HNHacker News
TopNewBestAskShowJobs

pgraf

136 karma · joined August 6, 2023

long time lurker
submissionscomments
pgraf··on How many of the 170k English words do you know?
Really interesting, but I would love to be able to express honestly when I just guessed. This way the result would be much more scientifically sound. Four answers have a 25% chance of random correctness, which is a bit high in my opinion. I think either adding a "I don't know" or a confidence level (Known/educated guess/wild guess) would help.
pgraf··on The founder's playbook: Building an AI-native startup
This problem really bothers me as well. I think that ultimately this problem boils down to reducing search cost[0], which the internet has already partially done. I think AI will reduce them further if it is not captured by the advertisement industry for the average user. However, we cannot assume a fully rational customer in the real world. Especially in software, the customer does not know what they are looking for most of the time. Further they cannot evaluate how good your offering is vs competitors without investing a significant amount of time, which in turn increases search cost.

[0] https://en.wikipedia.org/wiki/Search_cost

pgraf··on Google employee charged with $1M Polymarket insider trading bet on search term
Pretty ironic find: Extracting knowledge from cryptocurrencies - Michele Spagnuolo https://www.youtube.com/watch?v=9P04hm7tmgs
pgraf··on Goodbye Visa and Mastercard: 130M Europeans switching to sovereign payment
Wero uses AWS for their infrastructure... So much about their sovereignty focus.

Source(German): https://netzpolitik.org/2026/uneingeloestes-versprechen-auf-...

pgraf··on Slowness is a virtue
The quip about IQ tests might be true for common range IQ tests, but IQ tests that test for very high IQ like the Ultra test [0] are untimed and unsupervised.

[0] https://megasociety.org/admission/ultra/

pgraf··on Amazon to invest another $4B in Anthropic
Could you maybe post it here? I think many of us would find it useful to try.
pgraf··on Homemade AI drone software finds people when search and rescue teams can't
I don‘t see any hint of AI being used here, but rather a handcrafted computer vision algorithm. Can anyone more involved in the matter elaborate if there was an actual AI model used?
pgraf··on CUNY paid Oracle $600M for its HR software (2013)
Sorry if that came around as rude. From personal experience I have not met any professor in my life who could lead such a project, let alone with students that don’t have any work experience… And you imply there should be multiple of them for the project to succeed
pgraf··on CUNY paid Oracle $600M for its HR software (2013)
> I get that there would be risk, but if it was under the supervision of professors (who hopefully are good at building, not just lecturing theory) […]

Good joke here! If you are actually serious, please tell us which university you encountered where the majority of professors actually did something productive in computer science

pgraf··on Kim Dotcom's extradition to the U.S. given green light by New Zealand
> The US government is so powerful, they are the only country that enforces a draconian global taxation scheme on any citizen or person who has ever held a US green card […]

While it may be true that they are the only ones able to do it effectively, there are some other countries with citizenship-based taxation. According to Wikipedia[0] these currently are: Hungary, Eritrea, Myanmar and Tajikistan

Some other countries have similar policies for tax heavens.

[0]: https://en.wikipedia.org/wiki/International_taxation#Citizen...

pgraf··on Is "Rich Dad Poor Dad" a Fraud?
On another note the author of the book, Robert Kiyosaki, has also been a rampant promoter of Bitcoin. Just recently he predicted the price of one Bitcoin to be 10 million USD soon: https://www.nasdaq.com/articles/robert-kiyosaki-predicts-10-...

I don't think you should take someone who says that seriously for your financial planning.

pgraf··on Comparing HTTP/3 vs. HTTP/2 Performance (2020)
Care to elaborate?
pgraf··on Linux Network Performance Ultimate Guide
If I may ask, what is your use case so that a L3 tunnel does not suffice?
pgraf··on On Building Systems That Will Fail (1991)
One quote that I find funny from today’s point of view:

As we approach the present, corresponding to a personal computer, the graph really should become more complicated since one consequence of computers becoming super-cheap is that increasingly, they are being embedded in other equipment. The modern automobile is but one example. And it remains to be seen how general-purpose the current wave of palm-sized computers will be with their stylus inputs.

pgraf··on "Out of Band" network management is not trivial
Sounds like a problem that should be (rather easily) fixable in the Operating System, no?

If the emergency call doesn’t go through, try the call over a different network. This would also mitigate problems we see from time to time where emergency calls don’t work because the uplink to the emergency call center was impacted either physically or by a bad software update.

pgraf··on RegreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems
Genuinely curious, how would you block an attacker from getting to your SSH port without knowing the path you will connect from (which is the case for remote access) at configuration time? I don‘t see how Path-Aware Networking would replace a VPN solution
pgraf··on Chat Control Must Be Stopped – Now
FYI, 84% of ID has voted pro chat-control in 2021.

https://mepwatch.eu/9/vote.html?v=134463&eugroup=ID

pgraf··on What You Get After Running an SSH Honeypot for 30 Days
Just be aware that with your strategy “blocking 50% of unwanted traffic” means blocking non-attack traffic, as these Internet security companies are mostly legitimate. The automated attack traffic that you actually want to block is in the other half and will frequently change IPs.
pgraf··on Microsoft Chose Profit over Security, Whistleblower Says
Imagine a major bridge that was built by a contractor. A internal safety inspector repeatedly warned his supervisors of structural deficiencies that could lead to the collapse of the bridge. Furthermore, in the pass of time two external sources publicly warned about the issue, but the company downplayed the importance. Finally, the bridge collapses. It becomes evident that the company did nothing about the issue because it didn‘t want to loose contracts selling more flawed bridges. The public would justifiably go nuts, and there would be legal consequences for everyone involved.

What is different in our industry that companies (and managers) get away with such malice?

pgraf··on Microsoft Chose Profit over Security, Whistleblower Says
It is true that nothing is 100% secure. Sitting on a major security vulnerability internally with a motivated employee pushing to fix it and doing nothing for business reasons is not negligence, but malice. People in the chain of command need to be held accountable for this.
pgraf··on A Single Vulnerability Can Bring Down the JavaScript Ecosystem
TLDR: A Denial-of-Service vulnerability triggered via cache poisoning on registry.npmjs.org which can render individual packages inaccessible

I don't see the big security impact that the headline suggests, as active big-scale exploitation would likely be quickly noticed and fixed. The most interesting attack vector IMHO would be to block individual security fixes to packages on a small scale.

pgraf··on Engineering for Slow Internet
Shouldn’t HTTP compression reap most of the benefits of this approach for bigger pages?
pgraf··on Tracking Illicit Brazilian Beef from the Amazon to Your Burger
Which… is largely fed to our livestock?
pgraf··on Lions OS: secure – fast – adaptable
Can anyone elaborate which (proposed) advantages LionsOS has over Genode?
pgraf··on Personal VPN services are snake oil
According to this article, this is probably a myth:

https://www.theatlantic.com/health/archive/2018/09/victorian...

https://archive.is/idRiW

pgraf··on Personal VPN services are snake oil
They can still deduce it from the TLS SNI unless the web server you access supports TLS 1.3 Encrypted Client Hello. https://en.m.wikipedia.org/wiki/Server_Name_Indication
pgraf··on eC Programming Language
Seems to be hugged to death. https://archive.is/xixuj
pgraf··on Universities Lost the Internet
perfect use case for the public suffix list (https://github.com/publicsuffix/list)

e.g. add *.ext.workplace.com

pgraf··on 4T transistors, one giant chip (Cerebras WSE-3) [video]
related discussion (2021): https://news.ycombinator.com/item?id=27459466
pgraf··on gh-116167: Allow disabling the GIL
If anyone wondered GIL = Global Interpreter Lock
Page 1 of 2Next →