HNHacker News
TopNewBestAskShowJobs

danielvf

9,793 karma · joined December 13, 2013

daniel at leancoder dot com

Long time builder: - Web applications - Embedded firmware - Blockchain applications and security.

submissionscomments
danielvf··on The title cards in Blade Runner are amazing
The em dashs are a callback to the silent film title cards days –– they represent a pause in speech.
danielvf··on UEFA and its national associations will not participate in FIFA competitions
For local NFL games in a bigger stadium that, most people attending do drive, but do not park at the stadium, rather nearby, then walk the rest of the way. This spreads out the traffic over a much larger set of roads.
danielvf··on Turn And Face The Strange
Sprites are a beautiful place to make an abstraction.

But I have never used a buggier infrastructure product in 30 years of development than when I tried sprites. Data loss left and right, sprites going into unconnectable zombie mode. Couldn't use even load snapshots because half the system seemed to think the sprite was fine, and half seemed to think it was dead. I gave up after two weeks of losing stuff over lunch or overnight or in the middle of working. I vividly remember scrolling through my terminal history, copy/pasting out work I could find to save from a dead sprite. I would guess that half or more of the sprites I launched had some kind of problem.

Hope they get things stable. The concept is great.

danielvf··on Wolves are reconquering Europe. Can people learn to live with them?
1. Wolves were basically exterminated in the continental US for most of the 20th century 2. There were still deaths from wolf attacks in North America during that time

https://en.wikipedia.org/wiki/List_of_wolf_attacks_in_North_...

danielvf··on Fraud investigation is believing your lying eyes
The report to the government about a more than 50% fraud rate was from six years ago. The Minnesota government was not serious about dealing with problem. Most businesses would not last that long with a 50% customer fraud rate.

Yes, there were some investigations and convictions, but nothing to on a scale that would deal with problem, nor any systematic change to a level paying huge amounts of money to scammers.

danielvf··on Fraud investigation is believing your lying eyes
Here's a rap video, the entirety of which bragging about fraud against the government:

https://www.youtube.com/watch?v=K0ck7hTsug8

"I just been swipin' for EDD

Go to the bank, get a stack at least

This ** here better than sellin' Ps

I made some racks that I couldn't believe

Ten cards, that's two-hunnid large"

(For context, "EDD" is California’s Employment Development Department.)

danielvf··on Robin Williams' daughter pleads for people to stop sending AI videos of her dad
Similarly, it drives me up the wall with people posting black and white "historical photographs" of history happenings, that are AI slop, and from the wrong era.

Just yesterday someone posted a "photo" of a 1921 where a submarine lost power, and built sails out of bedsheets to get home.

But the photo posted looked like a post WWII two submarine, rigged like a clipper ship, rather than the real life janky 1920's bed sheet rig and characters everywhere.

Actual incident (with actual photo): https://en.wikipedia.org/wiki/USS_R-14

danielvf··on ICEBlock handled my vulnerability report in the worst possible way
Yes. As someone who spent years on the receiving end of these, I'd change my original post to be about "real" vulnerabilities, not the results of automated scans.
danielvf··on ICEBlock handled my vulnerability report in the worst possible way
In the software development / security world, someone reporting a vulnerability to you is one of the greatest things one human can do for another.

I've been burned in the long past when trying to be helpful to an activist. The accuracy of information provided was never a consideration.

danielvf··on We regret but have to temporary suspend the shipments to USA
Yes, it's a very logical part of a tariff regime, and tariffs penalize domestic manufacturers without it.

But wow, are tariffs (and other micro taxes) disruptive on getting things done efficiently.

danielvf··on Court records reveal Sig Sauer knew of pistol risks for years
So the important bit here is that the guns failed drop testing. And that's bad.

The rest of the article seems to misunderstand FMEA style "write down every conceivable bad scenario in the universe, how bad it is, and then what you have done to stop it", and then spins this as "look at all these horrible known issues they knew about". I hope a jury doesn't view it the same way, because it would be an epic bad for safety everywhere if engineers writing down a list of bad things to avoid and mitigate was forbidden by company lawyers.

danielvf··on 60% of medal of honor recipients are Irish or Irish-American
As others have pointed out, this is primarily due to the American Civil War when the Medal of Honors was given out much more freely than today.

Here's the breakdown on more recent conflicts:

WWII, 625 total recipients, 13 Irish, 2.1%.

In the Korean War, there were 152 Medal of Honors, 3 given to Irish, or 1.9%.

In the Vietnam War, there were 271 Medal of Honors, 13 given to Irish, or 4.8%.

There were 36 Medal of Honor medals given out in the wars in Iraq and Afganistan. Of these, 3 are marked as Irish on that page, or 10.7%.

danielvf··on Show HN: Draw A Fish and watch it swim with the others
I carefully drew a lion fish. Turns out only 37% odds of being a fish. (https://en.wikipedia.org/wiki/Lionfish)

Fun idea, fun site!

danielvf··on What Makes Europe Better Than America?
Don't be fooled by the headline - that's neither the authors words, nor his opinion, but an editor trying to bait viewers.

The article itself is good, and worth a read.

You can read the full article on the author's own substance here. https://walkingtheworld.substack.com/p/is-it-euro-poor-or-am...

danielvf··on My experiment living in a tent in Hong Kong's jungle
For camping in humid summers, it's amazing how much difference a power bank and little fan can make. A little electricity goes a long way.
danielvf··on Uber's new shuttles look suspiciously familiar to anyone who's taken a bus
My guess is that the people who are paying $13 each way for a 30-minute commute are paying orders of magnitudes more than that in taxes already.

Also, given that this is not a huge number of people, relative to public transportation in NYC, it would probably not make much of a budget increase.

danielvf··on The Problem with Teens Isn't Smartphones–It's Their Families
As almost every other commenter here has said, this is just a bad article in practically every way. It's quite possible that the problem isn't smart phones, but this article completely fails to show this.

Even the suicide data that they decide is the proper measure of mental health, and according to them proves that teens don't have a problem, shows a 2x increase in teen girl suicide.

I'm going to so something I almost never do, and flag, since this is just bait. I would love to read a case for this with a better argument however.

danielvf··on A crypto founder faked his death. We found him alive at his dad's house
Market cap doesn't equal what people have purchased.

See this classic from 2015:

https://medium.com/signal-v-noise/press-release-basecamp-val...

danielvf··on Curl: We still have not seen a valid security report done with AI help
I handle reports for a one million dollar bug bounty program.

AI spam is bad. We've also never had a valid report from an by an LLM (that we could tell).

People using them will take any being told why a bug report is not valid, questions, or asks for clarification and run them back through the same confused LLM. The second pass through generates even deeper nonsense.

It's making even responding with anything but "closed as spam" not worth the time.

I believe that one day there will be great code examining security tools. But people believe in their hearts that that day is today, and that they are riding the backs of fire breathing hack dragons. It's the people that concern me. They cannot tell the difference between truth and garbage.

danielvf··on We identified a North Korean hacker who tried to get a job
> And how sure are you these weren't random hackers or trolls, but actual NK agents?

"Agents" is way too big of a word. Just cogs in a corporate theft machine.

There's a lot of reasons I'm sure, but the biggest is because before a hack they asked for help doing something simple with a crypto address that was later used to test run the 50 million dollar theft that was North Korea. And also trying to drop North Korean linked malware is another data point.

This also hits my point about both dangerous and amateurs. They pulled off pretty sophisticated heist but, had to ask for help, asked for help using a crypto address tied to the theft, and blew the cover on an identity they had been building up for a year.

Here's a twitter thread I put together of both my conversation and others with this particular account:

https://x.com/danielvf/status/1905642180749775189

danielvf··on We identified a North Korean hacker who tried to get a job
I am saying they are both a credible threat and many are amateurs. Those are not mutually exclusive.

You are talking about North Korea attackers from a theoretical point of view. For many people dealing with them is just a normal part of work. It's not an unknown that needs to be worked out logically from an armchair.

I'm saying this as someone who personally chatted with a North Korea persona that later tried to drop exploits on people, and the persona belonged to hacking group with at least one 50 million dollar heist. I've also seen the screenshots on many chats with North Koreans.

danielvf··on We identified a North Korean hacker who tried to get a job
These aren't spies first. They are often children of well to do, high loyalty group North Koreans. It's just a privileged job.

The skill and IQ level varies widely, from super smart to super unskilled. And these roughly get sorted out into different groups with different MO's. North Koreans aren't some uniformly skilled group. You could be targeted by a team of world class bytecode exploit geniuses who rehearses every move, or by the equivalent of Milton from Office Space.

Dissing Kim is something that is not currently widely permitted in NK. Just isn't worth personally.

Not saying no one from NK never will, but so far almost everyone will immediately stop the conversation at this point. There are plenty of crypto people who have monthly or weekly encounters with NK job applicants.

danielvf··on We identified a North Korean hacker who tried to get a job
It used to be only against specific industries, but now it's evolving. Now they have groups just going after remote IT jobs regardless of industry.
danielvf··on We identified a North Korean hacker who tried to get a job
North Korea's efforts have been evolving.

In the past, they just tried to break into bank computers, then into crypto company's computers. For the last two years, they've been working on getting people into crypto companies.

But now they appear to have enough people to spare than they also have groups working on "honest" employment as remote workers, who may not even have theft as the first thing on their mind.

Here's a federal case where a US woman was convicted of helping North Korea steal the identities of 70 people, and then remote in as them, to do remote work:

https://www.justice.gov/usao-dc/pr/arizona-woman-pleads-guil...

danielvf··on Amazon denies tariff pricing plan after White House calls it "hostile/political"
I see a lot of comments here and in the other thread talking about Amazon's high profits on retail sales, so I looked up the last earnings report.

For the year of 2024, Amazon made a 5.5% operating profit on non-AWS revenue. This is before taxes and, I think, before leases on buildings and property.

https://s2.q4cdn.com/299287126/files/doc_financials/2024/q4/...

danielvf··on The raccoons who made computer magazine ads great
It's buried deep in the article, but what made PC Connection amazing was the shipping.

You could phone call a human in the wee hours of the morning, and have it show up later that same day. Or pay only a little and have it into two days. Compared to every other mail-order retailer in the universe at the time, it was insane, to have such selection and speed.

danielvf··on Canadian math prodigy allegedly stole $65M in crypto
Don't worry, he also had a ""POST-EXPLOITATION" plan.

Which included, among other things, "KEEP the configs Burn the evidence, including the histfile Book flight to: Pack Bags"

danielvf··on Canadian math prodigy allegedly stole $65M in crypto
There is a US indictment which lays out the basics of the which laws Medjedovic is accused of breaking.

https://www.justice.gov/usao-edny/pr/canadian-national-charg...

danielvf··on Canadian math prodigy allegedly stole $65M in crypto
In this case the only person espousing the idea of "code is law" is the hacker. Neither the blockchain's builders, nor the hacked protocol, nor the users are saying that.

"code is law" is a meme that primarily lives on hacker news. Only a tiny fraction of crypto people believe it or say it.

danielvf··on Canadian math prodigy allegedly stole $65M in crypto
There's a very relevant XKCD on this, where someone discovers a clever "bug" in an insurance contract, and is then disappointed.

https://xkcd.com/1494/

Page 1 of 34Next →