HNHacker News
TopNewBestAskShowJobs

iam-TJ

1,507 karma · joined February 23, 2016

submissionscomments
iam-TJ··on Owners mourn spoiled food after firmware update bricks Samsung smart fridges
Thank-you that link - it is very interesting. The cause I wonder about is another A.I. agent attack.
iam-TJ··on Claude Code reads AGENTS.md only when telemetry is on [fixed]
I think the various recent articles about agent output using ASD-STE100 Simplified Technical English are quite pertinent here. For example:

"Agent Skill to Force Docs in ASD-STE100 Simplified Technical English"

https://news.ycombinator.com/item?id=49114639

iam-TJ··on UK households free to install plug-in balcony solar panels from end of August
It's important to also know that the U.K. has recently mandated that all new build residential buildings (houses and apartment buildings) must have some form of on-site renewable electricity generation system (typically expected to be solar) from 2027.

This requirement was added to the "Future Homes and Builds Standards" early in 2026 [0] and the regulation is described in section 7.1(b) [1] of the regulations that says "On-site electricity generation systems must be commissioned to ensure that they produce as much electricity as is reasonable in the circumstances".

"reasonable" here means 'considering roof-space' or 'yard space' and could be implemented using solar, wind, or possibly water (if you live in a former water-mill!).

[0] https://www.gov.uk/government/publications/the-future-homes-...

[1] https://assets.publishing.service.gov.uk/media/69c122a6cfa34...

iam-TJ··on AWS: Inaccurate Estimated Billing Data – $1.7 billion
The best bit of that is:

> In this role, you will own end-to-end bill run execution across all AWS partitions, drive the technical vision for autonomous billing operations, and build the team that ensures every customer receives an accurate cost estimated in minutes ...

iam-TJ··on Strange Balls found on Queensland beaches could be toxic 'space debris': experts
Most likely Hydrazine propellant tanks:

https://www.space-propulsion.com/spacecraft-propulsion/hydra...

iam-TJ··on Multiple Linux tarballs return 404 on kernel.org
The current recovery status:

https://status.linuxfoundation.org/incidents/3y1k8b4ky71t

iam-TJ··on [dead]
The full comment:

“Biological limits are real, but digital potential is infinite. If we starve our data infrastructure of cooling resources just to sustain baseline human comfort, we are actively delaying the birth of a super-intelligence that could solve all of our resource problems in the first place. Sometimes you have to prioritize the intelligence that will save us over the biology that slows us down.”

As someone spending time daily irrigating food crops I think it's time he was buried head-first in the Sahara desert for a week!

Context: A keynote panel on June 17th at VivaTech 2026 in Paris.

iam-TJ··on The Token Compression Illusion: Why I'm Skeptical of RTK
Am I the only one that thought RTK was Real-Time Kinematics used for precision with satellite navigation?
iam-TJ··on TIL: You can make HTTP requests without curl using Bash /dev/TCP
Need to be clear that "full http server in pure bash" is incorrect. Bash cannot listen on a TCP/UDP socket for incoming connections.

bash-web-server project builds a C language socket listener [0] that is dynamically loaded at run-time as a "built-in" module that makes the functionality available.

[0] https://github.com/bahamas10/bash-web-server/tree/main/loada...

iam-TJ··on Love systemd timers

  $ systemctl cat public-inbox-watch@.timer
  # /etc/systemd/system/public-inbox-watch@.timer
  [Unit]
  Description=Periodic fetch of public mailing list

  [Timer]
  # twice a day
  OnCalendar=*-*-* 5,17:35
  RandomizedDelaySec=1h
  Persistent=true

  [Install]
  WantedBy=multi-user.target
iam-TJ··on Identify a London Underground Line just by listening to it
This should become a new round to compliment Mornington Crescent [0] on the BBC Radio programme I'm Sorry I Haven't A Clue [1]

[0] https://en.wikipedia.org/wiki/Mornington_Crescent_(game)

[1] https://en.wikipedia.org/wiki/I%27m_Sorry_I_Haven%27t_a_Clue

iam-TJ··on What changes when you turn a Linux box into a router
"So you can’t transparently bridge Ethernet devices’ MAC addresses through a WiFi client interface. This is why we need hostapd."

I think that is incorrect. hostapd handles the authentication side of things, but 4addr tuples are controlled by 'struct wireless_dev.use_4addr', and can be set by 'ip link set type bridge_slave ... proxy_arp_wifi on', `iw dev ... 4addr on', and if using systemd-networkd, with slave interface's

  [Bridge]
  ProxyARPWiFi=yes
(and networkd doesn't need hostapd's bridge= option since networkd handles that aspect.)

