HNHacker News
TopNewBestAskShowJobs

codeguro

74 karma · joined September 12, 2020

submissionscomments
codeguro··on DOGE puts $1 spending limit on government employee credit cards
> It's supposed to be slow an inefficient.

For creating new legislature. Because the relationship between the government and individuals is fundamentally that of force.

> It provides a lot of jobs to people who are otherwise unemployable.

I disagree. The purpose of the government is to secure individual liberties and provide national stability. ALL its programs must serve that strategic objective. Its purpose is not to provide handouts or employment; that is incidental. You don't want incompetent buffoons running the government anyway, or you'll get a bureaucratic inefficient mess.

> a lot of jobs and businesses are just not necessary

So what? There's nothing wrong with having people learn skills in the private sector. At least their relationship to the people around them isn't based on force like it is with the government. Who are you to proclaim what businesses and jobs are necessary anyway? If a business is successful, it must be serving someone, somewhere well enough for them to be paid anyway.

> when COVID hit something like 1/3rd of people either stop worked or worked massive reduced hours and the truth of the matter is the world kept spinning JUST FINE

A lot of people lost their jobs and livelihoods unnecessarily, because they were forced out by the new government regulations. Sure, they may have still lived, but I can promise you their quality of life has reduced. There was more unemployment. More people depended on government benefits provided by productive people still working, rather than depending on themselves and their own businesses. It takes a lot of mental gymnastics to make rhetoric that twists that into a good thing. It's only good if you want more and bigger government with more control, all at the taxpayers' expense.

codeguro··on DOGE puts $1 spending limit on government employee credit cards
I would like to see the IRS take my income when it's disbanded.

> a government is just a corporation with an army behind it

This is a bad analogy. A corporation, and a corporation that can use force, have completely different properties. Walmart cannot hold a gun to my head and force me to pay for illegal alien's hotels. They can only get by if they sell products worth buying, and in a free and fair market, they can flourish only based on merit. They must cut the fat and make better deals and better products if they want to grow. The government does not have the pressures of a free and fair market. If the government needs more money, they print it, or they take it from me. Both are a form of tax. They don't cut their own fat. They have no incentive. They only grow. I may get downvoted for this, but I think Elon is doing good work. He managed to get twitter running on about 20% of the employees and I think he can do the same with government. From my perspective, the only people who complain about this are those that want to see a perpetually growing central government who don't see the danger of having a centralized power encroaching and taxing every aspect of our lives, and those who are in on it themselves.

codeguro··on The FizzBuzz that did not get me the job
> The interviewers tried to tell him to approach it like an industrial-grade solution, not a weird academic exercise.

Wrong. They put in silly rules like "Max of 30 lines" and "Mutating array operations are forbidden". These do not describe industrial-grade rules. They describe an academic, esoteric challenge. And then when he provides them with it, they punish him for his creativity by adding in bullshit rules retroactively e.g. "Hardcoding matrices is forbidden."

You just sound upset that he's able to walk the walk but you WANT him to be just a bullshitter.

codeguro··on The FizzBuzz that did not get me the job
> I wish all the best to him, but reading between the lines is a useful skill regardless of this specific situation.

I disagree. This is not a fair ask, especially for a programming position. Programming and maths in particular puts a lot of emphasis on attention to detail.

If he can write it in X, and there's no rule against it, and the job gets done well, then there is no issue. Arguing any further of it is unproductive. He's applying for software development, not for public relations.

> "I don't think that will be a good idea" is not a suggestion, it's an order.

Then it should be a rule. "Reading between the lines" sounds like an excuse to me for bullshit criteria. It should be written, it should be explicit, and it should be known. If the interviewer is uncomfortable writing it down as a rule then that tells me they KNOW that it's too silly or pedantic. This whole idea of unwritten rules is a double standard designed to weed out neurodivergent or autistic individuals who are more than capable of fulfilling job requirements and, to me, seems like a potentially illegal form of discrimination that violates disability civil rights laws.

codeguro··on Bad Apple but it's 6,500 regexes that I search for in Vim
Either you can't distinguish bullet hell games from porn or you're projecting.
codeguro··on Bad Apple but it's 6,500 regexes that I search for in Vim
Touhou is just a bullet hell game, relax. Being this upset over it is more a reflection where your mind is at rather than everyone else's.
codeguro··on Bad Apple but it's 6,500 regexes that I search for in Vim
This is pretty cool! I like the creativity. The games this is based on are pretty good too. Danmaku are hypnotic
codeguro··on Visualizing quaternions (2018)
>It shouldn't need more than 3 variables But you do. Think about what it means to describe orientation. You need enough degrees of freedom.

When describing rotation of of a sphere projected onto a 2d plane, having two variables (X,Y) isn't enough. Because the sphere could rotate about the axis between the origin and that point. There's an an entire degree of freedom you could describe for a complete rotation about that axis.

In the same way, having 3 variables to describe a quaternion rotation is not enough. You again, have an entire degree of freedom you could rotate the quaternion about.

codeguro··on When an app asks for permissions, it should have a “feed fake data” option
Apple doesn't get to dictate what constitutes a good user experience. Especially for me - that is my prerogative and mine alone.

So yes, I will be extremely happy with it. This opens doors to all kinds of software that can compete with one another, and if I don't like it, I can simply uninstall it myself.

codeguro··on PGP signatures on PyPI: worse than useless
>Yes, which is just as worthless as the one you used

Wrong. One produces a valid signature, the other does not. I couldn't care less for your point of view - my interest align with my clients.

>No, there's no point. It is worthless whether it verifies or not.

An invalid signature indicates the message has been tampered with.

>they're all equally worthless unless there's a way for me to develop trust into one of them

Have you tried engaging with the parent post instead of talking past it? Attributing trust to some key an entirely orthogonal issue to the utility of a PKI protocol.

> In the situation you're providing here, there's no way for me to trust anyone, so your signature might as well not be there.

Sigh. First off, it tells you two things. (1) The message was signed by the holder of the private key if the signature is valid, and (2) the message has been tampered with if the signature is invalid. And you don't even need to trust the key to deduce these facts. Second, you still haven't forged that signature, so the fact that you're arguing past me instead of posting a valid & forged signature only proves my point. You can't do it.

codeguro··on PGP signatures on PyPI: worse than useless
>The guarantee is worthless, HN could generate a new key with the same "Anonymous" name

Actually, it's not. That new key is an entirely different identity, and if you're struggling making the distinction between its "name" and its "identity", I'd argue you're not the target audience for PGP in the first place. There are 45,000 John Smiths in the world. Are you going to also argue that the concept of identity is thwarted by this fact? No. I believe this argument is made in bad faith.

>and use it to sign whatever they wanted to sign, and modify your comment to post that. I have no way of finding out whether this already happened or not.

Have you tried checking the signature? (hint: it's invalid - HackerNews manipulates the whitespace). Verifying signatures is incredibly easy in GnuPG. Would you like me to walk you through it?

>In general posting GPG signed messages in forums is of dubious utility, unless you're a celebrity of some sort and have a key with a decent amount of signatures on it.

On the contrary, it's quite useful. Public key cryptopgraphy allows you to be absolutely certain that a messages with a valid signature were signed by the holder of the private key. You don't need to know who that person is, but you can be certain that he holds the corollary private key. Your argument seems to be conflating _that_ with an argument on the metadata e.g. the authenticity of the public key itself, and that's an entirely different discussion orthogonal to the _utility_ of PGP.

By the way, GPG is just an implementation of the OpenPGP protocol. There's more than one implementation (RNP, sequoia, and OpenPGP.js, to name some for instance).

>Even then, GPG makes path finding extremely inconvenient, so even though I'm very well connected on the PGP WoT, it'd take me a serious amount of work to verify a signature

So? I never said it was easy. At the end of the day, you'd have to trust someone. PGP allows you to trust your web of friends. TLS requires you to trust some certificate authority. You're not really making any case against PGP here. Moreover, it's net even close to the use-case I argued.

For a journalist trying to report his findings in an unfriendly country, PGP is an excellent choice. For a client to secure communications with his lawyer, PGP is an excellent choice. And I'm still waiting for you to forge that signature to prove me wrong.

codeguro··on PGP signatures on PyPI: worse than useless
-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA512

Its use is securing communications over an insecure channel. I can guarantee you that this message has not been tampered with in any way by HackerNews admins if the public key validates the signature of this message. If they have tried to tampered with it, the fact that they don't have the public key would demonstrate an invalid signature. So not only would you know if this message is really from me, you'd also know if it was tampered with.

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEE1fNGaYoJAL3MgB6BiFKu2r3sclYFAmRqepgACgkQiFKu2r3s clZ8YQgAkeR2l3eRGZdw0pKGYwO5H7ShqWeQrNK8O5lJVxUmQki+U43CJwlRmhrh iC8dPcSoiv+oXj6ziNxz4zgXnTNsb5OH2/lN7kMBEhsLjFNYMHxbaRfCWeznDrde uYzu0l5RqgTAL8fAxgIQ0smJuT9a8UDqzKmWO8N68nUG/L+aR0EfPb37MnTwXOk6 JGZFhKBEl4ZZ1Fq45YgGQNNX7jDerzxQG5Iu8pEZuVLi3g3d6CrgAEJhP865BjYX FPZ+IcalTkNH9x3IQ8E+QZXatu98mEPCOKLz0jbuJHAhH1TlKy0ya/vNVgVlstgj

9nl5ujnpkCsRn4iUZ+Iq+0vNOxkMbA==

=yisw

-----END PGP SIGNATURE-----

codeguro··on PGP signatures on PyPI: worse than useless
I disagree. As far as technicality goes, PGP is a pretty strong decentralized model. GnuPG is a pretty solid implementation of PGP.

Are they perfect? No. Do they merit this much criticism? Obviously not. This whole thing reads like an opinion piece criticizing implementation details and attributing it to the whole design. I did a spot check on the guy's authoritative sources and found them _extremely biased_, with one referring to an article disparaging DSA, who prefixes his technicals with "more important articles" arguing that white people somehow cannot experience racism even if they experienced racial prejudice. And they expect to be taken seriously? It's insanity.

But back to the technical aspect - _Of Course_ you should not use 1024-bi RSA or DSA keys. Of course you should choose prime numbers. If someone chooses to use a non-prime field you're going to have problems - that's not a problem with the PGP protocol or with RSA or DSA. If you're trusting public keys from complete strangers, _you're doing it wrong_. If you're not verifying that the fingerprint matches, _you're doing it wrong_.

For a journalist trying to report his findings in an unfriendly country to a secured third party, PGP is an excellent choice. For a client to secure communications with his lawyer, PGP is an excellent choice. And for anyone who would argue the contrary, I challenge them to forge a signature for the following identity. Go on, I dare you.

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQENBGRqTLABCADPc27v3wK4EhBAuoWn5GAVz15r/6osSf41eQ5W83dAmUp4IeIq bHLOvI44nVGiTUrawnpk1oHdOyZxthdo14KL0mplLTAWI0oYzcFClrhNOWa1cB5a K8ZYL0lwlM2YvhGQMaLzJKqEjO+JxLnqKIZeV9iYt9c16igvatVm37DP0NBVFF+V /58g3haNDjvQg4fPOvVIJ8SuIK1vPuTrb1ob2PLFBmHwwmzNGWfWHBBm6izxXZ85 ad56Rp/gca7j02qjnSE1X8S9s0OAJ6AAYRkWhtr/EUw3mjOjGSv32lFrsB7qvSu4 kEl/GY0PhcmnpSwi79vvva82fHZrvfKnbuoHABEBAAG0CUFub255bW91c4kBTgQT AQoAOBYhBNXzRmmKCQC9zIAegYhSrtq97HJWBQJkakywAhsDBQsJCAcCBhUKCQgL AgQWAgMBAh4BAheAAAoJEIhSrtq97HJWMUQIALwWlE1MyiL2vOjG3srY2m6gnE/p iDI9YzQECRr88R0CTSFOvGU8rFwwGNBavtMHfl9BJyJFVk82VK/mWCW7j37CJNu9 ObxqIuvZc35Op9G5LHlEFj/Hal4B3LqyIzm0Kb2IsY7HPMGNmLEQW8gw+PvkNJHr jaEF8eQ/vhboh+rxYn1COiAlBcxpHr3vvCtrsrlqhc1bPRb49ItJ5ybooDaLkl9T prHruCUzsCobYSiT7A85i6wwFvkICCIQZpPCR7cgVqyffjmjLlTPSWpu/+aCp1GP c6532MLqPGhEaFGrTWJzq9ApdQnbbNOt9kkMGCL1GLPGkPNQq0k2R0LNkmA= =A+3o

-----END PGP PUBLIC KEY BLOCK-----

Only I own this private key, and only I can sign with it. It's stored offline, secured and airgapped. It'd take more energy than there is on the planet to crack it. But I can easily prove I'm the owner. Trapdoor functions are a wonderful thing. If I were given your public key, and it _followed protocol_ and was a strong key, I'd be able secure communications to you in such a way _even I wouldn't be able to decrypt them_.

----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512

Go on, forge something. I'm waiting. -----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEE1fNGaYoJAL3MgB6BiFKu2r3sclYFAmRqTYgACgkQiFKu2r3s clYdUAf+IBIVIxZ1tSbNsKc/Cay0f6weJwUxmr59v7Q/UNzDUcn468Ei0CO9WSVi klMob9uxBrnB9nGYeHcYULUxGZxAwbooQU8XDrE4x4btvARUaRgP0x+ikw6XY/1t N60SeHG9BVxL0EULrlQpNAbbBEQVk59jcKHTHQg8yTcKujw0DiBlJnmQTW5UOaoq UMJRKDBRJAOsrRBDLO2JjWRuFB8dhcVRNv5gqqPg+YyIdcsd/XQyXObyIyHznoAl gjyu9R8hi2Y0vrpNW8mniapDXsm09hOzpaMZqkNSGDRQJVLYWaUMJMs7epwKnL4z x3Virwk8u9NDj4NqjUmzaw2wpvI5iQ== =f62G

-----END PGP SIGNATURE-----

codeguro··on Utah is first US state to limit teen social media access
> Wikipedia editors generally exhibit honest behaviour

Oh, shut up. Even the co-founder of wikipedia Larry Sanger no longer trusts wikipedia because its staff and biases are so far skewed to the left that he can no longer trust it. You are in a cult if you honestly think this kind of disingenuous editing is trustworthy.

https://m.youtube.com/watch?v=R_ygjNVFDMM

codeguro··on Utah is first US state to limit teen social media access
Parents, for their children’s best interests, have a prerogative to control what their children are exposed to. Social media is absolutely within that domain. I’m inclined to believe anyone who disagrees with that principle is a potential predator who seeks to undermine that authority. Sexual preferences are fundamentally sexual in nature, and parents absolutely have the prerogative to gatekeep the kinds of content their children are exposed to, especially sexual content. Children cannot (and should not be) expect(ed) to have any real form of privacy while under the care and supervision and oversight of their own parents. If parents see their children on internet chats they have a right to be involved and snoop on the logs and intervene to nip bad ideas in the bud. They have a prerogative in influencing the upbringing of their children in every aspect of their lives. Children simply cannot consent to life-changing decisions such as having sex, or sexual reassignment surgeries, or taking puberty-blocking hormones (aka sterilization drugs also given to convicted pedophiles). This includes intervening when strangers on the internet are grooming their sons / daughters to convince them they are gay or trans orcc by whatever.
codeguro··on Utah Gov. signs laws requiring parental consent for minors to use social media
Nice straw man, but I’m right here. Go see what I’m actually objecting to after reading my post a little more critically. Read the other post in this thread while you’re at it.
codeguro··on Book ban attempts reach “unparalleled” 20-year high in 2022
Amazing. I make a case for the legitimacy of authority of parents and your first reaction is a veiled attack on the nuclear family unit.

Please, go on. Tell us all just what you intend to do with those children.

codeguro··on Book ban attempts reach “unparalleled” 20-year high in 2022
> Just because a parent THINKS "being gay" is sexually suggestive doesn't mean that it IS.

But categorically, actually being gay is. By any dictionary, the word “gay”classifies a very specific sexual preference. Sexual preferences are fundamentally sexual in nature, and parents absolutely have the prerogative to gatekeep the kinds of content their children are exposed to, especially sexual content. I realize you might have your objections to this but it doesn’t make it any less true. The law is clear on this fact.

codeguro··on Utah Gov. signs laws requiring parental consent for minors to use social media
Predators go on social media sites to pass off as children in order to groom those children all the time. Don’t feign ignorance at the fact that age verification techniques helps site operators weed those weirdos out.
codeguro··on Utah Gov. signs laws requiring parental consent for minors to use social media
Anyone who’s looked critically at the studies of social media on teens, especially teenage girls, will observe how catastrophic its effects are on the mental health of the minors. It spikes anxiety, reduces confidence, and induces dopamine addiction, which hurts attention span and cognition. It’s a disaster, and I understand the intent of the bill on its face.

That said, I agree in principle that parents, for their children’s best interests, have a prerogative to control what their children are exposed to. Social media is absolutely within that domain. I’m inclined to believe anyone who disagrees with that principle is a potential predator who seeks to undermine that authority.

I do not think age verification with a government-issued ID is an effective way to do this. At least not as it is. There is undue risk exposing sensitive personal information. If the folks working in govt were more clever, they’d see that the verification would instead depend on some hash or digital signature and where the government would issue some certificate authority to mediate the legitimacy of the signatures. Zero-knowledge proofs are the answer here.

In all honesty though, I think the more appropriate solution is to simply have parents themselves (as opposed to governments) to moderate their children rather than control how content providers conduct their business. If their children cannot be trusted with a cellphone to keep away from tik-tok, then simply lock down their device or give their children a dumb phone. The margin of abuse and risk is far greater with a centralized power like the government. Governments turn corrupt all the time.

codeguro··on The Political Bias of ChatGPT – Extended Analysis
They deliberately ignore established scientific consensus with regards to the biological and physical differences between men and women. That’s why they say “men can get pregnant!” and insist that MtF transgenders should compete in women’s sports. They have eroded definitions of terms like “gender” which used to be synonymous with “sex” to push a narrative, and silenced physicians/pediatricians who (correctly) voice observations that the hormone-altering drugs given to children sterilizes them. Climate change is another issue. No democrat had ever been able to demonstrate in a manner which its falsehood could can be verified, the degree to which human activity contributes to climate change (e.g. is it 2%? 5%? 50%?). Even though there’s a large push to “go green” and tear down the foundation to our modern infrastructure and energies (coal, petroleum, and gas). Just now there’s been a large push to ban gas stoves as an element to “combat climate change” despite the insignificant contribution to the global-warming pie chart.

There’s a lot more, and there’s a lot that the republicans & democrats are both guilty of (e.g. the suppression of studies of cognitive abilities between the races e.g. the gaussian distributions of IQ, despite IQs being comparably reliable in predicting academic success, job performance, career potential and creativity). They like to say “race is skin deep”, while ignoring the fact that even children of mixed-race parents cannot accept a bone-marrow transplant from their own parents - it will be rejected. It literally goes further than bone deep. These are just a handful of observations anyone can verify for themselves.

codeguro··on The Odin – DIY genetic engineering
> Have you forgotten that the world is full of bad actors who are literally trying to eat people?

Your premise here is false. If X thing is bad, a number of other people doing it doesn’t make it OK. If anything, it makes it worse, not better. If all your friends jumped off the edge of a cliff to suicide, would you do it?

codeguro··on Voice.ai: GPL Violations with a Side of DRM
Section 5, paragraph (c):

c) You must license the entire work, as a whole, under this License to anyone who comes into possession of a copy. This License will therefore apply, along with any applicable section 7 additional terms, to the whole of the work, and all its parts, regardless of how they are packaged. This License gives no permission to license the work in any other way, but it does not invalidate such permission if you have separately received it.

See also, paragraph (b):

b) The work must carry prominent notices stating that it is released under this License and any conditions added under section 7. This requirement modifies the requirement in section 4 to "keep intact all notices".

codeguro··on Toward policy for open-source software as infrastructure
RMS cares quite a bit about it, as do I. You don’t talk for everybody.
codeguro··on Toward policy for open-source software as infrastructure
No, he’s right. The GPL has everything to do with freedom. Money and monetary aspects are entirely orthogonal to the GPL and the FSF as a whole. This is said by Stallman and the GNU projects itself. https://www.gnu.org/philosophy/selling.en.html
codeguro··on Toward policy for open-source software as infrastructure
YOU ARE WRONG ABOUT THIS. See: https://www.gnu.org/philosophy/selling.en.html
codeguro··on Windows 11: a spyware machine out of users' control
> you are why windows updates are now forced

This is blatantly, flat out wrong. Even the implicit premise here is wrong.

It is not Microsoft’s prerogative to update my device. They don’t own my device. They don’t get to decide when I decide to install new software. That right exclusively belongs to me. Even congress doesn’t get to have a say in this. Users have private property rights. And this, what Microsoft is doing, is bordering illegality.

codeguro··on Voice.ai: GPL Violations with a Side of DRM
Read the AGPL again. It has specific clauses that say that integration, not modification, of AGPL’d software applies it. Just using the AGPL’d software is the trigger.
codeguro··on Voice.ai: GPL Violations with a Side of DRM
> but much harder to give away the source code

On the contrary, it’s actually quite easy. They can simply upload the repository on github’s or simply tar snapshots of the source for their releases and host it themselves.

No, the issue is not that it’s hard. It’s that they don’t want to comply with copyright law. That’s an issue of criminality, not difficulty.

codeguro··on Voice.ai: GPL Violations with a Side of DRM
> This approach is what drives corporations to adopt zero-GPL policies.

Good! That’s precisely the whole point of the GPL. That is: to prevent proprietary code, which harms users, from being mixed with Free Software! Proprietary software is harmful to the users. OpenAI is malware, it has cryptominers in it. It also sets off antivirus scanners. Now we’ll get to see if their claims are true by looking at the code for ourselves

← PreviousPage 2 of 4Next →