Hacker Newsnew | past | comments | ask | show | jobs | submit | V__'s commentslogin

Fingers crossed it doesn't burn your house down when your out and about. At least put it somewhere outside.


I have plenty of fire alarms, both local and remote, and extinguishers of different types around, I'm not too worried :) But thanks for the concern kind stranger!


At least put it in a coffee cup or something like that!


YES!!

The other thing to do is discharge it, so it has little energy stored to maintain/enlarge a fire

A drone engineer I worked with would immediately put any suspect battery into a barrel of water for several days, then get them disposed of properly.

The risk really seems trivial, probably because of our extensive experience with ordinary alkaline and NiCad batteries with a very benign degradation pattern, but the risk with Li-Ion is no joke.

All your fire extinguishers will do you no good if it goes off while you are out of the house. Also, the fire extinguishers will only suppress the surrounding fire, and do nothing about the core Li-Ion fire itself.


It's trivial until they go, and then it is instant misery. I've done it on purpose just to see how bad it would be and even knowing it will happen it will still surprise you with how sudden, total and hot those things burn. You have < 2 seconds from first signs of ignition to all-out fire with the battery moving all over the place due to outgassing. It's a thing to behold.


How am I supposed to be able to observe it slowly swell more over time then? I think I might have overstated how big this battery is, or understated how small it is. It's fiiine :)


Your extinguisher will do absolutely nothing. Get rid of it. Soon. Better now.


The extinguisher is not for the battery itself silly, it's for when everything else around it is on fire :)


But if the fire continues after the extinguisher is done… what is covering that scenario?


Lol, literally none of those will meaningfully reduce or stop the damage if it happens.

Very applicable example for the thread!


A non-profit I help out sometimes, was affected, and I have to say the emails were not that clear. Because it's hard to figure out what is part of a license, the free tier etc. I let it lapse, because we migrated of Office, but apparently the license also applied to Intune.

Fine, so I bought licenses but apparently Microsoft deletes "some" of the data. All groups were still there, users and the device ids.. but not the devices themselves. I could see all devices associated to a user but couldn't recreate or restore them in device management. Thus, I had to re-enroll multiple devices. Will migrate off Intune in the future, since it's garbage but haven't found a good alternative for Android devices yet.


"protect your freedom" does a lot of work here..


> They also ate less overall,

I can't look it up right now, but calorie restriction also shows this correlation, so maybe it is not sugar at all.


I understand the sentiment, but think about the non-technical user. Every time I use my mothers or any elderlies phone there are a lot of screenshots in the gallery, because they accidentally click the combo. How many people get scammed using screen sharing? It isn't that unreasonable to prevent this vector just to be more safe, especially if the bank might be partially at fault if a scam happens.


People also take pictures of their government IDs (passports, drivers license, etc) and utility bills.

Should the phone identify those things and automatically blur out all of the sensitive information in those photos too?

I’d prefer if my phone did neither that nor told the apps that a screenshot was being taken nor allowing the apps to hide anything that was on screen when a screenshot is taken.

It’s my phone, I want to decide what I take photos and screenshots of.


> especially if the bank might be partially at fault if a scam happens

That's the crux.

Yes, it is unreasonable, because scams have proven to be just as effective at getting people to just read the details out over the phone line, and bank these days are not showing much sensitive information in the open anyways (my recent annoyance - someone thought it's a good idea to never show the full account number on screen, showing just first and last few digits, and an option to copy to clipboard...).

Meanwhile, those very apps tend to be ones people would most often want to screenshot for legitimate reasons - e.g. to communicate or make a record of specific transactions, accounts, their states, metadata, etc. None of which is copyable text in the app, and most of it isn't even properly exportable, so it's not like there's any other way.


Add a system setting to ON/OFF this feature. Add a recommendation to set this as ON in the "Security Checkup" section which all modern systems have as of lately, that pops-up a couple times a year for suggesting good defaults to the user.

Done.


This just reinforces the notion that apple is the one that actually owns the phone and they generously let you use it.

Just do a security alert pop up "You are screenshotting potentially sensitive information, are you sure you want to continue".


Unfortunately “are you sure?” checks simply don't work, too many people are trained to just click yes/OK to close the message and get back to what they were trying to do.


Well, it sounds like those people are just too stupid to own phones at all then.


And worst of all, it doesn't matter if you are one of those people or not, for some reason all software you get to use must be designed for the lowest common denominator.


To careless, not too stupid, at least in most cases.

The same can be said wrt people being too careless to have their car/bike/etc. Or powertools.

In any of those cases, just try take them away and see how that goes…


"are you sure" checks work if you force deliberate effort on the part of the user.

Imagine having to type "I want to get hacked" on a keyboard layout which randomizes with every character.


The number of times I've seen people blow though prompts which directly refer to the issue they are coming to me about... SMH


Trained by the many more prompts that are irrelevant in practice, and merely stand between a person and the task they're trying to accomplish.

It's not like computers give people a good reason to read the error popups. 90% of them these days are just "oops, computer pooped itself, a well trained army of monkeys is on its way to clean it up; try again later <tinyprint>0xbunchofbullshit-hexadecimal-uuids-for-vendor-telemetry</tinyprint> ;-)" anyway.

Most of the time, people are given only two options: give up on their task, or ignore the popup. No point in reading the message in such cases, it brings zero value.


I'd say the problem is that delete usually has a popup. Sure you don't really want to delete without any kind of confirmation, way too many people would click something on accident and if there's not a way to undo it (which has it's own issues), then a popup is a simple solution, but it does result in this unfortunate behavior.


Honestly, if I were to dig, then for my generation[0], I'd blame save and close popups more, but even more than that, flaky component-based software. At some point in the Windows 98/NT and then 2000/XP era, you'd often see software throwing "fatal errors" and then continuing to happily chug along, possibly with subtly broken features, and ready to throw more inconsequential "fatal errors" if you moved your mouse the wrong way.

Repeated exposure built immunity.

You get a scary error with incomprehensible details[1], maybe the app closes, so you open it again and continue until the next error happens; maybe it doesn't close, just keeps going - maybe partially broken, maybe not. Either way, text is incomprehensible, but dismissing the message lets you keep going, so you learn that. At some point you see the message, think "oh this again", and close it without thinking. Works 90% of the time, for the other 10% you have coping strategies like "press CTRL+S every 30 seconds", "use Save As instead of save", or "make a copy of the file at start of your work session" all committed to muscle memory.

The modals with two or more buttons were the annoying ones. Asking you to make a decision. Asking you to stop. Eventually you learned to press the right button for ones where it mattered, and go straight for [X] or "Cancel" for everything else. And it worked.

Then came the web, and that's a rant for another time, but suffice it to say, the advertisers successfully taught everyone that you should always click the "X" button on anything that pops up without reading it, way before web apps became a thing.

We've worked out some useful UX patterns since. Non-blocking notifications, side panes, undo, undo history (still annoyingly uncommon). I don't think there's a single solution to the problem, but I am sure of the underlying principle that should guide it:

Whatever you do, do not become an obstacle standing between the user and the thing they're trying to do.

--

[0] - Can't speak for the kids these days, who learned computers after Windows ME times, or just grew straight into mobile revolution and mostly skipped dealing with PCs.

[1] - That was bad, but we've since overcorrected in the opposite direction. Ideal is IMO enough information to give you a clue about internal and external causes and state of the program, even if you have no technical background, because people bent on doing a task and even minimally curious can use that to random-walk into a solution. Basically: something you can act on as a user if you really care to.


Well, then make it harder to accidentally make a screenshot. E.g. make the user confirm (and then memorize whatevr setting).


People also get scammed using accessibility services, so some banks deliberately make their app inaccessible unless you're running a whitelisted screen reader. If you are running a non-whitelisted screen reader...


Samsung has had this for about ten years now. Switch to the app switch view, hold the icon at the top and pin the app. If I remember correctly, on some versions this had to be enabled once in settings.


For anyone curious, it's the CLOUD act:

> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.

[1] https://en.wikipedia.org/wiki/CLOUD_Act


The point of control is Congress, until we stop electing corpratist politicians, we will continue to get bad legislation.


It doesn't matter if it's Congress. At the end of the day America's internal governance systems are America's problem. The rest of the world should not care if a certain branch is causing issues, and frankly, is starting to come to that conclusion.

It's unfortunate for us, but we very rarely isolate individual government systems for other nations.


It's weird how everyone focuses on that part of the CLOUD Act. The CLOUD Act actually did two things: (1) that, and (2) provided an expedited way for the US to enter into Mutual Legal Assistance Treaties (MLATs) with other countries.

It was the MLAT thing that the various civil liberties groups object to (I'll cover the problems with those down below). There was very little objection to the first part.

The first part was not controversial because pretty much every country has something equivalent (for reasons I'll cover below), as did the US except specifically in the case of data covered by the SCA due to poor drafting.

One of the big reasons for the SCA was created was the emerging "third party doctrine" meant that instead of having to get a warrant or subpoena against you to get your data they could simply subpoena it from any of your service providers that had it. The SCA made it so the third party doctrine subpoenas would not apply to stored communications.

There were still cases where the government would need to compel the service provider to turn over the data. They wanted something with the probable cause requirements of a warrant but the delivery method of a subpoena. (A subpoena asks someone who controls the data to turn a copy over. A warrant is for when the government wants to raid the data center and seize the data. Since that involves the government directly acting where the data is located it only applies to someplace where they have jurisdiction).

So they created a new thing, the SCA warrant. The called it a "warrant" because it had the probable cause requirements of a warrant, but neglected to add something saying that in other respects it functions like a subpoena. I'll call this a pseudo-warrant.

The SCA was not the first pseudo-warrant. That would be the warrants under the Wiretap Act of 1968. Territoriality questions did not arise under that because by its nature the data it sought copies of was always in the US.

With the SCA the data might not necessarily be in the US. Years later Microsoft argued that because it is a "warrant" it should have the territorial restrictions that normal warrants have. The CLOUD Act clarified that it was indeed supposed to be like a subpoena as far as territoriality goes.

There have been some more pseudo-warrants created since then, but their drafters learned from the SCA and made sure the original legislation was clear on just what they were.

The reason pretty much every country has something like that, going back well before online documents, is because not having such a thing leads to big problems. If anyone in the country could shield documents from subpoenas (or whatever the equivalent is called in that country) by merely storing them across a border every company with documents that it needs to keep but that might be incriminating later would get sent to a storage facility across a border as soon as they were no longer actively using them.

For example as soon as a car company in Detroit releases a new car all the documents where during development engineers brought up safety concerns which management decided to not address would be sent across the bridge to a storage facility in Canada.

With electronic documents it is even easier. You would not have to wait until you aren't actively using the documents to stick them outside the country. Just stick your file server across a border and make sure you only have copies in country when someone is actively reading or editing them.

And so pretty much everywhere subpoenas compel someone in the country who controls the documents to fetch them (or copies) and turn them over. The actual location of the documents is completely irrelevant.

The thing that was worrying about the CLOUD Act was the MLAT provisions. MLATs are treaties where the participating countries agree on law enforcement. They include things like sharing information and cooperating on investigations. Normally these are enacted just like any other treaty. The executive branch negotiates them and then the Senate votes on ratification.

The CLOUD Act adds an expedited process where the Attorney General and the Secretary of State can sign an MLAT. Congress is not involved. These agreements allow foreign law enforcement to make requests directly to US service providers instead of going through the diplomatic channels normal MLAT requests go through, and they allow them access to stored communications that the SCA would normally block.

There are some safeguards. The foreign government is not supposed to intentionally target US people who are in the US and are not not supposed to use the data they get to infringe freedom of expression. There's also a 180 day window before these executive MLATs take effect during which Congress can block them by passing a joint resolution to do so.

Civil rights groups and many others were not impressed with those safeguards.


Which wouldn't matter where the data is located, so I don't think that this is the reason Fastmail is doing it, because a savvy enough company would know that the problem is that the company is US based.


They're Australian


Australian companies are also subject to the USA Cloud Act. As is the UK, with Canada coming on board soon too.

Even the entire EU is in the process of negotiating the same agreement.

https://www.justice.gov/archives/opa/pr/united-states-and-ca...

https://www.justice.gov/archives/opa/pr/justice-department-a...


Your linked information doesn't indicate anywhere that Australia or any other foreign government is subject to US law. The latter states that negotiation with the EU on this topic was suspended in 2019.

Things have changed. With Chinese law in regards to data within Chinese jurisdiction a long-standing thing and an unfriendly American government potentially in power for an extended period, other countries are realizing the importance of data sovereignty.


https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...

> The latter states that negotiation with the EU on this topic was suspended in 2019.

Dated 2023:

> Justice Department and European Commission Announces Resumption of U.S. and EU Negotiations on Electronic Evidence in Criminal Investigations

The negotiations are still ongoing. Canada is further along than the EU.


That is plain wrong, and on top of that, the CLOUD act doesn't really solve anything because if the order to obtain data is legal for the US arm but illegal for the EU arm, releasing the data from say Ireland to the US would immediately lead to steep monetary and legal penalties for the EU arm.


It is not wrong...

You can read the text right here:

https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...

The same agreement is in place with the UK. Canada and EU are currently in the process of negotiating it.


That’s not going to help anyone.

The Five Eyes is an Anglosphere intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are party to the multilateral UKUSA Agreement, a treaty for joint cooperation in signals intelligence.

https://en.wikipedia.org/wiki/Five_Eyes


Even being stored in EU doesn't preclude your data from being targeted by signals intelligence. Which is different than requiring US based companies to provide non-US data to American government.

Does fastmail have a US presence? If no - then they're not bound at all by US jurisdiction.


Meanwhile, in realPolitik, they are Australian, they are subject to AU government pressure, and the AU government is deeply intertwined with and compliant to US government wishes, AUKUS, Pine Gap, Harold Holt Sub communications, Over the horizon radar on China, etc.

See: https://roncobb.net/img/cartoons/aus/k5092-on-Tucker_Box-cuu...


> Does fastmail have a US presence? If no - then they're not bound at all by US jurisdiction.

This hasn't been true for several years. All Australian companies (and UK companies) are under jurisdiction of the US Cloud Act. Just the same as American companies are.

https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...


No, it would be a different act in each country.

They didn't even manage to extradite Kim Dotcom for years.


Kim dotcom was extradited from New Zealand, not Australia. They're different places.


They're both Five Eyes


Sure, but the point was that the US doesn't even need to exercise their capabilities under the five eyes treaty. They have a separate Cloud act agreement with Australia already which is a more direct route to get what they want.


The question isn’t whether a service has a presence in the sense of employees or regional office, or headquarters.

The question is: do they office services to residents of said country / state.

If so they may well be subject to certain laws that, if broken, could result in penalties up to an including extradition of the responsible officers.


As an Australian, all I can say is stop being naive.


isn't there this five eyes thingy?


that's surveillance orgs agreeing to cooperate, but they're still just surveillance orgs, all they can do is surveil


This looks really close to what I need. I manage a few laptops for a non-profit. For now, it is all done by hand, since I haven't found a good solution for Linux and I will kill myself before using Windows and Intune again.

I would love to see configurations for Linux Mint's Cinnamon. Is there a way to execute custom scripts? How does the user mapping work exactly? Could I create a user in Authentik with a laptop-permission and this would map to a Linux user account?

Nonetheless, this is really great work so far, and if you keep it as nice and tidy as it currently looks, then you might make a nice niche for yourself. I can't wait to try it out.


Would ansible meet some or all of your needs?


That's what I thought as well, I manage a small (50-ish) fleet of Linux Desktops using Ansible. Not perfect, but good enough that it mostly gets the job done.


Unfortunately, only LDAP is currently supported. There is no implementation of Enterprise SSO like Oauth/SAML. It's planned for the future, but not in priority for now.

I have never tested Cinnamon, but it should work in theory, because it stores most of it's settings in dconf.

Custom scripts: deliberately not, so far. Once a management agent runs arbitrary scripts as root, it stops being a policy system and becomes remote-code-execution-as-a-service — the security review, the audit story, and the "what exactly is enforced on this machine?" It may be implemented in the future, but with a ENV variable/config property from the application configuration. The same goes for configuration management systems like Ansible.

Thank you for the interest! I'm interested in developing a community around the software.


Is there a reason you cannot use samba group policy objects, sssd or one of the other solutions out there?


The question now becomes: Will the AI bubble pop before we get sea datacenters?


To be fair, how is Google blocking you from downloading an app, a Wero problem though?


The publisher, in this case Postbank, decides what countries to allow installs from for an app. Google just enforces the policy the publisher sets.


Country availability is a policy set up by the app publisher, not a Google policy


Which is complete bullshit with the Euro having been specifically invented to be used across the EU.

I had a similar moment of stupidifiedment trying to park in Germany with a phone set to Dutch region. Euro in cash works everywhere Euros are accepted but apps on the freaking Internet? Nah, gotta restrict that to the publisher country only.


Switzerland is not part of the EU nor the Eurozone though. It's still a shortsighted stance of Postbank not to open the app to at least the DACH region, but that specific argument carries little weight.


I accidentally skipped that part :(


I mean, there's some reason for it as EU countries have different laws and regulations, but yes, it's a dumb choice on the publisher's part


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: