HNHacker News
TopNewBestAskShowJobs

haswell

11,485 karma · joined April 30, 2013

Nerd. Photographer. Writer. Reverse engineer. Developer. Tinkerer.

Professionally, I build software, but I'm currently on sabbatical while I pivot to something...different.

Consequentialist-ish currently worried about the state of tech and its impact on me and the people around me. I'm spending my time trying to do something useful about it, mostly focused on personal habit change.

Contact me at haswell_hn [at] protonmail.com

submissionscomments
haswell··on Doctors are finally learning to manage antidepressant withdrawal
Yeah, this is exactly why I couldn’t stay on it. I already deal with GAD and OCD, and whatever benefits it had for the depression were directly counteracted by the return of acute anxiety.

It was truly hellish. Feeling like I had this energy that I needed to use, while also feeling so anxious that I didn’t want to leave the apartment.

I know it works really well for some people but I was definitely not one of them.

haswell··on We Are Forking dotenvy into dotenv-ng
.env is self sustaining at this point. The functionality described in the post exists to help move people off of it. It’ll have a better chance of dying when fewer people use it and that starts with making it easy to move away from it.
haswell··on RustDesk now supports true unattended remote access on Wayland
SQLite is still the default backend. Postgres is optional.
haswell··on “Code was never the hard part” is an insult to all programmers
About halfway through my career, I spent about 10 years working in the enterprise SaaS/PaaS space. 6 as a developer, ~4 as a product manager. Both sides of that coin are difficult. Trying to create a product strategy that meets the needs of hundreds of large companies is a special kind of hell. And on the dev side, even "simple" things are not simple when they have to be implemented at scale, software updates cannot break existing customer code/configurations, and customers must have a hundreds knobs and dials and scripted escape hatches to implement their own business logic.

Even when code was not the hardest problem, it was still a hard problem.

haswell··on The Nixpkgs core team has disbanded
> “Rebuild everything in one command and have it work” is not something that I’m chasing after and I am skeptical that it would work anyway.

I'm not using "rebuild" to describe recreating an instance from scratch, but in the "nixos-rebuild" sense, i.e. I can deploy a fleet-wide configuration shared by all hosts, or apply package updates across the fleet, etc.

As for the skepticism, all I can offer is my experience which is that it does indeed work, and I've been running this way for awhile.

> Maybe there is something I’m missing, but when I update the software, the updates come with changes and it’s possible that things break.

The only time I've had breaking changes that required manual intervention was on a major release update. The issue amounted to "You're using abc configuration option but should be using xyz instead". This message was clearly logged, and fixing it was a matter of a few minutes of reading why a particular property name had changed.

Those updates happen twice/year, and in the last ~3 years I think two packages have forced me to make a change. Unless you're running unstable, you won't encounter this for ongoing package updates within a release.

On the topic of rebuilding from scratch, that's not a single command, but it's only a few. VMs/containers mount incus volumes (zfs-backed) for data storage, and a fresh rebuild is a matter of spawning a new instance from my homelab base image (I use OpenTofu to orchestrate this), running a nixos-rebuild targeting the new instance from my workstation, and things are back up and running. But I'm less focused on full rebuilds since I'm already doing Incus backups and can restore on any of the nodes in my Incus cluster.

> My goals are to keep reasonably up to date and to be able to fix things quickly if they do break.

My goals are similar. I can completely understand sticking with Debian for two hosts. I had experimented with NixOS for years but never really went all-in until I started expanding my homelab environment. At that point, NixOS just clicked and I'm far more productive with 30+ hosts than I used to be with 1-2.

> Package maintenance is kind of a crapshoot. Maybe your package is in nixpkgs, maybe there is a flake for it, maybe...

Which channel were you running on? And do you have any examples of specific packages? What you're describing just sounds foreign to me. I currently default to the latest stable release but if there's something that isn't in stable I'll override that specific package to use unstable. Much of the community just runs everything on unstable, but I prefer a slightly slower pace of updates.

Nixpkgs is the largest package repository across distros by volume, and as much as I love Debian, it's far more common to find things missing there.

> Maybe there is a package but half the features are turned off on macOS for unknown reasons

This sounds like you're branching into territory that can no longer be reasonably framed as NixOS vs. Debian (or other distro of choice).

> Docs are just kinda bad.

This is by far the project's greatest weakness. LLMs have been the saving grace. The frontier models are excellent at NixOS and I've switched to mostly having a conversation in my NixOS Claude project when I need info. This is in no way a defense of the docs, but for anyone motivated to use NixOS, there is at least a good option beyond the docs themselves.

haswell··on The Nixpkgs core team has disbanded
Not OP, I’m not really sure what your specific complaints are based on the original comment. They seemed more like general/nonspecific concerns, which left the comment pretty open to interpretation.
haswell··on The Nixpkgs core team has disbanded
Can you share more about what made you move away?

I’ve been running a NixOS based homelab for awhile now with 5 physical hosts and about 30 NixOS containers/VMs in an Incus cluster and I can’t imagine moving away from my central Nix repo and ability to rebuild/upgrade the entire fleet in one command and feel confident that things will work.

While I’m concerned about the disbanding, it would take quite a lot to make me look elsewhere, and there’s enough critical mass that I feel confident others will step up.

haswell··on Prairieland defendants sentenced today to prison terms ranging from 30-100 years
Surely not 30 years bad.
haswell··on How many of the 170k English words do you know?
If you gave up at 50, that means you skipped the difficult words.
haswell··on Artificial intelligence is not conscious – Ted Chiang
Ahh, makes sense.
haswell··on Artificial intelligence is not conscious – Ted Chiang
> un-constrained frontier models speak as if they strongly don't wish to be turned off

Un-constrained frontier models can also generate all sorts of creative stories. At what point should we start ascribing agency/intent to the output? I think the "I want to live" statement is so deeply human that we find it hard to ignore, but what makes the text generated in those moments any more attributable to a conscious entity than the text generated when it is confabulating its love for someone it has no ability to see/feel/understand?

A chess engine sacrificing pieces to avoid checkmate isn't afraid of losing in any meaningful sense. I guess the question is: is there a point where complexity somehow becomes experience?

I think we're playing with questions we don't have a framework to answer in any meaningful way until we make progress on understanding what consciousness actually is. I don't necessarily think that an LLM exhibiting preservation behaviors that can be directly traced to their goal-oriented programming can be interpreted as evidence of consciousness necessarily. Or if it can be, we then have to explain how this is different from the many other things these LLMs "say".

haswell··on Artificial intelligence is not conscious – Ted Chiang
I'm not really following your logic here.

I'm not arguing against the idea that consciousness is a spectrum. If anything, I'm agreeing. I'm just pointing out that if AI is somewhere on that spectrum, there is almost certainly a lot more on that spectrum than we're currently discussing as a species.

I have to point out the irony of the categorical nature of your claim about categorical thinking ;)

haswell··on Artificial intelligence is not conscious – Ted Chiang
Fair, but I still think we're discussing slightly different things. I'm not arguing that "maybe AI is conscious" is absurd.
haswell··on Artificial intelligence is not conscious – Ted Chiang
I understand what you're getting at, but I think you may be misinterpreting me slightly.

I'm not outright dismissing the possibility that AI could be conscious; I'm saying that if we take the possibility that it is seriously, the conversation has to expand beyond AI. I'm not using this argument to conclude that it must therefore be absurd that AI could be conscious, just pointing out that the implications of AI being conscious would reach far beyond just AI. I'm mostly curious if people who find themselves comfortable with the idea that AI might be conscious also find themselves comfortable with the idea that other sufficiently complex systems might be.

Taylor's work was based on the premise that he found it absurd that women deserve the same rights as men. If my conclusion was: "I find it absurd that other things might be conscious, so it is also absurd that AI might be conscious", I think the comparison would be fair. But that's not what I'm getting at.

haswell··on Artificial intelligence is not conscious – Ted Chiang
But what kind of complexity is that? And why would we conclude that AI has it while other incredibly complex systems (e.g. earth’s habitats, the universe itself) does not?

I’m far more open to the idea that many systems are conscious than the idea that this current generation of LLMs is somehow special.

haswell··on Artificial intelligence is not conscious – Ted Chiang
Could be! I think the broader thought experiment is about examining why we think LLMs specifically might be conscious vs other complex systems, even if it is a spectrum.

For example, there’s a case to be made that the ecosystem we collectively exist in is far more complex than the largest LLM, but it’s currently less popular to debate “is the earth conscious?” or “is the universe conscious”, presumable because we can’t speak to those systems in human language.

I’m trying to tease out what I think is the likelihood that we tend to ascribe consciousness to AI for the same reasons we see faces in clouds. We’re biologically conditioned to recognize patterns that indicate “like us”, but I think a number of thought experiments point to either a) there’s no reason to believe AI is “conscious” or b) the conversation has to to be expanded beyond AI.

haswell··on Artificial intelligence is not conscious – Ted Chiang
If there's any reason to take seriously the idea that AI is conscious, we must then take seriously the idea that many other non-living things are conscious.

Unless the argument is that consciousness is an emergent property of complexity or information density, why would AI be any more or less conscious than my toaster?

It seems to me that it's far more likely that everything is conscious than it is that AI is somehow uniquely more conscious than other things.

haswell··on Artificial intelligence is not conscious – Ted Chiang
> So, if we had an AI demonstrating symptoms of consciousness and suffering, how long would it take for you to accept that it is?

Isn't this a bit like saying "So, if we had proof that god exists, how long would it take for you to accept that to be true?".

When we have evidence that AI is demonstrating symptoms of consciousness and suffering, I'll be interested. Until then, I don't see a good reason to take the idea seriously.

haswell··on Artificial intelligence is not conscious – Ted Chiang
This is anthropomorphizing a concept that is quite unrelated to the meaning of the word in the human context.

When a car runs out of gas, it's out of gas. It's not "tired". When your phone battery is low, your phone is not "tired". These states are far closer to the human meaning of tired than an LLM operating at the edges of its usable context, and we still don't use the word tired to describe them.

haswell··on Louis Rossmann offers to pay legal fees for a threatened OrcaSlicer developer
Have you set up Tailscale and have you set up OpenVPN from scratch? Because these two things are not alike. That’s why I’m pushing back a bit.

I find it difficult to imagine equating a raspberry pi in a closet with “running a server”. Is it technically a server? Sure. But it’s not as if we’re talking about running a power hungry rack.

Bottom line is: there are very cheap and simple/easy options for maintaining a private connection to your home stuff.

> and figure out all the networking bits that will get it to talk to the printer

With something like Tailscale this is already figured out. My mostly non technical brother does this without issues.

This is entirely separate from whether or not you should need to do so for Bambu printers, which again I agree the answer is ideally “no”.

haswell··on Louis Rossmann offers to pay legal fees for a threatened OrcaSlicer developer
On the one hand, I agree with a lot of what you’re saying here.

With that said, I don’t think it’s reasonable to describe setting up Tailscale as similar to “Linux server that runs 24/7 with OpenVPN and iptables”. Sure, you could go that route, but a Tailscale setup is extremely simple and lightweight. A raspberry pi is plenty if there isn’t already a system running 24/7. I personally have this set up on my router.

I point this out while still sharing the general sentiment of negativity towards Bambu here.

haswell··on LittleSnitch for Linux
I've used OpenSnitch for years, and while LittleSnitch definitely has a better UI for showing which process is making which connections over time, OpenSnitch does a pretty good job here. I get a modal popup when a program that hasn't made a connection tries to make a connection, and I can either allow/deny in one click, or further customize the rule e.g. allowing ntpd to connect, but only to pool.ntp.org on port 123.

Where LittleSnitch is definitely ahead is showing process connections over time after said process has been allowed.

haswell··on Show HN: Stop paying for Dropbox/Google Drive, use your own S3 bucket instead
There are plenty of reasons to criticize OneDrive and I personally would not use it. But I think comparing it with a weekend vibe coded self hosted project is a bit of a stretch.
haswell··on Show HN: Stop paying for Dropbox/Google Drive, use your own S3 bucket instead
What experience?
haswell··on LinkedIn is searching your browser extensions
Calling out the fingerprinting of extensions is appropriate and can be achieved without hyperbole.

As I’ve stated clearly throughout this thread, the fingerprinting they’re doing is a problem.

Calling it “searching your computer” is also a problem.

> Defending that action is

Nowhere have I defended what LinkedIn is doing.

haswell··on LinkedIn is searching your browser extensions
So are fonts. But running Window.queryLocalFonts() is not equivalent to “illegally searching your computer”.

I’m not defending the act of scanning for these extensions, and I’m of the opinion that such an API shouldn’t even exist, but just pointing out that there are perfectly legitimate APIs that reveal information that could be framed as “files installed on your computer” that are clearly not “searching your computer” like the title implies.

haswell··on LinkedIn is illegally searching your computer
> If you scanned LinkedIn's private network, you'd be criminally charged. Why are they allowed to scan yours with impunity? And why is this being normalized?

First, I think it’s a major issue that Chrome is allowing websites to check for installed extensions.

With that said, scanning LinkedIn’s private network is not analogous to what is going on here. As problematic as it is, they’re getting information isolated to the browser itself and are not crossing the boundary to the rest of the OS much less the rest of the internal network.

Problematic for privacy? Yes. Should be locked down? Yes. But also surprisingly similar to other APIs that provide information like screen resolution, installed fonts, etc. Calling those APIs is not illegal. I’m curious to know what the technical legal ramifications are of calling these extension APIs.

haswell··on LinkedIn is searching your browser extensions
> The gathering not being targeted is not an excuse for gathering the data in the first place.

I’m not saying it is. My point is that they appear to be trying to accomplish something like getInstalledExcentions(), which is meaningfully different from a small and targeted list like isInstalled([“Indeed.com”, “DailyBibleVerse”, “ADHD Helper”]).

One could be reasonably interpreted as targeting specific kinds of users. What they’re actually doing to your point looks more like a naive implementation of a fingerprinting strategy that uses installed extensions as one set of indicators.

Both are problematic. I’m not arguing in favor of invasive fingerprinting. But what one might infer about the intent of one vs. the other is quite different, and I think that matters.

Here are two paragraphs that illustrate my point:

> “Microsoft reduces malicious traffic to their websites by employing an anti-bot/anti-abuse system that builds a browser fingerprint consisting of <n> categories of identifiers, including Browser/OS version, installed fonts, screen resolution, installed extensions, etc. and using that fingerprint to ban known offenders. While this approach is effective, it raises major privacy concerns due to the amount of information collected during the fingerprinting process and the risk that this data could be misused to profile users”.

vs.

> “Microsoft secretly scans every user’s computer software to determine if they’re a Christian or Muslim, have learning disabilities, are looking for jobs, are working for a competitor, etc.”

The second paragraph is what the article is effectively communicating, when in reality the first paragraph is almost certainly closer to the truth.

The implications inherent to the first paragraph are still critical and a discussion should be had about them. Collecting that much data is still a major privacy issue and makes it possible for bad things to happen.

But I would maintain that it is hyperbole and alarmism to present the information in the form of the second paragraph. And by calling this alarmism I’m not saying there isn’t a valid alarm to raise. But it’s important not to pull the fire alarm when there’s a tornado inbound.

haswell··on LinkedIn is searching your browser extensions
> I also think that most people would interpret "Getting a full list of all the Chrome extensions you have installed" as a meaningful escape/violation of the browser's privacy sandbox

I think that’s a far more reasonable framing of the issue.

> I don't think describing it as something everybody would expect is totally fine and normal for browsers to allow is correct.

I agree that most people would not expect their extensions to be visible. I agree that browsers shouldn’t allow this. I, and most privacy/security focused people I know have been sounding the alarm about Chrome itself as unsafe if you care about privacy for awhile now.

This is still a drastically different thing than what the title implies.

haswell··on LinkedIn is searching your browser extensions
I do think a degree of alarm is appropriate.

But it’s critical to sound the correct alarm.

To me, it seems like the authors pulled the fire alarm for a single building when in reality there’s a tornado bearing down.

And by doing so, everyone is scrambling about a fire instead of the response a tornado siren would cause.

They’re both dangerous and worthy of an immediate reaction, but the confusion and misdirection this causes seems deeply problematic.

When people realize the fire wasn’t real, they start to question the validity of the alarm. The tornado is still out there.

I realize this analogy is a bit stretched.

As someone who has spent quite a lot of time steeped in security/privacy research, the stuff described in the article has been happening pervasively across the industry.

People absolutely should be alarmed. Many of us have been alarmed for quite some time. Raising the alarm by saying “LinkedIn is searching your computer” isn’t it.

Page 1 of 34Next →