HNHacker News
TopNewBestAskShowJobs

caylus

343 karma · joined August 30, 2015

submissionscomments
caylus··on The SpaceFN concept – setting up your space key as a layer switch
QMK, one of the keyboard configuration tools referenced by the article, has the "quick tap term" feature that handles this:

> When the user holds a key after tapping it, the tapping function is repeated by default, rather than activating the hold function. This allows keeping the ability to auto-repeat the tapping function of a dual-role key.

ref. https://github.com/qmk/qmk_firmware/blob/master/docs/tap_hol...

I use both space and backspace (in the caps lock position) as dual-function keys and find it very usable when I occasionally want to repeat-tap them.

caylus··on Major standard library changes in Go 1.20
> I can no longer edit the original comment

Okay, great, we're getting somewhere. So you concede that the true number of human birth defects is on the order of 4-5 nines.

We know this because we've observed a huge sample size of human births. Meanwhile, the experiment you reference only observed a small set of planarian worm amputations. So we can't conclude there are even 4-5 nines of reliability there, let alone "100%".

Otherwise, we could simply observe a few hundred human births, observe no defects, and conclude that human births are also "100%" reliable.

In our original debate, we were both slightly wrong about the number of nines of reliability in human births. However, you are now infinitely wrong by claiming an infinite number of nines of reliability in planarian worm amputations. I don't know whether the actual number of nines is 5, or 10, or 20, but I can be certain that it's not infinity, because that would violate the laws of probability.

caylus··on Major standard library changes in Go 1.20
> pointless, hyperbolic figure is irrelevant

Then why not simply give the correct, still impressive, figure, as I suggested?

> the regeneration is always, 100% a head, if no change in the bioelectrical gradients

This is also a meaningless statement. It's correct 100% of the time, except when something goes wrong and it's not.

Can you quantify the likelihood of something going wrong with the "bioelectrical gradient"? I'm not familiar with this organism but I suspect it's several nines, but less than 7.

In general, probabilities less than a certain amount stop being meaningful, because it's more likely that the model used generate the probability fails to reflect reality. See https://www.lesswrong.com/posts/AJ9dX59QXokZb35fk/when-not-t...

caylus··on Major standard library changes in Go 1.20
> 99.99999+% of newborns have 2 hands, 2 legs, and 1 head

This number is far too high. The rate of conjoined twins (violating "1 head") is about 1 in 50,000 [1], and the rate of "limb reduction defects" (violating "2 hands and 2 legs") is about 1 in 1,900 [2].

Those correspond to 99.998% and 99.94% respectively. 3-4 nines is still impressive for such a complex system, but let's not claim it's 7+ nines.

[1] https://www.chop.edu/conditions-diseases/conjoined-twins [2] https://www.cdc.gov/ncbddd/birthdefects/ul-limbreductiondefe...

caylus··on Flat-to-curved screens have an identity crisis
I'm not sure how the math works for 3D games, but I would think that for 2D games, a curved monitor actually reduces distortion.

In a flat monitor centered in front of your head, the distance between your eyes and different pixels on the screen varies depending on how close they are to the edge, thus distorting the sizes of the rendered sprites. Curving the edges reduces this effect (depending of course on the exact curvature and distance to the monitor).

I guess the key question for 3D is whether the rendering engine already attempts to compensate for this effect. It seems difficult for it to do so, since monitor sizes and distances vary so much, but I suppose that's what settings like field-of-view are for.

caylus··on Most Texans pay more in taxes than Californians, data suggests
In general yes, but I think Prop 13 complicates matters, because it's not just a lower tax rate, but rather applies unequally to different properties based on their transaction history. (e.g. a property built or sold recently gets high taxes, while one that's been unchanged remains low)

So we can divide the rental market into high-tax and low-tax properties. The landlords of high-tax properties must incorporate the tax into the rent. Meanwhile, the landlords of low-tax properties can set their rents just as high, since they compete in the same market, and pocket the tax difference.

In contrast, a flat property tax reduction would increase the profit margins of all landlords equally, and any one of them could start undercutting the others and be undercut in return, which over time in an efficient market will tend to lower prices back to a similar margin before the tax reduction.

caylus··on Rust should not have provided `unwrap`
> Well, that puts regex compilation in the same category as array indexing in my mind, and means that the default regex compilation function should panic on the user’s behalf

I like the Go stdlib idiom for this: many functions have a version with a "Must" prefix that has the behavior of panicking rather than returning an error.

e.g. for regexp: https://pkg.go.dev/regexp#MustCompile

caylus··on Tesla Autopilot Almost Steers Model 3 into Oncoming Train
> An incoming train that any human (with normal sight) would have no problems to detect?

To be fair, failing to yield to oncoming traffic when turning left is an extremely common mistake for human drivers to make as well.

In fact, earlier in the video, the car correctly yielded to an oncoming car, the human driver overrode it, then complained that the oncoming car "cut him off"! https://youtu.be/yxX4tDkSc_g?t=494

caylus··on “Crypto drainer” template facilitates theft
Others in the thread have mentioned that the MetaMask wallet provides a warning prior to allowing a site like this to access the wallet.

For reference, this appears to be an example of that warning: https://github.com/MetaMask/metamask-extension/issues/11337

Transcript: "Signing this message can have dangerous side effects. Only sign messages from sites you fully trust with your entire account. This dangerous method will be removed in a future version."

Presumably part of the issue is that a legitimate "NFT mint" transaction might also carry the same warning.

caylus··on Loot boxes in video games
This goes far beyond a "working definition" in that it encompasses literally every game that unlocks content in any way. /Some/ distinction is needed to differentiate a "loot box" from every other game mechanic.

It would be like using "a metal object that can harm people" as a working definition of an assault weapon. If the definition also includes ladders, cars, and push-pins, it's far too broad to be useful in any discussion.

caylus··on Loot boxes in video games
Even worse, the definition doesn't even say anything about an element of chance!

If when my character levels up through gameplay they unlock a new ability, that would also seem to meet this absurdly overbroad definition of a "loot box".

Even if we added the requirement of real money purchase, offering some features of a game only as part of a paid expansion also has nothing to do with "loot boxes".

caylus··on Bad government policy is fueling the infant formula shortage
There may be thousands of banks, but all but a few manage their funds at one of the big few, essentially acting as resellers of the big banks' services. For example, I my bank is "Ally Bank", but if I ask them for instructions on how to receive a wire transfer, they instruct me to direct it to "JP Morgan Chase Bank, N.A.", the largest bank in the U.S. I previously used the brand "Simple Bank", which provided accounts via "The Bancorp Bank", the 5th largest.

It's a similar case to cell phone providers: although there are hundreds in the U.S., all but four do not operate their own network, but rather resell the network of one of the big four.

It's an interesting question, though, how much this consolidation is due to regulation versus being a result of a natural monopoly, i.e. high barrier to entry for the type of business.

caylus··on Coinbase warns that bankruptcy could wipe out user funds
Sure, banks can create money "out of thin air" because the liability created when the loaned money is debited is balanced out by the asset of the loan owned to them.

But if the loan defaults, the asset disappears, and if this happens enough the bank risks becoming insolvent and no longer being able to repay other liabilities like its deposits unless bailed out.

Maybe that's what you're alluding to - the Fed will always bail them out so deposits are never lost? That's probably true in practice, but a loan from the Fed can't in of itself restore solvency, since it's still both an asset and a liability. In the most extreme case, the bank would still go bankrupt, investors would lose their money, and depositors could also lose some of their money unless individually bailed out by the FDIC.

Back to the original discussion - the key question here is are people who hold cryptocurrency at Coinbase considered "investors" or "depositors", and are they protected by the FDIC? The latter is almost certainly no, and the former determines how much they can expect to get repaid if Coinbase goes bankrupt.

caylus··on Ask HN: Hiring managers why don't you post salary range in your job postings?
> We regularly lose people to FAANG because we just can't comp the same,

This would seem to support the GP's point - it sounds like you do have an inflexible top dollar range, meaning listing it up front would help to avoid wasting the time of you and candidates who are expecting more.

caylus··on Coinbase warns that bankruptcy could wipe out user funds
While I agree making a bad loan is the most likely reason for a bank to lose deposits, I wouldn't go so far as to call it "the" reason.

Robbery, embezzlement, or natural disaster [1] can also result in loss of funds that would be covered by FDIC, and those risks exist for cryptocurrency too, albeit in somewhat different forms.

[1]: see this paper, which found that "disaster damages play a significant role in bank failures": https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2506710

caylus··on Stripe responds to the Financial Connections/Plaid kerfuffle
Where did you get "verbal abuse" from? We're talking about competition, so a far closer analogy would be an NBA player having to play a a game against one of their friends. Should they not have to do that in exchange for their salary?
caylus··on The Dunning-Kruger Effect Is Autocorrelation
> people you encounter who wildly overestimate their ability are more likely to people who are poor performers

How is this helpful? You won't know whether someone is "overestimating" their ability until you learn both their estimated and actual performance, at which point you don't need to guess whether they're "likely" to have poor actual performance.

caylus··on A dirty dish by the sink can be a big marriage problem
> The actual reason to make ones bed is to let air circulate in the parts of the bed

I don't follow - doesn't making a bed involve covering the bottom sheet and mattress cover, which is likely what absorbed the most sweat, with the top sheet and blankets, which would block the airflow to it?

When I need to air out my bed, I push the blanket and top sheet over to the side opposite the side I slept, which makes it look messier, not nicely made.

caylus··on Debian still having trouble with merged /usr
> - /bin/python3 is a symlink to /usr/bin/python3

You don't symlink everything in /usr/bin to /bin, just "all regular files that have traditionally been in /bin" (per the article).

python3 has not traditionally been in /bin, so /bin/python3 would not be linked.

caylus··on US Senate votes unanimously to make daylight savings time permanent
In some areas, standard workdays would span "days". So e.g. a business would need to post its hours as "M-F, 00:00 - 1:00, 17:00 - 24:00". (actually it's even worse as the last 00:00 - 1:00 is on a Saturday)

Or imagine chatting with a friend at 23:00 about plans after you get off work at 1:00 the following "day". "See you tomorrow?"

Or do you reserve "tomorrow" for telling someone at 8:00 that you'll get back to them when you wake up at 16:00 that same "day"?

Today people only have to deal with this when communicating with people many time zones away, but now it's an issue even within a single area!

caylus··on Body Ritual Among the Nacirema (1956) [pdf]
> No matter how grave the emergency, the guardians of such temples will not admit a client if he cannot give a rich gift to the custodian

My first reaction on reading this was, "no, it's illegal for a hospital to deny emergency care". But then I noticed this was written in 1956, whereas the EMTALA was only passed in 1986. Good to know we've improved at least a little bit.

caylus··on US Senate votes unanimously to make daylight savings time permanent
If we abolished time zones, it wouldn't make sense /ever/ for people in some parts of the world, even when communicating with people close to them. That's worse.
caylus··on America produces enough oil to meet its needs, so why do we import crude?
> Lack of price controls did not prevent blackouts to Texans in the US last year. It did cause many folks to be saddled with insane bills.

You're conflating two distinct sets of people:

- Most consumers pay a fixed price for electricity set by their utility. Many of these people experience blackouts when there was insufficient supply at that price.

- Some consumers opted into paying a variable price for electricity. As supply decreased, the price they paid massively increased. But in exchange for the high bills, these customers did not experience blackouts, or at least experienced them later than others.

Some in the second group, in retrospect, would have preferred the blackout to the increased price, or perhaps didn't understand the implications of their decision when they originally signed up for a variable and uncapped price. But overall, this situation perfectly illustrates the tradeoffs of controlled vs. uncontrolled prices in the face of supply shortage.

caylus··on A quick breakdown of what SWIFT is and why it matters
I address electronic transfers in the next paragraph. Even if initially transferred only within the bank, it is likely to eventually be transferred to another bank, which requires the bank to transfer corresponding reserves to that other bank.

Only the Federal Reserve can create truly unlimited amounts of money without the risk that customers might request transfers that exhaust their reserves.

Complying with reserve requirements imposed by the Federal Reserve on banks help to mitigate this risk, but they are not the true restriction. Even if the reserve requirement was zero, banks would need to keep some reserves or they would be completely unable to fulfil requests to transfer funds to other banks. And even if a bank exceeded the reserve requirement, for example by keeping 50% reserves rather than 10%, they would be insolvent if customers requested 51% of balances transferred out and were unable to cover it with loans from other banks.

caylus··on A quick breakdown of what SWIFT is and why it matters
> when you borrow $500,000 from the bank, the bank’s funds don’t go down by $500,000

While technically true, this is a bit misleading, because if you actually /do/ anything with the $500,000, that does in fact cause the bank's funds (i.e. reserves) to go down.

If you withdraw it in cash, then the bank will have to give you some of the Federal Reserve Notes it has in its vault, and when they request more from the Federal Reserve, their account there will be debited $500,000.

Or if you send it to someone at a different bank, then to settle the transaction your bank's balance at the Federal Reserve (or another intermediary bank) will go down by $500,000, and the other bank's will go up. This tends to average out if both banks are receiving deposits and making loans at equal rates, but if they become imbalanced the bank is at risk of its reserves falling below the requirements, which it must remedy or risk bankruptcy.

You're right that low interest rates make it easier for banks to create money, though, because one option a bank has to remedy low reserves is to borrow them from another bank at an interest rate that the Federal Reserve can influence.

caylus··on In our cashless society, we need to take digital jail seriously
My claim is that when evaluating when an authority's actions were reasonable, we should lend little to no credence to statements by that same authority claiming the actions were reasonable, especially when it is impossible to verify even who exactly was targeted, let alone why.

As a contrasting case, if a police department arrested some people during a protest and released a statement about why, a journalist could verify that against the public records and even follow along the criminal proceedings. How can we verify claims made by the RCMP about their extrajudicial actions?

caylus··on In our cashless society, we need to take digital jail seriously
If anything this reinforces the author's point about the dangers of lack of transparency of "digital jail". How do we know that statement is true? It's hard to hide who has been jailed (though "disappearances" come close), whereas we have no choice but to take the word of the entity which we have granted unchecked power that it has not abused that power.

There's also plenty of wiggle room in their statement - they said they froze the accounts of "influencers" and people they "suspect" committed illegal acts. If it turns out they did in fact freeze someone who just donated, they didn't technically lie if they can fit them into one of those vague groups.

caylus··on Using www-authenticate for user authentication
Over HTTPS? I don't see how that's possible unless they are TLS-MITM proxies, in which case you've completely lost regardless of your authentication method.

Placing the username and password in the URL results in the same TLS-protected HTTP header as normal basic authentication:

    $ curl -v https://user:pass@example.com/page
    [...]
    > GET /page HTTP/2
    > Host: example.com
    > authorization: Basic dXNlcjpwYXNz
    > user-agent: curl/7.77.0
    > accept: */*
    > 
Even over HTTP, a proxy that intentionally logs the URL accessed would not see the username and password in the initial "GET" line. It would have to go out of its way to extract it from the Authorization header, which is still present regardless of how the basic authentication was initiated.

If you meant user agents logging the username and password as part of the history, I suppose you could consider that a bug but it could also be considered a feature. Presumably if you're using a URL of that form your intent is in fact to be able to link or bookmark the URL including the credentials.

caylus··on Everything we're told about website identity assurance is wrong
> This is an attack that doesn't really have an analogue in meatspace

Here's a potential analogue - sometimes people stand in parking lots and collect fees, claiming to be representatives of the lot's owner, but in reality pocketing the money.

Some lots counter this by posting signs along the lines of "do not pay any attendant; pay only via kiosk/online". But since some lots do in fact collect payment via attendants, a potential way to secure this would be for the attendant to present proof that they are employed by a certain company. While the customer might not be able to verify that "ABC Parking, Inc." is in fact the owner of the lot, at least they would have a trail to follow if they were scammed.

This is an area where cyberspace has an advantage - the closest analogue to an EV certificate in the physical world would be a piece of paper with some official seal on it, which can still be forged in a way not easily detectable by the average person.

caylus··on Idiocracy: A disturbingly prophetic look at the future
Perhaps they want to limit their corporate position on political issues to the ones directly relevant to them, so as to not repel people who disagree on an unrelated issue.

Their original memo (https://blog.coinbase.com/coinbase-is-a-mission-focused-comp...) puts it this way:

> We don’t engage here when issues are unrelated to our core mission

Page 1 of 3Next →