Hacker Newsnew | past | comments | ask | show | jobs | submit | OptionX's commentslogin

I agree they they should, but that would be hard before, now in the IoT-hell where even your lightbulbs and internet-facing and capable of being proxies seems like a herculean effort.

Pretty sure I saw an article on HN a few days ago about, in part, how a bunch on seemingly innocuous apps for smart tvs, stuff like screen savers and the like, all ran proxy servers (in the users residential address) under the hood. I think it was in the GamerNexus investigation on the whole LG Tv spying on people IIRC.


That's why GP mentioned "Smart TV".

A random Internet-connected smart plug made by KOCKJAKD and sold on Aliexpress? Almost impossible to catch.

A major brand like LG, with US presence and sold in brick-and-mortar stores? Much more possible. It also makes a much juicier target for lawyers, thus making it much more likely to get sued. And once there is a precedent, other manufactures would be in danger too. Hopefully after losing a whole bunch of money, the manufacturers will start cracking down on those residential proxies.

(Except that discovery is going to be painful. "Use discovery to find out what's on the other end" is easy to write, but in practice it means regular people dealing with bailiffs just because they happen to buy wrong brand of smart TV)


Fortunately you only need to find a one of the many possible devices to sue. Just winning a couple of these will send a message. The goal isn't the $$$ directly (the lawyers are the only ones who win) it is to send a message that you are forever responsible for your vulnerable devices and so you better make them secure.

The hard part is if any of the devices are from someplace that doesn't have a US (or whatever country they are in) presence. That country my ignore the lawsuit.


  > I agree they they should, but that would be hard before, ... seems like a herculean effort.

  | We choose to go to the Moon in this decade and do the other things, not because they are easy, but because they are hard; because that goal will serve to organize and measure the best of our energies and skills, because that challenge is one that we are willing to accept, one we are unwilling to postpone, and one we intend to win, and the others, too.
So what, they are hard. So are so many of humanity's greatest achievements.

Honestly, these companies win when we buy into the belief that these things are too hard. They're lazy and are just like any of us that make excuses to not do chores or other things that we should. But the reality is that for pursing our civilization forward we should pursue the toughest problems. It is just about will. It'll be tiring. Some will kick and scream, throwing tantrums. But we aren't just any animal, we're humans. We can do literally anything if we decide it's worthwhile.

Importantly, we shouldn't just jump onto the next hype train, we should be passionate, nuanced, and pursue for the sake of pursuit. We don't have to put all our eggs in one basket. We shouldn't. We have enough time, resources, and energy to pursue so much. But as soon as at pretend we live in a finite world we tend to self destruct and fight over constraints we've made up. The universe is limitless, as are our minds.


AFAIK most people's contract with their ISP includes fine print that forbids a lot of the nasty things these IoT and "smart" devices do.

Doesn't matter from the point of view of a lawsuit from an outside attacked party.

IANAL, but a harmed party outside of the 'binding arbitration' nonsense might be a way work around arbitration and drag the company into a court.

Exactly, the harmed party is not subject to binding arbitration. The harmed party isn't going to bring someone to court for their bad devices - nobody has enough assets to be worth suing (other than perhaps to compel them cooperate with the discovery process) . However the company that made those devices is worth suing.

Alibaba is an interesting question though - if the device is from China (or some such) it isn't clear what the courts can do...


What do they do that you think is prohibited by a residential ISP contract?

Running a proxy server and running a botnet, at least.

Pretty sure for anyone outside North America the shipping absolutely kills the value proposition nowadays. Last time I checked to replace my deskmat both it and the cables were about as much for shipping as for the items themselves. And taxes on top of that. That, for example, turns a 20 cad cable, already on the pricey side into a 40+ cad one. I do not know if there are any officials redistributors in other continents, but I don't think there are.

Yes, we all know the US economy is effectively severed from that of the rest of the world now.

LTT is Canadian though. It's simply the shipping costs globally are expensive.

Annyways; I like the LTT TrueSpec cables although I think the thickness of the connector is slightly too small.

It feels loose in multiple of my devices, e.g. S22 Ultra & S23 Ultra. No other connector feels this loose.


If you purchase multiple cables at once, the shipping cost per cable goes down, I'd think.

Not saying that's easy considering their stock issues. Maybe it's better now.


Google is the worst offender, but a lot of companies are increasingly hiding themselves behind a wall of automated systems to completely neuter users ability to challenge any decision unilaterally taken by the them. The LLM-age has worsen the situation but it started well before it.

At some point it may be necessary to add the requirement for large companies to have a both human contact point and perhaps a requirement for specifics on account terminations and the like, or at least a way to request them, to the letter of the law.


It’s a strategy. Ask RyanAir. They systematically shut down any way to communicate with them, except lawsuits. Tried their chatbot, hotline, email, letter, fax, small claims court (I’m not joking they don’t even care about that). Unless you turn up with a court order and confiscate a plane, they simply won’t give a fuck, and I’m sure it’s a tactic to deter 99% of their problems before they start

These companies have correctly figured out that customers will still give them money, even if they provide no customer support, are actively hostile to their customers, and only respond to lawsuits. Such a weird timeline we are on! People willingly do business with companies who are actively against them.

> People willingly do business with companies who are actively against them.

Sometimes it's because they don't have a choice.

Case in point, since we're already talking about them: Ryanair. I'd cheerfully never fly with them again after, several years ago, they denied my wife and I boarding to a plane despite the fact the screens round about were still saying final call. Not just us either: about half a dozen other people missed that flight because the screens in the main terminal only updated with the departure gate a few minutes before final call and we happened to be quite a long way away when that happened. I've never had anything like it happen at any airport before or since.

Be that as it may: we can't practically avoid using Ryanair. My wife is from another country and Ryanair is one of only two airlines that fly there from the UK at all and the only airline that flies there from the nearest international airport (roughly half an hour away as opposed to 2+ hours away).

So we fly Ryanair even though neither of us want to: there simply isn't another practical or sensible choice.


Sometimes you don't get a choice, which is even more frustrating.

We got an admittedly very good deal to switch cell carriers. Part of that deal was receiving a debit card with my phone's trade in value loaded. That card turned out to be digital. I put it on my phone without thinking too much of it. However, given my lack of experience with Apple Pay, I didn't realize that I now didn't have access to my own card number. When I try to use the debit card, I am asked for a PIN that I've never been given an option to set up. When I call the card provider, the automated system demands a card number. Which I don't have.

Granted, it was my ignorance as a user that is responsible for some of this but it's pretty clear that the lack of access and support is intentional.


> People willingly do business with companies who are actively against them.

The banking industry has been hostile toward poor people for ages. When I was in my early 20s, an employee at a bank let me open a savings account without meeting the minimum balance for an instant penalty.

Of course, I'd get that shit reversed on that person's dereliction of duty to warn me when we were discussing how much I'd allocate to it if it happened today, but I was young and dumb and didn't know how to stand up for myself at the time. This was early 2000s, so hardly a recent change.


No.

These companies have correctly figured out that it's much cheaper to buy out governments so they won't actually punish them for all the regulations they break or institute new such regulations.

That's the weird timeline we're on. Governments willingly ignoring large scale violations by large corporations who actively harm their voters they're supposed to represent.


Ryanair admittedly wins on price and regulatory setup in EU provides guarantees that planes are safe.

Yes, Ryanair stole 100 euro from me once, but if next flight is 50 to 250 euro cheaper than competition...

I did some big projects motivated entirely by spite (project was overall helpful, but I would not do this if someone would be less nasty). But I still would use Ryanair.


> Yes, Ryanair stole 100 euro from me once, but if next flight is 50 to 250 euro cheaper than competition...

I swore off them a few years ago.

Plane started boarding around when it was due to land. We got on, seeing about 3cm of snow around. It went to the runway, whereupon the weather wasn't good enough so the plane waited. And waited. And waited. And then the pilot turned off internal power because we were waiting so long. And then the airspace was closed for the night and every Ryanair plane did what we did and taxied back to the airport and deplaned all of us, creating a queue at the help desk that didn't clear until 8am the next morning, or at least that was when I got to the front having stood up all night.

I was supposed to be back in the office and working by this point.

They told us to check online for rebookings: couldn't do that, their website was overloaded, though I could sometimes get as far as the schedule before it failed on me, and the next official opening was about 5 days later at the start of the queue and 7 days later when I reached the end. Other airlines were now charging £1000 for next-day flights.

Got a standby ticket for a few hours later. Went through security again. It was also cancelled.

At this point I went to my brother's place near Portsmouth, slept enough to recover, took the ferry to France, and took the train from Caen to Berlin, and this was still both cheaper than any replacement flight and faster than waiting for Ryanair to offer another flight that would also be subject to the same general climate.

If the plane had landed on time before it got to us, it would've taken off before the weather got so bad.

Had a very understanding boss at the time. I miss working with him.


In this specific story you have general Ryanair shittiness but from what I see 80% of annoyance would be the same with other companies.

Ryanair are the only ones that I have flown with who often depart roughly when they were supposed to land.

British Airways is the same. After they wrongfully didn't let me board my flight I had to escalate to the Dutch aviation authority (ILT, they sided in my favor within 3 days of me sending my letter in, that's how blatantly in the right I was) in order to get them to stop ignoring my emails, and even with the letter from ILT I still had to escalate to CEDR and they still took forever to compensate me what I was owed after legally being bound to do so. Along the way they tried every scummy tactic that exists, including sending me an email to close my CEDR case and they pinky promise they'll compensate me if I do that (which should be HIGHLY illegal but apparently isn't). They even went over the legally enforced time limits! They had 2 months after CEDR made their ruling in my favor to pay me back, and I STILL had to hound them after 2 and a half months to get my fucking money!

If I wasn't as idiotically stubborn as I am, I would've given up a month into the 8 month ordeal it eventually turned into. I guarantee you the vast majority of people wouldn't bother escalating to their CAA, or contact the relevant courts or authorities, which is what these scummy tactics are designed for. They would've been ignored like I did, then they would've given up because what's even the point?

The fact that we're allowing companies to get away with bullshit like this is ludicrous to me


> The fact that we're allowing companies to get away with bullshit like this is ludicrous to me

Hope you're not voting for any parties that don't explicitly run on a platform of stopping companies getting away with bullshit.

I'm pretty sure the Netherlands does have at least one such party, as other European countries I'm more familiar with do, no matter how small they might be.


>The fact that we're allowing companies to get away with bullshit like this is ludicrous to me.

If they decide to not reply it becomes much more resource consuming to go down the legal road.

I had this with DoorDash, even if you call they just say some specialised team needs to look at it and they'll email you back, surprise, they never do.


This isn't laissez faire. Along with useless binding arbitration they precisely lobbied for a marketplace devoid of consumer protections or redress channels. We now live in an age of strict Non-liability.

This is why after 2 good faith attempts, I just report them to the government. It turns out when you report a car insurance company to the state regulatory body, you suddenly know how to contact you. Nope, to bad. Deal with the government. Felt sweet to get a check in the mail from the IRS after resolution.

That was the most recent time, but I've done it a couple of times. I do everything digitally, so it's always easy to prove my case.


Land line telephone accounts: regulated

Cell phone accounts: no regulatory oversight

This pattern of deregulated modernization isn't just a pattern. It's a scandal.


> small claims court (I’m not joking they don’t even care about that)

If they don't show up, doesn't that mean you win by default? (And then you can indeed send a bailiff to seize a plane...)


Depending on the jurisdiction, getting a judgement alone doesn't allow you to have a bailiff enforce it.

Yes, you can win in small claims if the other party doesn't show. I suspect a plane might exceed the "small claims" limit though!


Pity it still departed for London after the notice had been affixed.

The limit applies to what you can claim, rather than what you can impound in enforcing the court order.

Oh it does but just because you win doesn’t mean they start caring. A bailiff won’t really get involved for 500 euro compensation. A debt collection agency might. They want a cut of your compensation to deal with RyanAir because they know how annoying they are. Like, sure, you can start a 10 month project over 500 euros and maybe it’ll be fruitful eventually. But who does that? It’s insane. Answer your emails for fuck sake

The fact that this has become acceptable is the real problem.

You don't want to harm the economy, do you?

I'm sure the people who will get hurt have plenty of money.

Same with Amazon Japan. It blocked my account with no way to contact them, never used again.

Funny you should say that. I'm not a big Instagram user, but have had an account for years. The company I work for has just started an Instagram campaign, and asked anyone who wanted to, to check out their campaign and give it a like. I did so, and a minute later received this email:

"Your Instagram account has been suspended. This is because your account, or activity on it, doesn't follow our Community Standards on account integrity.

If you think that we made a mistake, you have until 8 March 2027 to appeal."

I've now uploaded my drivers licence, a photo of my passport and still apparently that's not good enough for them.

My latest rejection says I have only one more chance. No idea what the transgression was, but apparently there is no recourse.

I guess it's a good thing I don't really give a crap about Instagram in the first place, isn't it.


> I guess it's a good thing I don't really give a crap about Instagram in the first place, isn't it.

If you were willing to upload your driver's license and passport for a mere chance at getting back an account you don't give a crap about I'd hate to see what you'd do for one you do care about! Facebook demanded my driver's license at one point out of the blue. I simply abandoned the account, I was already pretty over them at that point anyway. About a year later it let me log in just fine and had forgotten all about how badly it had needed a scan of my license for security. In fact I didn't even remember the password, it just auto logged in from an email link.

You kind of confirm what I suspected though, that they'll just keep asking for more stuff leaving you more exposed and they're under no obligation to actually give you the account back no matter what you do.

I don't use discord but IIRC I read that if your account was banned they were asking for a mobile number to get it back. Instead of getting it back if you complied they just added the mobile number to their ban list so you couldn't make a new account with it.


> I've now uploaded my drivers licence, a photo of my passport and still apparently that's not good enough for them.

That's not a good practice to begin with. Your insta account doesn't matter but your privacy and government-issued documents do matter.


Meta knows you work for them, and sees it as boosting or gaming the algo.

There are a gazillion accounts that do this constantly, and all of them appeal.


> I've now uploaded my drivers licence, a photo of my passport and still apparently that's not good enough for them.

After the recent news about >150 million drivers' license photos being stolen from an ID verification service, I'd be very hesitant to do this for anything I didn't absolutely need. ID theft is a lot easier when someone has a photo of your sensitive documents.

https://news.ycombinator.com/item?id=49561320


> uploaded my drivers licence, a photo of my passport

Sounds like its working as designed. This is why you never cross streams between work and personal life.


My wife lost her Facebook account because Facebook autolinked it to someone else's Instagram (not hers), then shut that one down for abuse.

No appeal process.

Luckily she didn't use Facebook much.


The sad thing is if you go through that final step you'll probably receive a permanent ban.

But if you go on Swapd right now and pay a Meta employee $500 while it's still in appealable state you'll get your account unlocked in an hour.

Make it make sense.


I opened a Google Workspace account for my solo business to have an email address at my domain, got suspended a month later, had no way of contacting support since they require login and I was the only user, filed an appeal, got no response after a month, eventually contacted their Twitter support account and had access restored, but through this all they charged me for the subscription three times while I was locked out and before I could cancel. I contacted their support after I was restored and they said they wouldn’t refund me because the Workspace account wasn’t suspended just my individual user (even though they acknowledged I was the only user). I had receipts and screenshots of everything including confirmation from Google’s own UI that I was suspended for that entire period, but I just have to let Google steal $100 from me now because what else am I going to do?

Also their explanation for the lockout was that I failed the verification step too many times, which I don’t recall failing even once.


> At some point it may be necessary to add the requirement for large companies to have a both human contact point and perhaps a requirement for specifics on account terminations and the like, or at least a way to request them, to the letter of the law.

This is already implemented, under the EU's Digital Services Act, you can appeal and get specifics about account terminations - see https://digital-strategy.ec.europa.eu/en/policies/dsa-out-co...



Making the decision is easy, dealing with the consequences is not.

[flagged]


WTF? Please don't fantasize about building concentration camps or use vile terms of derision on HN. The guidelines make it clear we're trying for something better here, and we have to ban accounts that do this repeatedly. No matter how upset you are at GitHub, you owe this community better if you want to participate here. https://news.ycombinator.com/newsguidelines.html

Between China and the US which have laid claim to Greenland and have in no uncertain terms said they would use military force to acquire it?

Which one provides weapons to Russia, a nation in an active war against Europe?

And AFAIK the US has not even claimed Greenland.


A truth that in practice does not seem to hold up once your valuation passes a certain threshold.

Wrong. AI companies is still legally liable for anything their models do when they operate them. There is no special exception for them. But the fact is that not every potential crime results in litigation. Many crimes are only prosecuted if the wronged party actually wants to sue, and often that doesn't happen.

> AI companies is still legally liable for anything their models do when they operate them.

I admire your optimism. But until we see these companies prosecuted for the crimes they have committed out in the open (like massive copyright improvement), I'm not going to hold my breath that they will ever be held to account for anything they do.


This isn't necessary related to this project but I got thinking about while reading it. Isn't it weird that shared memory was a cost saving measure by not having GPU dedicated has now been rechristened unified memory and is now a feature?

I understand why the AI people want it to help with the latency between the CPU and GPU. But having people in some cases use it as for marketing is kinda like getting watered down beer and getting told its a good thing because alcohol is bad for you.


Technically, “unified memory” is where both the GPU and CPU have access to the RAM over the same bus, which is different from the older, reviled “shared memory”, where the RAM was always at least one bus hop away from the GPU. But yes, there is a certain amount of spin to it, isn't there? (“You have less total memory now, and that's a Good Thing!”)

> I understand why the AI people want it to help with the latency between the CPU and GPU.

The reason AI users like it is because it provides a large amount of higher-bandwidth memory at a price much lower than an equivalent GPU.

If you had 16GB of DDR5 in a normal 2-channel consumer board it would not be this fast.

This gives 16GB of high speed memory for a very low price compared to a full GPU.

The larger unified memory systems like Strix Halo or Apple Silicon provide access to high bandwidth memory at scales you can’t get with any consumer GPU.

> But having people in some cases use it as for marketing is kinda like getting watered down beer and getting told its a good thing because alcohol is bad for you

I don’t think you understand the benefits of having high speed memory attached at a low price point.

Yes we would all prefer to have the same amount of even faster memory attached to a dedicated GPU, but that’s not happening at this price point.

Better analogy would be that this is an entry-level sports car for the price of a Honda Civic but you’re complaining that it’s not a Lamborghini.


> The reason AI users like it is because it provides a large amount of higher-bandwidth memory at a price much lower than an equivalent GPU.

But unified memory isn't providing high bandwidth. Apple's specific implementation on pro or higher chips does. There's a zillion desktops and laptops running unified memory at low to medium-low speeds, and the baseline M series is part of that with its 128 bit bus.

Most unified memory devices are handicapped because of the unification, not boosted. Yet people keep praising unified memory.


> want it to help with the latency

Primarily the bottleneck actually. PCIe bandwidth is extremely limited.

GDDR has worse latency than DDR and scaling it up to larger capacities faces challenges. So if you unify memory your options are small GDDR, large DDR, or expensive HBM.

Unusually, the BC-250 and PS5 both use GDDR with the CPU so the memory bandwidth is great but the latency not so much AFAIK. It's like using a dGPU as a full computer.


So instead of putting more cache on the cpu you just put the cpu on the cache.

Sort of, but the cache architecture is replaced with memory architecture. But you could look at it either way.

A stockyard doesn't consume into the gigawatts of power.

There is not a concerted effort to build thousand upon thousands of stockyards across the globe.

Stockyards wont increase the planets reliance of oil, since green technologies don't scale that fast. Same planet that feeling the effect of climate change quite clearly.

All for close to zero upside for the surrounding community. At least the stockyard would have given you cheaper meat. What are data centers going to give? Discount tokens?

That's why your stockyard does not have the same pushback.


Stockyards and the increase in beef consumption it enables would do far more damage global warming-wise than increases electrical load that could be solar offset in a few years.

Also nobody is pushing for “thousand upon thousands” of these. Again, hysteria


Such investment in technicalities to undermine the above post could itself speak of zealotry to a certain side in itself if one was prone to cynicism.

Not to mention that those nuances, as you state, mean very little. To say it was trained solely on copyrighted material or to say it was trained in large part on copyrighted material doesn't much move the needle over the fact it was done, a lot. Making a distinction between an "80 year old copyrighted work" or a recent one is also moot as it a matter of public record they themselves didn't make that distinction and happily fed on both kinds.

On to not being able to say they didn't ever do anything altruistic, well animal rights and welfare had great strides under the Nazi regime, not sure it evens out the rest. The same logic can be applied to the current state of affairs, doing a little good does not even out a lot of bad.

In closing, nuance is relevant when its relevant, after that its just being pedantic.


I thought fe80::whatever was only for link local, and link local was only for 1-1 communication with router for SLAAC.

After you'd get a unique local than thebn would be used for normal routing needs.

Did I get the wrong?


You can use link local for whatever you want, I don't think there's a restriction, is there?

Even though it's rare, I actually do use it if I want to talk to another host on a very specific interface. Sometimes there's multiple paths.


I when to check and I think I get it now, the link-local is routeable (switchable?) but only at the local level, but then you might ask why bother with SLAAC at all then. It's due to router being unable to route anything with a link local origin or destination as they are not globally unique so if you need to talk to anything past layer 2 you need unique-local address (or global).


Yeah, but you can still talk to other hosts on the same link, not just the router, at any layer protocol. Link local addresses are not routable, but if you want to talk on the same network segment, that's fine.


Case in point, when I SSH from my laptop to my desktop using mDNS hostnames, I see “Last connection from: fe80::<something>”.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: