HN user

shittyadmin

1,596 karma
Posts0
Comments378
View on HN
No posts found.

That's factually incorrect. No one in the EU can sue a California company for failing to comply with EU laws so long as the company does not have a physical presence in the EU. They'd have to block their site or something as an EU court has no jurisdiction over a California company and would be unable to take action against them.

An explicit law would need to be made in your jurisdiction forcing you to comply with their laws. I'm not aware of any such thing.

I accept payments from the EU and do not comply with GDPR. They can't sue me in my country's court for violating their laws. It really is that simple.

They'd have no repercussions except to block my site - and I'm guessing they didn't intend GDPR to turn into an internet filter.

You don't reside there, you're not liable to abide by their laws. I run a small US company, I don't have to comply with GDPR for example. Same applies here.

I don't see why any company would implement this, perhaps appeasing regulators at the federal level.

There've been a few cases where the ransomware was not decryptable - sites like BleepingComputer frequently discuss which ransomware have been cracked by researchers, which are currently actively run and will provide keys and which are undecryptable and you shouldn't pay in any circumstances. Basically it just makes things more complicated, but people are still willing to pay if they can in their specific case and the one they're infected with is reported as regularly providing good keys.

I feel this is actually a decent service for a few reasons:

- Many average users don't want to understand cryptocurrencies, how to safely and securely buy and use it is a challenge in and of itself.

- They're on the hook and the client pays nothing if the ransomer fails to provide a working key.

- They'll also manage the ransom decryption software - if there's problems with it there are 3rd party tools that can often do a better job of decryption than the original decryption tool, again, this is something that's going to be complicated for average users to deal with.

- For some ransomware there are decryption processes available without the need to pay the ransom, figuring out which of these applies can be challenging

- Certain institutions may be unable or unwilling to work with the attacker directly - introducing a middle man to broker can help solve this.

Overall the piece seems somewhat hyperbolic.

I only focused on the JAMA study as I'd seen it before, sorry about that I see it may have looked pretty slanted now, I wanted to have a better look at the positive metaanalysis, however the link on wikipedia was broken, look at where it points on wikipedia, you'll see "Cite error: The named reference Gotink was invoked but never defined (see the help page)."

I'm not disagreeing with you about that depression and anxiety thing, but it seems a bit of a stretch to suggest it to a generally mentally healthy person.

If you don't believe me, I'd highly recommend checking out this paper:

https://jamanetwork.com/journals/jamainternalmedicine/fullar...

"We found low evidence of no effect or insufficient evidence of any effect of meditation programs on positive mood, attention, substance use, eating habits, sleep, and weight."

As for "destruction of other cultures" - well, people use the same excuses to say that homeopathy is great and crystal healing will cure your cancer. It's a non-sense argument. This has no cultural bearing at all, just a rejection of bullshit. I have no interest in blindly approving things without analysis just because they came from other cultures. Study them. The results here are sketchy at best.

Did you read your own link? One line from it mentions the study that actually brought me to this conclusion:

"A meta-analysis on meditation research published in JAMA in 2014,[167] (that included a combined total of 3515 participants), found insufficient evidence of any effect of meditation programs on positive mood, attention, substance use, eating habits, sleep, and weight."

While there may be other with differing results it's... pretty sketchy in any case. I would hardly say scientific enough to belong in such a class.

I had a look at this when I considered meditation once but found it'd most likely just be a waste of my time. I'd rather not flush my time down the toilet.

I mean the whole idea of "mindfulness" and "meditation" are the sort of pseudoscientific bullshit that just plain don't belong in a scientific class.

Sure, they may have some benefits, but they're essentially just placebo effect. There has to be more interesting science on the topic than that...

Like - imagine if US was attacked and the attacker killed 60 million Americans. I can almost guarantee that no matter how strongly Americans believe in the 1st amendment, saying that it hasn't happened would be made illegal.

Why would scale change people's values compared to say 9/11? It's important to me that we're the deciders of truth for ourselves. I believe people fighting in those wars have fought for my right to believe what I choose and not what a government tells me.

Think about this in the context China, even today and I think you'll see why I feel this is an incredibly valuable right. Governments can lie too, the American one has many times throughout history and we should and do demand a right to question it.

because you can just ask for permission from Android

You cannot ask for permission to bypass sandbox restrictions on Android. You need root access, which means physical access to do things like unlock the bootloader or an exploit.

iOS sandbox seems slightly weaker here due to the use of hidden/private functions to protect certain things, sideloaded apps would likely be a bigger risk on iOS than Android at the moment, but that's not something unresolvable.

In any case, the things you're discussing aren't really so problematic - isolation systems are only getting better, OS level ones are improving every day. We could easily have sandboxes at this level just as secure as the javascript ones.

Why exactly should that be illegal? The government should not be the decider of truths.

At least if private entities implement this kind of thing, those who wish can still discuss it someplace else.

Though pushing these things under the rug doesn't have the best reputation (see recent 8chan tied shooting).

I think the main factor here is that the Chinese government spying on me likely would have no impact on my life, while the US government spying on me has a direct impact. So as an average US citizen, I should be far more concerned about US spying than Chinese spying.

I absolutely agree though, I'd be far more afraid of using a Chinese device as a Chinese citizen than as an American citizen using an American device. China has far worse human rights abuses, it's just the ways they can impact most Americans are minimal in comparison.

I feel it's reasonable for an individual to be concerned about your own country's human rights abuses first and foremost as those are the ones you're personally most likely to contend with.

What you seem to be saying is that they're sending location data periodically even after disabling location history. That I believe is false. Any location sending after that is by user or app demand.

Achieving this on an Android device isn't impossible by any means: deny location to all apps and those apps won't be able to call the Google Fused Location API. If you want location without using Google's API, allow only select apps which use direct on-device GPS access, it's readily available in the Android API without the need to pull in the Google Play Location Services package.

From your linked article:

For example, Google stores a snapshot of where you are when you merely open its Maps app

Yeah, that's exactly the kind of thing I'm talking about. In order to download map tiles around you, show nearby stuff, traffic, etc they need to know where you are. So yes, that means they get your location.

But that has nothing to do with the sort of periodic background location reporting used in Location History that people are concerned about. Disabling Location History and not using Maps or other Google location based apps or APIs means they won't get your location.

Also note that there's no mention of play store access, phone calls or any other sorts of usages which seem like they shouldn't ask for location in that article.

They make a bit of a big deal about searching for "chocolate chip cookies" not requiring localized results, but from a technical perspective I think it's obvious that they just send it with the request regardless, they don't know . Trivial to disable if you don't want that though. In fact, both this an the Maps example will happen even on iOS devices as the article points out.

When I said I found those claims exaggerated last time I looked into it, this is exactly what I meant. They must get a lot of clicks by making this stuff out to be more nefarious.

Yes, this is why I said most of what I feel is problematic, you're able to disable automatic location collection but not all location collection.

Your opening maps question is an interesting one, I automatically assume any data that goes to their servers is fair game, so if I'm asking Google to give me driving directions or even open a map and show me where I am (which requires loading map data for the area), I'm clearly making that choice.

I suppose it's possible they could behave better, but once data leaves my device, it's out of my control and I have to assume the worst.

I think you're misunderstanding what was said in that testimony. Yes, Google still collects your location if you turn off location history and then use Google Maps or an app calls their fused location API, they do not periodically collect it unprompted if you have location history off. That's why I used the word "most". Because I feel it's obvious that they'll get your location in the other cases.

Your first link is broken, but if you think I'm mistaken here, please point me in the direction of a technical analysis showing this, I'd love to see it.

Most of this can be disabled simply by disabling Location History. Apple is definitely better for not keeping this kind of thing - however even with an Apple or Librem device, your carrier will store your location and hand it off to law enforcement more readily than even Google would, so keep that in mind.

Being concerned about your location privacy and having a connected cell phone in your possession at all times are mutually exclusive ideas with the current state of things. Short of major legal changes it will not be possible.

It was based on his wording that I drew my conclusions, they provide many services outside of location history which do mandate on demand location data, you know? Do you have any evidence that they're still doing periodic location after location history is disabled? I had heard concerns but it seemed they were exaggerated last I checked. Should be pretty obvious in RE if that's true.

Ultimately though, you're still not getting around being tracked, your cell provider collects that location data even if Google doesn't. Just having a cell phone and a SIM puts you in a pretty awful state privacy wise.

What they're referring to in that article is that when you use Google Maps and as you're following driving directions, their servers get your location so they can compute your route and offer you better routes and notifications about accidents and such along the way. That part I feel I signed up for and is perfectly fine.

It's been stretched by media to make it sound nefarious, but no one has shown that they're actually sending location data when history is disabled and you're not using maps.

It's not like it's a button you can press to "turn it off".

Yes, there's literally a button you can press. No rooting, no reflashing necessary.

Google Account -> Data & Personlization -> Location History

Done. In fact, as is mentioned in this article even, Google explicitly alerts you when you first enable it and allows you to opt out of it.

Once you've done this, the only time Google will get your location is if you use Maps or Location API services.