Hacker Newsnew | past | comments | ask | show | jobs | submit | Mystery-Machine's commentslogin

> they exclude EU visitors

GDPR is applicable on EU citizens, disregarding where they browse from. So either they have to track whether you're an EU citizen/EU visitor or they track EU visitors when browsing from outside of EU. This makes it not GDPR compliant.

The main issue is that your privacy policy is most likely not mentioning this third-party tracking because you were not even aware of it. Who is going to be responsible? Who is going to be fined for not mentioning this tracking in _your_ privacy policy? You. (Your company)


What a great article!

> Shipping them 20MB of javascript before we even render a form would be a ridiculous thing to do.

> I have seen teams waste person-months of effort wrangling React validation libraries.

> It is not acceptable to bounce users on old browsers, users with bad network connections, users using assistive technologies.

> Build a web application that works on a playstation portable on a 3G connection - if you do, it will work for all your users, and it will still work 30 years from now.

The other day I added a fix so that the website would work in a PS5. Before that I didn’t even know that PS5 has a browser.


I love it! A few questions that made me think: - how do you know that "people use it for all kinds of things"? I just read your privacy policy and I'm concerned about my AI agent possibly leaking some API key to Hutch and then you can read it. - how is this free? You're hosting on Vercel, one of the most expensive hosting providers. What happens when this goes semi-viral? How do I know you won't just pull the plug to cut costs or start charging $500/month? I don't want to sign up, invest my time, and then lose access. - I signed up and now I can't access privacy policy nor terms of service pages, because when I go to https://hutchdb.com/ I get redirected to https://hutchdb.com/dashboard


This is all very fair criticisms. This thread asked: "What are tools you have made for yourself?" and that's genuinely what this is. I wanted it so I made it and then AI makes it so easy to just throw up a marketing page.

I've a a handful of dev friends that have started to use it as well and give their feedback and it's been slowly growing as I've added sharing/invites.

I would absolutely not recommend putting big production data into it currently.

My vision for it was something more like how the #1 use of spreadsheets is actually people making lists and not actually people doing lots of calculations.

Given the uptake today (thanks everybody!) and your feedback (thanks Mystery-Machine) I'm going to work at addressing your concerns.


You completely ignored every question related to costs/privacy.


I thought it was more implied, but let me be more explicit:

- This is something I made for myself without a lot of commercial thought, so I still haven't thought through pricing + usage + limits + operational limits. In it's current wildly unoptimized state it's still very cheap to run.

- For the specific concern about API Key leakage there's not a lot I can do about that (that I'm aware of) as the logic of what gets sent is handled by the client AI. It is possible to pull down and audit both the tools + instructions that are published by the MCP server if there are concerns on that side.


Please never do this again. It's insane that the 3.1GB download kicks off as soon as you open the page.


Censorship is not a solution. Instead, companies, whose messages are misleading, could pay a fine for their misleading message. Otherwise, you end up in 1984...sorry, I mistyped "UK in 2026".


No.

You avoid having companies, who can swallow the bill, making whatever claims they like without having to much to worry about other than a slap on the wrist - Their claims are already out. J&J, P&G, Unilever et al - you may trust them to do the right thing, i don't.


That’s a solved problem, though? Just adjust the fine based on the company’s revenue


It's only "solved" if the solution is actually happening.


> J&J, P&G, Unilever et al - you may trust them to do the right thing, i don't.

Would the UK government actually stop any of these advertisers? It seems more likely they would stop people critcising the UK government.


I'd be cool fining Meta 1% of global revenue for every fraudulent ad on their platform.


Ditto for Alphabet with scammy and malicious Youtube ads.


A fine doesn’t undo a lie that’s already made it around the world.

Although given Brexit I’d question how useful the ASA actually is. It seems Russian funded politicians were free to spew endless lies at the average citizen with no repercussions.


Then, make them pay for an ad apology where they retract their previous one, and which runs for at least the same time.


That's literally censorship though. If you get fined for saying a thing, you are being censored.


Quoting Wikipedia[1] quoting the US Supreme Court,

The thread running through all these cases is that prior restraints on speech and publication are the most serious and the least tolerable infringement on First Amendment rights. A criminal penalty or a judgment in a defamation case is subject to the whole panoply of protections afforded by deferring the impact of the judgment until all avenues of appellate review have been exhausted. Only after judgment has become final, correct or otherwise, does the law's sanction become fully operative.

A prior restraint, by contrast and by definition, has an immediate and irreversible sanction. If it can be said that a threat of criminal or civil sanctions after publication "chills" speech, prior restraint "freezes" it at least for the time.

[1] https://en.wikipedia.org/wiki/Prior_restraint#Judicial_view


Go to a theatre and start shouting "fire"

Free speech isn't about saying whatever you want without consequence.

And this is a bloody ad on the TV.


You can shout fire in a theater all you want.

What you can't do is shout it in a way that makes people believe there is legitimate danger AND your actions cause subsequent panic.

The crime isn't so much about the speech as it is about the damage that that speech causes.

It's a subtle distinction, but an important one.


And can we agree that there are lies that companies tell on adverts that can cause damage?

Carlsbergs tag line is still "probably the best beer in the world" despite it probably being not.

So the comparison works.


  > And can we agree that there are lies that companies tell on adverts that can cause damage?
Yes, and very often those companies get sued. I'll agree no often enough. But I'll also note that the outrage leading up to the lawsuit is far more visible than the results of that legal action. I'll also agree that that legal action is often too slow.

  > Carlsbergs tag line is still "probably the best beer in the world" despite it probably being not.
The lie has to be believable and cause damage. Was the unclear from my comment?

Even if they remove "probably" they could still get away with it because it isn't going to be believable and I doubt you could show damage. Just in the same way so many cafes have "Best coffee in X" and how frequently you see mugs like "Best Dad in the world." No one is getting sued over those because they aren't believable. I agree they're deceptive and in bad taste, but I think if you take some time to sit down and think about it you'll realize that to make statements like those illegal you're going to have a lot of unintended consequences.


I said you can't say whatever you want without consequence. Giving the example of shouting fire.

You responded pointing out it has to be believable, ie real harm done.

I brought it back full circle showing that adverts can 'lie' if it isn't believable.

I am pointing out you are reinforcing my original point, not detracting from it.


Oh okay that's the misunderstanding. I thought you were trying to rebut my comment. My bad.


You can even charge once a week or even less, depends on the usage.

You also don't have a gas station inside your apartment. Depending on which car you get, you could go charge it to charging station. I'm not saying this is instant process.


I'd love to hear more about this kind of attack being exploited in the wild. I understand it's theoretically possible, but...good luck! :)

You're guessing a cipher key by guessing typed characters with the only information being number of packets sent and the time they were sent at. Good luck. :)


THANK YOU!

I'm baffled about this "security feature". Besides from this only being relevant to timing keystrokes during the SSH session, not while typing the SSH password, I really don't understand how can someone eavesdrop on this? They'd have to have access to the client or server shell (root?) in order to be able to get the keystrokes typing speed. I've also never heard of keystroke typing speed hacking/guessing keystrokes. The odds are very low IMO to get that right.

I'd be much more scared of someone literally watching me type on my computer, where you can see/record the keys being pressed.


Anyone who can spy on the network between the client and server can see the timing. This includes basically anyone on the same LAN as you, anyone who sets up a WiFi access point with a SSID you auto-connect to, anyone at your ISP or VPN provider, the NSA and god knows who else.

And the timing is still sensitive. [1] does suggest that it can be used to significantly narrow the possible passwords you have, which could lead to a compromise. Not only that, but timing can be sensitive in other ways --- it can lead to de-anonymization by correlating with other events, it can lead to profiling of what kind of activity you are doing over ssh.

So this does solve a potentially sensitive issue, it's just nuanced and not a complete security break.

[1] https://people.eecs.berkeley.edu/~daw/papers/ssh-use01.pdf


> For me personally, I have decided I will never be an Anthropic customer, because I refuse to do business with a company that takes its customers for granted.

Archaeologist.dev Made a Big Mistake

If guided by this morality column, Archaeologist should immediately stop using pretty-much anything they are using in their life. There's no company today that doesn't have their hands dirty. The life is a dance between choosing the least bad option, not radically cutting off any sight of "bad".


> How much better would this library be if an expert team hand crafted it over the course of several months?

It's an interesting assumption that an expert team would build a better library. I'd change this question to: would an expert team build this library better?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: