HNHacker News
TopNewBestAskShowJobs

cowsup

953 karma · joined July 30, 2021

submissionscomments
cowsup··on .name Termination
The idea is:

* .name is open for everybody

* a company called "Global Name Registry" scooped up a BUNCH of common last names, including fraser.name

* Global Name Registry then sold access to neil.fraser.name for far cheaper than the fraser.name domain would cost on its own; someone else could also buy john.fraser.name or jane.fraser.name, so the single fraser.name domain that they owned could have dozens of customers associated to it. They worked with ICANN to allow each domain to have its own registered owner.

* The article in the OP bought neil.fraser.name and has used it for years

* Verisign bought Global Name Registry; later they realized, hey, we're sorta not making a lot of money on this idea, and we're spending a lot of time/resources maintaining these domains "for cheap" and chasing renewals, and not scooping up more customers. Let's just stop it and stop paying for fraser.name and the potentially hundreds of other domains we own.

* Neil Fraser, not the only Fraser in the world, is upset because he might lose the domain he's had forever

So one CAN buy the mwai.name domain, as you have, and continue using vpn.mwai.name just fine. It's just you can't "officially" start selling out these subdomains as a separate registrar entry.

cowsup··on Climate change is strengthening El Niño, coral records suggest
The very first graph you cited shows that we've had such a low number of natural disasters in the 21st century outside of Earthquakes, and now we're starting to tick back up with non-Earthquake deaths.

You would think, with all of the advancements in medicine, technology, and infrastructure, we'd be continuing to see improvements. Instead, it's ticking back up. Why do you think that is?

cowsup··on Web Browsers on Video Game Consoles
I remember poking around at the Wii U browser. Nintendo had examples of fetching the current state of buttons, analog sticks, and the touch screen to monitor for input.

While cool on paper, there wasn't a preventDefault() solution. So you could make a simple game where a sprite could move around and respond to "A," but if you press B, the browser would try to go Back a page. As the article mentions, the shoulder buttons activated a Gyro-based scroll mode (which wasn't great). "B" would go Back a page, Y would close/open the "curtain" on the TV, X would open the URL bar (thus showing the software keyboard and taking over all inputs), and Start/Select also did something, although I've since forgotten what.

So, although all button inputs were present, almost all of them also did something on the browser level, so nothing exciting ever came of it.

cowsup··on Spotify adds 'Verified' badges to distinguish human artists from AI
I think there's a difference between music that people will cherish for decades to come, and music that will sell in the short-term. This isn't even me being an "old man yelling at cloud," you can look at what was charting in the 80s-90s and recognize some songs, but others just got lost to time. They were fine, but they weren't special.

AI music will fill the gap. The "song of the summer," the latest TikTok trend, and music that plays for department store ads, will be produced and distributed by labels, without the need of a particular artist whose image they have to worry about. How many times have labels, who invested a lot of time and money into artists, had to deal with the artist having an episode or scandal? AI eliminates that risk.

I think trying to avoid AI music will be like trying to avoid auto-tune, or digital instruments, or people mixing tracks in ways that are impossible to replicate with real-world instruments in real-time. It'll be common at first, harder later, and impossible/silly in the future.

cowsup··on Grok 4.3
I don't think Twitter/X know for sure who the bots are, since Elon has been pretty vocal about trying to stop them for ages, yet I still get lots of spam DMs (as do others with far fewer followers/reach).

Even if 95% of the spam gets actively reported and dealt with, that still leaves a ton of nonsense on the platform, getting fed into the LLM. And spam has only gotten worse over the years, as the barrier to entry has lowered and lowered.

cowsup··on Vercel April 2026 security incident
> Still no email blast from Vercel alerting users, which is concerning.

On the one hand, I get that it's a Sunday, and the CEO can't just write a mass email without approval from legal or other comms teams.

But on the other hand... It's Sunday. Unless you're tuned-in to social media over the weekend, your main provider could be undergoing a meltdown while you are completely unaware. Many higher-up folks check company email over the weekend, but if they're traveling or relaxing, social media might be the furthest thing from their mind. It really bites that this is the only way to get critical information.

cowsup··on Intelligence being available on tap has killed the expert
Such has been the case with many technological advancements. You can change the date on this to 1999 and complain that the Internet has accomplished this; suddenly everyone can get information on car repairs, recipes, and the like, without needing to do lots of research ahead of time or take a course, thus killing the need for a mechanic or a bakery.

Outside of software development, a lot of things that AI can do still require a human to understand and do it. I can't tell Claude to change my oil, or ChatGPT to bake me a cake. I can use them as tools to teach me what to do, same as the Internet, or TV programs, or books, or any other "invention."

cowsup··on Discourse Is Not Going Closed Source
Great piece. I thought the same of Cal's announcement; it basically boiled down to "we're willing to shift our entire business to a security-through-obscurity approach." It won't be long until systems are sophisticated enough that they can target an application over the course of a weekend, and try thousands of exploits across each possible endpoint you offer, to see what happens, regardless of whether or not your source code is public.

Anyone who's launched anything on the web -- anything at all -- and looked at the logs will see all sorts of endpoints being requested for /wp-admin/ or random WordPress plugins, even if their site has never, and will never, run WordPress. Imagine this at scale, with every possible attack method imaginable, blindly hitting everything on the web. That's where I think we're headed, and closed source won't fix that.

cowsup··on Cloudflare confirms downtime on August 23rd, silently posts it on status page
I was experiencing something similar over the weekend. Just happened to see this post. Lots of hours spent digging over the weekend!!!
cowsup··on Someone at YouTube needs glasses
I think it also helps them figure out which videos keep people on YouTube longer. If I scroll to a section of the page that has 6 videos, and I stare at them for 10 seconds, then scroll down, they'll know that one or two of those videos must have been somewhat interesting. But if I stare at 6 videos, then scroll away 2 seconds later, it knows that nothing in that batch was worthwhile.

The fewer videos they have in focus at a time, the more accurate their algorithms can be.

cowsup··on Ask HN: Is the freemium model the future for AI-platforms?
Advertisements have helped finance the web for decades. AI could be no different.

What type of advertisers would want to advertise next to an AI chat window? How often would ads show? Would the users still enjoy using the platform if you showed enough ads to offset the cost of running the service?

Lot of questions that all boil down to "it depends." None of the big players want to dilute their product with ads (yet). But I definitely think some will be willing.

cowsup··on Devin is now generally available
Good software can be art. And like all art, we have hit the stage in which code can also be cranked out en masse, thoughtlessly, for a quick buck. It was only inevitable.
cowsup··on A few thoughts on domain verification for social media
The lack of domain re-verification seems important. The other things listed are the case for any social media platform, but they bear repeating.

I hope domain re-verification is fairly automatic once implemented. If I remove my Bluesky information from my DNS, it should be a safe assumption that the affiliated account will soon lose its username, maybe within a week or two. Same if I'm buying a domain; I wouldn't want lingering accounts for months or years after the fact. If it's a more manual process, that could be annoying, especially since you can also use subdomains -- someone could be "admin.example.com" and fly under the radar when selling example.com.

cowsup··on Researchers spot black hole feeding at 40x its theoretical limit
I find such thoughts exciting. In the future, children will be taught basic facts that, to us in the first half of the 21st century, are some of the most complicated questions of the universe.
cowsup··on Bluesky's at Protocol: Pros and Cons for Developers
> how does bluesky solve the problem of building your castle in another man's kingdom?

Bluesky (the platform) doesn't, and they acknowledge that. It's centrally owned, and is prone to all of the risks that any other centralized platform offers.

> if I do something controversial or using regulatory arbitrage, I'm interested in how AT is useful for managing that risk.

AT is completely decentralized, like email.

If your account is @motohagiography.example.com, other AT instances will make a DNS query to example.com to see if that has an entry that the AT protocol recognizes. If so, it will make a connection to that instance, and gather your content for display.

However, if a particular instance sees their a volume of unwanted accounts from example.com, they could blacklist that domain from interacting with their instance, so, even with this setup, you are at the mercy of the "big players" respecting you — just like if you try to send email to users using Gmail and Google decides you're suspect.

And, if you violate the laws of where you're located, law enforcement will handle that the same as they would if you violating the laws over HTTP or over email.

cowsup··on Ask HN: Is there a way to ensure one-person-one-account at all?
Nope. Almost everybody has more than one device (laptop, phone, and maybe a tablet) with more than one IP (both home wifi and phone data). Everyone has multiple email addresses.

You could get by with requiring a unique phone number, but that still risks excluding users, and can get expensive if you intend on catering to an international audience. Even in that case, some people may have a landline and a cell phone, or they may use a friend/spouse/relative’s phone to circumvent your limits.

cowsup··on Show HN: A quiz to see if you can tell real vs. deepfake videos
Fun! I played this without sound, and got all of them correct.

I think part of the problem is that I knew that some videos were fake, so I was looking to see if their lips matched other movements. If somebody is talking fast, but their body language/movements are far slower than their talking, then it’s a pretty obvious tell.

If I had just seen one of these videos out in the wild, I can’t say if I’d immediately notice they’re fake, since that wouldn’t be the first thing on my mind. I think it’s probably impossible to get an accurate test given this limitation, but this test would be good for more casual people to try (i.e., people outside of HN).

cowsup··on Ask HN: Does My Company Think I'm a Cybersecurity Risk?
Given what you wrote, it's hard to tell one way or another what they think about you personally. Was the code stored on your personal device, or a company-issued one? If it's company-issued, it's probably nothing to worry about, since, if they were to terminate you, they could immediately restrict your access to the codebase.

I view it vastly more likely that this isn't anything personal, it's just a new corporate decision to limit who has access to the code. If someone's job is a bit more complicated, but they can still do their work, while the company is far more protected, that is a good trade-off for lots of folks.

Also, your company "looking to reduce expenses" doesn't mean anything. Every company is. You will hear that, in some form or another, in almost any organization. If they have to increase spend for cybersecurity, they will.

cowsup··on How I quit social media – Without missing out on anything
> I run YouTube revanced not even for the Adblock but just to remove shorts. [...] I might feel differently about this one day and turn off the algorithm completely on YouTube, but I have not done so yet.

Turn off your YouTube history/algorithm. It’s free, and it immediately prevents the Shorts tab from working, and kills your homepage. This means you have to actively subscribe to YouTube channels you enjoy, or search for topics you want to know about in that moment. I cannot recommend it enough.

cowsup··on I hate Stripe, so I'm going to build my own payment processor
They seem against any nay-sayers, so I’ll respect that and bite my tongue.

The silver lining is that, their idea (which they later reveal that they “forgot to mention” will also include full banking support and the issuance of cards) is very complicated and will require years of non-stop planning and paperwork before a single customer can be onboarded.

This isn’t handing your friend the keys to a jet and letting them fly a plane, this is your friend wanting to enroll in pilot school. It’s good to try, and, if you realize it’s not for you, there’s nobody harmed as a result.

cowsup··on Brazilian court orders suspension of X
The core facts are: Brazil demanded information regarding Brazilian users, and believed it was in their right to do so. X believed that the requests did not comply with Brazilian laws, and refused. Neither side yielded, so X closed up shop in Brazil, and, as a result, Brazil is blocking access to X.
cowsup··on Ask HN: How to Avoid Microplastics/PFAS
There are many small things you can do right now — avoid buying food or drink that is in plastic, avoid storing leftovers in plastic, avoid plastic cutlery and plates. Never heat up food in the aforementioned plastic.

But the 80% number may be hard to reach, depending on what your current intake is. And since there’s no real way to measure what your intake is, and how low you get, it’ll be much harder.

Moving to a farm won’t necessarily help. You still need to buy things to run a farm, many of which are packaged in plastic. You still need clothes. There will always be some element of risk involved.

cowsup··on .INTERNAL is now reserved for private-use applications
.com is not a full word either (company), or .org (organization), .net (internet), .gov (government), ...
cowsup··on Susan Wojcicki has died
I feel like there's an unwritten "recently" in there. If you were to speak ill of Colonel Sanders, nobody would berate you for speaking ill of the dead. But when a CEO like Wojcicki, who made changes that were unpopular to the end-users (but helped turn YouTube into an actual profitable company) dies, it's considered very impolite to use that opportunity to bad-mouth decisions she made. When her son died earlier this year, that would've been a bad time to speak ill of her, as well, even though she herself was still alive.

A better phrase may be "Don't say things that will hurt the feelings of those who are grieving," but that doesn't roll off the tongue so easily.

cowsup··on Third Party Cookies Must Be Removed from the Web Platform
To explain CHIPS very simply: In the Internet of yore, if you loaded example.com and it had facebook.com embedded, then facebook.com would be able to access all of the facebook.com cookies. This is fine on paper, but Facebook encouraged well-meaning website owners to add a "Share" button to encourage organic sharing of their website. When users loaded a page with this button, that embed would get access to all of the facebook.com cookies, thus being able to know who you are, and the site you were visiting from. They'd record this and use it for advertisements.

With CHIPS, you can login to Facebook.com and your cookies are stored in the "cookie jar" labelled "facebook.com." Then, when you go to example.com, the "cookie jar" that the Facebook embed can use is "example.com->facebook.com." This means that Facebook cannot use cookies to track you across every website.

Unlike outright blocking cookies, however, CHIPS still allow well-behaved embeds to function. This allows customer service chatrooms to retain history, videos to remember where you last stopped, and so forth, even on subsequent refreshes, since they can read and write to their own "example.com->[embedded site domain]" cookie jar.

This compromise perfectly breaks cross-site tracking, while allowing useful third-party embeds to still operate.

cowsup··on Ask HN: What do you advise people who want to 'start a career in AI'?
I’d give the same advice to someone wanting to start a career in web design, mobile app development, or video editing — it’s like any other software-focused field.

First, find a problem that you personally encounter that could be solved, and solve it. Don’t worry about marketing, profits, companies, any of that; just do it for yourself. Learn what works, what doesn’t work, and get it done. Then do it again with a more complicated problem. Rinse and repeat, many times over.

Then from there, you’ll know a lot of the ropes, and you can either release your own software, or join a company that’s looking for someone with your talents — or both.

cowsup··on A Markdown Lorem Ipsum API
Definitely convenient, but I question the need for an ever-changing API for this sort of thing. If you reload the endpoint (which can be done directly in the browser, which I like) the order of the markdown and paragraphs change. So, if I'm testing this when developing, and I want to find the perfect numbered bullet points, I have to scroll around and find them again, each time the API is hit.

It could be argued that I could build something on my own that grabs the result and caches it to make refreshing less jarring, but at that point, why bother with an API at all?

cowsup··on The Death of the Dining Room
I’m surprised they didn’t touch on the Internet as a factor. Before, dinner parties were the best way for friends to catch up and talk, and fill one another in on their lives. Everybody would gather around for hours, and talk about new things going on in their careers, their children, other friends, news, sports, you name it.

Nowadays, you can just hop onto your group chat(s) and fill everyone in on these things in real time. So, the dinner party became less of a necessity for social interaction; and the actual dinner itself was never the point. With less of a need to hang around for hours on end to catch up, it’s become more efficient to just go to a restaurant, spend an hour or so, and then leave. Nobody is left to clean up, or spend half the day preparing meals.

cowsup··on Posthumous Letters: Could They Uncover Truths in Cases Like Madeleine McCann?
Based on what the homepage says, it seems you're handling this by allowing the recipient to get the decryption keys right away, and then also your system will handle the 3-day period. Is that correct?

If so, your entire promise about it being inaccessible to law enforcement falls apart. Law enforcement will demand the encrypted data, and then the person who received the message will likely hand over the decryption key, and that's all they need. Something to keep in mind when making these promises to customers.

I think you should also lean way more into the "final farewell" aspect of it — not necessarily a love letter, but a nice "Goodbye, everybody" message, and focus on how a platform like this can be useful to send personal information, like passwords, to recipients who may need them after you're gone. Everybody is going to die, so you have a huge market, here.

In contrast, focusing on "this is great for serial killers" is very grim, and I don't think any serial killer is going to want to hand over their credit card information and associate that to correspondence they send to the victim of the family. It's also a bit tasteless to use an active missing person case (Madeleine McCann) when promoting your project to potential other criminals.

cowsup··on The accidental tyranny of user interfaces
Some of these UI decisions are more technical versus tyrannical. I use Linux every day, yet I can understand why Google doesn’t have such detailed progress reports: If you are using Google Docs, and you want to convert a file to Google Sheets, that likely requires several different microservices working in tandem to handle your request.

For them to build out a real-time feed that tells you the progress would perhaps require a complete change in how these microservices behave (so they can all feed real-time, ongoing data to the client), and not provide any real benefit. The only time I really pay attention to my Linux boot sequence is if something is stuck or an error appears, so I can handle it. Seeing what Google Sheets is doing may be “neat,” but I completely understand why that’s not a good reason to build it out, and it wouldn’t make anyone outside of Google employees more productive.

Page 1 of 6Next →