HN user

throwaway192874

208 karma
Posts0
Comments36
View on HN
No posts found.

Well now you're shifting the goal posts to a different topic. I was responding to your claim of this set of companies being random and your concern about some not being included

The size of these companies is irrelevant to that point

And who are these companies you keep mentioning? They don't even come up when I search them on DuckDuckGo. That's how small they are in comparison to the companies the author included as "big tech"

Why have we chosen these 13 random publications? I'm assuming that the NYT is included literally just because the people who did this study don't like the NYT?

These are some of the biggest media publications that write about tech issues, these aren't just "random" choices. This author seems to focus on "big tech media" as is mentioned in the article multiple times, these are big tech media, independent journalists are not.

Anecdotal, but I know every one of them off the top of my head, I've personally never heard of AnandTech and had to google it.

Perhaps if they were to remove the concept of nil in golang, but since they are all about backwards compatibility (which is nice to be fair), I don't think there's much change of seeing mainstream adoption because of how many existing projects will rely on default value in certain circumstances

I'd love to be proven wrong, but even with generics if you start using option types, it's going to be like JS and TypeScript where you'll have some parts nicely typed and others are the wild west

Most project management systems have methods for dealing with checklists, this is definitely not what slack is designed to do no matter how much they market it as a "productivity tool"

So if you're not using something for project management first you need one of those, but just about everyone does, and once you have one you can start using it's checklist features

Then it depends on what that specific software offers, but even if it doesn't have a true feature for creating "templatized checklists" which I assume people want so they can repeat the same list, most have duplication functionality so you can just create one as a template and duplicate it as needed.

Legitimate question, is there enough interesting information in this book worth reading if you already agree with the premise, that in complex situations checklists can be good?

I've known about it for awhile and this review does a good job at providing a real-world example of where it's useful, so other than ideas of how to make good checklists I'm not sure if actually reading it is something I should do

I think it's hard for me to say exactly without a side by side comparison, partially because this one had different toppings than my normal burgers do, but it seems fairly comparable in flavor and I would buy these again. I've also had an impossible burger a few years back at a nicer restaurant and that was good too.

I think both are to the point that if I didn't know what I was eating and didn't deeply try to analyze and compare, I could eat one without any idea that it's not meat.

I'm now somewhat interested the next time I see my family to see if I can pull off a ruse of making burgers for dinner from these and see if anyone even notices, particularly my brother who would say there's no way you could trick him XD

This is an incredibly unconvincing article that flat out misrepresents facts or didn't do enough research to actually understand what happened.

Most of it complains saying that Impossible Foods went to market without being approved by the FDA and implies it's unsafe, but that seems to be literally 100% false and completely misrepresents the facts from my basic research on it.

They received FDA approval in Oct 2019 [0]. The Center for Food Safety filed a lawsuit against _the FDA and Impossible Foods_ later that year saying they didn't think a strong enough standard for approval was done. Earlier this year, the court ruled in favor of the FDA and said they did have enough reason to believe it was safe. [1]

[0] https://impossiblefoods.com/media/news-releases/2019/07/fda-...

[1] https://www.theverge.com/2021/5/3/22418036/impossible-foods-...

I had some more written about this but it doesn't even explain the method it claims is better, provides no scientific evidence for them, and ends by saying things like "WILL NOT SAVE US" and "NOT MORE HUMANE" bold and in caps. You can make up your own mind on how trustworthy this is.

it recommended me (to rent) what I thought was a science documentary about space and the cosmos once and i just trusted it wouldn't recommend me some crazy conspiracy theory and rented it... NOPE.

It was about how ancient aliens mined out the moon and control us or some other crazy pills kind of idea

My actual normal video recommendations are quite good and shift alongside my interests over time quite well without prolific use of "not interested" or incognito shrugs. Rented movies seems bad though, especially since I'm already a paying premium user!

I see you're an economics professor with an interest in computation, and perhaps learning to program? Awesome!

Ask any experienced programmer how often they use StackOverflow, and they'll tell you daily. It's an invaluable resource to our community and we often wonder how we got along without it before.

In particular, it's great for highly specific questions about very niche things. Like, with this version of this library and in this stack, this very odd behavior is happening and I only see it in IE8, what could it be? That's not something you'll find and answer for on MDN. MDN is a fantastic reference resource when you know what you're looking for and need the details, but it's not a Q&A platform about anything.

SO is not perfect, sometimes you have to dig for the right information (something this change is trying to improve), and perhaps it's not ideal for beginners, but I wouldn't want to live in a world without something like StackOverflow, and would be significantly less productive

right? These word by word break down responses don't ever get anywhere

the whole argument he's making has operates on the presumtion that the vacccine is unsafe, contrary to mainstream scientific opinion. Then the only evidence he has to back that up is lack of evidence on long term effects.

But...the type of which would potentially appease him is only possible with a time machine, so it's literally impossible to appease him

Having talked with a guy basically trying to recruit for it at the aerospace village at Defcon one year, I can say that working for the government without really working for them (e.g. not wearing suits) was a big part of how he sold it. That you're still a civilian and things like that, but get to work on cool stuff like hacking aircrafts

The web UI is severely limited compared to the desktop client which is why I suspect they do this (even though I disagree with it).

I've had some very confusing meetings because I worked at a company that required us to use web, but the presenter wasn't and what she was seeing didn't match us which led to some confusing scenarios. Things like the grid view weren't there last I used it and some of the more advanced presenter features just don't do anything for web iirc

There's a whole book on this history of zero you may enjoy called "Zero: The Biography of a Dangerous Idea" that goes into the whole story of how it came to be including problems and resistance along the way

(mods I promise I'm not here to shill this book but people keep wondering about the history and that's a great resource that I like XD)

There's a book called "Zero: The Biography of a Dangerous Idea" that goes into the history of zero in detail, admittedly I haven't finished reading the book myself but got at least partway through and it was fascinating to read about it and I'll one day finish it :)

What you said about it not being in the numeric system is definitely part of it (ex: roman numerals not having it) but also all the problems that come up with zero have to be dealt with (e.g allowing dividing by it allows you to prove anything, and there's a great proof that winston churchill is a carrot in the book showing as such), and there's some overlap with religions in fearing "nothing" and what that might mean

The purity of CBD and, in particular, the composition of the materials labelled as CBD are also important, especially in light of our findings suggesting that other cannabinoids such as THC might act to counter CBD antiviral efficacy. This essentially eliminates the feasibility of marijuana serving as an effective source of antiviral CBD, in addition to issues related to its legal status.

Well shit

You forgot to read the sentence before that

Prior to their release, the source code of both the new ProtonMail and Proton Calendar underwent an extensive security audit. We are happy to announce the final report was overwhelmingly positive, and the audit uncovered no major issues or security vulnerabilities.

This report was done before the release of the new software, and important issues fixed. What they said was accurate given there was only one medium severity finding, and no highs or critical. For example, the site now returns a CSP preventing inline JS so this wouldn't work anymore even if they didn't fix the underlying XSS.

The fact that exploiting this required the user to intentionally right click and show the image in a new tab (since it already renders it inline w/o xss) is why it was categorized that way since it's unlikely someone would do this by default.

Most companies never disclose anything like this, so them disclosing there was a vulnerability found in a report they paid for and then published isn't really a strike against them and I'm fine with this language. It's a little marketing speak but I don't agree it's inaccurate for them to say so

Password Managers 5 years ago

As it looks like Tavis isn't hanging out and responding to comments here, I thought it'd be worth linking to a question and response he gave on Twitter as most comments revolve around this point.

@diractelda: Based on your thoughts, it seems a more accurate statement is "Don't use a password manager that interacts with your browser automatically unless it's the built in password system. Non-integrated password stores are fine."

@tavis: Yep, that's a fair summary, I was just trying to be punchy

https://twitter.com/taviso/status/1401253440622235649?s=20

Password Managers 5 years ago

fyi Tavis is a very well known and respected security researcher from Project Zero, and this is his site so it's nothing to worry about :) I mean he _could_ hack everyone if he wanted but he'd pretty quickly be in a whole lot of trouble

You can see that he links to this as his site on Twitter here: https://twitter.com/taviso

Interestingly, I wonder if Norton doesn't like it since the name is related to an old vulnerability. From his site:

Q. What is the origin of your domain name?

There was a bug in early Pentiums called the f00f bug, it would cause a deadlock if you used in invalid operand with cmpxchg8b with the lock prefix. It was an important vulnerability at the time, and I thought it would be fun to own lock.cmpxchg8b.com.

Password Managers 5 years ago

Password managers have servers sending code over to the browser? After the installation process?

Yes, LastPass is all web based IIRC, even 1Password switched to a web based offering when they switched to a subscription model. I'm still a happy customer of their previous product which was a one time purchase and uses software installs instead, database synced with w/e you want (Dropbox, GDrive, etc)

The official press release is here [0], and does a good job at describing what happened, and imo supports my argument of ignorance/negligence than intent.

Two independent programs with separate purposes, sometimes accidentally trading with each other which could affect the price. This information was included in API data (since it was just normal trades) which can create the appearance of activity or volume that doesn't truly exist. But these were real trades, so in some ways it does still exist it's just that CB happens to be on both sides.

[0] https://www.cftc.gov/PressRoom/PressReleases/8369-21

Plausible deniability is used by bad actors, and the existence of investors investing in founders who will do anything to protect their investment isn't a myth - it gets discussed a few times per year in threads on HN and Reddit.

I agree that has been used like this and will be in the future, but it's different to claim it's possible than spread FUD that it is actually happening (not directed at you to be clear). The latter is what you commonly see in online discussions revolving around Coinbase, though really with all tech companies.

Yeah, they already have the asset when you click buy. On "consumer", the blue one, when you click buy it literally does a direct market order off of Coinbase Pro to purchase the asset, and since it's on Pro they already have the crypto on platform.

OP said this:

After not paying attention to cryptocurrency for a few years and then opening a Coinbase account earlier this year, I was SHOCKED how fast and easy everything was.

I read this as having just created the account and impressed by the platform, not a comparison between the past and now shrug

They've definitely done tons of work to try and address scaling problems, have solved many and will continue to do so, but it's not like you just "solve" scaling once and never have to think about it again. The scale they are seeing now is nothing like they saw in previous runs, so it's always new milestones, something new breaks and then something else to fix.

There's also been a lack of a clear vision from engineering leadership at the top for many years which hasn't helped either.

We recently know that Coinbase has had bad behavior of manipulating the price and find a measly $6 million for market manipulation, so it seems not outside their character.

My understanding of this is that a couple of internal systems accidentally interacted in a way that was later deemed bad, not an intentional manipulation. And when the COO noticed this action was taken to replace the system with a version that fixed this issue [0]. This was in 2015-2018 when they company was significantly smaller with less expertise on that front. If this had had a significant impact on consumers I would expect to see a larger fine, but I'm not at all well informed on the topic.

Having worked at various startups, the old adage of "don't ascribe malice to what can be explained by incompetence" resonates with me. You so regularly see wild speculation happening on the outside when inside you're just like "wtf that was just a bug, not some grand conspiracy". I expect that this issue falls under that category, lack of knowledge rather than part of their "character"

[0] https://decrypt.co/62155/coinbase-fined-6-5-million-over-tra...

For individuals this isn't hard, but for large institutions it's very non-trivial. There's a reason that none of the major exchanges do this, it's not just incompetence or lack of desire.

Coinbase, and various other exchanges are regulated in the US so they undergo regular audits where having to prove funds is part of it. Some exchanges, I think it was Kraken, has published some version of those results, but the problem with these is at that point you're saying you trust the auditor and the process, which is another thing people would complain about anyways.

Technically, it's also very nontrivial to prove ownership of millions of addresses when they are also constantly changing (due to new address generation). Proving ownership of addresses stored in cold storage is even more involved, and would actually put the funds at risk because you would need to us bring the key out of cold storage to do so. Furthermore, people would likely not be satisfied with a one-time proof, so you need to operationalize this and do it on some regular basis.

Lastly, while this would be nice to have, it's frankly not something I expect any major exchange to do because it's simply not worth the investment. Most customers don't care and are happy to trust the government and regulations to ensure they are good enough. While I understand people are concerned because of what happened with MtGox, that doesn't mean that every other company after is involved in some big conspiracy about lying how much crypto they have. It's just FUD/conspiratorial thinking without real evidence to back it up.

The exchange going down at key moments (read: when the app is seeing peak traffic at new milestones regularly) is basically expected for a young fast growing SV startup, and doesn't support the argument that they are nefarious things going on

That's also the time when the system has to scale the most, so it's not exactly surprising to see this. Unfortunate and something that should be improved yes, but doesn't really support an argument of them trying to prevent people from selling since that is exactly when you'd expect the system to fall over.