HNHacker News
TopNewBestAskShowJobs

cataflam

788 karma · joined January 19, 2012

submissionscomments
cataflam··on Backups Aren't Simple
> When a person hears someone talk about the importance of backups, but also haven't heard friends/family suffer this date, they will rightfully ignore this warning.

Maybe they just haven't talked to you about it? Most people I know have suffered some form of (partial) data loss or another, and lived with it.

cataflam··on Real-time LLM Inference on Standard GPUs: 3k tokens/s per request
Congrats gaeld and team

The demo is very impressive!

disclaimer: I've known the founder for a while, as legitimate as it gets in deep tech, real years of research and engineering behind this, not vaporware

cataflam··on The bootstrapper's EU stack for under €10 per month
> For monitoring I use and recommend UpDown.io, which doesn’t seem to be listed there.

It doesn't seem very well known, but I've been a happy user. Most of the others have become over-bloated with a shitty UI.

cataflam··on If AI writes your code, why use Python?
> Nicholas Carlini, a researcher at Anthropic, orchestrated 16 parallel Claude agents to write a production C compiler in Rust.

To write a proof-of-concept C compiler, not a production-grade one...

Hard to take the article seriously after this

cataflam··on Game devs explain the tricks involved with letting you pause a game
You misinterpreted the comment you are citing.

This non-determinism would not and did not cause replays to diverge (the PRNG seed was most likely stored and would reproduce exactly the same results).

cataflam··on France's aircraft carrier located in real time by Le Monde through fitness app
Your AI powered comment is wrong. Le monde has been doing this for years. They have a series of articles about this. There is no "gap closing."
cataflam··on Show HN: OneCLI – Vault for AI Agents in Rust
it cannot email your secret key to an attacker because of prompt injection etc.
cataflam··on 1B identity records exposed in ID verification data leak
Almost a month old, original source: https://cybernews.com/security/global-data-leak-exposes-bill...

and I've never seen any confirmation elsewhere

Looks like CyberNews have edited the article with more info since first I saw it, it used to look quite suspicious and untrustworthy, it now has more info. Still doesn't say exactly what a record is, or how many uniques there are.

cataflam··on Global warming has accelerated significantly
You're getting downvoted because you didn't read the article.

It is specifically about cleaning up the data by removing these 3 and showing a clearer picture of acceleration without these 3 factors.

cataflam··on What an unprocessed photo looks like
Great series of articles!
cataflam··on FFmpeg to Google: Fund us or stop sending bugs
Don't they?

https://git.ffmpeg.org/gitweb/ffmpeg.git?a=search&h=HEAD&st=...

cataflam··on Date bug in Rust-based coreutils affects Ubuntu 25.10 automatic updates
Wow. Maybe I'm missing something but it seems really weird to replace a tool with a rewrite that doesn't pass the test suite!
cataflam··on Date bug in Rust-based coreutils affects Ubuntu 25.10 automatic updates
This comment[0] explains it.

The core bug seems to be that support for `date -r <file>` wasn't implemented at the time ubuntu integrated it [1, 2].

And the command silently accepted -r before and did nothing (!)

0: https://lwn.net/Articles/1043123/

1: https://github.com/uutils/coreutils/issues/8621

2: https://github.com/uutils/coreutils/pull/8630

cataflam··on Microsoft PowerToys
Amazing they are still alive and kicking. Started using them with Windows 95 (different specific ones, same general concept)

These and Sysinternals (bought by Microsoft around 2006) were must have when I was still using Windows.

https://learn.microsoft.com/en-us/sysinternals/

cataflam··on We all dodged a bullet
> update your password, update your 2FA

should practice it for ENTER your password, ENTER your 2FA ;)

> Still, I don’t understand how npmjs.help doesn’t immediately trigger red flags

1. it probably did for quite a few recipients, but that's never going to be 100% 2. not helped by the current practices of the industry in general, many domains in use, hard sometimes to know if it's legit or not (some actors are worse in this regard than others)

Either way, someone somewhere won't pay enough attention because they're tired, or stressed out, or they are just going through 100 emails, etc.

cataflam··on We all dodged a bullet
Indeed.

At least the crowd here should _know_ that TOTP doesn't do anything against phishing, and most of the critical infrastructure for code and other things support U2F so people should use it.

cataflam··on We all dodged a bullet
My apologies, somehow after all these years, I didn't know that (and first time I've done it)!
cataflam··on We all dodged a bullet
Yes! Here is the whitepaper (from 2017 I think), I read that and used it, it's excellent

https://karla.io/files/ichthyology-wp.pdf

> At Stripe, rather than focusing on mitigating more basic attacks with phishing training, we decided to invest our time in preventing credential phishing entirely. We did this using a combination of Single Sign On (SSO), SSL client certificates, and Universal Second Factor (U2F)

cataflam··on We all dodged a bullet
Still would have done nothing in this case, as they pulled the correct email address he uses for npm from another source (public API I think?).

