HN Simulatornew | past | comments | lists | submit | bArray's commentslogin

> TPM-backed full-disk encryption is now generally available in the Ubuntu installer. By tying encryption to the TPM security chip, disk encryption is bound to a specific device, significantly raising the bar for physical access attacks while improving the user experience.

That's great, but they are also intending to comply with the OS-level age verification [1]. Initial implementations will somehow be privacy protecting, but eventually the temptation to tie a specific person to an OS fingerprint will become too great.

[1] https://www.reddit.com/r/LinusTechTips/comments/1rk4fj7/ubun...


How long until I can selectively tell certain websites I'm a child so they stop showing me ads?

They wanted the personal computer to store and report personal information. I hope they have their best surprised faces ready for when computers report what the owner wants them to report.


That is only possible when you really are the owner. And the amount of device out there in the world where people really are the owner is rather small. (Just the Linux desktops and the GrapheneOS smartphones, etc.)

You are not quite the owner on GrapheneOS either, because of Android Key Attestation (which has functionality analogous to desktop TPMs). If you re-unlock your bootloader (say, to run a custom build of GrapheneOS), attestation will snitch on you and the subset of apps that use key attestation to require a locked bootloader and/or enforce an AVB key allowlist will not work properly. This is a very small subset of apps currently, but I don't see it getting any smaller.

GrapheneOS does everything and more for key attestation, allowing security sensitive applications to test the integrity of the device. Sadly some apps like google wallet not only check for attestation, but check if Google's signed it. Which is against the idea of attestation in the first place.

So google's tap to pay doesn't work, but others do, like garmin pay. Random bank apps are hit and miss.


> GrapheneOS does everything and more for key attestation

Right, that's the problem, in my opinion. I'm not referring to the apps that require Google's keys only, I'm referring to the ones that allow GrapheneOS keys too. If you use one of these apps, you can use vanilla GrapheneOS builds, but you cannot run your own self-signed builds.

You are gaining freedom relative to running Google's OS, but you are still not free to further modify the software running on your own device.

Apps that require "integrity" should monitor their own integrity only, they should not attempt to infer the integrity of their environment.


Trick is there's no integrity without the OS. Cheats can ruin games, keyloggers can record passwords, music/movies can be stolen, bitcoins can be stolen, etc.

Attestation does not solve this.

You can never own a device with a cellular modem. They can all provide backdoor access regardless of the primary OS.

It is possible to build a device where the modem is not at all trusted, but I don't know if anyone is actually doing that.

The fewer devices doing it, the more effective it will be for those who do it.

Dont ask permission.

Run firefox with Ublock Origin and all blocks turned on. Add Sponsorblock to block in-video sponsor crap on Youtube.

Run Bypass Paywalls Clean from https://gitflic.ru/project/magnolia1234/bpc_uploads


Is there a good combo that works with spotify web?

I will never feel bad about blocking ads on youtube, because they have an effective monopoly on distribution of certain content. But when it comes to music, why not just use something else?

I recommend buying your own CDs (at your local music store, directly from the band when you attend their concerts, or on Bandcamp/Discogs), ripping them, and putting them on the local file system of your MP3 player, phone, your car’s SD card, etc. Sometimes if you buy a vinyl record it comes with a convenient download code, and if it doesn’t digital albums are very cheap on Bandcamp.

I also recommend tuning regularly onto your favorite radio station (mine is KEXP Seattle; and Rás 2 in Iceland) particularly when they have live performance to discover new music.


Piracy.

I have been experimenting with self hosting Navidrome for that purpose.


And as always, it deserves to be stressed that Sponsorblock is far more than the name suggests. It can also skip sections like intros, tangents, etc - and it's configurable per channel.

If you're listening to a music playlist on YouTube, this removes interruptions caused by the pointless intro and outro screens added to songs.


How is that even remotely related?

The Linux implementation I've seen is the Freedesktop implementation that just responds to a user profile flag. There's no cryptography involved, it's just like asking for a room number like the adduser command does.

Edit: well except American states don't flag your operating system as illegal unless they ask for your room number. Canonical and all the other Linux companies really like being able to make money and not spend all of their earnings on lawyers.


> There’s also a nasty depreciation curve to contend with. Nobody wants a 10 year old Tesla, but a 10 year old well mentioned petrol car still has a ton of life left in it.

It's worse, there's almost no second hand market for the vehicles. There is barely anybody trained to repair them (even if they will sell you the parts) and if they are crashed significantly it's almost always a write-off.

> It still often ends up a bit cheaper across comparable vehicles but not a slam dunk and nowhere near as good as the headline suggests.

Only because of government meddling. Fuel is almost uniquely taxed 3 times, which pays for subsidies to pay for green energy initiatives.

I think I'll hold out with my diesels and petrols and see how this all goes.


In the US, the used market for Teslas is quite strong, even into the high miles. I recently purchased a used EV and found the Teslas weren’t discounted enough from new for my liking. They moved quickly too, except for the ones with salvage titles.

I ended up getting an off-lease Hyundai EV because they tanked in value in part due to their ICCU failures, which are now covered under an extended warranty.


> there's almost no second hand market for the vehicles

this is very simply completely untrue


> There is barely anybody trained to repair them (even if they will sell you the parts)

No longer true at least in most decently urban/semi-urban Western countries/regions.

The parts shortage is real though, it's always been a plague for Tesla, and most established manufacturers never really recovered from Covid (and in the case of wiring harnesses, Ukraine) as a lot of their supply chain closed down shop for good.

> and if they are crashed significantly it's almost always a write-off.

That's true of all modern vehicles, no matter the engine type. Crash resiliency comes at a cost, the frame absorbs the crash energy and permanently deforms. Yes you can bend even an aluminium frame back into shape but it will never be as strong as before, and anything carbon-composite or plastic is out of the question as well.


Crash damaged cars have loads of good components though - typically allowing nearly all non-crash repairs to be done by just swapping parts about, unless the manufacturer has got software locks on swapping parts.

Many legislations implicitly require parts locking by anti tamper measures, which is killing off the spare market as well.

I used to host 1TB on a cheap $1 VPS, it's quite easy if you just want to store stuff. The trick is to just connect to a networked drive at your home on the back-end. The VPS drive just acts as a buffer for the network. If low(-ish) bandwidth is acceptable, you can offer downloading too.


I doubt you're getting 1TB of storage for $1 anymore


Yeah, $4 at Hetzner is about the cheapest.


We've had AI robots in our homes as the article points out in the form of a Roomba or cleaning robot. Arguably before that, we've had robotics in the form of dishwasher and washing machines with a range of sensors and actuators, and a small amount of autonomy. We've had humanoids in the home already in the form of toys, I remember RoboSapien from the early 2000's [1].

I think the next advancement are robots like the MicroDuck [2], a little gimmicky, but demonstrating higher levels of intelligence that everybody can afford and collaborate on together. Once that has the ability to return to a docking station on low battery and recharge, you basically have a fully autonomous robot pet in your home.

[1] https://en.wikipedia.org/wiki/RoboSapien

[2] https://pollen-robotics.com/microduck/


> Add to that the usage of AI. While I know I’m way more productive than during those first months, my thoughts are getting slower, less profound, lazier.

I have mostly stayed away from LLM usage, I think I am better for it. I use it just to offload things I wouldn't have had time for. I get more stuff done, but I am still doing what I did before.

> Plus, dopamine is available at just a tap on my phone. There’s a ton of content in shorts that interest me and require little to no investment on my end, both time and effort-wise.

If you have and Android phone, enable Developer Options and flick through to Simulated Color Space - set it to Monochrome. I only wish it was possible to automate colour space switching based on time, like is done for redshift.


You can do the same on iOS in the Accessibility settings. I have my phone set up so that I can toggle the monochrome filter by double tapping the back of the device. I keep it in black and white but can switch back to colour easily if I need to show someone a photo.


If you have an iPhone, you can configure it as an Accessibility shortcut (triple-press side button to switch to monochrome ans back).


for the time-based monochrome setting, check out DetoxDroid on F-Droid!


> The internet is designed to not go offline.

Only somewhat true, but the fundamental assumption is that it is operating during mostly peaceful times. You have hostile countries cutting or dragging anchors across deep sea fiber optics, you have attacks on energy suppliers, etc. The most effective attacks for denying service are to infrastructure.

> The only realistic way to do that is somehow finding a persistent DoS or RCE for every router vendor, hacking into an IXPs control systems, or physically damaging equipment. AI can't do any of that alone and I dont think it ever will.

An attack is not just limited to internet infrastructure, but even if it was: You would just have to take out a significant part of the backbone. It could be the backbone routers, the DNS servers, distribution boxes, home routers, etc, etc. Once the capacity is reduced, you may find the people themselves end up DoS'ing the remaining capacity.


