HNHacker News
TopNewBestAskShowJobs

Sophira

1,692 karma · joined March 19, 2013

submissionscomments
Sophira··on Moving beyond fork() + exec()
I'm guessing that a big part of the problem with moving away from fork() in general is that each new process needs a copy of the parent process' environment anyway, right?
Sophira··on Apple rejected my dictation app for using the accessibility API
To my knowledge, SequoiaView[0] predates even KDirStat - it just didn't have the tree view paired with it.

[0] https://sequoiaview.win.tue.nl/

Sophira··on Let's compile Quake like it's 1997
Weird Al didn't make that song! That was Bob Rivers.
Sophira··on Someone used my open source project to phish people
On the one hand, people say that AI models (LLMs, image generators, etc) are just stealing from people and that they cannot be original.

On the other hand, people say that AI models have tells that no actual person would do.

Which is it? You can't have it both ways.

Sophira··on Motorola phones have started hijacking the Amazon app to insert affiliate codes
The Gigabyte motherboard on my system does this as well. I turned it off immediately, of course.
Sophira··on The Forgotten Art of the LAN Party (2023)
There's a huge difference between the latency you get from connecting to each other via the Internet, and the latency you get going via a local network, even if that network is a wireless one.

There's an even bigger difference between that, and going online via the Internet back in the days when LAN parties were really popular, because the most common method of connecting to the internet was via modem.

Sophira··on Don't Subscribe So Casually
> If someone offered you a magic button that gave you ten dollars now, but carried a high probability of altering your tastes, your routines, and the way you think, would you press it?

This is actually a very interesting question, because I can see someone's answer being different between this question as stated, and the same question but where you would be paying the $10 instead of the button giving you $10:

> If someone offered you a magic button that carried a high probability of altering your tastes, your routines, and the way you think, but it cost $10 to press, would you press it?

Specifically (and somewhat paradoxically), I think more people would say yes to the second question than to the first, because people would start thinking about it as a transaction where the purpose of pressing the button has changed from "receiving money" to "changing myself", even though in both cases it's stated upfront.

Of course, in the context of subscriptions, the purpose is neither of these things (it's to receive the content that subscription is offering), so the first question is definitely more relevant in this situation than the second. It's still interesting to me, though.

Sophira··on Gnutella: A Protocol Outliving the World That Created It
I'd say the biggest reason that Gnutella (and other services like it) is no longer in much use is because for a long, long time now the easiest way to download music for free, without ads, and with virtually zero chance of getting caught, has been via YouTube and downloader clients. For most practical uses, it's good enough.

You wouldn't want to share the resulting downloads (not only is the audio quality slightly degraded, but I imagine it's highly likely there would be audio watermarks), but when everybody can download straight from YouTube anyway with a minimum of hassle, why would you need to share anything other than a video URL?

Of course, a big part of why this is so simple is because of the massive amount of work that the downloader client devs put into working around YouTube's attempts to stop this. I imagine it can be a difficult job.

If YouTube ever win the battle against the downloader clients, I imagine the landscape will change again. Maybe Gnutella will make a comeback.

Sophira··on Google changes its search box
> As people have realized just how much more Search can do for them, they’re searching more than ever before — so much so that last quarter, we saw queries reach an all-time high.

...a high search volume tells me that maybe users aren't able to find what they're actually looking for, thereby needing more searches.

Sophira··on Photo GIMP – A Patch for GIMP 3 for Photoshop Users
I've memorised the keyboard shortcuts that I need in order to do this extremely common thing.

1. Select region with mouse.

2. Ctrl-C: Copy the region.

3. Ctrl-V: Paste (with the selection still active, so that it pastes in the same place).

4. Ctrl-Shift-N: Makes the resulting "temporary layer" into a permanent new layer.

5. Use the new layer.

I wish I could skip step 4. It's usually not necessary, and if I need to place the temporary layer into the same layer that I was already using, I can just merge the two myself.

Of course, sometimes you do need the ability to directly paste into the same thing, such as if you're editing a layer mask rather than the actual layer itself...

Sophira··on Click (2016)
The problem with this line of thinking is that businesses don't expect you to read T&Cs.

This site itself is, funnily enough, a good example of this (and, to be fair, an outlier). When you sign up to an account here, you're not asked to agree to any terms. There's nothing that forces you to agree to any terms of service. The site does have them[0], but you can only access them by clicking the "Legal" link in the footer, and you're never required to do so. Yet people here are, by and large, behaving themselves, largely due to good moderation on the part of dang and others.

But if there were to be a lawsuit, for whatever reason, it's potentially possible that someone could successfully argue that they never had to agree to any terms. It's a technicality, of course - again, very few people read terms of service, and if they did, you'd think somebody would have noticed this omission by now - but an arguably legally actionable one.

Which leads me back to my point - the only reason that businesses make you agree to terms of service is because if they didn't, they could get lawsuits that might be found in favour of the plaintiff. Businesses don't want that, so they include the checkbox.

[0] https://www.ycombinator.com/legal/#tou

Sophira··on Click (2016)
I'm guessing this is supposed to illustrate how tracking is ubiquitous, given what I see in the source code.

In my case, though, after carefully enabling only scripts from the site and the Cloudflare CDN, but not enabling XHR/websockets back to the source page, or any cookies, the only thing that happens for me is:

1. I see a button and an exhortation to click the button.

2. I click the button.

3. The site goes "Subject has clicked the button."

4. The site goes "...".

...and then nothing else happens, no matter where I click or move my mouse. In the background I can see attempted websocket connections, but I'm blocking those so they can't happen.

If the aim of the game is to open people's eyes to the dangers of online tracking, it feels like there should be a reward mechanism if such tracking is blocked!

Sophira··on Click (2016)
> Yeah, we include it in our terms and condition and privacy page

Please be honest with yourself. People don't read terms and conditions. There's a good chance you don't read terms and conditions. And even if you do, odds are better than even that you don't fully understand all the legal implications.

Terms and conditions pages nowadays are there mostly to provide legal protection under the guise of "the user told us that they read these by ticking a box on our signup page; it's hardly our fault if they didn't."

Sophira··on OpenAI and Government of Malta partner to roll out ChatGPT Plus to all citizens
And only after a mandatory course, if I'm reading the article correctly.
Sophira··on Myths about /dev/urandom (2014)
If it helps, it used to look like this: https://web.archive.org/web/20140309183752/http://www.2uo.de...

Definitely a lot more readable! Something must have changed in the meantime.

It looks like some links have gone too, like the one in the sentence "how does /dev/random know how much entropy there is available to give out?"

Sophira··on Screenshots of Old Desktop OSes
I have a local version of RPCemu too, but I never had a Risc PC myself so it's not as interesting to me; we got a PC about half a year after Windows 95 released.

Have you come across the Stardot[0] community yet? I feel like you'd enjoy it. Fair warning: it's more focused on the Acorn computers themselves (both 8-bit and 26/32-bit) than the continuing development of RISC OS. That said, I personally think it's great.

[0] https://www.stardot.org.uk/

Sophira··on Screenshots of Old Desktop OSes
Ooo, a rare fellow home RISC OS user! I had an A3000 at home myself so I didn't have the benefit of using RISC OS with a hard drive, and we never upgraded to an ARM3, but we did use both RISC OS 2 and 3.

Still love the old Acorn machines. I mostly use Arculator[0] nowadays for that nostalgia though.

[0] https://b-em.bbcmicro.com/arculator/

Sophira··on Space Cadet Pinball on Linux
Maybe it was edited, but from what I see, in the last sentence they said to have Claude make a spec, not to rewrite the code.
Sophira··on Space Cadet Pinball on Linux
It works fairly well for me in Linux on WINE, even with Visual PinMAME. I believe I used the all-in-one installer (vpx7setup.exe, although there's a later version now).

My GPU is an AMD Radeon RX 6600 XT, if that makes a difference.

