HNHacker News
TopNewBestAskShowJobs

praseodym

2,533 karma · joined June 18, 2013

submissionscomments
praseodym··on Apple Copland D11E4 Booting in the Browser
According to her Wikipedia page she wanted to go for Solaris and was against acquiring NeXT: https://en.wikipedia.org/wiki/Ellen_Hancock#:~:text=was%20ag...
praseodym··on bzip3
zstd has a built-in benchmark mode to compare different compression levels, e.g. `zstd -b1 -e9 [FILE]` to test levels 1 to 9 (try up to 22 if you have enough spare time)
praseodym··on bzip3
Note that the dictionary options are only needed to improve compression ratios when compressing lots of small messages. If you have a bigger file (eg a tar file of Usenet messages) the regular Zstd compression will build a good dictionary without additional options.
praseodym··on Cloud in a Bottle: making self-hosting accessible to everyone
This also adds a lot of moving parts and failure modes. For self-hosting I’d rather have downtime on a simple system that’s easy to fix rather than a complex setup that stays up but needs more maintenance when some component fails.
praseodym··on Htmx 4.0
Is it just a coincidence that the image for this release is the same as for Omarchy Quattro? https://youtu.be/F7fe9pa8OeE
praseodym··on New Mac Studio with M5 Max and M5 Ultra
My home server is an ASUS NUC 14 Essential which idles at 5W with a bunch of services running. Its peak performance is probably less than the Mac Mini, but the hardware is cheap (at least it was before RAM/storage got expensive) and it’s a great platform to run Linux on.
praseodym··on Slack Code
They announced something one day after Slack Code: https://github.blog/changelog/2026-08-21-shared-agentic-work...
praseodym··on Malicious Rust crate Arrayref runs a build-time payload
cargo-deny can audit build scripts, but unfortunately not prevent execution of malicious build scripts exactly for the reason you gave. It could still help if you only ever use cargo add and update in a sandbox.

See https://embarkstudios.github.io/cargo-deny/checks/bans/cfg.h...

praseodym··on Malicious Rust crate Arrayref runs a build-time payload
You’re right about attackers being able to change runtime code.

pnpm does have some other features to prevent supply chain attacks, so there is still something to learn from other ecosystems. For example pnpm has a cooldown period for new dependencies and can prevent trust policy downgrades (eg new version published without build provenance where older versions did have it). See https://pnpm.io/supply-chain-security

praseodym··on Malicious Rust crate Arrayref runs a build-time payload
As mentioned by others it’s just as easy for an attacker to modify a crate’s runtime code.
praseodym··on Malicious Rust crate Arrayref runs a build-time payload
Post on the Rust blog: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on...

Discussion: https://news.ycombinator.com/item?id=49372853

praseodym··on Malicious Rust crate Arrayref runs a build-time payload
Unfortunately Cargo doesn’t have security controls in place to prevent these kinds of attacks. For example pnpm has controls to allowlist install scripts for dependencies and will warn about new install scripts (without executing them).

There is an open issue for this: https://github.com/rust-lang/cargo/issues/13681

praseodym··on The space bit of SpaceX is worth $8 a share, says Morgan Stanley
Don’t forget that SpaceX has 3.884 billion outstanding shares!
praseodym··on Hetzner Price Adjustment
Just wait for the hyperscalers to follow suit
praseodym··on Bricks and Minifigs Stole a Man's $200k Lego Collection
The screenshot of the Facebook post says they purchased the sets for approximately $20,000.
praseodym··on Migrating from Go to Rust
Note that many Rust libraries consist of multiple crates, which all end up in the dependency graph. This makes the number of dependencies seem higher than it actually is: the separate crates have the same maintainers and are often part of the same upstream git repo.

I agree with the general sentiment though. Rust also has a lot of crates that are stuck semi-unmaintained at some 0.x version, often with no better alternative.

praseodym··on How can Apple deal with the memory shortage?
> since Apple saved money on not participating in the AI data-center fiasco

They have unused custom built AI servers sitting in warehouses: https://news.ycombinator.com/item?id=47221264

praseodym··on We need a federation of forges
Forgejo also has a roadmap for federation but it looks like development is progressing rather slowly: https://codeberg.org/forgejo-contrib/federation/src/branch/m...
praseodym··on Case study: recovery of a corrupted 12 TB multi-device pool
ZFS on Linux has had many bugs over the years, notably with ZFS-native encryption and especially sending/receiving encrypted volumes. Another issue is that using swap on ZFS is still guaranteed to hang the kernel in low memory scenarios, because ZFS needs to allocate memory to write to swap.
praseodym··on Fedora 44 on the Raspberry Pi 5
I'm seeing 4-4.5 Watt idle. I've disabled WiFi in the BIOS (using wired Ethernet) and ran `powertop --auto-tune`, but not much else.
praseodym··on Fedora 44 on the Raspberry Pi 5
I’m using an ASUS NUC 14 Essential Kit N355. It’s a bit more expensive than the Pi 5, but also more powerful (8 cores and decent GPU). There is also a more affordable N150 model. And even lower budget are the N150 mini PCs from Chinese manufacturers, but they often mess up things like cooling in a hardware revision (compared to the favorable review that you’d read).

And forgot to mention this before: Intel CPUs with built-in GPUs have very performant and energy efficient hardware video codecs, whereas the Raspberry Pi 5 is limited and lacks software support.

praseodym··on Fedora 44 on the Raspberry Pi 5
This is exactly why I’ve to replaced my home server by a low-power x86 NUC instead. No custom build needed to run NixOS and idle power consumption turns out to be slightly lower than the Raspberry Pi 5.
praseodym··on Zed will require age identification for its services
They sent out an email to clarify that there will be no age verification and that the '18 or older' rule was introduced to avoid that:

> You must be at least 18 years old to use the Service (Zed’s AI-enabled software-as-a-service offering, including features like account creation/sign in, Zed Free and Zed Pro, and collaboration). See https://zed.dev/terms#21-eligibility. We set the threshold at 18 due to children's data privacy obligations under COPPA, equivalent international frameworks, and an increasing number of state and regional laws that extend protections to anyone under 18. Those regulations require parental consent verification, age-gated data handling, and separate retention policies for minors. Building and maintaining that infrastructure is a real cost for a small team, and getting it wrong carries regulatory risk. Setting the line at 18 lets us maintain a single privacy framework for all account holders without carve-outs.

praseodym··on Apple Studio Display and Studio Display XDR
The hardware is great, but the software is lacking. macOS only supports resolution-based scaling which makes anything but the default 200% pixel scaling mode look bad. For example, with a 27" 4K display many users will want to use 150% or 175% scaling to get enough real estate, but the image will look blurry because macOS renders at a higher resolution and then downscales to the 4K resolution of the screen.

Both Windows and Linux (Wayland) support scaling the UI itself, and with their support for sub-pixel anti-aliasing (that macOS also lacks) this makes text look a lot more crisp.

praseodym··on Sparse File LRU Cache
Microsoft MS-DOS and Windows supported this in the 90s with DriveSpace, and modern file systems like btrfs and zfs also support transparent compression.
praseodym··on Bugs Apple loves
Issues caused by restoring from backups were super common in the early iOS days. It makes me wonder how many weird bugs can be fixed these days by starting from scratch instead of migrating years of cruft through backup/restore.
praseodym··on I migrated to an almost all-EU stack and saved 500€ per year
They might not be dependent on ad revenue, but they are a greedy company that will not leave any money on the table. Next year, more ads are coming to the App Store that already generates a profit of over $10 billion/year: https://9to5mac.com/2025/12/17/apple-announces-more-ads-are-...
praseodym··on Android and iPhone users can now share files, starting with the Pixel 10
MacOS doesn’t have a gatekeeper status in the Digital Markets Act (DMA), so Apple doesn’t need to provide it. This shows that they only provide the SDK because of regulatory pressure, and try to maintain their vendor lock-in where possible.
praseodym··on AirPods libreated from Apple's ecosystem
Multipoint connectivity is part of the spec but apparently AirPods only support it if you pretend to be an Apple device.
praseodym··on Advent of Code 2025, there will be 12 days of puzzles
The FAQ mentions there will be only 12 days of puzzles and no global leaderboard: https://adventofcode.com/2025/about#faq_num_days

The AoC author also posted about this on Reddit: https://www.reddit.com/r/adventofcode/comments/1ocwh04/chang...

Page 1 of 14Next →