HNHacker News
TopNewBestAskShowJobs

nirui

2,062 karma · joined June 12, 2019

You know, I figured if I run this undefined behavior long enough, eventually one day that server will just jump down the shelf and fix the red black tree by itself.

[ my public key: https://keybase.io/nirui; my proof: https://keybase.io/nirui/sigs/oi8UKCZcYxKij-Pi43fDt35S1cHWmEKrFeMHZ4wW5Mo ]

submissionscomments
nirui··on Don't couple your Go code to GitHub
I'm guessing by commercial software, you mean GitHub etc.

Well, I too dislikes their enterprise tune, "Changing is consistent, GitHub give you advantage (over other companies)" blahblahblah. Many developers I know are on GitHub because it was/is the place for individual developers to share code, not because the "company advantages".

HOWEVER, I can't ignore the fact that individual developers just can't pay enough to keep the machine running, so it's reasonable for GitHub to pivot towards commercial market. On the other side, GitHub is still benevolent enough to provide some enterprise-class service back to freetier users. This arrangement checks out for me so far.

I do self-host some of my projects too with Gitea. But I never dare to use my domain in my Go packages, due to long-term security concerns.

When I initialize my projects, I just use .internal domain, then if I decided to upload the project to GitHub, I'll change the URL to GitHub to make it more convenient to the users. Otherwise, manual download and `replace` directive like I suggested.

nirui··on US sanctions force The Netherlands off Microsoft and toward alternative NixOS
This don't make things better through.

Putin and Trump sits in the opposite side of the political spectrum, so as the country they lead, and yet they still managed to archive something similar.

It's not that hard to manage the country to a point where nothing in the country, even law, can hurt it's leader anymore. Sometime a bit of time and patient is all it takes.

nirui··on I switched to Brave
The "We won't sell you data, pinky promise..." argument from article https://kevquirk.com/is-firefox-firefucked is reasonable, but if you're really hating AI ... well, Brave has their own AI called Leo, which is IMO even better implemented than Firefox's.
nirui··on Don't couple your Go code to GitHub
A GitHub URL at least is still an credible identifier, your custom domains is not, and likely will never be given how the system is accustomed to. Domain is for branding, not identification.

Unless of course, it's special domains that has identification built in, such as .onion which is generated in such way (cryptographic keys) no other people can easily obtain control even after the domain is no longer maintained.

If you really don't want to use GitHub, an alternative is just use .internal suffix (i.e. yourproject.internal/project) in combination with `replace` directives in go.mod. But that require your user to manually download/install your package and then edit their own go.mod.

nirui··on CAPTCHAs don't prove you're human – they prove you're American
Major Internet companies are still American-centrist, after all, many of them are American platforms and concerns (if not only concerns) American interests.

Google for example, they provide CAPTCHA to train their own AIs. Since Google mainly operate in the US, it make sense for them to optimize for Americans.

Another example is Cloudflare's CAPTCHA page, which is created based on measurements of American/first-world networks. But if your connection is "sub-optimal" (a.k.a, not first-world enough), it is possible that you don't even get the chance to load the verification scripts before the server cuts the connection and force a page reload, forming an infinite dead loop.

I feel the Internet is no longer international anymore, especially after all the AI scrapers. Now days are the days of contraction and everyone is guarding their own boring little caves against what they've defined as "thievery/stealing", while putting very little effort into actual useful thing such as gaining market and user (a.k.a expansion). The CAPTCHA implements maybe a sickness of it.

nirui··on Nobody pays for FOSS, we can force them to
Depends on what you're doing, the "source-available" model may not work. Because many software earns their money through just few tricks, maybe it's more user-friendly design, maybe it's better predictive algorithm etc. These tricks hidden deep in the logic so it's hard for the competitors to figure out in months time.

But if you made the source code available, the trick will be reveled in plan sight and you lose advantage quickly. After that, you turned software making a laborer's game (you need add laborer to add and/or steal ideas faster than your competitors), it's way less fun.

If you want to make money, you have to play the art of balance. How much do you want to make open, and how much advantage you want to withhold.

nirui··on Warren Buffett Steps Down as Berkshire Chairman, Names Son to Replace Him
I wish I saw this comment two years ago while the stock price of one of our local company is still cheap. I sold all my shared before the price slightly tanked, earning just around 14% profit. Now two years later the price has gone up ~100% and they paid dividends twice during the time.

Should have treated it the old-fashion way, not the modern day-trading way.

nirui··on How Uber Protects Against Retry Storms
I think the example is still too generic.

First thing is, if your service has 7 call layers, maybe it's just too deep.

Second thing is, I found that retry strategy works the best if you define it based on what the nodes are actually doing (instead of treating them as generic nodes). For example, if node D is a database failing a transaction, you may just configure it to retry the transaction instead of doing an application-initialized request resubmit, because the database probably knows better about why the transaction has failed than the application connected to it.

Third thing is, retry is worth it only when progress has been and/or can still be made. If the resources is no longer available forever, then there's no point of retrying.

nirui··on Dario, Please
The problem about AI censorship is that, you can't preform bans without also create privileges at the same time. Sure, you can censor your AI to provide a "safe" version to the public, but someone will have the access/privilege to the uncensored version.

What stops the CEOs or even employees of the AI firms from creating something harmful such as WMDs etc themselves? They almost definitely already have that access. And this is not a zero-possibility thing, given how some of the top CEOs has preformed these years. Remember that one guy who did a \o salute in public, and the private island thing?

If Americans don't like Chinese AI, all cool. But then maybe they should start true open AI companies to build for the betterment of mankind instead of letting these few for-profit CEOs daily yelling nonsensical lies to cover those profit-seeking sinister asses.

nirui··on Forgejo <=16.0.3 Critical RCE
I'm just reading the code here:

  // Before template expansion, .git was removed so that a fresh repo can be initialized; remove it again in case
  // some template variable usage has conflicted with this directory and impacts git operations.
  if err := root.RemoveAll(".git"); err != nil {
    return fmt.Errorf("unable to remove .git folder")
  }
Why the `err` isn't carried by the error message? For security? Then maybe log it internally?

User/operator can't really fix the problem if you keep giving them information this vague.

nirui··on .name Termination
Hmmm, I was wondering who were the "volunteers or people paid to do fundamental research" (in their project docs), it turned out to be new grads LOL.

But I wouldn't blame Torrent or IPFS, these project maybe less shiny, but they actually work, so :)

nirui··on I resigned from Anthropic today
If I may guess, given how delicate chem or bio weapons are, even if AI can lay out a method to create one, the first thing the weapon would destroy is likely it's creator(s).

Of course, with the exception that such weapon is created by organized crime groups, such as drug cartels such.

Probably don't worry nation states tho, these guys already got way worse things in their warehouses than what individual baddies could ever imagine.

nirui··on Nvidia's Jensen Huang says 'AGI has arrived' and congratulates OpenAI
Speak of that, I'm kinda surprised not one Full Self-Driving enabled Tesla has ever sneak out of their owner's locked garage to rob a bank or something.
nirui··on .name Termination
Wonder what's up with the GNUnet (https://www.gnunet.org). Apparently there's still activity on it's development, but I didn't see adaptation/integration, even in free software like Linux. Sure it's not 1.0 yet, but the open source world is filled with sub 1.0 software that works great.

A stable online identify is important, that's maybe why you rent those domains etc. But after rent and forego quite a few, I slowly realized that domain at it's current format isn't a stable presence, instead it's more like branding instead of an identify. If an identify can be operated by different people without it's previous operator agreeing, is it truly an identify?

But I do need an identify, always under my control as much as possible, so people can trust the content and service running on it without having to guess if it's still me operating it.

nirui··on California lawmakers unanimously pass Linux exemption from age-verification law
Wow, you guys are really REALLY naive aren't you.

They made it sound like it, but this is not a victory at all, this is a temporary strategic compromise to silence the most sensitive/foreseen privacy advocator for now. But they will not stop here, instead they'll keep advancing the mechanisms, opinions and laws, so one day when the pieces aligned, they can come back to turn this tap off while having people lied to their side.

Forced age verification needs to be abolished completely and people who advocated for it punished to the point that their political career ends, this should be the baseline.

But of course, based on my understanding of everything, no, nobody will do anything effective against it. Everyone will just be "Yeah... they forced a component on my system that could act as spyware to monitor me, then have me pay for it without give me any control. But guess what, I will accept it because they said it's good for the future of mankind", like a peasant would. This is the tax you paid ended up for you, you know?

nirui··on Defrag98: Windows 98 Disk Defragmenter Simulator Online
Fuck! Why I'm just staring at it like I did ~20 years ago. It's not even real!

And it blue screens?

nirui··on Stopping the smart TV from being used against you
Not sure if it's just me, but I started really dislike the "tech product" these days.

You bought this TV and it might install malware on your computer, so to use it you also have to buy a blocker that might be a scam. Where is the joy in all of this?

My X.com was shadowbanned, I got tired trying to resolve it, so I made the ban permanent with a simple element `.click` against the Like button of one of my post done inside a very quick `window.setInterval`. One of the best decision I ever made during the past few years.

I'm also in the process of getting my Steam account deleted because my friend told me it has been flagged while all I did was just using it as I would normally, no hacking, no cheating etc, paying all with my own money instead of gift card.

Maybe I'm old, I got really tired on performing maintenance on other people's bad intent or mistakes. But you know what, sometimes, cutting things off from your life can be beneficial, it makes you focus on things that truly matter to you, or at least it triggers the review process while you making the decisions.

Do you really need a TV anyway? Just so you can then spend more on it to watch stuff that you'll probably forget within a week? Less stuff, less suffering.

nirui··on Software engineering is about managing complexity
> By algorithmic thinking, I mean defining a set of basic rules to follow and applying everyday...

This is actually kinda a good suggesting for everyday life as well. Many problem people face are too complex to figure out without systematic analysis, and with this method of thinking, complexity can be simplified.

Of course you have to do some swaps:

    > Understand data flows                    -> Understand whats, hows and whys
    > Choose appropriate data structures       -> Choose appropriate tools
    > Reason about time and space complexity   -> Reason about cost and effectiveness
BTW: Is this article was about LLMs induced identity crisis? I noticed quite a few blogs written in a similar color trying to realign themselves in the new world of AI.

Of course that's a reasonable thing to consider, but in addition to that, I think it's also kinda useful to remember why you started as a software engineer to begin with, what were you planning that drives you to select this path? Will AIs be a blocker of that plan, or a enhancer?

nirui··on One corner of China’s internet is insisting that the Tang Dynasty never existed
> The outlandish claim has since spread far and wide

Is this significant? I never saw anyone talking about it on my side of corner.

But, It's not really that surprising. A significant part of human civilization still believes that we humans were created by beings who live somewhere in the sky/atmosphere, and these beings are watching our every move to punish or reward us, and you beg really really hard, they'll help you (if they didn't, you ain't begging hard enough).

nirui··on The entire city of San Francisco as a video game
Now sure how to "steal" cars, but when I press V to call a vehicle it eventually says "Vehicle unavailable - stay on foot".

But what did available was a glider, so I guess my only form of faster transportation in the city is to glide to anywhere I want :)

nirui··on Felony charges for citizen deleting phone data at US Border
What if, instead of a Duress password, the password you gave to the agent was very long and they simply typed it wrong, and the phone now asks for a much stricter authentication that require it to be in a specific location and environment (for example, inside the office of an user-designated lawyer) to continue to the unlock? Will that still counts as a felony? The data is still there, stored safely inside a phone, the agent just need to get their asses to the lawyer office.

What if, by some bad luck, that lawyer moved on to other job ventures, sold his office along with the equipment needed to unlock the phone? Will that still counts as a felony? The equipment maybe still in circulation and the data is still on the phone.

nirui··on Canada will match US tariffs 'dollar for dollar' as trade talks break down
It's like all the other nations were at fault. But maybe these nations "caved" because the strategy implemented by the US worked.

And China, based on my understanding, is looking for ways to reduce US influence anyway at least domestically. So, a worsen-yet-controllable US-China relationship maybe considered beneficial on that end. The tests (lockdown etc) done during COVID time has proven that Chinese people endures much more suffering before they begin to rise up, so the economic problems introduced by not caving to the US is just a small cake for the lead party to handle.

nirui··on And then the men with guns tell you to do it anyway
> I asked him about the incident - he talked about how they built the SMS infrastructure, what they did to secure it, how they prevented spam, and how one day armed men arrived.

Maybe this confusing can be resolved if you view the authority, spammers, and "armed men" as equals. For example, you can treat them as interest groups, but with different level of power. It's a game, it's about incentives, desire, promise and payment, nothing about "do the right thing" or "for the people".

Now it's the Armed Forces got the top power, so you obey them until either they get replaced, or your own power grown so you don't have to continue pretending. The rule is just that simple.

And on the referenced "Civic Hygiene" article:

> But! Shock horror! After creating the database, the Government loses the election and the homophobes at UKIP get in to power! Now they have a database of every gay in the village, and can harass then, try to "cure" them, or make their lives a living hell.

Then, you just get cured ;) It's like a magic. Previous day you are a guy with a deeply lovely boyfriend, today you are seeking to marry the most beautiful woman available, because the cure they give you make you realized how disgusting the hairs on man's legs really are, ew! puke! Just lie, everybody can do that. Truth only belongs to people you love and love you, not the people who don't care about you, not even the neutral public.

BTW: Completely off-topic here: There was an article titled "Incentives are for losers" posted few weeks ago: https://news.ycombinator.com/item?id=49227652. It was beautifully put together, the leftist part of me almost convinced.... But, the rest of me realized that if you look the real "successful" people out there, the rich and powerful etc, you'll found that they all succeed by chasing the right incentives. Interesting uh?

nirui··on Civilians under siege by Mexican cartel fight back with AK-47s, grenades
Based on all the historical events, I'm guessing it'll eventually balance itself out. The violent vigilante groups are one critical weight on the scale. Without it, the cartels will have free-range to commit whatever atrocity they want without needing to think about the consequences.

Now, with these vigilante groups that speaks the exact same language that the cartels too understands, it gives those cartels a reason to think before they bully civilians. Because if they did it wrong, there's a chance some of them will start to lose bodyparts in a very unanesthetical way. If a few once incontestable cartel leaders puts on a show of crying and begging for mercy in a darknet video, it tends to educate everyone on what power really means potentially in a good way.

Of course, none of it is reasonable and civil, it's the darkest part of human behavior, but sadly sometimes it's the only way to communicate with the bad people. Mr. Hitler didn't surrender because the allies did a good job showing him that killing is bad, instead they bomb that rat in his own hole and scared him to death.

I don't like violence and I don't like people who uses it unnecessarily, but it's still a tool in the toolbox just in case the opponent is that unrecoverably bad.

nirui··on After Losses, Retail Investors Flock to 3x Leverage as 2x Product Are Restricted
Investment or business do also have some gambling factors in it. And both usually cost extreme amounts of money to get started.

However, I found that if the bar of doing business is high enough, "investing" in stock market maybe safer than start a proper business. Because if a business failed, you likely lost a huge amount wealth, including everything you put into the business and maybe more. Whereas if you buy stock responsibly (for example, DCA VOO/&QQQ), there's a high chance you'll eventually bounce back.

Maybe that's one reason the young Koreans invested so much in their stock markets. Their country failed them by restricting them from opportunities, the only way they can save themselves is by gambling.

nirui··on Go 1.27 Interactive Tour
Not here against Generic methods, but I feel the Go team is in a mid-age crisis where they lack of new things to do to prove themselves. See their iterators mini-drama not long ago?

I feel the sumtype/emum/routine demanders should yell a little harder so Go team can find their purpose again.

nirui··on Cloudflare's new AI traffic options for customers
Yes, it only work if the scraper, or rather scrapers cannot collaborate in a smart way (for example, doing Cookie sharing among themselves). That's limited by how Cloudflare page rule work, it don't really support anything that is too "dynamic", for example you can't concat/mix a Cookie with a Request date and then compare it, you can only check if there's a Cookie or Request date match a static value.

If you want something more powerful, there's also Cloudflare workers, which you can program to do whatever you want. But that one may cost you to run.

Also in my case, the scraper IPs are all over the globe, and almost each access is from a different one, so simple IP blocking don't work unless I block Vietnam, Brazil, Bangladesh, Argentina and the US etc (https://i.imgur.com/eWI5meM.png). But then, the scrapers might just go to another country next month.

Since I deployed those rules, the access from scrapers has almost stopped, while normal search engine crawls are almost unaffected. So it do still work for me, even if it's very rudimentary. But hey, security though obscurity it alone is not enough, but it sometimes do delay the attacks.

nirui··on Cloudflare's new AI traffic options for customers
> not take down systems

"Block on pages with ads" is probably about preventing the AI crawlers from clicking on the ads which maybe considered cheating by the ad company.

If you want to prevent "bot attacks", maybe the "Block" option will do the trick.

But of course, to do all that you need to put some trust on Cloudflare, because they're the one identifying the bots from normal users.

For me, as someone who's hosting a Gitea instance behind Cloudflare, I have a Configuration Rule set that says: if the client is trying to access a URL that is beyond certain length limit, then trigger "Browser Integrity Check" and "I’m Under Attack", a.k.a stricter security checks.

The match expression of the rule looked something like this:

    (
      len(http.request.uri) > !!!!!SET LENGTH LIMIT!!!!! and
      not lower(http.request.uri.path) contains ".git/" and
      not lower(http.request.uri.path) contains "api/"
    )
(The `!!!!!SET LENGTH LIMIT!!!!!` is an integer of the length limit you wanted to set)

This rule alone basically blocked all abusive bot traffic to almost zero for my site (https://i.imgur.com/LaOjjvV.png, see the traffic drop around 10 clock and Cloudflare mitigation kicks in).

But of course, you need to figure out your own rules based on the characteristic of the website. Also, you can be more creative: for example, my actual rule is more complex than that, it also checks to see if a cookie is not set, and only triggers when all condition are met:

    (
      len(http.request.uri) > !!!!!SET LENGTH LIMIT!!!!! and
      not lower(http.request.uri.path) contains ".git/" and
      not lower(http.request.uri.path) contains "api/" and
      not http.cookie wildcard "*!!!!!COOKIE NAME!!!!!=!!!!!COOKIE VALUE!!!!!*"
    )
then, as part two of that rule, I have a Response Header Transform Rules that says:

    (
      len(http.request.uri) <= !!!!!SET LENGTH LIMIT!!!!! and
      not http.cookie contains "!!!!!COOKIE NAME!!!!!=!!!!!COOKIE VALUE!!!!!"
    )
and if this Response Header Transform Rules is triggered, it sets the cookie `!!!!!COOKIE NAME!!!!!=!!!!!COOKIE VALUE!!!!!`.

(Note: `!!!!!COOKIE NAME!!!!!` and `!!!!!COOKIE VALUE!!!!!` are the variables you need to customize)

When you put the two rules together, it forces clients to access "shallow" (short URL) pages first as an user would normally do, before they can access "deeper" (long URL) content hosted on the site without triggering more strict security checks. If that makes sense.

Also, don't forget the cookie basically also dug a hole in the security setting. So it's really a balance between avoid annoying the user and protect your site. You need to be smart and be flexible about it, otherwise your users will just leave.

nirui··on Startup founders urge U.S. government not to shut off Chinese open weight AI
One question here: Why you don't see a lot of good American open weight models on the market? I'm guess it's about money? Could there be ways to lower that cost? Sharing idle GPUs through network (like Folding@home, BOINC), open and fair market for training data, open source training framework, and such?

This whole Chinese AI thing makes me giggle at these American AI companies, but the ultimate solution/long-term goal is still to make the technology universal. I don't think China alone can make it happen.

Also, if Americans can too offer open weight models, that could change the logic of their laws, making it more open rather than protective.

nirui··on Claude Code uses Bun written in Rust now
That's why it matters for people to hold the control of the tech, not companies, as I've already mentioned quite clearly.

LLM is here to stay, keep denying the fact won't work. What does is to make the tech so abundant, it flushes the bad actors, such as for-profit AIs, completely out. It's either this, or get crushed by for-profit AIs, pick one.

Page 1 of 22Next →