• 0 Posts
  • 120 Comments
Joined 4 years ago
cake
Cake day: January 21st, 2021

help-circle
  • I paid for GPM for quite a while. I then started working at Google and beta tested YouTube Music from very early on and gave lots of feedback about how it sucked. When they shut down GPM I cancelled my YouTube Premium membership and installed an ad blocker. Not just YTM but so many things about YouTube were getting worse and worse and I couldn’t find it in myself to keep paying for a service that kept removing features.




  • This isn’t how YouTube has streamed videos for many, many years.

    Most video and live streams work by serving a sequence of small self-contained video files (often in the 1-5s range). Sometimes audio is also separate files (avoids duplication as you often use the same audio for all video qualities as well as enables audio-only streaming). This is done for a few reasons but primarily to allow quite seamless switching between quality levels on-the-fly.

    Inserting ads in a stream like this is trivial. You just add a few ad chunks between the regular video chunks. The only real complication is that the ad needs to start at a chunk boundary. (And if you want it to be hard to detect you probably want the length of the ad to be a multiple of the regular chunk size). There is no re-encoding or other processing required at all. Just update the “playlist” (the list of chunks in the video) and the player will play the ad without knowing that it is “different” from the rest of the chunks.


  • kevincox@lemmy.mltoTechnology@lemmy.world*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    8 days ago

    That is a pretty weak argument. The issues are minor and in a library that people are moving off of to a better build and stronger validated library. Yes, it should have been like that in the first place, but the problem is minor and being addressed.

    I would look more to the various features of Matrix that aren’t encrypted like room names, topics, reactions, … and not to mention the oodles of unencrypted metadata. I really wouldn’t call Matrix a high-privacy system.

    I like Matrix and use it regularly, but it definitely doesn’t have a privacy-first mindset like Signal does. I’m hoping that this improves over time, but without a strong privacy first leadership it seems unlikely to happen.



  • kevincox@lemmy.mltoPrivacy@lemmy.mlIn search for a good VPN
    link
    fedilink
    arrow-up
    8
    arrow-down
    1
    ·
    24 days ago

    I mean it is always better to have more open source. But the point of the multi-hop system is that you don’t need to trust the server. Even if the server was open source:

    1. You wouldn’t know that we are running an unmodified version.
    2. If you need to trust the server then someone could compel us to tap it or monitor it.

    The open source client is enough to verify this and the security of the whole scheme.


  • Because these buckets probably don’t exist (citation needed on all of these, I don’t have access to data from a large online store).

    I suspect that this is actually a “good” recommendation in the face of many other facts.

    1. Any recommendation has a very low risk of success. Outside of searching contexts (where there is clear intent) I suspect that the chance of a recommendation leading to a purchase is <1%.
    2. You usually make more money from bigger sales. So showing a 1% expected $1k GPU is better than showing a 20% expected purchase $20 pair of sunglasses (and I doubt any recommendation has 20% purchase rate outside of clear sources intent).
    3. People return things. Return rate is much higher than 1% on many platforms and some good chunk of these will want a similar product to replace the defective/bad/unsuitable one.
      • For Amazon this maybe isn’t a good excuse because they should be able to incorporate return information into the recommendations. But even then, lots of people may prefer to order a second one before going through with the return. Maybe they want to do a comparison to be sure that they like the new one more before sending the first back.
    4. People do have uses for multiple even for things that wouldn’t seem that way at first glance. If I just bought a GPU and am happy with it maybe my partner needs an upgrade (or gets a little jealous). Maybe I will see a similar or identical product recommended and get it for her. Maybe I like my new fridge and also want to replace my second basement fridge with it, or maybe the quietness of the new one made me realize how loud the other one is and I want to get a similar model to replace it.
    5. People recommend things to each other. Maybe I just bought a GPU and my buddy is asking if I like it. The next day I see a recommendation for a GPU that I think is a good open for them, I send the link.

    Yes, all of these scenarios are unlikely, but I suspect that is actually significantly higher than the baseline, and for the big items that people usually complain about much more profitable. I suspect you see these ads because they work. Not as in they are often right, but that they have higher expected value than other available ads.


  • kevincox@lemmy.mltoPrivacy@lemmy.mlIn search for a good VPN
    link
    fedilink
    arrow-up
    26
    arrow-down
    1
    ·
    24 days ago

    Mullvad is one of the best options if you care about privacy. They take privacy seriously, both on their side and pushing users towards private options. They also support fully anonymous payments. Their price is also incredibly reasonable.

    I’m actually working on a VPN product as well. It is a multi-hop system so that we can’t track you. But it isn’t publicly available yet, so in the meantime I happily recommend Mullvad.



  • I don’t think it is that simple. I think that outline is about the “focus”. So if I press enter it will activate that tab, if I press tab it will move the focus to the “Entire Screen” tab.

    The UX issue is that there are two concepts of focus in this UI. There is “which tab is active” and “what UI element will pressing enter activate”. These two are not sufficiently differentiated which leads to a confusing experience.

    Or maybe there can just be no keyboard focus indicator by default, but that may be annoying for keyboard power users. But this is generally how it works on the web, you have to press tab once to move keyboard focus to the first interactive element.




  • This is basically admitting that consumers don’t actually value their subscription service for the cost. If users were buying used bikes and signing up for subscriptions Peloton would be thrilled, they would do everything that they could to encourage that like free trials. But it must be that most people who buy used bikes don’t find the subscription worth it and cancel within a few months. Adding this fee both extracts more money and creates a sunk cost fallacy that will cause them to go longer before cancelling.

    If the product sold itself they would just let people pay them subscriptions, its basically free money.


  • These are all good points. This is why it is important to match your recommendations to the person. For example if I know they have Chrome and a Google account I might just recommend using that. Yes, it isn’t end-to-end encrypted and Google isn’t great for privacy but at least they are already managing logins over all of their devices.

    In many cases perfect is the enemy of better. I would rather them use any password manager and unique passwords (even “a text file on their desktop”) than them sticking to one password anywhere because other solutions are too complicated.


  • It depends on your threat model. It does mostly reduce the benefit from 2FA, but you are probably still very safe if you use a random password per site. I mostly use 2FA when forced (other than a few high-value accounts) so I don’t worry about it. For most people having a random password which is auto-filled so that you don’t type it into the wrong site is more than sufficient to keep themselves secure.



  • kevincox@lemmy.mltoPrivacy@lemmy.mlUse a password manager
    link
    fedilink
    arrow-up
    10
    arrow-down
    2
    ·
    2 months ago

    Honestly nothing. I recommend this to everyone because it is the easiest way to set up and offers huge advantages.

    1. No more password reuse, per site random passwords.
    2. Auto-fill reduces chance of phishing attacks work because you get suspicious if the password doesn’t auto-fill.
    3. Most browsers will integrate it into their sync service to reduce the risk of you losing your passwords.

    I think these are the two biggest benefits and every browser password manager will accomplish both.


  • These are real issues however they are pretty easy to mitigate, and I would say that the upsides of a password manager far outweigh the downsides.

    1. Make sure that you are regularly typing your master password for the first bit. After that you’ll never forget it. You can also help them out by saving a copy of their master password for them at least until they are sure they have memorized it. There are also password managers where you can recovery your account as long as you have the keys cached on at least one device.

    2. This is far, far outweighed by the risk of password reuse. This is because when a single one of the sites you use gets hacked then people will take that credential list and try it on every other site. So with a password manager there is just one target, without it is one of hundreds of sites where you reused your password. Many password managers also have end-to-end encryption so without your password the sync service can’t be hacked (as it doesn’t have access to your passwords).


  • Basically they license out the system to companies. You can get a rough idea here: https://what3words.com/business

    The idea is that by making it free to individuals they build up market familiarity and expectation. Free personal use is just marketing for the paid product. Then they can turn to businesses and convince them that they should offer their system as a service and charge them for it.

    The closest alternative is probably Plus Codes. They are driven by Google but are free to use for everything with a pretty plain and simple Terms of Use.

    Instead of words they use an alphanumeric encoding. The main downside is that this can be less memorable but the upside is that it works for users of all languages and you can shorten the codes by using a Country or City reference as well as control the precision.