HN user

szbalint

60 karma
Posts1
Comments10
View on HN

We have to weight a complex set of circumstances:

- smoking is an exceptionally harmful habit, so just by coming up with any other activity at random one is likely to end up healthier

- this also means advising smokers to switch to vaping even without knowing the health effects of vaping makes sense - marketing vaping to non-smokers should be severely limited though

- marketing vaping to kids like juul does, should be downright illegal

How Uber Got Lost 7 years ago

Because Mike is the NYT beat reporter for a number of tech companies like Facebook or Uber.

Ten euros worth of Amazon gift cards as birthday gift from the company.

That amount has a great way of signaling that the company is too cheap to do anything real, but too unsophisticated to realize they then should have just given a slice of cake or a birthday card.

Talking about Firefox, I've recently heard some people getting annoyed that Firefox now depends upon Rust and Rust doesn't build on their obscure legacy platform.

I'm in turn getting annoyed at the complete lack of cost/benefit analysis that this entails.

Every software project has to deal with limited resources and the attitude that the vast majority of people running on more mainstream platforms should forsake improvements (in security or usability by Rust for example) in order to support Solaris, Illumos, HP-UX or any of those niche platforms, well that just pisses me off.

I still have a 32bit Debian installation (originally installed around 2003 and been Ship of Theseus-d over the years so it actually has 64bit hardware now) that I didn't have the time or motivation to upgrade, but if 32bit support would go away tomorrow I'd understand. What's the percentage of 32bit vs 64bit users? 0.3%?

This conversation reminds me of discussions around cryptographic hash functions:

https://slideplayer.com/slide/12035043/69/images/28/Reaction...

Google clearly considered it an important enough issue to spend considerable resources on trying to mitigate Spectre and in the end only gave up because they didn't find a feasible way to do so. They emphatically didn't conclude that it's fine because attacks are impractical.

This attitude was learned the hard way though: about a decade ago the PoC or gtfo attitude was prevalent among browser makers and large tech companies. Theoretical vulnerabilities were dismissed if no immediate proof of concept was provided.

What changed this was a bunch of security/cryptographical vulnerabilities. MD5 was known to be theoretically week for years and years, but when researchers minted their "can break every SSL/TLS connection" intermediate certificate to finally make browser vendors move on the issue, it was too late.

You see with systemic issues, in cryptography or hardware, by the time you actually demonstrate a PoC, things are way too late: it takes years if not half a decade (as in MD5's case, or with older TLS versions) to deprecate insecure things, if you look at the timelines.

So for issues in fundamental building blocks, it's more or less irrelevant if there is a working PoC today or not: if we don't move to fix the underlying issue and start acting on a roadmap to move away from insecure things, people _will_ come up with a working exploit that allows practical attacks. If mitigation is only attempted at that point then we're being left vulnerable for years to come.

I think the really damning bit is:

According to Frau-Meigs, independent funding for academics as well as journalists is extremely important. “Google and Facebook are paying these partnerships from their direct marketing arm, not through more neutral foundations,” she says.

This seems to be implying that Facebook and Google are paying these partnerships partly or mainly to coopt the researchers in order to avoid public relations or regulatory issues.

Google attempted to fix Chrome against Spectre but gave up, so what you're saying about no feasible attack is not true.

See: https://v8.dev/blog/spectre

we quickly discovered that software mitigation of all possible leaks due to Spectre was infeasible.

Are there many other security issues that are easier to exploit with potentially higher impact? Sure. Does this mean that Spectre is fixed or can be mitigated in software? No. It's a bit like the formerly theoretical timing attacks against TLS: attacks only get better.

This comes from a government in which the junior coalition partner is the far-right FPÖ, an openly pro-Putin and authoritarian party.

This law is part of their campaign to browbeat the press and public sphere into submission and it is following attempts to rein the austrian public broadcaster (orf) in.

The proposed law is useless for any legitimate purpose, as anonymity was never a problem with hate speech or other things. People are willing to engage in hate speech, libel or just in overall awful things with their name attached without reservation already.

It's weird that technology oriented people see code/IT in terms of infrastructure, but too little from a city as such.

I'm living in Vienna, Austria which is a city consistently rated to be in the top 5 most livable cities by multiple independent evaluations.

How did that happen? A strong sense of ownership and infrastructure thinking over a _century_.

Just to mention the obvious, property prices do not exist in a vacuum and cities where property prices go through such a steep and continuous rise as in London, Moscow, San Francisco etc. are not a reflection of desirability or market forces but rather the total abdication of planning and responsibility from the local authorities.

There are dozens of things local leadership can do to fix infrastructure and living standards issues, never let anyone tell you otherwise.