HNHacker News
TopNewBestAskShowJobs

n3t

563 karma · joined February 19, 2014

[ my public key: https://keybase.io/n3t; my proof: https://keybase.io/n3t/sigs/A1BuEOe8rc5Nxa_-Q9HJb0ZwrOtBtgezPQknFAGN8lM ]
submissionscomments
n3t··on Oxidizing Ubuntu: adopting Rust utilities by default
https://doc.rust-lang.org/rust-by-example/scope/lifetime/sta... says:

> As a reference lifetime 'static indicates that the data pointed to by the reference lives for the remaining lifetime of the running program.

n3t··on Ask HN: I have excess compute, how can I contribute positively to the Internet?
I run fishnet[0] to help Lichess[1] analyze chess games.

[0]: https://github.com/lichess-org/fishnet [1]: https://lichess.org/

n3t··on Executive wealth as a factor in return-to-office
> Increased footfall is beneficial for the economy. People generally spend more when they're outside than they would if they were at home.

It sounds like the broken window fallacy.

n3t··on My Experience Biohacking
The author mentions MRI in the article.
n3t··on Ask HN: Can all of 32bit computing fit within a single 16GB permutation of 2^32?
I won't directly answer your questions but consider this. We have a function F that accepts an argument of size N and returns the result after N² instructions. Its time complexity is O(N²).

Now consider F'. F' is like F but we limit N to a fixed constant -- for example we say that N must be ≤ 2³². In this case, _for every input_ F' returns the result after at most (2³²)² = 2⁶⁴ instructions. Its time complexity is O(1). Note that O(2⁶⁴) = O(2⁶⁴ * 1) = O(1).

---

Technically, all implementable-on-real-machines algorithms either return after O(1) instructions, or loop after O(1) instructions. But being O(1) doesn't imply being fast in practice.

You might be also interested in reading about galactic algorithms: https://en.wikipedia.org/wiki/Galactic_algorithm.

n3t··on Ask HN: Does anyone use sound effects in their dev environment?
At a previous job we had a service that handled around 1 query per second.

I crafted a oneliner that `tail -f`'d the logs and played a note for each response. I believe there were different notes for different HTTP status codes but it was years ago so the details flee me.

n3t··on Ask HN: How do I save my content from AI crawlers?
A lot of shady scrapers run on residential IP addresses.
n3t··on Pin
> there are about 4 different ways to implement object moving

What are they?

n3t··on Negative Temperature
Arithmetic underflow, obviously.
n3t··on Leaking URLs to the Clown
Searching for "all articles are available offline and without an internet connection" (with the quotes) in your favorite search engine might help.
n3t··on Anki – Powerful, intelligent flash cards
Can you share what your typical flashcard for the book looks like?
n3t··on Ask HN: What fuel for my data furnace?
I run fishnet[0] to help Lichess[1] analyze chess games.

[0]: https://github.com/lichess-org/fishnet [1]: https://lichess.org/

n3t··on Go, Containers, and the Linux Scheduler
After reading https://kubernetes.io/docs/tasks/administer-cluster/cpu-mana..., I think we have different policies set for the CPU Manager.

In my case it's `"cpuManagerPolicy": "none"` and I suppose you're using `"static"` policy.

Well, TIL. Thanks!

n3t··on Go, Containers, and the Linux Scheduler
I re-did the experiment again with `taskset` and got the same results, i.e. the mask is independent of creation of the "Guaranteed QoS" Pod.

FWIW, `taskset` uses the same syscall as `nproc` (according to `strace`).

n3t··on Go, Containers, and the Linux Scheduler
If by "CPU mask" you refer to the `sched_getaffinity` syscall, I can't reproduce this behavior.

What I tried: I created a "Burstable" Pod and run `nproc` [0] on it. It returned N CPUs (N > 1).

Then I created a "Guaranteed QoS" Pod with both requests and limit set to 1 CPU. `nproc` returned N CPUs on it.

I went back to the "Burstable" Pod. It returned N.

I created a fresh "Burstable" Pod and run `nproc` on it, got N again. Please note that the "Guaranteed QoS" Pod is still running.

> Pods with Guaranteed QoS will have exactly the number of CPUs they asked for, no more or less

Well, in my case I asked for 1 CPU and got more, i.e. N CPUs.

Also, please note that Pods might ask for fractional CPUs.

[0]: coreutils `nproc` program uses `sched_getaffinity` syscall under the hood, at least on my system. I've just checked it with `strace` to be sure.

n3t··on Go, Containers, and the Linux Scheduler
> which of problematic in K8s where the visible CPUs may change while your process runs

This is new to me. What is this… behavior? What keywords should I use to find any details about it?

The only thing that rings a bell is requests/limit parameters of a pod but you can't change them on an existing pod AFAIK.

n3t··on Ask HN: Alternative Jira UIs?
I've heard good things about JiraCLI → https://github.com/ankitpokhrel/jira-cli.
n3t··on Cryptography may offer a solution to the AI-labeling problem
Exactly.

What your parent described is a type of trusted timestamping and one doesn't need blockchain to implement it.

[0]: https://en.wikipedia.org/wiki/Trusted_timestamping

n3t··on Python Cheatsheet
> That is a lot of data for a single page IMO.

It is great for a cheat sheet to be on a single page. It makes ctrl+f searching useful and quick.

n3t··on The curse of scalable technology
How can k3s be simpler to operate than Kubernetes when k3s is a Kubernetes distribution?
n3t··on Show HN: A fully open-source (Apache 2.0)implementation of llama
> GPL is a copyleft license which requires you to share anything that you build using the original software.

That's not true.

> This makes it difficult for commercial use.

Yeah, too bad it's so difficult for companies to use Linux commercially. /s

n3t··on Apple introduces end-to-end encryption for backups
You encrypt a file first, then you calculate hash of the encrypted file.
n3t··on Ask HN: What weird technical scene are you fond/part of?
Wow, this is great. Do you have any good links to learn more about this?
n3t··on Tim Berners-Lee: Web3 is not the web
> data backing the site will never be lost

Data can be lost.

I put a few files on IPFS some time ago. That files are no longer accessible because I stopped hosting them.

> Site will never go down

As long as there is a node hosting the data you're looking for. So it can go down.

n3t··on Launch HN: Akiflow (YC S20) – Bring your tasks and calendars together
Sounds interesting. What are you referring to?
n3t··on Evolution of HTTP
Can one create a CA with a limitation to `*.example.com`?

Or can one install an arbitrary CA and limit it to `*.example.com`?

n3t··on Data Structures Sketches
A non-mobile link: https://en.wikipedia.org/wiki/Count%E2%80%93min_sketch
n3t··on An app can be a home-cooked meal (2020)
Aren't free apps a conflict of interest then?

I can imagine that a good platform for making "home-cooked apps" would be beneficial both to Apple and to buyers of their products.

I believe Shortcuts was a move in the right direction.

n3t··on Bitwarden: Avoid at all costs (outage issue)
Let me quote some excerpts from their license FAQ[0]:

> With respect to the server software available under the Bitwarden License, production use requires a separate commercial agreement with Bitwarden

> The right to use the software in a production environment, or environments directly supporting production, requires a paid Bitwarden subscription

> The Bitwarden License does not qualify as an open source license under the OSI definition

[0]: https://github.com/bitwarden/server/blob/master/LICENSE_FAQ.... (permalink → https://github.com/bitwarden/server/blob/f848eb247767fbba8a4...)

n3t··on Ask HN: What happened to vanilla HTML/CSS/JS development?
You seem to have more experience in PCI-related stuff so I won't comment on that. I'd like to focus on engineering point of view, not compliance matter.

Let's say a company's app has a security vulnerability. Let's consider 2 scenarios: (A) using Angular vs (B) using an internal framework.

From engineering perspective it doesn't matter if it's (A) or (B). It's not like the internal framework will be perfect and bug-free.

In both cases it is company's responsibility to patch their app. In case (A) they can fix it in their internal fork of Angular; or fix it upstream; or update Angular to an unaffected version. In case (B) they have to fix their framework.

You stated that:

> When a company decides to use Angular (for example), they're also deciding to jump on the rat-wheel that is constant upgrades to the next version.

> Meanwhile, that vanilla app will just keep working in perpetuity.

and I disagree with it.

If a company doesn't care about security, they can have Angular "working in perpetuity" as well as their vanilla app.

If they do care about security, their vanilla app will not (securely) "work in perpetuity" since it will need a fix sooner or later.

← PreviousPage 2 of 4Next →