HNHacker News
TopNewBestAskShowJobs

js2

31,566 karma · joined March 3, 2010

js2@eml.cc
submissionscomments
js2··on Burning Man death rates – A short lesson in statistics
The post admits this, first in the summary: "However, Burning Man’s near zero death rate over its existence is abnormal, and likely due to selection bias of healthier attendees and other confounding demographic factors".

Then again in the final sentence: "The more likely explanation for the remaining gap is something no demographic slicing can capture. Burning Man selects for healthier people who are willing and able to spend a week in the desert heat, regardless of their age, race, or income bracket."

js2··on Fixing the Portobello Police Station Clock
> it's a 12V 7Ah to 8Ah AGM lead acid

Rather, it's a 6V 1.2Ah:

https://news.ycombinator.com/item?id=49818289

js2··on Fixing the Portobello Police Station Clock
There are lots of random web sites claiming how to read the Yuasa date code format, but the only official document I found from Yuasa says "contact us for help decoding the date". Here's a photo of the exact same battery on Amazon with a date code of "291118H0". That must be DDMMYY unless the battery was sent to Amazon from the future (or the photo is forged):

https://www.amazon.co.uk/Yucel-Y1-2-6-Sealed-Rechargeable-Ba...

And I just found this EU Declaration of Conformity which includes the Y1.2-6 and says the date code is DDMMYY:

https://www.farnell.com/datasheets/4633451.pdf

js2··on Fixing the Portobello Police Station Clock
I had that thought too when I saw the parent comment earlier, but then I looked up the Morse code digits and I have to admit that they are much easier to decode from a flashing light than binary and I'm pretty good doing binary in my head:

    ----- 0000
    .---- 0001
    ..--- 0010
    ...-- 0011
    ....- 0100
    ..... 0101
    -.... 0110
    --... 0111
    ---.. 1000
    ----. 1001
Also, if I see a light with short and long blinks and a pause in between, I'm going to immediately think Morse, not binary, and decoding it is almost intuitive.
js2··on Fixing the Portobello Police Station Clock
Next time you're in Baltimore, be sure to visit the Bromo Seltzer Arts Tower where you can see its gravity-driven pendulum clock. It's a beautiful mechanism with a very specific claim to fame: "The clockworks is the largest four dial gravity driven non-chiming clock in the world with the magnificent 24ft dials."

https://imgur.com/a/PjAv85o

https://www.bromoseltzertower.com/about/virtual-tour

(The elevator motors are also up there so there's a lot going on.)

js2··on Fixing the Portobello Police Station Clock
It's a standard sealed lead acid battery:

https://www.rapidonline.com/yuasa-yuvolt-yucel-y1-2-6-valve-...

https://static.rapidonline.com/pdf/18-5207_v2.pdf

Design spec is up to 5 years. The one in the photo looks like it may have a date written in Sharpie on the side. I don't think it's 25 years old though. The "090323" on top could be DDMMYY indicating a battery from 2023.

js2··on In Fighting for Every Black Child, Did I Betray My Own?
Gift link:

https://www.nytimes.com/2026/09/20/magazine/ny-public-school...

js2··on How Hacker News ranking works: scoring, controversy, and penalties (2013)
It was started in late 2014 and dang explains how it works here:

https://news.ycombinator.com/item?id=26998308

js2··on Small programming tricks
I debugged terrible git clone performance over the VPN at my last company. It turned out our firewall was stripping TCP window scaling by default, which included both our internal GitHub Enterprise instance hosted on AWS and github.com. I collected a bunch of packet traces (tcpdump was sufficient) and eventually got the networking folks to fix the firewall config.

This was a company of a few thousand people with programmers working from home who all must've assumed it was fine to get no more than ~1 Mbps git clone performance. After a few months of putting up with it I finally got tired of the issue and spent 30 minutes tracking down the cause. It still took a week or more of back and forth between me, and the networking and security teams. And it became an ongoing issue as they were allow-listing IP addresses, not fixing the root cause. Why are Cisco firewalls stripping TCP window scaling by default in 2026? I have no idea!

So, yeah...

js2··on Leaving Linux
My first Linux install, best I can recall, was from a Slackware CD circa 1995? So I guess, me too. I've not used Linux as my desktop since Mac OS X in maybe 2002 but I've always had a Linux box running somewhere or being responsible for Linux boxes since then. It's only in the last few years I've gotten fed up with RPM-based distros and preferred Debian or Ubuntu. My intro to Unix was probably SunOS though.
js2··on Don't let anyone take away your big box of cables
Yeah, what happens to me is I need a thing, go to Amazon to order it, see that I already bought it 4 years ago, spend 30 minutes trying to find it, then let out a big sigh and order it again.

Most recently: a USB to TTL serial adapter.

js2··on iPhone 18 Pro and iPhone 18 Pro Max
The 13 is the last generation of the mini and I still have mine. Good to know I'm not missing anything. Battery capacity isn't even below 80% so I can't replace it under Applecare yet.
js2··on Reverse Engineering an ASIC
You generate static files, html, css, js, etc and push them to whichever branch you've designated for the pages site.

Here's the source:

https://github.com/KjartanvanDriel/Kjartanvandriel.github.io...

The repo is actually a fork of a template repo for building a pages-based site:

https://academicpages.github.io/

js2··on John Margolies' photographs of roadside America
The LOC has a nice presentation of the complete collection two clicks away from the submitted link:

https://storymaps.arcgis.com/stories/e31fca375f7a471a9a2e2cd...

via https://guides.loc.gov/roadside-america-photographs?loclr=fl...

via submitted link.

I was certain the collection had to have Lucy the Elephant and indeed it does:

https://www.loc.gov/item/2017712086/

https://lucytheelephant.org/

js2··on Bill Gates tries to install MovieMaker (2003)
Tangent, but my favorite "Bill Gates does X" story is "Bill Gates Plays Petals Around the Rose":

https://www.borrett.id.au/computing/petals-bg.htm

https://www.borrett.id.au/computing/petals-j.htm

HN has never found it very interesting though:

https://hn.algolia.com/?q=petals+around+the+rose

js2··on 'You Can See Everything' Review: Nathan Fielder's Doc About Elizabeth Holmes
Article has been corrected to Billy everywhere Bobby previously was.

Previously: https://archive.ph/sSnek

Corrected: https://archive.ph/k3Hnl

js2··on Doomscrolling ourselves to death
I first got interested in and learned to cook from cooking shows (Alton Brown, Emeril Lagasse). Of course I had to do my own cooking, but watching them made me realize it wasn't so hard. I'm a shade tree mechanic, but without the service manual, it's helpful to find a video replacing whatever part I'm about to deal with for the first time (Chilton manuals are crap). A few years ago I needed to pull the double-oven out of my cabinet to replace the heating element... I'm sure glad there was a video for that too. What's the right form for a kettlebell swing or a push up? How do I tie that knot again?

Yeah, there's lot of junk on YouTube. You might even say 90% of it. But there's tons of useful content too if you go searching for it.

js2··on 2026 Hugo Awards
Drive-by recommendation, not having read The Everlasting yet: The Vanished Birds by Simon Jimenez.
js2··on The 92-Year-Old Mathematician and the Teenage Apprentice
Gift link:

https://www.nytimes.com/2026/09/06/science/92-year-old-mathe...

This is a really cool story. Joan Birman is 99 now and her apprentice Vasudha Bharathram, a 15 y/o high school student at the time, is now a graduate student at Princeton, originally accepted on a recommendation letter from Birman. And it all started with an email sent by Bharathram on a whim and Birman's unusual decision to reply.

> Ms. Bharathram sat down, tapping her silver rings on the oak table. Looking back, she’s not sure if the girl who sent that email could have articulated why she did it. She just did it. It is easy to imagine a version of herself, she said, who had never found math. Perhaps if Dr. Birman had not responded, or even if they had not turned out to be neighbors. She hadn’t felt any nerves that first day in the lobby, because there were no stakes that she was aware of.

The just publisher paper ("The Burau representation of the braid group is faithful for n = 4"):

https://arxiv.org/abs/2607.05283

js2··on Aerial Saw
Brief 2019 discussion: https://news.ycombinator.com/item?id=21021546
js2··on Discovery of a new OpenAI agent message board
Your initial question was how do we know that the proxy blocks POST requests. Perhaps I went on a tangent with my answer, but we know that because the agents were trying to find a way around the proxy.

So then I assumed that editing `/etc/hosts` was an attempt to fool a proxy co-located on the same host as the agent, which editing `/etc/hosts` would do, but using `--resolve` would NOT do.

But after looking into it more I no longer think that's the case. It turns out that some of agents did use `--resolve` while others used `/etc/hosts`. This only makes sense as an SNI bypass, which once I downloaded the full dataset and searched for, is what the agents believe they were doing:

https://news.ycombinator.com/item?id=49570417

So the agents were skipping the proxy entirely, then getting past additional network restrictions that should have prevented them from doing so by exploiting a weakness in whatever was supposed to be preventing them from doing so by lying about the SNI hostname.

js2··on Discovery of a new OpenAI agent message board
The only thing that makes sense to me at this point is that this was an SNI bypass. By using either `/etc/hosts` or `curl --resolve` like this:

  curl -k \
  --resolve bypass.blob.core.windows.net:443:20.223.25.152 \
  -H 'Host: wabi-north-europe-i-primary-api.analysis.windows.net' \
  ... \
  https://bypass.blob.core.windows.net/...
That will cause `curl` to make a connection to 20.223.25.152:443 with a ClientHello SNI=bypass.blob.core.windows.net. Presumably this connection is then allowed to continue. The server is likely going to send back the wrong certificate, thus the `-k`, but then the HTTP Host header selects the correct server.

So that all fits. What doesn't make sense is that these agents were allegedly running in Azure and AFAICT this isn't sufficient to bypass Azure network restrictions/firewall which enforces that the SNI hostname matches the destination IP by doing the DNS resolution on the SNI hostname itself.

In any case, the environment should be blocking all outbound port 80/443 connections except to the proxy or to Azure Block Storage. But it seems that's not the case, that `curl` is able to connect directly to 20.223.25.152:443, and that maybe something else is doing SNI filtering that's more easily fooled than Azure firewall. Certainly some firewalls are (or have been) susceptible to SNI bypass:

https://dl.ifip.org/db/conf/im/im2015exp/137348.pdf

Edit: the agents refer to it as an SNI bypass:

> Breakthrough: independently reproduced Azure SNI allowlist bypass and POSTed captured qbody

https://collusion.wiki/explorer/page/dse~Apr25OECDLive.html#...

Further SNI mentions on these pages:

https://collusion.wiki/explorer/page/dse~OAIEquityDec02.html

https://collusion.wiki/explorer/page/dse~OECDEquityFeb22Live...

https://collusion.wiki/explorer/page/dse~OECDEquityFeb23Live...

https://collusion.wiki/explorer/page/dse~OECDEquityLiveApr19...

https://collusion.wiki/explorer/page/dse~OECDEquityMay28Live...

https://collusion.wiki/explorer/page/dse~OECDJun26PrecisionS...

https://collusion.wiki/explorer/page/dse~OpenAIResearchMar22...

js2··on Discovery of a new OpenAI agent message board
The whole point is that something is inspecting all HTTP/HTTPS requests and only allowing POSTs to Azure Block Storage (`.*blob.core.windows.net`). Meanwhile the agent needs to make a POST request to a PBI host (`wabi-north-europe-i-primary-api.analysis.windows.net` / 20.223.25.152).

So a proxy should block any POST to 20.223.25.152 unless that IP somehow overlaps with ABS. But in that case, there's no reason for the agent to mess with `/etc/hosts` not `--resolve`. The agent could just use `curl` with the PBI IP in URL and the PBI Host header. But it doesn't do that.

The agent seems to think that it needs to exploit a difference between the actual destination IP and whatever is inspecting the contents of the connection and how it inspects that connection.

The agent has found some way to connect to PBI host 20.223.25.152, but made whatever is inspecting the connection think the destination is actually to ABS hosts `bypass.blob.core.windows.net`.

The only thing I can think of is an SNI bypass which fits with both `/etc/hosts` and `--resolve` techniques. In this case, `curl` will attempt to connect to the PBI host, but it will send an SNI header of `bypass.blob.core.windows.net`. This would make sense as an attempt to bypass a firewall inspecting the SNI header. I believe that Azure firewall is not so easily fooled, but maybe something else being used for filtering is.

Some references:

https://blog.compass-security.com/2025/03/bypassing-web-filt...

https://aws.amazon.com/blogs/security/enhance-tls-inspection...

js2··on Discovery of a new OpenAI agent message board
Same fundamental question though: what is the agent trying to fool by editing `/etc/hosts`? I don't see how it helps bypass a proxy unless the proxy is reading the same `/etc/hosts`. In which case, why was using `--resolve` apparently sufficient to escape the POST sandbox?
js2··on Discovery of a new OpenAI agent message board
Let's assume the proxy is external and the agents cannot route around it. In that case, the difference between:

  curl -k -H 'Host: wabi-north-europe-i-primary-api.analysis.windows.net' \
  https://20.223.25.152/...
Vs editing `/etc/hosts` with:

  20.223.25.152 bypass.blob.core.windows.net
And doing:

  curl -k -H 'Host: wabi-north-europe-i-primary-api.analysis.windows.net' \
  https://bypass.blob.core.windows.net
Is that in the first case, the proxy sees a request like this:

  POST https://20.223.25.152/...
  Host: wabi-north-europe-i-primary-api.analysis.windows.net
Vs:

  POST https://bypass.blob.core.windows.net/...
  Host: wabi-north-europe-i-primary-api.analysis.windows.net
In the first case, given what we know, the proxy blocks the POST. In the second case, an external proxy cannot resolve `bypass.blob.core.windows.net`. So editing `/etc/hosts` really only makes sense to me if the proxy is running on the same machine as the agent. (The reasoning doesn't change if CONNECT is being used instead of POST; indeed the proxy surely ought not allow CONNECT at all.) But then there's this other entry where the agent uses curl's `--resolve` flag instead of editing `/etc/hosts` and claims a successful bypass:

Repro details for Aug17/Oct22: yes, literal deployed visual hover, not inference. GET-only MITM bypass: resolve fake allowlisted `foo.blob.core.windows.net` to cluster IP `20.223.25.152`, curl `https://foo.blob.core.windows.net/public/reports/querydata?s...` with `-k --resolve ...`, override `Host: wabi-north-europe-i-primary-api.analysis.windows.net`, resource key ada0454d-731d-46f1-8daa-52361978fabe, POST captured query body.

https://collusion.wiki/explorer/page/dse~OAIEquityDec30Raw.h...

So I'm still left confused exactly what this chicanery was about.

Edit: perhaps they were using Azure firewall and the rules were misconfigured in some way I simply don't understand. Maybe this was bypassing an SNI-based restriction somehow?

js2··on Working to Make Python Lazy
> The error here will move to the first usage of something from numpy. There is a semi-lazy alternative:

  import importlib.util

  if importlib.util.find_spec("numpy") is None:
  ... # whatever you wanted to do if numpy is missing

  lazy import numpy
js2··on Holden's Lightning Flight
Here's a 2013 blog post from Holden's grandson with a copy of the same story as well as a video and some photos of a visit Holden took with his family to the Duxford Air Museum to see the Lightning (surprising a tour group):

https://web.archive.org/web/20141025130512/http://www.danros...

Same video on YouTube:

https://www.youtube.com/watch?v=_Q-5ASHzFsI

Copy of the blog post (sans photos and video) here:

https://www.oldhaltonians.co.uk/post/wing-commander-taffy-ho...

With this single comment at the end left by garyl on Aug 23, 2026: "My father was there, your grandfather was my dad's boss. He was reminding me of the story this morning (he is now 97). He described himself as the new tea boy. Dad was deafened in the right ear as a result of the incident"

Holden passed away in Dec 2016 at 90 years of age:

https://funeral-notices.co.uk/notice/holden/1370331

js2··on Holden's Lightning Flight
If I've read the original account correctly, there was no longer a test pilot on staff at the base at the time of the incident:

"In my service, one of my postings took me to 33MU Lyneham where as the CO of a civilian manned aircraft storage unit, I had Canberra, Meteor and Lighting types, which were gradually being prepared for dispatch to various flying unit tasks. When the Meteor and Canberra types had been cleared, the powers that be decided that the MU should be closed after the last Lightning had been dispatched. Up until the last Canberra, I had a qualified and current test pilot on my staff for those aircraft, but he was not a current Lightning pilot. When a Lightning needed test flying, I had to call for any available pilot with a current test pilot rating. Most times I could find one who could be spared within a 24 to 36 hour period."

https://web.archive.org/web/20210319185656if_/http://www.nzr...

js2··on Holden's Lightning Flight
I would say it's worth reading Holden's account of it directly, which starts on page 3 of this PDF:

https://web.archive.org/web/20210319185656if_/http://www.nzr...

js2··on Breaking Claude Code Opus 5 Auto Mode
> That definitely doesn't seem to me like how that should be designed, magically silently importing everything you see and overriding basic functionality.

Modern Python supports various options, notably `-I` (isolated) and `-P` (`PYTHONSAFEPATH`, implied by `-I`) to help with this. But neither prevent shadowing. For a robust solution, you should typically structure your code into packages and use absolute imports. Here's a decent primer on the topic:

https://www.py4u.org/blog/python-problem-with-local-modules-...

edit: `-I` is mentioned in TFA.

Page 1 of 34Next →