I think the long term solution to the privacy problem is going to be to switch to a vehicle marking system which can only be usefully used by law enforcement. Example, if instead of license plates you had a transponder that sends out encrypted metadata about the vehicle in a way that only law enforcement could decrypt it. Obviously there are still problems of abuse of law enforcement keys but it raises the bar significantly and it prevents private companies from building a business out of collecting the data.
You introduce a new problem, which is that eyewitness reports of crimes etc can’t identify the vehicles as easily, but that could be viewed as an acceptable loss. Or the problem could conceivably be solved with more technology if we can have dynamically changing license plates (which, again, require law enforcement keys to map back to a real identity for the vehicle).
The only other way I see is that we change laws so that a company like flock collecting this data and then offering it to the government is treated the same as if the government collected it itself. But now that the cat is out of that bag and there is big money behind it, I don’t really see it going back.
This is exactly why my reaction to this was “who has one box of cables? Doesn’t everyone have an array of 18 stackable bins of cables sorted by function and vaguely grouped by vintage?”
Don’t ever let anyone take away your wildly overengineered cable shrine.
> Hey HN! I wanted to see how far you can push modern JavaScript Proxies without all the heavy overhead of a traditional framework. The result is Mador: a tiny ~80-line reactive state tuple ([r, w]) that lets you make any DOM element reactive using a simple CSS selector, automated dependency tracking, and batched microtasks. No build steps required—just drop it in. I built this over the weekend just to experiment with clean, zero-dependency reactivity. Would love to hear your thoughts or see where you'd run into limits with something like this!
Unsure why this comment from the author was flagged/dead but it certainly doesn’t seem to run afoul of HN guidelines.
The interesting thing is that the "don't carry the data" scenario of wiping your phone and restoring it after you're across the border is not functionally different from the "just don't carry the keys across the border" scenario. I would be comfortable with a dd archive of my encrypted phone contents in an short-lived S3 bucket that I could restore with a simple passphrase-derived key, for example. It's hard for the law to recognize that they haven't achieved anything useful by forcing me to do that instead of just lose the key.
One thing this case makes me wonder is if the government would have a problem with someone walking across the border with a completely virgin phone. They must have wiped it, right? Would they try to prosecute? How could they possibly know the defendant in this case actually had anything on his phone before the duress code was entered?
It's immensely different. Leaps and bounds different. Why?
Well, once you have been told to unlock the device, you're already in a legally binding process. The phone is at this point evidence. It was not evidence before. It was not evidence a month ago. It really is just that simple.
Now, they could view prior wipe as suspicious, but as a US citizen they cannot prevent entry. And they may be able to seize your phone(suspicious!). Which is why simply stating the truth politely "I believe in privacy, and loath government poking into the private affairs of citizens" might help down the road if you want to sue. Might.
Border guards protect the realm, after all, and have wide latitude.
From my side, my truthful argument for wipe has always been that all of my buisness clients, emails, data might be on my phone. I have a duty to protect their privacy.
Making reasonable statements takes the edge off of 'suspicious', and the more people who wipe? The less suspicious it becomes.
The biggest thibg anyone could do, is make 100% restorable backups for non-rooted Android a thing. It's doable, but a PITA right now. Make it one-click, perfect, reliable, and more will do it.
And then it isn't unusual, it's normal, and the suspicious elements vanishes.
Of course, as Google is mired in asshattery lately, I'd expect any attempts to protect us all, such as ASOP patches or bug reports, would be fought against and ignored. Helping the world, protecting travellers, political dissidents, not on their radar.
They even fight such things.
Because in this day and age, Google does not have your back. Instead, they shove knives there.
> Well, once you have been told to unlock the device, you're already in a legally binding process
In none of my scenarios am I describing actions to be taken after you have been told to unlock the phone. I’m talking about before you ever approach the border. There is no functional difference between wiping a key which encrypts the entire device (but leaving the encrypted data in place) vs wiping the entire device, from a security point of view, except one requires twiddling fewer bits to restore the data.
My point is that the law is unable to see that equivalence, but it is also unable to compel a different result. If choice A and B are identical for security purposes but the government can technically prosecute A but not B, all they have accomplished is forcing people to choose B.
The Aftermath: Because the encryption keys are already instantly nuked at the hardware level, the phone boots directly into the Google Pixel recovery or factory-fresh setup screen.
