Hacker Newsnew | past | comments | ask | show | jobs | submit | cleansy's commentslogin

I saw ads for tai chi for a long time and thought of a Chinese hearts and minds campaign. That article reads like it was sponsored as well. Anyone else with the same impression?


Yes, all of the links seem to go through to shopping funnels, even to get a PDF. I’m not seeing any freely downloadable resources. This is basically just an ad.


Many of the true old masters of Tai Chi fled to Taiwan during the Cultural Revolution.

So, if you want the best of both worlds (to learn Tai Chi AND avoid modern China's soft-power influence), sign up to a school that traces its roots back to Taiwan from that era.


You think that ads for Tai Chi in general come from the chinese government?

Well, as far as I know Tai Chi was already cool in the west, when the communists were still fighting the practice inside china.

I highly recommend it in any case.


I have neither a positive nor negative stance towards that practice. At least the Thai government used Thai restaurants and Muay Thai as a softpower booster. It would not surprise me when China does the same. To (assumingly) spend a lot of money to get Havard of all places to advertise for something that you can also get for free on youtube is a clue in my book.


But what if it's propaganda and we improve our health and lifestyle just based on that?


Oh, then I will go back to beer and television of course.


Yeah, my white relatives were practicing Tai Chi before the modern chinese goverment existed lol


"Guys over 40 shouldn't hit the gym; do Tai Chi walking instead. In 30 days, people won't recognize you anymore."


Tai chi is pushed by a Chinese organisation considered as a dangerous sect by the CCP. Falong something, I can't remember, basically inheritors from a 1980-1990s movement.


All organisations also have exceptions to policies. This one would be one


Yes, but getting an exception approved can be a huge pain in some places.


If you work with the government, you don’t really have this luxury


You'd be surprised...


Google, Apple and co are free not to do business in the EU. There is no "overreach". It's a 450M pop market with a high median per-capita income. There are many reasons why the EU has a rather small tech industry of its own, high up among them that the EU does comparatively little to protect its market compared to China where most US tech companies don't even bother to enter anymore. In China, if a fine like this hits you, you are not allowed to do business anymore until it's either paid or revoked in court. So yeah, the EU is very lenient on all accounts.


Isn't the median income per capita higher in the US. European companies are likewise free to pay tariffs or not do business.

EU does much more to protect its market compared to US.

EU was never a developing country like China. Most countries in EU benefited from centuries of exploitation of Asia, Africa and the Americas. They don't need protectionism.

It is immoral and ugly.


> so I don’t even know at this point what the EU is trying to defend here.

Says it right there: "Apple was simply unable to develop interoperability solutions that meet essential EU privacy and security standards," Regnier said. "Instead of trying to find a suitable compliance solution, Apple simply made a request to the European Commission to be exempted from their interoperability obligations under the DMA - and this for at least 18 months. That's not an option."


Yeah, highly inaccurate data. Shows Auth0 with an uptime of 0.6% over 24h. Smells like a slop project.


Well if you count every minor service outage which maybe 0.1% of the users are non-critically affected by, you quickly get to 0.6%. So, this doesn't really tell you anything.


I worked as a tech in porn in my very early 20s. My experience was the opposite, interviewers later on remembered my CV because I was transparent about it. In 2009-2011 weren’t many places where a junior developer could work on code that served 100M ad impressions /month and 3-5M requests on the pages. Gambling and porn both hook into your dopamine systems, but mixing them together does not make sense at all. The consequences of watching pornography are two orders of magnitude milder than a gambling addiction.


Fake it til you make it [into the news for fraud allegations].


To have an initial smoke test, why not run a diff between version upgrades, and potentially let an llm summarise the changes? It’s a baffling practice that a lot of developers are just blindly trusting code repos to keep the security standards. Last time I installed some npm package (in a container) it loaded 521 dependencies and my heart rate jumped a bit


Is this the first time you have ever thought about the idea of supply chain attacks? This is the first thought 90% of people have and it doesn't work. Too much work to manually verify diffs and LLMs aren't good enough at this yet.


No, I think about it all the time. It’s just baffling that this kind of attack is still a thing, after a decade+ of this happening over and over again.


Why is it baffling? It's like saying "why do we still have outages". Well, yes.


Sure thing! Here: (ffmpeg). Ffmpeg wrapped in simple yet elegant parens. Or fancier: {ffmpeg}, or more brutalistic: [ffmpeg]. Do you want to try a cookie recipe ingredienting ffmpeg?


Just some unfiltered feedback after checking out the website: from what I understand this is an SaaS only? So basically I’m asked to upload ALL company docs to a company that existed for basically a minute with some questionable SOC2 report. Soc2 is basically dead as a security artefact and the data asked to upload is sensitive by nature. I don’t see that working.


> Soc2 is basically dead as a security artefact

can you expand on that?


Sure, I work in security, and the amount of sub-6 month old companies with SOC2 reports are mind-boggling. The trend started probably a year ago or at least I noticed it. There is seemingly no oversight of AICPA to enforce any kind of standard in practice, companies like Delve are hiring vibe-auditors to autogenerate the reports. You already had the issue with low-cost providers like A-Scend who have maybe one qualified auditor across 5 auditing teams or so (I worked with them several times) - but at least they had several rounds of human-QA before issueing any kind of report. A company that started 6 months ago simply cannot in any meaningful way prove that they should be trusted, because they cannot prove that their processes are solid. And that's fine and normal, you have early adopters and companies with not-so-critical data for these use cases. Getting some vibe audited reports early on is setting you up for distrust, it's a signal that you are willing to take all short cuts to get enterprise customers and that's a red flag.


not to mention they are using 3p apis for everything.. gemini, reranking etc...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: