HNHacker News
TopNewBestAskShowJobs

matthberg

3,555 karma · joined December 25, 2016

submissionscomments
matthberg··on DALL·E: Introducing Outpainting
Which now supports inpainting (as of 36 minutes ago): https://www.reddit.com/r/StableDiffusion/comments/x2tk1g/sta...
matthberg··on From Oscilloscope to Wireshark: A UDP Story
For oscilloscope/logic analyzer work I've encountered Sigrok as the goto tool to use (yet I have not used it myself yet, lacking the hardware at the moment). They have suites of different parsers for nearly every network protocol, which can also be applied on top of each other.

https://sigrok.org/

matthberg··on From Oscilloscope to Wireshark: A UDP Story
Huh, analogous to RAW photography and postprocessing rather than on-camera jpg creation, I guess.
matthberg··on Show HN: I created a browser automation tool
Looks like a simple enough design that vector would probably be more space efficient and have infinite resolution. The product looks interesting too!
matthberg··on I have 218 browser tabs open
It's not the best of habits yet I currently have 3109, recently migrated to Sidebery from Panorama View [0]. I'll likely go pruning soon, yet having time context of what I was looking at (by neighboring tabs and indent levels) is so useful for sparking my memory and associating ideas. I've tried using bookmarks and tagging yet the tooling around that is annoying enough I keep coming back to having an obscene amount of tabs open.

Ideally, I'd like a bookmarking system which allows for referencing tab history, past visits and other tabs viewed in each visit's timeframe, manual tagging, external references, and more, yet that doesn't exist yet. I've looked into developing such an extension, yet tab history APIs are clunky enough I haven't bothered going further. If anyone knows of other extensions that fill this niche, I'd love to hear of them.

[0]: https://addons.mozilla.org/en-US/firefox/addon/panorama-view... This used to be a built-in feature of Firefox, which I used until I was forced to switch to the addon.

matthberg··on I have 218 browser tabs open
I'm not quite sure what you're talking about. Firefox allows thousands of tabs without stopping new tabs being created. I currently have 3109 open (with only a dozen or so loaded though) which has survived abrupt power loss, freezing and force quitting, and updates across several years worth of versions both in the background and manually triggered. It's using 1571MB RAM at the moment and rarely goes over 10Gb, even after having viewed hundreds of tabs recently. In that case it's easy enough to unload everything by restarting the browser or selecting a bunch of tabs then unloading them with Sidebery.
matthberg··on Color.js Released
This looks fantastic for working with colors, and from a great developer too. A very very similar js library is Culori [0, 1], which I discovered on the original Oklab introduction post [2].

If you're doing generative artwork or any procedural work with a non-fixed palette, a good color library and working in linear or Oklab based colorspace is a must. Using sRGB or HSV/B when interpolating for gradients or generating palettes or complementary colors is extremely painful; a 50% brightness (HSV) yellow is visually much brighter than a 50% brightness purple, with similar issues cropping up for saturation. Balancing the lighting and contrast of programmatically generated colors is so much simpler when you have a perceptually uniform colorspace like OkLCh, or linear RGB if you're working with predefined hex values.

[0]: https://culorijs.org/

[1]: https://github.com/Evercoder/culori

[2]: https://bottosson.github.io/posts/oklab/

matthberg··on Anti-Interdiction on the Librem 5 USA
This reminds me of a recently discussed [0,1] new method for tamper evident packing. The item is completely surrounded with multi-colored small objects (like rice, though plastic pellets would probably be better for customs to avoid plant pest inspections) in a clear vacuum sealed bag. The random patterns are too complex to recreate after tampering since accessing the device requires breaking the vacuum seal and disturbing the pattern, then resealing it and somehow manipulating the grains back into place from the other side of the plastic. Sending photos from each side for comparison on an off-channel medium is all that's required to verify tamper safety. The pellets or rice stay in place surprisingly well under a vacuum seal, and nesting of vacuum seal bags can be used to increase security or daisy-chain in multiple packages.

This might be worth looking into for Purism since it takes a lot less effort than painting each screwhead, which I believe has also been defeated without detection (it's mentioned in the linked article). Maybe a combined approach would work best for narrowing down the tampered with areas.

0: https://news.ycombinator.com/item?id=31897530

1: https://dys2p.com/en/2021-12-tamper-evident-protection.html

matthberg··on Film grain synthesis in AV1 (2019)
That's an interesting idea. I reckon the complexity added with rendering vector graphics (text in particular, font rendering is notoriously difficult) outweighs the bandwidth savings, but still it seems like an area ripe for exploration. Canvas-like APIs might be too complicated to encode/decode efficiently, yet I suspect something closer to a Web/OpenGL fragment shader would be much more manageable (yet likely much worse for interactivity unfortunately). While that wouldn't quite mesh with the idea of vector-like text you proposed (without a heavy library or two thrown in), I suspect the engineering put into the existing graphics pipeline would make it a more feasible approach to augmented video. Looking at the stuff on Shadertoy.com and Inigo Quilez's work shows the capabilities of fragment shader based graphics, yet I suspect all of the magic would be in the details of the file format and encoding strategy. If anyone pokes around or explores a video/shader hybrid format let me know and post it on HN, I bet a bunch of people would be interested.
matthberg··on New in Calibre 6.0
I use it to load books onto a kindle and to process ebooks. I like adding metadata, making basic style tweaks or edits (like fixing OCR typoes or em/en/- mishaps), and tagging and cataloging. There's a setting to load all files plopped in a directory into the calibre system, which is both accessible through the GUI and as an author-grouped directory structure with standardized filetypes, which I find quite helpful. Also useful is the DeDRM plugin to make books bought from Amazon or Google Books accessible with any format (plus all the other benefits of DRM free media, like customizability and portability).

One aspect of working with digital books I haven't solved yet is syncing bookmarks and highlights across devices, or making them easily searchable. I'm sure there's a plugin or tool which makes it easy, yet I just haven't found it yet.

matthberg··on New in Calibre 6.0
Calibre does its job so well it's downright essential for anyone thinking about dealing with ebooks. Glad to hear that full text search is added in this version, using it with a bunch of reference books saved will be so useful. It might be worth splitting out the fiction books I have to clean up the results. Maybe it works with tag filtering, I'll have to check.
matthberg··on Show HN: Copy React code from any site
Wow, $20/month or $120 yearly for what looks like a very thin wrapper on inspect-element features. I'm sure some might be willing to pay for the convenience it adds, yet with a free near-equivalent baked into every browser that's a tough sell.
matthberg··on Build Your Own Magneto Charger
For those interested in magnets, I cannot recommend Applied Science's video on it enough. He shows how analogous they are to circuits, introduces the lingo and main concepts, and more. I can't remember at the moment whether his video covers the making of magnets themselves, yet for a general introduction it seems perfect:

Engineering Magnetics -- practical introduction to the BH curve (49:56)

https://youtu.be/4UFKl9fULkA

matthberg··on Straight.el: next-gen, purely functional package manager for the Emacs hacker
I use this in combination with `use-package`.

Here's the relevant section copied from my config, copied from right at the top:

  ;; Straight bootstrap
  (defvar bootstrap-version)
  (let ((bootstrap-file
         (expand-file-name "straight/repos/straight.el/bootstrap.el" user-emacs-directory))
        (bootstrap-version 5))
    (unless (file-exists-p bootstrap-file)
      (with-current-buffer
          (url-retrieve-synchronously
           "https://raw.githubusercontent.com/raxod502/straight.el/develop/install.el"
           'silent 'inhibit-cookies)
        (goto-char (point-max))
        (eval-print-last-sexp)))
    (load bootstrap-file nil 'nomessage))

  ;; Set up use-package for tidier package configuration/installation
  (straight-use-package 'use-package)
  (setq straight-use-package-by-default t)

  ;; Add diminish, which makes it easier to customize lighters (minor mode display)
  (use-package diminish)
I use it since it allows for transparent installations, meaning you can find the straight folder (in my case "~/.config/emacs/straight/repos/") and see git repos for all of your installed packages. From there you can edit them, commit to upstream, pull, all of the usual stuff.

Another main reason to use it is that it allows for repeatable installations, something I had struggled with previously with `package.el`. Run `M-x straight-freeze-versions`, and you have a lock file made with the exact commits of all of the dependencies you're running. That way, you don't need to push your entire emacs config folder up to your dotfiles repo, and can get a new install of emacs set up feature-(and bug)-exact on new machines easily.

One gripe I have about it though is that flycheck no longer recognizes `use-package` syntax in my init file and throws a bunch of warnings as a result. If anyone knows a quick fix, please let me know!

matthberg··on Roboto but Make It Flex
Here's the github repo for the font: https://github.com/googlefonts/roboto-flex

I always find it interesting to track the updates for google fonts on their repos (when possible), since you can see fixed bugs and also sometimes find people who've forked it to add features.

matthberg··on Including “And. And. And. And. And.” in a Google doc causes it to crash
Apparently from a poem: https://news.ycombinator.com/item?id=31278566

That comment is from the submitter of the issue (and HN post), the poem is from Eliza Callahan (copy found here): https://durationandthebodyelizacallahan.cargo.site

The relevant excerpt: "I thought about my body. It’s past. It’s present… Which made me think about the word and. And. And. And. And. And. Then."

matthberg··on What are your most used self-hosted applications?
I was curious about this too, and looked into it. It's referring to a suite of piracy apps, for automatically building libraries from trackers.

Wiki (linked from one of the githubs, has links to all apps and more info than the githubs): https://wiki.servarr.com/

Lidarr (Music): https://github.com/Lidarr/Lidarr

Radarr (Movies): https://github.com/radarr/radarr

Readarr (Books): https://github.com/readarr/readarr

Sonarr (TV): https://github.com/sonarr/sonarr

matthberg··on Linux containers in 500 lines of code (2016)
Might benefit from a (2016) tag. Date gotten from the homepage: https://blog.lizzie.io/
matthberg··on Tudor Networks
A striking yet somewhat confusing way to visualize this data. With the X axis being the average year of all letters sent by a person, interpreting the distance between corespondents is somewhat challenging. It's hard to know how a line from someone averaging around 1575 to someone around 1530 should be interpreted, since their letters aren't exactly time traveling. The difference could be explained by relative ages, yet I reckon there are other interesting factors to consider (corresponding with one set of people early in life, changing to another with age possibly). The timeline you get by clicking on "Explore by time" provides some more data, yet it isn't quite clear 100% there either.
matthberg··on 1kb Fluid Simulation Quine
For a little more info: http://www.p01.org/fluid_simulation_quine/
matthberg··on Lego Spectrometer (2017)
Found this after looking into cheaper alternatives to yesterday's post on a DIY spectrometer with a raspberry pi [0].

Also interesting, and even cheaper, is a paper spectrometer which attaches to a phone camera by the same designer as this Lego one [1].

0: https://news.ycombinator.com/item?id=30027804

1: https://publiclab.org/wiki/papercraft-spectrometer

matthberg··on On Emacs 28’ context menu and Unix mouse-usage in general
Not quite the case, thankfully. I'm left handed and greatly benefit from this style of keyboard layout. I tend to notice that I'm more finger-agile with my left hand, which helps with quickly chained left hand shortcuts (C-z/x/c/v/a/s/tab, M-x, anything with shift or windows) and WASD movement.

As for the right, as some other commenters have noted it really isn't that bad to use your non-dominant hand with a mouse. Most of the movement precision comes from the wrist and elbow, rather than finer finger control.

matthberg··on One decade later, Minecraft world generation is interesting again
I also recently (today in fact) encountered the Terralith datapack, it's rather impressive and I'm tempted to try it out. From what I know it doesn't add any new blocks, instead it just reuses existing vanilla ones.

There's a trailer they made for a recent update that shows off some of the terrain results:

https://youtu.be/zmIvURR_-eg

matthberg··on Schemaverse, a space based strategy game to learn PostgreSQL
I encountered the same error message, yet it seemed to be from a broken link instead. From the homepage [0] while signed in, I clicked on "How to play" right under the query entry box. It sent me to this page, which is a different url from the one you linked: https://wiki.github.com/Abstrct/Schemaverse/how-to-play

0: https://schemaverse.com/tw/index.php

matthberg··on Rust programming for web developers, by a web developer
I believe the author is present, and this should have been a [Show HN]. The submitter's username matches the author's username on the site, and the submitter has replied to feedback comments as the author would.

(Not the previous commenter, yet thought this context was the most relevant)

matthberg··on Sign arbitrary data with your SSH keys
Looking forwards to when this gets added to git in v2.34. Setting up pgp for commit signing is such a pain. Yet since ssh is installed everywhere and I'm using it for git anyways, that's one less setup step to worry about.
matthberg··on GTFOBins
True, yet in a few cases the not-dropping of privileges is a real risk, like with `less` [0], which allows for arbitrary shell access despite being meant for for just paging. Also, it's useful to know that a program is sloppy with permissions in case any bugs are found in it; a CS prof I once had always insisted we dropped permissions and capabilities as soon as we were done with them so that any calls to other libraries or our own buggy code could do the least damage possible, just like how it's good practice to not run every command as root.

[0]: https://gtfobins.github.io/gtfobins/less/

matthberg··on GTFOBins
Also if you haven't already, check out some of the OverTheWire wargames [0]. I sure wish I had found this site before trying some of them.

[0]: https://overthewire.org/wargames/

matthberg··on GTFOBins
I also found this a bit overly obvious at first, yet when considering it from an unintended side effects/uses perspective it's actually a valid thing to consider. For example, `less`[0] might be used with `sudo` to view a file owned by another user. This is all good until you remember that you can run arbitrary commands by just hitting '!' in the paging view, which are also runs with `sudo` privileges. Though that might seem like a bit of a contrived example, through unintended features otherwise safe tools can be unexpectedly dangerous (the entire point of this site).

For a real-ish world example of this effect, one of the OverTheWire wargame challenges [1] (spoilers for bandit) has a user login "shell" be a message saying login was prohibited, printed with `less`. When you resize your console window to a point where scrolling is needed and then attempt login, you can then interact with `less` and use '!' to run commands as the current user and print the key. Now you may say this isn't relevant to the `sudo` category of risk since who runs `sudo less` without also being able to run `sudo anything`, but many other apps use less as their pager, and some of those make much more sense to allow for general use with sudo (like say allowing all users to update apps, or any of hundreds of other insignificant things).

In short, I think the `sudo` and `setuid` notices might be better considered as "permission transparent", i.e. any permissions or access you hand to the listed tools are handed directly to the user as well. There are secure ways to not do this when writing programs, like by setting all of the real, effective, and saved uids [2] to something non-root (or the original calling user, if available) and totally wiping the capabilities sets before `exec()`ing anything, yet that's just what I remember from a computer security class a few years ago, you would probably be best off looking into it further if you're writing anything security sensitive.

[0]: https://gtfobins.github.io/gtfobins/less/

[1]: https://overthewire.org/wargames/bandit/

[2]: https://man7.org/linux/man-pages/man2/setresuid.2.html

matthberg··on BookWyrm is a federated Goodreads replacement
That info is out of date, bookwyrm.social is in open registration now. A more accurate list of instances is available here: https://joinbookwyrm.com/instances/. I signed up on bookwyrm.social (here: https://bookwyrm.social), though it took a notably long time to receive the email confirmation message.
← PreviousPage 3 of 9Next →