HNHacker News
TopNewBestAskShowJobs

p4bl0

19,415 karma · joined May 10, 2010

Blog: https://p4bl0.net/

Website: https://pablo.rauzy.name/ http://pablo2httpff4vogufavlmbxw4jkgb3amnywex2xdnchpztkdu2luead.onion/

Links: https://pablo.plus/

submissionscomments
p4bl0··on Self-Hosting on the Dark Web
A link in a comment is not the same as a front page link it terms of traffic, and when this link is a .onion, you probably divide at least by a few hundreds if not thousands the number of people who will click on it (even the few percents who have Tor Browser installed probably visit HN using their regular browser so visiting the link requires to open a new browser — or to change your proxy settings of you use Tor the old school way).

I really believe the single threaded BusyBox httpd running on a low end mini PC in my bedroom will stand hosting my static web site without any trouble.

p4bl0··on Self-Hosting on the Dark Web
My personal website has been hosted on Tor for years. It's easy to do from your home even behind a NAT because it's an outgoing connection from your point of view (which also makes it a great way to expose local services even when you are behind a NAT and don't not have a static IP), and by design your personal IP is hidden from your visitors.

I wrote about it in 2600 almost ten years ago (already?!). A copy of my article can be found here: https://pablorauzy.fr/outreach/2600/how-to-run-a-tor-hidden-...

If you have an Onion copy of your website, don't forget the Onion-Location http header which will automatically redirect Tor Browser users to the onion version of the website even if they visit it at the clear web address.

If it interests people, I also have a follow up article about I2P: https://pablorauzy.fr/outreach/2600/how-to-run-an-i2p-hidden...

p4bl0··on Don't couple your Go code to GitHub
True, but beware of the domain name you're using. Because VeriSign may unilaterally decide to delete your domain name along with thousands of others [1] and you're back to square one…

[1] https://neil.fraser.name/news/2026/09/03/

p4bl0··on Minimal Phone 2
Like a lot of similar devices, it looks cool, but, just like a lot of similar devices which have a physical keyboard, it will probably never be released with anything else than a US qwerty keyboard, so I'm already out.

Update: didn't scroll down enough! Indeed they have. Neat.

p4bl0··on Forgejo <=16.0.3 Critical RCE
They also have a releases RSS feed. I have those in my mail client (Thunderbird) directly for the projects that I must closely follow critical updates of.
p4bl0··on Git hosting that never leaves Europe
That's awesome. Thanks for working on this!
p4bl0··on How to Create a Tor Exit Node (2015)
> you may get law enforcement knocking on your door with questions

If you host an exit node on your home internet connection, the daily thing you will struggle with is not law enforcement, but rather the fact that your public IP will be blocked by most big websites to the point that simply browsing the web will become a pain.

p4bl0··on .name Termination
Update report: they are still categorically refusing, even for third-level customer who are alone (and have always been for 20 years) on the second-level they use. It makes no sense.
p4bl0··on .name Termination
The .name predates the TLD well-off crap. The first huge bulk of new TLDs happened in 2014, .name dates back from 2001, just like .info or .coop.

Also, .name filled an actual need for general non ccTLD: companies had .com, organizations had .org, Internet related stuff had .net, there was .gov, .edu, .mil, and ccTLDs, but nothing made for individuals. It filled this use case, it actually made sense.

p4bl0··on .name Termination
> There should be a conflict resolution to gracefully degrade the third level to 2nd level when there is no competing name on the second level.

Yes. I've been asking VeriSign for this for years, and they always refused.

p4bl0··on .name Termination
Not at the very beginning, but then it became possible.
p4bl0··on .name Termination
Another thing that should be obvious and yet they refuse to do: when there is a single third-level customer for a given second-level, offer them a way to get the second level domain. I've been asking VeriSign this for 15+ years, they always said no, even if at some point they confirmed that there were no other third-level than mine under that second-level domain. They're insane and should not be in charge.
p4bl0··on .name Termination
Really? Mine have been discontinued without notice something like 15 years ago!
p4bl0··on .name Termination
At the beginning of the existence of the .name TLD you couldn't do that, you were forced to register firstname.lastname.name and provide an ID to justify registering this specific domain.

With it you got an email redirection from firstname@lastname.name to the address of your choice. At some point this feature was discontinued (I assume when VeriSign took control of the .name TLD), a bit after it was decided (again by VeriSign) to allow registering first level .name domain. My main email address stopped working from one day to another without me being warned in any way.

When this happened I've emailed VeriSign and my registrar at the time, and tried several time since then, to be able to register the first level domain I'm the only one using, but they categorically refuse, despite recognizing that a single subdomain has ever been registered. They kept saying that I could just let the domain expire, wait for the grace period, and register it once it's liberated, hoping that no one does it before me, and without any solution for the downtime in the mean time…

And now this… fuck VeriSign -_-

p4bl0··on Why do so many tools have JSON config files?
Hey, thanks for Caddy! It's awesome :).
p4bl0··on Bye, Bye GitHub
I agree. GitLab UI was great and the simplicity of its CI/CD is unequaled on other forges. It's sad that Forgejo went with the actions model from GitHub which introduce a lot of useless complexity. But it seems that Woodpecker CI [1] could be a good candidate to replace GitLab CI, as it uses very similar concepts and workflow description files.

[1] https://woodpecker-ci.org/

p4bl0··on Bye, Bye GitHub
GitLab is also getting worse and worse. They're going full-in on AI and each new release is more cluttered with useless features and requires more and more resources to run smoothly. After six years self-hosting a GitLab instance for a few hundred users (among which a few dozens are quite active), I abandoned this summer and I'm currently migrating the instance to Forgejo.
p4bl0··on Immich 3.0
I teach a free software development course to my undergrad students. It's really exciting to stumble upon one of the work they did for my class in the wild (it's the first listed bug fix — which is the last of the three pull requests this student got merged in Immich during my course). I feel so proud! :)
p4bl0··on A field guide to the modern front end for developers who hand-wrote HTML
This is too oddly written to read in its entirety and I don't get the point. I mostly still do things like it says it worked in 2008. The difference with the "modern" workflow with 1400 packages and a build system is that web pages I put online just work, unlike most modern website which are horribly bug ridden and take ages to load and render.
p4bl0··on Obfuscation: Building the Final Boss of Cryptography
I really don't understand that some people are still trying to sell blockchain-based electronic voting. But anyway, I just wanted to tell a fun anecdote about the impossibility of making an obfuscater that works for any arbitrary program, or rather, since this is trivial for Quines [1], that it is possible to protect any program from obfuscation by making a simili-Quine of it. Given a program P, it is possible to construct a program Q(P) that takes an additional optional boolean input that defaults to false and which, when this additional input is false (i.e., by default), behaves exactly like the program P, but when called with the additional input set to true, acts as a Quine instead of executing P, thus outputs the source code for Q(P) (which is constructed to includes P's source code). This is guaranteed to work basically because an obfuscater cannot change the behavior of a program without breaking indistinguishability. I remember having a lot of fun working on that as an undergrad a long time ago [2].

[1] https://en.wikipedia.org/wiki/Quine_(computing)

[2] https://eprint.iacr.org/2011/497.pdf

p4bl0··on There are no instances in ATProto
I think the analogy presented here is broken. RSS doesn't depend on Google Reader at all. Even at its prime, RSS depended less on Google Reader than email depends on Gmail now. In ATProto, AppViews heavily depends on Relays to be useful, and Relays are quite expensive to run. Also, the yellow circles which represent blogs in the RSS illustration are really not of the same nature as the same circles which represent posts on Facebook. Blogs are self-sufficient, for example.

I'm not saying ATProto is bad at all, but I feel like this blog post adds more confusion than it clarifies anything.

p4bl0··on Developer gets Half-Life running at 30 FPS on a Nokia N95
I liked Symbian a lot, but I agree that Maemo was superior! Two after what I told above, in 2010, a few friends of mine had N900 and they seemed great. I was still in my study at the time and I interviewed for a summer internship at Nokia to work on Maemo and it was going great, but at some point during the recruitment process, that part of Nokia was sold (to Intel I think? the MeeGo project was announced a bit later) so they stopped all hiring even of interns and I had to find another internship.
p4bl0··on Developer gets Half-Life running at 30 FPS on a Nokia N95
Oooh! I fondly remember my N95! Pictures and movies it took were great, at least for the time, and it had apps and a lot of stuffs like a browser that were presented as new on the phone space when the first iPhone was released, while I had my N95 for almost a year at this time. Symbian was a really nice system.
p4bl0··on OCaml Onboarding: Introduction to the Dune build system
This is a good introduction to Dune, but frankly, Dune kinda sucks. I mean, it is very powerful, and works very well, but it's too much of a hassle, especially for beginners. I don't want a language specific build system to require two different files to actually be usable, even on very simple projects… I still use it because it is the de facto standard, but I really preferred ocamlbuild [1], which was actually a tool that just worked without any configuration necessary for simple projects that uses standard tools. Where you would need to write a Makefile and call make, you could just write nothing and call ocamlbuild and it would just work. Dune lost that ability entirely.

[1] https://github.com/ocaml/ocamlbuild/blob/master/manual/manua...

p4bl0··on No Let, No Rec, No Problem: A Gentler Introduction to the Y and Z Combinators
So it's as confusing as I thought to do it that way. I wasn't sure if I thought so because I'm already familiar with all these concepts or because this introduction is indeed convoluted. Thanks for taking the time to reply!
p4bl0··on Ask HN: Why is the HN crowd so anti-AI?
Thanks for putting it this way. I have to admit I was really astonished by the question as I feel like HN is very much pro-AI at least in the sense that there is more AI promotion on HN than there is AI acceptance among people in the real world. It's been months if not years since most of the posts are about genAI, and in a largely favorable way. It's actually quite fascinating that for some people it feels like the opposite.
p4bl0··on No Let, No Rec, No Problem: A Gentler Introduction to the Y and Z Combinators
I feel like introducing lambda calculus (using JS syntax) would be less cumbersome and convoluted than referring to "the challenge" without really justifying it and deferring to respect the rules for so long. But maybe some people entirely unfamiliar with these concepts find this approach easier?
p4bl0··on sp.h: Fixing C by giving it a high quality, ultra portable standard library
I agree with that. I'm just stating that it's contradictory with the project's own principles.

> Program directly against syscalls

It's the very first one of the listed principles. In the paragraph after this title it even says it "must" be the case in italic to insist on it, and there's a footnote to define what they mean, which is very clear in that pthreads should be out according to this principle.

p4bl0··on sp.h: Fixing C by giving it a high quality, ultra portable standard library
First, thanks for sharing this link, it was an interesting read! A few remarks below.

I had a hard time reading the wc code in the article. First I had to go to the GitHub to understand that "da" stands for dynamic array, and then understand that what the author calls wc is not at all the wc linux commands, which by default gives you the number of lines, words, and characters in a file, not the count of occurrences of each word in the file, which is what the proposed code does.

Also, since I had to read the GitHub README, another remark: it says that sp_io uses pthreads rather than fork and exec. Both of those approach (but especially pthreads) are contradictory to the explicit goals of programming against lowest level interfaces. I believe the lowest level syscall is clone3 [1], which gives you more fine grained control on what is shared between the parent and child processes, allowing to implement fork or threads.

[1] https://manpages.debian.org/trixie/manpages-dev/clone3.2.en....

p4bl0··on Rational quantum mechanics: Testing quantum theory with quantum computers
The author of this paper holds that quantum computers will never be able to go above the limit of a thousand qubits.

> Hence, insofar as a classical computer will never factor a 2,048-bit RSA integer, RaQM (rational quantum mechanics) predicts that a quantum computer will not either. This predicted breakdown of QM could be testable in less than 5 y.

People here who know about quantum computing, what do you think of this work?

Page 1 of 34Next →