HNHacker News
TopNewBestAskShowJobs

moring

1,256 karma · joined January 19, 2018

submissionscomments
moring··on America.gov
Even worse, you'll often encounter a situation where:

Party A makes statement A,

Party B makes statement B,

Statements A and B are in contradition,

Party A claims that both parties agree that statement A is true,

Party B claims that both parties agree that statement B is true.

If you seek truth about reality, you better take humans out of the loop...

moring··on NRC issues first U.S. construction permit for a BWRX-300 small modular reactor
The point of small modular reactors is not the cost of the first one, but that the cost goes down with each subsequent one. The cost of the first one is expected to be high. IMHO this is very well explained in "How Big Things Get Done" by Bent Flyvbjerg.
moring··on America.gov
> Facts themselves are not partisan.

That statement itself is partisan. So is the meta-statement about who agrees with that first statement.

Really, any messy argument is about the claim who made which claims.

moring··on What About Rails?
> a CLI app does exactly what you ask for, and has a manual documenting exactly what command do what, and the output is consistent, the same command does the same thing period

This is a very software-engineery point of view and totally false for the ordinary user. Heck, it is even false for me as a software engineer.

> since you know people like moving a mouse and clicking on buttons

No, they like well-designed user interfaces, and the UI design of a typical CLI is abysmal.

moring··on Show HN: What if the speed of light was 5 km/h?
Didn't even think of this, but yes: 5km/h ~ 1m/s, which is 1/10^8 the real c. This multiplies the sun's Schwarzschild radius (normally ca. 3km according to Wikipedia) by 10^16, making it 310^13 km, with 1AU = 15010^6 km.

It's yet another xkcd-level apocalypse.

moring··on Java is memory efficient [audio]
This does not match my experience. The amount of manual tuning needed for memory management in C/C++ (which Java was designed to improve upon) was orders of magnitude greater than with Java just to get it correct, let alone efficient in terms of memory usage and performance.
moring··on Debian votes to allow "responsible use of generative AI"
In that case, isn't a sufficiently reasoned "why" a contribution in itself?

Not trying to downplay the time wasted to reject the PR, though.

moring··on Debian votes to allow "responsible use of generative AI"
I don't, please enlighten me.
moring··on Debian votes to allow "responsible use of generative AI"
Now replace "Claude" by "human" and see how your comment goes.

Specifically, humans are known to decide subconsciously, then invent some "reasoning" out of thin air to justify it.

This matches my experience with decision-making in software projects.

moring··on Debian votes to allow "responsible use of generative AI"
I'm not convinced it blows up. It might also end up placing a larger burden on contributors, and especially first-time contributors, to provide concise, high-quality documentation that justifies their contribution.

I'm thinking of something like: Explain, in at most 300 characters, why we should merge your change, or at least why we should invest the time to read a longer explanation (somethings things ARE complex). If you don't do that, or those 300 characters aren't convincing, or have nothing to do with your change or the longer explanation, then you get a canned response so the maintainers waste minimal time.

moring··on Bootstrappable Builds: How and Why
> because you're not going to be verifying that signature by hand

At least verifying a signature is something that does not need complex hardware, so chances are that your trusted hardware can do that.

> Your own trusted hardware AND software, because you're not going to be verifying that signature by hand, and you're not going to load the binary file in memory by hand, so either a kernel or system software (like UEFI) will be handling your trusted binary first. > > But then you're back to needing a clean bootstrap again. (...)

But having solved that bootstrapping problem, you are likewise back to square one with trusting "the payload", only this time the payload isn't the actual payload but the OS kernel, UEFI or whatever that obtains and verifies the actual payload.

You have that OS kernel or UEFI as source code, but you don't know if the source code contains a backdoor unless you either verify it manually, or have it verified and signed in some way by a third party you trust, and there the whole signature thing comes back.

(BTW thanks for the discussion. I'm really enjoying this!)

moring··on Bootstrappable Builds: How and Why
The more I think about it, the more I think that bootstrapping the build isn't actually the huge problem it first seemed to be. There are practical problems to solve, but they CAN be solved.

In contrast, how can you make sure that the actual payload code hasn't been tampered with? It is written in a high-level language, but it gets stored and viewed on devices that have backdoors in their CPU microcode and huge OSes that can hide god knows what. The author can sign the code, but that doesn't tell anything other than it was really the author who signed it and the code hasn't been modified afterwards -- if the author's system was compromised, the code can contain backdoors before being signed. So you need to validate the (signed or not) code to be correct, but you're doing so on an untrusted system. It goes on and on.

You'd probably need the code to be verified, then signed, by a trusted party on a trusted system. THAT signature then means the payload hasn't been tampered with, and can be trusted after it gets built on your trusted system (and this is where the bootstrap problem happens, and gets solved).

All this is obviously still glossing over the problem how to obtain hardware you can trust.

...edit: But if you have all that, then you don't need a complex bootstrapping anymore. A trusted actor can verify, or even build, a trusted system by hand on trusted hardware, sign it, and then you can use that (binary!) as long as you run it on your own trusted hardware and verify the signature first.

The bootstrapping then becomes a tool to ensure reproducibility, but is no longer needed for trust.

moring··on Bootstrappable Builds: How and Why
Just for perspective, the people working on his are pursuing their hobbies and sharpening their programming skills. In contrast, you are using your time to whine about it on the internet.
moring··on Bootstrappable Builds: How and Why
Opcode mnemonics is something that a tool can show when you inspect a binary. You will need to go up the ladder a lot before the source code is more expressive than a disassembly. Comments are a good point though, but since they do no affect the semantics, they could be provided as a separate file that does not have to be reproducible (since compromised comments are at worst misleading or confusing).

The GCC example is valid, but can also be explained by its size.

I like the idea of bootstrapping in a Lisp-like language since it is extremely expressive for its simplicity. But then you need an interpreter for that, which must be trusted. I've been nerd-sniped by the whole thing and I'm thinking about an extremely simple virtual machine for the seed, with the actual seed code being a binary for that VM that implements a Lisp. Then an audit of the seed becomes disassembling the VM code for the Lisp interpreter, which is only moderately complex because the VM is as simple as possible.

moring··on Bootstrappable Builds: How and Why
> The hex0 program provides a way to turn a string of hexadecimal text into a binary with those bytes.

I'll use this to ask for an explanation about the fundamental idea: How is hex text better than a binary blob? Both need detailed knowledge to understand; both need a tool to display (reading ASCII or binary), either of which could be compromised in a "trusting trust" sense.

It seems to me that the actually important aspects of the initial "seed" are its size (larger is harder to verify) and that the language used (whether it is Lisp, binary machine code or whatever) has rigorously defined semantics.

(Orthogonal to that, you'd want to store everything, seed and the rest, on a medium that cannot hide anything from you, and use that as the source. But that applies to all approaches.)

moring··on CEO fired developers to make room for AI. Developers create open source AI CEO
It saddens me that we're banning speech patterns on HN, not discussing arguments. I have seen this in another thread yesterday(?), where somebody was accused of being an LLM based on speech patterns and downvoted, no further evidence needed. This site used to be above that level.
moring··on Death to px, long live ch
I tried and with 1:1 zoom, a "10cm" width DIV was actually less than 7cm. Why even call it "cm" if it is actually "whatever, I don't know"...
moring··on NP-overrated
> It's NP-hard

What is the "n that goes to infinity" for Sudoku? I thought that you could iterate through all possible 9x9 grids and find the ones that satisfy the rules AND are consistent with the "known" numbers. That would make it O(1), not NP-hard.

moring··on A shell exclamation mark is not for yelling. Be lazy
Worse, the "press up-arrow to get the previous command, then fix the errors in it" flow is broken when an exclamation mark causes a syntax error.
moring··on Company Offering '100% Human-Written, Never AI' Medical Research Is 100% AI
We put it into the "irrelevant" section because AI is no worse than a human support drone who has no useful knowledge nor permission to act. It is one of those cases where AI is only tangentially related to the actual problem.
moring··on Why Book Corners won't sync contributions back to OpenStreetMap
This can probably be added to the toolchain pretty easily when non-OSM "signals" are converted to OSM format first. All you need then is an OSM data merging tool, all other tools will then get the same data format as before.
moring··on Dependabot version updates introduce default package cooldown
> Anyone who hasn't thought deeply enough to answer this question doesn't have the privelige to say "just curate it, what's the problem?". Curation isn't that simple, as any distro package manager volunteer would tell you.

Your logic is self-defeating. How are distro volunteers going to know that you are interested in this topic if, by your logic, you don't have the privilege to ask them in the first place?

But I don't think that asking needs any privilege. I'm going to ask again: Why not? Or worded differently: What is stopping language package managers that is not at the same time stopping distro package managers?

moring··on Dependabot version updates introduce default package cooldown
> language package managers are not [curated]

Why not? Seems like exactly what is being asked for.

moring··on Just Let Me Write Digits
> So statistically speaking I’m surprised that this bug hasn’t been noticed and fixed yet!

I'm not so surprised, given that you cannot write support tickets if the bug prevents you from registering...

Also, I don't think people have high hopes that a broken government website will ever get fixed.

moring··on Einstein's relativity rules chemical bonds in heavy elements, new research shows
Am I right with my assumption that by "fundamentally different problem", you mean we lack a good simulation model, but that the number of degrees of freedom would actually be manageable?
moring··on Einstein's relativity rules chemical bonds in heavy elements, new research shows
> From the perspective of a deterministic universe, creative works theoretically can be explained as a physics outcome

In other words, physics can explain Shakespeare's plays when you hand-wave away the biggest reason it cannot.

> theoretically

... meaning not in reality, but in an abstraction of reality that conveniently leaves out the hard part.

> This is just a data problem though.

The word "just" makes it sound like that data problem is a minor inconvenience, and not a fundamental obstacle.

Becoming a billionaire is simple, after all it's just a money problem.

I mean, you're right in that (leaving out quantum randomness), you could predict macroscopic outcomes based on a physics simulation that includes all elementary particles explicitly, if you assume that such a simulation can be scaled from <10 particles to macroscopic numbers. But there is no evidence that this assumption is true, so it remains an interesting thought experiment that gets confused with reality because people like to slap the "in theory" label on it.

moring··on Developers don't understand CORS (2019)
> it’s meant to protect the users from themselves

This is false. It is meant to protect users from a confused-deputy attack made by malicious websites, where that website makes a request to a "serious" API but the user has never asked for, or approved, that request.

Blaming the user for everything that happens serves nobody.

moring··on Developers don't understand CORS (2019)
The message in the dev tools is, at least for Chrome, extremely developer unfriendly: The blocked request is displayed in a very strange way, without any information that it was blocked, nor that CORS was the reason for it, nor how that decision was made based on the preflight request.

You have to already know from experience that these strange devoid-of-information requests have been blocked by CORS, then find the preflight request, and there you will find a bit more information, but still much less than would be possible to show.

Showing more information would, AFAIK, not circumvent the layer of security that CORS (or actually origin isolation, which CORS makes an exemption from) adds. My best guess is that this just had very low priority when building the dev tools.

moring··on If your product is Great, it doesn't need to be Good (2010)
And yet, you did buy the fan despite the bright LED (because you didn't know it was there when you bought it). Rowenta got your money, so from their perspective, they did everything right.
moring··on Every Byte Matters
The article shows nicely how "every byte matters" is false. First, it starts off by talking about the cost of a new field, when the actual topic is array-of-structs vs. struct-of-arrays. Then, this:

> How much of an impact can this have? > Reading is:alive (1 byte) Across 1M Monsters

You aren't reading one byte here, you are reading 1M bytes! Of course, optimizing the access to 1M bytes is something to consider. Optimizing the access to one byte isn't.

The article is definitely worth reading IMHO, but it really needs a better headline!

Page 1 of 19Next →