens.

Re: your second point, you're right, if the on-demand permissions handler were the default, more apps would handle it gracefully. However, it's not, and most apps today crash because they don't handle SecurityException when they call the android APIs. Also, you're assuming developers will act in good faith and will do whatever the users want. I would not be surprised at all if companies like Zynga, if they knew the user didn't give them the permissions, implement all sorts of dark UIs to trick/force the user to give them their data.

Should we not protect users just because they're too trusting with computers to realize what's going on?

I see where the Swype folks are coming from, but it's a bit like the people who complained against the existence of mailinator.com a decade back. Are they seriously claiming that a company whose entire business is based on making sense of dubious data will completely break down if its analysis service gets some bad inputs? How do they deal with shady manufacturers who return wrong data?

Swype is operating in a marketplace that is full of apps crying wolf and asking for way more permissions than they need, usually for unknown purposes. For example, I like to read The Verge and use its app[1], but it has "read phone status and identity" and "modify or delete the contents of your USB storage" in its manifest, which I'm not comfortable with. There is nothing that explains what they use this information for, how long they store it, and who they share it with. Heck, my desktop browser doesn't give theverge.com this permission and yet the site functions just fine.

Why should I bare my personal data to the whole world just because one developer is too lazy to implement checks on his inputs?

[1] https://play.google.com/store/apps/details?id=com.verge.andr...

I agree, but look at the grief Microsoft got when they tried it with Vista's UAC prompts... more permission popups is clearly not what the majority of users want.

I think one solution is having the prompts integrate with the sort of crowdsourcing algorithm that XPrivacy has (e.g., if >90% of users have granted the app permissions on the address book, then don't show the prompt.)

Another important feature is that the app should not know if the user has granted it the permissions it asked for. If the user doesn't want to, the system should just feed the app bogus data and let the user continue interacting with other parts of the app (as we see today, most apps don't really need the data they collect in order to work.)

The entire store experience is the opposite of what Eric Lippert calls the Pit of Success: literally no one involved in the process is incentivized to protect your data. Developers ask for all the permissions they can get away with because users get confused by multiple warnings, users blindly click accept on everything because they've learnt they can't use the app without that, Google is blindly complicit in all this because for some reason, they think everyone is as interested in/capable of protecting user data as they are... (Or they just don't care.)

XPrivacy should really come installed by default with Android: the new versions are really quite good (especially with the cloudsourcing and on-demand bits) and really highlight how atrocious most apps are with your personal data. And it is a hell of a lot more effective than relying on companies like Avast to detect and remove bad actors from the market. I've lost track of the number of times random apps (most of whom are just shells around a website) ask permissions for my full phone number, Google and Facebook accounts, contact info etc. for no reason at all. At this point, I'm scared of using Android without the module. (not that ios or windows are any better)

GPS just means the plane knows where it is. The equipment necessary for the plane to inform the airline ops about its location is still vulnerable to all sorts of problems, even with the kind of anal development practices required by FAA and equivalent agencies. Airports usually have have radars that track nearby airspace, but otherwise, I think most planes are tracked by the ADS-B signals that they actively transmit (insecurely).

It's not as bad now, since most platforms these days insist on a push mechanism that is common to all the apps. You're stuck with different UIs, but the cost is still like running a single client. Even better, because now they cannot run continuously in the background.

I agree, but what happens when you want to share just a part of the page, not the whole (for example, something on your tumblr dashboard)?

I think IE, of all things, had a feature a few releases back for exactly this scenario: a page could define some markup around the content that was shareable, and users could add browser plugins that picked them up and published them wherever they wanted. Does anyone remember what it was called?

Does anyone know what TempleOSV2 is talking about? I can't reply to his comment in this thread because it's marked as dead, but it sounds very interesting.

I don't think it's still as simple as entering your username/password if you don't have your paired device nearby: you also need a recovery key. I got bitten by this once: I didn't remember entering, or even being asked about a recovery key when I set up my account, so I was forced to reset my data. Luckily, I still had my bookmarks in Chrome, so I didn't lose any data, but the entire experience was frustrating.

Also, quick addendum: you _can_ specify an addition password in Chrome so your data is encrypted before it gets sent to Google. It's pretty much identical to FF Sync then, and much more user friendly.

They couldn't do it. The compiler does static verifications that, say, a value of type Meter when divided by a value of type second results in a value of type Meter/Second, where '/' is a custom concept built into the F# compiler. The .NET runtime knows nothing about these custom types.

Keepass proper has a global Ctrl+Alt+A shortcut that automatically types in your username and password into the form: I've found it works fine on the majority of sites (almost everyone uses username-tab-password-enter, but for the few that don't, you can specify a custom auto type format in keepass. It even has an option to obfuscate the typing to trick keyloggers).

For android, I recommend Keypass2Android: it comes with a custom keyboard you can enable temporarily, which inputs your password without going through the android clipboard. I use it with the dropbox app as well, I'm not sure why it's not working for you.

The entire reason why WP is lacking traction is because of IOS and Android's ecosystems, not because of any special merits in their OS code. Indeed, that is also why Windows proper is still dominant on desktop. Throwing away compatibility with the ecosystem would be the height of folly. (Also, there are office clients for all these platforms: they don't work as well as they do in Windows, but they do exist)

I think it's the equivalent of the middlebrow dismissal we so often see here in HN, rather than any faith in humanity. As you mentioned, it is just too easy to come up with a generic "how dare you" response, which is guaranteed to draw in existing prejudices and pitchforks. I don't think the intent is to drown out rational debate of the original statement -- it just happens to be the victim in the race for clickcounts.

I'm confused, what is the context here? The comment is humorous, but the microsoft rep did reply back with (what seems like) working code. In 2009.

Also, why does one need the MSHTML Timer API these days?

I agree about the tax issue as well, but I thought this post was particularly articulate about analyzing an issue from a perspective that was unusual to me. I didn't have a good enough counterpoint to his argument, so I submitted the link here to get some discussion going. I don't think the intention here was advocacy or judgement.

You and I may be moderates, but you have to agree, there definitely are more than enough people who would support mob justice (to take a mild example, the attacks on Google's buses recently... the entire situation seems like a powder keg)

I don't get it. This is the exact same model Roku, Google, Xbox, Ouya et al are trying to follow, and so far, they've all had limited success. Even Netflix and Amazon had to give up chasing after content and had to resort to making their own. What makes Apple's attempt so different from all the others in this area? (No sarcasm intended, I'm genuinely curious.) What leverage do they have that can guarantee them the kind of instant success that the idevices had?

I guess integration with their other products is one advantage, but really, most other consoles have smartphone apps as well, and they're nothing special. The integration with Airplay that TFA touts seems rather dubious... isn't that just normal QOS any old router can do?

EDIT: The most obvious advantage, I guess, is the large corpus of devs who are willing to rewrite their apps to target a new form factor. No other company right now commands that sort of manpower, and that, indirectly, may be enough to convince content owners and game publishers to target their platform.