HNHacker News
TopNewBestAskShowJobs

saclark11

225 karma · joined July 21, 2013

Software Engineer
submissionscomments
saclark11··on Revisiting Interface Segregation in Go
You can do this in Go by making a type declaration defining a function and then adding a method with the same signature on that type, which calls the function. The Go standard library does exactly this with the `HandlerFunc` type [1].

  // The HandlerFunc type is an adapter to allow the use of
  // ordinary functions as HTTP handlers. If f is a function
  // with the appropriate signature, HandlerFunc(f) is a
  // [Handler] that calls f.
  type HandlerFunc func(ResponseWriter, *Request)
  
  // ServeHTTP calls f(w, r).
  func (f HandlerFunc) ServeHTTP(w ResponseWriter, r *Request) {
      f(w, r)
  }
[1]: https://cs.opensource.google/go/go/+/refs/tags/go1.25.4:src/...
saclark11··on Steve Wozniak: Life to me was never about accomplishment, but about happiness
Sounds like you'll love "Spend Bill Gates' Money" [1]

[1]: https://neal.fun/spend

saclark11··on Fast cryptographically safe GUID generator for Go
Advertising any UUID/GUID generator as cryptographically secure, or relying on it to be so, is a mistake, in my opinion.

You use a UUID when you need a universally unique ID whose guessability properties are not a critical security requirement. While the V4 UUID spec (which this package does not implement, but most users might assume it does) states that a UUID implementation SHOULD be cryptographically secure [1], it also states that they MUST NOT be used as security capabilities [2]. This is b/c they are not intended as secure tokens, but many users mistakenly assume them to be suitable as such. Not to mention, V4 UUIDs only have 122 bits of entropy, not 128, since 6 bits are reserved for version and variant information, which many users don't realize.

So you can generate a UUID that is suitable as a secure token, but at that point don't call it a UUID. Just call it a secure token. And if you need a secure token, use something like Go's `Text()` function from `crypto/rand` [3].

The situation reminds me of how the Go team updated the `math/rand` and `math/rand/v2` packages to use a CSPRNG as a defensive measure [4], while still urging users to use `crypto/rand` in secure contexts.

[1]: https://www.rfc-editor.org/rfc/rfc9562.html#unguessability

[2]: https://www.rfc-editor.org/rfc/rfc9562.html#Security

[3]: https://pkg.go.dev/crypto/rand@go1.24.5#Text

[4]: https://go.dev/blog/chacha8rand

saclark11··on Fast cryptographically safe GUID generator for Go
> "UUID" was already taken by Google.

This shouldn't really matter as your import paths are obviously different. `github.com/google/uuid` and `github.com/sdrapkin/guid` can happily coexist. Any file/codebase importing both (which would ideally be avoided in the first place) can alias them.

> IMHO "Guid" is just as well known

I think the point the commenter was trying to make is that these do not adhere to the UUID spec. You don't specify which version, but judging by the docs and your comparison to `github.com/google/uuid`, I'd wager most folks looking at this library would assume they are supposed to be V4 UUIDs.

saclark11··on Show HN: Qrkey – Offline private key backup on paper
Something similar, but encrypted, is PaperAge [1]. Admittedly, I haven't used it, but it seems like a nice solution for secure physical backup of small secrets. The catch, of course, is now you need to make sure you never forget your passphrase or back that up off-site somewhere else.

[1]: https://github.com/matiaskorhonen/paper-age

saclark11··on Show HN: Go Plan9 Memo
> Overall, pretty weird stuff. I am not sure why the Go team went down this route. Maybe it simplifies the compiler by having this bespoke assembly format?

Rob Pike spoke on the design of Go's assembler at a talk in 2016 [1][2]. I think it basically came down to the observation that most assembly language is roughly the same, so why not build a common assembly language that "lets you talk to the machine at the lowest level and yet not have to learn a new syntax." It also enables them to automatically generate a working assembler given an instruction manual PDF for a new architecture as input.

[1]: https://www.youtube.com/watch?v=KINIAgRpkDA [2]: https://go.dev/talks/2016/asm.slide#1

saclark11··on Show HN: Go Plan9 Memo
Yes. Two of Go's creators, Rob Pike and Ken Thompson, were also authors of Plan 9 at Bell Labs.
saclark11··on Show HN: Ruroco – like port knocking, but better
I wonder if Moxie would now consider knockknock "cryptographically doomed"? From the README, whose commit [1] is dated 2011-09-15:

> The request is encrypted using AES in CTR mode, with an HMAC-SHA1 using the authenticate-then-encrypt paradigm.

A mere three months later, he would publish The Cryptographic Doom Principle [2] (dated 2011-12-13).

[1]: https://github.com/moxie0/knockknock/commit/e24eb33f666fc092...

[2]: https://moxie.org/2011/12/13/the-cryptographic-doom-principl...

saclark11··on JIT WireGuard
Pretty much, yes. If you imagine “Bob” has a policy that he can only converse with numbers in his address book, then you could think of it as:

  1. -> Alice calls Bob

    1.a. Bob does not pick up the call, but adds the number shown from caller ID to his address book

  2. <- Bob calls the number (Alice) back
  3. -> Alice picks up and they talk happily
saclark11··on Unix and Beyond: An Interview with Ken Thompson (1999)
My interpretation is he's lamenting that certain Unix OS abstractions (e.g. open, close, read, and write) do not lend themselves well to building distributed systems, like a distributed filesystem. Plan9, for example, designed it's API with such possibilities in mind.
saclark11··on Bug in reader/writer locks in Windows API
Agreed. I avoid reader-writer locks unless absolutely required and benchmarks prove it worthwhile.

Their usage often fails to outperform a regular lock due to additional overhead. They seem to make sense only in specific high-contention scenarios where arrival rate is high and/or the critical section has a long duration [1].

[1]: https://petsta.net/blog/2022-09-30-rwmutex/ - Go specific, but I suspect these results hold true for most implementations of reader-writer locks.

saclark11··on Go 1.22
> When io.Copy copies from a TCPConn to a UnixConn, it will now use Linux's splice(2) system call if possible, using the new method TCPConn.WriteTo.

Interface upgrades, yet again, transparently giving us more zero-copy IO. Love how much mileage they’re able to get out of this pattern in the io package.

saclark11··on 'When I tried to play, my hand spasmed and shook': why musicians get the yips
Jazz guitarist Julian Lage suffered from focal dystonia and talks a little about his recovery/retraining process in his interview with Rick Beato [1]

1. https://youtu.be/49KwbU0hT3w?t=3220&si=MSExP8OTYzohMr-P

saclark11··on OpenBSD 7.4
I'm curious to hear others' answers to this question as well. I've been looking into building my own OpenBSD based home router and so far thinking a Protectli Vault [1] would fit the bill.

1. https://protectli.com

saclark11··on Show HN: A new stdlib for Golang focusing on platform native support
Well, turns out I'm no longer able to reproduce the issue either. I just turned DDG Privacy Essentials back on for https://cs.opensource.google and I was able to view the site just fine.

Back when it was happening (maybe ~1 year ago?), I was using the latest versions of Firefox and DDG Privacy Essentials and it ocurred even if I went directly to https://cs.opensource.google. I had confirmed back then that when I turned DDG Privacy Essentials on I got "Permission denied", but with it off I was able to view the page.

I'm on the latest verisons of Firefox and DDG Privacy Essentials now. Seems it is no longer an issue in the latest version(s).

saclark11··on Show HN: A new stdlib for Golang focusing on platform native support
Do you have any privacy/ad-blocking extensions installed? I used to have the same issue and realized it was due to the DuckDuckGo Privacy Essentials extension. When I turn that extension's protections off for cs.opensource.google then it works.
saclark11··on I don't want to host services but I do
This post resonates with me and briefly acknowledges the thing that scares me the most about self hosting personal stuff for myself and loved ones: the bus factor. I haven't heard many self-hosting proponents talk about their strategy to mitigate the bus factor. I really want to self-host, but it seems like such a headache and a risk.
saclark11··on JetBrains Mono Typeface
I see a lot of folks in this thread lamenting the usage of ligatures, but note that the downloaded set of font files includes a "JetBrainsMonoNL" version of all variants, which does not include ligatures ("NL", as in, "No Ligatures").

I do not like ligatures either, yet this is my favorite monospaced font. I use JetBrainsMonoNL in all the places.

saclark11··on Ask HN: Anyone Interviewed at Fly.io?
I applied to Fly.io and a big part of that was because of their hiring process. Reading about the way they think about finding good candidates resonated with me. The role for which I applied was something I am deeply interested in, and would love to get into, might _possibly_ have the chops, but for which I probably do not yet have "the" resume. It felt like a Hail Mary to apply but I figured if nothing else I'd learn alot in the process and if I'm really lucky, might even get some constructive feedback.

I didn't clear the work sample but man, I had fun doing it. I learned a ton. I most appreciated that they gave me legitimate feedback as to why they decided not to move ahead with me. It highlighted a gap in my current knowledge/experience that I was glad to discover.

That being said, it did take a very long time to get a final answer back from them, but overall I'm a happpy reject. Could even see myself applying again some day.

saclark11··on Visual Studio Code 1.0
There is an extension for vim mode: https://marketplace.visualstudio.com/items?itemName=vscodevi...
saclark11··on The Enduring Mystery of 'Jawn', Philadelphia's All-Purpose Noun
I am from, and live, just outside Philly and I had no idea "jawn" was strictly a Philly thing (err...jawn) haha. Cool to find out it has such a unique etymology!
saclark11··on The Sounds of Sorting Algorithms
This is awesome. What I also found really cool is that this inadvertently lets you "hear the sound" of chrome/firefox throttling the `setTimeout` calls when the tab is inactive [1]. Run one of the sorting algorithms in chrome or firefox and then switch to a new tab. You'll notice it slows down. Switch back and forth between the tabs and it's almost like you are conducting of the algorithm :)

[1] http://blog.pivotal.io/labs/labs/chrome-and-firefox-throttle...

saclark11··on I was an undercover Uber driver
Came here to the comments to ask the same question about the page refresh. At one point the page even completely blanked out and served me an error message directly from the server. It wasn't anything particularly sensitive, but an information leak none-the-less.
saclark11··on How Secret Used Automated Testing for Their Android Launch
I appreciate TestMunk's goal to make automated mobile testing easier and more accessible, and I truly hope they succeed in that, but for the love of testing, please do not view that example feature file at the bottom as an example of proper Gherkin.

It is riddled with implementation details and brittle explicit waits. To be fair, they did clearly state: "we generally recommend against fixed waits" but then please do not put this forth as an example to be copied. Scenarios should describe the behavior from a user perspective and leave out implementation details. You should not have to change the your Gherkin no matter how much the underlying implementation changes so long as the expected behavior remains the same. Not to mention the misuse of the Given/When/Then keywords and the "I logout" steps -- that is what before/after hooks are for.

I also recognize TestMunk points out that this feature utilizes standard steps to get your first test cases going and to get some screenshots. They also advocate for the page object pattern, which is good, but it might be helpful to be clear that this is not how you'd actually want to write your Gherkin, whose true value comes when written with/for product owners, free of implementation details.

saclark11··on What It's Like To Drop 150,000 Feet Straight Down [video]
Simply amazing.
saclark11··on What other Websites do HN users browse besides HN?
Echo JS, Ars Technica, .Net Magazine, and a slew of blogs.

And oh yeah, Twitter.