HN user

nyx

1,765 karma

https://bsky.app/profile/nyx.ms

Posts3
Comments110
View on HN

I'm not a fan of Apple or Google, and it feels bad that all of our notifications pass through APNS or FCM. Megacorps shouldn't have control over our digital lives to the extent that they do, and anyone talking about this gets my full attention and support.

Except for marketers! I don't think there's a less sympathetic category of technologists, save for maybe CSAM peddlers.

You're upset that you can't get "visibility" into whether the bullshit ad you tried to ram down my throat landed on target? You're worried that I'm a dormant user and my phone will silently delete the spam you sent to try to hook me back into engaging with whatever worthless product you're hawking?

World's tiniest violin, buddy. Boo fucking hoo. Your last paragraph says the "senders" (read: spammers) who make it through the next decade intact will be, to lightly paraphrase, the ones who send messages the recipients actually wanted. You say that like it's a bad thing!

The computer is in my life because it is a tool that does the things I want. It is not an open mic for marketing sleazebags to try to sell me shit. May every single one of your attempts to invade my life and hijack my attention be flushed swiftly down the toilet.

I was in Japan recently and did find that my non-Japanese Pixel phone wasn't allowed to use the mobile Suica app, even though the hardware supports it. Some nerds on XDA figured out the mechanism preventing it[0], and if you're rooted it seems like you can run a Magisk module to patch the region check in the PixelNfc component[1].

I guess it's down to licensing for the FeliCa smart card system or something? I will say, as a privacy person, I'm pretty jealous of the ubiquity of IC card payments there. You can buy the card at a kiosk with zero KYC and top it up with cash at the same kiosk. Since it's a stored-value system, it works offline, and you get the convenience of paying with a card with nearly all of the anonymity of paying with cash.

[0] https://xdaforums.com/t/global-pixel-device-unlock-felica-su...

[1] https://github.com/jjyao88/unlock-felica-pixel

Agree that "control" is a much better framing, since it doesn't suggest a need for secrecy and therefore embarrassing/unacceptable/untoward behavior that needs to stay behind drawn window blinds. I'm also fond of "agency" and "digital self-sovereignty" as alternatives.

But fine, I'll be the one to say it: Cloudflare isn't one of the good guys here and as an entity it shouldn't be trusted. It doesn't matter how pure their stated motives appear to be now, or how unmarred their track record is so far. It's a corporation that has control over an ever-increasing share of internet infrastructure, and is susceptible to the same risks as any other tech monopolist basket that we all decide to put our eggs in. Maybe more risky than the others, given how deep in the stack its influence is buried.

What happens when a government forces it to NXDOMAIN porn or put nuisance captchas in front of dissident blogs? Is there some reason people think this one is different?

iPhone Pocket 8 months ago

You're right, of course, but I don't think blame rests solely on the individual consumer here... I guess it's a bit of a chicken-and-egg problem, wherein Apple makes $200 knitted iPhone scrotes because they know people will line up to buy it, and people will line up to buy $200 knitted iPhone scrotes because Apple made them.

And people have brand loyalty to Apple stuff because quality, or design, or something... but for a product like this, which to me is prima facie a ridiculous, impractical, high-priced, fast-fashion item, you know that the marketers are cashing in on that brand loyalty almost exclusively (in the absence of any intrinsic value).

Half-baked thoughts, I'm sure people have written properly about this. But the conclusion I leap to is that marketing people are the great Satan here. Fuck those guys.

The way I see it, the suggestion that one can simply "vote with their wallet" is absolutely a pro-corporation stance because it pretends that consumers and megacorps have equal footing in the market. This premise is a bit of a spherical cow because it--conveniently for corporations--ignores monopoly, price fixing, anti-consumer corporate fraud at scale and flouting of regulations. Perhaps, in the frictionless vacuum of an Ayn Rand wet dream where every interaction is a transaction between two equals operating perfectly rationally, where there's no governments thus no regulatory capture, no barriers to entry, and so on, this might make sense--but in our world it does not.

You tell me that nothing will change the companies apart from market forces, but in response to another commenter you said it well yourself: "this kind of behavior should be illegal." If we had consumer protection laws, and those laws had teeth, maybe a company would have to consider the possible risk to future profits of engaging in the next abusive, ethically bankrupt scheme. It wouldn't be possible to be, as former FTC chair and antitrust warrior Lina Khan put it, "too big to care."

I'm not so naive as to imagine that more economic guardrails are a panacea for consumer suffering, but to me it seems that the globalized economy and its Western democratic hegemons have spent much of the post-WWII era on a deregulatory death march, and we can see with our own eyes how well it's going.

I wonder what the "free-market" types will say to minimize criticisms like those in this thread once everything that can possibly be purchased requires bending over for this sort of abuse.

Is the fantasy that some entrepreneurial savior will come along and voluntarily forgo all the massive spying profits in order to cater to the minute proportion of consumers perceptive enough to realize they're getting molested on the daily?

How about smartphones, for example? "Vote with your wallet," says the smirking corporatocrat, "and just buy a mobile operating system that respects your personal privacy." Alright professor, looks like my choices are iOS or Android, so I'm kind of hosed either way? Unless I want to return to a 2004 feature set, or perhaps a GNU/Linux paperweight with a 20-minute battery life that can't use banking apps or place phone calls?

I exaggerate (but in my opinion only slightly), and sincere apologies for tone--but it's quite frustrating to be met again and again with such a smug dismissal of what to many of us feels like an inescapable horror. This depraved race to the bottom, with every MBA-steered ship vying to see who can violate us the hardest, seems to be standard practice these days, and "purchase different products" puts the onus on consumers to fix what isn't their fault in a way that leaves an awful taste in my mouth.

Yep, downloading copies of videos so I can watch them on long flights is one of my main use cases for yt-dlp.

I suppose someone more sycophantic to the wishes of trillion-dollar corporations could argue that I'm not entitled to do this for free, and that YouTube offers an offline download option as part of its $13.99/mo Premium offering. To them, I'd say "you're right, also go pound sand lol."

Felony contempt of business model! The DMCA and its anti-circumvention provisions bring us a rich history of abuse, including such gems as "Lexmark suing a company that figured out how to interoperate with its ink cartridge business and thus give consumers more ink cartridge options" and "Chamberlain suing a company that figured out how to interoperate with its garage door openers and thus give consumers more garage door remote options".

I admit I don't shed many tears for the poor movie publishers, but even setting piracy completely aside, these laws are anti-consumer garbage. One wonders aloud if there are limits to the insanity copyright owners are entitled to inflict on their customers. How about surreptitiously installing malware on people's machines to make sure they play nice?[0]

[0] https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...

In summary, YouTube is A/B testing a change where specific clients receive only DRM-locked video streams. This is notable because yt-dlp impersonates those clients during normal operation. Since yt-dlp won't support decrypting DRM-locked videos, this change breaks yt-dlp's ability to download any videos.

To respond to your specific questions:

- innertube is the name for private YouTube APIs. (Here's a library that talks to innertube https://github.com/tombulled/innertube/, although yt-dlp has its own separate client code.) These APIs are intended for consumption by the various types of YouTube client software.

- The "tv" client is one of the types of client (see other examples here: https://github.com/tombulled/innertube/blob/main/innertube/c...)

- TVHTML5 is the specific client (as opposed to e.g. TVLITE or TVANDROID)... presumably different TVs run different specific TV clients, with consumption of different specific TV APIs.

- When yt-dlp downloads a video, it roughly performs this sequence of steps: pretend to be one of the types of clients supported by innertube; download the top-level video object; parse out the list of possible formats. These formats are like "MP4, 1080p, with AAC audio" or "Ogg, audio only". (The original issue report shows a better example in the verbose output dump.) By default, yt-dlp just grabs the best quality audio and best quality video stream, downloads them, and muxes them together into a single file, but you can configure this behavior. DRM formats are formats that are protected by (presumably) Widevine: https://en.wikipedia.org/wiki/Widevine, the decryption of which yt-dlp has stated will not be supported.

- Available means they're an option for our yt-dlp client to download. Videos don't necessarily have all formats for all clients; for instance, a video might not have a 4K option, because it was never uploaded in 4K. Or it might have a 4K upload, but YouTube won't show 4K options to a client that doesn't support 4K decoding.

- In this case, it means this specific internal client type can't download the video, because when yt-dlp reaches out, it gets ONLY formats that are DRM-locked. This is of note, I think, because the TV client is a way to get high-quality video from the YouTube API without having to pass it a valid YouTube login token (further down the issue, the reporter says providing a token allows the "web" innertube client to work).

I've rambled about this on here before, but I'm pretty bothered that the media coverage of these always mentions the 25-year import law, but also always frames it simply as a matter of exemption from safety and emissions standards, never deigning to mention that the law originated in the first place as a protectionist measure.

In the late 80s, Mercedes in North America was getting its lunch eaten by grey-market importers who were bringing European models over and undercutting the American dealers on price. So they blew millions lobbying the government to crack down on these imports, and found a not-wholly-unsubstantiated justification in safety concerns around modifications not complying with American safety standards. So the US just enacted a sweeping ban of any new imports; you can bring in dodgy old cars from the 1990s unmodified, but you can't bring in a 2024 European Mercedes or Japanese kei truck, because they're "unsafe". The new cars can't be titled, and if the feds find out you got one in anyway, they'll literally confiscate it and throw it in the crusher.

Seeing Whistlindiesel in the article makes me realize that there could be a bipartisan coalition here of "government should let me do what I want" conservatives and libertarians, and urban-design lefties who resent having to drive everywhere and would love to buy the minimum amount of car possible to meet their needs if such a thing were possible. My conspiracy theory is that burying the lede on this is intentional because people buying $12,000 Japanese imports wouldn't be buying $60,000 F-150s.

It looks like you're doing great work here, thanks a bunch; looking forward to seeing this project develop.

Selling custom integrations, managed instances, white-glove support with an SLA, and so on seems like a reasonable funding model for a project based on an open-source, self-hostable platform. But I'm a little disheartened to read that you're maintaining a closed fork with "goodies" in it.

How do you decide which features (better test suite?) end up in the non-libre, payware fork of your software? If someone contributed a feature to the open-source version that already exists in the payware version, would you allow it to be merged or would you refuse the pull request?

Nitter worked by signing in with special "guest accounts" that I think were given to fresh downloads of the mobile apps.[0] Last year, X fully disabled that functionality, which left most Nitter instances broken. At that point, the developer publicly abandoned/ended the project.

The couple of instances floating around that still work are, to my knowledge, forks of the original Nitter that have been upgraded to work with a pool of manually created X accounts, which is a relatively expensive and fragile approach that most instances probably aren't up for taking.

[0] https://github.com/zedeus/nitter/issues/983#issuecomment-168...

My understanding is that Nitter instances like this one, now that guest accounts don't exist anymore, depend on a pool of manually-created Twitter accounts. If the use case is people infrequently viewing the occasional tweet or thread, it's relatively easy to keep the pool of accounts healthy. If the Nitter instance is abused by scrapers or bots, its accounts will quickly be banned by Twitter itself, and the instance dies. So it's important to have anti-botting protections.

I've found that this instance works perfectly once you're past the bot wall. I'm not affiliated with it, but I use it daily and post it instead of x.com every single time I share a tweet.

Starting Hospice 2 years ago

Low-hanging fruit of dodgy medical claims aside: why would you post this as a response to someone announcing that they are shortly going to die from cancer? Is the intent to make the point that this person's current situation could likely have been avoided if they had simply followed a particular diet regimen? Or perhaps as a PSA to others who may currently be facing cancer themselves?

Irrespective of the value or veracity of the specific advice offered, to comment something like this here is supremely tone-deaf. Read the room.

As someone who has to interview candidates occasionally, I love the idea of a real-time interview copilot system. Here's why.

I see two main ways it could shake out.

In the less exciting case, the copilot isn't very good. It takes a long time, or produces assistance that obviously came from an LLM, or gets candidates regurgitating nonsense during the interview. In that case, I get a decent "don't hire" signal, for the same reason I wouldn't want to hire someone who was getting a friend to message them answers during a live interview.

In the more exciting case, the copilot is really good. It allows candidates who wouldn't otherwise pass the coding interview (whether for technical skill reasons, or behavioral reasons, or whatever) to breeze through like an expert. If this were to happen, I think it would massively devalue the "do LeetCode hards on a whiteboard" style of coding interview, and force interviewers to favor signals that are more relevant to real-world employee performance.

Well, until in the long run, the AI gets good enough to excel at all of the qualities that make human employees good employees... in which case we'll all retire to a life of comfortable, post-singularity, fully automated luxury gay space communism. Right?

Just what I want when I'm looking for information about a restaurant! An improv partner that hallucinates bullshit when I ask simple questions. Here was my experience: https://imgur.com/a/qRVO2DW

I'm honestly so over this stuff. Yeah, LLMs are cool tech and awesome for a few select use cases, but this is just an objectively poor concept for a service--to have any utility, this thing needs to be fairly accurate about things like menu options and pricing, and I can't imagine getting a better experience from a chatbot than a curated database like Google Maps or, you know, the restaurant website.

The big selling point here appears to be "personalized" recommendations, which I'm sure is code for "our service builds a dossier on you, then lets businesses bribe us for access to it; or, if we manage to build your trust, we'll also let businesses bribe us to skew our recommendations in their favor."

The latter case is how Google Maps works, but at least in their case the information you get around all the hyper-targeted advertisements is relatively accurate. We don't need more sleazy "platform" companies trying to plant themselves in the middle of value streams that exist because of Maslow's hierarchy, and the very last thing we need is companies that do this atop the half-baked technology du jour and end up serving up a steaming pile of functionally worthless spyware.

Huh, didn't know about "ChatGPT-User"... I've always been a fan of a slightly blacker-hat approach to this problem: rather than block those user agents outright, wouldn't it be way more fun to serve them nonsense or irrelevant garbage-filled versions of your pages?

VPP is really neat tech. I recently worked on a product that employed it, and it was impressive to see a commodity low-power CPU pushing tens of gigabits of traffic.