HNHacker News
TopNewBestAskShowJobs

ongy

334 karma · joined October 8, 2021

submissionscomments
ongy··on Most people prefer traditional architecture
From a quick look at the Wiki page

I prefer Sydney Opera's outside shape.

The wiki pictures of the inside of the Heydar Aliyev Center also look odd to horrible to me.

ongy··on Steam Frame starts at $1059
Source?

Last I checked I'm allowed 100Wh of power bank on a flight. And for flights where that's not enough I'm used to having a (~100W) socket.

ongy··on Opening up 'Zero-Knowledge Proof' technology to promote privacy in age assurance
I tried to find something definitive, but it would take more time than I have right now. So to some degree this is assumptions, though generalized.

* Does the site know who the user is: No. That's the entire purpose here.

* Does the site know who the attestor is: Yes, they need to validate asymmetric crypto on the proof, so they need a list of public keys (which they can attach attestor identity to).

* Does the attestor know what kind of content I want to visit: They should not. With the JWT you can validate without telling the attestor which user's proof you validate. OTOH, if there's some "is this one revoked" type of API one could easily re-introduce such an information channel on accident.

* does the attestor know who the user is: Yes (or at least have some bits of information about you they are willing to attest to others. In practice assume it's Google/Apple/MS with information associated with your account, or your bank or ...)

* Does the user always know site/attestor: From a technical perspective yes. From a practical human one... doubtful.

--Googler, though far removed from this project, so no internal knowledge.

ongy··on Bias Compounds, Variance Washes Out
Gotta admit, I was expecting some hiring/Social biases topic.

This was quite interesting though. Surprised to see it work so well on a real example.

ongy··on It's hard to justify buying a Framework 12
I have the Framework 12".

It's hard to justify the price unless you put value to Framework's gimmicks and mission.

There's no illusion that I'm not paying extra to vote with my wallet for sustainability. And I'm on with that.

ongy··on When networking doesn't work
In my university times I wrote a library (to help with some homework we gave students) that calculated the CRC32 for ethernet.

Which worked well unless compiled with `strict-aliasing` gcc optimizations enabled...

Just writing UDP RFC compliant code doesn't protect you from running into annoying behavior with your programming language of choice...

ongy··on jj – the CLI for Jujutsu
I think you are talking about colocation, which is slightly different than the `jj git push` `jj git fetch` type commands.

Colocation has its uses bit is a bit finicky. The push/pull compatibility works perfectly fine (with some caveats of github being broken that can be worked around).

ongy··on GitHub Stacked PRs
It's the third attempt of building the mono repo.

But not the 3rd mono repo on the same technology to avoid some scaling limit.

ongy··on WolfGuard: WireGuard with FIPS 140-3 cryptography
Crypto wise, fips is outdated but not horrible.

Actual fips compliant (certified) gives you confidence in some basic competence of the solution.

Just fips compatible (i.e. picking algos that could be fips compliant) is generally neutral to negative.

I'm not 100% up to date, so that might have changed, but AEAD used to be easier if you don't follow fips than fips compatible. Still possible, but more foot guns due to regulatory lag in techniques.

Overall, IMO the other top-level comment of "only fips if you have pencil pusher benefit" applies.

ongy··on Migrating to the EU
I'm aware. I'm worried we'll get an Aussie customer at work and I have to fix their access to our systems...

Granted, we already have US/EU/Asia as distinct regions. AUS would just make fail over even worse.

ongy··on Migrating to the EU
Smack center of Europe (southern Germany) Got >100ms pings.
ongy··on Migrating to the EU
I love fastmail, but I really wish they had servers close to me.

The high ping kills the throughput on davfs and makes their website hosting a pain to update :(

ongy··on SCM as a database for the code
Your pseudo XML seems quite broken, since the supposed git style doesn't close the parent at all.

But the git directory entry contains: * a type (this one is quite limited, so I'm not sure how well that could be (ab)used * a name * a pointer to the content

Which is exaclty what an AST entry has.

ongy··on SCM as a database for the code
the git server would continue to work.

The cli really isn't the greatest either way. But there's lots of infrastructure to make the sharing work reasonably well.

ongy··on SCM as a database for the code
An AST is a tree as much as the directory structure currently encoded in git.

It shouldn't be hard to build a bijective mapping between a file system and AST.

ongy··on SCM as a database for the code
Why do you think it has too many children? If we are talking direct descendents, I have seen way larger directories in file systems (git managed) than I've ever seen in an AST.

I don't think there's a limit in git. The structure might be a bit deep for git and thus some things might be unoptimized, but the shape is the same.

Tree.

ongy··on SCM as a database for the code
That black hole behavior is a result of corporate processes though.

Not a result of git.

Business continuity (no uncontrolled external dependencies) and corporate security teams wanting to be able to scan everything. Also wanting to update everyone's dependencies when they backport something.

Once you got those requirements, most of the benefits of multi-repo / roundtripping over releases just don't hold anymore.

The entanglement can be stronger, but if teams build clean APIs it's no harder than removing it from a cluster of individual repositories. That might be a pretty load bearing if though.

ongy··on SCM as a database for the code
What issues do you see in git's data model to abandon it as wire format for syncing?
ongy··on Discord/Twitch/Snapchat age verification bypass
Which either allows to use a fingerprint of the signing key to be used for the same.

Or would open the system up to the originally posted attack of providing ~an open relay.

ongy··on Discord/Twitch/Snapchat age verification bypass
Ahh. The not-quite-a-hotel. I don't think I ever used them.
ongy··on Discord/Twitch/Snapchat age verification bypass
How does that prevent the ID service from discovering which services you use it for?
ongy··on Discord/Twitch/Snapchat age verification bypass
You could do some scheme that hashes a site specific identifier with an identifier on the smart element of the id.

If that ever repeats, the same I'd was used twice. At the same time, the site ID would act as salt to prevent simple matching between services.

ongy··on Discord/Twitch/Snapchat age verification bypass
Which hotel asks for id online..? I've only ever had to provide it once on-site and checking in.

And when then, only when I'm in foreign countries.

ongy··on Discord/Twitch/Snapchat age verification bypass
My main issue is trust.

In real world scenarios, I can observe them while they handle my ID. And systematic abuse(e.g. some video that gets stored and shows it clearly) would be a violation taken serious

With online providers it's barely news worthy if they abuse the data they get.

I'm not against age verification (at least not strongly), but I'd want it in a 2 party 0 trust way. I.e. one party signs a jwt like thing only containing one bit, the other validates it without ever contacting the issuer about the specific token.

So one knows the identity, one knows the usage But they are never related

ongy··on A case study in PDF forensics: The Epstein PDFs
No printer.
ongy··on FOSDEM 2026 – Open-Source Conference in Brussels – Day#1 Recap
Iirc. Jack was accepted by the organizers but pressured out by the community.

Also, about github: Had a chat with the Gitlab chap doing the Git talk in the main track. Apparently they dialed back their involvement with upstream git quite a bit. Github is currently providing a lot of infra gratis (thanks!) but is at best neutral to code and community.

ongy··on FOSDEM 2026 – Open-Source Conference in Brussels – Day#1 Recap
Agreed, this year was a bit light on questions.

OTOH, 80% of the reason I go to talks is to see if the person has interesting things to say and grab them after the talk for a chat. I.e. it sucks for the remote experience, but I think for on-site it's fine to just talk more.

Gets harder if you consider the talks the main attraction, but I really see them more as hooks to talk to people about interesting topics.

ongy··on FOSDEM 2026 – Open-Source Conference in Brussels – Day#1 Recap
Eurostar was fine for me. Getting to the Eurostar within Germany apparently sucked for some. But I took a later train and didn't have issues there either.
ongy··on FOSDEM 2026 – Open-Source Conference in Brussels – Day#1 Recap
It's mainly re-hashed. I think I've seen the same talk twice before? At least once.

It's a very "I've made a cool thing. This is what I think is cool about it" type of talk. Which I don't think is uncommon for FOSDEM. Maybe a bit uncommon for a higher profile figure like Lennart.

ongy··on FOSDEM 2026 – Open-Source Conference in Brussels – Day#1 Recap
The most important realization about FOSDEM is really:

There's no way you can fully experience it or do it optimal.

It's really about making sure you get value out of it, listen to some interesting talks and meet some people.

Page 1 of 5Next →