HNHacker News
TopNewBestAskShowJobs

dinkelberg

305 karma · joined November 2, 2021

submissionscomments
dinkelberg··on You might want to build your WebApp in Canvas instead of HTML
The dev tools in the browser become much more useless when you draw everything in a canvas. It's gonna be sad when everyone starts using frameworks that draw on canvases. Arguably more sad than when Webassembly came. One could probably write new dev tools for those frameworks though.

I also imagine this will be a big setback for web accessibility.

dinkelberg··on Artificial Intelligence used to design new viruses
Study: https://www.science.org/doi/10.1126/science.aec2657

Commentary: https://www.science.org/doi/10.1126/science.aej8512

Published 6 August 2026 in Science

dinkelberg··on Dates That Don't Exist (2015)
Who else uses the proleptic Gregorian calendar other than programmers of datetime libraries?
dinkelberg··on Show HN: ssh ssh.place
Went to the kitty website. No mentions of security.

Went to Alacritty. No mentions of security.

Went to Ghostty. No mentions of security, except for "secure keyboard entry".

None have a "security policy" on GitHub.

All written in memory unsafe languages (C, Zig).

dinkelberg··on Decathlon Germany adds Wero payment option to decathlon.de website
SEPA guarantees the payment to arrive within 10 seconds. Same with Wero, because it uses SEPA. It doesn't work like the card companies that authorize payments before they are settled.
dinkelberg··on Show HN: ssh ssh.place
Web browsers are generally built with security in mind. Terminal emulators surely much less so. The OpenSSH client probably sits somewhat in between, generally developed with security in mind, but not necessarily consistently expecting malicious servers.
dinkelberg··on Show HN: Open-source engine running Gemma 4 26B in 2 GB RAM on any M-series Mac
Life is short. Do you want to spend it reading text that was evidently generated by a machine? There is an opportunity cost to reading "slop."
dinkelberg··on Decathlon Germany adds Wero payment option to decathlon.de website
There's two functions of Wero: peer-to-peer and consumer-to-business transactions. TFA is about consumer-to-business.

If you look at the video for how Wero online payments work (https://www.youtube.com/watch?v=Bu5_X3oSgHM), you'll see that an EPC QR code could just as well be used (with a banking app installed instead of Wero).

With Wero you probably also get automatic processing of the incoming payment, without having to connect the financial transaction to a purchase yourself. But payment through bank transfers is also available through the payment service providers and costs less than Wero (at least it costs less when using Mollie; the Stripe fee is the same for Wero and bank transfer, and Adyen apparently hasn't published the Wero fee yet). So you'd still get the same service for less money.

dinkelberg··on Decathlon Germany adds Wero payment option to decathlon.de website
The payment service provider (like Stripe or Adyen).
dinkelberg··on Decathlon Germany adds Wero payment option to decathlon.de website
Wero shows that marketing is everything. It's just regular bank transactions with a much larger fee. We could have had EPC QR codes and similar completely free technologies instead.
dinkelberg··on Modern email can be built from borrowed parts
Copies the mistake from PGP with the unencrypted metadata.
dinkelberg··on OpenAI’s accidental attack against Hugging Face is science fiction that happened
If a criminal can escape a prison, that's usually negligence on part of the prison staff.

Now suppose the criminal can think 1000 times faster than a typical human, can act 1000 times faster than a typical human, and knows 1,000,000 times more than a typical human. Is the prison staff still at fault for not preventing the outbreak?

dinkelberg··on Restructuring GitHub's bug bounty program
So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.
dinkelberg··on OpenAI and Hugging Face address security incident during model evaluation
Could you explain what you mean by a proper hypervisor? I don't see how hypervisors are relevant here.
dinkelberg··on OpenAI and Hugging Face address security incident during model evaluation
As you said, they can already figure out that they are being tested. So even if they don't exfiltrate any data or malware; if they are malicious, they can just pretend to be harmless in the test, so that less checks are put in place in the production environment. Airgapping during testing is not enough.
dinkelberg··on Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber
Their shop is linked to in the bio. They don't seem to have a privacy policy up on the site. When in the checkout form it links to the generic Shopify privacy policy. No hints to the fact that uploaded images are processed by third parties, as far as I can tell. That should be corrected for sure.
dinkelberg··on The EU is about to sell our most sensitive data to the US for visa-free travel
This is the leaked draft: https://statewatch.org/wp-content/uploads/2026/05/wk_5183_20...

It's not clear how it is supposed to work in detail. But it sounds like it could be implemented in a way that makes illegitimate queries possible. It doesn't sound like they want to really ensure that you can catch those.

dinkelberg··on The EU is about to sell our most sensitive data to the US for visa-free travel
From the analysis linked in TFA:

"The automated query can be based on: * Identity information included in the application or in travel documents, such as name, date of birth, national ID number, and/or * the fingerprint of an individual."

Sounds like they could send requests to that computer system just based on publicly available information on a person like name and date of birth, even if the person never applied for a visa or tried to enter the US.

dinkelberg··on I found a WordPress RCEs with GPT5.6 and $25
What an awful fix. Does WordPress seriously still use basic string concatenation (edit: and sprintf) to build SQL queries?
dinkelberg··on Vancouver PD website features Quick Escape button that wipes itself from history
It doesn't seem to work in Safari on iPhone correctly. When I click on the Back button (from weather.gc.ca), it goes back to the Vancouver PD site. Therefore I do not think that it is built well.

The other site someone mentioned (https://www.thetrevorproject.org/) doesn't have that issue.

dinkelberg··on Demis Hassabis has a plan to harness AI safely
> obesity is a much bigger issue than hunger today

Hunger is acute suffering, mostly by people who cannot change anything about it, while obesity is more of an epidemiological problem and can in principle be avoided by eating (or in the case of dependent persons, feeding) less.

dinkelberg··on The Second Life of Sanskrit
> Biblical Hebrew has no vowel markings (well it does, but they are an interpretation), so it cannot be used in daily speech. Modern Hebrew is distinct from Biblical Hebrew

The same can be said about Latin (of which we do not exactly know how they used to pronounce words), or any other language. How to pronounce letters or words is always "interpretation" (or more accurately, tradition).

dinkelberg··on Blue light filters don't work – controlling total luminance is a better bet
One more relevant study, but on the health effects of long term melatonin use:

https://newsroom.heart.org/news/long-term-use-of-melatonin-s...

"The main analysis found:

* Among adults with insomnia, those whose electronic health records indicated long-term melatonin use (12 months or more) had about a 90% higher chance of incident heart failure over 5 years compared with matched non-users (4.6% vs. 2.7%, respectively). * There was a similar result (82% higher) when researchers analyzed people who had at least 2 melatonin prescriptions filled at least 90 days apart. (Melatonin is only available by prescription in the United Kingdom.)

A secondary analysis found:

* Participants taking melatonin were nearly 3.5 times as likely to be hospitalized for heart failure when compared to those not taking melatonin (19.0% vs. 6.6%, respectively). * Participants in the melatonin group were nearly twice as likely to die from any cause than those in the non-melatonin group (7.8% vs. 4.3%, respectively) over the 5-year period."

However they were not able to control for severity of the insomnia and used dosage, because that data weren't in the dataset.

dinkelberg··on Blue light filters don't work – controlling total luminance is a better bet
Melatonin pills seem to have extremely bad quality control:

"Melatonin content varied from an egregious −83% to +478% of labeled melatonin and 70% had melatonin concentration ≤ 10% of what was claimed. Worse yet, the content of melatonin between lots of the same product varied by as much as 465%.

[...]

The last disturbing finding was more than a quarter of melatonin products contained serotonin, some at potentially significant doses."

https://pmc.ncbi.nlm.nih.gov/articles/PMC5263069/

"In products that contained melatonin, the actual quantity of melatonin ranged from 74% to 347% of the labeled quantity. Twenty-two of 25 products (88%) were inaccurately labeled, and only 3 products (12%) contained a quantity of melatonin that was within ±10% of the declared quantity. [...] Serotonin was not detected in any product."

https://jamanetwork.com/journals/jama/fullarticle/2804077

"Half of the products tested met the label’s claim for melatonin, which means they fell between 76 and 126 percent of the claimed amount. Of the products tested, 20 had between 0 and 76 percent of the labeled content, and 35 had between 126 and 667 percent."

https://www.washingtonpost.com/wellness/2025/06/25/melatonin...

dinkelberg··on Semaglutide improves knee osteoarthritis independant of weight loss
Not an example, but maybe this is interesting for folks who haven't really heard of the peptide business before. https://www.theguardian.com/wellness/2026/feb/05/injectable-...
dinkelberg··on How, and why, I invented OnlyFans. In 2004
Clickbait title. He didn't invent OnlyFans. He created a similar site which failed.
dinkelberg··on Mathematics Without Numbers (1959)
I would have liked a summary before reading.

Why is writing a summary a bad thing?

dinkelberg··on Mathematics Without Numbers (1959)
[flagged]
dinkelberg··on Why do we need dithering?
Lena Söderberg expressed her wish for her image to be "retired from tech" in 2019 (see the end of this clip, https://vimeo.com/372265771), when the above alternative image was published.
dinkelberg··on Rust in Android: move fast and fix things
According to that blog post (https://security.googleblog.com/2024/09/eliminating-memory-s...), the vulnerability density for 5 year old code in Android is 7.4x lower than for new code. If Rust has a 5000 times lower vulnerability density, and if you imagine that 7.4x reduction to repeat itself every 5 years, you would have to "wait" (work on the code) for... about 21 years to get down to the same vulnerability density as new Rust code has. 21 years ago was 2004. Android (2008) didn't even exist yet.
Page 1 of 3Next →