HN comments - Digest ⚙️ Edit Settings

Period: 2024-12-28 20:02 - 2025-01-05 00:01 📚 All Digests

AI Digest

新评论总结

为什么加拿大应该加入欧盟

我很富有,但不知道该做什么

代码挑战活动2024年纯SQL版

告诉HN:无法通过Cloudflare挑战影响我的浏览体验

我今天的一篇论文被拒绝了

DOOM CAPTCHA

2025新年快乐

美国信用卡违约率激增至2010年以来最高水平

告诉HN:互联网先驱约翰·弗里尔去世

AI公司导致论坛流量激增

“Obelisks”:人类消化系统中的新生命类别

关于SQLite的有趣事实

通行钥匙技术优雅,但绝对不是可用安全

吉米·卡特去世

苹果照片在iOS 18和macOS 15中收集数据

我自动化了我的求职申请过程

苹果照片在iOS 18和macOS 15中收集数据(评论续)



Details

bestcomments

  • New comment by BJones12 in "Why Canada Should Join the EU"
  • Content:

    > Europeans could learn from Canada how to allow immigration in a fashion that the population embraces rather than tolerates

    Clearly the author is ignorant. Canadians are sick of immigration. Young Canadians doubly so. Racism is becoming more acceptable by the day.


  • New comment by antics in "I am rich and have no idea what to do"
  • Content:

    You are catching a lot of flak for this, but there is one thing you are right about. If you make tens of millions of dollars, and can't figure out what to do with those resources, you shouldn't be calling your coworkers NPCs. You're the NPC.

    I truly mean this in an entirely non-judgemental way. I wish the author luck in achieving his dream of becoming high agency rather than simply high freedom. I wish it for everyone who wants it.


  • New comment by pech0rin in "I am rich and have no idea what to do"
  • Content:

    This is the most childish thing I’ve read. And shows a lot about he doesn’t have any people relying on him or community to support. He takes one hike and throws away 60m. Doesn’t try to find anything interesting to do at Atlassian just calls his coworkers NPCs. This is zero-empathy Peter Pan syndrome at its worse.

    Sad how he just goes adventure hopping to try and find meaning. The problem is no matter where you are you are also there. Time to look inward and not outward.


  • New comment by akamaka in "I am rich and have no idea what to do"
  • Content:

    > I should work for Elon and Vivek at DOGE and help America get off its current crash to defaulting on its own debt

    I’ve got an idea: take some good economics courses so that you learn how government spending actually works.


  • New comment by madrox in "I am rich and have no idea what to do"
  • Content:

    I don't think you have to have Fuck You Money to get to this point. Most people eventually become disillusioned with work enough that they reevaluate what matters to them. Getting a very profitable exit is just one way to trigger that experience.

    In my experience, a lot of people who get into this state start self-sabotaging hard as a way of rejecting what feels, ironically, like losing control. Sudden freedom can feel foreign and lot like your world got forcibly taken away from you. I'm not surprised the author is turning down opportunities and breaking off with his girlfriend. It's a way of taking back control.

    When this happened to me, I pivoted hard from getting satisfaction out of what I built to getting satisfaction out of developing people. Now I take great pride out of the careers I've nurtured...a lot more than what I've built, in most ways. I've heard others express similar ideas in different ways, like "I now enjoy making other people rich."

    No matter what, I encourage the author to use this time to build connections instead of destroying them (real connections...not work or SF acquaintances). Something I did not read in this essay is how he grew closer to anyone (in fact, I read the opposite). No path out of this valley involves traveling alone.


  • New comment by cj in "I am rich and have no idea what to do"
  • Content:

    I don’t think his problem is money.

    I think his problem is his identity (founder of Loom) suddenly disappeared.

    Now he needs to develop a new identity.

    This is especially difficult for single founders without kids (in the sense that people with spouse/kids already derive much of their identity from those 2 things).

    Selling a company isn’t all that different from going through a divorce (in the sense that your identity needs to be completely rebuilt from scratch)


  • New comment by scop in "Advent of Code 2024 in pure SQL"
  • Content:

    I reacted to this title the way I react a new menu item at Taco Bell: a strange mixture of desire, shame, and admiration for human ingenuity.


  • New comment by Animats in "Tell HN: Impassable Cloudflare challenges are ruining my browsing experience"
  • Content:

    > The "unsubscribe" button in Indeed's job notification emails leads me to an impassable Cloudflare challenge.

    That's a CAN-SPAM act violation.

    FTC: "Tell recipients how to opt out of receiving future marketing email from you. Your message must include a clear and conspicuous explanation of how the recipient can opt out of getting marketing email from you in the future. Craft the notice in a way that’s easy for an ordinary person to recognize, read, and understand. Creative use of type size, color, and location can improve clarity. Give a return email address or another easy Internet-based way to allow people to communicate their choice to you. You may create a menu to allow a recipient to opt out of certain types of messages, but you must include the option to stop all marketing messages from you. Make sure your spam filter doesn’t block these opt-out requests."[1]

    Experian was recently fined for making it hard to opt out of their marketing emails.

    The actual regulation text:

    § 316.5 Prohibition on charging a fee or imposing other requirements on recipients who wish to opt out.

    Neither a sender nor any person acting on behalf of a sender may require that any recipient pay any fee, provide any information other than the recipient's electronic mail address and opt-out preferences, or take any other steps except sending a reply electronic mail message or visiting a single Internet Web page, in order to:

    (a) Use a return electronic mail address or other Internet-based mechanism, required by 15 U.S.C. 7704(a)(3), to submit a request not to receive future commercial electronic mail messages from a sender; or

    (b) Have such a request honored as required by 15 U.S.C. 7704(a)(3)(B) and (a)(4).

    That seems to cover it. File a CAN-SPAM act complaint ([email protected]). Send a copy to the legal department of the sender.

    [1] https://www.ftc.gov/business-guidance/resources/can-spam-act...


  • New comment by cperciva in "One of my papers got declined today"
  • Content:

    In 2005, my paper on breaking RSA by observing a single private-key operation from a different hyperthread sharing the same L1 cache -- literally the first publication of a cryptographic attack exploiting shared caches -- was rejected from the cryptology preprint archive on the grounds that "it was about CPU architecture, not cryptography". Rejection from journals is like rejection from VCs -- it happens all the time and often not for any good reason.

    (That paper has now been cited 971 times according to Google Scholar, despite never appearing in a journal.)


  • New comment by dwaltrip in "Terence Tao: One of my papers got declined today"
  • Content:

    Hilarious irony:

    > With hindsight, some of my past rejections have become amusing. With a coauthor, I once almost solved a conjecture, establishing the result with an "epsilon loss" in a key parameter. We submitted to a highly reputable journal, but it was rejected on the grounds that it did not resolve the full conjecture. So we submitted elsewhere, and the paper was accepted.

    > The following year, we managed to finally prove the full conjecture without the epsilon loss, and decided to try submitting to the highly reputable journal again. This time, the paper was rejected for only being an epsilon improvement over the previous literature!


  • New comment by charlesabarnes in "DOOM CAPTCHA"
  • Content:

    I tried to do it the intended way, but found it too difficult. I was able to cheese it by staying in the starting area and killing the enemies that spawned to the right.


  • New comment by Donald in "Happy New Year 2025"
  • Content:

    45^2 = 2025

    Happy perfect square year, everyone. The previous one was 1936 and the next one will be 2116.


  • New comment by davidclark in "US credit card defaults jump to highest level since 2010"
  • Content:

    > Credit card delinquency rates, which are seen as a precursor to write-offs, peaked in July, according to data from Moody’s, but have only fallen slightly and remain nearly a percentage point higher than they were on average in the year before the pandemic.

    This is a prime example of a style of reporting that really grinds my gears.

    The citation is clearly to another internet source, so a link should be provided. If it truly cannot be linked because it is private, more context is still needed to understand what this data means.

    I actually can’t find the source myself, but I can find “Delinquency Rate on Credit Card Loans, All Commercial Banks” from the Federal Reserve. [1]

    The percents from that source somewhat match those referenced in the FT quote. “Peaked in July”

    - 2024Q1 3.15%

    - 2024Q2 3.24%

    - 2024Q3 3.23%

    Using 2019 as “the year before the pandemic”, the average was 2.5825. Is +0.6475 “nearly a percentage point”? I guess it technically would round up.

    Seemingly important context that the quote doesn’t give is that 3.23% is lower than any time 1991Q3 to 2011Q4. But, maybe the trend matters more for this metric.

    [1] https://fred.stlouisfed.org/series/DRCCLACBS


  • New comment by ghewgill in "Tell HN: John Friel my father, internet pioneer and creator of QModem, has died"
  • Content:

    I worked with John for a few years in the 1990s. This was during the heyday of BBSes, when he joined our small team at Mustang Software after Mustang bought Qmodem. John moved to Bakersfield California (with his family, including OP!) to be with us. John left a few years later due to I think business differences with management.

    John was personable and full of joy. He always loved a good joke. I remember the parties (not wild, we were pretty tame back then) we would have around the pool at his place. He was generous with his time.

    The story of Qmodem itself was a bit different. Qmodem for DOS was a one-man shareware business and was John's pride and joy. It was clear that he poured everything into that program. It was finely tuned and just worked. Times were changing though, and people were calling for a Windows version. Unfortunately, John was not interested in learning Windows programming, so Scott Hunter (now at Microsoft), Dan Horn, and I built Qmodem for Windows. It was good, but it really never had the same level of polish that John's work did. It was "Qmodem" in name only.

    After John left Mustang he also left Bakersfield and I lost touch with him. I'm sure he continued to make the people around him smile. Thank you for your time and contributions, John.


  • New comment by markerz in "AI companies cause most of traffic on forums"
  • Content:

    One of my websites was absolutely destroyed by Meta's AI bot: Meta-ExternalAgent https://developers.facebook.com/docs/sharing/webmasters/web-...

    It seems a bit naive for some reason and doesn't do performance back-off the way I would expect from Google Bot. It just kept repeatedly requesting more and more until my server crashed, then it would back off for a minute and then request more again.

    My solution was to add a Cloudflare rule to block requests from their User-Agent. I also added more nofollow rules to links and a robots.txt but those are just suggestions and some bots seem to ignore them.

    Cloudflare also has a feature to block known AI bots and even suspected AI bots: https://blog.cloudflare.com/declaring-your-aindependence-blo... As much as I dislike Cloudflare centralization, this was a super convenient feature.


  • New comment by ababaian in "'Obelisks': New class of life has been found in human digestive system"
  • Content:

    Cool :) I'm a co-author on this. AMA.

    This is now a peer-reviewed paper, published last month in Cell [https://www.cell.com/cell/fulltext/S0092-8674(24)01091-2].

    Obelisks are part of a larger research program we're developing at the University of Toronto + collaborators, see also: Virus-Viroid Hybrids paper [https://www.nature.com/articles/s41467-023-38301-2] and the Zeta-Elements [https://www.nature.com/articles/s41586-021-04332-2].

    Computational biology is driving a revolutionary expansion of our understanding of Earth's biodiversity. I believe Zeta-elements, Ambiviruses, and Obelisks are just the beginning. If you're interested, our "Laboratory for RNA-Based Lifeforms" (University of Toronto) is hiring passionate developers/post-docs/graduate students [https://www.rnalab.ca].

    Edit: OK going to call it for now. I'll check in later today if there's any outstanding questions.


  • New comment by chrismorgan in "Fun facts about SQLite"
  • Content:

    > SQLite is not open source in the legal sense, as “open source” has a specific definition and requires licenses approved by the Open Source Initiative (OSI).

    This is wrong, and harmfully wrong. OSI are not the arbiters of open source. Their Open Source Definition, though generally useful and accepted, is not without legitimate criticism and controversy. As for their approval, that’s a dreadful thing to rely on for any purpose; <https://writing.kemitchell.com/2019/05/05/Rely-on-OSI.html> is a good description of most of what’s wrong with it (it doesn’t really get into the broken politics enough; but some of his other articles contain more), and I like its summary: “The list of OSI-approved licenses reflects OSI’s practical and political history, not any useful, consistently functional category of license terms.”

    As for whether SQLite is open source, well, the only reason a public domain dedication doesn’t meet the OSD is that it’s not a license. It’s more open. In a way that is legally mildly uncertain in some jurisdictions, sure, but to call it “not open source in the legal sense” is just wrong.


  • New comment by freetonik in "Passkey technology is elegant, but it's most definitely not usable security"
  • Content:

    In some parallel universe, each computing device manufacturer is required by law to provide a storage so that the user can plug in their single, universal, transferrable set of security credentials (like passkeys). Instead of "many cooks" mentioned in the article, there is one standard.

    I cannot bring myself to agree to any "switch to passkey" prompt from any device because I have no idea (and too tired to figure out) how and where that key will be stored, how do I deal with different devices, etc. I already have a universal solution for credentials: 1password, which is cross-platform. With Apple's keychain, and I suspect other companies' solutions, passkeys are connected to your account and at best synced between devices from the same manufacturer. But even with Apple, I can't sync stuff between my personal and work computer because they use different Apple IDs, even though the underlying true identity (me) is the same.

    Like with many other solutions, the current approach with passkeys is designed for an imaginary "user in vacuum" model each company dreams about, where people are 100% into one ecosystem, forever.


  • New comment by jmclnx in "Jimmy Carter has died"
  • Content:

    Looking back, to me he was a much better president then people believed in the 80s.

    I believe if he got re-elected in 1980, the US would be in a much better place. One thing, it could be argued real work on Climate Change would have begun in 1981 as opposed to where we are now, which is just watching the average probably blowing past 3C in around 70 years from now.

    For his loss in 1980, I still blame Kennedy.

    RIP, he did a lot to help regular people through his life, far more than our current crop of politicians.


  • New comment by jchw in "Apple Photos phones home on iOS 18 and macOS 15"
  • Content:

    What I want is very simple: I want software that doesn't send anything to the Internet without some explicit intent first. All of that work to try to make this feature plausibly private is cool engineering work, and there's absolutely nothing wrong with implementing a feature like this, but it should absolutely be opt-in.

    Trust in software will continue to erode until software stops treating end users and their data and resources (e.g. network connections) as the vendor's own playground. Local on-device data shouldn't be leaking out of radio interfaces unexpectedly, period. There should be a user intent tied to any feature where local data is sent out to the network.

    So why didn't Apple just simply ask for user permission to enable this feature? My cynical opinion is because Apple knows some portion of users would instantly disallow this if prompted, but they feel they know better than those users. I don't like this attitude, and I suspect it is the same reason why there is an increasing discontent growing towards opt-out telemetry, too.


  • New comment by MrMember in "I automated my job application process"
  • Content:

    I'm seeing a lot of back in forth in the comments between hiring managers and employees discussing who is more responsible for the current situation, but from the perspective of someone looking for a job what should I be doing?

    I've been pretty aggressively looking for a job for the past six months or so. I have 10+ years of professional software dev experience so I've mostly been looking at senior dev positions. I haven't used LLMs at all in my resume, cover letters, etc. I only apply to jobs that I believe I meet the requirements for and that I would likely accept if given an offer. How do I signal that 1) I am a real person 2) I really do have the job experience and skills listed on my resume, and 3) I really am interested in the specific job I'm applying for. Because doing this my hit rate has been abysmal. I've had maybe 10-12 initial phone screens (never an issue, I easily make it past these). Past that I've had maybe 3-4 interviews that get into the later rounds. From that I've had zero offers.

    So why should I keep doing what I'm doing when it's getting me nowhere? Why shouldn't I switch to an automated "shotgun" approach that applies me to as many jobs as possible to which I vaguely fit the requirements? The only other way I've seen suggested to signal that I'm a real person with real experience is to know someone in the company who can vouch for me (which I almost never do).


  • New comment by scosman in "Apple Photos phones home on iOS 18 and macOS 15"
  • Content:

    "I don't understand most of the technical details of Apple's blog post"

    I do:

    - Client side vectorization: the photo is processed locally, preparing a non-reversible vector representation before sending (think semantic hash).

    - Differential privacy: a decent amount of noise is added the the vector before sending it. Enough to make it impossible to reverse lookup the vector. The noise level here is ε = 0.8, which is quite good privacy.

    - OHTTP relay: it's sent through a 3rd party so Apple never knows your IP address. The contents are encrypted so the 3rd party never doesn't learn anything either (some risk of exposing "IP X is an apple photos user", but nothing about the content of the library).

    - Homomorphic encryption: The lookup work is performed on server with encrypted data. Apple can't decrypt the vector contents, or response contents. Only the client can decrypt the result of the lookup.

    This is what a good privacy story looks like. Multiple levels of privacy security, when any one of the latter 3 should be enough alone to protect privacy.

    "It ought to be up to the individual user to decide their own tolerance for the risk of privacy violations." -> The author themselves looks to be an Apple security researcher, and are saying they can't make an informed choice here.

    I'm not sure what the right call is here. But the conclusion "Thus, the only way to guarantee computing privacy is to not send data off the device." isn't true. There are other tools to provide privacy (DP, homomorphic encryption), while also using services. They are immensely complicated, and user's can't realistically evaluate risk. But if you want features that require larger-than-disk datasets, or frequently changing content, you need tools like this.