Hacker Newsnew | past | comments | ask | show | jobs | submit | a2128's commentslogin

Don't be too alarmed by that notice, I use it daily on Wayland without any resulting issues as far as I can tell

As someone who, at a point, would copy homework from someone else, copy book reports from online, and use the answer sheets to complete assignments, I can tell you this strategy is long known to accumulate and not prevent cognitive debt


> would copy homework from someone else

I was pretty good at it - mostly remembered to change the name at the top of the paper too.

Struggled at moderated exams; think it must have been the time pressure or something.


> I can tell you this strategy is long known to accumulate and not prevent cognitive debt

When you say "long known" it sounds like this is established science. Is there a link you can share?


If you do it mindlessly, I'm sure you are right. But one could try to understand and integrate each piece of code as they "copy" it over. May be hard to sustain though.


u sure?


How so?


It seems to me a lot of Google lately is to block things they don't like using ways that only look like side effects.

The introduction of Manifest V3 API in Chrome for extensions, and disabling Manifest V2 for security reasons. It just so happened that ad blockers were made incompatible with the Manifest V3 API. It's a little blatant considering this came right around the time that YouTube began showing warning messages to users with ad blockers...

Requiring developers to verify their apps via Google Play Developer Console and blocking any unverified APK installations. This is done in such a way that it just so happens to squash F-Droid and most FOSS apps for most people, and blocks any serious competition to Google Play or any apps they don't like.

Of course, there's all this talk about preventing malware, but it is a fact that if you download any random ringtone or PDF app on Google Play it's going to come with probably 25 trackers and send your data to every jurisdiction in the world, and many apps even fail to declare any of this via Google Play data safety or privacy policy. Let's not forget that spyware is a form of malware. Take a look at the leaderboard :) https://reports.exodus-privacy.eu.org/en/reports/list/?filte...

In my opinion, this would probably be an indication that maybe Google controls too much technology and that they may need to be broken up to ensure fair competition. For Christ's sake they almost broke up Microsoft not that long ago for shipping a browser with their operating system, and now Google is blatantly controlling the operating system, the platform and app store, the ecosystem, the browser, the ad network, and abusing their power over it however they can.


I still can’t believe that an advertising company was able to effectively neuter ad/content blocking for 80% of the world under the guise of wholly invented safety issues.


They wouldn't have been able to if people didn't use a browser created by an advertising company.


uBlock origin and Brave shields work great. Never had a problem.


Roblox has a long history of not supporting Linux, and the game was rendered unplayable for many years. In 2022 it became possible following some Wine patches, but then they began to implement a kernel-level anticheat. Roblox initially committed to keeping Wine working but suddenly went back on that and blocked it without notice. Today, the last remaining way is through running the Android version of the game through an Android container or emulator. The TFA is about stopping this exact method of running the game though...


This isn't true. Roblox never had and does not have a kernel anti-cheat.


My mistake, I just assumed their Byfron anti-cheat is kernel level because that's the most common reason why anticheats take issue with Wine. If their anti-cheat operates entirely in usermode, then their decision to block Wine is even more baffling to me.


It is not kernel level, they use a number of pretty fancy user mode tricks to prevent people messing with the game.

They encrypt every page and register an exception handler that decrypts the page when a fault is reached to keep memory secure. They do cache timing checks to see if a page was recently in the working set outside of the expected control flow and will flag you if you fail the check too many times because it indicates tampering.


While the page decryption trick should work in Wine just fine (ZeroIT Lab Theia does that too, right?), I don’t remember if Wine provides workingset info like Windows.


Yes, Wine was (EDIT: partially) compatible with the Roblox anti-cheat, and there was a period in time where Roblox with its anti-cheat ran on Wine. Eventually, however, a decision was made to block Wine.

EDIT It looks like the Roblox anti-cheat devs themselves explained why Wine was blocked:

https://devforum.roblox.com/t/roblox-on-linux-everything-sum...


Yes, it does. Wine lets you register a VEH. They do other stuff to prevent Wine and virtual machines in general that I am not fully aware of.

Even then it's just a fancy party trick, you can suspend the process call the decryption function enumerating all the pages and take a full dump to get the binary

FYI; Theia is a very bad product. It absolutely tanks binary performance and does little to prevent a moderately competent engineer from cheating in your game.


Are the other Zero IT Lab products like their code virtualizer of similar quality to Theia? My only exposure has been that one RE//verse presentation and shitposts on UC.


I can't speak for all the products, but from what I have heard it's pretty bad. Pay close attention to the shitposts on UC, they regularly get taken down but have some interesting information in them.


I personally liked their Code virtualizer. And it's under active development. Sorry to hear about Theia, I haven't run into it yet.


Wine doesn't provide every userspace facility Windows does.


The TFA explains that it is up to game to decide if they want to use attestation.


In my opinion the whole "it's just a reference and national govs can decide" is a nonsense excuse to diffuse blame in a circle. The only outcome is that national governments will closely follow the reference and reuse the decision, the citizens of each country then have to manually complain to their own government individually, at which point they might get ignored because, well the reference implementation has it or talks about it, so they're just following the recommended security requirements, and who are you anyway to be demanding our system get less secure are you some kind of cybercriminal?

Play Integrity is still recommended to be evaluated in the documentation, with no mentions of its consequences. https://github.com/eu-digital-identity-wallet/av-app-android...


In the case of Roblox they have a horrible system where they estimate your age and only allow you to interact with people of a similar age, meaning if you verified your kid with your face then they'd only be able to interact with adults and not other kids. At least that's the theory. It doesn't take a lot of effort to figure out how a predator could misuse this system to their advantage (which is why I call it horrible)

Reference: https://en.help.roblox.com/hc/en-us/articles/39143693116052-...


Predators have been using roblox since its inception, but I don't think they are doing age verification because of that. They're looking to expand into more adult experiences and, of all horrible ideas, dating.


I think it is much simpler: they are feeling regulatory pressure. In various countries there are increasingly strict laws that allow people to hold companies accountable for issues on their platform. By using age verification, they can increasingly move responsibility away.


I’ve seen Roblox invest and conduct child safety research for several years now.

Maybe they are expanding into other industries, but the safety focus predates that.


    Sign in to confirm you’re not a bot
    This helps protect our community. Learn more
We need to protect the community by checks notes restricting access to useful informational videos...


Why should you have any right to look through everyone's private communications? Nobody really has any choice to reject your EULA if they want to stay in contact with someone on your service. I could force you to sign a ToS that includes "By using our service you owe us $10 million and agree to donate your kidney to our CEO" in order to reach your overseas grandma, but that doesn't mean it's actually enforceable or legal...


> Over time, Windows Lite becomes the main, and only, version of Windows. Development and maintenance costs fall, and somehow Microsoft makes more money than they ever did on an OS.

Looking from the outside, it doesn't seem that Microsoft treats Windows as an isolated product anymore with a balance sheet of sales versus development costs. Rather, it's an advertising billboard for their other money-making products like Edge, Copilot, Microsoft 365, OneDrive, and at some point Candy Crush of all things(?). In fact this isn't isolated to just Windows or Microsoft either. SwiftKey pushes you to use OneDrive, Google (search engine) famously pushed Google products and there were antitrust discussions about that. Advertising was just some annoying thing that was necessary to power free web services but now it's infiltrated the very core of our day-to-day technology. Until we can get proper antitrust enforcement, we'll only see technological stagnation get worse as more products become boring billboard monopolies with little incentives to get better.


Every console on the market right now is locked-down proprietary garbage, that's the basic reality. The PlayStation 5, the Xbox One, they are also technically x86 PCs as they run on x86 processors, but they are specifically locked down to prevent any use outside of their narrow use cases that are optimized to make them money. Valve is really the only company that's developing proper consoles with a custom operating system and custom AMD chips while not locking down the hardware, despite the strong incentives of locking people into paying them 30% forever and preventing access to competing game stores


to be fair, they subsidize the hardware costs. microsoft loses $100+ on each box they sell.


Sure and maybe Google also subsidizes the Pixel phones because they'll make up for it with Google Play transaction fees. But what if I don't want something that's arguably illegal price dumping, and would rather pay a bit extra to actually own my hardware and be able to run what I want, even after it's discontinued? We don't get such an option.

Quickly more and more companies are adopting the model of finding ways to trap the user into continuously paying them more money after the sale, then locking down hardware and software to ensure the customer is properly trapped, and maybe price cutting their competitors a bit. The death of mobile computing is actively happening right before our eyes as Google completes the trap by restricting users ability to install apks. Ultimately customers end up paying more and having a shittier experience as a result of this.

I think it needs to be applauded when a company refuses to engage with this model and simply lets you own what you bought and paid for, and brings this idea to a market that has long been infected with lockdownitis. (Unfortunately in this case the price is not "a little bit higher", but what can you do when component prices have become crazy...)


So put the price up by $100 and include $100 of non-transferable digital credits on the XBox account to spend on games.


That’s not how sticker shock works.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: