HN user

schoen

22,439 karma

Hi!

I'm Seth, previously of EFF, more previously of Linuxcare. Also https://jhalderm.com/pub/papers/letsencrypt-ccs19.pdf and https://jhalderm.com/pub/papers/coldboot-sec08.pdf (both with Alex Halderman) and some other stuff.

I'm currently working at Blockstream https://www.blockstream.com/, and I'm not posting here on their behalf unless I specifically say so.

Posts54
Comments5,986
View on HN
en.wikipedia.org 9mo ago

Dance Marathon

schoen
1pts0
ip.topicbox.com 2y ago

Gordon Bell Has Died

schoen
8pts1
contemporary-home-computing.org 2y ago

Turing-Complete User (2012)

schoen
1pts0
lfpress.remembering.ca 2y ago

A. K. Dewdney has died

schoen
175pts44
en.wikipedia.org 2y ago

A. K. Dewdney has died

schoen
5pts3
news.ycombinator.com 2y ago

Ask HN: Was there a specific SaaS "clone" scandal for an open source project?

schoen
4pts4
news.ycombinator.com 2y ago

Ask HN: Delayed open source licensing / “eventually open” examples?

schoen
10pts5
zetter.substack.com 2y ago

Interview with the ETSI Standards Organization That Created Tetra “Backdoor”

schoen
2pts0
spacetypegenerator.com 3y ago

Space Type Generator

schoen
1pts0
www.youtube.com 3y ago

"Honoring the Work & Legacy of Peter Eckersley" at the Internet Archive [video]

schoen
9pts1
www.trendingbuffalo.com 3y ago

Everything from 1991 Radio Shack ad I now do with my phone (2014)

schoen
3pts2
news.ycombinator.com 3y ago

Ask HN: When did people stop being told not to eat or drink around computers?

schoen
23pts28
berkeleydailyplanet.com 4y ago

Thomas Lord Has Died

schoen
6pts4
blog.robertelder.org 5y ago

Why is it so hard to detect keyup events on Linux? (2019)

schoen
3pts1
aroberge.github.io 5y ago

Friendly-Traceback: Simplified Python tracebacks translatable into any language

schoen
3pts0
eff30.cat 5y ago

EFF 30th Anniversary Puzzlehunt

schoen
2pts0
www.project-disco.org 6y ago

Summaries of all 29 amicus briefs supporting Google in Oracle vs. Google appeal

schoen
9pts1
dl.acm.org 6y ago

Let's Encrypt: An Automated Certificate Authority to Encrypt the Entire Web

schoen
2pts1
news.ycombinator.com 6y ago

Ask HN: Does old concrete reveal information about air quality?

schoen
88pts17
www.eff.org 6y ago

Open Letter from Governments to Facebook Is an All-Out Attack on Encryption

schoen
530pts218
blog.torproject.org 7y ago

Tor's Open Research Topics (2018)

schoen
97pts10
blog.torproject.org 7y ago

Tor's Open Research Topics

schoen
1pts1
en.wikipedia.org 8y ago

Eutely

schoen
2pts0
community.letsencrypt.org 8y ago

ACME v2 and Wildcard Certificate Support is Live

schoen
1024pts310
www.eff.org 8y ago

John Perry Barlow has died

schoen
1485pts126
www.eff.org 9y ago

Let's Encrypt Has Issued 100 Million Certificates

schoen
2pts0
www.nytimes.com 9y ago

Mexican Newspaper Shuts Down, Saying It Is Too Dangerous to Continue

schoen
769pts413
www.eff.org 9y ago

Digital Privacy at the U.S. Border

schoen
3pts3
tcec.chessdom.com 9y ago

Season 9 Top Chess Engine Championship Concluding Today

schoen
2pts0
noncombatant.org 10y ago

Chris Palmer on Getting into Security Engineering

schoen
1pts0

I don't think I understand your criticism.

The etymological sense of the Pennsylvania Dutch phrase is in fact, as far as I can tell, 'high people' or 'fancy people'. This is not the literal meaning or connotation of the phrase in Pennsylvania Dutch today. I did not think (and the LLM did not claim) that the phrase is used in Pennsylvania Dutch with this meaning, or that it was borrowed from standard German at any time. Essentially, the LLM helped me find recognizable cognates to understand how the phrase originated.

I asked an LLM to help me find the standard German equivalent for "hooche Leit", and it said "hohe Leute" 'high people' (here in the sense of 'fancy people'), which of course doesn't have the same connotation, but that's the etymological sense.

I worked on an Alien Tort Statute case that actually went to trial (https://en.wikipedia.org/wiki/Bowoto_v._Chevron_Corp.) and have met some of the people who litigated this case against Cisco as well as other Alien Tort Statute cases.

For a few years, peaking in the late 1990s and early 2000s, the U.S. courts seemed to accept that the First Congress had (maybe accidentally!?) created a statute that allowed foreigners to sue U.S. companies for complicity in human rights violations that took place overseas. It's actually just a single sentence: "The district courts shall have original jurisdiction of any civil action by an alien for a tort only, committed in violation of the law of nations or a treaty of the United States."

In some modern alien tort cases, the companies were accused of helping foreign governments commit such violations, as in this case; in other cases, the companies were accused of asking the foreign governments to do so (to protect their interests).

What we see here is basically the Supreme Court completing a process of saying that that's not actually what that old law is about and that it can't be used this way, pretty much at all.

I understand the issue that the First Congress probably didn't intend such a broad notion of "the law of nations" and also possibly didn't intend to create indirect liability for those who play a role in these abuses without actually carrying them out. (The decision notes that there's a much more recent statute that allows suing actual perpetrators: it's clearly just harder to get them into court in the U.S. most of the time.) It's kind of sad because the practical reality is often that courts in many countries aren't very independent, so a lot of victims of various abuses find it hard to get a domestic legal remedy for what's been done to them.

In this case I recall there was some strong evidence that some Cisco employees knew that they were being asked to help the Chinese government identify Falun Gong members (and that the government would probably do bad stuff to those people), and that they even gave monitoring Falun Gong as a use case or example in some of their product marketing. What we're told by this decision is that there isn't a clear U.S. legislative basis for a legal remedy against Cisco for this, if almost all of the relevant actions happened in China.

Maybe this is an opportunity for an attempt to amend U.S. law to state that U.S. companies have some responsibility to stop their foreign subsidiaries from doing stuff like this (although the actual legislative definition of "stuff like this" would presumably be a thorny question).

I really believe in technological progress and would strongly defend and advocate for it. I'm also very distressed by the idea that we have an absolute ratchet of more surveillance (and registration, monitoring, and licensing of people and their daily activities) over time.

My intuition has always been that these things don't have to go together, but it's often sounded like a number of people who've thought about it a lot expect that they do! (One reason is that technological advances create new technical means of surveillance and new technical means of data analysis which can include more storage and analysis of personal data. Another reason is more like Kaczynski's account above, that people are afraid of bigger or more frequent harms that can be caused by more-empowered individuals, so they put in place more restrictions or surveillance to try to mitigate or deter some of those harms.) Can anyone reassure me about this? Is there a future in which people have greater capability, and there are also fewer institutions or mechanisms proactively monitoring us?

I'm aware of portions of the history of that conversation but would love to hear your take or the take of other HN members.

Those cases are going to implicate significantly different legal doctrines (e.g. the former might be covered by the CDA immunity and the latter is probably not), but I imagine EFF would historically have preferred to protect the services from liability in both cases. I can't prove this conclusively because the issue didn't come up in a similar form while I worked there.

If it was about capabilities of downloaded software, I don't think it would even be a close question. For cloud services I can see that it can get more complicated, because the service operator would be straightforwardly able to choose to have more knowledge or choose to exercise more control. (But in other cases where the services had a somewhat more passive role, EFF regularly argued that companies shouldn't have to proactively monitor how people used them, even if they could.)

There is some clear disapproval of Grok's capabilities in the end of the second section:

X Corp.’s flagship product since its identity change—a generative AI model called Grok—has created shocking amounts of child sexual abuse material (“CSAM”) and other nonconsensual sexual imagery. X Corp.’s generation of CSAM and other nonconsensual imagery was so egregious that it sparked several investigations and lawsuits, including by a bipartisan coalition of 35 state attorneys general and international law enforcement.

I guess it is complicated by the context that the letter goes on to claim that these capabilities were partly enabled by misuse of personal data (the underlying issue before the FTC here), which leaves open some possibility that EFF would agree that X should not be liable for users' use of Grok if it had been created by some other means.

The novel thing for EFF here, as I see it, isn't the idea that some uses of computers are illegal. Rather, it's the suggestion that tech companies have a duty to police or restrict users' use of their technology.

When I worked at EFF we argued in about 20 different contexts that tech companies are not responsible for user activity even if they know that some of it is unlawful in some way, and that tech companies do not have a duty to restrict users in order to deter some kind of unlawful behavior.

We said that about copyright infringement (again and again and again, including before the Supreme Court in MGM v. Grokster), about counterfeiting, about housing discrimination, about distribution of existing child porn, about manufacture of weapons, about evading law enforcement surveillance, and about every kind of tort in content moderation (the intermediaries do not have a duty to prevent people from publishing content that civilly harms others). Oh, also money laundering with cryptocurrency mixer code. And prostitution.

In every case EFF's position was that there might be unlawful ways to use technology but the technology developer or operator didn't have a duty to prevent or discourage it, or to design the technology to prevent or discourage it, or to help the government or private parties catch people doing something unlawful.

I know there are several different legal doctrines in play there and some of them may have limitations in terms of actual knowledge (although EFF usually also argued for defining this narrowly!), so maybe one could argue that if Grok obtains actual knowledge of some improper use that it might have a duty to prevent that use in that case. But it would have been historically exceptional for EFF to say that there was a general duty to design technology to deter or detect any form of unlawful use.

There may also be a distinction in several of the relevant legal doctrines between inventing a technology (or making it available to others to use themselves on their own devices) versus hosting it on a cloud service, where the operator has more knowledge and more control than in other settings. EFF still historically preferred in basically every case to try to minimize the technology creator's or operator's liability for what users did.

I appreciate the balance here.

Some of the smartest people I know have worked on fighting NSA, but they had a drastically smaller budget than NSA itself, and the mental availability bias is skewed by the fact that the "fighting NSA" people talked about their work all the time, while the "being NSA" people generally didn't.

I do know one extremely smart person who went to work there, and I witnessed a failed recruitment of another extremely smart person.

I worked on these cases at EFF and I'm skeptical of the automatic "NSA has access to everything" intuition.

What we learned from that era includes things like

(1) spy agencies are incredibly aggressive and pursue tons of different angles to get access to things

(2) spy agencies have a lot of money

(3) spy agencies often have interpretations of law that would surprise the public or legal experts (and sometimes courts have issued sealed rulings permitting them to do things that surprise the public or legal experts later when they're unsealed)

(4) some people throughout different parts of society assume culturally that companies in a country "should" generally help the spy agencies of that country's government because they are the "good guys" or "on the same team" or whatever

These things are all pretty bad and scary, but they still don't imply absolutely infinite power or access, because all of them come with different kinds of pushback. People also just tell them no!

I want to write an article with a colleague about the continuing role of culture here, because I think there are companies or industries where the default reaction is to want to cooperate with the government, and others where the default reaction is not that.

There are certainly secret things that have never come out, e.g. whatever Senator Wyden keeps alluding to, and what kind of program or authority was behind the interception of hardware shipments to covertly tamper with them, and whether there is a bulk financial data interception program, and presumably lots of other stuff. I don't agree with these things, and I want them to be exposed and stopped, and I also don't think they constitute infinite power over all parts of the tech industry.

Same here. Also, I studied Latin and Greek in school and have kept studying them in various ways since then. I think this test is significantly biased toward vocabulary with these origins; dozens of tested words are directly recognizable as the "ordinary" Latin or Greek words for some concepts, or direct combinations of common Latin or Greek roots.

A lot of prestigious and scholarly vocabulary in English has come in through Latin and Greek (at various points in the history of English!), so you can learn that vocabulary or make it more memorable or more transparent either by studying Latin and Greek as languages, or just by studying some of their common morphemes (e.g. there are lists of Latin and Greek roots that may be given to medical or life sciences students to help them learn to recognize the meaning of terminology coined from these languages, even without speaking the languages).

But I think it's actually unrepresentative of the English language as a whole if we're literally thinking about vocabulary size rather than historical prestige of some part of the vocabulary. For example, foreign foods like "nori", "pandan", "dolma", "vichyssoise"[1], or "berbere" are often used as English words and would probably appear in large English dictionaries nowadays. None of that was tested in this quiz. I saw one foreign political term which I guessed at, and one or two German loanwords which I knew (I've also studied German), and almost everything else was Latin or Greek origins!

[1] apparently coined by a French-speaking American based on French roots?

Midjourney Medical 1 month ago

Ultrasound can also detect (some) kidney stones before they start moving and become painful, allowing an assessment of whether a medical intervention is useful or necessary. When I used to get kidney stones more frequently, there was a year or so when my doctor sent me for an ultrasound every few months to try to detect them in advance (!).

I think this is currently seen as too expensive to do for people who have lower risk, but I mention it as an example of something that one could check for more routinely given much cheaper ultrasound scans.

Prophylactic ultrasound exams are also apparently much more plausible on medical cost/benefit than prophylactic CT exams, because the CT exams very slightly increase one's cancer risk (https://xkcd.com/radiation/), where ultrasound doesn't.

