HNHacker News
TopNewBestAskShowJobs

quectophoton

1,351 karma · joined February 8, 2023

World's Smallest Photon.
submissionscomments
quectophoton··on Don't couple your Go code to GitHub
> you can use the 'replace' statement in your go mod to change where the Go build system will try to pull the dependencies from

Heads up for anyone who doesn't know: this only works at the "top level". Any replace directives in your dependencies will be ignored[1].

So for example if you have a dependency tree like [main -> thirdpartyframework -> golang.org/x/net/http2], and thirdpartyframework uses a vulnerable version of `golang.org/x/net/http2`, you can't just fix it by patching the thirdpartyframework repository with a replace directive; no, because that would be too convenient. Instead, the replace directive needs to be at the main module, where it doesn't make sense and is inconvenient.

Even though I like Go, it really seems like they don't care about anything other than monorepos. As soon as you need to work with forks, mirrors, or even just private modules[2][3], the tooling actively works against you. Also using your custom module proxy is a pain.

[1] See: https://go.dev/ref/mod#go-mod-file-replace:~:text=replace%20...

[2]: If you've only used private modules hosted on GitHub you might not have noticed too much pain because the Go tooling has hardcoded behavior specifically for GitHub and a few mainstream forges. You don't find out about this until you try to self-host something like Forgejo on your own domain thinking it would Just Work(tm), but it doesn't, and now you're left wondering why tf it works with GitHub but not with your own forge instance.

[3]: I think there's no hardcoded code for SourceHut, so you might be able to experience the inconvenience by hosting private modules in there.

quectophoton··on Stop making swap partitions—use swap files instead
I mentioned this in a response[1] to a sibling comment, but my question is more about learning what are the advantages of swap itself, other than just cheaper slow RAM.

What does the OS do differently with swap vs RAM? What can I do with swap that I cannot do with RAM? Things like that.

[1]: https://news.ycombinator.com/item?id=49670574

quectophoton··on Stop making swap partitions—use swap files instead
In my examples nothing is taking away from nothing, I'm just asking if, if two situations have the same total amount of GB, what's the actual difference between RAM+swap vs entirely RAM.

Use the 32+32 numbers if you're more comfortable with those round numbers.

If I have a system running comfortably with 32GB RAM + 32GB swap (no OOM, no swap thrashing), and I upgrade to 64GB RAM + 0 swap, what actual negative effects would I be getting for the lack of swap?

That's my question, to know if swap has any benefits other than being additional slow RAM.

quectophoton··on Stop making swap partitions—use swap files instead
Something I've never understood is why, say, 60GB RAM + 4GB swap is supposed to be faster than 64GB RAM + no swap. Or why 64GB RAM + 4GB swap is supposed to be faster than 68GB RAM.

I get the hibernation argument, but not the arguments implying swap is always better.

Actively using 60GB RAM and moving 4GB of unused pages to swap (60+4), is somehow faster than actively using 60GB RAM and keeping unused pages in the remaining 4GB RAM (64+0)?

EDIT: If you prefer more round numbers, feel free to replace them with "32GB RAM + 32GB swap" and "64GB RAM + no swap" respectively.

quectophoton··on Shopify acquires Tailwind
Reading charitably, when writing that part of the comment they probably were thinking of links that look like buttons, for example the "Get started" link in Tailwind's home page.

Regardless of how that specific one looks like, I wouldn't like if it were replaced by a <button>.

quectophoton··on A faster way to calculate the day of the week
I don't know what's wrong with me, but I can't do mental calculations with dates because I always think I'm off-by-one, no matter what.

I prefer to "move vertically" in the month. Knowing that 1=8=15=22=29, using prlin's example for December 25 (sibling comment), I'd go like:

"12 is Saturday, 15 is Tuesday, 22 is also Tuesday, so 25 is Friday."

So, starting from key date (12), moving to "the 1 column" (15), moving up or down to the closest/easiest date (22), and then finishing from there.

Slower for sure, but easier for me to not lose track. And now having a known day in every month thanks to rmunn's mnemonic, is going to be a huge help.

quectophoton··on Don't paste the AI, please
> Points to the future where my bots talk to your bots.

Relevant comic from 2014: https://www.smbc-comics.com/index.php?id=3576

quectophoton··on Only 2.6% of the most visited websites have fully valid HTML
React.js with JSX (which people use to avoid writing HTML) is basically the opposite on its tolerance for mistakes but somehow it seems pretty popular, to say the least.
quectophoton··on I hate packaging my software for Linux
Parent post already told you a way to distribute your software to Linux users; assuming your tarballs with prebuilt binaries "just work", as in, it's enough to untar it wherever (/opt?) and create a symlink in $PATH for your executable.

But from your comments, the message I get is that you want to apply to become a maintainer in each and every Linux distribution's package repositories, both mainstream and niche? And apparently also create packages for some alternative package managers too? (e.g. mise, npm, Terra)

quectophoton··on A year of fighting scrapers on my 1.5 million-page website
Tangential but still related to that story, but the battle for the meaning of "REST" is already lost.

Saying an API follows REST but doesn't implement HATEOAS (part of its definition), is like saying a database follows ACID but doesn't implement Atomicity. Or like saying a software is Open Source but doesn't allow use for commercial purposes.

Yet somehow for one of those 3 cases it became accepted to misuse the term that way ("[original meaning] but without this one constraint"), but if someone misuses the term for the other two cases then everyone suddenly cares and insist that people should use a different term to describe their thing.

quectophoton··on Proving a human wrote something
Online typing speed tests are in a really good position to collect and sell this data, if they aren't already doing it.
quectophoton··on AI, Vim, and the Illusion of Flow
> Similar to how us vim users keep updating/rewriting our config.

What (or why) are those frequent config changes?

I use neovim and I can say I've migrated[1] to vim packages (from Pathogen) years ago, and I also git-clone a repo once every few years if I want LSP support for a language I haven't used before.

But I wouldn't call this "keep updating/rewriting".

[1]: By removing a line from my config, and then running `mv` once.

quectophoton··on I joined the IndieWeb, here's what I learned
As far as I understand, everything ends up centralized to USA anyway (ICANN), who then tells everyone what TLDs are allowed or not.
quectophoton··on The KIDS Act would require age checks to get online
> The equivalent would be if I got carded every time I stepped out of my house just in case I might decide to buy alcohol later.

More like requiring ID verification in fridges just to be able to open them, because they might contain alcohol (probably followed by RFID stuff or something).

quectophoton··on HackerRank open sourced its ATS. My resume scored 90/100. Oh wait 74. No – 88
> For one role we got ~70 applications and all CVs looked obviously AI-written.

Were those ~70 applications all of them, or were those ~70 applications the result of an AI filtering from a larger amount?

If the latter, are you sure your AI is not filtering out the hand-written CVs and giving you the ones that have been AI-assisted or AI-written (with or without "the usual AI signs")?

quectophoton··on Bun Rust rewrite: "codebase fails basic miri checks, allows for UB in safe rust"
Don't forget:

* No relative imports.

* The `require` directives from the `go.mod` files of your dependencies are always ignored.

Those two combined, mean that there's no easy way to fork a dependency. It's doable, but some of the maintenance overhead could have been avoided.

We don't even get a `go mod tidy` flag that lets us say, "yes, I understand the risks, just copy any `replace` directives that you find in my dependencies". With a flag like that, even if the `replace` directive is still copied everywhere, at least it's automatically copied during a routine `go mod tidy` invocation.

They already have `// indirect` comments, so those could have a `// indirect, replaced by X` comment or something like that.

quectophoton··on A Caddy Cert Expired Because Systemd-Resolved Was Selectively Broken
> My recommendation for DNS - on servers - would be to install unbound locally and use that.

At least on Ubuntu 26.04, you can't easily bind Unbound on a WireGuard interface because of services dependency order, so the Unbound service errors during system boot because the WireGuard interface doesn't exist yet. And IIRC neither `ip-transparent` nor `interface-automatic` fixed it.

On Alpine Linux all this just works.

quectophoton··on Nintendo announces price increases for Nintendo Switch 2
And when you don't need the Steam Deck for gaming anymore, it is still useful as a home server.
quectophoton··on Gambling ads on social media reach more than twice as many men as women: study
I don't know, if I didn't know Mullvad or GrapheneOS, and saw ad on TV, I'd probably check it out.

Or an ad about an ISP with IPv6 support, at the very least it would make me check if my current ISP finally added support, and consider options otherwise.

Or one about some new colocation service that happens to open near my location, you bet I'd check out their website and maybe even pay them a visit.

(I don't watch TV, but my point stands.)

quectophoton··on Gambling ads on social media reach more than twice as many men as women: study
> I am sure ads can work on me, and the HN crowd, if I was targeted.

EU-based cloud, 100% sovereignty, AGPL code, colocation services included. Prepaid balance and SEPA direct debit supported.

[Read more]

quectophoton··on Maybe you shouldn't install new software for a bit
If `docker` is already there, why even bother with `sudo` when you can just:

    docker run --rm -it -v '/:/mnt' -u 'root' 'alpine' '/bin/sh' '-l'
Chances are that the person who set up Docker didn't do it properly.
quectophoton··on Three Inverse Laws of AI
If it helps, I didn't find anything wrong with your comment.

I appreciate the link and the info :)

quectophoton··on Three Inverse Laws of AI
> Humans must not anthropomorphise AI systems.

Can someone explain why this is a bad thing, while at the same time it's a good thing to say stuff like "put a computer to sleep", "hibernate", "killing" processes, processes having "child" processes, "reaping", "what does the error say?", "touch", etc?

To me that's just language, and humans just using casual language.

quectophoton··on VS Code inserting 'Co-Authored-by Copilot' into commits regardless of usage
A text input field for entering your command line(s), with a text log for the output, does indeed seem to be the crabs of software. Usually with some abstractions that allow you to write longer scripts[1] and just refer to them by a short name or alias, and compose those scripts together from your command prompt.

You could say it's the terminal[2] user interface.

[1]: https://www.merriam-webster.com/dictionary/script

[2]: https://www.merriam-webster.com/dictionary/terminal

quectophoton··on Functional programmers need to take a look at Zig
> 1. Go, when I first saw code I wrote almost a decade ago still compiles and runs in Go, I decided to use Go for everything. There were some initial troubles when I started using it a decade ago, but now it's painless.

And fewer dependencies, and fewer vulnerabilities (if any at all, depending on your few dependencies).

Go is "only" a pain when you want to use your own copy of packages (because `replace` directives are always ignored everywhere except on the "root" package), and whenever you want to work with private Git repositories outside of the forges that have hardcoded config in the Go code (like GitHub) (because Go assumes there's an HTTPS server, and the only way to force it to use only SSH is with ugly workarounds AFAIK).

But despite this I still prefer it for personal projects because I can come back after not touching it for years, and the most I need to do is maybe update `golang.org/x/net` or something like that.

quectophoton··on Carrot Disclosure: Forgejo
> I'm also not impressed with a carrot disclosure that looks like this. Running a python script to compromise a locally hosted instance? Bruh, you have physical hardware and host shell access. That python script could be doing anything including running as root.

> Show us the exploit hitting a remote server.

Watch out, their script works on HN too, as a proof here's me logging in to YOUR computer's root account (a bit more redacted for obvious reasons):

    $ python3 ./poc/chain_alpha.py --target dangus > out.txt
    $ grep Backdoor out.txt |  sed -r 's@[^:]+$@ [REDACTED]@g'
    [+]   Backdoor admin created: [REDACTED]
    $ grep IP out.txt |  sed -r 's@[^:]+$@ [REDACTED]@g'
    [+]   IPv4 address for dangus: [REDACTED]
    $ grep 'debug2: shell' out.txt
    [+]   debug2: shell request accepted on channel 0
    $ tail -n12 out.txt 
    ================================================================
    [+] COMMAND EXECUTION CONFIRMED!
    ================================================================
    
    Server-side output (received via SSH, with `set -x`):

      + id -u
      0
      + id -g
      0
    
    ================================================================
    $ sha256 ./poc/chain_alpha.py
    c10d28a5ff74646683953874b035ca6ba56742db2f95198b54e561523e1880d7  ./poc/chain_alpha.py
quectophoton··on The 49MB web page
Out of curiosity, do you have (and want to share) stats about requests per second? It's always nice to know these things for future reference.

No worries if not :)

quectophoton··on Allow me to get to know you, mistakes and all
I think there was an SMBC comic about this topic, but I don't think I can find it, and the site doesn't exactly make it easy. I don't even remember if it was pre-2020 or not.

It was about how people would get a thing (a robot?) that would repeat whatever they said but in a more fancy way (or something along those lines), to make them sound smarter. Then the people would start depending on these robots to communicate at all, to the point their speech degrades and they start making unintelligible noises that the robots still translate into actual speech.

EDIT: Found it, from 2014: https://smbc-comics.com/index.php?id=3576

quectophoton··on Ageless Linux – Software for humans of indeterminate age
Years later: "The current measures are a step in the right direction, but we have found them insufficient. We are now requiring the use of this specific proprietary binary blob for any action related to the verification process. It will conveniently run as a daemon so its exposed API will be accessible to any application that needs to query it, and it will automatically update itself so you don't have to worry about it, just set it up once and forget about it."

It might also include some additional text like "we have decided to collaborate with systemd to integrate this proprietary binary blob, to maximize the reach and eliminating any pains in the setup process caused by the vibrant ecosystem of package managers, while at the same time avoiding disrupting the development process of the Linux kernel".

quectophoton··on Emacs and Vim in the Age of AI
If I had to use AI with neovim I'd probably use https://github.com/ThePrimeagen/99 or one with a similar workflow.
Page 1 of 19Next →