HNHacker News
TopNewBestAskShowJobs

k_sze

2,382 karma · joined December 21, 2012

Python, Django, Groovy, and Grails beginner. Hacker Reborn. Dislikes the syntax of Objective-C. Abhors PHP.

[ my public key: https://keybase.io/k_sze; my proof: https://keybase.io/k_sze/sigs/uWPMz0iLZVW--W0utFDhUqLRvuFGKOamBD6AesHm3U0 ]

submissionscomments
k_sze··on Ask HN: Who wants to be hired? (October 2026)
Location: Calgary, Canada

Remote: Yes

Willing to relocate: No

Technologies: JavaScript/TypeScript/Node.js/Express.js/OpenAPI/Python/Django/C/C++/C#/.NET/Java/Groovy/Spring Framework/Grails/Redux/Backbone.js/Snowflake/MySQL/PostgreSQL/MongoDB/Redis/SaltStack/Docker/Podman/Jenkins Ci/Circle CI/SonarQube/Azure DevOps/git/Linux/Windows/Mac/bash/zsh/Powershell

Résumé: available upon request

E-mail: kal@kalunite.net

k_sze··on South Korea proposes talks to officially end war with North
No way SK is going to convince NK to abandon nukes. The point of having nukes is not to intimidate SK or JP. It is to deter the US.
k_sze··on Your ePub Is fine
The author says that "In a perfect world, RMSDK would just stop living in the CSS stone-ages or at least provide some kind of error handling instead of dropping the whole book, but I’m not holding my breath."

This is blatantly wrong.

In a perfect world, RMSDK wouldn't exist in the first place and Adobe would have gone bankrupt and become history at least 10 years ago.

k_sze··on Malicious npm packages detected across Red Hat Cloud Services
Nice work!

Is there a sensible way to add a cooldown to Docker/Podman image pulling?

k_sze··on I tried to prove I'm not AI. My aunt wasn't convinced
Another shameless plug for my PeerAuth project, which can also tackle this problem. https://ksze.github.io/PeerAuth/
k_sze··on How Does Microwaving Grapes Create Plumes of Plasma? (2019)
And this is when we realize that the title deserves a [2019] tag.
k_sze··on Steam Controller
Wrong layout. The Xbox layout is the only correct layout. I’ll die on this hill. :P
k_sze··on Meta replaces WhatsApp for Windows with web wrapper
Erm, so why wouldn’t I just use WhatsApp as a PWA? I wouldn’t even need to waste the disk space for yet another browser runtime.
k_sze··on Users Stuck in YubiKey Re-Enrollment Loop on X (Twitter)
I was very confused, too. I mean, I do have a YubiKey but Twitter/X has never (or for a very very very long time not) asked me to use my YubiKey to authenticate. As far as I could remember, I only need to use OTP from Authy as 2FA to login. So the whole thing smelled really fishy.
k_sze··on DeepSeek OCR
It's interesting how they use "Gundam" in their variant names. I gather that Gundam-M and Gundam are their most powerful ones.
k_sze··on Japanese scientists develop artificial blood compatible with all blood types
It's odd. It seems like this is not the first Japanese team to have developped artificial blood. I did a quick search and it seems there was another team at least as early as 2019 (https://web.archive.org/web/20201111233217/http://www.asahi....)

So what's different this time?

(Upon further examination, the 2019 team at the National Defense Medical College also had Dr Hiromi Sakai. So why is this news now?)

k_sze··on Apple M3 Ultra
Why did Apple call it M3 Ultra when it's supposed to be more performant than the current top of the line M4 Max? Why not just call it M4 Ultra?
k_sze··on QwQ-32B: Embracing the Power of Reinforcement Learning
Oddly, the Chinese LLM host SiliconFlow only makes it available with 32k context, which is even smaller than their DeepSeek-R1 offering.
k_sze··on Kaspersky exposes hidden malware on GitHub stealing personal data
You're confusing Kaspersky with Kasparov, perhaps?
k_sze··on Kaspersky exposes hidden malware on GitHub stealing personal data
I'm in Canada and I just get auto-redirected to the kaspersky.ca home page when I try to visit the link.
k_sze··on Surgery implants tooth material in eye as scaffolding for lens
One thing I don't understand is how the surgeon ensures the lens is positioned correctly. We're talking about a rigid lens that can no longer be controlled via muscles, right? Doesn't any misalignment mean you get a fuzzy image at best? And even if you can get a sharp image for some given, fixed distance, you still can't control whether to focus on near things or far things when you look, right??
k_sze··on DeepSeek open source DeepEP – library for MoE training and Inference
Practically speaking, is it possible for NVIDIA to "pull the rug" later, intentionally or otherwise, by subtly changing the behaviour of this out-of-doc instruction on new architectures?
k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
I think that the scenario you describe requires one of two conditions:

  1. The attacker knows the time and medium through which the two persons call each other, and have control over the medium, being able to inject themselves;
  2. The attacker coerces one of the two persons to perform authentication.
You have a much bigger problem if any of the above is true.
k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
That sounds interesting! I'm looking forward to seeing what you build.
k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
I'll try to find an SVG-based QR code library.
k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
I asked Google Gemini 2.0 Flash and Perplexity.ai, the QR code display problem on Tor Browser for desktop appears to have to do with the browser's anti-fingerprinting mechanism.

This is the explanation that the AIs gave me:

# begin explanation The issue you're experiencing with QR codes showing up as vertical stripes in the Tor browser when using QRCode.js is due to Tor Browser's anti-fingerprinting feature.

Tor Browser is designed to protect user privacy, and one of the ways it does this is by randomizing the output of the HTML5 Canvas API. QRCode.js uses the Canvas API to draw QR codes. When Tor Browser randomizes the Canvas output, it distorts the QR code image, causing it to appear as vertical stripes instead of a readable QR code.

This is a known issue and is intentional behavior in Tor Browser to prevent fingerprinting. Fingerprinting is a technique websites use to uniquely identify and track users based on various browser characteristics, including how the browser renders content like Canvas elements.

Here are the solutions based on my research:

Lower Tor Browser's Security Level: The simplest workaround is to temporarily lower Tor Browser's security level from "Safer" or "Safest" to "Standard". You can do this in Tor Browser's settings under "Privacy & Security" -> "Security Level". Setting it to "Standard" disables the Canvas fingerprinting protection, which should allow QRCode.js to render QR codes correctly. However, this will slightly reduce your privacy while using Tor Browser.

Use a Different Browser: If you need to generate QR codes reliably and use them, the most straightforward solution is to use a different browser like Safari, Firefox, or Chrome, as you've already observed that the QR codes work correctly in these browsers. You can use a non-Tor browser specifically for generating and scanning QR codes, and then switch back to Tor Browser for your privacy-sensitive browsing.

Advanced Configuration (Not Recommended for Most Users): For advanced users, it might be possible to modify Tor Browser's about:config settings to disable specific anti-fingerprinting measures related to Canvas, such as canvas.poison or privacy.resistFingerprinting. However, this is strongly discouraged unless you fully understand the privacy implications, as it can weaken Tor Browser's privacy protections. It's generally better to use one of the first two options.

In summary, the striped QR code issue is a trade-off between strong privacy protection and website functionality in Tor Browser. Tor prioritizes privacy by randomizing Canvas output, which unfortunately breaks some features like QR code generation using libraries like QRCode.js. The recommended solutions are to either temporarily lower the security level in Tor Browser or use a different browser for QR code related tasks. # end explanation

As well as the proposed solution: # begin solution The issue with QR codes appearing as vertical stripes in Tor Browser when using QRCode.js is due to Tor Browser's anti-fingerprinting feature, which randomizes the Canvas API output. This intentional behavior to protect privacy disrupts QRCode.js's ability to render QR codes correctly.

Solutions include:

1. Lowering Tor Browser's security level to "Standard".

2. Using a different browser for QR code generation.

3. Advanced users can modify `about:config` settings, but this is not recommended.

The recommended solutions are to temporarily lower the security level in Tor Browser or use a different browser for QR code related tasks. # end solution

k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
Looks like the problem is with the desktop Tor browser. I can see that the QR codes are displayed as two square images with coloured vertical stripes instead of real QR codes. That's such as weird problem.

In any case, I have just added the display of the base32 secret key.

k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
OK, I can make it output the secret as text.
k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
Desktop or mobile?
k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
This has been fixed. After every click of the "Generate" button: 1. any existing QR codes are replaced; 2. the new QR codes scroll into view automatically.
k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
Actually the QR codes should be replaced if you click "Generate" multiple times. I guess that also needs to be fixed.
k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
Yes, that's what I had in mind. Wait at most 30 seconds, the code will then have rotated and the roles can be reversed.
k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
Hmm, I wanted to require less fiddling around by the user once the QR code is scanned, which is why I generate two QR codes that encode the same secret but with different labels.
k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
Thank you for the feedback! I’ll try to see what I can do about it. Perhaps make the QR codes display in a modal in front of the original content. Alternatively, I can try having the page automatically scroll (with ease-in and ease-out) to the QR codes.
k_sze··on PeerAuth, TOTP-based peer authentication in the post-truth world
I’m glad you like it. The whole thing might be a bit paranoid, but it was a fun exercise trying to get an LLM to code for me (I used DeepSeek to code the base, and then manually fixed some stuff, and then asked DeepSeek to add i18n for me).
Page 1 of 30Next →