HN user

pieno

218 karma
Posts0
Comments45
View on HN
No posts found.
Cloudflare Warp 4 years ago

You have to click on one of the links to find out what this actually does in addition to Cloudflare’s 1^4 DNS server:

Enter our own WireGuard implementation called BoringTun. The WARP application uses BoringTun to encrypt all the traffic from your device and send it directly to Cloudflare’s edge, ensuring that no one in between is snooping on what you're doing. If the site you are visiting is already a Cloudflare customer, the content is immediately sent down to your device. With WARP+ we use Argo Smart Routing to devise the shortest path through our global network of data centers to reach whomever you are talking to.

[0] https://blog.cloudflare.com/warp-for-desktop/

The absolute, invariable first rule in tech writing is to know your audience.

While that’s definitely true for tech writing generally, I feel it’s usually not the best advice for someone wanting to improve their technical writing.

Tech writing is first and for all “writing”. I feel that’s where a lot of people are struggling already: they may know vocabulary and grammar, but they have difficulties to write a well structured text. Even a single paragraph consisting of two or three sentences can be very hard for many people to actually think about. They may have been focusing on “shortcut” rules such as “maximum X words per sentence” or “maximum Y sentences per paragraph”. But those are more often than not a distraction to actually think about a logically structured text.

It’s important to have a narrative to guide the reader through the text, presenting new pieces of information in a logical sequence, and anticipating how a reader could misunderstand what you’re trying to say. For fiction writers, coming up with a narrative feels natural (even if it still can be hard). However, non-fiction writers may not even realise that they need some kind of narrative.

You do need to know your audience to anticipate how your reader could misunderstand your text, but I think it’s best to start practising by writing for yourself or someone like yourself. Write something about a topic you know pretty well, but do not master perfectly. Then, read what you’ve written one or two weeks later, and see if it still makes sense to you. If some parts seem confusing, try improving them.

You could do the same with texts written by someone else: whenever you think the text is confusing or unclear, try improving itself.

Do not just quickly add a word or sentence that specifically addresses your confusion, but take a step back and try to understand what caused the confusion. Try to really think about the order in which information is presented, whether that information is explained clearly, and whether all information in your text is necessary to understand the point you’re making.

Totally agreed!

It’s a bit ambiguous, but the Apple App Store guidelines seem to require you to be able to opt-out from marketing push notifications, while still keeping other notifications.

From guideline 4.5.4: “Push Notifications should not be used for promotions or direct marketing purposes unless customers have explicitly opted in to receive them via consent language displayed in your app’s UI, and you provide a method in your app for a user to opt out from receiving such messages. (..)” [0]

The developer/user experience guidelines also recommend to have a clear screen to opt-in and out of different types of notifications, and never to abuse privileges (e.g. send marketing notifications with a “time critical” flag to break through focus mode etc.).

I really hated Uber Eats when I thought they were abusing their notification privileges to send spam. But I recently found out that they do allow you to opt out of marketing notifications while still allowing order-related notifications (although they really are pushing it (pun intended) by sending at least two post-delivery notifications asking for tips and ratings, which could easily wait until I actually open the app again or at least be limited to just one delivery confirmation notification). Not sure if they are asking for clear opt-ins for new customers (they probably assumed opt-in based on some general consent I gave before this Apple policy came into effect).

[0] https://developer.apple.com/app-store/review/guidelines/#app...

[1] https://developer.apple.com/design/human-interface-guideline... (“Sending Marketing Notifications” at the end)

Also, subscribe to a channel, get recommended their entire repertoire of the last decade. I have stopped subscribing, and I'm actively unsubscribing from most channels except the very small ones that post twice a year and I don't want to miss.

I fear that there is a very big group (that is usually not on HN) that actually likes this. People who get absolutely hyped on some new channel and just have to watch everything on that channel. Not because it’s interesting content, but because for those few hours/days/weeks they feel that they “belong” to the community of that channel (even if they don’t meaningfully interact or discuss with the other people in that community or even the creator). This also gives them social status with friends. Then after a few hours/days/weeks, repeat the cycle (multiple cycles can run in parallel but not too much as it would affect your social status of being part of the hip cult-of-the-day). Obviously those people also watch stuff outside that channel, but they don’t mind being presented with videos of the same channel all the time, because again bragging rights that come with “oh I’ve really seen everything, look at this: seen it, seen it, …”).

(Seems a bit similar to some other demographic that is extremely into watching sports…)

This was indeed a very deliberate choice by Google, and they have been blogging about it since at least 2011[0]. There are quite some blog posts by Google and others discussing the evolution in online maps from the high contrast design focused on roads and cities, to more “fluid” designs where there is a bit more room to show buildings, forests, waterways and other landmarks that are more suited for exploration rather than navigation.

[0] https://maps.googleblog.com/2011/07/evolving-look-of-google-...

This is pretty common in Europe. This may be different because regulation is usually a lot more flexible here regarding car lights (e.g. adaptive headlights) than in the US (although I understand the US is catching up, and there are obviously some areas where the EU has been more strict in terms of daytime lighting and side visibility, mostly for safety reasons).

Most German cars will flash the brake lights when you push the brakes hard, and they will also automatically turn on hazard lights if you brake hard to a (near) full stop (assuming you were going some minimum speed of 50 or 70 km/h).

ABS stepping in is not a requirement as far as I could tell (had this a few times when erring on the side of caution when the light turned yellow). Not requiring ABS makes sense because even if you’re driving on proper roads and your recent German car has great tires and brakes and doesn’t need ABS to decelerate quickly, the truck behind you probably still needs a bit more time and early warning to avoid a collision.

I think it’s actually the kind of simplistic analysis you are referring to that got us into this mess. If we would have put a bit more belief in the epidemic models and acted accordingly from the beginning, we would be a lot better off right now.

But even now, two years into the pandemic, the “people” and policy still seem to be unable to take any action until we see very widespread disastrous effects that were predicted weeks or months in advance. Even now, people still don’t care about an increase from 10 to 20 cases (or any other metric) and won’t take action until they see cases going from 1,000 to 2,000.

Remember the ridicule Merkel faced when she told journalists in summer 2020 that models showed that Germany would see a huge second wave by fall? That just seemed completely nuts to those journalists at the time given the very low number of cases at the time, even if there was already exponential growth again at that moment.

Wirecutter is owned by the New York Times Company and explicitly says they don’t get paid by manufacturers (except through affiliate links to Amazon) and recommendations are purely based on editorial testing. NYTCo really can’t afford to lie about editorial independence, particularly for something that’s not even their core business.

Quote from their site: > We work with total editorial independence. That means nothing appears on the site as a recommendation unless our writers and editors have deemed it the best through our rigorous reporting and testing.

Looks like an interesting project! But I feel like you are asking your users to put a lot of confidence in you to take everything you’re saying for granted. I’m not implying bad faith here, but privacy conscious people typically like to see a bit more detail and evidence of security, rather than general claims/statements.

For example, some things I’m wondering about and would like to know before considering giving the app a try:

* how exactly are you handling encryption? How do you avoid leakage of encryption keys/pass phrases through iOS device backups or other cases where your iOS account could be compromised?

* what does “end to end encryption” mean in this case? There is no sharing feature as far as I can tell, so it’s not about e2e encrypted communications. I assume in this case e2e means continuous encryption at all times (on device and remote) except when the user actually uses the app.

* how do you handle metadata? What’s the trade-off between ease of use (quickly finding photos or scrolling through my full photo collection) and encryption/security?

* how credible is a business model of €5/year/user for something that seems to require quite a bit of work to keep secure? Even if there’s no storage/server cost because you use iCloud storage, there’s still a substantial developer cost to have feature parity with similar photo storage apps and keep up with ever-changing App Store requirements and security developments.

Hope this helps to find out what your (potential) users care about and whether you could improve communication/marketing on those points :-)

Accessing material that has been deemed illegal enough to be the subject of a country-wide block is generally going to be a criminal offense.

That’s not the issue discussed here, I think. We’re not talking about someone circumventing censorship in their own country (which is obviously illegal in your own country).

What we’re talking about here are IP-based country filters imposed by websites such as Netflix or BBC iPlayer, restricting visitors from certain countries to access all or certain content. Circumventing that filter by using a VPN (thereby masquerading as someone in a “permitted visitor country”) is obviously going to be a breach of the terms & conditions of that website and/or license conditions of content made available. But the argument apparently raised by LinkedIn in this case is that this is also a criminal offence of gaining unauthorised access to systems (I.e. legalspeak for what’s colloquially referred to as “hacking”), which would likely lead to (more severe) prosecution and punishment.

It’s actually exactly the other way around: countries don’t comply with other countries’ copyrights, but they must offer the same level of protection to authors of works created abroad as they give to authors of works created locally (I.e. non-discrimination of foreign works/authors). And they must also offer a minimum level of copyright protection as specified in the convention. The egregious content removal remedies offered by the DMCA in the US are luckily not part of those minimum protections, so most sane countries have a more balanced procedure for content removal remedies.

I’d take this one step further: the whole system in Europe is designed to keep everyone at “average” wages across the board.

Due to the (extremely steep) progressive tax system, there’s a lot of friction in (serious) pay raises. Why give someone a raise of €1,000/month when at the end of the day they will end up with less than half that?

Or why would you keep working full-time if by working 4 days you only give up 10% of net pay? Your ‘hourly wage’ actually goes up.

And it doesn’t stop with progressive taxation: a huge number of expenses are income-linked. So with your net pay increase of €500/month, you also start paying a lot more for child care or loose other benefits.

Instead, you could start working 4 out of 5 days: 1 day less to pay for childcare, and the cost per day of the remaining 4 days also goes down because your pre-tax income went down by 20% (all while net income only reduced by 10%)).

So in the end I don’t think people are getting paid less in Europe simply because taxes are higher or because there are more general benefits, but rather because there are actual systemic incentives to getting paid less. And I think this really affects typical upper-average income, where realistic incremental pay raises just aren’t really worth it for a lot of people. There’s a hurdle to reach a much higher level of income (let’s say top 10% bracket) where the increase in expenses and loss of benefits becomes insignificant (or you’ve already reached maximum levels of income-linked expenses) compared to the massively higher income level.

Game of Thrones* has shown hollywood that there is an appetite for epic storytelling, and that people are willing to sit through 7 season of shows to be entertained by an engaging story.

I really want to believe this, but I’m afraid Hollywood understood GoT’s success as “people want to see dragons”. Even early TV reviews were focusing on the dragons part, and recommending other shows that had dragons (or Middle Ages fights).

A lot of Hollywood and TV reviewers apparently failed to appreciate that people may just have really like the epic story of a world, rather than a typical story of a couple of main characters. This is also apparent from the evolution the show went through, diverging into a more mainstream story focusing on main characters rather than the story/world itself.

Buying only 25% sounds good from Notion’s perspective but is absolutely the worst possible deal for Automate’s shareholders. The value of the remaining 75% Automate shares would tank after that deal because Notion basically owns you with their 25% shares, board seat and preferred contract.

I feel like they keep falling for the centralisation/decentralisation pendulum trap, which goes like this:

1. Teams in the organisation create some good products that solve specific discrete requirements, such as an email client, a document editor, text chat, audio calls, video calls, video conferencing, etc. This usually goes along with marketing slogans like “x, reinvented” etc

2. Someone comes up with this great vision of a single unified interface in which all those discrete apps are integrated. The marketing here usually includes terms like “seamless”, “enterprise” etc.

3. Some other people notice that the discrete products have become so tightly integrated that they are missing out on users that do not want to sign up for the integrated enterprise experience, but who just want the discrete product feature. Usually competitors will have stepped into that void created in step 2 and it’s easy to convince management that they’re leaving money on the table for competitors. Just extracting some features into a stand-alone product is sold internally as a quick-win (it never is).

4. Go back to step 2

I think a lot of sites are conflating cookie consent and GDPR consent. You only need GDPR consent when processing personal data, so you don’t need consent just for storing settings in a cookie (as long as those settings do not contain personal data or identifiers linked to personal data). But many sites will ask “GDPR consent” or claim “GDPR legitimate interest” for those settings cookies in any case (in my view that’s a dark pattern in itself because you’re actually making the side harder or impossible to use and thereby inducing visitors to just click the big green “accept all” button to get it over with already…)

What a dystopian world we live in when people/companies can just plainly and publicly say that they don’t agree and won’t comply with a binding law with supervision mechanisms and penalties, and still have the general public believe that there’s nothing we can do about it...

And mind you: we’re not (just) talking about the top-5 tech companies and 0.01% here. This attitude is shares by almost every other company out there, and I have a feeling (based on anecdata) that the issue is even worse in smaller companies who think they don’t have to comply because they’re small or because they’re a startup or because they just need to “move fast and break things”… and we seem to accept that…

But why ask for consent right away when someone just visits your website for the first time? Imagine that you walk into a shop and the owner starts harassing you right away, blocking your path and your view and nagging you whether you consent to them following you around the shop tracking what you’re looking at, what you touch, what you actually purchase, and then give the shop next door a call to tell them all about your visit so that they can all “improve your shopping experience by giving you personalised recommendations”. Pretty sure almost no one would keep shopping there. In fact, this is pretty clear from Apple’s new do not track option where Facebook said in their quarterly report that it’s really hurting then (contrary to their statements that all of their users already happily consented to tracking and that they’re actually doing their users a favour by tracking them).

What should really happen is that sites just stop asking for bullshit consent to being tracked. No one will consent to being tracked if given an actual, clear and explicit opt-in choice, if there’s absolutely no downside in refusing consent and no one is tricked into giving consent by dark patterns.

Websites should just abstain from processing personal data until the visitor does something that actually requires personal data (e.g. sign up, make a purchase, …). In those cases, most obvious processing of personal data can be done based on other grounds (performance of contract, legitimate purposes, …) so really there should not be any consent nag screens needed at all except for some very specific exceptional cases…

That’s actually the entire point: this should not be standardised. That would make it useless. The purpose of GDPR is that, in principle, you need consent to process personal data. The consent must be specific both in terms of what data is processed, and in terms of why it is processed. The consent must also be explicit (no opt-out or implicit consent by browsing a site) and voluntary (no coerced consent by refusing service for not giving away personal data that is not specifically required for the service you’re asking for). Standardised widgets are exactly the opposite of all that.

In a way it’s very frustrating to see all these nonsense cookie banners that absolutely do not comply with GDPR at all. Why nag visitors with annoying cookie banners when your website is just as “illegal” as when it wouldn’t have a nag screen at all. This is really the worst of both worlds.

Then again, it’s perfectly understandable for companies to comply just a little, as they can then start long arguments with regulators on whether their implementation is compliant or not and whether they are getting valid, specific, express and voluntary consent (rather than just getting fined right away because there’s clearly no consent being asked at all which would make it too easy for the regulator).

So I’m really glad to see someone picking up this battle to actually enforce GDPR and call out the complete joke/smokescreen that most companies have made of it…

I really don’t think Apple is consciously allowing these apps because they get profit either way. They’re very well aware that the long term success and profits of the App Store and the Apple ecosystem are based on users’ trust and frictionless experiences. In fact, Apple guidelines stressed pretty early on in the app store’s life (2010) that “we don’t need any more fart apps” in the App Store. I really don’t believe that they would risk their brand and image being affected by a very short-term focus on 30% commission on some scammy apps.

Also, more generally, even if this was conscious behaviour by Apple, I don’t think this really linked to “unregulated capitalism”. In any economic/political system you will find that some people serve their own interests while harming others or the public interest. Whether those “own interests” are amassing money, assets, power, access to goods/services or anything else deemed “valuable” in that system does not chance the dynamics of that basic conflict of interests which will cause trouble in any system. I’m afraid that’s human nature and there’s no system that can fully align those interests or avoid the negative effects of conflicts of interest.

Firefox 90 5 years ago

The maintenance service is not checking for updates. It is still Firefox itself that checks for updates, but instead of launching the updater.exe (which triggers the UAC dialog), Firefox will start the maintenance service and tell the service there is a new update. The service will stop Firefox, run the updater to install the new version of Firefox (which does not require a UAC because the service already has elevated permissions), restart Firefox (updated version), and then stop itself. So this is not your typical update service such as Java or Adobe have which continuously runs in the background, but rather an interesting trick to run executables with elevated on-demand of a non-elevated executable.

That’s the right to full erasure. Revoking consent for processing your data for marketing purposes should be possible at any time and as easy as giving consent:

“The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.” (Article 7(3) GDPR)

That does not mean that you cannot take a few days to process the revocation, but it does mean that you should handle it as soon as possible and the burden is on you as data processor to ensure you still have valid (non-revoked) consent before sending another mail.

No, the underlying issue is the US DMCA assuming that a takedown claimant holds valid copyright until disputed by the alleged copyright infringer, and absolutely zero real risk of liability for invalid takedown claims by copyright holders.

Google is “complicit” (at least in the moral sense, not sure about the legal sense) by providing a broken service that appears to be unable to distinguish different performances of public domain works.

But the principal legal and moral burden is still on the takedown claimant to represent that a certain video is indeed copyright infringement and not another performance altogether or fair use of copyrighted works. They should not be able to get away with large-scale false statements. Even for claims that relate to actual copyright infringement, they could not have a “good faith belief” of copyright infringement because they are simply relying on a known broken system (of Google) without appropriately verifying their claims, even after many successful disputes relating to the same issue.

It seems like you and GP are agreeing on the fact that right now we don’t do too many preventive checks because the cost of testing is higher than the benefits (mainly because false positives could lead to risky and invasive follow-up testing to confirm that it’s indeed a /false/ positive; and knowing that you have something sooner rather than later may not meaningfully affect the outcome of the disease; and costs of tests and trained personnel are huge).

But GP seems to be saying that they hope to see better tests in the future, that are not risky or invasive, don’t have as much false positives, and are less costly to do, so that the equation would change and we could actually meaningfully improve outcomes by doing large-scale preventive testing.

You would still likely have cases where you cannot /improve/ outcome by knowing sooner that you have a disease, but as long as you are not making matters worse and improving chances for a significant subset of people, all while keeping costs the same or even decrease costs, this seems like a great evolution.

If you agree to the statement that any accountant which uses Excel formulas to do bookkeeping is also a software developer

They are as much a software developer as they are a writer because they write e-mails; a presenter because they present the annual accounts to the CFO; and a cleaner because they put away their mugs at the end of the day (usually.. hopefully..)

You don’t have to be someone because you sometimes do something that other person also does.

I think it’s actually the other way round. The IRS, banks and insurers design and mandate use of their own forms, and if you you deviated one bit from their form they happily deny your request, or they will even just plain ignore you. They just have the power to put the burden on the user to fill in the form in a way that their system can process. That’s not really who this software is aiming at. Sure, the IRS e.a. can and probably will use these advanced extraction services, but only once the technology is readily available and reasonably priced.

Instead, this software is aimed at companies processing all sorts of documents with structured data, but without (very) strict form requirements (or with very low compliance with those requirements). Processing invoices is actually one of the best examples out there: every company has to do it, the basic data structure is nearly universally identical, and yet the form is so different and complex to process with general purpose tools (hence specially designed tools for invoice recognition). These companies may have found great value in processing these forms and may be willing to pay for advanced text extraction tools, because their only alternative is manual processing (aided) by humans.

Not the GP and I agree that as a mere user you’d not easily violate the GPL. But even as a developer it’s less free than you seem to imply: the GPL actually requires more than just distributing the source: you must also license the modified or additional code under the GPL. If you create “derivative works” of GPL licensed software, you are not free to distribute your modified or new code under a more permissive (non-copyleft) license such as the BSD license.

Note that you can find whole textbooks on what constitutes “derivative works”, but in any case it’s much broader than just forking a library. Basically any software that integrates the GPL licensed code (other than integration by way of loosely couples interfaces communicating via other means) is a derivative work.

For example, when your enterprisy application bundles and uses a GPL library to generate PDF’s of some of its data, the enterprisy application as a whole typically becomes a derivative work, which means (11) you must distribute the source of the full application together with any binary distribution of the app and (2) that source must be licensed under GPL.

I used WPF a few times when it just came out. Really enjoyed it (definitely compared to what was available at the time). I think a lot of people felt the same way but then Microsoft really killed it by being ambiguous on its future and not giving it any love or attention. Microsoft was betting on their new Universal/Moderm/Metro UI with JS-or-something but AFAIK that never really became a mature technology that could be used for anything other than simple “fart button” style apps. Only recently have they realised what a great technology they have floundered and started giving it some love again, unfortunately only after most fans had already left the party.

The risk of a coup is already covered to some extend in the GPL itself[0]. Article 14 which also governs the “or later” spec says: “Such new versions will be similar in spirit to the present version, but may differ in detail to address new problems or concerns.” It’s not crystal clear but you should be able to invoke this if GPLv4 would no longer be compatible with the basic idea of a “free, copyleft license” described in the preamble. You could then say that GPLv4 does not apply to anything licensed “GPLv3 or later” because GPLv4 is incompatible with that basic idea.

Also, any “relicensing” would only apply to changes made after the license change. You cannot unilaterally revoke the original “GPLv3 or later” license on works that are already released under that license (see the term provision in article 2 of the GPL).

[0] http://www.gnu.org/licenses/gpl-3.0.txt