HNHacker News
TopNewBestAskShowJobs

negative_zero

628 karma · joined February 28, 2018

submissionscomments
negative_zero··on GrapheneOS – When an app is slow
Odd. Google Pixel 7 with GrapheneOS here. OsmAnd works perfectly fine for me without disabling any exploit protection options.
negative_zero··on PCB is brought to you by Fable 5
Now get it through compliance :)
negative_zero··on How to Make a Nintendo 64 Game in 2026
Obligatory link to an interview with three of the Goldeneye developers about the development of the game. I found it very fascinating.

https://youtube.com/watch?v=bNN9XhGZ3Yw

(Also The Centre for Computing History YouTube channel is seriously underrated)

negative_zero··on What I learned selling 2,500 MIDI recorders: Hardware is not so hard
As usual for these posts. No certifications. No proper markings. Probably non compliant. Will probably go unpunished.
negative_zero··on What I learned selling 2,500 MIDI recorders: Hardware is not so hard
Modular Approval is an FCC thing only. CE doesn't have it.
negative_zero··on Texas grid flags risks as data centers, crypto sites fail voltage tests
It always seems wild to me how, in the US, something like the grid is just a wild west.

"ERCOT said it is reviewing the test failures and drawing up plans to protect the grid from disruptions."

Why are they even allowed to connect? / Why are they not kicked off? / Why aren't they being forced to add their own grid inertia?

negative_zero··on Motorola announces a partnership with GrapheneOS
Any chance of having a finger print scanner on the back of the phone?

I personally really dislike the screen ones. They're slower, less reliable and the location is unnatural.

negative_zero··on A small number of samples can poison LLMs of any size
So if I am a small open source developer or run small website, this could be added to my AI scraping defences?

If something like Nepenthes added poisoned pages to it's tarpit then a small number of users can just poison all LLMs?

negative_zero··on Why do we need MAC addresses?
Network people: Do we even need MAC addresses anymore? Can we not just have a UUID that the device generates?

They seem to get more abuse over time i.e. MACs are how a car is uniquely identified and authenticated with fast charging CCS networks for Autocharge.

negative_zero··on Privacy and Security Risks in the eSIM Ecosystem [pdf]
I've also had APN issues with physical SIMs, they are definitely not perfect. But I have never had an unusable "bricked" physical SIM. My eSIMs gripes are from being unable to use the eSIM at all. It's essentially a brick at that point.
negative_zero··on Privacy and Security Risks in the eSIM Ecosystem [pdf]
I did not know that. It's amazing how the usability and utility has taken such a big hit.
negative_zero··on Privacy and Security Risks in the eSIM Ecosystem [pdf]
Calling it "eSIM" is BS marketing. Every time I've used them it's been painful. I don't know the details but it absolutely is not "SIM technology". "eSIM" is something completely different.

A regular SIM: you just pop a SIM card into your phone and it just God damn works.

But eSIMs? I've used eSIMs from five carriers in three different countries and every time there is some issue:

* "Oh you need our god awful app to install an eSIM" (of course I couldn't easily download it because Google play geo hides apps).

* "If your phone is stolen overseas you can simply use this QR barcode again to register an eSIM to a new phone" (I couldn't).

* "Works with all phones". (It didn't because phone manufacturers have to bake Telco specific data into your phones firmware. Not supported? You're shit out of luck).

I could go on..

The fact that there are now privacy and security issues is not surprisingly at all. This isn't teetching issues. The drafters of the eSIM standard should be publicly flogged.

negative_zero··on Linux and Secure Boot certificate expiration
Well I can say that the update is not going 100% smoothly. I have a pending KEK update in Fedora but it's a test key (bug filed but no progress as of yet).
negative_zero··on Global EV Charging Points with Open Charge Map
Why would I use this over PlugShare?
negative_zero··on NASA acknowledges it cannot quantify risk of Starliner propulsion issues
The limitation is both ISS scheduling (it's very busy now and has been for a while) and number of available docking ports.

It's part of why the next crew dragon mission is being delayed, it needs to use the docking port currently occupied by Starliner (and Starliner can't leave until Boeing updates and uploads software for full autonomous operations).

negative_zero··on Rising rates of cancer in young people prompts hunt for environmental culprit
I would add PFASs to the suspect list.
negative_zero··on Ranked choice is 'the hot reform' in democracy. Here's what you should know
100% agree. IMO, these days it seems like FPTP is more actually a source of instability (than stability it is often claimed is one of it's benefits).
negative_zero··on Ranked choice is 'the hot reform' in democracy. Here's what you should know
Just want to add some nuance:

STV is used for the Australian Federal Senate.

The federal lower chamber (House of Representatives) uses optional preferential voting for candidates in a federal electorate.

I'm not sure if NZ is a fair comparison as it uses MMP, which is deliberately designed to favour multiple parties forming coalitions, not independents.

negative_zero··on How to validate a market with development boards and SD cards
Excellent additions. Sadly for Canada, some companies I worked with didn't bother because of these differences. "US market is big enough for launching. Maybe we'll come back to Canada later." They rarely did.
negative_zero··on How to validate a market with development boards and SD cards
One company I have worked with had an internal rule for "radiated emissions": You had to be 10dB (1 order of magnitude) underneath the limits before going for a formal cert. Non-negotiable.

Part of the reason for this rule was that they:

1) OEMed their products.

2) Sold products that could be used in complex and bespoke CAN networks with goodness knows what else.

3) There was a chance of interfering with Marine VHF radio which is used for emergencies. The EU rules were (still are) not actually strict enough for preventing interference with that band.

negative_zero··on How to validate a market with development boards and SD cards
There used to be. But they've been almost completely stripped away because of rampant abuse.
negative_zero··on How to validate a market with development boards and SD cards
Hard agree that pricing for standards is generally insane. IMO if the law requires it, it should be free + maybe a $10 admin. Anything else is BS. Standards bodies already make a killing off their membership fees. There are alternatives and workarounds though, here is one: https://news.ycombinator.com/item?id=36452660

If you don't want to hire a consultant then don't. You can do it yourself. Go get a EEE degree and then spend 5-15 years working as a EEE in product development and certification. Then you'll be good to go :)

Or just blind self certify and pay the lawyers, Friendly Spectrum Agency and other spectrum users (like cell phone companies) when they come knocking and asking for damages from you.

Here is a free primer I replied with earlier today: https://news.ycombinator.com/item?id=40926870

negative_zero··on How to validate a market with development boards and SD cards
As someone who has built relationships with labs to the point where I had "special privileges" the most important thing you can do is:

Make your test setup as easy as possible.

To expand on that:

1) Realise that you're mostly working with testing technicians NOT engineers. They see all sorts of weird and wild stuff. They often have to parse poorly written and complicated manuals written by engineers who don't have a clue about writing manuals and make poor implicit assumptions about the "target audience".

2) It's frankly, often soul destroying work (hence the churn, especially at the bigger labs). They use the crappy manuals for crappy products (but everyone thinks their product is the bees knees) try and set it all up. Then it doesn't work. Or it fails because the customer didn't do any pre-compliance work and was "hoping it would just pass". Well time is money, now they have to break the setup down because they've wasted 1 hour on the phone to some engineer who doesn't know what's wrong and is trying to trouble shoot through the phone. Now they get to do ALL that again with one else's crappy product.

So how do you make it as easy as possible for them?

1) Your setup should be plug and play and I mean TRULY plug and play. No manual should be required for putting the device into some hacky test state. Get the software engineers to automate it.

Does a button need pushing? Automate it or just remove the requirement somehow.

Does it need wiring up? Nail it all down on a giant piece of ply wood. Zip tie down all the cables. All the dummy loads. Any other devices. The only thing they should need to connect is the power cable.

Does a laptop need to drive it? Automate everything on there. ONE SCRIPT, maybe a menu in there depending on what test they are running. Make the laptop bullet proof. Get a nice laptop that boots and runs fast (not the one at the bottom of the IT donor pile). Give them a mouse to use.

Remove ALL of these barriers. AUTOMATE it ALL. Don't require them to baby sit it. That's a waste of their time.

PLUG AND PLAY.

2) Make it easy for a technician to see if and when the device is working VS it's not working. Don't give them instructions on "open this menu, do this, do that ..." no.

Put a red LED on it and a green one. Don't have one in your product? Be creative, Retrofit something. Have a special test UX on the device. Hell you should have special test firmware as a reference point.

They should be able to, at a single glance, look at the product and know: "Is it still working/running?"

So now imagine you have done all of that effort. Now put yourself in the shoes of that technician. One of the test stands is available early because a crappy product failed. They gaze towards the giant pile of crap they have to get through. Many are a a giant plastic box with tangles of cable, hand written crappy instructions, an IBM thinkpad from 1995 to drive it, no labels on any of the cables ....

... but amongst it they see your PLUG AND PLAY testable product. It's all mounted on a plywood stand, ready to go. There is almost a light from heaven illuminating it, it's so beautiful, it's so easy throw on a test stand and GO (and then do something else).

Guess which one is jumping the queue and going on that test stand? (And time is money remember. A test stand not testing is loosing money).

negative_zero··on How to validate a market with development boards and SD cards
Ethics approval for a medical device is a completely different thing from EMC regulations (which is what normally people mean when talking about FCC and CE for a device).

"I can't imagine having to have each hardware iteration certified by the FCC."

Depending on your device and the magnitude of the changes, this might simply be the reality for you. This is why I always try to tell people that you need compliance at the table from the start or you really risk making life very difficult for yourself. Find yourself a compliance specialist or at least a hardware engineer who is familiar with the regulations.

EDIT: You CAN'T just iterate ad-infinitum for free without consequence like you do for software. This thinking and approach, only works in software land. No where else.

It would be ridiculous to build a house and having the builder iterate on your house over 2-3 years to finish it, no?

negative_zero··on How to validate a market with development boards and SD cards
See my response to a similar question here: https://news.ycombinator.com/item?id=40926103
negative_zero··on How to validate a market with development boards and SD cards
EMC compliance rules are needed so that all our electronic devices (running software mind you) can continue to function. Part of the rules are about squeezing as much "performance" as possible out of the "thing" that is the electromagnetic spectrum. It's simple physics.

The other part of the rules are for human safety. Devices can directly hurt people (like a microwave) or indirectly (like a crappy device that prevented ambulance phone calls going through).

It's as simple as that (and not perfectionism or being mean to the poor software people).

""we're going to teach you how to cheaply get your product to market in a way that respects the spectrum" I'm available to do exactly that for you at my hourly rate :D

negative_zero··on How to validate a market with development boards and SD cards
You are correct on the spread spectrum clocks. Outside of military, they really soley exist for compliance (specifically unintended electromagnetic emissions) and are increasingly everywhere out of necessity. If an integrator needs spread spectrum locked on, there is no doubt a BIOS available that does just that.

"Now that I'm in position to ask ;)"

Ask away :) This is boring for 99.99999% of the population so I don't get to talk about it often :)

"I've wondered about the glass/plastic window PC cases.. Surely a PC case itself would not be required to have any emission tests done on it, or would it?"

You're right, a PC case itself does not need EMC compliance, but a PC case that's sold with a power supply does. So does one with built in fans and lights or anything electronic. IMO and very much off the cuff, certing the case + lights and fans without a whole computer inside is probably reasonable. But I would personally try cert with a whole PC (defence in depth).

"On the other hand, might the PC motherboard emissions be certified with the assumption that it will be placed inside a case?"

Yes it can be certed that way. Generally if it is, the details have to be in the manual.

But also, legally, you don't really need to cert a motherboard because it will always be integrated into another thing. However the reality of the PC architecture is that it is extremely modular and reach module is extremely complex. It's simply not at all practical for any systems integrator to try to modify those modules to try and make a whole PC compliant so that they can sell it. Even sticking the whole thing in a metal case might not be enough because the case has cables attached to and unwanted emissions and get out via those.

So for practical purposes manufacturers of motherboards, graphics cards, PSUs, hard drives etc vigorously test and cert their products with decent margins so that no matter what cards are used or how a PC is put together, the sum will be compliant. And this rule holds pretty well in general at all scales, from the individual parts and submodules that come together to make a product up to several products wired together in your house with power and network cables.

And system integrators can demand these requirements because it's necessary for the industry to function. I found a few years ago on Dell's website their manual for part suppliers. It listed every standard they required, made stricter and even had additions of their own so that they could sell with your module everywhere in the world, because they sell everywhere. It basically a thick manual on making a computer "world compatible".

"And then finally comes a consumer (or even a small integrator) and sticks in a PC motherboard inside a windowed case—but in this case the case might not be doing much on the RF side. Or maybe the cases provide better RF protection than they look like or the MBs don't need a case for that reason in the first place :)."

And the consumer benefits from everything I explained earlier. They can buy parts and assemble a computer that will be compliant. It's also why computer shops can build you a PC and sell without a cert and it'll be fine. Just the sheer effort of all these manufacturers so that they have a market to sell into means that the problem is solved for small players in the traditional PC world. The traditional PC industry is quite unique in that way actually.

negative_zero··on How to validate a market with development boards and SD cards
No problems. You are very welcome :)

It sounds like you are actually doing some things right :) FCC, for example, have scope for "modular approval". Order a radio module (with modular approval), do exactly as the datasheet tells you and you can "piggy back" off the radio modules radio certs. But you will still need to test and cert for things like your own "unintentional emissions", maybe ESD and other things (NOT actual compliance advice btw, this is just to give a rough picture).

"That said, while I actually enjoyed the snark in your reply, there are those of us who actually do want to get this right and do the right thing, despite lacking years of experience and an infinite budget."

Oh I absolutely know you people are out there :) (I've consulted for them. I've also consulted for the ones who are learning the hard way...)

I don't intend to be mean with posts like this on HN, but some reality on these posts is just needed IMO. Especially given how much software dominates product development these days and people just don't know.

I think it's difficult for new comers, but I don't know how you fix that other than asking a consultant. The earlier the better. You can certainly make early feature and design choices to make your certs simpler (and cheaper) down the road.

That said, I think a good place to start for anyone is the following:

1) Find a product that is broadly similar to yours. Is it like a small computer? Is it a wired network device like a router? Maybe it's like a bluetooth dongle or smartwatch? Find one from a large reputable company and search said company's website for their "EU Declaration of Conformity". On these docs (even though it is not required) many companies list the standards that the device is compliant with. They have names like: EN 55022, EN 60950, IEC 61000-3-3.

NOTE - This is for EU only, but they have massive regulatory reach. Also many FCC and EU standards are very similar or even the same. Over time they have been converging more and more.

2) Do this for a few different devices of the same or similar category and you will notice many which are always there and some that are sometimes there. Now you have a starting template of standards that you might need.

3) With this starting template, you can now look up the standards names and often download the first few pages free to get an idea for what they are for.

4) Get a quote from a lab. They often do a lot of testing for product importers (as onus is also on said importers), so they can have "non-engineer friendly" forms that you can fill in. This will give you a price but also some information on what they think you need (they have to be careful though because they have to maintain their independence). Tell them you want CE (Europe) and FCC (North America). This covers much of the world for you. Many countries, even those with their own standards, also simply accept CE and FCC (again this is all in very very broad strokes). Many standards are also just copy and pasted between different regulatory domains but they change the name. So the original standards body will have their name for it. When the EU recognises it, it'll get an "EN" number for it's name (for example).

4b) Consider a hiring consultant for a short chat to "downsize" the standards you need and maybe they can point out any you might be missing. Good ones can also advise you on things you can do to avoid standards (and this is not in an illegal way). If you understand the rules well, you can sometimes make small changes and avoid whole sets of rules and testing (classic one IMO is a radio device. In VERY GENERAL TERMS, if it's going to be used more than 40cm from a human, then you don't need to test for human absorption of RF energy. My Chromecast, for example, has a disclaimer on it so that they can claim exactly this (IMO of course) ). How to find a good consultant? Well that's hard and I don't have a sure fire way sorry. Some labs have business cards of small local consultants.

5) Source copies of the standards and read them (Yes it'll likely be heavy reading). Most standards sellers (including the national ones) are crooks. Don't use them. Instead go to the Estonian Centre for Standardisation and Accreditation: https://www.evs.ee/en . They are the cheapest source I know of for standards in English (and only English matters). Further details in an old comment of mine here: https://news.ycombinator.com/item?id=36452660

These above steps are the same steps that I myself use.

Sources to read ... sadly I've not found many good ones. I think the best one that I would recommend is https://incompliancemag.com/ It's dry and does what it says on the tin. But their archives have some great articles by experts. They cover new standards, certing particular devices, testing technology etc. Even the ads can be kind of informative I think. It's good for learning the general layout of the field. Not a shallow learning curve but not steep either IMO (It's also free in digital form).

negative_zero··on How to validate a market with development boards and SD cards
Then it's on you as the importer. This is part of why lots of stuff on AliExpress and dodgy Amazon 3rd party supplies is cheap. It's non compliant stuff that is not even sold in China. It's export only, and for the wrong reasons.
negative_zero··on How to validate a market with development boards and SD cards
In the purest theoretical sense yes, in practice no. So that you don't have to recert everytime, you

1) test and exercise your product to extremes so that you can say with high certainty that: no matter what the customer loads, it won't breach the rules.

2) As pjc50 mentioned: Lock down the parts which the user could potentially cause the most damage with. i.e lock down that radio firmware (why is why none of it is open source).

If you do (1) and (2) and a few other things, you buy down your risk sufficiently that you can confidently demonstrate that re-certs are not needed.

The Author of the parent article IMO is doing the exact opposite.

There are also half-way houses: Just doing "pre-compliance testing". So not a formal cert, your just doing a quick test in an anaechoic chamber or even on a table top scanner. Of course this only applies to things you can self-certify. Some things, like radios (WiFi, Bluetooth etc.), you cannot self-certify. That's why almost everyone buys the radio as a module (To buy down their risk). By consequence: That's why those radio module manufacturers have the firmware locked down hard and engineer and cert the radios to have big margins.

There are a lot of rules yes, but there is actually a lot of flexibility and common sense in the system too (but it is still imperfect, absolutely). But that flexibility does not allow for horsing around. If you can demonstrate to Friendly Spectrum Agency all this due diligence, you are going to have a MUCH better time.

Page 1 of 4Next →