HNHacker News
TopNewBestAskShowJobs

kenmacd

334 karma · joined December 13, 2013

my public key: https://keybase.io/kenmacd; my proof: https://keybase.io/kenmacd/sigs/g5xURBRm8cP8h-SbNwHSFrcFp5iG-oPcn_R3y0GvEC8
submissionscomments
kenmacd··on When Does Life Stop? A New Way of Harvesting Organs Divides Doctors.
> There is not any version of this issue that isn't a particularly morbid form of the trolley problem.

Do you believe withdrawing life support is murder? What about a doctor following a patients do-not-resuscitate order?

If an accident causes someone to be decapitated, is transplanting the heart from the headless corpse still murder? What if it wasn't an accident but a beheading; who committed the murder, the person that cut off the persons head, or the person that transplanted the heart (or was the victim murdered twice).

kenmacd··on When Does Life Stop? A New Way of Harvesting Organs Divides Doctors.
> I’ll admit this article gave me some uncomfortable feelings over that fact.

Which part made you uncomfortable? Would it improve your comfort level if they started by cutting of your head?

> they at least need to provide multiple classes of Organ Donor

Places do have choices allowing donors to decide which organs, and you could make more specific wishes known in a personal directive. I'm not sure 'classes' makes sense though, as there's a lot of different variables that different people could think should be encoded in an organ donor class.

kenmacd··on Toyota's $10k Future Pickup Truck Is Basic Transportation Perfection
While I applaud the modularity here, I just can't get excited about a ICE vehicle from a company actively lobbying against BEVs.
kenmacd··on From S3 to R2: An economic opportunity
There's at least a couple of reasons that your analogy doesn't really work.

First a lot of these roads are 'free' and yet you're still being charged for it. If two large networks come to an agreement then they connect the two networks (ie build that road), but no money changes hands.

Second if there is a paid peering agreement in place (ie say AWS had a cost to push your data out), that still wouldn't be billed to them in the way they're charging you. Instead they'd be paying for the rate of traffic at something like the 95th percentile of the max. This means that you could download a petabyte of data from them when the pipe isn't busy and cost them nothing, or you could download a gigabyte when it's busy and push up the costs.

kenmacd··on Why every microwave sucks these days
I have an LG that's an inverter one. I agree though, don't buy a non-inverter model if you care at all about the quality of what comes out of it.

And for the above poster, +30 starts it, it plays a little tune when done, and then every maybe 30s afterwards for 2 or 3 times. Oh, and the turntable rotates at 0.1Hz so a mug's handle is facing the same way it went in after any interval of ten seconds.

kenmacd··on 26% of the top websites are now blocking GPTBot
And yet you didn't cite any of the reference material you used to post that reply, or any of the reference material that led to you having that opinion in the first place.

I'm not being flippant here. We all use massive amounts of reference material to even think the most basic thoughts. Expecting you—or an algorithm—to be able to quote or even know the reference material that let to anything you say is a pretty high bar.

kenmacd··on 26% of the top websites are now blocking GPTBot
That's a good question... I suppose it seems to me like they're trying to keep useful information locked down. Even though this bot isn't 'public', it's still feels a bit like they're an author saying they don't want their book in a library. Actually it's even worse than that because they want to pick and choose who is allowed to read their words.

I guess another way I see it is like the site has put a banner at the top saying I can read their content, but can't use anything I learn from it, and can't tell you or anyone else about anything I've read. I get that in this case the 'me' is an algorithm and not a person, but does that really matter? If I read a lot of info on welding and then offer a 'learn to weld' class, how much does that differ from what the openai algorithm is doing. (And if it is public, are these same sites going to welcome the bots? I doubt it)

It also seems rather reactive and not well thought out. To include a quote from an Ars article (which gptbot can't read):

> As a thought experiment, imagine an online business declaring that it didn't want its website indexed by Google in the year 2002—a self-defeating move when that was the most popular on-ramp for finding information online.[1]

Or a couple quote Stephen King on another site that gptbot can't read[2]:

> I have said in one of my few forays into nonfiction (On Writing) that you can’t learn to write unless you’re a reader, and unless you read a lot.

> Would I forbid the teaching (if that is the word) of my stories to computers? Not even if I could. I might as well be King Canute, forbidding the tide to come in. Or a Luddite trying to stop industrial progress by hammering a steam loom to pieces.

As I said, to each their own. I just would have expected a site like NPR, that lists it's mission as "to create a more informed public", to not take actions that work directly against that goal.

[1] https://arstechnica.com/information-technology/2023/08/opena...

[2] https://www.theatlantic.com/books/archive/2023/08/stephen-ki...

kenmacd··on 26% of the top websites are now blocking GPTBot
I really don't understand why sites would do this. To each their own, but it currently lowers my opinion of the site. I was disappointed to see NPR and Ars on the list.
kenmacd··on How mobile apps illegally share personal data
Thanks, I should take a look. I've also been meaning to try DivestOS.

I'm certainly not holding my breath on more GrapheneOS support, as so few people care. I'm not entirely sure it'd be the right fit for me anyway. I'm currently using a microg setup with lsposed so I can patch out some junk in modern apps (like Outlook trying to be device admin), and this kind of hooking is not something GrapheneOS is interested in (a feature request I opened a while back: https://github.com/GrapheneOS/os-issue-tracker/issues/284).

kenmacd··on How mobile apps illegally share personal data
As much as I'd love to run GrapheneOS—and in the context of the original post—I just can't bring myself to willingly give the Google ad-machine my money. I keep hoping another manufacturer will step up and drive support for their devices.
kenmacd··on Govt of Canada proposes a 4% Link Tax
> The so called democratic process objectively sucks.

It's not the democratic process that's the issue, it's the first-past-the-post. Fortunately the party to win the 2015 election vowed: "To make sure that every vote counts, the Government will undertake consultations on electoral reform, and will take action to ensure that 2015 will be the last federal election conducted under the first-past-the-post voting system.", so it must be fixed...

kenmacd··on Lazygit: Simple terminal UI for Git commands
>> git absorb will automatically identify which commits are safe to modify, and which staged changes belong to each of those commits. It will then write fixup! commits for each of those changes.

This looks like exactly what I wanted. Thank you!

kenmacd··on Lazygit: Simple terminal UI for Git commands
Ty. I've seen similar in other tools, and I agree that it's super quick... unless you sign your commits with a key that requires a physical touch of a yubikey. Then it's <tap> <wait> <tap> <wait> for every commit that comes after the one you just modified.
kenmacd··on Lazygit: Simple terminal UI for Git commands
Interesting project... in the hopes of maybe nerd-sniping you (or having someone tell me where it already exists), I'll tell you the story I'd really like a solution to but can never seem to find time to build:

I have 5 un-pushed commits. I missed a 1-line change to that first one. I add that one line change to staging (gitui/lazygit/whatever), then I want to `git commit --fixup=COMMIT`. Finding that COMMIT is always a manual process for me for two reasons.

First I have to find the commit to which it applies. This commit is almost always the commit that changed the same line, or added lines around it, or something similar. I guess you could say it's the commit with the closest proximity to the change I'm adding.

Second I have to find the hash of that commit. If I've since done something like an autosquash rebase then it'll have changed. I generally end up using the mouse to do a copy/paste at this point.

Why not skip the fixup commits and just rebase right then, you might ask. Well the commits are signed, and signing requires tapping my yubikey for each commit after that.

I would really like to be able to do something like `git commit --I'm-an-idiot-and-missed-this-so-please-apply-a-fixup-to-the-proper-commit`, and have it do the figuring out for me.

kenmacd··on Proton Pass: Open-Source and Encrypted Password Manager App
Correct me if I'm wrong, but I suspect this has the same issue preventing me from using it as does Bitwarden, namely: if I give you my vault and my password, you can access all my passwords.

With how common hardware security keys (or even just tpm2) are these days this limitation seems inexcusable to me. Which is why I'll stick with gopass/pass using my yubikey (w/ touch policy fixed). You might hack my machine and trick me in to decrypting a few passwords, but at least you won't make off with them all.

kenmacd··on Signal president says company will not comply with U.K. ‘mass surveillance’ law
> e.g. phones, mail.

What about all the in-person conversations. Seems those might be considered just a bit more traditional than phones conversations, and haven't been subject to those same search warrants.

> So what we're saying is E2E apps are more important than current law we have, and we want to invalidate the ability of the police to investigate crime. > > How can that make sense?

(*proposed* British online safety legislation)

Let's expand on that then: how can it make sense what humans can have in-person conversations that are not subject to search warrants. These e2e-private-in-person conversations prevent the state from investigating crime.

If police should be able to always access your digital information, would you support the same in the case of non-digital information. Should building codes be updated to require microphones be installed in very room?

If you're not in support of microphones in every room, then please tell me why the conversation between two parties, be they lovers or criminals, should lose it's ability to be private the moment it crosses the internet?

kenmacd··on Self-hosted photo and video backups directly from your mobile phone
While containers solve a lot of problems, they do create a bunch of new problems. For example that 'every dependency' is a double-edged sword. Now instead of just one version of OpenSSL on my host I have a bunch. Half them are vulnerable, and none of them share the same memory.

Personally I'm looking forward to when this is included in Nix so I get a ephemeral/reproducible install that doesn't add a second copy of both postgres and ngingx.

kenmacd··on Firefox address bar
Well, in case you decide to move back, give Sidebery a try. I switched a while back haven't had any issues.
kenmacd··on Wolfi: A community Linux OS designed for the container and cloud-native era
Wait, are you me? I tried to convince musl to not break in this case (https://www.openwall.com/lists/musl/2022/12/04/1), but mostly got a "we're right, cloudflare's wrong" answer. Tweeted at Cloudflare about the issue (https://twitter.com/KennyMacDermid/status/160055878578481971...) and never heard back. I really don't care who's right, and can't change who's using Cloudflare+DNSSEC, so instead I just don't use musl.

[Previous comment](https://news.ycombinator.com/item?id=35058094): ---

My personal 'musl broke it' story comes from resolving domains from Cloudflare that use DNSSEC in a K8 cluster. Basically this:

  - K8 sets container to use `ndot:5`, causing the search list to be used
  - Musl walks that search list looking for domain
  - Cloudflare does not set the NXDOMAIN flag on a DNSSEC domain but does include an NSEC record (if you query with the dnssec flag).
  - Musl takes this 'NOERROR' reply and returns an EAI_NODATA.
Is Cloudflare wrong? I don't know, maybe. They say some things about the standards[0] and that it's technically 'right'. I don't see why they couldn't change the behaviour for queries without the dnssec flag, but I digress.

The issue is that every other libc I tested will continue searching and actually resolve the domain. Musl is the odd one out, and _only_ in the case where the search list ends up with domain using Cloudflare and dnssec.

Even if Musl is 'right' here, when it disagrees with major implementations and a major DNS nameserver does it really matter?

[0]: https://blog.cloudflare.com/black-lies/ ---

kenmacd··on Google is about to make life more difficult for custom ROM fans
> The real issues are bootloaders which cannot be unlocked

I haven't run in to that lately, but an issue I find much more annoying is the lack of support around re-locking with a custom root of trust. I think a few others support it, but I've only seen mention of it on the Pixel phones (and I won't buy Google hardware after they wouldn't replace my Pixel 3 that was bricked by their EDL hardware issue).

kenmacd··on NRF52840 Connect Kit – Rapid prototyping kit for your next connected projects
I miss Particle's mesh support. It worked great for me in my tiny environment. I tried to get a thread border router running using zephyr on a xenon with the ethernet featherwing, but couldn't get it working.
kenmacd··on Arduino Joins Zephyr Project
I would think so. I've tried to do 'feature' groups of options, but without any way to do optional includes I gave up on that idea.

Maybe I'm just doing it wrong with just trying to add the dependencies I want. It might work better if I used the menuconfig GUI. To me though it seems if I decide I want to enable 'CONFIG_NET_TCP' on my project, I shouldn't also have to specify 'CONFIG_NETWORKING'.

As for why it works better in the kernel, that's a good question that I don't know the answer to as it's been years since I tried to build a kernel with a minimum configuration.

kenmacd··on Arduino Joins Zephyr Project
Zephyr has a lot of good points, but I really wish it didn't use Kconfig. Getting a working config seems to be mostly a matter of copying an already working example. It might be okay for hardware side of things, but it's a really bad at software/feature dependency.

Set https://docs.zephyrproject.org/latest/build/kconfig/tips.htm... and the issue: https://github.com/zephyrproject-rtos/zephyr/issues/52575. And don't even get me started on trying anything to group options together.

kenmacd··on Nostr – Decentralized social network
What does it rate-limit based on? If it's just IP address then I doubt that'll do much good as it won't stop any spammer worth their salt and yet could affect large groups stuck behind a NAT device.
kenmacd··on A photon-recycling incandescent lighting device
> Consider that electricity mostly comes from renewables now, it just doesn't matter what the efficiency is.

As far as I know we're not yet in a post-scarcity energy economy.

Think of your favorite topic of research. Now consider if you'd rather spend some of that renewable energy furthering that research, or on generating unwanted heat from a bulb and then moving that heat out of your living space.

kenmacd··on I Will Never Use Alpine Linux Ever Again
Maybe. The problem is that I couldn't control the DNS settings where this code was run, nor could I control what ended up in the search domain. The query did not have the +dnssec flag, but that didn't actually help because Cloudflare wasn't setting NXDOMAIN either way.

This was in golang code, so I ended up switching to `netdns=go` because like all the other libc's, the golang resolving code worked fine.

kenmacd··on I Will Never Use Alpine Linux Ever Again
My personal 'musl broke it' story comes from resolving domains from Cloudflare that use DNSSEC in a K8 cluster. Basically this:

* K8 sets container to use `ndot:5`, causing the search list to be used * Musl walks that search list looking for domain * Cloudflare does not set the NXDOMAIN flag on a DNSSEC domain but does include an NSEC record (if you query with the dnssec flag). * Musl takes this 'NOERROR' reply and returns an EAI_NODATA.

Is Cloudflare wrong? I don't know, maybe. They say some things about the standards[0] and that it's technically 'right'. I don't see why they couldn't change the behaviour for queries without the dnssec flag, but I digress.

The issue is that every other libc I tested will continue searching and actually resolve the domain. Musl is the odd one out, and _only_ in the case where the search list ends up with domain using Cloudflare and dnssec.

Even if Musl is 'right' here, when it disagrees with major implementations and a major DNS nameserver does it really matter?

[0]: https://blog.cloudflare.com/black-lies/

kenmacd··on LEDs from Dubai (2021)
They're under contract, but just as the "make them and we'll keep others from competing with you here", not "you can't sell these elsewhere".

The only reason you "can't buy them" is because you wouldn't (or at least people wouldn't). You can't easily tell how good the LED setup is in the bulbs, and price isn't necessarily a good indicator, so you're unlikely to pick the more expensive item.

kenmacd··on We Found 28,000 Apps Sending TikTok Data. Banning the App Won't Help
I can't see it for me, but who knows. The same holds for my family though, they're much more likely to deal with the US government than China.

I maybe should add that I'm not saying I like any of the general data collection, and I'm not saying I think the risk is high that either government will 'disappear' me/family. I just read the article expecting to read about behaviour that was beyond what other companies were doing, but I didn't see it. I'd be willing to entertain that there's more the US intelligence knows but aren't saying though.

kenmacd··on We Found 28,000 Apps Sending TikTok Data. Banning the App Won't Help
In my (Canadian) view my data going to the US is a lot worse.

From a physical safety perspective, I'm unlikely to ever go to China, but I do sometimes have to fly in to or through the US. In doing so I risk being held in solidarity confinement and extradited to a another country to be tortured (see Maher Arar). Or perhaps held in some prison with no rights because it's just slightly outside the US, and again tortured depending on the daily definition of what's not actually torture. That I haven't actually done anything doesn't seem to matter very much.

Plus a large amount of my data already passes through the US, where it's collected. Because I'm not an American I'm not even afforded the little bit of privacy protection of this data. For example it's not easy to use my Canadian voip provider without the traffic being routing through the US.

The US is also a much larger threat to country's sovereignty than China is. For example they've basically forced my government to hand over Canadian bank account data unless citizens explicitly decree that they're not from the US. They've forced through ridiculous DRM and drug laws.

← PreviousPage 4 of 8Next →