HNHacker News
TopNewBestAskShowJobs

ItsBob

538 karma · joined December 8, 2021

https://hockeytastic.com

I built it originally for my son... It uses sports psychology and research-backed cognitive science to completely transform off-ice stickhandling practice. It brings elite cognitive load training, usually reserved for expensive sports science labs, right to your home. My son loves it. His coach constantly talks about his stickhandling and it's clear that he's benefitted from it. Anyway, if you want a shot, let me know as right now it's in testing and you can have a really long free trial :)

hello@hockeytastic.com

submissionscomments
ItsBob··on Anthropic takes $5B from Amazon and pledges $100B in cloud spending in return
I think you're right. I think they are tightening the noose!

I use Gemini quite extensively - I have a 5TB storage plan with Google so I get Pro thrown in. I also have Github Copilot Pro for IDE integration.

However, lately it feels like I keep tripping the circuit breaker on Gemini more easily and get the message about using up all my Pro tokens for the next 3 hours.

I used to be able to work most of the day before it hit the brakes but I can trigger it before work in the mornings now... that seems to me like they're tightening the usage limits!

I use a Dell Micro PC with an Intel Core Ultra 265 so it's nice and fast but it has no GPU, hence the reason I use Gemini but I'm now starting to think that, despite the RAM cost, before the end of the year I'll buy a PC with a monster GPU in it and run all my AI locally... the direction of travel is clearly heading towards a massive cost increase so might as well get ahead of it: it's not going to become cheaper, that's for sure!

ItsBob··on Atlassian to cut roughly 1,600 jobs in pivot to AI
I'm curious how you use Sheets as a Trello-like replacement. I use Trello from time to time but my most recent project is using actual Post-It notes stuck to my monitor, wall etc.

If Sheets works (I love simplicity) then I'll give it a go but I checked and I can't find any templates for Kanban or such.

ItsBob··on Jolla phone – a full-stack European alternative
Just an FYI... I don't know what their service is like but they won't respond to my emails asking for a refund so, tomorrow I have to contact my CC provider now. Not happy :-(
ItsBob··on Firefox 148 Launches with AI Kill Switch Feature and More Enhancements
Maybe it's just me but why is it on by default? Why is this shit not off in the first place? Why can't Firefox just be a browser with great html, css, js rendering and then have a bunch of toggles for extra crap that people want? Do they actually have metrics that show "When we enable this crap by default we make an extra $X Million per year"? I'd put money on that being untrue. I bet it's like the data-driven ad spend - I've yet to see anything that proves that hoovering up bajillions of data points on each person moves the needle on spending beyond just showing a context-relevant ad, e.g. An ad for fishing gear on a blog post about fishing gear!

Honestly, I feel more and more every day like old-man-shaking-fist-at-clouds! Can we not just have something that works without spying, without engagement-driven shit switched on all the fucking time?

I think of the Simpsons Mr Brown meme where he's asking "Is it me that's wrong?".

I can't be the only person that thinks this way!

ItsBob··on Mobile carriers can get your GPS location
Yeah, Nationwide has the little PIN code device which definitely helps with transactions but not logging in: that's still old-school.
ItsBob··on Mobile carriers can get your GPS location
I can tell you with almost 100% certainty: no banks in the UK use any 2FA other than SMS-based.

I spent December last year looking for a new bank to move to. One of my criteria (not the most important but it was on the list) was better-than-SMS 2FA.

No one offers it. There may be some niche, loosely-based finance org that does but none of the banks or Building Societies do.

So, unfortunately, you need it in the UK.

ItsBob··on Ask HN: Is it still worth pursuing a software startup?
> Considering there is very little moat left in software and big companies can copy your product in no time?

Having worked in the corporate world all my working life I can safely say with confidence that big companies absolutely DO NOT move fast. Do not underestimate the power of middle-management to destroy momentum!

Solve a problem for someone and if it was a painful one, they'll pay you for it.

ItsBob··on HP Reveals Keyboard Computer with Ryzen AI Chip
If you scroll further down, there's an image of a woman holding an opened keyboard with a SODIMM in her other hand so I'd guess that means it's user-swappable.
ItsBob··on Ask HN: What skills do you want to develop or improve in 2026?
Two things for me:

1. Develop discipline around the piano

2. Build my side hustle beyond a side hustle (Kopi - replicate a production DB schema and relational subsets of its data for local development in seconds)

ItsBob··on Jingle Bells (Batman Smells): An incomplete festive folk-rhyme taxonomy
My wife and I had a good chuckle at these. The one we both remember is the one about Penguin losing his lollipop and buying a Milky Way.

However, we both agreed that when comparing the UK(ish) and US(ish) variants, the UK ones are much more fun and colourful: The US ones seem a little, erm, boring!

ItsBob··on Ask HN: What Are You Working On? (December 2025)
I'm working on something called Kopi: a CLI tool that replaces the slow process of restoring massive production database backups on a dev machine with a "surgical slicing" approach, spinning up lightweight, referentially intact Docker containers in seconds: It spins up the exact schema of your source db and generates safe, synthetic datasets in seconds. It can, if you want, also replicate the actual data in the source DB but with automatically anonymized PII data.

It can replicate a DB in as little as 9 seconds.

It's Open Core: Community Edition and Pro/Enterprise editions.

Still a WiP --> https://kopidev.com

ItsBob··on Windows 11 adds AI agent that runs in background with access to personal folders
I'm replying to you from Windows 11 IoT Enterprise LTSC courtesy of massgravel (or massgrave... not sure wth it's actually called now!) and it's activated until 2038.

The only thing it didn't have out of the box that I wanted was Microsoft Store (so that I could install Winget and Terminal) but you install it from an elevated powershell command with "wsreset -i" and that's it done.

It also has the original version of Notepad, not that abomination with the tabs and Copilot!

Oh, no Copilot whatsoever in fact.

All the instructions for IoT (including where to get it... legitimately) are on the massgrave github page and website.

And before I am accused of sailing the high seas... I'm not! The activation script just activates complicated processes built-in to Windows: it doesn't "hack" it or anything!

ItsBob··on I have recordings proving Coinbase knew about breach months before disclosure
I had one of those umpteen years ago with RBS. I hated it at the time too :)

However, I use a Yubikey as often as I can nowadays and authenticator apps too where possible.

I'd like the option to use one but I can't :(

ItsBob··on I have recordings proving Coinbase knew about breach months before disclosure
FWIW, I work for a major financial organization in the UK as a software architect and I've brought it up more than once over the years in various roles: not a single bank in the UK supports Yubikeys or custom Authenticator apps.

Not one (I last checked about a month ago!)

Security, while pretty good, is still lacking imo!

ItsBob··on I’m worried that they put co-pilot in Excel
I have to agree... I have no idea why I wrote that. Silly me. It's a bit of a global statement.

There are, however, definitely domains it can excel: things like entry-level call handlers... I think they're screwed in all honesty!

Edit: clarified some stuff...

ItsBob··on I’m worried that they put co-pilot in Excel
I see where you are coming from but in my head, Brenda isn't real.

She represents the typical domain-experts that use Excel imo. They have an understanding of some part of the business and express it while using Excel in a deterministic way: enter a value of X, multiply it by Y and it keeps producing Z forever!

You can train AI to be a better domain expert. That's not in question, however with AI, you introduce a dice roll: it may not miltiply X and Y to get Z... it might get something else. Sometimes. Maybe.

If your spreadsheet is a list of names going on the next annual accounts department outing then the risk is minimal.

If it's your annual accounts that the stock market needs to work out billion dollar investment portfolios, then you are asking for all the pain that it will likely bring.

ItsBob··on I’m worried that they put co-pilot in Excel
It's not as black-and-white as "Brenda good, AI bad". It's much more nuanced than this.

When it comes to (traditional) coding, for the most part, when I program a function to do X, every single time I run that function from now until the heat death of the sun, it will always produce Y. Forever! When it does, we understand why, and when it doesn't, we also can understand why it didn't!

When I use AI to perform X, every single time I run that AI from now until the heat death of the sun it will maybe produce Y. Forever! When it does, we don't understand why, and when it doesn't, we also don't understand why!

We know that Brenda might screw up sometimes but she doesn't run at the speed of light, isn't able to produce a thousand lines of Excel Macro in 3 seconds, doesn't hallucinate (well, let's hope she doesn't), can follow instructions etc. If she does make a mistake, we can find it, fix it, ask her what happened etc. before the damage is too great.

In short: when AI does anything at all, we only have, at best, a rough approximation of why it did it. With Brenda, it only takes a couple of questions to figure it out!

Before anyone says I'm against AI, I love it and am neck-deep in it all day when programming (not vibe-coding!) so I have a full understanding of what I'm getting myself into but I also know its limitations!

ItsBob··on Vanilla JavaScript
Haha, not trolling.

I tend not to use libraries for JS, preferring to write actual vanilla JavaScript, hence the reason the name rubs me up the wrong way :)

ItsBob··on Win11Debloat – declutter and improve your Windows experience
I'm not sure it is off-topic. The parent to this one was talking about, presumably, dodgy Windows keys (that shouldn't be allowed) but from my understanding, the massgrave scripts just use internal Windows mechanisms to activate.

It's not actively usurping Windows security.

In fact, I've read more than once that Microsoft tech support have been known to use massgrave scripts to help with activation-related issues with clients: Although I should caveat that with saying that it may have been Reddit I found that info so pinch of salt and all that...

So, my take on this is if the massgrave scripts allow activation without breaking any laws then sobeit. I'm talking about doing stuff that, while it appears dodgy, actually just manipulates the ultra-complicated processes under the hood that Microsoft has already built into the OS.

It's like publicising the workarounds for the now-mandatory Microsoft account when installing Windows 11. These involve things like reg hacks and commands: they're already in Windows so publicise them all you want imo.

ItsBob··on Vanilla JavaScript
I really wish this wasn't called Vanilla JavaScript... that's what I call actual JavaScript, you know, the language without libraries!

I don't normally feel strongly one way or the other about stuff but this really rips my knitting!

Note: Credit to the creators for making something and puting it out there but man, that name :(

ItsBob··on Win11Debloat – declutter and improve your Windows experience
No need if you use the IoT version and the massgrave activation script. It uses the built-in activation mechanisms in Windows to activate until 2038 or something.

I'm using the Windows 11 Enterprise IoT LTSC with activation until 2038 right now.

ItsBob··on Aggressive bots ruined my weekend
> If a client has an IP in this set, they get a simple UTF8 constant string in the response body "You have exceeded resource limits, please try again later".

Would a simple 429 not do the same thing? You could log repeated 429's and banish accordingly.

ItsBob··on Aggressive bots ruined my weekend
I admit, my approach was rather nuclear but it worked at the time.

I think an evolution would be to use some sort of exponential backoff, e.g. first time offenders get banned for an hour, second time is 4 hours, third time and you're sent into the abyss!

Still crude but fun to play about with.

ItsBob··on Aggressive bots ruined my weekend
> It's interesting to study, right?

Definitely! I wasn't experiencing any issues, hell it wasn't even for public consumption at that time so no great loss to me but I found a few things fascinating (and somewhat stupid!) about it:

1. The sheer number of automated requests to scrape my content

2. That a massive number of the bots openly had "bot" or some derivative in the user agent and they were accessing a page I'd explicitly denied! :D

3. That an equally large number were faking their user agents to look like regular users and still hitting a page that a regular user couldn't possibly ever hit!

Something I did notice but it was towards the end and I didn't pursue it (I should log it better the next time for analysis!) was that the endpoint was dynamically generated and only existed in the robots.txt for a short time but there were bots I caught later on, long after that auto-generated page was created (and after the IP was banned) that still went for that same page: clearly the same entities!

My spidey senses are tingling. Next time, I'm going to log the shit out of these requests and publish as much as I can for others to analyse and dissect... might be interesting.

ItsBob··on Aggressive bots ruined my weekend
I had a website earlier this year running on Hetzner. It was purely experimenting with some ASP.NET stuff but when looking at the logs, I noticed a shit-load of attempts at various WordPress-related endpoints.

I then read something about a guy who deliberately put a honeypot in his robots.txt file. It was pointing to a completely bogus endpoint. Now, the theory was, humans won't read robots.txt so there's no danger, but bots and the like will often read robots.txt (at least to figure out what you have... they'll ignore the "deny" for the most part!) and if they try and go to that fake endpoint you can be 100% sure (well, as close as possible) that it's not a human and you can ban them.

So I tried that.

I auto-generated a robots.txt file on the fly. It was cached for 60 seconds or so as I didn't want to expend too many resource on it. When you asked for it, you either got the cached one or I created a new one. The CPU-usage was negligible.

However, I changed the "deny" endpoint each time I built the file in case the baddies cached it, however, it still went to the same ASP.NET controller method. By hitting it, I sent a 10GB zip bomb and your IP was automatically added to the FW block list.

It was quite simple: anyone that hit that endpoint MUST be dodgy... I believe I even had comments for the humans that stumbled across it letting them know that if they went to this endpoint in their browser it was an automatic addition to the firewall blocklist.

Anyway... at first I caught a shit load of bad guys. There were thousands at first and then the numbers dropped and dropped to only tens per day.

Anyway, this is a single data point but for me, it worked... I have no regrets about the zip bomb either :)

I have another site that I'm working on so I may evolve it a bit so that you are banned for a short time and if you come back to the dodgy endpoint then I know you're a bot so into the abyss with you!

It's not perfect but it worked for me anyway.

ItsBob··on Retiring Windows 10 and Microsoft's move towards a surveillance state
Go here [0] to get the links to Windows 10 and Windows 11 LTSC.

Also, the script to activate it, go here [1] for that.

[0] - https://massgrave.dev/windows_ltsc_links

[1] - https://massgrave.dev/

I'm using Windows 10 IoT Enterprise LTSC to write this and using Massgrave(l) it's activated to 2038 or something now. The only thing I wanted that LTSC didn't have out of the box was the Microsoft Store but you install that from PowerShell with the command "wsreset -i" and wait for 30s or so :)

ItsBob··on Ryanair flight landed at Manchester airport with six minutes of fuel left
In this case, they likely had adequate fuel for, the usual eventualities but the weather in Scotland was particularly bad that night across the whole country (source: I live near Prestwick airport).

Either Edinburgh (on the east coast) or Prestwick (on the west coast) are ok (one or the other or both) but in this case neither was suitable so the nearest was Manchester - definitely an edge-case.

I don't know how much fuel they had, or if they could've fitted any more on the plane but it was unusual circumstances.

There was a military plane right behind it with the same issue that night too.

ItsBob··on OpenAI, Nvidia fuel $1T AI market with web of circular deals
If memory serves, it's shit like this that sank Global Crossing: creative accounting, I think it was called at the time.
ItsBob··on Microsoft is plugging more holes that let you use Windows 11 without MS account
Latency. It's everywhere. Open file Explorer and it lags. Change the volume and the slider lags with the example sound and just a general sluggishness compared to Windows 10.

Also updates have broken my printer 3 times (that I can remember). At least once my network connection failed due to updates.

With the resources they have, it's unforgivable.

ItsBob··on Microsoft is plugging more holes that let you use Windows 11 without MS account
I was using Win 11 for a year or so until recently but I'd had enough. It was laggy and I was scared to download updates as they break things way too often.

I understand the complexity with the Windows codebase... it's fkn massive! However, to be able to push out a Windows update and break something literally every single time is something for the history books!

Anyway, I need Windows for some of my software, like my VST's (Roland Earth Piano, XLN Audio) so Linux isn't an option unless there is something I'm missing!

I use Windows 10 IoT Enterprise LTSC with the Massgrave activation... that's me until I retire hopefully. I'd encourage everyone to do the same.

← PreviousPage 2 of 6Next →