We need to remember how to operate without the Internet, and de-risk our dependence on it. Whether that's reducing the use of computers in our daily lives, or getting more open-source-software-runs-offline-on-my-machine.
We did it before. We forgot at the time when things were more-or-less free.
(I don't know how we do this. I'm as dependent as ever.)
I don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd.
This isn't only a digital sovereignty issue, it's also an anti-competition issue.
This is the correct intuition. The problem can be solved with antitrust by forcing hardware vendors to ship their devices without an operating system. Then the market will deliver the parenting solutions that don't require mass surveillance. We're currently being blocked from doing so by anti-competitive measures.
They already regulate the amount of rain water you can collect, or how much water you can take from your own well, or how many solar panels you're allowed to use
You feel bad because it touches your own personal toy, but if you zoom out you'll discover the vast majority of it was already fucked up
The reality of the matter is that it is virtually impossible for Europe to even begin to displace Apple or Google devices, and especially not operating systems and all the ecosystem that goes along with it.
The EU politicians are just publicly paying lip-service to "digital sovereignty" while they quietly hope this all just blows over when Trump is gone in 2 years.
> it is virtually impossible for Europe to even begin to displace Apple or Google devices
It's hard for sure but they are not even trying, the non-duopoly alternatives are run by hobbyists in their free time and just get shit on by EU bureaucrats
What do you expect - the EU to centrally plan a phone OS? They are capitalist with regulations, you know, not communist. Someone has to actually make one themselves.
Most of the free hardware and software alternatives are already European, like MNT, and GrapheneOS. They just don't have market share.
Now that would be pretty good. I thought there was already an unlockable bootloader mandate but it seems I was mistaken. Most phone makers openly violate GPL and don't get punished, too.
Agreed, I doubt that a mega-behemoth like Google or Microsoft could emerge in Europe. Especially not on a compressed timescale.
But if they really wanted digital verification without the surveillance capitalism built in, I’m sure there are plenty of companies that could do it. Especially if it was around an open source framework.
Anti-corruption regulators are paid to look away. If they start investigating corruption like e.g. Ukraine does, then the EU countries will be perceived as corrupt. The goal of these institutions is to keep things under the rug so to speak.
That's why you barely see anything being done and yet everyone can see how corrupt things are.
My understanding is that you are not forced to use this. Sites in the EU that will be required to verify user age will be free to use any method they wish as long as they can show it is as effective as the app and it does not violate privacy laws.
Most analysts expect sites will offer multiple ways, for a variety of reasons.
Eventually when the full EU Digital Identity Wallet is available age checks can be done using that and the age-only app will go away. For the full wallet the rules explicitly require platforms to have fallback mechanisms for users who are not using the digital wallet.
And how, exactly, will one acquire this "full EU Digital Identity Wallet"? Will I be able to compile it from source and run it on a computing device of my own choosing?
There is no "effective" method without hardware remote attestation. If I control the system, I can just spoof whatever "verification" it is you're asking.
The whole point of hardware attestation is to put a cryptographic key in the computer that the users can't ever get at, then use that key to prove the computer booted a corporate owned operating system that's 100% aligned with government and capitalist surveillance and other cyberpunk dystopia nonsense.
Install a custom system that you control and they will say you have "tampered" with your device, and that transgression will get you ostracized from digital society.
This is what will happen, and if we let it happen might as well close down this site because everything the word hacker ever stood for will have been destroyed.
You can of course create an independent attestation database at any time and mandate its use - verifying that the custom OS you use fits minimum security requirements for digital ID use.
We use that approach in several other industries.
But.... that requires work beyond just complaining.
> You can of course create an independent attestation database at any time
Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices.
Come on now.
> minimum security requirements for digital ID use
Also known as "the user has no control over the device".
Because users who have control can simply spoof this silly "digital ID" and there's nothing anyone can do about it.
> We use that approach in several other industries.
Your industries include the user of the device in their threat models. They want the device secured against the user. Absolutely unacceptable.
> Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices.
That sounds mostly like copium just to motivate your complete inaction.
Again - independent, EU based, attestation database is completely possible to make and we're using similar approval processes across multiple industries to certify hardware - locally, here in EU.
But yea, if you think you'll be able to print passport at home and then go travel and demand that government recognizes that as an ID document, you're a bit optimistic.
> Why not tell us more about the requirements for hardware certification?
Err, it's actually pretty simple: the token/certificate representing your ID (or credit card, or anything really) cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM when issued. And it cannot be duplicated.
It's the same set of requirements that are put on credit card smart chips and biometric chips in EU IDs and Passports (which are essentially also TPMs).
But sure, it's a all an evil conspiracy against general purpose computing. And they're all out to get ya. Now smash that downvote for a vote against the evil establishment.
> cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM
So it must be secure against the user, as expected.
Preventing the user from "tampering" with the token means carving out a section of the machine and putting it out of his reach. You just created a government embassy on the user's machine. There's no telling what it will be abused for, and there's no escape.
> But sure, it's a all an evil conspiracy against general purpose computing.
You just advocated for putting an inescapable persisent cryptographic government ID on everybody's computers. This is the literal implementation of the surveillance state. Everything you do online, this token gets sent. It's the end of anonymity. Not even Tor gets around this.
> Having a physical card fallback here is a necessity and nothing in these proposals shows that the physical card ID is going away.
It doesn't have to go away. Once the capability is there, they can and probably will simply make it mandatory to even so much as get an internet connection from your ISP. No unbreakable ID chip? No internet for you.
The "fallback card" is exactly what added the necessary friction that prevented everything under the sun from demanding these sorts of verifications out of everybody alive.
It was somewhat tolerable when it was just a financial transaction. It's still highly problematic given that AML/KYC laws are just the financial arm of global warrantless mass surveillance, but at least it was contained to the financial domain and it was possible to avoid credit cards and use cash instead. Putting this stuff in every computer kicks it up into 1984 territory by allowing tracking of anyone posting wrongthink online.
>Err, it's actually pretty simple: the token/certificate representing your ID (or credit card, or anything really) cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM when issued. And it cannot be duplicated.
So you need a proprietary browser running on a proprietary OS (both userspace and the kernel) with proprietary TPM hardware. You just proved the point. No more Linux.
>But.... that requires work beyond just complaining.
So you have to build an entire parallel internet just because you want to use Linux? That's what your argument boils down to.
The people who are complaining on HN are not platform operators, the platform operators don't care at all. To them it's not even about whether it requires work, they literally don't care.
For the people who care, it's not a matter of work, because they don't operate the platform.
Websites will do the easiest, lowest friction, and most user-familiar thing possible to comply with the laws. And that is just Google or Apple device attestation.
I literally lol'd at the "Most analysts expect..." line.
Yea, most analysts didn't expect the cookie banner nightmare we're living in either.
To think you can get only the narrow outcomes you want with zero unintended consequences while building root-level infrastructure for 1984 just illustrates the laughable hubris of the authoritarian impulse.
I was horrified by the literal waterboarding scene in Shrek. Granted it was a year or two before the USA started trying to normalise that form of torture. I don’t know what was in the popular consciousness in the US at the time. But it’s very spooky.
Children’s fiction has always had a very dark side though.
Yeah, I think the “adult media disguised as kids media” has been a thing for a long time.
But I also think that a lot of teen and preteen media has very little functional distinction from adult media.
A lot of non-parents don’t realize that the difference between G and PG can be huge. Shrek sounds like it should be something for a 3 year old but it really isn’t. Even without the torture scene it’s immediacy really scary. You have to go with something a lot more gentle than that for young kids.
I think the torture scene is funny to an adult as a mockery of the zeitgeist if you decide to interpret it that way. After all, Farquad is intended to be a villain.
It's been dark since the Grimms, and likely long before!
I just rewatched it (link in sibling link). It's mocking Farquaad, but I think is clearly meant to be taken as slapstick. Implying that torture is no big deal.
Yeah and I guess there are two directions you can go with slapstick like that: “it’s minimizing torture in a disturbing way,” or “all slapstick comedy necessitates suspension of disbelief.”
There is no 'literal waterboarding scene' in the theatrically released Shrek. In the scene you've seen, unless you're deep into dubious fan-remakes, Gingy 'just' gets dipped in milk (mostly off-screen) by an executioner-style heavy, then Lord Farquaad taunts them with their torn-off legs, which suggests legs-first dipping, not the head-first submersion that is the entire point of waterboarding.
Still pretty bad (even though the gingerbread buttons were apparently spared), but... not literal, and not even figurative, waterboarding.
At the opening of the scene, the gingerbread man is being drowned in milk. You see from the shadow, and the voice, that he's having his head submerged in liquid. then Lord Farquaad says "enough! he's ready to talk". So that's simulated drowning as part of interrogation to get information.
Nit-picking about the exact _orientation_ of the victim, and therefore what type of simulated-drowning torture this constitutes, is somewhat missing the point I was trying to make! i.e. that torture is normalised to the point of being slapstick in a children's film.
You think they did math on this? No, all he did was have a tantrum where they got attention to themselves and patted themselves on the bat for doing something.
They didn't think through the ecological results of someone scraping off the destroyed concrete and pouring more.
I don't think these ideas are as toxic to the current political climate as you think they are. We're probably just a few short years away from the current generation of right-wing populists integrating ideas like "children are useless eaters that are your property to command, make them give back from all that you gave to them" and "work safety and environmental regulations are an emasculating evil, real men want to breathe poison and take risks" right into the core of their platforms.
Are we talking about the environmental impact? Or are we talking about the vandalism perpetrated by activists? Attention on the protestors is not necessarily attention on the protestors' cause.
I mostly see commenters quipping about how this will just mean the concert will have to be re poured, resulting in yet more emissions. The bulk of the comments are about the protestors, not the environmental impact of this data center.
It's literally a building that turns electricity into reasonably intelligent text and we're still here talking about environmental impacts. Is this where we're at with NIMBYism in the West now? Will there ever be popular support to build industrial production any more?
I think that's trying to see something that isn't there, just to try and make some sense out of things. The reality is much simpler - they are elected parlimentarians, same as any regional government, and they vote without much thought based on quick brief summary. System to protect the children? Sounds great, let's vote yes - anyone who doesn't is a pedo, right?
There’s a huge amount of stuff that the EU does that no one consented to, or had a realistic democratic avenue to influence.
I’m in the UK and very anti Brexit. But were we still in, I would have no idea how to influence what happens behind those closed doors at the European Commision.
Granted the current UK Labour/ Conservative pact on these issues show they’re completely out of control. But I still theoretically know how I could influence policy.
Theoretically, you vote for the Parliament, and they influence the Commission.
The Parliament and Courts keep the Commission in check, although their… misguided rule of majority is bound to allow some nonsense to pass. Especially since the Commission is, in my view, made up of people that do NOT want what the citizens do. You could argue they represent the majority of their specific countries, but even that is stretching things a bit given how many people actually vote.
So: the Parliament, the Courts (you can bring them issues), the European Citizens’ Initiative, and indirectly through your own country’s agencies (e.g. your local DPA).
It’s not that different from the high levels of indirection and bureaucracy in most democracies, I think. (Not that I’m defending the EU, there’s plenty to attack.)
> But I still theoretically know how I could influence policy.
I mean even in the EU there's theoretic ways to influence policy, it's just that the system is currently sabotaged and/or partly not strong enough to withstand politicians who want to actively work against it.
Not being for or against UK or Brexit, but I don't think this is a EU problem. These kinds of problems exist in all European democracies, at least this is what it feels like currently.
Infinite scroll evolved alongside algorithms that incentivise addictive content. So it’s “good” UX in that it’s effective for consuming addictive content…
When I’m trying to do something constructive, like search or browse, infinite scroll is IMHO disastrously bad. You can’t keep your place in the list, or jump ahead/back.
How does that differ from 'when asked to load more items, simply take the entire list (which may have changed) and remove the items already shown on previous pages'?
The fact that, in general, you don’t know what was on the previous pages, if anything. The user may just randomly decide to open page 3 without having visited the previous two pages. Or they clicked “next” after having page 2 open on their computer for several days and meanwhile they used your website on a different device.
If implementing this idea, it wouldn't just be page 3 any more, it would be page numbered 3 excluding IDs 75833,6857362,2737,...
Reddit page links include both the number of the first item on the page (only cosmetic) and the last item on the previous page (which actually determines what is displayed).
The challenge is to retain an ordering over the result set. How would infinite scroll behave any differently in this case? The changing results seems to be an orthogonal concern to pagination/infinite scroll.
Infinite scroll makes the problem much easier, even if it’s still a problem. The only action you need to support is loading more results, which you can do by loading all results and filtering out those already shown. With pagination, the user may say “give me page 3” and you have no idea what was on pages 1 and 2, if they were even loaded.
But the underlying table changed since. I'm not very familiar with these myself, but it seams to me that the best solution is to keep a session cursor for the user, and these are a lot simpler when you only ever move it forward.
It's slightly different but I don't see why there should be a notable difference in difficulty. You need to somehow represent what you saw so far and act based on that.
Is the client sending that info back to the server every time it requests more posts? You can do the same thing with pagination. Embed a list of post IDs into the next button.
There's potentially a difference if the server's sending repeat posts and you're doing client-side filtering of what to show next. But do any sites work that way?
(And of course these issues only exist when your list of results changes order. It the list merely grows then you can paginate with start=xxx)
IMO "pages of search results" is one of the problems where the closer you look, the more potential problems and inconsistencies you see until you realize it's a leaky abstraction, and sometimes it gets too leaky.
We want visitors to imagine that we just plopped a binder of sorted results down in front of them for their page-by-page perusal, but the suggests permanence and invariants we don't want to provide (because it's harder.) For example, the assurance that page 2 will always have the same items on it unless they "search again", and the last item on page 2 will not not duplicate itself on the top of page 3 as they page forward.
By way of contrast, imagine a system where a result-set was not just a UI metaphor, but real domain concept. Do a search, and you get a Result which is a limited-size listing generated at time X for user Y and will be cached for Z.
You can implement pagination exactly the same way. It's a UX decision that has nothing to do with underlying queries, although it typically maps.
The typical infinite scroll that I've seen implemented does not work the way you describe though, it's just pagination without controls. The reason it works is because it's pushing content you never asked for anyway and it just keeps pushing. Without any sense of pages you'll never know the difference.
Just use really long pages and require them to hit next page after viewing 100 items, then start showing the next batch of feedslop. How is that changing anything?
Users know that they are scrolling endlessly, they just don’t care. Adding a “more” button every now and then isn’t going to change that.
Cursor based pagination only works if the items are sorted in strict chronological order. Otherwise, the problem remains. Consider the list
[A B C] D E F G H …
where the brackets represent the first page. If the user clicks the next page button (asking for the next page after C), but meanwhile the order changed, they get this:
A D C [B F E] G H …
Notice how they now see B twice and completely miss out on D. In constrast, infinite scroll will take the new infinite list and remove A B C, leaving D F E …
I guess the argument is that, while it's the same whether the user asks for "give me page 3" or "give me scrollbar Y coordinate 2160", the user is more likely to do the first or at least to care about the correctness of its result?
Why does the user need to see a page number? You could just show a “forward” and a “back” button. Keep records of what they’ve seen recently so you can replay prior pages. If they view too many pages just silently drop earlier pages; it’s a feed, not a perfect paginated list.
I mean sure, if you do it that way. But its easy to encode the page starting index and pagenate from there. Its even exactly the same algorithm as infinite scroll.
That second style will never change (unless you insert entries into the past). The first style will change. But it hardly makes it impossible to keep your place in the list; if you come back three years later, you'll find that that link goes to a random location, but if you come back next week, that link is going to go to a place that is very close to the place you left off, requiring minimal adjustment to find your place again.
Ah yes, let me just look at Instagram for the ideal model of infinite scroll UX. You can't even scroll up to something you've actually subscribed to that you didn't mean to scroll past without it tossing it into the memory hole and replacing it with something you don't care about.
Did you think HN has an unusable and bad interface? It seems to be a remarkably popular website despite having hard pages that change order on every refresh.
While that's true I think that once the feed has been observed in a certain way the advantages of stability outweigh the advantages of showing a tweaked version the second time it is loaded.
if i refresh the page it should be almost the same. maybe a couple new things at the very top, but i should still be able to find the thing i was just looking at.
by comparison, facebook auto-reloads while you're halfway down a page, and wont show you any of the same things. its an incredibly poor experience
I get frustrated by this so much, because sometimes I come across a post with a video or something I want to see, but I leave it for a few minutes to take care of something, and then when I come back it auto reloads and I can't find it anymore, the back button won't work, scrolling through the timeline is futile, it's just gone.
Maybe re-read the thread? A real-time conversation is not infinite content, it’s chronological and it ends when there are no more new or old messages. You shouldn’t use pagination, and I don’t expect this law or any similar law to enforce pagination on real-time conversations.
We did it before. We forgot at the time when things were more-or-less free.
(I don't know how we do this. I'm as dependent as ever.)
reply