HNHacker News
TopNewBestAskShowJobs

hddqsb

421 karma · joined September 6, 2017

submissionscomments
hddqsb··on Toasts are bad UX
I thought this was going to be about Android (which makes heavy use of that term), and I was expecting completely different complaints:

- The toast disappears quickly, so you might not have time to read it / take a screenshot

- It's not possible to copy the text

- Long text is truncated (e.g. exception messages)

hddqsb··on Wolfram Alpha's math input is broken
There is a serious bug in Wolfram Alpha's "math input" mode. When you enter e²ⁿ, it is interpreted as e²n (full details at the end). This was reported to them a month ago and still hasn't been fixed, so I figured it was time for some public shaming ;)

I've been really impressed with Wolfram Alpha over the years (both the natural language parsing and the power of Mathematica); my main issue until now has been that the natural language parser tends fail on inputs beyond some length (fortunately Mathematica syntax is also supported and works well). So I was very surprised when this glaring bug in math input mode was shared with me.

Full steps to reproduce:

1. Go to https://www.wolframalpha.com/

2. Click "MATH INPUT"

3. Click the "power" button (second from the right, icon is two boxes with one in superscript)

4. Type "e" (it should go in the first box)

5. Click the superscript box

6. Type "2n"

7. Click the "=" button

Result: The input field correctly shows e²ⁿ (with the "n" in superscript), but the formula shown in the "Input" section is e²n (the "n" is outside the exponent) and the "Plot" section shows a straight line which confirms that the input was misinterpreted as e² * n.

Explicitly adding parentheses around the "2n" fixes this. Ironically, when you do that the "Input" section shows the formula as e²ⁿ (without the parentheses; the same version that fails when entered in the input field).

hddqsb··on The new PostgreSQL 17 make dist
Docker & co. also let you create a clean build environment (to a lesser extent), and I find them less intrusive than Nix / Guix.
hddqsb··on ps aux written in bash without forking
Fix:

  ps() { for i in /proc/[0-9]*; do readarray -d '' -t cmdline < "$i/cmdline"; printf "%s: %s\n" "${i#/proc/}" "${cmdline[*]}"; done; }
hddqsb··on Ask HN: Fast data structures for disjoint intervals?
A little late to the party...

> The slow cases usually tend to be trying to find wider slots and skipping through many smaller slots. There are often a lot of bookings up to the first wide enough slot too though, so it's a little bit of both.

This right here is the first critical issue. It doesn't matter how fast the data structure is if you're then going to do a linear search over the available slots to find the next one wide enough.

A good data structure for doing this efficiently is a range tree (https://en.wikipedia.org/wiki/Range_tree), where in each node you store the maximum width of the available slots covered by the node. That lets you find the first available slot after some time t and wider than some duration w in O(log(n)), where n is the number of available slots. (It might not be obvious if you're not familiar with range trees; I'm happy to provide more details.)

For the implementation, there are a few options:

A. The simplest is to use a complete range tree, where the leaf nodes are all the possible times. You can lazily create nodes to avoid massive memory usage for sparse ranges. The advantage is that you don't need to do any balancing; the disadvantage is that the time complexity is O(long(T)) where T is the total number of possible times; so it's going to be a little slower on very sparse datasets.

B. The O(log(n)) implementation that's being called for is a self-balancing binary tree (e.g. red-black), modified to also store the maximums in each node. Unfortunately most libraries don't give you low-level control over the tree's nodes, so you'd likely need to copy the code and modify it (or implement the self-balancing tree from scratch).

C. If those are still too slow (and you're certain that your implementation is really O(log(n))), you'll need to improve the cache efficiency. That basically comes down to using larger nodes. The obvious approach is to switch to a B-tree; but you could also keep your nodes binary and just change the way they are allocated to emulate the memory layout of a B-tree (this is simpler but slower because it still uses lots of pointers). Another idea is to replace the first few layers of the tree with a hash table (or a simple array if your data is dense enough). Likewise you can replace the leaf nodes with small arrays.

hddqsb··on Spanish High Court banned Telegram
The article's actual title is "High Court orders temporary suspension of Telegram's services in Spain", not "Spanish High Court banned Telegram".

This is a temporary suspension while investigating "after media companies complained it was allowing users to upload their content without permission".

hddqsb··on Basic proxy implementation using io_uring
Great sleuthing, the missing piece of the puzzle is that the file contents are inside a <code> element while the line numbers are not, and <code> elements have a default font so they don't inherit the font from their parent element. Changing the selector to the following fixes the issue:

  div#cgit pre, div#cgit code { ... }
(The buggy CSS is not present in the the official cgit repository, so I assume the owner of kernel.dk is running a patched version of cgit.)
hddqsb··on SSH3: SSHv2 using HTTP/3 and QUIC
There is now an open issue: https://github.com/francoismichel/ssh3/issues/79
hddqsb··on SSH over HTTPS
In fact the article mentions a tool for this (sslh), but rejects it because it hides the source IP from the HTTP backend (and other reasons).
hddqsb··on SSH over HTTPS
In the case of SSH, there is a single connection (in fact SSH implements its own multiplexing), so I don't see the advantage of HTTP/2.
hddqsb··on Xmas.c (1988)
I agree. Stack Exchange's Code Golf has public source, but the best there is 644 bytes: https://codegolf.stackexchange.com/a/4198
hddqsb··on SSH over HTTPS
Yes, that's likely to work on many firewalls, but:

- it means you can't also serve HTTP on those ports (so you'd need a dedicated IP address for SSH), and

- as @charcircuit wrote, it won't resist deep packet inspection.

(But if DPI is a problem and you have a spare IP address, you could just use SSH over TLS without needing the HTTP CONNECT stuff and Apache.)

hddqsb··on Nvidia sued for stealing trade secrets: blunder showed rival company's code
This article is not about graphics drivers. The project in question is "advanced parking and driving assistance technology".
hddqsb··on Sopwith – a classic bi-plane shoot 'em up from 1984 in the browser
Tip: If pull up/down feel backward to you when the plane is flipped, go into the options and enable "Harry keys mode" :)
hddqsb··on I analyzed Stack Overflow for secrets
Yep. The relevant parts from the article:

> ... I run a simple scan ... against all the 74 real looking GitHub user tokens ... and discovered that 6 of them are actually valid.

> ... only 2 of them actually have bio and email, but one of them (a c/c++ developer) has a repo with 3.4k stars ...

> I obviously couldn’t verify all the secrets. From most of them I’ll probably be banned, so I stooped here.

As an alternative to manually testing the credentials (and risking bans), I wonder if any organisations would agree to test the credentials for you if you sent them a list of suspected leaks. If the organisation doesn't tell you which ones were valid (and takes responsibility for revoking/notifying), I don't see much room for abuse. Might be hard to convince the organisation of that though!

hddqsb··on De-crufted Windows 11 coming to Europe soon
A clever person got that account banned. When you try logging in with that email and a random password, it will fail, and Windows will allow you create a local account. (ref: https://news.ycombinator.com/item?id=37179504, https://news.ycombinator.com/item?id=33049235).
hddqsb··on Setenv Is Not Thread Safe and C Doesn't Want to Fix It
It is perfectly reasonable and consistent for one thread to set an environment variable while other threads are reading different environment variables.
hddqsb··on Setenv Is Not Thread Safe and C Doesn't Want to Fix It
Sure, some applications might require custom higher-level synchronisation, but it's still important for getenv/setenv to be thread-safe (i.e. not crash):

- The race might be irrelevant (e.g. simultaneous calls that access different variables are fine).

- The application author might not have complete control over all calls to getenv/setenv (e.g. if using a third-party library).

hddqsb··on Debugging tricks in the browser
In Chrome you can inspect your closure (as you clarified in https://news.ycombinator.com/item?id=38226743#38231705) using the "Watch" pane, and then look at its "[[Scopes]]" pseudo-property. I don't think there is a way in Firefox.
hddqsb··on Base64 Encoding, Explained
> printf can also replace a lot of uses of the "date" command

Very cool (but bash-specific). Manual: https://www.gnu.org/software/bash/manual/bash.html#index-pri...

> sh /bin/echo -n "test"

This is gibberish -- it's trying to execute /bin/echo as if it was a shell script. Maybe you meant:

  sh -c '/bin/echo -n "test"'
hddqsb··on I, Voyager: Open-Source Software Planetarium
EDIT:

- They do have several non-spherical moons and asteroids (bottom left), which is awesome. I tried finding a 3D model of Charon online; NASA's model (https://science.nasa.gov/resource/charon-3d-model/) is disappointingly spherical, on the other hand https://3d-asteroids.space/moons/P1-Charon has a satisfyingly bumpy surface (for half of Charon).

- Fixing the zoom direction is almost within reach -- there is an option "Mouse Rate: In/Out" which defaults to 1 and can be used to slow down / speed up zooming, unfortunately it won't let me set it to a negative value to flip the direction.

hddqsb··on I, Voyager: Open-Source Software Planetarium
Very cool. Some small criticism/feedback:

- Pluto is shown as if it is spinning around itself, but in reality Charon (its largest moon) is so heavy (12.2% of Pluto) that their barycentre (https://en.wikipedia.org/wiki/Barycenter_(astronomy)) is actually outside of Pluto's surface.

- All the planets and moons are shown as perfectly spherical, but for the smaller ones (e.g. Charon) that's not accurate. Not sure if there is a practical way to fix this though.

- Zooming using the scrollwheel is backwards -- rolling the scroll wheel up zooms out, but in all other applications on my system it zooms in.

- The panels are very annoying. They can be hidden by unticking in the top right corner, but they still come back on mouseover (getting in the way when trying to click on a planet). I can't find a way to completely close them; they can be moved around, but they refuse to go offscreen. "Options > GUI Size> Small" helps a little.

hddqsb··on In search of the least viewed article on Wikipedia (2022)
It's not a big deal because there is no need to retry 20 times. The probability of getting a deleted article several times in a row is very low, so you could limit to e.g. 5 tries, and if all are deleted fall back to the next non-deleted article (or even a hard-coded article). The bias would be negligible assuming the proportion of deleted articles is low; to guarantee that it is low, one can periodically renumber to eliminated deleted articles (this can be done efficiently using the trick suggested by @munificent; but the naive O(n) approach would probably be good enough).
hddqsb··on Getaddrinfo() on glibc calls getenv(), oh boy
For the curious: They make getenv() thread-safe by intentionally leaking the old environment, which they argue is acceptable because the memory leak is bounded to 3x the space actually needed.

The getenv/setenv/putenv/environ API looks terrible on closer inspection -- it does not appear possible for an implementation to be safe, leak-free, and efficient.

hddqsb··on Getaddrinfo() on glibc calls getenv(), oh boy
Good point about `putenv()`; however there is also `setenv()`, which does make a copy, so you are wrong about `getenv()` in general.

POSIX explicitly states "The string [returned by getenv] may be overwritten by a subsequent call to getenv(), setenv(), unsetenv(), or putenv()" (https://pubs.opengroup.org/onlinepubs/9699919799.2008edition...).

hddqsb··on Fair coins tend to land on the same side they started
@robocat linked a great video showing how to do this: https://m.youtube.com/watch?v=A-L7KOjyDrE
hddqsb··on Python 3.12
You have a minor bug -- when len(lst) is a multiple of batch_size, this will have an extra iteration at the end with an empty batch. The fixed version is `range((len(lst) + batch_size - 1) // batch_size)`, which emulates `ceil(len(lst) / batch_size)`. Yet more proof that this should be part of stdlib :)

Personally I think I'd actually write it like this:

    for i in range(0, len(lst), batch_size):
        batch = lst[i:i+batch_size]
The docs give another pretty nice implementation using iter() and islice() in a loop (but it uses the walrus operator `:=` so it requires Python 3.8+ as written).
hddqsb··on Fake recruiter lured aerospace employee with trojanized coding challenge
The attackers didn't even use a trojan project/source. They just sent a malicious .exe (wrapped in an .iso file) and asked the victim to run it and write a C++ program that produces the same output.
hddqsb··on FreeRDP: A remote desktop protocol implementation
I'm also curious about this; I don't know how secure the traditional native clients are (FreeRDP, Vinagre, Remmina, etc.).

On the other hand, there are browser-based clients such as Apache Guacamole and noVNC, which are protected by the browser's security sandbox. They require a server component, but that can be run in a sandbox or on the untrusted server. There are some limitations to running in a browser (e.g. some keyboard shortcuts might not be forwarded).

hddqsb··on PID Control Challenges
It's robust. I hamstrung the model solution by forcing pistonAcceleration to be 0, and forcing hingeAcceleration to be 0 during the first second, but it still "caught" and balanced the ball.
Page 1 of 8Next →