Hacker Newsnew | past | comments | ask | show | jobs | submit | kd913's commentslogin

Snaps are a lot lot better in this regard especially in the perspective of connections.

You can define connections to home, camera, network etc...

I have not seen the same in flatpak.


Sure flatpak have a static permission system too, even it is not recommended and xdg portals are the way of integrating with a host.

https://flathub.org/en/apps/com.github.tchx84.Flatseal


I don't get why a big company like Zoom, with presumably lots of users who are on Linux, only gives us a .rpm/.deb instead of a Snap/Flatpak. Seems like doing the minimum.

Snaps is a sure-fire way to only get used on Ubuntu. So that would be worse than distributing .rpm/.deb.

It's possible to distribute more than one format.........

Odd how much data people are trusting with a company on a monetary cliff edge.

Sure send them all your financial, personal data, they won't ever sell it on to the highest bidder for a new profit stream.

Using it as a therapist, financial advisor, health expert and blackboard has always been a terrible idea.


Always wondered why making something like a rust memory safe Firefox, Linux, vlc, ffmpeg or curl isn’t a benchmark for these LLMs.

My theory is hedgies and investment banks using semi and ai hype as a liquidity bridge to drop into SpaceX which happens next week.

Arm and AMD pumped to insane levels on basically nothing.

What proof is there for your narrative versus mine?


:D The proof for theory tends to be somewhat stable, by which I mean: 'the theory can be tested and produces results in line with what the theory predicts.'

If you are asking why one theory tends to be better than another is qualitative at best, but irrelevant quick. Once the two theories settled in people's brains, it only exacerbated the sell off. In a sense, the theories were irrelevant. Their impact, however, was not.

In other words, I think you have the entire structure all wrong. It is not binary at all. Or, at least, it does not require for it to be mutually exclusive.


> a liquidity bridge to drop into SpaceX

What does this mean?


It means financial companies have been illogically pumping semiconductor companies the last 5 months despite the profits, royalties and supply chain being entire worse than a year ago.

They pumped ai adjacent stocks to draw retail in, to provide liquidity now when they are in theory forced to purchase SpaceX.

Effectively getting people to buy semi-ai stocks at a premium to fund their forced purchase for SpaceX.


> AMD is nothing

What?

SpaceX is the hype not AMD guy


I will admit that I am starting to understand Musk's contempt for retail investors. edit: They have no problem lining behind supporting what is now effectively Musk oriented slush fund.


How often do you have to do fast transfers from computer to computer?

Would argue for those purposes 40gig thunderbolt makes a lot more sense.


It would but none of my systems have thunderbolt and besides that my NASes are on the other side of the flat where the noise doesn't bother me. Thunderbolt only reaches a metre or two. I assume thunderbolt PCI cards are a thing but the distance is a bigger problem.

I need fast transfers pretty often. I do a weekly image of all my workstations as backup. Right now I do them overnight as it's limited to 110MB/s but this could be done within 15 minutes with 10gbit.

Also, huge media files.


If this is true, I feel teh wifi alliance have a tonne to answer for the ewaste they generate.

WPA3 moved from symmetric AES to ECDH which is vulnerable to Quantum. Gonna be a tonne of IOT inverters waste.


WPA3 moved from PBKDF to ECDH. AES CCMP and GCMP are still the underlying block ciphers in WPA3 with some other extensions for China


For what it's worth, cryptography engineers were generally not happy with the Dragonfly PAKE, and PQC was a legitimate concern even in 2012.


For those curious, a more elegant PAKE family is being formalized:

CPace (balanced): https://datatracker.ietf.org/doc/draft-irtf-cfrg-cpace/

OPAQUE (augumented): https://datatracker.ietf.org/doc/rfc9807/


Just yesterday I used an IoT device with WEP as the only WiFi option. Needless tosay, I use the wired connection.

The say the 's' in IoT stands for secure, and from my experience that is true. Pretty much nothing is getting thrown out, because it isn't secure.


WPA3 was announced in 2018 [0]. I don't think it's reasonable to blame them for not anticipating the next decade of cryptographic research.

...but even if they had, what realistically could they have done about it? ML-KEM was only standardized in 2024 [1].

also, the addition of ECDH in WPA3 was to address an existing, very real, not-theoretical attack [2]:

> WPA and WPA2 do not provide forward secrecy, meaning that once an adverse person discovers the pre-shared key, they can potentially decrypt all packets encrypted using that PSK transmitted in the future and even past, which could be passively and silently collected by the attacker. This also means an attacker can silently capture and decrypt others' packets if a WPA-protected access point is provided free of charge at a public place, because its password is usually shared to anyone in that place.

