Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
isilofi
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
isilofi
3y ago
Nobody in power in industry and almost nobody from the consumer side cares about working conditions in any typical outsourcing country. Quite the opposite, "less regulation", "lower cost" and things like that are directl
32.
▲
by
isilofi
3y ago
Yes, but to make this "self-consistent" 0 * 0 = 1 would need to hold. And I'm totally sure that they don't have that...
33.
▲
by
isilofi
3y ago
Upon a closer look, do not trust the numbers on https://rust-random.github.io/book/guide-rngs.html in any way, they are clearly bogus and implausible. Their figure for their "StepRNG" which is just a counter
34.
▲
by
isilofi
3y ago
For many kinds of Monte Carlo algorithms, CSPRNGs are stupidly slow. The author compares two handpicked examples of a fast CSPRNG and a very slow PRNG, arriving at a factor of 4. In practice, e.g. comparing to very simple stuff like multipl
35.
▲
by
isilofi
3y ago
Yes. Welcome to the hell of "No debugging, no fixing anything. Call vendor support and hope for the best"
36.
▲
by
isilofi
3y ago
Well. I was in the "analytics is mostly bad" camp anyways. But the things that you just told me are more of the "analytics are far worse than you think" kind. Like "how the hell aren't those people in jail righ
37.
▲
by
isilofi
3y ago
Maybe the app is already modified for such use and just needs to be given a "start spying" command.
38.
▲
by
isilofi
3y ago
Disappointing, no proper Linux support. Just "ask on discord".
39.
▲
by
isilofi
3y ago
If you have something to report, usually you are somehow involved. The company might then try to pin responsibility on you for doing the bad thing and trying to verbally blackmail them.
40.
▲
by
isilofi
3y ago
> You report these things verbally in person, not on written media. I think this is dangerous. If push comes to shove, you will not have anything to defend yourself with, because of no documentation.
41.
▲
by
isilofi
3y ago
I don't know. I just know that they left the company, to everyone's surprise, shortly after something was reported, to work on something completely different two towns over.
42.
▲
by
isilofi
3y ago
Maybe, maybe not. But his main fault was pointing out the possible legal problem. As soon as he pointed to it, simple negligence and a possible Chewbacca defense became intent. Which is a huge difference in legal interpretation and penaltie
43.
▲
by
isilofi
3y ago
I don't know about Jim Rutt, but my overall impression is that most, if not all, companies are supposedly encouraging this culture of giving "bad news" and non-retaliation. Also reinforced by the usual compliance voodoo about
44.
▲
by
isilofi
3y ago
dupe: https://news.ycombinator.com/item?id=38345858 (also dupe, but already moved: https://news.ycombinator.com/item?id=38353937 )
45.
▲
by
isilofi
3y ago
In technical circles, yes. But those things trickle down over time, through the media, marketing drones, bureaucrats and politicians even sometimes down to the rest of the population. So when things are already dead with our kind, e.g. the
46.
▲
by
isilofi
3y ago
"Blockchain" is one of the current buzzwords that has to be slapped on everything. Not long before they do a v2 with "AI".
47.
▲
by
isilofi
3y ago
Yes. Almost none of those get i18n, hotkeys, shortcuts, taborder, screenreaders and other accessibility right.
48.
▲
by
isilofi
3y ago
- It allows a user to easily extend their current work environment (i.e. MS Office applications). Other languages and IDEs could do that, too, but not so easily. This allows users to somewhat more gracefully extend their documents/data
49.
▲
by
isilofi
3y ago
The catholic church in general is kind of a counterexample in certain aspects, but only because of reasons. The Maltese Order is just one aspect of the general weirdness of the church organisation overall, there are also the separate intern
50.
▲
by
isilofi
3y ago
It pretty much is. A government does govern two things, a population and a corresponding land area. You may try to have one without the other, but that would lead to massive problems because of the way humans and their home area interact. I
51.
▲
by
isilofi
3y ago
We shouldn't. TPM-based security is only sufficient against unsophisticated attackers such as a common thief stealing your laptop from your backpack.
52.
▲
by
isilofi
3y ago
You may even kill civilians on purpose to hit a military target, if on balance the military objective justifies the civilian loss of life.
53.
▲
by
isilofi
3y ago
The legitimate and legal (under international law and the articles of war) way is to weigh the military objective against the civilian damage and casualties and decide if this is still a viable target. E.g. it might be legitimate to flatten
54.
▲
by
isilofi
3y ago
No, manually distrusting will probably be considered illegal. "Browsers shall ensure", no exceptions: https://news.ycombinator.com/item?id=38109691 I would also urge you to refrain from using terminology such as &
55.
▲
by
isilofi
3y ago
You can manually distrust hardcoded CAs in all common browsers. But even now, this is rarely used because it is tedious, there are roughly a hundred active CAs. And depending on how that law will be interpreted by courts, manually distrusti
56.
▲
by
isilofi
3y ago
Webapps are also vulnerable because the Javascript can be manipulated in a MitM attack. The only way around this would be a "real" app.
57.
▲
by
isilofi
3y ago
It is "easily", because current commercially available "firewall" appliances include that kind of capabilities. Just a few clicks, install a CA certificate, add a logging endpoint, done. Certain regulated industries like
58.
▲
by
isilofi
3y ago
Website-based end-to-end encryption isn't usually. In most cases, the "e2e-encrypting" website will deliver the Javascript that does the "e2e-encryption", which can easily be manipulated to provide a copy of all mes
59.
▲
by
isilofi
3y ago
There is no way for e2echat.com to make sure that the client will insist on a certain safe CA. Sure, in case e2echat.com controls all clients this would be possible, but this is a rare case. In the general case, any CA can sign any website
60.
▲
by
isilofi
3y ago
I suppose this is the first step towards a stricter kind of the German "Impressumspflicht". Currently, if you are operating a website in any kind of (even most remotely) commercial function, you need an imprint. Lacking one, you g
More ›