HNHacker News
TopNewBestAskShowJobs

buildfocus

404 karma · joined May 13, 2016

submissionscomments
buildfocus··on Google AI Ultra
And lots of other features don't work, particularly external integrations. Gemini on Android refuses to do basic things like set a timer unless chat history is enabled. It is the one key feature I really want to pay extra to get, and that preference goes x2 when the AI provider is Google.
buildfocus··on US vs. Google amicus curiae brief of Y Combinator in support of plaintiffs [pdf]
> On every Kagi comment, there is “Have you used Kagi recently? It’s improved a lot!” — to the level that I suspect they have bots to upgrade the brand image

Odd to dismiss a point purely because it's consistently made, especially without much apparent disagreement. Perhaps more likely: there are just _many_ happy Kagi customers in the HN community.

As one data point: I use Kagi, and agree with GP, and I am not a bot (activity of this HN account predates existence of Kagi by many years).

That doesn't dismiss your experience of course, lots of people use search engines in different ways! Personally, I found the ads & other crap of Google drowned out results, and I frequently hit SEO spam etc where site reranking was helpful. I'm sure there's scenarios where that doesn't make sense though, it's not for everybody (not everybody can justify paying for search, just for starters).

buildfocus··on Framework 13 AMD Setup with FreeBSD
All except fractional scaling worked for me out of the box with Mint. Fractional scaling isn't working just for Linux reasons rather than a Framework limitation (in my case, I'm using Regolith, and wayland is still experimental and not default).
buildfocus··on Polypane, The browser for ambitious web developers
Why don't you do subscription?

I've heard plenty of arguments on the 'financial tools to manage them are bad' (forget about them, hard to cancel) but few against 'paying money proportional to how much I use the product'. As a general concept that seems reasonable to me - if you use a product for 10 years, it's fair to pay more than somebody who uses it for a couple of months.

In a world where finance improves (more subs via Apple Pay et al, more banks like Revolut that show & allow unilaterally blocking any given recurring charge) would you still avoid them?

buildfocus··on Y Combinator urges the White House to support Europe's Digital Markets Act
Spain - the bank asks for evidence of income (payslips or tax returns), existing funds (bank/broker statements) and checks outstanding debts (via a public register: https://www.bde.es/wbe/en/para-ciudadano/gestiones/informaci...). Risk analysis runs on that data directly. There's no credit history where you need to have ever borrowed money before.

Average interest rate on mortgages in Spain with this system appears to be _half_ that of the US, so it seems this isn't so ineffective that premiums have to spike to match. (is that right? https://www.bankrate.com/mortgages/mortgage-rates/ suggests 6% interest mortgages is a current average in the USA while Spain is below 3% now - personal anecdotes plus gov stats shows 3.25% average on all issued mortgages in 2024: https://ine.es/dyngs/INEbase/en/operacion.htm?c=Estadistica_...)

buildfocus··on MacBook Air M4
No, normal usage with no special power saver options. Turning off WiFi+minimal brightness+power saving etc pushes it further, but I'm rarely in a scenario where I want to do that for more than a couple of hours anyway.

I've heard Windows defaults or more advanced Linux games can do better, but at this stage I don't feel the need.

buildfocus··on MacBook Air M4
Is the performance gap so huge? Power efficiency yes, absolutely, but for peak performance last I saw the last AMD vs M3 benchmarks were a slightly slower single core, and a little faster in multicore. Doesn't seem as world changing as described.
buildfocus··on MacBook Air M4
I upgraded to the AMD board and the larger batteries and this improved significantly - 7/8 hours of real usage now, which for me is fine. On linux with minor tweaking. Depends what you need, but surely for most people a full workday without power is manageable!
buildfocus··on It is no longer safe to move our governments and societies to US clouds
Scaleway at least is genuinely not a bad alternative for this kind of thing already today - they do have plenty of managed services like serverless functions, object storage, queues, etc, in addition to the simple VMs and container hosting.
buildfocus··on What should I expect from moving tech jobs from USA to Europe?
Depends where you go in Europe, but my strong impression is that the relative cost of living is very significantly lower than FAANG-like equivalent locations in the US (SF, Seattle, NY, etc).

Remote for the US is definitely still the best way to get the benefit of the difference though, and even with a lower paying US role in return that could be worthwhile.

Remote work visas for Spain and I think Portugal are designed for exactly that case and should fit the bill nicely if you have remote work. Alternatively if you can't get any, it gets significantly more complicated - finding a well-off-relative-to-local-cost-of-living local software job is quite possible in many many major EU cities, but will take time and require some adjustment en route (to local norms, paperwork, and languages) so the visa situation can be challenging. Doable but requires research and work.

buildfocus··on European Alternatives for Popular Services
I found Scaleway & Bunny through this list a while back (as a managed cloud & CDN provider respectively) and I've been extremely happy with both, having migrated there from a mix of Netlify/Digital Ocean/Cloudflare.

Significantly more convincing privacy story than US providers (especially as the US authorities start to look increasingly unpredictable) but also just genuinely excellent service, UX & pricing.

It is worth looking beyond the standard providers, nobody ever got fired for picking AWS, but that doesn't make it the best option.

buildfocus··on US and UK refuse to sign AI safety declaration at summit
> Imaging telling hackers from the past that people on a website called “hacker news” would be arguing about how important it is that the government criminalize running code on your own computer.

My understanding is that approximately zero government-level safety discussion is restriction of just building & running AI yourself. There are no limits of AI hacking even in the EU AI regaultion or discussions I've seen.

Regulation is around business & government applications and practical use cases: no unaccountable AI making final employment decisions, no widespread facial recognition in public spaces, transparency requirements for AI usage in high-risk areas (health, education, justice), no AIs with guns, etc.

buildfocus··on A memory leak in Apple's Network Extension framework
This isn't backwards compatibility though - the example in the post here is a major bug in an actively supported API.

Apple dropping support for old things over time is a reasonable philosophy, but Apple breaking current things unintentionally and then neither fixing nor communicating about it, primarily because they don't actively engage with their ecosystem in general, is a problematic choice on their part.

buildfocus··on Claude for Desktop
This is not true - both GDPR & ePrivacy rules apply to any software, none of it is specific to websites (although obviously that's where it's most easily abused, and where most of the attention is).
buildfocus··on Launch HN: Integuru (YC W24) – Reverse-engineer internal APIs using LLMs
If you have root, HTTP Toolkit will handle most of that for you - it can detect root via ADB, install systems certs automatically, and install Frida & intercept individual app targets with most cert pinning disabled (frida scripts it uses are here: https://github.com/httptoolkit/frida-interception-and-unpinn...).

No manual setup or config, just click a button and done.

Avoiding in-depth detection is left as an exercise for the reader, although there are a small set of existing countermeasures in there. In practice, there is definitely a very long tail of further cases of increasing complexity, with diminishing returns on automated solutions, but it turns out in practice you can automate quite a long way down that path and cover most normal cases.

Flutter is the one awkward case here I've found that doesn't fully work. Very interested to see if there are generalizable automated solutions there, or if the recent fork announcements mean the slow death of flutter anyway...

buildfocus··on Working from home is powering productivity
Offshoring & distribution of remote work may be bad for you but very very good for humanity.

There will still be local opportunities and huge benefits of being in the first world due to better education and networks. Those benefits will be diluted by remote work/offshoring increasing, and others will benefit due to that.

Probably the increased productivity itself will boost everything for everybody (better matches of employees & employers = higher productivity & cheaper products everywhere... eventually) but in times of change it can be rough in the short term if your income depended on a tightly protected market and the protection just disappeared.

buildfocus··on EU: Definition of "potential terrorists" opens door to broad information-sharing
Again, this is not different to local democratic processes.

Voters typically cannot directly stop somebody being named leader of their party or given a specific role within government for multiple terms. If you dislike them, you pressure your elected representative to change that.

Almost all representative democracy is accountability through a representative, not directly through control of government internals & positions.

buildfocus··on EU: Definition of "potential terrorists" opens door to broad information-sharing
Is this not similar to ministerial roles and civil servant positions in most governments? You don't vote for the commissioners directly, but your elected representative (leader of your government) does, and that's your path to express preferences & drive accountability. If you don't like the selection, take it up with them.

In the UK for example, the people elect members of parliament as their representatives, but MPs choose their party leaders, and the governing party leadership chooses its ministers without any public consultation or debate. What's the difference?

buildfocus··on If we want a shift to walking, we need to prioritize dignity
A few countries now have remote work visas (Spain definitely, Portugal too I think). As long as you make good money (any software engineer salary is fine) and it comes from abroad, that'll work to get you in the door. Alternatively you can find an big international company (who will often work in English) with a local office.

In Western Europe at least, English-only in day to day life will be a moderate challenge but not a critical one (many people speak at least basic English, you get good at pointing effectively, you learn essentials much faster than you think), you'll find people & services targeted at expats to solve exactly this problem, you meet many many other foreigners in the same situation, and with a little time you really can learn a language even if you've never done it before (and doing so is genuinely an interesting and meaningful project that many people enjoy).

I moved to Spain with no Spanish. First year or so is tricky but manageable and definitely not boring, and then from there on it's relatively smooth sailing. Quite a few years later now, worked out great, best decision I ever made.

buildfocus··on If we want a shift to walking, we need to prioritize dignity
Barcelona is also a very walkable city (across the entire area of 2 million people, not just the very center) and is definitely the upper end of Spanish income.

A big part of this is long term cultural: medieval towns (and even much older) were all clustered very tightly into blocks with city walls against attacks, those slowly evolved into the vast majority of the towns & villages in Spain today, and have left a culture where flats and dense city centers are the expected norm and the primary model, even for towns surrounded by empty space. You can easily find small towns of apartment blocks and tight wall to wall houses in windy city centers, of just 1000 people, surrounded by fields for miles.

The Spanish would argue that surburanism is generally less enjoyable (walkability, community, socialability) and less secure (houses are easier to rob than non-ground floor flats) while dense apartment/etc living is better value (less land cost, shared maintainence in apartment blocks) and provides better airflow/heat management & opportunity for balcony views (attic flats etc).

buildfocus··on Firefox 128 enables "privacy-preserving" ad measurements by default
It uses multiple aggregation services, each of which get only partial data for each event, such that no individual service can track you, even if they wanted to. Initially the two aggregators are run by Mozilla and ISRG - your privacy is at risk only if you think both are malicious and actively sharing all the data between each other to track you.

As the number of aggregators increases this gets better - as long as you trust at least one aggregators involved then your individual data remains untrackable.

Also, in general if you think Mozilla is likely to _actively_ lie to you to steal your data and track you, you're probably using the wrong browser in the first place and the aggregation service makes little difference.

buildfocus··on Ad-tech setting 'Privacy-Preserving Attribution' is opt-out in Firefox 128
This is not a tracking mechanism - it's quite convincingly private to _all_ participants in the protocol (only you, as the browser client, have the full data). Websites specifically receive only aggregate data from their complete user base, not any individual info.

Whether it's worthwhile and/or will help reduce industry tracking practices is a good & separate question, but it's not reasonable to describe this as anything akin to a attack on privacy.

buildfocus··on Jeff Geerling: Corporate Open Source Is Dead
There are uses for CLAs besides rug pulls. For example, if you want to offer software as AGPL, accept community contributions, but be able to _also_ offer a non-AGPL option to paying customers (who effectively pay to be allowed to integrate the license without themselves being subject to licensing risk). Quite a few big orgs have a full ban on internal use of AGPL software so this can be very valuable.

That requires a CLA (as I understand it, IANAL) because you're relicensing a contributor's contribution. At the same time though, I wouldn't consider it a rugpull - contributors lose nothing here, and the open source project gains a funding mechanism (a rare thing in open source).

buildfocus··on iOS404
For dangerous ones like WebUSB you can't just click 'Allow' - after granting permission, it shows you a list of connected devices, and you have to actively select the device you want the website to access, and then approve it.
buildfocus··on iOS404
All the dangerous ones come with comprehensive permissions prompts, and browsers can offer options for don't ask again/never ask etc, so if you're not interested there's still little downside to those being available for those who are.

Personally, I've found a bunch of these super useful, as user and a developer. Being able to use tools like https://www.espruino.com/ide/ to play with hardware straight from the web is amazing.

buildfocus··on Ask HN: What underrated open source project deserves more recognition?
https://httptoolkit.com - HTTP debugging proxy with really easy one-click launch to intercept android devices/browsers/docker containers/etc.
buildfocus··on Cracking Meta's Messenger Certificate Pinning on macOS
...yes.

Unavoidable hard restrictions like this make it dramatically harder to do malware research (thereby reducing security overall) and cause huge & unreasonable problems the moment you see a false positive.

I'm all for user protection, but there is a limit. There's no point aiming for 'impossible' - if the user could be convinced past enough security warnings in the OS, they can equally be convinced to just type their banking passwords into the attacker's phone directly.

I think there's a responsibility on the platform to make possible consequences clear, and make dangerous actions quite difficult, but totally blocking full user control of their own devices is counter productive.

buildfocus··on Open Collective Official Statement – OCF Dissolution
Open Collective isn't shutting down - open-source funding is unaffected. The Open Collective _Foundation_ (OCF) appear to be part of the funding structure for open collective sponsorship of charitable but not necessarily open source organisations in the US, and only groups using the OCF to host their finances are affected.
buildfocus··on The /unblock API from Browserless: dodging bot detection as a service
Attestation creates all sorts of challenges absolutely, but it actually doesn't really help here - there's plenty of services doing this on real devices, and no real challenges to doing so at the prices people will pay. The overhead is the one-off cost of the cheapest legitimate device that will attest, split between the many users to get near 100% utilisation over a large period. Once you look at cheap androids & PCs, this gets very cheap indeed.

The only solution is actual paid services, or real-user verification (and deduplication, which means little privacy, which means legal problems in much of the world) for free accounts.

If you publish something on the internet for free, you _must_ accept that people can read it automatically. You can make it difficult, make it a bit more expensive, but at the end of the day paid data means paywalls.

buildfocus··on OpenAI – Application for US trademark “GPT” has failed
I don't think the debate here is about motivation - the concern is that in itself, regardless of the reasons, attempting to trademark a generic technical term is bad behaviour.
← PreviousPage 2 of 3Next →