Hacker Newsnew | past | comments | ask | show | jobs | submit | more sorbus's commentslogin

I'm generally an Asus person, but the Sony Z series is just amazing. 16 hours of battery life with an additional sheet battery, 2.5lbs, a nice processor and an option for a 1920x1080 display. Looks pretty good too, but it's the portability and battery life that really gets me. Sadly, the basic model with a sheet battery is about $2060, and configuring it to be really shiny would bring the price up to a bit under $3000, which, being a college student, is rather out of my budget.


If jamming becomes common, it would take very little time for drones to be modified to be autonomous, or to follow a predetermined flight path if they lose contact with the controller. It might be effective now, and it gets points for being fairly easy to implement, but it's not going to be effective for long.


It's called a hellban. You can continue to read and comment, but no other users see your contributions. It's a really good way to deal with users who are posting spam (if you browse with showdead turned on, you'll occasionally see long dead posts filled with links), or trolls. If there were an indicator of a hellban, it would be somewhat ineffective, because then users would just make new accounts.

Anyways, looking at your comment history, there doesn't seem to be anything that deserves it. No spam, just a few lightly downvoted comments. But there's a lot going on behind the scenes, and most of this is automated, so you probably just ran into whatever indicators or metrics HN uses to determine whether to hellban users (or take away their ability to flag, or whatever else). The only way to deal with it is probably to email PG, if you want your old account back.


It would be really irritating for many people; that behavior is best left to the user and the browser (most mice have middle-click which opens a link in a new tab, and - on my laptop, at least - tapping with two fingers opens a link in a new tab. Browsers can also be configured to open off-site links in new tabs).


I just find it irritating when I forget to ctrl-click and having to refresh the HN page. Posted stories are not necessarily in same order. Maybe it's just me :/


That's just you. I perhaps find it equally irritating when I click a link and it goes to a new tab.

If I wanted it to go to a new tab, I'd have CTRL+clicked.

*Edit -- "That's just you" is definitely too harsh a statement, as I'm sure there are a ton of people that agree with you -- That said, I don't see a compelling reason to futz around with default browser behavior unnecessarily, and I'd wager that doing so is considered bad UI.


He's already in the USA, and his identity has been known for a while. That makes it sound pretty different to me - no issues with jurisdiction or identifying him. If Apple had a legal case against him, or if the FBI feels that he has committed crimes, there's nothing stopping them going after him.


"It's probably better to have him inside the tent pissing out, than outside the tent pissing in." - Lyndon B. Johnson

Seems like an apt quote; from Apple's point of view, it's much, much better to have Comex helping them increase their security and make it harder for their devices to be jailbroken than for him to be trying to circumvent their security, especially as he's shown himself to be quite effective at circumventing it. Admittedly, we don't don't what he's going to be working on, and his subsequent tweets show an expectation that future versions of iOS will still be jailbroken, so perhaps he's not going to be involved with security (or, just as likely, recognizes that perfect security is impossible).


I wouldn't say security is impossible, but it isn't worth the time and effort some companies put into it.

For example, Apple could stop putting 30 pin connectors on the iPhone, replacing it with only a power port to charge the device, then sandbox the rest of their apps on the phone (currently every jailbreak involving a vulnerability had to do with the fact that Apple doesn't sandbox their own applications like they do with third party applications.)

Of course you could argue that you could take the device apart and hook up leads to the circuitry in an attempt to flash the device, but you're going to stop over 99.9% of the jail breaking community from jail breaking their devices.


That's incorrect. All apps are sandboxed — Safari most of all, in fact — comex just found ways to break out of the sandbox, usually by exploiting something in the iOS kernel.

In addition, while it is possible to make the dock connector power only, it's only possible as of iOS 5 (with WiFi syncing). Also, that dramatically increases the cost of repair: a single corrupted file can't just be fixed in a quick bootloader-level restore, it requires reprogramming the entire device at the factory (let alone the difficulty of simply transferring a large music library from a computer without USB).

It's definitely not "simple" for Apple to make jailbreaking more difficult than they have. iOS 4.3+ include all of the security measures you'd expect in a modern OS: W^X, ASLR, codesigning, etc. And still it was possible to evade those and exploit the browser+kernel in a foolproof, web jailbreak.

(I designed the website for http://jailbreakme.com/, and while comex did put a crazy amount of work into that project, it is certainly possible that someone could repeat it.)


> I wouldn't say security is impossible, but it isn't worth the time and effort some companies put into it.

That's why I said that perfect security is impossible. It's entirely possible to lock something down to the point where 99.9% of people who would be interested in jailbreaking a device don't have the technical knowledge or skill required to break it (or just aren't willing to risk destroying the device), but some people will still figure out how to get around the security, even if it takes them a while (of course, if a jail-break isn't available until the version it's jail-breaking is obsolete, then the manufacturer could be said to win the battle).


> A little known-fact Dhuey recalls is that Jobs has hearing loss.

> “When we did the iPod we had to make sure it would be loud enough for Steve to hear the music,” says Dhuey. “We had to balance his need for volume with a French law against things that were too loud."

Well, that explains a lot. It's a pity that Jobs needing to have music louder to be able to hear it has led to a generation of people who are getting hearing loss from having their music turned up too loudly.


Uh, no. That problem predates Apple's entry into the space by decades.

If you want to get down to the real root cause, the root problem is biological; the human ear's damage threshold is significantly lower than its pain threshold. That's not an easy problem to solve.


> Would you rather talk to an expert on a subject matter, or post a question on SO and hope someone has had a similar experience?

Personally, I would rather that people post their questions - and then receive the answers - somewhere that's easily searchable, so that when other people have the same questions they can easily find an answer. There is certainly value in increasing the number of experts, though, so perhaps that's what you were pointing at.


I was alluding to the fact that talking directly to a FB dev to get or give suggestions is extremely valuable. Especially when speaking on non-trivial topics.


"We're rolling out sharing and +snippets globally over the next week, but if you’d like to try the new +1 button now, you can join our Google+ Platform Preview."


That's got it. Good eye!


Are you saying that the fact that this issue doesn't effect many people means that it's not a serious security problem?


He's saying that since the issue doesn't affect many people it didn't get found right away. It is a serious security problem for businesses that use Mac OS X with LDAP. However, it's not a serious security problem for me.


It's been known for just under a month, since five days after OS X Lion was released, so that interpretation of his statement seems incorrect.


In the interest of expedience, let me be blunt: very few security researchers give a shit about how OS X Server uses LDAP.

We're all pretty busy lately, too.

(-2. You guys are funny. In case it matters: I'm not being snarky. They really don't).


> This looks both real and a pretty serious issue (I wonder how it went by almost a month without getting picked up by the security community).

Followed by:

> Not many people in the security community use Mac servers in such a way that they need LDAP, and of those people, very few are running Lion on their servers.

Therefore, we see that Mr. Ptacek thinks "it went by almost a month without getting picked up by the security community" because "Not many people in the security community use Mac servers".


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: