Just look at Lisa Su or Steve Jobs.
It has a name, it's called "survivorship bias".
HN user
Just look at Lisa Su or Steve Jobs.
It has a name, it's called "survivorship bias".
speaking as a founder/CEO [...] Proven talent comes with a massive price tag, but it's almost always worth it.
I see no bias here /s.
Investors aren't dumb.
They are not dumb, just incompetent in the domains where they invest the money. And surrounded by yes-men because they are the ones writing the checks.
I like the current world better.
Think about that in the next years when you finally realise how screwed we are.
All bikes look the same, all cars look the same, all cameras look the same, all bridges, all dams, hell all smartphones look exactly the same! The whole goddamn point of UX is that you make something that is usable, and hence familiar to your users.
People who say "I was making GPUs before them, and they built their own GPUs that behave like GPUs so they copied me" don't understand how stuff is built. The hard part in engineering is not "imagining the high-level concept", it's actually making it work. Even if you can open electronics and study it to design and build your own, it requires a lot of expertise. And if you manage to do it, then you are an expert, period.
I'm sure many people find comfort in saying stuff like "You know what? I was a bit of a visionary because when I saw the first personal computer, I imagined that it would be cool if it could be orders of magnitudes faster and smaller such that it fits in a pocket". As if that was the hard part.
Typically, too many people spend a lot of time talking about UI and stuff like "unpacking" as if that was the most important part. But usually that's because they have no idea about how it works under the hood, so the only thing to discuss is whether the round edges are great or not.
Wait. I say "how does wasting 10% have more impact if you waste 10% of 10 or 10% of 1000?", and they answer "it's just not worth doing it for 1".
I just don't see how this is related to waste. Of course if it's not profitable when you sell 100% of what you produce, then it is not profitable (that's a tautology). My question is: why is it more profitable to sell the same amount but to waste more?
Turns out someone explained in another comment [1], and the "it's just not worth it for one mushroom" just does not explain it.
so might as well get the real deal.
Almost the same thing for twice the price, just for the pleasure of saying that you believe Apple was first?
1. PWAs load in the browser too
I keep getting that kind of answers, and it just tells me that people just don't get my one point about end-to-end encryption...
I don't think the e2e encryption argument really holds up, as you have to trust the app vendor too.
... and that shows a misunderstanding of end-to-end encryption again.
It does not matter whether it is coded in Javascript or not. What matters is how it works. If it sends the data in plaintext, it's not proper end-to-end encryption. If it sends the data weakly encrypted in such a way that it is trivial to decrypt, it is not proper end-to-end encryption. If it fundamentally dynamically executes code coming from the server whenever it wants, then it defeats the point of end-to-end encryption.
That means that for end-to-end encryption to work well, you have a bunch of constraints.
- The Signal client app is a good example: it's open source and it is distributed in such a way that you can reasonably trust it (i.e. it's reasonable to believe that Signal and Google are not colluding to attack you personally, and if you believe they do you can reasonably compare that you run the same app as someone else). This all makes it very difficult for Signal and Google to attack it.
- Anything that dynamically loads Javascript from the server and runs it is a poor fit for end-to-end encryption. Whether it loads in the browser (like web.whatsapp.com) or does something dynamic that allows the server to modify the code you run this one time and without leaving a trace, it does not matter. The fact is that everything that you load in the browser works like this, so a simple rule is that everything that you load in the browser is a poor fit for end-to-end encryption. Then of course because it is an app does not mean it is a good app, but that was never my point.
What difference does it make?
I think it makes a difference.
To find other examples, I don't find it unacceptable that Samsung doesn't try to support GrapheneOS on their phones, even though it would benefit their users and I. Or that Google doesn't support misp for Android. Because I like RISC-V does not mean that Microsoft should be forced to support RISC-V. And because I like Erlang does not mean that Linux should accept Erlang contributions into the kernel.
I don't find it unacceptable that Apple doesn't work on supporting Asahi Linux. But I would find it unacceptable if they added some kind of hardware attestation that would prevent it from running.
It's the difference between "I will not help you do what you want" and "I will block you from doing what you want".
Right. Yeah it seems like we agree. My point is that if you dynamically run code coming directly from a server, you have to trust the server, and that is fundamentally a problem for end-to-end encryption.
I totally agree that PWAs count as apps and are eligible for end-to-end encryption (as long as they don't dynamically run code coming directly from a server). I don't know exactly the story on iOS though, I just know that I like "native apps" better then PWAs, but that's a preference.
I'm just trying to condemn Apple's preferential treatment of native apps
Are they actively working against PWAs, or are they refusing to spend resources supporting another technology? I could understand that they don't want to go out of their way to add new "features" they don't care about.
It sounds to me like saying "I don't really care about football except the finals of the world cup. I wish we discovered alien football, that would interest me".
I get the point, but it sounds like you just don't care about football in the first place.
I can't tell if you genuinely don't understand the difference between "installing a signed archive once and then running it multiple times" and "running code dynamically in a browser that is fundamentally made to be able to change next time you hit refresh".
Whatever you load in your browser is not signed, and it's not saved.
A PWA does not run in a browser, it is a browser. The question with it is whether you get the benefit of an app (you download it all at once and run it) or if it's just shipping a browser for wasting resources but then it still loads and execute the code dynamically everytime you open it (which again defeats the purpose of end-to-end encryption).
And you'd be right. None of that is practical. Why is that?
Well it's a design decision. It's just not made for that. If it loads in the browser, it's fundamentally not made for end-to-end encryption. Now you can use webtech and build an archive that behaves like an app. I am not saying that "Javascript cannot do end-to-end encryption". I am saying that loading a webapp (that is, in the browser) defeats the purpose of end-to-end encryption.
Is it some inherent difference between native code and code running in a sandbox? I think not.
Again, native code running on iOS and Android do run in a sandbox. You can always run code in a sandbox, it does not have to be webtech.
And it does not have to be "native code" to qualify as an app. You can use Javascript to develop an app. The difference is not in the tech itself, but in its distribution. A webapp is distributed dynamically in a browser, and as such it doesn't work with end-to-end encryption because a webapp assumes that you trust the server. That's fine in many situations (like talking to your bank), but not for end-to-end encryption, period.
Aren't the undiscovered ones just different colored insects or jellyfish?
I was answering to someone saying that they would dream of seeing animals from another planet. Pretty sure that they (like everybody else) cannot list 0.01% of the insects out there.
If one is interested in animals, there is more to discover on Earth than what they can realistically do in their whole life. Being interested in alien animals feels like "I don't actually care about animals, but I find the idea cool".
I just don't get how it is cheaper in total to produce more units and throw them away.
If you make more units, it's cheaper per unit. But doesn't it mean that waste is always a loss?
Right. So what you're saying is that instead you should be allowed to go in the forest to get another 99 mushrooms, give them the same treatment, and then throw them away? And suddenly it's worth it for one mushroom if you threw away 99 other mushrooms in the process?
And as a result you get monopolies like TooBigTech and you can't compete anyway.
I mean at this point they may as well have a deal to let the mafia steal cars in the parking lot and share the benefits...
Isn't that law exactly trying to avoid that kind of waste?
Hmm... say you estimate that you will sell 1000 items of "normal size", you stock 1000 items, and hope that you sell all of them. You end up selling 900, you have a remaining 10%.
No say you estimate that you will sell 10 items of "less common size", you stock 10 items, and hope that you sell all of them. You end up selling 9, you have a remaining 10%.
How does that make a difference?
Sometimes? It happened more and more and when every second question was like this, I left. I wasn't going to fight against moderators forever.
That was before AI.
Happened to me as well. People would close it as duplicate when it clearly was different, they just did not understand the question themselves.
I personally left SO because I felt moderation had become toxic, and that was before AI. And I was relatively active, like in the top 5%.
This. I left SO before AI because moderators were terrible.
Then they started literally falling out of the sky.
Yep, something must have gone horribly wrong with QA.
You can downvote me as much as you want, but that's a genuine question: there are more species on Earth than any of us know. Before hoping to find new animals on new planets, why not caring about what's on ours?
This is only true if you are using apps that require no communication with a server
End-to-end encryption is all about going through an untrusted server. You don't need end-to-end encryption otherwise.
Otherwise it's constant forced updates
There are apps that allow you to verify that you are running the same signed binary as others. Think key transparency but for apps. It's trivial to do.
basing security on the version number of the installed app
Obviously you don't base your security on the version number of the installed app?!
since you can't guarantee the server will send the same replies to 2 different users
With a website, you cannot. When you open protonmail.com in your browser, you don't know if you are running the same code as I am when I do the same.
With a mobile app, you can. You get a signed binary, it's trivial to compare. Also even if you don't check that, if you get the Signal app through the Google Play Store, it means that the app is signed by Signal but distributed by Google. They have to collude in order to have you get a different binary.
I can't parse the part about e2e not making sense for webpages.
It's what I'm saying above:
- If you audit the Signal sources, compile them and run them, then you don't have to trust the server.
- If you use the Signal app distributed by Google, you can trust that you got the same app as everybody else who downloaded it through the Play Store, unless Signal and Google collude.
- If you open protonmail.com in your browser, you have to blindly trust that the Proton server is sending you the code you expect. But if you have to blindly trust the server, then it's not exactly end-to-end encryption anymore, is it?
This is pretty funny distinction to make
Is it? Wikipedia says: "A web application (or web app) is application software that is created with web technologies and runs via a web browser."
It's hardly a surprise you find web apps inferior if you define them so.
Then I guess we agree :-).
A browser adds cross-platform ease for devs and a sandbox for security at a slight performance cost.
Mobile apps also run in a sandbox. But a sandbox does not magically remove all security concerns.
My point about security was regarding end-to-end encryption. If you don't trust the server, then the model where you dynamically execute whatever the server sends you every time you use the app is fundamentally a problem. I assume it is the reason why you cannot run Signal in the browser even though they distribute an ElectronJS desktop app (I believe it's ElectronJS?).
A store adds gatekeeping (for better or worse) and a 30% tax.
Sure, but that's not all of it. A store adds a third-party intermediary:
- If Signal wants you specifically to run a modified version of their client that will leak your key to the Signal owners, they have to get Google to serve you a different version of their app, and hope that you don't compare it with someone else (which you can trivially do with an app). In other words they have to collude, and if you really care you may well realise it.
- If Google wants you specifically to run a modified version of Signal that will leak your key to Google, they have to make the Signal Foundation sign their modified build, otherwise your phone will refuse to install the update. They also have to hope that you don't compare it with someone else. In other words they have to collude, and if you care you may well realise it.
- If ProtonMail wants you specifically to run a modified version of their web client that will leak your key to Proton, they can just serve a different version of the client this one time only, just for you. They don't have to collude with anyone else, AND there is absolutely no reasonable way for you to realise it.
It's not "UX choices", it's the difference between "reasonable end-to-end encryption" and "having to trust the server".
You have no rights whatsoever to question what a person is willing to put into an open source project.
You are being manipulative. In your sentence, "to question" means "to challenge, dispute, or express doubt about". When I said it was a fair question, I said it made sense to wonder why one would invest so much into a project and not be willing to invest $200, which is obviously perceived as marginal by the person who asked the question.
A constructive answer may be: "because they can afford working on this in their free time for 10 years, but they cannot afford spending $200 on it". Another one may be: "you are over-estimating what $200 of AI would do there, if it was enough they would probably do it". There are many ways to engage in a constructive manner.
Now talking about mirrors, let me quote you one last time:
It seems that you still haven't realized the gigantic hole in your arguments
educate yourself before posting meaningless texts
So that we still have animal to kill in our lifetime, after the ones on Earth are all extinct?
Many people use phones with years of missing security patches
Right, yeah that's actually a good reason to use GrapheneOS.
It doesn't specifically need to be a GrapheneOS device, but it's a good choice in general and doesn't require being technically savvy to use or even install it.
I totally agree here. Very good choice, and I would argue that a "normal" person wouldn't make the difference between GrapheneOS with sandbox Play Services and stock Android. Installing may be intimidating, even though the GrapheneOS installer is extremely impressive (it just works and doesn't require any knowledge). Still normies tend to get intimidated just from the idea of reinstalling their system :-).