HN user

saintfire

497 karma
Posts0
Comments179
View on HN
No posts found.

I mean his device was pwnd completely. Its not a stretch that attempts to warn are suppressed.

That or he didn't notice or could have assumed the notice itself was one of many phishing attempts against large orgs.

If I saw a notification that my account was compromised by Pegasus I'd personally assume phishing.

Immich 3.0 20 days ago

Maybe I'm missing something but the linked discussion has a link to a closed issue that links a PR that added the feature you say is missing.

Limited by material. They store electric charge by using thin layers of insulating material and pooling negative charge on one side and positive on the other. You can puncture the material and release energy as a typical conductor, it's not stored chemically.

I hate compilers 1 month ago

It chooses the challenge weight based on signals. If your phone looks like a phone from a residential IP you get a simple challenge.

If you then spam requests you might get another, harder, hallenge appear.

If you have a data center IP and look like bot traffic you get a hard challenge out the gate.

AFAIU after looking at their docs several months ago.

Push based, sure. Allowing SMS, I still hold, undermines all of this.

They "secure" this behind password which you entered to trigger the SMS push in the first place.

Offering an "out" to a more secure flow means your secure flow may as well not exist.

Additionally, phishing a pushed OTP is not really much harder since you can trigger the push and then just have the user finish off the flow for you, provided they don't read the IP or whatever you display them (they won't, they think they're signing in), effectively the same as a TOTP.

I can't tell if this is satire.

DeepSeek did the same thing the american companies did on a much smaller scale.

They took the output of one company and trained a model.

American companies took the output of all IP they could illegally* acquire and trained a model.

The world does need protection from abusers, you're right.

EDIT: illegal in some cases (see 82TB of torrented ebooks), immoral in most.

Anecdotally, I don't know anyone who picks up random tools, unrelated to AI, because AI is advertised.

Usually when I see people see a pop-off for Try our AI assistant I hear "Fuck off" or "leave me alone" while they close it. It's like everything has a modern Clippy.

Personally I do see it as a VC signal, as if they gave up on making a good tool and started working on slopifying it.

60% is lower than I imagined, tbh. Most people aren't doing agentic workflows and AI is likely not a selling point.

I use a basic OTP password instead of Microsoft's ironically less secure (see SMS as 2FA) with my work MS account. Perhaps your org disabled it but it is definitely something a Microsoft account can do.

And yet, I incessantly get spoofed numbers calling me from the same "central office code". Also resulting in people with the same code "returning my calls" and then getting angry that I say I didn't call them.

Preventing number spoofing would help significantly with spam calling. At least the ones from local numbers.

I see everyone coming up with an arbitrary date of when Google lost their moral compass that aligns with their own moral compass. In that vein, I feel like when Brin and Page released a paper stating how PageRank could never be beneficial to a consumer with ads and then launched an ad company powered by page rank is when Google became evil.

Siri AI 1 month ago

Nor have they been keen on letting users OR devs customize the ui.

The unused variable error drives me insane

If they wanted the release build to be an error I wouldn't care. Having the current solution be "have the editor automatically change code to include or remove the underscore" is so wrong to me. Just invented a problem that needs tooling to modify source code to fix.

Maybe they already did and the answer was in some way lacking so they asked a peer.

Being mentored is infinitely better than a text box spitting out subtly wrong answers.

If I ever start using any query strings, I’ll allow only known parameters.

They aren't saying the concept of query strings are bad, They're saying unsolicited query strings during referal are the issue.

I've found widewine a blessing because news sites that autoplay trash seem to be the only group that uses it (other than paid media platforms like Netflix and Spotify).

The blessing is I can just reject it and it blocks all their videos from playing/downloading.

Its hyperbolic but hits the point.

I've helped multiple coworkers (in a non-computer related field) sideload F-Droid for a few spyware/ad free apps they liked the look of.

Id sideload my own phone using adb but I'd tell them theyre out of luck.

I'm in a similar boat, but I've found where I once habitually put things in the same workspace every time and was able to trivially recall them, I now end up all over the place.

Also I've been missing scratch deeply.

I'm sure it's solvable with some diligence and config changes, but I haven't invested the time yet.

Every self checkout around here has an employee staffing ~6 terminals. They're supposed to be watching for things like that. Usually theyre just staring vacantly into space, which I get, that job pays nothing and provides 0 mental stimulation.

When you see a TV being purchased, though, it wouldn't be hard to just watch that it in fact got checked in as such.

Sort of a funny example since "batterygate" centered on degraded iPhone batteries in which Apple argued the best possible move is to throttle phones so they don't shutdown unexpectedly.

Most people would argue the best outcome is spending <100$ and 1 min of your time to have your phone restored to like-new speed.

You say this matter of factly and yet I've seen countless people talk about using termux more than a desktop shell.

Maybe iPhone is different but most phones you can connect a keyboard to, making the shell pretty usable. Not my cup of tea but I have tried it. I'm still holding out on the dream that a good Linux phone might exist one day.

Not really. It's not the same program at all. They just took the name for an inexplicable reason. They even had to make a paragraph disclaimer stating it isn't and never will be the same program.