HNHacker News
TopNewBestAskShowJobs

nalllar

717 karma · joined August 7, 2015

submissionscomments
nalllar··on Acetaminophen vs. ibuprofen
Yeah this is optimizing for the good case instead of tail risks and mistakes and we see too many overdoses already.

Of course, we could press the fix this immediately button by requiring acetaminophen to be sold mixed with NAC but that would be too easy.

nalllar··on Signed, Sealed, Stolen: How We Patched Critical Vulnerabilities Under Fire [video]
For context before playing the video, this talk from FOSDEM 2026 is about patching security issues under active exploitation in the continuwuity matrix homeserver implementation and was published by Jade who is one of continuwuity's maintainers.

Slides: https://fosdem.org/2026/events/attachments/ETMLM8-signed_sea...

nalllar··on Semantic ablation: Why AI writing is generic and boring
It almost certainly is AI generated. It reads like it is, pangram thinks it is, https://www.pangram.com/history/02bead1c-c36e-461b-8fa7-8699... and pangram's unlikely to give false positives https://www.pangram.com/blog/third-party-pangram-evals
nalllar··on AI generated posts about AI failures (keep showing up on HN)
I keep running into posts about AI written by AI via friends who found them on HN. HN commenters seem unaware.

Semantic ablation: Why AI writing is generic and boring https://news.ycombinator.com/item?id=47049088

The Singularity will occur on a Tuesday https://news.ycombinator.com/item?id=46962996

The singularity will occur on a tuesday received thousands of votes. It wasn't bad but I'd have preferred less AI fluff around the fun modelling.

Why's this so prevalent here?

nalllar··on Semantic ablation: Why AI writing is generic and boring
The article itself reads as an AI generated output, complete with classic Not Just X … Y hallmarks from forever ago, 100% on pangram's low false positive detector. I'm not sure if it's some experiment on their readerbase or what. pangram result: https://www.pangram.com/history/02bead1c-c36e-461b-8fa7-8699...

So many AI generated AI bashing articles lately. I wrote a post complaining about running into these, and asking people who've sent me these AI articles multiple of them came from HN. https://lunnova.dev/articles/ai-bashing-ai-slop/

nalllar··on Ask HN: Are you afraid of AI making you unemployable within the next few years?
Somewhat.
nalllar··on HipKittens: Fast and furious AMD kernels
Spending >10 minutes doing template instantiation for a single kernel for a single ISA is impressive!

`device_grouped_conv2d_fwd_xdl_ngchw_gkcyx_ngkhw_f16_instance`, what are you doing to our poor friend clang?

nalllar··on Learning from failure to tackle hard problems
qqxufo's recent posts read like a large langle mangle to me
nalllar··on We all dodged a bullet
> 1. NEVER EVER login from an email link. EVER. There are enough legit and phishing emails asking you to do this that it's basically impossible to tell one from the other. The only way to win is to not try.

Sites choosing to replace password login with initiating the login process and then clicking a "magic link" in your email client is awful for developing good habits here, or for giving good general advice. :c

nalllar··on Measuring the impact of AI on experienced open-source developer productivity
If you interact with internet comments and discussions as an amorphous blob of people you'll see a constant trickle of the view that models now are useful, and before were useless.

If you pay attention to who says it, you'll find that people have different personal thresholds for finding llms useful, not that any given person like steveklabnik above keeps flip-flopping on their view.

This is a variant on the goomba fallacy: https://englishinprogress.net/gen-z-slang/goomba-fallacy-exp...

nalllar··on ROCm Device Support Wishlist
Thanks for all your work on this.
nalllar··on ROCm Device Support Wishlist
I had the impression Debian applied patches that widen arch support from what upstream officially supports, including for the MI50/MI60.

https://salsa.debian.org/rocm-team/rocm-hipamd/-/raw/d6d2014... (one patch of many)

nalllar··on Amazon's AI crawler is making my Git server unstable
xena said "forward confirming reverse" twice which means rdns and then resolving that forward to confirm it matches.
nalllar··on [dead]
"brand safety" is far removed from what they care about and would likely exist without that sphere's input given corporate trust & safety teams' history.

It has certainly negatively polarized people against any form of safety near AI.

nalllar··on Making a rickroll laser: A parametric speaker
Is this dangerous in terms of hearing damage due to the perceived low sound level alongside inaudible louder ultrasound?
nalllar··on A leadership crisis in the Nix community
People want them not to be advertised at official Nix events, not to bar them from using it. That wauld be impossible due to licensing so isn't on the table.

Would you require the FSF to accept a sponsorship from anyone and to advertise them in return?

nalllar··on Autoconf makes me think we stopped evolving too soon
conan makes it very hard to build a project offline and with a fixed set of inputs, it makes things worse in important ways if you care about reproducibility.
nalllar··on FOSDEM 2024: PineTime Talk
I really like my pinetime. It has way better battery life than android wearos watches - 2 weeks! - and does the few things I actually need, showing the time, alarms and notifications.
nalllar··on Nvidia is now more valuable than Amazon and Google
Their biggest competitor in the GPU space is AMD who have spent years chasing deadlock issues that won't stay fixed, playing whackamole, in between trying to do actual driver development. Following the amdgpu mailing list is not fun.
nalllar··on Wayland Isn't Going to Save the Linux Desktop (2022)
Currently you can't turn off vsync on wayland, except some limited cases involving full screen apps with direct scanout that may not even be implemented in your compositor or may not be possible due to missing implementation for async page flips with atomic modesetting.

Due to design issues relating to implicit sync with wayland any misbehaving app can cause your entire desktop to drop frames so if you're a multi monitor user expect stutters when the browser you have open in the background was a little too slow. Or worse if an app is badly broken [1]

The good news is that all of this is fixable. Windows has forced compositing for most cases and it performs much more consistently. A browser taking a while to render can't hang unrelated windows' composition. Wayland compositors can get there too eventually by moving to explicit sync APIs [2].

For now if you do care about these issues staying on compositorless X is the least bad option.

[1]: https://github.com/ascent12/compositor-killer

[2]: https://www.collabora.com/news-and-blog/blog/2022/06/09/brid...

nalllar··on Melatonin as a treatment for food waste
cumulative exposure to dihenhydramine is linked to dementia so it also shouldn't be used regularly
nalllar··on The ARM powered ThinkPad x13s, as a developer
I run Linux on it, it works but you need a non mainline kernel (github.com/steev x13s branches iirc) and a dtb in the EFI partition
nalllar··on Encrypted DNS and NTP = Deadlock
DNSSEC has the same bootstrap issue. I've had a device fail to sync its time because DNSSEC validation was on and all DNS requests were failing, which prevented lookup of the NTP server address.
nalllar··on Google removed my Yubikeys from a Google account 'just to be safe'
Makes rather little sense if so, given it's a hardware key. The most likely casees where the key is used to do something that trips this afaict are:

* genuine key, user does something fine that trips a heuristic

* genuine key, user's device is compromised

In either of these cases removing the key is making the account less secure. Google also removed all the keys associated with the account instead of just the key that was used.

Having a yubikey physically stolen and also knowing the details to log in with seems like it should be very rare.

If they're going to have a process that removes the keys they need to be so confident that they lock the account and go through some sort of IDV process to turn it back on. Removing the keys and leaving you with just a password that you just set up on the device that just logged in using the key is obviously not the right approach if you think the key's compromised because the password's just as compromised.

nalllar··on Google removed my Yubikeys from a Google account 'just to be safe'
Unfortunately for my hopes of getting this fixed, this post started getting flagged after it sat at the number 1 spot earlier today, or maybe Dang bumped it down because there are too many google support posts.

:P

nalllar··on Google removed my Yubikeys from a Google account 'just to be safe'
I don't have it but it looks like you have to initiate the call from the Google One page and they call you, they don't have an inbound number.

Googling "google one phone number" did show me a potential scam result in the infobox at "gooogle-live-personn" on google sites that obviously isn't official. You can't make this stuff up.

nalllar··on Google removed my Yubikeys from a Google account 'just to be safe'
If you are locked out you can't access Google One's support.
nalllar··on Google removed my Yubikeys from a Google account 'just to be safe'
Thanks for the heads up.

I don't use lastpass, but if I did I wouldn't have to because this "Just to be safe" process also reset/removed the recovery keys.

nalllar··on Google removed my Yubikeys from a Google account 'just to be safe'
Unfortunately due to a lack of customer support posting here gives me the best chance of getting it fixed!

If google had working support flows I would not have written this up or posted here about it.

A few years back I lost access to a different google account as the recovery phone number was a landline and google was trying to send SMS messsages to it. I had the right password but it thought I was suspicious and insisted on SMS verification. I never managed to reach a human to get something done about the issue.

nalllar··on Google removed my Yubikeys from a Google account 'just to be safe'
Anti-ATO should not clear out security keys that have been registered for a long time. If suspicious new keys were added, it should clear those.

From the audit log in my email no new keys were added before this was tripped.

I am not using a VPN and as far as I know I am not doing anything unusual. I might be committing the crime of having a Linux Firefox user agent but I somewhat doubt that was the problem, that's not that unusual.

Page 1 of 5Next →