HNHacker News
TopNewBestAskShowJobs

csmantle

967 karma · joined February 6, 2025

a random guy.

me plus hn-reply at csmantle dot top

[ my public key: https://keybase.io/csharpermantle; my proof: https://keybase.io/csharpermantle/sigs/yY8_8cVL2gNkK1GB4SKuo0EEcsWPP6vUBAejHBNdWxA ]

submissionscomments
csmantle··on JavaScript engines zoo – Compare every JavaScript engine
What surprises me is that under the "Show variants" checkbox, SpiderMonkey 24 from 2013 outperforms 147alpha by ~2000 pts -- almost 10% --, while having 1/4 LOC, 1/3 binary size and almost 1:1 on other metrics. (SM 24 targets ES5, however)
csmantle··on JETSTREAM: A Jeffrey Epstein exploration tool
The apronym "JETSTREAM" stands for "a Jeffrey Epstein Timeline Search, Tracking, Relationship Exploration and Analysis, and Mapping tool".
csmantle··on Debian adds LoongArch as officially supported architecture
There seems to be a community-run site about this:

https://loongfans.cn/en/pages/intro.html#i-m-sold-where-can-...

csmantle··on Show HN: Picknplace.js, an alternative to drag-and-drop
This actually caused a constant switching of attention on mobile. Each time an element is picked up I'll have to look at the bottom toolbar, then the floating element in the center, then back to the bottom to place it, so on and so forth. And the list in the demo is not that long yet.

------

Will this work on lists that sre short? It seems that it relies on overflow to move the element

csmantle··on Richard Stallman on ChatGPT
> GNU grep also generates output ”with indifference to the truth”.

GNU grep respects user arguments and input files to the dot. It is not probabilistic.

csmantle··on The C++ standard for the F-35 Fighter Jet [video]
"AI" comes in various flavors. It could be a expert system, a decision forest, a CNN, a Transformer, etc. In most inference scenarios the model is fixed, the input/output shapes are pre-defined and actions are prescribed. So it's not that dynamic after all.
csmantle··on Stop Hacklore – An Open Letter
CVEs are better viewed as "a uniform numbering system that ensures we are talking about the same bug" today. But updating software is good anyway.

> Browsers are designed to be secure from default settings.

Not quite. They are usually designed to be both fast and safe, but neither goal is considered "done" yet in modern ones. If you want max security, you'll likely have to disable all performance boosts like JS JIT.

csmantle··on Stopping bad guys from using my open source project (feedback wanted)
This seems to pass a transitive requirement to users.

Suppose your libpopular forbids ill-faith actors from using it. Also suppose that I wrote a my-utility, a neutral tool, that depends on libpopular. If some bad actor uses my-utility for wrongdoing, will I be responsible for their behavior? Will my-utility be in breach of your license?

csmantle··on I don't care how well your "AI" works
> programmers should be some of the most worry-free individuals on this planet, the job is easy, well-paid, not a lot of health drawbacks if you have a proper setup and relatively easy to find a new job when you need it

Not in where I live though. Competition is fierce, both in industry and academia, for most posts being saturated and most employees face "HR optimization" in their late 30s. Not to mention working over time, and its physical consequences.

csmantle··on Tabloid: The Clickbait Headline Programming Language
This would benefit from combining the literal rules from TrumpScript [0]:

> All numbers must be strictly greater than 1 million. The small stuff is inconsequential to us.

[0]: https://github.com/samshadwell/TrumpScript

csmantle··on A prvalue is not a temporary
This will soon gets cumbersome if we're trying to construct some large struct literals (rather than arrays) directly on heap. Rust should be able to elide the unnecessary stack allocation here.
csmantle··on Magika 1.0: now faster, smarter, and rebuilt in Rust
From the paper [0], they're using a specialized model structure, so at least they are not part of the LLM hype. That's good. But I still wonder how this compares to existing rule- and manual heuristics-based approaches like github/linguist.

[0]: https://securityresearch.google/magika/2025_icse_magika.pdf

csmantle··on Show HN: I built an 8-bit CPU simulator in Python from scratch
This is a single-cycle, architecture-level simulator with no microarch details or "complex" features (privileged infra, mapped memory, etc). But it is a good starting demo.

BTW, why invent Yet-Another-Toy-Arch(tm)? If a more established architecture is used, existing toolchains can be utilized to produce images for running. Many popular RISC ISAs have "simplified" editions which are void of many complex features, so they hardly need more efforts to implement with respect to this one.

csmantle··on Element: setHTML() method
I think innerText and setHTML() have different purposes. The former inserts the whole string as a text leaf, while the latter tries to preserve structures that are meaningful in context.

---

Libraries can surely do the same job, but then the exact behavior would vary among a sea of those libs. Having specs defined [0] for such an interface would hopefully iron out much of these variations, as well as enabling some performance gains.

[0]: https://wicg.github.io/sanitizer-api/#dom-element-sethtml

csmantle··on Cryptographic Issues in Cloudflare's Circl FourQ Implementation (CVE-2025-8556)
User-supplied EC point validation is one of the most basic yet crucial steps in a sound implementation. I wonder why no one (and no tests) at CloudFlare caught these carelessnesses pre-signoff and pre-release.
csmantle··on Getting syntax highlighting wrong
Nowadays "syntax highlighting" acutally means "syntax colorization" more. It's purpose is not just to mark specific tokens/lexemes/phrases (as in compiler principles), but to differentiate between them. Making something "stand out" is no longer the goal No.1. Human minds are not automata, so colorization actually helps a lot in parsing and preprocessing the text beforehand.
csmantle··on I am a programmer, not a rubber-stamp that approves Copilot generated code
This is almost inevitable when something industrializes; people maximize profit by quickly shipping things that barely works. We need someone who try to excel in technology, and AI just amplifies this need.
csmantle··on A quiet change to RSA
The undergrad lectures I took placed almost equal emphasis on crypto over Zp and crypto over EC. For most students without deep abstract algebra backgrounds, introduction to operations and principles are more friendly and tractable over Zp.
csmantle··on Talk Python in Production
And you definitely don't want to miss "Web Arppss" running on "Limux"!
csmantle··on Talk Python in Production
I don't know, but the "Read Online" button leads me to "https[://]talkpython.fm/books/python-in-production/#read-online", and that URL then tries to redirect to "https[://]talkpython.fm/books/python-in-production#read-online". (Notice how the last slash of the path is missing).

This forced my browser to reload the page, and it beats the entire purpose of anchoring and fragment-based navs.

csmantle··on Discord says 70k users may have had their government IDs leaked in breach
Trolls likely have access to phone number farms though. And in some parts of the world it's extra cheap to mass-register phone numbers. Trolls wouldn't be harmed in a data leak, only normal users get hurt.
csmantle··on Being blocked from contributing to lodash
Most OSS projects have a scale of expectation for external contributors depending on what they propose, either implied or written (like in [^0]). A hypothetical but likely scale would be from typo/docs fixes (lowest), bugfixes, new features, to CI/CD and release workflow (highest). Generally, the wider audience your patch might influence, the more you are expected to know about the project itself, its workflow, collaboration, best practices, code quality and maturity, etc. in the first place.

I agree that banning people without prior communication is rude, but looking at OP's PR[^1], I tend to concur with lodash maintainers this time. The PR gets no description, no explanation, and no prior discussion or RFCs. It adds a totally new GitHub Actions pipeline, while lodash isn't even using GitHub Actions now. It contains various fixup commits that should be squashed. One commit has a super long subject that should be split up. OP here went straight to the top level to propose a brand new release workflow, but the lodash maintainers obviously didn't consider them to be ready for such contributions.

These are common mistakes every contributor would make in the beginning, and I don't think the maintainers meant it personal. As many other comments have pointed out, by choosing an easier task, getting familiar with the workflow, and building trust, OP can get their patch landed.

[^0]: https://www.mozilla.org/en-US/about/governance/policies/comm...

[^1]: https://github.com/lodash/lodash/pull/6014

csmantle··on Toybox: All-in-one Linux command line
I guess it has already been posted in 2021: https://news.ycombinator.com/item?id=28627433
csmantle··on You can't parse XML with regex. Let's do it anyways
> Takes a few minutes to get the answer [...]

... then waste a few hundred minutes being misled by hallucination. It's quite the opposite of what "cracking open the code" is.

csmantle··on Show HN: Traceroute Visualizer
I believe they already provided "Standard traceroute example", "Flyingroutes example (with protocol breakdown)" and "MTR example (with packet loss and timing statistics)".
csmantle··on VMScape and why Xen dodged it
I think the author actually meant "Yes, vmscape can leak information on Xen, but only leaks from a miniature Dom0 process." Leaking from an small pool not being a security issue they seemed to consider.

Agreed on the point about hw-level mitigation. The leakage still exists. Containing it in a watertight box is quick and effective, and it does avoid extra overhead. But it doesn't patch the hole.

csmantle··on Just let me select text
Yeah that's possible for us geeks ;) But UX talks about how everyone interacts with our site. We couldn't just ask all visitors to be experts.
csmantle··on Just let me select text
I sometimes shop on Japanese webstores for CDs and merch. Many of these sites are actually where natives buy stuff, so few to no translations are available there. It's a routine for me to copy the Japanese on the nav bar to a translator, then get a list like "Cart <tab> Orders <tab> Account <tab> Help".

Another example for buttons. Assuming I don't speak Chinese, how could I know what "下单" and "返回" mean without copy-pasting them into a translator?

csmantle··on In defence of swap: common misconceptions (2018)
A side note, stack memories are usually not physically returned to the OS. When (de)allocating on stack, only the stack pointer is moved within the pages preallocated by the OS.
csmantle··on Using Claude Code to modernize a 25-year-old kernel driver
It's a good example of a developer who knows what to do with and what to expect from AI. And a healthy sprinkle of skepticism, because of which he chose to make the driver a separate module.
← PreviousPage 2 of 3Next →