HNHacker News
TopNewBestAskShowJobs

sakisv

973 karma · joined September 16, 2015

https://www.sakisv.net
submissionscomments
sakisv··on GrapheneOS' rewritten Messages app is released
That's true as well, especially if you're still developing and changing things - because you tend to realise problems only after you've pushed the new screenshot :P
sakisv··on GrapheneOS' rewritten Messages app is released
I think the reason is that you can get quite much of a tunnel vision while developing. Everyone involved already knows what they're building and how it looks, so it's very easy to overlook it.

Case in point, I recently wrote a CLI to show which of your AWS infra is not captured in terraform, and you can either print the result as a json to consume by a machine or generate a dashboard with some charts. It took me an embarrassing while to realise that I should have included a damned screenshot in the README, in fact I think I only realised when I wanted to show it to my brother.

sakisv··on Instagram's head says engagement falls by half without the algorithm
cue the smallest sad violin

Snarky reaction aside, and actually reading the article, it says that the problem is something along the lines of "we incentivized and rewarded business accounts to post large volumes, so now if you switch to chronological order you will see more of these posts which reduces user satisfaction".

Well, that just means that the company will have to adapt before their users start unfollowing spammy accounts and the whole "influencer" business takes a hit. Though tbh, not sure how much of a hit it could take but hey, when instagram says engagement falls, I allow myself to feel optimistic for a brief moment.

sakisv··on Brits would quite like their private messages to stay private
While this may be a bit of a tongue-in-cheek comment, I've started to think that this is exactly how it should be:

People that are elected by the public and hold the power to define every aspect of our lives, should be held to the absolute highest level of scrutiny possible. Every aspect and every single moment of their lives should be transparent and recorded while they hold office, no exceptions whatsoever.

I will concede that having it broadcasted may be a tad hard to do, but there should be a record of what happened during their time - in fact there should be a way to answer the question "what was minister X doing at 2026-08-29 20:13:14 UTC?"

And for the argument that says "oh then nobody would want to do it", I think that's in favour of this approach. Look around at what we're dealing with, and which people want to win elections and the fervour with which they go about it.

We should be trying to make this kind of "job" as unappealing as possible. It should be a chore, not something to go after.

sakisv··on CosmosEscape: Taking over Every Database in Azure Cosmos DB
oh ffs, I forgot about this. I was thinking of the other one though from 2021 mentioned in a sibling comment, and it was indeed, again, with cosmos
sakisv··on CosmosEscape: Taking over Every Database in Azure Cosmos DB
Is it me or was there a similar vulnerability reported a few years ago? Something about the attacker getting access to all platform's users' databases, though not sure if it was cosmos or something similar.
sakisv··on Claude Code is steganographically marking requests
Depends on the software.

In this case, the companies that make and provide AI models that are increasingly used to interact with me on critical things (banks, public sector services) then yes.

Abso-fucking-lutely they should be regulated like crazy.

In fact I'm really surprised by the amount of people that are not worried by how many parts of their lives are being handed over to be managed by a probabilistic system that is controlled by a private company with next to zero oversight.

There must be a greater liability than "oops, you're right to push back"

sakisv··on Chrome is looking to permanently drop MV2 extension
Mac
sakisv··on Chrome is looking to permanently drop MV2 extension
This is not true. I'm a Firefox user and it works perfectly fine in Firefox.
sakisv··on The operating cost of adult and gambling startups
I wanted to draw the distinction between something that destroys lives over a longer period of time (smoking) VS something like gambling where you could lose your life's savings in seconds.

The alcohol mentioned in a sibling comment also ticks the box.

For the sugar, I'd say yes, no, no, yes and "not too much, but I'm keeping an eye out".

sakisv··on The operating cost of adult and gambling startups
Not the original person you replied to, but as far as I'm concerned there are a few questions that could very easily indicate which side of the line is something.

E.g.

- Is it addictive?

- Does it have the potential to destroy lives?

- Does it have the potential to destroy lives in seconds?

- Does it have a strong lobbying mechanism behind it? (n.b. things that are good and nice rarely need someone to bribe people to accept them)

or simply:

- Would you be worried if your child did it?

I think the number of "yes" that you get draws a very clear line.

sakisv··on Some secret management belongs in your HTTP proxy
This feels like a good idea in principle, but I can't shake the feeling that it just moves the goalposts one step away:

Now your app doesn't have direct access to your stripe/github/aws/whatever keys (which is good!) but you still need to have _some_ authentication against your proxy.

If you have a per-app authentication, then if your app's key leaks, then whoever uses it will be able to reach all the external services your app can, i.e. with one key you lose everything. On the other hand, if you have per-endpoint authentication, then you didn't really solve anything, you still have to manage X secrets.

Even worse, from the perspective of the team who owns and runs the proxy, chances are you are going to use per-app AND per-endpoint authentication, because this will allow you to revoke bad keys without breaking everyone else, etc.

What this really solves is subscription management for (big?) organisations. Now that you have a proxy, you only need a single key to talk to <external-service>, no need to have to manage subscriptions, user onboarding and offboarding, etc. You just need to negotiate ratelimits.

sakisv··on Migrating to the EU
While I agree in principle, I have to remind you (and to myself) that Australia is part of the Five Eyes: https://en.wikipedia.org/wiki/Five_Eyes
sakisv··on Can you slim macOS down?
For me it's quite simple: It works and it stays out of my way.

I've owned a macbook since 2010, with a short break during the touchbar era when I got myself an XPS with windows which I dual-booted with ubuntu and later a system76 that comes with their own flavour of Ubuntu, called Pop! Os.

The situation in windows (windows 10 at the time) was abysmal. Completely incoherent UI, settings spread across different menus, ads in start menu, slow and broken search, constant nagging to update windows, to update the drivers, to tell me that the drivers have been updated, to install or update my antivirus, etc. These were not things that I installed myself, these were included with Dell's setup of the machine.

On the system76 laptop things were different. Things were calm, I could configure everything as I wanted and things worked. Until at some point I installed a new version of something, which had nothing to do with sound, but it broke sound, just as I was preparing to join a meeting, and just as we were going into the second phase of lockdowns in late 2020 so online meetings were here to stay.

My macbooks are reliable. I've got the M1 as soon as it came out and I never got a single issue with it. I've upgraded twice (I think) across major versions and everything worked. I don't have to worry about it leaving me hanging when I need it.

(And that's not taking into account things like build quality, touchpad quality, battery life, silence, etc)

In the end of the day, I do a lot of debugging as part of my work. When I don't work, I want to choose what I will be debugging, not have it forced on me.

And don't get me wrong: I see where Apple is going, I know that they're a greedy company that want to maintain their iron grip and have the final say on what we can and cannot do on our machines.

However, for me for the time being it's the least bad option.

sakisv··on Rust--: Rust without the borrow checker
Ah, that's a fair point. In that case then yes, I have been bothered by the borrow checker very much indeed lol.
sakisv··on Rust--: Rust without the borrow checker
As someone who's only did a couple of small toy-projects in rust I was never annoyed by the borrow checker. I find it nothing but a small mental shift and I kinda like it.

What I _do_ find annoying though and I cannot wrap my head around are lifetimes. Every time I think I understand it, I end up getting it wrong.

sakisv··on Pricing Changes for GitHub Actions
Given that a lot of places that deal with money use them, I find your comment quite interesting and would like to learn more :)
sakisv··on GitLab discovers widespread NPM supply chain attack
The way I solve the plain text problem is through a combination of direnv[1] and pass[2].

For a given project, I have a `./creds` directory which is managed with pass and it contains all the access tokens and api keys that are relevant for that project, one per file, for example, `./creds/cloudflare/api_token`. Pass encrypts all these files via gpg, for which I use a key stored on a Yubikey.

Next to the `./creds` directory, I have an `.envrc` which includes some lines that read the encrypted files and store their values in environment variables, like so: `export CLOUDFLARE_API_TOKEN=$(pass creds/cloudflare/api_token)`.

Every time that I `cd` into that project's directory, direnv reads and executes that file (just once) and all these are stored as environment variables, but only for that terminal/session.

This solves the problem of plain-text files, but of course the values remain in ENV and something malicious could look for some well known variable names to extract from there. Personally I try to install things in a new termux tab every time which is less than ideal.

I'd like to see if and how other people solve this problem

[1]: https://direnv.net/ [2]: https://www.passwordstore.org/

sakisv··on Cloudflare Global Network experiencing issues
I would be tempted to put it on my CV :D
sakisv··on Cloudflare Global Network experiencing issues
Well, you can never be sure that he didn't:

https://www.fastly.com/blog/summary-of-june-8-outage

sakisv··on Apple alerts exploit developer that his iPhone was targeted with gov spyware
I think I agree with what I think you're trying to say.

However I don't agree with the repercussions of this, which are the same ones that make all reasonable people, security experts included, oppose EU's ChatControl or the UK's backdoor requests: There is no way to ensure and protect the people that need protection, as there is no way to ensure that only "the good guys" have it.

We tend to bullshit ourselves into believing that because spyware software like Predator are weapons, meaning that only countries would be allowed to buy them and use them (same way that Jeff Bezos cannot buy and use an F-35 for example). We see though, that certain individuals _can_ get their hands on these things and use them however they want.

For example, 3 years ago someone adjacent to the greek government bought and used Predator against MEPs, journalists, army generals, mafia bosses, MPs of opposing parties and even MPs of their own, ruling, party. The greek government of course denied that they did it, and they said that this individual did not act under the instructions of the government (though they then changed the law to prevent anyone for learning details about it, but that's a different story).

So, apart from adopting the same approach as with ChatControl and encryption backdoors, i.e. banning them, I don't know how we could protect ourselves against them.

sakisv··on ChatGPT Pulse
So, this is Google Now but instead of one company having access to the data on their systems, now you're giving access to your data from different companies/sources to OpenAI.

(I do miss Google Now, it really did feel like the future)

sakisv··on Major rule about cooking meat turns out to be wrong
The "major rule" in question is whether you should rest the meat after cooking or not.
sakisv··on Ask HN: What software subscriptions are worth paying for?
Essentials: my own domain for emails, Fastmail, Bitwarden, Google for 100GB of storage.

Less essential: Obsidian, Kagi (this one may be bumped to the "essentials" at some point), a few VPS on Hetzner to run some projects, domain names for said projects.

Just because I like them and want to support them: Signal

sakisv··on Ask HN: What are you working on? (March 2025)
I want to SaaS-ify my scraping process. It's gotten to a point that it works nice and reliably for me, now I need to wrap it in a good DX package and call it version 0.1.

(The main drive behind this was not to sell it, but to have a UI for when a website changes its layout and I'm on holidays and don't have access to my terminal and/or my yubikeys)

sakisv··on Zen browser had a backdoor enabled by default
Starting a bit of a tangent here I admit, but this makes me much more worried about the future of mobile browsing.

Sure, soon enough a decent non-chromium based desktop browser will come along, be it Zen or something else, but what about the mobile world?

Right now firefox is perfect for me: It makes the web browsable by allowing ublock origin, it syncs my tabs, history and bookmarks, it's great.

Moving to a scenario that we have a different browser on the desktop and a different one on the phone or, worse, the same on the phone but without adblocking sounds like a huge regression.

P.S. Regarding Zen: If you want to be taken seriously, or at least as something more than a toy project, teaching your maintainers how to talk to your (potential) users will go a long way. Telling them off will not gain you any friends. (I'm referring to the github discussion mentioned in a sibling comment: https://github.com/zen-browser/desktop/discussions/5907)

sakisv··on What, if anything, should I do about using Mozilla's Firefox
That sucks. I'm kind in the same boat, but with one additional requirement: It should have an android app that I can install uBlock origin. The few times that I had to browse from a phone without an adblock I had to stand in awe as to what a lot/most people have to suffer through daily.

(The other more minor requirement for me is bookmark tags, but I may be able to hijack my way around that)

sakisv··on Show HN: I made a site to tell the time in corporate
I have no reason to doubt your explanation and intention, however I think it would have been more efficient if this misunderstanding could be avoided.

Maybe something like "This looks good. Would be nice to see it extended to support companies that do not follow the calendar year.".

sakisv··on Ask HN: What country would you like to relocate to and why?
Switzerland.

I'm from Greece and I've always dreamt of living there, but through the various turns of life I ended living for almost a decade in the UK first, so now I'm looking to make the move.

(So if anyone from Switzerland is reading this and is looking for an SRE from an EU country, feel free to reach out at cv@ my username.net)

Lately though I've been thinking about Norway as well, though I feel that transition would be much harder.

sakisv··on Bitwarden introduces mandatory 2FA for new devices
oh nice! Thanks!!!
Page 1 of 7Next →