HNHacker News
TopNewBestAskShowJobs

rettichschnidi

299 karma · joined July 5, 2022

submissionscomments
rettichschnidi··on CERN bids farewell to the LHC and enters Long Shutdown 3
> Photos don’t do it justice.

And it does not capture the awe when you notice the constant crackling sounds down there. For which, as the tour guide explained to us, nobody knows the root cause, despite bright minds investigating it.

Sadly, I could not find any sources online about this topic.

rettichschnidi··on Embedded Recipes 2026 Day One – Live
Embedded Recipes is a 2-day, single-track technical conference, focussing on embedded open source software.

https://embedded-recipes.org/2026/

rettichschnidi··on Why Switzerland has 25 Gbit internet and America doesn't
Swisscom has to do better, as regulated by the government. One can get 80/8 Mbit/s for CHF 65/month: https://www.swisscom.ch/en/residential/landline-subscription...
rettichschnidi··on Feature Request: Only allow for –ff merges for PRs
> I was having some success at getting their attention by working for a very large company who pays them a LOT of money, but then they laid off everybody who was working on this
rettichschnidi··on TL;DR of Deep Dive into LLMs Like ChatGPT by Andrej Karpathy
Sadly, the OSAID also does not require training data to be available. :(
rettichschnidi··on Kagi – Introducing Fair Pricing
Would love to see Kagi and Mozilla to collaborate.
rettichschnidi··on Firewood, Coal, Uranium – Bitcoin: The Next Step in Energy Transport
Aaaaaaand, its gone. "We can't seem to find the page you're looking for."

Archived: https://archive.ph/UEDWh

rettichschnidi··on Firewood, Coal, Uranium – Bitcoin: The Next Step in Energy Transport
This is wild...
rettichschnidi··on Snyk security researcher deploys malicious NPM packages targeting cursor.com
Sorry, but you screwed up royally. Scary to see that Snyk still does not see this.

Ethically, your work was even lower than that of those who test their AI tools on FOSS code, send in bogus reports and thus waste maintainer's time. Experimenting on unwitting humans and ecosystems is not okay.

rettichschnidi··on Snyk security researcher deploys malicious NPM packages targeting cursor.com
OT: Has anyone ever gotten (proper) SBOMs for Snyks own tools and services? Asking because they want to sell my employee their solution (which does SBOMs).
rettichschnidi··on Why systemd is a problem for embedded Linux
We (https://github.com/husqvarnagroup/smart-garden-gateway-publi...) are using systemd on devices with 128 MB of RAM and are happy with it. It solves so many problems one usually has to fiddle with, totally worth a few MBs of RAM.
rettichschnidi··on OSI Board AMA at All Things Open
Once again this kind of argument:

> "The reality is that if only a handful of companies and a handful of governments have the resources" to rebuild models, it is not a practical goal for open-source AI.

Any chance one could build a (working) system for training in a distributed way?

Because e.g. Folding@home was able to accumulate quite some computational power this way:

> Folding@home is one of the world's fastest computing systems. With heightened interest in the project as a result of the COVID-19 pandemic,[8] the system achieved a speed of approximately 1.22 exaflops by late March 2020 and reached 2.43 exaflops by April 12, 2020,[9] making it the world's first exaflop computing system. This level of performance from its large-scale computing network has allowed researchers to run computationally costly atomic-level simulations of protein folding thousands of times longer than formerly achieved.

Source: https://en.wikipedia.org/wiki/Folding@home

rettichschnidi··on Open Source AI Definition Erodes the Meaning of "Open Source"
Bradley is putting up quite a fight:

> Finally, rather than merely be a pundit on this matter, I am instead today putting myself forward to try to be part of the solution. I plan to run for the OSI Board of Directors at the next elections on a single-issue platform: I will work arduously for my entire term to see the OSAID repealed, and republished not as a definition, but merely recommendations, and to also issue a statement that OSI published the definition sooner than was appropriate. I'll write further about the matter as the next OSI Board election approaches. I also call on other software rights activists to run with me on a similar platform; the OSI has myriad seats that are elected by different constituents, so there is opportunity to run as a ticket on this issue.

♥

rettichschnidi··on The Open Source Definition 2.0 [work in progress]
I guess this is (much closer to) what Bruce Perens wants instead of the (current) OSAID draft:

> Nor is one necessary, because the original OSD works for AI. You need to treat the training data as source code, and you need to apply the rules to both pieces: the underlying software of the machine learning system, and the training data. This can get complicated because sometimes the training data expands in real time as the system gets more queries.

https://www.linkedin.com/feed/update/urn:li:activity:7254500...

rettichschnidi··on We shrunk our Javascript monorepo git size
Some examples, in no particular order.

Hampering the productivity:

- Review messages get sent out before review is actually finished. It should be sent out only once the reviewer has finished the work.

- Code reviews are implemented in a terrible way compared to GitHub or GitLab.

  - Re-requesting a review once you did implemented proposed changes? Takes a single click on GitHub, but can not be done in Azure DevOps. I need to e.g. send a Slack message to the reviewer or remove and re-add them as reviewer.

  - Knowing to what line of code a reviewer was giving feedback to? Not possible after the PR got updated, because the feedback of the reviewer sticks to the original line number, which might now contain something entirely different.
- Reviewing the commit messages in a PR takes way too many clicks. This causes people to not review the commit messages, letting bad commit messages pass and thus making it harder for future developers trying to figure out why something got implemented the way it did. Examples:

  - Too many clicks to review a commit message: PR -> Commits -> Commit -> Details

  - Comments on a specific commit does not shown in the commits PR
- Unreliable servers. E.g. "remote: TF401035: The object '<snip>' does not exist.\nfatal: the remote end hung up unexpectedly" happens too often on git fetch. Usually works on a 2nd try.

- Interprets IPv6 addresses in commit messages as emoji. E.g. fc00::6:100:0:0 becomes fc00::60:0.

- Can not cancel a stage before it actually has started (Wasting time, cycles)

- Terrible diffs (can not give a public example)

- Network issues. E.g. checkouts that should take a few seconds take 15+ minutes (can not give a public example)

- Step "checkout": Changes working folder for following steps (shitty docs, shitty behaviour)

- The documentation reads as if their creators get paid by the number of words, but not for actually being useful. Whereas GitHub for example has actually useful documentation.

- PR are always "Show everything", instead of "Active comments" (what I want). Resets itself on every reload.

- Tabs are hardcoded (?) to be displayed as 4 chars - but we want 8 (Zephyr)

- Re-running a pipeline run (manually) does not retain the resources selected in the last run

Security:

- DevOps does not support modern SSH keys, one has to use RSA keys (https://developercommunity.visualstudio.com/t/support-non-rs...). It took them multiple years to allow RSA keys which are not deprecated by OpenSSH due to security concerns (https://devblogs.microsoft.com/devops/ssh-rsa-deprecation/), yet no support for modern algos. This also rules out the usage of hardware tokens, e.g. YubiKeys.

Azure DevOps is dying. Thus, things will not get better:

- New, useful features get implemented by Microsoft for GitHub, but not for DevOps. E.g. https://devblogs.microsoft.com/devops/static-web-app-pr-work...

- "Nearly everyone who works on AzDevOps today became a GitHub employee last year or was hired directly by GitHub since then." (Reddit, https://www.reddit.com/r/azuredevops/comments/nvyuvp/comment...)

- Looking at Azure DevOps Released Features (https://learn.microsoft.com/en-us/azure/devops/release-notes...) it is quite obvious how much things have slowed down since e.g. 2019.

Lastly - their support is ridiculously bad.

rettichschnidi··on Codeberg Reconsidering OSI License Approval in Terms of Use
«ToxicCandy Model» is a great term!
rettichschnidi··on Codeberg Reconsidering OSI License Approval in Terms of Use
EU AI Act (https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:...) as of today (CTRL + F "open-source"):

> (89) Third parties making accessible to the public tools, services, processes, or AI components other than general-purpose AI models, should not be mandated to comply with requirements targeting the responsibilities along the AI value chain, in particular towards the provider that has used or integrated them, when those tools, services, processes, or AI components are made accessible under a free and open-source licence. ...

> Article 2, 12. This Regulation does not apply to AI systems released under free and open-source licences, unless they are placed on the market or put into service as high-risk AI systems or as an AI system that falls under Article 5 or 50.

Let's see if the EU AI Act will be adjusted in the same spirit as discussed in the linked discussion.

rettichschnidi··on We shrunk our Javascript monorepo git size
I'm surprised they are actually using Azure DevOps internally. Creating your own hell I guess.
rettichschnidi··on OSI readies controversial open-source AI definition
> If you don't want to give others permission to use and modify everything that was used to build the program, why are you wanting to trick me in thinking you are, and still calling it open source?

Because there is an excemption clause in the EU AI Act for free and open source AI.

rettichschnidi··on The OSI lacks competence to define Open Source AI
Your 2nd link does not lead to a page where I could find the sentence "We see the role of the designer as a facilitator rather than an expert."
rettichschnidi··on End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem
Founders with US affiliation/physicist creating crypto products [1], faulty claims how the relevant Swiss law (BÜPF) applies to them [2], doing crypto in JavaScript on the client side, etc. To me, this smells like Crypto AG [3][4].

[1] https://proton.me/about/team

[2] https://steigerlegal.ch/2019/07/27/protonmail-transparenzber...

[3] https://en.wikipedia.org/wiki/Crypto_AG

[4] https://en.wikipedia.org/wiki/Operation_Rubicon

rettichschnidi··on Woodworking as an escape from the absurdity of software
Any recommended readings on the "unable to estimate" claim?
rettichschnidi··on Passkeys – Under the Hood
Meanwhile, Microsoft sabotages FIDO2/Firefox on office.com: https://news.ycombinator.com/item?id=38502340
rettichschnidi··on Here Are the Secret Locations of ShotSpotter Gunfire Sensors
Paywalled. Can't read.
rettichschnidi··on End of SSH-RSA Support for Azure Repos
This means that even in 2024, there will be no support for ED25519, and no support for FIDO2.
rettichschnidi··on Contiki – OS for networked, memory-constrained systems
https://www.tado.com/ (at least was in the past)