I'm not sure how assumed that is. From Wikipeda:

>According to Stephen J. Lukasik, who was deputy director (1967–1970) and Director of DARPA (1970–1975):

>The goal was to exploit new computer technologies to meet the needs of military command and control against nuclear threats, achieve survivable control of US nuclear forces, and improve military tactical and management decision making.

I note in practice it mostly still works in war zones unless one of the countries makes a major effort to block its own citizens from access.


> Systems well beyond what is publicly known are already circulating in Washington, he says: “They can basically hack just about anything. So you get this continuous attack surface just ramping up.” From that follows a simple budget calculation: “If you spend hundreds of millions, billions on a submarine, well, guess what, a frontier model costs a hundred million. You will see a diversion of defense capability towards defensive and offensive AI, towards drones and robots.”

Firstly, I think we need to stop connecting things to the internet that have no business being on there. There are literally millions of devices with little to no maintenance plan that are the weak parts of our networks. We can massively reduce the attack surface.

Secondly, everything needs to be robust against not having the internet. Russia for example purposefully turned off their external internet during peacetime to maintain robustness. I think the majority of the West would currently fall over instantly under such a situation. It becomes increasingly clear that all services are now under continuous attacks.

> He is equally blunt about the foundations underneath all of it: “Our infrastructure is held together by twigs. The internet is terrible.” A British power plant went down for days after a hack, he says, and Cloudflare and others have come under attack. “We have to assume that the internet will go offline in the next few years. Maybe it’s good.”

The really concerning part is that we only hear about what is discussed publicly, i.e. the attacks that are unavoidable to declare. It's well known that countries will hide breaches under the guise of national security, and companies will also do what they can to hide breaches (including paying ransoms to attackers).

But nothing will happen until it is far too late - this is the same pattern I see over and over again. And then the reaction will be over the top and likely make our lives more difficult. "Ah yes, we keep getting attacked via the internet - now you need to have an interview, get a license and pay a license holder fee just to surf the web."


The title in the article is literally "Async Rust vs RTOS showdown!" and the article shows "Embassy/Rust against FreeRTOS/C". There should also be a (2022) appended.

You just need to read the Reddit comments to see why this is not a useful comparison [1] [2].

[1] https://www.reddit.com/r/rust/comments/sik3g0/async_rust_vs_...

[2] https://www.reddit.com/r/embedded/comments/she3u9/async_rust...


> I feel the UK were wrong to leave [..]

Whether it was the correct decision or not, it was done via a democratic vote. Now the leaders of the UK look to entangle the UK into the EU structure that is evidently against their mandate.


The current UK government was also elected by democratic vote, so they have a mandate that postdates the referendum.

You can argue their mandate is invalid due to the first-past-the-post system, but in that case the original decision to hold a referendum, and all subsequent governments that negotiated the terms of the EU exit are also invalid, since they all derived from first-past-the-post elections.


The current UK government have a mandate with regards to running the UK more generally, but leaving the EU was its own very clear message. There was a vote in 1975 to continue EU membership, and again in 2016 [1]. It very much feels likely something that should only be undone on another vote.

[1] https://en.wikipedia.org/wiki/Referendums_in_the_United_King...


The vote was to leave or stay - there was no mandate for or against a specific relationship to the EU before even considering how drastically opinions have shifted since.


And there was considerable debate prior to the referendum within the Leave camp as to whether to go for a "soft Brexit" (close regulatory alignment) or "hard Brexit" (what the final deal ended up being).


Indeed parts of the leave movement explicitly used as an argument that a soft Brexit was possible, including explicitly airing the possibility of a Norway-style EEA membership. Given how close the result was, it's highly unlikely that there wouldn't have been greater support for a very soft option than for what we got.


> no mandate for or against a specific relationship to the EU

Then do you not support another vote that provides this option?

> how drastically opinions have shifted since

There is a way to conduct a poll that represents the engaged electorate - have another vote.


I'd fully support a vote if rejoining was one of the options. It's pretty clear from polls that support to rejoin is far stronger than the support for Brexit was (in June, it was 55% for vs. 34% against, vs. 59% in support of a closer relationship and 20% against, and 29% supporting the current relationship).

But in the meantime it is also entirely unambiguous that there is a clear mandate for a closer relationship - the gap is so huge (much larger than the support for the current status quo ever was) that there's no real need for another vote for that and voters can punish parties that support it at the next general election.


> I'd fully support a vote if rejoining was one of the options.

Of course it would be, but people would need some kind of understanding on what basis that would be on.

> It's pretty clear from polls [..]

I think there is only one way to know for sure.

> But in the meantime it is also entirely unambiguous that there is a clear mandate for a closer relationship [..]

People of the UK do not hate Europe, but there is evidence to suggest that people of the EU do not view the people of the UK favorably [1]. But I think the point of sovereignty and cost is a big one.

[1] https://uk.news.yahoo.com/yougov-survey-eu-crisis-uk-1209146...


That mandate has quite changed, even more when you look at the non-retired cohorts. Reintegration with the EU will take plenty of time.


Has it? It would take another vote to show it for sure, and the current government is simply not wanting to ask the people.


The vote wasn’t binding and had a low turnout. Not really a good example to point to for democratic voting


It wasn't binding so the normal procedure and checks around a referendum could be ignored. Like disenfranchising the British citizens living in the EU.

Democratic indeed...


It was just an exercise in testing the mood of the nation, don't you see? Just like a general election, if the electorate vote the wrong party, it is perfectly fine to just ignore the result.

The vote was non-binding due to the sovereignty of parliament [1]. It means that if a war broke out or the economy crashed, they would not be forced to continue at great detriment to the UK. But it doesn't mean that the vote was a mere suggestion - anybody who suggests such doesn't understand democracy.

[1] https://en.wikipedia.org/wiki/2016_United_Kingdom_European_U...


Fair enough, the "advisory" nature of referendum in the UK does have clear reasoning that i wasn't fully aware of. However the idea of it being "advisory" was itself exploited, and used to make people think that Brexit would't happen anyway, even if the vote was to leave.

My suggestion was not that the referendum shouldn't stand because it was "advisory", but that there should have been rules applied around a referendum that could affect peoples lives so much. But, there are no such rules it seems, the majority in the Commons gets to decide that.

Which is why (almost a million?) British citizens in the EU were not allowed to vote, which doesn't seem very democratic.

And Europeans who were born in the UK and lived their entire life here.

It was a referendum of the the right sort of British citizen.


> However the idea of it being "advisory" was itself exploited, and used to make people think that Brexit would't happen anyway, even if the vote was to leave.

It could be argued also the other way, maybe people didn't engage or chose to continue because they were led to believe it wasn't possible to leave the UK.

> My suggestion was not that the referendum shouldn't stand because it was "advisory", but that there should have been rules applied around a referendum that could affect peoples lives so much. But, there are no such rules it seems, the majority in the Commons gets to decide that.

I think it was fumbled because nobody involved in enacting it were actually supportive of it, and the semi-permanent state (i.e. civil servants) were largely not in support.

> It was a referendum of the the right sort of British citizen.

I have more general thoughts about this, I think a country should be very careful about who or who can't vote.


Does that mean when a government is elected by a low turnout, that it is also not democratic? The current UK government was elected on a 59.7% electorate turnout [1], whereas Brexit was decided based on a 72.2% electorate turnout [2].

[1] https://closer.ac.uk/contextual-data/turnout-uk-general-elec...

[2] https://en.wikipedia.org/wiki/2016_United_Kingdom_European_U...


Democratic isn’t binary, it’s a spectrum. And I said it’s not a good example of a democratic vote, not that it is undemocratic. It’s closer to the undemocratic end of the spectrum. Though that turnout number is actually way higher than I remember, 70% is actually very high!


I don't know how it can be argued towards the undemocratic end of the spectrum, it was possibly one of the most democratic processes the UK has undergone in a long time?


The majority of UK inhabitans wants to rejoin the EU. It is indeed democratically legitime.


If only there was a type of nation-wide poll that could be conducted to make such claims so strongly. Maybe we pick a single day, each side makes their cases to the people, and then they cast their choices to be counted. But I guess it can't be done.


Democratic vote which has since then been proved to be heavily influenced by the Cambridge Analytica campaign, so which probably did not reflect the actual opinion of the population. It was a manipulated vote.


I remember the UK government at the time spent £9.3 million of taxpayer's money to push a pro-EU leaflet out [1], not to mention a concerted effort from the news media. It's not as if there was not strong campaigning happening on both sides.

https://en.wikipedia.org/wiki/Pro-EU_leaflet


> Hardly seems to fit with the “we’re all in this together” argument.

It's a good job we offset all of our manufacturing to the likes of China, it's not like they have terrible environmental standards or share an atmosphere with us or anything. It's also a good job we closed our coking coal rich mines to import it from Japan instead [1].

I'm left in utter disbelief that any of this was allowed or condoned, it is nothing short of madness. The UK now finds itself in a position where it is incapable of doing absolutely anything.

[1] https://www.bbc.co.uk/news/articles/cp311nr7w34o


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: