HNHacker News
TopNewBestAskShowJobs

stebalien

470 karma · joined December 30, 2014

A decentralized systems software engineer.

Web: <https://stebalien.com/>

submissionscomments
stebalien··on Federal regulator says Amazon can be held responsible for faulty goods
It means that Amazon is responsible for recalling faulty products, not that they're responsible for handling products recalled by the manufacture.

In general, the seller is responsible for the products they sell, regardless of who manufactured it. This gives the buyer a clear party they can sue, likely a party that has a presence in their jurisdiction. Amazon can turn around and go after the manufacture, but that's not the buyer's problem.

Amazon tried to call themselves a "marketplace" to avoid this liability, but nobody's buying that.

stebalien··on For advertising, Firefox now collects user data by default
It's all other parties, actually. I'm assuming Mozilla and friends are trusted and that the cryptography is perfect.

I've filed an issue at https://github.com/patcg-individual-drafts/ipa/issues/90 but I'm still not sure if that's the right repo.

stebalien··on For advertising, Firefox now collects user data by default
Those docs look out of date and appear to be designed for "app" ecosystems. The latest proposal from Mozilla is https://docs.google.com/document/d/1QMHkAQ4JiuJkNcyGjAkOikPK...

And I'm now quite sure this system is insecure. Fundamentally, either:

1. There is some magical sybil protection: An attacker can only spend their own privacy budget without affecting the rest of the system.

2. The system can be saturated: An attacker can spend everyone's privacy budget.

3. The system is not private: An attacker can exceed the "safe" privacy budget by combining information from multiple sybils.

stebalien··on For advertising, Firefox now collects user data by default
I can try. But I'm pretty sure what they're trying to do is fundamentally impossible without some kind of sybil protection.
stebalien··on For advertising, Firefox now collects user data by default
This works by adding noise. Can't an attacker bypass it by boosting the signal? Assuming the attacker can create sybil advertisers/browsers, this should be totally doable:

1. Define some baseline set of M impressions with various ad identifiers and from various sybil advertisers.

2. For each target user, define some set of M marker impressions, also with various ad identifiers and from various and sybil advertisers.

3. Save all impressions (marker + baseline) on a bunch of sybil browsers to get above the reporting baseline with some probability.

4. If/when a target user visits a target website, request a conversion report for each ad/advertiser.

You now have a baseline signal (from the baseline ads/advertisers) and a marker signal (from the marker ads/advertisers). If this is one of your target users, you'd expect their "marker" signal signal to be stronger than the baseline.

stebalien··on Anybody have problems with bookmark organization like me?
I'd recommend finding a note-taking/capture flow you're comfortable with, then use that for bookmarking. Org-mode, obsidian, logseq, etc.

1. You can solve the "remember random thing" problem once and for all.

2. Such tools usually have efficient capture workflows that let you capture now and organize later.

3. Note-taking applications tend to be more flexible and featureful than bookmarking applications.

The main downside is that browser integration can suffer, but you can usually find companion extensions for capturing notes at a minimum.

stebalien··on Emacs Easydraw – drawing tool inside Emacs
If you're looking for a more actively developed collaborative editing mode, take a look at https://github.com/casouri/collab-mode.
stebalien··on Bluesky adds direct messages
In my experience, temporary fixes are more likely to "stick" the better they are at addressing the problem. The fact that nobody is satisfied with this fix is a good sign.
stebalien··on Bluesky adds direct messages
It's a stop-gap because people want DMs and implementing them correctly (decentralized, e2e encrypted, etc.) is non-trivial. Rushing e2e encryption is not a good idea (and no, you can't just slap on matrix/signal and call it a day).

The alternatives are to:

1. Wait a bit longer for something half-baked that appears to meet the goals (i.e., something you're going to regret but will be unable to replace). 2. Wait even longer for something perfect.

By making the protocol centralized and stupid-simple, it's also stupid-simple to replace in when everyone is done painting the perfect bikeshed.

stebalien··on Ollama now supports AMD graphics cards
Not yet: https://github.com/ollama/ollama/issues/2637
stebalien··on Disputed, Not Rejected
Obfuscating your commandline is racy. The only fix for issues like this is to not pass passwords on the commandline, except when debugging.
stebalien··on Guix on the Framework 13 AMD
This is an issue with any software that tries to maintain backwards compatibility, not Linux. Windows has:

- Many years worth of different control panels.

- Little consistency with respect to toolkits in general.

- Fractional scaling issues in applications using older toolkits (e.g., open up the policy editor and notice the blurry fonts). Microsoft is actually giving up here and has been experimenting with ML-based scaling for old applications (an approach I expect we'll eventually see in Linux as well).

Apple handles this by breaking compatibility every so often, forcing old software out of the picture.

stebalien··on Framework Laptop 16 Review
Yeah, sleep on the 11th gen is basically worthless. But the battery upgrade (especially after a few years of wear and tear) and the new AMD board are worth it.

... unless you watch a lot of video. Hardware video decoding uses more power than software video decoding in many cases: https://gitlab.freedesktop.org/mesa/mesa/-/issues/10223

stebalien··on Framework Laptop 16 Review
My FW13 AMD laptop (61Wh battery) can last 11hr+, technically. If I'm doing anything other than light web browsing, that quickly drops to 8hr. If I'm watching videos, it's more like 5hr.

Unfortunately, at least on Linux, it requires quite a bit of tuning for the moment. But there are some pretty good guides.

Suspend battery life still isn't great, but it's _much_ better (with s2idle supported) on the latest-gen AMD platform.

I previously had the 11th gen Intel and... I got much better battery life than you, but it was still pretty bad.

stebalien··on Blocked by Cloudflare
Enabled them and restarted, still nothing (although there's a chance I messed it up somewhere, I haven't tested it thoroughly). But honestly, I don't really care given that 99% of the web works otherwise.
stebalien··on Blocked by Cloudflare
Not OP, but GitLab always cycles for me on LibreWolf, even with "enhanced tracking protection" turned off. It's likely because I disable WebGL?

7f3b42d2bee22efb

stebalien··on Emacs is my new window manager
I've been using EXWM (Emacs X Window Manager) for over 6 years now and can't go back.

- I have _one_ window manager for my files, browser, and terminals. - Everything is keyboard driven with a centrally managed set of hotkeys. - Everything integrates with everything else. It's the convenience of an IDE without ever having to leave it. - Because it's lisp based, every aspect of my environment can be inspected, debugged, and modified at runtime.

Of course, some recent advancements in Emacs really help here:

- LSP support means it's no longer a "second class" IDE/editor. - Native compilation of Elisp means it's much snappier.

stebalien··on “looks like Firefox quietly added ads into the address bar”
You may be right, but it's very unclear. I came to my conclusion because Firefox calls every result a "Firefox Suggest" result (see the title at the top of the results).

From https://blog.mozilla.org/data/2021/09/15/data-and-firefox-su..., it looks like Firefox (currently) matches your search terms against a local list before forwarding them. So not everything is sent, but anything including a term specified by the advertising agency.

It's unclear if it includes the entire search query or just the single word. That same blog post seems to indicate that mozilla "may" send the entire query. It also appears that Mozilla is sending city level location data.

Of course, that same blog post implies that the feature is opt-in (which it definitely isn't).

stebalien··on “looks like Firefox quietly added ads into the address bar”
It's nothing like pocket ads. They send everything you type and the item you click on. Take a look at the "What data is shared if you enable contextual suggestions?" section.
stebalien··on “looks like Firefox quietly added ads into the address bar”
"Enabled for US users only" because they'd go bankrupt due to GDPR violations otherwise.

I had disabled search suggestions because I didn't want a key logger in my address bar and Mozilla most certainly did not get my consent or notify me of any changes to the privacy policy before they helpfully enabled this "feature" for me.

stebalien··on FFmpeg for browser and Node, powered by WebAssembly
The original point of the GPL was to ensure that end-users retained their rights to the source code. See https://www.gnu.org/philosophy/free-sw.en.html#four-freedoms.
stebalien··on Why is it so hard to see code from 5 minutes ago?
It can even persist history across restarts if you set undo-tree-auto-save-history.
stebalien··on Simple techniques to optimise Go programs
Unfortunately, that's still wrong (I think). Go will still allocate a temporary slice-header on the heap and then de-allocate it when it's dereferenced.

I believe the only way to do this without unsafe code is to pool these slice-headers as in https://github.com/libp2p/go-buffer-pool/blob/master/pool.go.

stebalien··on IPFS, Again
IPFS was started in 2014, long before Protocol Labs started working on Filecoin.
stebalien··on IPFS, Again
Several of the key members have shifted focus but there's still a core IPFS team. But we're still spread quite thin.

We're still paying down years of documentation debt but there has been quite a bit of progress:

* Expanded https://docs.ipfs.io/ with a concepts section. * Tutorials https://proto.school/#/ * A ton of work on libp2p specs (https://github.com/libp2p/specs/commits/master) along with a full time documentation writer.

stebalien··on PeerPad – A realtime P2P collaborative editing tool powered by IPFS
> If you want a p2p system because you care mostly about removing servers as a bottleneck, then this may not be an issue, but if you care about removing servers because you don't trust intermediaries, then this only gets you half way there.

This is, actually, truly peer-to-peer. Those are connections to the bootstrap nodes, you can set your own bootstrap nodes if you want but you do need to be seeded with a few initial peers to find new peers. If you want to establish a browser-to-browser connection, you will need some server to help setup the WebRTC connection; this is the unfortunate reality of browsers. However, you can (theoretically^) connect to arbitrary non-browser IPFS nodes over a websocket connection (that's what's happening here) without some "blessed" node acting as the rendezvous.

^Unfortunately, there's a bit of a wrinkle:

1. Most non-browser IPFS nodes don't listen on websockets by default. The transport is still experimental and and has some bugs.

2. If you load IPFS from an https origin, browsers won't generally allow you to establish connections to non-https websocket endpoints. Unfortunately, even if you enable listening on the websocket transport on your IPFS node, you'll end up listening on an http (not https) websocket. This is because IPFS manages the encryption of the connection itself (IPFS addresses, or "peer IDs", are cryptographic hashes of public keys) and doesn't use (or play well with) the CA system. To work around this, the bootstrap nodes have nginx proxies out in front that to handle HTTPs connections. Most (all other?) nodes don't.

stebalien··on Keyboard latency
This rule comes from UX design user studies. However, the actual rule is that people perceive an event happening within 100ms as "instantaneous". Or, in other words, two events happening within 100ms of each other won't feel like distinct events. This doesn't mean that users won't notice the delay and it doesn't even mean users won't be frustrated by it, it's just a matter of human perception of distinct events in time.

Unfortunately, programmers/UX designers have a tendency to generalize this rule and use it to excuse slow user interfaces.

stebalien··on Filecoin: A Decentralized Storage Network [pdf]
> can you explain how the protocol can tell the difference between a legitimate hardware

From the perspective of the network, there is no difference. When you agree to dedicate some storage to the network, you post a collateral in FIlecoin. If you lose something you've agreed to store (fail to prove that you're storing it when asked to do so by the network), you pay a penalty out of your collateral.

> Is payment only collected upon retrieval

No. Storage miners continuously prove (probabilistically) to the network that they're storing the files they've agreed to store.

stebalien··on Filecoin: A Decentralized Storage Network [pdf]
You can absolutely take down the offending material; you'll just lose the collateral (you can also transfer the contract to someone else but that will likely not be legal in all jurisdictions). However, as the contracts are made between the clients and miners directly, miners can choose to charge anonymous/untrusted clients more to make up for this potential eventuality.
stebalien··on Filecoin: A Decentralized Storage Network [pdf]
How is this any different from what Amazon does? They don't manually inspect all uploaded files. Instead, they rely on legal protections given to service providers.

Filecoin miners can do the same by (a) registering as service providers and (b) complying with blacklists and takedown notices as mandated by their legal jurisdiction. Note: Filecoin miners don't just store arbitrary files assigned by the network; they sign contracts with specific clients to store specific files. The only difference from Amazon is that the network itself enforces these contracts.

← PreviousPage 3 of 4Next →