HNHacker News
TopNewBestAskShowJobs

snackbroken

647 karma · joined December 5, 2024

submissionscomments
snackbroken··on "Negative" views of Broadcom driving VMware migrations, rival says
> Just because a company folds doesn't mean they can violate licensing agreements.

It does if that's the law. Every jurisdiction routinely overrules contracts as unenforceable on the basis of some overriding law, so it wouldn't even really be that unusual. Whether it's a good idea or not is another question and one that depends almost entirely on second, third and higher order effects.

There probably is a world where all software is libre software and we still see similar rates of development, but it's not at all clear how you could get there. Especially not if you cared about the damage caused by upending the business models of a significant fraction of the world economy.

snackbroken··on Claude Code's source code has been leaked via a map file in their NPM registry
> Lately, it's been crashing if I hold the Backspace key down for too long.

Golden opportunity to re-enact xkcd 1172.

snackbroken··on Android Developer Verification
"Meet me in the middle" says the unjust man.

You take a step forward.

He takes a step back.

"Meet me in the middle" says the unjust man.

snackbroken··on Olympic Committee bars transgender athletes from women’s events
> It's clear how insane this culture war against trans people is when you consider this only applies to trans women and not trans men?

In most sports, the "mens" division is actually an open division that accepts all participants regardless of sex. Women just don't compete in it because they have no shot at getting a decent placement. The fact that males and females can't fairly compete with each other is the raison d'être of the women's league. This, and not culture war propaganda reasons is why only the most deranged bigots have an issue with trans men competing in "mens" sports.

snackbroken··on Slovenian officials blame Israeli firm Black Cube for trying to manipulate vote
The EU is perfectly capable of collaborating even when it can't reach full consensus or when it wants to include peripheral states without them becoming full members. See for example the Schengen area, Eurozone, European Economic Area, and more recently (and specifically to circumvent member state vetos) when the enhanced cooperation procedures were invoked to lend money to Ukraine.
snackbroken··on GrapheneOS refuses to comply with new age verification laws for operating system
People who live in authoritarian states like North Korea or California can (and arguably should) ignore the fact that GrapheneOS is illegal where they live and use it anyway.
snackbroken··on Trivy ecosystem supply chain briefly compromised
As the complexity of a system increases, the number of single points of failure also tends to increase. Sometimes you can make sure that several subsystems need to fail before the whole system fails. Often, the best you can do is swap one SPoF (e.g. unreliable power grid) for another, more robust SPoF (unreliable UPS).
snackbroken··on Afroman found not liable in defamation case
"Actual malice" is confusingly not about if the defendant was acting maliciously. It is specific legal jargon meaning that the defendant knowingly or with reckless disregard for the truth made the false statements.
snackbroken··on Afroman found not liable in defamation case
That wasn't actually what I was implying. Just that if the plaintiff isn't even willing to assert that the statements were false, what are you wasting the court's time for?

  > He falsely claimed my wife is cheating on me!
  > So you assert that your wife didn't cheat on you?
  > No.
  > ???
snackbroken··on Afroman found not liable in defamation case
Going on the stand and stating that you "don't know" whether the allegedly defamatory statements you are suing over are true or not is a... bold legal strategy.
snackbroken··on Meta Platforms: Lobbying, dark money, and the App Store Accountability Act
My general point is that you can have anonymity or you can prevent ID spoofing, but the two are mutually exclusive.
snackbroken··on Reddit User Uncovers Who Is Behind Meta's $2B Lobbying for Age Verification Tech
Ah, so it does leak your identity through the timing side channel. In other words, your anonymity is only dependent on the govt not coordinating with service providers to de-anonymize users. I assumed the 2fa app just held cryptographic keys and did some 0kp magic to show that the cert belongs to a government-attested adult. Phoning home all the time makes it trivial for the government to abuse people's privacy; they can just compel service providers to provide logs of logins.
snackbroken··on Reddit User Uncovers Who Is Behind Meta's $2B Lobbying for Age Verification Tech
The automated attack setup I'm envisioning is something like: 18 year old buys a cheapo laptop + phone and connects the two over ADB or some purpose built automation app (think appium). 18 year old puts the phone on a tripod pointed at the laptop screen. 14 year olds at school pay $10 a year for use of the service and install a browser extension that forwards the QR codes from whichever service they wanna use to the 18 year old's computer. Changing every couple of seconds is not an issue here, they all live in the same city and have <10ms ping.

The only high friction part of this is that someone needs to write the software for it, but that doesn't seem like all that difficult of a project and open source solutions are likely to appear within weeks of social media requiring it. If there really is no information shared with the other party beyond "yup, user is over the age of maturity" you could even run this as a free public TOR service without fear of ever getting caught.

snackbroken··on Reddit User Uncovers Who Is Behind Meta's $2B Lobbying for Age Verification Tech
> He would need to be next to you every time you log in.

