HN user

wmt

1,203 karma
Posts6
Comments222
View on HN

This not an anti-Trump story. The story is about the DA and the police filing obviously wrongful felony charges.

Sure, a bigger number of protesters also got similar charges, but that's not a big news because it's everything but obvious that the charges are bogus.

With reporters covering the event the situation is different. Mass arrests during riots I fully understand, and then reporters may get caught up in the net, but after you identify the reporters, you let them go. You don't file felony charges against reporters filming the event, unless of course you are a crooked DA.

The Nordics, where having kids also increases your happiness, are also very high on individualism as opposed to collectivism. The key difference to the US are the public policies that allow families never to stress about things like arranging daycare to the kids from the day they born.

These policies are not there to combat individualism, but to enable it with taxpaid support networks. Most of them are not poor aids, but state benefits that everyone enjoys, like the free or cheap high quality daycare used by the poor and rich alike.

How much more? I always imagined that it's more likely for a standard user to open every email attachment and execute it than it is to get targeted by a malicious attacker who knows what software your users are running and writes exploits tailored for them, but I could be wrong.

Typical AV for Linux is for server products serving mainly Windows clients, and the Windows clients are more probable to run random binaries.

Linux malware, outside of someone trying to crack the computer, largely doesn't exist because have you ever tried to ship binaries for all Linux distros?

Yet, Tor pages I've read certainly weren't describing themselves as a tool of U.S. intelligence agencies funded by their fronts.

I'm not sure DARPA or Naval Research Laboratory are really intelligence agency fronts.

https://www.torproject.org/about/sponsors.html.en

Tor is supported by intelligence agencies because of the value it brings to them. For someone undercover, Tor is a great way to keep in touch, and if you're confronted you have a plausible explanation of wanting to buy LSD or watch kiddie porn or whatever most people use Tor for.

I wonder how does that even work? If someone drops in an injured person and leaves, will the hospital just let the injured person die on the floor? If bystanders doing nothing raises headlines in India, I'd imagine hospitals doing that would be an even bigger scandal.

I always though it was a reference for covering the ground around strawberry plants with dry straws. Strawberries especially go bad if the berries touch moist ground, gathering mold or fungus, and you'll also want to avoid weeds, so a thick layer of dried straws work perfectly for farming strawberries.

I think the real title is "The Oxford Etymologist doesn't know how strawberry got their name"

About those tests, you should know that the testing orgs are using an array a computers with up-to-date AV solutions, and then making them all go to e.g. websites dealing malware right then as soon as they find a new sources of malware attacks.

I honestly cannot imagine a better way to objectively test how well the products fare against attacks against an average Internet user.

Edit: If I was not clear, nobody tests with historical samples anymore. Only live attacks are being used for tests.

The only tests against real malware out there I've seen are done by AV-Test and AV-Comparatives, and the top products are pretty good at blocking them. Calling them useless sounds more like your hopes than facts, like calling seatbelts useless because people die in car accidents.

Uninstalling Flash, Adobe reader, Office and JRE, and using Chrome with adblock also helps you enormously, but is still a far cry for any user having difficulties with finding the download-button from sourceforge.

Getting a signing cert is easy as just buying one from Honest Achmed's Used Cars and Certificates, so the only real use for signed software with malware protection is to manually maintain your own list of trusted signers.

It's a really sad truth that to this date the only effective way to almost fully stop malware is to take away the ability from people to do what they want with their computers.

All operating systems that have some way to allow people to run malware, will get malware. Windows, OSX, GNU, Android all can get infected quite easily. Then there's iOS where you cannot, and instead Apple decides which software you can or cannot run.

The downside is of course that you cannot run any software going against the corporate values of Apple.

If you want the right to shoot yourself in the foot, AV is the necessary evil you must have, unless of course you're sure you'll never visit a website that contains an exploit, old or zeroday, against you browser or its components, and you will never open a office document, PDF or executable that has malware in it. And even then you can get owned.

The funny thing is that we can measure reality with all kinds of instruments, and based on those measurements have been able to make theories (in the scientific meaning of the word) that have taken us to other planets of our solar system.

So yeah, I'd say our perception of reality is pretty okay.

Agile is Dead 10 years ago

Agile and was indeed the OOP Design Patterns of the late 2000s. Sure, there's many smart things in it, and many of those will survive, but when consultants started selling cargocultish dance moves you have to do to succeed, and where all failures happened because you were just not pure enough, it became as awkward as AbstractsSingletonFactories.

Why would you want to do that with ruby script instead of your favorite editor, or tr/sed on the commandline? And why would you write a "Close file" comment before file.close?

If you just read the reasons why you shouldn't use it for comparisons, you should also understand why it's pointless to use VT for testing if you bypass AV or not. To quote:

-VirusTotal's antivirus engines are commandline versions, so depending on the product, they will not behave exactly the same as the desktop versions: for instance, desktop solutions may use techniques based on behavioural analysis and count with personal firewalls that may decrease entry points and mitigate propagation, etc.

-In VirusTotal desktop-oriented solutions coexist with perimeter-oriented solutions; heuristics in this latter group may be more aggressive and paranoid, since the impact of false positives is less visible in the perimeter. It is simply not fair to compare both groups.

-Some of the solutions included in VirusTotal are parametrized (in coherence with the developer company's desire) with a different heuristic/agressiveness level than the official end-user default configuration.

"Americans who went to college and graduate school did well. They scored above their peers with similar degrees in other developed countries.

For young adults with a high school diploma or less, things did not look so good. These Americans performed significantly worse than those in other countries with the same education level."

Doesn't that just mean that smart kids in America are more likely to get a higher education than in other many other countries?

The focus on Apple writing the OS is something I've wondered about the whole debate, as the core of the issue was never about writing the code, but signing it.

The FBI also could've ordered Apple to sign their house-made FBIOS for iPhone to crack the decryption, and Apple complying would've undermined the iOS security at least as must as the current scenario.

There you go again, misunderstanding what was actually said. I never questioned your understanding of the technology, but your understanding of what Krebs says.

Krebs also understands the technology, and quotes David Qu from Foscam about how their P2P technically works.

Maybe you should read the story again. The core focus of the criticism is directed at punching holes through firewalls by default, and in this case you cannot even disable it.

"This is a concern because the P2P function built into Foscam P2P cameras is designed to punch through firewalls and can’t be switched off without applying a firmware update plus an additional patch that the company only released after repeated pleas from users on its support forum."

Later he quotes Nicholas Weaver from ICSI:

"Given the seemingly cavalier attitude and the almost certain lack of automatic updates, it is almost certain that these devices are remotely exploitable."

On Windows version big repositories are now noticeably faster than with the old version, which makes this feel like an improvement despite its glaring flaws, like the hassle for the mandatory registration with a bogus mailinator email-address, or the brand new UI bugs.

Finland still carries horse meat, but it's still a rarity, as nobody grows horses for making meat, and it's just adult horses that were put down for some other reason. The nice thing about it being so rare is that it's really cheap! You might get a good horse steak from the meat counter half the price of the best beef steaks, and it's much better than any beef steak I've ever eaten in any country.

Reindeer steaks on the other hand, those are among the best steaks made out of any animal I've eaten. There the price comes from the fact that reindeer herds need hundreds if not thousands of square kilometres to roam freely. The good thing is that Finland has 123 000 sqkms of wilderness (roughly the size of Greece or Mississippi) officially dedicated for herding reindeer!

I’ve worked 80-hour weeks for the past decade (occasionally 100-hour weeks)

Wow. This if anything will screw you up. 12 hours of work + 8 hours of sleep per day 7 days a week leaves you with 4 hours for commuting, showering, making dinner, doing laundry, working out and relaxing.

Doing eighty hours per week can be wonderfully efficient - for a few weeks. After that you start to get sloppy, and soon you're performing worse than those doing a 40 hour week. Work a not a sprint, and not even a marathon, and more like running around the globe because you like to run.

Work shouldn't even be means to an end of becoming rich, and being rich without a respected job you're proud of is boring and hollow. Unlike prestige, once your income or wealth exceeds the limit where you have to stress about money, having more money won't make your life happier.