Hacker Newsnew | past | comments | ask | show | jobs | submit | caiob's commentslogin

Regulation is the reason the EU can't become a hub for startups.


Unbridled data collection is a requirement for a startup? Maybe in the US, pump-and-dump-startup schemes; I like to think other countries found companies that actually do something useful.

I mean Spotify has been one of the biggest driving forces in reducing music piracy, in part thanks to being more convenient.

On the other hand, they don't pay artists nearly enough so the flipside is that to the artists it doesn't actually make that much of a difference whether someone listens to them on Spotify or just pirates the music.


> Unbridled data collection is a requirement for a startup?

Well, yeah, most of the time? Can you name a unicorn that doesn't collect and use data en masse?


Really wonderful, sustainable businesses when the inevitable privacy legislation hits the books in the United States. Just great high quality revenue, wish I could get in on some of that


I'm not sure it's all inevitable. Still some constitutional challenges to go.


No. The lack of regulation in the US is.

The solution is to firewall the internet in the UE.


I can't wait until I'm literally forced to use qwant.com. I love daily frustration. It's good for the health.


frustration is what lead to innovation.


Have you used Baidu or most Chinese apps? I'm not sure this has proven true in that example walled garden.


Despite what these “studies” say, the Amazon is NOT near a tipping point of destruction. In fact, it’s not even close. These publications fail to disclose that these fires are seasonal and will continue to happen without man-interference. These so-called protection of the Amazon is part of an agenda rich countries have to keep Brazil uncompetitive. How about we start rebuilding green space in Western Europe? How about we start planting more trees in southern California?


I am going to go ahead and put more credibility into peer-reviewed research in Nature than some random HN comment without sources.


The link is no not a peer-reviewed research in Nature, it is a "News Feature" written by "a science writer based in Manaus, Brazil."

The cites for the tipping point are two editorials written by the same team of two researches in Science Advances, these are editorials, not research articles.

They cite https://agupubs.onlinelibrary.wiley.com/doi/full/10.1029/200... that is a peer-reviewed research article in Geophysical Research Letters.

The research article claims that with a 40% deforestation the rain reduction will cause problems, but in the editorial they use hand waving to reduce that to 20%.


The goal is to get more people involved. Doesn't it make sense to lower the entry barrier by implementing a more popular syntax?


Yes, that's definitely the balance to maintain. Ease of entry, vs tooling to manage the project as it grows. The main reason I see it being an inhibition is due to the size of the HTML spec, and the number of pages that it will need.

I think this is why a lot of sites take markdown, then add their own extensions, like how there is "Github Markdown" among many other flavors. That's definitely one route, but I see something like ReStructuredText or Asciidoc as more mature and interoperable, while still being relatively easy to master in the same way as Markdown. Since they can both produce docbook output, vastly easing any migrations in the future by adhering to an industry standard.


It's not that easy. We have 60+k pages carried over from 15 years of organic evolution. It's unstructured and messy. A move away from HTML to something "more popular syntax" (like Markdown) is NOT easy.


Why does Mozilla insist on Pocket?


Your comment makes no sense. What does tax negotiation have to do with chaos responsibility and privacy breach?


Talking about responsibility to society is hypocritical when you're paying lawyers to hide money away from medical care, schools, infrastructure and other tax funded sources in countries all over the world.

Tim seems like a person only interested in talking in points that smear his competition. Understandable from pure selfish business perspective, but the fact that he's trying to make a moral argument just leaves a bad taste in our mouth.


Any beta testers here able to confirm whether Terminal.app supports True Color now?


Can't answer that but on a related note, recent zsh fully supports true color. You could always use it in things like prompts with literal escape sequences but it'll also work for syntax highlighting etc and interpret colours in hex triplet form for you now.


It doesn't look like it.


Why not just "invalidate" the client? At best, you're making your application "safe" for 900ms or whatever the expiry date is.


What do you mean by "invalidate the client"?


Seriously?


I would like to know what you mean. “Invalidating the client” seems almost nonsensical since you don’t control the client.


You do control what clients (think client_id/secret) can use your APIs. Don't you? You figure it out from there.


No. The discussion here is about using JWT for sessions with web clients.

If you’re registering a dedicated client id and secret for each web client, they you’re doing something wrong. If you’re doing this and then also using JWT, then you’re doing something really bizarre, and still wrong.

Id/secret pairs can make lots of sense for integrating partner services with your API. They make no sense for web clients, where you should be authing a user and not a client.


Classic hostility on HN. I'm out, I'll go find my tribe.


Nowhere was I hostile. I answered your comments politely and clearly. You were arrogant and condescending but you apparently don't actually know what you're talking about.

Please do go find your tribe of condescending devs with fragile egos.


No, you don't control the client. The attackers do.


Yes, seriously. How to invalidate is exactly what is being discussed.


I bruteforce a password for your JWT-enabled app. Then I have a token. Copy the token from my browser ( usually just open Network tab at the inspector and copy the headers for the request ). Then I store the token at my server and make it execute a request to the app on intervals to prevent from expiring ( reissue ) the token.

How can you invalidate my server now?


Last time I checked Quebec reaped the benefits of Alberta's oil sands... didn't they?


Are you like a Russian troll trying to sow dissent or something? We're talking about poutine!


Nope. The OP is talking about cultural appropriation as if Quebec and Canada were 2 different places. They’re not.


Seriously?


Yes. I don't understand the surprise.


Every support ticket on Apple's forum is breaking news now.[0]

[0]: https://www.youtube.com/watch?v=J_lRJuQtBmc&feature=youtu.be


> their team (managers and developers) are all over twitter and reddit trying to explain the privacy violations away

That's literally their jobs as Chrome evangelists. They're just doing what they're told.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: