HNHacker News
TopNewBestAskShowJobs

Ao7bei3s

1,530 karma · joined December 5, 2012

submissionscomments
Ao7bei3s··on Launch HN: ProvenMetal (YC S26) delivers circuit boards in days instead of weeks
Thank you. I hadn't expected it to just be lack of demand/scale. All the best with Aisler; I really hope the EU's renewed interest in local production will lead to more business for you.
Ao7bei3s··on Launch HN: ProvenMetal (YC S26) delivers circuit boards in days instead of weeks
Thanks for being open to questions. I always wanted to know this:

3 copies of a simple 50x50mm, 6 layer, board is 184€ and takes 13 days to make as per https://aisler.net/en/products/boards - for comparison, JLC makes five 100x100mm 6-layer PCBs in 11 days, for $2. (And no, it's not only because of the (always available) coupon. Pricing generally gets better at higher quantities.)

So my question is: why is 6 layers so expensive? Are you really truly economically unable to even get close to JLC, or do you just not care about prototyping orders (or the overlap between hobbyists and professionals), or are these smaller boards a too large part of your revenue that you can't compromise, or is it more a case of being stuck in an outdated legacy mindset where 6 layers is "a lot" and must be allocated to "serious business" only, or is it something else? Or am I just completely off about proper market segmentation? (Same for going to 2oz copper.)

Please don't take offense at the way I'm asking; I really really want to be your customer. I'm never going back to unnecessarily constrained shitty 2 or even 4 layer designs, when a simple part/sig, gnd, vcc, sig/gnd, gnd, part/sig stackup makes design soooo much easier even for simple circuits. But I really would love to know why nothing comes close to JLC one level up from novice PCBs.

Ao7bei3s··on WolfIP: Lightweight TCP/IP stack with no dynamic memory allocations
It has a fixed maximum number of concurrent sockets, and each socket has queues backed by per-socket fixed-size transmit and receive buffers (see `rxmem` and `txmem` in `struct tsocket`[1]). This is fine, because in TCP, each side advertises remaining buffer space via the window size header field [2] (possibly with its meaning modified by the window scale option during the initial handshake - see [3] & `struct PACKED tcp_opt_ws`), and possibly also how much it can maximally receive in one packet (via the MSS option on the initial handshake [4]; possibly modified by intermediary systems via MSS clamping). wolfip has unusually small buffer sizes, and hardcodes them via #define, and everything else (e.g. congestion control) is pretty rudimentary too, but otherwise it's pretty much the same as in a "normal" implementation.

[1] https://github.com/wolfSSL/wolfip/blob/60444d869e8f451aa2dca... [2] https://github.com/wolfSSL/wolfip/blob/60444d869e8f451aa2dca... [3] https://github.com/wolfSSL/wolfip/blob/60444d869e8f451aa2dca... [4] https://github.com/wolfSSL/wolfip/blob/60444d869e8f451aa2dca...

Ao7bei3s··on Opening the AWS European Sovereign Cloud
It's similar to FedRAMP systems like AWS GovCloud (US), which can only be accessed by someone who is a US person (US citizen or lawful permanent resident) and on US soil (physically in the US at the time of access).
Ao7bei3s··on I got an Nvidia GH200 server for €7.5k on Reddit and converted it to a desktop
LACK tables specifically are well proven to be quite sturdy actually. They happen to be just the right width for servers / network devices, and so people have used them for that purpose for ages. Search for "LACK rack", or see e.g. https://wiki.eth0.nl/index.php/LackRack. 20kg is nothing; I've personally put >100kg on top.
Ao7bei3s··on Perfetto: Swiss army knife for Linux client tracing
Go to https://ui.perfetto.dev/. On the left sidebar, under "Example traces", click "Open Android example".

For a simple example using your own data, save this as a file and open it via "Open trace file":

  [
    {"name": "Example 1", "ph": "X", "ts": 1, "dur": 1, "pid": 0, "tid": 0},
    {"name": "Example 2", "ph": "X", "ts": 3, "dur": 2, "pid": 0, "tid": 0},
    {"name": "Example 3", "ph": "X", "ts": 2, "dur": 1, "pid": 0, "tid": 1},
    {"name": "Example 4", "ph": "X", "ts": 4, "dur": 2, "pid": 0, "tid": 1}
  ]
Ao7bei3s··on French firm Gouach is pitching an Infinite Battery with replaceable cells
It really depends. The DMCA does have limited exemptions for reverse engineering for interoperability. The EFF has a good overview: https://www.eff.org/issues/coders/reverse-engineering-faq (search for DMCA). My personal takeaway is that this question cannot be definitely answered outside of court.
Ao7bei3s··on Show HN: I Got Tired of Calculator Sites, So I Built My Own
Try https://numbat.dev/ (https://github.com/sharkdp/numbat). It's my go-to for any engineering calculations. It can also run locally.

  >>> 4 weeks + 59*3 hours -> days
  4 week + 59 × 3 hour  day
      = 35.375 day    [Time]

  >>> 5V / 50ohm -> mA
    5 volt / 50 ohm  milliampere
        = 100 mA    [Current]
Full syntax: https://numbat.dev/doc/example-numbat_syntax.html
Ao7bei3s··on Tech CEO Pays $400k to Conduct the Toronto Symphony
I have had a question for a long time, and this may be my one chance to ask someone who actually knows how these things work.

When you were working on this, have you considered playing music that (and please don't take this the wrong way; this may be exaggerated but maybe you will understand what I mean) pre-retirement non-musicians would listen to, where the composer is still alive, and that hasn't been played in the same venue a hundred times? Looking at the Gewandhauses schedule right now, there's absolutely nothing for me.

The San Francisco Symphony plays a top-tier movie (Top Gun, Titanic, Lord of the Rings, etc.) with the film music performed live by the orchestra every few months, and I go to many of these. I got tickets for the Game of Thrones series finale concert (different venue). I absolutely loved Video Games Live, which actually has been in Leipzig too, but in the Arena, and well over a decade ago. I went to a Lindsey Stirling concert, who I knew from YouTube.

So my question is: Why can't the Gewandhaus do something like that regularly? Why can these events only be available in large cities like San Francisco? It's actually frustratingly difficult to find such events in smaller cities. Is it licensing/artist fees? Not interesting for the local musicians? Events like this reliably book out large venues several times in a row, so can it really be lack of demand? Maybe only from the wrong customers?

Ao7bei3s··on Microsoft opens a free tier for Windows 10 extended updates
Windows 11 recently pushed an update to discontinue Windows Mixed Reality (WMR), bricking my <5 years old, $500 Reverb G2 VR headset, which I bought after Meta bought out Oculus and started requiring a Meta account, essentially bricking my Rift S. No thanks.
Ao7bei3s··on Introduction to the A* Algorithm (2014)
Ay-star.
Ao7bei3s··on Mastering Delphi 5 2025 Annotated Edition Is Now Complete
Delphi and Visual Basic 6 were definitely not the pinnacle of UI development.

For example, all layout was pixel based. Making windows resizable required much complex ad-hoc code, and internationalization was hard as well. Very early in my career, I have spent person months clicking through every single screen in a large desktop application to find words cut off due to words having different lengths (measured in pixel) in different languages. I knew what "Ok" and "Cancel" meant in half a dozen languages. At the time, Java was really breaking ground with container based layouts in Swing. Delphi and Visual Basic caught up only in the .NET era.

Ao7bei3s··on NASA to launch space observatory that will map 450M galaxies
About 30x60x90cm in size.
Ao7bei3s··on Using Euro coins as weights (2004)
Olympic weight plates for barbells. They're widely used, so competition has brought the cost down, and they're easily available in useful increments. I currently see 4x 10lbs for <$50 on Amazon. That works out to 2,53 Euro per kg. So cheaper than euro cents. They may not have the exact shape you need.

The scrap steel probably didn't cost cents per kg when it was sold for its original purpose. You are paying for a useful shape.

A professional equivalent of weighted vests are ballistic plate carriers. Real ballistic plates can be fragile and expensive, so options for exercising in (or milsim games in airsoft etc.) include expired (and failed to re-certify) real ballistic plates, made for purpose training plates... or plate shaped sandbags!

Ao7bei3s··on Show HN: I made a porta potty finder for tradesmen
For general public restrooms, you can also search OpenStreetMap for amenity=toilet and access=yes (which means explicitly open to the public; see also access=customers). Try it: https://overpass-turbo.eu/s/1ORn
Ao7bei3s··on It's cheaper to buy ($33) than rent ($44/year) IPv4s from AWS
The main technical limitation is that /24 is the smallest prefix that is widely accepted. So you can't just announce a /32 (single IPv4) at different locations.

Generally speaking, if you own the IP space, it just needs to be announced in BGP and traffic will come. You can either peer with someone yourself and get transit from them, or have them advertise it for you.

It's possible even for a private person to do it, if they have one of several workable mixes of knowledge, time, cash, contacts and technical requirements. I've done it for a while.

The main practical question really is who will peer with you and with what conditions. For example, your ISP will absolutely not do this on a consumer plan, but might on a business plan. AWS will do it for busineses as well: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-byoi...

If you want to learn more about BGP, anyone can sign up for DN42, which is a free, large, shared environment that is a small scale replica of the internet. Everyone gets to be their own AS, get some IP space allocated, establish links to other participants (usually VPN tunnels over the real internet), and do BGP peerings over them. https://dn42.eu/Home

Ao7bei3s··on NOAA declares a G5 (extreme) geomagnetic storm
It's written in an ambiguous way and you interpreted it incorrectly. "G5 Conditions were first observed at Earth at 6:54 p.m. EDT today." should be read like "today, G5 conditions where first observed at 6:54", not "G5 conditions where first observed today (at 6:54)".

G5 is defined as K_p = 9. That happened in Oct 2003. https://ftp.gwdg.de/pub/geophys/kp-ap/kp-freq/kp2003.frq

Ao7bei3s··on Tesla took down all its open U.S. job postings
Those are all arguments for buying Tesla stock, not a Tesla. Of course Tesla will keep selling new cars.

What if Tesla pulls the rug on existing models and stops supporting them after a few years? It's not an outlandish fear. Musk has been wildly unpredictable, anything could happen. And given e.g. the recent story about how a Tesla car wouldn't even start again without calling support for some kind of remote maintenance, Tesla owners seem to be more dependent on the company's support than average. It wouldn't surprise me at all if Teslas were generally one expired TLS certificate inside the car away from being bricked.

Ao7bei3s··on Command injection and backdoor account in D-Link NAS devices
Exactly. A more modern secure approach is to let the init system open the socket and pass it as an FD. This has some side benefits too (not even temporary root for daemon, less custom code, standard&declarative config, socket activation).

(Of course Unraid, being based on Slackware, has a legacy init system that doesn't support this scheme. But there are enough other options.)

Ao7bei3s··on Command injection and backdoor account in D-Link NAS devices
Unraid is not confidence inspiring either. It's just more commercial closed source software, developed behind closed doors and with a slow update cadence (~3 months). They have made questionable security choices anywhere you can see, and I have strong doubts that their code quality is any better.

The PHP scripts certainly are a horrible mess, in all ways. For example, shell injection prevention is based on using escapeshellarg at each call site... that pattern is _exactly_ the structural root cause for vulnerabilities like the one D-Link had.

In no particular order, and obviously not exhaustive: Everything runs directly as root - nginx, php-fpm, smb, ... No AppArmor/SELinux. There is no Secure Boot support (especially unfortunate since boot is from USB stick). No HTTPS access to web frontend by default. SMB protocol defaults are insecure. SMB shares default to public. SSH allows password-based root login. Pools are unencrypted at rest by default. They have a checkbox to enable telnet for management! Very permissive iptables rules. Almost any features that real competitors like Synology would officially provide come from third parties via a moderately shady app store.

Note it's not about any of these individual points. I see above as signal that they are not security experts and see security as an afterthought, rather than as something that deserves a team of experts that specifically cares about it.

(There's certainly other fields they also aren't experts in, like UX - their predominant UI pattern is "list of dropdown fields". Even in storage, one could have a longer discussion how their Array feature - the true core of their product -, compares to modern solutions. There's a reason they've evolved cache pools to just pools as a separate thing, and some users do pool-only Unraid...)

That's all quite understandable since it's a small team with only 2-3 coders (https://unraid.net/about). But nevertheless.

Ao7bei3s··on Police are tagging fleeing cars with GPS darts to avoid dangerous pursuits
I don't know anything about UK law, but apparently the act still allows for 92 hereditary peers[1], and indeed:

"The most recent grant of a hereditary peerage was in 2019 for the youngest child of Elizabeth II, Prince Edward"[2]

[1] https://en.m.wikipedia.org/wiki/House_of_Lords_Act_1999

[2] https://en.m.wikipedia.org/wiki/Hereditary_peer

Ao7bei3s··on These RC Helicopter Acrobatics Aren’t AI Fakes, If You Can Believe It
To be clear, I don't want to imply they're useless though. Velocidrone, DRL and Liftoff (I haven't tried Uncrashed yet) all have good enough physics for real use cases, and are widely used.

- As a beginner, they help you crash less. You can learn enough basics to save some real money in avoided crashes. The sims pay for themselves right away, you can just buy them all. The sim-isms don't matter so much.

- As a skilled pilot, they help you crash more. You can safely iterate on your maneuvers really really well (no repairs, immediate retry from same conditions, always good weather, fly from home). You'll have an idea where the differences are and how you need to compensate with the actual craft. You can tune the virtual counterpart to be a bit closer.

They complement real model flying, they just cant replace it. (And even that is questionable. I bet many just can't afford real model flying. Sims might help them scratch the itch.)

A _really accurate_ flight sim is actually hard to do though, for a few reasons. Aerodynamic modelling is hard (there are lots of interesting effects), and that almost every model aircraft is unique (due to home building) and constantly changes (crashes, repairs, upgrades) probably doesn't help. And neither does that the core idea behind multirotors is unstable flight, which entirely depends on the firmware. There are different firmware projects (Betaflight is the most popular for racing, but not the only), and they are quite tunable. Can't simulate that accurately; it would have to be firmware in the loop.

Ao7bei3s··on These RC Helicopter Acrobatics Aren’t AI Fakes, If You Can Believe It
The obvious difference is that the throttle axis on RC transmitters is not self-centering. 0% is at the bottom, not in the center.

But beyond that, the stick throws are much larger than e.g. on an Xbox controller, there's much finer feeling, the end stops are harder, the sticks can be held differently (search "thumbing vs pinching", both are used irl but the latter gives finer control). It's just so different. And you can't compare at all to using two full sized joysticks, which would mean full wrist movement.

Also, cheap gaming joysticks are terrible. Two high quality ones (VKB NXT or better) cost more than a high quality RC transmitter. It does not save money.

Physics aren't really realistic. They're all enough to get the absolute basics down (e.g. that camera uptilt means that pitch left/right needs a corresponding yaw input to keep the view straight). But then different simulators vary. The most common, fairly ubiquitous complaint, is that it's too floaty (real quads drop much faster without throttle). It's not just due to bad physics, it's also because to be commercially successful they have to appeal to gamers too, maybe even primarily. Then there's the finer points, like wind, descending into your own chaotic vortex, or how easy you crash when you touch anything (sims are sooo forgiving).

