HNHacker News
TopNewBestAskShowJobs

stebalien

470 karma · joined December 30, 2014

A decentralized systems software engineer.

Web: <https://stebalien.com/>

submissionscomments
stebalien··on I built a GPU back end for Emacs
In case anyone is curious, ezemtsov (EWM author) has a Skai port of Emacs [1] built for Wayland (only).

[1]: https://codeberg.org/ezemtsov/emacs

stebalien··on I built a GPU back end for Emacs
https://github.com/tanrax/emacs-gpu/tree/wayland-pgtk-backen...

The main emacs-gpu branch doesn't have wayland support.

stebalien··on Meta's ships facial recognition on smart glasses
I expect cameras will start to come with built-in IR filters in that case.
stebalien··on Bijou64: A variable-length integer encoding
Sup b5! I always look forward to new work by expede (and n0).
stebalien··on Bijou64: A variable-length integer encoding
I've used LEB128 (with canonicalisation) extensively and... this looks so much nicer for most use-cases (length prefixed, supports the full uint64 range without that extra 10th byte).

The downside is the encoding size. LEB128 quickly grows to 2 bytes, but stays at 2 bytes all the way to 2^14. This is important if you're using these numbers as tags/identifiers as we were in the multicodec [1] project, or for network message lengths. bijou64 only gives you 500 <= 2 byte numbers.

[1]: https://github.com/multiformats/multicodec

stebalien··on My I3-Emacs Integration
I keep trying it (coming from EXWM) but I get lots of lag, stutters, and poor fractional scaling. I'm not sure how much of that is "GTK under wayland", Emacs's PGTK build (known to have lag/rendering issues), AMD kernel drivers (?), or EWM itself; but it's not yet a replacement for EXWM in my experience.
stebalien··on Qwen3.7-Max: The Agent Frontier
Have you tried enabling MTP? Those numbers are similar to what I was getting on my Strix Halo box, but configuring/enabling MTP doubled the TG speed of the 27B model (18-20 t/s now).
stebalien··on Googlebook
Features like the magic cursor look cool: an infinitely flexible context menu. However, context menus make it clear what you can and cannot do. If the magic cursor can't "do everything reasonable", it'll be just as usable as Siri.

I'd be more likely to believe them if they had already implemented this feature on their Pixel phones, but they haven't so I expect it probably isn't "done".

stebalien··on Local privilege escalation in Lix and Nix
Nix and Lix daemon implementations are affected by buffer overflows vulnerabilities that allow a local attacker to gain arbitrary code execution as the daemon user (root in multi-user installations).
stebalien··on Roblox shares plummet 18% as child safety measures weigh on bookings
They aren't:

> Users only speak to other players ±1 age group

I.e., 18-20 can speak to 16-17 AND 21+, but 21+ can only speak to 18+

stebalien··on Box to save memory in Rust
Box<str> is still two words (length and pointer). That's better than the 3 words (length, pointer, capacity) for strings, but Box<String> is one word (not including the heap allocation).
stebalien··on My first impressions on ROCm and Strix Halo
At least for qwen3.5, it looks like unsloth has updated their quantization algorithms to avoid bf16. See the march 5th update:

https://huggingface.co/unsloth/Qwen3.5-35B-A3B-GGUF/discussi...

I assume they're applying the same technique going forward, but I have no idea how to determine if this is the case.

stebalien··on Backblaze has stopped backing up OneDrive and Dropbox folders and maybe others
I've actually spent some time debugging why git causes so many issues with the backup software I use (restic).

Ironically, I believe you have it backwards: pack files, git's solution to the "too many tiny files" problem, are the issue here; not the tiny files themselves.

In my experience, incremental backup software works best with many small files that never change. Scanning is usually just a matter of checking modification times and moving on. This isn't fast, but it's fast enough for backups and can be optimized by monitoring for file changes in a long-running daemon.

However, lots of mostly identical files ARE an issue for filesystems as they tend to waste a lot of space. Git solves this issue by packing these small objects into larger pack files, then compressing them.

Unfortunately, it's those pack files that cause issues for backup software: any time git "garbage collects" and creates new pack files, it ends up deleting and creating a bunch of large files filled with what looks like random data (due to compression). Constantly creating/deleting large files filled with random data wreaks havoc on incremental/deduplicating backup systems.

stebalien··on Make tmux pretty and usable (2024)
My experience is that Emacs wants to be your everything, and works best if you let it. Have you tried putting your terminals inside of Emacs instead of the other way around?

* If you need a "real" terminal emulator, you can use something like vterm (https://github.com/akermu/emacs-libvterm/).

* If you need to be able to attach/detach Emacs sessions on remote machines, you can use something like dtach or abducto (https://www.brain-dump.org/projects/abduco/).

stebalien··on Waymo Safety Impact
I live in LA and Waymos are the only cars I don't have to play chicken with when crossing the street. Even the drivers that see you will just give you a "sorry, I'm in a rush" wave as they nearly run you over.
stebalien··on Kagi Small Web
I've been using it for 2.5 years at this point, and have the same experience. I don't think it's hopeless, but Kagi will need to step up their methods. IMO, there's actually a lot they can do here.
stebalien··on Is legal the same as legitimate: AI reimplementation and the erosion of copyleft
Copyleft is a mirror of copyright, not a way to fight copyright. It grants rights to the consumer where copyright grants rights to the creator. Importantly, it gives the end-user the right to modify the software running on their devices.

Unfortunately, there are cases where you simply can't just "re-implement" something. E.g., because doing so requires access to restricted tools, keys, or proprietary specifications.

stebalien··on Court finds Fourth Amendment doesn’t support broad search of protesters’ devices
The case was filed in 2023.
stebalien··on AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]
Maybe I've just lost all patience for fluff, but I gave up trying to figure out what the attack was from the article pretty quickly where the abstract answered all my questions immediately.
stebalien··on AirSnitch: Demystifying and breaking client isolation in Wi-Fi networks [pdf]
The article is hot garbage, here's the abstract from the paper (https://www.ndss-symposium.org/ndss-paper/airsnitch-demystif...):

To prevent malicious Wi-Fi clients from attacking other clients on the same network, vendors have introduced client isolation, a combination of mechanisms that block direct communication between clients. However, client isolation is not a standardized feature, making its security guarantees unclear. In this paper, we undertake a structured security analysis of Wi-Fi client isolation and uncover new classes of attacks that bypass this protection. We identify several root causes behind these weaknesses. First, Wi-Fi keys that protect broadcast frames are improperly managed and can be abused to bypass client isolation. Second, isolation is often only enforced at the MAC or IP layer, but not both. Third, weak synchronization of a client’s identity across the network stack allows one to bypass Wi-Fi client isolation at the network layer instead, enabling the interception of uplink and downlink traffic of other clients as well as internal backend devices. Every tested router and network was vulnerable to at least one attack. More broadly, the lack of standardization leads to inconsistent, ad hoc, and often incomplete implementations of isolation across vendors. Building on these insights, we design and evaluate end-toend attacks that enable full machine-in-the-middle capabilities in modern Wi-Fi networks. Although client isolation effectively mitigates legacy attacks like ARP spoofing, which has long been considered the only universal method for achieving machinein-the-middle positioning in local area networks, our attack introduces a general and practical alternative that restores this capability, even in the presence of client isolation.

stebalien··on UK House of Lords attempting to ban use of VPNs by anyone under 16
> democracy

house of lords

stebalien··on Copper thieves are wreaking havoc across America
We do need to provide better services, but that's not going to solve this issue. The vast majority of people struggling to make ends meet don't stoop to destroying public infrastructure. Only the true anti-social assholes go there.
stebalien··on How stealth addresses work in Monero
This article left me more confused than enlightened. I recommend reading https://risencrypto.github.io/Monero/ instead as it actually explains how the cryptography fits into Monero.
stebalien··on Dr Matthew Garrett v Dr Roy Schestowitz and Anor
For anyone interested, the story is told in the "truth defense" section:

https://caselaw.nationalarchives.gov.uk/ewhc/kb/2025/3063#lv...

stebalien··on How I am deeply integrating Emacs
You likely don't need to optimize anything; Emacs has seen some pretty significant optimizations recently (native Emacs Lisp compilation, tree-sitter modes, better handling of long lines, etc.) so performance is rarely the issue.

However, you do need to avoid call-process (spawning blocking processes) as much as possible. Also, my experience with TRAMP has been pretty awful due to the fix for https://debbugs.gnu.org/cgi/bugreport.cgi?bug=12145 (literally: TRAMP blocks all of Emacs while waiting on a network connection).

stebalien··on How I am deeply integrating Emacs
If you want to try eshell, try combining it with EAT (eat-eshell-mode).

> Maybe in my retirement I will end my career by helping to make emacs + EXWM multi threaded. I am guessing that is a daunting project, but it sure would be fulfilling.

This isn't fixable with threads, unfortunately. The issue is that:

1. Emacs e.g., launches a process with call-process. This blocks EVERYTHING (including other threads). 2. That process wants to map the window but EXWM can't respond to this request because Emacs is blocked. 3. The call to call-process never returns because the process can't create its window.

You'd have to fix Emacs to not block everything in cases like this, but that has been tried before: https://mail.gnu.org/archive/html/emacs-devel/2023-06/msg007...

At this point, I think the right answer is to write a minimal out-of-process window manager (e.g., a wayland compositor).

1. During normal operation, it would behave like EXWM and ask Emacs how to manage windows, etc. 2. In special cases (TBD), it would behave autonomously, acting like a standard floating window manager until Emacs becomes responsive again.

stebalien··on How I am deeply integrating Emacs
IMO, they're a great way to get started without having to invest too much time up-front. On the other hand, that was 10 years ago and it's a LOT easier to throw together a usable config nowadays; with LSP + built-in tree-sitter modes, you no longer need 3 packages per language plus a bunch of configuration glue.
stebalien··on Self-hosting email like it's 1984
I used to do this. What finally killed it wasn't reputation, it was the fact that I needed 100% uptime or risk losing messages, getting my address blacklisted, etc. Email is supposed to be resilient to down time (retries, trying each MX record, etc.) but I found that large mail providers tend to just bounce and walk away.

Worse, GitHub (back in 2016 and 2018) would mark a recipient as "unavailable" after a single bounce, refusing to send any more notifications to that address. They since improved the situation and their support was actually very helpful and responsive here, but it's pretty clear that modern SMTP senders have an expectation that recipients will be "always online" that didn't exist when the protocol was invented.

stebalien··on Where it's at://
Ah, that's exactly what I was looking for. Thanks!

I guess I get why it works that way (avoids some issues with domain expiration) but... honestly, I'd rather have my domain name in control. Even after registering my own rotation key, I'm still at the mercy of the centralized PLC directory.

Unfortunately, it looks like it's not possible to migrate to a web DID without starting over.

stebalien··on Where it's at://
Is there any documentation on how to do this without running a custom appserver and/or PDS? Can I create my own DID and delegate to another DID?
Page 1 of 4Next →