HN user

nocoment

70 karma
Posts1
Comments24
View on HN

Bummer, I thought this was on candlepin bowling! Last I heard a startup survived by taking over the league so it would make more sense on HN.

It also doesn't suffer from the "too easy" problem of 10 pin. For example, no one has officially bowled a perfect candlepin game.

I was going to respond with Germany. Specifically, the East German state did not own up to it like the West despite it being great propaganda for the founding of a communist state.

A government does not gain from showing its society a proper mirror. It runs the risk of losing ground by having "insulted" the guilty older generation and national identity, and simultaneously plants the distrust for itself (it mostly is that older generation) to form a youth revolt (the RAF supposedly formed from this distrust in West Germany.)

Angular 2.0 12 years ago

just replace the value of "ns.someService" worldwide with a mock.

Having a window-wide namespace might make sense in the test, but it is pretty risky/limiting if you are writing a component that should be reused in contexts you don't fully control. There are other ways around that besides DI, but they will probably have similar trade-offs in safety EOU, etc.

A CPU with an accumulator register (default locations that accepts the result for each instruction and is usually one of the operands in each new instruction.)

I guess that is a bit less capable than an actual stack machine like FORTH but sort of the starting point of this programming mentality (at least as I think of it.)

Yeah, I don't think it is odd for an American in general just in the context of valuing time.

You don't think about the 30-60 minutes in the car because you are sitting there killing yourself faster, but wasting less bodily energy than sleeping.

The time spent making coffee is probably good for your lifespan, but standing around, moving and cleaning things feels bad for us lazy apes..

I still don't understand why a consortium of insurance companies doesn't run studies looking for better outcomes with out-of-patent and un-patented drugs.

Their tests would be of already approved drugs.

In many situations they could save a bundle and in others they would dissuade drug companies from pushing the advertising and costs.

The statistics on everything they test would show their general level of bias (assuming drugs aren't getting any worse.)

Dangerous links (Google ad network masquerading as downloads of the content.)

First listing is from a commercial solver, rather sales oriented, though it looks like the topics may not depend on it?

I'm not really against them. I worked somewhere that kept having hiring freezes and they would have made everyone (except payroll perhaps) happier if they made a sequence of short lived offers. Instead, a favored and frequently overqualified candidate would drag their feet and ultimately no one was hired.

I've never simply delayed as a candidate, if I've been less than thrilled with an offer, I've simply stated the terms necessary for me to accept the job right away. Thus far I've either gotten my terms or met about midway with a little time to contemplate the acceptability of the perceived loss.

This makes it far easier for the hiring manager to make a decisions in parallel, request a higher salary for all his negotiations once if necessary, maybe extend a exploding offer to a similar candidate and not have to string along a series of ranked candidates.

I think the point was that Yelp's algorithm is not clear and is >rumored< to be biased to raise their own income.

While google is higher profile and would not keep an intentional practice secret for long, it is also not an entirely neutral party.

For example, changing it's algorithms to move businesses lower than other sites (review, blog, forum, etc) may make sense from the user perspective to a degree. But taking that even further works against both the customer and businesses to google's monetary benefit. Then the businesses must purchase SEM from google for searches that were directed at finding the business.

Dropping organic list algorithm changes whenever they hurt SEM profit combined with A/B testing to raise conversion rates/revenue on the advertising could end up with an effective extortion racket simply because that is optimal when you have a monopoly.

The article seemed pretty balanced actually. He is not a convicted criminal thanks to unfortunate loopholes..

Tracking his business closely would be a good opportunity for legislators looking to reform payment systems. But any reform would have to affect a whole class of payments designed based on human psychological defects. I.e. a good reform is a big battle with most phone companies, gyms, etc.

I found it funny to reach the end and see their affiliate marketing... So, thanks "theatlantic", and I would fund your article through what sounds like a very legitimate affiliate retirement plan, but Jesus is already a part of my father's retirement plan. (He swears to him he'll never retire.)

An ISP is in an ideal position to coordinate resistance to censorship. Everyone using your service to provide content should be able to opt-in to being a proxy for all other content. Then censors get to select between allowing all content, no objector's content or attempt to filter too high in the stack and/or violate copyright.

When you put it like that, paying for such oversight is well worth it. Would the military request less if it was more efficient or would it keep its budget and just fight (== exchange GDP for the "benefit" of additional limitless risk) on more simultaneous fronts?

Really, I don't see that many private sector companies competing on the big contracts no matter what you do. But for the smaller profit and more general purpose projects, the problem is that their purchasers interfere with the process to get what they want/need as the buyer. For example, they needed our systems and we didn't much care about learning their processes, so an Aerospace seemed to take the bulk of the profits by making a package that depended on us.

If the system were equally complex yet more transparent/published and tamper resistant then I don't think corruption would be so rampant and cost may at least be allocated to regular companies that choose to navigate them alone. But with no system at all, I think the Aerospace that took most of the profits would have taken even more and delivered still less.

Yep, to be clear I was pointing out that a TPM with remote attestation can't avoid implementing DRM in the true sense of protecting specific content to the extent possible on the device.

I think the permanently gimped system stuff like a key restricted secure boot is really something else. It is in some sense an acknowledgment of the impossibility of DRM actually preventing every single copier and gains more from leveraging its play time monopoly to lower the value of all non-DRM content which may or may not be pirated.

A system that denied all open content with a TPM would indeed be very broken in terms of design and would only start to make sense if the hardware was much more customized than a typical PC platform.

I've been in a role of evaluating security vulnerabilities on security products and features from many different origins..

All I am saying is that I am in a position to estimate ~9/10 of everything critically exceeds the competence of its authors to safely combine features and security. So a primary explanation for failure that only applies to 40%(60%?) of the market doesn't sound right to me.

So either we disagree considerably on proportion of software that is poorly implemented or you are saying the majority of commercial software is also written by hobbyists?

Sometimes open source is also competent and well-vetted, but vetting is expensive, and there is a lot of amateur crypto out there.

You seem to be implying that one must be a hobbyist in order to write incompetent crypto software with no or incompetent review and tend to need company resources to get quality code reviews.

Having crypto is often an important checkmark and tack on for shipping a product and usually no one in the product group is competent to analyze the security of the way they tacked on encryption. If a few in the larger company are competent, they will avoid reviewing these projects. Being the engineer everyone associates with delays and frustrations doesn't do much for you and there will never be any proof of the costs you may have prevented.

The few better than I know how to criticize implementations that I have seen haveusually had considerable cross company and university involvement. That usually means open source or a lot of NDA and complex license agreements for cross organization code sharing.

Are there any TPM implementations where the user doesn't control the TPM?

The design of the TPM prevents the user from ever fully controlling it, so complete revocation of access is unnecessary. Anything in the system/bootup can update a PCR, revoking some or all access to essential keys.

Take the chromebook I am using right now. The user can disable secureboot (which isn't actually implemented with the TPM) and use an unsigned image, but can not create an image signed by themselves.

With either boot, I nominally have control of the TPM, so far so good. But the PCR values written by the boot process will be different so I can not use keys from one boot in the other. For example, my encrypted filesystems from the google boot are inaccessible.

This is great for the security of my data if my chromebook is stolen. But it also means a web service like my companies' VPN or MPAA's movie server could demand that I use attestment to show I am using a google configured chromebook, if I did a custom boot the attestment will not have the right PCR values, so I am incapable of using the service.

TPMs aren't needed to provide a DRM scenario - UEFI Secure Boot can do that by itself, right?

AFAIK, UEFI secure boot limits the device based on a list of public keys, but has no access to any form of secret key. So booting an insecure clone to contact a DRM protected service (or otherwise emulate the secured device) works perfectly fine.