HNHacker News
TopNewBestAskShowJobs

albntomat0

1,267 karma · joined May 11, 2014

submissionscomments
albntomat0··on Playing with BOLT and Postgres
I posted this in a comment already, but the results here line up with the original BOLT paper.

“For the GCC and Clang compilers, our evaluation shows that BOLT speeds up their binaries by up to 20.4% on top of FDO and LTO, and up to 52.1% if the binaries are built without FDO and LTO.”

“Up to” though is always hard to evaluate.

albntomat0··on Playing with BOLT and Postgres
There’s a section of the article at the end about how Postgres doesn’t have LTO enabled by default. I’m assuming they’re not doing PGO/FDO either?

From the Bolt paper: “For the GCC and Clang compilers, our evaluation shows that BOLT speeds up their binaries by up to 20.4% on top of FDO and LTO, and up to 52.1% if the binaries are built without FDO and LTO.”

albntomat0··on Michael Lewis's Blind Side
A large number of people, less than the “hundred million” that you mention (Wikipedia says FTX had “over one million” customers [0]) lost their highly speculative investment. Yes it’s a crime, and yes it’s serious. All I’m asking for is some nuance.

[0]: https://en.m.wikipedia.org/wiki/FTX

albntomat0··on Michael Lewis's Blind Side
My view is that folks lost their life savings on crypto on FTX is only a more extreme version of those who lost their live savings on crypto on some other exchange. The fraud is terrible, but only exasperates the problems of those gambling with limited resources to absorb loses.
albntomat0··on Michael Lewis's Blind Side
I do not. My comment was in response to the parent comment saying that financial crime “absolutely causes people to die” and “create far more misery than your average mugger”.
albntomat0··on Michael Lewis's Blind Side
To what degree was the money lost by SBF/etc going to be put towards saving lives, versus the dreams of the average crypto person?
albntomat0··on Anki – Powerful, intelligent flash cards
I’ve used their tarballed installer, which is straightforward. The app itself then checks for updates, and displays a reminder when there’s a new version.

Not as nice as having an updated version in apt, but it’s a trivial amount of work for something I personally get so much value out of.

albntomat0··on ICJ orders Israel to prevent genocide in Gaza, stops short of ordering ceasefire
Written, a combination of New York Times, Washington Post, and what Google News aggregates (frequently includes Fox and a mix of websites of local news websites)
albntomat0··on ICJ orders Israel to prevent genocide in Gaza, stops short of ordering ceasefire
> In America, it's wall-to-wall "police say"-like IDF clips and Bill Maher condemnation, dehumanization, and equivocating Palestine supporters with Hamas terrorists. The talking heads cheerfully greet Netanyahu.

As someone who also consumes US news, this does not describe what I’ve seen.

albntomat0··on ICJ orders Israel to prevent genocide in Gaza, stops short of ordering ceasefire
I find it hard to believe there’s correlation between the beginnings of Russia-Ukraine and Israel-Hamas and who the US president is.

If anything, Russia and Hamas are each less likely to spark each conflict (in the specific sense of invading Ukraine and 7 October, not the preconditions) knowing that the US is more likely to provide arms to Ukraine and Israel.

albntomat0··on If you make $10M in sales, Apple's cut is $6.2M annually
It’s disingenuous because they intentionally chose numbers on the pricing curve that resulted in the most clickbaity results.

There are plenty of valid criticisms, but I felt the author’s post missed sufficient nuance.

albntomat0··on If you make $10M in sales, Apple's cut is $6.2M annually
I can’t say I’m a fan of the pricing model, but the linked tweet makes specific choices regarding the number of installs, which in turn determines the pricing.

The tweet has 10M installs, where each one makes a $1. 5M installs where each one produces $2 in revenue results in a smaller cut by Apple. 20M installs at $0.50 results in a larger cut.

albntomat0··on No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
I looked it up, and the extended security updates for Google Pixel is only a recent change:

Pixel 8: released in 2023, updates through 2030 Pixel 5: released in 2020, stopped getting updates in October 2023.

https://support.google.com/pixelphone/answer/4457705?hl=en

albntomat0··on Apple wins bid to pause Apple Watch ban at US appeals court
Is there a concrete explanation of what Masimo’s actual innovation was in their patents?

They were posted in a previous thread, and the way they were written made it unclear what was actually covered. Is Apple allegedly infringing on the idea of putting a blood oxygen sensor in a watch, a technical innovation in how to do so effectively, or something else entirely?

albntomat0··on Facebook Is Being Overrun with Stolen, AI-Gen Images That People Think Are Real
T-Mobile also doesn’t send your texts to millions of people based on the engagement they generate.
albntomat0··on If You Bought a Tesla One Year Ago It Has Lost as Much as $40k in Value
Summary: Tesla has decreased its prices over the last year, affecting the resale value of existing vehicles. Author makes this out to be entirely bad.
albntomat0··on The Decades-Long Travesty That Made Millions of Americans Mistrust Their Schools
I’ve often wondered if a similar result happened for me. Six year old me got Pokémon Blue, which is pretty much all text based. Coupled with comic books at a friends house, I had great internal motivation to figure those out!
albntomat0··on Walmart customers getting hostile at self-checkout – they blame anti-theft tech
I got accustomed to pausing whenever the machine was speaking, to avoid the race condition I mentioned above. I went with a friend to a different store, in a new city, and she was very confused by the weird set of behaviors I had learned to keep the original machines happy.
albntomat0··on Walmart customers getting hostile at self-checkout – they blame anti-theft tech
I’ve had significant issues with some particular models of self-checkout. They have some sort of weight check after scanning an item, to see if I’ve placed it in the basket. I assume they’re matching up the items known weight, with the change in the weight in my bag.

However, it’s implemented poorly, with frequent false positives. Furthermore, there’s a race condition between scanning the item, the machine saying “place it in the bag”, and the actual weight check. If I move too fast, the item is in my bag before the check starts, and I have to wait for assistance.

Maybe folks are frustrated that their theft is being caught, but high frustration seems to be the base case here.

albntomat0··on Why you shouldn't join Y Combinator
Direct from the article:

"BUT YOU JUST WANT TO SELL YOUR COURSE!!! Ahahaha, you caught me! It’s true. I do have something to sell you. I run a community for small-time entrepreneurs who are satisfied with reliably attainable mediocre success. The YC folks feel sorry for our joy with mediocrity while they’re out there changing the world. And we reciprocate the emotion.

So yes, I am promoting something that goes against everything YC stands for. But if you think YC is not also selling you something, I have a bridge to sell you. But maybe I’m being a bit too harsh. Because what is it that YC is selling you exactly?

Me, I charge you a one-time payment of $245, and you get access to my community, which includes live workshops, recorded classes, a group chat, and a few other things. It’s very clear what I’m doing. I ask for some money in exchange for access, and those who give me the money get access. Even my 6 year old kid understands it."

albntomat0··on Why you shouldn't join Y Combinator
Yes, and I’m free to criticize it for being a mediocre article with a clickbait headline.
albntomat0··on Why you shouldn't join Y Combinator
I considered that as an issue with being a vc funded startup founder. I could have made that part slightly more clear.

Once again, a much broader issue than just YC! The author could have written the exact same article, just with VC instead of YC.

albntomat0··on Why you shouldn't join Y Combinator
The article discusses known issues being a startup founder, such as the low odds of success, as if they’re unique to YC, followed by a pitch for his own product.
albntomat0··on Google assigns a CVE for libwebp and gives it a 10.0 score
I agree it's definitely possible, and I'm certain we'll see a vuln due to some crazy Rust optimizations in the future.

That said, not switching over to a memory safe language, in my opinion, is letting perfect be the enemy of the good. Folks will still be able to write footguns, but better language choices will prevent bugs in the all the non-crazy optimized parts.

albntomat0··on Google assigns a CVE for libwebp and gives it a 10.0 score
Ahh cool! I was unaware of Wuffs. Thanks for sharing!
albntomat0··on Google assigns a CVE for libwebp and gives it a 10.0 score
There's a substantial difference between a hobbyist writing a random project in C, and Google writing an image processing implementation, and then including it in Chrome and Android.
albntomat0··on Google assigns a CVE for libwebp and gives it a 10.0 score
Yes, and so are Python, Lisp, Haskell, and a million other languages that were available in 2010.

None of those are suitable options for an image decoding library on the range of WebP supported platforms.

albntomat0··on Google assigns a CVE for libwebp and gives it a 10.0 score
Additional timeline info, as I was curious myself. WebP is old enough that a memory safe language was not a feasible option when the project started.

Android 12 was the first version to support Rust code, and came out in 2021 [0, link talks about the first year of integration].

On the iOS side (which also was affected by this), Swift 1.0 came out in ~2014.

As far as I can tell, Chrome doesn't yet support a memory safe language, but do have a bunch of other safety things built in (see MiraclePtr, sandboxing, etc). Since both WebP and Chrome are from Google, this would stop a possible transition.

WebP was announced in 2010, and had its first stable release in 2018 [1].

[0]: https://security.googleblog.com/2022/12/memory-safe-language...

[1]: https://en.wikipedia.org/wiki/WebP

albntomat0··on The WebP 0day
Apple and Chrome specifically matter here because those where the targets being exploited in the wild, and have the most direct attack surface with the largest number of users.

The author mentions that many other systems need to patch as well. However, wow many of those billion Python docker pulls are rendering untrusted WebP images? Same for Node, etc. These should also be promptly patched, but they're not in the same ballpark here as iOS/Android/Chrome.

albntomat0··on The WebP 0day
The author is the former lead of Google Project Zero, and the article is an in depth look at a low level bug.

He’s certainly aware of memory safe programming.

Page 1 of 14Next →