HNHacker News
TopNewBestAskShowJobs

jackjeff

1,125 karma · joined June 15, 2012

submissionscomments
jackjeff··on Green card interviews end in handcuffs for spouses of U.S. citizens
So the right process is to request for a K1 fiancé visa which takes over a year?!

I can see why people were tempted to cut corners, especially given past tolerance…

jackjeff··on Time to start de-Appling
The UK (same as the US) has lots of extra territorial laws. Enforcing them is another matter.

It’s easy to make Apple budge because they have money ties to the Uk.

This works less well for unsavory websites not complying with UK law. See https://prestonbyrne.com/2025/10/16/the-ofcom-files/

jackjeff··on IP blocking the UK is not enough to comply with the Online Safety Act
The UK has no problem asking their ISPs to block the Pirate Bay. Why can’t OFCOM do this? I don’t understand the attempt to pursue this in a foreign country. It’s fairly obvious that what they’re doing are not considered crimes in the US and politically it looks bad from Trump and his administration. And also, until 5 mins ago I had no idea this site existed. Now I do. Seems to achieve the polar opposite as I’m in the UK and browsing a dangerous forbidden site now. Wooooo
jackjeff··on YouTube erased more than 700 videos documenting Israeli human rights violations
The problem is that these private companies have taken a disproportionate place in public discourse. You are absolutely right that freedom of speech does not guarantee the right to post anything on YouTube (someone else's website). In fact YouTube has the right (protected speech) to censor you and refuse to let you post long as they don't do in a discriminatory way (for instance, only "white people" can post would be discriminatory/illegal).

The problem is that in practice, if you can't do YouTube, Facebook, Tiktok, INsta, etc... your speech will not be heard by anyone. It's like if a tree falls in the forest and nobody is there to hear it, the fact that it makes sound is irrelevant. So effectively, it amounts to censorship, even though the government potentially had no hand in it.

Now imagine someone in Trump administration pressured Google with a juicy contract, or the prospect of an expensive lawsuit, and the quid pro quo was dumping these videos that annoy "our Israeli friends". This kind of "pay to play" is at minimum corruption. It may also fall of short of constitutional guarantees for free speech. Ironically, it is exactly the same thing a lot of members of the Trump administration have accused Biden of doing (exhibit: the so called "Twitter Files" etc... ), although I don't believe this went anywhere in federal courts (am I wrong?)

I honestly don't know what the answer is. But I would not be surprised if in 50 years time, some of these large companies get regulated as "utilities" and are no longer able to yank "videos" from their platform just because they feel like it. And every time they "abuse" their powers, I feel like we get an inch closer to that onerous regulation.

jackjeff··on YouTube erased more than 700 videos documenting Israeli human rights violations
The article has a very long list of alleged Israeli violations of international law and human rights. Here's a quick summary.

Genocide in Gaza. It is described as a "genocidal campaign" implying systematic targeting of a national, ethnic, or religious group, prohibited under the 1948 Genocide Convention. This is what the ICC is investigating now.

War Crimes:

- Killing of Palestinian civilians, including children and families.

- Killing of journalist Shireen Abu Akleh, a violation of the Geneva Conventions protecting civilians and journalists in conflict zones.

- Destruction of Palestinian homes in the occupied West Bank, possibly constituting collective punishment or unlawful destruction of property under the Fourth Geneva Convention.

- Intentionally starving civilians by blocking humanitarian aid into Gaza, explicitly prohibited under Article 54 of Additional Protocol I to the Geneva Conventions and cited in ICC arrest warrants for Israeli officials.

- Torture of Palestinian detainees by Israeli forces, a violation of the UN Convention Against Torture.

The article also alleges complicity from the US authorities and corporations (YouTube, Google, MailChimp).

jackjeff··on YouTube erased more than 700 videos documenting Israeli human rights violations
The irony is that JD Vance lectured the Europeans about their lack of freedom of speech in Europe while invited in Germany.
jackjeff··on Ofcom fines 4chan £20K and counting for violating UK's Online Safety Act
I’d be curious to know how the UK going to enforce its extra territorial law against a company with no ties to the UK?
jackjeff··on UK Petition: Do not introduce Digital ID cards
No doubt it’ll be an open source app you’ll be able to recompile for your non Android/iOS computers. Otherwise I really hope to government gifts me an ID computer.
jackjeff··on A teen was suicidal. ChatGPT was the friend he confided in
Don’t cars and ropes and drills occasionally kill people too? Society seems to have accepted that fact long ago.

Somehow we expect the digital world to be devoid of risks.

Cryptography that only the good guys can crack is another example of this mindset.

Now I’m not saying ClosedAI look good on this, their safety layer clearly failed and the sycophantic BS did not help.

But I reckon this kind of failure more will always exist in LLMs. Society will have to learn this just like we learned cars are dangerous.

jackjeff··on I built a native Windows Todo app in pure C (278 KB, no frameworks)
I remember doing that for some custom installer I wrote. It felt like a good idea for 5mins until it got flagged by a bunch of anti virus software… had to sign the installer in the end and spent a lot of time reporting false positives.
jackjeff··on I built a native Windows Todo app in pure C (278 KB, no frameworks)
I’m surprised it’s that big to be honest. I was expecting it to be smaller or half the size to be taken by some app icon. I remember writing this kind of stuff back in the days and it was smaller.

Is it due to MinGw maybe?

jackjeff··on We're building a dystopia just to make people click on ads [video]
I did not realize that worked so well. I gave up on Safari a while ago. Will give it another shot with AdBlock Pro then. Is it with the free tier?

I just use ublock Origin with Firefox on Mac/Pc and Orion on iOS.

The annoyance list takes care of the cookie banners.

jackjeff··on How encryption for Cinema Movies works
Oh thanks. I missed that. I guess that works pretty well too!
jackjeff··on How encryption for Cinema Movies works
> The video stream is encoded as one single JPEG2000 picture per frame. Each frame is encrypted with the same static AES key.

Is this not a problem? It’s not a good idea to reuse the same key to encrypt very similar files. Similar to ECB. See the famous penguin https://words.filippo.io/the-ecb-penguin/

I’m surprised they don’t use something like XTS commonly used for disk encryption. It derives a unique key for each block/frame and allow you to access each individual blocks/frames non sequentially.

jackjeff··on Better Error Handling
Checking for errors after every line (like in Go) is the worst. Used to do that in c/c++ calling win32 APIs. Know what happened when sloppy developers come along? They don’t bother checking and you have really bizarre impossible to debug problems because things fail in mysterious ways. At least with an exception if you “forget” to catch it blows up in your face and it’ll be obvious

Sure monads are cool and I’d be tempted to use them. They make it impossible for forget to check for errors and if you don’t care you can panic.

But JS is not Rust. And the default is obviously to use exceptions.

You’ll have to rewrap every API under the moon. So for Monads in JS to make sense you need a lot of weird code that’s awkward to write with exceptions to justify the costs.

I’m not sure the example of doing a retry in the API is “enough” to justify the cost. Also in the example, I’m not sure you should retry. Retries can be dangerous especially if you pile them on top of other retries: https://devblogs.microsoft.com/oldnewthing/20051107-20/?p=33...

jackjeff··on Apple takes UK to court over 'backdoor' order
That’s not necessarily true.

RIPA notices do indeed assume you’re in possession of the keys of anything encrypted and you must disclose when asked nicely.

You just need an airtight provable way of showing you have a way to destroy that key when you push a button and do that before the notice arrive. I suspect that’s after they seize your stuff.

jackjeff··on Claude 3.7 Sonnet and Claude Code
Could not agree more! I have 20+ years experience and use Cursor/Sonnet daily. It saves huge amounts of time.

But I can’t imagine this tool in the hands of someone who does not have a solid understanding of programming.

You need to understand when to push back and why. It’s like doing mini code reviews all the time. LLMs are very convincing and will happily generate garbage with the utmost authority.

Don’t trust and absolutely verify.

jackjeff··on Lobsters blocking UK users because of the Online Safety Act
As a person living in the UK, I really hope the rest of the world gives the middle finger to this pathetic extra territorial law by totally ignoring it.

They can ask ISPs to do the censorship if they really want to keep us “safe”.

jackjeff··on What's Going on at the FBI?
I think it’s unprecedented for every FBI agent to fill up a questionnaire to admit whether they worked on a case where the president himself was an active participant.
jackjeff··on Open-R1: an open reproduction of DeepSeek-R1
That’s a good point. Wouldn’t OpenR1 suffer from the same problem? Or does being open somehow shield them from legal repercussions?
jackjeff··on TikTok says it is restoring service for U.S. users
As long as this is the only place the fascist upraising happens… better than being forced out of your job, making all other political parties illegal, being beaten by mobs patrolling the streets while the police looks the other way, canceling elections ad vitam eternam on national security grounds, I mean stuff that proper fascists used to do back in the days.

In the mean time, if I wanted 30 seconds clips of cat videos I’m sure I could use a VPN. Let’s ban it. Teach people censorship is utter BS like every Chinese person knows by now. Sadly my attention span is slightly longer than 30s so I’m not even gonna bother

jackjeff··on UK bans daytime TV ads for cereals, muffins and burgers
If only I ever watched ads on live TV I would have noticed…
jackjeff··on Ask HN: What ist your AdBlock strategy?
I use ublock Origin on the Orion browser on iOS.
jackjeff··on Firefox-Passwords-Decryptor: Extracts and decrypts passwords saved in Firefox
Ab yeah. In that case it makes perfect sense.

But honestly I’d stay away from PBDKF2 at this stage. If you look at OWASP they recommend 600k rounds. That number is getting bigger and bigger all the time (10k rounds used to be enough over a decade ago)

https://cheatsheetseries.owasp.org/cheatsheets/Password_Stor...

I would use Argon or scrypt (which is basically PBKDF2 in a loop with some weird mixes) instead.

jackjeff··on Firefox-Passwords-Decryptor: Extracts and decrypts passwords saved in Firefox
I'm not defending this choice, and I think you're right in general.

In this case, the only thing encrypted with TripleDES is the password itself, so the practicality of a crib or other known plaintext attacks is debatable in my opinion.

If you use the same (or similar) password everywhere, then you have bigger worries than Firefox use of TripleDES. Password stuffing based with leaks from poorly hashed password DB (cough facebook cough) is likely the most practical attack vector in this case.

If all your passwords are like q@qrG#Z4ARYm^qjeTEMN2Kh45v^p7L# then crib like attacks are impractical.

There are other weird/debatable choices in the Firefox encryption layer:

- Why bother with CBC? Things like AES-GCM or other authenticated* encryption mode would be nicer. Not sure it's a flaw here (google the cryptographic doom principle of Moxie Marlinspike)

- Why not wrap the encryption keys with some kind of "key wrap" mode instead. There are such things as AES-KV for instance.

- Why do the weird PBDKF2 derivation here? It's not based on a password the player enters, so there's nothing to "strengthen"? Seems oddly unnecessary (or I don't understand and there's a password somewhere).

- If there's a password then PBKDF2 is really really shit compared to scrypt or even better one the variant of argon OWASP said you should use.

jackjeff··on Firefox-Passwords-Decryptor: Extracts and decrypts passwords saved in Firefox
It uses both AES and TripleDES

If you glance at the code there's a single "key encryption key" in the whole SQLITE file (in the 'metadata' table). That key is decrypted using AES with the PBKDF2 derived secret.

Then each password is in turn encrypted using TripleDES. The "data encryption key" for each these records is in turn encrypted using the aforementioned "key encryption key".

My suspicion is that the TripleDES format must be really old, and when they migrated the crypto layer to use AES they just re-encrypted the top layer (the "key encryption key" later) to use AES. It's much faster (and safer) to just re-encrypt all the TripleDES keys with the new AES than go and mess with "all" the records in the database. It's inelegant and lazy but you effectively get "AES level" of security without having to do all the work, so to speak…

https://github.com/Sohimaster/Firefox-Passwords-Decryptor/bl...

jackjeff··on Why the ISO format has to die
There are many ways in which ISO files are useful. You have native support in Linux and Windows (you can mount). You usually also have support in virtualization or emulation software like VMWare Parallels, VirtualBox, HyperV…

So I get it Etcher for someone who wants to do it on a USB stick is probably as easy if not easier than using cat or dd. I reckon I can probably create the ISO file with Etcher too. But I’ve installed countless distros and never had to download Etcher since I could always point the virtual CD to an ISO file.

Bonus point. I don’t need to learn anything about file systems and partitions and block sizes… it just works. I have no idea how these bootable medias work since I never had to make one.

jackjeff··on Please do not attempt to simplify this code
Comments go out of date because of bad developers.

The same people who do the bare minimum for tests not to explode. But won’t add a new test case for the new branches they just introduced.

The same people who will mangle the code base introducing bizarre dependencies or copy paste the same piece of code rather than refactor.

People who fail to handle errors correctly. My favorite: by wrapping code in a if statement without an else. (else? Get a weird error without logs! Miles away from the call site!)

People who don’t validate inputs.

People who don’t give a monkey about adding context to errors making the thing impossible to debug in prod when they explode.

People who are too lazy or in incompetent to do their job properly and will always jump at the opportunity to save 5 minutes now but waste 5 hours of everybody else’s time later. Because of course these people can’t fix their own bugs!

And of course these are the people who make comments go out of date. I’ve seen them implement a thing literally the line below a TODO or FIXME comment and not delete the line.

Comments going out of date is a shit excuse for not writing comments as far as I’m concerned.

The fact that some people are incompetent should not drive engineering decisions. You should always assume a minimal level of competency.

jackjeff··on Initial details about why CrowdStrike's CSAgent.sys crashed
If you get have privileged escalation vulnerability there are worse things you can do. Just making the system unbootable by destroying the boot sector/EFI partition and overwriting system files. No more rebooting in safe mode and no more deleting a single file to fix the boot.

This would probably be classified as a terrorist attack and frankly it’s just a matter of time until we get one some day. A small dedicated team could pull it off. It’s just so happens that the people with the skills currently either opt for cyber criminality (crypto lockers and such), work for a state actor (think Stuxnet) or play defense in a cyber security firm.

jackjeff··on US EPA Enforcement and Compliance on Apple Fabrication
I don’t know. As a shareholder it sounds like the dumbest move ever. In what universe would it make sense to have a fab so close to an appartment building and vent toxic gas. It’s a PR disaster waiting to happen. Whatever savings you make by avoiding regulation you pay back in fines and reputation damages.

What is it they saved here? Could they not fab this in a less populated area and just follow a few more regulations. We’re not talking about a company with razor thin margins. They spent outrageous amounts of money building the spaceship HQ.

I genuinely want to understand if this is stupidity or if there’s really a profit incentive that makes “fiduciary” sense.

← PreviousPage 2 of 10Next →