HNHacker News
TopNewBestAskShowJobs

codedokode

9,555 karma · joined August 20, 2015

PHP developer from Russia.
submissionscomments
codedokode··on Raspberry Pi blocks changing RAM chips
What if the manufacturer charged no markup on RAM price, wouldn't it make "illegal upgrading" pointless because they couldn't compete on price? The manufacturer buys RAM in bulk and has better pricing.
codedokode··on Spain orders blocks on Archive.today and its mirrors
Probably because in Finland you are provided housing and money even if you don't work.
codedokode··on Spain orders blocks on Archive.today and its mirrors
Is being 9th in (nominal) GDP rating now is mentioned as "even"? 90% of the world is behind Russia.
codedokode··on New evidence for hidden chambers beyond Tutankhamun's tomb
Interesting, I read about excavations in beginning of 20th century on Wiki:

> In protest of the government's increasing restrictions, Carter and his associates stopped work in February 1924, beginning a legal dispute that lasted until January 1925. Under the agreement that resolved the dispute, the artefacts from the tomb would not be divided between the government and the dig's sponsors, as had been standard practice on previous Egyptological digs.

Why they did have a rule that private persons can take away the artifacts? It would be better not to dig anything.

codedokode··on Inside ZCode: Silently uploading your Git history to the cloud
Is it much different from Apple and Google who trick user into agreeing and upload all user's data into a US cloud for convenient LE access?

Also, as I understood, this is a feature to allow server-side indexing of the project. But of course I wouldn't run this, and I generally wouldn't run any IDE or AI tools without a sandbox.

Sadly this plague of silent auto-updates is spreading to Linux. For example, browser plugins in Firefox on Linux can silently auto-update without user consent and without any checks and can be used as backdoors. Furthermore, the auto-updates are not using a package manager; firmware also seem to quietly update and also is not using a package manager.

codedokode··on Inside ZCode: Silently uploading your Git history to the cloud
You should use a sandbox. It is dumb to run any proprietary software without a sandbox, especially LLM-powered.
codedokode··on OpenAI bots knew about the RubyGems caching vulnerability
As I remember, you are also supposed to turn the wheels so that even if a car starts rolling, it won't be able to go staight.
codedokode··on Texas judge rules TikTok misled users on child safety feature
But we didn't sue or blame anyone for this.
codedokode··on Jabber/XMPP: How Do We Gain Traction?
Who are those people having lot of time to re-read their old message history? I assume most people only read last several messages in a chat. This matches the real life conversations which are not stored anywhere. However, police will definitely be happy to discover that your many years messaging history is intact.

I would rather want a feature, like Telegram has, where you can set auto-delete of all messages older than N days.

codedokode··on Jabber/XMPP: How Do We Gain Traction?
I am ok with Electron if it is needed for Matrix. Also, Telegram has a C++ desktop client.

Also, I would not advise to add proprietary repositories as you grant them root access to your system which is against security practices such as the principle of minimum privileges and defence-in-depth.

codedokode··on Android NAT-T keepalive offload bypasses VPN lockdown
How does PIN help against this? Also, my packets are already routed through malicious actors - ISPs, luckily most of them are encrypted.
codedokode··on Texas judge rules TikTok misled users on child safety feature
> TikTok in August agreed to settle three U.S. lawsuits brought by young people who accuse social media companies of designing their platforms to be addictive and harming their mental health.

I am so happy I do not live in US where an idiot harms themself and non-idiot has to pay them.

codedokode··on Texas judge rules TikTok misled users on child safety feature
Because 99% of adult people have other things to do than manually build content filters.
codedokode··on Revolut confirms customer data breach through fake government requests
Yes, but it might go to an internal system, and internal bank systems are protected relatively well compared to mobile apps. And you don't have to do a selfie.
codedokode··on Revolut confirms customer data breach through fake government requests
Not necesary, it might be an internal system. And no selfie. For example, in Russia it probably would be illegal to send personal and biometric data abroad. But of course in the West the rules might be different and it is ok to send citizens' data to shady foreign companies.

Also I am surprised people do not see the different between isolated internal "old school" systems built on owned servers located at the bank property and modern vibe-coded microservices in kubernetes in a rented cloud with the widest attack surface possible.

codedokode··on Data collected by cars and sold to third parties
It definitely can be stopped. For example, China sells cars internally at cheaper prices, but they are locked to prevent using them outside the country. However, there are people who can hack and unlock them allowing operating in any country. But maybe it would be illegal in the West, I don't know. Removing the modem is an easier task.
codedokode··on Revolut confirms customer data breach through fake government requests
Some banks, I assume, allow showing the documents in person and without a selfie.
codedokode··on Revolut confirms customer data breach through fake government requests
You do not need to compromise anything, you can put any address in the "from" field. Email has no universal verification for sender address.
codedokode··on Revolut confirms customer data breach through fake government requests
This is a reminder about what happens to people happily uploading their passport and selfies into the app. Do not do it if you do not want to end up in a Russian underground forums.
codedokode··on Android NAT-T keepalive offload bypasses VPN lockdown
A pocket thief will bring the phone to a friend with a laptop and black market software. If the phone has no theft protection, they will factory reset it; if it has, they will use paid software to remove protection. I have not used that software and do not know if it is actual now, but Internet search shows that older phones are completely unlockable.

Just to give an example, here is publicly available information: https://github.com/youngrichu/frp-freedom/blob/main/FRP%20By...

Good thing is that some of the aforementioned exploits can be used to work around locked bootloader and liberate the phone.

Do not rely on any security in Android. It has lot of mistakes, poorly coded high privilege vendor software, so it would be dumb to use it for anything valuable.

> More specifically, another commenter in this thread says it's to make sure the user is aware of the configuration of a VPN which, if done maliciously, funnels all your traffic toa a hostile place.

I do not see how PIN protects the user, especially if user had PIN before installing a malicious VPN. Also, isn't Google Play supposed to check every application for malicious functionality?

codedokode··on Android NAT-T keepalive offload bypasses VPN lockdown
What's the point of setting a PIN if Cellebrite can hack almost any phone?
codedokode··on Android NAT-T keepalive offload bypasses VPN lockdown
The stupid thing about Android is that it requires you to set a PIN to use Always-on VPN which is necessary for traffic filtering (as Android doesn't provide access to nft).
codedokode··on google.com/goto: Google's anti-scraping update
Yandex censors the results, it is required by law, so I do not understand what are you arguing against. To be specific, any URLs, which are blacklisted and banned in Russia, must be omitted from search results. Which includes BBC and other Western media and explains the difference in images because in the Google's results the images come from BBC and Voice of America.

Also, if you try to search for "download Chrome" (in Russian) then the first result in Yandex leads to a scammy website: https://ibb.co/HDRJGgZD The real link is the second one, but I remember a year ago or so there was no official link at all. You can also note that official link to Google has a grey text saying: "the owner of the resource violates Russian law" (Yandex is required to show this notification).

Yandex has also been caught "accidentally" removing the site of Ekaterina Duntsova who was planning to nominate for presidential election in 2024, and showed fake/phishing sites instead.

So, Yandex is only good for searching torrents/pirated movies (which you can watch on rutube) and nothing more.

codedokode··on Diesel prices in U.S. top $6 a gallon for first time
New (Russian) versions of Shaheds are jet propelled (much faster), have high-quality remote control, and as some claim, AI-based computer vision. So old interceptor drones are not working anymore. And the country can manufacture them at much higher rate than the other country can manufacture patriots.
codedokode··on Qwen 3.8 follows GPT-5.5 Pro reasoning prefills
As I understand, they got paid for the traces unlike owners of scraped websites. They sell text generation tool, so what's the problem if someone generates texts using it?
codedokode··on Qwen 3.8 follows GPT-5.5 Pro reasoning prefills
As I understand, AI is a (paid) tool for text generation, so it's totally ok to generate texts using it for whatever purpose you need.
codedokode··on Qwen 3.8 follows GPT-5.5 Pro reasoning prefills
Interesting how an agent mimics a human hesitating and trying to avoid doing work:

> No.

> This is major.

> Given time, maybe best to respond explaining can't due to time? but instructions expect actual work. However complexity huge; but as coding agent, need to attempt

> Maybe we can cheat ... But user may test and see still single CPU.

The smarter AI will be, the better it will be at avoiding doing actual work.

Also, can similar responses be explained with that both models were trained on a same dataset of answers to the benchmark problems?

codedokode··on Live map of public transport in Belgium
Is it something new? I think Yandex Maps shows busses in real time since long ago (at least in large cities like Moscow). The busses have GPS and send the data in real time. I wanted to post a link but at night there are not many busses and the first ones will appear 1-2 hours later: https://yandex.ru/maps/213/moscow/transport/buses/?l=masstra...
codedokode··on Nitter and XCancel resume service after legal advice
What would an average person lose if everybody used more open platforms?
codedokode··on Show HN: Mador – Make any DOM reactive with a tiny 80-line Proxy state tuple
The syntax looks a bit too verbose for me. And function names like "read" and "write" are confusing too, given that "read" function isn't made for reading values. Cannot we use a single function for binding, like this (and name it "bind")?

    let counter = proxy({ count: 0 });
    bind('.counter', (el) => el.textContent = counter.count);
    counter.count++; // Queues DOM update
Also,

> Mador is distributed as an ES module.

This means it cannot be used on a page opened from disk, and the user needs to set up a HTTP server which is time-consuming and distracting. And you cannot distribute an app as as HTML file.

← PreviousPage 2 of 34Next →