<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ohithereyou</title><link>https://news.ycombinator.com/user?id=ohithereyou</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 15 Jun 2026 12:07:31 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ohithereyou" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ohithereyou in "Lisp: Good News, Bad News, How to Win Big (1991)"]]></title><description><![CDATA[
<p>Shitposting and its consequences have been a disaster for Intenet discourse.</p>
]]></description><pubDate>Sun, 15 Mar 2020 20:41:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=22586569</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22586569</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22586569</guid></item><item><title><![CDATA[New comment by ohithereyou in "U.S. Labor Department allows unemployment benefits for coronavirus"]]></title><description><![CDATA[
<p>If COVID-19 digs in deep in the US then there is going to be a transformational change in how US citizens think about work, travel, entertainment, security, and the relationship between US citizens and their government.  All of these aspects are intertwined:<p>Work: More people will work more time from home and many firms will switch to virtually full time remote with limited physical gathering.  This will decrease the cost of office rents and alter the work/life balance.  It will affect wages because people can live outside of city centers and still work so companies will pay less.  We may be on the cusp of US government guaranteed sick leave.<p>Travel: People will, for the short term, do less travel for pleasure, but the big impact, long term, business trips will decrease.  More and more business meetings will be replaced with voice and video conferencing.  There was no big driver other than some cost reduction here, but now safety and security will be the big drivers here.  Global pandemic concerns (prevention, containment) will complicate travel to varying degrees, and in a way that most US citizens aren't used to - it will affect interstate travel, not just trans-national travel.<p>Entertainment: Many of the sports that have been deferred or canceled will likely be replaced with other forms of entertainment that can be viewed on television or the Internet.  Fewer people will go to live performances, both because they can't (cancelled by the government) and reluctant to after COVID clears.  This will affect service workers - where most of the lesser skilled jobs have been created in the last three decades.<p>Security: Security will no longer be seen as just a physical access control concern.  Business has been preparing over the last two decades for the eventuality of global pandemic - now they can put those plans into action, and the impacts of them will cascade into personal lives.  US citizens will be demanding more from their government in disaster preparedness on pandemics - it will affect travel.<p>All of these tie into how US citizens see their relationship with their government, and what they demand from it.</p>
]]></description><pubDate>Fri, 13 Mar 2020 17:50:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=22569309</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22569309</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22569309</guid></item><item><title><![CDATA[New comment by ohithereyou in "Covid-19 is now officially a pandemic, WHO says"]]></title><description><![CDATA[
<p>Isn't it the aspirational goal for several churches/religious orders to do just this?</p>
]]></description><pubDate>Wed, 11 Mar 2020 19:38:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=22549635</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22549635</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22549635</guid></item><item><title><![CDATA[New comment by ohithereyou in "The PS2’s Backwards Compatibility from the Engineer Who Built It"]]></title><description><![CDATA[
<p>Why would they add that when they can just sell you a remaster for the price of a new game?</p>
]]></description><pubDate>Sat, 07 Mar 2020 03:00:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=22509431</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22509431</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22509431</guid></item><item><title><![CDATA[New comment by ohithereyou in "Purge site data when site identified via old tracking cookies"]]></title><description><![CDATA[
<p>If you're going to treat investigative reporting and news gathering as a profit making venture then you can only charge what the market is willing to pay, and for the vast majority of people, that's nothing.</p>
]]></description><pubDate>Fri, 06 Mar 2020 03:22:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=22500737</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22500737</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22500737</guid></item><item><title><![CDATA[New comment by ohithereyou in "Purge site data when site identified via old tracking cookies"]]></title><description><![CDATA[
<p>Think of the poor buggy whip makers!<p>Not every desirable activity in life is profitable.  If your business plan is "make website -> get money" then perhaps you're in the wrong business.</p>
]]></description><pubDate>Thu, 05 Mar 2020 21:39:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=22498639</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22498639</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22498639</guid></item><item><title><![CDATA[New comment by ohithereyou in "Purge site data when site identified via old tracking cookies"]]></title><description><![CDATA[
<p>A site that renders completely blank without JavaScript is a site that I don't enable JavaScript for.  They don't want me to view it, and nine times out of ten I can find the information elsewhere.</p>
]]></description><pubDate>Thu, 05 Mar 2020 21:36:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=22498604</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22498604</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22498604</guid></item><item><title><![CDATA[New comment by ohithereyou in "GOG asks you to please not abuse its expansive new 30-day refund policy"]]></title><description><![CDATA[
<p>GOG games are DRM free and typically show up on torrent sites immediately after release, so anybody who wants to pirate the game won't bother to go through the buy->download->refund flow with them.</p>
]]></description><pubDate>Wed, 26 Feb 2020 17:43:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=22425274</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22425274</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22425274</guid></item><item><title><![CDATA[New comment by ohithereyou in "Show HN: Shox: A customisable status bar for your terminal"]]></title><description><![CDATA[
<p>Terminal middleware already exists - screen and tmux seem to be the most popular here.</p>
]]></description><pubDate>Wed, 26 Feb 2020 03:03:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=22419892</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22419892</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22419892</guid></item><item><title><![CDATA[New comment by ohithereyou in "Say It Is So: Baseball’s Disgrace"]]></title><description><![CDATA[
<p>Wait, does anybody actually believe any major sport doesn't look the other way when the right team cheats assuming it gets more butts in seats?  Major sports aren't about the purity of the game.  They're about money - pure and simple.<p>If MLB could replace all of the players with robots that played a game simulated on a computer, designed to play out a storyline as a drama instead of a legitimate competition, and make more money doing it then they would in a heartbeat and not lose a wink of sleep over it.</p>
]]></description><pubDate>Tue, 25 Feb 2020 20:58:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=22417364</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22417364</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22417364</guid></item><item><title><![CDATA[New comment by ohithereyou in "Modern, functional Common Lisp: myths and best practices"]]></title><description><![CDATA[
<p>What sort of encryption and authentication can I expect if I do that?  Can anybody who guesses the port dump code into my running Lisp instance?</p>
]]></description><pubDate>Tue, 25 Feb 2020 13:09:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=22412861</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22412861</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22412861</guid></item><item><title><![CDATA[New comment by ohithereyou in "“We found PayPal vulnerabilities and PayPal punished us for it”"]]></title><description><![CDATA[
<p>Legitimately interested in your explanation as to how this specific research would be a crime absent contact with HackerOne.  Please cite statute.  I'm not saying you're wrong - simply asking you to back up your claim with evidence.</p>
]]></description><pubDate>Mon, 24 Feb 2020 17:10:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=22405939</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22405939</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22405939</guid></item><item><title><![CDATA[New comment by ohithereyou in "“We found PayPal vulnerabilities and PayPal punished us for it”"]]></title><description><![CDATA[
<p>"Dark web" for things that are not relevant to Five Eyes and NSA when they are relevant.  At least in those cases, with good opsec for the "dark web", you can be reasonably sure the company who made the product can't retaliate against you.</p>
]]></description><pubDate>Mon, 24 Feb 2020 17:07:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=22405890</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22405890</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22405890</guid></item><item><title><![CDATA[New comment by ohithereyou in "“We found PayPal vulnerabilities and PayPal punished us for it”"]]></title><description><![CDATA[
<p>That sounds like it's a payout lottery.  H1 can't force its customers to pay.  It's acting as a go-between on behalf of its customer, the company offering the bounty, not as an neuteal arbiter when there is a dispute.<p>Perhaps I would take them seriously if there was an escrow account companies paid into and was released to the reporting party when a plurality of multiple, disinterested parties agreed that the report was valid.</p>
]]></description><pubDate>Mon, 24 Feb 2020 17:05:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=22405863</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22405863</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22405863</guid></item><item><title><![CDATA[New comment by ohithereyou in "“We found PayPal vulnerabilities and PayPal punished us for it”"]]></title><description><![CDATA[
<p>> not let your anger cause you to do something stupid<p>Note: I didn't say that I would do this for every company.  Just ones that use HackerOne.  They have decided to abdicate their responsibility for their security vunerability reporting, and I feel completely justified in dumping info on their vulnerabilities.<p>Releasing the details of a vulnerability is not stupid.  The users of the software/service deserve to know the data/service they're using is unsafe when a vendor refuses to act on a valid security issue<p>>If you disclose a vulnerability, the company HAS EVERY RIGHT to sue you.<p>You don't need the right to file a lawsuit to file a lawsuit.  You just file the lawsuit.  Now, you need an actual, actionable claim to prevail a a plaintiff in a lawsuit.  Whether such a thing exists in practice is something we leave to lawyers to argue about and judges/juries to decide.<p>If your company is in a competitive industry and I release the details of a vunerability in your software and you sue me then that vulnerability and lawsuit becomes marketing item number one for all of your competitors.<p>>this is why these bug bounties and established ways of notifying the company of the vulnerabilities exists<p>Arguably why they exist.  In reality, they tend to exist to give people an incentive to not dump the vuln details on the black market, embargo bugs so customers don't leave, and attempt to maintain a good relationship with security researchers.  They do not grant immunity from being sued or somehow grant the legal right for security researchers to do their work as your comment seems to indicate.<p>Your post reads like propaganda from a bug bounty organization.  I'm not saying that you're shilling, just that you're misinformed.  In the US it is generally legal to conduct security research.  In the US it is legal to communicate the results of that research publicly so long as you have not agreed in some contract to not do so.<p>Where did you get the idea that legitimate security research is a crime?</p>
]]></description><pubDate>Mon, 24 Feb 2020 16:57:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=22405772</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22405772</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22405772</guid></item><item><title><![CDATA[New comment by ohithereyou in "“We found PayPal vulnerabilities and PayPal punished us for it”"]]></title><description><![CDATA[
<p>Are there other cases where PCI-DSS compliance requirements are selectively enforced?</p>
]]></description><pubDate>Mon, 24 Feb 2020 13:55:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=22403947</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22403947</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22403947</guid></item><item><title><![CDATA[New comment by ohithereyou in "“We found PayPal vulnerabilities and PayPal punished us for it”"]]></title><description><![CDATA[
<p>All the more reason to not submit bugs like this to HackerOne.  If you can bypass 2FA by having only one factor then I wouldn't consider that 'stolen credentials' and more a singular stolen credential.  Their system is designed to defend against this and it does so ineffectively.  That is, by definiton, a security issue.<p>I wish I could define what is and isn't a bug in my code at work.  My defect rate would be incredible.</p>
]]></description><pubDate>Mon, 24 Feb 2020 13:52:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=22403929</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22403929</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22403929</guid></item><item><title><![CDATA[New comment by ohithereyou in "“We found PayPal vulnerabilities and PayPal punished us for it”"]]></title><description><![CDATA[
<p>The market for a freelance security researcher out there is hard, no doubt, but disclosing bugs publically is an addition to your resume, akin to any other professional development you do.  It demonstrates you can do the work and it shows the skills you have.<p>Suing someone for disclosing an actual bug is a long term losing proposition for any company in a competitive industry.</p>
]]></description><pubDate>Mon, 24 Feb 2020 13:50:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=22403908</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22403908</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22403908</guid></item><item><title><![CDATA[New comment by ohithereyou in "“We found PayPal vulnerabilities and PayPal punished us for it”"]]></title><description><![CDATA[
<p>I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported.  I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.</p>
]]></description><pubDate>Mon, 24 Feb 2020 13:39:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=22403843</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22403843</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22403843</guid></item><item><title><![CDATA[New comment by ohithereyou in "Daily Life with the Offline Laptop"]]></title><description><![CDATA[
<p>What sort of development do you do on the PowerBook?</p>
]]></description><pubDate>Mon, 24 Feb 2020 11:12:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=22403119</link><dc:creator>ohithereyou</dc:creator><comments>https://news.ycombinator.com/item?id=22403119</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22403119</guid></item></channel></rss>