0: https://en.wikipedia.org/wiki/Wi-Fi_Protected_Access#WPA3

1: https://en.wikipedia.org/wiki/ML-KEM

2: https://en.wikipedia.org/wiki/Wi-Fi_Protected_Access#Lack_of...


Does it matter if an attacker can decrypt public wifi traffic? You already have to assume the most likely adversary (e.g. the most likely to sell your information) is the entity running the free wifi, and they can already see everything.


It is precisely because the operator of the wifi is not necessarily the adversary a user may be most concerned about. They may be, but they are not the only one. They are the one you know can be, but they aren't the only one.


> You already have to assume the most likely adversary is the entity running the free wifi

why do you have to assume that?

you're at Acme Coffeeshop. their wifi password is "greatcoffee" and it's printed next to the cash register where all customers can see it.

with WPA2 you have to consider N possible adversaries - Acme Coffee themselves, as well as every single other person at the coffeeshop.

...and also anyone else within signal range of their AP. maybe I live in an apartment above the coffeeshop, and think "lol it'd be fun to collect all that traffic and see if any of it is unencrypted".

with WPA3 you only have to consider the single possible adversary, the coffeeshop themselves.


Because it's a near certainty (at least in the US) that businesses will spy on you to the extent that they can, but it's actually incredibly rare to be around a nerd with Wireshark? Things like facebook used to not use https long after public wifi was ubiquitous and you could easily sniff people, and it basically didn't matter. Now nearly everything uses TLS so it really doesn't matter. Actually most public wifi I encounter has no security.


> Actually most public wifi I encounter has no security.

that was also one of the things fixed [0] in WPA3.

it sounds like you don't consider it relevant to your personal threat model. but the experts in charge of the standard apparently thought it was important to have in general.

0: https://en.wikipedia.org/wiki/Opportunistic_Wireless_Encrypt...


Apple is about to deprecate the iphone 11/SE 2020 version. Am gonna repurpose them as webcams given the 12MP camera put in there is arguably better than the brand new ones they put on new macs.

The phone now has a limited lifespan though because of this prior stupidity where eventually am gonna get into spicy pillow territory. At that point the phone prematurely dies.

We are going into a period where we are throwing away devices with 12mp+ cameras, and processors arguably faster than most desktops. It was arguable when the phones were old and legacy, but at this point the cameras on there are stupidly good.

We need these phones to be repurposed for a second life and actually capture their manufacture energy costs.

Frankly, if Apple allowed old iphones to be used for server usage, it is kind of crazy how efficient per dollar that would be.


ARM is a bloody financial hand grenade.

10% of the stock is floated.

90% of the stock is owned by Masa who used it for collateral for his 18 billion loan for Stargate. THat is against 33 banks who have a strong incentivise to dump in a margin call situation.

Their revenues are circular for the last 4 years, with 30% growth purely coming from Softbank shuffling their own money.

They are gonna be the canary in the coal mine for when the AI bubble implodes.


The US job stats were revised down for 2025 to 181k, but somehow the Country gained 130k in January?

Is anyone looking at this and the CBO figures and not just realising the government is straight lying about the figures?

Gonna believe Powell and Waller on this one.


They worked out because there was an excess of energy and water to handle it.

We will see how the maths works out given there is 19 GW shortage of power. 7 year lead time for Siemens power turbines, 3-5 years for transformers.

Raw commodities are shooting up, not enough education to cover nuclear and SMEs and the RoI is already underwater.


My cynical take is that it'll works out just fine for the data centers, but the neighbouring communities won't care for the constant rolling blackouts.


Okay but even in that case the hardware suffers significant under utilisation which massively hits RoI. (I think I read they only achieve 30% utilisation in this scenario)


Why would that be the case if we assume the grid prioritizes the data centers?


That is not a correct assumption. https://ig.ft.com/ai-power/

Reports in North Virginia and Texas are stating existing data centres are being capped 30% to prevent residential brownouts.


That article appears to be stuck behind a paywall, so I can't speak to it.

That's good for now, but considering the federal push to prevent states from creating AI regulations, and the overall technological oligopoly we have going on, I wonder if, in the near future, their energy requirements might get prioritized. Again, cynical. Possibly making up scenarios. I'm just concerned when more and more centers pop up in communities with less protections.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: