HNHacker News
TopNewBestAskShowJobs

kbuck

1,020 karma · joined December 5, 2011

submissionscomments
kbuck··on If PyPy is 6.3 times faster than CPython, why not just use it?
Yep, this was on a Debian 6.0.2 install, with packages from apt.
kbuck··on If PyPy is 6.3 times faster than CPython, why not just use it?
This was with Twisted 10.1.0 and Python 2.6.6. I remember being in extreme disbelief when I found that it was using select/poll instead of epoll (who does that, especially when they already have epoll support?). I ended up writing this:

  for reactor in ["epoll", "kq"]:
      try:
          rn = reactor + "reactor"
          getattr(__import__("twisted.internet", fromlist=[rn], rn).install()
          print "Auto-selecting reactor: " + reactor
          break
      except ImportError:
          pass
kbuck··on If PyPy is 6.3 times faster than CPython, why not just use it?
I actually experimented a while ago by running a long-running Twisted-based daemon on top of PyPy to see if I could squeeze more speed out. PyPy did indeed vastly increase the speed versus the plain Python version, but once I discovered that Twisted was using select/poll by default and switched it to epoll, my performance issues with the original CPython version were gone (and PyPy couldn't use Twisted's epoll at the time).

Another major issue was that running the daemon under PyPy used about 5 times the memory that the CPython version did. This was a really old version of PyPy, though, so they have probably fixed some of this memory greediness.

kbuck··on Intel Says No to Ubuntu's New Display Server
I don't think it's entirely a corporate move here. Free software contributions aren't infinite; if you have $N developers working on integrating support for display servers, then it's simple math that having to support two display servers means that you'll have $N/2 developers working on each, and will therefore get half the work done (and, since they'll probably still have to support X11 for a while, make that $N/3). Ubuntu selfishly forked Mir instead of choosing to try to use Wayland (especially when they had originally committed to using Wayland[1]), so the burden is on them here. It also doesn't help that Canonical employees were using the inclusion of XMir support as political fodder[2].

[1] http://www.markshuttleworth.com/archives/551 [2] https://twitter.com/olliries/status/375704285083738112

kbuck··on Ask HN: Why would I see [dead] before my submission titles?
Dead posts have been killed by either automated spam prevention or the editors. See "In my profile, what does showdead do?" here: http://ycombinator.com/newsfaq.html
kbuck··on Out-Tridging Tridge by improving rsync
This isn't entirely correct; rdiff-backup will give you a full copy of the latest version of the file as well as a set of binary diffs that can be applied in sequence to roll it back to an earlier version. rdiff-backup will actually end up being a little more space efficient for each incremental change since its diffs don't need to store entire filesystem blocks.
kbuck··on GNOME Disabling Middle Click Paste
This change was backed out: https://git.gnome.org/browse/gnome-settings-daemon/commit/pl...
kbuck··on Anatomy of a hack: even your 'complicated' password is easy to crack
If you use the printable representation of the hash, the dictionary of characters that the hash uses is only digits 0-9 and a-f. While they likely still won't guess this, it's better to use 40 characters of the printable output of /dev/urandom directly, e.g.:

  dd if=/dev/urandom bs=512 count=1 | strings -n1 | tr -d '\n'
Edit: the original question, before it was deleted, was whether using a hash of data from /dev/urandom would result in a good password.
kbuck··on Newest YouTube user to fight a takedown is copyright guru Lawrence Lessig
No, the article says that only a few lawsuits have resulted in damages per section 512(f) of the DMCA [1] (which places a penalty on knowingly misrepresenting a work when filing a DMCA notice against it, if I am reading correctly). It sounds like they're able to sue under 512(f) in this case because Liberation Music pressed the issue even after they had been notified that the use was fair use. I am not a lawyer, though.

[1] http://www.copyright.gov/title17/92chap5.html#512

kbuck··on San Francisco Real Estate Exuberance
I live in the bay (but not SF), and the biggest thing that would would give me pause here is that I don't want to live in Boise, Denver, or Phoenix.

Some people are fine with living anywhere. Others are looking for good weather, a specific culture, or something else.

kbuck··on Tor use is now forbidden on Kimsufi's OVH
FreeNode's use is a bit more extensive than just requiring an email address - you have to create the account from a non-Tor IP, so if you do something bad and get banned, they ban the account (thus preventing further access from you via Tor) and then also have the option of banning the IP that registered the account (preventing it from registering further accounts that will be abused via Tor). If they really want to, they can also ban the email address, but in practice this really isn't worthwhile as it's so easy to get a different one.
kbuck··on A Tour Inside CloudFlare's Latest Generation Servers
It surprises me that the SYN attacks are being mitigated on the machines themselves; I was under the impression that this is typically done with hardware firewalls that offload the TCP handshake (thus filtering out spoofed SYN packets and other connections that the remote machine doesn't intend on actually establishing).

It does seem like doing it on the target machine will reduce latency a bit, though, since the hardware TCP offloaders usually repeat the TCP handshake (this time to the actual server) after confirming that it's valid.

kbuck··on I believe "noreply" is bad customer service
Typically, noreply addresses are used as a blackhole for mail that probably won't be replied to, and any replies are either auto-generated (e.g. mail delivery failure notices), spam, or other undesirable mail.

I have seen a good compromise for this, though: a piece of software I use sets the sending address to "noreply.support@mydomain.com"; if you want to reply to the message (and you aren't a spammer or mailer-daemon), you simply delete the "noreply." from the beginning.

kbuck··on Grep too slow? Use git-grep
There's another interesting method for speeding up regex searches as well - a trigram index[1]. This is what Google's code search used to do. A simple command-line version written in Go[2] was released for local use. There's even an ack replacement based upon it[3].

[1] http://swtch.com/~rsc/regexp/regexp4.html [2] http://code.google.com/p/codesearch/ [3] https://github.com/rliebling/fastrAck

kbuck··on AT&T will start selling customers’ usage data
They'll probably make a large sum of cash out of it, too, and subscribers definitely won't see a decrease in their bill.

I was rather surprised myself when I priced out wireless service; AT&T came out $20 more expensive than everywhere else and their reps couldn't come up with a way to give me a more competitive price. I went elsewhere (as I was planning to do anyway).

Unfortunately I am stuck with AT&T for my residential internet access; my apartment isn't wired for cable (and refuses to let the cable company wire it), AT&T is the only available phone service, and sonic.net doesn't have a nearby DSL hub. That leaves me with U-Verse, dialup, or something wireless (and therefore laggy).

kbuck··on Mac Pro
Actually, a 16x PCIe 3.0 slot can do ~128Gbit/s each way - ~256Gbit/s in total[1].

[1]: http://www.pcisig.com/news_room/faqs/pcie3.0_faq/#EQ3

kbuck··on Yahoo, please start with a Vulnerability Reward Program
I don't think this analogy works. With this analogy, they'd have to be adding bugs to the code and then "finding" them to get the reward. In this case, having a reward would most likely result in more people specifically looking for bugs, but they'd be looking for them so that they could report them and get money for it. It's better to have to pay out a bug bounty than have a malicious entity find and exploit the bug later.
kbuck··on A determined 'hacker' decrypts RDS-TMC
There's more about the discovery of the RDS data here: http://windytan.blogspot.fi/2013/04/how-i-discovered-rds.htm...

(there's also a couple links at the end of this article discussing how she modified her radio to provide a digital interface for the data)

kbuck··on Tesla Model S Suspension Walkaround
They effectively do dissipate the extra energy already - as heat, from the physical brakes. If they can't charge the battery faster than .25g of breaking would provide, there's no reason to put increased stress on the engine (it's much more expensive than a physical braking system).
kbuck··on So, I tried Dwolla
FYI, those sound like credit check questions. They probably did some sort of credit pull.

(They know the answers to these because the credit reporting agencies know how much the house cost, where it was located, what previous address(es) you've had on your credit accounts (including credit cards), etc.)

kbuck··on Check your router for open ports
I was talking about portscan.me, not checkmyrouter.org - unless you happen to run both.
kbuck··on Check your router for open ports
It's rather disappointing that this doesn't default to using nmap's -PN option, since they can be reasonably sure that the host actually is up (after all, it just requested the web page). Not all routers respond to ping.
kbuck··on We are currently taking a DDoS attack and are working to mitigate
The attackers would just find such a user and spoof their IP. DDoS is a hard problem to solve, and it's a shame that so many ISPs and datacenters don't work harder to prevent spoofed traffic. On top of this, they'd still need routers and switches in front of their machines big enough to handle the traffic from the attack plus the load of trying to filter out the good traffic (this kind of hardware is quite expensive).
kbuck··on Firefox: Why we won’t enable Do-Not-Track by default
Putting aside my opinion on do-not-track, I think it's perfectly reasonable that it's off by default, simply because that is the current behavior of the browser. If they enabled it by default, they'd be changing it out from under current users.
kbuck··on Firefox: Why we won’t enable Do-Not-Track by default
Forcing the user to choose something and refusing to run if they don't, even when it's a non-essential setting like this? That's a terrible idea. I'm annoyed enough when browsers ask me if I'd like to set them as default; the last thing I want is a 10-page questionnaire of the browser's settings.
kbuck··on The inside story of Lenovo's ThinkPad redesign
Sorry, Lenovo, I'd rather have "dropped 3 feet onto tile floor and still works fine" than "thin and sleek". This is why I buy ThinkPads, not because they're trendy and look cool. My laptop is for getting things done, not acting as a fashion accessory.

I also don't really see the logic behind getting rid of the hardware buttons for the trackpoint but keeping the VGA port. How are hardware mouse buttons uglier than a VGA port? Every time I look at my VGA port, I wish it were HDMI or DisplayPort.

It looks like my current ThinkPad will be my last.

kbuck··on The inside story of Lenovo's ThinkPad redesign
Gestures are one thing, but I've got a laptop now that has "virtual buttons" on a trackpad (the trackpad even physically clicks down) and it's excessively annoying to use. I can't feel which "button" I'm pressing, so mistakes are made. I'd rather have a trackpoint + 3 hardware buttons any day.
kbuck··on What's up with HN?
There's a third class as well: single-byte UDP and/or TCP SYN: designed to overload the routers and/or switches close to your machine (and if it it's a VM, the hypervisor as well). TCP SYN can also end up overloading the OS's TCP stack (although syncookies are an incredibly easy defence against the latter).
kbuck··on How I spend my first 5 minutes on a server
Why install fail2ban? You already have SSH password auth disabled, and you only allow SSH connections from your office. Won't this just risk banning your own office if someone's SSH client is misconfigured?
kbuck··on Why I Like Go
Frankly, I think a lot of the people currently working with C/C++ are avoiding Go because of the garbage collector. You can't trust a garbage collector; you don't know when it will run, how long it'll take, or how quickly it will free the memory you used. C/C++ programmers are used to having complete control over all of this. Sure, you could familiarize yourself with the internals of whichever GC you're working with, but at that point you might as well have invested the same amount of time writing the program in a language without a GC.
← PreviousPage 5 of 6Next →