HN user

norenh

187 karma
Posts0
Comments41
View on HN
No posts found.

As someone who worked with Unix/Linux and command line arguments for 30 years and still "abuse" cat like the documentation, I regularly hear this complaint.

Yes, "cmd <file" is more efficient for the computer but not for the reader in many cases. I read from left to the right and the pipeline might be long or "cmd" might have plenty of arguments (or both). Having "cat file | cmd" immediately gives me the context for what I am working with and corresponds well with "take this file, do this, then that, etc" with it) and makes it easier for me to grok what is happening (the first operation will have some kind of input from stdin). Without that, the context starts with the (first) operation like in the sentence "do this operation, on this file (,then this, etc)". I might not be familiar with it or knowing the arguments it expects.

At least for me, the first variant comes more naturally and is quicker to follow (in most cases), so unless it is performance sensitive that is what I end up with (and cat is insanely fast for most cases).

Could you name another browser with enough backing to be able to keep up?

Besides Google Chrome (controlled and backed by the surveillance overlords) and Safari (Kept alive by Apple cultists) I see very few free alternatives that can stand on their own. The other options are various niche browsers that leech on one of these three that might have a few changes here and there but lacks the real capability to stand on their own legs.

What I mean with capacity to stand on their own legs is that the group behind it should;

  * Be able to be a part in development of web-standards

  * Be able to keep up with ever changing web-standards

  * Be able to suggest and develop new web-standards if needed

  * Be able to maintain a modern web-browser

This needs a relevant user-base, active developers and standard-committee members as well as infrastructure and cash-flow to maintain it for expected stuff like add-ons and various other bits needed (on-line checks, certificate handling, etc) that is expected from a modern browser.

I am worried about Mozilla but I see no reason to declare that the end is nigh just yet.

Firefox is still very much relevant to me, although I use mainly linux-distros and do not normally use webpages as applications (I browse with javascript disabled, unless there are specific needs). I would love to see some more options out there, but alternatives to Firefox are currently not on the horizon for me.

24-bit audio is obviously a noticeable improvement even on $150 headphones

Not going to question your subjective experience, but I do not think most people will hear any difference between 16 and 24 bit playbacks under normal conditions, even with fancy headphones.

"120dB is greater than the difference between a mosquito somewhere in the same room and a jackhammer a foot away.... or the difference between a deserted 'soundproof' room and a sound loud enough to cause hearing damage in seconds.

16 bits is enough to store all we can hear, and will be enough forever." [1]

[1] https://people.xiph.org/~xiphmont/demo/neil-young.html

Thanks! This info is always nice to have when setting up firewalls. Every application should come with a list of connections made, what the purpose is and what the consequences are if you disallow it.

Does IF Metall already represent all of Tesla's employees?

No, but Sweden has mainly unions based on industries (like IF Metall represents workers in industrial and metal-sector, you have Transport that represents workers in transport industry, Unionen of white-collar trade workers, etc). There might even be no workers in the specific union at the specific workplace and they might still go on strike since they are the union you are supposed to negotiate with. There are requirements of negotiation but no requirements of results from that, which is the cause of the current situation at Tesla. Tesla "negotiated" but flatly refused any outcome involving the union so they fulfilled the lawful requirements. Now the Union uses the tools they have in place when the negotiations ends badly so everything is going as expected.

Does that mean there are no active Tesla services in Sweden during the strike?

Like I wrote above, Tesla might have all services running if they have workers doing it, but chances are at least some are members of IF Metall. There is also the effect of sympthy strikes from various other unions: https://www.ifmetall.se/aktuellt/tesla/darfor-tvingas-if-met... This includes transport (loading/unloading in harbors, transport of goods, etc), Electricians (yep, you can guess it, practically everything involving electricity), Builders (maintenance and construction of buildings), service and communication (This is postal workers refusing delivery of post/goods to/from Tesla), etc. The effect goes beyond Teslas services and will extend to all kinds of infrastructure and other parts of society unless Tesla manage to get their own self-sufficient (and probably totally isolated) mini-society without any needs from other parties.

So the more Tesla refuses to find a deal, the more the unions can escalate and it will get quite tricky to find laborers who want to deal with you. Other companies might refuse to deal with you with risk having the strike extend to you to if this goes far enough.

If union membership is really the way of life in Sweden, is there anything preventing the government from a legislative solution?

It is really complicated, but the main thing preventing government going in with a legislative solution is that no-one (neither the industry or the laborers) wants it. It has been a solution that the union(s) and industry can solve this by themself and as long as they can, the government will stay out of it. This is kind of unique relaxed solution that puts a lot of responsibility on both the industry and the unions to sort things out and has worked well so far. Playing hard-ball like Elon will probably not end well for Tesla in Sweden (possibly Europe) if this continues since the system is kinda built on being mature and able to negotiate. My way or the highway attitudes are not well regarded.

Just mandate collective agreements?

