Hacker Newsnew | past | comments | ask | show | jobs | submit | vulpino's commentslogin

Dropbox does too! Unfortunately, those are the only sites supporting U2F I know of at the moment.


http://www.dongleauth.info/ maintains a list of sites supporting U2F devices. There aren't many yet, but it looks like a Wordpress plugin exists that may end up in core. There are also a handful of additional sites listed in issues and pull requests on the site's GitHub page (https://github.com/Nitrokey/dongleauth).

(I'm not affiliated with the site, I just check it periodically and thought it might be of use here.)


Bitbucket as well.


That's new! Took more tries than normal to register, but that's great. They took so long to roll out even TOTP based auth, I figured it would be ages before seeing U2F.


Google also supports U2F


I'm not the author, but enabling NoSelfIntersect totally ruined the frame rate for me. I was barely able to open the controls to disable it again. It's possible it's not on by default as a performance consideration.


Yup, that setting is implemented in a somewhat naive way. The way it works is that I iterate through every pair of points on the cloth, check for when they get too close, and if they are, I introduce a spring to push them apart. So effectively this introduces a short-range repulsive force between pieces of the cloth.

Avoiding self intersections results in more realistic cloth behavior like folds and wrinkles. The problem is, iterating through all pairs of points comes at a computational cost, and can really drop the frame-rate, particularly for large cloths. So I decided to keep this setting off by default until I have a smarter way to implement this (e.g. using quadtrees).


The bar graphs were not designed to compare total amount of lines for each gender/age-range combination. Rather, they're meant to indicate how the percentage of lines for each gender is skewed older for male actors vs younger for female actors.

If they were to determine the length of each bar using amount of lines instead of percentage of lines, all that would be immediately clear is that females have less lines, a fact well established in the rest of the article, and the point would be lost.


author here. YESSSSS


They deduct points as it's still open source. And they are more applauding the fact that WhatsApp - probably the most widely used messaging app currently - has adopted strong end to end encryption, something which other clients have been loathe to do.

This is a win. To disregard everything that WhatsApp and Signal have accomplished because WhatsApp isn't open source is silly.


> This is a win. To disregard everything that WhatsApp and Signal have accomplished because WhatsApp isn't open source is silly.

Is it? If the next Snowden uses WhatsApp on the basis of this recommendation, and it turns out (say) the NSA has backdoored their RNG and is scanning all messages sent over WhatsApp, that person is going to find themselves jailed or maybe executed. You can't say "it's secure except for not being open source"; the stakes are too high for that.


No but to blindly trust in it is silly. Even openssl had a heart-bleed bug that persisted for years without most people realizing it. All it takes is one bug for the entire thing to be useless.


And heartbleed is also than example of open source not being totally secure. It was a bug that persisted for years before it was found - and OpenSSL is open source.

It's just as foolish to blindly trust OSS. There will always be holes - the main point to OSS is not to combat these, as they will exist regardless. Rather, it is so one might know exactly what they're installing/using, without having to trust the corporation behind it.


no it's foolish to trust something that hasn't been independently reviewed. How can EFF recommend something that hasn't even been subjected to an independent security audit?


The goal is not to be perfect, but to kickstart encryption adoption by a large non technical audience I believe.

Sure that's no excuse for potentially bad crypto but it's worth it if this gets proper infosec into the public reach in the end. I'm confident this is a first step to having trustable encryption "in the real world" even if it's another client/company providing it later. Call me an optimist :)


> one bug

Everything can have bugs. The problem with this software is that it's a centralized single point of failure. Only a proper federated protocol can be resistant to subversion by business, government, or other interests.


Official website: https://sandbox.mit.edu/

Apparently Sam Altman is holding a talk/Q&A there on the 13th. It's an intriguing concept - I'm not aware of any similar programs at other colleges.


It's similar to Velocity at UW: http://velocity.uwaterloo.ca/


And my university (UAlberta) is having trouble with people graduating in CS, because within an hour all of higher level courses were booked so people can't take the courses they need to graduate, some people are forced to take a year off among other things.


I thought in most universities, the higher you are (Senior/junior) you get early/priority registration period, and it makes sense.

I find it strange not to have it.


How about:

"Maybe Microsoft should consider open sourcing the components of their system which track users. It's possible that this would help rebuild the trust that was eroded with the release of Windows 10."


Thanks. Tried to change it... but the "edit" link was gone by that time. Oh well, next time. :)


I've been really happy with Dropbox Paper (invite only right now, http://paper.dropbox.com, an article overviewing it: http://www.techinsider.io/hands-on-with-dropbox-paper-2015-1...).

Canvas looks strikingly similar to this (almost exactly the same aesthetically), and I'm curious what the "killer feature(s)" are which give it an advantage over Paper, which is developed by a much larger company (Dropbox).


Came here to say the same thing. Extremely similar to Dropbox Paper.

I haven't been that happy with Dropbox Paper though. It doesn't handle basic things like bullets in indented blocks, or line/paragraph breaks in numbered lists. Hackpad (Dropbox acquisition) didn't look as nice, but had more functionality. Now Paper is replacing Hackpad.

I'll be giving Canvas a try.


Let me know how it goes! jonathan [at] usecanvas [dot] com


Is Dropbox Paper planning integrations with third parties? I can already do basic collaborative editing in Google Docs, and it sounds like Paper is similar to that. The killer feature for me (when shipped) is being able to drop in native representations from the other tools I used heavily (Slack, Trello, GitHub, etc) into a document that I'm collaborating on.

For example, right now in a Google Doc if I want to connect it to a Trello list I need to add a bullet for each card in the list, make it a link to the card, and keep both things in sync. What if I could just drop in the whole list (or even a whole board in some cases) and have my project plan and my specific cards in the same context without jumping between different tools? That's a killer feature for me if they can pull it off.


This is ludicrous.

> "hahah, you’re actually being a dick. so, fuck you. don’t e-mail me back."

This is the developer the community gathered behind? Not only is that incredibly unprofessional (to say the least), kik is a registered trademark.

And - I've said this before, but I will repeat it here - unpublishing all your modules from npm ("liberating") is such a selfish and childish move, especially when so many people depend on your modules. That's the behavior of a preschooler. That's not "power to the people," as Azer put it in his original post. That's just an attempt to show that Azer has the power to bring chaos to the ecosystem.

People are so quick to jump to the defense of someone who is having their "freedom" suppressed, without knowledge of the situation.


Where does it end? An individual working on an open-sourced project has to get strong-armed out of a 3-letter name because a corporation paid for it? Isn't that concept a little ludicrous in its own right?

Could this eventually end up a constant corporate whack-a-mole until project names ultimately degrade to random strings of consonants?

If it's professional to contact someone and say "Hey buddy, we're bigger than you — change or we'll ruin you" then maybe "fuck you" is necessary.


That's a very slippery slope. Kik is an app and company that has been going on for years. It existed long before Azer's "kik" and, even if Azer does not know what it is, most people know "Kik" as the phone app and not the bootstrapping tool.

To extrapolate this incident to "companies will start snatching up three letter names, and nothing will ever be able to use a three letter name" is ridiculous.


"Most" people don't know of either.

Kik is a messaging app, kik is a node module. Was someone going to call up the app store and install a node module? Was someone potentially going to install a messaging app into their node project?

I think there are a lot of slippery slopes here.


Well, if Kik - the company - really intends to release a node module that would be enough to confuse some people.


That's the same absolutely absurd argument that npm made.

Who actually installs a module without actually seeing what it does first?


I associate Kik with a textile discounter. Just because they are known by parts of the population and have copyrights in some countries, do they really have the right to claim their name pretty much everywhere?


It's not copyright, but trademark (it's a subtle, but important distinction). And for trademarks, the short answer is it depends. Some trademarks have no protection (generics or ones that become generic) and others have infinite protection (famous marks, like Apple and Disney). While most have protection in their field (think the word Mac, it's a computer, a burger and a cusmotic brand).

Field however is hard to define, for example Trademark offices have categories and theoretically, you cannot have 2 trademarks owned by 2 different entities. That said, it does happen, because the "fields" are actually defined by likelihood of confusion, which is shown in court. If this is all confusing, it is.

But long story short, if your mark is famous (and kik's would be considered famous), you're the only one allowed to use it, and you HAVE TO in force it, otherwise, you lose it.


So if Disney wants https://www.npmjs.com/package/jasmine than they should have it? Just like that? With a polite request with "P.S. lawyers!"


I'm happy to make an issue of professionalism in a professional environment. I spend my day in suits around businesses that will openly tell you they won't work with you because your tie looked cheap. There are businesses involved here, and people in business roles making, imo, unprofessional threats.

When you work all day, and then come home to provide unpaid support for a project, things are different. You're sitting in front on a television in shorts, in the least professional environment imaginable, and you're helping people who have issues with your code, because that's what it means to give to the community.

Then someone comes out swinging with a list of demands, regarding what you do in your own time. What is the return threat? "He wasn't professional so I'll stop making unpaid use of his products"?


Since when do people have to be 100% professional in all their dealings 24 hours everyday in order to be in the right?


Maybe we could shoot for at least 25% professional?


Maybe not professional at all times, but what about polite?


I think threatening someone with lawyers is exactly what it sounds like: a threat. This is not polite behavior even if the text was written in a polite manner.


suppose you were in Azer's situation, where a corporation has threatened legal action against you, and then did an end-run around you and used their influence to have the maintainers of your software distribution platform act against you unilaterally.

would you feel like you had been treated justly? what would your response be?


Would I feel like I had been treated justly? Of course not. I would be angry. But in a situation like that, I can't blame npm because their hand was forced and I can't blame Kik for defending their trademark. Especially if they're planning on making a "kik" package that has something to do with, you know, their kik.

I'd like to think I'd be professional enough to change the name of the package once I was prompted by kik, reupload, and be done with it. I'd be miffed, but it's a piece of software. It won't ruin me to rebrand it. It'll take an afternoon, at most.

Cursing at people and calling people names, I'd like to think that we're above that as human beings, no matter how upset we are. That's something that teenagers in League of Legends do. That's not what a professional software engineer does.


> But in a situation like that, I can't blame npm because their hand was forced

was it really though? can you show me where NPM had any kind of obligation to unilaterally take one side in this dispute?


They were not "forced" by court order or any other legal means, but they were "forced" because I can imagine going to court over the entire ordeal would have been incredibly draining on their finances and manpower and ultimately pointless. I'm willing to bet that whatever fallout this results in for npm (even as big as this has become) is ten times better than whatever would have happened if they'd decided to fight Kik over it. They probably just wouldn't exist anymore as a company.


I don't think it would have affected NPM whatsoever. The "draining" court battle would have been between Azer and KIK. to me the most confusing and inappropriate behavior in this whole sorry situation was that of NPM.

its easy for me to see where both KIK and Azer had legitimate claims to the name and its also totally legitimate for two parties to NOT come to an agreement outside of court. We have courts to settle disputes. That is where this should have ended up.

NPM effectively denied Azer his potential legal remedy by unilaterally supporting KIK.


But Kik Interactive wouldn't have taken them to court over this. It's a 100-person company. No one has the time, or the motivation to go on a tangent like that. Especially since they'll be paying hundreds or low-thousands in lawyer fees just to file.

npm dun goofed.


I'm not a lawyer but I imagine it would be taken care of as a court order in the lawsuit between Kik and Azer. Suing npm or github for a trademark dispute they have with Azer would be silly. The most I could see levied directly against npm is a cease-and-desist. But I guess just mentioning lawyers is enough for npm to hand over a module namespace.


Hold on, hold on. Let's say you have worked hard on a project that you were not paid for, totally out of love for software.

And out of nowhere, a corporation threatens you to re-brand it else you are gonna face consequences, you are saying you will rename the package and be done with it ? Just like that ? Without asking why .. or finding a compromise ? I am sorry to say, but that's not how most people think.

Maybe this would have played differently if Bob would have used better language. But the fact that he went off with "our trademark lawyers are going to be banging on your door and taking down your accounts" would have pissed off any person.

And why can't a software engineer be "unprofessional" in his own private time when he is dealing with "unprofessional" people in the first place ? Have you even read any of Linus' mails ?


"kik" is not actually a Trademark of KIK Interactive.

They do have "KIK" trademarked[0], but it is only claimed for:

>Computer software for use with mobile phones and portable computing devices to exchange, share and create text with other users; computer software for electronic messaging services; computer software for use with mobile phones and portable computing devices to exchange and share digital photos; computer software for use with mobile phones and portable computing devices to download audio, video, digital photos and programs; electronic payment systems, namely, a computer application software used for processing electronic payments to and from others; computer software for use with mobile phones and portable computing devices to create video and digital photos to share with other users; computer software for use with mobile phones to launch other applications and connect to other software services.

>Electronic payment services

>Electronic messaging services; wireless digital messaging services; telecommunications services, namely, electronic transmission of text messages; telecommunications services, namely, electronic transmission of digital photos; telecommunications services, namely, electronic transmission of audio, video, digital photos and computer programs; computer services, namely, providing interactive technology that allows users to create video and share audio and video with other users; telecommunications services, namely, providing computer software services for use with mobile phones and portable computing devices to create video and digital photos to share with other users.

As far as I can tell, kik [1] does not provide goods or services even remotely related to the KIK trademark.

[0] http://tmsearch.uspto.gov/bin/showfield?f=doc&state=4807:385...

[1] https://github.com/azer/kik


And it's entirely possible (maybe even likely) that npm would have won in a court of law. But the legal expenses were probably simply not an option, and I don't blame them for that.


I don't see how NPM has any legal expenses if they only respond to valid court orders?

If KIK believes kik being on npm is an infringement on their Trademark, let them prove it in a court of law.

I don't see why NPM needs to be involved in this dispute at all.


Because that's just not how the legal system works, at least not in the United States (Kik Interactive is located in Canada, npm Inc. is located in the US, so it's possible for Kik to file a lawsuit against npm in the US.)

Full disclosure, I'm not on Kik's side here. I think they should have let Azer keep the kik npm module. I'm just trying to explain why npm could be legally threatened.

Kik sent npm a request to take down a package with their trademarked name. If npm declined, they could have filed suit against npm. They would not have to prove that their trademark was valid before doing so. Even if they didn't have a trademark, they could file the case, knowing they would lose. It would be a very short case. Npm's lawyers would have to submit evidence that Kik didn't own the trademark, and the case would be dismissed.

But the important part here is that they would need to show up to court with lawyers, and this is not free. This is why (again, at least in the US) legal threats from big companies like Kik to small developers (or other individuals, or even smaller companies) like Azer are so threatening and offensive. Even if the company is in the wrong, and the small developer is in the right, the cost of hiring a lawyer and going to court is so expensive that you're better off just letting them have their way, even if they're wrong.


> they would need to show up to court with lawyers, and this is not free.

So what's the rule there? You show up to court without lawyers and you automatically lose?


The point is that even showing up costs time and possibly travel expenses. Court proceedings are slow, so without a lawyer, you'll spend days of your time in court fighting the case.

It's possible to defend yourself without a lawyer. People have done it successfully. However, to be successful, you have to spend a lot of time learning, understanding and using the law to your advantage, and it's usually not worth it. Even lawyers will hire other lawyers to defend them, if they're defendants in a case outside their area of speciality.

There's a pervasive attitude that representing yourself without a lawyer lowers your chance of winning, though there are no hard statistics either way.

If you don't show up at all, you'll almost always lose. In many cases, if you fail to show up, the judge is required to rule in favor of the only party that showed up. Even if that wasn't the case, if the judge is only listening to one side of an argument, they're likely to agree with that side.


NPM doesn't need to send a lawyer or any representative.

KIK must prove infringement to get a court order and they won't be able to because they claim no Trademark protection in any goods or services that `kik` deals in.

NPM could have been a dispassionate observer, but decided to take it upon themselves to arbitrate a Trademark dispute. To me, this opens them up to liability if they make any incorrect decision or findings. Why would they want to take on this liability?

There is no pressing need for them to become involved. They should have let Trademark courts handle Trademark disputes.


> Kik sent npm a request to take down a package with their trademarked name.

I think they just asked for help in resolving the issue they made up. and used word "lawyers" few times. That's apparently is all what it takes US company to fold.


I won't defend either Azer or Kik. This whole episode just has me shaking my head. Why do people need to include a module for 10 lines of code that do something basic? Azer's actions brought chaos to the ecosystem because people started depending on the ecosystem to think for them. It wasn't something huge like Express or Mongoose that broke the internet, it was a stupid string padding function.


I'd imagine that, if NPM were contacted by a lawyer as the developer states, that there was the threat of legal action. So, then, you are correct and technically I should title the article "NPM, Under Threat Of Legal Action, Removes Package From Registry," or "NPM Complies With Request Made By Lawyer."

I don't think NPM at any point valued the lawyer's opinion. But do you really think it's feasible for them to go to court? An app with millions of users is not going to change its name. A command line tool with less than 100 stars on github can surely afford to.

Was removing the package the morally "right" thing to do? Unlikely. It's clear he wasn't intentionally infringing on the kik trademark. But he (the developer) acts as if it was something NPM did willingly, and clear proof that NPM is a malicious organization designed to usurp the community of its power. That's an absurd claim.


I'll look into it, thank you!


The reactuate react+redux+stuff stack may provide useful prior art therefore.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: