HN user

sdflhasjd

3,293 karma
Posts3
Comments703
View on HN

Google (not saying it's a good search engine, but people use it) puts putty.org at the top of search results.

The results shows as:

  Download PuTTY - a free SSH and telnet client for Windows.
  PuTTY is an SSH and telnet client, developed originally by Simon Tatham for the Windows platform. PuTTY is open source software that is available with source...

I've got my own personal story about a cold call revealing my personal phone number had been leaked by Lusha, a "GDPR Compliant" B2B tool that sourced data from shady apps.

On a day off work, I got a cold call to my personal mobile. This salesperson called me by my name and then tried to flog something relevant to my job. Being hugely irritated, I shared my thoughts with the caller demanded to know where they'd found my number. They were at least a little bit apologetic, and said they found it on LinkedIn using a plugin called "Lusha".

Lusha's website has claims about being GDPR compliant, but at the same time being a "crowsourced data community". They do at least publish a "Privacy Policy" and some contact details for a data controller.

I emailed them with a Subject Access Request, which they responded to two weeks later in a very cagey manner. Actually, I did some sleuthing of my own. I found an unlisted link for a broken OneTrust request form. This didn't seem to be linked anywhere on the website and I literally guessed the URL for it. After some poking around in the debugging console, I recieve a more fully furnished copy of my profile.

The data source for my email was... "Lusha's email guess algorithm" - now, one of the downsides of working for a small business and getting a firstname@domain.com is that guessing it isn't particularly difficult.

The data source for my phone number was more interesting. "L.S Mobile Apps Holdings Ltd." a company I'd never heard of, but eventually found an App Store[0] and Play Store[1] listing under a very similar name.

Looking at the apps published by this company, you can immediately see where this is going: a "Caller ID" and an even more transparent "Contacts Backup" app - both having complete access to all your contacts. At this point it becomes clear where my contact information has actually come from: someone I probably work with has created a contact in their phone with both my email and personal phone number, then used one or two of these apps.

I decided to pick the Contacts backup app to take a closer look. Installing the app on a wiped phone, I explored the UI, disassembled code and snooped the requests to their servers to see where exactly this mysterious "GDPR Compliance" was. The primary functionality is of course to create an account, upload all your contacts, and let you sign in on another phone to download them. There was some effort to make this work for most users, workarounds for edge cases, etc. It was more than the low-effort app I was expecting.

All the sharing functionality was checked behind a "consent" dialogue (and I use that term extremely loosely). The deal was that app would helpfully hydrate my entire contacts book with missing details! All I had to do was share it in turn. What I found peculiar about this was it simply didn't work. It seemed as through not only would the server not populate the missing data, but the code that handled this client-side was unfinished.

If you're wondering what the link between Lusha & L.S Mobile Apps is, they're effectively the same company. Yoni Tserruya, the co-founder of Lusha, has their fingerprints all over the the certificates used to sign the Android LSM Apps. It's clear this app's data is what they've built their company on.

Now, both Google and Apple have well known to display "Data Sharing" information as part of the store pages. The Play Store page explicitly says "No data shared with third parties", whereas the App Store omits the usual section you'd see when data is shared with third parties.

I contacted both Apple and Google with full details about what I'd found, and in the least surprising event to my saga, they did nothing.

Sadly, instead of having any satisfying conclusion, what I saw was what I already knew. I even got angry when reading their privacy policy, and how completely clear that all this "GDPR Compliance" labelling they have is there to sell their product to EU customers and they're clearly not compliant.

Here's some ragebait for the rest of HN who cares about their data:

- French DPA (CNIL) says Lusha is full of shit, but they can't do anything because they're based in Israel[2]

- Lusha doesn't think consent is important[3]

  [0] - https://apps.apple.com/gb/developer/lsm-apps/id1634388352
  [1] - https://play.google.com/store/apps/dev?id=5128998142474323958
  [2] - https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000046775564?isSuggest=true
  [3] - https://www.lusha.com/privacy-articles/please-show-me-where-i-have-consented/

Ebay do something similar too. You can immediately provide positive feedback, but you have to wait 7 days to add negative feedback. This is ostensibly to encourage sellers to address issues to retain reputation. Sellers can also get negative feedback removed after the fact by doing refunds, etc.

This means high volume low value sellers have little incentive to actually properly describe things or post correctly. A common issue I keep seeing is sellers using slower postage than paid for. You can immediately see from the tracking number, even if you wait 7+ days to submit feedback, you'll get a 'sorry' refund and the feedback is somehow 'addressed' without them going back in time and delivering it faster.

Online reviews are just a sham now, Goodhart's law etc as even if the reviews aren't fake, they're encouraged or incentivised from real customers. Look up any service provider on TrustPilot and it's the same: hundreds of 5-star reviews from people told to add a review just after signing up, a dozen 1-star reviews from bad customer service, and barely anything in between.

BS546 is very uncommon now, but can still be found in some relatively modern british homes and businesses where the sockets are used to "code" for connected appliances. For example, the 5A socket may be wired up to a switched lighting circuit to connect lamps but prevent connecting higher power appliances. I've also seen the 15A sockets being placed in communal areas of flats to provide cleaning and maintenance staff power while discouraging tenants from using them.

The thing is that shunning WhatsApp and Facebook doesn't put you back to a time before they existed, it cuts you off completely because they've dispaced what used to exist. Before Facebook there was email and SMS, before that there were phone calls, letters, etc. None of those really exist any more. If something happens, it goes into the family WhatsApp group, if you're not in the group then you don't find out. My parents and their generation still answer the phone at least, and I convinced some fairly close people to use Signal, but generally I'm more disconnected from my family than I would have been in another time.

I remember removing the IR filter from a cheap webcam and seeing everything in a new light (haha, pun intended) was fascinating. One of my black coats that didn't get hot under the sun and appeared more reflective and. I remember some opaque things like Coke being much more translucent.

These winning photos are a bit boring my comparison, the ghostly effect of foliage in IR is cool but a bit overdone when there's so many and there were so many other interesting differences in every day objects.

I'd love to do the same with my mirrorless camera but it's a quite destructive operation.

My thought is that Expo prioritises web compatibility too much to the point that it leans into conventions with things like navigation that are web-oriented and these contribute towards an app not feeling like a native app.

Probably the first "we adopted x" blog post that I can find relatable and spot-on.

I think it's one of the big misconceptions that React Native is _the_ path to get your web devs or even existing code onto mobiles. That's how you get the criticism that RN builds bad, mouldy apps.

Between our clients that have had this issue with quality and shops in the same space as us that haven't (one who boasts a review on one of their apps being "an example on how to build a proper fully native app"), having a good portion of native devs on the team is a big differentiator. Unfortunately this means a RN Team isn't as cheap as some hope.

They fixed it in the sense that there's an opt-in offline-only print mode and they do work without a connection. It still requires you to do an initial setup using the mobile app, so if you're an offline-first kind of person, their printers are definitely not for you

I used an A7C2 + Sony FE 50mm f2.8 macro. The lightbox was a custom build based on the design that I found linked on HN recently: https://jackw01.github.io/scanlight/. This was then mounted vertically on the toolhead of my 3D printer with the camera on a tripod, I then used the Z and X axes to scan across the negative.

Although I had success with PTGui and it "just worked", I didn't fancy paying for it and instead used Hugin in the end. This lead me to take around 63 pictures with 50% overlap.

The film was a 4x5 negative and after stitching I'd say the effective DPI was ~4500

I see you mentioned using a 3D printer for scanning medium format film. I did something similar, but took the opposite approach. I placed the film on a lightbox and mounted that to the printer, then had that move around in front of a camera with macro lens. I did not have much of a problem with alignment.

That being said, this was a one-off, but once I had enough overlap with each capture, PTGui was able to switch it together relatively hands-free, even with it having lots of sky.

These "antique" scanners give out such good quality, but it's a shame they're so awkward to use. I was too scared of a reconditioned hand-me-down and having to deal with missing trays and emulated windows XP. Instead, I managed to get a consistent-ish setup for scanning negatives using a Sony A7 III camera, though this was a case of digitising an existing collection, so I went through them all in one go with a 3d printed mask and feed mechanism.

With the author lamenting about SD cards being awkward; it reminds me of one thing has been immensely useful with the A7 III is the built-in FTP auto-upload. This surprised me as reviews didn't mention it, and as a seeminly high-end consumer camera I wasn't expecting such a "professional" feature. I just have it upload everything to my NAS.

Now my next task is to do the same with thousands of dirty slides, which is turning out to be far more challenging...

It would be interesting to replicate this with a shorter wavelength. I tried doing some stuff with UV LEDs but was frustrated by how inefficient they were. Bog standard 385nm "UV" LEDs emit so much blue light that weak fluorescence was easily washed out. I wonder if that could be messing with your calibration (or even if the extra blue light could be doing some sort of quenching).

During boot, for example, even modern Windows boxes show a BIOS screen followed by a brief blinking cursor before the Windows graphics mode takes over.

This hasn't really been the case for more than 10 years now. EFI based systems will boot without changing display modes. Some hobby custom PCs might have compatibility modes enabled, but any laptop or prebult system is going to go from logo to login without flickering.

The license is pretty specific, if the API counts as a "service".

  i. If you distribute or make available the Llama Materials (or any derivative works thereof), or a product or service (including another AI model) that contains any of them, you shall (A) provide a copy of this Agreement with any such Llama Materials; and (B) prominently display “Built with Llama” on a related website, user interface, blogpost, about page, or product documentation.

Here's a bit of a quirk: I uploaded a webcomic as an example, all the dialog was ALL CAPS, but the output was inconsistently either sentence case or title case between panels.

I also tried some real examples a problem I'd like to use OCR with: I've got some old slides that needs digitising, and most of them are labelled, uploading one of these provides the output:

  The image appears to be a photograph of a slide or film frame, possibly from an old camera or projector. The slide is yellowed with age and has a rectangular cutout in the center, which is filled with a dark gray or black material. The cutout is surrounded by a thin border, and there is some text written on the slide in black ink.

  The text reads "Once Upon a Time" and is written in a cursive font. It is located at the bottom of the slide, below the cutout. There is also a small number "1069" written in the same font and color, but it is not clear what this number refers to.

  Overall, the image suggests that the slide is an old photograph or film frame that has been preserved for many years. The yellowing of the slide and the cursive writing suggest that it may be from the early 20th century or earlier.
So aside from unnecessary repetitious description of the slide, (and the "yellowing" is actually just white balance being off, though I can forgive that), the actual written text (not cursive) was "Once Uniquitous." and the number was 106g. It's very clearly a 'g' and not a '9'.

What I think is interesting about this is that it might be a demonstration of biases in models, it focuses too much on the slide being an antique that it hallucinated a completely cliche title. Also, it missed the forest for the trees and that the "black square" was the slide being front-lit so the text could be read, so the transparency wasn't visible.

Additionally, the API itself seems to have file size or resolution limits that are not documented