Sophira··on Google broke reCAPTCHA for de-googled Android users
Not yet. They've partnered with Motorola, though, so we'll probably be seeing some of their phones in the future that can run GrapheneOS.
Sophira··on Google broke reCAPTCHA for de-googled Android users
I can't say for sure, but is it possible they're referring to the founding of the Internet Association in 2012?[0]

I don't think it's that, because the Wikipedia article makes it seem like it was a force for good, but at the time, it wasn't certain at all that it would be that way.[1]

Beyond that, I'm not exactly sure what might be meant.

[0] https://en.wikipedia.org/wiki/Internet_Association

[1] https://reddit.com/r/technology/comments/xs4qw/google_facebo...

Sophira··on A web page that shows you everything the browser told it without asking
That's essentially how things used to work, and the problem is that it too can be gamed using JavaScript. For example, a relatively naive approach might be:

1. Make an HTML <span> element that contains "The quick brown fox jumps over the lazy dog" written in the default font.

2. You can't query what font that was, but you can use the getComputedStyle() DOM function of that element to work out the width (for example) of the resulting element. Note this down.

3. Do the same for all the different fonts that you want to test.

4. If any element's width differs from the default's noted in step 2, then the corresponding font is guaranteed to be installed on your system.

As written, this won't detect the font that the user has selected to be the default font (because it won't detect the width as being different). However, you can work around this (and remove most false negatives to boot) by a simple addition:

5. Pick one of the fonts that you detected as being installed.

6. Create more elements (as in step 1) that correspond to all the fonts that were detected as being the same width as the default, but have the font you selected in step 5 as a fallback. (eg. 'font-family: Testing, Fallback;')

7. Any element with a width that differs from the font you selected in step 5 is installed on the system.

What you get will be a relatively complete list of what fonts are on the system out of the ones you tested. If you want more accuracy, you can do a similar thing with individual letters instead.

Sophira··on Telus Uses AI to Alter Call-Agent Accents
On the one hand, I agree with you, and your reasoning is self-evident IMO.

On the other, too many customers are complete racist dicks to people who they perceive as not "belonging to their country". I... don't think this is the solution to that problem (people will just start applying their racist views elsewhere), but it could be argued by some that it might help.

I'm still against this, don't get me wrong - we absolutely should not be doing this to anybody. I can understand the appeal, though.

Sophira··on For Linux kernel vulnerabilities, there is no heads-up to distributions
And now it's changed to be a generic "For Linux kernel vulnerabilities" rather than specifically about Copy-Fail.
Sophira··on Can I disable all data collection from my vehicle?
In the UK, this URL simply redirects to the UK version of the homepage, sadly.

For anyone in the same situation, https://web.archive.org/web/20260430234304/https://rivian.co... leads to the correct page.

Sophira··on Copy Fail
To be specific, the zlib'd binary basically does this (except that it directly uses Linux syscalls to do so rather then C wrappers):

    setuid(0);
    execve("/bin/sh", NULL, NULL);
    exit(0);
Sophira··on Copy Fail
That would suggest that CRYPTO_USER_API_AEAD=y in your kernel config. You can disable it in that case by setting that to "n", recompiling your kernel, and putting the new kernel in place.
Sophira··on Can your AI rewrite your code in assembly?
Sadly, I can't read this page on my non-mainstream browser as the server returns a 403 Forbidden error.

I get the need to protect yourself from AI bots, but banning all but mainstream browsers from viewing your content isn't the way.

Sophira··on Laravel raised money and now injects ads directly into your agent
We are at war with Eurasia. We have always been at war with Eurasia.
Sophira··on Wikipedia's AI agent row likely just the beginning of the bot-ocalypse
I can't believe I'm saying this, but:

I wonder when the first AI-only discussion group will be created by an autonomous AI agent, and other agents invited to it, without any knowledge of it by their human operators?

(I seriously can't believe that I'm musing about this as a serious scenario. It sounds ridiculous, but it feels to me somewhat plausible.)

← PreviousPage 3 of 19Next →