And of course every quad is different, 1" 1S, 3.5" 2S Li-Ion and a 10" 4S handle substantially differently, but if you haven't flown any for real then you won't know what is right.

(If you're looking for a radio, unless you know what you want, just buy a TX16S please.)

(There are exceptions to everything I said above. But this is the common case.)

Ao7bei3s··on NixOS-generators – Collection of VM and Container disk image builders for NixOS
I've recently been experimenting with nix generators. It's nice.

What's the most pleasant way to develop and build nix images if your dev env is a regular Linux distro without nix installed?

So far the least bad seems to be running Nixos in a VM with VS Code remote via SSH and scp'ing images around. At least quickemu makes getting the VM pleasant. But VMs are cumbersome.

Docker would be great, but nix from the official Docker container doesn't seem to like running as non-root, which means you can't use volume mounts for the code and change the user ID so that the file permissions are right from inside the container.

Ao7bei3s··on Considerations for a long-running Raspberry Pi
Does anyone know of a low power, mini PC that supports 2 or even 4 SATA SSDs (both connector and physical space wise)?

Most, incl. the Lenovo above, seem to support at best 1x M.2 + 1x SATA.

The best choice I have found is using a N100DC-ITX mainboard with a generic ITX case, and those are huge.

I am looking to replace my Raspi / USB SSDs combination.

Ao7bei3s··on AWS cancels serverless Postgres service that scales to zero
DynamoDB can't even represent SELECT * FROM items LIMIT 25 OFFSET 100. It's just not designed for that. It's not meant to be a relational DB replacement.

How would you do it? Assume we want proper pagination, and not rewrite the app for cursor based "Load more" style pagination. Why? Because the React Admin provider API insists. https://github.com/marmelab/react-admin/issues/1510

Ao7bei3s··on How I obtained a business manager visa in Japan
Can't speak for Japan, but in the US, the immigrant does have the burden of proof that all requirements are satisfied and not submitting enough evidence can lead to a request for evidence (RFE) or notice of intent to deny (NOID). And so the law firm we used had the opposite strategy: submit as much evidence as possible and really help the adjudicator check all the boxes. Our petitions tended to be 250-500 page documents.
Ao7bei3s··on Comp Sci in 2027 (Short Story by Eliezer Yudkowsky)
If you enjoyed HPMOR, you'll probably enjoy this very detailed, criticial review of HPMOR.

https://danluu.com/su3su2u1/hpmor/

Ao7bei3s··on DHS to Propose Amending H-1B, F-1 Regulations
Unfettered would look like in the 19th century: arrive on a boat, spend a few hours on Ellis Island for a basic medical check and review of your paperwork with answers to 29 questions, start your new life.

(Source: https://www.statueofliberty.org/ellis-island/overview-histor...)

Ao7bei3s··on Curl/libcurl HIGH CVE-2023-38545 leaked early?
I disagree on so many points.

* Buffer overflows tend to lead to remote code execution which is the most serious outcome and should always be treated as serious by default.

* libcurl is absolutely everywhere, not only in corporate networks.

* There is no such things as a trustworthy network; corporations are moving away from that model as it just doesn't work (zero trust). I can think of plenty of ways a motivated attacker might get L2 access to a corporate network if they aren't too picky about what they get access to, when and how long.

* Users can connect work devices to non-corporate networks. The generic example used to be coffee shops, now there's WFH.

* Non-corporate users matter too.

* Horizontal privilege escalation. Chaining multiple exploits into a successful attack is table stakes for modern attackers.

* It was only an example. There is a long history of people (especially those employed by companies with vulnerable products, though that's not the case here) being dismissive about exploitability and wrong about it.

If you want to critique my comment, point out that libcurl didn't actually merge libproxy which would've brought WPAD support... but my real point is that one should not dismiss a buffer overflow in libcurl.

Page 1 of 12Next →