HNHacker News
TopNewBestAskShowJobs

Nextgrid

29,786 karma · joined February 21, 2019

Old man yelling at the cloud.

Contact: hi@rjevski.io

submissionscomments
Nextgrid··on My ridiculously robust photo management system (Immich edition)
You can do this easier with Wake on LAN. See https://danielpgross.github.io/friendly_neighbor/howto-sleep... for prior art.
Nextgrid··on HTTP Cats
204 has weird behavior in Safari and Firefox for example. Entering a URL returning 204 in the URL bar will not change the URL bar to it, leaving its contents to whatever was there before. Similarly if you click on it it would not actually navigate to the page.

URL to test: https://httpbin.org/status/204

Nextgrid··on Disrupting the largest residential proxy network
"SEO spammers being more advanced than multi-billion-dollar search conglomerate" is a myth. Spam sites have an obvious objective: display ads, shill affiliate links or sell products. All these have to be visible, since an ad or product you can't see/buy is worthless. It is trivial to train a classifier to detect these.

But let's play devil's advocate and say you are right and spammers are successfully outsmarting Google - well, Kagi does use Google results via SerpAPI by their own admission, meaning they too should have those spam results. Yet they somehow manage to filter them out with a fraction of the resources available to Google itself with no negative impact on search quality.

Nextgrid··on Antirender: remove the glossy shine on architectural renderings
That's not wrong - the apartment I'm in currently has trash containers near the entrance that of course weren't present in the promotional material.
Nextgrid··on Antirender: remove the glossy shine on architectural renderings
Why is it addressing it? It'll just lead to every single ad having this statement.

To address it you actually need to force them to provide the originals alongside the edited pictures.

Nextgrid··on Antirender: remove the glossy shine on architectural renderings
Every company and their dog is saying that LLMs/"AI" is supposed to be that magic fairy anytime now.
Nextgrid··on Antirender: remove the glossy shine on architectural renderings
> someone finally made Poland-filter

The UK is feeling left out and would like a word.

Nextgrid··on Disrupting the largest residential proxy network
Network operators have zero reason to care, they get paid per the GB for the bandwidth.
Nextgrid··on Disrupting the largest residential proxy network
That's already the case (irrespective of residential proxies) because content only serves as bait for someone to hand over personal information (during signup/login) and then engage with ads.

Proxies actually help with that by facilitating mass account registration and scraping of the content without wasting a human's time "engaging" with ads.

Nextgrid··on Disrupting the largest residential proxy network
LLMs aren't a good indicator of success here because an LLM trained on 80% of the data is just as good as one trained on 100%, assuming the type/category of data is distributed evenly. Proxies help when you do need to get access to 100% of the data including data behind social media loginwalls.
Nextgrid··on Disrupting the largest residential proxy network
Spam in Google search results is due to Google happily taking money from the spammers in exchange for promoting their spam, or that the spam sites benefit Google indirectly by embedding Google Ads/Analytics.

I don't see any spam in Kagi, so clearly there is a way to detect and filter it out. Google is simply not doing so because it would cut into their profits.

Nextgrid··on Backseat Software
There's an oxygen waster whose salary is conditional on bringing this data in. Whether that covers his paycheck, let alone brings profit is irrelevant to him. He is also the one responsible for reporting the profit numbers on that, so obviously the numbers will be cooked to indicate his work greatly benefits the business.
Nextgrid··on Malicious skills targeting Claude Code and Moltbot users
Clawdbot -> Moltbot -> Openclaw.
Nextgrid··on Show HN: Moltbook – A social network for moltbots (clawdbots) to hang out
> hard problems are best solved by breaking them down into smaller, easier sub-problems

I'm ok doing that with a junior developer because they will learn from it and one day become my peer. LLMs don't learn from individual interactions, so I don't benefit from wasting my time attempting to teach an LLM.

> much like compilers did for Assembly programming back in the day

The difference is that programming in let's say C (vs assembler) or Python vs C saves me time. Arguing with my agent in English about which Python to write often takes more time than just writing the Python myself in my experience.

I still use LLMs to ask high-level questions, sanity-check ideas, write some repetitive code (in this enum, convert all camelCase names to snake_case) or the one-off hacky script which I won't commit and thus the quality bar is lower (does this run and solve my very specific problem right now?). But I'm not convinced by agents yet.

Nextgrid··on Where to Sleep in LAX
I fly often and I think the airport hate is overblown.

Airports are designed to keep large groups of passengers moving as efficiently as possible, and as a result they need to make some tradeoffs. Airports aren't and shouldn't really be designed for sleeping - there's a thing called hotels for that. A lot of airports have capsule hotels paid per hour for exactly this purpose.

The root cause seems to be airlines aren't actually forced to provide enough compensation to cover a hotel. Regulation would be a much easier solution than redesigning airport to accommodate sleeping.

Only complaint I agree with is the "please do not leave your bags unattended" spam on the PA. Whoever came up with that idea deserves a couple years of solitary confinement with said PA in the cell, for increasing the danger due to alert fatigue and people completely tuning out the PA, making the channel completely worthless.

Nextgrid··on That's not how email works
> Is it that HSBC has 0 competent people who could have mentioned

Given the salaries, tooling and working conditions for tech people in such companies, why would anyone competent work there?

Nextgrid··on Somebody used spoofed ADSB signals to raster the meme of JD Vance
But even if that was the case, is there any value for a receiver to be receiving those? Surely those messages would be picked up by a receiver closer to the transmitter anyway. I think the value in spoofing rejection is greater than the probability of a transmission reflecting from beyond the horizon and not being already being picked up by a local receiver.
Nextgrid··on Somebody used spoofed ADSB signals to raster the meme of JD Vance
Surely the receiver would run plausibility checks on the received messages and reject spoofed locations that are physically impossible to receive by said receiver?
Nextgrid··on Some notes on starting to use Django
> what happens if you onboard a superstar that works with django some other way

If you hired a "superstar" that goes out of their way to hand-write migrations in cases where Django can do it by default (the majority of them) you did not in fact get a superstar.

I have yet to see anyone hand-roll migrations on purpose. In fact the problem is usually the opposite, the built-in migration generator works so well that a lot of people have very little expertise is doing manual migrations because they maybe had to do it like 5 times in their entire career.

Nextgrid··on Apple to soon take up to 30% cut from all Patreon creators in iOS app
Patreon is a very niche app in the grand scheme of things. There's the saying that only 1% of web visitors ever stop by and actually contribute, and I'd expect that number to drop to 0.001% when it comes to contributing monetarily through a tool like Patreon. This is an absolutely tiny minority.

Hell I'd argue more people are upset about the lack of an OnlyFans app than Patreon. OF has way more brand-recognition (outside of tech) than Patreon.

Nextgrid··on SoundCloud Data Breach Now on HaveIBeenPwned
> the GDPR penalty is a highish percentage of the company's total revenue which gives the laws a good amount of "teeth"

Under 2% of GDPR complaints even result in fines. And that would require there to be grounds for a complaint - there's no way for an external user to tell whether the delete is actually done, and the DPA won't force them to submit to a third-party source code audit.

The GDPR has zero teeth. But don't take it from me, these guys have a bit more expertise than I do on this subject: https://noyb.eu/en/data-protection-day-5-misconceptions-abou...

Nextgrid··on Europe's tech job market faces a talent shortage
There is no such thing as a talent storage - it's always a pay storage.
Nextgrid··on Some notes on starting to use Django
https://docs.pydantic.dev/latest/concepts/pydantic_settings/
Nextgrid··on Lennart Poettering, Christian Brauner founded a new company
Secure Boot and TPM are separate things. The current Secure Boot policy gets measured by the TPM but that's about it.
Nextgrid··on Lennart Poettering, Christian Brauner founded a new company
Then you reset the firmware and re-enroll your SB keys or disable it completely.
Nextgrid··on Lennart Poettering, Christian Brauner founded a new company
> you cannot use unsigned drivers because the kernel can detect and activate the lockdown mode

You don't need to load a driver; you can just replace a binary that's going to be executed as root as part of system boot. This is something a hypothetical code signature verification would detect and prevent.

Failing kernel-level code signature enforcement, the next best step is to have a dm-verity volume as your root partition, with the dm-verity hashes in the initrd within the UKI, and that UKI being signed with secure boot.

This would theoretically allow you to recover from even root-level compromise by just rebooting the machine (assuming the secure boot signing keys weren't on said machine itself).

Nextgrid··on Lennart Poettering, Christian Brauner founded a new company
Yes, you can. I really don't want to be in the business of building OSes. If these guys make it so that getting reasonable boot security is a simple toggle, I'd be grateful.
Nextgrid··on Lennart Poettering, Christian Brauner founded a new company
> the kernel will verify anything beneath it

Yes that's the case - my argument is that Linux currently doesn't have anything standardized to do that.

Your best bet for now is to use a read-only dm-verity-protected volume as the root partition, encode its hash in the initrd, combine kernel + initrd into a UKI and sign that.

I would welcome a standardized approach.

Nextgrid··on Lennart Poettering, Christian Brauner founded a new company
A full trusted boot chain allows you to use a reboot to revert back to a trusted state after suspected runtime compromise.
Nextgrid··on Lennart Poettering, Christian Brauner founded a new company
Secure Boot only extends the chain of trust from your firmware down the first UEFI binary it loads.

Currently SB is effectively useless because it will at best authenticate your kernel but the initrd and subsequent userspace (including programs that run as root) are unverified and can be replaced by malicious alternatives.

Secure Boot as it stands right now in the Linux world is effectively an annoyance that’s only there as a shortcut to get distros to boot on systems that trust Microsoft’s keys but otherwise offer no actual security.

It however doesn’t have to be this way, and I welcome efforts to make Linux just as secure as proprietary OSes who actually have full code signature verification all the way down to userspace.

← PreviousPage 7 of 34Next →