HNHacker News
TopNewBestAskShowJobs

steventhedev

1,122 karma · joined October 23, 2013

Flawed human being, but always trying to improve
submissionscomments
steventhedev··on Flip Fluid on Flip Dots
I'm always amazed by the precision work this guy does. My only nit with this article was he didn't link the Eurovision entry:

https://youtu.be/I0tqgGVQkew

steventhedev··on Vibe coding and agentic engineering are getting closer than I'd like
The dirty secret if you work inside BigCorp and look around at the projects they're showcasing:

1. They're low stakes to get wrong.

2. The most common is MCPs or similar ai-tooling.

3. Making them look good takes time and effort still. It's a multiplier, not a replacement.

4. Quality and maintainability require investment. I had to restart an agentic project several times because it painted itself into a corner.

steventhedev··on Why One Key Shouldn't Rule Them All: Threshold Signatures for the Rest of Us
The entire point of this is that the complexity is encapsulated on the signing side - not the verifier. So it's more that you would split the keys between systems you control - say the reverse proxy and the application server.

Or one that's checked into your version control (representing that it is your company's code that's running) and one that lives on the server (representing that it is a server your company controls).

Or to take your example - a key in the repo, a key from the dev, and a key from the build server.

steventhedev··on Spyware maker NSO Group confirms acquisition by US investors
More like a failure on TechCrunch. There is an implied agreement and violating it will result in a flat refusal to talk outside of prepared press releases.

This isn't good journalism and should not be celebrated.

steventhedev··on The "Wage Level" Mirage: H-1B proposal could help outsourcers and hurt US talent
Reading through that I stand corrected. Thank you for sharing a link.

At the same time, if a US person applies and is similarly qualified, they must be offered the job.

Which is trivially abuseable by offering substantially less for the H-1B position. I'm not sure if there's an easy policy solution for that.

steventhedev··on The "Wage Level" Mirage: H-1B proposal could help outsourcers and hurt US talent
No.

The H1-B visa is intended for bringing specific technical expertise that does not exist in the US for a set period of time. This is why one of the requirements is that you must have interviewed US persons first. Its the same reason it's a nonimmigration visa.

The rampant abuse of the visa has a remedy - criminal charges against the HR directors of any company who is found to have committed fraud, and capping the number of visas per company (setting up many shell companies is a strong signal that fraud is being committed).

If an H1-B worker can't negotiate on a global level for their expertise - they should not be on that visa.

steventhedev··on %CPU utilization is a lie
%cpu is misleading at best, and should largely be considered harmful.

System load is well defined, matches user expectations, and covers several edge cases (auditd going crazy, broken CPU timers, etc).

steventhedev··on SQLite offline sync for Android quick start
Elastic license, so many people refer to this as source available rather than open source
steventhedev··on Realizing we needed two sorts of alerts for our temperature monitoring
Temperature sensors are a great example for alerting because they fluctuate constantly, have multiple seasonalities, and failures can be subtle. In the end, you'll want:

1. If the sensor dies and there is no data at all

2. If the sensor gets stuck (giving same value)

3. If the sensor slowly drifts (adjusting for daily, weekly, and yearly seasons) - indicating a clogged filter or leaking refrigerant

4. Statistical spikes - this is the hardest to tune so you need to treat it as a model that detects anomalies and it takes a long time to label extremely rare events

5. Static thresholds, over varying windows to deal with sensor error and transient spikes.

It also raises questions like "if the sensor is reporting 400C then either the building is on fire or the sensor is broken", or "how do we get the alert if the building is indeed on fire" and the inevitable followup: do we even need to get an alert if the building is on literal fire?

steventhedev··on TikZJax: Embedding LaTeX Drawings in HTML
I'm fond of using KaTeX for my personal blog posts. There is support for server side rendering for KaTeX (but not on GitHub pages because it necessarily opens it to arbitrary code execution - I asked).

But it notably lacks tikz support and if it can emit SVGs I'm beginning to wonder why I even use KaTeX and not something like this (beyond my personal anti-JS sentiment)

steventhedev··on Show HN: JuryNow – Get an anonymous instant verdict from 12 real people
Why not juries of 13 people? That way you never have a clean tie?
steventhedev··on The effect of deactivating Facebook and Instagram on users' emotional state
It means that there is a statistically significant improvement, but that improvement is tiny, and will not make you happier than your peers all by itself (assuming a standard peer group of 200 people - you'd likely swap places with 1 or 2 people).

Of course, this study only considered normative people, not marginalized or those who were experiencing active harm from exposure to social media - your personal results may vary and it's important to remember that science is imperfect and social sciences are doubly so.

If going off Facebook improves your life - you do you.

steventhedev··on TikZJax: Embedding LaTeX Drawings in HTML
Apparently there are some forks that offer more features and fix some of those bugs. Maybe one of those can help you?

This is the one that was shared on lobsters, but there are likely more: https://bill-ion.github.io/tikzjax-live/

steventhedev··on TLS certificate lifetimes will officially reduce to 47 days
TLS chose the threat model that includes MITM - there's no good reason that should ever change. All I'm arguing is that having a middle ground between http and https would prevent eavesdropping, and that investment elsewhere could have been used to mitigate the MITM attacks (to the benefit of all protocols, even those that don't offer confidentiality). Instead we got OpenSSL and the CA model with all it's warts.

More importantly - this debate gets raised in every single HN post related to TLS or CAs. Answering with a "my threat model is better than yours" or somehow that my threat model is incorrect is even more silly than offering a configuration of TLS without authenticity. Maybe if we had invested more effort in 801.x and IPSec then we would get those same guarantees that TLS offers, but for all traffic and for free everywhere with no need for CA shenanigans or shortening lifetimes. Maybe in that alternative world we would be arguing that nonrepudiation is a valuable property or not.

steventhedev··on TLS certificate lifetimes will officially reduce to 47 days
Yes. MITM attacks do happen in reality. But by their nature they require active participation which for practical purposes means leaving some sort of trail. More importantly is that by decoupling confidentionality from authenticity, you can easily prevent eavesdropping attacks at scale.

Which for some threat models is sufficiently good.

steventhedev··on TLS certificate lifetimes will officially reduce to 47 days
MITM attacks are common, but noisy - BGP hijacks are literally public to the internet by their nature. I believe that insisting on coupling confidentiality to authenticity is counterproductive and prevents the development of more sophisticated security models and network design.
steventhedev··on TLS certificate lifetimes will officially reduce to 47 days
There is a security model where MITM is not viable - and separating that specific threat from that of passive eavesdropping is incredibly useful.
steventhedev··on Zig's new LinkedList API (it's time to learn fieldParentPtr)
The generic version in TFA puts the data type allocated alongside the next pointer - no additional allocation needed. The only functional difference is if the zig compiler is not sufficiently advanced to understand it can reorder the fields (hence the alignment question).

The removal scenario is merely specifying that you are passing in ConnectionListNode instead of a Connection. Although maybe it's a good idea to think about how they compose comparatively.

steventhedev··on Zig's new LinkedList API (it's time to learn fieldParentPtr)
This feels like a net negative result. It removes some of the complexity of using generics, but it couples between the data type and the collections it can be indexed by.

What are the benefits of this approach? Is it limited to data alignment, or is it out of a greater desire to remove generics?

steventhedev··on Leaked data reveals Israeli govt campaign to remove pro-Palestine posts on Meta
At no point did submeta qualify their statement to only apply to former soldiers. Quite the rather - they removed the nuance that did exist in their quoted propaganda articles and made it explicitly based on national origin only.
steventhedev··on Leaked data reveals Israeli govt campaign to remove pro-Palestine posts on Meta
By that incredibly racist logic Meta should only hire born and bred Americans. How many Russians work at Meta? How many Palestinians?
steventhedev··on Google to buy Wiz for $32B
That is suspiciously equal to the "Other revenue" line in Meta's 10-K.

Given that likely rolls up other products I doubt it's all coming from Whatsapp.

[0]: https://d18rn0p25nwr6d.cloudfront.net/CIK-0001326801/1f8bf8e...

steventhedev··on Meta slashes staff stock awards as group embarks on AI spending drive
Same pipeline, but if it's a friend who wants to work with you then you have someone who is not in recruiting who you can ping for updates if the process gets stuck.

Depending on the company, there may even be referral bonuses so there's a financial incentive for your "insider" to follow up.

steventhedev··on Why is my CPU usage always 100%?
Aside from the technical beauty of this post, what is the practical impact of this?

Fan speeds should ideally be looking at temperature sensors, CPU idling is working albeit with interrupt waits as pointed out here. The only impact seems to be surprise that the CPU is working harder than it really is when looking at this number.

It's far better to look at the system load (which was 0.0 - already a strong hint this system is working below capacity). It has a formal definition (average waiting cpu task queue depth over 1, 5, 10 minutes) and succinctly captures the concept of "this machine is under load".

Many years ago, a coworker deployed a bad auditd config. CPU usage was below 10%, but system load was 20x the number of cores. We moved all our alerts to system load and used that instead.

steventhedev··on You can use C-Reduce for any language
It's intended to run for producing compiler test cases, so there shouldn't be any code that's actually running.

CPython includes a flag to only run parsing/compiling to bytecode. While you can use it like they did here and run the code - it really depends on how much you trust every possible subset of your code

steventhedev··on Creating a QR Code step by step
I took a code theory course in grad school. It was the most rigorous course I took, and for all of the 5 students it was difficult, but I'm also really glad I took it.

Reed Solomon was about two thirds of the way through the semester, and the gist is that it's based on polynomials - with enough points you can define exactly where the polynomial is - so include some extra points and that way if some get lost along the way you can recreate them.

The rest of it is how to apply that for binary data (finite fields). Which is mathematically beautiful, but where they get somewhat complex.

steventhedev··on Gemini AI tells the user to die
From reading through the transcript - it feels like the context window cut off when they asked it about emotional abuse and the model got stuck in a local minima of spitting out examples of abuse.
steventhedev··on A change of heart regarding employee metrics
There are a few exceptions to this, with varying degrees of justification:

1. An underperforming teammate when your personal rating is tied to team metrics. Which is a shit way to run a team.

2. You are a tech lead in a company where the career and level expectations are that you will assist in performance managing ICs on the team. Which is being a manager in all but name.

3. You truly care about the personal performance of these "slackers", which is a good sign that you want to be on the management track, but probably shouldn't be.

4. You have some strong external incentive like slackers directly impacting the values of your shares (and you own enough for it to make a difference)

5. You are a petty asshole.

I will never cease to be amazed how many people will fall into number 5 - but will insist they are doing it for other reasons.

steventhedev··on Where the Digital Sidewalk Ends
Why not bulk import this from your city/county/municipality GIS system?

Dunno about San Francisco city, but many will track sidewalks as part of maintenance management. Depending on how well organized they are, they might have additional features such as trees and street lighting.

steventhedev··on An n-ball Between n-balls
This is a really good demonstration of the curse of dimensionality[0]

[0]: https://en.m.wikipedia.org/wiki/Curse_of_dimensionality

Page 1 of 9Next →