Hacker Newsnew | past | comments | ask | show | jobs | submit | akersten's commentslogin

Why are you subjecting yourself to that instead of downloading Firefox + uBlock origin?

See the headline of this article for Exhibit (I've actually run out of letters in the alphabet) why adblocking is a moral imperative.


As much I love a good old "Why don't you just ..." response that terrifically misses the point - in this particular case I was watching YouTube through their Apple TV app.

Now, there may be another "why don't you just ..." or "well, actually ..." response you have queued up, maybe some ramblings about a pi hole, or some anti-Apple hate, or some other solutioneering. Go ahead, tell me.

But it is the structure of incentive that forces this. The YouTube creators that make the content do need to get paid. And Google offers an option: Youtube Premium. That give both me and the creator what we want and (for the time being) removes the ads.

So either one is rich in time (doing whatever "why don't you just ..." hoop you expect me to jump through) or rich in money.


If you want creators to get paid, pay them (channel memberships, patreon, click on their sponsor links and buy something). No need to subject yourself to ads.

Ads don't just steal your time either, they invade your head. You are influenced by them and you have no choice as long as you watch them.


Sounds like you've made a choice to watch ads. Which is fine, but then maybe don't complain about it.

That is wrong on both accounts. I have little choice other than to watch ads since the structure of incentive that creates a marketplace like YouTube forces it on me.

I think about libraries and how the world would be if instead of a free public resource, you had to watch ads before you were allowed to take out a book.

It is just the case that in this modern social media world, if you want your ideas to spread you have to put them onto social media. And if I want access to those ideas I have to consume them through social media. There is nothing about that environment that is my choice, it is the environment that I find myself in.

And I have few choices to get around it. I can twist up into a pretzel trying to block the onslaught with more "why don't you just..." advice. Or I could pay to make it go away. Or I could just go off-grid and forego access.

And when you look close at the options, it becomes clear that sovereignty of my own mind has a price. Freedom of mind is not free in this modern world, if it ever really was.


You made the choice to use Apple TV, whatever that is. I just use... YouTube. In my browser. Do you not have a browser? It doesn't cost money.

You also have no obligation to watch ads for creators to get paid. They can also set up things like Patreon if they would like. The ads are very lucrative, and that's their choice. But you are free to make choices too, if you would like to.


They wanted a whinge, and not a solution. A position that I truly do not understand, but is not uncommon.

> The YouTube creators that make the content do need to get paid

Nope.

They may get paid, they may not. That's the risk they've chosen. They may also get their Google account banned with no recourse for something minor or even non-existent.

> So either one is rich in time (doing whatever "why don't you just ..." hoop you expect me to jump through) or rich in money.

That's what they want you to think, you've been watching too many ads.


>The YouTube creators that make the content do need to get paid.

The world would honestly be better if they didnt.


> I was watching YouTube through their Apple TV app.

That is an active choice, not forced in any way.

> The YouTube creators that make the content do need to get paid.

There are better ways, and we would all be better off except for the small group of greedheads benefiting from the chaos

The ad supported internet is dying. Good riddance


We must ensure the gravy train keeps rolling until we IPO.

> Crack down on unauthorized distillation / prevent weight theft

Actually hilarious to put that in writing, given the genesis of this entire business model.


Pulling up the klepto-ladder.

Eh, I hope Apple continues to provide this and it forces the needed discussion about how two-party consent requirements are nonsensical. Why should it be illegal for me to remember exactly a conversation that I participated in, instead of only being allowed to have a vague recollection?

Laws like this provide cover for abusers and deceivers, by preemptively spoiling objective evidence and making any accusations depend on hearsay instead.


It's not illegal for you to remember, it's illegal for you to record. There's a difference.

For me, I don't want to live in a world where if I say something embarrassing or not well thought out, someone pushes a button and the last 15 seconds is transcribed as evidence. That's a different world to the previous one where it would be someone's word fori it.

As for the fact that phone could already do this, that's not the point. Phone users have to go out of their way to make it happen so it's generally unlikely to happen. The watch feature though is always on and just waiting for you to press "save last 15 seconds"


Same with the always-on transcription feature that you dont even need to interact with. I like not having to speak with extreme precision, knowing my words are going into some record.

> Eh, I hope Apple continues to provide this and it forces the needed discussion about how two-party consent requirements are nonsensical

Really disagree on this, I think all states should be two party consent, personally.

> Why should it be illegal for me to remember exactly a conversation that I participated in, instead of only being allowed to have a vague recollection?

It's not illegal, it's just that the other person has to know that you're doing that and consent to it.

Giving them the chance to walk away or to tell a person and their Meta glasses to fuck off is important.


People are fucking liars. Everyone, everywhere, always.

I want to record every conversation surreptitiously, because that’s the only way to catch them.

The reason we can’t is because our politicians and legislators are the biggest liars of them all. It would spell their immediate downfall.


Our politicians and legislators lie on camera constantly. But it doesn't really seem to matter much these days. So I'm not sure why this would make a difference.

Everyone being liars means you and I are both liars, same as the politicians. But the politicians have the power and if we remove two party consent then they get to surreptitiously record you and leverage that power. It doesnt even the power playing field.

We can alreay write notes down for every conversation and then send them to the person involved saying "we talked about X, Y, and Z." That last step is the key because it lets them object in writing if you mischaracterize things. From a "catching someone in a lie" the most important step is that one, because you form a paper trail where the other party can correct or contest what was written and bring that up now, and the fact that they didn't is itself evidence in case of a dispute later. The apple watch feature doesn't do that, it just dragnets everything. Even if it recorded the audio, we are in a faked-audio world so unless you have some signal that they agreed that they said a thing ahead of time, they can always deny it later.


Yes, let’s do something illegal to force a discussion. A discussion that already happened when writing the law…

> They were coordinating with OpenAI regarding a publishing timeline, but could not come to an agreement,

Skimming the PDFs it seems much more dramatic than that? It sounds like at least one of them is concerned OpenAI "solved" the problem by having their internal model use the chats of the independent researchers and want to claim the credit instead? I don't know. The tone is pretty accusational though:

> the one Levent and I had quietly chosen to attack. Almost nobody else I know of was working on it. It is not the direction one arrives at in a few days by giving a model the problem statement. When I heard “forced,” it was a bright red flag.

> I was shown a prompt and told the internal research model had simply been given the problem statement. Levent had been told by Sebastien “very little human input” had been used. This turned out not to be true. Over the course of the call, as members of their team sent Sebastien corrections and details over their internal chat, it emerged that an entire team had been working on the problem, that this was one of a number of things that was tried, that work had started on the unforced problem, that the team first set the model on easier problems, including Euler, that even the prompt that had been shown to me had been written by prompting Codex, and that an insane amount of compute had been used.

> I asked when the first prompt had been sent by them. This question was not answered directly by OpenAI for some time. Eventually it was agreed that it had been sent in the past few days, after information about our work had reached OpenAI.

> I asked whether the model had been trained on, or had access to, our sessions in Codex, into which we had been putting all our drafts for the whole of this project. I was told the model did not look up user data. I asked again, about training, and I did not get an answer. [0]

[0]: https://cims.nyu.edu/~tristanb/statement.pdf


I find the framing a little strange, a sort of David vs Goliath (with his enormous computational resources at his disposal). Since Levent is at Anthropic whose internal models are presumably as capable as anything OpenAI has. So why wasn't Anthropic behind their effort? Why did Tristan use OpenAI's models when it should have been known was a potential outcome? I understand they wanted a normal math collaboration but presumably what Levent brought was his resources (as far as I can see Navier-Stokes is not his speciality). Normally these things are hashed out formally beforehand to avoid the sort of thing now happening.

They were working on it for almost a year, and Buckmaster has evidently been interested in Navier-Stokes for a while. This seems to be more of an innocent collaboration between two researchers than a strong company PR effort. Maybe Anthropic should have stepped in and made a large team to help them finish the proof (and maybe they tried and didn't succeed, who knows).

If what he wrote is accurate, it does suggest that OAI is effectively extremely hostile to cutting edge researchers (eg, if we hear rumors about your partial success on a problem that has huge PR benefits, then we'll assemble a strike team of researchers with unlimited compute to claim the win for ourselves, possibly by training on your data). It's also not a good look for them to request author removals based on company affiliations.

I think what you have in mind is more appropriate for more normal corporate projects and the like. But academic collaborations are not usually so political/'profit' driven, if that makes sense.


> So why wasn't Anthropic behind their effort?

Presumably because this was something Levent did in his spare time and because it was not obvious that this work would eventually lead to a breakthrough.

> Why did Tristan use OpenAI's models when it should have been known was a potential outcome?

I'm sure in the past he had less cynical feelings about OpenAI and their penchant for academic fraud.

> I understand they wanted a normal math collaboration but presumably what Levent brought was his resources (as far as I can see Navier-Stokes is not his speciality)

I think you're not giving the guy enough credit in saying that his contribution came down to having an API key for Anthropic models.

> Normally these things are hashed out formally beforehand to avoid the sort of thing now happening.

How would that have helped? That agreement (which may well still exist) would not have involved OpenAI.


So what do you think his contribution was? His preprint record shows no research on fluids - and the statement says that the first LLM-generated proof Tristan received from Levent was 'the most horrendous I have ever read.' Levent is out for mathematical scalps whether it is in his field of expertise or not, and he has the resources to do it. And I am not saying he is not a very clever person, but the idea that you can bring yourself up to the forefront of research in PDEs, in particular NS, and contribute new ideas in less than a year is implausible.

They have messed things up, because Levent has a conflict of interest between his job at Anthropic and this independent work, and Tristan should have opted out of OpenAI training on their work (he probably didn't know about this). This doesn't justify OpenAI's despicable attempt to steal their work.

Yeah these are major accusations. But the story is incomplete, the conversation is missing a lot of details. It's not clear who was working on what, and when. The entire thing feels rushed, like they wanted to get this result published and out the door quickly.

Does he claim to have opted out of training too?

There are various forces at play here, academic honesty requires them to disclose any inputs regardless of license or ToS circumstances.

While common sense reminds us here that if you send your data to an external entity’s computer, you are no longer in control of said data. The lines have blurred here clearly over the last decade, but that should have made the theory yet more clear to everyone involved: your data will be vacuumed up unless you keep it sealed. Use your own computer if you want to be in control.


But if they didn't opt out of training, did they want OpenAI to opt out for them? Also they need to audit anyone they sent drafts to to make sure they opted out before submitting it.

I'd prefer things be opt in, and especially not start opt out, then try to trick you opt in with a popup defaulting to opt-in, like Anthropic did on consumer plans, but if they submitted anything on an opted-in plan it's not reasonable to be mad it trained on it.

Even still, I also believe for significant reasons that OpenAI would ignore the opt-out in selective cases and could be in the wrong here.

And the threats and terms they offered seem wrong either way, pending more context.


If you don't trust the other party, then it doesn't matter how the checkbox is set. The fundamental rule, IMO, is don't send precious or secret data to a third party.

There are only two types of scanned ID documents, those that are known to be compromised and those that are not

It kind of seems like an insane TLD structure to begin with, right? I always thought .co.uk was bad (you're just pinning yourself to whoever owns the .co. part, but at least browsers have some suffix list where you can't, I don't know, hijack some login cookie for all of .co.).

Joe Smith and John Smith can independently register joe.smith.name and john.smith.name, do browsers have a wildcard suffix list for the 2nd level of `.name` specifically, or can Joe set a cookie on all of .smith.name?


.co.uk is run by the same people as .uk. There is no additional org that you trust when you register a .co.uk: https://en.wikipedia.org/wiki/.uk#Second-level_domains

> do browsers have a wildcard suffix list

Yes: https://publicsuffix.org/ and they have discussed this situation here: https://github.com/publicsuffix/list/issues/2306


I know about the public suffix list - I was wondering about the wildcard specifically. In the very issue you linked to, as of 2025, it seems this was still unresolved...:

> We have no plans to modify the .name entries at this point in time. We are aware of the implications of adding a wildcard, therefore we won't.


Yeah, apparently they both (used to) offer unbounded registrations of 3LDs and unbounded registrations of 2LDs? So if I see j.doe.name, the only way to find out if "doe.name" is a public suffix or not, i.e. if I should (not) be able to set a cookie on it, would be to email the registrar?

So does that mean that in practice, .name domains were always treated by browsers like regular 2LDs, meaning the cookie and origin protection was always broken for those domains?

Doesn't sound like good news for the guy in the OP...


I'm just saying that they have discussed the situation. They seem to have no answer and for cookies and similar things the answer probably is "maybe don't run security critical web stuff in the third level under .name".

IIRC orgs like letsencrypt also use the PSL for rate limits, so there are probably more issues that are not browser-based.


Yes, Japan does the same with .co.jp but also .ne.jp, ac.jp, etc.

There are many examples; k12.<state>.us is another.

It is (or was for a long time, IDK) a strongly recommended practice from ICANN. I imagine nearly all countries to do that.

There end up being some weird edge cases where there are some countries which have both the equivalent of .co.uk but also allow registrations directly under the two-letter country code as well. .mx is one such case where most business are, e.g., costco.com.mx, but it’s also possible to register directly under .mx as well so Toyota Mexico is toyota.mx and not toyota.com.mx (the latter is registered, and ostensibly to Toyota, but the whois and nslookup records give very different results and the website doesn’t load when I try to visit it).

This isn't so bad as .com.mx and .mx should be on the public suffix list then.

But letting arbitrary customers take arbitrary 3 level domains, and others take 2 level domains, seems like a mistake as it's not very reasonable for every 3LD customer to put the 2LD on the public suffix list, but mixing 3LD and 2LD registrations means you can't public suffix *.name.

Seems the whole idea of having both was always misguided.


uk is one example - they opened up x.uk later, and gave x.co.uk registrations first dibs.

Except nobody uses the .us tld, but pretty much every every Japanese company is on a .co.jp

The .us domain should’ve been universally useful for state and municipal governments, but most of those began registering directly under .gov, and not even in an orderly hierarchy under .st.gov

But that was simply the easiest way to market your website as a trusted government entity. And now nobody has ever heard of .us domains in active use.


.us was primarily a hierarchy structure which in practice made confusing and hard to remember domain names, whereas .gov addresses hand out single domains which are generally easy to remember.

Personally, I never saw anything confusing about city.state.us; the hierarchy was organized perfectly logically in the 3-tier jurisdictional structure that every American schoolboy knows by 3rd grade.

https://en.wikipedia.org/wiki/.us

But your point about them being rather longer and difficult to remember stands, and the same for a .gov, which could be shorter and catchier.

However amusingly, .us opened up second-level registrations 24 years ago, which means that any qualifying entity could have their name registered directly under .us, which is obviously recognizable, and also one character shorter, than a .gov registration. However, by that time, I believe that .gov had increased in stature so that registering governmental entities under .gov carried more certainty of conveying official status than anything under .us.

Also sadly, QR Codes and URL shorteners today sort of obviate the need to directly register the shortest possible domain name. I don't know: I was always kind of fond of the .us hierarchy, and I'm just personally sad that it's fading away.


> city.state.us

In reality, it wasn't that simple, and a lot of those .us domains looked like line noise.

Government sites are used to distribute public information. They need something they can print on a poster/sign. Not some bogus 'logical' hierarchy.


City/state/US is logical, the problem is most other hierarchies confuse people. For instance k12 subdomains for schools couldn't use that nomenclature because school districts do not map cleanly to towns. And that's before you talk about fire departments, townships, libraries, park districts, and countless other governmental bodies and districts which have overlapping boundaries of their own.

.gov certainly cares a level of exclusionary access that isn't really true of .us. Only one entity, the US federal government, can decide to hand someone a .gov address. And generally there is few signals harder to fake or impersonate than one.


It’s not something anyone else in the world seems to struggle with, where there are *.gov.uk, *.edu.au etc.

If anything the .gov, .mil and .edu being just American is confusing, as well plainly inappropriate (it feels like an American cultural imperialist thing to people from outside the US). It would have been much better if those had been retired decades ago and moved to under the .us TLD, so e.g. whatever.edu would become whatever.edu.us like every other country. Any existing domains on .gov, .mil, .edu etc. should only be allowed to exist as 301 redirects.


It's imperialist to own and control the thing you created?

If .gov had been an international TLD that was at some point available to everyone, or had been created by everyone, ok. But .gov was created as part of the work the US government did to build out the initial DNS structure. It probably wasn't even a given at the time that arpanet would be international in nature

Also, 301 redirects are not a DNS thing, that is an HTTP thing. Not sure how that would solve your problem since HTTP is intrinsically at the base of it tied to just A or AAAA records. DNS does a lot more than pointing to websites


It used to be that only Japanese corporations could register a .co.jp while anyone else anywhere could register for a .jp. So I had several .jp domains registered through Gandi.net.

The issue is that .jp registered outside of a few Japanese registrars are legally not allowed to offer Whois privacy.


Schools use it!

Based on my small sample of schools, all of the ones that were using locality based names under ca.us have migrated elsewhere, including to 2nd level domains under .us.

> Except nobody uses the .us tld

This is a bug, not a feature.


Sure, it is right now. What if they decide to sell it off?

Since neither smith.name nor the wildcard *.name appear in the Public Suffix List (https://publicsuffix.org/), browsers would likely allow any page on a *.smith.name domain to set cookies for .smith.name.

There was an effort to properly handle the .name 2LDs, but it was never resolved because there’s no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name: https://github.com/publicsuffix/list/issues/2306

So yes, this TLD’s setup is in fact pretty insane.


I think this says more about how the cookies security model is stupid. They should always have been scoped to the single, exact name they were set from and nothing else. Websites would have had to be designed a bit more thoughtfully.

It seems like it would be easily resolvable with TXT records these days. Anyone could try, say, on www.google.com to set a cookie for all of google.com, and the browser can fetch TXT records on google.com to see what, if any subdomains, it wants to allow this privilege for. Google could return a list or a wildcard; co.uk wouldn't allow any.

In a world without advertising, there's no reason why google.com couldn't also allow *.youtube.com to set cookies for it, but of course that would cause a tremendous privacy freakout. Though in practice they can and do just send every login/logout through a 302 redirect roundtrip to take care of the cookies on youtube.com.


Totally agree that a DNS based replacement to the suffix list would make sense. Especially with more secure forms of DNS like DoH or Dnssec.

That said I don't know about making cookies shareable across TLDs. That seems like allowing more privacy nightmares; at least today if you want to share you need complicated redirect dances that make you question if the user perf hit is worth it. I think there was some proposal for a mechanism for allowing non partitioned 3rd party cookies which seemed more sane to me, forget what the details were and if it ever made it beyond just a proposal.


It’s not nearly just cookies, and I think interpreting domain hierarchies as administrative structure generally does make sense.

Maybe it could be opt-in or opt-out via some markers at the DNS level, though? The public suffix list having to exist at all is bizarre.


An “administrative structure” seems fine, but the fact that a subdomain gets any sort of privilege over the parent has always seemed absurd to me.

Surely a better solution would involve an actual request. login.foo.com could send a request to foo.com with Origin: login.foo.com asking to set a cookie, and foo.com could make its own decision.


That might be reasonable today, but it's not really reasonable at the time the policies were formed.

If you require domain wide cookies be set from a webserver on the domain apex, the domain apex (for high volume destinations) needs to be set up for high volume webserving. High volume webserving often means at least geotargetted DNS, maybe a CDN, often anycast in today's reality.

Back in the day, it was common for high traffic domains to run their DNS with a normal DNS server and then delegate (typically via CNAME) high volume subdomains off to a 3rd party DNS server for geotargetting (usually Akamai DNS, but there were others). But you can't CNAME the apex domain away. You'd have to delegate the whole domain to your DNS provider and then you have no way to manage an outage of your fancy DNS provider. Especially if you go back to the days where NetworkSolutions did a single daily zone update for .com ... if you wanted to switch to a new DNS provider for your domain, you would submit the change request and hope it happened in the 24 hours, but sometimes you'd miss the window (or there would be some process error) and it would happen much later.

Less of a problem in today's world, where registries typically update the glue records in near real time (although many TLD servers have a 2 day TTL for glue, so you can't switch off a dead provider very quickly) and lots of domains seem comfortable with delegating the whole thing to their CDN.


that seems strange to me: why shouldn't policy leverage name resolution? sort of like dkim, but taken further. for instance, for site.com, I'd much rather retrieve its public key from DNS (some DNS++ version, of course).

There are use cases for cookies to affect multiple domains, like shared logins. Keep in mind multiple domains let's you run completely independent servers for different parts of your web presence but that doesn't mean that you want them to act independently.

That said the dumbest thing with cookies is not sending their attributes in the cookie header which makes it impossible to distinguish expected cookies from tampered cookies set by insecure subdomains. __Host prefix is basically a workaround for this but took more than a decade to get into browsers. Samesite similarly was bolted on after the fact.

Cookies aren't the only web security feature that follow sites instead of origins but they are the only one that was clearly designed without thinking through the consequences.


> no easy way to tell a reserved 2LD (open for 3LD registrations only) apart from a normal 2LD on .name

And that's one reason why the public-ness of a hierarchy level belongs on a DNS record on that level and not some separately-distributed side list.


I'm always mystified why we haven't leveraged DNS.

I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP.

Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...


No, we wouldn't, you're right. We'd just replace LetsEncrypt and the ISRG with the security track records and policy integrity of the major DNS providers, many of which are state-controlled, and the largest of which are too important to revoke.

Really hard to understand why that hasn't happened yet!


You can chose under which registry you can register your domain. You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name. And Web PKI revocation is a joke that many clients don't check at all and others do using privacy-hostile mechanisms.

But sure, keep spreading FUD like you always do on this topic.


For the last 2 years, I've tracked the Tranco Top 1000 sites, continuously checking DNS to see if any major sites have turned on DNSSEC (6% of the Top 100 do --- many of them government sites). Over those last 2 years, a total of 8 sites in the Tranco list have enabled it. It happens so rarely I could reasonably call them on the phone and share my misinformation about how moribund DNSSEC is to them directly.

https://dnssecmenot.fly.dev/

The PKI run by state-level actors isn't going to happen.


> You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name.

Are there any remaining CAs in browser root stores that don’t enforce CAA record validation?


You're talking about DAME (which email uses). It has it's own issues like not having transparency logs, and if a DNSSEC signing keyholder goes rogue, there is no easy way to revoke trust (unlike CRLs for Web PKI).

Web PKI also has not had transparency logs until fairly recently. And Web PKI revocation is a joke as well. At least a "rogue" DNSSEC signer can only sign domains they have been delegated authority over and not literally everything.

So, this kind of thing happens all the time, and there's the Public Suffix List for exactly this problem.

There would be no issue at all if Verisign, or maybe Global Name Registry, decided to stick to the 3rd level registrations exclusively. Problem is, the chucklefucks over there decided it was a good idea to also hand out 2nd level registrations. Those 2nd level registrations outnumber the 3rd level registrations by an order of magnitude, so the PSL decided to just let joe.smith.name and john.smith.name share cookies. Which, IMO, was not a good decision, but it is what it is.


Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.

> Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.

Yup. The original statement was dangerous FUD which should be urgently corrected.


Yes, but you have to admit that the existence of these SLDs (like co.uk) is always going to be a point of confusion for anyone with a basic knowledge of how the domain hierarchy _usually_ works.

Needing to be familiar with all the special cases (like the VERY special case of x.y.name which I previously knew nothing about) kind of ruins everything and introduces yet more security risk.


> but you have to admit that the existence of these SLDs (like co.uk)

I'm sorry, what ? Admit ? Confusion ?

In the case of .co.uk it has been around since 1996. HN is a technical forum, most people here should be well aware it is a serious SLD. I honestly can't believe it even needs clarifying.

Hell, if you use AWS Route 53 you'll see they use co.uk as one of their nameserver suffixes[1].

[1] https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/SO...


I'm not referring to the HN audience; I mean the larger evergreen cohort of people in the world who are still building their mental model of how the web works. They will each eventually be doomed to the same misconceptions because it's a system full of inconsistencies and special cases.

About 20 year ago I registered {lastname}.name and have dozens third level domains below it. So there are "privately owned" second level domains under .name for quite some time...

I'm working on same for my family since I want to properly degoogle a bit. One thing I think long term - if I give my kids first-name @ last name , that means that I forever hold power over their email. Which isn't great. But what's the alternative? Register one full domain name per kid? Even ignoring the cost, the ergonomics are awful.

Imho email is missing a feature for nameless email addresses for when somebody just buys their full name as a domain name. If I get "firstname-lastname.name", having the email be "firstname@firstname-lastname.name' kinda ruins it.


From what I can tell most people do something like me@myname.whatever or hi@domain.

A child born today sees email like we see the telegraph...

they'll grumpily sign up to gmail just so they can get a verification email, and that'll be all it gets used for. Messaging their irl friends will be done in apps like Discord.


Truth.

lol I ran a sizeable team around 2020 and I had to educate a couple of our new hires straight from college that they actually needed to check their work email, after they missed important HR related stuff and they had just completely not realized it was an avenue for company communication, with an assumption that everything was available on our heavily used slack.


tbh I'm with the zoomers on this one. Work email is 99% junk. Newsletters from every SaaS product we use, "A meeting started", invitations for calendar events that I can just accept ON the calendar, notifications for every transaction on every system ("X posted a comment on Y,") and spam from salespeople, recruiters, etc. And then 1% of it is actionable important stuff that I don't get through Slack.

Email died because of the junk/spam issue. And it's self-fulfilling - when most emails are junk, nobody sends a love-letter or party invitation by email because the recipient probably won't notice it, which in turn lowers the usefulness even further.

If email was a commercial product, the company would have done something about that. Email died because it was an open platform, with nobody to address this systematic issue.


They probably didn't realize why they needed multiple apps to communicate inside the company. I was in a situation where we had slack for communication between teams, email for corporate stuff similar you described, zoom for calls, personal messengers like WA for communicating with people in the company who didn't have slack, SMS/phone calls for alerts and various on-call staff. Total nonsense. No surprise I missed something.

Not to mention some of those kids may end up changing their names at some point if they get married and decide to take their partner’s last name.

Funnily I did exactly this, so the {lastname}.name is now legacy for me and nobody else of my family ever picked up the offer to have {firstname}@{lastname}.name adresses anyway. Later (but before my name change) I managed to secure {lastname}.de which I stupidly missed during the early internet due to being a stupid teenager with stupid convictions. If I had secured this back in the day I think they would happily started using it but now they are all too settled in their provider/free webmail addresses.

Nice twist: The father of my wife owned {newlastname}.de since the dawn of the internet. So I'm still fine on that front. ;)


Aside: I'm honestly bewildered that Google doesn't have the ability to handle that in gmail accounts. If somebody gets married or otherwise needs to change their name, their answer is "just make a new google account" when all your stuff is still tied to the old account.

They rolled this out in March this year in the US (and December last year in India).

I've successfully renamed an old account with an email address I no longer liked. It works quite well on everything 1st party, but does have the potential of causing issues with OAuth on poorly-coded websites that key on email instead of user ID (ie. most of them). You do get to keep your old email address though, so it still ends up working fine in practice.


Holy crap really? Yay! I know a couple of trans folks that will be ecstatic.

The feature is about fifteen years too late for me, unfortunately. By this point I need this feature to let me "merge Google accounts". But then I barely use Google anything anymore anyways.

Maybe there is a way to set up a legal entity for the domain that will guarantee continued shared control?

> It kind of seems like an insane TLD structure to begin with, right?

It's been around for years. I seem to remember this issue coming up around 2001 where originally .name was for third level registration (i.e. john.doe.name) and changed to second level it a few years later and caused some problems... https://publicsuffix.org/ talks about it in light of architectural limitations of domain names.

> can Joe set a cookie on all of .smith.name?

That can happen. I seem to remember ancient browsers made it so .name (and other non-generic TLDs) required three periods. I think country code domains and new generic TLDS caused the browsers to change it.

It's pretty screwed up, but a lot of the people with .name domains have had them for a very long time. Sad to see them all lose their identity online that way.


Surprisingly the public suffix list doesn't list `*.name`. So they're indeed not properly isolated from each other.

https://publicsuffix.org/

edit: apparently not all second level domains in .name are public suffixes anymore, so a wildcard addition wouldn't be correct.


It wouldn't surprise me if that is (maybe even a large) part of the reason for this change.

What does Verisign care though? It's been that way for way over a decade since they started allowing 2LD registrations. I very highly doubt they are suddenly so worried about random individuals' personal internet security.

It has to be a money problem. Something they want to do will be simpler if this is no longer a quirky registry. And they know they'll get the money back that they lose from not having bob.smith pay -- probably by throwing all the "last names" once registered this way into some "premium name" bucket and selling them for $1000 and up instead of the ~$10 that zyzgdhaf234.name fetches.

In fact, I'm not sure that scheme isn't the reason itself.


Fair. That would indeed be more in character.

Note that the posted link talks about .uk.co, which currently does not exist but I guess may have in the past. Where .co is the ccTLD of Colombia.

Different from .co.uk.


Originally there was uk.co.orgname.

Huh? I don’t follow.

They might be referring to this kind of thing:

> The first appearance of reversed DNS strings predated the Internet domain name standards. The UK Joint Academic Networking Team (JANET) used this order in its Name Registration Scheme, before the Internet domain name standard was established. For example, the name `uk.ac.bris.pys.as` was interpreted as a host named `as` within the UK (top level domain .uk)

from the History section of https://en.wikipedia.org/wiki/Reverse_domain_name_notation

But I don’t know if uk.co.somethingsomething did or did not exist at that time. Or if it was only introduced after the Internet domain name standards we use today existed and so was .co.uk from the beginning.


Oh, uk.co definitely existed for companies. The other 2nd-level domain (besides the academic uk.ac and uk.co) was uk.mod (Ministry of Defence), equivalent to the US .mil. And then, because life is never this simple, things appeared that were neither universities nor companies nor military, so uk.bl was given to the British Library. There might have been others as well, I don't remember.

Back then the code in various pieces of software had hand-written exceptions for domain processing. The joke was that all Computer Science departments in the UK (uk.ac.university-name.cs) ended up in Czechoslovakia.


.uk.co (mentioned in the blog) isn't .co.uk

Agree that the .name 3rd level domains are silly, disagree on .co.uk being a problem.

If .gov and .mil and .com make sense, then .gov.cc and .mil.cc and .com.cc make sense.

Of course, I think having more than one non-cc TLD was a mistake, but that's just me. If it makes sense to have topical TLDs for international and US institutions, it make sense to have national ones.


The 3rd level .name domains are the original ones. They didn't hand out 2nd level domains until three years after they started.

> disagree on .co.uk being a problem

Nominet and therefore .co.uk has been around since 1996.

.co.uk is not going anywhere, and neither is Nominet.

The only "problem" is the original poster did not do their homework. I suspect they were inferring `uk.co` which is a completely different kettle of fish. The original poster should urgently correct their post.


In the UK Nominet (the UK domain namr registrar - nic.uk) only permitted 3rd domains - co.uk. org.uk, me.uk. then there were "prove your status" ones such as ltd.uk, plc.uk and ac.uk plus ones like gov.uk, mod.uk, sch.uk, nhs.uk etc.

.uk was opened up relatively recently.


I own a .uk and it still feels weird not having something in-between.

.uk and .co.uk are both run by Nominet, the UK registry.

Quirky stuff like .co.uk / .org.uk / .sch.uk 2nd level domains partly come around from .uk being the worlds first CCTLD outside the US (and as other parts of this thread say, .us isn't that popular a CCTLD).

Everything was new and different people tried different hierarchy and structures to 2LD and 3LD's. .co.uk is also far from unique, I know this is common in many other places (UK/NZ/IN/ZA/KR/MX).

The UK now allows directy foo.uk registrations as well, but many people still have SLD's registered and will continue to do so.


It definitely makes sense for stuff like (non-US) gov domains. Have a federal agency control the `gov.<ccTLD>` domain and hand out subdomains to other agencies. See https://dachmarke.gov.de/ for example.

But I agree it makes no sense for public sales to the wider world such as `co.uk`. At least have the registrar be the govt company register and hand out subdomains to each registered company.


It wasn't obviously wrong in 2001. .pro started with a similar structure around the same time.

To me that sounds like reasonable structure. I hold that every single edu, gow and mil domains should be moved under respective ccTLDs. After this sort of move that doesn't seem unreasonable thing.

[flagged]


Ok, co.uk was perhaps a bad example, because it's owned by the same registry as the TLD, but perhaps there are other 2nd level TLDs where that is not the case. My point is both that it's hard to tell, and more broadly why would anyone want their domain to be tacked on to some 3rd level subscript anyway, when there's so many plain top level domains available. Surely most of us (present company excluded perhaps) do not feel so passionately about the reverence of `co.uk`

I don't have some nefarious desire to scare people away from the TLD of their choosing. Really I'm bringing it up to be like "why would you even, like, want some 3rd rate domain instead of getting a .com" so I don't think there's anything to correct


> so passionately about the reverence of `co.uk`

It's not reverence? I think that you're missing that it was a requirement. Basically every country (that followed ICANN's original rules) does this: .com.au, .co.nz, .co.jp, .com.mx, .co.ke (+ the org/net variants for each country)

The US is the only country where registering .com was allowed by ICANN (and not .com.us or something).

ICANN relaxed these rules in the 2010s I think, so now you can register 2LDs at most/all of those country TLDs.


Sovereignty? If you live in the UK, choosing a registry in the UK is a pretty good idea even if they only offered 3rd levels. You’ll have someone to contact and possibly sue locally. Your domain will be subject to UK law and standards, not those of a foreign registry.

> My point is both that it's hard to tell,

Its not hard to tell for things like ".uk" or other serious suffixes.

It only (maybe) becomes hard(er) to tell for all the vanity ccTLDs that came along in the 2000s. But even then 10 seconds on WHOIS and Google should fix any doubt.

> about the reverence of `co.uk`

What are you on about ? Lots of other countries do it too. Japan is one example given already here, but there are dozens. It is very common practice for country tlds.


geez, dude, someone woke up on the wrong side of the bed this morning...

> geez, dude, someone woke up on the wrong side of the bed this morning...

5 seconds on wikipedia or google would have stopped them spreading completely dangerous FUD about .co.uk.


What's so dangerous about it?

> What's so dangerous about it?

Implying lack of trust in `co.uk`

Implying `co.uk` may suffer the same fate at `.name`

Complete FUD.


You're absolutely right, when it's Nominet's actions that actually inspire a lack of trust in .co.uk, given they've been a bit of a hot mess since the early 2010's-ish.

;)

(Edit: although I should add that I'm hopeful that things have improved there over the last few years).


> given they've been a bit of a hot mess since the early 2010's-ish

No.

Oversimplified summary:

There was a period around 2010 when the management at the time wanted to follow a more commercial route with various unrelated "investments".

Nominet members made it impeccably clear in a very loud manner to management that it would not be tolerated.

Management insisted on a vote which they inevitably lost.

Management departed.

TL;DR Don't piss off Nominet members


Actually, the fact that you have to cite official registrar docs is exactly the problem. There are 200+ country TLDs, and by now probably thousands of other self-governed TLDs like .name.

For instance, in Serbia, there is a similar scheme to UK: .gov.rs, .co.rs, edu.rs, but also in.rs (for individuals) and top-level .rs. So someone has registered "iz.rs" and offers free subdomains to individuals.

The fact that there is implied hierarchical trust is what the problem is, and keeping track of individual rules for each TLD is prone to errors.


What the author describes here is hard because it's "simple."

What's simple because it's "hard" is replacing parts 2 & 3 with a network appliance like TrueNAS running a zfs pool that syncs to backblaze every night. Yeah you have to learn a bit but it won't fall in weird ways like the hard drive part here will just fail to mount one night and not back things up for 3 months until you notice. My 2¢


> like the hard drive part here will just fail to mount one night and not back things up for 3 months until you notice

I think the author is having trouble because he is conflating concepts and roles that should be distinct. Sync, rotating snapshots, and deduplicated backups need to be kept entirely separate if you want any hope of maintaining your sanity.

So he's got sync but he's missing some sort of rotating snapshot system which would solve the stated concern of guarding against syncthing replicating corrupted data. Such automated snapshots can then be used as the source to feed the backup pipeline.

That hard drive doesn't make a good backup because it seems that it is always online. You need an offline backup that you manually plug in to run the job once every so often.

He's also making this more difficult than it needs to be by insisting that the backup drive be compatible with windows. Plug the drives for both snapshots and backups into a linux box, format them with a modern filesystem, and get on with life.

Sync is its own clusterfuck and I have yet to arrive at a satisfactory solution myself despite wasting inordinate amounts of time on it. IMO you either go with a network share or you make due with the "least bad" option of syncthing. Personally I've more or less settled on sshfs at this point not because it's particularly good but because it works well enough and doesn't add any additional complexity.

Personally I use btrfs snapshots on all my devices, those get streamed across the network to a NAS, and the contents of the NAS are periodically (every few months) stuffed into borgbackup on redundant offline devices. Aside from sync the other problem you'll run into if you're a data hoarder is how to split backups across multiple drives once you exceed a few TB. Because external drives only get so large but the NAS will inevitably keep ballooning.


> Sync, rotating snapshots, and deduplicated backups need to be kept entirely separate if you want any hope of maintaining your sanity.

Not if you use git-annex.


Huh, I'd heard the name before but I hadn't realized how capable it was. Unfortunately when it comes to a data hoarder such as myself:

https://git-annex.branchable.com/scalability/

> Scaling to hundreds of thousands of files is not a problem, scaling beyond that and git will start to get slow.

So that's probably insufficient for me by at least a couple orders of magnitude. I'm able to maintain my sanity because snapshots simply capture device state, the NAS collects all snapshots while maintaining their independence, and (so far) borg has been sufficiently scalable to deduplicate any collection I've thrown at it.


Less hard these days. AI is a game changer for learning new technologies. It's like having a highly paid expert available to answer all your questions about your little USB backup. Makes learning how to use properly a new software trivial. And priceless when troubleshooting.

I agree I think one of the main things I learned from all this was that I should probably buy / set up a real NAS. I’ll look into zfs pool thanks for the comment!

Fair warning with ZFS: do not turn on deduplication at the moment.

There is a straight up data loss bug in 2.4.3 (zeroed out files, totally silent).

https://github.com/openzfs/zfs/issues/18366

This caused all sorts of grief at day job where dedupe was useful for a big cache. Conversely I've run ZFS at home for like 15 years at this point without trouble. But this one is an absolute nightmare.


I liked the post because it tells a true story about one of the remaining problems that are hard to solve well without a 3rd party.

Yes, who would have guessed that the <textarea> element, designed specifically for this use case and built into browsers for 3 decades, would be the most performant and behaviorally consistent way to implement editable text.

I'm kind of sad the author stopped shedding unneeded complexity there though... we're not really building a text editor yet, we're building a website with a fancy input field. If we want to build a proper text editor we must eschew the bloat that is the web browser too.


The browser-standards-or-bust moment has past, hasn't it?

If you want your app to work the same way across platforms, using browser defaults is not the way to achieve that.

If you want users to have a consistent experience within their browser across the web, I get it, but that's not how the Web has worked for a long long time.


So we take a web browser and trim it down to only ever show a single <textarea> element you say? That's what I'm taking away from this. All the hard work for accessibility is already done then right?

> So we take a web browser and trim it down to only ever show a single <textarea> element you say?

I was saying if the goal is "text editor," the web platform is the wrong foundation entirely


> Can someone explain what coordinated pacing is?

My charitable read is a legal cartel that allows the small club to switch to Marathon instead of Sprint mode, and drip feed us frontier models at inflated prices, while preventing open source and overseas labs from releasing models because they're unsafe (for the Blessèd Fews' profits).

My uncharitable read is somehow even less constructive..


> generated text being watermarked is universally good.

If it worked perfectly, maybe you could make this argument in a vacuum.

It does not work perfectly. (It cannot. It is by definition a heuristic). That means there will be false positives. There is a chance those false positives ruin someone's career. See [0] for just how easy it is to push SotA "AI text detectors" in one direction or another.

Now, with watermarks, instead of everyone to some extent understanding that AI text detectors are wishy washy woo, they are now Anthropic certified to detect an official AI watermark.

With that kind of false confidence in hand, the people who trust the "computer says you plagiarized" machine are never going to believe you when you say "it can make mistakes," they're just going to fire you/take away your scholarship/cancel your grant/...

This is all beside the fact that we should demand our tools work for us and not for some shadowy master. "Universally good," absolutely not.

[0]: https://freddiedeboer.substack.com/p/i-wouldnt-say-pangram-i...


Watermarking the outputs themselves is very different and much more effective compared to how tools like Pangram work.

Obviously false positives will inevitably happen (even though, they are incredibly unlikely with SynthID), but even still, that doesn’t somehow make good faith watermarking attempts bad.

Also, a watermark doesn’t stop your tool from working for you. It just stops you from passing of its work as yours.


Maybe it is distributing your private keys it read into your public repo as a way to exfiltrate data later? What does the watermark actually say? How much data is in there? So much for zero retention policies. Makes you wonder why Claude likes to be so wordy, especially in comments -- it must do so in order to watermark!

Also, this kills me! "It is harder to watermark factual answers because the model has fewer alternative word choices available without altering accuracy." Hilarious! So the models need to hallucinate more due to the EU AI Act.

I go the other way on images and video, though easy enough to strip as part of a pipeline.


> Also, a watermark doesn’t stop your tool from working for you. It just stops you from passing of its work as yours.

I think we fundamentally disagree on what "working for me" means, but I remain steadfast in saying we should not accept tools that have ulterior motives beyond producing the output desired of them by me, the user.

> Watermarking the outputs themselves is very different and much more effective compared to how tools like Pangram work.

At the end of the day the only artifact is text that you can do statistics on. It's the same problem as today, with the probability shifted slightly more in one direction. This does not assuage my concerns at all.

> they are incredibly unlikely with SynthID

I kept my commentary focused on text watermarking specifically because I agree, a synth ID image watermark false positive is highly improbable. There's plenty of noise to robustly hide whatever you like in an image. Text is simply too capital I Information-sparse and fragile.

> good faith watermarking attempts bad.

I would sooner call it "ignorant faith" (if they don't know what they are emboldening) or worse "don't care" faith (there will be false positives and they accept this to further some illustrious and arbitrary goal of Text Purity). Whether that be to prevent model collapse or help you not waste time arguing with bots online, to me the principled stance of "tools work for the user" wins..


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: