HNHacker News
TopNewBestAskShowJobs

dcomp

239 karma · joined January 9, 2017

submissionscomments
dcomp··on When I say “alphabetical order”, I mean “alphabetical order”
I think the algorithm is probably incorrect. A number starting with 0 should be treated lexically not numerically. Otherwise you have a situation where img_1_01.jpg and img_01_1.jpg does not have a complete ordering.
dcomp··on FCC wants all phones unlocked in sixty days, AT&T and T-Mobile aren't so keen
there's a setting in the developer options called OEM unlock which allows the bootloader to be unlocked

It is still shipped locked. Unlocking wipes the device.

It also doesn't work if your device is carrier locked.

dcomp··on A bold new look for the Gov.uk homepage
I think the plan is for each GP's prescribing system/appointment system to export enough data that you can just use the NHS app for your needs. i know I can book appointments through it. Obviously doesn't help when the GP is still sifting through paper records. But those are few and far between.
dcomp··on Why ACPI?
I'm only slightly familiar with the specific features ACPI provides. But isn't the solution the following

For every "feature" provided by the SMM or bios.

Export a UUID ( eg NVME resume implementation1) Have that feature have an enable and disable function. Have each feature have a dependency on each iorange / firmware device it needs access to.

If the kernel know how to implement the feature it can just disable the feature and then as long as it follows the dependency tree and can see nothing else accesses those ranges. It can know that it has exclusive use. If it doesn't have exclusive use it must use the firmware to access those ranges if possible or fall back to no support

If the firmware has a feature without a disable function. The kernel knows it can never access that hardware directly/safely.

You could even have a "lock device" that if you take you know that SMM won't access those io ranges whilst you have the lock.

Obviously this all requires vendor support

dcomp··on Aspartame sweetener to be declared possible cancer risk by WHO, say reports
I thought there was already common terminology for probability of side effects [0]

Very common = greater than 1 in 10

Common = 1 in 100 to 1 in 10

Uncommon [formerly 'less commonly' in BNF publications] = 1 in 1000 to 1 in 100

Rare = 1 in 10 000 to 1 in 1000

Very rare = less than 1 in 10 000

Frequency not known = frequency is not defined by product literature or the side-effect has been reported from post-marketing surveillance data

[0] https://bnf.nice.org.uk/medicines-guidance/adverse-reactions...

dcomp··on Outlook now ignores Windows' Default Browser and opens links in Edge by default
I'm getting office365 nagging me to change the pdf viewer on android after each download in chrome about 15 minutes after the download. Can't find the setting to stop it.
dcomp··on Framework Laptop Cupholder Expansion Card
For those wondering, this is a joke from the LTT WAN Show [0]

[0] https://www.youtube.com/live/CSOF8RFrihM?feature=share&t=982...

dcomp··on Surpassing 10Gb/S over Tailscale
I've switched to tailscale because their nat busting is actually hard to do "by hand"
dcomp··on The FTC wants to ban tough-to-cancel subscriptions
Most likely an early disconnection fee during the minimum term. Nearly everyone has a minimum term with virgin media as they only apply promotional discounts if you have a 12,18 or 24 month minimum term and the price shoots up as soon as you roll over onto the monthly.

[1] https://www.virginmedia.com/legal/fibre-optic-services-terms...

dcomp··on Let's Encrypt now supports ACME-CAA: closing the DV loophole
Technically they could force root nameservers (based in the US) to intercept/proxy the whole gtld.

So all except n (netnod (EU)) and i (WIDE (JP))

dcomp··on Rust in the Linux Kernel: Just the Beginning
> The only thing that concerns me now is the Rust code in kernel is not GPLv2. Not sure if that's intentional.

The only code that isn't GPLv2 is the alloc crate. Which is basically a copy of upstream with some changes. All the kernel specific stuff is GPL

dcomp··on A pair of Linux kernel modules using Rust
From what I understand a rust panic will just call BUG(). There is no support for unwinding as such.

Most likely you would have to use .get() which returns an Option rather than [] array index which panics.

dcomp··on New UK data laws could be incompatible with GDPR in the EU
It's quite scary that the House of lords (unelected peers), previously seen as undemocratic may be the only thing stopping the commons from rushing through legislation as they don't have to pander to public option. Which I guess was always their purpose
dcomp··on Why rails buckle in Britain
To be fair they have been monitoring deaths before [0], just the first time there's a national warning to the public.

Quite a few schools have decided to use this warning to close as they are unable to manage heat on their premises [1]

[0] https://www.gov.uk/government/publications/phe-heatwave-mort...

dcomp··on Why rails buckle in Britain
And for further context its the first RED (danger to life) warning [0] (for the purposes of heat, other red warning have been issued [1])

[0] https://www.metoffice.gov.uk/about-us/press-office/news/weat... [1] https://www.metoffice.gov.uk/weather/learn-about/past-uk-wea...

dcomp··on Upwork asking me for a $12.5k refund as the client was using someone else’s card
Probably because you can't dispute for any reason. But if there wasn't enough notice. If you don't give 10 working days notice (unless initiated by the person). An immediate refund can be requested.

Bad service isn't a reason for a refund. And if the person doesn't say "This debit was in error. I wasn't given notice" or similar the bank will usually say this is a legitimate direct debit [0] https://www.directdebit.co.uk/DirectDebitExplained/pages/dir...

dcomp··on Update on Linux hibernation support when lockdown is enabled
In a high security situation. It would not be a password, but a smartcard which authenticates the device before providing its key, and the device authenticating the smartcard.

Edit: For the purposes of the Networked Evil Maid Attacks. Mutual Authentication (of device and user) is currently the purpose of research. It has not needed to be implemented yet as the regular Evil Maid is still possible due to the fact that Secure Boot is currently the easier target to circumvent. Once Secure Boot becomes harder to circumvent and old "assumed" buggy kernels are revoked from running. Networked Evil Maid counter measures will need to be implemented as standard

dcomp··on Update on Linux hibernation support when lockdown is enabled
You have a disk encrypted laptop. That key is protected by a password.

Secure boot means that when you log in you can trust that the disk decryption screen is not a disk encryption key exfiltration screen waiting for you to enter your password so that a disk backup taken earlier can be decrypted.

How?

The disk encryption is based on a key in the TPM which only is decrypted with your password. That TPM gets wiped when you disable secure boot. The result is that when you enter your password either you get a correct decryption key or your disk encryption key has already been wiped. Assuming it's not possible to run untrusted code before the disk encryption key login screen with secure boot enabled.

kernel lockdown is part of the parcel for making sure that untrusted code does not run that can exfiltrate the disk decryption key.

dcomp··on I had to give a wrong answer to get the job (2017)
For the record. Most analog clocks have smooth motion for minute and hour (for the precision of the gearing). Its the second hand that ticks.
dcomp··on Steve Wozniak backs right-to-repair movement
I was just about to comment about this video that was in my feed.

Louis Rossman publicly asking Steve Wozniak to back right to repair because it's faster than finding someone in his social circle etc to pass the message

dcomp··on Maybe you don't need Rust and WASM to speed up your JS (2018)
Regarding caching and memoisation. Isn't the main benefit memory usage saving. I wonder if it's possible to do parsing for speed and then background deduplication for memory savings. (I don't know what the status is of multithreading in js or wasm)
dcomp··on Google Messages end-to-end encryption is now out of beta
Probably some weird carrier RCS registration issue. My wife uses a s10e on EE (UK) and I use a Pixel 4 XL on Vodafone (UK) and I get RCS messages between us. Only use it for the delivery and read notifications but it works.

I do remember having loads of problems with RCS registration failing on the Samsung side, or just disabling itself.

Edit: Specifically I think it won't register whilst on WiFi and requires the correct mobile APN. I used to switch APNs to get a public IP address/ unfiltered internet

dcomp··on Google Messages end-to-end encryption is now out of beta
I remember thinking RCS was a great idea and everyone saying it was useless as it didn't support E2E. [0]

But I love that RCS has enabled cross carrier (For carriers supporting RCS) E2E messaging.

And the main benefit over iMessage is that there isn't the messaging blackhole problem when changing device.

[0] https://news.ycombinator.com/item?id=16919875

dcomp··on YouTubers have to declare ads. Why doesn't anyone else? [video]
Most likely because spearmint was short for Wrigley's spearmint which was trademarked. I don't think spearmint chewing gum was a generic term at the time. Similar to how sellotape(TM) was trademarked but now cellotape is a generic term.
dcomp··on Golang's network stack attempts to parse HTTP headers as UTF-8
I still fight with case-sensitive matching breaking HTTP2 -> HTTP1.1 proxies
dcomp··on Golang's network stack attempts to parse HTTP headers as UTF-8
Technically isn't incorrect but is a violation of SHOULD. I still think a SHOULD should be a requirement for a general purpose library. With reasons given for not following it.

Edit: And with HTTP having case-insensitive matching (which is most likely broken in lots of hand written implementations). This is rife with the possibility for errors

Taken from RFC 7230 3.2.4 Field parsing

  Historically, HTTP has allowed field content with text in the
   ISO-8859-1 charset [ISO-8859-1], supporting other charsets only
   through use of [RFC2047] encoding.  In practice, most HTTP header
   field values use only a subset of the US-ASCII charset [USASCII].
   Newly defined header fields SHOULD limit their field values to
   US-ASCII octets.  A recipient SHOULD treat other octets in field
   content (obs-text) as opaque data.
dcomp··on Sci-Hub Founder Criticizes Sudden Twitter Ban over “Counterfeit” Content
Also when I was in academia (masters). If my university didn't subscribe to a journal (and it wasn't available via an inter-library loan (In the UK you can ask for a journal from another university)). I would just shoot an email to the author asking for a copy

Edit: Actually I usually sent emails even when we did have a hard copy but no online access. Just because I couldn't be bothered to find the physical copy

dcomp··on Letsencrypt, the Good, the Bad and the Ugly
For the record, snapd is available all the way back to 14.04 [1]

I use acme.sh with dns, it just plonks a certificate in a directory of your choice and runs a reload command of your choice. I actually upload the certificate into a kubernetes cluster. All repeated by cron

[1] https://snapcraft.io/docs/installing-snap-on-ubuntu

dcomp··on Symbian Won
The only thing more annoying is when it ignores the remember this site checkbox.

The current ones will ignore the remember this site probably due to a stupid group policy.

Possibly forgets on logoff

dcomp··on EU's GPS satellites have been down for four days in mysterious outage
My 2p: I think an atomic clock has failed
Page 1 of 2Next →