Hacker Newsnew | past | comments | ask | show | jobs | submit | wat10000's commentslogin

I don’t think it ever made sense. Code reuse improves efficiency when the code can be shared in memory, or when it needs to be updated and you only have to change it in one place. JS packages don’t give you sharing beyond what you’d get from copying the code. And these little things don’t need to be updated, and in fact you probably don’t want them to be.

It’s a case of doing something without understanding why it’s done. Packages are good, code sharing is good, so use it for everything. But it misses why they’re good.


This is all very easy to say in hindsight. It's missing the context of having been there, I think. Things were just different.

Also, way more fun.


I was definitely saying it at the time. But I wasn't embedded in the ecosystem, it was very much "those JavaScript guys are nuts, why would they do this?"

The question is, why should they care at all? Will this hurt their business?

Any breach of security on a system like this is a big flashing red-alert to me.

If it could lead an attacker to get ANY of their data... Persons, places, events, etc is pretty damning stuff to be exfiltrated.

Stalking/Domestic Violence, blackmail, timed robberies, you name it... That data shouldn't really be in anyone's hands in my opinion, but in anyone's hands (good guys / bad guys) it's pretty powerful.


Getting persistent access to Flock's internal network is a high-priority item for every US adversary, who doesn't want free intel collection on the movements of persons of interest? Knowing who the FBI and local cops are monitoring in is the counter-counter-intelligence cherry on top of a self-inflicted dragnet surveillance cake.

Any entity with access to flock servers can virtually stake-out anyone/everyone driving past Flock camera to monitor their movements. In a hot war, this would provide actionable data to support assassination via road-side bomb/drone strikes.


I mean... currently any cop can do that, and it's a lot easier to bribe a single cop than to break into flock network.

https://edition.cnn.com/2026/08/26/us/flock-kentucky-police-...

A single cop can do it 2000 times it seems before they get caught

And it's not a lone case: https://www.washingtonpost.com/technology/2026/08/02/how-pol...


.. with friends like these, who needs enemies

It's a red-alert to you and me, but Flock won't care. People already don't want these cameras in their cities, but police departments buy them anyway. What does it matter if there's one more reason you don't want them?

That's why you or I would care, but that doesn't answer the question of why they would.

Large companies tend to be amoral. Unless it affects them monetarily (possibly indirectly) they're not going to care. Given what they do to make money, I don't see any of these things hurting them.


Apparently police are accessing the network via their personal devices. I highly doubt their security practices online are any better than this. I wouldn't be surprised either to see things that chinese manufacturers do such as intentional back doors.

Overall this goes from disappointing to fairly repugnant.


Allegedly you can buy credentials on the darkweb to perform national searches. Might explain why some of the logged reasons for recent searches were “LMAO”

The normal explanation is plenty, unless you’ve never met, read about, or heard anyone talk about, law enforcement officers (who are human beings - for better and for worse).

How many of us have had coworkers who put something like that into a commit message? And that's a message that's at least notionally supposed to be helpful to you or your coworkers, rather than existing purely for the purposes of oversight you don't want in the first place.

I would expect law enforcement coworkers to understand the law, department procedure, and public requests for their data. That’s expecting too much from the academy, I guess.

Those that fail to meet standards should be fired to spare the taxpayers from the lawsuits coming from AI-assisted complainants.

It’s also too much for Flock’s YC-funded technology to implement a field filter that rejects “LMAO” as a valid request.

At the very least, your local staff’s nationwide stalking credentials being harvested by phishing and abused by others should carry criminal negligence penalties. Governments should pass that liability onto this YC-funded startup company.


It’s a federally protected right to skip over law enforcement officers candidates because they rank too high on an aptitude or IQ test.

Reasonable people would expect what you expect. We are not reasonable people.


This meme will not die, and here you can see it blossoming into something even weirder.

There is one (1) case in the literature, back in the early 2000s, where a department rejected a candidate as overqualified based on a cognitive assessment; the rejected applicant took that department to court and lost.

That's it; that's all the evidence.

Against that: most police departments around the country administer written tests with general cognitive components for which there is a floor score and no ceiling (the POST, the NTN, &c). And virtually no departments --- none I'm aware of --- administer IQ tests.

From all this, we've now got "a federally protected right"?


Yes, that’s how court / legal precedent works - for better and for worse.

Feel free to consult an attorney.

Edit: I thought the case went further up - but, “persuasive precedent” for other jurisdictions due all the same.

Edit2: since I’m seeing the username of someone with a decent clue,

> and no ceiling

was there one on paper for the hiring standards of the dept in the case in question?

Does that matter?, if there’s no legal issue with using it as a disqualifying factor? - for any candidate - whether or not they even score well?


Many moons ago, I was involved in the technical side of volunteer work for domestic violence victims escaping abusive relationships with e.g. law enforcement (cops), who even fifteen years ago had sweeping powers to track and stalk their victims. Things like actual anonymous burner phones and the ability to e.g. create new email accounts without government identification were critical to the process of getting these people out safely, or alive, without fear of retaliation.

I can't even imagine how difficult this job must be nowadays, with bullshit like Flock spanning hundreds of police departments participating in their nationally-linked database. I have zero sources for what I'm about to say, but my instinct is that the political machines (expanding powers hidden behind "think of the children") behind how technology is evolving today has gotten people killed.


Quite potentially, yes. Their name is already mud among many voters, if they're shown to be treating data insecurely then that's another reason why local governments might consider terminating contracts with them.

Feels like their purpose is to test the boundaries, take the hits, and eventually sell off

They want the good, bad and ugly to flock to them as it were and vaporize them so Axon and Motorola Solutions can just pick up right where they left off. And people will just ignore or forget it because it's not the same company.

Is there any recent example of a company getting breached and its data exfiltrated, where the business was actually hurt? I predict we'll get a standard boilerplate "We take security very seriously" press release, a narrative that blames the evil hackers entirely and not the company's negligence, and then that will be that.

Would the DNC in the last US national election count?

They could stick to taking payment in exchange for service like some weird old-fashioned business, but I guess that doesn't get the sort of growth that justifies a trillion-dollar valuation.

It has for Anthropic. Consumer vs enterprise though I guess.

Without the pesky training costs or stock compensation taken into account, yes.

Yeah, I can’t imagine why they’d be OK with voluntarily joining an international organization, but not be OK with being conquered and annexed by military force.

A roundabout can be as simple as a circle painted in the middle of an intersection, plus a bit of signage. It doesn’t have to be a big thing.

Isn’t this exactly how AlphaZero was trained? The rules are known and well defined so the training process can generate games without any outside data.

The only reason LLMs are this bad at chess is because the labs don’t care about chess performance so they’re not going out of their way to train the models for it. The ability they do have is from what chess information happens to be in the training data, plus whatever general reasoning abilities they may be able to apply.


I wonder how current models would fare. The ones they tested are fairly old now.

I see no problem with a rule that effectively says no company can exist if it holds such detailed records on millions of people.

Something much more targeted is appropriate there. Maybe we need a regulatory framework where people own their own data. Make it impractical, expensive and burdensome to hold personal data you don't absolutely need.

That has nothing to do with changing the whole approach to -- really undermining the whole idea of -- corporations. Limited liability is the only way they can work. It's a cornerstone of every developed economy.


Corporate officers can already be held individually liable for some things. This would just add another one, it wouldn’t be undermining the whole idea of corporations. If individuals can be held personally liable for their company’s failure to pay payroll taxes and corporations still manage to exist and do business, then I don’t see why this would be so different.

What situation do you have in mind when you say "...individuals can be held personally liable for their company’s failure to pay payroll taxes..."?

I’m not quite sure how to answer that. The situation I have in mind is the one described in the bit you quoted. A company doesn’t pay legally required payroll taxes, then depending on circumstances, corporate officers may be personally liable for them. See: https://www.irs.gov/irm/part5/irm_05-017-007

IRM 5.17.7 (https://www.irs.gov/irm/part5/irm_05-017-007), is about corporate officers who have a duty "...to account for, collect, and pay over..." taxes and failed to perform that duty.

I don't think this is at all similar to jsrozner's solution, which is to assign liability to "...every person who has ever worked for IDScan at any level of management...".

The IRM is describing officers with culpability as individuals whereas jsrozner is really proposing to do without any individuate consideration of wrongdoing at all.


That's too pessimistic. But it is a spectrum. You can't guarantee 100% success against 100% of potential attackers, but it still matters how easy it is to get into something. There's a pretty big difference between a Windows 95 machine hooked directly to the internet and something like a fully up-to-date iPhone. The iPhone is still hackable, but in practice it's so difficult that you're unlikely to be targeted unless you get the attention of a national government.

It also requires actually caring about security and putting effort into it. These data breaches are usually systems where little attention was paid to security in the first place, and e.g. getting ahold of one user's password is enough to lose the game. Getting companies to care about security is really hard, but it does happen.


Yes, we really went there. There's zero legitimate doubt. If nothing else, consider: the Soviets were locked in a massive propaganda war with the US over the respective countries' space achievements, with the Soviets spending vast resources to show that their ideology was superior by showing what they could achieve in space. They had no trouble tracking American activity in space. If the moon landings had been fake, wouldn't the Soviets have brought their receipts and utterly humiliated their rivals?

We haven't gone again since because there's not much point to it. The US spent an amount of money equivalent to about 10 Manhattan Projects to ultimately put a dozen people on the moon for a cumulative total of somewhat less than one person-month. There was no military utility to it, no commercial benefit, just some science and exploration. Once you've done that a few times, what's the impetus to continue?

The technology was so bleeding-edge that each mission required a huge amount of bespoke manufacturing that got thrown away after a single use, and massive teams of people to run everything, such that each individual mission still cost billions of inflation-adjusted dollars. The American public's stomach for spending such vast sums of money just didn't last. Imagine if you needed to build and throw away an entire Airbus A380 to reach the summit of Mt. Everest. Maybe it would have been summited a few times to show it could be done, but we probably wouldn't keep doing it.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: