HNHacker News
TopNewBestAskShowJobs

capitainenemo

1,869 karma · joined December 10, 2020

submissionscomments
capitainenemo··on JPEG XL Test Page
... update. after reading the comments in the rust migration security bug, I saw they mentioned "only building in nightly for now"

I grabbed the nightly firefox, flipped the jxl switch, and it does indeed render fine, so I guess the rust implementation is functioning, just not enabled in stable.

... also, I see no evidence that it was ever enabled in the stable builds, even for the C++ version, so I'm guessing Zen just turned it on. Which... is fine, but maybe not very cautious.

capitainenemo··on cURL removes bug bounties
Interesting. First I've heard of Xwiki - it does look nice, and what with Atlassian's price increases... do you have any migration tips?

[edit] I found https://extensions.xwiki.org/xwiki/bin/view/Extension/Conflu... - hopefully that's a good reference.

capitainenemo··on cURL removes bug bounties
Amusingly, exactly opposite experience here. That said, our on-prem is jira and confluence integrated with db on same machine, and apache in front doing additional caching. I imagine like so many things it is how you set it up...
capitainenemo··on Scientists find a way to regrow cartilage in mice and human tissue samples
Well, the article notes that it seemed effective on human tissue samples.

   The researchers also tested cartilage taken from patients undergoing total knee replacement for osteoarthritis. After one week of treatment with the 15-PGDH inhibitor, the tissue showed fewer 15-PGDH-producing chondrocytes, reduced expression of cartilage degradation and fibrocartilage genes, and early signs of articular cartilage regeneration.
So, IMO that shows hope for once it goes to trials.
capitainenemo··on JPEG XL Test Page
Checking the Firefox bugs on this, it seems they decided to replace the C++ libjxl with a rust version which is a WIP, to address security concerns with the implementation. All this started a few months ago.

Maybe the zen fork is a bit older and still using the C++ one?

capitainenemo··on cURL removes bug bounties
I suspect that applies specifically to their cloud rewrite which was apparently a bloat of JS libs and hundreds of requests even by Atlassian standards. The on-prem self-host Confluence I've used is still pretty snappy and pleasant to use and without throwing an absurd amount of resources at it. We do have quite a lot of actually-useful documentation in it.

That said, Atlassian is busy relentlessly raising the price for self-host to push people into their cloud roach motel, so we'll probably be on some alternative (either FOSS or commercial, but self-host) soon too.

capitainenemo··on Mozilla's open source AI strategy
It definitely uses whatever is available, but on review of the models (and there are quite a few) the ones I checked included instructions for integrating into linux speech engines.

What your distro uses by default might be espeak-ng, but you could use mozilla TTS or festival or piper or anything else. It makes sense to not bundle an entire system that repeats things that are available on all desktop environments and mobile these days, but instead call out to those from the browser functionality - especially given the enormous size of high quality speech models - not to mention the localisation issue. I think the TTS project was just to increase availability of high quality FOSS alternatives. Getting those into your distro is more of a distro packager thing.

capitainenemo··on Git Rebase for the Terrified
In mercurial you could have those in phase hidden for future reference. In jujutsu you can have those in a local set, but not push upstream. Only unfortunate thing with jujutsu is because it is trying to be a git overlay, you lose state that a mercurial clone on another machine would have.
capitainenemo··on Mozilla's open source AI strategy
Click Reader mode on a web page, then the read aloud option in the sidebar.

Note that how well it works on Linux will depend on your distro and default settings, as is common for Linux world. They do try to provide setup instructions if your linux distro has issues.

... now whether that model is integrated by default, no idea. I imagine that depends on size.

Oh, and mozilla's off-line translate for private translation of web pages... that's another neat AI thing they added that I've found super helpful. Chrome still requires sending the content to their servers.

capitainenemo··on Mozilla's open source AI strategy
Mozilla did integrate TTS into Firefox - in fact, one of the better FOSS TTS AI models out their was their initiative. https://github.com/mozilla/TTS
capitainenemo··on A spider web unlike any seen before
It's probably a pretty natural path for the wasp assuming it survived the initial time you were running the vac. The shopvac is just a big container with at the top an exit path following the wall naturally out the tube. They don't even tend to have a flap like smaller hand vacs might have to keep dust from falling out during use.
capitainenemo··on GPT-5.2
Belated update on this. Gemini reasoning did much better than quick on bracket city today (an easy puzzle but still). It only failed to solve one clue outright, got another wrong but due to ambiguity in the expression referenced and in a way that still fit the next level down making the final answer fairly cleanly solved. Still clearly has a harder time with it than the connections puzzle.
capitainenemo··on GPT-5.2
And performs very well on the latest 100 puzzles too, so isn't just learning the data set (unless I guess they routinely index this repo).

I wonder how well AIs would do at bracket city. I tried gemini on it and was underwhelmed. It made a lot of terrible connections and often bled data from one level into the next.

capitainenemo··on 30 Year Anniversary of WarCraft II: Tides of Darkness
Well, when I saw the first Supreme Commander video it looked a lot like Sprint RTS running Balanced Annihilation to me. Right down to how the terrain deformation worked and the command queuing.

Was there any particular reason for the fork? There's a lot of Spring RTS projects but they all use the same codebase. http://springrts.com/wiki/Games

capitainenemo··on 30 Year Anniversary of WarCraft II: Tides of Darkness
Huh. I'm familiar with the Spring RTS FOSS project (https://springrts.com) which started as a reimplementation of TA, and of course Planetary Annihilation, but not "Beyond All Reason" - do you have an authoritative link?
capitainenemo··on 30 Year Anniversary of WarCraft II: Tides of Darkness
WarCraft was a huge part of our LAN parties, but mechanics wise, Total Annihilation was a much bigger leap forward in terms of use of 3D terrain and ballistics and commands, so we played that a lot more.

Warcraft had more differentiable units and a better story though.

capitainenemo··on The privacy nightmare of browser fingerprinting
Oh, and a bit of followup. I tried the EFF cover your tracks on a Firefox profile with resist fingerprinting, and almost all the bits of identifying information came from the window size (which EFF considers "brittle") and the UA (I was testing in Firefox Nightly).

Apparently you need to add the hidden pref: firefox.resistFingerprinting.letterboxing

Enabling letterboxing knocked off 5 bits of identifying information. Apparently my 1800px wide letterbox was still pretty identifiable, but, an improvement.

Setting a chrome user agent string using a user agent string manager dropped that one from 12ish bits to <4 bits. 'course, that has disadvantage of reducing firefox visibility online further, and probably being more recognisable with the other values (like mozilla in the webgl info). Using firefox stable for windows was <5bits, so probably best to use that if on linux. Although, it might conflict with the font list unless a windows font list was pulled in.

capitainenemo··on The privacy nightmare of browser fingerprinting
It does not wipe your browser history. I can definitely attest to that since my generic JS active + resistFingerprinting profile has a history going back years. It does set your timezone to UTC in JS on websites. I've mostly encountered that when playing Wordle ;)
capitainenemo··on The privacy nightmare of browser fingerprinting
I've had good success with tracking tool tests and resistFingerprinting. Granted, I usually use it with uMatrix/NoScript most of the time which cuts down on the available data a lot and maybe makes it an unfair test. One issue, I expect, is simply not enough people using resist fingerprinting to add variation to the mix. Since it's off by default, and only a small % of users use Firefox and an even tinier percentage use resistFingerprinting, unlike your example of Tor where probably most people on the tor network use the tor browser, it's likely that simply blocking things is a fingerprint all on its own. The solution there would be to get more people using it :)

I will say one downside to using it is far more bot detection websites freaking out over generic information being returned to them, causing some sites to break (some of their settings breaking webgl games too due to low values). Using a different profile avoids this, or explicitly whitelisting certain sites in privacy.resistFingerprinting.exemptedDomains - obviously if a site is using a generic tracking service for bot detection, that kills a fair amount of the benefit of the flag, so a separate profile might be best. I wish firefox had a container option for this.

... and. not too sure what you mean by changing window size on a non-standardised device. They do try to ensure the window sizes are at standard intervals, as if they were fullscreened at typical widths to reduce fingerprinting, but surely that applies to using Tor too? I mean, people don't use Tor on dedicated monitors at standard sizes.

capitainenemo··on The privacy nightmare of browser fingerprinting
privacy.resistFingerprinting = true is basically activating most of the Tor browser features in baseline Firefox. That's why it is turned off by default. It does all the things you listed above only at a lower level than a user script. It's been in Firefox for over a decade.

https://www.ghacks.net/2018/03/01/a-history-of-fingerprintin...

The flag was in fact designed to control the activation of the Tor browser uplift features, and reduce maintenance issues. That way the Tor browser could pretty much just be Firefox with certain flags turned on.

capitainenemo··on The privacy nightmare of browser fingerprinting
unfamiliar with the Arkenfox user.js but are any of these things that are beyond what firefox enables out of the box if you turn on privacy.resistFingerprinting ? Because what you describe seems to be all stuff it does just by flipping flag.
capitainenemo··on The privacy nightmare of browser fingerprinting
Firefox does pretty damn well though, especially with privacy.resistFingerprinting set to true
capitainenemo··on A Whale-Surfing Fish
https://www.nature.com/articles/s41598-021-94342-x

They might have some benefit to the host, but they also cost them energy in drag.

capitainenemo··on Frozen String Literals: Past, Present, Future?
With regards to what rust team is admitting or not... https://wtf-8.codeberg.page/#the-wtf-8-encoding "It is identical to generalized UTF-8, with the additional well-formedness constraint that a surrogate pair byte sequence is ill-formed. It is a strict subset of generalized UTF-8 and a strict superset of UTF-8."

https://wtf-8.codeberg.page/#intended-audience "WTF-8 is a hack intended to be used internally in self-contained systems with components that need to support potentially ill-formed UTF-16 for legacy reasons.

Any WTF-8 data must be converted to a Unicode encoding at the system’s boundary before being emitted. UTF-8 is recommended. WTF-8 must not be used to represent text in a file format or for transmission over the Internet."

They seem very transparent, and certainly are not proposing it as a general type.

capitainenemo··on Springs and Bounces in Native CSS
https://news.ycombinator.com/item?id=45736461 duplicate from 9 days ago, 41 comments
capitainenemo··on FBI tries to unmask owner of archive.is
While it's true people are upset at AI companies profiting off of artist creations with no compensation, I know a lot of people are also reacting to how the recent AI companies have been scraping the web. The reason folks are using Anubis and other methods is because unlike Google which did have archiving of sites for a long time (which was actually a great service), these new companies do not respect robots.txt, do not crawl at a reasonable rate (for us, thousands of hits a minute from their botnets - usually baidu/tencent, but also plenty of US IPs), hit the same resource repeatedly, ignoring headers intended to give cache hints, stupidly hitting thousands of variations of a page when crawling search results with no detection that they are getting basically the same thing... And when you ban them, they then switch to residential ranges. It really is malicious.
capitainenemo··on Frozen String Literals: Past, Present, Future?
... and honestly, since java has both stringbuffer and string I feel it's really in the "has mutable" camp too
capitainenemo··on Frozen String Literals: Past, Present, Future?
Cool, although I feel if on one side you have Java, JavaScript, Python, Go and on the other Perl, PHP, C/C++, Ruby, Rust it's hard to say overwhelming majority in either direction.

Also someone below claims python byte arrays can be considered mutable strings, although I have no idea of the stringy ergonomics of that and whether it would be convenient to do - I try to avoid python too.

capitainenemo··on Frozen String Literals: Past, Present, Future?
Sure, that doesn't change the point that mutable strings are a thing in those languages. And I don't think C's const is really a "mutability qualifier" - certainly not a very effective one at any rate.
capitainenemo··on Frozen String Literals: Past, Present, Future?
Article claims python 3 uses UTF-8.

https://stackoverflow.com/questions/1838170/ "In Python 3.3 and above, the internal representation of the string will depend on the string, and can be any of latin-1, UCS-2 or UCS-4, as described in PEP 393."

Article also says PHP has immutable strings. They are mutable, although often copied.

Article also claims majority of popular languages have immutable strings. As well as the ones listed there is also PHP and Rust (and C, but they did say C++ - and obviously Ruby since that's the subject of the article).

I'm also a bit surprised by the last sentence. "However, if you do measure a negative performance impact, there is no doubt you are measuring incorrectly." There must surely be programs doing a lot of string building or in-place modification that would benefit from non-frozen.

← PreviousPage 4 of 29Next →