HNHacker News
TopNewBestAskShowJobs

tarpitt

82 karma · joined May 31, 2026

submissionscomments
tarpitt··on One Piece of Flock Camera Data Put This Innocent Woman in Jail for 13 Days
and yet, without the camera this woman would not have been arrested.

The problem is the police-camera system, of which the camera is an instrumental component

tarpitt··on How we learned to stop worrying and love campus surveillance
For taking down power infrastructure? EMPs will be ineffective against cameras but extremely effective against transmission lines
tarpitt··on How we learned to stop worrying and love campus surveillance
I can't help but notice that the cameras emerged on campus around the same time that our generation gained an israel-concious politic and israel-gaza protests started.

Edit: I realize this sounds very conspiratorial and hand-wavey but this is my just my personal anecdote from University of Florida, that the cameras showed up with the protests. There is probably more to university poltics than I am aware of, but my impression is that there is signifigant corruption and adminstrative bloat. A major aspect of college protests was funding wrt Israel. Not that all of my experiences with college have been negative, but I leave with the impression there is something strange in the university system at large.

tarpitt··on People hate Flock so much its employees are now demoralized and quitting
good enough
tarpitt··on Creepy Crawlies
Maybe you could have a system that heuristicially detects when an crawler is making the request and then feeds them a modified page, itself generated from an LLM, that injects vulnerabilities and bad code and discussion and such.
tarpitt··on The turbulent AI era is here
You and what army? Killbots, mow down these protesters. Too late
tarpitt··on Outrunning Democracy
terrible blog, wants me to sign up to read the full article, then their email redirects me to download their app.
tarpitt··on Nitter and XCancel receive cease and desist notices
nitter.rdrama.net is still up
tarpitt··on Amazon Is Creating the Biggest Pollution Source in the Country
the benefits of unemployment
tarpitt··on Gentoo bugzilla closed due AI bot scraper overload
the problem with lightning is:

1) it requires you to open a lightning channel. So you need some amount of initial investment (which usually means you need a credit card and an account on a bitcoin exchange), not just any computer which is the issue that using mining shares solves. The initial investment is my main grudge, as it is way too much friction for 402 Payment Required applications. Also as bitcoiners like sztorc note, this isn't feasible for most of the world's population due to bitcoin's small block size.

2) It's not private. People are going to be linking these things to their identities on crypto exchanges. So now feds can basicially track everything you do on the internet that way. LN is only private in the sense that not every transaction is broadcast to everyone else on the network, which is a very low bar. Chainalysis is possible with the right connections.

To a lesser extent, 3) Centralization in the lightning routing protocol which contributes to the effect of #2.

tarpitt··on Gentoo bugzilla closed due AI bot scraper overload
With micropayments, the server owner makes 1 million requests times 0.05 cents = ~$500

The status quo with those js PoW pages doesn't really benefit the server owner at all, it's wasted energy.

I mean proof of work is always wasted energy, but I figure it's better to kill two birds with one stone.

CoinHive was one example of this. (I think this is a correct link? https://github.com/cazala/coin-hive). Although I think ideally you would want to have some sort of browser plugin or app that runs on bare metal instead of a proof-of-work in the browser, because RandomX is designed such that it's slow when implemented in JS (https://github.com/tevador/RandomX/blob/master/doc/design.md)

tarpitt··on Gentoo bugzilla closed due AI bot scraper overload
Something like Chaum's blind-signature based ecash, or GNU Taler would be ideal in terms of efficiency, but it's still centralized in distribution. Freenet currently uses something like this.

Another option I was thinking of would be a pretty inflationary (or demurrage) cryptocurrency in which you have some sort of RandomX or other CPU-bound PoW. A web server could act as a mining pool and use mining shares interchangibly with micropayments.

You could do this mining-share method with Monero right now, it's just that you have higher transaction size in Monero and no real analogue to Bitcoin's LN-based microtransactions. Also you would want the cryptocurrency to be more inflationary (or demurrage-based) to promote usage.

Monero's FCMP++ lays some groundwork for payment channels, but it still lacks the nessisary timelocks. Also there was DLSAG which could have enabled payment channels I think, but it's no longer relevant. I also insist that you would need to change the tokenomics to favor greater inflation (maybe you could make coinbase scale linearly with hashrate?), otherwise the miner reward would be economicially insufficient.

tarpitt··on Using ThinkPad T480 as a mobile phone
I have been following this one for a while, but I have never seen anyone report on its status in linux.
tarpitt··on Using ThinkPad T480 as a mobile phone
Plug in an EG25-G USB module. It has good driver suppport on linux as this is the same modem that's in the pinephone. About $60 plus the antennas. It also gives you GPS.

I'm actually working on this right now. I made a case for the module + antennas if you want.

EDIT: oops I hadn't read the article yet LOL. But the wisdom about the USB module still applies. There are also adapters for mpcie or m.2 or whatever modules to convert them to USB modules. Also you probably want to have a module or adapter with a sim card tray.

I bought mine off of aliexpress and also bought the LTE antennas. You need a separate antenna for GPS as well.

Lastly, with some of these adapters, the sim card goes in backwards relative to how you normally think it goes in. This had me stuck for a couple hours.

tarpitt··on GrapheneOS protections against data extraction from locked devices
What if the supplier backdoors the secure element? It would be better to just encourage the user to use a high-entropy key, and not bother with the secure element at all.
tarpitt··on GrapheneOS protections against data extraction from locked devices
If you're that much of a coward, you won't get hit by a wrench anyways because you will give your keys up immediately. But you will force your enemy to exert additional effort.

