HNHacker News
TopNewBestAskShowJobs

DecoPerson

1,371 karma · joined June 28, 2013

Ex-game designer
submissionscomments
DecoPerson··on Nested String Interpolation in Groovy
The syntax highlighter not understanding GStrings (heh) doesn't help here.

It's obvious once you release that whatever is inside a GString is simply an expression.

    def expr = foo."${baz}"
    println("Bar value: ${expr}")
This makes sense.

But this, or any of the other variations...

    def expr = foo." + baz + "
    println("Bar value: ${expr}")
...does not make sense.

If the syntax highlighter understood GStrings, then this would be obvious.

Let S be string colour and _ be non-string colour:

    println("Bar value: ${foo."${baz}"}")
    ________SSSSSSSSSSSSSS____SSS___SSSS_
DecoPerson··on Everything that's wrong with Google Search in one image
They seem to classify users in a way that puts technically-proficient users in a separate class to regular users.

One class receives a more traditional experience.

The other receives whatever they're currently pushing. For example, my Dad's Gmail has a much higher "ad email" : "real email" ratio than mine. Also, the styling of an "ad email" line is far more subtle than what I receive.

I checked with my technical friends. They all receive similar experiences to what I do. But my parents and other people I help with their personal tech receive the ad-heavy version.

My conspiracy theory is that they're trying to detect journalists, lawmakers, regulators, and more, in an attempt to avoid being forced to push ads less aggressively.

DecoPerson··on I feel Apple has lost its alignment with me and other long-time customers
AussieBroadband (who use Optus wholesale). I love 'em, and literally my only complaints after years of using them are:

- lack of eSIM support

- invoice/statement layout hard to read

- businesses can use the residential NBN plans but they don't display correctly on their Carbon business portal

- some advanced mobile service control codes to configure message bank, call forwarding, etc, don't seem to work

Everything else about them has been perfect. Great service, reasonable prices, perfect reliability (zero downtime AFAIK!), and Australian-owned.

(Gonna chuck my AussieBroaband referral code here in case this convinces someone to switch! 13610811)

DecoPerson··on I feel Apple has lost its alignment with me and other long-time customers
Some small carriers in Australia don't support eSIMs, even though they're required for Apple Watches and other devices, and also second phone numbers in phones without dual SIM card trays.

I'm hoping that the iPhone Air will make them prioritise eSIM support!

DecoPerson··on Emailing a one-time code is worse than passwords
The attack pattern is:

1) User goes to BAD website and signs up.

2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.”

3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email.

4) GOOD sends a one-time login code email to the user’s email address.

5) The user is very likely to trust this email, because it’s from GOOD, and why would GOOD send it if it’s not a proper login?

6) User enters code into BAD’s website.

7) BAD uses code to login to GOOD’s website as the user. BAD now has full access to the user’s GOOD account.

This is why “email me a one-time code” is one of the worst authentication flows for phishing. It’s just so hard to stop users from making this mistake.

“Click a link in the email” is a tiny bit better because it takes the user straight to the GOOD website, and passing that link to BAD is more tedious and therefore more suspicious. However, if some popular email service suddenly decides your login emails or the login link within should be blocked, then suddenly many of your users cannot login.

Passkeys is the way to go. Password manager support for passkeys is getting really good. And I assure you, all passkeys being lost when a user loses their phone is far, far better than what’s been happening with passwords. I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money.

DecoPerson··on SQLite Date and Time Functions (2007)
One huge benefit of using SQLite over a traditional server/client DBMS is the ability to easily add SQL functions that call into your host language and memory-space.

For example, we’re using better-sqlite3 which has a convenient API for adding SQL functions [1], and we have dozens of helper methods for dealing with time using the temporal-polyfill module.

We have custom JSON-based serialisation formats for PlainDate, PlainTime, PlainDateTime, ZonedDateTome, etc. Then in SQL we can call ‘isDate_Between__(a, b, c)`.

a, b, and c are deserialised by the JS (TS) function, the logic is run, and the result is returned to SQLite. We’ve had no performance issues with this approach, though we’re only dealing with simple CRUD stuff. No big data.

You can even use these functions with generated columns and indexes, but I haven’t found a proper use for this yet in my work.

[1] https://github.com/WiseLibs/better-sqlite3/blob/HEAD/docs/ap...

DecoPerson··on Ask HN: Selling software to company I work for as an employee
If it’s outside your job description, you’re not obliged to do anything.

You’re not a slave. You can say no to your boss. You’re on equal footing (though your boss generally has more power/wealth so can bully/manipulate you). It’s up to your boss as to what they do when you say no. If you’re a good employee when it comes to your usual responsibilities, then they’ll keep you.

If your boss tells you to write software as part of your job and you’re not a software engineer, you can tell them to get stuffed (or sign the contract and both parties benefit!).

Edit: I just re-read the original post and saw that the OP is a software engineer. Ignore everything I said. This sounds like a terrible idea. You’ll burn all your bridges if you pursue this avenue.

DecoPerson··on Ask HN: Selling software to company I work for as an employee
Just write a clear and concise summary of a contract.

“You get: [these features]”

“I get: [money and the IP]”

“We measure success and payment milestones are triggered by: [Clear KPIs and deadlines]”

Make sure the 1-2 page doc has your name on it, and ask your boss for permission to drop a paper version on the desks of the higher ups.

You can be employed and enter into a separate contract.

Edit: I just re-read the original post and saw that the OP is a software engineer. Ignore everything I said. This sounds like a terrible idea. You’ll burn all your bridges if you pursue this avenue.

DecoPerson··on Chrome Origin Trial: Device Bound Session Credentials
User asks (human) Assistant to login to their online banking and make a transfer. No problem. No digital security system can stop this (bar requiring true biometrics on every sign-in, which isn’t happening soon).

User asks Company (with human staff) to login and do the same thing. Perhaps the company is an accounting firm, a legal firm, or a “manage my company for me” kind of firm. No problem.

User asks Company which makes self-hosted business management tools to login to their online banking. Oh shit!!! This is a violation of the ToS! The Company that makes this tool is violating the bank’s rights! The user doesn’t understand how they’re letting themselves get hacked!! Block block block! (Also some banks realise that can charge a fee for such access!)

Everyone on HN sees how that last case — the most useful given how great automation is these days — should be permitted.

I wish the governing layers of society could also see how useful such automation is.

These Device-Bound Session Credentials could result in the death of many good automation solutions.

The last hope is TPM emulation, but I’m sure that TPM attestation will become a part of this spec, and attestation prevents useful emulation. In this future, Microsoft and others will be able to charge the banks a great deal of money to help “protect their customers” via TPM attestation licensing fees, involving rotation, distribution, and verification of keys.

I’m guessing the protocol will somehow prevent one TPM being used for too many different user accounts with one entity (bank), preventing cloud-TPM-as—a-service being a solution to this. If you have 5,000 users that want to let your app connect to their Bobby's Bank online banking, then you’ll need 5,000 different TPMs. Also Microsoft (or whoever) could detect and blacklist “shared” TPMs entirely to kill TPMaaS entirely.

Robotic Process Automation on the user’s desktop, perhaps in a hidden Puppeteer browser, could still work. But that’s obviously a great deal harder to implement than just “install this Chrome extension and press this button to give me your cookies.”

Goodbye web freedom, and my software product :(

DecoPerson··on Attacking My Landlord's Boiler
The Flipper Zero is great, and could handle all of the hacking/investigation part by installing custom firmware.

The original product understandably arrives with heavily-restricted firmware (I imagine to reduce the amount of flak the company receives). However, it is incredibly easy to install Flipper Unleashed or similar, which removes all said restrictions and adds a lot of additional functionality.

Possessing the tools that could be used to commit a crime is not necessarily a crime in and of itself! Just be careful with what you do or, depending on what country you’re in, you might find some men in suits knocking at your door.

Personally, I wanted to replay “encrypted” 433MHz signals for my own devices (electric gate, roller door, roller shutters, …) and this was disabled with the Flipper’s region set to Australia.

DecoPerson··on React for Two Computers
Author invents a programming language where the code is server-side JSX tags ("Early World") and the runtime evaluation is divided into as multiple lazily-evaluated stages ("Late World") in the browser.

Author unfortunately fails to justify or provide a demonstration that justifies the increased complexity over current methodology.

Interesting exploration of an unexplored space, but should be more concise (and use either better or no attempts at humour).

> In the Early world, you dissolve all the Early Components with interpret. This gives you a string that represents how to finish the computation in the Late world: [code]

> In the Late world, you parse that string, load the references, and then dissolve the Late Components with interpret. That leaves you with a tree of Primitives: [code]

> Finally, those Primitives are ready to be turned into DOM or some other format: [code]

DecoPerson··on Why can we not use AI to audit agent systems instead of human in the loop?
You can this. This is currently being done, but not talked about much.

Results vary, so it’s not one of the main courses of interest at the moment.

DecoPerson··on Car tires shed a quarter of all microplastics in the environment
Manufacture in country A and sell in country B. Or vice versa.

But never manufacture and sell in the same country, or the government might try to get you to pay for your negative externalities!

And now, there’s this annoying predicament where as you introduce more laws and more enforcement, you only cripple your own economy and rarely cause any significant improvement along the lines of what you hope. Look at Australia — we have all these appliance safety laws, but all of the appliances are made overseas and there’s no good point for the government to inspect and enforce compliance with those laws. I just bought a generic vacuum sealer from an online shop the other day. It was cheaper than buying at a brick & mortar store, even with delivery, and it definitely does not comply with Australia safety standards.

We’ve killed our local industry, and our economy is suffering for it. I don’t think the answer is to remove the safety/etc laws, but instead to tax all imports enormously. Be aggressive and unfair so that local industry is immediately viable. It’ll be painful, but it’s what most countries need. Comparative advantage turned out to be a terrible basis for international trade.

DecoPerson··on SQLiteStudio: Create, edit, browse SQLite databases
Be very careful using this over Samba, even with WAL mode enabled. I corrupted an important testing DB this way. Thankfully .recover came to the rescue and only a small amount of data was lost (but the test team had to wait a couple hours for me to bring the test environment back online).
DecoPerson··on Wooden satellite heads to space in Mars exploration test
Outer Wilds was accurate!

Wooden spaceships, helmets, and other contraptions, augmented with metals and… other “spoiler” materials.

To anyone interested in space with a day or two to spare, I highly recommend playing Outer Wilds. It’s very good and unlike any other game (and I can’t explain why without spoiling the magic).

DecoPerson··on Sets, types and type checking
Sharing my TypeScript Result type for anyone who’s crazy like me and wishes they had “if let” and doesn’t want “.value” everywhere.

You can do this:

    const user = await fetchUserDTO(123);
    // user is Result<UserDTO, Error>
    if(!isOk(user)) { something(user.err); return; }
    user.name; // user is narrowed to UserDTO
Source:

    export const FailSym: unique symbol = (globalThis as any).____FailSym ?? Symbol('FailSym');
    (globalThis as any).____FailSym = FailSym;
    export type Result<T, E> = T | {
        [FailSym]: true,
        err: E
    }
    
    export function Ok<T>(val: T): Result<T, never> { return val; }
    export function Fail<E>(err: E): Result<never, E> { return {[FailSym]: true, err}; }
    
    export function isOk<T, E>(val: Result<T, E>): val is T { return !(typeof val == 'object' && val != null && FailSym in val); }
    export function isFail<T, E>(val: Result<T, E>): val is Result<never, E> { return typeof val == 'object' && val != null && FailSym in val; }
    
    export function resultify<T, E>(promise: Promise<T>): Promise<Result<T, E>> {
        return promise.then(Ok, err => Fail(err as any));
    }
DecoPerson··on "Everything" is a filename search engine for Windows
I’ve used Everything 1.5 and Everything Server 1.5 for our small business to help our employees find files on the SMB file share since about 2022. It has been very good. People don’t have to waste time doing deep folder hierarchies. They’ve settled on “DATE Rough description” folders with a bunch of documents inside relevant to that “task”. These task folders can be forgotten, but with good folder and file naming, are easy to stumble upon later using Everything when we need info on an old task/project/etc.

The new Microsoft 365 stuff is so shiny, but the poor integration with traditional SMB shares is incredibly frustrating. We now have two split areas of documents: SMB and “The Cloud”. Nothing they offer for SharePoint/OneDrive Business/Azure gives proper integration between old and new.

Even worse, the new documents are often silo’d into specific user’s personal OneDrive which is basically undiscoverable by default. The old workflow of choosing a place to save the document early kept documents visible and rapidly shared. Now someone could be drafting a document for days before others even see it. Or they could forget to ever move it from their personal space to a team/shared space.

sigh

I’m thinking I’ll code a simple tool that creates hyperlinks to SharePoint in SMB.

DecoPerson··on Google Gemini tried to kill me
good assumption + confirming response = ok

good assumption + negative response = ok (research)

bad assumption + negative response = ok (research)

bad assumption + confirming response = uh oh

I also use LLMs every day, but you must be very self-aware well using them otherwise they can waste a lot of your time.

DecoPerson··on Their bionic eyes are now obsolete and unsupported (2022)
Public trustee. That’s how it works with other assets, like apartment buildings with people living in them. Often public trustees will outsource the management & disposal of these assets. Hopefully for the people depending on the assets, “disposal” means “sale to a new owner.”
DecoPerson··on Passkeys: A shattered dream
Try Keepassium on iOS. It removed my need to “cache” anything in the keychain.
DecoPerson··on Disney to take $1.5B stake in Epic Games
Epic Games is not just games anymore.

Take a look at how The Mandalorian (a Disney production) was filmed. Epic Games’ software played a large part.

It goes beyond just film & television. They offer solutions for the automotive industry, aviation simulation industry, mining sims, trucking sims, medical sims, architecture, live broadcast, …

Hmm, I think I might invest if I can!

DecoPerson··on Evolving the Infinite Canvas
This appears to be exploration, to see if we can find new useful ways to display and interact with information.

There have been many, many experiments in the past. Design features that work (such as listy designs, tabular designs, 2D designs, non-overlapping designs, etc etc) have stuck around. By "work", I mean that they are useful, practical, easy to understand, easy to implement, non-patented, etc etc.

If we stop experimenting, then we will stop finding new useful design features and UI design will stagnate.

Yes, current UI design is "good enough." But where's the fun in that? Whatever you believe the purpose of life is, experimenting and furthering humanity's knowledge is typically considered a good thing.

I think that this particular experiment is useful, and that there is potential here for more efficient note-taking and knowledge sorting (which could, in the future, potentially benefit everyone). Imagine an author writing plot point ideas into an infinite canvas, then assembling them on the fly. And then they bring those points into a second canvas, where they group them by character. Then they can freely move the plot points between characters, or leave them to the side, not assigned to any character but there, on the "plot points by character" canvas, ready to be dragged on. But then if they're looking at the plot points on the "plot points by time" canvas, and they set a plot point's character to "X", then it will automatically move that plot point into the region of character "X" on the "plot points by character" canvas.

That's just one example. I can imagine more, such as a materials researcher trying to design an industrial process. They could be working through potential chemical products, trying to decide which to use at a particular point of the process. This freeform canvas would let them keep a card for each potential choice right next to the place in the process that it would be used. That proximity of information could be useful.

I've found that Blueprints (a 2D scripting language) in Unreal Engine get really messy, and you're constantly neatening your programs. This particular experiment, with its anti-overlap and automatic grouping features, might lead to good changes in Blueprints in UE that make them neater by nature.

DecoPerson··on Show HN: An open-source, self-hostable synced narration platform for ebooks
> Once we have individual tracks to work with, we begin transcription. This is the most resource intensive part of the process. We rely on the Whisper AI transcription model from OpenAI, via WhisperX. The WhisperX project also uses wave2vec2 to provide accurate word-level timestamps, which is important for sentence-level synchronization. The transcription process is fairly standard; the only interesting addition to the process that Storyteller makes is to supply an "initial prompt" to the transcription model, outlining its task as transcribing an audiobook chapter and providing a list of words from the book that don't exist in the English dictionary as hints.

https://smoores.gitlab.io/storyteller/docs/how-it-works/the-...

DecoPerson··on DocuSeal – Open-source Document Signing
(I’m not a lawyer.)

Some lawyer friends I have (here in Australia) have told me that electronic signatures (of the kind like DocuSign and Adobe Sign that have you “adopt” a digital signature and click a “Sign” button) should only be used in situations where the other party’s actions soon after signing will confirm their intention to be bound by the document.

For example, if there is a sales contract and the buyer proceeds to pay the money, then that payment shows intent to follow the purchase agreement.

Or, if someone sends an email after signing saying “All done. I look forward to working with you.” — that has the same effect.

To use it for something where the other party will be doing nothing for a long time (like a guarantor on a loan or lease) or acting unpredictably (like a house tenant) would be very risky. The other party could easily use the defence of “I didn’t click the button… I didn’t even know about the contract.” even if they did know and did click the button.

So why use a digital signing system? Efficiency!

It’s quicker and easier. You can get dozens done with the same time & effort it takes to arrange a single wet signature. It’s multilingual. It’s automated. It’s fancy!

Having any signature, whether wet or digital, shows that your side is following proper process. The signing of a document is an important moment, and the specific date & time often has real commercial, accounting or legal ramifications. Even if you could easily show to a court that the other party has “agreed” without signing (e.g. via email, text, phone, etc) and is acting in accordance, it’s better to just avoid the court in the first place.

To summarise:

Wet signatures are best. The other party would be crazy to challenge them.

Digital signatures are better than just an email saying “I agree.” The other party would have to be brave to challenge one.

An email saying “I agree” is better than a handshake.

(Again, I’m not a lawyer! I would love to hear a lawyer’s opinion. Though, please do so anonymously — I don’t want anyone getting in trouble!)

DecoPerson··on Biscuit authorization
JWTs are complex.

Encrypted session cookies are a proven solution, widely used, and easy to implement yourself using only core libraries (http, crypto, JSON) without introducing security flaws IFF you are an experienced programmer and don’t deviate from the norm.

JWTs are complex. Too complex to implement yourself, so you need to introduce dependencies. Dependencies are usually huge, and each line of code introduces risk (even if that line is for a configuration you don’t use!). Using JWTs at all is far more risky, even if you are an experienced programmer.

If JWTs provides immense benefits over session tokens for your use case, that risk might be worth it. However, for most web apps, session tokens are good enough.

DecoPerson··on New insights into neural end-of-life
A1 is a parent of A2, and A2 a parent of A3.

A1 has a genetic trait that makes old age a terribly painful experience, and the moment of death a horrifying ordeal. Far worse than what most experience.

A2 becomes scared of death. As A2 gets older, they behave chaotically because of the trauma from watching A1 die painfully and the fear that they’ll experience the same fate.

A2 does not take good care of A3.

I hope this example (unscientifically) shows that there are likely some strong trends toward genetic traits that support a peaceful end of life period.

I suspect there are also multigenerational trends toward older members dying before they become a drain on a tribe’s resources. An obvious historically-useful benefit, that now leaves us worried sick about our aging parents (that they’ll slip and fall, and activate the “end of life” phase, where they’d have passed away if it weren’t for medical intervention).

DecoPerson··on Biscuit authorization
Include an expiry time in the encrypted part. The encryption, and the fact the token decrypts invalidly if not encrypted with the correct key, acts like a discount JWT.

Encrypted session tokens with embedded expiry will serve the needs of 99% of applications/services.

DecoPerson··on Building Node.js applications without dependencies
If you’re OK importing node’s internal modules [0], which I believe are loaded anyway, you could achieve a lot, though it definitely wouldn’t be worth it.

No developer is an island. [1]

[0] https://github.com/nodejs/node/tree/main/lib/internal

[1] https://youtu.be/TY9xsT6S75A?si=uqPUuxKNl_1vqMhm

DecoPerson··on Ask HN: What apps have you created for your own use?
Using TypeScript + Node + esbuild + my own build system (that lets me do hygenic macros!! and also codegen), I have made:

Accounting system (creditors/payments, debtors/billing, bank reconciliation) with optimised workflows suited to our businesses (which exports to Xero so we have a “real” accounting system too). Has a touch of AI — I use ChatGPT to help with bank reconciliation.

Lots of tools related to the above. Like automating budget reports and stuff.

“megasearch” which is just a lightweight interface that wraps full text search queries of Everything (for files), Microsoft Graph (for emails, tasks & calendar), and Fuse.js (for iMessages, Telegram, & WhatsApp messages that I manually import). I really want to automate message importing, and I really really want to make this search actual file contents (alas Everything gets slow if you index content), and I really reallly really want to make this use a vector DB and AI search!

“video-clone” — paste any video url and it downloads it using yt-dlp, uploads it to my file server, and gives me a public URL.

Parcel inventory system for our post office. This was the most involved. I made an Android app AND REGRET USING REACT NATIVE! Version 2, which is nearly done, is a simple Java app with a web view. Version 1 has been used by staff since September 2022, handling thousands of parcels per day, with very little maintenance! It’s mostly a CRUD app, but I’m quite proud of it.

I also use this Node platform for random stuff — like one-off scripts for scraping web content, or crunching some spreadsheets in a way that’s annoying to do with just formulas or Excel’s other features.

Having an environment that is batteries-included, debugging-friendly, logged, connected, scheduler’d, web UI’d, CLI’d, etc, plus that I’m familiar with makes programming far more suited as a pocketknife tool. Oh, especially when it comes to dates, times, and datetime formatting! TC39 + my helper methods = less fear of dates

DecoPerson··on Don't disable buttons
Good advice!

I go one step further with buttons in my own React UI library, and I wish all UI libraries did the same:

When a button is “disabled”, it should show why either on hover or on click.

It’s a common frustration in software, especially complex ones like Adobe Photoshop or Autodesk Fusion 360, where a button is disabled and you cannot figure out why. For example: you can’t fill because it’s a “smart layer” and you need to rasterise it. Or you can’t “join” because both CAD bodies are fixed.

The programs KNOW why the button is disabled — otherwise how would it know to disable the button! So show the user why!

This alone would save countless person-hours and reduce a lot of frustration.

← PreviousPage 2 of 9Next →