HN user

unknownsavage

533 karma
Posts2
Comments40
View on HN

They forwarded from one card to another? AWS charged a closed card and the bank forwarded it?

Yup.

By the way, if you can't authenticate with Amazon as the rightful owner of that account, it sounds unreasonable for them to comply to a stranger asking them to simply remove a credit card number of some account.

I disagree. If I can provide a full credit card number, they should be able to remove it from all accounts. Either the card is compromised, or I'm telling the truth.

For people who haven't read the article this is extremely misleading:

The ends with him agreeing how the film sucks and maybe the prosecutor was right!

He says that, only as a joke that it's so bad it should've been illegal. While in reality a great mis-justice was done to the man, and he was railroaded into accepting a plea-deal due to the gravity of the unfair charges.

I recently upgraded from the 2015 to the current gen.

2015 pros: * Better battery life * Way better keyboard * More robust * More useful port selection * Trackpad is a more reasonable size

2018 pros: * Way better speakers * Slightly better screen * Lighter * Faster * Trackpad is not mechanical * Finger print login is useful

I'd really love a proper "pro" macbook pro, that sacrificed a bit of the thin-and-lightness for an actual professional level of stuff (better cooling, more ports, bigger battery, no touchbar)

One thing I found to make the touchbar less annoying is go keyboard -> Touchbar shows "Expanded Control Strip". At least then you get a full strip of useful buttons that aren't constantly switching with the application.

The main issue though is with "Expanded Control Strip" the touchbar locks up (while holding a key down) about 2 or 3 times a week (which can only be fixed by a restart or: "sudo pkill TouchBarServer")

The whole thing is pretty inexcusable for such an expensive machine, but I like the macos ecosystem.

There are plenty of opportunities for things to be stollen from checked in luggage at the arriving airport.

This actually happened to me on a flight into the US, with an expensive set of german kitchen knives in checked-in. In the US my suitcase was taken out of the normal line for extra checking (I guess because the knives showed up in an xray?).

They then later gave me my suitcase, but the entire knife set was missing. No documentation that it was taken. No one even cared. No recourse. And nothing came of it.

If I have something valuable that I couldn't take in my carryon again, I'd rather just DHL than trust the TSA to not steal it.

New Surface Pro 9 years ago

I think you're confused. I bought a Macbook in New Zealand, and had it's motherboard replaced for free in the US. Then later bought a new Macbook in the US and it serviced in Germany.

Lisp Quickstart 9 years ago

The lisp quickstart is indeed one of the key advantages of lsip:

    $ time sbcl --script hello.lisp 
    Hello World!

    real	0m0.026s
    user	0m0.009s
    sys	0m0.013s
Compared with languages with a much bigger starting curve:
    $ time node hello.js 
    Hello World!
  
    real	0m0.113s
    user	0m0.052s
    sys	0m0.022s

The grandstanding is corny at best. Take the first example:

Despite continued assaults on the credibility of her contributions to modern computer science as the world’s first computer programmer, Ada Lovelace coded.

Yet in reality she was very much respected in her day, and despite her challenges received widespread support. The first "assaults" on her scope of her contributions came over 100 after her death, and not some sexism she had to fight and overcome.

One issue with buying two keys is they internally have different keys, so you need to connect both to each new account which is a pain in the ass and stops you just keeping one somewhere very safe (i.e. safety deposit box, or a safe at a friends house)

The trezor only lets you backup the key during the initialization stage. After that the key can never be recovered. Also you can set a password so it's encrypted as well, so even if someone finds your paper backup it's not particularly useful.

This is really awful, for it to work well you would need to buy multiple keys and each time use them all to register (which precludes the option of storing the backup key somewhere safe).

Straight from the yubico website: "It is recommended that users register at least two U2F devices with every service provider should a U2F device be misplaced"

That's just a plain usability nightmare, and not to mention expensive.

The trezor one works a lot more sanely for u2f, you get a recovery key when you first set it up (it uses the screen to output it, so even if your computer has malware it can't be compromised) and can leave it in a safe at your friends place.

Lavabit Reloaded 10 years ago

If you want encryption, don't use email.

That's total nonsense.

Search isn't possible

It absolutely is, in both theory and practice. The server stores an encrypted index, and the client walks it (requesting parts as needed). It's going to little slower, and a lot more complex but it's doable.

If you lose your private key, we can't recover your email

This is a damn feature. I had my icloud account social engineered (someone walked into an apple store claiming to be me and they couldn't get their iphone syncing to "their account"). I'll never again trust another company with my private stuff.

Spam checking on content isn't possible

This is probably your best point. It's definitely harder to do well

To access mail on multiple devices, the private key needs to be shared securely between them

This is a non-issue. It can easily be derived from a password

I've always been interesting in doing this in Japan, this is without a doubt the best resource I've ever seen on the matter. Well done to the author, thanks for writing this up.

Actually their view point is perfectly consistent. They criticized _bitcoin_ not the blockchain. While a blockchain could support some of the regulatory required undo stuff (by appending a record that it's been undone), bitcoin itself certainly doesn't won't let you roll back a bunch of transactions.

I really don't think this is a big deal. I run a medium size website with well over 2000 uniques users per day and also require the referer header to use the website. So far, I've yet to receive a single complaint or find a browser that doesn't send it.

It might be optional as per the spec, but it's completely ubiquitous at this point, and provides an easy way to add an extra layer of safety for web developers.

One thing most people don't think about. The kelly criterion isn't particularly useful for investors, as you need to be able to quantify the expected outcomes. It's not particularly useful for gamblers (rarely do they have quantifiable positive expected value), but it's an absolutely amazing resource for casinos themselves.

Almost every bet that happens on a casino floor the casino can quantify their expected returns and risks and knowing the state of their bankroll knowing what is sensible to risk or not.

But other than that, it probably is mainly useful to teach investors a healthy fear of variance. If it'd be foolish for a casino with a $1M bankroll to let a roulette player bet more than $12000 on a spin, it might give you a healthy sense of the importance of diversification.

I think it's against Amazon's policy because it's against reddit's. Either way, I hold Amazon 100% fault. When you go to an affiliate link, e.g.

https://www.amazon.com/KONG-Cozie-Marvin-Moose-Medium/dp/B00...

They don't do a redirect or use pushState to remove the "tag" part, so it's completely expected that people might copy and paste the URL to share. And that's even without the person acting maliciously, god help you if someone wants to kill your affiliate account.

All attempts to contacted them ended in a dead end of "sorry, abuses are handled by a special team who can not be directly contacted". And when we finally got the abuse team to respond, the most they ever did was confirmed the affiliate link was posted on reddit. And we have in writing them saying that a single instance of someone posting the link on reddit is grounds for your account suspension, even if that wasn't you.

I really regret now not making a big deal about it, and writing a shaming blog. But at the time I just wanted my wife to move on and focus on something more productive. It was a huge emotional blow to her, as the site was something she was very proud of and something she did on her source of money (As a family we are financially fine, but having her own little stream of money she could use on random silly/unnecessary purchases made her feel a lot better).

Something similar happened to my wife as an Amazon affiliate. It took quite a while to piece together, but after about 4 or 5 back and forths, we figured out what happened.

Someone had clicked on her affiliate link, then copy and pasted it onto reddit to share the Amazon product with some people (without knowing it had the affiliate link as ?tag=....). Because reddit is a site you are not allowed to share affiliate links, Amazon suspended the account.

The person who had shared the link was obviously even a legitimate reddit user, and the post was pretty minor only getting a few upvotes (we only found it via a search). But because of this, Amazon suspended over $500 of earnings, and killed a site that took many months to build and establish. And now my wife is now on a "refuse to respond" to list for trying to contact them multiple times to get someone who can apply a little bit of reason to the situation.

I think in hindsight we made the mistake of not trying to publicize the issue and Amazon could just ignore it. So here's an upvote for the OP