HNHacker News
TopNewBestAskShowJobs

ris

4,328 karma · joined July 18, 2013

submissionscomments
ris··on Why isn't mutable a subtype of immutable, or vice versa?
One of the problems with this comes if you're able to dynamically promote something that was passed to you as an "immutable" type to its actual implementation type, you can break this "contract".

I'm currently being annoyed by python's type hinting system, which has exactly this sort of hierarchy for containers, but there's nothing stopping a caller/callee from using type-narrowing to "discover" that the underlying type is actually e.g. a (mutable) list, and then modifying it without any complaints from the type checker. The only way to enforce this would be to actually convert to an immutable implementation type, involving unnecessary copying.

ris··on EVE Online moves to Python 3
https://pypi.org/project/greenlet/
ris··on Show HN: Make your logo extra bright on HDR screens
This is why we can't have nice things.
ris··on GrapheneOS protections against data extraction from locked devices
I hate this meme.

The point is to at least make them resort to hitting you with the $5 wrench, at which point they're probably committing a more serious offence than what you're up for (dependent on country).

ris··on Looking Forward to Postgres 19: It's About Time
Cool feature, but I'm a little uneasy with UPDATE operations adding new rows to a table. It upsets a lot of a DBA's assumptions.
ris··on Escaping the trap of US tech dependence
Tech dependence is nothing compared to the world's dependence on US financial infrastructure.
ris··on Ultra-Wide Band: A Transformational Technology for the Internet of Things
Infineon sales piece.
ris··on We replaced H.264 streaming with JPEG screenshots (and it worked better)
Corporate IT needs to die.
ris··on Vm.overcommit_memory=2 is the right setting for servers
This rules out some extremely useful sparse memory tricks you can pull with massive mmaps that only ever get partially accessed (in unpredictable patterns).
ris··on VPN location claims don't match real traffic exits
Zscaler enrages me with their use of the term "zero trust" in marketing, because due to their MitM-ing of TLS, they become a single-point-of-interception for all your organisation's traffic. "100%-trust" would better describe it for me, as you have to have 100% trust of Zscaler and anyone who has admin access to your organisation's Zscaler account.
ris··on Eurydice: a Rust to C compiler
Using nix to install Ansible, oof you're hurting me..
ris··on Search tool that only returns content created before ChatGPT's public release
For a while I've been saying it's a pity we hadn't been regularly trusted-timestamping everything before that point as a matter of course.
ris··on Modern cars are spying on you. Here's what you can do about it
The only company that appear to be taking a different tack on this are https://www.slate.auto

Anyone know of any others?

ris··on NFCGate flagged as malware even after multiple followups saying it isn't
Malware scanners are such trash.
ris··on Stopping bad guys from using my open source project (feedback wanted)
There are very few pieces of free software that don't lean very heavily on top of a mountain of other free software that make it possible, and I think the author would be surprised how much of that was written by people who strongly disagreed with his worldview and considered him a "bad guy".
ris··on Hardening the C++ Standard Library at scale
See also the "lite assertions" mode @ https://gcc.gnu.org/wiki/LibstdcxxDebugMode for glibc, however these are less well documented and it's less clear what performance impact these measures are expected to have.
ris··on Unofficial Microsoft Teams client for Linux
Native applications are a scourge, if only from a security standpoint.
ris··on Reverse-engineered CUPS driver for Phomemo receipt/label printers
Have been tempted to get one of these just for printing out tickets/QR codes so I can keep my dumbphone and not fight dried up ink cartridges etc.
ris··on ZOZO's Contact Solver for physics-based simulations
If they ever get liquidated I wonder who's going to end up with that massive dataset of photos of people looking like a tit.

Or perhaps they'll pivot..

ris··on D2: Diagram Scripting Language
I can't be the only one to find the TALA output to be the worst of all the engines. I almost always end up using ELK.
ris··on Britain to introduce compulsory digital ID for workers
> My government requires me, by law, to send it tens of thousands of dollars every year

That's only because you have those tens of thousands to give it. The same will not generally be true for people who have nothing.

ris··on Hardening Firefox – a checklist for improved browser privacy
The paradox being that every thing you customize about your browser config becomes another thing that can potentially be fingerprinted and makes you stand out as one of the 1% who has ever looked in about:config.
ris··on Hardening Firefox – a checklist for improved browser privacy
Disable WebGL. Not in a funny javascripty extension, in about:config.
ris··on Ransomware crews don't care about your endpoint security they killed it
> While it's still a good idea for companies to have an endpoint protection software on their employees' machines

Disagree

ris··on OpenTelemetry Is Great, but Who the Hell Is Going to Pay for It?
The logging examples given don't appear to be too different to what any structured & annotated logging mechanism would give you. On top of that it's normally encoded with grpc, so that's already one-up on basic json-encoded structured logs.

The main difference I see with otel is the ability to repeatedly aggregate/decimate/discard your data at whatever tier(s) you deem necessary using opentelemetry-collector. The amount of data you end up with is up to you.

ris··on Low-background Steel: content without AI contamination
> I'm not as allergic to AI content as some

I suspect it's less about phobia, more about avoiding training AI on its own output.

This is actually something I'd been discussing with colleagues recently. Pre-AI content is only ever going to become more precious because it's one thing we can never make more of.

Ideally we'd have been cryptographically timestamping all data available in ~2015, but we are where we are now.

ris··on Why We're Moving on from Nix
It's the idea that every application can near-arbitrarily choose a bespoke-but-exact mix of versions of every underlying package and assume they all work together. This is same attitude that leads to seemingly every application on planet earth needing to individually duplicate the work of reacting to every single dependabot update for their thousands of underlying packages and deal with the fallout of conflicts when they arise.

Packages in nixpkgs follow the "managed distribution" model, where almost all package combinations can be expected to work together, remain reasonably stable (on the stable branch) for 6 months receiving security backports, then you do all your major upgrades when you jump to the next stable branch when it is released.

ris··on Why We're Moving on from Nix
The main problem here is wanting to hang on to the "bespoke version soup" attitude that language package managers encourage (and is totally unsustainable). The alternative Mise doesn't appear to have any ability to understand version constraints between packages and certainly doesn't run tests for each installed package to ensure it works correctly with the surrounding versions. So you're not getting remotely the same thing.
ris··on DiffX – Next-Generation Extensible Diff Format
Binary data - definitely a problem.
ris··on Live facial recognition cameras may become 'commonplace' as police use soars
https://en.wikipedia.org/wiki/The_Ministry_of_Silly_Walks
Page 1 of 34Next →