Hacker Newsnew | past | comments | ask | show | jobs | submit | mike_d's commentslogin

Celestial navigation requires an accurate clock and an almanac that needs to be updated. It is completely impractical for non-military applications.


Is that really that impractical?

With a quick calculation 50 ms time offset would mean about 20 meter difference. You can get that accuracy with NTP over residential internet and a better TCXO could hold that for a day. You could sync clocks and download the almanac at each airport. The almanac could be digitally signed and NTP has an option for authentication, too. That's about 10 USD of hardware (plus what you need for image capture and processing).

I'm pretty sure with dedicated hardware and better solutions you could get much better accuracy.


They did it in the 60s for the B2 bomber[0]. I think computers are slightly faster and more reliable today, so it at least seems plausible.

[0] https://www.righto.com/2026/04/B-52-star-tracker-angle-compu...


Does the almanac need updating? I regularly use plate solving with my telescope and I've never had to update it's stars database


I'm not sure how it played out in 2011, but as of now it looks like the win condition hinges on the redirect.

For the heck of it I confirmed "http://www.longbets.org/601" does in fact result in a 301 redirect to "https://longbets.org/601/". I suspected they might have used a 302.


At any large employer you sign an agreement to follow the employee handbook and internal policies. They all say the same thing: don't violate the policies even if directed to by your manager.

In this case Apple's legal department had identified the serials and IMEIs as PII.

This is why the case is in civil court and not criminal (because Apple didn't violate any "laws" as you claim). It is a contract dispute.


Boardman notified Apple’s legal team. At that point it was their decision to make. If they had told him to stop, that’d be one thing. But they didn’t, and it wasn’t up to Boardman to interpret the policy differently.


The employee didn’t have a contract with Apple so it isn’t a contract dispute. These would be statutory causes of action (also civil, but different than contract law) based on the claims in the suit. The plaintiff alleges Apple broke the law, but specifically whistleblower retaliation and disability discrimination statutes, not consumer privacy laws (which is sort of a secondary concern to the whistleblower claim, since those protections can apply even if no law was actually broken).


There should be safety testing, but no guardrails that limit models for cyber or bio research.

Guardrails are not a safety measure, they are a pay-to-play scheme that allows the people with deep pockets to have access to offensive and defensive capabilities first.


> US installed a dictator in Iran because UK was angry that Iran nationalized the UK owned oil fields.

> Did i say anything that was untrue? Or do people not like the truth?

It is widely assumed, but not factually correct, that the US was responsible.

On August 15th 1953 the CIA staged a coup to overthrow the government, but it failed. By the next day the State Department was actively trying to enter into diplomatic talks.

Three days later a group of clerics headed by Ayatollah Borujerdi took advantage of the situation and stirred up unrest that was ultimately responsible for the Shah taking power. They had been concerned about Mossadeq embracing secular liberalism and a referendum that dissolved the Majlis (parliament/congress). MI-6 had offered them support, but they rejected it.

I would highly recommend this book if you can get a copy: https://www.amazon.com/Iran-CIA-Fall-Mosaddeq-Revisited/dp/0...


> On 19 August 1953, Prime Minister of Iran Mohammad Mosaddegh was overthrown in a coup d'état that strengthened the rule of Mohammad Reza Pahlavi, the Shah of Iran. It was instigated by the United Kingdom (MI6), under the name Operation Boot[5][6][7][8] and the United States (CIA), under the name TP-AJAX Project[9] or Operation Ajax. A key motive was to protect British oil interests in Iran after Mosaddegh nationalized the country's oil industry

Straight from Wikipedia


That was the understanding until the CIA released a bunch of documents in 2017 which revealed that it was such an abysmal failure that they almost called off the entire thing.

The attempted coup brought out a lot of pro Mossadeq protestors. It wasn't until the 19th when clerics organized anti Mossadeq protestors that it took hold.

Might be worth flagging to Wikipedia editors for a review.


Idk which is correct, but I really wouldn't take Wikipedia at face value for this kind of topic. Would dig into the sources if I were more interested.


Even if we take these claims at face value, think about how this looks from the Iranian side:

- Failed coup attempt threatens government

- 'Ooops sorry just pranking you lol'

- Distracted government challenged by internal actor

- Power vacuum followed by monarchy

I'm sorry, this is like disclaiming responsibility for shooting at you on the grounds that most of my bullets missed and the one that hit just winged you. It's not my fault that your grumpy neighbor exploited the situation to attack you and then a third actor exploited the situation to seize all your assets!


> To the best of my knowledge, a domain can only be renewed in advance for up to 10 years.

That is the rule for COM/NET/ORG. ccTLDs can do what they please.

That said, as a registrar I highly recommend people renew important domains for 9 years. It gives you maximum buffer but allows you to transfer to a new registrar even if your old or new one has the same misconception hard coded.


What domain zone let you register for more than 10 years?


None do at present, AFAIK. But ccTLD could do that, if they wanted to; there is no rule against it, unlike the gTLDs.


That's weird there no such zones then. It would be nice to be able to pay for a domain 50 years in advance.


It’s an accounting issue. It is also why all coupons, gift cards, etc. expire. When you buy a domain, or get a coupon, the company basically has to treat that as a debt that the company owes you, and this has to go on the books as a kind of liability. No company want too much of that.


The DNS isn't 50 years old. There's absolutely no certainty your payment for the last year's will mean anything. Also if you're older than 35, you'll probably be dead. If you're not dead you probably won't care about the domain any more. Certainly all current politicians and the current political and economic systems will be dead. It's unclear there will be any reason to still have the domain and that it won't be blocking some innovative economic activity. It's unclear there will still be an internet.


It won't protect you against the country hosting the registry being nuked but it will likely shield you from future price hikes because not honoring pas renewals would quickly get the registry a reputation for being a fraud. Which is probably also why there is a limit - no registry wants to be bound by arbitrary long timed liabilities.


It looks like the person you replied to deleted their comment, but I assume it was about GL-iNet being a Chinese company.

They have a tiny Hong Kong office that handles marketing as well as a US office for technical support, but the entirety of engineering and manufacturing is in Shenzhen and Chengdu.

Because they provide a hosted site-to-site VPN service they are obligated to hold a B13 license. One of the conditions of which is the ability for the Chinese government to request access to devices worldwide.


I bought one of their travel routers to play with and even though it's OpenWRT based, I consider it Chinese firmware because they add their own stuff on top of it. The fact that it's even possible that it can be enrolled in their GoodCloud remote access....no thanks. I consider it an untrusted device except when I have stock OpenWRT on it. I know it's paranoia but companies like that marketing to the tech crowd/devs especially now with their KVM's just seems slightly fishy.


That is interesting (and I recommend you flash stock openwrt instead, I did on mine). But no, the parent comment I replied to claimed Israeli / IDF connections.


Because a modern wifi router requires a minimum of 6 antennas. 9 is even better.

This lends itself to a spider like design with just a ton of antennas sticking out of a box, or a trash can with the antennas hidden inside around the outside edge.

Do you have other ideas for how to lay it out?



The Mikrotik HAP have terrible coverage, and the other two are the hallmark trashcan design I mentioned.


My radio knowledge is not up to par, but couldn't a phased array antenna setup allow for friendlier form factors?


But usually it is a phased-array setup, or it seems to be, with a row of antennas.

Another setup is circular or semicircular. I suppose it allows for a more uniform directional diagram across the entire 360°, because a straight phased array has harder time emitting sideways.


> It would only be a backdoor if it's implemented as a backdoor.

You don't seem to know how backdoors work.

Oppressive regimes mandate that tech companies pre-install apps to protect people from spam calls, or install specific root certificates so they can intercept your traffic and insert a helpful banner into your browsing session to remind you when to pray.

The EU isn't going to ask Apple to add DataCollectionBackdoor(). They are going to demand that in the spirit of freedom and happiness EU companies must have access to Apple users private data.


Your example completely ignores the temporal dimension.

The best practice was to rotate your passwords, but we discovered that this led users to picking less secure and easier to remember passwords and patterns.

Once technology offered up solutions to problems like password managers and breach notifications, that recommendation changed.

PCI used to mandate password changes for in-scope accounts (meaning they have access to credit card flows). Now that MFA is widely deployed that requirement only remains for accounts that do not have a second factor for authentication.

If you were ahead of the curve and implemented strong password policies that did not conform the the PCI baseline, all you had to do was explain to the auditor why. Assuming what you were doing genuinely increased your security posture it would be approved.


They specifically addressed the temporal element:

> They haven’t kept up.

Other standards all used to recommend password rotation. Most have amended it to deprecate or even prohibit password rotation.

> Once technology offered up solutions to problems like password managers and breach notifications, that recommendation changed

It wasn’t just that.

The original recommendation for password expiration failed to take into account the human practices that resulted.

Everyone has worked in an office with passwords on post-it notes, or seen passwords numbered with sequentially incremented integers at the end. Password rotation isn’t merely a baseline level of assurance, it has a negative impact on security because of the effect it has on password hygiene. In practice, passwords that expire can be easily guessed by appending something to the end of the prior password. And they are more likely to be written down in plaintext.

Permanent, non-expiring passwords without MFA are stronger in practice than expiring passwords.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: