HN user

voidnullnil

-9 karma
Posts0
Comments56
View on HN
No posts found.

False.

1. Anti-user mechanisms (SafetyNet) annoy users.

2. Even though SafetyNet may not be as annoying as something like UAC, it still has deep reaching effects[1] since now the standards are proprietary and nobody can make an actual good UI alternative to the garbage dog-slow banking app.

The irony is your stale rhetoric only applies the other way: Users who were saved by "risk analysis" and firewall type systems don't know they were saved and don't care.

1. I assume this attestation is checked on the app's server - I assume Google signs their attestation that your device is "good" and this is verifiable by the server of the banking app. Otherwise the in app checks could just be nopped.

people are killing themselves because of instagram

Literally every social issue on the web for the last 20 years follows this one simple formula:

X causes Y. Yes it sounds stupid, but read this long winded reasoning or spend the next 70 hours of your life going down my trail of studies to back this up

And nobody actually invests their lives in rebuking them, and they get bored and stop talking about it 5 years later.

This only works for so long until the devs get tired of spoonfeeding. More importantly: There shouldn't be subtle nuances in something like a web routing library which is _supposed_ to be trivial. Just the other day I had the experience of watching a grown man give a presentation on his beloved HTTP library, explaining fundamentals of asynchronous (TM) programming and syntax as if the audience does not understand their own programming language in 2021, after seeing the previous 500 LangX.FrameworkY.HTTPlibs. This shouldn't be a thing. We shouldn't be relearning basic shit every day. The problem aside from UNIX being a giant pile of garbage, and HTTP being utterly pointless (can you even name what problem is being solved when you create a new p2p application and make them talk HTTP to each other?), is that everyone keeps making their new languages and libs to "fix" one tiny issue, and they _always_ lack basic knowledge of the past 50 years of PL history, such as Standard ML which is better than whatever they just came up with.

1 - mandate disclaimers in front of all videos describing the possible negative effects of porn

Why would you think this will work? My parents, school, etc already gave you a million false warnings about porn and yet I looked at it. Did that even work for smoking? I think smoking only stopped once vape replaced it. Now I have to skip the intro logo as well as some stupid disclaimer, and producers have to waste more of their time on legal checkboxes, great.

2 - hold video hosting sites liable if content is shown to minors.

That's not a concrete plan. Do we need photo ID here? Some experimental crypto to disclose your government certified age to the website so it can decide not to kick you off? What about a forum where anyone can post any image? Does the forum have to be legally liable to block minors if it has no rule against porn?

The internet worked perfect in 2000. I got my porn when I was 13 and had no problem. There was not a single complaint aside from corporate scum trying to enforce DMCA crap (the multi billion dollar company was complaining, nobody else). Only when all you American idiots came in 2010 from faceberg all these pretend social problems started existing. The internet is literally just data transmission and this act could not be more harmless if you wanted it to be. Quite literally, the internet is the most harmless technology in existence. It cannot give you any disease, etc. It costs nothing, etc. What we are seeing here is the American art of being a professional victim. One should start by observing that almost every single complaint about the internet starts with "I read some text and now I am offended".

I envision the internet as community run, and free. The current internet is all obsolete garbage. The problem is, on this new internet we wont actually be able to make it because everything will be illegal by then. It will be illegal to run point to point to your neighbour because of some stupid porno law that has absolutely nothing to do with your application.

[porn companies] need regulation

No, nothing needs regulation. Stop making the internet fucking worse. Can we go back to 2000 now (not that it was good then either since the internet was fundamentally broken already)? This is like the bat shit insane morons who think having a popup about cookies on every page is solving the """privacy""" issue.

Literally every single political issue on HN is bogus. Take the ad blocking issue for instance, nothing that has ads actually matters. Your "solutions" like Brave are pure garbage.

The "privacy" issue doesn't exist because if we were using sane tech instead of webshit, there wouldn't be any tracking since it wouldn't be conceptually possible. Why the hell can tech even track you in the first place for reading static documents? This is a poor analog that cannot even compete with paper newspapers (which are also much more legible because they are not on LCDs).

Net neutrality doesn't matter because nobody can ELI5 why I should care about it. Since the internet is all garbage, it shouldn't be an issue that it's expensive. Just don't use it. Make a free replacement. Cuban citizens have already done it.

Now let me try and list CURRENT_YEAR.addictions:

- Games

- Working out

- Porn

- Social media

- TV (youtube or whatever you use now)

- HN (muh dunning kruger syndrome, imposter, et al)

- Eating

- Lotto tickets

- Stock market

- Programming

- Working

- Drugs

- Things that are sort of drugs but not

- Any substance what so ever

- Benchmarking

- Politics

- Literally any hobby

Oh look guys, HN needs to be regulated because I can come up with a person who has problems because of it.

Guys we need to regulate fat and high calorie food. Oh wait it grows on trees.

People who see a problem and immediately go "we need regulation to solve this" (and even proceed to come up with some ad-hoc hypothesis of how it solves the problem after it's proven that it doesn't solve it in a substantial way) are morons. There is actually something wrong with their brain. They hold back progress. Every new law is a potential stumbling block for progress and thus why new legislation should be avoided at all costs. See MECHANISM NOT POLICY article on wikipedia to see how people already knew about this 70 years ago in tech.

To take this one step further: Adding surprise semantics like capturing time (and the dev not being aware of it) will lead to security vulnerabilities (side channels because the code is essentially timestamping when various parts of the code are hit) as well as privacy issues (PII leaking, clock skew leaking, whatever).

My thesis is that computers are so full of unwanted unneeded things like this that there is no engineer who knows them all as well as having a good understanding software engineering as well as infosec. Most vulnerabilities are due to lack of understanding how the primitives work, as opposed to flaws in reasoning (the former is clearly distinct: the summary provided to save him from spending a month looking at the implementation is inadequate).

I have designed UUIDs myself and they are simply a long random bitstring. The random part is already necessary because we need sufficient randomness for crypto to work in the first place. IETF likes to "engineer" things.

No, it isn't. It's a private company determining how and who it conducts business with. Being a 'patrician' of your own property is completely fine and in fact a basic right, and if you don't like Mailchimp's content policies, go to a competitor.

Correct. They can do what they want. However, the title of the article is still correct.

The most annoying thing is that everyone denouncing Apple's action still agree that "CSAM" is a problem that needs action by technology companies (and thus decentralized stuff should be illegal). While "CSAM" is a problem, just like any crime, it's completely overblown and much more rare than they pretend it is. NO. The internet doesn't need regulation. Never.

- Most instances of "child abuse" involve something that matches the legal term, but involves teenagers and is almost certainly not abuse

- Lots of conservatives want to punish said teens and anyone involved for sexuality and go along with the sophistry of calling people abuse victims when they have consensual sex or post their nude photos online

- Naturally, there is no incentive to look at naked 5 year olds, because that's not how the human body works. This is an edge case and is what the media makes out to be the norm

Stop pretending to have a "mature perspective". Companies should literally never touch your data unless there is a search warrant. Now that I read this article I'm concerned about what WhatsApp is doing.

I am truly sorry for your loss in that your brain is implemented using regex.

I meant "white collar big boys", but I did not bother to edit as I'm writing.

The guy above is claiming everyone who is against apple's yet-another-bogus-TPM-style-snakeoil is a little geek who does not understand anything outside their little tunnel.

Also now that I re-read his comment:

Edit: After digging in, HN commentary is missing the most relevant details about this particular implementation. iCloud image checking compares to known CSAM image hashes - this means effectively zero false positive rate.

False: it's a perceptual hash. Ignoring the fact that if for some reason you choose to let people host stuff in your icloud account (perhaps as a neat hack), which may be out of terms of service, but certainly not worth 20 years of jail: perceptual hashes have false positives, and can confuse images that appear harmless but were crafted to look like $badimg. But you don't have to be technical to understand that having your devices police you is bad, you just have to not be blinded by politics and boogeyman your state has sold you.

Am I missing something? Apple says they literally scan stuff locally on your iCrap now and call the police on you if you have $badstuff. Nobody should be having their data scanned in the first place. Is iCloud unencryped? Such a thing exists in 2021? I've been using end to end crypto since 2000. I don't understand why consumers want their devices to do all kinds of special non-utilitarian stuff (I mean I totally understand, it's called politics).

This new iCrap is like a toaster that reports you if you put illegally imported bread in it. It will be just like the toaster which will have no measureable impact on illegal imports. Even if $badguys are so dumb to continue using the tech (iCloud???) and lots go to jail, lots more will appear and simply avoid the exact specific cause that sent previous batch to jail. They do not even thave to think.

The problem with all this is that everyone is applauding Apple for their bullshit, and so they will applaud the government when they say "oh no, looks like criminals are using non-backdoored data storage methods, what a surprise! we need to make it illegal to have a data storage service without going through a 6 month process to setup a government approved remote auditing service".

Then there's also the fact that this is all a pile of experimental crypto [1] being used to solve nothing. Apple has created the exact situation of Cloudflare Pass: they pointlessly made $badip solve a captcha to view a read-only page, and provided a bunch of experimental crypto in a browser plugin to let him use one captcha for multiple domains (they would normally each require their own captcha and corresponding session cookie). They later stopped blocking $badip all together after they realized they are wrong (this took literally 10 years).

1. https://www.apple.com/child-safety/ "CSAM detection" section

You can be against this kind of thing from Apple, but as a result more CSAM will be undetected.

You cannot claim to be making "the real reasonable analysis" and write this. So much for "you're all geeks stuck on technical details". Quite the contrary: I'm sick of bogus software pretending to solve problems for me, while the quality of tech has exponential degraded over the last 20 years (often due to trying to solve some unsolvable problem in a bad way that backfires).

Now imagine you have a 16 year old girlfriend. She sends you a nude photo. Your phone calls the cops on you (it doesn't matter if the phone doesn't quite do this now, it will in the future. They will use their ML crap to detect the age of subjects in photos and explicitness of the photo). You normally wouldn't go to jail for this since 16 is legal in 99% of the civilized world, but thanks to America with their super duper "non-technical" innovations that only big boy white collars can understand, you can go to jail for having a photo of your legal girlfriend.

Yaeh, my point was that it is trivial to define a pad function and call it instead of needing some syntax like Erlang. But now I see there is deconstruction too, which is more arguably useful to take the time to add syntax for.

Can't you just stake more coins in PoS and receive more income? I though this was how PoS coins worked. How else would you even have a notion of people requried to satisfy the condition "all people get the same amount"? Surely not photo ID?

Cryptocurrency:

  - My money is secured by a private key and nobody can touch it ever unless they get my private key. I can simply be cautious about my private key and I know there is no other way anyone can ever get my money
  - I can fill out a text box with the amount I want to send and press send
  - I don't have to deal with some harebrained naming system. I can literally just send to someone's public key. This is literally how cryptography is inteded to work. It's up to _me_ how I obtain his public key.
  - Monero etc exists (admittedly, not sure if it still works when someone has all the mining/stake power)
  - Some guy is getting rich because he owns more miners or stake
Fiat:
  - My password is 8 digits (this is not even an exaggeration, some of the biggest banks in my country do this)
  - The bank might give all my money away if someone knows where I ate KFC last
  - My money may be stolen for other reasons, because the bank wont tell me what data I need to keep private to avoid having someone transact as me
  - The ID they use for authentication was also given to some 30 other e-commerce platforms and cannot be considered secure
  - There is almost certainly a way to get into my account without the password
  - I have to be paranoid and try to keep random trivia private such as how much I payed on an electricity bill
  - I have to type codes from insecure SMS on a phone that I do not want in the first place, because the bank and all e-commerce platforms considers me an idiot and does not even give me an option to turn that shit off
  - If I transfer from one country to another, my transaction may be blocked
  - If I transfer some certain amount, my transfer may be blocked
  - If I use a certain IP address, my transfer may be blocked
  - If I transact at a certain time, my transfer may be blocked
  - If I update Firefox too fast or too slow, my transfer may be blocked
  - If I click buttons to fast or too slow, my transfer may be blocked
  - Someone might hack my computer because it has a Big 4 web browser and the giant stack of software required to support that, instead of a hypothetical OS where people care about security and don't use C, at the cost of some microseconds.
  - If I change my email address (which I don't want associated to banking in the first place) for some reason, my transfer may be blocked
  - When I call the bank, I have to be polite and try to avoid saying anything suspicious (in their own mind) that will make them hold my money yet longer. I will have to supply them will all kinds of nonsense like where I ate KFC last, more ID, and a "phone password"
  - My transactions may be permanently blocked and there's nothing I can do about it because the bank reps just talk to a black box "risk analysis" machine and at some point there's no way to override its decisions
  - Money I receive can be "reversed" for all kinds of bogus, emotional, and/or "risk analysis" reasons
  - The bank can just take my money and claim I was hacked. They have N pieces of my photo ID, address, phone number, email, and much more, and so they can choose a few people they don't like and do this to only them
  - I have to interact with my bank through web pages that crash every 3 button clicks, and PDF files that may or may not render correctly (or snail mail, which is equally full of bad security)
  - Some guy is getting rich because he's positioned a certain way with the bank
TL;DR even if the top cryptocurrencies were effectively centralized by one entity controlling all miner/staking power, I would still want to use them at least for transacting, just so I can have a sane interface to money.

(As someone strongly against adding new features to languages,) I've never understood where there would be any need for anything more complicated than list concatenation when assembling bits. In some language with list notation, (++ being concatenation of two lists) you could do something like this:

[0] ++ sendSeq ++ recvSeq ++ [poll]

say sendSeq was one bit but we still wanted it to take 3 bits:

[0] ++ pad 3 sendSeq ++ poll ++ recvSeq

given some "pad" function defined in a library

The only reason it's "hard" in C is because the operations are induced from what the machine can do efficiently and without "a sufficiently smart compiler".

The author could have been unaware that it's possible to program computers without knowledge of binary arithmetic and bit level operations.

The entire web does this, not just Google.

Alert is pure garbage and should not have made it past the 90s. Also, basic auth popups need to go too. Not sure why browsers would ever make those focus stealing in the first place. There should not be one single way for a web application to steal focus. The current workaround is to download a buggy ad blocker (last time I used chrome, just like firefox it has no way to turn popups off).

Edit: I just remembered alert no longer steals focus on modern browsers (IIRC). But basic auth still does (at least on my 50 year old fork of firefox).

That's not how this works. This discussion is about preventing a something like a server from being exploited. How many stack smashes have you seen against a server written in a memory-safe language?