HNHacker News
TopNewBestAskShowJobs

chrismorgan

26,906 karma · joined September 13, 2012

https://chrismorgan.info/, me@chrismorgan.info

I’m available for hire for consulting, training and mentoring in Rust, everything web, performance and more: https://chrismorgan.info/hire-me/

[ my public key: https://keybase.io/chrismorgan; my proof: https://keybase.io/chrismorgan/sigs/rEm41-0pghG3ITW8S5HeuFLA9TznvPSlg9NKgXXRXqQ ]

submissionscomments
chrismorgan··on Vermont replacing power plants with home batteries
The whole depth of discharge thing does make it harder to compare them. I said upthread “slightly higher capacity” for LiFePO₄, but I feel like by recommendations I’ve heard it’s more like 20–40% higher, which is really quite a bit.
chrismorgan··on Vermont replacing power plants with home batteries
I’ve seen and heard of a lot of lead-acid battery home inverter and desktop UPS setups in India (extremely common due to grid unreliability). Desktop UPS batteries sound to consistently be completely useless (<10% capacity, typically 0%) in 3–5 years, and the larger home inverter batteries are typically in poor shape by around 5 years.

I haven’t known any Lithium-ion batteries yet, so I have no personal figures on them. But what I’ve heard is generally more like “they said 8–10 years but it’s still fine after 12”.

chrismorgan··on Vermont replacing power plants with home batteries
I was looking into this stuff early this year in India, and found LiFePO₄ more compelling on paper: two or three times the cost, but lasting two or three times as long, allowing deeper discharge so it should be equivalent to slightly higher capacity, and requiring no maintenance. I could easily have overlooked or misunderstood something, and am interested in counterarguments.
chrismorgan··on Improving site performance by shipping more CSS
Compile everything together and you know what names are used. I can’t comment on whether it’s easy or even possible with the specific toolchain in question, but the concept is very straightforward.
chrismorgan··on Tells of a Slop UI
> Emoji Slop

Not just emoji, icons in general, in both website generation and image generation.

chrismorgan··on Improving site performance by shipping more CSS
You could also drop the hash part and gain most of that improvement. Or module and hash and do better on compression (because the hash is high-entropy).

Rudimentary experiment on https://github.githubassets.com/assets/te.1288ac5c9584fbf2.m... on replacing /(?<module>[A-Za-z0-9_-]+)__(?<local>[A-Za-z0-9_-]+)__(?<hash>[A-Za-z0-9_]{5})\b/:

${module}__${local}__${hash} (original): 72967 raw, 10993 br.

${module}__${local}: 68459 raw, 8867 br.

${hash}: 48754 raw, 8189 br.

${local}: 52610 raw, 7927 br. (Now in practice a few of these are likely to need disambiguation, so it’s probably a tad smaller than realistic.)

Frankly I think ${local} is the right target, with global disambiguation where necessary. For typical systems, I consider the hash approach to be foolish: its value is when interacting with unknown other styles, but when you’re compiling everything you should know everything, so you can disambiguate more selectively and succinctly/compressibly, as JS build tools like Rollup do (in flattening modules with colliding names, you’ll get Foo, Foo$1, Foo$2, &c.).

chrismorgan··on OpenAI agents tried to bruteforce a UN website's API fields
https://www.felonybench.com/
chrismorgan··on How I changed teaching after AI managed to do all my homework assignments
> "you fail them" can mean both "you give them a failing grade" and "you fail to provide the support they need", right?

Yes, but as written the latter would not be a reasonable parse. For that sense: “you have failed them”, sure; “you are failing them”, sure; even “in acting so, you fail them”; but “and then you fail them” as an entire sentence would be very weird. The emphasis I placed on “fail” also doesn’t feel particularly compatible with that sense of the word.

chrismorgan··on The Copilot+ PC brand is dead
It may or may not be easy, depending on your environment, but you can remap keys. I have `input * xkb_options "caps:backspace,compose:ralt"` in my ~/.config/sway/config, for example, plus `input ‹laptop keyboard identifier› xkb_file "~/.config/sway/keymap.xkb"` with that file fixing XF86AudioMicMute (which has key code 256, but X only supports up to 255 and I’m still not quite sure why this was necessary), and now remapping RShift to LCtrl which died early this year.

But… ouch. From https://itsfoss.com/remap-copilot-key-linux/ and other sources, sounds like the Copilot button is LMeta+LShift+F23. Why a combo when using an esoteric key not on anyone’s keyboard anyway? Ugh. That’ll make it harder to sort out, though still possible.

chrismorgan··on How I changed teaching after AI managed to do all my homework assignments
And then you fail them. I suspect an institute genuinely empowered to do so, where the expectations were declared up front and followed through on consistently, would fare well, after the dust settled.
chrismorgan··on How I changed teaching after AI managed to do all my homework assignments
What you’re calling evaluating is a part of the learning process for the student, not just about confirming that the student knows the thing. LLMs are actively undermining learning in this way. There was useful friction which has been removed.
chrismorgan··on Goodbye Google
> uncertainty about the motives of another, omnipotent supernatural intelligence

It’s not uncertainty about the motives; those and the end state are clear. It’s just the details of how we get there (“God’s plan”) that aren’t clear.

chrismorgan··on OpenAI breaches Medicare, Albanese reveals
https://www.felonybench.com/ scores increase apace.
chrismorgan··on A brief history of Windows scroll bar shortcuts
In Linux/GTK, clicking in the gutter navigates to that position, and I have just discovered that Shift+clicking is equivalent to PageUp/PageDown, and that right-clicking seems to also be equivalent to PageUp/PageDown in Firefox, but scrolls at a fixed slow pace while the button is held in LibreOffice (15s per screenful at 6fps in Writer) and Inkscape (3s per screenful, smooth), and that middle-clicking is mostly PageUp/PageDown, but noop in Firefox; and I think those are the only apps I use (maybe even have installed) with regular scroll bars.

Oh yeah, one more, BibleTime which is Qt: it’s fairly Windowsy, click is PageUp/PageDown, right click is context menu (Scroll here, ---, Top, Bottom, ---, Page up, Page down, ---, Scroll up, Scroll down), Shift+click is same as click, middle-click is scroll here.

(These sorts of things are also one reason why you shouldn’t implement your own scroll bars in web pages: different platforms behave differently, and you can’t match it all sanely or sometimes at all.)

chrismorgan··on WordPress: Unauthenticated path traversal leading to conditional RCE
> That should be the default, not something you need to take extra care over.

I agree. That’s one of the problems of PHP’s file-based execution model, and how the likes of Apache and nginx work. Drupal is no paragon of security, but it’s far closer than WordPress. For all its faults, even Node.js avoids this class of problem.

chrismorgan··on WordPress: Unauthenticated path traversal leading to conditional RCE
WordPress’s security model is distilled insanity, concentrated vulnerability. You’re supposed to give your site write access to its code, which turns almost any vulnerability into complete and persistent site takeover. Not to mention how many things will store code in the database and execute it from there, and how much of its design is fragile as anything, and how many plugins, often popular ones, do obviously dumb things that would not have been possible in most ecosystems.

Drupal (also popular in governments and such), by contrast, will check that it can’t write to anything but its designated file uploads directory, and complain if it can, and has careful guidance around avoiding letting uploads be accidentally executable too. The blast radius of the typical vulnerability, and the possibility of persistent takeover, is drastically reduced.

It’s possible to use C correctly, but in practice using it invites security problems, because it’s frightfully easy to make subtle but disastrous mistakes, even for experts, so there are reasons why people are moving to safe languages.

WordPress is that kind of bad. It has always been bad, though it’s somewhat less bad than it used to be. Some of its badness is a part of how it got popular.

chrismorgan··on WordPress: Unauthenticated path traversal leading to conditional RCE
The patch (identified from https://github.com/WordPress/wordpress-develop/compare/7.1.1...):

https://github.com/WordPress/wordpress-develop/commit/9c4e85...

chrismorgan··on 9 Ads per Minute: FIFA Cup 26 – "the price of the beautiful game"
I would be astonished to find a business wasting only half of its advertising spend.
chrismorgan··on Noodle Gallery – Self-hosted photo and video manager forked from Immich
Better link: https://opennoodle.de/

The submitted title’s framing “alternative to Google Photos and Immich” is dodgy because this is a soft fork of Immich, adding certain features, described in https://opennoodle.de/noodle-gallery-vs-immich/.

chrismorgan··on Disney+: New user agreement allows ads before movies in all subscriptions
A lot of the ads on the field and perimeter are themselves inpainted. And becoming more and more offensive over time, with animation and flashing and such as technical capabilities improve and viewers become accustomed and don’t revolt.
chrismorgan··on AI-generated posters don’t have to be horrible
The Designers Republic one arguably avoids it. Only one of its five is an icon: three are zero-padded numbers and one is a smudge where someone forgot to stamp the icon.
chrismorgan··on Making a movie in pure SVG using SMIL
In 2004, when they were working on 0.40, it was on the roadmap for 0.49 <https://wiki.inkscape.org/wiki/index.php?title=Roadmap&oldid...>. Unfortunately it never happened, though they invite people interested in implementing it to join the development team <https://inkscape.org/learn/animation/>.
chrismorgan··on Chopping up books when they're physically too big
Printing is a good constraint against getting too long, both the physical and cost constraints. Though the Harry Potter series in full still managed to reach a million words.

For another comparison, the Bible is around three quarters of a million words, and tends to use special paper (20–40gsm/30–50 micron) so it works in one volume.

Handwriting is also a good idea for encouraging keeping lengths down; typing and dictation make verbosity too easy; and as for LLMs, words are clearly far too cheap there.

chrismorgan··on The CSS Zen Garden dream, finally shipped
And the entire analogy is incoherent.

And how all six people links are to LinkedIn, when most of them have websites. (Wouldn’t surprise me if some of the LinkedIn profiles were incorrect, but since you can no longer view anything on LinkedIn without having an account…)

chrismorgan··on The CSS Zen Garden dream, finally shipped
I see no connection whatsoever with the CSS Zen Garden dream. CSS Zen Garden was about applying radically different styles to the same markup. This is about newer CSS features like Custom Properties, Flex and Grid making maintenance of a single stylesheet for a single completely typical website.
chrismorgan··on Cloudflare AKE cuts origin HelloRetryRequests from 52% to 3.7%
Genuine question: why wouldn’t they have been doing this already? It feels like obvious low-hanging fruit on a critical path, so I presume there’s something more to it than I’m imagining.
chrismorgan··on Base84 deserves a place in file names
Not much is actually UCS-2; almost all things like that are rather unvalidated UTF-16, also known as sequences of UTF-16 code units.
chrismorgan··on Base84 deserves a place in file names
Approximately nothing that uses UTF-16 validates it (I can’t think of a single thing that does), so surrogates will work fine. At least until a UTF-8 system touches it, because they normally do validate (Go is an uncommon exception in not validating).
chrismorgan··on Compiler Can Undo Your Security Checks
> Rust also has UB, btw

Not at all the same. C and C++ are full of hazards and I get the impression it’s genuinely difficult to avoid entirely in normal code bases, and typically impossible to avoid statically. Whereas in Rust it’s all gated behind the unsafe keyword, and if you don’t use it (and most code bases never need to use it), you cannot encounter UB; and that scoping makes it far easier to control and handle correctly.

chrismorgan··on Antiquated HTML Snippets and Artefacts
Yeah, I was responding to the new micros post here rather than the earlier Lobsters list.
Page 1 of 34Next →