HNHacker News
TopNewBestAskShowJobs

Matt3o12_

1,387 karma · joined February 26, 2015

Hey, my name is Matteo. If you have any questions feel free to drop me a line at info@matt3o12.de

meet.hn/city/de-Berlin

submissionscomments
Matt3o12_··on Emergency SOS via satellite
So when I ride the bus or train, I'm allowed to use my phone? What about when I use an uber (or lift or any of the many many other local alternatives)?

Not everyone that moves at driving speeds is driving, especially in places outside of America.

Matt3o12_··on Show HN: Wa-tunnel – HTTP Tunneling through Whatsapp
Have you tried different throttles? Did you get any whatsapp account(s) banned at higher speed?
Matt3o12_··on Thatcher killed the UK’s superfast broadband before it even existed
Yea there are many examples of high level corruption in the german government (and most western governments actually, including the US). A recent example is the mask scandal with CDU/CSU (same party) https://www.dw.com/en/german-mask-scandal-unforgivable-viola...

You will not find much local corruption though, which is what most people think of when they hear corrupt countries. Local corruption is paying of a cop, judge, that kind of stuff. I’m sure it also happens in Germany, but that is very very rare.

Matt3o12_··on Apple Discontinues macOS Server
I haven’t seen any errors and macOS seems to handle it greacefully. You can also disable it on macOS clients for network servers individually but that seems to be a loosing battle (even if you control all clients). They are finder settings after all

https://serverfault.com/a/5567

Thumbs.db files are created on my windows 11 pc at least. They’re only created for files that have metadata that requires reading those files. Explorer likes to display the metadata (sometimes) for some folders that have a lot of media in it (pictures, music, videos, etc). If the thumbs.db file is missing, windows will partially read every media file on the server to show thumbnails, that obviously creates unnecessary load but it’s really a trade off that might not make sense for most.

Matt3o12_··on Apple Discontinues macOS Server
Assuming you’re running a smb server, you could just veto the files. Windows isn’t much better since it likes to create thumbs.db almost everywhere too (which I also veto, but vetoing them can increase the load and bandwidth requirements and your server and clients)
Matt3o12_··on A public letter to CloudFlare to fix their snoopy vendor
Getting it to work the first time was a pain. Basically, you want to disable cloudflare (just untick the box so that it goes directly to your server, you can keep using cloudflare's dns server), then obtain the normal way, and reactivate Cloudflare. But I would highly recommend using cerbot's cloduflare dns plugin[1] instead so that you can (re)create the certificate w/o disabling cloudflare.

1: https://certbot-dns-cloudflare.readthedocs.io/en/latest/

Matt3o12_··on Authenticated Boot and Disk Encryption on Linux
I believe OP is referring to the fact that a sophisticated attack has access to the hardware and you continue using it afterwards. They could, for example, change the unencrypted /boot partition to log the password you use to decrypt your partition. Or, if you sign the boot partition, they could install a hardware key logger, or do any other kind of hardware modification that defeats the security. Preventing this kind of attack is incredible difficult. They are many means to prevent those kind of attacks but, for the most part, it just making it harder for the attacker so that the attacker needs to become even more sophisticated.

Full disk encryption only helps if you are worried that your hardware gets stolen

Matt3o12_··on Marvell Announces First PCIe 5.0 NVMe SSD Controllers: Up to 14 GB/S
The heatsink doesn't really work, though, and is marketing for the most part [1].

I have a crucial P1 NVME SSD and I can make it overheat pretty reliably. Pretty much any synthetic workload makes it overload if the SSD is empty (it reaches 70° pretty quickly and even starts throttling until it reaches 80° and the whole system starts shuttering because of extreme throttling do it doesn't damage itself. Although I have not properly tested it, it seems that not using any heatsinks from my motherboard makes the temps actually better but it still overheats.

The main reason it can overheat quickly is probably because its sitting in a really bad position where it gets close to zero airflow despite being in an airflow focused case. Most motherboards place the nvme slot directly under the GPU. The main problem seems to be that the controller is overheating when it's writing at close to 2000 MB/s. It's also important to note that only the controller (an actual relatively powerful ARM processor), not the flash memory, seems to overheat.

Fortunately, this is mostly not an issue because it's a QLC drive and the workload is unrealistic in the real world. When writing to an empty drive at 2000MB/s (Queue depth 4, 128k sequential writes), it takes 2 minutes until the cache is full. The way its currently used, it takes 30 secs for the cache to become full and for write speeds to drop to 150MB/s. The only way it has every overheated in the real world was during the loading screen of a gameplay when it reached 78C quickly (and I only noticed it in the hardware monitor). If the GPU hadn't heated up the nvme drive before (it was sitting at 65C mostly idle), and starved it for air, I doubt it would have hit 60C.

So until motherboards start placing nvme where it can get some actual cooling, or they make actual functioning heatsinks, their power usage can make a difference.

[1]: https://www.gamersnexus.net/guides/2781-msi-m2-heat-shield-i... but there are many more articles/forum posts with similar issues.

Matt3o12_··on Ask HN: Is HN slow today?
I hope you don’t mind me asking but what’s the purpose of having a comment in the top to direct to different pages. There is already a more button on the bottom which makes the top comment kind of redundant.

Also a tip for others when HN is slow or almost down (like when Google was down): you can open a private tab and navigate HN from there. Since you’re not logged in, you’re served a copy from cloud flare. It’s usually out of date by 1min or so but good enough for reading in my opinion.

Matt3o12_··on Why can’t you buy a good webcam?
> The IEC 60320 connectors were specified for exactly that reason. Honestly, I don't get why these were not made mandatory for all kinds of appliances. There are even locking variants available if vibration is of concern.

I'm not sure what you mean by the second sentence but you can't use most appliances made for Europe in America and vice versa. Most electronic appliances depend on the input voltage and supplying 240V can easily cause a fire. That is true for almost all electronic appliances (water heater, fan, washing machine, etc) but not true most "computer related devices" such as a monitor, PSU, charger. Since those devices already operate on a much lower DC Voltage, they often have transformers (not sure if that's the right word), that can scale down the current from either 120 or 240. [0]

That being said, a mandatory IEC connector (and it's variances) would help a lot to cut down unnecessary e-waste. Instead of throwing away a device because the cable is damaged, you can easily order a replacement that is around $2 and high quality, instead of relying third party cords that might have bad wiring from a non reputable brand. The reason they are not mandatory, though, is that most companies like to have their own connectors so that you either overpay for it or just buy a new device.

[0]: You should still always read the specs on the input current for the device though. It is dangerous to rely on the fact that similar devices can operate at 120V/240V because yours might not. You can usually see the specs on the website/packaging or usually near the input plug.

Matt3o12_··on Cyberpunk 2077 runs on Linux through the Proton compatibility layer
> You can buy games and just play them, 1080p60 on hardware you never have to pay for.

Honestly, this worries me the most. There doesn’t seem to be a way to transfer the licenses out of stadia, which means, even though you “bought the game“, you’re still at googles mercy for your continued enjoyment of the game. What if they decide that the hardware costs are too much for Google, and you now have to pay a monthly fee? What if they decide that stadia is not the success they hoped for and close it down (which Google is not known for doing at all…). Unless there are clear migrations paths away from stadia, I’d stay away from it because Google have shown that they are not afraid to change/EOL any of their products with no regards to their existing customers (just look at their lifetime free photos service, etc)

Matt3o12_··on AMD CPU sales skyrocket with Ryzen 5000 launch, leaving Intel in the dust
This is not necessarily true. Apple sells their non Intel macs with Thunderbolt and there are some ryzen motherboards with thunderbolt support [1]. That being said, Thunderbolt is a lot less common on AMD boards probably because it is a lot more expensive then it would be on an Intel board. And Laptops so far have always received the budget treatment for ryzen chips (want a better screen? intel only, etc).

So I think lack of thunderbolt comes down to manufacturers not wanting to pay as much for their AMD R&D and keep costs down with simple, budget motherboards.

Or, if you needed Thunderbolt 3, you could just wait until USB 4 is commonplace, which is basically Thunderbolt 3 + some more.

[1]: https://www.asrock.com/mb/AMD/X570%20Phantom%20Gaming-ITXTB3... (there are more, and even ATX boards, first one I could find).

Matt3o12_··on Linux's Stateless H.264 Decode Interface Ready to Be Deemed Stable
Can someone explain the purpose of this decoder? As far as I know, decoding H.264 is already pretty solid on Linux and I don't know what benefits of making it stateless there are. I could definitely see why a stateless encoder would be beneficial (i.e. to spread out the load), but isn't decoding h.264 already a solved problem?
Matt3o12_··on Does Apple really log every app you run? A technical look
Well, the problem is that OSCP is leaking which applications you open (and when you open them) which is the big deal IMO. One solution would be that the OSCP is checking the HTTPs certificate in cleartext once upon startup (and maybe once every day or so thereafter), and is using HTTPs for all subsequent application requests.

I don't really see a problem here how that could cause a loop. This way, an attacker can only see:

- When you boot your Mac because it verifies the HTTPs certificate once.

- When the OSCP daemon makes a clear text request to check that the HTTPs cert is still ok

- That you have just opened an application (but not which application)

IMO that still leaks an unacceptable amount of meta data but it is miles better then using cleartext. Maybe a bloom filter here would be a much better solution + make the daemon regularly fetch bad signature that are not added the the filter yet instead of pulling. Sure the filter may hit false positives sometimes but in that case, the OSCP server could be checked and apple could see if a certificate has a high rate of false positives and adjust the bloom filter accordingly.

Matt3o12_··on AMD Zen 3 Ryzen Deep Dive Review
Apple also helped a lot indirectly. They have been spending billions on R&D for their SoC's and outsourced the production of the waffers to TSMC which used Apples R&D money to contribute to their 7nm and 5nm node (though Zen 3 is "still" on 7nm).

Although AMDs and Dr. Lisa Su's achievement are not to be underestimated, I doubt the 7nm processes would be as mature as it is right now without Apple.

Matt3o12_··on GitHub Warns Users Reposting YouTube-DL They Could Be Banned
In Germany it is quite common to get a fine for that (an adhortatory letter or Abmahnung in German).

Media companies monitor torrents, and as soon as they see a new German ip address seeding, they send a letter to the ISP with the IP address and timestamp. The ISPs send the law firm the real user address and then they send you a letter demanding a fine for illegally uploading copyrighted material often between 1000-3000€. If you don't pay up, they take you to court.

This is quite common and many people see letters even if they only seed for a few seconds. Apparently the easiest way is to just ignore the letters and pretend you don't live there but I wouldn't be so sure (a friend told me that's what he did and it allegedly worked but I have no experience with either).

So this is a lot less drastic but still quite as effective. And it even makes VPNs risky because disconnecting and exposing your real IP for even one second is enough to receive that letter (though not all torrents are monitored and private torrents are usually safe because the German RIAA doesnt have access to it).

I recommend you take a look at the Wikipedia about "Abmahnung" how that is even possible when the copyright holders don't sue themselves: https://en.wikipedia.org/wiki/Abmahnung

Matt3o12_··on The world needs nuclear power and we shouldn’t be afraid of it
I think the biggest problem with nuclear energy is humanity itself. We are simply not capable of making long term commitment and keeping them. Sure theoretically nuclear power is safe, especially in developed countries like the US and Europe.

But let's pretend we build a super safe nuclear facility somewhere in Europe. In the beginning we will be very vigilant. The depleted ore will be properly stored (or whatever the toxic nuclear byproduct is). Maintenance will be kept to highest standard but what happens in 20 years? During that time frame a lot can change, a country can be bankrupted, and has to cut a budget. What is a fairly rich country today might not be one in 20 years.

But let's say that doesn't happen. We also always try to optimize. Say we fill our storage for depleted ore, and we look for a new one. We figure out that we can outsource it to another country because it is cheaper. This country has the same standards we do, so we happily give it to them. But after a while they can't accept anymore so we start looking for other countries to sell our waste product to, and because we have already outsourced it once, we will probably do it again but this time at lower standards.

What I am saying is, it is really difficult to predict how we handle a nuclear plant built today, 40-100 years from now, because this is how long the lifetime of a plant and its byproducts are at minimum.

Meanwhile wind/solar/batteries has a much better defined lifetime. After only 10 years we will most likely recycle them. Yes sometimes recycling them creates unnecessary waste because some countries/companies/people will cut corners but the damage caused by improperly recycled solar and even batteries is so much lower then the damage of what a nuclear power plant can do.

So the question is, do we trust all countries that 'can safely operate a nuclear plant today' to do so in 20-50 years? What about the waste products? Can we be sure that they will always be properly stored? That every country checks their stores for leaks regularly over 100 years? And this doesn't even account for developing countries that want -- and possible need nuclear power -- to catch up to developed countries. Can we just deny it to them while we are doing it ourselves?

If humanity has proven anything, it's that we are not capable of making such decisions of a long period of time reliably.

Matt3o12_··on The Arm64 memory tagging extension in Linux
But doesn't this feature exactly help with this bug? Two memory allocations should now return different pointers (because the MTE nibble is different) therefore the comparision should fail. Unless ofcourse the application was using this undefined behavior (which would be very buggy since malloc can randomly refuse to reuse the same address even though it was freed and therefore create extremely hard and difficult to track bugs).
Matt3o12_··on Put tiny businesses back into residential neighborhoods
> It only makes sense when it's about noisy and air-polluting businesses, grocery/whatever stores and offices are absolutely great to be dispersed within residential areas!

Grocery stores (even small ones) can be very noisy, especially with extended business hours these days. I used to live In an apartment above a grocery story with a small parking lot for a long time. This was also in a mixed zone area (mostly residential, a few shops, barber, etc).

At 6am, trucks start rolling up and delivering food (although they are only supposed to do that at 7am, on some days they’ll start at 6). That means very loud beeping from the trucks backing up and shouting to the grocery employees above engine noise. Throughout the day, there will be random noise (honking in the parking lot, people slamming their cart into the barrier, etc) and sometimes people get drunk in the parking lot and start shouting (usually until 11pm, the grocery store closed at 10). And once in a while, their security system went of and the police show up and make some noise at 4am. With an open window (which you had to have in the summer — air conditioning is an exception in the part of Europe where I lived) you can hear all that noise almost as if you are standing next to it.

I never minded it too much since I’m a very heavy sleeper but I can definitely see that some people would get very poor quality sleep. And no landlord ever wants a store to be built above their apartments because it lowers the value dramatically due to the mentioned reasons.

Matt3o12_··on Gitqlite: Query Git Repositories with SQL
That seems like a really cool project, but I couldn't figure out how exactly the where filter was implemented. Can you point me to the code that implements it?
Matt3o12_··on Microsoft is shutting down Mixer and partnering with Facebook Gaming
> massive expense of data transfer

Does anyone here know how video platforms like Twitch managed to get started considering how expensive cloud data transfer pricing is? The steam bandwidth is considerably higher then video bandwidth (twitch uses a bitrate at around 8000k while YouTube has 3414k for comparable 1080p60fps videos). They also cannot take advantage of edge delivery expect for very large streamers because viewers expect a latency of 3secs or lower to their favorite stream.

I am really curious if anyone here knows how they managed to get started? They probably couldn't take advantage of super low bandwidth prices until recently because they were too small but had very expensive requirements (a lot of streamers only streaming to a very limited amount of people with high quality while also having a few very very large streamers stream to a huge amount of viewers and all of that in real time).

> It makes me doubt the profitability of Twitch, although you can be sure they are breathing a sigh of relief today.

I think twitch is highly profitable these days. Streamers have a considerable amount of subscribers, who pay a monthly fee of $5 (or sometimes even more) and stay for long durations. Twitch takes a 30-50% cut (lower depending on how big the streamer is and if twitch likes the streamer). Even streamers who average less then 1,000 concurrent viewers sometimes have between 100-500 subs.

And they have also created bits, which is a virtual currency viewers can use to tip their favorite streamers and twitch takes a similar cut (and they only let you but it in bulk beforehand to make it less transparent on how much you actually spent on them, similar to many mobile games in-app purchase model). And they play ads before streams (and during streams if they streamer decides to play them for a small cut), they also heavily advertise amazon prime (twitch streams constantly say hey you can use amazon prime to subscribe to me for free), they have premium users and probably even more monetization techniques.

Matt3o12_··on IKEA's shopping malls arm plans U.S. entry in major play
Can someone who understands tax law explain how this is legal and is continuously being tolerated? This clearly goes against the spirit of the law.
Matt3o12_··on Don’t require a user to be interested twice: lessons on reducing signup friction
What is your thread model? What’s the worst thing a spammer can do if they sign up? For most websites, what spammers can do is very limited so why are you expecting spammers to sign up in the first place?

If you really think a captcha is necessary, limit it. For example, require that a captcha is required for two account registrants with a 24h period from the same ip. Don’t require captchas for logins unless a reasonable limit of attempts has been exceeded (5 wrong passwords within 24h by the same ip for example).

If your site is small, a captcha is often overkill. A hidden input can trick pretty much any automated spam bot (if input empty, real user, otherwise bot). Just make sure you do enough research so accessibility readers also work with that field properly.

If a spammer targets you, you can always active a captcha manually, although by the time you realize it, it might be too late.

Keep in mind that a captcha only adds friction to the spammer (and users). Bypassing reCAPTCHA is possible for any motivated spammer for only a few cents/captcha. There are services that have humans in developing countries solve them for you. Coupled with a headless chromium, you can easily build a reputation so that google will let you through. For testing credit cards, this setup is definitely used and most likely worth it. So a captcha will not always save you from bots.

Also keep in mind that hacker news does not have a captcha and the amount of spammers is minimal.

Matt3o12_··on German man living at Delhi airport since March 18
There were plenty of flights to Germany at the beginning of the lockdown. They were called rescue flights and I’m sure the German government would have loved to have him on board that flight (so that they can arrest him in Germany).

It’s sounded like he wanted to go to another country but couldn’t due to the lack of international flights.

Matt3o12_··on German man living at Delhi airport since March 18
> “While others were facilitated by their embassies concerned and were taken for quarantine, officials from the German embassy informed the Indian bureau of immigration that Ziebat is a wanted criminal in their country with several cases of assault and other crimes registered against him. Since he was on a foreign land, they did not take his custody."

This sounds highly suspicious to me. If he is a wanted criminal, I would imagine the German government is especially keen to take him home so that he can be held responsible for his crimes. It sounds to me like he doesn't want to leave for Germany and they can't make him board a "rescue flight".

Matt3o12_··on Ubuntu 20.04 LTS’ snap obsession has snapped me off of it
Really? I constantly run into disk space issues. Apple still ships their flagship 13" macbook pro 128gb storage and they charge $200 for another 128gb. While other manufacturer's laptops charge a lot less for storage these days, most still only come with 256 which is not enough these days for development IMO.

Even on my desktop, I managed to fill 750GB with various VMs and android development tools (the SDKs, etc). While I am not sure how much compression could have saved me, it could still be worth it (especially since I only use certain VMs or SDK version once a month).

Matt3o12_··on Ubuntu 20.04 LTS’ snap obsession has snapped me off of it
Apparently, snaps are compressed to save disk space, which is why they take so long to start:

- https://www.reddit.com/r/Ubuntu/comments/9scoif/snap_package...

Saving disk space is certainly useful for rarely used apps, however, your web browser (and any other frequencely used apps), shouldn't be compressed, especially if there is ample disk space.

Matt3o12_··on Show HN: A Go unikernel capable of running GUI programs
Wow super cool project and it's super impressive that you could do that with only 6400 logical lines of code (according to cloc) and without any dependencies (expect one for the gui part & material icons).

Can you explain how you implemented the GPU? What resources did you use?

Matt3o12_··on Slack account takeovers using HTTP Request Smuggling
I think this rather applies to API clients which can handle that differently. A quick test for python's shows that all headers are redirect regardless:

  requests.request("GET", "http://localhost/redirect-to?url=http%3A%2F%2Fhttpbin.org%2Fget", headers={"x-foo": "bar", "Cookies": "abc=dcv;"}).json()
  
  {
    "args": {},
    "headers": {
      "Accept": "*/*",
      "Accept-Encoding": "gzip, deflate",
      "Cookies": "abc=dcv;",
      "Host": "httpbin.org",
      "User-Agent": "python-requests/2.22.0",
      "X-Amzn-Trace-Id": "Root=1-5e6bebe1-cd6e71729a818015a06aa7cb",
      "X-Foo": "bar"
    },
    "origin": "91.58.8.128",
    "url": "http://httpbin.org/get"
  }
  

I'm running a local copy of httpbin on localhost, so python's request should not send sensitive headers for redirects but it does. Golang is a bit more explicit about it's http client behavior:

> • when forwarding sensitive headers like "Authorization", "WWW-Authenticate", and "Cookie" to untrusted targets. These headers will be ignored when following a redirect to a domain that is not a subdomain match or exact match of the initial domain. For example, a redirect from "foo.com" to either "foo.com" or "sub.foo.com" will forward the sensitive headers, but a redirect to "bar.com" will not.

https://golang.org/pkg/net/http/#Client

Though this might also cause problems if you are using sensitive non standard headers such as X-Token for token authentication, etc.

So while you could probably mitigate this vulnerability on some clients, you are trusting the server to only redirect you to trusted URLs which is not the case here.

Matt3o12_··on Linode launches free DDoS protection
I’m curious, does anyone know what that means specifically? How can they differentiate normal traffic from malicious traffic? What exactly triggers it? Is a ping flood with a slow (50mbits) internet connect enough? I am aware that the details are mostly likely private to protect them from abuse and are also a trade secret but I have a very hard time to find a general approach that might be similar to their solution?
Page 1 of 14Next →