HNHacker News
TopNewBestAskShowJobs

H4ZB7

31 karma · joined January 13, 2023

submissionscomments
H4ZB7··on The Online Safety Bill: An attack on encryption
i'm pretty sure both the article and the person you replied to are talking about verbal abuse as opposed to illegal content. and no, websites DO NOT have an obligation to make sure their content is legal. that's your own misconception as well as many judges but at the end of the day forcing people to chase intractable problems is always wrong and naive. the root problem here is that it's possible for content to be illegal, along with billion dollar brainwashing profit oriented prosecution business that made you think this is a rampant problem (it isn't).

this article is uninteresting clickbait by fake grassroots webshit crypto company that can be cracked in 2 seconds solely because their trusted code base is hundreds of millions of lines of code in 7 different languages including C. we are just here to cringe at yet another UK police state episode more than anything particular the article stated

H4ZB7··on The Online Safety Bill: An attack on encryption
the fact that such a proposal can even fly shows how broken every country is. none of them care the slightest about the freedom they so boast. banning encryption makes absolutely no sense, it's like banning whispering. or banning having a conversation and not going and writing it down after in case a police needs to audit it. the literal only reason it makes sense is when you watch a hollywood movie and you think encryption actually means something else like firing missiles. the problem is there are about 100x too many unneeded people in justice, and on top of that its half controlled by corpos who think you should go to jail for 100 years for bypassing [1] their copyright protection to decrease their losses by 0.0000000000001%, all while being a CURRENT_YEAR dogshit company like LG or Samsung or EA or Epic that produces absolutely nothing of value but has large capital

1. again, one of their key reasoning points is always that they saw a hollywood movie and they think copy protection circumvention means something else like being a ninja running into a building and quickly killing 3 people with a katana

H4ZB7··on Shells are two things
just like every component of a fully un*x braindamaged OS, the shell only gives you speed where it increase the likelihood of errors (and security vulnerabilities, lots of them). every single thing you can do in the shell is a vuln by default until you write a verbose workaround. since nobody does that, in practice the shell is just insecure and fast(ish) user experience. pl design is a big field and some C/java/sh programmer's opinion doesn't nearly represent it. even python is better than sh in every way; merely showing that it doesn't have a bunch of useful functions in scope by default (duh, it wasn't geared for that use case) doesn't prove that sh is fundamentally a good language for a console (its not).
H4ZB7··on DNS0: The European public DNS that makes your internet safer
> 100% European

but is it gluten free? /s at least it's not google or cloudflare

it's pretty funny how a completely irrelevant broken protocol that i don't actually needed (could just type the 4 IP digits) is the central talking point of politics junkies

H4ZB7··on Connecticut parents arrested for letting kids walk to Dunkin' Donuts
i didn't say the car culture cause is mutually exclusive to statism. the problem is statism, regardless of car culture. the thread does bring up a good point about the average idiot who will fall over and die the moment his company stops paying him enough for his car, but that's not the issue. the main problem here is statism, and not just statism, but extreme statism. every country today follows an extreme form of statism, not just some reasonable moderate version. this is why a cop in america has to have a gun, for instance.

and you display it perfectly, i reject the mentality where breathing has to be illegal and we all suffocate until someone makes an exception for it to be legal, and in return you use "libertarian" as an insult, like a typical wingnut. whatever, you guys can enjoy your pointless 4chan teenager tier pontificating over the connection of car culture to what will end as police cameras being installed in our homes, while i sit back and read another article about how i'm right where a 15 year old goes to jail for "misusing a computer" because computers have to be used correctly or else its illegal due to the fact that you don't live in an enlightened state like you think you do but you just look to me the same way you think some reactionary hell in the middle east looks.

https://www.bbc.com/news/uk-northern-ireland-64481598

actually, here's a better way to put it. the average person is a coward and will instantly agree with any law that purports to fight some problem that looks legit. he's also a consumer, and will buy any law that alleges to make his life more convenient. that is how law is treated today, and why we pay for way more police than necessary as well as why they think they can go make up new problems to fight. it really is that simple, after all, you either believe covid is a hoax or you believe that elementary school children need to learn that two males can have sex. none of you deserve to be taken seriously like the adults you think you are. this is a forum of webdevs who have an inflated sense of intellect due to their wage who can program as good as a 15 year old PHP hacker, after all.

H4ZB7··on Connecticut parents arrested for letting kids walk to Dunkin' Donuts
uhh no the blatant problem here is american mentality where everything is illegal by default including breathing and walking. breathing is only legal because it's necessary to survive. walking is legal but only on certain areas of land. you HNers display this mentality every single day with your latest "oh cookies should be illegal" and "oh AI should be illegal" nonsense. your narrative about car culture (the first time i heard this one) is insane and probably some left wing talking point or something, i don't read the news. normies have that pathetic mentality you describe regardless of cars. call it american mentality, not car mentality, although it's actually the same in all countries (including whatever "well designed" city like oslo or whatever you have in mind), but america invented it. tl;dr the disease is statism, not car culture.
H4ZB7··on C was not created as an abstract machine
because they don't have any. C operates on headcannon
H4ZB7··on How likely is losing a Google account?
no. whats amazing is that a bunch of people who supposedly care about such basic fundamentals like having open protocols always unanimously agree with "the company has an advanced proprietary risk analytics model to decide whether and how you get to log in. we can't talk about it because of security reasons".

well, the article is just wrong but i don't feel like going into the nuances of how identity works with a bunch of zero attention span web devs but i blame UN*X for this situation by making computers too hard to use (both securely and at all) with contraptions like email and PGP. all authentication should be done with public keys. open protocols require solid foundations which include the user being security-competent. you can layer on the "poor old dumb user" stuff on top of that, for example by letting him have a 3rd party company hold his private key. but again, this article is just wrong and scoped into very specific things people like to "debate" while having no clue about the big picture. it's absurd to even imagine that the web meta (a bunch of dot com boomers who dont give a fuck about anything other than going with the flow and creating solutions looking for problems, and knee jerk solutions to current problems) represents anything about established security engineering literature

H4ZB7··on New Distro 'BlendOS' Combines Arch Linux, Fedora Linux and Ubuntu
I thought all distros were created by 13 year olds?
H4ZB7··on Attacker with access to XML config can trigger keepass.exe to obtain passwords
business logic
H4ZB7··on Attacker with access to XML config can trigger keepass.exe to obtain passwords
gotta love how every discussion pertaining to program isolation in the last 20 years is just "well all these years i thought this thing isolates processes like it ought to do", followed by a quick, "nope, it actually doesn't". i blame UN*X
H4ZB7··on Attacker with access to XML config can trigger keepass.exe to obtain passwords
you extremely have no idea what you're talking about. the password exists because that's how encryption works, and no other reason. if your hard drive is stolen, they need the password. there is not one single other reason that the password exists
H4ZB7··on Attacker with access to XML config can trigger keepass.exe to obtain passwords
witch hunt level nonsense.

windows and linux desktops are just a bunch of programs running in shared memory and disk space. every program can read or modify the data of any other (see ReadProcessMemory, WriteProcessMemory (ptrace for linux)). simple. all these people claiming that there is an issue simply don't realize this simple fact (well, some do, but they're just even more wrong). the worst part is that devs often give into this nonsense, like they did in all those nightmarish hellscape 2003 pseudosecurity laden programs. gotta love when some program prevents me from doing something for "security" when it actually does not make security any better but is just pandering to some charlatans' concerns.

H4ZB7··on ASCII table and history – Or, why does Ctrl+i insert a Tab in my terminal?
i said open source sucks because the community is on UN*X mentality.

why does the console (it should be called console, as terminal refers to a setup that was obsolete 30 years ago) not have a proper input line? why does pasting a newline make it run? i should be able to type a command and edit it in a line that is a separate UI element from the text output. there is no compatibility argument here. only 0.001% of programs actually need to do anything other than be run and output text (and just text, not escape characters that do funny stuff). there's no dilemma that you love to imagine where changing it to work this way would cause massive incompatibility problems. we could even just make a new console called dumbtextconsole that works this way

viewing some logs from the shell is annoying as hell because the input goes into the program and once the program exits the shell runs whatever you typed. this is obviously a bad UI design. you will always have this stupid invisible buffer that you have to keep track of in your head the number of times you accidentally typed a letter there. if you ssh or tmux in, then you are more likely to enter bogus characters by accident when mistyping a command to ssh/tmux. the argument that its needed for compatibility is still moot if you only want a console for running commands. you dont need those interactive commands either. those are the most bogus hacky scripts that serve no purpose. i dont need a terminal to edit files either, that can be done with a proper GUI that runs outside the console.

it's also a security vulnerability the way shell input works. since you might paste something with a newline on the end and it will automatically execute. the idea that you should be responsible for what's in your clipboard is just bogus. you are resorting to some ad-hoc philosophy to argue this. if there was simple a proper input line where you pressed enter to run it, this wouldn't be a concern.

that one python shell.. Dreampy does this, no problem. the insane user who thinks it's a thing for some function to hijack random parts of the terminal[1] has his program break, and the rest of stuff just continues to work

this post also answers the "there are no alternatives" hackjobs in this comment chain. clearly there are alternatives, i just stated some, and once you follow this line of thought it actually leads to an entirely different OS (duh, why did i even have to state this, oh yeah, because you're disingenuous hackjobs). the fact that these people have the audacity to claim that UN*X, which is a absolutely highly specific way of designing things, that would never happen in isolation, is the only way to design an OS, proves how big of an issue this is in the software industry.

1. the insanity here being obviously that once you change random attributes about the global shared state, you have to assume other programs don't get the same idea as you and do stuff in conflicting ways

H4ZB7··on ASCII table and history – Or, why does Ctrl+i insert a Tab in my terminal?
>performance performance

UN*X does not have anything that makes it inherently performant in contrast to a sanely designed OS with one language instead of 10 that all do the same thing, a terminal emulator which is by design non performant, and a bunch of text formats that are also non performant and have bad semantics

> These small tools, with little preparation (The AWK programming language, man ksh, "perldoc perlintro"...) can do in days what for the programmers of non-Unix OSs took weeks of clumsy Python hacking.

no, it really can't. if you are string flinging on such a high level, your code is broken to hell. the reason perl awk bash sed suck so much is that they are intrinsically insecure the moment any input anywhere can be controlled by an adversary (and just wonky and gets in the user's way without even talking about security). working around that requires extreme levels of discipline that go far beyond programming in a real general purpose programming language (java, C#, ML, Pascla, Ada, etc). the moment you are able to write a secure *sh program, you are spending 3x as much time per line of code than in a real language.

H4ZB7··on ASCII table and history – Or, why does Ctrl+i insert a Tab in my terminal?
wait, you're arguing that devices should emulate a typewriter that hasn't existed for 30 years because it somehow makes them easier to debug, while this thread is about how they cause obscure problems that require you to understand escape codes to fix for things as basic as key mapping? perl does not make anything easier to debug... everytime i read perl i have to learn the subset this particular user is using, and everything in perl is a backdoor like 10x worse than bash
H4ZB7··on Heat pumps of the 1800s are becoming the technology of the future
TIL heat pumps weren't invented in the last few years
H4ZB7··on ASCII table and history – Or, why does Ctrl+i insert a Tab in my terminal?
terminal is useless garbage. i literally have PTSD from using the mouse scroll wheel while reading a man page because for the longest time there was some obscure misconfiguration or bug in my terminal or something above it: you would scroll and some random pieces of text here and there would not render. whenever i read a man page on that system, i would realize i missed an important part later on because the bug where that piece of text doesn't render was present. this isn't because graphics programming is hard, it's because the terminal is obscure error prone crap that nobody not even the most die hard hackers want to learn to configure properly (the most die hard only learn enough terminal stuff to look smarter than their peers, and stop at that)

the idea of your program not doing graphics, but instead invoking and interacting with a simulated model of a teletype (a device nobody born after 1990 even knows what is) so then the graphics stack can render its behavior to screen is completely asinine, like on the "anyone who uses this in their work should be fired" level.

i could never decide what's stupider, this or the C language. both were obsolete 30 years ago. yet diehard patriotic nostalgia tripping nerds who have no idea how software engineering works but just want to learn complicated things to look cool fought tooth and nail to keep this crap alive for decades. whenever someone says "the UN*X way", they really are saying, "I designed something modularily, you could have never thought of that", but what it really means are all these insane nonsense ideas that don't even begin to make sense, like:

  -a filesystem centric security model that doesn't even begin to address real world use cases
  -C
  -ad hoc encodings that never mattered like octal, everything being a int<my machine word size>
  -*sh
  -perl, tcl
  -terminal emulators
  -DNS
  -all these shitty little tools that compose horribly, like sed, where you have to pass --sandbox to make up for the fact that it indeed composes horribly
  -web and email, which are thoroughly embedded in UN\*X influence, and ergo, suck big time
  -X.509
this is why open source sucks and is barely a competitor to proprietary garbage running in your IoT device. in fact, every single vulnerability in them springs from these bad ideas.

i have

H4ZB7··on A command line tool that draw plots on the terminal
what's the point in all these terminal programs posted here every day? why would i ever draw stuff with text when it's just going to be converted back to pixels by the OS anyway? there's clearly a bigger reason than just being able to do stuff without the slow desktop environment. but what is it?
← PreviousPage 2 of 2