It's exceptionally apparent you've caused destructive behaviour, after the phone is in evidence.
None of the other scenarios, show your duress pin factory resetting the device, then dropping into a setup screen, after the border agent confiscated it. So much of tbe law is intent, coupled with knowledge of your situation.
There's nothing new here really. Throw a diary into the fireplace at home? Fine! Travel with a blank diary? Fine!
Grqb it from a border guard and and rip it up? Trouble.
It's not about the state of the device at the border. It's intent to change the state after confiscation.
That's not the scenario I'm talking about at all. I'm considering entering the duress code before you approach the border and before the border guard gets anywhere near it, on the assumption that you have a byte perfect backup which is trivial to restore somewhere in the cloud.
Well I certainly hope. I have my suspicions that if you pre-wiped your key but left the data “intact” but unusable, you open yourself to the law declaring that as somehow withholding evidence. Actually wiping the entire phone and restoring is certainly the safest in terms of how others may interpret it.
> It's immensely different. Leaps and bounds different. Why? [O]nce you have been told to unlock the device, you're already in a legally binding process.
From a factual point of view, rather than the narrow legal one offered, it is not materially different to delete a phone in anticipation of a future search. In most cases, outside the customs context, it's just harder for the government to prove obstruction of justice.
What's different here is that the government only had a right to search the phone in relation to the border, and the government used that right not just to search for contraband like the law anticipates. If someone dumped their contraband and made it disappear before actually crossing a border, would that be an evidence-related crime? What if they thought about a contraband conspiracy, and then intentionally forgot? What if the customs office presented a form to all travelers, well in advance of formal screening, that they must preserve their contraband henceforth? And then they decided not to smuggle it? Interesting questions legally, but factually, considering criminal charges in those scenarios over the evidentiary situation would be pretty silly.
So then, when you delete purportedly contraband data at the border, have you really just done a public service of removing one more potentially contraband item from border inspection? Or is it that once any of us create data in the vicinity of a border or in a context where we might approach a border in the future with the access device or storage medium, do we all have a duty to preserve it for inspection until the customs authorities get around to inspecting us? Or is it just that this series of hypotheticals illustrate that we have here an epic mash-up of misinterpretation here?
One can’t help but wonder if a motivated DOJ could twist a “destruction of the evidence” charge out of someone dumping a kilo of cocaine just before traveling to the US.
Maybe just don't enter a duress pin, causing the phone to blatantly wipe, and rrboot, and enter a setup screen, right after a customs officer confiscates your potential "contraband", and demands the pin?
I mean really, this act is exceptionally blunt, clear, and overt. All this hand waving won't change things.
I like the idea of a phone that automatically wipes itself if I don’t act to stop it. I wonder about the legality of that if the duress code is considered “destroying evidence.”
If all you want to do is host repositories, “just” is the appropriate word here. For lone wolf work, all I care about is having a remote that mirrors all the changes and branches I create locally. It’s just redundancy. A git bare repo and SSH are all that’s needed.
I don’t do pull requests to myself, and I don’t need a bug tracker or CI.
> Never had a case where suddenly within a minute you get 4, 5 downvotes?
Well, no, I never have, but if I did, my first reaction would be to think I struck a nerve and had a bunch of people react, not that there was a conspiracy.
You’d think so if that was like a continuous process. You wouldn’t if you get a couple of upvotes during the day, then 5 downvotes during 1 minute, and nothing more for hours. What really pisses me off on this site is that continuing arguments (as in a discussion based on arguments, not being argumentative) often leads to people downvoting to kill the convo. So many unproductive discussions here where you know your arguments are fine but people just downvote because they can. Not surprised soma y people are like ”fuck it, throw away account it is”.
I notice that the stat the article repeatedly quotes is MAU for usage of the mobile app, but one of the things I love about Bluesky is that you don’t need to use a mobile app to have a good UX. I use the mobile browser to access it, so I’m not in that MAU number. Perhaps bsky has a larger number of active users that don’t use the app?
To be clear, since the mobile app users are decreasing, what you would actually need to claim is that "web users are more likely to continue using the app than mobile users are", not just that "there are a lot of web users", since the base assumption is that web and mobile users use the site in similar ways. I don't really see any reason to believe the former, and actually having worked on social media extensively I think there's a strong chance that the opposite is true, that if mobile users are declining web users are declining even faster. There's a reason sites push mobile apps so much and it's because retention is normally far better.
A cursory search of bluesky web vs. mobile (surprisingly) suggests that the web experience might actually be better and users seems to recommend it over the app.
This is rare but does suggest a possible effect where users realize this over time and switch.
Here’s another site that tracks monthly active users based on people posting or other activity such as liking a post. It also shows a decline in activity. Scroll down and it looks like a decline of about 40% over a year.
Same. With the exception of Reddit (which I use a different client for anyway), I tend to just use the sites themselves.
Part of it is just not wanting those apps to invade the rest of my life. I know I can turn off notifications and things, but for some weird reason it helps me stay a bit more detached from social media when I'm forced to rely on the site.
The other part is privacy. I don't want the Facebook app on my phone. I don't want to have to worry about what permissions it wants and whether I've unchecked the right things. Using the web is easier for me in that respect.
Not only that, part of the point of the whole "atproto" business is to allow alternate frontends and backends. The official mobile app is kind of bad. A number of people have migrated to Blacksky (alternate backend) following a moderation fallout as well.
Not having the app installed but being a monthly active user, not just someone who's driving by because they clicked on a link on mobile seems like an edge case and I'm pretty sure it won't make a difference to the numbers.
I only install games, apps that are required by specific services in the country, and the streaming apps due to the download capability, everything else is mobile Web.
My problem is usually that I bookmark in the app, but then forget about the bookmarks as they are in the walled garden. I've built something for that a few years ago (https://getbirdfeeder.com) that just sends me my Bluesky (And X, Mastodon etc.) bookmarks straight to my email inbox once a month.
It's never about the technology or if it's theoretically feasible but that tracking, push notifications and ad blocking are much better handled in mobile apps for most platforms.
More, as you have the advertising identifiers from Apple / Google on mobile and you are also not able to block tracking scripts / tracking ads like on mobile web (At least not without more effort or installing additional software or a vpn).
This is not true. I’ve worked in this space. Whenever users had the choice, they chose native iOS about two thirds of the time, native Android about a quarter of the time, and web about 10% of the time. This is across all platforms, including desktop, so the actual user preference for web was even lower than that. We didn’t care which platform people used and weren’t pushing people onto native.
Users genuinely prefer native apps. People don’t seem to have any problem accepting this when you compare things like Electron to desktop apps. It matters even more on resource-constrained mobile devices.
> native apps are only made to the benefit of the companies, not the users.
We literally built the apps because people wanted them. The whole reason the App Store exists is because when Steve Jobs told everybody that to build iPhone apps you should build web apps, people revolted and demanded native apps. The preference for native apps over web apps predates the App Store.
People wanted them because mobile web sites sucked, and because it was difficult to build a decent mobile UX using early mobile web tech. That’s not true anymore but people still reach for apps by reflex even though it makes absolutely no sense most of the time. I don’t want your native code running on my device if a website serves the purpose just as well.
The “why are you making me use an app” backlash will come eventually and nobody will be saying “people want apps” anymore.
I have no idea how Bluesky works as native app, always used the mobile Web version.
Same applies to every other social media web sites I use, and yes I need to click away the banner that regularly asks to install the native app, which would anyway be Electron for mobile.
So you didn’t read the article, made an assumption about its content, question someone who did, then blame Adblock for your confusion, instead of just following the conversation?
No I was confused that they wouldn’t count the browser users when there is no good reason to when they try to eval their user base? MAU commonly includes web users as well.
I blame TechCrunch for creating a website that I can’t read but yea fair criticism I didn’t read the article.
I didn’t question GP i asked if they knew why web users aren’t counted.
Do they explain in the article why they would only count mobile users as MAU?
You introduce a new problem, which is that eyewitness reports of crimes etc can’t identify the vehicles as easily, but that could be viewed as an acceptable loss. Or the problem could conceivably be solved with more technology if we can have dynamically changing license plates (which, again, require law enforcement keys to map back to a real identity for the vehicle).
The only other way I see is that we change laws so that a company like flock collecting this data and then offering it to the government is treated the same as if the government collected it itself. But now that the cat is out of that bag and there is big money behind it, I don’t really see it going back.
reply