HNHacker News
TopNewBestAskShowJobs

creatonez

3,282 karma · joined June 2, 2016

submissionscomments
creatonez··on Virus Stole a Human Gene and Won't Let Go of It
The NYT subscriber links recently changed, it now requires making a free account to use the link.

But to be clear, the rule is against unofficial mirroring. Officially sanctioned methods are fine.

creatonez··on Virus Stole a Human Gene and Won't Let Go of It
IIRC the staff will usually intentionally elevate bypass links to the top whenever they see them posted in the comments. (And when a link has already been posted they tend to sink comments like yours that complain without providing a link, lol)
creatonez··on Virus Stole a Human Gene and Won't Let Go of It
The HN rules are that paywalled content can be posted only if it's trivially bypassable via a free tool. The NYTimes links work on fresh IP addresses as part of a free allowance for new readers, which is why the proxy-based archive website archive.today is able to get through. I'm not a big fan of this being allowed, but there is some thought to it at least, they aren't just allowing anything.
creatonez··on Updated Google Maps shows destruction of the city of Rafah
Genocide doesn't actually work as a tactic, especially in an urban setting. It strengthens the victim's resolve. The Palestinian people are not known for giving up on survival.
creatonez··on Updated Google Maps shows destruction of the city of Rafah
They don't, that's the point. All of the street view footage is from before the start of the current genocide. Gaza is under one of the most complete internet and media blackouts on earth, even the roaming international sim card loophole has been closed.
creatonez··on Cf: The Agentic CLI for the Cloudflare API
Is this a joke? Why would you want to use a random word generator on production infrastructure configuration? Cloudflare should be blocking these malicious/incompetent users, not enabling them.
creatonez··on When did Google get so weird?
All of this culture is gone except for Google Doodles. Sterilized to the bone.
creatonez··on When did Google get so weird?
The people writing suicide hotline PSAs aren't hopped up on the most idiotic internet mental health pop-science nonsense, and are not based on a random number generator.
creatonez··on When did Google get so weird?
Ah. So Google cancelled April fools to make every day a big joke?
creatonez··on When did Google get so weird?
I absolutely hate this so much. I type "define" because I'm looking for a dictionary definition. Dictionary authors provide a careful consideration to the fluidity of language, and they write dictionaries in the format they do for a reason. The AI overview comes from web retrieval, which sources definitions from random idiots on the internet. These random idiots will just repeat what I already thought the word meant, offer up a common misconception or etymological fallacy, or give the 'annoying grammar nazi' take.
creatonez··on Self-Hosting on the Dark Web
Exit node are an entirely optional part of the Tor network. If you run a relay or a hidden service you are not forced to participate in the exit node side of things. It's also not recommended to combine these roles because it could have security implications for your hidden service.
creatonez··on PipePipe: NewPipe hard fork implementing SponsorBlock
Just a heads up, this includes support for Return YouTube Dislike, which tells a third party service what videos you click on and has no measures to ensure anonymity like SponsorBlock does. The option for disabling it doesn't seem to do anything.
creatonez··on Pentium II at 600Mhz with Voodoo 3 Emulated on 86Box with M6 Mac Mini
Are we sure that's true for Crysis
creatonez··on Show HN: Avoid smooth spinners, use low-FPS spinners
> [1]: https://en.wikipedia.org/wiki/Spinner_(computing)

Hah, I did not expect that. I can't imagine any end users will be able to name that one.

creatonez··on F-Droid 2.0
They're not necessarily wrong about it being scam resistant, based on some of the research into the psychology of scams. Adding time defuses the urgency of phone scams, leaving plenty of time to seek a second opinion from family members or the internet, and forcing the scammer to re-explain what the original goal was. It's too much time to breathe and defuses the fight or flight reaction needed for a high success rate. You mention URLs, but a web browser based scam page doesn't accomplish much, because the scammer's goal with fake apps is to acquire persistent remote access (akin to how the AnyDesk Android app uses accessibility permissions for Teamviewer-like remote access to an entire phone).

But yeah, it's hilarious that they're pushing this so hard when the Google Play Store still has so much malware.

creatonez··on F-Droid 2.0
IIRC, it's the button to permanently activate it that is only available for one hour. Once you do manage to press it, you've permanently enabled it. If you miss the window, you have to start the 24 hours again.
creatonez··on Show HN: Air-gapped file encryption as self-decrypting HTML page
ZIP encryption is quite flawed.

That being said, I can see this being useful for a similar use case where encrypted ZIPs are useful. When malware testing, you sometimes want to avoid accidentally running the malware or exposing it to antivirus software until briefly before testing begins. Encrypted zips (as well as simple transformations like ROT13 or reversing the bytes in the file) can help control the moment the malware is unleashed. This HTML based tool could be useful for doing this in network sandboxed systems, with the specific property that it's testing the antivirus behavior when the file is marked as browser downloaded.

creatonez··on 'That's so AI ' What gen Alpha's biggest insult tells us
This FAQ is hilarious. I guess the default assumption is that if kids say something they don't actually mean it or know what it means. But no, they do. Often they are just using language in a more advanced generalized way than you, rather than being confined to distinct boxes. Children's brains are language factories.
creatonez··on Why is the liver so weirdly regenerative?
Selfish gene theory is discredited as reductionist and mostly wrong. You can't ignore the whole organism.
creatonez··on F-Droid 2.0
It seems google is going to allow an "advanced flow" that is scam resistant by requiring the user to wait 24 hours before they can start installing their own apps. It sucks, but assuming they don't change the plan again, F-Droid should be able to continue working.
creatonez··on What to do when your Waymo holds up a Secret Service motorcade
> “I need this vehicle to be out of here NOW, or it will be crushed,”

Sounds like the proper response is "my car has been disobeying me for the past 30 minutes, so crushed is fine" and then get out

creatonez··on AMD's random number generator can't generate a 0?
> CryptoJS / Ill Bloom (2026)

This is the one I'm referring to, it used some very dumb `Math.random()`-with-unverified-incantations code that should have been obvious if anyone had just looked at it. This one is responsible for the majority of hackable bitcoin addresses. It's really embarrassing that this kept going until 2020.

(At one point this would have been a tricky situation, though, because around 2009-2013 when bitcoin wallets were first being generated in web browsers, Internet Explorer didn't provide a CSPRNG API. Because of the prevalence of IE, an in-javascript CSPRNG would have been justified as a fallback if it had proper cryptographic mixing of mouse input entropy and perhaps timing execution jitter entropy as well, along with good entropy estimation to decide when enough seeding has been performed to start generating keys. Some wallet websites actually did mouse entropy collection at the time (e.g. https://www.bitaddress.org), but often with dubious mixing. Might have been best to just ban Internet Explorer.)

> Libbitcoin / Milk Sad (2023)

Mersenne twister... likewise should have been identified as not even remotely correct. Not a serious CSPRNG at all. Similar to the CryptoJS case.

> Trust Wallet Browser Extension (2023)

Also Mersenne twister, similar to the CryptoJS case.

> Trust Wallet iOS / Trezor Library

Time-based seeding, with an exceptionally weak PRNG with only 32 bits of state. Similar to the CryptoJS case.

> Android SecureRandom (2013)

This is a buffer bug that caused existing seed data to be overwritten by newer data rather than correctly appending it. The serious cryptographic primitives weren't broken, just the input. But it is genuinely scary. Unlike the other examples, it wasn't immediately identifiable because it gave the appearance that a CSPRNG was being implemented, and being a platform API it is just as scary as the Debian bug in 2008.

creatonez··on AMD's random number generator can't generate a 0?
> Because, in the applied world, upstream bugs in "secure" system RNGs have been the cause of stolen crypto [...]

You mean javascript libraries that do a bit of Math.random() and a miniscule amount of mixing, that had been widely considered poor practice for years while old bitcoin wallet generator websites were burning users with it?

Has any actual serious CSPRNG exposed bitcoin wallets?

creatonez··on AMD's random number generator can't generate a 0?
Refusing the platform's CSPRNG for such nonsense reasons is perhaps the dumbest form of POSIX worship. This is obviously an area where platform feature detection makes sense, there's no reason to follow a religion of standards adherence when it directly leads you into harm's way
creatonez··on PDF Forgeries Are Surprisingly Rare (2022)
> (Or better yet: upload it directly to Libgen/Sci-Hub and let everyone else redistribute it.)

Can this actually be done without an ISBN or DOI number?

creatonez··on OpenAI agents carried out an undisclosed attack on RubyGems
The AI didn't plug in an ethernet cable into itself
creatonez··on Fedora 45 beta drags the Linux console into the 21st century
It does, and much more. It's basically a "what if we actually cared about fully text mode computing" project. It even has stuff like optional GPU acceleration (which a lot of people scoff at, but is very much necessary for very high screen resolutions combined with TUIs), mouse support, and multiseat configurations.
creatonez··on OpenAI agents carried out an undisclosed attack on RubyGems
You shouldn't be allowed to have an internet connection if you're going to use it for unsandboxed agent slop with no access controls or human confirmation. This has nothing to do with hypothetical future AGI. It's the same type of idiocy as pressing a bunch of random buttons on a chemical factory control panel and then thinking you won't be criminally charged for it because the equipment caused the problem.

If you actually have a serious use case that needs 24/7 unmonitored agents, you can assemble all of the data the agents need locally and avoid these insanely obvious and well documented risks associated of running a random word generator with the ability to HTTP POST.

(And just in general, please stop subjecting the rest of the world to any automated actions that cannot be reversed by a human override. Same goes for cloud services subjecting users to quick non-appealable bans based on faulty automated detections. Or the current rollout of predictive policing technologies across the world. Or the automated bomb targeting in the ongoing Gaza genocide. )

In my view, proliferation of highly automated technology is not the concern, but rather its diffusion into human systems without thought put into whether it even meets our requirements for basic ethics, domain-specific correctness, and ways to mitigate a fuckup when it does happen. In this case, the detrimental diffusion into human systems was only allowed because someone made a decision (no access controls on the bot) that we can already easily characterize as a mistake that will need to be both mitigated (via a massive upgrade in cyber defense, especially with the help of AI fuzz testing but also more stringent compilers/linters/formal verifiers) and prevented from happening in legitimate regulations-abiding organizations in the first place. This kind of stuff will be slowed down at some point as we learn from hard mistakes, but the current craze is getting quite stupid.

creatonez··on Haiku R1/beta6 has been released
> Focusrite Scarlett

If it's the one I'm thinking of, this device includes a read-only ~100KiB USB mass storage device filled with .lnk files to remind you to register the device to get your bundled digital goods (a bunch of DAW plugins).

You might want to try connecting the interface with Windows and install the focusrite driver. This will set the device to a "pro audio" mode, unlock the higher sample rates, and permanently make it stop behaving as a mass storage device. Not sure if this fixes Haiku OS USB audio compatibility, but it's a good bet and helps avoid the annoying mass storage device volume.

If you don't have a Windows machine to do this on, you can do it in a libvirt or qemu virtual machine on Linux using USB host device passthrough. Once you do it, it doesn't have to be done again, I'm guessing they implemented this with an eFuse.

creatonez··on Xwayland 26.1.0 rc1
> EGLStream support is removed

Wait, does this mean Nvidia won't have GPU acceleration for apps under XWayland anymore? Or is EGLStream not what I think it is?

Page 1 of 34Next →