HNHacker News
TopNewBestAskShowJobs

piaste

2,538 karma · joined June 8, 2016

submissionscomments
piaste··on PipePipe: NewPipe hard fork implementing SponsorBlock
Are you using a VPN? Youtube will be a jerk to those IPs. I need to set my exit node to either Poland or Albania to watch YT. (The latter incidentally is supposed to act as an ad-blocker due to local legislation banning some types of ads, but I have my own ad-blockers so I cannot confirm.)
piaste··on Claude is only available to people over 18 years
No. The simple relay thing only works if you can trust that they aren't comparing notes. But if I could trust them not to do so, I would already trust them when they say that they do not log your identity.

ZKPs allow you to be the relay between Chase and Pornhub, and you know exactly which data is shared between the two. Chase would obviously have no idea whether you used the certificate for Pornhub or anything else; and Pornhub will know that their request was validated by _a_ trusted ID provider, but not necessarily which particular one out of a group (issuer-hidden ZKPs).

piaste··on Anthropic's ‘watermark’ text adulteration in Claude is a perversion of writing
> Why not switch it around?

Because a malicious human will gladly copy/paste LLM text and sign it with his "I, a human, definitely wrote this academic paper" key?

piaste··on I wrote an bash enumerator because I was sick of xargs
I tried to switch to nushell full-time but couldn't stick with it.

Ironically, the main friction point were not old-fashioned tools (which `from ssv` usually handled nicely) but the 'new generation' of core CLI tools like eza or fzf. They have really nice visualizations, but they do not output structured data as a middle step, so all the colours and lines only play havoc with nu's parsing.

Since I need to "ls" a lot more often than I need to do data manipulation, the tools won and I went back to zsh. Still keep nu around for the occasional config/data file wrangling though.

piaste··on Removing the modem and GPS from my 2024 RAV4 hybrid
It doesn't stop Android Auto from doing whatever with the car data, but it's sandboxed to have no more default privileges than a regular app, so it can be denied access to your phone's data by default (apps, contacts, etc.). Wireless AA will only work if you grant it extra privileges; wired AA does not need them.

You can also "firewall" AA via something like TrackerControl, this would let you block connections to eg. Google Analytics servers without denying network access altogether (which would likely cause AA to stop working). I've only used AA with short-term rentals so I didn't spend too much time exploring these options.

piaste··on Googlebook
> Beyond that, this is a laptop that is running a really shitty, 'apps only, no you cannot do anything useful with this' operating system. I have an awful lot of complaints about MacOS's relatively restrictive use cases, but it's still at least a General Purpose OS. Android on laptop is very much not.

Android 16+ offers a built-in integrated Linux VM that can be enabled from Developer Mode, and if this[0] third-party site is accurate, "Android on laptop" will have it enabled by default.

So it should not be too different from working on a Windows laptop with WSL2, or on an OSTree distro where you use distroboxes to work with non-sandboxed programs.

(fwiw, I would still refuse to have one of these for personal use because Google is a shameless data robber. Unless someone were to de-google Aluminium like LineageOS and GrapheneOS did for Android, but that would probably take years.)

[0] https://aluminium-os.com/

piaste··on The locals don't know
> It’s such an annoying question because the honest answer is I eat what the locals eat, which is to say the most authentic Japanese cuisine is what you find in a Japanese supermarket. That’s what the people of Japan are actually eating.

Well, that's only true if you also observe what Japanese customers are buying and do your best to mimic their habits.

You could go into any Italian supermarket and fill your cart with weißwurst, avocados, and Camembert cheese - and they're all right there in the meat, fruit, and dairy areas respectively, not in an 'ethnic' corner - but it would be hardly a good representation of what the locals typically eat.

piaste··on Zed 1.0
> so something that 95% of the users of Zed will end up doing?

Will they? I downloaded it for a test run, and there was no pressure to create a Zed account. I got the impression that it's something you'd do if you wanted to use their cloud AI services, and I can't really see why you'd want a third party involved instead of just bringing your own subscription to your favourite model.

piaste··on Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
By "release infrastructure" I didn't mean gain admin access to github.com, I meant gaining the credentials to push out a release of that particular package.
piaste··on Used La Marzocco machines are coveted by cafe owners and collectors
That's correct. In practice we would often rephrase to avoid the double 'la', not because it's grammatically incorrect but because it is awkward to read (less so in speech). Compare:

French: C'est une citation de De Gaulle.

German: Das ist ein Zitat von Von Neumann.

Both correct, but one would probably add "Charles" or "John" between the two 'de' or 'von' just to break them up.

piaste··on Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
The cooldown is a defence against malicious actors compromising the release infrastructure.

Having the forge control it half-defeats the point; the attackers who gained permission to push a malicious release, might well have also gained permission to mark it as "urgent security hotfix, install immediately 0 cooldown".

piaste··on GrapheneOS: Duress Pin/Password
Even in that scenario, having the duress pin option does not make things worse. It's functionally equivalent to smashing the phone, just easier to do with one hand.

i.e. whatever they do to you if you wiped the phone via duress PIN, they would already do to you if you managed to smash the phone.

piaste··on Proton Mail Helped FBI Unmask Anonymous 'Stop Cop City' Protester
> Other Email providers such as Tuta which also offer encrypted emails, were forced to install a backdoor. As soon as the police arrive, every future email sent to the account in question is copied unencrypted without the person being informed.

Important caveat: Tuta was required by a court to provide police with access to a customer's _unencrypted_ emails (ie regular SMTP mail). The police had also asked for a backdoor to Tuta's E2E emails, and that request was rejected by the courts.

piaste··on Mondrian Entered the Public Domain. The Estate Disagrees
The enforcement isn't the issue, it's the scarcity.
piaste··on Welcome to Gas Town
Often it's to acquire the founders' knowledge and/or IP.

But Gastown is MIT licensed, and Yegge is bragging about never having looked at the code at all.

piaste··on 'Source available' is not open source, and that's okay
> I always wonder why people bother with providing source under a source available license. [..] There's little to no benefit to outside users. Any work they do on the code is effectively free work they do for you that entitles them to nothing.

Don't need to make PRs to benefit from the source being available. Running software whose source code has been under public eyeballs, and that I have compiled myself (or that a trusted third-party has compiled) is far more secure than running a binary blob that may or may not do what the developer's marketing page promises.

> If something like Bun (recently acquired by anthropic) becomes orphaned, we'd still have the git source code and a permissive license.

Closed-source apps have had source-code escrow clauses for a long time, exactly to avoid that problem. "If my company shuts down, you get all the source code and can do whatever you want with it."

Such clauses can, and should, be brought over to source-available licenses, where they would also be trivial since you don't even need a physical escrow.

piaste··on Hacking on the ReMarkable 2
> same crime as sellers of 'light' products which replace nutritious ingredients with water or air

The analogy, in this case, would be replacing NON-nutritious ingredients with water or air.

piaste··on Bazzite: Operating System for Linux gaming
There's nothing any UniversalBlue image tweaks that you couldn't tweak yourself. It's just adding/removing packages, adding/removing drivers, a few configuration scripts, and a bunch of tweaks to fix well-known gaming-related issues.

But the point is that, if you want to game on Linux, you probably want to perform exactly or almost exactly the same tweaks that Bazzite already does. So why bother doing them yourself?

It's not even a linux-from-scratch situation where you'd do it for the sake of learning. Googling "my controller doesn't work right", finding some discussion threads, and copy-pasting a bunch of fixes isn't particularly interesting.

piaste··on Bazzite: Operating System for Linux gaming
I want to bear witness that I did exactly that when I downmoted one of my computers from 'gaming machine' to 'closet server'.

One `rpm-ostree rebase` from Bazzite to a server-oriented flavour of Fedora Silverblue and it's been running and updating flawlessly since then.

piaste··on Learning to read Arthur Whitney's C to become smart (2024)
It was a theoretical question. It's not the first time I hear the complaint '$previous_dev left a bunch of unmaintainable macro tricks in a C codebase' and I thought, since those macros get expanded as part of the compilation process, surely it should be possible to intercept and capture the expanded version?

Even if a whitelist is not available (the SO question involves a particular C++ preprocessor and may not apply to others), a hacky approach might be to comment out all the #defines in the codebase, uncomment the ones you want to get rid of, and then run the full preprocessor task on it. Ugly but probably doable for a one-time refactoring.

piaste··on Learning to read Arthur Whitney's C to become smart (2024)
Layman question: say you have a C codebase with a bunch of preprocessor macros and you want to get rid of a particular one that's too clever, and assume no other macros depend on it.

Is it possible to command the preprocessor to take the source files as input and print them out with that one particular macro expanded and no other changes?

Intuitively, it sounds like it should be possible, and then you'd end up with a code base with a bunch of repetition but one fewer too-clever abstraction - and refactoring to deal with repetition (if necessary!) is a far more approachable and well-understood problem.

(Kind of like how some fancy compiles-to-javascript languages have a literal 'mytool --escape' command that will turn the entire code base into a plain, non-minified javascript in case you ever want to stop using them.)

piaste··on Show HN: Are You a Good Estimator?
One quick improvement would be to style the number boxes to include decimal separators. For a few answers I was squinting to check if I had typed six or seven zeroes, for example.
piaste··on Privacy Badger is a free browser extension made by EFF to stop spying
They work perfectly fine side-by-side, too.
piaste··on Austria hails 'brain gain' in luring 25 academics away from US after cuts
Austria has 9 million people. Scaled up in proportion to US population, that's the equivalent of ~940 academics. Still not huge, but a somewhat bigger drop.
piaste··on Is it possible to allow sideloading and keep users safe?
What if the bank abstained from evaluating your own stuff, and instead provided you with whatever they consider a 'good' device? Like a powered-up version of the TOTP hardware tokens they used to provide 15 years ago.

Instead of negotiating over what you do with your own devices, when you open a bank account they loan you a small, cheap, ultra-locked-down phone-like device that only runs the bank app and biometric verification. You may still use a web interface for online banking if you want a bigger screen and keyboard, but regardless all transactions need a confirmation through the bank's device.

This way you're free to do whatever you want with your hardware (including even not having one!), without requiring every bank to support every possible platform under the sun.

piaste··on 1948: Catholic Church publishes final edition of “Index Librorum Prohibitorum”
Umberto Eco once jokingly lamented the deprecation of the Index, writing that it was a "very handy canon of books one ought to read to call oneself an educated person".
piaste··on EU proposal to scan all private messages gains momentum
I'm sure you just linked the first google result you found, and it's not like the internet wasn't full of crappy 'quote' websites in the halcyon days of 2021, but it's incredibly depressing to click that link and get drowned in paragraphs of worthless AI blathering.

After a quick search - and ignoring Google's helpful clanker who tries to point you to the _wrong_ Orwell text - it's not hard to find a clean source:

https://www.telelib.com/authors/O/OrwellGeorge/prose/RoadToW...

piaste··on Graphene OS: a security-enhanced Android build
> Work profiles are inferior to separate user profiles, which are built-in to GrapheneOS.

Different use cases. User profiles are only active when you manually switch to them, while work profiles are active _alongside_ your main profile.

So for untrusted apps that you only use occasionally and on-demand (like the myriads of travel / shopping / random services apps), user profiles are great. For apps that you want to keep in the background, such as the proprietary messaging apps that all your friends use, a work profile is much nicer.

piaste··on Wait. HOW MANY supernova explode every year?
Use the cross-eye trick to superimpose the two pictures, then it becomes quickly noticeable as it will appear to blink.
piaste··on Podman Quadlets with Podman Desktop
A public facing web server, I doubt it. But for a private one it can make a lot of sense - you are probably only using N services at a time, where N is the number of users.

As for what can be so resource intensive that it's worth to wait for startup time instead of running everything at the same time - a bunch of specialized LLMs is the obvious example. Or maybe you're a hobbyist cramming a hundred services into a tiny computer.

Page 1 of 32Next →