Or you can just text him a screenshot of the QR code. You could probably even automate this.

snackbroken··on Reddit User Uncovers Who Is Behind Meta's $2B Lobbying for Age Verification Tech
This particular slope has consistently had people pratfalling over and over again for hundreds of years.
snackbroken··on Reddit User Uncovers Who Is Behind Meta's $2B Lobbying for Age Verification Tech
If there's no information provided beyond proof-of-age, what's stopping my friend's 18 year old brother from lending his ID to every 14 year old at school? IRL that's negated by the liquor store clerk looking at the kid who is obviously underage and seeing that his face doesn't match the borrowed card he just nervously presented.
snackbroken··on Meta’s renewed commitment to jemalloc
For video games it is pretty bad, because reading back a page from disk containing "freed" (from the application perspective, but not returned to the OS) junk you don't care about is significantly slower than the OS just handing you a fresh one. A 10-20ms delay is a noticeable stutter and even on an SSD that's only a handful of round-trips.
snackbroken··on Roblox is minting teen millionaires
>Yeah I'm not seeing how this is supposed to work

You could verify the ID of an adult who vouches for the child they are a legal guardian of. That way, if it turns out that Brayden(M12) is actually Linda(F45) you know who to send law enforcement to to ask some very pointed questions.

That said, I don't think online ID verification is effective and even if it was, it wouldn't be worth the level of mass privacy invasion. If your goal is actually to help kids who are victims of abuse, your efforts are much better spent elsewhere. For example: making child abuse report hotlines/websites more easily accessible and widely known, fixing social services so that they actually provide better help when requested instead of making things worse, better education for children about what is and is not OK behavior even from "trusted" adults, and how to get help from someone who isn't a relative when you need it. "Stranger danger" hysteria catches all the outrage and public discussion, but is the least common source of abuse.

snackbroken··on The Eternal Promise: A History of Attempts to Eliminate Programmers
Beaucoup.
snackbroken··on Discord/Twitch/Snapchat age verification bypass
> I'd be a lot more fine with it if it was just algorithms designed for addiction (defining that in law is tricky)

An alternative to playing whac-a-mole with all the innovative bad behavior companies cook up is to address the incentives directly: ads are the primary driving force behind the suck. If we are already on board with restricting speech for the greater good, that's where we should start. Options include (from most to least heavy-handed/effective):

1) Outlaw endorsing a product or service in exchange for compensation. I.e. ban ads altogether.

2) Outlaw unsolicited advertisements, including "bundling" of ads with something the recipient values. I.e. only allow ads in the form of catalogues, trade shows, industry newsletters, yellow pages. Extreme care has to be taken here to ensure only actual opt-in advertisements are allowed and to avoid a GDPR situation where marketers with a rapist mentality can endlessly nag you to opt in or make consent forms confusing/coercive.

3) Outlaw personalized advertising and the collection/use of personal information[1] for any purpose other than what is strictly necessary[2] to deliver the product or service your customer has requested. I.e. GDPR, but without a "consent" loophole.

These options are far from exhaustive and out of the three presented, only the first two are likely to have the effect of killing predatory services that aren't worth paying for.

[1] Any information about an individual or small group of individuals, regardless of whether or not that information is tied to a unique identifier (e.g. an IP address, a user ID, or a session token), and regardless of whether or not you can tie such an identifier to a flesh-and-blood person ("We don't know that 'adf0386jsdl7vcs' is Steve at so-and-so address" is not a valid excuse). Aggregate population-level statistics are usually, but not necessarily, in the clear.

[2] "Our business model is only viable if we do this" does not rise to the level of strictly necessary. "We physically can not deliver your package unless you tell us where to" does, barely.

snackbroken··on Discord/Twitch/Snapchat age verification bypass
First, children also have a right to free speech. It is perhaps even more important than for adults, as children are not empowered to do anything but speak.

Second, it's turn-key authoritarianism. E.g. "show me the IDs of everyone who has talked about being gay" or "show me a list of the 10,000 people who are part of <community> that's embarrassing me politically" or "which of my enemies like to watch embarrassing pornography?".

Even if you honestly do delete the data you collect today, it's trivial to flip a switch tomorrow and start keeping everything forever. Training people to accept "papers, please" with this excuse is just boiling the frog. Further, even if you never actually do keep these records long term, the simple fact that you are collecting them has a chilling effect because people understand that the risk is there and they know they are being watched.

snackbroken··on Efficient String Compression for Modern Database Systems
Doesn't interning usually refer to when you only consider identical copies, as opposed to dictionary compression where you allow for concatenations? E.g.

