Hacker Newsnew | past | comments | ask | show | jobs | submit | collabs's commentslogin

Because it sucks. But maybe it should suck? It would make us think twice before adding dependencies.

I use dotnet and I never liked seeing dlls and binary files in my diffs. I would argue if we are adding vendor code to our projects, we should demand the FULL source code instead of dlls. Maybe it is already possible with things like x unit. I have never given it much thought... But then that vendoree code has to come from somewhere as well, right? I mean there is something to be said about provenance or something here?

Sorry if this feels like a stream of consciousness because it is ↔


Vendoring dependencies doesn’t necessarily mean you have to include binary objects in your repo. They could be content-addressable artifacts in your org’s private blob store.

i.e. they could be NIH git-lfs.

The fact that Congress is currently abdicating its responsibility does not mean that it is actually powerless. Technically, Congress has tremendous powers if it chooses to wield it. SCOTUS can try to rule a law is unconstitutional but Congress can impeach and remove justices at any time. Of course, we hope Congress members will pay the price when it comes time for reelection but at the time of this decision, as long as they can somehow remain united, Congress reigns supreme.

> Congress can impeach and remove justices at any time.

The impeachment process requires a majority of the House and two thirds of the Senate, and then any replacement would have to be nominated by the President rather than Congress. Meanwhile the existing decision stands, and even the dissenting Supreme Court Justices (if there were any) should follow it as a result of stare decisis, and might even be inclined to because removing their colleagues under those circumstances could make them uneasy.


I feel like f-droid is still very much a developer / advanced power user tool. I have not tried the 2.0 release candidate yet but with my version I get things like

> F-Droid: Repo timestamp expected 1790110069568, but was 1790205675224 IzzyOnDroid F-Droid Repo: Repo timestamp expected 1790100093000, but was 1790272636000

The real problem I think is who should this message go to? My guess is we don't want to have mindless telemetry going from every single user to some central database or repository somewhere. My injection isn't even privacy here. It is that when we have lots of data coming from all over the world, I am afraid someone still has to sift through all this data and make sense of it but we can only understand and prioritize things we already know or are at least able to understand. I feel like this is pulling us in different directions — we want a simpler interface but we also want to expose all sorts of application states that require advanced understanding of how the system works. And someone needs to decide which bucket any particular message goes to — perhaps there is a more opaque but less frightening message like "sync had a hiccup, will retry" or even no message at all surfaces to the user unless it fails multiple consecutive times for the simple, default bucket and more verbose more frequent messages for those who want to see them?

But then even as I write this I can feel like this adds more maintenance headache, even as I push decision making to avoid having to think about a default, I still have to think about a default. The more I think about it, the less sure I am.


The new version is a lot more dumbed-down and end-user-friendly. (I didn't like it, personally, but I can imagine that more people in general will.)

I agree. The new version should be better for normal users which should help make F-droid more popular and maybe a real alternative to the Play store for people in general, not just power users.

I created a second LinkedIn account for testing purposes and recently I started getting this which I thought was strange as this account had been live for several years. What changed recently? Could this restriction also be because of the push to block mass scraping?

----

Access to your account has been temporarily restricted

Why did this happen?

We take proactive actions to protect you when we detect potential unauthorized access or other activity that doesn’t comply with our policies.

What can I do next?

We first need to verify your identity to ensure your account safety. To regain access to your account, please submit a government-issued ID.

Learn more about verifying your identity.

----


They've been doing this for a while, they also scan your browser for thousands of known extensions... It's basically impossible to create a new account unless you send them a pictures of your balls next to a valid passport

> they also scan your browser for thousands of known extensions

Works in Chrome, doesn't work in Firefox. Firefox randomizes extension IDs per install.

"Chrome extensions can expose internal files to web pages through the web_accessible_resources field in their manifest.json. When an extension is installed and has exposed a resource, a fetch() request to chrome-extension://{id}/{file} will succeed. When the extension is not installed, Chrome blocks the request and the promise rejects.

LinkedIn tests every extension in the list this way."

https://news.ycombinator.com/item?id=47613981

https://news.ycombinator.com/item?id=47967262


I recently tried to revive my account after not having accessed it for a decade or so. They asked for my gov issued ID, to be processed by the Persona service. Um, hell no.

Facebook has been doing this to me too when trying to revive my old account for using stuff like Marketplace.

I get wanting some kind of verification but hell no I'm not giving you a photo of my ID.

Let me make a new account then. But they won't.


> The results suggest that low-skill foreign and low-skill American workers are poor substitutes for one another. The authors' estimates put the elasticity of substitution between H-2B and US workers at roughly 0.8 to 2.2, far below related studies of immigrants in low-skill work, which typically find an elasticity of 4 to 10, and nowhere near the perfect substitutability assumed in some influential studies.

I feel like the wording "low-skill" has become a technical term that doesn't mean what the word says and it makes people make assumptions they shouldn't with regards to these jobs. A lot of these so called low skill jobs require a highly specific job experience and/or productivity to simply keep pace and not drag down the rest of the team. We talk about Joel Spolsky and how a poor hire in a software development team can hurt morale but it simply isn't that big of a factor with us as it is in these so called low-skilled jobs but we aren't ready for that conversation.

Also about housing, who do you think builds all these additional housing units if we don't bring in the labor we need to build them?


well_ackshually, tik tok has a well known, long, and rich history of suppressing certain search keywords.

Maybe you didn't have T9 enabled but I consider it censorship when I type bitch and it gives me chubi.

Even now I wonder if I am allowed to type bitch here...

I guess we will find out.


But typing "b*tch" with T9 is just as difficult (if not more) as typing "bitch". Anyway, I guess I never had a need to swear much over SMS. On IRC, on the other hand...

You can also choose to host your own repositories like futo and new pipe do.

Part of the value of F-Droid is the curated distribution model that hopefully catches the worst behaving developers that think they have a god given right to your data though.

Hopefully the process is straight forward so others can easily pick it up.

I DO NOT prefer traditional architecture. I prefer whatever is inexpensive and practical. Hanging brick cladding in front of a modern building is neither inexpensive nor practical. What I really care about is the savings associated with this ruthless cost cutting and brutalist simplification to be passed on to the ordinary folks instead of being hoarded by the oligarchs.

My opinion is that someone somewhere is paying for those ads and Google needs to get positive identification of a human being for any ad. Google has a near monopoly so there is no reason Google can't force this requirement arbitrarily. Once you have positive identification, suspend them pending further investigation if they serve any dodgy ad. I will be genuinely surprised if Google makes any money off of these dodgy ads. How? Like how does this money flow? Where does it come from?

There has to be a way to enforce positive identification, right?

Google already does this for Google play developers. I can't use a US credit card to pay for the USD 25 fee for a student on Bangladesh for example because I understand the payment method is one of the signals they use to make sure the student developer is a real person.

Is this something Google won't do on its own without being forced to act?


Potential issues: - There are some well-known ways around developer verification (peopl in some countries _need_ them for one reason or another so - they use non-local cards,etc) - it's very basic verification and people who pay for ads likely arleady do it (payment have to come from somewhere). - Proof of address is also spoofable and there are some situations were people making/providing fakes when they don't mean ill intent towards anybody else (example: Russia, some of ways to make non-Russian-only Visa/MC require making fake proof) but such methods could also be abused for doing actual harm. - ID verification sometimes complicated if a lot of countries are involved. Example: I'm not at all sure at least one person in Google actually knew what Abhazian passport is and how to verify it ?


These are pathetic excuses for a company with 400 billion in revenue. If they can't afford to hire people and develop systems, that means they don't have a viable business model that doesn't rely on scamming. Simple as that. I'm so tired of such excuses used for companies that make insane profits. What, they get to do that because alternatives are too complicated? I'm too stupid to get a phd in [insert field here], so I should be able to make a living running scams? These are the people who are claiming to work on AI and potentially AGI. Utterly ridiculous.

Google as just as scammy as the scammers. For many years they manipulated auctions to capture more market share.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: