HNHacker News
TopNewBestAskShowJobs

gwillen

1,589 karma · joined April 1, 2010

[ my public key: https://keybase.io/gwillen; my proof: https://keybase.io/gwillen/sigs/Xla3yrn6We4GJ__jYz_0O9Ws247vyfgp4FRvVYf5jNg ]
submissionscomments
gwillen··on Welcome to Libera Chat
I don't think anybody trusts christel anymore, but I'm not sure why any of the other staff would be implicated in the sale. As far as they all claim, anyway, they were not aware that Andrew Lee believed/claimed he had ownership of the network; and in fact they claim they were all promised by christel that this was not the case.
gwillen··on Welcome to Libera Chat
Well, from the current front page of freenode.net:

https://web.archive.org/web/20210520103526/https://freenode....

"The rumors of a 'hostile takeover' are simply untrue - I've been the guardian and owner of freenode since 2017, when Christel, the former owner approached me and asked if I was interested in purchasing it, as we had in previous years discussed this."

gwillen··on Leaving Freenode for a new network
From what I'm seeing, everything I'm active in is moving (including my own channels) -- the old ones aren't being shut down yet, mostly because people want to give libera.chat a few days first to make sure it doesn't suffer major hiccups. But the new ones are going to be the permanent ones, I expect. (That's certainly our plan.)
gwillen··on Leaving Freenode for a new network
I think libera.chat has successfully positioned itself as the clear successor to freenode; all the projects I'm a part of on freenode have moved / are moving there. I'm sure it's not perfect, and it's been having some teething issues with load and such (as expected). But it seems like ~100% of freenode's volunteer staff have moved over to libera.chat, so my impression is that the writing is on the wall for freenode. (The server links were never especially stable when they _had_ staff; now that they have no staff, I expect stability to suffer heavily.)
gwillen··on Ask HN: My startup has more annual subscribers than monthly. What to make of it?
I have heard debit-only cards in the US referred to as "ATM cards" occasionally, but that was a few years ago. I think if an account belongs to a minor child, it may not be possible to get a regular debit card (that also works with the credit card network), but an ATM card may be possible? That's the only reason I'm aware of to get one.
gwillen··on The end of TenFourFox and what I've learned from it
> The bug reports I liked least were the ones that complained about some pervasive, completely disabling flaw permeating the entire browser from top to bottom. Invariably this was that the browser "was slow," but startup crashes were probably a distant second place. The bug report would inevitably add something along the lines of this should be obvious, or talk about the symptom(s) as if everyone must be experiencing it (them).

> I'm not doubting what people say they're seeing. But you should also consider that asserting the software has such a grave fault effectively alleges I either don't use the software or care about it, or I would have noticed.

It sucks to get these kinds of reports when you are a solo dev who uses your own project, and you really do actively use the software and care about it.

But I feel like I've been trained over the years that the devs very often do _not_ seem to use their own software or care about it. So if a major showstopping problem happens on my machine, and it repros on my other machine, and then again on a randomly-selected friend's machine, I tend to assume it's widespread and the devs just don't care that much. (I still try to clearly state the repro conditions as best I am able. But if I can't find a system it _doesn't_ repro on, then it's hard to be specific.)

Sadly, this is probably a case where lots of otherwise-good users have been let down by shitty devs, and lots of otherwise-good devs have been let down by shitty users, and nobody trusts anybody anymore.

(Most recent irritating example: Google Sheets for Android has a 'remove' menu item in the 'Last opened by me' view, which claims (when I select a document owned by another user) that it will remove the document from view, but "Collaborators will still have access." At least the last two times I checked, this isn't true; it will effectively delete the document, for everyone but the owner. This has been the case for months at least; I believe it may have started when Google Drive switched their model to disallow "hard links" of documents. I'm suspicious about whether anybody on the Google Drive team has a very clear mental picture of what their sharing/containment model even _is_ anymore, at least for free users who don't have a "workspace". I reported this using the 'feedback' tool in the app, but I'm well aware that it will not reach anybody who cares.)

gwillen··on Thunderbird 2020 Financial Report
Did they move? When I installed Thunderbird on my Windows 10 machine recently, I noted that Maildir was available as an option, and switched to it. But it seemed like mbox was still the default, and certain behavior seems to be glitchy on Maildir. (I get frequent notifications about compaction of mailboxes, despite the fact that Maildir cannot be, and does not need to be, compacted.)
gwillen··on Starlink is now Accepting General Pre-orders
> well built, engineered and maintained

Fortunately for Starlink, there's not much worry about Comcast having any of those things.

gwillen··on Bitcoin's fundamental value is negative given its environmental impact
Ethereum hasn't even migrated to "Ethereum technology". They have been claiming for years that they are planning to move from Proof of Work to Proof of Stake. Maybe someday they will.

My take on this: I remain unconvinced that any form of Proof of Stake can give the same security properties we easily get from Proof of Work. I won't say never, but getting Bitcoin to move would take a very convincing argument about the viability of PoS, and so far that's not happening. (Especially given that the poster child for PoS does not actually _use_ PoS yet, they just keep promising it "soon".)

gwillen··on Open-source, not open-contribution
> can't this be solved by putting the "burden of PR" on the PR-er? A long checklist of "I have read this" and "I have tested this" should raise the PR bar high enough to make the code review cost worth it.

People definitely do not read those. The less useful their PR is, the less likely they are to have read any of the stuff in the template.

gwillen··on Why do they still make car alarms? (2015)
I'm pretty skeptical of the value of this gimmick, but my impression is that dealers get big kickbacks to push it. When I bought my car, I tried to opt-out of Phantom Footprints (as I did with every single overpriced extra), and they ended up giving it to me for free.
gwillen··on Google Maps changes a route after the drama of young people lost on a ghost road
I suspect I know the cause of this -- there was a change to Google Maps not long ago, related to how it computes destination points when your destination is a large area (such as a large park.) It used to try to take you to the official address, or some central point; these days, what I observe is that it takes you to _some_ point where the road hits the edge of the destination area. I'm not sure how it chooses what point, but it looks like it missed.

(Note: I don't work for Google, and haven't for many years. I mostly noticed this change because it finally fixed a longstanding directions issue that I first reported ABOUT TEN YEARS AGO, involving directions to the Pittsburgh International Airport.)

gwillen··on An AI Girlfriend Seducing China’s Lonely Men
I often describe the sensation of trying to read ML-generated text as "feeling like I'm having a stroke". Phrasing not original to me obviously, but I like it. Although I've never had a stroke myself, so I can't say how accurate that is.
gwillen··on Google illegally spied on workers before firing them, US labor board alleges
As one of the people who gave a counterexample, let me just say that I don't support people downvoting you, and I would much rather live in your reality than this one. (Thank you for treating your employees better than most.)
gwillen··on Comprehensive Guide to Email Deliverability
Pardon my French, but I don't give a flying fuck about how deliverable someone's "campaigns" written by their "creatives" are to the "clients" on their "targeted lists".

I want to know how I, a human being running a mailserver, can consistently ensure that other email users -- most notably Gmail users -- can consistently receive and read the _individual_ emails I send, at a rate of _maybe_ half a dozen on a busy day.

As far as I can tell (admittedly largely from the stories of others, as I have basically given up on this myself at this point), there are lots of guides to deliverability of email marketing campaigns, and Google will work with marketers to ensure that their email gets delivered, but for a small non-commercial mailserver without a full-time staff it's not really practical to expect reliable delivery. Which seems sad and backwards to me.

gwillen··on Google illegally spied on workers before firing them, US labor board alleges
I was hired right out of school by Google in 2007. I was absolutely presented with various contract documents on day 1 to sign. In fact, I was not even given paper copies of them; I was supposed to click my agreement in an intranet signing tool.

(I couldn't say what fraction of my employment paperwork was handled in this way, but things like IP assignment were definitely included.)

gwillen··on Face ID and Touch ID for the Web
I'm curious -- do you host your own email, or use a lesser-known email provider?

I am increasingly seeing failures where sites seem to be blackholing outgoing email, I suspect based on the destination domain, and unaware that they are even doing this / extremely insistent that they are not. I've gotten login-email failures like you describe from a couple of sites, and seemingly similar failures from those "email your kid this story" sharing systems on two news sites my mother uses. In all these cases, the messages simply never arrive at the destination SMTP server.

gwillen··on Git Exercises
Regarding problem 2: It's hard to know what exactly you're seeing, but be aware that the output of "git log" is only pretending to be linear; it's really a tree/graph. ("git log --graph" can help, but the output can also be annoying to parse.) So when you see multiple copies of a commit "in a row", chances are that they are really present on different branches which were later merged. If they have the same commit ID, I would probably call this just a display quirk -- there's really only one "copy" in truth, but for some reason the history is confusing "git log". But if they have different commit IDs, that means (as far as I know) that someone has done a "git rebase" or a "git cherry-pick", which you didn't mention in your description.
gwillen··on Tips for immersive video calls
Ahh, but the key problem which leads me to swear and make generalizations is this: Not everyone is an idiot; but idiots don't know they're idiots. (Also, to be clear, I don't think that people who unknowingly transmit background noise on calls are idiots. Clueless, sure. Inconsiderate, sure, if someone's pointed it out and they're still doing it.)
gwillen··on Tips for immersive video calls
Let me summarize my take on the 'don't mute' advice in this article:

* Is the call 1:1 or extremely small? If so, it's down to the preferences of the people in the call. Otherwise, for larger calls:

* Are you in a quiet environment? * That was a trick question. You are not in a quiet environment. You think you are, because your human brain is good at filtering out background noise. Your microphone is not. You are not being forced to actually listen to what your microphone hears. The rest of us are. Mute your fucking microphone!

gwillen··on Zoom towns and the new housing market for the two Americas
> no grocery store

I can't tell if you forgot about Ava's, or if you've never actually _been_ to downtown Mountain View, or if you only consider chain supermarkets to count.

gwillen··on Portable MRI promises to provide immediate diagnosis in virtually any setting
For the curious who want more information, I found a paper discussing the general issues involved in "low-field" MRI:

https://onlinelibrary.wiley.com/doi/full/10.1002/jmri.26637

For their purposes, "low-field" goes down to 0.25T, which is still somewhat higher than the machine linked here, but they extrapolate values of some of the parameters all the way down to 0. (And it seems like the general principles are mostly the same.)

gwillen··on Microsoft Put Off Fixing Zero Day for 2 Years
This is an easy and popular bug to write. The ZIP file format (which is used for JAR files as well), which puts the header at the end, is truly the sin that keeps on giving.

A consequence of this choice is that ANY file concatenated with a ZIP file is a ZIP file (and the same therefore goes for JAR files as well.) So if you concatenate an MSI file with a ZIP/JAR file, your MSI file detector will look at the file and go "yeah, looks good!", and your ZIP/JAR file detector will also say yes. (This also shows off the hazards of automatic filetype sniffing.)

This is related to one of the very oldest Android rooting vulnerabilities. The update.zip files use the signed JAR file format, where the file contains a signature on its own contents. Naturally the signature can't cover the entire file; it only covers the contents referenced by the header.

But the sin-that-keeps-on-giving strikes even harder here: The end-of-file ZIP header also has an end-of-header comment field, of arbitrary size! This means that a single file can actually have MULTIPLE valid ZIP headers. Which means two different tools can interpret the file as two different ZIP files (much as the bug here can interpret the same file as either a ZIP or an MSI.)

Don't do drugs, kids. And don't do automatic filetype detection. And don't do ZIP/JAR files if you can avoid it. And for the love of god, don't put your header at the end.

gwillen··on The Magic of Math in Modern Cryptography [video]
As another commenter mentioned, this is all done modulo some large prime (or, apparently, in some cases, a carefully-chosen composite number with a large prime factor), so 2^y^x=B^x=R=A^y=2^x^y mod p. (Note that mathematicians use "mod" in a notation that is sometimes surprising to programmers. "x = y mod p" means that _both_ x and y are reduced mod p.) The security of this hinges on the difficulty of the "discrete logarithm problem" -- that is, given R = 2^a mod p, it is computationally intractable to find a = log_2(R) mod p (with appropriate parameter choices.)
gwillen··on Walking Dream – single-player adventure game for the Oculus Quest
I will be very curious what the minimum area requirement for the game is. I can't imagine redirected walking being very convincing in the Quest's minimum 6.5 x 6.5 ft square.
gwillen··on Oculus sunsets Go, will add easier Quest app distribution
Sideloaded apps now give multiple scary warnings about the Terms of Service: See e.g. https://www.howtogeek.com/wp-content/uploads/2020/05/4487.pn... .

"May put your account and device at risk" is not going to get you a viable third-party app ecosystem, especially when it's an open question what Facebook/Oculus might decide to clamp down on in the future.

gwillen··on Oculus sunsets Go, will add easier Quest app distribution
Beat Saber is the big hit, which I love; but if you're really into rhythm games I would also take a look at Audica, from Harmonix.

If you are into puzzle-light exploration in a beautiful space, I would highly recommend Fujii as a hidden gem. The only drawback is that it's pretty short.

Not really "content", but if you are interested in productivity apps, Immersed or BigScreen are among the options for streaming your desktop to your headset, depending on what platform you're on. They can also be used for online VR screensharing. (Disclosure: I have a small stake in Immersed.)

The various streaming apps (Netflix, Amazon Prime Video, Youtube, etc.) are not exactly novel, but I like being able to watch stuff without being in front of the computer. (I finally have the screen on the ceiling that I've always wanted.)

gwillen··on A Google Cloud support engineer solves a tough DNS case
My recollection, assuming it's the same machine I'm thinking of, is that it wasn't reserved for our team; rather, we left a do-nothing job permanently allocated to it, in order to prevent some poor other sucker from getting their job scheduled on it. (Because we, through painful experience, were well aware the machine had hardware problems; but we had long since given up on convincing the responsible parties to take it out of the pool, since it passed all their internal tests every time we complained. I don't remember how long this situation existed before someone finally took it out back and shot it.)

Could be a different incident and a different machine, though. I'm sure this story happened more than once.

gwillen··on The Firefox Browser is a privacy nightmare on desktop and mobile
This is a kind of bizarre hitpiece. As noted on the previous post linked below: (1) Chrome -- the far and away most popular alternative -- is worse in every way, and (2) PIA, the company publishing the post, is owned by a (former?) malware purveyor: https://torrentfreak.com/private-internet-access-to-be-acqui...
gwillen··on Tinyland
I am excited to have been one of the pals who helped with this! It's an awesome project.
← PreviousPage 3 of 15Next →