HNHacker News
TopNewBestAskShowJobs

muvlon

1,160 karma · joined August 28, 2025

submissionscomments
muvlon··on US sanctions force The Netherlands off Microsoft and toward alternative NixOS
Sure, but that's nothing new. Russia has always been investing into domestic alternatives, even going to great lengths to build their own CPU architecture and such. But they've been a sworn enemy of the West so that's nothing surprising, and neither is China doing the same. The EU so far was considered firmly in the sphere of influence of the US, which is why this development is interesting.
muvlon··on US sanctions force The Netherlands off Microsoft and toward alternative NixOS
I think NixOS is also just much better suited for this particular job than SUSE. We use NixOS for everybody at work even though we're a German company.
muvlon··on US sanctions force The Netherlands off Microsoft and toward alternative NixOS
Not just the foundation, the inventors of Nix and NixOS are Dutch too, it came out Utrecht University. Even the name is from dutch "niks" for "nothing", the snowflake came later and is basically a retcon.

As for practical use, sure there are some rough corners (this is true for every Linux distro), but I don't think there's any horrible showstoppers. In fact it's particularly well-suited for use by organizations (as opposed to private individual use) because it's great for making highly customized but reproducible setups.

muvlon··on US sanctions force The Netherlands off Microsoft and toward alternative NixOS
And reducing exposure to US sanctions (for example by investing into alternatives to Windows or Visa/MasterCard) is an appropriate response for the affected countries.
muvlon··on AI has no intent and no motivation
Heck, they're already being deployed carelessly and making people suffer. So far it's mostly in places where making people suffer was already part of the deal, like fending off customer support tickets or denying insurance claims. But I can see it getting much worse.
muvlon··on What Sun got wrong
It can be that easy if you want a small number of servers and are willing to pay the outrageous sticker price. In reality, nobody pays $5k for that R360. You either play their game and deal with their insane sales team to get a big discount or you buy from a partner instead of Dell directly. We did the latter and it was just as easy as ordering from Dell online but also way cheaper.
muvlon··on Android 17 is the first since 3.x to add new APIs without releasing to the AOSP
Yes, if the banking app refuses to run on Graphene, you can forget about Waydroid completely. Hell will freeze over before Waydroid passes play integrity.
muvlon··on C++26: Trivial infinite loops are no longer undefined behaviour
I mean that's what they did, and that's why there's that UB. All I'm saying is that this is the "weird platform behaviors exist and must be legalized by the standard" kind of UB and not the "we want a 0.5% win for benchmaxxing" kind of UB (the standard has plenty of both).
muvlon··on C++26: Trivial infinite loops are no longer undefined behaviour
The compiler can assume that the function will return, but it can also statically deduce that the function cannot return. That's a contradiction, so the compiler deduces that the function is simply UB when called, i.e. no need to emit an epilogue. It's the logical principle of explosion in compiler format, basically.
muvlon··on C++26: Trivial infinite loops are no longer undefined behaviour
It's not even about optimizing some big tech codebase by 0.5%. The progress guarantees in particular are in place s.t. Nvidia can choose a certain implementation strategy in Cuda C++ that has "surprising" consequences for users (one thread getting stuck in an infinite loop that never yields can livelock its entire warp) but still get to claim "full C++ standards compliance".
muvlon··on We must pace the frontier
Well sure, but access to that compute is gated by simple credentials (like API tokens). Those can be hacked.

Imagine for example if a model hacks into ~every Linux computer on the internet using an 0day and steals their OpenAI, anthropic and openrouter credentials. It now has access to billions of compute and the only way to fully stop that is for multiple major providers to shut down services entirely. That's already well into "billions of dollars of damage" territory.

muvlon··on Actively exploited sandbox RCE in all Chromium versions
I'll believe this when it's done. Nothing I've seen so far indicates that this would be feasible.

As a practical counterexample, the Linux kernel has a verifier for eBPF code that is loaded by untrusted users. That is a much more constrained environment than JS, but they still constantly have verifier bugs. It's so bad that distros almost universally distrust the verifier and instead set things up s.t. only root can load any eBPF code.

muvlon··on Actively exploited sandbox RCE in all Chromium versions
What would that even look like? What is "benign"? The browser environment already has pretty strict rules for what the JS can do. It's not allowed to read your files, see your webcam without permission, know about other tabs or windows etc.

The problem here is that the browser failed to correctly implement those rules. If the chromium team cannot do that, what makes you think they can implement any other kind of "benign code" verification with zero bugs?

muvlon··on The safest job from AI may be writing
There may well be some writing jobs that are safe for the reasons given in this post, but that doesn't help all the writers I know who have already lost their jobs and are struggling to find work.

It's not enough that humans can tell the difference and feel an ick, there also need to be enough organizations willing to pay money for that difference. From my vantage point, there are not. It turns out that for a ton of the writing produced by companies, the quality of the prose wasn't really "load-bearing" as Claude puts it. That writing is there to occupy a space and look professional at a glance, the same way elevator music is tolerable for the duration of an elevator ride.

muvlon··on TurboKV: Insanely fast Rust key-value store
As of a couple years ago, mmap actually has a MAP_SYNC flag that makes it durable in the DB sense. The caveat is that it requires DAX on the file and so comes with a whole bunch of restrictions w.r.t. filesystem, storage media and even CPU architecture.
muvlon··on Tell HN: PayPal blocks GrapheneOS
You need to use your bank's app for Wero, and many EU banks' apps refuse to run on GrapheneOS for the same reasons as PayPal. This is sadly not a clear win for Wero.
muvlon··on CEO fired developers to make room for AI. Developers create open source AI CEO
The group who is currently winning this group vs. group war doesn't want you to think there is one.
muvlon··on Black hole singularity is a surface not a point
Astronomical distances are vast, million trillion miles too far, that's over a hundred thousand light years. There are known stellar-mass black holes within just 2000 light years of the Earth. Heck, there might be a primordial black hole in the inner Oort cloud and not only would it not destroy earth, we'd have (are having) trouble detecting it.
muvlon··on Jabber/XMPP: 25 Years of Digital Independence
At 11 years old, XMPP had 0 usable clients (I was there and tried them). That's one less than Matrix.
muvlon··on US announces new sanctions on top ICC figures
ICC and ICJ have different roles. The ICJ's subjects are countries whereas the ICC deals with individuals.

In this case, the ICC has jurisdiction because the alleged crimes were committed in the territory of a signatory (Palestine) and because Palestine indeed found itself unable to prosecute them.

muvlon··on The Amazon tax
Has that actually happened in retail stores? All I can find on the topic is about online purchases (or ordering/paying online and picking it up at the store).

To do this in brick-and-mortar, you'd have to use remotely programmable price tags and detect who is looking at what, which seems doable, but then you still run into all kinds of tough questions with no good answers. If I happen to see the price tag change from $3.49 (perhaps set for the person in front of me) to $4.49 and I put that item in my cart, which price am I getting charged at the register? And did a legal sale even occur if I wasn't aware what I would be paying? I don't think it's going to work.

muvlon··on The Amazon tax
This "dark forest" feeling is what has recently driven me back to brick-and-mortar stores. Of course they can and do manipulate me via ads, store layout etc. but at least the store looks the same for me as for the person before or after me. They can't algorithmically optimize the store around my behavior in particular.
muvlon··on Tell HN: Cloudflare silently injects its analytics when you switch nameservers
Nope, you don't need your own AS for this to work, nor do you need to use BGP. They support static routes too. BGP peering support is actually "beta" according to Cloudflare: https://developers.cloudflare.com/magic-transit/get-started/...

You do ideally want your own /24, though even that's not a hard requirement. And it can be provider-assigned space as long as your provider is willing to sign an LOA for you.

As for competitors, there are a few that start in the low 4 digits per month for similar services. That's not to say Cloudflare doesn't have anything unique to offer though, they're great at scale and standardization.

muvlon··on AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira
And worse: GitHub Actions not a full-fledged programming environment by itself either, so you're inevitably going to have to deal with nontrivial shell scripts on top of all the YAML mess.
muvlon··on Tell HN: Cloudflare silently injects its analytics when you switch nameservers
They have a product called Magic Transit that offers DDoS protection and such for plain IP traffic, where Cloudflare does not terminate TLS. Pricing is not public but starts in the five-digit USD per month range according to people I talk to.

This may tell you something about how keen Cloudflare are to handle traffic they themselves cannot decrypt.

muvlon··on Europe's scorched landscapes seen from space after summer heatwaves
I'm in Europe, the sky here is literally red at night from fires we are failing to extinguish. France, Spain, UK, Belgium, Germany, Croatia, Serbia are all going through this to different degrees right now.
muvlon··on A spectre is haunting Unicode
Meanwhile, Latin a and Cyrillic а, which look identical, have the same origin and are often pronounced identically too, get separate codepoints. CJK unification was not based on any clear preestablished principles but simply an attempt to cling to 16-bit codepoints, Asian languages be damned.
muvlon··on To save C, we must save ABI (2022)
> explanation of how byte-level access to memory objects is done in other languages.

I'm not pjmlp but I can explain this for the case of Rust, where this works a bit like C but with a few interesting differences.

Mainly, in Rust there is not a concept of a "memory object" per se in the runtime semantics. Memory is made of allocations and allocations are made of bytes. Unlike C, bytes are guaranteed to be 8 bits in size. Every byte of memory can hold integer values (0x00 to 0xff), pieces of a pointer or be uninitialized. That means there is nothing like strict aliasing, and therefore no need to have special rules for byte-level access. You can alias any type as any other type, so long as you avoid all the other sources of UB (out-of-bounds access, uninitialized memory access etc.).

The way to practically access this is much the same as in C. You can do things like cast pointers between different types and project a pointer to a struct to a pointer to one of its fields. It should be noted that, unlike with major C implementations, structs do not have a stable, well-defined layout, so if you do manual pointer math you need to put #[repr(C)] on the struct to get C layout rules (which might still yield platform-dependent field offsets, e.g. size_t is not the same size everywhere).

Note also that these are the dynamic rules of Rust, you need to follow these when writing unsafe code to avoid UB. The static rules of safe Rust are much more restrictive and don't allow much at all. It is possible to write unsafe code that exposes safe abstractions for this, one example is the "bytemuck" crate. It provides macros that can parse a type definition to check certain properties (e.g. well-defined layout, no padding) and then provide you with safe functions for byte-level access. Since there is no strict aliasing, for certain types you can also get safe functions for access at other granularities. For example:

  #[repr(C)] struct Foo {
    x: u32,
    y: u16,
    z: u16
  }
can be safely accessed as an array of u32 values (uint32_t in C), but

  #[repr(C)] struct Bar {
    x1: u16,
    x2: u16,
    y: u16,
    z: u16
  }
can not, for alignment reasons.
muvlon··on Squeak 6.1
Huh, I actually think it's the opposite. Classic Linux distros like debian are much more like Lisp, everything is the same big mutable pile of state and you query and edit it from within the system itself. The REPL is just your shell. It's very live and interactive and a bit scary at times.

NixOS by contrast takes the entire Linux userland and makes it an immutable, dead compiler artifact. So it is to debian like C or Rust are to Lisp.

muvlon··on Melatonin impairs morning cognition in healthy young adults (2023)
They're supplements, not medication, but I've seen crazy variation in the dosages of Vitamin D pills.
Page 1 of 5Next →