HNHacker News
TopNewBestAskShowJobs

0xCMP

2,707 karma · joined December 31, 2014

submissionscomments
0xCMP··on The Who Cares Era
A lot of the comments complaining about working at companies with coworkers or leadership that don't care about hard work never seem to take the time to think about why that may be.

In short: the problem is the customer/consumer. All of us.

Who really doesn't care? The person paying. Or at least the median person paying. For most industries the customer does not care about hard work or whatever. It's always something else. Ongoing operations cost money. Growing costs money. In the end you need revenue to pay for on going work and justify investment or loans to help make more money. But the customer who will provide that needed revenue DOES NOT CARE about all these things we want.

This happens with citizens and infrastructure. This happens with businesses and their internal dev teams. It happens inside FAANNG all the time.

I don't know how to fix it, but certainly demanding change against an uncontrollable reality is not a sustainable solution. In the face of such a reality you can certainly understand how and why "not caring" is the only rational response.

Probably the only way to escape it is to work at companies that are pre-revenue and have enough external investment to fund their operations. Oh hey...

0xCMP··on Why I no longer have an old-school cert on my HTTPS site
I use Cloudflare for everything I can and then currently use Namecheap for anything it doesn't support. I haven't tried Porkbun mostly because I'm okay with what I have already.
0xCMP··on Why I no longer have an old-school cert on my HTTPS site
If you try to open anything with just HTTP on an iOS device (e.g. "Hey, look at this thing I made and have served on the public internet! <link>") it just won't load.

This was my experience sending a link to someone who primarily uses an iPad and is non-technical. They were not going to find/open their Macbook to see the link.

0xCMP··on Japan's IC cards are weird and wonderful
In japan it's optimized for speed thanks to the IC working so fast so you are only slowed down if something fails. It rarely fails (if you're not a tourist...) so you see people walking through them pretty quickly and I have seen people run into each other because they assumed the next person was gonna go through.
0xCMP··on Japan's IC cards are weird and wonderful
There are several operators mentioned in the article. One is possibly switching entirely to QR because renewing the IC contract is too expensive.

Some are cutting back to just Suica and Icoca. Some are switching to, or using from the start, tap-and-pay (Visa, EMV, etc.).

0xCMP··on Japan's IC cards are weird and wonderful
iOS supports ICs fine. It has supported Suica since 2017 when I used it instead of the physical card.

Forcing use of an app and QR codes does seem like a significant step back, although I guess it makes paper tickets much easier to implement with the same scanner.

0xCMP··on Honey has now lost 4M Chrome users after shady tactics were revealed
I think they're referring to https://ground.news/blindspot
0xCMP··on Wired is dropping paywalls for FOIA-based reporting. Others should follow
To be fair some people genuinely do subscribe for this, but it's best to think of it as a justification to do the "right thing".
0xCMP··on How to gain code execution on hundreds of millions of people and popular apps
No, the hashing either when generating or checking is very fast like you said. Hashing itself isn't the culprit, but the battle between browsers and those fingerprinting users.

Originally the point of using a shared CDN like this was that if others used it too the file would already be cached on the user's computer and make it even faster. But, this feature was used for fingerprinting users by checking which files from other websites were cached and browsers have isolated the caches in response which makes it impossible to get the speed benefits from before.

So if you're not getting that speed benefit, and only really getting a tiny bandwidth reduction, the risks of serving the file from a 3rd party (which could be mitigated by the hashes) aren't worth it compared to simply vendoring the file and serving it yourself.

So it's not that hashing prevents caching or lowers response times, but that the risk it is mitigating isn't worth the effort. Just 'err on serving the file yourself.

0xCMP··on DeepSeek releases distributed DuckDB
I think to be clearer it would have been written "DeepSeek Drops Distributed version of DuckDB". Otherwise it looks like they used DuckDB (the distributed one?) and they have something new or better they're using now.
0xCMP··on How to gain code execution on hundreds of millions of people and popular apps
Because if you're not getting the real benefit (improved response times due to caching) you can stop worrying about hashing it properly or not and simply serve a copy you know to be good (or at least known and probably version controlled). Now you don't need to hash or know which hash is correct or worry about the user getting served the wrong file because someone else got hacked.
0xCMP··on Show HN: I made a website where you can create your own "Life in Weeks" timeline
Still plenty of places have "shadow security questions" based on knowing the answers to some of these things already.
0xCMP··on Fans are better than tech at organizing information online (2019)
https://archive.today/Ho1dM
0xCMP··on Digital Services Playbook
I never really saw anyone bad mouthing USDS even here. Can you explain why you think people didn't like USDS?

I'm sure there was some resentment from other agencies that USDS helping them implied they didn't know what they were doing or something, but on HN it has basically been non-stop positive from what I've seen. Echos of the same things in this thread: that they wish they were in a position to sacrifice their pay in order to contribute meaningfully to the government where they have the most chance at impact.

IIUC Login.gov and the much more unified design system based on Material Design for government websites came from USDS.

0xCMP··on A year of uv: pros, cons, and should you migrate
I think this is an awesome feature and will probably a great alternative to my use of nix to do similar things for scripts/python if nothing else because it's way less overhead to get it running and playing with something.

Nix for all it's benefits here can be quite slow and make it otherwise pretty annoying to use as a shebang in my experience versus just writing a package/derivation to add to your shell environment (i.e. it's already fully "built" and wrapped. but also requires a lot more ceremony + "switching" either the OS or HM configs).

0xCMP··on Privacy Is Not Dead: Beware the All-or-Nothing Mindset
It's also important to remember how easy it feels to setup and use when it's all done and working.

When you're starting out you're learning everything and trying to adjust your current usage with the limits of the private alternatives. And then we live in a society there is the learning curve for those who want to interact with you and are somehow willing to cooperate and use a more secure/private thing than the tool/service they're used to.

Let people get better and encourage them to keep going is definitely the right advice. The tone, intent, and timing of telling people how to keep going further is as important as the advice or recommendations you're giving them.

0xCMP··on Finding Flow: Escaping digital distractions through deep work and slow living
I think while things may complain simply pulling the power to the ISP modem/router and doing a full shutdown of any phone would replicate what they are doing. If you wanted you could have a separate AP from the router that could stay running even when the router loses internet to keep the local network running, but if we're being honest... does it really matter?

Most devices might complain, but most will simply stop working silently and then reconnect when they have a chance. Some might need to be power cycled because they gave up trying to connect (I had a smart garage door that had bad connectivity and would sometimes do a version of this).

0xCMP··on U.K. orders Apple to let it spy on users’ encrypted accounts
Right, but the point is they went through the motions to attempt to follow the law. They weren't simply saying someone else was doing the work and then doing it themselves. They at least attempt to follow the law internally. Which is not something we knew for certain or not in the public.
0xCMP··on 0-click deanonymization attack targeting Signal, Discord, other platforms
Well, unlike with tracking pixels, you are not in the direct request path and cannot block it. You also have no way monitor/log if it is happening (like you can in theory with a packet capture).

It's obvious in hindsight, but I bet no one would have mentioned this possibility as why you should disable notification previews or that simply receiving a notification would possibly reveal this information.

0xCMP··on Before Squid Game, there was Battle Royale
They left a pretty heavy cliff-hangar in the very last few minutes of the last episode.
0xCMP··on A story on home server security
sorry, yes to build it is fine, but managing them with Nix (e.g. dealing with which ports to expose and etc like in the article) requires NixOS.

edit: I actually never checked, but I guess nothing stops home-manager or nix-darwin from working too, but I don't think either supports running containers by default. EOD all NixOS does is make a systemd service which runs `docker run ..` for you.

0xCMP··on AI-assisted coding will change software engineering: hard truths
But compiled code loses a lot of the "extra" data. Also these are "language" models so I would be surprised if training on binaries was much more efficient versus writing in some kind of language.

Besides, how do you even check the result now without running untrusted code? Every run of the model you need to reverse-engineer the binary?

0xCMP··on A story on home server security
Of course, that means you need to run NixOS for that to work (which I also do everywhere) and there are networking problems with Docker/Podman in NixOS you need to address yourself. Whereas Docker "runs anywhere" these days.

Worth noting the tradeoffs, but I agree using Nix for this makes life more pleasant and easy to maintain.

0xCMP··on Phishers Love New TLDs Like .shop, .top and .xyz
They're different. Companies register all kinds of crazy domains and redirect you through them all the time. Why is it crazy that some marketing person at Dell thought it would be cool to link people to 'dell dot shop'? I would check the certificates, but honestly only as a precaution. If the website looks correct that isn't such an insane thing.

That is exactly why it's so dangerous and effective versus your example.

0xCMP··on Tip pressure might work in the moment, but customers are less likely to return
I have heard this before, and I get the sentiment, but a supermarket usually already prices things for the local area. The same company in different location can have different prices for the same exact thing. So companies can already handle localized pricing. They just use it for their advantage and hide the cost of taxes.

Other countries handle this fine. It really isn't any more complicated than properly collecting the sale taxes already. Just decide the price of a thing and add the tax then show the final price. You could also, which is something I saw done in Japan, show the Tax Free price so it's easier to compare.

But I kind of don't buy that it would actually much harder than any other hard thing supermarkets do to put the full price on a jug of milk or etc.

0xCMP··on The Influence of Bell Labs
I think most "tech/bay" companies offer 3-4 weeks of vacation + holidays. Some have mandatory minimums a year and ability to accrue up to 30 days of PTO at a time in my experience. (e.g. not "unlimited", but specific amounts of PTO earned/used)
0xCMP··on We're Leaving Kubernetes
Agreed that it may be the right solution, but it smells bad. If I was there I would be trying to reduce the complexity where I could.
0xCMP··on We're Leaving Kubernetes
I think it's a fair to assume OP would have tried to run only some of the services and has seen or experienced problems with doing that.
0xCMP··on We're Leaving Kubernetes
It's very likely not their decisions that lead to this, but their responsibility to improve velocity.

Imagine the goal is to fix the problems (e.g. make it possible to run less of the services or something like that): How do you do that without first running all the services, making the proper changes, and then testing those changes? You need to be able to run all the services in that interim period.

So, wouldn't it be nice if there were a solution for this in-general? And, maybe, it would lead to better conditions later on. But in the meantime there is really no way around the existing design/decisions/etc. You simply have to deal with that reality and engineer around it.

0xCMP··on Cash: A small jQuery alternative for modern browsers
modern browsers support the import syntax natively, so it really shouldn't be a lot of overhead to import it.
← PreviousPage 3 of 34Next →