I think it was looser on release for those juicy benchmarks, tighter now. On release I wasn’t getting refusals, then a few days ago I asked it whether a generic quote (think “he walked to the store”) broke standard punctuation rules, and it blocked me for breaking rules. I wish I were joking. Rephrasing to not use the keyword “rules” worked.
Relatedly, Apple finally kicked me off the quick update bandwagon with macOS/iOS 26, and I was surprised to learn that no, Apple does not let you just say no to updates. You get a permanent red badge that you can only dismiss by fully turning off system notifications, you get nagged literally thousands of times, and if any of those times you don’t repeat your rejection quickly enough, it overrides your non-consent and updates. That’s all with updates turned off. HN comment sections had led me to believe that consensual updates are a pro of Apple over Windows and an example of Apple’s class, but they don’t exist, the actual software is everything people lambast Windows for.
I have a script to add an /etc/hosts entry for `127.0.0.1 gdmf.apple.com` and that seems to eliminate any nagging, just remove when it's time to update.
Sounds like an unauthorized access of my computer - a fine of a dollar per byte, per person, should make Apple turn the hell around. 15 billion dollars times how many Apple users that have been wronged in this manner? Apple would be dead instantly.
I think you'll find that you agreed to it somewhere in their voluminous terms of service.
I looked it up and indeed, it's in section 1, paragraph C:
Your Device will periodically check with Apple for Apple Software Changes. If a change is available, the change may automatically download and install onto your Device
and, if applicable, your peripheral devices. By using the Apple Software, you agree that Apple may download and install automatic Apple Software Changes onto your Device and your peripheral devices.
He said it's "unauthorized access of his computer", even though he implicitly authorized it by clicking through the agreement (apparently without reading it).
If people actually read these clickthrough agreements and started sending devices back when they don't agree, it would encourage the industry to change.
No one "needs" an iPhone, they can support one of the open source phones with far less onerous terms.
You can still consider it unauthorized, if you do not consider the authorization to be valid in the first place. I can also get people to sign away their life on a contract, that's not going to mean anything, because signing away your life is not possible in the first place.
> If people actually read these clickthrough agreements
I would live in such a world too, but that is a fairy tale. In a lot of situations, you don't get to see the contract before you have signed it. I had the situation in a bank contract. The bank clerk tells me it's mandatory, to sign that waiver, I tell her it's not. She won't sign the main contract, until I signed that waiver. I tell her that's illegal. Doesn't matter. After I signed it, I get to read the waiver, it clearly states, that it is not mandatory, and whether it gets signed does not have any effect on the main contract, as is required by law (with citation).
Because of these things, the laws says some things can't be established and most other things must be established with informed consent. It's on the company to ensure that this is collected. No, a tick on "I have read and understand the Terms and Conditions" is not informed consent.
Honestly, we don't need any law changes actually, because most of these things the tech companies do is plain illegal in every step.
The Regional Court of Berlin held in a judgment of 16 January 2018 (docket no. 16 O 341/15, German language version of the judgment available here) that Facebook's default privacy settings and parts of their terms and conditions were invalid. This judgment provides important guidance on consent and transparency.
Background
The Federation of German Consumer Organizations (Federation) sued Facebook and requested cease and desist regarding some of its default settings and terms and conditions.
The Federation argued that Facebook's default settings violated the requirement of explicit consent. For example, the default settings included a location service in Facebook's mobile app revealing the location of the person that the user is chatting to. In addition, boxes were pre-activated allowing search engines to link to the user's timeline.
The Federation also argued that various clauses in the terms and conditions of Facebook were invalid, including clauses that provide consent of the user (i) to transferring personal data to and processing personal data in the U.S. and (ii) using the name and profile picture of the user for commercial, sponsored or related content.
Judgment of the Regional Court of Berlin
First, the Regional Court of Berlin found that five default settings were invalid because the requirements of informed consent were not fulfilled. The court stated that informed consent requires that an organization must provide comprehensive information about the background and the scope of the consent in order for the consent to be based on an entirely free decision of the user. Default settings cannot be regarded as informed consent if the user is not explicitly and actively notified of the default settings in the registration procedure. Facebook did not sufficiently ensure that the user was aware of the default settings. The court noted that a "virtual privacy tour" that Facebook offered, but that was not mandatory, did not change this. Not every user would make use of this privacy tour and "realistically", most of the users would not further review the privacy settings.
Next, the court held that the consent declarations in the terms and conditions were not transparent and therefore the users were not able to give informed consent. With regard to the consent to the transfer of personal data to the United States, the court observed that the user was not informed about which categories of personal data were transferred, why they were transferred, how they are further used in the U.S. and which standards of data security are applied. Further, the court concluded that the consent language for using the name and profile picture for commercial, sponsored or related content was not transparent. The extent of the usage of the name and profile picture was not clear for the user and not further explained. The court noted that the example that was provided in the consent wording (i.e., use for a brand that the user likes) was not sufficient information about the scope of the consent.
IMO the notion that such one-sided agreements are not made under duress needs to die in a fire. I wish there were a viable grassroots political movement to remove the corporate boot from our neck; until that point, fuck these terms of servitude and every abuse they enable.
The nagging notifications are only a small part. Apple has far more effective ways of forcing updates on you. On iPhones, for instance, the Unicode tables ship with the OS version, so unless you update, you cannot render newly added emoji codepoints. Given how central emojis have become to pop culture - and how determined the Unicode Consortium seems to keep adding more of them - the whole situation almost looks like a conspiracy, if you squint. But that's just the tip of the iceberg.
In the App Store, Apple won't let you filter for apps compatible with your iOS version. So sooner or later, you have to manually try installing every search result just to see whether it errors out. There's no explanation for not adding such a trivial filter other than to annoy users on purpose. Without jailbreaking, you also can't install earlier (compatible) versions of a given app. And by the way, updating iOS eventually just turns into buying a new iPhone, once the latest iOS no longer supports your device at all.
But the worst part is how critical software components are bundled with the OS too. On iPhone, that means WebKit. So very soon your Internet browsing experience starts to rot, because the only way to get a version supporting the latest Web standards is to update the whole of iOS. Likewise, on Macs, your runtimes/frameworks are bundled as well, so you can't update them individually. Eventually, the only way to install even non-native apps is to update the whole macOS.
This is what you sign up for when you buy an Apple product. Apple has mastered the art of tempting you without letting you realize what's really going on until it's too late. Apple was, is, and always will be evil. The clue is in their logo.
> Apple has far more effective ways of forcing updates on you
Let's not forget forcing physical upgrades: a new .x update of iOS that suddenly decides a bit of hardware is now broken and bricks the phone. Apple Store said £400 plus to fix despite my explaining it was their update that bricked it - every component was working fine
I never heard of that. Is this documented anywhere? Also doesn't Apple Store usually replace the whole device for a repair, rather than individual hardware components?
I can send you my bricked phone to inspect if you like? I did a minor update just sat in the car, then it got stuck in a boot loop, no attempt at DFU rescue etc worked. Phone was perfectly fine up to the update including face ID, speakers etc
Apple aren't going to document their planned obsolescence at apple.com I'm afraid
“Pick all the numbers in the range with exactly the same probability” is a very important property of RNGs. Yes, skipping 16542 would be equally bad.
You can frame it around being “non predictable”, but then you need to define those words. It’s not, for example, a poker game where it’s trying to bluff you, right? It’s also not about just making predictions < 100% reliable and declaring victory. It must specifically make all predictions no better than random guessing, and that entails picking any number in range with equal probability, otherwise predictions like “it will be {hot spot}” or “it won’t be {cold spot}” do better than random chance. In this case, specifically, I can predict with 100% accuracy that the result won’t be 0, and that’s a flaw in its unpredictability. I can also predict a bunch of other things with slightly higher accuracy than random guessing, like that it will be odd or greater than max ÷ 2.
Why do you think it’s vibe coded? Just asking to see if I can learn something. I can see it’s very standard corpo-aesthetic, uses callouts for the sake of callouts, and is horribly laggy, but corpo websites were doing all that long before AI. It also seems to be using a bunch of Cloudflare-specific terminology that I’d think would take longer to review and correct an AI on than to type yourself.
One tell is: if you can code that hero there's no excuse for the silly bugs.
For example, the hero is fairly impressive in mobile but it's broken in desktop. And then you scroll down to the next section and there's overflowing text.
when you unblind a blind signature all the signer knows is that it's a signature they signed at some point, they know nothing (true zero knowledge) about when or where they signed it among all the other signatures.
Yes, and then you have a signed piece of data that others can verify. How does that help you with preventing duplication of signatures?
E-cash depends on the secrecy of the signed data, and immediate redemption with the issuer once it's been spent/accepted. This is a terrible model for physical cash.
> immediate redemption with the issuer once it's been spent/accepted. This is a terrible model for physical cash
not when everything is now online.
also the obvious way such cash would work is that "redemption" is just the new minting of coin. the central authority will mint a new coin by blindly signing your secret after you "destroy" the spent coin by giving them the unblinded signature.
This thread is about printing QR codes on physical cash. GGP explicitly said:
> That's really neat! Seems potentially adaptable to paper currency--a verifiable QR code digital signature of the bill's serial number creates a cryptographically hard obstacle to counterfeiting!
I don't see how any e-cash solutions can help here.
it would depend on the government and the situation. I suspect most don't realize this is possible. a small government can generate immediate demand for their currency doing this.
The original e-cash paper is from 1983. Governments absolutely know this is possible.
It's just much "too private" to get any political traction. At the very least, I suspect an acceptable modern alternative would either have caps on what can be sent/received completely anonymously (e.g. per recipient and timespan) or want non-anonymous recipients (to allow for VAT/sales tax accounting etc.)
Goodwill liquidation is what I’ve been calling it.
I think we might be coloring it as we’d like it to be, though. Only rarely does it end in brand death, more often they just get a bad reputation then keep going, sometimes not even less profitably. I think the intent might be more along the lines of recalibrating to a lower expectation of consumer discernment or rationality.
I’d like to propose a rule that all the Finder bashers in this thread accompany their complaint with at least one concrete example.
I’m no Apple fanboy, but blind hate is just as bad as blind love, and so far 100% of the specifics brought up have turned out to be people who just don’t have a basic familiarity with the software. I genuinely don’t begrudge a person sticking to what they know, but it’s a point towards what’s good for you and maybe whether it’s intuitive, not towards whether Finder is objectively good or lacks features. I’d be happy to read both real issues and people learning more about Finder, but just “Finder sucks” doesn’t help anybody.
The keybindings (and lack of documentation for them) in Finder sucks, having to google how to show hidden files in a save dialogue every time I have to do it sucks, having to search through the UI every time for the non-obvious way to get to a specific path sucks. Do I need to mention .DS_Store?
There are loads of different file managers for many different operating systems, they look and act the way they do from years of refining UX in response to the way users actually interact with them. This is why the file manager on my android phone is so similar to the one on my windows machine, and my linux install. All of them are different to Finder which appeared to lock some UX decisions in circa 1990 and then refuse to budge, this is why Finder sucks.
It's the one OS where file and folder manipulation via the terminal is actually sometimes faster for me, no need to go digging for the specific ritual Finder uses in opposition to every other file manager to do the task.
I think frustrating is the most appropriate word. Finder is great if my files are organized and I know exactly where something is. My concrete one... The save dialog opens where it was last, so files land in places I didn’t choose, and nothing in Finder or Spotlight helps me later unless I remember the name or the contents.
In the open and save file dialogs, the location is a dropdown containing, amongst other things, recent locations, which would list where the file ended up. I think the number of recents is configurable in System Settings.
It should also show up in the Recents sidebar entry, though I don’t use it so I’m not sure.
The save dialog sidebar is configurable, I’ve put my “inbox” there.
I agree it would be better for this to be an option, but I think the status quo is more clicks, not nothing exists.
reply