HNHacker News
TopNewBestAskShowJobs

kevincox

15,190 karma · joined November 20, 2013

https://kevincox.ca
submissionscomments
kevincox··on Gitea 28.0
Of course I wouldn't recommend taking the conclusion. But it is a valuable view of some differences that the Forgejo developers perceive as valuable.
kevincox··on The new Firefox design is here
Seriously, are you proud of the new look? SHOW IT TO ME. Even the video was mostly themed mock-ups that didn't show what the actual design looks like. Just post a screenshot of the whole browser.
kevincox··on Dutch governments builds alternative for Microsoft based on NixOS
llama.cpp has a flake in-repo that I often use for trying out different branches and patches. I also have yet to have an issue just replacing the src and build number attribute in the nixpkgs build (in one cases I wanted to add an additional CMake flag but that was also easy).

IMHO this is way easier than without Nix in many cases as figuring out the upstream build process and getting it running can often be quite the chore. With Nix it is all set up for you.

kevincox··on We just shipped support for the ugliest part of HTTP: Vary
One major issue with Vary is that it makes cache coalescing very complicated. This is because you can't know whether two requests will share a response until you get that response. So for subsequent requests you need to decide if you should block it hoping that the response will satisfy it or if you should send it through pessimistically, possibly triggering a thundering herd effect on every cache rotation.

I'm not sure if it is possible to solve this nicely in a generic way, but it does make it a bit ugly.

kevincox··on Linux support is coming to Snapdragon X2 Series
Thanks. This link has more detail about Linux support. I submitted it separately for discussion.

https://news.ycombinator.com/item?id=49824189

kevincox··on OpenAI bots knew about the RubyGems caching vulnerability
I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.
kevincox··on Make your first edit to OpenStreetMap
Documenting public water sources is an incredible public good. I thank you for your efforts.
kevincox··on Rust is tier-1 language at Microsoft
How does Rust help with 2 at all? IIUC the main requirements were not memory or performance related but TPM and instruction set minimums.
kevincox··on What do Visa and Mastercard do? An intro to card networks
No, but my credit card has no battery, requires no cell service, is waterprrof and quite durable.

I see the advantages of the Chinese system but I really found myself missing my card.

- While payer-offline payments were possible most merchants didn't want to (and some seemed unable to) so payments in places with bad cell service were painful.

- It was a lot more steps to open the app and enter scanning mode or display your code than to just tap a card or phone.

- It was always unclear if you were scanning or being scanned, leading to friction for every payment (generally larger brands scan you and you scan for smaller merchants).

Honestly for in-person card payments are just nicer.

For online WeChat was better, but no different than Apple Pay or Google Pay except for course that it is standardized by the government.

kevincox··on Jellyfin 12.0
This is almost certainly a you problem. Tons of people play remuxes with Jellyfin.

I would check that your client supports the requisite codecs, and has a sufficient network connection. Or alternatively check that your server has enough horsepower (GPU or CPU) to transcode.

kevincox··on Delidded Intel I9-14900KS CT Scan
Probably because the account has only ever submitted its own content.

https://news.ycombinator.com/submitted?id=LabsLucas

> Please don't use HN primarily for promotion. It's ok to post your own stuff part of the time, but the primary use of the site should be for curiosity.

> https://news.ycombinator.com/newsguidelines.html

kevincox··on Can I opt out of my input or output data being used for training?
Yes, I found this comment very hard to understand until I realised they were talking about it being opt-out with no setting to change it. (At first I thought it was opt-in by default, and the "by default" implies that there is a setting to change the opt-in/opt-out setting)
kevincox··on Play Store blocks AuroraStore, hurting GrapheneOS users
This also has nothing to do with GrapheneOS except for some user overlap.
kevincox··on Saving 100 terabytes of memory by optimizing 1.1.1.1's DNS cache
It sounds like you are just writing your own allocator? That sounds great, but why is it going to be better than jemalloc?

There are many reasons a specialized allocator can be better, but just saying "write your own" doesn't really add much value to the discussion.

kevincox··on Three ways to smuggle SQLite into Nix
It seems that you could just compile the data into the WASM blob. Then use a more optimized query engine than sqlite. This should be very fast to compile (most of the WASM is just a byte buffer, the code is just a few binary searches and some result encoding). The downside is that you need to recompile to update the repo, but I don't think that should be particularly expensive.
kevincox··on The August 17 outage
Thundering herd is different. Thundering herd is when a lot of clients trigger requests at the same time. Common situations being a specific time, some other event just occurred or synchronize on other parts of your infrastructure (such as readers queuing behind a R/W lock that then get unblocked at the same time to continue to make a bunch of requests at the same time.

Request amplification via retries is a different problem that causes large amounts of traffic (but it is generally more steady than spiky)

kevincox··on Malicious Rust crate Arrayref runs a build-time payload
Sandboxing the process only works well when the malware requires more capabilities than the software itself.

So if your software needs to make HTTP requests and read the filesystem then the malware will be able to make HTTP requests and read the filesystem, which is enough for a ton of malware. Sure, maybe you can limit the directories it can access a bit and possibly some sort of network filtering, but it isn't a silver bullet.

Capability security in-language would make a huge difference, because the more granular you "sandbox" the less likely it is that the compromised component has the access it wants. For example if the HTTP client library is compromised maybe it can't access the filesystem so can't steal your cookies. Or maybe like in this case no permissions were needed at all and despite the process having enough capabilities for malware this malware can at worst return bad values and try to chain this to an exploit which is far more difficult than just running it itself.

kevincox··on Win-V combo from Windows on Ubuntu
It is if you use full-disk-encryption which is highly recommended.
kevincox··on Show HN: Declarative-forms – await an object the way prompt() awaits a string
I really like this approach. It is very natural for modal dialogs to be things that you await. I have used it in various projects in the past.

The main downside is if you need to affect the dialog from "outside". For example data that refreshes and needs to update the form (although in most cases a changing form is an anti-pattern anyways). But also any form of dynamically updating data (a clock) or lazy loading (maybe for a dropdown that depends on others) you are going to want a full UI library rather than a one-shot declarative form.

When I used this I had a separate call to create the dialog and await the result. This way there is a handle you can use to update the data if you need to. But even then if you are using React it probably doesn't integrate as cleanly as a "regular" component would.

But still, I think in most cases this is what you need and the easiest way to get it. I wouldn't take a more complicated approach until you need to.

kevincox··on Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing
I assume this oracle will be behind 20 layers of anti-bot protection, CAPTCHAs and hardware attestation challenged. It will be incredibly painful to use. It won't stop the motivated attackers, but will make it too annoying for the average person.
kevincox··on Tell HN: Cloudflare silently injects its analytics when you switch nameservers
Yup, I explicitly had all anaytics turned off. But had a few sites using Cloudflare for caching. Now I'm checking and seeing this on all of them. This is gross and unacceptable. "Caching" does not mean "modifying my site".
kevincox··on AI by Hand
I clicked "Back" to leave the user-hostile website.
kevincox··on Dear people who work at the airport
Or just anyone involved in communication at all. For example my condo management team has names for every part of the building that they just assume that everyone understands. They don't seem to understand that most of the people living here don't spend most of their time reading the building floor plan.
kevincox··on 'Not acceptable': Judge orders Google to make rival app store installs easier
This storm fronts are really just Google trying to dig in as deep as possible.

On one end they are trying to fight the requirements for alternative app stores and making them as hard as possible to use.

On the other end they are trying to put hooks so that they can block installations of apps from other app stores.

Then they hope that regulation will take longer to dislodge the various methods they are using to retain control.

kevincox··on Text AI watermarks will always be trivial to remove
> Malicious compliance is to make cookie acceptance much easier than refusal.

That isn't malicious compliance, it is just non-compliance. If the equally difficult rule wasn't there then it would be malicious compliance.

kevincox··on GLM-5.3: Frontier coding with emergent cyber capabilities
This isn't latency bound, it is trivially parallelize. So you want to run it on the most efficient compute you have, not the fastest.
kevincox··on Pixel 11 Pro Fold
This used to be a critical feature for me I used to customize the colour per-app so I could see what notifications I had at a glance. However always-on displays have supplanted this use case for me.
kevincox··on Muse Glimmer: 30B-parameter model optimized for always-on local agent workflows
No compaction happened. (That is set near 256k.) It seems to really not like my domain but I've seen it for various things as well (especially high-entropy tokens). Dropping random characters or various things. I've tried various flash attention and context quantization settings but nothing seemed to resolve it completely.
kevincox··on London Underground begins scanning passengers' faces
This sentence struck me as well. It says what it is focused on, but nothing about what it actually captures.

What I would like to see is something like this:

- The detectors have a per-determined list of suspect faces and only record information when those faces are spotted.

- These detectors keep only a fixed length of recording that is permanently deleted unless it is actively linked to a crime and explicitly held as part of that investigation.

But it says nothing concrete. Just some nonsense about "focus" which doesn't mean anything.

kevincox··on Updated GPG Key for Signing Firefox and Thunderbird Releases
SSS doesn't support signing AFAIK. When I last looked into it GPG/PGP doesn't support shared signing.

You can use SSS to encrypt the signing key, but then you need to fully materialize the signing key to actually sign the release. Which makes the exact situation that occurred here possible.

The only way to do multi-signer PGP is outside of the PGP protocol, you just need to sign the artifact multiple times then have the verifier assert that a sufficient number of signatures are present. But again, this isn't supported by the regular PGP tools.

Page 1 of 34Next →