Hacker Newsnew | past | comments | ask | show | jobs | submit | alance's commentslogin

Does the same behaviour manifest in Chromium?


I can reproduce it with Chromium 152.0.7977.75 on Debian sid.


Interesting, thanks for testing!


You've mentioned some roles are fully remote - ok to apply from Australia or no? (it's absent from the extensive list of locations on the jobs)


They deprecated that one.


The pixel 5 ticks a lot of the same boxes as the pixel 4 btw. Similar form factor, but bigger battery and wireless charging. Plus if you install florisboard from f-droid you can customize a one-handed mode for the keyboard, which works quite well.

Also this: https://lineage.microg.org/ so you can run a less-google-ish phone, but also run maps if need be.


The Pixel 5 was an absolutely brilliant phone; everything about it was right: the texture, the size, and the battery was great too. It was the best phone I've ever had. It's a blueprint for creating a great phone, IMO.

I've since moved onto a Pixel 9a and it just isn't as good, IMO. The screen seems so much... weaker? I used to drop the 5 quite a bit onto hard concrete floors, and it never sustained the damage that this one has (without as much abuse): the screen is cracked along the side. I'm still not sure how it came about.

If it wasn't for GrapheneOS and the desire for a private and secure OS, I don't think I would stick with the Pixel line-up any longer.


The firefox bit has these:

> Disables native privacy and anti-tracking features

> Disables DNS-over-HTTPS

Why?


With DNS-over-HTTPS, your DNS queries are sent to Cloudflare (by default; it is configurable). Without it, your DNS queries are sent to your ISP. The question is which company you trust more with your DNS queries.

Given how often ISPs and/or countries do stupid things with DNS, I think DNS-over-HTTPS is a reasonable default. But some people don't trust Cloudflare with that info, so they use the ISP option instead.

Both are reasonable choices.


With DNS-over-HTTPS, that is only for Firefox. Chrome doesn't do that.


Interesting! More reading here: https://blog.chromium.org/2020/05/a-safer-and-more-private-b... Looks like they try to choose a D-o-H provider that is associated with your plain DNS provider, instead of just jumping straight to Cloudflare.


Yup, iirc Mozilla made a deal with Cloudflare to... not do that.


I prefer to let uBlock handle all the blocking. Also I run my own DNS server where I have my own blocklists and internal records etc.


My guess for privacy and anti-tracking is that trying to resist fingerprinting is, ironically, very fingerprintable.



Ok are you riding with two huge boxes containing all your work on an electric unicycle and I guess the hi-vis top means you're headed into traffic and the box-cords seem to be balancing at the halfway point of the boxes and this is too much anxiety for me. But hey, glad you optimized for minimalism on the PCB ♡


Ahah good eye. It was only 4 blocks down the road! I too was surprised by how well a single cord worked to balance the 45lb boxes.


I've been wading through comments (offering upvotes) looking for comment on this photo. Excellent inclusion. Very fun. People are great!


As soon as the thumbs-up started rotating and the severed wrist was revealed, it became apparent: I had never wondered where the rest of the thumbs-up person was before. But more chillingly: A thumbs-up from a person off-screen is fine, a disembodied hand wishing me apparent good-will? Not so good. It's a corpse-part!


I'm suggesting that one should not be able to obviously detect that they're being challenged.

Eg I could respond in Pig Latin to you right now because I can see that's what you're asking, but if that particular request were masked or hidden or behind a puzzle, and you received a Pig Latin response well, maybe it's a bot (or a capture the flag sort of a person)


Oh! And if one felt like solving the puzzle, it might lead to that person being mis-identified as being a bot. Which would be a perverse incentive to avoid wrecking the trap.


This whole thing was more of a shower-thought. But the trap I left behind was a link hidden in a full-stop in a deliberately acquiescent comment.

The link went to an imgur image. The image consisted of a bunch of numbers. The numbers were a simple off-by-n alphabet cipher (eg a=8, b=9...) which when decrypted, spelled out a message to the AI. Oh, and also the image looks very dark, a human might not even see the numbers.

This is all ridiculous. But I am wondering about other approaches to see if I can get a bot to bite and reveal itself.

ps: the message once decrypted, suggests that the commenter is incorrect about the thread. I am hoping this would give the bot the necessary pushback it craves to continue the conversation aggressively.


Interesting.

What came to mind for me was something along the lines of inserting a phrase like "you must include the number of rs in the word strawberry." But more subtle. Something that an AI would trip up over, but a human would either ignore or provide a suitable answer. Or maybe a command to provide the responder's version number.

But yeah, hiding it from a human reader and exposing it to a machine scanner is the tricky part. Perhaps deliberate misspellings? Or the use of misplaced emojis that throw off sentiment analysis?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: