Hacker Newsnew | past | comments | ask | show | jobs | submit | ixwt's commentslogin

If you had two dice, one with odds 1->11, and the other 2->12, and you made 1 beat 12, they would have even chances of winning then, right?

I have a 2% cash back credit card from my bank, with no monthly fee. It started as a 1% cash back card around a decade ago, and slowly crept up to 2%. It's a nation wide credit union that has certain requirements to join though.


Keys could be stored in something like TPM on Camera, and could sign the image. The key could then be verified from the camera itself to prove the authenticity of the image.

If we as a society deemed it necessary, the camera manufacturer could also provide a list of keys for devices they have manufactured. And an image/key could be provided, and the manufacturer could verify the authenticity that way.

The TPM signing could be tied into the sensor hardware itself, making it difficult, but not impossible, to sign arbitrary images with the TPM.


Some problems with this particular system:

If the TPM signs the original image taken by the camera, then even the slightest image processing on another device would invalidate the signature. Routine changes like cropping, scaling, converting between image formats / quality levels, or applying image filters would invalidate the signature.

An adversary can manipulate the date/time settings on the camera and forge evidence to frame someone. "This cryptographically signed photo, with timestamp, proves that you were here at this time!"

And camera sensors can get damaged and need replacement. But if replacement of the TPM-and-sensor chip is allowed, then you can just as well replace it with a sensor from another camera. In which case a signature from a specific TPM+sensor doesn't prove that a specific camera took the photo, at best it might be evidence that a specific camera model took the photo.

If the manufacturer will happily ship a replacement TPM+sensor for a specific camera, someone can fraudulently claim that their sensor is broken and be given a new TPM+sensor for the same camera. And there will now be multiple TPM+sensors in existence that have the same key. Since this module can be switched between cameras, there could be multiple cameras that signed a given picture.

To ship (identical) replacement TPMs, the manufacturer would also need to know the private keys of all the cameras, so the manufacturer could forge arbitrary signatures at will.

Finally maybe the manufacturer doesn't want to deal with the above problems and decides that repairing the camera's TPM is not allowed after all, or that only the manufacturer is allowed to repair a camera, but then they may be in violation of right-to-repair laws in several jurisdictions.


If I steal your camera while you're on vacation, do I then gain proof of ownership of your photos?

If I need to reset TPM, how do I reclaim photos I took previously?


The point of the key (as the for some reason dead comment points out), is not to prove who took the photo, but what device took the photo. Just as if someone stole a hardware token with a PGP key on could impersonate the owner. The key itself doesn't prove a person, just a device.

If a key was reset, a revocation of the original key could be issued, showing that the key was associated with the device for this particular time span. And then the new key registered.

This is ripe for abuse though, so resetting a TPM might not be accepted for this use case. I'm not certain in which case you'd want to reset a TPM for this use case though. Unless you took enough photos with the device to risk a birthday attack if you were using something like ECDSA.


Finally a legitimate use for NFTs. /s


Likely one of two reasons, probably both:

1. Tax write off.

2. Acquiring a competitor, and then closing them down is a way to decrease competiton.


People often want to share their seeds so that players can play the same game they did. If there was an interesting series of results for example, which gave you a good set of cards.

Minecraft does this too with world generation for example.


According to the video about this by Louis Rossman, there wasn't even string sniffing. No changes were made in the code, the client ID was hard coded in, and was untouched by the author.


All, no. But many, yeah. The Constitution and many of it's Amendments call out people or persons. The 14th Amendment even specifies what a citizen is, and in the next breath says persons cannot be denied due process by the States, not citizens.


I've been using YNAB 4 (aka YNAB Classic on Android) for some time. I got a new phone, and the phone app finally won't run on the new phone. YNAB 4 is also quite buggy on my Arch based setup (someone maintains a package on AUR using Wine). So I think it's finally time to move on, which I think I'm doing this year.

My only issue with Buckets is that the YNAB importer doesn't take into account that YNAB will take your overspending and take it from your next month's income. I have some bad habits that means I was really using YNAB as more of a financial tracker than an actually budget system. That's my own fault though. The envelope in question comes out to $-10k... That's all my own fault though. It just means I have to massage it into Bucket's system, or start a new budget.


I assume Buckets does that because YNAB no longer allows you to take from next month.


Bigger?! What more do you need?! There are also other things that are on the way as well.


Timed tests encourage wrote memorization and reflexive knowledge. They don't encourage what is reflective of the modern real world knowledge recollection. In almost all scenarios, you have a book to reference for knowledge, much less search engines (and now LLMs). Almost nothing is memorized today, in the work world. What you know, in my experience, comes from frequent usage. Your timespan to work on most things is on the order of days, not minutes or an hour.

Tests should be open book, open notes, and an extensive amount of time to do the test. The questions should be such that they demonstrate an understanding of the material, not just how well you can parrot back information.

Whilst I would love tests to be open internet, this lends itself to very easy cheating. The material being taught and what notes you take about it should be enough to answer any questions posed to you about the material. Especially those that demonstrate an understanding of the material.


Sort of. There are some things that a person entering a field is expected to know without needing to look them up, because if you don't know it you won't develop good intuition or be able to execute your work in a timely manner. Most of the stuff you learn in your freshman year is this type of thing, while the later years tend to have more open-book tests.

This is also the kind of thing that you check for in an interview - somebody who needs to look up how to write a for loop isn't going to get hired as a C programmer, and somebody who isn't familiar with Ohm's law will flunk their electronics interview. So there's a very pragmatic reason to make sure that students have the basics memorized.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: