HNHacker News
TopNewBestAskShowJobs

alance

75 karma · joined March 25, 2012

submissionscomments
alance··on Chrome again exempts Google from user site data settings
Does the same behaviour manifest in Chromium?
alance··on Ask HN: Who is hiring? (September 2026)
You've mentioned some roles are fully remote - ok to apply from Australia or no? (it's absent from the extensive list of locations on the jobs)
alance··on Felony charges for citizen deleting phone data at US Border
They deprecated that one.
alance··on Pixel 11 Pro Fold feels like the end of an era
The pixel 5 ticks a lot of the same boxes as the pixel 4 btw. Similar form factor, but bigger battery and wireless charging. Plus if you install florisboard from f-droid you can customize a one-handed mode for the keyboard, which works quite well.

Also this: https://lineage.microg.org/ so you can run a less-google-ish phone, but also run maps if need be.

alance··on Browser De-Slop
The firefox bit has these:

> Disables native privacy and anti-tracking features

> Disables DNS-over-HTTPS

Why?

alance··on Privacy is an underrated advantage in Slack apps
Clickable: https://dibsonstuff.com/privacy-concerns-queue-bot-vs-dibs-o...
alance··on What I learned selling 2,500 MIDI recorders: Hardware is not so hard
Ok are you riding with two huge boxes containing all your work on an electric unicycle and I guess the hi-vis top means you're headed into traffic and the box-cords seem to be balancing at the halfway point of the boxes and this is too much anxiety for me. But hey, glad you optimized for minimalism on the PCB ♡
alance··on Designing emoji for the way we communicate today
As soon as the thumbs-up started rotating and the severed wrist was revealed, it became apparent: I had never wondered where the rest of the thumbs-up person was before. But more chillingly: A thumbs-up from a person off-screen is fine, a disembodied hand wishing me apparent good-will? Not so good. It's a corpse-part!
alance··on I'd prefer to avoid AI comments on Reddit and HN
Oh! And if one felt like solving the puzzle, it might lead to that person being mis-identified as being a bot. Which would be a perverse incentive to avoid wrecking the trap.
alance··on I'd prefer to avoid AI comments on Reddit and HN
I'm suggesting that one should not be able to obviously detect that they're being challenged.

Eg I could respond in Pig Latin to you right now because I can see that's what you're asking, but if that particular request were masked or hidden or behind a puzzle, and you received a Pig Latin response well, maybe it's a bot (or a capture the flag sort of a person)

alance··on I'd prefer to avoid AI comments on Reddit and HN
This whole thing was more of a shower-thought. But the trap I left behind was a link hidden in a full-stop in a deliberately acquiescent comment.

The link went to an imgur image. The image consisted of a bunch of numbers. The numbers were a simple off-by-n alphabet cipher (eg a=8, b=9...) which when decrypted, spelled out a message to the AI. Oh, and also the image looks very dark, a human might not even see the numbers.

This is all ridiculous. But I am wondering about other approaches to see if I can get a bot to bite and reveal itself.

ps: the message once decrypted, suggests that the commenter is incorrect about the thread. I am hoping this would give the bot the necessary pushback it craves to continue the conversation aggressively.

alance··on Ask HN: What Are You Working On? (July 2026)
A local neighbourhood cake-stall marketplace. Got a great recipe and some time to bake? Put a picture of your sweet treat up, and get strangers knocking on your front door. You get cash-in-hand, delicious reviews and get to share your family recipes with your local community. No need for shopify, websites, and middle-men. Not sure what to call it, maybe something like onlynonnas.com ?
alance··on Ask HN: What Are You Working On? (July 2026)
Did you take a look at one of the chat-based queuing platforms, something like https://dibsonstuff.com people seem to use it for taking turns with servers, but it sounds a bit like it might work for your use-case too.
alance··on OpenWrt One – Open Hardware Router
Sounds like you might need to screw your own mounting post in at the 30mm mark.
alance··on Meta Shuts Down End-to-End Encryption for Instagram Messaging
Perhaps they should phase out the encryption on WhatsApp as well?
alance··on Cal.com is going closed source
I only found cal.com in the first place because I searched for an open source calendly alternative.
alance··on Session is shutting down in 90 days
Or why not include the source of your claim up front?

From GitHub comments: https://github.com/signalapp/Signal-Android/issues/10247

Greyson:

> Hi there, sorry, this issue was fixed in 5.17 (which hit 100% production on 7/21)

They had a difficult to reproduce problem reported in late December 2020, and got the fix rolled out seven months later.

Not sure your criticism "absolutely inexcusable slop code" is well considered.

alance··on Session is shutting down in 90 days
Source?
alance··on Ageless Linux – Software for humans of indeterminate age
Australia as well.
alance··on Boy I was wrong about the Fediverse
There are probably parallels with rap artists. There are those that improvise and flow.

(the rest of us edit and re-edit)

alance··on Backing up all the little things with a Pi5
Jotted down my backup process for home. Spoiler: it's a bunch of SSDs sitting on top of a Raspberry Pi. But there's a few fun things in there too: raid, encryption, cron, make, rsync, ssh, Home Assistant and a tiny loaner dog. Enjoy.
alance··on Start all of your commands with a comma (2009)
Just on your first suggestion, this also means that if a person or process can drop a file (unknown to you) into your ~/bin/ then they can wreak havoc. Eg they can override `sudo` to capture your password, or override `rm` to send your files somewhere interesting, and so on.

Btw on the second suggestion, I think there's a command named `command` that can help with that sort of thing, avoids recursive pitfalls.

alance··on Termux
Fwiw termux + rsync for android phone backup (eg rsync /storage/emulated/0/) will grab most things.
alance··on Bye Bye Gmail
I used to self-host email, it was mostly all initial setup and then it just worked for years. Eventually I got a bit wary about the security side of an internet-accessible box and decided to move the whole thing over to AWS SES. Wrote it up here:

https://alexlance.blog/email.html

alance··on Customer growth is slow. Who do I talk to?
Good question. So one change I made last year was to cap the number of queues the free account could utilize. It's sort of hard to know for certain if that was what moved the needle though.

There has been a suggestion that maybe the free plan could just be a time-limited trial instead.

But it feels like there is some risk associated with that - as often a customer will use the free plan for (eg) six months, before hitting the limits and becoming a paid account.

alance··on Ask HN: What did you find out or explore today?
A talk about creating from Ethan Hawke called "Give yourself permission to be creative"

https://www.youtube.com/watch?v=WRS9Gek4V5Q

But my takeaway was more like "Give yourself permission to be bad"

Felt good to be reminded that if you want to make interesting things, it's ok to flail around. It'll feel foolish and that's completely ok, perhaps necessary.

alance··on Ask HN: What did you find out or explore today?
Might have been this thing:

https://v.redd.it/fpa35i6b97dg1/CMAF_1080.mp4

alance··on A personal password manager that works over SSH
It seems like the choices are:

a) a cloud-based password service (eg 1password) or

b) a local-storage password database (eg pass, KeePassXC)

My preference is not to store personal account details with an internet accessible third-party (but I can see the value in it for an organization).

And with the local solutions, it doesn't really seem pleasant to manage, use, synchronize and backup password databases across multiple machines. Also it seems like you're just one laptop disk dying away from possibly losing credentials.

To be clear I'm not suggesting anybody should use my hacky script - the article is meant to be more like: "well I don't love this, but here's how I do things".

Got another approach?

alance··on Replacing my mail server with AWS SES
For many years I used an EC2 server for my personal email (running Debian and Postfix) but I recently decided it might be better to have one less internet-facing server to worry about.

This article documents the setup for AWS SES to handle incoming/outgoing mail delivery.

alance··on Using extended attributes to tag files
Ha, it suddenly sounds like trouble.

Eg: one could piggy-back an entirely new file onto an existing file (it might have to be text encoded?).

It looks like the kernel might impose a limit of 64KiB on a file's metadata, but that's still quite a lot of room for data smuggling...

Page 1 of 3Next →