HNHacker News
TopNewBestAskShowJobs

m0dest

1,220 karma · joined September 19, 2013

submissionscomments
m0dest··on 98% isn't much
Yes, the decision to rely on modern CSS is more like serving restaurant food that contains cilantro. The predominant failure mode is partial credit.

The quality perception of this user segment is relative, too. That visitor who is using a version of Chrome that is 4 years stale? Their experience on the rest of the web was not pixel-perfect today. Many sites are inexplicably buggy for them. They might even be used to having to switch devices to complete some tasks.

Continuing to surf the web with a long-unpatched browser is also overtly negligent [1]. That negligent 2% of users is not a protected class. As such, you might observe that this 2% of users contributes only 0.2% of revenue / engagement / value and make a self-interested decision to stop supporting them.

[1] Except brief windows of time when old Apple devices continue to get Safari security updates without getting feature updates. Not relevant to the author's CSS nesting example.

m0dest··on A faster heart for F-Droid
Even if it's just the build server, it's really hard to defend just having 1 physical server for a project that aspires to be a core part of the software distribution infrastructure for thousands of users.

The build server going down means that no one's app can be updated, even for critical security updates.

For something that important, they should aspire to 99.999% ("five nines of") reliability. With a single physical server, achieving five nines over a long period of time usually means that you were both lucky (no hardware failures other than redundant storage) and probably irresponsible (applied kernel updates infrequently - even if only on the hypervisor level).

Now... 2 servers in 2 different basements? That could achieve five nines ;)

m0dest··on Unpowered SSDs slowly lose data
So, product idea: A powered "cold storage box" for M.2 SSDs. 2 to 8 M.2 slots. Periodically, an internal computer connects one of the slots, reads every byte, waits for some period of time, then powers off. Maybe shows a little green light next to each drive when the last read was successful. Could be battery-powered.
m0dest··on How to fix subsystem request failed on channel 0
Yeah, regardless of how one feels about the design decision to fail without fallback, the messaging seems like an oversight.
m0dest··on Google flags Immich sites as dangerous
It looks like Mozilla does use DNS to verify requests to join the list, at least.

  $ dig +short txt _psl.website.one @1.1.1.1
  "https://github.com/publicsuffix/list/pull/2625"
Doing this DNS in the browser in real-time would be a performance challenge, though. PSL affects the scope of cookies (github.io is on the PSL, so a.github.io can't set a cookie that b.github.io can read). So the relevant PSL needs to be known before the first HTTP response comes back.
m0dest··on Why Apple's Severance gets edited over remote desktop software
These days, if you're just wiring to a single workstation in a nearby next room, 50 meter active optical Thunderbolt 3/4 cables can carry 5K+ DisplayPort video passthrough and data from your USB peripherals.

(It's "passthrough" and not "uncompressed" because DisplayPort may use DSC depending on the resolution and frame rate.)

US$500 for an optical cable can be a lot cheaper than paying for HDMI extender sender and receiver boxes.

m0dest··on M4 Mac mini's efficiency
With a locked screen, key presses go to the password field. I have twice caused my user account to become disabled due to too many password attempts while cleaning my keyboard.
m0dest··on FTC's rule banning fake online reviews goes into effect
Yes. Most of the major apps play this review game, and there's no way to compete if you don't play it too.

The major apps typically exploit selection bias to solicit 5-star reviews. They will wait until the user meets some criteria for "having a good experience" and show an app review prompt at that moment.

Then, having amassed thousands of 5-star reviews, they will turn up the threshold so that only a trickle of the most likely 5-star reviews keep on trickling in to negate any negative organic reviews.

There's a related practice of "pre-prompting" where the app first asks the user whether they are satisfied and only solicits a real app review from those who pass the screening question.

It's all quite shady and makes it hard to trust app reviews. But until the app stores solve this, app developers need to play the game.

m0dest··on Show HN: 1-FPS encrypted screen sharing for introverts
Yep, this is achieved using slices, which can be arbitrary regions of the frame. Each slice can have its own quantization parameters (ranging from highly lossy to perceptually lossless). Each slice can also switch between intraframe prediction (more like still image encoding) and interframe prediction (relative to prior frames).

So, with this, you can have high-quality static text in one region of the frame while there is lossy motion encoding (e.g. for an animating UI element) in another region of the frame.

m0dest··on Show HN: 1-FPS encrypted screen sharing for introverts
The state of the art here is really Parsec, Moonlight, and Apple's "High Performance Screen Sharing" [0]. All three of these use hardware-accelerated HEVC in some UDP encapsulation. Under the right network conditions, they achieve very crisp text, 4K60 4:4:4 with low latency.

[0]: https://support.apple.com/guide/mac-help/screen-sharing-type...

m0dest··on Suspicious data pattern in recent Venezuelan election
If you were forced against your will to aid in this type of fraud, might you not intentionally include a subtle error in your work that reveals its illegitimacy to a careful observer?
m0dest··on TinyPod – Apple Watch case with scroll wheel
From what I can tell, the "Request Ride" intent for Uber is broken (throws error on any request) and has been like this for at least 2 years.

The Ride Request API [1] seems closed off to developers now, too.

[1] https://developer.uber.com/docs/riders/introduction

m0dest··on Reverse engineering Ticketmaster's rotating barcodes
Exactly. The privacy characteristics of government ID cards are worse than any other solution. When sharing such an ID, a person is providing several global, stable identifiers (e.g. ID number, full legal name). For adtech and data brokers, this is the ultimate fingerprint for tracking and matching.

In a perfect world, the digitization of these IDs would come with modern digital privacy and security. Scanning your ID number would only provide a recipient-specific ID that couldn't be matched with other vendors. Age eligibility and driver's licensing status would be presented as separate signed attestations that share no other data.

We aren't even heading in that direction yet.

m0dest··on Passkeys: A shattered dream
The lock-in situation with passkeys seems far worse than with password managers, though. There is no "export" option for iCloud passkeys - despite being cloud-synced across your Apple devices.

If you decide to switch from an iPhone to an Android phone, you're looking at an arduous process of enrolling a new passkey for every single site.

m0dest··on The FCC needs to stop 5G fast lanes
iOS 17 added explicit support for 5G slicing for QoS in consumer apps: https://developer.apple.com/documentation/network/nwparamete...

Android 14 added 5G slicing upsell for consumer apps: https://source.android.com/docs/core/connect/5g-slicing#5g-s...

This is imminent.

m0dest··on Backdoor in upstream xz/liblzma leading to SSH server compromise
It probably makes sense to start isolating build processes from test case resources.
m0dest··on HBO Max new Captcha system
Only in the US. In all other markets, the HBO Max app still functions, and the Max app will only show a "not available" message.
m0dest··on Show HN: Beepberry – a portable e-paper computer for hackers
The trademark issues with the BlackBerry logo on the keyboard, combined with the "Beepberry" name, are going to be a problem.
m0dest··on AT&T Wireless traffic shaping apparently making some websites unusable
When you tunnel/encapsulate your traffic, many variables change at the same time, such as:

- maximum transmission unit (MTU)

- TCP maximum segment size (MSS)

- different DNS responses leading to different edge servers

- TCP reordering, which may now occur on the tunnel layer

- lost packet retransmission, which may now occur on the tunnel layer

- time to live (TTL) hop count on the packet

- IPv4 may be used for some connections that were previously using IPv6, as some VPN services are IPv4-only

- different peering between the VPN server and the edge server

ISP traffic categorization is only one variable.

m0dest··on Tell HN: YouTube's web UI just got even worse
(likes / views) is still interesting, but you need to grade on a curve
m0dest··on Ask HN: Am I getting older or did typing on the iPhone become unbearable?
https://www.apple.com/ios/feature-availability/#quicktype-ke...

QuickType Keyboard: Multilingual Typing

English, Chinese, French, German, Italian, Japanese, Spanish, Portuguese, Dutch, and Hindi

m0dest··on Ask HN: Am I getting older or did typing on the iPhone become unbearable?
iOS autodetects and automatically switches languages as you described. The globe icon is just for switching key layouts. Language is independent of key layout.
m0dest··on Apple previews Lockdown Mode
Do you really trust your average IT department to make an informed decision about whether WebKit JIT is currently secure or not? I don't see Apple putting these in MDM Configuration Profiles. If they do, it will only be for Supervised Devices (i.e. devices owned by your employer, must be wiped to enroll).
m0dest··on Our plans for Thunderbird on Android
If anyone is getting a sense of deja vu, it's because this is was Outlook mobile strategy. Microsoft acquired a popular third-party Exchange mail client for iOS/Android, named Acompli, and rebranded it to Outlook.
m0dest··on An Ode to Apple’s Hide My Email
This is the million dollar question that Apple hasn't answered. What happens to these forwarding addressses if you cancel iCloud+?

The result is bad either way. It's either A or B. (A) Canceling iCloud+ doesn't remove existing Hide My Email addresses - which makes it possible to abuse by creating tons of extra addresses before canceling. Or: (B) Canceling iCloud+ deletes all of your Hide My Email addresses, locking you out of dozens of services (e.g. anything that sends an email as a MFA).

I suspect that it is actually (A). Someone just needs to test this and report out.

m0dest··on Letting users tick a ‘none’ checkbox
Don't forget that mobile is the majority now. As long as the hit target is appropriately sized, this is the kind of task that is much faster with touch than mouse/trackpad.

Users value attention more than time. I'd bet that 4 yes/no radio buttons require a lot less attention than trying to parse the example question from the article ("Will you be travelling to any of the following countries with any of these trailers? Select all countries that apply.")

m0dest··on macOS Monterey's new network quality tool is surprisingly good
This is awesome. I hope the client code will be included in the Apple's open source repository [1] after they update it for Monterey. It's hard to fully rely on a test without seeing its implementation, especially the responsiveness portion.

[1] https://opensource.apple.com/

m0dest··on Apple requires account deletion within apps in AppStore starting January 31
Frankly, this would still be a good start compared to the norm today: You can't even find information about account deletion from most mobile apps, let alone initiate the process.
m0dest··on Facebook bans, sends C&D letter to developer of Unfollow Everything extension
I tried to remove myself from all of Facebook's Audience-Based Advertising lists - the ones where companies upload lists of people that they want to target with ads.

https://www.facebook.com/adpreferences/ad_settings

I'm on over 300 lists. Removing myself from each one took 6 clicks. I tried to automate it with Selenium, but their bot detector caught it and banned my device from opting out of any lists (!)

m0dest··on Lithuania says throw away Chinese phones due to censorship concerns
No, they're separate baseband chips with Qualcomm-designed Snapdragon ICs running Apple-signed firmware with their own build flavors of Qualcomm's RTOS. Apple has to verify that the fab produces the low-level hardware exactly as designed, but nothing is going to sneak into that firmware.
Page 1 of 6Next →