HN user

thw0rted

57 karma
Posts0
Comments145
View on HN
No posts found.

I'm not arguing against democracy: it's the worst system except all the other ones. I didn't think much of Brexit, I think they really shafted themselves, but at the same time I get the strong impression that EU governance is hopelessly broken.

I don't have to bring a solution to notice that the system we have is not working. (That's not to say I don't wish I had one, I just don't.)

Maybe I'm just too jaded but I don't think "making voices heard" matters -- in the link I posted upthread, the overwhelming majority of voters did not want the Chat Control measure to pass, but it did anyway, "for the children". (I can't even do that -- I'm an American living over here, I have no say in politics but am subject to a lot of their rules.)

Maybe we'll get lucky and the next vote will fail, or maybe if it passes there will be providers that refuse to comply. I think if it happens, it's far more likely that most will cave, and a few will just pull the plug and stop offering service.

Your post I originally replied to said

They've tried to do this for decades and have failed.... Let's see how voters like it.

My "point" is that I thought the same way you did -- look what a mess Clipper Chip was, they always want backdoors but surely a voice of reason will show up, etc -- but something has changed. Couple the vote in the EU with the way the major tech companies reacted to GDPR (you'd be surprised how many sites simply block all of Europe rather than comply) and it's a wakeup call. There is a real chance of the bad guys winning here.

If you think EU policy only impacts the EU, you didn't pay attention to what happened with GDPR. Some companies might scan only EU-to-EU communications, some might scan communications where only one end is in the EU, and some might just scan everything because why build two completely separate systems rather than just doing whatever is compliant everywhere you operate?

From everything that I've read, iCloud Photo Library is currently encrypted on the server, with a key that Apple only uses when presented with a warrant. If I ran the company (disclaimer: I do not) I'd implement this with an airgapped system in a vault somewhere, where a very small number of people have access to bring encrypted images in on a CD-R under two-person control.

That being said, one of two things is true. Either Apple does exactly what they say, in which case they are not able to perform server-side content / fingerprint scanning, or Apple is outright lying about only using their key on behalf of law enforcement. This latter case would open them to all sorts of legal liabilities, like a suit from shareholders for false reports. It would also require the silence of every Apple engineer who has ever been involved in at least their iCloud Photo program, and probably a bunch of server infrastructure as well. Additionally, they'd be legally obligated to report their scan results to the NCMEC but would have to do so in a way that doesn't give away that they're lying about how their systems work.

...if a human actually gets the file, figures out what type it is, and examines it for themselves, they'd be obligated to report it. With the number of Win10 devices in the world, how big would their security team have to be to hand-groom every automatically submitted "suspicious" sample? (For that matter, why would a vanilla JPG get flagged as "suspicious" in the first place?)

Well, since Talking About Statistics Is Hard, you have to look at the exact phrasing from the website: it "ensures less than a one in one trillion chance per year of incorrectly flagging a given account". So, each of those billion accounts has a 1:1T chance of false positive. If I remember my stat 101 correctly, that should translate to a 1:1000 chance of having at least 1 false positive on the planet during any given year. (And remember, even a false positive just means that a human reviews your photos, not that you get reported to the police.)

I think your take is correct but doesn't answer the question about why this matching has to take place on the device, if it's only for photos that are going into iCloud, and the iCloud contents are already being stored unencrypted.

The only remotely plausible answer I've seen is that Apple wants to keep potentially-violating material out of their general storage, and flagged images are being sent to the review team instead of regular backup, but that's a pretty weak guess.

I still don't understand how there are people on HN who think that giving their kids less access to technology is somehow a virtuous position to take. When I was the same age as my kids I could have gotten into all sorts of shit on a BBS or Compuserve forum -- my parents had no idea what was going on, but they'd given me a basic sense of right and wrong, and somebody to talk to if I was concerned. You've got to educate them about the world, but cutting them off from it is not the way to do that.

Dumb question: do we know from what they've released publicly if it will be possible for security researchers to snag a copy of the database, perform the same perceptual hash algorithm on a given image, and determine if there's a "hit", without violating some kind of license term?

Perhaps the community could run a crowdsourced "keep them honest" service web service -- upload the latest illegal-in-China Winnie-the-Pooh meme, oh hey look at that, it's in the China-only version of the database, isn't that weird, etc etc. (Obviously you wouldn't want people "testing" images that are in the database for the actual stated purpose...)

If the software is scanning everything, and they were already scanning uploaded content, why have a press release at all? If you're deploying an unrestricted panopticon to all your devices, why on earth would you go to the trouble of announcing it in the first place?

"It is an effective deterrent" to using this one specific platform to distribute CSAM. The problem with this solution is the exact same problem with the tired old "solution" to E2E encryption that gets trotted out every couple of months. If you add monitoring to the tool that criminals are using -- especially, especially if the company loudly and publicly announces that they are adding monitoring! -- you will, at best, catch a few of the very dumbest possible criminals, while the rest move on to one of countless available non-monitored tools.

For a backup use case, I haven't been able to beat the value of a Microsoft premium-whatever family plan. Routinely on sale for $60/yr, it gets you 1TB of backup plus an Office license for 6 users. Obviously you don't have as much control over it as "bare" cloud storage but it's hard to match the price.

Security.txt 5 years ago

This. They did a bad job of explaining why they chose an expiration date in the draft RFC[1].

If information and resources referenced in a "security.txt" file are incorrect or not kept up to date, this can result in security reports not being received by the organization or sent to incorrect contacts, thus exposing possible security issues to third parties.

Yes, the information could change after you write the file. No, it is not possible to know, when you write the file, at what future point the information will become incorrect. The document should have a "last reviewed" date, then the consumer can decide for themselves if it has been updated recently enough to be trustworthy.

1: https://tools.ietf.org/html/draft-foudil-securitytxt-11#sect...

AFAIK, when collapsed the ribbon interface should take up no more vertical space than a conventional menu. This is mostly a user education issue -- I think if they shipped products where the ribbon was collapsed by default, people wouldn't get used to using it as quickly, but they also don't loudly call out the fact that it's collapsible, and maybe they should.

The ribbon gets a lot of grief, but I think it is a step forward from conventional menus in discoverability. The secret is having multiple types and sizes of controls. If you have 3 top level menu items with 4 option each, a user can very quickly scan for what they're trying to do. If you have 6 or 8 top level categories and 10-30 items under each, it's a totally different story.

With menus, you have to use sub and even sub-sub menus for organization, and the user has to mouse over or use the keyboard to see the sub-options. Every sub(-sub) menu looks the same, maybe with a tiny icon to help find it. With the ribbon, every top level category naturally has major sub-groupings (horizontally), within which more important / commonly-used items can use larger icons, split buttons can be used to show a default action with related actions in a drop-down, and option-groups can be presented as a dropdown or expanded to show them all at once (think "view layout" in a file explorer).

I have to admit I had a negative reaction to the ribbon initially, but especially with the thoughtful integration into Windows Explorer it's really grown on me since. I'm not sure it's appropriate to replace every use of a conventional menu bar but I think it's the best fit in a lot of places.

On desktop at least, there is a very subtle vertical line coming out of the top of the avatar image of the linked tweet. When you start to scroll up, you'll see that this line is part of the "thread" indicator that links all the posts above it. On my screen, it's about the same as the "x-height" (lower-case letter size) of the username font, at the thickness of the UI grid lines.

It would of course be much better to have the previous tweet partially on-screen, possibly under a small gradient.

There's a variant / corollary of the Efficient Market Hypothesis here, though.

Let's say the GP's XML library has The GTA Bug, i.e. it uses a quadratic-performance loop when parsing. The bug will go undiscovered until any one consumer of the library a) sees enough performance impact to care, b) has the expertise to profile their application and finds that the library is at fault, and c) reports the problem back to the library owner so that it can be fixed. This combination might be unlikely but since only one consumer has to have all those properties, the probability scales inversely with the number of library users.