HNHacker News
TopNewBestAskShowJobs

cm3

3,067 karma · joined September 17, 2012

submissionscomments
cm3··on This Summer in Redox: A Complete Rewrite of the Kernel
We really need to have a mainstream desktop microkernel operating system because:

1. no need anymore for kernel bypass mechanisms (too many to name for linux, btw)

2. decoupling of drivers from the kernel

3. instead of waiting for a backport of a new syscall to an LTS kernel, something like that will be just part of your system's stdlib

4. extremely reduced need to reboot a machine

5. driver faults can be recovered from gracefully, just like in Erlang's supervisor scheme

6. seL4's capability system allows for a safer system overall, with less hacks

Seeing how even Intel is introducing a message passing network with growing number of cores in their mainstream CPU designs, we should be over the general objections regarding a message passing design. They call it QMD, and it's something they already have in their Xeon Phi line for some time for obvious reasons, just as countless other general purpose or special purpose chip designs have had for a long time.

I wonder if one could get funding for an effort like Robigalia to reach production quality and have Servo running on it. Given the feature set of Servo, it's a safe bet that the required features would provide a reasonably complete system to replace your Linux machine.

The bigger struggle would be getting hardware vendors to contribute to FreeBSD and Linux drivers to also provide some level of support for a non-C code base. Though, moving up to that abstraction and language level should make it easier to write working hardware drivers.

cm3··on This Summer in Redox: A Complete Rewrite of the Kernel
Because Redox's aim is to be as little non-Rust as possible. I agree it'd be ill-advised to rewrite seL4 rather than use it, even though it's been a while since a revision was verified, because it's been battle tested, is continually improved and small enough to trust.
cm3··on This Summer in Redox: A Complete Rewrite of the Kernel
> In order to continue the development in a reasonable speed, we stop conforming to the specification of ZFS. As such, we can no longer call it a ZFS implementation.

They have their valid reasons, but it's a shame, because an implementation of the very complex ZFS filesystem in Rust would have been a great thing to have. Not to mention the ability to mount redox zfs images with illumos or FreeBSD or ZOL.

cm3··on This Summer in Redox: A Complete Rewrite of the Kernel
Yeah, I wish they had teamed up with Robigalia in order to build on seL4 or at least translated that 1:1 to Rust, foregoing the verified nature of seL4.
cm3··on Keith Ohlfs, NeXTSTEP Designer, has passed away
Do you know of an icon set conversion of those that would work with gtk3? Even most icon themes that work with gtk2 are incorrectly structured for gtk3, with wrong icons display for, say, +/- controls. Using the ugly Adwaita set because it's the only complete and working one. The Haiku icon set also only works with gtk2.
cm3··on Buttery Smooth Emacs
I am one of those X11-only, no-toolkit Emacs users. The only times I need gtk support is when I run a variant build with gtk3 support in order to have a native Wayland window which doesn't require Xwayland. But I primarily use X11 so the no-toolkit, X11-only build.
cm3··on Buttery Smooth Emacs
Sure, that's why I asked if there's topic branch, even if now obsolete, which I could merge into the 25.1 branch. I'll do some digging, since this seems to be a single commit from what I can tell.
cm3··on Buttery Smooth Emacs
Can we get this in 25.1.2 or in a branch/commit on top of 25.1 for those of use who don't want to track trunk's development, given how long the reschedule schedule is? The patch from the list didn't the apply cleanly, but I haven't tried to merge it in a git repo (yet).
cm3··on My Mechanical Keyboard
I have tenkeyless cherry mx keyboard already, but I know there have been tenkeyless model M's in the past, which is what I was interested in.
cm3··on My Mechanical Keyboard
I tried and failed to get comfortable with thinkpad trackpoints, so if it's anything like that, I'm afraid it will just sit there unused.
cm3··on My Mechanical Keyboard
I'm just grateful pc gamers' realization of the benefits of proper key mechanisms has led to more production when it seemed like mechanical keyboards were only marketed in the enterprise. There was a time when flat rubber keyboards were all the hype.
cm3··on My Mechanical Keyboard
If that's the same company, then the price seems to have dropped substantially.
cm3··on My Mechanical Keyboard
In cases where there is no PCB with PS/2, do you know if the adapter when connected to PS/2 has the exact same behavior or are is it a lesser/compatibility mode without the full benefits?

Anytime I sit at a machine where the USB chip happens to reset, I wish it would use PS/2. It's just not the same, and I'm not even using n-key-rollover.

cm3··on My Mechanical Keyboard
IBM used to make tenkeyless Model M's, wish Unicomp would offer the same since I'm very used to having the mouse closer to my hands. Then I could give a Model M a serious try, having used Cherry MXes for two decades, with the occasional one day excursion on a Sun or HP workstation keyboard.
cm3··on My Mechanical Keyboard
I cannot type comfortably on anything but MX black or browns, so I wasn't able to use an ergonomic keyboard yet. There's one company in Australia that builds to order ergonomic keyboard with mx keys, but the price is in the same range as HHKB, which makes it hard to order blindly from across the world, and custom built on top, which means hard to send back for quality deficiencies.

Are there other ergonomic keyboards with mx switches?

I'm using a tenkeyless mx black at the moment where I had to insert multiple layers of padding to dampen the echo sound of the pcb on each key press.

cm3··on The WhatsApp suicide
I've just realized that both Dave and Thomas have been focusing on the topic of abuse prevention, while my comments concern fixing the inexcusably wrong treatment of victims. That must be source of the major misunderstanding here. Huh.
cm3··on Intel driven MacBook Pros have secondary ARM processor for Touch ID and security
On Thinkpads you can disable the routing of signals of the mic and camera in the firmware. Afterwards, it's not available to the kernel. Whether that's somehow hackable via a UEFI bug I don't know, but there are also laptops with physical switches the mic, wifi and a lid for the camera. Your safest bet is to open it up and disconnect the device, which is less likely to raise alarms on Linux and BSD than it is under macos, I assume.
cm3··on The WhatsApp suicide
Thanks, now that you point it out, I can see how that part can overshadow the whole comment and be read in a way I didn't intend to. I'll aim to do better in future comments.

I admit that I'm less prepared to comment in a minefield topic like this than I had thought, as my comment has been easily, and rightfully so, misinterpreted. I'm sorry about that and grateful you do not assume too much. Knowing the etymology of 'victim', it would never cross my mind to do so.

I agree with your explanation how rape and subsequent shaming and general mistreatment is being facilitated, and I think the root cause is our conflicted and unhealthy approach to sexuality. I don't think it would reach the same effect if sexuality was a mundane topic, so that abuse can be treated as a crime rather than, as you say, presented as disobedience by those in positions of power and widespread misogyny in general. If it wasn't a taboo topic, victims would probably be more inclined to come forward and falsely accused but acquitted wouldn't be shunned as easily. That's the gist of my theory, if I look at it like a programmer, a logician. How true that is in the real world I don't know, and I'm sorry for not phrasing it as an open question to begin with.

Basically I tried and failed to paint a complete picture how society prefers to mark abuse victims as well as falsely accused perpetrators as personae non grata rather than find solutions to the problem. Tragically, society fails so much that it causes and is responsible for suicides. I blame society only, and theorize that our inexcusably wrong approach to sexuality facilitates it.

Neither was I trying to say that her death is an inevitable outcome or that men are somehow led to commit those heinous crimes. Thinking men have no choice and have to be protected is why some wives have to wear veils. It's wrong, at least 2300 years late in human society, and nothing I stand behind. Seeing how my comment has been interpreted that way convinced me that I'm unprepared to debate this topic in an international plaintext forum among people who don't know each other personally. Sorry.

Any insensitivity I may have expressed in the comment is because I'm a technically minded person first, thinking in terms of logic, and looking for the root cause of a segfault (societal flaw). I guess I'll stay with technical topics where there's a closed world with rules I can look up.

This thread, and your comment in particular, provided me with a more complete picture than I had this morning. Thanks for pointing out the flaws and incomplete parts of my thoughts. I believe in constructive criticism and open debate, so asking someone "did you really mean .... or what is it you're trying to say?" is my preferred approach rather than making assumptions, so thanks. Also, yes, if we knew each other personally, you'd have been more likely to correct me, knowing what kind of person I am. Thank you for not reducing me to a utf-8 blob on HN.

cm3··on The WhatsApp suicide
KirinDave points out in a sibling comment that what I wrote here can be read to blame rape victims. Under no circumstance is that the message I was trying communicate, but I take full responsibility for failing to write an unambiguous comment. I did not mean to blame the victim, and don't think I did, but I'm willing to learn from my failed wording to not repeat in the future. What I tried to express is that due to the way sexuality is handled in most societies, we mistreat rape victims as a result. I'm sorry I failed to convey that message clearly.

I'd be grateful if you can quote what parts can be read in a way that I didn't intend them to be, and I'll either choose less ambiguous expressions or omit the thought entirely, seeing how hard it is to communicate precisely.

cm3··on The WhatsApp suicide
It's unfortunate that's how you read my comment, and I take full responsibility for failing to write an unambiguous comment. I did not mean to blame the victim, and don't think I did, but I'm willing to improve the wording to not repeat what you say blames the victim. Please quote what parts can be read in a way that I didn't intend them to be. In fact, what I tried to express is that due to the way sexuality is handled in most societies, we mistreat rape victims as a result. I'm sorry I failed to be clear about that.
cm3··on The WhatsApp suicide
You're right. In some communities it's enough for a police car to come to your house for the neighborhood to treat you differently.
cm3··on The WhatsApp suicide
My point was that the structure of said society may lend itself more to facilitate the events leading to the inexcusable, tragic result. That said, there have also been harassment/bullying (not comparing, equalizing the events, to be clear) victims in the US that committed suicide, so I think I get what you're asking.

Let me try to rephrase: I'm not saying this was the case in this incident, but the fairly unique classification rules of the society in question may increase the chances of such an outcome and be another reason to rethink the rules.

cm3··on The WhatsApp suicide
I'm sorry, what are you asking?
cm3··on The WhatsApp suicide
And it may not have helped that the place in question has tribalism in place which classifies persons by their heritage in ways that are unimaginable to most of the HN crowd.
cm3··on The WhatsApp suicide
Some societies are worse than others, but if even in the self-proclaimed modern civilization of the western world professionals in the adult entertainment or sex/erotic services industry are treated like 2nd class citizens, there's a need for a more substantial shift in perception and treatment of something that's as natural as eating and sleeping. It's unnatural that many societies have created ways to suppress human nature in many ways they deem morally incorrect, and it's very wrong that laws reflect the moral world views of some.

I won't go into how there used to be societies which in some regards were more open and safer than today's, or how the treatment by a part of some religious communities goes against those religions' core beliefs.

Empowering people to defend themselves and deal with abuse in a dignified way is very important, and we first need to stop blaming victims as "promiscuous" or "having asked for it". This isn't very different from how we treat people who went to prison.

EDIT: We also need to find a good way to investigate accusations without automatically assuming that, for instance, alleged male perpetrators are by default considered (not found, to be clear) guilty, or that wives do not abuse their husbands. The described societal defects are partly to blame, as are underequipped/unskilled law enforcement or judicial departments. If someone can lose their job and family because anybody merely publicly accuses them of a sex crime or adultery, then it's clear we have a problem on the other end of the spectrum. To me, both are caused by related societal flaws and will take a long time to correct. Another way this surfaces is that people tend to worry more about a government official's personal life than their positive/negative acts in office.

cm3··on Intel driven MacBook Pros have secondary ARM processor for Touch ID and security
Given that iSight and Facetime HD cameras required drivers and firmware to get running under Linux, I would be positively surprised if the new camera is easier to set up, meaning I don't think it works right now. Even the existing camera support isn't 100%, with features like suspend/resume being flaky, all due to it being reverse engineered.

That said, the options for developer laptops has shifted in favor of general x86 computers, including very light-weight machines and ones with mechanical keyboards. If I want to use Linux on it, my first choice wouldn't be a macbook. So, unless you require macos for work, you have have a more diverse variety of laptops to find one that suites you best.

cm3··on AtomBombing: A Code Injection That Bypasses Current Security Solutions
Thanks, I need to reread it, because I'm not sure who invokes the syscall. Quite possibly it's automated via an innocuous looking DDE invocation. Basically, I'm wondering what piece of code writes to the table and then makes some other aimed for application run the code from the table. If it's a piece of code that's already running as the same user, then the aim must be to make a higher privileged application to execute the code from the table. Need to brush up my Win32 knowledge to make sense of it, I guess.
cm3··on AtomBombing: A Code Injection That Bypasses Current Security Solutions
Windows Atom Tables are nothing special and are, like many APIs invented for other features, very old. Think using lookup for DLLs in the same dir as the program or autorun.ini as similar old feature that were abused as attack vectors.

https://msdn.microsoft.com/en-us/library/windows/desktop/ms6...

cm3··on AtomBombing: A Code Injection That Bypasses Current Security Solutions
I've read all the text yesterday and still don't see an explanation how code is executed. I know Windows atom tables as a feature used in DDE (say for clipboard infrastructure), and it's been there like forever, but how is the code from the table executed?
cm3··on Incident Report: Inadvertent Private Repository Disclosure
If you have private repositories that should never be public, no matter what, which isn't true for most users of private repositories, then:

Given that git provides many transports and ways to push commits around, I agree. If you have to be safe, there's no reason to use github or a self-hosted git collaboration service (gitlab, etc) on a publicly accessible server, regardless of access control measures. If you really need to have sources on a remote machine, you can limit the potential damage by only sharing archives of a certain revision, without history.

I know many will dismiss it, but if you're serious about the repositories being private, then the most you make them accessible is via an on-premises hosted gitlab instance, which is local to the company network, not accessible via the public network, and only allowed to, if you want, by dialing into VPN first. Then, to be safe, you null-route anything but the VPN traffic on the connected off-premises developer machine.

Access keys get stolen, just like SSH keys are, so you need to use a VPN service that requires additional security like the use of OTP key generators or similar measures.

This probably sounds like a hassle in the day and age of people just going for the comfort of private github or gitlab repositories, but it's what companies have been doing for almost 20 years as standard practice.

You cannot consider any git repository, even on your own root server, safe to keep private code on. CIOs would argue against that practice for good reason. The same CIOs require work laptops to encrypt all data.

If you don't need to be that serious, then an incident like this should be planned and accounted for as part of using such hosting, and shouldn't be a big deal.

← PreviousPage 2 of 34Next →