But what collective agreement? The system in Sweden is built on negotiation between the involved parties and finding some kind of common and sensible ground. There is really no easy top-down fix for that if one party refuses to play ball. Either the other party need to fight back or the whole system collapses and we risk ending up with government moving in, which neither party wants.

One reason is that tuta does not require you to have any other connection to create and account. Protonmail require a second mail, phone or possibly some kind of payment if I recall correctly (for verification?) that could be linked from your account in theory.

Without having a good anonymous starting point, protonmail does not let you get that starting point, at least the last time I tired (maybe a year ago).

100% this. As a consumer that tries to do active choices the current model breaks any kind of active choices to support or not support an artist, except nudging it somewhere in the margins. If your pot is only going to work you interact with, you can suddenly make an impact for smaller artists.

The counterargument I see is that subscribers who listen to lots of different artists will have a smaller share of the pot for each artist than someone who listen to just one artist. But I see the inequality here is not as bad as the other option where almost all my subscriber fee now goes to a few mainstream artists I probably never listened to. I also bet a lot of smaller artists would benefit more with a per-user pot, instead of always getting a minuscule share from the global pot.

I see only issues abandoning copyright (for example it is the protection that makes Open Source Licenses work), but we should definitely discuss the length of it. The current trend of longer and longer periods of copyright protection can be questioned and I wonder if society would not benefit with a severely cut copyright period. Berne convention and other international treaties makes it hard to change below Life + 50 years, but I see no reason all the right incentives for individuals and companies would be there if you cut it to just 20-30 years after publication. The benefits of new derivative works, access and sharing knowledge and other areas would be great for society as a whole.

The moral right of claiming ownership to a work should still be protected forever.

While technically true, that DDR5 comes with "on-die ECC", it is only because the memory is so unreliable it will not work properly without it. However, even then, it is not the same as true ECC that have a extra data correction chip on the memory module and also protects against send errors to the CPU.

Depends on your needs, but it is fairly simple to buy a domain-name and manage the dns-servers and hosting of web-server (and I guess e-mail) yourself. If you have a A/AAAA-record in your top TLD pointing directly to your nameservers you do not depend on anyone but the root servers and TLD-servers to be available (in regards to DNS). Now, you just need to find a TLD that is not managed by one of the big ones, but that should be fairly easy.

This is very sad news for all Swedes. Here is an article in english: https://sweden.postsen.com/trends/49453/The-YouTube-channel-...

And for Swedes you can watch a short interview with him on Swedish Televison in the first 8 minutes of this program: https://www.svtplay.se/video/33989650/sverige/sverige-sasong...

The program above is from the last shutdown and the example given there about his most popular clip was a very old show of Bonnie Tyler. SVT, at the time, made the clip available officially via SVT Play again but has since disappeared from their service almost as a reminder that culture will disappear from the public unless enthusiast like Rosa Mannen can make them available somewhere.

2000-Watt Society 4 years ago

The article mentions "no more than 2,000 watts (i.e. 2 kWh per hour or 48 kWh per day) by the year 2050, without lowering their standard of living" so it is not 2kWh/day but 2kWh/hour. You are already below it in your household.

My personal preference is to begin with STIG from DoD Cyber Exchange: https://public.cyber.mil/stigs/downloads/

They take a while to come for the latest version of a OS and none is out for Ubuntu later than 20.04 yet, but it is a very good starting point for a checklist even if you do not run a DoD system (a lot of the points might be specific for these but easily skipped) and depending on changes between versions, some parts might still apply. For a recently released OS you usually have to rely on the system documentation from the system creator (Canonical in this case) but most of my experience is from the Red Hat world so not sure how good it is for other distros.

If you start with the best practices for your OS/distro and then dig into a hardening guide (like STIG) you should probably have a pretty good understanding and base documentation for your specific use-case. As always, if you use a specific service/software on top of that (a web-server, mail-server, etc) you will need to dig into the documentation of that specific product and after that check for hardening guides.

The general principle of removing/disabling/blocking everything that you do not use is usually a good one. Knowing what you actually use and the exceptions is what makes it hard :-)

Hi, this sounds interesting... But when I try to enter the site I just get a image of an armadillo. I do browse with javascript disabled so that is most likely the reason, but I can also imagine that a fair bit of your audience are among the slightly more paranoid end so if you want to reach out I would recommend you to make a page that can be viewed without requiring javascript.

I guess that is the reason why every musician should copy their master to a cassette tape and go to a shitty car with a tape-player and listen there, why every developer should have a very old crap-computer to run their software on and why every UX designer should have a crappy screen to view their design on. :-)

I would argue that it is illegal because it hides criminal activity and is a mean to gain from crime even if caught. When laundering money you are trying to hide that the gains are from illegal activity. Normally if you gain something from illegal activity, the justice system could confiscate it and no gains would be made. But if you are allowed to launder the money, we would basically say that it is OK to gain from illegal activity as long as you hide it or that it is OK to help people to gain resources from criminal activity.

Whenever I access a organization that primarily deals with computer security, I mostly judge them reversely based on the complexity of tech used (well, modern TLS is probably the one exception). A simple static site that probably would look fine in elinks is what I am after. Anything that requires javascript or increases the attack surface are big warning signs to me.

To me, this site loads fast, uses very little eye-candy and gets you right to the list of tools with clear links that are easy to overview and go through so it seems like mission accomplished for highlighting them.

Swedish guy here, can confirm that it was often called "Blåtand" in various circumstances in Sweden at the time (20ish years ago). I have worked with Ericsson-employees who also called it "Blåtand" but nowadays it is less common and "Bluetooth" has taken over as the way to refer to it here.

Like others have mentioned here the demo seems to be able to categorize users into certain groups, but it is unclear how useful it is for fingerprinting and track an individual. I would love to see some statistics on it because from the data the demo gathers it seems like it will have a hard time to make out individuals in many cases. I find the technique used in the paper "Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel Defenses" [1] more interesting, although highly impractical. I guess there might be more practical CSS-based techniques that could fingerprint an individual and track them over several sites, but I have a hard time to see the limited tracking presented in this article would be very effective.

[1] https://arxiv.org/abs/2103.04952

Life continued as normal in Sweden...

Sweden had less formal lockdowns, but recommendations that was largely followed . Also limited opening hours for restaurants and closed events with live audience. Most workers stayed at home, traveling went down A LOT and people could not visit care homes etc. If you compare the effect on society it was largely the same as the rest of Scandinavia that did have slightly more formal lockdowns.

Lots of companies (restaurants, cultural events like concerts, theatre etc.) had real economical issues and a lot of people became unemployed. Could be worse, but still it is misleading to say life continued as normal. A quick google show that unemployment in Sweden doubled during the pandemic and that is largely attributed to the measures that took place as a response to the pandemic.

The bound is basically set by the CA/Browser Forum [1] where the current baseline requirements [2] are stipulating:

"6.3.2

Certificate operational periods and key pair usage periods Subscriber Certificates issued on or after 1 September 2020 SHOULD NOT have a Validity Period greater than 397 days and MUST NOT have a Validity Period greater than 398 days. Subscriber Certificates issued after 1 March 2018, but prior to 1 September 2020, MUST NOT have a Validity Period greater than 825 days. Subscriber Certificates issued after 1 July 2016 but prior to 1 March 2018 MUST NOT have a Validity Period greater than 39 months.

For the purpose of calculations, a day is measured as 86,400 seconds. Any amount of time greater than this, including fractional seconds and/or leap seconds, shall represent an additional day. For this reason, Subscriber Certificates SHOULD NOT be issued for the maximum permissible time by default, in order to account for such adjustments."

- CA-Browser-Forum BR 1.7.9, p67

[1] https://cabforum.org/

[2] https://cabforum.org/baseline-requirements-documents/

I would argue that the main reason is that we are stuck with a centralized Internet with a somewhat large initial step to start a new service. If everyone get IPv6 we are all able to be a first class citizen on the Internet, meaning I can run a webserver or whatever from home. Once I am ready I can move on to a hosting provider with all the extra costs and hassle it comes with. Without IPv6, we are stuck with a two tier system of Internet users. Basically consumers and providers where the step to become a provider is larger than when you can simply start from home with whatever scrap you have in your garage.

IPv6 will also simplify a lot of things (being able to scrap NAT (note, you will still need a firewall) and avoid protocol issues for End-to-End services) but that is just a bonus.

Sounds good initially, until you realize the ancient setup was there for a reason (for example a person responsible for quality assurance for a legacy system a few still use). :-)

Not saying it is likely, but from working with production systems that could have come from the stone-age I am too well aware of the possible risks of meddling with a setup that looks obviously wrong or too old to be used anymore, only to realize way too late that it was there for a very good reason.

Resident in Sweden here and heavy user of the self-checkout. My experience is that self-checkout is slightly slower than the serviced one. For a serviced checkout I try to put all bar-codes towards the cashiers scanner (it is a nice thing to do, the cashiers do not like juggling either) when putting stuff on the belt and I will need to unpack from my basket, pay and pack it to my bag. The same is operations needs to be done for the self-checkout but even the best setups needs some managing of the machine that the cashier would have parallelized in a serviced one. Usually it is slightly more fiddly to do packaging and scanning on a self-checkout system than on a serviced larger belt.

However, considering that there are usually many more self-checkout terminals available with much less queue it means that the total time spent is less than on a service one. My local store, open until 23, usually closes down the self-checkout terminals the last hour since there are too few people to make it worthwhile and you rarely have a queue to the serviced station.

So I totally agree that the serf service checkout is slower for that actual station but considering that the store can cram in much more of those in the same space and they need much less personnel to manage it saves everyone time and money to use them, unless there is no queue to the serviced checkout (and personnel is manning it at the moment).