HNHacker News
TopNewBestAskShowJobs

alerighi

1,971 karma · joined April 10, 2017

submissionscomments
alerighi··on Pixel 11 doesn't yet meet the GrapheneOS security standards and may be skipped
If you say something about it you are accused to be a communist because you are against free market, from people that doesn't even know what the term free market means (yes, we need rules to make the market truly free, deregulation is not the way).
alerighi··on Powerless F1 drivers frustrated by Bahrain F1 software glitch
This F1 is shit, I've lost interest in it. When the race winner is not determined by the pilot skills, or the team, or the car itself, but by some software, battery power, excessive ruling, lawyers, etc. it's to me not at an interest to be seen.

To me F1 shall go back, remove all the crappy rules made in the last 20 years, return to pure gasoline V10 engines, no turbo, no hybrid, minimal electronic, no closed park, no limit in consumption of fuel, tires, etc, return to refueling during the race, and let the better pilot with the best car and the best team win.

These F1 is too sophisticated, at this point to me makes very little sense even racing, just race the car in a simulator at this point, everything is decided by the electronics and algorithms anyway, seeing talented pilots like Max Verstappen or Lewis Hamilton struggle to race because the electronics of the car doesn't let them show their potential, because they have to "save battery" or "save fuel" or "save tires", doesn't make a good show to me.

alerighi··on Big Tech ruined the cloud, so we're renaming ours
That is something not required in a domestic setting, that is what HomeAssistant is designed for. I don't know why your children needs to have access to HA (or the internet afterall).
alerighi··on Git 3.0's upcoming SHA-256 default will be a costly mistake
You are basically resolving a non-existent security problem by generating a far bigger security problem, because I'm 100% sure that a ton of software just assumes that a git commit hash fits in a `char[40]` and thus will buffer overflow like hell if they try to operate on new repositories.

And we are talking about who knows how many tools that work with git built in the years, and this is also made it worse from the fact that most tools just invoke the git binary and capture its output instead of passing from a library.

I like more the solution proposed at the end of the article, do not change sha-1 but instead, if you are relying on git commit for security purposes (that was never the intended use) add another header to the git object with a sha-256, so that with the small expense of computing the hash twice you don't break 20 years of existing tools that make the assumption of the git commit being 40 character long.

alerighi··on Git 3.0's upcoming SHA-256 default will be a costly mistake
If you rely on the commit SHA-1 as a integrity verification it's your problem. Git was never intended to be used as an integrity check.
alerighi··on AI companies in race to demonstrate their model most threatening to humanity
To launch a nuclear missile you need to physically insert a launch code than only the president has closed in a suitcase that is well guarded, as well as physically turn two keys that are enough distant apart that one person alone couldn't.

Now, unless your AI gains access to the codes, and sends two robots in a bunker or nuclear submarine to insert the code and turn the keys to launch the missile, you can be modestly sure that no AI could launch a nuclear missile or nonsense like that.

I'm quite frankly more worried that some foolish president decides one day to launch a nuclear missile than an AI could do it.

Now that we return to the real world, the only thing AI could do is to attach systems that are connected to the internet (and critical systems are not), but let's be real, AI are not really that intelligent by themself, it's not that someday an AI could decide like in Matrix or Terminator to exterminate humans, because (at least now) AI have no consciousness and can't really decide what to do.

An human can of course use an AI to carry out cyberattacks, as he can do that also without AI like it's done since the internet exists, but it's an entirely different thing (a human using a tool, AI, to do damage VS the AI itself that decides by himself to destroy the human race).

alerighi··on What About Rails?
A chatbot is worse than a CLI app: a CLI app does exactly what you ask for, and has a manual documenting exactly what command do what, and the output is consistent, the same command does the same thing period.

A chatbot using an LLM of course not, it suffers from hallucinations, it may do what you want but there is a change it won't and you have to fight it to get the desired result.

Chatbots are far WORSE than traditional UI for everything. If some product has a chatbot functions it's the first thing I disable, if it's not possible to disable it, I avoid the product.

And GUI applications are typically preferred, at least for the normal people and not us nerds, to CLI applications, since you know people like moving a mouse and clicking on buttons (or tapping them on a touchscreen) that learning commands: a chatbot doesn't make the CLI experience less awful for the average user, and for the nerd user, he prefers to use the CLI directly (replace asking the chatbot with man or --help and you don't need to emit tons of CO2 and transmit your personal data to a datacenter on the other side of the world to do stuff you did with MS-DOS)

alerighi··on I'm tired of being on the network
Except it's impossible nowadays, since most apps require Google Play Integrity attestation and doesn't work on GrapheneOS.

And if it wasn't for these apps (for example banking apps, since someone decided that it's now impossible to use your homebanking from a PC since it's not secure enough) I would already use a Nokia 3310.

alerighi··on F-Droid 2.0
So basically Google is being now more of an asshole than Apple (that now allows app sideloading and third party stores, at least in the EU). I'm and Android user since the beginning and for once I'm start considering for the next phone that I could as well get an iPhone, basically all the good open stuff of Android is long gone (back in the days I used to flash a new ROM every week), and at least Apple is better in regards of privacy than Google.
alerighi··on AMD's random number generator can't generate a 0?
> There is a reason so much effort is put in TPM and remote attestation and so on

If you trust TPM not to be backdoored... come on, you don't think the NSA or who else has put effort in getting a backdoor inside? They even tried to put one in Linux and it's documented, never the less in anything proprietary...

> It can just read the generated seed directly from user space without the program ever knowing about it.

Not that simple: it has to know exactly where in memory it's stored, and that requires understanding of the source code of the program that is encrypting data. That is not of course a simple task if someone wants to write a malware that just "steals" encrypted data from any software just by looking at the network traffic, like you would do if you compromise the RNG of the OS.

> clock_gettime() just reads a value that the kernel has set, so that's not particularly difficult to fake.

You can sample the call millions of time and understand if the value is truly random or there is a pattern. It's something detectable. Software like GPG that doesn't trust what the OS gives you already do that (as well as combining multiple entropy sources).

> It's fine if you use it as a strictly additional source of entropy, but then the whole argument that it is superior because it avoids syscalls goes out of the window, because you're doing strictly _more_ work.

Avoiding the syscall could have other benefits, not only performance. For example: a program making that syscall may be flagged by a possible backdoor as a process with something interesting in it, and thus a potential spyware may be interested in take, for example, the memory image of that program and send it to a remote system for it to be analyzed. The fact that the reading of the current time doesn't pass from a system calls means that it's not possible to identify that process as "some process that uses cryptography and thus has something interesting in it to hide".

alerighi··on OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005
I mean, the LLM could do it even without all the HUMAN knowledge that was stealed during training about the Enigma machine?

We are fooling to me, there is no intelligence in these models, they just apply methods that were invented by humans without any consciousness on what they are doing.

alerighi··on I said no and Apple said yes
And soldered RAM and SSD, even battery replacement that with other computer is simple is a difficult task. Only USB-C ports, so you have always to carry a stupid adapter for normal things like connecting a USB stick or a network cable. ARM architecture so old software needs emulation to run, emulation that makes computer performance horrible.

Sure, Linux laptops are not "pretty", but I don't need a computer to be pretty, in fact I hope that someone starts to produce again laptops identical to old IBM thinkpads (not the insult to the brand that Lenovo is building) but with modern hardware, a computer that had every port you need on it, no adapter required, that you could have it fall from a ladder and not break, with removable battery, hard drive, with the trackpoint instead of those stupid trackpads, I want it even with a DVD burner fuck it. I don't care it to be small, I care it to be functional.

alerighi··on AMD's random number generator can't generate a 0?
Depends in what trust do you have over your hardware/OS. If you assume the hardware is potentially backdoored, and the OS is proprietary, or even if open could have malware/rootkits that can thinker around the random number generator, the solution of using a sole implementation inside the program (assuming the sha256 function is inside the program itself) maybe better.

Sure an infected system may as well fake time values, but that is much more difficult and it's possible to detect from a userspace program. For example you mention to use getentroy, but on a compromised system you know how easy it is to change something that is implemented in a system library (e.g. libc) or even if you read /dev/random directly without passing from the libc how easy it's to make it read whatever you want?

To me that is not that bad implementation, in fact it's an implementation that is used in a lot of security software (including GPG, not as the sole source of course but as one of many).

alerighi··on We write code by hand
It's not the same example, the excavator is driven by a human being, it's a tool (in coding world the same as using an high level programming language instead of writing bits into the computer memory).

The LLM *may* be used as a mere tool, that is something you ask question time to time, but shouldn't be the thing that makes the work that you should do. Because if we arrive at this point (hopefully never) at that point the CEO of the tech companies may as well say, why we still need developers? Let's fire all of them.

Fortunately they did not, because there is STILL VALUE in writing code by hand, understanding what it happens, what the code will do, etc. I hope this will not be a lost skill, or well, if it does good for me, because the same as nowadays things being able to repair electronic devices makes a ton of money (I've considered opening a repair shop) because there is no one still doing it, will do programmers that well, know how to program.

alerighi··on ZuckOff is a free app that sees Meta glasses before they see you
If one person knows how to code, they don't need an LLM. I've tried using all of them on my job, and I will give them a second chance time by time (to see if the claims made by these big tech hold up) and ALL of the time I've didn't noticed any speedup compared to coding manually.

If you are an experienced programmer (not someone that did an online course and calls like this) with YEARS of experience in coding in multiple languages really, the only real limitation is the speed at which you can type on the keyboard, that is usually way faster than what the even good LLM is able to emit tokens.

This not considering token expense: if we see at the point of view of the company, it's way cheaper an experienced programmer, that in my country costs you 4000 a month tax included, than the tokens that an LLM would use to do the same job.

On top of that there is the environmental impact of all of this, and why they are almost making me not use my car because it's euro 5 and now there is euro 6, these AI companies are emitting tons of CO2 to do stuff that human beings can do with 1/1000 the energy that these AI companies use.

alerighi··on AI-generated posters don’t have to be horrible
To me if you ask to a 10 years old kid and give him a PC with Microsoft Paint on it it will you will have a much better result than any AI-generated option in the post. If there are graphics designer that produce a worse result of what AI creates, it's because they probably use AI as well.

The problem of AI generated stuff (we see the problem of manifests, but I'm a software engineer and with computer programs it's exactly the same thing) is that they immediately look non-human, and our brain trained itself to detect, and thus get irritated by, AI generated content.

It looks fake, it hurts to see, it seems fine at first glance fine but it's not, everyone seems identical because the AI is not, despite of the name, creative, it just a hyper complex copy/paste machine, and obviously the result just looks copy/paste as well.

alerighi··on I don't like passkeys
To the day where your device breaks, you had set a passkey to access your Google account (because the phone did prompted it up and you did not understand and clicked yes), you did not setup a recovery method (such as another email/SMS) or you did setup a recovery method that still depends on the Google passkey access (e.g. a second email account where you sign in with Google or has Google as a two factor verification!) and you are locked out of your Google account. Good luck at that point contacting Google assistance, you may as well consider that account as lost forever since there is no way to talk with an human being.

And unfortunately is something I start to see to family members/friends that are not tech experts when they ask me to setup them up a new phone... at least the passwords they would have written them in some notebook that they had at home, or always used the same for everything, but with passkey... and when you tell them that they lost access to their email, possibly the files backed up to Google Drive/Google Photos, etc they are surely not happy.

Also passkeys makes it difficult to get access to your account in an emergency scenario, what if I loose my phone and I'm not signed in to other devices? Maybe I've setup an SMS as a recovery method, but first I have to get to my phone company to request another SIM card, maybe I'm on vacation on the other side of the earth in vacation for 2 weeks, I'm locked out of my Google account, and from all accounts that uses the passkey as a sign-in method (including, for example, the account that I need to use to check in on my return flight, or my banking app that I need to pay stuff!)

alerighi··on Nearly impossible? How Fairphone built the ethical, repairable Fairphone Gen 6+
I've bought new a Google Pixel 7a two years ago, paid for it 400 euros. After 1 year I've dropped it, landed on a corner, screen completely broken, replacement costed screen costed me nearly 120 euros (and was not an original screen, otherwise I would have spent more). Just costs much money because of the fucking fingerprint reader under the screen that why couldn't put it in the back of the phone as they did for many years. Broken it again, fuck it I will not repair it again, with the cost of the repair I may as well buy a new phone.

Then I've decided that is worth either spending money on phones whose replacement parts doesn't cost half of the phone itself, or just buying the cheapest Xiaomi or similar chineese brand phone and when it breaks buy a new one or repair it (funny enough cheap phones are more repairable than expensive ones, so I usually repair them).

alerighi··on AnkiDroid: Google Play no longer allowing Open Collective donation link
Nooo what you are saying communist. I also think so, but each time someone (typically the EU) does something in the direction (e.g. digital market act) the US government, companies and citizens accuse us to be communists, against progress, that we overregulate, that the "free market" regulates by itself, and similar bullshit.
alerighi··on AnkiDroid: Google Play no longer allowing Open Collective donation link
Being a developer, I can say that working with Google is a pain. There is no possibility to talk with a human, all communication is answered by the same AI-generated response that links you to the same AI-generated documentation.

And if such AI does something wrong (which it does) no matter what they WILL REMOVE your app. Because they don't care about you. Sometimes the only way out is to publish the app again with another package identifier, because once they flagged it even if you remove all reference to the offending feature there is no way that they will accept it (it unfortunately happened, fortunately before releasing the app to the public so we could switch without affecting users).

In some sense I prefer Apple (and I say it as an Android user), you surely pay an annual fee to publish to the store, but if you have some issues you can open a ticket where a fucking real human will look into it and answer you, and explain what to to.

alerighi··on Suica, Japan's First IC Transit Card
Maybe it was advanced for the time being created, to me it's just any other RFID card that is issued everywhere else in the world in the matter of read speed, from every public transit card that I find in every EU country I've visited (maybe for a US citizen not used to public transit it seems something special, I don't know), to skipasses, to even your gym card.

Having the option to also pay with credit card would be much more convenient to tourists, when I visited Japan I've had difficulties finding the right place to get a SUICA card (being that my Android phone didn't have Felica chip, as most phones sold outside Japan), and on top of that you almost everywhere need to charge it with only cash. And you can charge it only by 500 or 1000 yen at the time (depending on the machine), and of course tickets always have not round prices like 110 yen. And you have 500 yen of deposit for a card that probably costs to them 10 yen to manufacturer, unless you get the red SUICA card that you can get only in some special machines at the airport but with that you don't get back the unused credit when you leave (you can spend it at vending machine tough).

So the speed saving of a couple of ms of not having to pay by tapping your normal credit card is completely vanished by wasting time to charge that card.

BTW even if they don't want to put credit card POS on every station (I get it, it's expensive and they need to pay fees if someone uses a card, compared to cash) they could make a system that uses regular NFC (would be 100ms slower, who cares) at least for tourists so they can use it with a regular NFC card in their phone wallet that they can charge with an app without requiring a technology that only works in phone sold in Japan?

alerighi··on Suica, Japan's First IC Transit Card
Well you can get it only in some kind of machines, and you need to pay it cash. Also you need to use cash to charge it, and you can charge it minimum by 1000 or 500 yen at a time depending on the station, not less.

The digital version only works on iPhones, since Android phones sold outside Japan doesn't have the Felica chip, or if they have it (e.g. Google Pixel) is disabled in EU/US firmware because the manufacturer doesn't want to pay a fee for every phone to Sony for something 99.999% of people that will never travel to Japan would use.

alerighi··on France reaches 94.9% fiber coverage in 2026
In Italy we are at 78% of addresses covered. That doesn't mean automatically that one gets fiber. First at all, if someone doesn't need to download heavy stuff and has a good coverage a 5G SIM with unlimited data (something you can get for 10/15 euros a month) is cheaper than a fiber connection (that starts from 25 euros).

Second a lot of people has still FTTC even if it has FTTH, mostly because FTTC offers a speed that is enough for most people (100Mbit/s) and upgrading may have costs (the installation of the fiber is at the expense of the ISP, but if you need to make modifications, such as put a pipe from your house to the street in which they will put the fiber, it's at your expense). In some cases even if fiber is present it's difficult/not possible to get it into your house (for example you live in a condo and the other tenants doesn't want to spend money to make the modifications that are needed to pass the wires).

In any case they have started to switch off copper (since it costs money to maintain an infrastructure that has decades), so either way customers will be forced to move to fiber or 5G network in the upcoming years. In any case a fault on a copper line is likely not to be repaired...

alerighi··on Apple introduces M6 and M5 Ultra
It doesn't really matter, because x86 processors inside are almost similar to modern ARM processors, the instructions that most programs use are more or less the same, and more complex "legacy" instructions are just emulated by splitting them into simpler instructions inside the CPU.

To me people that say that x86 is slow etc. never used an x86 processor with anything other than Windows. Yes, Windows is shit and laptops that run Windows are for the same reason shit. I get it. But on an x86 system you can run other OS, and, for example, a Linux distro with well tweaked power consumption parameters can get you even 3 days of battery life, or even more.

The point is that Windows keeps almost always the CPU above the minimum frequency, because it's full of useless background services, because programs are not well optimized for the hardware (to maximize backward compatibility they don't compile target x86_64 v3 for example and thus don't leverage on features and instructions available on new CPU or fall in the emulation case I've mentioned initially), and other reasons.

With a Linux distro you can keep the CPU at 600Mhz while web browsing, you can even turn off cores that you don't need, and the battery with this configuration surely lasts ages (at that point it becomes more predominant the consumption of other peripherals such as the display).

alerighi··on Apple introduces M6 and M5 Ultra
Really in Linux you can setup then do do whatever you want, you can setup them the same of Windows or MacOS if you want.
alerighi··on Apple introduces M6 and M5 Ultra
I have in my basement a PC with Windows 98 that feels way faster using it than a modern Windows 11 full of vibecoded AI slop features.
alerighi··on New Mac Studio with M5 Max and M5 Ultra
For this reason: more upgradable

Apple wants to sell you a new system every couple of years, they don't want you to upgrade. They want you to throw it away the system completely and replace it (and they claim they are environmentally sustainable, btw) when in the PC world you would replace RAM, CPU, GPU, motherboard, maybe the SSD, but surely you can keep the power supply for decades, keep cooling fans, not talking about the chassis that could last 50 years because it's a just metal box.

They are a rip off these products, and I don't understand people that buys them.

BTW even when Apple did produce towers like Mac Pro they did so in a purposely non-standard way, such that you couldn't, for example, replace the PSU with a standard ATX one, the only standard components were really RAM, HDD, CD-ROM drive and in Intel models the CPU, and of course PCI expansion boards (sort of, because to work GPUs needed to have an Apple specific firmware in the old PowerPC models). You couldn't for example upgrade the motherboard, if you wanted to change the CPU to a new generation you also needed to buy a entirely new Mac with a new chassis, new PSU, etc even if what you had were perfectly fine.

alerighi··on New Mac Studio with M5 Max and M5 Ultra
Same thing, I still have at home a desktop I've built when I was 17 (now I'm 30!) and still runs fine for day to day tasks, of course with Linux on it. It has 8Gb of RAM (DDR3), 512Gb SSD (not original of course because back then they did cost an astronomic price) and an i7 CPU that I've overclocked, an NVIDIA GPU with 2Gb of memory that still plays older games fine.

To me there is no reason to update a PC if you don't use Windows or MacOS that forces you to purchase a new hardware to do the same things. Just look at Windows 11, full of useless AI features, weights a ton, and in the end it's probably faster a PC from 25 years ago with Windows XP.

alerighi··on RAG Is Simpler Than You Think
Everything that is generate from a LLM is shit, I don't know why people continue using it. I'm waiting for this bubble to explode once for all so we can return doing things in the sane way.
alerighi··on How Europe is killing makers and micro-entrepreneurs
My barber in Italy just doesn't make me a receipt in exchange for a discount if I pay him cash so he doesn't have to pay taxes. Come on... the cost to operating a small business are usually low/there are tax exceptions, and they most of the time are even not payed at all.

Of course if you are a person that ships 20 packages you don't register a company to do so, nobody will, you just sell them privately (and the exception to sell things privately is quite high, in my country you can do it up to 5000 euros AT YEAR, after that you need to declare the income in your tax declaration but still you don't need to register a company if it's not your main income).

Page 1 of 24Next →