Not everyone that moves at driving speeds is driving, especially in places outside of America.
1,387 karma · joined February 26, 2015
meet.hn/city/de-Berlin
Not everyone that moves at driving speeds is driving, especially in places outside of America.
You will not find much local corruption though, which is what most people think of when they hear corrupt countries. Local corruption is paying of a cop, judge, that kind of stuff. I’m sure it also happens in Germany, but that is very very rare.
https://serverfault.com/a/5567
Thumbs.db files are created on my windows 11 pc at least. They’re only created for files that have metadata that requires reading those files. Explorer likes to display the metadata (sometimes) for some folders that have a lot of media in it (pictures, music, videos, etc). If the thumbs.db file is missing, windows will partially read every media file on the server to show thumbnails, that obviously creates unnecessary load but it’s really a trade off that might not make sense for most.
Full disk encryption only helps if you are worried that your hardware gets stolen
I have a crucial P1 NVME SSD and I can make it overheat pretty reliably. Pretty much any synthetic workload makes it overload if the SSD is empty (it reaches 70° pretty quickly and even starts throttling until it reaches 80° and the whole system starts shuttering because of extreme throttling do it doesn't damage itself. Although I have not properly tested it, it seems that not using any heatsinks from my motherboard makes the temps actually better but it still overheats.
The main reason it can overheat quickly is probably because its sitting in a really bad position where it gets close to zero airflow despite being in an airflow focused case. Most motherboards place the nvme slot directly under the GPU. The main problem seems to be that the controller is overheating when it's writing at close to 2000 MB/s. It's also important to note that only the controller (an actual relatively powerful ARM processor), not the flash memory, seems to overheat.
Fortunately, this is mostly not an issue because it's a QLC drive and the workload is unrealistic in the real world. When writing to an empty drive at 2000MB/s (Queue depth 4, 128k sequential writes), it takes 2 minutes until the cache is full. The way its currently used, it takes 30 secs for the cache to become full and for write speeds to drop to 150MB/s. The only way it has every overheated in the real world was during the loading screen of a gameplay when it reached 78C quickly (and I only noticed it in the hardware monitor). If the GPU hadn't heated up the nvme drive before (it was sitting at 65C mostly idle), and starved it for air, I doubt it would have hit 60C.
So until motherboards start placing nvme where it can get some actual cooling, or they make actual functioning heatsinks, their power usage can make a difference.
[1]: https://www.gamersnexus.net/guides/2781-msi-m2-heat-shield-i... but there are many more articles/forum posts with similar issues.
Also a tip for others when HN is slow or almost down (like when Google was down): you can open a private tab and navigate HN from there. Since you’re not logged in, you’re served a copy from cloud flare. It’s usually out of date by 1min or so but good enough for reading in my opinion.
I'm not sure what you mean by the second sentence but you can't use most appliances made for Europe in America and vice versa. Most electronic appliances depend on the input voltage and supplying 240V can easily cause a fire. That is true for almost all electronic appliances (water heater, fan, washing machine, etc) but not true most "computer related devices" such as a monitor, PSU, charger. Since those devices already operate on a much lower DC Voltage, they often have transformers (not sure if that's the right word), that can scale down the current from either 120 or 240. [0]
That being said, a mandatory IEC connector (and it's variances) would help a lot to cut down unnecessary e-waste. Instead of throwing away a device because the cable is damaged, you can easily order a replacement that is around $2 and high quality, instead of relying third party cords that might have bad wiring from a non reputable brand. The reason they are not mandatory, though, is that most companies like to have their own connectors so that you either overpay for it or just buy a new device.
[0]: You should still always read the specs on the input current for the device though. It is dangerous to rely on the fact that similar devices can operate at 120V/240V because yours might not. You can usually see the specs on the website/packaging or usually near the input plug.
Honestly, this worries me the most. There doesn’t seem to be a way to transfer the licenses out of stadia, which means, even though you “bought the game“, you’re still at googles mercy for your continued enjoyment of the game. What if they decide that the hardware costs are too much for Google, and you now have to pay a monthly fee? What if they decide that stadia is not the success they hoped for and close it down (which Google is not known for doing at all…). Unless there are clear migrations paths away from stadia, I’d stay away from it because Google have shown that they are not afraid to change/EOL any of their products with no regards to their existing customers (just look at their lifetime free photos service, etc)
So I think lack of thunderbolt comes down to manufacturers not wanting to pay as much for their AMD R&D and keep costs down with simple, budget motherboards.
Or, if you needed Thunderbolt 3, you could just wait until USB 4 is commonplace, which is basically Thunderbolt 3 + some more.
[1]: https://www.asrock.com/mb/AMD/X570%20Phantom%20Gaming-ITXTB3... (there are more, and even ATX boards, first one I could find).
I don't really see a problem here how that could cause a loop. This way, an attacker can only see:
- When you boot your Mac because it verifies the HTTPs certificate once.
- When the OSCP daemon makes a clear text request to check that the HTTPs cert is still ok
- That you have just opened an application (but not which application)
IMO that still leaks an unacceptable amount of meta data but it is miles better then using cleartext. Maybe a bloom filter here would be a much better solution + make the daemon regularly fetch bad signature that are not added the the filter yet instead of pulling. Sure the filter may hit false positives sometimes but in that case, the OSCP server could be checked and apple could see if a certificate has a high rate of false positives and adjust the bloom filter accordingly.
Although AMDs and Dr. Lisa Su's achievement are not to be underestimated, I doubt the 7nm processes would be as mature as it is right now without Apple.
Media companies monitor torrents, and as soon as they see a new German ip address seeding, they send a letter to the ISP with the IP address and timestamp. The ISPs send the law firm the real user address and then they send you a letter demanding a fine for illegally uploading copyrighted material often between 1000-3000€. If you don't pay up, they take you to court.
This is quite common and many people see letters even if they only seed for a few seconds. Apparently the easiest way is to just ignore the letters and pretend you don't live there but I wouldn't be so sure (a friend told me that's what he did and it allegedly worked but I have no experience with either).
So this is a lot less drastic but still quite as effective. And it even makes VPNs risky because disconnecting and exposing your real IP for even one second is enough to receive that letter (though not all torrents are monitored and private torrents are usually safe because the German RIAA doesnt have access to it).
I recommend you take a look at the Wikipedia about "Abmahnung" how that is even possible when the copyright holders don't sue themselves: https://en.wikipedia.org/wiki/Abmahnung
But let's pretend we build a super safe nuclear facility somewhere in Europe. In the beginning we will be very vigilant. The depleted ore will be properly stored (or whatever the toxic nuclear byproduct is). Maintenance will be kept to highest standard but what happens in 20 years? During that time frame a lot can change, a country can be bankrupted, and has to cut a budget. What is a fairly rich country today might not be one in 20 years.
But let's say that doesn't happen. We also always try to optimize. Say we fill our storage for depleted ore, and we look for a new one. We figure out that we can outsource it to another country because it is cheaper. This country has the same standards we do, so we happily give it to them. But after a while they can't accept anymore so we start looking for other countries to sell our waste product to, and because we have already outsourced it once, we will probably do it again but this time at lower standards.
What I am saying is, it is really difficult to predict how we handle a nuclear plant built today, 40-100 years from now, because this is how long the lifetime of a plant and its byproducts are at minimum.
Meanwhile wind/solar/batteries has a much better defined lifetime. After only 10 years we will most likely recycle them. Yes sometimes recycling them creates unnecessary waste because some countries/companies/people will cut corners but the damage caused by improperly recycled solar and even batteries is so much lower then the damage of what a nuclear power plant can do.
So the question is, do we trust all countries that 'can safely operate a nuclear plant today' to do so in 20-50 years? What about the waste products? Can we be sure that they will always be properly stored? That every country checks their stores for leaks regularly over 100 years? And this doesn't even account for developing countries that want -- and possible need nuclear power -- to catch up to developed countries. Can we just deny it to them while we are doing it ourselves?
If humanity has proven anything, it's that we are not capable of making such decisions of a long period of time reliably.
Grocery stores (even small ones) can be very noisy, especially with extended business hours these days. I used to live In an apartment above a grocery story with a small parking lot for a long time. This was also in a mixed zone area (mostly residential, a few shops, barber, etc).
At 6am, trucks start rolling up and delivering food (although they are only supposed to do that at 7am, on some days they’ll start at 6). That means very loud beeping from the trucks backing up and shouting to the grocery employees above engine noise. Throughout the day, there will be random noise (honking in the parking lot, people slamming their cart into the barrier, etc) and sometimes people get drunk in the parking lot and start shouting (usually until 11pm, the grocery store closed at 10). And once in a while, their security system went of and the police show up and make some noise at 4am. With an open window (which you had to have in the summer — air conditioning is an exception in the part of Europe where I lived) you can hear all that noise almost as if you are standing next to it.
I never minded it too much since I’m a very heavy sleeper but I can definitely see that some people would get very poor quality sleep. And no landlord ever wants a store to be built above their apartments because it lowers the value dramatically due to the mentioned reasons.
Does anyone here know how video platforms like Twitch managed to get started considering how expensive cloud data transfer pricing is? The steam bandwidth is considerably higher then video bandwidth (twitch uses a bitrate at around 8000k while YouTube has 3414k for comparable 1080p60fps videos). They also cannot take advantage of edge delivery expect for very large streamers because viewers expect a latency of 3secs or lower to their favorite stream.
I am really curious if anyone here knows how they managed to get started? They probably couldn't take advantage of super low bandwidth prices until recently because they were too small but had very expensive requirements (a lot of streamers only streaming to a very limited amount of people with high quality while also having a few very very large streamers stream to a huge amount of viewers and all of that in real time).
> It makes me doubt the profitability of Twitch, although you can be sure they are breathing a sigh of relief today.
I think twitch is highly profitable these days. Streamers have a considerable amount of subscribers, who pay a monthly fee of $5 (or sometimes even more) and stay for long durations. Twitch takes a 30-50% cut (lower depending on how big the streamer is and if twitch likes the streamer). Even streamers who average less then 1,000 concurrent viewers sometimes have between 100-500 subs.
And they have also created bits, which is a virtual currency viewers can use to tip their favorite streamers and twitch takes a similar cut (and they only let you but it in bulk beforehand to make it less transparent on how much you actually spent on them, similar to many mobile games in-app purchase model). And they play ads before streams (and during streams if they streamer decides to play them for a small cut), they also heavily advertise amazon prime (twitch streams constantly say hey you can use amazon prime to subscribe to me for free), they have premium users and probably even more monetization techniques.
If you really think a captcha is necessary, limit it. For example, require that a captcha is required for two account registrants with a 24h period from the same ip. Don’t require captchas for logins unless a reasonable limit of attempts has been exceeded (5 wrong passwords within 24h by the same ip for example).
If your site is small, a captcha is often overkill. A hidden input can trick pretty much any automated spam bot (if input empty, real user, otherwise bot). Just make sure you do enough research so accessibility readers also work with that field properly.
If a spammer targets you, you can always active a captcha manually, although by the time you realize it, it might be too late.
Keep in mind that a captcha only adds friction to the spammer (and users). Bypassing reCAPTCHA is possible for any motivated spammer for only a few cents/captcha. There are services that have humans in developing countries solve them for you. Coupled with a headless chromium, you can easily build a reputation so that google will let you through. For testing credit cards, this setup is definitely used and most likely worth it. So a captcha will not always save you from bots.
Also keep in mind that hacker news does not have a captcha and the amount of spammers is minimal.
It’s sounded like he wanted to go to another country but couldn’t due to the lack of international flights.
This sounds highly suspicious to me. If he is a wanted criminal, I would imagine the German government is especially keen to take him home so that he can be held responsible for his crimes. It sounds to me like he doesn't want to leave for Germany and they can't make him board a "rescue flight".
Even on my desktop, I managed to fill 750GB with various VMs and android development tools (the SDKs, etc). While I am not sure how much compression could have saved me, it could still be worth it (especially since I only use certain VMs or SDK version once a month).
- https://www.reddit.com/r/Ubuntu/comments/9scoif/snap_package...
Saving disk space is certainly useful for rarely used apps, however, your web browser (and any other frequencely used apps), shouldn't be compressed, especially if there is ample disk space.
Can you explain how you implemented the GPU? What resources did you use?
requests.request("GET", "http://localhost/redirect-to?url=http%3A%2F%2Fhttpbin.org%2Fget", headers={"x-foo": "bar", "Cookies": "abc=dcv;"}).json()
{
"args": {},
"headers": {
"Accept": "*/*",
"Accept-Encoding": "gzip, deflate",
"Cookies": "abc=dcv;",
"Host": "httpbin.org",
"User-Agent": "python-requests/2.22.0",
"X-Amzn-Trace-Id": "Root=1-5e6bebe1-cd6e71729a818015a06aa7cb",
"X-Foo": "bar"
},
"origin": "91.58.8.128",
"url": "http://httpbin.org/get"
}
I'm running a local copy of httpbin on localhost, so python's request should not send sensitive headers for redirects but it does. Golang is a bit more explicit about it's http client behavior:> • when forwarding sensitive headers like "Authorization", "WWW-Authenticate", and "Cookie" to untrusted targets. These headers will be ignored when following a redirect to a domain that is not a subdomain match or exact match of the initial domain. For example, a redirect from "foo.com" to either "foo.com" or "sub.foo.com" will forward the sensitive headers, but a redirect to "bar.com" will not.
https://golang.org/pkg/net/http/#Client
Though this might also cause problems if you are using sensitive non standard headers such as X-Token for token authentication, etc.
So while you could probably mitigate this vulnerability on some clients, you are trusting the server to only redirect you to trusted URLs which is not the case here.