HNHacker News
TopNewBestAskShowJobs

czarit

50 karma · joined August 25, 2023

submissionscomments
czarit··on Using Microsoft's New CLI Text Editor on Ubuntu
Really interesting development approach here. On unix, this depends on _one_ crate: libc. That crate is just a bunch of wrappers for libc. Absolutely everything else is implemented in the project itself. This is kind of baffling - they have their own everything (from base64 library to a cross platform terminal handling system) instead of using well-proven crates like termios. Why? I don't know. But very unusual in the rust world
czarit··on Using Logic in Writing
It is absolutely accepted in microeconomics, where one can assume that preferences are exogenous to the model (that is: not affected by changing the model's variables).

In macroeconomics it is not so simple, because the effects of a higher price for labor are felt all over the economy, leading to feedbacks that might increase overall employment. The Ford wage increase to increase demand for Ford's products is often cited - because there is a multiplier effect from economic activity even a single firm can theoretically benefit from handing out more money to its employees.

There are also arguments from near term versus long term. In the long term, economies with no access to very cheap labor feel more pressure to robotize production, leading to higher productivity and more production overall, and also might lead to a better educated workforce by simply excluding below-minimum-wage productive labor from getting any jobs, and therefore push some of them to school. Those are short term costs that have proven to lead to long term gains.

But I do also think it's not very common to assume that higher minimum wages will lead to a net increase in employment. It is more common to argue that it will lead to a better outcome (for some definition of good) in the aggregate, _even if_ it might lead to some unemployment.

czarit··on Bitwarden SDK relicensed from proprietary to GPLv3
This depends on the threat model. Having 2FA in the PW manager defends against someone phishing the password and database leaks on the server side, which are the most common in my threat model. But note that if they can phish your pw, they can probably phish your 2FA as well.

It does obviously not protect against the scenario where someone is breaking into your password vault.

I tend to enable 2FA but conveniently save the token in the PW manager for relatively low equity stuff, just to make it less enticing for an attacker, but use hardware FIDO for everything actually important.

czarit··on Alan Turing’s 1950 manual for the Mark I electronic computer [pdf]
POPCNT and LZCNT were added back with SSE4.2, which means all Intel CPUs since Nehalem and Haswell (respectively) and AMD since Barcelona support them.
czarit··on I Created 175 Fonts Using Rust
Very nice! One question: I was curious why you chose this subset of Scandinavian special characters.

There are three extended chars in Swedish (äöå) and Norwegian/Danish (æøå), but your fonts have æ, but not ø, which means you could drop the æ and still support Swedish, or add an ø to also support Norwegian and Danish. Was this an oversight or is there some locale that has just æ and not ø? (and before anyone asks I did not confuse æ with the oe-ligature œ, which is a different glyph used in French, and which the fonts also do support)

czarit··on Empathy for the user having sex with your software
They prioritize penetration testing, I would imagine.
czarit··on Paper Trails
Challenge: Tell me you have never read a thoughtful and contextualizing scholarly archival study without saying so.

Solution: "Dump it in a database and let AI sort it out"

czarit··on Pair Your Compilers at the ABI Café
Not really - Linux syscalls are stable, so you are free to run your binary with a statically compiled libc and never touch the installed one. You can also handcraft your syscalls in assembly.

This will not work on Windows, where the kernel API is a DLL and syscall numbes are routinely changed.

czarit··on Calendar types in watches
I have a Champion watch that (inexplicably) has days marked in English and Portuguese. It was purchased in Sweden.
czarit··on DMCA Notice Targeting 'Bypass Paywalls Clean' Isn't the Thing to Get Angry About
Guessing from the interface it exposes, BPC seems to work by making a ruleset matching sites with a battery of possible changes, including resetting cookies (to reset freebie-counters), fetching from Google cache, disabling javascript (for purely client-side paywalls) and by finding exceptions for the paywall (user-agent, referer, IP).

The last one is probably the one that is closest to being a breach of some law. If the plugin did not ship with rules for a lot of sites, it would probably be considered harmless, but shipping a list of the magic user-agents etc. that circumvents paywalls seems risky, legality-wise.

czarit··on Autoconf makes me think we stopped evolving too soon
> Storage capacity hasn't been relevant for over a decade.

The Linux installs that run your Pi, router, toaster, security camera and toothbrush begs to differ.

czarit··on Advent of Code 2023 is nigh
Easy mode for this use-case is to match on a reversed version of the regex on a reversed version of the string, but yeah, negative lookahead would be great.
czarit··on Let’s not encrypt (2019)
TLS solves two problems, but was originally designed to solve three. The author seems to be annoyed that it does not solve the third problem.

TLS (or SSL, really) was designed to solve trusted authentication - that you could be sure the website that responded to your request was your bank. The idea was that a manual review from an authority would verify that the owner of certificate x was the "real" y, for some definition of x, y, real and authority.

It does not solve that problem, I agree.

It does, however, solve two other problems: The problem of message integrity - noone intercepted and changed this message between server and client; and the problem of eavesdropping - noone can read the message by observing the network traffic alone.

Now, of course, this all depends on the fact that the connection was setup correctly, and a man-in-the-middle attack that can redirect all the traffic for some domain to their own servers would possibly succeed. But that is quite a high bar! Modifying DNS or shaping network traffic in that way requires deep access, and is much, much harder than attacks with no SSL/TLS.