HNHacker News
TopNewBestAskShowJobs

diggan

24,763 karma · joined March 2, 2012

https://notes.victor.earth

https://bsky.app/profile/victor.earth

hn@victor.earth

aspe:keyoxide.org:Q6B7ZBQITV7IE2RG4EMVKWT4VI

submissionscomments
diggan··on Niri – A scrollable-tiling Wayland compositor
Nvidia + Arch + Gnome3 + Wayland user here. I've tried Wayland on/off for the last couple of years, and made the switch I think late last year sometimes once I stopped seeing very obvious bugs/issues. Just about everything works fine nowadays in my experience.

Mostly made the switch because Wayland seems to run a lot smoother and efficient, especially when it came to Firefox for some reason.

diggan··on Niri – A scrollable-tiling Wayland compositor
Better that they're there so they can be disabled, rather than not there any no one gets any choice?

My pet-peeve is slow animations, as animations can help my eyes/attention to navigate to/from areas of the screen, but when they're too slow, it's just so damn frustrating that I prefer them off. But smooth, fast (nearly invisible) and clean animations seems to help me navigate better/focus faster than just being eye-candy.

diggan··on Amazon Vega OS and Vega Developer Tools
I'm wondering if this is what they themselves use for developing the Prime Video app? At least on LG, it's by far the slowest, laggiest and most broken app our family sometimes use.
diggan··on Blender 4.5 LTS
> CAD modeller are good at producing parametric 3d models

If that's the only thing they do better than Blender, then it sounds like their days are numbered. Has to be more benefits right? Blender exposes a pretty wide Python API, loading spreadsheets ends up pretty simple, and together with Geometry Nodes, you can even visualize it in a way that makes somewhat sense. Constraints been existing for a long time in Blender too.

diggan··on Blender 4.5 LTS
> Now all I need is automatic video stabilization

Motion tracking been existing for a long time in Blender, couldn't you use that and move object used to display the footage opposite of the tracked motion and basically get video stabilization?

diggan··on Gemini 3.0 Pro – early tests
> I would be so entertained if I found out an AI lab had wasted their time cheating on my dumb benchmark!

I don't think it's necessarily "cheating", it just happens as they're discovering and ingesting large ranges of content. A problem of public content, it's bound to be included sooner or later, directly or indirectly.

Nice to hear you're doing some sort of contingency though, and looking forward to the inevitable blog post announcing the change to a different bird and vehicle :)

diggan··on Two Amazon delivery drones crash into crane in commercial area of Tolleson, AZ
> But then how do you deliver to the upper floors of vertical buildings?

Maybe asking the obvious, do you need to? Why not drop the package downstairs, people can use the elevator like normal people? Assuming there is some sort of hand-off with identification.

diggan··on OpenAI's H1 2025: $4.3B in income, $13.5B in loss
> $2 billion on sales and marketing - anyone got any idea what this is?

Not sure where/how I read it, but remember coming across articles stating OpenAI has some agreements with schools, universities and even the US government. The cost of making those happen would probably go into "sales & marketing".

diggan··on Gemini 3.0 Pro – early tests
Unfortunately, as every public benchmark, once it ends up in the training sets and/or the developers aware of it, it stops being effective, and I think we've started to reach that point.

The only thing I've found to give me some sort of quantitative idea of how good a new model is, is my own private benchmarks. It doesn't cover everything I want to use LLMs for, and only has 20-30 tests per "category", but at least I'm 99% sure it isn't in the training datasets.

diggan··on Potential issues in curl found using AI assisted tools
> The creative part for me includes both the implementation and the design

The implementations LLMs end up writing are predicable, because my design locks down what it needs to do. I basically know exactly what they'll end up doing, and how, but it types faster than I do, that's why I hand it off while I go on to think about the next design iteration.

I currently send every single prompt to Claude, Codex, Qwen and Gemini (looks something like this: https://i.imgur.com/YewIjGu.png), and while the all most of the time succeed, doing it like this makes it clear that they're following what I imagined they'd do during the design phase, as they all end up with more or less the same solutions.

> If you like your expensive AI autocomplete

I don't know if you mean that in jest, but what I'm doing isn't "expensive AI autocomplete". I come up with what has to be done, the design for achieving so, then hand off the work. I don't actually write much code at all, just small adjustments when needed.

> and I find understanding my whole implementation faster

Yeah, I guess that's the difference between "vibe-coding" and what I (and others) are doing, as we're not giving up any understanding or control of the architecture and design, but instead focus mostly on those two things while handing off other work.

diggan··on Potential issues in curl found using AI assisted tools
> (and it's one of the poorest-rated models if you look at some comments).

Yeah, don't listen to "wisdom of the crowd" when it comes to LLM models, there seems to be a ton of fud going on, especially on subreddits.

GPT-OSS was piled on for being dumb in the first week of release, yet none of the software properly supported it at launch. As soon as it was working properly in llama.cpp, it was clear how strong the model was, but at that point the popular sentiments seems to have spread and solidified.

diggan··on Potential issues in curl found using AI assisted tools
> Creativity is fun. AIs automate that away.

I've been developing with LLMs on my side for months/about a year now, and feels like it's allowing me to be more creative, not less. But I'm not doing any "vibe-coding", maybe that's why?

The creative parts (for me) is coming up with the actual design of the software, and how it all fits together, what it should do and how, and I get to do that more than ever now.

diggan··on NL Judge: Meta must respect user's choice of recommendation system
Doesn't seem like it:

> 5.3. orders Meta Ireland to pay BoE a penalty of €100,000.00 for each day or part thereof that it does not, or does not fully, comply with the orders under 5.1 and/or 5.2, up to a maximum total of €5,000,000.00.

Original:

> 5.3. veroordeelt Meta Ierland om aan BoE een dangsom te betalen van € 100.000.00 oor iedere dag of gedeelte daarvan dat zij niet of niet volledig aan de beelen onder 5.1 en/of 5.2 oldoet. tot een maximum an in totaal € 5.000.000.00 is bereikt.

It seems like usually they start with smaller fines, and if the offense is repeated, they ramp it up. Kind of makes sense.

diggan··on Unix philosophy and filesystem access makes Claude Code amazing
You should really try it in WSL or proper Linux, the experience is vastly different. I've mostly been using Codex (non-interactively though) for a long time on Linux. I tried it out on Windows just the other day for the first time and quoting + PowerShell seems to really confuse it. It was borderline unusable for me as it spent most of the reasoning figuring out the right syntax of the tooling, on Linux there is barely anything of that.
diggan··on Jane Goodall has died
She was also on Spanish TV just five months ago, I was a bit surprised when she appeared there. Seems most of it is on YouTube as well (hoping it's not geo-restricted): https://www.youtube.com/watch?v=FE7lnl4ah9s
diggan··on Aphantasia and Psychedelics
Ever tried 2CB or mushrooms/psilocybin and if so, how prominent were the visuals? Always found those to be more visual (for better or worse), particularly compared to LSD, but I don't have aphantasia.
diggan··on Samsung 870 QVO 4TB SATA SSD-s: how are they doing after 4 years of use?
How much have been written to each of them across their lifetime?
diggan··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
I don't think so? I don't even know what a "CI vault automation" is, I store my credentials and secrets in 1Password, and use the CLI to get the secrets for the moments they're needed, I do all my development locally and things seem fine.
diggan··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
> JS's issue is that it allows you to run an objectively wrong code without throwing explicit error to the user, it just fails silently or does something magical. Seems innocent, until you realize what we use JS for, other than silly websites or ERP dashboards.

What some people see as a fault, others see as a feature :) For me, that's there to prevent entire websites from breaking because some small widget in the bottom right corner breaks, for example. Rather than stopping the entire runtime, it just surfaces that error in the developer tools, but lets the rest to continue working.

Then of course entire web apps crash because one tiny error somewhere (remember seeing a blank page with just some short error text in black in the middle? Those), but that doesn't mean that's the best way of doing things.

> Also remember that it is basically a Lisp wearing Java skin on top

I guess that's why I like it better than TS, that tries to move it away from that. I mainly do Clojure development day-to-day, and static types hardly ever gives me more "safety" than other approaches do. But again, what I do isn't more "correct" than what anyone else does, it's largely based on "It's better for me to program this way".

diggan··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
A bunch, ranging from JS to Clojure and everything in-between, depends on the project.

The approach also depends on the project. There is a bunch of different approaches and I don't think there is one approach that would work for every project, and sometimes I requires some wrangling but takes 5-10 minutes tops.

Some basic information about how you could make it work with 1Password: https://developer.1password.com/docs/cli/secrets-environment...

diggan··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
I don't use AWS and looking in ~/.config/gh I see two config files, no plain-text secrets.

With that said, it's not impossible some tool leaks their secrets into ~/.local, ~/.cache or ~/.config I suppose.

I thought they were referencing the common approach of adding environment variables with plaintext secrets to your shell config or as an individual file in $HOME, which been a big no-no for as long as I can remember.

I guess I'd reword it to "I'm not manually putting any cleartext secrets on disk" or something instead, if we wanted it to be 100% accurate.

diggan··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
Off-topic, but I love how different programmers think about things, and how nothing really is "correct" or "incorrect". Started thinking about it because for me it's the opposite, JS is an OK and at least usable language, as long as you avoid TS and all that comes with it.

Still, even I who'd call myself a JavaScript developer also try to avoid desktop applications made with just JS :)

diggan··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
Using a password manager for fetching them when needed. 1Password in my case, but I'm sure any password manager can be used for storing secrets for most programming projects.
diggan··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
> How many tokens do you have lying around in your home directory in plain text, able to be read by anything on your computer running as your user?

Zero? How many developers have plain-text tokens lying around on disk? Avoiding that been hammered into me from every developer more senior than me since I got involved with professional software development.

diggan··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
Probably signatures could alleviate most of these issues, as each publish would require the author to actually sign the artifact, and setup properly with hardware keys, this sort of malware couldn't spread. The NPM CI tokens that don't require 2fa kind of makes it less useful though.

Clojars (run by volunteers AFAIK) been doing signatures since forever, not sure why it's so difficult for Microsoft to follow their own yearly proclamation of "security is our top concern".

diggan··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
So rather than focusing on how Microsoft/npm et al can prevent similar situations in the future, you chose to think about what relevance/importance each individual package has?

There will always be packages that for some people are "but why?" but for others are "thank god I don't have to deal with that myself". Sure, colors and whatnot are tiny packages we probably could do without, but what are you really suggesting here? Someone sits and reviews every published package and rejects it if the package doesn't fit your ideal?

diggan··on Show HN: Omarchy on CachyOS
Haven't "launchers" existed for decades at this point though? I remember Crunchbang (RIP) having something similar for example, and that must have been almost two decades ago at this point.
diggan··on IETF Draft: Authenticated Transfer Repo and Sync Specification
TLDR/Introduction:

> The Authenticated Transfer (AT) repository and synchronization protocol addresses the challenges of building decentralized applications that require consistent data replication across distributed multi-party infrastructure. Traditional web platforms maintain user data at a single network location, creating vendor lock-in and limiting user agency over their digital identity and published content.

> In the AT model, user data is stored in cryptographically signed repositories that can be hosted, synchronized, and distributed by any compatible server while preserving data authenticity and user ownership. Each repository consists of a set of CBOR-encoded objects called records, organized lexicographically by type. The cryptographic structure allows repository contents to be re- distributed and cached by any network participant without requiring trust in intermediary hosts.

diggan··on The Socratic Journal Method: A Simple Journaling Method That Works
This is such fun comment because it's ambiguous enough to speak to both "the individual is the most important" and "family is everything" people :)
diggan··on Fukushima insects tested for cognition
We have something similar in Barcelona (maybe entire Spain? Apparently called NaviLens, colored squares rather than triangles) all around public transit points. They're used for blind people to navigate the public transit system :)

> As users sweep their environment with a smartphone, audio cues allow them to find and center the tag in the phone’s field of view. A shake of the wrist prompts the details contained within the tag to be read out (visually impaired people are often holding a guide dog or cane with their other hand). https://www.technologyreview.com/2019/06/06/135057/these-col...

← PreviousPage 2 of 34Next →