HNHacker News
TopNewBestAskShowJobs

notpushkin

7,228 karma · joined May 30, 2019

[Verifying my OpenPGP key: https://keyoxide.org/dbed7086f4662ac59eaa343536271a1d783b07c4]

alexander@notpushk.in

submissionscomments
notpushkin··on Nitter and XCancel receive cease and desist notices
Google has sent a cease and desist letter to youtube-dl. It didn’t work out well.

And of course, Google is an AI company, too.

notpushkin··on When str.lower() is a security vulnerability in Python
And before that one, user content was hosted on *.github.com! Wild times.
notpushkin··on The brain may be about to have its Ozempic moment
I think you can have a separation between days while still allowing 24/7 trading. Just schedule automatic operations like stock splits at midnight, and with a proper staging environment you can deploy software in the middle of the day, too (just give a heads-up first).

And of course, overnight trading is available on some stock exchanges now. (I’m not sure whether this is a new thing or has existed for a while, but I’ve only noticed it on TradingView for some papers about a year ago I think.)

notpushkin··on Executable Is a SQLite Database
“SQLite database as an executable format”? A bit farther away from the original but captures the meaning and sounds more neutral.
notpushkin··on Executable Is a SQLite Database
Well, for the usual reason :-)

I’m wondering if the anti-clickbait filter could benefit from some lightweight LLM integration. E.g. when the submission hits the front page, if the title was “de-clickbaited” and wasn’t changed manually yet, run it through a cheap model and see if that was the right call.

notpushkin··on Stop Making TUIs
> I didn't really need to see a million examples of the author's vibe coded slop before getting to the topic which the title suggested the article would be about.

Agreed. One would hope the article would go into detail of how to make a great GUI (including tips on how to make sure it’s easy to navigate with a keyboard).

notpushkin··on Stop Making TUIs
> cross-platform GUIs always look bad outside of the "main" platform

qBittorrent looks great on KDE, and would look great on macOS too if they used native icons (I’ve made a theme for that but was too lazy to install it when I was switching laptops). No idea about Gnome and Windows, but probably alright as well.

So, Qt can get you a long way. But you should of course adapt your app to platform conventions and guidelines.

notpushkin··on I accidentally logged hundreds of thousands of phone calls to military bases
> because the telefax machine [...] is currently broken (and not even for DNS reasons!)

Who knows! Maybe it’s working just fine, but the e164.arpa record is pointing to the public prosecutor’s teapot or something.

notpushkin··on Kagi added a setting for removing paywalled links from search results
I think we’re broadly in agreement: the more private options we have (with different levels of privacy), the better.

It’s possible, in theory, to use Privacy Pass to allow e.g. using credit card to pay for the whole subscription without associating the account with the payment. (E.g. one payment gives you 1 “pass”, and it can be used to extend your account validity for one month.) In practice, it’ll probably be fairly easy to correlate a payment with an account extension, as those would happen almost simultaneously, so a couple more levels are needed here (e.g. doing this through resellers, and maybe breaking up the subscription payment into, say, 30 “day passes” which are used in random order to make it harder to track).

Posteo’s “one-time code system” is a fair bit weaker than Privacy Pass btw: when they get a payment, they can still associate it with your account (so if you’ve paid using, say, bank transfer, they will know your name, and you’ll have to trust them not to store the link). But it can be used together with Privacy Pass :-)

notpushkin··on Kagi added a setting for removing paywalled links from search results
Privacy Pass would decouple each search from the account. I think it’s okay to have as an opt-in thing. But private payments should be the default IMO.
notpushkin··on AI companies destroy physical books – let's scan rare books before it's too late
> You cannot scan a book and share it without violating copyright law.

Hence the “leaking” part.

notpushkin··on Slack Code
GitHub has bigger problems at hand. The uptime won’t plummet by itself!
notpushkin··on Google has stopped pushing Git tags for some Android source code
> You had to install so much of google's stuff to get anywhere near proper experience that it just wasn't worth it

What was it? Personally, the only thing I miss from stock Android is the Google Wallet/Pay/Wallet. (I do use microG to get push notifications and embedded maps working.)

notpushkin··on Google has stopped pushing Git tags for some Android source code
Google has servers inside ISP networks that distribute YouTube videos. They pay nothing for the distribution costs, I think they don’t even pay for electricity/cooling. If they wanted to distribute Android source code, they wouldn’t have to pay a dime.
notpushkin··on Windows brings out the Rorschach test in everyone
Yep. Same thing with Adobe.
notpushkin··on Solo – a .so loader for static Linux binaries
I don’t think I’ve said it out loud more than a couple times in my life. But in general I think I spell out / pronounce the “dot” in file extensions unless it’s completely obvious from context.
notpushkin··on Quake Shareware, a CD-ROM just a little too full
Hmm, it could work then if they’ve pressed most of the game data first and then recorded the encrypted part for each disk. But I guess the tooling for such setup would still be too expensive.
notpushkin··on Quake Shareware, a CD-ROM just a little too full
I vaguely remember CD drives with a headphone jack output!

(E.g. this one: https://pavel.network/using-cd-drive-as-poor-man-audio-playe...)

notpushkin··on Ask HN: Alternatives to GitHub
Good point, I forgot they’ve recently banned it. Updated my comment.
notpushkin··on Ask HN: Alternatives to GitHub
> depending on what you’re developing it may or may not be a good fit for you

I think if your project is free / open source (edit: and you don’t use LLMs/AI), Codeberg is the a good starting point at least. You can move on to a self-hosted instance if you feel you’ve outgrown it, but even for larger projects I think you can get away with self-hosting just the CI runners.

And don’t forget to donate! https://donate.codeberg.org/ / https://join.codeberg.org/

notpushkin··on The AI Credit Resale Economy
> CREDITS FROM YC STARTUP SCHOOL

Is that still a thing? I’ve thought they’ve discontinued the deals section. (There are a lot of other ways to get a startup grant, of course.)

notpushkin··on The AI Credit Resale Economy
And I’m pretty sure that’s just the tip of the iceberg.
notpushkin··on Guiding Ships with Moire Patterns (2018)
It is used and I guess it works largely the same way as in author’s first picture: you get arrows pointing towards where you should correct your course to. Tom Scott has made a video on those: https://wew.youtube.com/watch?v=d99_h30swtM
notpushkin··on Firefox is now the last major browser that still supports uBlock Origin
> Maybe I'm foggy on the history. But isn't this like Fork #4 or #5 of some previous AdBlock extension?

IIRC it was written from scratch. It was called uBlock before, then a co-maintainer tried to pull some shit, and the original author had to fork it with a new name (I don’t remember the details, it’s been ages since then).

No selling out yet. The author also explicitly says they don’t accept donations. I don’t think he’s looking for a business model. But if that changes – yeah, the fork button is right there, so I don’t see a big problem here.

notpushkin··on Firefox is now the last major browser that still supports uBlock Origin
Waterfox, a Firefox fork, has actually built a builtin qdblocker. (And yes, they do whitelist their search partner by default, but you can turn that off.) Apparently it’s faster than uBlock Origin, but there’s been problems on some websites, so I’ll be sticking with uBO for now.

Edit: actually, it seems the underlying functionality was built by Mozilla themselves, just not exposed in the UI yet: https://news.ycombinator.com/item?id=49309020

notpushkin··on Firefox is now the last major browser that still supports uBlock Origin
> I get unsolvable recaptchas all the time, especially on cloudflare pages.

If you really mean reCAPTCHA (the one with a “select all squares that have X” kinda challenges), then Cloudflare hasn’t used that for quite a while now. archive.today uses a Cloudflare-looking (old style) page with a reCAPTCHA (and they do serve it quite often), but I don’t think I’ve seen other sites do that.

notpushkin··on I close SSH port 22 (and what I use instead)
Good point, thanks.
notpushkin··on I close SSH port 22 (and what I use instead)
Why even type anything? Just ssh to 7000, and use the same public key to authenticate. The server responds with “You’re in”, opens up 22 and closes the connection. You then ssh normally.

This bespoke server should not advertise it in any special way though (generic OpenSSH banner), and can be used to also ban port scanners if they try to do something fishy.

fwknop is impossible to even scan for, though, so it’s a bit more robust in that sense.

notpushkin··on I close SSH port 22 (and what I use instead)
You could run both on 443: https://github.com/yrutschle/sslh
notpushkin··on I close SSH port 22 (and what I use instead)
fwknop is a bit lower risk though. If all an attacker can do is open a port, they’ll still have to exploit OpenSSH.
← PreviousPage 5 of 34Next →