  Interning:
  1: "foo"
  2: "bar"

  my_string = "foo" // stored as ref->1
  my_other_string = "foobarbaz" // not found & too long to get interned, stored as "foobarbaz"

  Dictionary compression:
  1: "foo"
  2: "bar"
  
  my_string = "foo" // stored as ref->1
  my_other_string = "foobarbaz" // stored as ref->1,ref->2,"baz" (or ref->1,ref->2,ref->3 and "baz" is added to the dict)
snackbroken··on Proof of Corn
The diagram looks correct for me when I disable CSS on the page or edit it's font-family to be "monospace". Seems like Geist Mono might just be borked.
snackbroken··on Updates to our web search products and Programmable Search Engine capabilities
What's their angle here? Courts have been over the "Is scraping websites that don't want to be scraped OK?" question plenty of times. From

> SerpApi deceptively takes content that Google licenses from others (like images that appear in Knowledge Panels, real-time data in Search features and much more), and then resells it for a fee. In doing so, it willfully disregards the rights and directives of websites and providers whose content appears in Search.

it sounds like they are somehow suing on behalf of whoever they are licensing content from, but does that even give Google standing?

I guess I'm asking if they actually are hoping to win or just going for a "the process is the punishment"+"we have more money and lawyers than you" approach.

snackbroken··on ASCII characters are not pixels: a deep dive into ASCII rendering
> I don’t believe I’ve ever seen shape utilized in generated ASCII art, and I think that’s because it’s not really obvious how to consider shape when building an ASCII renderer.

Acerola worked a bit on this in 2024[1], using edge detection to layer correctly oriented |/-\ over the usual brightness-only pass. I think either technique has cases where one looks better than the other.

[1]https://www.youtube.com/watch?v=gg40RWiaHRY

snackbroken··on The Vietnam government has banned rooted phones from using any banking app
Because root is not the ultimate authority of what goes on in the phone; the hardware is, and the hardware contains a TPM (Treacherous Platform Module). The TPM has secret cryptographic keys it never shares with anyone, neither root nor an unrooted OS. When the phone starts, the TPM checks if the OS has been modified from what the manufacturer supplies or not.

The bank's app can then ask the OS to sign documents using the TPM's secret keys, and the OS forwards such requests to the TPM. The TPM refuses such requests from modified OS but obliges requests from an unmodified OS. The bank's servers refuse to accept documents not signed by the TPM.

Root can't pretend to be a TPM and make up some secret keys to sign documents with because the TPM's signature is itself signed by Google, so the bank can tell the difference between root's signature and a treacherous signature.

snackbroken··on Jeffgeerling.com has been migrated to Hugo
Consider not having your browser configured with prefers-color-scheme: dark.
snackbroken··on CSS Grid Lanes
In a newspaper the answer is simple. You linearly scan the leftmost column to the bottom of the page, then the next column, then the next, and so on until you get to the end of the page. At no point do you ever need to keep track of anything other than "this is how far I've gotten" to make sure you haven't missed anything. Columnar layout make sense in newspapers because both axes are fixed in size, so all you ever do is one long linear scan with wraparound.
snackbroken··on CSS Grid Lanes
> You scan it all and pick the article you are interested in

Okay. What order am I supposed to scan in so I don't lose my place and accidentally skip a block? Scanning column by column gets me cut off partial boxes that I'll have to remember to check again later, while scanning side to side forces me to keep track of each individual block I've already looked at, as opposed to a single pointer to "this is how far I've scanned". Alternatively, I can scan roughly left to right, top to bottom and just live with missing some blocks. That's not ideal either, because hopefully if you didn't think I'd like to look at all of them you wouldn't have included them on the page.

You're right that you can make a newspaper that's really inconvenient to read, but you wouldn't, because the failure case you'd end up with is CSS Grid Lanes.

snackbroken··on CSS Grid Lanes
It looks pretty, but fails at basic usability.

After reading the top-left block of text titled "Optimizing Webkit & Safari for Spedometer 3.0", what the fuck am I supposed to read next? Am I meant to go recursively column by column, or try to scrutinize pixels to determine which of the blocks are further up than the others, skipping haphazardly left and right across the page? A visual aid: https://imgur.com/a/0wHMmBG

Columnar layout is FUNDAMENTALLY BROKEN on media that doesn't have two fixed-size axes. Web layouts leave one axis free to expand as far as necessary to fit the content, so there is no sane algorithm for laying out arbitrary content this way. Either you end up with items ordered confusingly, or you end up having to scroll up and down repeatedly across the whole damn page, which can be arbitrarily long. Either option is terrible. Don't even get me started on how poorly this interacts with "infinite scroll".

← PreviousPage 2 of 5Next →