HNHacker News
TopNewBestAskShowJobs

gsnedders

6,254 karma · joined June 8, 2012

Web dev consultant, long time WHATWG/W3C contributor, linguist and computer scientist. I get paid by browser vendors to make the web more interoperable.

[ my public key: https://keybase.io/gsnedders; my proof: https://keybase.io/gsnedders/sigs/mzGxtKUO-Q2yYme3MggWJzaLZS6USlZuc8xRrS7iQi4 ]

submissionscomments
gsnedders··on Strands Decider 2B: a small, open-source, decision model
What I don’t get from this article is why strands-decider-2b v10 and strands-decider-2b v11 are shown as “other systems”, and with v11 notably outperforming v19 — why are these other systems, and why is v11 not the path taken?
gsnedders··on Cloudflare OHTTP gateway
OHTTP is designed for a relatively narrow use case: stateless requests where you don't want the gateway to be able to correlate multiple requests from the same client (i.e., it's not just about hiding the IP address).

A clear example of when this might be a good idea is DNS-over-HTTPS — you don't want the resolver being able to correlate multiple requests from the same client.

You _can_ try and do this with SOCKS5, however you need to be very careful to avoid sharing any state:

* You must use a new TCP connection for each request, with a new TLS and HTTP connection atop.

* You must ensure you do not use TLS Session Resumption or 0-RTT data.

* You must, to the maximum extent possible, be very conservative with what you send in the TLS ClientHello to avoid exposing fingerprinting data.

SOCKS5 is also unencrypted, and the request contains the destination: the hostname if the proxy resolves it, or the IP if the client resolved it itself (and ECH doesn't help here, since it only protects the SNI inside the TLS handshake that follows). With OHTTP, that's all inside the TLS connection to the relay.

OHTTP doesn't have the client sending up-front metadata about all the different encryption methods it supports to the gateway (it relies on the gateway to tell it what it supports, and the client just picks one); the gateway doesn't get to see any of the TLS fingerprinting surface (because that is only visible to the relay).

OHTTP also doesn't require there to be multiple new TCP connections made for every request (whereas with SOCKS5 you're looking at a new TCP connection from the client to the proxy, and from the proxy to the server, per request) — you can have a long-lived connection to the relay, and the relay can have a long-lived connection to the gateway (shared by many clients). That's a big latency win for applications like DNS-over-HTTPS.

The risks of key disclosure also differ between the two — with OHTTP, disclosure of the gateway key essentially means the relay can decrypt recorded traffic that used that key (as there is no forward secrecy), whereas disclosure of the client <-> relay and relay <-> gateway keys matters a lot less (because there is forward secrecy); with SOCKS5, you have forward secrecy via the end-to-end TLS connection.

For the use-case of a general-use proxy, work such as MASQUE provides a multi-hop approach to limit exposure to any single party, and that does provide an end-to-end TLS connection — but you with that you're back to exposing all the fingerprinting associated with it, though for a general use proxy you may also be sending session-specific data (like auth tokens) that clearly tie requests together anyway.

gsnedders··on ADHD, autism or complex trauma? [pdf]
https://pmc.ncbi.nlm.nih.gov/articles/PMC8328933/#S20 might be a good starting point here?
gsnedders··on ADHD, autism or complex trauma? [pdf]
From that meta article:

> For most people with ADHD, many genetic and environmental risk factors accumulate to cause the disorder.

i.e., for most people, there is no singular cause.

gsnedders··on Git 3.0's upcoming SHA-256 default will be a costly mistake
My reading of the docs is that when fetching/pushing from a SHA-256 repo, all objects are referred to (in the packfile fetched) by their SHA-256 names — then, when fetching, you locally compute the SHA-1 of each object for the translation table.

Presuming there’s some validation that SHA-1 names are unique, then that should be safe — the only way I can see one could do a pre-image attack is either fetching from a SHA-1 server (because then you don’t get the SHA-256 object name), which requires a second pre-image attack on SHA-1 (known to be feasible); or by having a second pre-image attack against both SHA-1 and SHA-256 simultaneously (and SHA-256 is still believed to be secure).

gsnedders··on The case against JPEG XL
AVIF _is_ AV1 in the HEIF container.

(.heif is sometimes used as a file extension generically, but HEIF is itself a container that can support various payloads.)

gsnedders··on Actively exploited sandbox RCE in all Chromium versions
This hasn’t been true in over a decade.
gsnedders··on Calibrate Before You Accelerate: Bias Toward Action in a New Role
It's also, inevitably, the newest people who are often the best at fixing basic documentation — because they're the ones who don't already know it.
gsnedders··on A spectre is haunting Unicode
> The peculiar properties of CJK characters and the philosophy (apparently the Japanese did not like Unicode's tendencies towards Aristotelian essentialism) under which they were implemented in Unicode probably singlehandedly forced unicode to expand beyond the BMP....

Note that Han Unification has a history predating Unicode, and the Unicode work very much followed on from that.

The most notable is CCCII, developed in Taiwan in the early 80s, and then standardised in various places.

That's not to say that it hasn't been controversial (it has!), nor to say that it hasn't caused problems (it has!), but it's also unfair to say that it's just Unicode doing its own special thing.

gsnedders··on England set to be one of the first countries to eliminate hepatitis C
There’s a decent amount of public health research that suggests that annual physical exams don’t actually have a large impact on health.

In the US case specifically, I always wonder how much of the benefit is just “here’s a free appointment with a doctor once a year”.

gsnedders··on The AI Billboards Are Killing SF
And I get it — when the name of FooBar Inc is on the billboard. When there’s neither a product name nor a company name, which seems to be happening more and more often, I just don’t get it!
gsnedders··on The AI Billboards Are Killing SF
I feel like SF has been full of frequently inscrutable billboards as long as I’ve been coming here — at least a decade.

It’s maybe got slightly more extreme recently, with an even larger percentage of them being inscrutable to me as someone who both works in tech and has a decent grasp of current industry trends.

I’ve never really got it — if even I don’t know what you’re advertising (or often, who is advertising!), how does this help your sales?

gsnedders··on Show HN: I worked on a new browser for 2 years, today it passed Acid 3
https://github.com/web-platform-tests/wpt/commits/master/aci... shows the history of the web-platform-tests copy of WPT, which has mostly followed Hixie’s earlier updates to Acid3 by simply commenting out assertions that no longer match what specs say.
gsnedders··on Stacked PRs are now live on GitHub
I’d still love a way to be able to rewrite commits at merge time, via Actions or otherwise.

The most obvious case is something like adding a Reviewed-By/Signed-off-by trailer based on reviewers, but there’s also a decent number of big projects that want more semantically meaningful commit identifiers (think more revision, in a numeric sense).

It seems like making merges async should make it a lot more possible to implement that!

gsnedders··on Stacked PRs are now live on GitHub
And enough of the time you can just match based on subject line, similar to how fixup/squash commits work with autosquash.

There’s enough ways you can match up commits, with plenty of prior art in this space.

gsnedders··on Open Book Touch: open-source e-reader
Being based on a microcontroller and having limited RAM, I do wonder how good its ePub implementation is, especially in terms of CSS, but also in terms of dealing with larger (XHTML) documents.
gsnedders··on To study how chips work, MIT researchers built their own operating system
This is why a distinction is often drawn between vulnerabilities and exploits — many more things can be weaknesses in a system that can only be exploited in combination with other vulnerabilities.

An obvious example is web browsers, where a vulnerability can easily be uninteresting because it lives in a sandboxed process… until you find a sandbox escape, then it is critical.

As long as you suspect there may be other vulnerabilities in the other layers, it is worthwhile investigating and fixing them, because defence in depth only works until someone manages to put together a full chain.

gsnedders··on Apple's weird anti-nausea dots cured my car sickness
It came in macOS Tahoe 26 — a year later than on iOS and iPadOS.

Personally, I find it somewhat less effective on larger screens, simply because my eyes are more likely to be further from the dots.

gsnedders··on Your ePub Is fine
Yes, every single CSS standard ever has required that.
gsnedders··on Your ePub Is fine
While plausible, I would suspect it’s more likely you’ve just run into bugs than forwards-compatible error behaviour — most ePubs don’t get anywhere near actually interesting CSS!
gsnedders··on Your ePub Is fine
epubcheck is meant to ensure conformance with the standards, not the interoperably implemented subset of the standards. (Which has lots of awkward questions: which implementations of the standards, which versions of those implementations, etc.)
gsnedders··on Your ePub Is fine
You are of course correct that ePub nowadays doesn’t mandate a given version of CSS (though earlier versions did!), but that doesn’t matter in this case: it’s non-conforming according to even CSS level 1 (1996), per https://www.w3.org/TR/REC-CSS1-961217#forward-compatible-par...

> illegal values, or values with illegal parts, are treated as if the declaration weren't there at all

So a conforming implementation would ignore that max-width property declaration, not raise an error.

And those earlier versions of ePub which defined a required subset of given CSS standards? The forwards-compatible parsing rules were part of their subset.

gsnedders··on Your ePub Is fine
To be clear, ADE’s behaviour is not conforming to any version of the standards it claims to implement. If it had been, it would reject that specific max-width property declaration as having an invalid value and ignore it, not reject the entire document: every single version of CSS has required that forwards-compatible behaviour.

PDF is not somehow immune to this either — a non-conforming implementation could similarly break what are meant to be forward-compatible extension points by raising an error on an unknown stream or object instead of (as required by the standard) ignoring it.

gsnedders··on Formal methods and the future of programming
Another obvious example are cryptographic hash functions: if you have a function f(s) = h, you can trivially specify a function inverse_f(h) = s st f(s) = h, and if you can infer a non-brute-force algorithm for that, you’ve just inferred a cryptographical weakness!
gsnedders··on macOS Container Machines
Only WSL2; WSL1 was an actual subsystem.
gsnedders··on Nvidia is proposing a beast of a CPU system for Windows PCs
It feels deeply unfortunate that even with Windows on AArch64 requiring ACPI that it still doesn’t suffice for Linux, unlike on x86.

And I know a lot of that lies on the vendors, but it does feel unfortunate (from a standardisation/conformance/certification point of view) that Windows requiring it doesn’t make it easy to boot other OSes!

gsnedders··on GTA 6 Developers Unionize
Who is outsourced here? It’s not immediately apparent from the article that people were being outsourced?
gsnedders··on GTA 6 Developers Unionize
> In a union, the only way up is seniority or, in other words, the amount of money you've paid in dues over the years.

I’m unaware of this ever being the case in the UK — the lack of closed shop units means that even when collective agreements cover promotion they cannot meaningfully set this based on dues paid, both because they don’t necessarily know how long each employee has been a member of the union, and regardless that would be illegal discrimination based on union membership vs not.

In the common case for private-sector white-collar collective agreements in the UK, promotion is mostly just required to be transparent, rather than setting out procedural rules for promotion.

Your focus on union dues also makes me suspect you’re commenting from the US, expecting a union environment much more like the US — and US unions are outliers in many ways.

Per https://iwgb.org.uk/en/join/game-worker/ union dues max out at £35/month for those earning £80k and more — this is vastly less than unions require as dues in the US, and that almost certainly reduces the impact that union dues have, even beyond the illegality of closed shop units.

gsnedders··on Testing Mac OS on the Apple Network Server 2.0 ROMs
Apple’s own style guide says to use the name of the appropriate release: https://support.apple.com/en-gb/guide/applestyleguide/apsg72...
gsnedders··on Introduction to Atom
RSS 2.0 is kinda an unspecified mess, and at least 15 year ago, if you wanted to be compatible with the majority of content you needed some weird heuristics to detect which interpretation of the spec a given feed was using (lol).

And Dave Winer was strongly against ever clarifying the spec, and that’s part of what led to Atom.

Page 1 of 34Next →