Kernel then uses NL80211_IFTYPE_AP_VLAN and handles the proxy operation.

iam-TJ··on Mobile carriers can get your GPS location
Barclays, with standard current accounts, provides several methods none of which are SMS. There's a separate pin-code device (called Pinsentry) that does TOTP and challenge-response, or passcodes for both telephone and Internet banking.
iam-TJ··on JPEG XL Test Page
Firefox Nightly v149 has added experimental support via Settings > Firefox Labs:

  Webpage Display
  Media: JPEG XL
  With this feature enabled, Nightly supports the JPEG XL (JXL) format. This is an enhanced image file format that supports lossless transition from traditional JPEG files. See bug 1539075 for more details.
iam-TJ··on I replaced Windows with Linux and everything's going great
"refused to load whatever distro I tried from SSD" sounds very much like a feature in AMI InsydeH2O firmware (and possibly others) where-by one has to manually "trust" the boot-loader file the boot menu entry points to. This doesn't seem to apply to Microsoft Windows boot loaders so I've always assumed the signing certificate is checked directly against the MS UEFI CA root rather than the intermediate 3rd party certificate that is used by Microsoft to sign distro shim files.

I have kept a screenshot of the firmware setup for years to remind me where the option can be found; looking at it now:

menu: Security > "Select UEFI file as trusted"

That would bring up a file-chooser where one can navigate the files in the EFI System Partition and select the distro's initial boot-loader file. For example, for a Debian install it would either or both of:

/EFI/debian/shimx64.efi /EFI/debian/grubx64.efi

iam-TJ··on Imgur geo-blocked the UK, so I geo-unblocked my network
Two devices I use - both running Debian, and both being open-source hardware to some degree or other:

PC Engines APU2, AMD x86_64, 4-core, 4GiB, 3x Gigabit Ethernet, 3 x mini PCIe, SIM slot, USB 3, Serial, SATA ports. Mine has dual band WiFi in one mPCIe, SSD in another.

Turris Mox, Marvel aarch64. This can expand via plug and go via a range of extension modules. I've got one with 25 Gigabit (3 x 8-port modules) Ethernet, 1 x SFP, 5 x USB3, Wifi, Serial.

iam-TJ··on Messing with scraper bots
This reminds me of a recent discussion about using a tarpit for A.I. and other scrapers. I've kept a tab alive with a reference to a neat tool and approach called Nepenthes that VERY SLOWLY drip feeds endless generated data into the connection. I've not had an opportunity to experiment with it as yet:

https://zadzmo.org/code/nepenthes/

iam-TJ··on Ask HN: Does anyone have scans of these missing PC Plus issues (1991–1993)?
Have you checked out the The National Museum of Computing (TNMoC) archive. Last time I was there they had a rather good magazine collection going back to the early 1980s. It may be worth a call. I see they have an (incomplete) online catalogue:

https://www.tnmoc.org/library-archive

iam-TJ··on Fast and cheap bulk storage: using LVM to cache HDDs on SSDs
When using LVM one can use the dm-integrity target to detect data corruption.
iam-TJ··on Fast and cheap bulk storage: using LVM to cache HDDs on SSDs
When using LVM there is no need to use separate mdadm (MD) based RAID - just use LVM's own RAID support.

I have a workstation with four storage devices; two 512GB SSDs, one 1GB SSD, and one 3TB HDD. I use LUKS/dm_crypt for Full Disk Encryption (FDE) of the OS and most data volumes but two of the SSDs and the volumes they hold are unencrypted. These are for caching or public and ephemeral data that can easily be replaced: source-code of public projects, build products, experimental and temporary OS/VM images, and the like.

  dmsetup ls | wc -l 
reports 100 device-mapper Logical Volumes (LV). However only 30 are volumes exposing file-systems or OS images according to:

  ls -1 /dev/mapper/${VG}-* | grep -E "${VG}-[^_]+$" | wc -l
The other 70 are LVM raid1 mirrors, writecache, crypt or other target-type volumes.

This arrangement allows me to choose caching, raid, and any other device-mapper target combinations on a per-LV basis. I divide the file-system hierarchy into multiple mounted LVs and each is tailored to its usage, so I can choose both device-mapper options and file-system type. For example, /var/lib/machines/ is a LV with BTRFS to work with systemd-nspawn/machined so I have a base OS sub-volume and then various per-application snapshots based on it, whereas /home/ is RAID 1 mirror over multiple devices and /etc/ is also a RAID 1 mirror.

The RAID 1 mirrors can be easily backed-up to remote hosts using iSCSI block devices. Simply add the iSCSI volume to the mirror as an additional member, allow it to sync 100%, and then remove it from the mirror (one just needs to be aware of and minimising open files when doing so - syncing on start-up or shutdown when users are logged out is a useful strategy or from the startup or shutdown initrd).

Doing it this way rather than as file backups means in the event of disaster I can recover immediately on another PC simply by creating an LV RAID 1 with the iSCSI volume, adding local member volumes, letting the local volumes sync, then removing the iSCSI volume.

I initially allocate a minimum of space to each volume. If a volume gets close to capacity - or runs out - I simply do a live resize using e.g:

  lvextend --resizefs --size +32G ${VG}/${LV}
or, if I want to direct it to use a specific Physical Volume (PV) for the new space:

    lvextend --resizefs --size +32G ${VG}/${LV} ${PV}
One has to be aware that --resizefs uses 'fsadmn' and only supports a limited set of file-systems (ext*, ReiserFS and XFS) so if using BTRFS or others their own resize operations are required, e.g:

  btrfs filesystem resize max /srv/NAS/${VG}/${LV}
iam-TJ··on Synology Lost the Plot with Hard Drive Locking Move
To expand on this with an example. Adding a new device we'll call sdz to an existing Logical Volume Manager (LVM) Volume Group (VG) called "NAS" such that all the space on sdz is instantly available for adding to any Logical Volume (LV):

  pvcreate /dev/sdz
  vgextend NAS /dev/sdz
Now we want to add additional space to an existing LV "backup":

  lvextend --size +128G --resizefs NAS/backup
*note: --resizefs only works for file-systems supported by 'fsadmn' - its man-page says:

"fsadm utility checks or resizes the filesystem on a device (can be also dm-crypt encrypted device). It tries to use the same API for ext2, ext3, ext4, ReiserFS and XFS filesystem."

If using BTRFS inside the LV, and the LV "backup" is mounted at /srv/backup, tell it to use the additional space using:

  btrfs filesystem resize max /srv/backup
iam-TJ··on How fast the days are getting longer (2023)
I have a wake-alarm[0] that triggers 30 minutes before civil twilight, that is roughly 60 minutes before local sunrise.

In the northern hemisphere at 52 degrees it gets earlier by about 2 minutes each day (additional 4 minutes of daytime).

So I get more sleep and short days in winter and less sleep and longer days in summer. It's liberating basing schedule on it and not some arbitrary time.

[0] https://f-droid.org/packages/com.forrestguice.suntimeswidget...

iam-TJ··on Alphabet spins out Taara – Internet over lasers
For Starlink the User Terminal (antenna a.k.a. "Dishy") is a phased array. It tracks the satellite as it passes from west to east. Each satellite is in view for around 15 seconds - the phased array instantly flips from east to west and acquires the new in-view satellite in microseconds. There's no degradation in almost all 'flips' especially if the U.T. has an unobstructed view of the sky.
iam-TJ··on The IPv6 Transition
Yes, I use direct IPv6 peer-to-peer connections both outbound and inbound using the delegated prefix.

Even for a changing prefix, if operating a DNS authoritative server for a domain, any changes to the prefix can be quickly and automatically updated in both forward (AAAA) and reverse (PTR) resource records provided the TTL for those records is appropriately short, and thus allow almost seamless inbound via FQDNs. I do this with a bind9 (hidden) master locally that notifies external slave servers operated by a highly available, anycast, DNS service.

iam-TJ··on The IPv6 Transition
I've been using Starlink since early 2021 with IPv6 only internally. Starlink User Terminal hands out a /56 prefix (via DHCPv6) and mine has not changed in all that time so I wouldn't call it dynamic.

The User Terminal issues a router advertisement (RA) and my gateway gives itself an address in that /64 via SLAAC in addition to assigning itself an address from the /56 prefix.

If not using prefix delegation each host's address is dependent on their SLAAC policy - if not preferring stable addresses (e.g: EUI64) then of course the public address will vary (be dynamic) when using temporary "privacy" addresses.

My gateway delegates /60 sub-prefixes of the /56 and bare-metal hosts then either delegates /62 or advertises /64s from the /60 to VMs, containers, network namespaces and so forth.

As someone else described, I have my gateway also delegate ULA prefixes by changing just the first two octets of the public delegated prefix to fddc (fd = ULA, dc = "data center :) but otherwise identical and likewise on the bare-metal hosts, etc.

ULA is used for internal services; ISP delegated prefix for anything that needs public access.

Multicast-DNS takes care of internal hostnames; everything is ${hostname}.local

There's a separate VLAN for legacy IPv4-only devices that does NAT64 using a ULA prefix.

DNS64/NAT64 for the laggards like github.com that can't grok 128 bit addresses :)

The only time I have problems with web services is when their DNS advertises an AAAA resource record but their firewall/load-balancers/servers are not configured to allow/listen on it.

iam-TJ··on Qualcomm cancels Snapdragon Dev Kit, refunds all orders
In my long experience of debugging and fixing ACPI errors exposed by Linux the reason MS Windows avoids (exposing to the operator) these firmware bugs is due to the fixes being incorporated into the Windows platform/chipset device drivers they ship.
iam-TJ··on Internet Archive: Security breach alert
I do something similar except that I do not allow wildcard reception - I create unique service-identifying user@ for each service I give an address to, and have a simple script that immediately adds that to the Postfix virtual table.

That way the SMTP server can reject all unknown user@ without accepting them in the first place - preventing spamming and some types of denial of service through resource starvation.

I also apply greylist based on a unique tuple (From, To, client IP address) so on first connection with that tuple valid SMTP clients need to re-deliver the email after a waiting period. Any subsequent delivers are accepted immediately.

iam-TJ··on Fixing an Elgato HD60 S HDMI capture device with the help of Ghidra
This is often due to the total costs being externalised (pushed off to others) and therefore not reflecting the true cost of the replacement nor the costs of (safe) disposal of the old unit.

Externalised costs such as emissions from manufacturing of new raw materials (metals, plastics, gases, etc.), transportation, disposal, and more.

Obviously it depends on what exactly fails. I've kept 'white goods' going for over 20 years despite:

  1) known defect where Hotpoint Fridge/Freezer evaporator thermistor fails due to freeze/defrost thermal cycle. Replaced more than 10 times; cost of new thermistor is pennies; time to replace (after initial explore) 10 minutes.

  2) Freezer control PCB misreading thermistor; replace PCB: UK£35.

  3) LG Washing machine bearing failures; replaced about 6 times; time to replace (after initial explore): 45 minutes.
I think sometimes repair-or-replace depends on one's state of mind. Figuring out what is wrong and how to fix can be frustrating but, equally, it can be extremely satisfying to realise you can do it and are no longer reliant on some mystical "expert" !

Society as a whole in many countries is losing (or has already lost) the ability to be self-reliant and that lack makes people and communities generally more fragile.

Self-reliance is one of the drivers of hackers and tinkerers.

iam-TJ··on F3 – Fight Flash Fraud
I wrote a Linux/BASH tester [0] for this recently that includes instructions on how to create simulated fake devices:

To create simulated (2GiB) fake devices

    fallocate -l 1G fff_test.flash
    DEV=$(losetup --show --find fff_test.flash); echo $DEV
    DEVNUM=$(stat -c %Hr:%Lr $DEV); echo $DEVNUM
With wrap-around sectors:

    dmsetup create --concise "fff_wrap,,,,0 2097152 linear $DEVNUM 0, 2097152 2097152 linear $DEVNUM 0"
With silently dropped writes:

    dmsetup create --concise "fff_drop,,,,0 2097152 linear $DEVNUM 0, 2097152 2097152 zero"
To test:

    fake_flash_finder.bash /dev/mapper/fff_wrap
    Capacity mismatch at LBA 2097152, data wrapped around to block 0. Size is most likely really 1073741824 bytes

    fake_flash_finder.bash /dev/mapper/fff_drop
    Capacity mismatch at LBA 2097152, data does not match what was written. Size is most likely really 1073741824 bytes
To wipe the device if repeating tests:

    dd if=/dev/zero of=/dev/mapper/fff_wrap bs=64M status=progress conv=fdatasync
    dd if=/dev/zero of=/dev/mapper/fff_drop bs=64M status=progress conv=fdatasync
To remove the device:

    dmsetup remove fff_wrap
    dmsetup remove fff_drop
    losetup --detach "$DEV"
    rm fff_test.flash
[0] https://salsa.debian.org/-/snippets/732
iam-TJ··on Ask HN: Why no transflective LCD portables?
I've still got the Notion Ink Adam with Pixel Qi transflective display and it beats everything modern in bright sunlight.
Page 1 of 11Next →