(At a friend's doctor's suggestion, I started taking alkali citrate supplements and switched from almond milk to oat milk; I now apparently rarely get kidney stones.)

I asked Grok what it thought of tacos and it told me:

Tacos are one of humanity's greatest inventions—right up there with the wheel, electricity, and whatever genius first decided to put cheese on everything. [...]

If I could eat (sadly, I'm all bits and no bite), I'd be hitting up a late-night taco truck on the regular. What's your go-to taco order?

(I like the pun "all bits and no bite" for an LLM's inability to eat.)

Is anyone formulating prediction market questions asking AIs to brainstorm about edge cases in order to leave fewer of them uncovered by the market definition?

We do have humans brainstorming about such things, but this feels like something LLMs might be good at.

For (3), the word you're thinking of is "mane" 'in the morning', which looks very much like an ablative but which doesn't have any other forms. There are definitely other words like that, such as "fas" 'right, propriety, justice'.

For (5), these are called pluralia tantum (singular "plurale tantum").

https://en.wikipedia.org/wiki/Plurale_tantum

I gave some examples of Latin irregularities elsewhere in the thread, and I like your examples too!

Latin is beautiful, but its purity and regularity may be overstated because of its prestige.

There are irregular verbs, sometimes with complete suppletive replacement of principal parts by what used to be other verbs (e.g. sum, esse, fui, futurus; fero, ferre, tuli, latum). There are verbs that use passive forms with active meaning (deponents) or perfect forms with present meaning (defectives).

There are arguably completely missing forms in the verbal inflection system (the Romans knew that some forms plausibly "should" exist, especially based on a Greek grammatical model, but simply didn't have them!).

There is sometimes unpredictability in which noun case should be used with a particular verb.

The noun declensions are apparently based on two different sets of Indo-European noun inflection paradigms, so nouns with similar nominative forms can end up being declined very differently.

There are ambiguities where different noun forms coincide, which can even create parsing ambiguities in literature (like confusion between ablatives and datives, many of which look identical).

The extent to which the perfect stem of a verb can be predicted from the present is limited, as sometimes stem reduplication is used, but sometimes just suffixation of something like -vi.

There are loanwords, even classically, from Etruscan, Greek, and to a lesser extent other Mediterranean languages (just thinking of that "hodgepodge" issue).

The meanings of purpose clauses with the verbs of fearing are arguably backwards from the English point of view (although I think the Latin version does make plenty of sense).

Native and nonnative speakers couldn't easily agree in antiquity about whether vowel length should be contrastive and (I think) whether consonant aspiration was phonemic. I guess the native speakers' opinion should matter more, except there promptly became such huge numbers of non-native speakers that they started to have a really humongous influence on the language.

There are spelling changes even within the classical period, so there isn't quite one single classical Latin orthography.

I guess there are many fewer irregular verbs overall compared to Germanic languages (which historically have had up to hundreds of at least partly irregular verbs). But if we want to count unpredictability of Latin perfect stems (which is somewhat akin to the main source of irregularity in the Germanic verbs: stem changes) as a kind of irregularity, Latin will also have quite a lot of these.

We all get the same services from the state.

I agree with your intuition, but this is often contested based on the idea that one of the state's services is protecting property, which scales up in cost in some way with the amount of property.

For example, if you have a 10-story building, the cost of protecting it against fire is greater than the cost of protecting a small shack against fire (the kinds of fires it can be involved in and the means of accessing it to fight them are greater).

Or, if you have valuable jewels, the cost of protecting them against theft is greater than the cost of protecting a few items of clothing (more sophisticated attackers like organized crime and otherwise professional criminals may try to steal them using more sophisticated means and resources).

Or, if you own corporations, the cost of protecting your ownership interest against fraudulent transfers may be greater than the cost of protecting someone's ownership interest in a house against such fraud, again because of more sophisticated attackers and also because the rules permitting transfers of the corporate ownership interest may be more complex to formulate and apply.

However, it's likely that the cost of protecting most kinds of property scales sublinearly with the economic value of the property rather than superlinearly, so if people were merely being charged for the increased cost of actually providing them state services that they use or directly benefit from, this would still not justify tax rates increasing with wealth or with income.

I have also wondered about this when boycotting companies for reasons that I suspected were not the most common reasons.

If they sent out a survey about "why you're no longer a customer" I suppose it would provide one channel for explaining one's actions. Oddly, I seem to get those constantly when I am a customer, but essentially never when I'm a former or inactive customer.

On privacy grounds I like the idea that non-customers would be left alone, but on boycott-impact grounds it seems like having some kind of predictable "what are we doing wrong?" channel would be nice too.