HNHacker News
TopNewBestAskShowJobs

TheDong

10,071 karma · joined August 28, 2014

submissionscomments
TheDong··on Project Gutenberg – keeps getting better
anubis only works against lazy scrapers, and at a cost to your users. I'd prefer people not use it.

Bot traffic comes from machines that usually have a lot of idle cpu (since they're largely blocked on network IO as they scrape a bunch of sites in parallel), so they can trivially solve the anubis "proof of work" challenge, save the cookie, and then not solve it again for that site.

The only reason scrapers don't solve it is if the developers were too lazy to implement it... and modern scrapers also do, codeberg stopped using anubis because modern scrapers were updated to solve it.

The "proof of work" has to be easy or else people on old cell phones couldn't access your site (since an old android phone would start to overheat and throttle trying to solve a challenge that would take a modern server even several seconds), and it also consumes your cell-phone user's batteries, which is a really precious resource for them compared to the idle cpu on a server.

TheDong··on Mullvad exit IPs are surprisingly identifying
It's simpler to implement because it's more stateless, and it's a better user experience.

If you get a new exit IP each time you connect, you need something like a NAT table to look up "key 0xabc exits ip 1.2.3.4", and that grows to be the size of the number of users you have active, and you need to save it forever so that when the NSA asks who used the IP for what duration you can tell them.

With a static mapping derived from the key, you don't need a table like that.

It's also better UX since it means reconnecting your VPN software (say you switch wifi hotspots) doesn't give you a different IP address, so things like SSH sessions can resume, which wouldn't be possible if it were a different public IP each time.

TheDong··on New Nginx Exploit
Only 19?

The venerable unix tool "less" is on v701 and was probably already over 300 before react was born

https://github.com/gwsw/less/releases/tag/v701

TheDong··on AluminiumOS, by Google: Android Reimagined for the Desktop
> Not officially affiliated with Google.

This thing stinks so hard of AI that it's impossible to trust any of the specific details.

IMO this is slop, it's not worth reading, once we have something written by an actual human with actual information about the subject, I'll read that.

TheDong··on Googlebook
You're on hacker news though, so you can install linux on it: https://wiki.postmarketos.org/wiki/Google_Pixel_3a_(google-s...

Pixel devices have historically been really good about letting you unlock the bootloader and install what you want, so even if Google drops support, the community can keep it going.

Apple devices just turn into useless bricks once apple deems them too old. Frankly, I think apple should be legally required to allow users to unlock devices, like you pay for the device, you should be able to use the hardware.

TheDong··on Googlebook
Google also has a better track record than some companies (cough apple) of keeping their devices unlockable/open enough that they can have a second life regardless of whether google keeps up on the software side.

You can install linux on the nexus 7 tablets.

You can install linux on the old PixelBook or Chromebook Pixel.

An iPad bought at the same time as the nexus 7 (the original iPad air) has become a useless insecure brick that can't even load modern websites, let alone support linux. The nexus 7 can have linux or a custom android rom flashed to work fine, albeit with a pretty crappy processor.

TheDong··on Dirtyfrag: Universal Linux LPE
A lot of these multi-tenant CI systems actually run everything in microVMs even if they present it to you as a container.

At this point, a microvm can be booted in ~200ms so you don't even have to keep a warm pool, you can just launch em on demand.

GitHub CI (actions) uses virtual machines.

TheDong··on How far behind is each major Chromium browser?
A lot of people are stuck with safari on iOS where there's not even another browser since apple bans them.

People choose to download Chrome over firefox, to ditch their custom browser engine (microsoft & opera) in favor of chromium.

We've centralized development effort on a large open source project.

Why exactly is this really really bad?

I find the safari situation bad because I can't use various web standards, it's closed source, etc, but the chromium one doesn't bother me. I just install firefox.

TheDong··on Alignment whack-a-mole: Finetuning activates recall of copyrighted books in LLMs
Copyleft is an abuse of copyright to pervert its intention. Copyright's intent was that you could not copy things freely, and copyleft is to ensure you can.

If there is no copyright, then you can copy things freely.

All that we need after that to realize the GPL ideal is to legally mandate that people have a right to access and modify source code of software/hardware they use, i.e. the government needs to mandate that Apple releases the iOS kernel and source code and that iPhones can be unlocked and custom kernels flashed, that John Deere must provide the tractor's source code, that my fridge releases its GPL-violating linux patches, etc etc.

You have the right to free speech, the right to a lawyer, and the right to source code. Simply amend the bill of rights.

TheDong··on Copy Fail
It's already a configurable option in the kernel which can be fully disabled by distros if they wanted to provide their own compatibility layer, or just not ship any software that has a hard dependency on it.
TheDong··on Bugs Rust won't catch
It's based on an interpretation of "derived from".

It does not matter if it's in the GPL explicitly or not since we're talking about uutils and their stance on it, and they've written that:

https://github.com/uutils/coreutils/blob/6b8a5a15b4f077f8609...

> we cannot accept any changes based on the GNU source code [..]. It is however possible to look at other implementations under a BSD or MIT license like Apple's implementation or OpenBSD.

The wording of that clearly implies that you should not look at GNU source code in order to contribute to uutils.

TheDong··on Regression: malware reminder on every read still causes subagent refusals
> the risk of being charged API is 0% when you are on a plan.

When you configure openclaw to use the oauth claude-code max authentication, there was a period where you were charged extra token rates. You might still be, I'm not sure, I don't want to try and risk getting banned.

It's not 0%, they've shown they're willing to sell you a plan, let you login with that plan, and then charge you differently.

TheDong··on Bugs Rust won't catch
What's even harder is doing that while trying to avoid the GPL, so doing that without reading the original source code.

uutils would be so much better imo if it was GPL and took direct inspiration from the coreutils source code.

TheDong··on Regression: malware reminder on every read still causes subagent refusals
Managed agents aren't particularly harder to replicate yourself either.

Give me a team of 3 good engineers, 4 months, and about $600k and I'll have a clone that operates on a warm pool of ec2 instances, or warm pool of k8s pods, or any other platform you might like. Or 1 good engineer, 1 month, and $200k of anthropic credits.

TheDong··on Regression: malware reminder on every read still causes subagent refusals
You know, you can write in English if you want on this english-language forum.

I assume you're saying "You can just generate your own harness to not be subject to these claude code issues".

Unfortunately, Anthropic has already made it clear that using claude code is the only way to be sure you won't get charged API pricing instead of max plan pricing, so the tokens are way more expensive.

TheDong··on Regression: malware reminder on every read still causes subagent refusals
This is an argument for open models, where you can run your model with your system prompt on your hardware, which prevents the provider from arbitrarily injecting system prompts.

This is an argument for open source tooling (like opencode) and open models (like deepseek).

Grok is not an open model, Elon does not get any credit for anything here.

TheDong··on When the cheap one is the cool one
You cannot run Linux on the macbook neo at the time of writing, unless you mean in a VM, and the processor + memory are barely enough to reasonably manage that. Even a mid-sized rust project, or a nixos build, would OOM for a VM.
TheDong··on An AI agent deleted our production database. The agent's confession is below
Yeah, I've run tests similar to this while evaluating gpt 5.4 vs claude 4.6

Claude is more likely to figure out workarounds and get things deleted if I tell it to delete stuff, so it performs much better in this benchmark and I prefer it.

GPT is more likely to stop and prompt you "I got an error deleting this, should I try another way?", and since the operator gets more of these prompts, they'll hit continue more withut even reading it, so it ends up being more annoying for the operator and not really reducing the chance of it happening imo.

If your workflow for your llm says "delete the ec2-instance", and the ec2 api gives back "deletion protection is on", I want my llm to turn off deletion protection and delete it.

I feel like you're implying that the reverse result, prompting the user, is better, but I disagree with that.

TheDong··on Magic: The Gathering took me from N2 to Japanese fluency
There are a ton of words where the loan-word is commonly used even when there's a native word.

For example, there's both "desuku" for desk, and also "tsukue" (the original japanese word). They're both in very common use. The loan-word has an ever-so-slight vibe of a western-style desk, while tsukue has an ever-so-slight vibe of a schoolroom desk.

Languages change over time, and english has had a large influence on Japanese.

Of course there's a word for damage in japanese ("higai" is probably the best fit for Magic), but there's also "dameeji" now, and it feels mildly more western-fantasy like to use it.

There isn't always a logical or obvious reason why a loan-word is used over a native word, as is true for a lot of linguistic changes (like in english, why does someone say "soda" vs "pop", why do some people call it a "pillbug" and some a "rolly-polly"?). Just accept that loan-words are used in some cases, and there's not always a reason other than "people just say it that way".

TheDong··on I bought Friendster for $30k – Here's what I'm doing with it
Yeah, sure. How do I sync my iCloud photos to my local NAS on linux? A: use a third-party app, they don't build their own.

How do I build an app for my iPhone locally and run it without ever connecting to their servers? I can do that for my phone running linux or for my phone running android, but on iOS I have to get signed by their servers to run code I wrote.

Linux respects my freedom to have my data exist locally, to build and run open source apps, and to modify the code on the devices I run.

Apple does not. They don't let me use their ecosystem from Linux, they do not let me patch the iOS kernel and run a modified version on the devices I run, I can't even access the source code for the macOS kernel.

Apple's filesystem abstraction and lack of something like android "intents" also makes it wildly difficult to do "local-first" computing where files are shared between apps cleanly.

TheDong··on I bought Friendster for $30k – Here's what I'm doing with it
> Nothing malicious

The first result is a sponsored result, and even after Friendster is indexed, if they don't pay apple's extortion-rate, the first result will still be for some other social media app.

Ads in the app store are malicious. There are people who have searched "Ledger bitcoin wallet", clicked the first link (a malicious app who paid apple enough money to be 'sponsored' for that search), and had all their money stolen.

TheDong··on Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
You do use the browser extension because it's a strong anti-phishing defense.

If someone links me to "rnicrosoft.com" with a perfectly cloned login page, my eyes might not notice that it's a phishing link, but my browser extension will refuse to autofill, and that will cause me to notice.

Phishing is one of the most common attacks, and also one of the easiest to fall for, so I think using the browser extension is on-net more secure even though it does increase your attack surface some.

I know proper 2fa, like webauthn/fido/yubikeys, also solves this (though totp 2fa does not), but a lot of the sites I use do not support a security key. If all my sites supported webauthn, I think avoiding the browser extension would be defensible.

TheDong··on GitHub CLI now collects pseudoanonymous telemetry
For most CLIs, I definitely feel extra network calls because they translate to real latency for commands that _should_ be quick.

If I run "gh alias set foo bar", and that takes even a marginally perceptible amount of time, I'll feel like the tool I'm using is poorly built since a local alias obviously doesn't need network calls.

I do see that `gh` is spawning a child to do sending in the background (https://github.com/cli/cli/blob/3ad29588b8bf9f2390be652f46ee...), which also is something I'd be annoyed at since having background processes lingering in a shell's session is bad manners for a command that doesn't have a very good reason to do so.

TheDong··on A Roblox cheat and one AI tool brought down Vercel's platform
dotenvx is a way to encrypt your secrets at rest. It's kinda like sops but not as good. https://getsops.io/

Notice how their tutorial says "run 'dotenvx run -- yourapp'". If you did 'dotenvx run -- env', all your secrets would be printed right there in plaintext, at runtime, since they're just encrypted at rest.

The equivalent in vercel would be encrypted in the database (the encrypted '.env' file), with a decryption key in the backend (the '.env.keys' file by default in dotenvx) used to show them in the frontend and decrypt them for running apps.

TheDong··on A Roblox cheat and one AI tool brought down Vercel's platform
They need to give your app the environment variables later so they cannot throw away the key.

For non-sensitive environment variables, they also show you the value in the dashboard so you can check and edit them later.

Things like 'NODE_ENV=production' vs 'NODE_ENV=development' is probably something the user wants to see, so that's another argument for letting the backend decrypt and display those values even ignoring the "running your app" part.

You're welcome to add an input that goes straight to '/dev/null' if you want, but it's not exactly a useful feature.

TheDong··on A Roblox cheat and one AI tool brought down Vercel's platform
They said "encrypted at rest", which they almost certainly are.

If you spin up an EC2 instance with an ftp server and check the "Encrypt my EBS volume" checkbox, all those files are 'encrypted at rest', but if your ftp password is 'admin/admin', your files will be exposed in plaintext quite quickly.

Vercel's backend is of course able to decrypt them too (or else it couldn't run your app for you), and so the attacker was able to view them, and presumably some other control on the backend made it so the sensitive ones can end up in your app, but can't be seen in whatever employee-only interface the attacker was viewing.

TheDong··on John Ternus to become Apple CEO
They should charge for it.

If you buy the 'iPhone Max' for $1500, you get ads, and if you buy the 'iPhone Max ad-free' for $3800, you don't get any ads in the app store, apple maps, apple news, or the various other apple services you use on only that one device. Similarly, you need to buy the ad-free edition of the iPad to not get ads there, and the ad-free version of the macbook for no ads there, and each of them can cost ~2.5x the cost.

I think that would be better than a monthly subscription since you'd just pay it once and then never think about it again.

TheDong··on OpenClaw isn't fooling me. I remember MS-DOS
All the other models performed much worse for the skills I'm using. I tried gpt-5.1 (and then 5.4 again recently), and also tried pointing it at OpenRouter and using a few of the cheaper models, and all of them added too much friction for me.

Be judgemental all you want, but I feel like I'm paying for less friction, and also more security since my experiments also showed claude to be the least vulnerable to prompt injection attempts.

TheDong··on OpenClaw isn't fooling me. I remember MS-DOS
If you've figured out how to pirate Anthropic's models and enough GPUs to run it for less than my API costs, I'm all ears
TheDong··on OpenClaw isn't fooling me. I remember MS-DOS
Note that the (edit: US) postal system is a for-profit system.

Given the trends of the capitalist US government, which constantly cedes more and more power to the private sector, especially google and apple, I assume we'll end up with a state-run model infrastructure as soon as we replace the government with Google, at which point Gemini simply becomes state infrastructure.

← PreviousPage 3 of 34Next →