Hacker Newsnew | past | comments | ask | show | jobs | submit | K0nserv's commentslogin

I've been reading Steven Pinker's "The Sense of Style". Unlike "The Elements of Style", which is fine, it does a good job anchoring its suggestion in first principals. I do think I need to read a book on grammar to truly appreciate it though.

"On Writing" is another book like "The Elements of Style", both are too prescriptive, albeit not useless.


Steven Pinker’s “The Language Instinct” is not a bad book for learning grammar. It’s a book about linguistics - not specifically grammar, but it covers diagramming sentences, and grammar falls out from there

I found his description of Classical Style very confusing and disorganized. You‘re much better off reading the original, Thomas & Turner.

The one thing you'd expect on a website like this: how the exploit works, is missing.

The entire thing feels like marketing.


I mean, they kind of do? I assume they're hesitant to write a how-to on how to tailor the exploit image:

>These are not out-of-the-box exploits. Exploitation requires fingerprinting the target version and tailoring the payload image(s). Some of our RCE attempts landed only after thousands of image uploads. That said, an AI agentic approach with a frontier model like GPT-5.6 Sol cut exploit development time down to roughly 1 to 3 days from initial probe to remote RCE. A motivated attacker can convert a vulnerable upload endpoint into RCE or an info leak.


I was under the impression the underlying issue has been patched. If it hasn't, this page and their initial blog post seem irresponsible. If it has indeed been patched why not provide a detailed write up?

Even outside of the current administration, isn't BLS data notorious for being adjusted after the fact, often downwards? Basing reporting on fresh BLS data seems ill-advised.


Yeah, it's survey based and some employers don't hit the first few deadlines.

Last month got revised to being positive, at the same time that this month was being released.


I have a slightly different take on the loss of changelogs, although I agree with the version in this post.

My gripe[0] is developers using GitHub’s “releases” feature in lieu of a CHANGELOG.md. This feels particularly pertinent in light of GitHub’s recent performance woes.

0: https://hugotunius.se/2024/01/20/stop-using-github-releases....


The critique is more that the average, or at least loud, C programmer is resistant to fixing these problems (for example via Rust) and often arrogantly claim it's just a skill issue.


The argument sometimes comes off like: "Why aren't you better at juggling double-edged swords that are on fire?" Perhaps the opposite side might say: "Why can't we juggle inertia-powered lighted yo-yos instead?"


With the exception of the C++ case, these all seem to result in DDOS which, while bad, are barely security issues. It speaks to the difference between C and these other languages (Go, Python, Rust).


It's because everything Republicans say is projection. They want to cheat, so accuse the Democrats of doing it first. In actuality it's the current admin that's laying gound-work for election fraud in November.


Looks beautiful, congrats on the launch! I've been looking for a replacement for my Apple Magic keyboard. I would love to buy one, but ISO layout is a must for me, also would like blank or swappable keycaps.


I'm taking a slightly different approach. I've started a project where I intentionally don't use agentic coding. I use LLMs for researcher and to learn, but write all the code by hand.

The goal is to maintain the taste, for lack of a better word, that I've developed over decades of programming.

Claude put me on to the concept "Étude", so I've taken to calling it my Étude project.


I don't want the market solving this. If we are going to do age checks it should be based on public key cryptography, be open source, and handled by the government. You verify with the government (or don't since they already know your age), you get some form of cryptographic attestation, present said attestation to websites/apps.

I'm not a fan of age verification in the first place, but I am extremely not a fan of random third parties doing the verifying.


Why do we need to verify age?

You can't tell me that these social media companies don't already know exactly how old someone is just based on the enormous data that is collected.


A big concern around age verification is that some people will be locked out because they can't prove their age.

Your solution here has the same flaw, I think. If the algorithm thinks I'm underage, I'm locked out.


being locked out = less profit = firing management by shareholders

it will solve by consumers, don't worry


The number of people who are marginalised is... marginal. By definition it doesn't have a sensible impact on profit. That's precisely why it is a problem to be marginalised.


Isn’t that… life?

Even literal regulated electricity utilities aren’t expected to provide service to every last marginal customer.

For example, a poor old grandma missing many electricity bill payments usually will see leniency if she is polite, the utility eventually won’t try to collect cash anymore and instead put a lien on the home while continuing to provide service.

But if the billing department receives multiple threats from her, then they may just cut the service.


I really hope our freedom's aren't relinquished on a platform as fortified as "It is what it is".


This doesn’t make sense?

How does “freedom” relate to an electrical utility deciding whether to cut service?


"Freemdom" is accepting that mostly marginalized people get their power cut because they are marginalized. Your reaction to that is to shrug and move on instead of investigating the systems below that keep the marginalized as so.

Even if we take marginalization out of it, this is the same kind of system that let's Healthcare recklessly utilize AI Systems to automatically reject patients' care, with a Herculean effort required to find a human to talk to. Its easy yo shrug until you are hallucinated into their crosshair.

But sure, that's "freedom".


Even after re-reading this comment, it still reads like gibberish. As if my example was half read, or not at all.

By definition, a billing department of a utility has to be able to “marginalize”… in order to function.

There’s literally no other way I can see for it to work.


Not entirely sure what you are trying to say, other than you don't really care as long as you are not the one who is marginalised.

Anyway it's generally a tradeoff: is it worth doing it? By adding very strict age verification systems and marginalising people, do we make society globally better or not? Will those age verification systems work to prevent underage people from accessing the stuff we don't want them to access in the first place? Not clear. If they do, will it result in underage people being better? Not clear. And if it does, will it have been worth the damage on the people it marginalised? Not clear.


Since my old reply was flagged, this now seems like coordinated trolling.

I really doubt you are genuinely incapable of understanding what “regulated electricity utilities” or “expected to provide service” means.


A whole this voting / flagging system here is basically lottery.

I can't write more than 5 posts per day and I can have negative karma because people doing more downvoting than upvoting.

So there is no point to wonder, if it's coordinated trolling or not.


I didn't downvote you, not sure what you are talking about.


Is this AI written?

I didn’t accuse you of downvoting. It’s literally not possible for HN users to downvote the comment they reply to.

Anyone with seemingly over 10k karma would know that.


I genuinely didn't know :-). I don't generally downvote comments I reply to. I don't downvote when I disagree, I downvote when I believe the comment is very low quality, in which case I don't engage at all.


It won't.

Do you aware how many people are locked out from access of the bank because the bank think they are too risky by some algorithm and no human review?

And people got rejected for flying because they have same name as somebody on no fly list?


yep, just like cases now where people are locked out of their accounts for no reason with no recourse. totally solved!


In the aggregate sure. But do you really think profit motive means they will be precise for every individual?


Because it's all about bringing in digital ID and gated internet. Not age.


They would prefer to know, not estimate, which is why they are pushing these initiatives basically on their own accord.

Also, if you've ever played with this kind of data, there is immense overlap between how some adults and some kids use the internet. Is this user legally a child, or just emotionally a child? Similar to the problem of "There is overlap between the smartest bears and dumbest tourists" in designing bear proof garbage cans.


They do already like YouTube and ChatGPT, so they'll ask for your age only when they're unsure.


And that should be highly illegal to demand that a user submits to age verification.


Why? Sounds like it'd be the exact opposite, if they're showing age gated stuff of course they'd ask for your age.


chatgpt began to spam me pretty hard for last a few months.

chatgpt basically never sent email and it's regular now - like 2 4 emails per month

so, it doesn't look great for chatgpt


If you want to use a service that is age restricted either by law or the company providing it how else would you do it? It's the same IRL. I don't like it as well and we certainly lived through the wild wild west times in the 90s and 00s but the more something gets economical important the more scrutiny it gets. Maybe we just need something new.


Well these kind of laws are trying to legislate technology into existence; we don’t have a means to do it, yet “we demand for the technology to exist through ‘reasonable methods’, now get to work.”

If that’s the nearly infinite wiggle room we’re playing with then I’d say what about Adult and Child versions of phones? You have to flash your ID to the clerk to buy an adult one, like buying cigarettes at a gas station, and then you get to do what the internet offers. Child phones - let parents and governments come up with whatever they want to block. The phone autoupdates in the background with the blocklist, the device can’t do those things. There ya go. Each person and family gets to make their own choices and nobody has to give an ID card to PornHub or a company that literally exists to harvest your information. Win-win?


We already have a version of the child phone: it's parental supervision.

When I was a kid there was no TV in my bedroom nor a computer. Everything I watched or did online was on full display in the family room. What changed in the modern home where that's not the case? Are kids glued to their phones because their parents are too?


I completely agree. In fact the tools already exist to make a “child” phone. I was just giving up some inconsequential ground since many people are apparently stuck on the government padding the earth to protect their fuck-trophy. “OK - government mandated OPTIONAL DNS filtering on all routers. Super easy interface, auto-subscribe to government compiled list.” Scratches their itch and doesn’t affect me since I just won’t enable it, nor will I buy the “child phone”, and I don’t have to send a rectal scan to Facebook either. Yay all around.


This is scary though too. If the gov managed a key server like this, almost all companies would start requiring it. But this effectively gives the gov a very easy way to lock you out of everything.


This is really nothing new and has always be the case It's not possible to tech yourself out of a political problem.

So if there is something being done we should choose a solution that has at least some accountability to the general public (through elected representatives).

The alternative is Google, Apple etc where almost anyone has exactly zero influence and the government can still block as they like.


If all alternatives are bad you should do none of them, not squabble about which one is slightly less bad.


Not doing anything is also an alternative, theoretically it can be worse than other alternatives too...


This will be possible if done by third parties anyway, it will just be apple, google and maybe meta, a single phone call is enough to cut you off. At least if the government is doing it, the app doesn't get your id.


Either the app will get the id, you will be prevented from running arbitrary software on your device, or the whole thing will not work because it becomes trivial to sell your age verification tokens.


Like the government doesn’t already have that power?


As opposed to if google, Microsoft and apple operate the key server and a government can influence them?


I'm already locked out by many of the private companies so...


EU already does this with the eIDAS system and it works quite well.


You're seriously proposing letting governments decide which of their citizens are allowed unrestricted access to the internet?

Of all the 3rd parties who could be responsible for this, I trust the government the least.

But really the best solution here is no third party. The device owner (e.g. parents) should be responsible for setting the user's age when setting up the device. Anything that tries to take that responsibility away from parents and give it to a third party is necessarily going to be highly authoritarian; putting that third party in the role of parent for everyone, adults included.


Out of all the 3rd parties, I think the government is the one that we can more cleanly hold accountable. Not only through voting but also requiring transparency. Is it the perfect system? Hell no, but the incentives for a traditional LLC not aligned with what this kind of service should offer


>>Of all the 3rd parties who could be responsible for this, I trust the government the least.

Really? can you name any 3rd party you'd trust with this more than your own government?

Given that you know, the government already has all of this info on us. This isn't a choice between "the government doesn't know how old I am" and "the government has all the info on me". Governments usually already do. They have enough data already to issue such proof just by the virtue of us living in the country. Tax records, birth records, driving licences, council taxes, passport info, medical information - there's more than enough to give me a cryptographic certificate that says "yes, gambiting is definitely 18 years old" without me having to do anything. Compared to literally any third party that cannot do any of this, unless they buy my marketing cookies on the open market or something, or yes - I actually go out of my way to give them my passport/credit card/selfies etc.


It’s not really about the info but restricting access to people. Imagine they restrict access to social medial to people with different political opinions as the ruling party in the government


The whole idea is that the government gives you a cryptographic token that proves you are over 18, but that token can be used anywhere. They don't get to say what websites can look at it, because...how would they.


The concern isn't that an authoritarian government locks you out of some age-restricted sites, it's that it locks you out of them all.


Well, sure. But that doesn't answer my original question - which 3rd party provider do you trust more with your own data more than the government[which in most cases already has this data]


Data ownership is just one area of concern. Controlling our access to the internet is another.

If age verification was an open standard, we could hope for competition so that we could jump ship from a bad actor. If one blocks our access, we would have alternatives. In theory.

Not so with a centralized government-mandated service.


Who is in charge of certifying implementers? What happens when I provide an implementation and don't verify anything at all?


I'm not saying age verification is a good idea, just that a centralized government-mandated implementation is a bad way to do an already bad idea.


The government can just arrest you and lock you out of all sites. It's not like they cannot do it today.


You can disable Internet access for millions instantly. You can't arrest millions.


Again, this can be done already? Look at any authoritarian country killing internet access the moment anything happens.


This could be more targeted, like a no-fly list for the internet. Political dissidents, journalists, etc. could be effectively exiled from online activity.


If it has to happen, this is exactly how it should. Please feel for those of us in the UK who are currently denied access to some pretty significant services unless we send our passport to a random third party.


> some pretty significant services

What services are those other than p*rn?


This is how it's planned in the EU is it not?


Maybe? I'm not sure since the UK is no longer part of the EU; we're running quite a bit behind on this kind of thing now.



That makes the most sense.

And, that public key of yours must be used only on given platforms. You want to participate on Facebook or Reddit, then you use that public key to prove who you are. Which platforms require verification is another issue.

But it should still be legal and allowed to access conventional forums, Usenet , tor accessible discord servers without having to prove who you are.

Otherwise , the right to organize is over and we effectively live in an authoritarian regime .


I’m from The Government, and I’m here to help.

One not entirely inaccurate definition of government is a loose agglomeration of third parties.

Or, less flatteringly, a stupendously large way too loose agglomeration of way too many third parties welding way too much power way too arbitrarily.


Despite that fun trope, in reality democratic government reguarly delivers very well: Traffic safety systems work easily, dependably, economically. The Internet was developed by the government, the web at a government-funded research institution. NASA is the most cutting edge, most adventurous organization in the history of humanity. The US military created GPS for example, and has more globalized operations than any other organization has ever imagined, and from the bottom of the sea to GEO. Diseases are managed and contained, etc.

(Now if the people want to tear apart government, democracy delivers that too.)


Good points. Governments haven't been all bad.

Although more recently, at least in Australia, it would be difficult to claim the federal government, and the Victorian state government, have done anything good.

By any metric one might care to measure they've made everything worse.


The difference here is that in a functioning democracy people have some control over their government. All the institutions are specifically built to be transparent and work for the public good, at least, in some sense of the word. A corporation, especially a monopoly doesn't care what you think, you have no control over it and the only thing that really matters to them is their bottom line. Are governments perfect? Of course not. Are random corpos better? Again, of course not.


Why not just let the parents set an age on the device via parental controls? Why do we need a whole cryptographic system and the government in between, for something that is really just a way to say « this device doesn’t want to have adult content »? It’s way simpler to have that at the device level, and would enable even adults who don’t want adult content to block it for themselves

Edit: I just realized that’s exactly what Android is announcing in the article, so that’s pretty neat


I want the market solving this but I don’t want to give any information to anyone who asks. I want Apple to verify me once, and then others to trust Apple that the device accessing their service is owned by someone over 18.

I’ll bet that most people are in the same boat - they trust their device manufacturer with information like their credit card number, but not anyone else.

And I think it’s a pragmatic compromise.


How does this work if you use Linux or Graphene OS?


It's not supposed to. Just one more way to limit our freedom to control our own devices.


And the market won't solve it in a way without perverse incentive unless you have government regulations. Too much money on the line at this point.


I’d personally prefer if nobody verified me ever, and people stopped asking for it altogether. It’s not a compromise, because nothing about this is pragmatic, necessary, or for any benefit of society—this is yet more creeping authoritarian control, and I’m absolutely floored how readily everyone else bends over for it. I say no. Fuck no. I will sabotage and obfuscate every aspect of this at every opportunity.

The people clutching pearls and screaming “what about the children” can deliver universal healthcare, child care, parental leave, and free education FIRST, and then I will extend a modicum of trust for their overriding “concerns”. Until then, I’m gonna treat this as the bad faith power grab that it very clearly is.


I don't want anyone to solving this.

This is problem generated by govt, and they just want to solve it with "children safety" as excuse. This is parents problem, not my problem.


It is a scary thought but I kind of like this idea. Having a yubi key that is issued by the government that is unique to you and has your age saved on it, it's by far the most private and secure way to verify your age.


No. It should be none of that. It should be a checkbox either set by the phone store when you buy the phone or set during the first boot process.


In this case will it be a transparent traceability and the mapping to user real identity close to 100%?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: