HNHacker News
TopNewBestAskShowJobs

alexfoo

806 karma · joined July 19, 2012

submissionscomments
alexfoo··on Owners mourn spoiled food after firmware update bricks Samsung smart fridges
It's beyond just "30s in each quadrant".

https://www.oralb.co.uk/en-gb/product-collections/oral-b-app for an example.

As I said it showed me I was neglecting certain areas over time and fixing that saved me more than the price of the toothbrush in under a year.

But feel free to continue to disagree with it as a gimmick. In my experience most people that do this are some of the lucky people that could brush their teeth once a week with a stick and still have no dental trouble, meanwhile a small percentage of people seem to have to take great care of their teeth, avoid a vast array of food/drink, and still end up paying out thousands each year to a dentist. Genetics plays a big part in it and you don't get to pick your genes.

alexfoo··on U.S. postal inspectors shut down website selling counterfeit postage labels
The UK moved to stamps with unique QR codes back in 2023 for the bulk of its stock.

https://www.royalmail.com/sending/barcoded-stamps

There are still some "Forever" stamps (those with pictures on or Christmas Stamps) but the old non-QR code non-forever stamps stopped being legal a while back (but you can always swap them for the new ones for free).

I've had people try and reuse a QR-coded stamp, you just get a postcard saying there's an item of mail with invalid postage for you to collect (and pay for). You get to look at it before you decide whether to pay the fine or not and then your argument is with the sender to reimburse you or not.

alexfoo··on Owners mourn spoiled food after firmware update bricks Samsung smart fridges
Are you sure that's all it does?

My $150 "smart toothbrush" (some Oral B iO model) has accelerometers to track its head position and the app lets you know if you're not covering certain areas well enough. Since using it properly (i.e. checking the app and adjusting my brushing) I don't have to go to the hygienist as often.

alexfoo··on Owners mourn spoiled food after firmware update bricks Samsung smart fridges
Certain models of the Mk3 Ford Focus (2011-2018) have a wet timing belt.

Needs changing at 100,000 to 150-000 miles or every 10 years.

The 10 year service is a spendy one.

alexfoo··on Two-tier encryption in the UK
> What did she say?

https://www.bbc.co.uk/news/articles/cx2910vrrygo

alexfoo··on Starlink ground station in Poland hit by fire in suspected arson attack
None of the original 5 buildings at Telehouse in London have any dishes on the roof but the new Telehouse South a few hundred yards to the South seems to have some on the roof but they don't look like they are for a SpaceX groundstation.

SpaceX groundstations look a bit different, they are a bunch of white domes about 1-2m in diameter, usually 8 or 9 of clustered together.

Here's an example in the UK: https://maps.app.goo.gl/Zy61dfdyp5xrq4w1A

It's handled by Arqiva here in the UK it seems, so no SpaceX branding on anything.

SpaceX also applied for two new grounds station sites in the UK, one a few miles West of Telehouse, south of Rainham. The other site is up in Harlow, Essex.

(I don't think any of this is secret, all of the info above can be found with some googling and scrolling in maps.)

alexfoo··on Apple Music to open concert venue in Battersea Power Station
Indeed. Absolutely sterile inside. They could have done so much more with it.

Proposed venue looks in keeping with this theme. Capacity of 600 and I'm sure whatever tickets will be priced to keep the hoi polloi away.

alexfoo··on Apple Music to open concert venue in Battersea Power Station
Amongst other films a few scenes in the 1994 MacGuyver movie (Lost Treasure of Atlantis) were filmed inside the power station before it was renovated.
alexfoo··on Show HN: Macros with a Behringer FCB1010 MIDI Pedalboard in macOS
You can keep your hands on the keyboard. Some people find having to move them away from their usual home place breaks their flow.

Sure there are things like an Elgato StreamDeck that you can do similar things with but they still require you to move a hand from the keyboard.

I suppose it is similar to using voice control things like Alexa. Setting a timer by hand in the kitchen isn’t exactly hard but it is so much more convenient to do it by voice if your hands are covered in raw chicken juice or the like.

alexfoo··on XCancel service is suspended until further notice
Lucky for you, but many people aren't so lucky.

My kids school puts some information that I need to see (not just "would like to see") on Instagram. Same with the sports team they play for.

I've complained to both about it but change is glacial. I'm lucky in that I know how to work around it, and I do my best to keep others who aren't so tech savvy updated about things they need to know but may have missed.

Irony is they moved most of this info from Twitter/X to Instagram.

alexfoo··on HP ZGX Fury Is Now Orderable: GB300 Superchip, 748GB Unified Memory
At the expected price point it would be nice if it came with a free pied-à-terre in Kensington (https://en.wikipedia.org/wiki/Kensington). Just a small studio apartment, nothing special.
alexfoo··on RSA-260 Factorized
2700 core years
alexfoo··on Reverse engineering my ADHD test
I sat a similar test at the start of my ADHD diagnosis (in the UK for reference).

The one I did (QbCheck) was a similar setup but you were presented with shapes on the screen, either a square or a circle, and either blue or red. All you had to do was press the spacebar when the shape on the screen was the same shape and colour as the previous one. No sound distracitons (or maybe I just had the volume muted.)

You also had to do the test on a laptop with a forward facing camera so the software could track eye movement.

I remember starting the test and thinking "This is exactly what my brain is wired for, I'm going to be awesome at this test!"

Within a minute my mind had already moved on to "I wonder how they score this test? I guess they're looking at accuracy, reaction times, how those trend over time, whether the accuracy/reactions goes up/down if they show the same shape/colour more than twice in a row?" etc...

It didn't take long for me to then get jolted into a "wait, did I just zone out a bit there and miss one?"

Then I became overly conscious of my eyes wandering around and not looking at the screen.

Then my mind moved on to "what if I'm too good at this and it means I won't get a diagnosis?"

Soon it was "When will this ever end? This must have been going on for ages!" only to find it had only been about 3 minutes.

The test took 20 minutes or so and I was mentally exhausted by the end of it.

My actual ADHD diagnosis was backed up by an 80 minute interview, basically doing the DSM-5 questions but linking it all back to childhood experiences too. I've no idea how much weight the QbCheck test had.

Glad I got the diagnosis, I've been masking both for years (diagnosed in my late 40s) but just got burnt out doing so. Medication helps but isn't perfect and since I'm probably AuDHD I find the ADHD medication amplifies some of the Autism traits and makes me into a bit of an emotional zombie, but that seems to be better than having zero motivation (aside from stress/deadlines and serious consequences).

alexfoo··on Reverse engineering my ADHD test
> ... my understanding is that in Europe it's virtually unheard of to have an adult diagnosis.

Can't speak for the whole of the continent but UK here and I got my ADHD diagnosis a few years shy of 50 years old. Wasn't tricky at all, just a long-ish (8 month) wait for a non-private diagnosis (not full NHS but via an outsourced provider via Right-To-Choose).

When going through the DSM-5 questions (during an ~80 minute interview) I was asked to give examples from both current life experience and from childhood, and that was enough.

alexfoo··on Stopping the smart TV from being used against you
It works both ways though.

The traffic was separated so that anything on the public hotspot was not attributed to the private subscriber network.

Secondly for years I lived somewhere very remote so that meant that hardly anyone ever got to use my broadband connection via such a hotspot, but I got to use hundreds of other peoples hotspots when I was somewhere less isolated.

I was quite happy to opt in to this system as I benefitted hugely from it.

alexfoo··on Stopping the smart TV from being used against you
A bit into tinfoilhat territory but just because they don't advertise that they have an 802.11 radio doesn't mean the devices can't have one. Or an LTE/4G/5G radio.

If the user data is worth that much then I wouldn't be surprised if some manufacturers put such radios in their non-smart TVs in order to try and gather such data.

I live in a densely populated part of a large UK city and (checks `nmcli dev wifi list`) there are 14 distinct wireless networks near me that aren't mine. There's a good chance that any IOT device could find something nearby, and there's even a whole load of LoRa nodes that it could use for a very slow uplink.

alexfoo··on AI agent bankrupted their operator while trying to scan DN42
They didn't. Sounds like they gave the robot an AWS key from an account that was already linked to a credit card.

The robot decided to spin up an expensive setup prior to getting access, so the setup was sitting there costing money whilst it did nothing.

If it had designed the setup but not spun it up until it had authorisation to join the network then it would have been much less costly an exercise.

alexfoo··on 1k Data Breaches Later, the Disclosure Lag Is Worse
It all comes down to where the boundary for data access is implemented, and how strictly.

If your webapp has unfettered database access then don't be surprised if it is hacked and someone can do `select * from users` and then posts that dump somewhere.

The attack surface changes if your webapp can only do a REST call to pull a single user record at a time. That way you can put some auditing in, you can put rate limiting in to detect that, etc.

Obviously the user record REST api endpoint is still vulnerable, but it's a much smaller attack surface, easier to audit, and can be monitored a lot more closely.

Yes, ultimately, there will still be a set of vulnerable humans that have access to the database servers themselves and they can always walk out of the place with an SD card hidden in a Rubik's cube but there has to be an element of trust somewhere.

The problem is that too many people put that trust boundary way too far out into the big bad Internet. Or don't even consider it at all and just rely on the fact that other targets are more appealing.

alexfoo··on 1k Data Breaches Later, the Disclosure Lag Is Worse
Plus addressing (or movable periods in gmail addresses, etc) is increasingly pointless for a whole host of reasons.

It may keep out the bottom x% of spammers/hackers but it doesn't do much for the increasingly sophisticated scams that are appearing.

If the bit before the + ends up in your inbox anyway then it'll just get stripped off and used. Spammers seeing this kind of thing across several breach dumps:

bob+trello@example.com, bob+spotify@example.com, bob+chase@example.com

and will leverage that to target spam at you for other sites, or just email bob@example.com as there's a good chance that'll get through.

Years ago I did a test with my own domain where I created who unique aliases with plus addresses, e.g. steve.smith+iawer@example.com, bob.jones+wpoqe@example.com

It didn't take long for emails to start arriving to steve.smith@example.com and bob.jones@example.com even though that email address had never been used anywhere ever before.

As others have said, you're better off just creating unique emails with `pwgen -s 16` such as wmR5pNhGI8yidU7N@example.com and storing that in your password manager alongside a similarly random password. (Yes, this is roughly what those unique email address services provide.)

Also many services/sites/providers simply assume the username is immutable. $DEITY forbid you might have to change your email address at some point in the future.

alexfoo··on 1k Data Breaches Later, the Disclosure Lag Is Worse
Can confirm it's free. I tried it based on the GP comment. There are various ways to prove it is your domain: token sent to one of a small number of email addresses like {admin,security,webmaster}@, DNS TXT record, place a small file in the root of the website, etc.

The only extra bits I saw for the other emails on my domain was a plus address I'd used for last.fm which had been leaked. None of the other emails (wife, kid, family, etc) appear in any breach.

I'm slowly moving away from using my own personal domain as it's becoming an ever increasing burden. I'm also concerned that my wife/kid will be left with something they may not have access to, or would stop working at some point, if I suddenly dropped dead.

alexfoo··on Ask HN: What was your "oh shit" moment with GenAI?
Someone in the house pressed the button to update the printer (Brother DCP-L3550CDW) firmware and the CSV page that was the basis for an existing Prometheus exporter (drum/toner lifespan, page counts, etc) stopped being a thing. Instead there was an HTML page with all of the information buried in various divs/etc.

I'd planned on writing something myself to parse the HTML and write a suitable exporter but I thought I'd give Claude a chance.

In a sandboxed VM I gave Claude a single static HTML file of the status page from the printer, also in the directory was the equivalent of "hello world" in Go, literally just the minimum needed to do `fmt.Printf("OK\n")`. The directory was called `brother-exporter`. That was it. No other instructions or information. I hadn't told it what it needed to write. I hadn't said what it should do. I hand't told it what language it was supposed to use.

Just by doing a `/init` in that directory Claude decided that it needed to write a Prometheus exporter in Go that would fetch and parse the HTML file from a printer (defaulting to 192.168.1.1) and then present the associated metrics in a way that they could be scraped by Prometheus.

It did this flawlessly in about 10 minutes.

I could have done it in several hours but this was definitely an "oh shit" moment for me. I think the biggest thing was the fact that it guess/assumed so much (correctly) from so little information in the beginning.

alexfoo··on Meta workers can opt out of being tracked at work up to 30 min
Dave Eggers' novel _The Circle_ (2013) is looking more and more prophetic every day.

https://en.wikipedia.org/wiki/The_Circle_(Eggers_novel)

alexfoo··on 10g Upgrade
For my own 10G homelab network I jumped the gun and got a couple of Intel X540-T1 cards for my two servers and balked at the cost of the RJ45-SFP+ transceivers (Unifi's version is ~USD60). (I'm sure there are cheaper options for the "not hot" flavour transceivers but I didn't want to have to gamble again.)

In the end I just replaced each X540-T1 with a X520-DA2 which are pretty much the same price on eBay (under USD20) and then I can just use a DAC that's a fraction of the cost of the RJ45-SFP+ transceivers.

alexfoo··on Adafruit Receives Demand Letter from Fenwick Legal Counsel on Behalf of Flux.ai
Indeed, however:

    10 x 0.1 = 1
alexfoo··on The newest Instagram “exploit” is the goofiest I've seen
Some companies are purposely obtuse about it.

My wife is trying to sort something with a famous Irish airline who are well known for messing people around. She has LPA/POA for her mother but rather than the airline accepting the VCode (this is the UK) the airline are requesting to see the original POA certificate which is just ridiculous. They seem to be moving a little quicker now there is solicitor involved.

Given how much back and forth there has been it's probably cost the airline more than just refunding the amount at the first request. We'll keep going to prove a point.

alexfoo··on What Is a Direct Attach Copper (DAC) Cable? (2021)
https://communityfibre.co.uk/fibre-deals for reference

[EDIT] The asymmetric supplier is BT via Openreach. Google something like "BT Fibre 500".

alexfoo··on What Is a Direct Attach Copper (DAC) Cable? (2021)
> Going for a cup of coffee means physical walk. Detaching from focussed mode means your mind gets in diffused mode. This is where/when creativity ensues.

Sure, but I want to choose when I do it, not have it forced upon me.

> 75 mbit up is pretty good compared to DSL (I bet it is cable)

It is FTTP not DSL or cable. BT Fibre 500 in the UK. Almost all of the deals through the legacy/monopoly provider (BT/Openreach) are asymmetric like this.

The 2500/2500 at the new property is a different provider that has their own network and so isn't tied into reselling Openreach's GPON infra.

alexfoo··on I analysed 20 years of my chats
The "Sasha" section brought back a load of memories from my childhood. As an Alex growing up in Western Europe with no connections to anything East it was just my Russophile father that used to call me Sandy or Sasha some of the time.
alexfoo··on What Is a Direct Attach Copper (DAC) Cable
Edwardian houses in the UK rarely have that level of access. No basement at all and I can't lift the carpets and floorboards to get to where I might be able to pass things through/around. No AC ducts. No coax to be able to use MoCA either.

But, yes, that video is exactly the kind of thing I had in mind for the bend insensitive fibre.

It all depends how I set things up (and I can't tell that until I've had more access to the property). The ONT and the rack with the USW-Aggregation switch are 10 yards apart, in terms of absolute distance, but probably 20 yards if you follow the walls/skirting-boards/etc.

The FTTP is presented as 2.5GbE Ethernet (apparently) so I can either:

a) put my Unifi Express 7 next to the ONT and then need a fibre run (something like https://uk.store.ui.com/uk/en/category/accessories-modules-f...) from the SFP+ port on the Express 7 to the USW-Aggregation in the rack.

However this will be sub-optimal in terms of Wifi and I'll probably need extra APs to cover all three floors and out into the back yard.

b) put my Unifi Express 7 in the hallway in the middle of the house (which should give me full Wifi coverage with no extra APs). This would mean a short (2m) DAC to connect it to the USW-Aggregation nearby, and I can use a 20m long flat/flexible Cat-6 Ethernet cable to go between the ONT and the Unifi Express 7.

alexfoo··on What Is a Direct Attach Copper (DAC) Cable? (2021)
I had a big debate with myself whether to go Mikrotik or Unifi. Being EU based I really wanted to go Mikrotik but ended up with Unifi as I'd had more experience of it when helping out friends/neighbours.

Maybe my "last house" (i.e. the one we'll get to see us through to retirement and beyond) will be Mikrotik based. By then I'll probably want as little computing stuff as possible and will just sit in a comfy chair doing crosswords and sudoku with a pencil.

Page 1 of 13Next →