HNHacker News
TopNewBestAskShowJobs

lights0123

2,054 karma · joined May 27, 2020

he/him

https://lights0123.com/

github.com/lights0123/

submissionscomments
lights0123··on 1.38 Millimeter Microcontroller
Rust does not rely on syscalls or libraries on embedded targets, which is what the #![no_std] marker at the top of the project indicates. On some platforms, like ESP32, Rust can make calls into the RTOS and don't need that marker, but other embedded targets don't provide access to the std crate and you need to interact with peripherals from Rust or by interfacing with C or assembly.

Rust's only requirement is that memcpy, memmove, memset, memcmp, bcmp, and strlen are available, and it can provide them if needed: https://github.com/rust-lang/compiler-builtins

lights0123··on When su replaced login for becoming another Unix login
GDM, at least, does: https://askubuntu.com/questions/910108/why-is-my-gdm-at-a-di...

This has stayed the case with the transition to Wayland: pressing Ctrl + Alt + F1 shows me the login screen, and Ctrl + Alt + F2 takes me back to the desktop.

lights0123··on Malicious npm packages detected across Red Hat Cloud Services
Software vulnerabilities are often not placed maliciously, and are present in the original source. If you don't patch them if discovered later, you'll be vulnerable to them.
lights0123··on Setting up a free *.city.state.us locality domain (2025)
Cloudflare only supports managing top level domains on the Free plan.
lights0123··on Postmortem: TanStack NPM supply-chain compromise
Until it overrides sudo in your $PATH to install malware after you enter your password later.
lights0123··on A web page that shows you everything the browser told it without asking
Not since browsers started partitioning caches in 2020: https://developer.chrome.com/blog/http-cache-partitioning/
lights0123··on Dirtyfrag: Universal Linux LPE
With the exploits published as-is, you'll only get root inside the container: there's no explicit namespace break, and calling setuid() in a container just gives you root in the container.

However, it can be used to modify files that are passed into the container (e.g. Docker run -v), or files that are shared with other containers (e.g. other Docker containers sharing the same layers). kube-proxy with Kubernetes happens to share a trusted binary with containers by default, which is how it can be exploited: https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kuber...

lights0123··on Localsend: An open-source cross-platform alternative to AirDrop
Only for discovery. The actual transfer happens over WiFi, which is many times faster.
lights0123··on Put your SSH keys in your TPM chip
I would love a world where I could put all my API keys in the TPM so malware couldn't gain persistent access to services after wiping my computer. This would be so easy if more providers used asymmetric keys, like through SSH or mTLS. Unfortunately, many don't, which means that stealing a single bearer token gives full access to services.

There's also the TPM speed issue. My computer takes ~500ms to sign with an ECC256 key with the TPM, which starts to become an issue when running scripts that use git operations in serial. This is a recurring problem that people tend to blame on export controls: https://stiankri.substack.com/p/tpm-performance

lights0123··on How Wake-On-LAN works (2020)
> The computer that you are trying to wake up also needs to be connect with an ethernet cable as it is not possible to send a magic packet over wifi.

While WiFi adapters may not support waking up the computer from a WiFi signal, you absolutely can send magic packets over WiFi as they're normally just UDP broadcast frames. Convenient for waking up a desktop from a laptop!

lights0123··on My university uses prompt injection to catch cheaters
I use a prompt like this that asks for model name and version! It's been effective so far, especially since I have edit history.
lights0123··on Root Persistence via macOS Recovery Mode Safari
Yep. While the Terminal is not an option from the 4 apps listed in the initial screen, it's available from Utilities → Terminal at the top. They even provide a convenient way to access the hard drive from another computer: https://support.apple.com/guide/mac-help/macos-recovery-a-ma...
lights0123··on SSH certificates: the better SSH experience
They do, for Enterprise customers only: https://docs.github.com/en/enterprise-cloud@latest/organizat...

They've rolled their host key one time, so there's little reason for them to use it on the host side.

lights0123··on Zstandard Across the Stack
Nice! There's also zstd's flush ability that I've used for streaming robotics data. You can write data and flush it over the network for realtime updates, but the compression stream stays open so it can still reference past messages. This means messages get smaller over time so you don't need to share a dictionary ahead of time. I'm not aware of other compression algorithms that have flushing capability like this.

> binary data to connected clients in tiny messages, each saying “field 5 on object X is now 123”

I wonder how Meta's newer, format-understanding OpenZL would do. I imagine its schemas could be auto-generated from protobuf.

lights0123··on Zstandard Across the Stack
They moved on to Courgette, then to Zucchini: https://chromium.googlesource.com/chromium/src/+/HEAD/compon...

These are optimized for compiled code though.

lights0123··on Show HN: Zerobox – Sandbox any command with file, network, credential controls
> zerobox --secret OPENAI_API_KEY=$OPENAI_API_KEY

Linux by default allows all users to read CLI arguments of running processes. While it looks like your bwrap invocation prevents the sandbox from looking at this process (--unshare-pid), any other process running on your system can read the secret.

lights0123··on This specific GitHub issue is crashing
all of GitHub is crashing right now, even though githubstatus.com only mentions pull requests being an issue.
lights0123··on CSS is DOOMed
> Interestingly, it was more choppy in Chromium.

Firefox's WebRender is truly a great creation. While Chrome is faster at most things especially involving JS, Firefox puts so much of its rendering on the GPU so moving elements around is incredibly fast.

lights0123··on Cocoa-Way – Native macOS Wayland compositor for running Linux apps seamlessly
While I agree with the rest of your comment, they do mention they use OrbStack as their hypervisor in their demo video.
lights0123··on Health NZ staff told to stop using ChatGPT to write clinical notes
Azure OpenAI is not the same as paying OpenAI directly. While you may not be able to pay OpenAI for them to run models in Australia, you can pay Azure: https://azure.microsoft.com/en-au/pricing/details/azure-open...

The models are licensed to Microsoft, and you pay them for the inference.

lights0123··on Health NZ staff told to stop using ChatGPT to write clinical notes
Many AI companies, including Azure with their OpenAI hosting, are more than willing to sign privacy agreements that allow processing sensitive medical data with their models.
lights0123··on Why does C have the best file API
Yes, it’s the SIGBUS signal.
lights0123··on C++26: Std:Is_within_lifetime
Python removes features all the time in 3.x releases. For example, I was not a fan of the distutils removal in 3.12 which broke many legacy but otherwise functional packages. Deprecated functions and classes are also removed from packages regularly.

They do publish removal plans years in advance, e.g. see Python 3.17's plans: https://docs.python.org/3/deprecations/pending-removal-in-3....

lights0123··on Show HN: Extracting React apps from Figma Make's undocumented binary format
I agree. It would likely have identified the separate deflate and zstd chunks automatically.
lights0123··on Dell admits it made a mistake when it abandoned XPS
It is slightly wider than the space bar. I've never had an issue with mine, as it is located exactly where I expect it to be.
lights0123··on I program on the subway
https://zealdocs.org/ is surprisingly decent.
lights0123··on Show HN: Shittp – Volatile Dotfiles over SSH
Yes, Firefox 147 will respect XDG dirs.
lights0123··on Rust's Block Pattern
GCC adds similar syntax as an extension to C: https://gcc.gnu.org/onlinedocs/gcc/Statement-Exprs.html

It's used all throughout the Linux kernel and useful for macros.

lights0123··on Shai-Hulud compromised a dev machine and raided GitHub org access: a post-mortem
noexec now prevents mmaping files on that filesystem as executable.
lights0123··on Show HN: Epstein's emails reconstructed in a message-style UI (OCR and LLMs)
See also: https://jmail.world/
Page 1 of 20Next →