HN user

nocsi

251 karma
Posts1
Comments172
View on HN

Why renewables? These guys don't have an energy problem. The states have made sure give them energy credits and other assurances on that. The problem they do have though is siphoning the water from everyone around them.

Microsoft actually has a design for mini datacenters that stay cool in the ocean and collect tidal energy. But it's way more fun to have states trying to court you into building datacenters cause it'll bring some jobs.

The 'problems' 1password faces... Apple has solved. I quit using 1password around 3 years ago, but at the time they were going all in on SaaS and quietly memory-holing the local-first vault approach that people were using them for. You know, letting people reference a sqlite db on icloud, google drive or whatever and that can be synced. 1Password cites credential leakage and security as a reason for for not implementing MCP, but they're giving the impression that MCP is the issue. Mind you, 1password has a very similar model to lastpass, that had 16bln creds leaked.

But seriously, Apple is actually in a better position to let mcp into their services if they wanted. The user credentials are all bound to your physical devices, which in turn cooperate to give a measure of identity to you. You don't need to let MCP have full access to everything, the secure enclave can generate short-lived certs. I'd be surprised if passkeys weren't able to do that already.

Glad I had the inkling to hoard gallons of fresh water and canned anchovies just this past week. I'm in Seattle btw, I remember this year we had a power outage the neighborhood people spent the entire week huddling around a fire in the culdesac.

And if the earthquake doesn't scare them, the volcano that triggers will. And if they're still not prepared, there's also the tsunami.

So technically the OS is supposed to be handling this, or at the least whatever app you're in is supposed to signal the MIME to the pasteboard. They even updated the APIs for it this year. I'm not complaining, just giving away loose headsup that they might rugpull you. Apple is particularly not a fan of oblique data transformations, especially since malware keeps going after the user's pasteboards.

Something worth implementing is multiple layers to the pasteboard content, so you're at least maintaining the original raw bytes. That and I always wanted a pasteboard that let you append contents to it. Just some ideas to consider

These same CEOs still don't realize that AI is very suited to replacing executive roles and outperforms your average CEO in every aspect without the human downsides. Shareholders would be way more interested in having a static board of AIs running public companies than replacing lowly workers that frankly will always be relatively cheap.

On the same coin, a lot of government can probably be performed by AI as well. Reminds me The Matrix where humanity delegates all governance to AI/machines

It’s like trying to study the effectiveness of antivirus. But you already said it. As long as it produces consumable metrics a c-level can ingest, then it’s worth it. Because really, how does it make sense to add something so invasive? Anyways in the 90s, antivirus makers also wrote viruses. They’d go on to flood networks with their creations, but magically block infection for their subscribers.

The Washington state tax package was to coerce Boeing to stay. To which to ate it and proceeded to move its HQ to Chicago and migrate manufacturing to North Carolina. WA state != US gov. Contrast Microsoft to Boeing. Taxpayers dob’t have to feed Microsoft to get them to work on public works. They are self-motivated to improve their environment, which in turns improves the quality of life for their workers and the residents.

Then go the opposite route. South Korea fines companies thousands of dollars every day a vulnerability isn't fixed. Security is one of those areas where negative reinforcement works better than positive reinforcement.

I’ve just started using [1Piece](https://app1piece.com/). Before this, I had BetterTouchTools just to mimick the window snapping. And years prior to that, I’d run a full dwm setup on Linux. The thing to understand however… is that these sort of things are a losing battle on macOS. Stuff like yabai/skhd break in between OS updates. Window management and apple is a battle you can always expect to lsoe

But how is multimouse useless? The researcher identified a problem, investigated and produced a plausible solution. The entirety of it was driven by a ‘use’. Besides that, what would you propose calling this org that operates somewhat autonomously in an enclave within Microsoft but focuses entirely on research and is staffed entirely by PhDs and PIs?

I’ve been primarily pentesting medical devices for the past few years and these companies will never willingly hand over code. If you want the code to audit then you’re going to have to yank it out of memory, a jtag or come up with some other disclosure. Not to excuse these companies, but they’re under an enormous amount of regulations between so many different regulatory bodies. But there’s a lot of reasons why infosec people avoid medical stuff in the first place, it’s not for the faint of heart. But then there’s probably worst stuff out there.. like auditing diebold voting machines.

People like to be broad, especially in FOIA requests considering each request is a query and could take months to get a response. If you’re asking broadly then you might get lucky. But I think you’re right, it’s time for a perspective shift. Ask not about the government hiding Aliens - ask about the aliens hiding from the government.

Kinda surprising how much power the EU can exert on tech companies.. and the rest of the world. But now we get one of my favorite classes of vulnerabilities: data format interoperability. Where every vendor implements things to specs, but the specs aren’t clear cut. Anyways, EU sure is asking a lot these days, and these companies are happy to oblige

You should’ve lead with being from Virginia. That entire state is layers of pay for play schemes. They might’ve removed road tests to “save money” but they’re more than happy to keep up car inspection, emissions, registration and a vehicle value tax.

Reminds me of Pokémon Go spoofers. It falls to having to trust that the client is truthfully reporting. You could probably improve the AIS system and do the whole Apple Find My network crowdsource thing - letting ships triangulate one another. But you’re still trusting signals that can be spoofed

I blocked TikTok a little over a year ago. I’ve been recognizing many TikTok-only content creators jumping ship to YouTube shorts. And these creators are also getting clobbered by YouTubers that have figured out the right way to chop up their long form videos into short morsels.

With that said, I think all of this is pointless. I don’t actually think TikTok will be relevant in 5 years. TikTok is just TikTok.. meanwhile YouTube, instagram and twitter have fully encroached on TikTok’s territory and audience

“Merger”… functionally it was more like a SPAC. Boeing buys McDonnel Douglas with shares with a bonus of letting them control the board. Boeing just announced their acquisition of spirit aerosystems, same company responsible for the fuselage mishaps. Somehow I doubt they’re buying them for any of their aerospace expertise, but rather to go in and burn all their records.

The Boeing of old has been long gone since you were last there. It’s all run by MBAs now whose sole purpose is to minimize how much engineering can be done by the company.

Expect more deaths in the future. They seem very content continuing to solve systemic engineering problems with only business strategy.

The details of the MD acquisition is pretty crazy. It was like an unintentional SPAC whereby the company you’re buying owns you

There’s a feature to use your iPhone to do keyboard input on an Apple Watch. Could it be that? Don’t tell me Apple left out some authentication. I know you can do something similar with text input when you’re on the same network as an Apple TV and someone’s inputting text. It’ll prompt on your iPhone to submit keyboard input.

Pentest engagements, you’re having to repeat the same tests over and over. That if you don’t automate it by the fifth repeat, you’ll lose your sanity. So the new automation tool now frees up time so you can audit on new novel areas in these engagements. But, it happens again. You’re slowly getting bored again until you inevitably write a tool to automate it. It’s a vicious cycle

It’s not that different than how’d you implement a multiplayer game. Take a real time strategy game (not quite the best example). But if you’re a client, you’d only be concerned with those you can see on the battlefield, especially if there’s a fog of war.

Anyways, you can also do things naively. Some RTS games just handed down the entire state to every client and let them figure it out. You can see how people would take advantage of that to strip away fog of war during online matches.

This category of software was actually really useful when I wanted accountability during R&D tasks on engagements. I used Timing, and it would parse the active window titles and create a timeline. Then the creator wanted to charge $80/year and I ended up dropping it completely. I also kinda realized that this sort of software isn’t that different than a RAT and an attacker could target these sort of things. I also figured Apple would’ve opened up their screen time API by now and this class of software would become redundant