HNHacker News
TopNewBestAskShowJobs

soneil

4,800 karma · joined December 20, 2010

submissionscomments
soneil··on Reliable 25 Gigabit Ethernet via Thunderbolt
Pretty much anywhere you have networked storage? Gigabit is about on-par with pre-sata ATA133.
soneil··on Debian's Git Transition
This was one of the "lessons learnt" from the XZ incident. One of the (many) steps they took to avoid scrutiny was modifications that existed in the real tarball but not the repo.
soneil··on Modern Walkmans
The sad thing is that's pretty accurate.

I do value the inconvenience. When I put an album on, I put an album on. I don't hit next, random, go wandering off down rabbitholes. I put the album on.

And I do see the cost as a feature, somewhat. It feels like I got something for my money, in a way that paying for a zip doesn't.

soneil··on Trains cancelled over fake bridge collapse image
What you'll tend to notice with "willing participants" is that they're not looking for truth, they're looking for confirmation. No-one asks for proof when you tell them what they want to hear.
soneil··on Trains cancelled over fake bridge collapse image
In my family it's the other way around - it's the people that used to tell us not to talk to strangers on the internet, and not to believe everything we see on the internet, who are now doing precisely that.
soneil··on Nearly all UK drivers say headlights are too bright
Isn't it great being able to rely on tech that isn't doing what we think it's doing.

I don't even need to keep an eye on my cooking anymore, the smoke alarm beeps when I get too close.

soneil··on RFCs: Blueprints of the Internet
My understanding is that the "nugget of truth" that birthed the "routing around nuclear attack" myth, is that it was a consideration in Paul Baran's packet-switching work at RAND.

So it wasn't a design consideration for ARPANET, but it would have shown up in enough early papers to give the myth some legs.

soneil··on Wireguard FPGA
bps are easy. packets per second is the crunch. Say you've got 64 bytes per packet, which would be a worst-case-scenario - you're down to 150Mpacket/sec. Sending one byte after another is the easy bit, the decisions are made per-packet.
soneil··on Hardware inspector fired for spotting an error he wasn't trained to find
> How do you physically solder a chip the wrong way around?

With effort, and bodge-wire. I've seen chips done dead-bug style when the board's been messed up (eg, the footprint is orientated for the bottom of the board, but placed on the top, and vice-versa).

It's definitely not something you'd ship, but a kludge that can get you working until the next board spin.

soneil··on Raspberry Pi 500+
> Nit: It's the Pi 500+

I really want to hope the name is a nod to the Amiga 500+ (which had twice the RAM of the A500 ..)

soneil··on I bought the cheapest EV, a used Nissan Leaf
I think the common mistake they’re alluding to is Europe and north America having conflicting standards for colour-coding the pumps. So here green is unleaded and black is diesel, which can catch American tourists unaware. (Especially so with language barriers, “sans plomb” in French is not intuitively petrol/gas/benzo)
soneil··on XZ Utils Backdoor Still Lurking in Docker Images
It'd be some fluke of an accident. You'd need to be targeting not only debian:testing/unstable, but specifically debian:testing-20240311. And then - making sure not to apt upgrade at any point so you don't accidentally get any updates from the last 18 months - you'd need to also install openssh-server to avail of the backdoor, plus a service manager because running sshd in the foreground killswitches said backdoor. And then don't forget to expose the ssh port otherwise our effort is wasted.

The most realistic way to hit this would be to have built an image 18 months ago, on top of :testing or :unstable, and then not update or rebuild it at any time in those 18 months - in which case removing anything from the repo wouldn't help you. Or be purposely trying to recreate an affected environment for testing/research, in which case it's on you.

You're not wrong that we should keep our shields up - but "update sometime in the last 18 months" perhaps isn't such a revelation.

One thing does come to mind though - I do wonder if there's a way to strongarm apt's dependencies mechanism into having openssh-server conflict with affected libxz versions, so that if you did apt update && apt install openssh-server in an affected image, it'd bring a fixed libxz along for the ride. (and the images don't carry apt manifests, so apt update is required and you would have today's package list.) You could still pin an affected version, so there'd still be enough rope to allow you to recreate a research environment.

soneil··on Kodak has no plans to cease, go out of business, or file for bankruptcy
I'm not convinced it was really their strategy on digital that killed them. I mean it's clear their film camera business was a "razor blades" model in support of their film business - then they tried to approach digital the same way, trying to figure out what razor blades they could sell us.

But it was largely working - Kodak were the market leaders[*] in digital cameras right up until the smartphone came out. The market for non-SLR/mirrorless cameras is down >98% from there. They could have owned 100% of that segment and they'd still be a nostalgia marque today.

Digital all but killed the film segment, and then smartphones all but killed their digital segment. They were winning in dead markets.

* In the US, according to some contemporary BusinessWeek article that wikipedia's sourced. But I'm willing to accept that it's within a margin of error of successful in that segment.

soneil··on Kodak has no plans to cease, go out of business, or file for bankruptcy
I was looking at CIPA stats[0] yesterday. This appears to be a Japanese trade association, so it covers a lot of the biggest names in photography - but not Kodak.

But the numbers surprised me much beyond what I thought I already knew. Interchangeable-lens cameras are down from 10.something million units in 2008, to 6.something million units in 2024. But fixed-lens (eg compact, point & shoot, etc) went from 106 million to 1.8 million over the same period.

Nokia survived the smartphone better than (non-interchangeable) cameras did.

[0] https://www.cipa.jp/e/stats/dc.html

soneil··on Germany's identity crisis: The trains no longer run on time
Ironically, DB owned many lines in the UK up until recently (via their ownership of Arriva)
soneil··on Geocities Backgrounds
The part that really feels different to me, is that I'm not sure that a 12yo equivalent of myself would get far with View Source anymore.

I think that was my single greatest resource, and on a huge majority of sites it won't get you far anymore.

soneil··on Neil Armstrong's customs form for moon rocks (2016)
That's the whole point of the parent comment - you don't trigger customs requirements by leaving and re-entering the country. You trigger them by entering from another country.

for example - you don't need a passport to travel from the US mainland to Hawaii. It doesn't matter that the aircraft cross international waters, it matters what country you were in last.

soneil··on Seven Engineers Suspended After $2.3M Bridge Includes 90-Degree Turn
There's been a bridge there since the 13th century, and the current bridge is a listed structure built 1857. It's not really something you'd choose to build today.
soneil··on The Scheme That Broke the Texas Lottery
We had an issue like this with a small office lottery at work.

So our "setup" was simple. Our national lottery has a 'bonus ball' mechanism. Each participant in the office lottery bought a number. If this week's bonus ball is your number, you win the pot. If no-one wins, the pot rolls over.

The issue we hit was people joining mid-roll. Say we have 10 players, rolled over 9 weeks putting $90 in the pot. On week 10, a new player joins, $11 joins the pot, and the new player wins $101 for their $1 in. This is legally fair, but everyone with $10 in the pot feels robbed by the $1 newbie.

We took the easy out and only accepted new members during a 'fresh' pot - which isn't practical for a state lottery.

But it shows the difference between legal fairness and perceived fairness. Someone being able to buy every combination is game-breaking - who would play a lottery where millionaires are guaranteed to win? But roll-overs twist the math until it pays off, and now everyone who's entered in the previous weeks is unwillingly playing a lottery where millionaires are guaranteed to win.

It's not impossible to fix either - if you want to fix it. Cap wins at $x and return the remainder to the pot; keep the maximum prize far under the point where buying combinations pays off, and you can keep offering that maximum prize until the roll-over is exhausted.

But if you're the one making a profit from the lottery, you don't want to fix it. Massive jackpots are a feature - they encourage more participants, more spending, more profit.

And it does seem unfair to protect a mechanism that's so easily exploited, just because it attracts more people to be exploited. And it really can't be good for the long-term health of the game, if people know that roll-overs will be exploited.

soneil··on Show HN: RM2000 Tape Recorder, an audio sampler for macOS
"This app is currently not available in your country or region." (Ireland)

Seems like a strange thing to be geolocked?

soneil··on Plutonium Mountain: The 17-year mission to guard remains of Soviet nuclear tests (2013)
Possibly. We'd need to know whether the Siberian equipment could survive Nevada to make that call.
soneil··on Letsencrypt will kill SMTP server auth following Chrome CA policy change
I have to go figure out exactly how this works now, as I'm likely affected.

When my smtp server connects to, eg gmail's smtp server - I'd ordinarily consider my smtp server the client within the scope of that connection.

So am I supposed to present a tlsclient EKU within outbound connections and tlsserver to incoming connections?

soneil··on Trump announces 100% tariffs on movies ‘produced in foreign lands’
What else would someone who dials 911 be trying to achieve? And does the benefit outweigh the cost?

911 has enough mindshare that it'd be silly to use it for anything else. And if you're not going to use it for anything, a redirect seems like a very productive way to park it.

soneil··on Europen Union creates Fedora-based Linux distribution for the public sector
The front page has a footer that names a single individual, and links to their personal site which feels a little less suspicious.
soneil··on What if America turned off Britain's weapons?
Interesting observation that the "UK doesn't even own its Trident missiles". Legally, they do. They bought title to 58 missiles, in what's effectively a co-mingled inventory. They're not leased, they're not borrowed, and it's certainly not charity.
soneil··on German tourist held indefinitely in San Diego area immigrant detention facility
I have a sibling who was deported from the US (long, stupid story). There was a 6 month gap from when we'd been told he'd been deported, to when he was actually deported. And this was 15-20 years ago, it's not a recent change.

It is absolutely a system that's designed to disappear people. It's just headcount for income, no-one cares who those heads belong to.

soneil··on Show HN: I made a site to tell the time in corporate
Fonts with 'routed' in their names are often a good place to look for this - they're named thus because they were designed to be scribed/engraved with a router, so very frequently have a constant width.

(and if you're up for a rabbit hole, https://aresluna.org/the-hardest-working-font-in-manhattan/ )

soneil··on How to add a directory to your PATH
I don't think I've ever lost a setting from there. the manpage (path_helper) was last updated 2007, so I think it's fair to say it's not a very dynamic corner of the OS.
soneil··on How to add a directory to your PATH
I really like the /etc/paths.d/ mechanism the mac uses. Such a simple thing, I'm surprised I haven't seen it adopted elsewhere.
soneil··on Former tech CEO suing to get the record of his arrest removed from the internet
I always understood this to be a trust issue. "We" (loosely, I'm English) tend towards trusting the courts, so we allow them to keep secrets. The US was built on a healthy distrust of the state, so names were released so people aren't "disappeared".

But the US has moved much more towards "no smoke without fire", leaving the release of names in an antiquated place.

← PreviousPage 2 of 34Next →