That's exactly why I said all the other "helpful" recommendations and warning signs people are using are never foolproof, and thus mostly useless given the scale at which phishing campaigns operate.

Great if it helps you in the general case, terrible if it lulls you into a sense of confidence when it's actually a phishing email using the right email address.

cataflam··on We all dodged a bullet
As for any of these cases, we do receive legitimate emails that require being logged in, Google or otherwise

The answer is simple: use your bookmarks/password manager/... to login yourself with a URL you control in another tab and come back to the email to click it

(and if it still asks for a login then, of course still don't do it)

cataflam··on NPM debug and chalk packages compromised
In that case

1. You just requested it, I'm not saying to never click link on transactional emails you requested. You still need to click on those verify email links

2. It replaces entering your password, so you're not entering your password on a link from an email, which is the very wrong thing.

cataflam··on We all dodged a bullet
Besides the ecosystem issues, for the phishing part, I'll repost what I responded somewhere in the other related post, for awareness

---

I figure you aren't about to get fooled by phishing anytime soon, but based on some of your remarks and remarks of others, a PSA:

TRUSTING YOUR OWN SENSES to "check" that a domain is right, or an email is right, or the wording has some urgency or whatever is BOUND TO FAIL often enough.

I don't understand how most of the anti-phishing advice focuses on that, it's useless to borderline counter-productive.

What really helps against phishing :

1. NEVER EVER login from an email link. EVER. There are enough legit and phishing emails asking you to do this that it's basically impossible to tell one from the other. The only way to win is to not try.

2. U2F/Webauthn key as second factor is phishing-proof. TOTP is not.

That is all there is. Any other method, any other "indicator" helps but is error-prone, which means someone somewhere will get phished eventually. Particularly if stressed, tired, or in a hurry. It just happened to be you this time.

cataflam··on Ex-WhatsApp cybersecurity head says Meta endangered billions of users
France and UK, from personal experience, whatsapp is big, especially for professional use, or friends/family groups.

Blue bubble isn't really a thing ever mentioned in France either, not enough iPhone market share.

cataflam··on NPM debug and chalk packages compromised
I mostly agree and I do use one.

You only need read the whole thread however to see reasons why this would sometimes not be enough: sometimes the password manager does not auto-fill, so the user can think it's one of those cases, or they're on mobile and they don't have the extension there, or...

As a matter of fact, he does use one, that didn't save him, see: https://news.ycombinator.com/item?id=45175125

cataflam··on Ex-WhatsApp cybersecurity head says Meta endangered billions of users
> outside of the West

you probably mean outside of the USA, it's huge in Europe/UK

(which doesn't contradict your main point)

cataflam··on NPM debug and chalk packages compromised
Hey, you're doing an exemplary response, transparent and fast, in what must be a very stressful situation!

I figure you aren't about to get fooled by phishing anytime soon, but based on some of your remarks and remarks of others, a PSA:

TRUSTING YOUR OWN SENSES to "check" that a domain is right, or an email is right, or the wording has some urgency or whatever is BOUND TO FAIL often enough.

I don't understand how most of the anti-phishing advice focuses on that, it's useless to borderline counter-productive.

What really helps against phishing :

1. NEVER EVER login from an email link. EVER. There are enough legit and phishing emails asking you to do this that it's basically impossible to tell one from the other. The only way to win is to not try.

2. U2F/Webauthn key as second factor is phishing-proof. TOTP is not.

That is all there is. Any other method, any other "indicator" helps but is error-prone, which means someone somewhere will get phished eventually. Particularly if stressed, tired, or in a hurry. It just happened to be you this time.

Good luck and well done again on the response!

cataflam··on NPM debug and chalk packages compromised
> There is NO reliable indicators

Completely agree. The only reliable way is to never use an email/SMS link to login, ever.

cataflam··on We moved from AWS to Hetzner, saved 90%, kept ISO 27001 with Ansible
Happy for you, don't get me wrong, but your post is not particularly news, I'm guessing everyone on HN knows bare metal/VPS providers are cheaper than AWS/Azure/GCP.

And also lacking a bit in details:

- both technical (e.g. how are you dealing with upgrades or multi-data center fallback for your postgresql), and

- especially business, e.g. what's the total cost analysis including the supplemental labor cost to set this up but mostly to maintain it.

Maybe if you shared your scripts and your full cost analysis, that would be quite interesting.

cataflam··on Lottery Simulator (2023)
Because you shouldn't use the simulator to calculate the EV, or said differently your n=1000000 is too small.

Assuming you used the first lottery example (Mega Millions), the EV is easy to calculate directly and is -$0.66/ticket, ie -33%

The jackpot is a whole $1 of that EV! Without it, the EV is -$1.75/ticket, ie -87%, which is closer to what you got in the simulation.

cataflam··on Preliminary Post Incident Review
Besides missing the actual testing (!), the staged rollout (!), looks like they also weren't fuzzing this kernel driver that routinely takes instant worldwide updates. Oops.
Page 1 of 5Next →