Hacker Newsnew | past | comments | ask | show | jobs | submit | ApolloFortyNine's commentslogin

The article seems to be muddying the water bringing up grapheneOS itself. Or maybe it's the EFF.

>Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. "It's concerning – and sends the message that [GrapheneOS] is criminal by default," said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.

Is the actual case about banning the OS? Because it seems pretty clear the case is about the result (the phone being wiped with a special passcode).

The better defense imo would be one of those 'wipe the phone if you get the password wrong x times' and try and claim you forgot under pressure. At least if you wanted to wipe the phone without being accused of destroying evidence during a search.


People want free content online. More than that, they just expect it.

Any future law in regards to this will likely just lead to the companies that already got consent (companies you already have accounts with) becoming even deeper entrenched.

Non targeted ads pay a small percentage of targeted ads.


What I hate about EU laws is they tend to word these things like this.

People act shocked when it leads to unintended side effects, but companies legal teams are just telling them they have no idea how a judge will interpret these broad wordings in regards to their business.

People say this fixes "future loopholes" but as you see with the cookie banner, it just leads to every company assuming the worst case scenario.

Going back years of conversation on cookie banners you'll see a constant argument on when they're required or not precisely because it's not defined explicitly.


So you think letting the scummy AdTech industry do whatever they want everywhere is the better "strategy"?

How long did it take x user to navigate from x screen to y screen is one of the most valuable metrics for any site, and most people consider this to require consent. Or at least it not being worth the risk to not ask.

Acting dense like this isn't productive... And literally this information would be stores as anonymous user 12345, but that still would require consent (probably, or at least arguably).


That can be implemented. Within a session you don't need to know it's the same person tomorrow, so a per-day key derived server-side is enough to measure that someone took 40 seconds from x to y. No cookie, no localStorage, nothing stored on the device, nothing to consent to. Hash ip + user agent + your domain with a secret salt that rotates and is destroyed every 24 hours, and you are on the safe side. Of course, recognizing users across days requires consent. But is that really necessary?

Or use some JS to put the time-on-page in the next request, right?

Is it a violation to send data that could theoretically be used for more invasive tracking than you actually do? I don't think so, or else you'd need consent just to receive an IP packet.


In the world of zscaler, CGNAT & corporate proxies, IP address is nowhere near enough.

>How long did it take x user to navigate from x screen to y screen is one of the most valuable metrics for any site

Stats like that are only used to implement dark patterns better and justify user hostile decisions since pretty much the time the idea of telemetry was introduced. Otherwise, we'd live in the world of perfect web ui and we're not.


If you did this people would only use the same half dozen sites and competitors would emerge.

We're borderline already there today when the cost of switching is typing a different url at the top of the screen. You add some mandatory 20 minute wait and you'll never see a new site again.

Google and Facebook would love it though.


Plus sites that don't track you

YouTube is a site that pretty much everyone has an account already for (and therefore have already consented), but say you make YouTube 2, you can only make money if people allow personalized ads (they pay 10-20x untargeted ads). 90% less revenue means your business model doesn't work. The government in the area has decided you can't refuse service to customers that cost you money (people who don't consent).

You simply will have to go out of business.

This is also why you see many large companies fighting for more regulation. It's harder for a competitor to emerge if they have to navigate mountains of red tape.


What if I want to start a restaurant that can only make money if I use expired ingredients, run the fridge at a higher temperature to save on electricity, and don't waste my employee's time by washing their hands? These food safety laws mean my business model doesn't work.

I simply will have to go out of business.


This is just a strawman, these aren't equivalent and I'm not going to waste time pretending they are. Might as well just compare ads to nuclear weapons at this point.

There are enough libertarians out there that believe that the government should not be involved in food safety inspections to establish that regulations like this ARE on a related spectrum. Do you have a right to trust that food you buy is safe or should you get to choose to buy raw milk? Do you have a right to consume online services while retaining privacy? It's a debate society constantly has, and the EU electorate has chosen the side of privacy over a specific business model, just like most developed societies have chosen food safety.

> Do you have a right to consume online services while retaining privacy?

This is the part I don't understand. I'm actually all for regulations like being able to demand they delete the saved data they have on you, restrictions on transferring data to the control of third parties without disclosure/permission, etc.

But if your definition of "privacy" extends to not wanting cookies to work like they were designed to, why can't it be your responsibility to use a browser (a User-Agent) that carries out your intentions?

With services that are mandatory for all of us to use (e.g. government), I can see how being stringent makes sense because the users have no choice. But I can't understand applying the same burdensome requirements to things that people can simply choose to use or not use, such as a restaurant or some random guy's blog. I could be convinced that large platforms (tough to define properly, but things like Amazon, Uber or Meta) may be subjected to additional rules, but the tough rules being applied to even tiny one-person startups does nothing but advantage the giant platforms who have hundreds of lawyers and can devote entire dev teams to building complicated compliance features.


You can still find articles lambasting the iphone for having a small screen, 'who would want to surf the web on their phone'.

The CEO is in large part responsible for picking what products have hope to grow the company. The iphone was far from a slam dunk, many thought it would fail. Now it's responsible for over half their revenue and they're one of the largest companies in the world.

>Then he became CEO and the company and was, finally, phenomenally successful.

I'm totally confused by your post, so you admit he became a good CEO then?


Yes, my opinion is that after being the CEO of Next and Pixar he became the CEO we associate with Apple's success in the 2000s.

Heartbleed, one of the worst bugs in terms of exploitability and reach, was a bug that many engineers would be able to spot, if they were explicitly looking for it.

That's the risk of tools like Mythos/Fable/any LLM. While a human's eyes would glaze over what looks like a standard memcpy, an LLM with the right context might instantly realize the payload length was never actually verified.

And since Heartbleed existed for years, despite the full bug existing in pretty much one file, in one of the most important libraries out there, it's right to be afraid of what other obvious bugs exist and are just waiting to be found.


Well at this point the goal is for Iran to stop randomly blowing up innocent cargo ships. Or firing missiles at airports and cities in retaliation.

[1] https://www.reuters.com/world/iran-war-live-us-says-iranian-...


That sounds like it would be a return to the status quo.


If that's the goal then the US and Israel are doing their best to stop it from happening. Iran is responding to provocations. Stop provoking them, no more blown up ships.


Iran has shown a willingness to do these things through proxies regardless of anyone else before.

Furthermore, if they want to deal with the US or Israel, then they should target American or Israeli assets. Not third party ships manned by citizens of neutral nations who just want to get to port and remit cash to their families back home.


Should they avoid doing that because it’s working really well at putting their opponents in a bad spot, while costing them almost nothing?

Those ships are bearing goods from (or taking goods to) countries that are hosting US forces attacking them. They’re valid targets, and blockading their shipping… I mean, the US does that to countries that haven’t even helped attack us, seems insane to suggest it’s somehow a foul to do that to countries that are helping attack you.


Running a blockade is a risky proposition; it's not something that happens by accident.

A lot of these "neutral" countries either host US military bases, US companies, or are otherwise aligned generally with the US.


Are they sailing under the flags of nations who are combatants in this war, yes or no?


US base in a country that allows its use = country is participating in the aggression = legitimate target


That's not answering the question. Are these ships being targeted sailing under the flag of a belligerent nation? Yes or no?


What about all those fishing boats the US has been blowing up?


Also wrong. So maybe both sides should stop targeting civilian ships.


What difference does that make? A blockade is a blockade, and oil is fungible, so it doesn't matter whose flag it is. Run a blockade, get blown up. Play stupid games, win stupid prizes.

Remember, the US blew up an UNARMED Iranian ship after what was basically a parade at sea in the Indian Ocean. The US started this, and keeps it going.


The don't blow randomly ships.

The US and Iran agreed (Point 4 and 5) on, for the next 60 days, Iran is "chief of traffic" in the strait.

Iran say now, ships have to take the route close to Iran. But some ships like to take the route close to Oman. Iran is just shooting on these ships.


Makes sense, drone technology has come an insane distance since these were developed.

Probably the biggest learning from the Ukraine war alone is the effectiveness of cheap drones. It was suspected for years but hadn't been put to the test yet.


>>Probably the biggest learning from the Ukraine war alone is the effectiveness of cheap drones. It was suspected for years but hadn't been put to the test yet.

Some of us were paying attention as early as the 2016-17 Battle of Mosul, when ISIS was using DJI drones to drop grenades into the turret hatches of Iraqi uparmored Humvees. Others started to notice during the Nagorno-Karabakh War in 2020, when Azeri UAV superiority dominated Armenian ground forces. But all of these professionals were like the military officers who observed the Boer Wars, and the Russo-Japanese War, and then wrote in the military journals of their day about how machineguns were gonna change warfare in a very bad way.

Flag officers still slept-walked into the carnage of WW1 trench warfare....shrug. "History doesn't repeat but it rhymes."


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: