Hacker Newsnew | past | comments | ask | show | jobs | submit | more gant's commentslogin

Very few cases can't be covered by either WSL or a VM, and having dual-booted for years I can tell you that after a few days you get into the habit of only booting the more convenient OS most of the time. It's twice the maintenance and 5-15 minutes of context switching every time you need to do something else.


Ah, WSL... which gives you the best of both worlds: unpredictable and unreliable Windows updates combined with whatever grievances you have about Linux applications.

If by 'booting to the most convenient OS' you mean 'booting to the OS which does not usurp your machine for internal housekeeping purposes (plus a little side of snooping here and there 'to enhance your experience') the moment you switch it on that would surely mean booting to some variant of Linux? Windows seems to think it is more important to try to install the 1709 or 1803 update pack for the umpteenth time, try to stuff the 'Windows 10 update assistant' down unwilling users' throats, ignoring all those 'do not update' flags and settings they were told to hack into the registry. Where the OS can suddenly decide that you obviously are not using that FileHistory backup so let's remove it altogether. In other words, the OS which isn't at the whim of a supplier with an agenda different from yours.


I didn't specify which operating systems, which makes it ironic that Windows was not involved at all in that process. I've used WSL, but on my Windows-only desktop that mostly runs games. See, my work machine never ran Windows. Good job going on a rant about it though.


I have a window sitting next to my Linux and I use it about twice a year, it's no maintenance at all (less than a VM I would say)


Pretty much. Should have that as default anyway to avoid sending tracking beacons to spammers.


If Google really wanted to help here, why don't they just, you know, make every part of YouTube less optimised for maximum view time. Remove autoplay, turn down the recommendations. Nah, we're gonna throw some optional, possibly ineffective shit into our mobile OS instead so we can say we did something.


Those features you listed seem like quite useful ones for day to day usage. Many things won’t have a bright line “this makes the product useful” vs. “this makes the product addictive” feature classification.


> Many things won’t have a bright line “

Agreed.

Though how often have you found autoplay by default makes YouTube useful?


For multi-parts videos?


So, not very often.


Multi-part videos exist? Just...why?

Youtube videos are up to 12 hours.

That's reminiscent of the good ol' VCR days.


Because for certain things, it's better to split the content on multiple parts. For example, I was watching a series of videos on Windows Server administration and the content was split into multiple parts and it made sense.


Still, why does YT need to default to autoplay on every time I load a watch page?


"User engagement"


Just because Denic doesn't allow private domain registrations doesn't mean you're supposed to go after people and dump their personal info into your popular blog. Large parts of the information was historical data persisted by third parties that'd be hard to expunge. There's a good reason for pr0gramm admins to want to remain anonymous - cha0s initially quit the site because he received an 80kg steel oven as sort of a threat. The post includes names and contact information of volunteer moderators that weren't even part of their company.

But Brian Krebs' private information - which is definitely out there - is to be kept out of public view? I'm sure he'd pursue legal action if I put that on my blog with some half-baked accusations

It's wrong, plain and simple, which is why pr0gramm moderators have been removing posts with both their own private information and krebs'.


If you don't have a 2FA password enabled and you're not online on another device you can login with your phone number.


Telegram can layer a password on top of your mobile number in a sort of reverse-two-factor way, but it's kind of a bad joke as I've mentioned above.


Telegram's security is a joke. They show the first and last letter of your password and the length (the number of asterisks they put in the middle changes) when you sign in. Next to some pretty bad implications (do they store the password in cleatext or just the length and two letters?) , that password is down to about 1/5 of its original entropy. Told them a year ago, they don't seem to care.

EDIT: Yes, Telegram uses passwords if you enable them. This is what the questionable query looks like: https://i.imgur.com/BAnddlg.png


They do? On which login do they show that information? I've only seen the kind-of two-factor one where you have to enter a code sent in a text message or with a telegram message to a different device.


Took a while for me to reinstall it, this is what it looks like (just after SMS auth):

https://i.imgur.com/BAnddlg.png

I counted the asterisks, they do in fact reveal the length of the password.


Isn't that a user-defined hint? Mine shows text that I manually entered the last time I changed my password.


Hint is a text field that you fill in when creating a new cloud password. The hint text is generated based on password if you did not fill it yourself.


> The hint text is generated based on password if you did not fill it yourself.

That... is a problem.


Telegram doesn't use passwords...



Wait, how are they turning the passcode into a 2048-bit key? Is this an RSA key? How do they ensure it's not factorable, etc.?


They probably just create the key and then encrypt it with the pass code, as people usually do in these cases.


A lot of banking apps store cached transaction data and authentication tokens on the "protected" (not accessable to non-root from other apps) part of the data partition. If you run without encryption or with either unlocked bootloader or TWRP installed, someone could just pull that from a device in recovery mode. That's also why unlocking the bootloader wipes your data partition usually.


And that matters how?

At least all German banks have to have an open API for transactions, and I can run my transactions with curl if I wanted to.

A banking app shouldn't care about how I run it, otherwise I'll just throw it out and use one of the open apps for HBCI.


This should be OR. If you have FDE enabled, then the data is encrypted and it doesn't matter if your bootloader is unlocked or you have a custom recovery installed -- all caveats about the trustworthiness of the crypto and strength of your key still apply.


Not even close to being that good, but parts of the Frankfurt Metro have basic station maps on the platforms.

Of-Marktplatz: https://dl2.pushbulletusercontent.com/lxmCMsRFcz6eOy53QqHHzk...

Of-Kaiserlei: https://dl2.pushbulletusercontent.com/BEJXV2Cp8UDZ1dbbXVRPZe...



Xfce display switching has yet to let me down.


xfce display switching is horribly unpolished. attach a monitor that is already set as secondary and watch all windows move to the new display.


Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: