HNHacker News
TopNewBestAskShowJobs

ValdikSS

1,445 karma · joined December 29, 2014

submissionscomments
ValdikSS··on The NX bit is not just about security
I wrote an 'unlocking exploit' as a kernel module some years ago, and obfuscated it with a bit of self-modifying code.

It could not make it work reliable. No matter which barries I set, I could not understand why is it not reliable, and had to remove the modifying code in the end.

I guess I hit the issue you've described, and now I know. Thanks!

ValdikSS··on I Changed My License
>MIT and source out on GitHub is the easiest way to build trust. You will find that some people simply "steal" your work in this arrangement, but much like with movie piracy I don't think they ever intended to compensate you or anyone else.

You've chosen the license which allows "stealing", why did you do that if you don't like that? Nobody forced you to do that, I hope.

How can I trust the person who published their code with the strict legal terms, but becomes sad when other people use their code exactly as the author said it could be used?

Every once in a while I read discussions about licenses, and puzzled every time why the author of the software chooses free license when the freedom of copying and distribution is seem to them as pirating. If the license is not suitable for you, why choose it?!

Licenses are about legal possibilities. You're looking for social/moral terms instead if I understood you correctly (something like CoC).

ValdikSS··on I Changed My License
>A long time ago, I didn’t mind huge tech companies getting rich partially via open source, now I do.

Is the concern that anybody will be earning money on your software (just that), or that you won't get any money, or that they will earn money and don't give back the code?

If the company earns money and opens the code, is that OK for you?

Just for you and for everyone information, Richard Stallman himself told people not only to sell their own software, but the software written by others as well!

> Actually, we encourage people who redistribute free software to charge as much as they wish or can. If a license does not permit users to make copies and sell them, it is a nonfree license. If this seems surprising to you, please read on.

https://www.gnu.org/philosophy/selling.html

AGPL, just as all other GPL, does not prohibit selling the software. If you goal is to make your software unsellable, please use your own licensing terms (there's nothing wrong with that!!!)

ValdikSS··on How Fairphone built the Fairphone Gen 6+
?

Even Steam Deck has a custom APU made specifically for it. Call it "customized" if you don't like "custom".

ValdikSS··on How Fairphone built the Fairphone Gen 6+
Well yes, I agree, but the option is there.
ValdikSS··on Nearly impossible? How Fairphone built the ethical, repairable Fairphone Gen 6+
With a charging input + 3.5mm dongle?

https://ae-pic-a1.aliexpress-media.com/kf/Sfa5566c711b14a4aa...

ValdikSS··on Nearly impossible? How Fairphone built the ethical, repairable Fairphone Gen 6+
Desktop computers work because Intel and AMD provide support to their chips to Windows and Linux, because these chips are used for desktop and servers, and these OS are what their customers use.

Mobile chips are not used for desktop and servers, not used for Windows and Linux. They are used for Android, and that's a 98% of the market. The customers of the chips (the companies which develop devices on the chips) just don't use Windows or Linux, that's why there's no reason for a chip company to support it.

Android does not use desktop/server firmware, desktop/server bootloader, and even desktop/server stock Linux kernel. They have their own Generic Kernel Image with the Android patches on top, strict Google requirements for the booting and working process, etc.

PC operating systems are supplied by third parties that are not part of the computer manufacturer, motherboard or processor vendor. All component manufacturers must write drivers for Windows, certify them with Microsoft, and make sure that their device works properly ideally on any computer. You, the user, buy (or obtain) a copy of the operating system from the operating system company.

The operating system for a appliance (smartphone) comes with the appliance itself (as a bundle), and is supplied by the appliance manufacturer, not by operating system manufacturer. The manufacturer of electronic components does not need to contact the creators of the operating systems, they write a driver for Android kernel (yes, for Android kernel, with all its wakelock subsystems and such in mind) and gives it to the manufacturer of the appliance directly (and sometimes only supplies hardware, and the driver must be made by the manufacturer of the appliance).

ValdikSS··on Nearly impossible? How Fairphone built the ethical, repairable Fairphone Gen 6+
>but standard enough that people by binned playstation 5 motherboards to use as computers

That doesn't mean that all the features are enabled right from the factory, or that the compatibility with already existing features is lost.

Modern chip's security features are pretty complicated and include hardware patches, hardware debug authentication, multiple provisioning states (and multi-key hierarchy for that), RMA states to clear all the private information, etc.

>Switch runs on basically the same Nvidia Tegra CPU/GPU as multiple android tablets.

Yes, and the one which got cracked with a bootrom vulnerability ;)

That's a pretty working motivation for a chip company to improve their chip security when the company as beefy as Nintendo tells them that their chip is vulnerable they're losing money because the customers can play for free ;). I'm pretty sure patchable bootroms started to be common only after Switch hack.

ValdikSS··on How Fairphone built the Fairphone Gen 6+
iPhone is top-of-the-line as well, because they control the whole software and the whole hardware (starting from basically all the chips). That's very rare in the industry.

There are just a bunch of companies which afford to do the same. Maybe Xiaomi will be the next one.

ValdikSS··on How Fairphone built the Fairphone Gen 6+
The headphone jack is inside USB-C connector. You can use USB-C-to-3.5mm passive (!) cable to connect your 3.5mm headphones, or you can buy 3.5mm headphones with USB-C audio connection.

There's no additional DAC involved, the analog audio is already on a USB-C pins.

ValdikSS··on How Fairphone built the Fairphone Gen 6+
GrapheneOS is like a veteran and war zone expert: for them, not only the external environment is considered extremely hostile that you should leave your house only wearing an armor and with bodyguards, but also the internal environment is hostile: your bodyguards could be bribed and work against you, that's why you need to somehow be protected against that as well.

Just as physical security, digital security most of the time not as radical, and tradeoffs are usually accepted, especially when they are "invisible": hardware and software security features are usually not mentioned in the specs and the regular and even power user just don't know most of them and what do they do.

When GrapheneOS says "private" and "secure", they mean top-of-the-line security features, updates as soon as possible, all available mitigations against zero-days and insecure code which will limit the impact before the patch, etc. Security as in a killdozer.

When other say "private" and "secure", most of the time it means: "we've followed all the recommendations applicable to our development budget, device price point, and support life time". Graphene does not like that definition of these words.

For smartphone, chip manufacturer goal is not to protect the user at all costs, but to provide reasonable security features for the price.

BUT the goal of chip manufacturer to protect the device at all costs is for… game consoles! That's why Xbox, PlayStation, Switch all run on a custom silicon and not an ordinary chips!

ValdikSS··on Restoring 5 GHz Wi-Fi on an LG C5 by changing its webOS region
Linux's wireless-regdb has proper 5G regulatory information for at least SA, CY, EG, QA, at least since 2017, just checked. The TV in the repo is 2025 year model.
ValdikSS··on How to get a free .arpa domain
You can get a TLS certificate on .arpa.

https://crt.sh/?q=%25.arpa&exclude=expired&group=none

There are websites as well

https://5.8.7.1.7.1.3.2.6.1.9.4.e164.arpa/

ValdikSS··on Suica, Japan's First IC Transit Card
I don't know how it works in your country, but in RU you only tap to get in, not to get out. There are no barriers to get out.

1. The card stores not only your ticket/cash data, but also your trips

2. You live far from the metro, so you ride by bus to the metro station. The metro station knows that you've just been on the bus (the bus activated 90 minutes window) and either don't account you or gives you a discount

3. You can also top-up the card using your smartphone with NFC. The smartphone writes data to the card (and can read your balance and a trip of course). But also, if your smartphone don't have NFC or you don't want to install the app, you can top-up using the web and write it to the card anywhere (inside the bus / on a metro station) with the regular validator (it not only reads, but writes the data received from the net as well)

ValdikSS··on Debugging my new network, when 10 Gigabit Ethernet Runs at 300 Megabits
Another example: PCIe ASPM exit latency. Fast LAN speed (because the card does not have time to go into sleep) but low internet speed (manages to enter ASPM if the host is at least 3ms away)

https://lore.kernel.org/intel-wired-lan/803760bf-04ff-4b23-8...

ValdikSS··on Suica, Japan's First IC Transit Card
>tap in/tap off sucks no matter how good the system is. It is fundamentally a wrong think.

Tap system doesn't have to end billing period on tap out, if that's what you're trying to say.

Moscow/Saint Petersburg cards have many options which you can combine (add-on packages), as well as a regular balance (wallet).

"90 minutes unlimited" does how it is named, and if you travel first by metro, then switch to a bus, you pay less in the bus.

ValdikSS··on The brain may be about to have its Ozempic moment
Hooray fatal insomnia
ValdikSS··on Jabber/XMPP: 25 Years of Digital Independence
XEP-0479: XMPP Compliance Suites 2023

https://xmpp.org/extensions/xep-0479.html

ValdikSS··on Jabber/XMPP: 25 Years of Digital Independence
Daniel (the author of the linked article) was one of the people to define profiles for human chatting: https://xmpp.org/extensions/xep-0479.html
ValdikSS··on Wi-Fi 8 is the first wireless upgrade in years that isn't chasing speed
Yeah, somehow nobody invented HCI for Wi-Fi chips. USB has it, Bluetooth has it, but not Wi-Fi.
ValdikSS··on Wi-Fi 8 is the first wireless upgrade in years that isn't chasing speed
There's only 1 (one) all-open chip I know of: ath9k ar9271 802.11n 2.4 GHz from 2011.

Atheros (now Qualcomm) released its firmware source: https://github.com/qca/open-ath9k-htc-firmware

I have many, many these dongles :)

ValdikSS··on AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
They probe all audio devices, including microphones, which probably temporarily switches Bluetooth devices into HPF mode due to how Bluetooth duplex audio works.

I'd argue it's "silent" though: aliexpress wakes up my audio card if nothing plays, which results in a very faint "pop" sound every time I open the tab.

It's been this way for ~3+ years at least.

ValdikSS··on Google has stopped pushing Git tags for some Android source code
>But the most important part is that once you have that source code, no one can stop you from redistributing it in a cheaper and more convenient way

Or vice-versa: you're free to sell publicly available free stuff.

https://www.gnu.org/philosophy/selling.html

ValdikSS··on How to avoid frustration for Open-Source contributors?
I will use the terminology which I invented and use, I don't know more appropriate words.

There's technical open source (code licensed under free license), social open source (accepting contributions, working towards the user, maintaining), and stewarded open source ("the product" with the team, roadmaps, release cycles, but the code is open and free).

Technical vs social: many projects are made to solve the issue of the author, and just published on the internet under a FOSS license for everyone, nothing more. For a random project on the internet, you should not by default assume that the author is willing to fix the issue you report, implement the feature you'd like to have, or merge your contributed code — author may not be interested in solving your issue, they already solved theirs. That's open source which does not have social component.

What you have here is a stewarded open source: a Google project which have a team on a salary. The team has their own plans and goals on their product, and in addition they accept contributions. They might not be interested in them, or even be hostile to external contributions, because some PRs just disrupt their plans, not suitable in their architecture view, or could be seen as a maintenance burden which they didn't ask for. Check CONTRIBUTING.md in the repository: the code contribution is in the bottom of the list, and they have a hour and a half movie on how to contribute!

Since this is a team on a salary, your task is first and foremost to explain the issue you have, and make it clear what is wrong currently, why is it wrong, and how it could be improved. The code contribution should follow only after you've been understood and the issue has been confirmed as an issue. Only then you can make a suggestion PR if you feel so ("I fixed it this way, it works for me, take a look").

Issues with your PR:

- Minor one: used only what-have-been-done technical description instead of just describing the issue in plain words. Not "Reduce iOS pointer latency by dispatching pending input before BeginFrame" and a wall of refactoring later, but "Faster vsync and pointer painting performance", with short technical summary inside of PR message (maybe even video/tests of vsync latency before/after), and all the meat inside the commit message. Keep PR worded in a simple terms.

- Used PR comments as a chat: you wrote like 8 messages one after another in an hour. Give the developers some time to think, to maybe reconsider their decision or vision. The person might just had a bad day and you're just nagging them with questions which require thinking and remembering the code. Wait at least a day, or better a week, before responding to the message with outcome you did not expect.

- After "the infrastructure is broken, we're trying to remove it completely" message it'd better to ask if the developers have ideas, plans, or maybe draft implementation on how it could be improved, and if anybody is working on that already, instead of defending your position when you received decline.

You've got frustrated and disappointed that your PR did not get merged. I understand you and I was in your shoes. However keep in mind what I wrote about stewarded projects and take a closer look where are you contributing at: a project which requires you to sign CLA, which means to give your code authorship to the company. Do you really want to improve the product which is developed for money, without you getting money and giving away code authorship?

Won't write anything in addition, just recommend reading these two articles:

https://sneak.berlin/20250720/the-agpl-is-nonfree/, it's about completely different topic, but read from "Gifts absolutely do not work like that". And https://dri.es/license-only-versus-stewarded-open-source

ValdikSS··on Win-V combo from Windows on Ubuntu
There's also Actions Configuration, where you can implement custom actions based on the clipboard contents in Win+V dialogue.

One of mine: if there's something resembling postal tracking number according to regexp, add "Print label" item which prints its barcode on my Bluetooth thermoprinter.

ValdikSS··on Win-V combo from Windows on Ubuntu
Go to Klipper → Configure Clipboard → Shortcuts

And set shortcut for "Next History Item" and "Previous History Item".

Believe me, it would be much better.

Configure WIN+A and WIN+S for example.

ValdikSS··on Win-V combo from Windows on Ubuntu
It's not the same thing, it's much better, because you can have a shortcut for "clipboard backwards" and "clipboard forwards", which changes clipboard content based on the history of it.

In other words, if you want 3rd history item from the top, unlike on Windows, where you need to press Win+V, down, down, enter, here I press CTRL+W, W.

ValdikSS··on Claude writing a macOS driver for my obscure HP printer built only for Windows
USB-only is a cost cutting measure. Canon CAPT printers have so low amount of RAM that the page is streamed over USB. There's not enough RAM (1-2 MB) to accept the full compressed page at once for complex pages.

Network/Wi-Fi printers have at least 16 MB of RAM, usually 64+ MB nowadays.

ValdikSS··on Claude writing a macOS driver for my obscure HP printer built only for Windows
Printers of the 80s and early 90s were more performant PCs than the typical PC which printed on it. Because you can't process full color 600 DPI page on the 90s PC with 8-16 MB of RAM, but the printer needs to do that.
ValdikSS··on Claude writing a macOS driver for my obscure HP printer built only for Windows
Once and for all solution is to run a dedicated print server for outdated printers, which implement AirPrint/Mopria and convert the incoming data into printer's native language. This way it withstands all the PC/smartphone OS updates and don't require compatibility fixes.

I've spent 3 years on improving all the underlying stack and drivers to make it work reliably and bug-free, but the current RAM prices resulting in 2x price increase for the cheapest SBC, which makes the project economically infeasible to continue.

People on Reddit told me that in US there just "is'nt any non-wifi models". I'm not sure how true this is. If you have anything to comment, please do: https://old.reddit.com/r/printers/comments/1v09kb8/usbtowifi...

← PreviousPage 2 of 14Next →