HN user

onosendai

2,420 karma
Posts95
Comments68
View on HN
en.wikipedia.org 1y ago

Waggle Dance

onosendai
4pts0
csas.ei.columbia.edu 8y ago

OK, US government – see you in court

onosendai
15pts0
dingyichen.wordpress.com 8y ago

Startup Sequences of Shells

onosendai
32pts6
www.lieberbiber.de 9y ago

Ubuntu for mobile devices post mortem analysis

onosendai
1pts0
www.dmytri.info 9y ago

Hackers can’t solve surveillance (2015)

onosendai
3pts0
www.linux.com 9y ago

Chapeau Is Exactly What the Linux Desktop Needs

onosendai
2pts0
insights.ubuntu.com 10y ago

Notice of security breach on Ubuntu Forums

onosendai
39pts12
blogs.gnome.org 10y ago

Do you trust this application?

onosendai
7pts0
www.techrepublic.com 10y ago

Why the Linux Mint hack is an indicator of a larger problem

onosendai
2pts1
arstechnica.com 10y ago

Mysterious collector opens world’s largest private Apple exhibition in Prague

onosendai
2pts0
theintercept.com 10y ago

How DOJ Gagged Google Over Surveillance of Jacob Appelbaum

onosendai
5pts0
levels.io 11y ago

How I build stuff

onosendai
3pts0
arstechnica.com 11y ago

Russia publicly joins war on Tor privacy with $111,000 bounty

onosendai
9pts1
www.wired.com 12y ago

British Ex-Spy Launches Fund to Support Whistleblowers Like Snowden

onosendai
2pts0
www.theguardian.com 12y ago

Bletchley Park accused of airbrushing Edward Snowden from history

onosendai
8pts3
www.thoughtcrime.org 12y ago

A Crypto Challenge For The Telegram Developers

onosendai
1pts0
arstechnica.com 12y ago

Do bees know what they don’t know?

onosendai
1pts0
arstechnica.com 12y ago

To restore credibility, NIST will audit its standards development process

onosendai
2pts0
scummvm.org 12y ago

ScummVM The Movie - 12th Anniversary Celebration

onosendai
7pts0
www.salon.com 12y ago

Dave Eggers made me quit Twitter

onosendai
3pts0
www.locusmag.com 12y ago

Cory Doctorow: Writing in the Age of Distraction (2009)

onosendai
10pts0
www.aljazeera.com 12y ago

Hungary moves to criminalise the homeless

onosendai
2pts1
arstechnica.com 12y ago

Gabe Newell: Linux is the future of gaming, new hardware coming soon

onosendai
404pts300
www.ietf.org 12y ago

PRISM-Proof Security Considerations

onosendai
75pts20
libv.livejournal.com 12y ago

Intel & Mir: The point-of-view of a graphics driver developing bystander

onosendai
2pts0
coding2learn.org 12y ago

How We Were Trained to Lower the Drawbridge

onosendai
1pts0
www.demilked.com 12y ago

Secret Fore-Edge Paintings Found on the Pages of a 19th Century Book

onosendai
12pts0
boingboing.net 12y ago

UK censorwall bans VPNs

onosendai
3pts0
www.cyanogenmod.org 12y ago

CyanogenMod Account

onosendai
3pts0
www.schneier.com 12y ago

The NSA is Commandeering the Internet

onosendai
5pts0

I'm incredibly saddened by his passing away, even if it was expected given the recent decline of his health.

I'm not going to touch on his films, which are all special and definitely worth watching, but if anyone who didn't know him wants a primer on his complex, sometimes surreal, but I think ultimately endearing personality, then this is a nice introduction:

https://www.youtube.com/watch?v=TqZpi8zAqe0

Mechanical Watch 4 years ago

The first Eco-Drives came out in the mid 90s. If you look around you'll find quite a few reports from people who bought the very first ones, and which are still ticking away virtually maintenance-free for 25+ years and counting. My own, a dive watch with around 10 years, which has actually been used for its stated purpose, is also still problem-free and with zero maintenance so far.

The only thing you need to be mindful of with Eco-Drives is that you can't let it lose all charge. It can keep functioning in complete darkness for around 6 months, according to the specs, but if you do this enough times the battery will lose the ability to hold charge and will need to be replaced, and there are plenty of reports to this effect. If you're not planning on wearing it, just leave it somewhere that it can get natural light, instead of a drawer, and you should be good.

While mechanical watches are undoubtedly cool and elegant, they're not perfect timekeepers, and when they do need maintenance it's not something trivial which you can perform yourself. For my day-to-day watch I'll take an accurate quartz movement with virtually zero maintenance any day. In other words an Eco-Drive, or something similar.

Lobotomizing Gnome 8 years ago

I've been using dnf to continuously upgrade my Fedora installation between 24 and 28, and it's worked pretty much flawlessly.

It's gotten to the point that system upgrades are as boring as the regular stream of updates that you receive daily, the only difference being that every 6 months you get more updates than usual being pushed.

Remember when the first real tool you had to perform system upgrades on Fedora was called FedUp? It was quite amazing, not to mention unexpected, seeing Fedora go from being one of the worst distros to upgrade to one of the best.

They do acknowledge the source of the font:

"Hack has deep roots in the libre, open source typeface community and includes the contributions of the Bitstream Vera & DejaVu projects."

It's a bit disingenuous though. I'd call Hack a straight copy of Deja Vu Sans Mono, with a few very minor tweaks. On Linux using the TTF fonts I can't even see a difference in line height:

http://i.imgur.com/wxTr0at.png

http://i.imgur.com/OO1bJFE.png

The only glyphs I can tell which are slightly different are 'i', '0' and '_'.

It seems both NoScript and AdBlock Plus have become really permissive as of late regarding their whitelists. While ABP is a bit shady with their 'acceptable ads' deals, I believe in NoScript's case it's probably due to not wanting to break things too badly for less technically minded users.

Regardless, I've replaced both extensions with uBlock Origin. While UB in default deny mode is not as fine grained as NS, it does the job and doesn't compromise on default whitelists at the expense of a little breakage (gorhill is very adamant on this point).

I've also noticed that I retain information much better when I'm actually writing it down on paper, than when I take quick notes on a laptop. I don't know the cognitive basis for this, but I suspect that it has something to do with it being a much 'slower' medium to register information in. Somehow your brain is forced to focus on the information that's at hand, instead of immediately trying to skip ahead to what's coming up next.

I don't use moleskines though, they're way overpriced for the poor quality paper they offer (i.e. it's not fountain pen friendly, which is what I usually use). Spiral notebooks are much cheaper, practical and usually provide better quality paper.

Are services shuting down at greater rates that in the past decade?

Probably not, but the model has shifted and there's a greater offering of services nowadays. Given the choice available and all the niches covered, it's very easy to start using one of them and coming to rely on it for some facet of your life/work, only to have it shut down with little prior notice and leaving you out to dry.

The parent's point is that if you use locally running software without any dependencies on external services you're much more secure in the event you need to migrate away from them, since you can do it at your own pace and with much more control over the entire process. Also, if you're using FOSS, it makes it less likely the support will just cease since, if there's enough interest, someone else (even you) can carry it forward.

especially since Google (and many other cloud providers) don't provide any kind of easy client-side encryption options

That's like wishing printer manufacturers would provide an easy way to refill their ink cartridges. It will never happen because no company will knowingly undermine its own business model.

Google's (and others') model is to access and mine as much of your own personal data as possible, so the idea that you're in sole control of it is anathema to their stated mission.

It used to be that one was generally pretty well aware of exactly what data was handed over when using their services, since the interaction with them was carried out in a limited, well understood manner (browser window, gmail/search site). Since they now control the entire stack from the hardware up to the services, and for the most part the workings of the entire system are opaque, it's very easy to leak data you never intended to, which compounds nicely for them (and unfortunately for you) with their goal.

So, in short, your data will never be safe if you hand it over to someone whose goal is to monetize it by being able to read it.

As far as quick 'n dirty solutions go, if you're not overly concerned with security, you can always use "python -m SimpleHTTPServer" to serve all the files on the current directory over HTTP.

I also recall that KDE had a panel applet that pretty much did the same thing on the 3.x days (not sure it's been ported to 4.x)

I second this. I've been using youtube-dl for years and it's essential for viewing video content on your terms.

A little know fact that no one seems to mention about this tool is that, the name notwithstanding, it also supports many other sites besides Youtube (use --list-extractors for a full list, currently 108!)

This is a collection of quick shell recipes, so in that context it's perfectly acceptable. Besides, there are some environments where you can't just install packages willy-nilly, even if they're present on the repositories.

The quick 'n dirty recipe to test the disk write speed isn't ideal, since there's the buffer cache which significantly skews the results. A much better way would be:

sync && time sh -c "dd if=/dev/zero of=foo bs=1M count=10000 && sync"

Then just divide 10000 (or whatever value you choose) by the number of seconds elapsed and you should get a much closer approximation of the sequential write speed, taking into account completely flushing the buffer to disk.

I also moved away from Unity after about a year or so of using it (some good ideas, but too unstable for my taste), and instead of going Debian, which was my initial impulse, I decided to give Ubuntu Gnome a try. This is a Ubuntu variant that isn't talked about much, and it's still early days for them, but it shows some promise.

You basically get the same Ubuntu base you're used to with all the repositories and PPAs intact, which if we're being honest are probably second to none in the whole Linux landscape, with a pretty vanilla GNOME 3 stack.

The devs just put out a call for more contributors today (http://ubuntugnome.org/urgent-need-for-more-contributors), and I'd love to see this distro take off. I'm also interested in seeing how they'll handle the whole Mir situation.

Another option, which isn't 100% free but still manages to avoid the Google Play Services layer, which is what the article focuses on, is running an alternative ROM such as Cyanogenmod, skip flashing the Google apps package, and install an alternate package repository such as f-droid.org which features only FOSS apps.

Most alternative ROMs have binary drivers pulled from the official ROMs, but it should be no worse than running a Linux distro with, say, non-free binary firmware images which are loaded on demand for wireless cards, and you strike a better balance between a fairly open system and the latest hardware.

I believe you're right. The thing that probably stops most modern democratic nations from going to war, if we're being pragmatic, is the political backlash to its leaders stemming from the loss of citizen lives. If you remove this from the equation, nations will likely be more predisposed to engage in conflict; its leaders will be shielded from the most immediate downsides of war, and the population more predisposed to ignore it.

I've been using an X230 as my personal laptop for a while and I absolutely love it. Comparing it to my work T430, it's smaller, with a vastly better screen (IPS, albeit lower resolution) and on the whole it doesn't make too many compromises versus the T series.

I second the Lenovo service manuals. Behind the excellent Linux support they're the reason I buy Thinkpads. Not only can you completely disassemble them, reading through their service manuals it's almost like Lenovo encourages you to do it. Compared to this, a teardown of the 2013 Macbook Air makes for some pretty depressing reading: soldered RAM, proprietary SSD modules, proprietary screws, etc. I get why people buy the Air and Ultrabooks, but I'm glad the T and X series are still around and still dependable workhorses that you can service yourself with nothing more complicated than a swiss army knife.

I also got an Open, planning on using it as my everyday phone, at least for a while. My requirements for this role weren't too stringent, since it's a new platform. So the only two things it needed to do was perform and receive calls, and allow me to manage contacts.

It fails miserably on the second one. The only options to import contacts are through Facebook, which I don't use, and from a SIM card, which is what I ended up using. Pretty limited, to say the least, but the real kicker is that it has no option to actually export contacts. So if you use it for a while and decide either to wipe the device, or to stop using it, you have no option to retrieve contacts you've since added. I've investigated if it was possible to at least back them up using an ADB shell (it is, supposedly it's an sqlite DB), but apparently you need root on the device to do this, which isn't possible on the default install. I didn't investigate any further when I realized I was actually using Android debug tools at 3 am to get my contacts out of a supposedly consumer ready device.

Needless to say any software updates probably aren't forthcoming from ZTE, since even the upgrade routine fails with an error on these devices (https://support.mozilla.org/en-US/questions/967817).

Another thing that bugs me is that while Mozilla are distancing themselves, and their branding, from the likes of the Geeksphone Peak+ (http://techcrunch.com/2013/07/25/peak-plus), which as far as I can tell receives timely updates and has a vibrant community, saying it's not a Firefox OS phone, they're also busy directing people to the manufacturers (ZTE in this case) whenever there is a problem with the officially blessed Firefox OS version running on the first consumer grade FFOS phone.

Next time I waste more time trying to get basic functionality working, I'll just build my own updated images of FFOS (https://developer.mozilla.org/en-US/docs/Mozilla/Firefox_OS/...) and see if things have improved by then.

[dead] 13 years ago

Looking at the latest Tor Browser Bundle (2.4.17-beta-2):

it's trivial to break Tor IP address anonymity, as described on the Tor website, through the use of Flash, Java, and add-ons that bypass the typical port proxy

The bundle doesn't ship with any plugins enabled, the only plugin included in the package is Flash, and if you try to enable it it displays a warning explaining the risks and asking for confirmation before continuing.

The only extensions it ships with are HTTPS-Everywhere, NoScript, the built-in Firefox PDF viewer and Torbutton.

HTML tags that call out to FTP bypassing the standard web ports

FTP connections on the Tor Browser go through the proxy, same as HTTP connections. You can test this easily enough by looking at Vidalia as you open an FTP connection. Also the site makes it clear that FTP outside the Tor Browser must be manually configured to go through the proxy (https://www.torproject.org/docs/faq.html.en#FTP)

Tor traffic relies on an exit node, operated by an unknown person, that can sniff your unencrypted traffic

Tor provides anonymity, if you decide to pass unencrypted traffic through it, it's your responsibility. The site makes this clear enough (https://www.torproject.org/download/download-easy.html.en#wa...)

I'm not sure what to make of the rest of your argument, that companies such as Google have incentives not to abuse your privacy, while it's been show time and again that their only choices are to comply with secret government surveillance orders or shut down. Somehow, I think their incentives fall on the side of making money so I doubt they'll choose the latter. I mean, think of the poor stockholders left high and dry.

Yeah, now that I think back on it, Trine 2 had been out for some time by the time I got it through the Humble Store, which was what Frozenbyte used to sell the game outside of Steam and other DRM'ed distribution channels.

And I just got it again, apparently. Not sure what the 'Complete Story' edition is all about, but hey, more content can't be bad.

You don't find too many details about Kowloon floating around, which is a shame since it was quite a unique settlement.

The best source of information about it is probably a photo essay called "City of Darkness" (http://www.amazon.com/City-Darkness-Life-Kowloon-Walled/dp/1...) which is frequently out of print, but which I highly recommend if you can snag a copy. It's a fascinating historical document in its own right, and one of the few reliable sources of information about the walled city, which is why it's referenced so heavily in the Wikipedia article.

Monocle 13 years ago

Like you said, adding friction can improve things (you mentioned requiring proof of identity)

I said adding proof of a real identity would have some impact, but it would create more problems than it solved, thus it would not improve things.

The fact remains that adding any sort of friction should be expected to cut down the number of asses

It should also be expected to cut down on the number of users. My argument is that if your objective is to improve the quality of the comments there are more effective ways of doing it, like effective moderation schemes.

I don't see why requiring authentication via a service that's generally not anonymous (Twitter or GitHub) is a bad idea

Because it's not effective. It raises the barrier to entry, excluding several users who would add value to discussions, without providing any meaningful level of protection. Also, neither of them, as far as I am aware, enforces a real name policy, so I'm not sure what you mean by them being "generally not anonymous."

Monocle 13 years ago

I understand the purpose, I'm questioning its efficacy.

Monocle 13 years ago

Social accountability is provided by linking your Twitter or GitHub accounts

I never understood the reasoning behind this kind of social login. If you're dead set on being an ass, then you'll be one regardless, even if it takes creating a burner Twitter or GH account. Anything short of demanding proof of identity and linking your real name is useless (and now you have two problems.) All this achieves is forcing people to sign up to another service in order to use your own. A low barrier to entry with community moderation is enough to keep the value of the comments high, while keeping noise to a minimum.

Liferea is also what I'm using for the time being, but I think he's only listing cloud based Reader alternatives.

I've noticed an interesting side effect from using a desktop based aggregator that doesn't sync with a smartphone; while before I'd obsessively comb through new items throughout the day, sometimes even impacting conversations, now I read everything in one fell swoop when I turn on my personal laptop at the end of the day. No more pulling the phone out at awkward places and times, the productivity benefits, at least for me, are immense.

One could argue that it's down to discipline, but if you actually have a mechanism that enforces this behavior it makes things immensely easier.

Encrypting everything at the block level has gotten reliable enough that there are no excuses not to apply it to any and all kinds of mobile devices.

With Ubuntu 12.10 onwards you have the option to use dm-crypt for full disk encryption baked right into the installer. With 12.04 and earlier you have to use the alternate CD, but it's still painless. Android also uses dm-crypt for its FDE implementation, also dead easy to enable.

With a password manager for the rest of your passwords, and an SSH key for remote system access, you can manage everything only knowing three different passphrases.

Using FDE precludes theft protection programs, obviously, since an attacker wouldn't have access to a live OS. But if you're willing to forego a bit of fun (see https://www.youtube.com/watch?v=U4oB28ksiIo) and the chance to recover the hardware, you have a pretty solid guarantee that no one will get to your data.

And, of course, daily backups, which is another can of worms. Personally I just rsync to a remote system and offsite that data periodically.