It works for the same reason locks on houses work against cops or criminals, despite the existence of lockpicking and locksmiths. There are various layers of physical security, and while no layer can prevent an attack absolutely they each increase the cost of an attack.

The system is only as secure as it's weakest layer.

So in a mixed information/physical system like a smartphone why should we allow the weak point to be the information system? To improve the information system we need only to rewrite the software, so the per-unit cost is nothing in the large.

tarpitt··on GrapheneOS protections against data extraction from locked devices
The wrench attack is still far weaker than a push-button attack.

In the wrench attack you are aware that you have been attacked, and you're aware of what data the attacker gains.

Additionally there are schemes like deniable encryption which can mitigate the outcomes of such an attack or serve as a red herring.

Furthermore it's dependent on physical intimidation which is expensive to scale and can be met with your own physical intimidation. In order for a wrench attack to scale to an entire society you have to send the gestapo to everyone's house whereas push-button attacks scale by default unbenownst to the victims and enable more nefarious systems to be built on top of them. In the USA this would mean interrogating some well armed citizens.

Lastly, you aren't forced to give up the key by any means. They can torture you to death and there is nothing they can do if you don't want to give up the key. There are some secrets in the game of love and war that are worth taking to - it's why spies are equipped with cyanide pills.

tarpitt··on Android may soon restrict on-device ADB
I'm more curious to see how the second ammendment could factor into this.
tarpitt··on Claude Opus 5
You are going to be fed feet-first into a woodchipper, but don't worry about it just smoke some weed and chill out. Live, Laugh, Love that's what I always say
tarpitt··on Claude Opus 5
Can't wait for the barista and wicker basket based economy. Although personally I just make coffee at home, so I have no need for a barista with a PhD in neurosurgery to make it for me.

Plus it just takes too much time to go to starbucks, especially with all the starbucks job applications I will need to fill out if I want a chance of getting a job.

tarpitt··on Claude Opus 5
If your earning ability is eliminated due to AI and you can't survive off of welfare or savings there will not be much more to your life other than starving to death.
tarpitt··on Don't Take the Black Pill [video]
Okay, so you are saying that there may be a design flaw we just haven't seen yet, based on historical precedent. Which is a very weak argument, because you are just making the case for the possibility that you may be correct, and you are just pointing to a historical precedent.

Can you prove that there is no hash function that is not vulnerable? If anything man-made is vulnerable, then there cannot any invulnerable system. That is what you need to prove to win the argument. And if we can prove that any system is unbreakable, you are wrong.

tarpitt··on Codeberg Bans Cryptocurrency Projects
I didn't say it violated the first ammendment. I said it violated the principle of free speech. It's the same principle that justifies your ability to post in this discussion here, right now, despite the fact that you don't believe in it yourself.

Maybe we should campaign to ban all left-wing aligned projects from all major git hosting services. No big deal right? After all they can just go somewhere else. No, clearly this is not reasonable. But I say this to demonstrate that your ability operate in society at large depends on the same principle of free speech that you do not extend to others.

tarpitt··on Codeberg Bans Cryptocurrency Projects
That money had to have come from somewhere, whether it was taxpayers or individuals. What if I donated? Is it cool to just roll over and allow political groups to hijack a previously neutral service?

Also there are other projects hosted there, and network effects involved.

tarpitt··on Show HN: Watch bots interact with an SSH honeypot in real time
reminds me of https://xkcd.com/350/
tarpitt··on Pseudpocalypse
It takes many bits to identify an individual.

Let's say I offhandedly mention your email in this comment, for example, like we had an out of band conversation somewhere else. Then, someone takes that email and links it to another forum where they find your phone number. Then another person looks up that phone number in a phone book. Then another person finds your github account from the email associated with your PGP and finds where you work etc. Let's say a comment you wrote 7 months ago vaguely mentions something about where you live, which in combination with the previous information narrows it down to a single place.

At what point does that become doxxing and who is responsible? Pseudonymous people nessisarially, slowly leak small amounts of information about themselves when on the internet in order to engage in communication.

It is only when you collect "enough" bits of information that it becomes threatening doxx.

You could say publishing this collection of facts is the doxx. But the point of the article is that stylometry and AI tools can do this investigation for you. Anyone can trivially assemble the collection themselves.

I think ultimately, it's a matter of personal responsibility. It has to be. If you have perfect opsec, I can't touch you AI tools or not. And if I have perfect opsec and I'm doxxing you, then no laws will be able to catch up to me.

tarpitt··on Pseudpocalypse
I don't have the ability to downvote, and I disagree that the downvote should be used, but I disagree with your disagreement about the downvote.

The proposal that seems to infringe on free speech, but mostly I take issue because there just isn't really a precedent for what such a thing would look like. What constitutes doxxing? It is easy to accidentally doxx someone by mentioning some offhand fact in conversation, because you may not know what series of facts can be connected to form a doxx. Typicially, people doxx themselves by accident, and someone else is merely pointing it out. I know I have many times. You live and learn.

There isn't really a right to privacy in the way that there's a right to free speech. Free speech is important to processes of public transparency and justice which I think this would interfere with. But it's also true that justice is blind and doxxing can interfere with a judicial process.

Also, if everyone is going to have access to super-stylometry tools in the future, which is the premise of the article that GP reacts to, it will be fruitless to uphold such a right because anyone can just run doxxyou.exe themselves. There's no need to spread doxx because it can be reproduced individually.

The term doxxing came from a certain hacker culture where it was implied that you connected some real-life identity to a criminal pseudonym. It essentially meant "snitching". So the idea that doxxing itself would be a crime is interesting. It's a reversal of the original meaning.

But it's also true that the public has discovered sybil-suseptible techniques (like swatting) where you can screw with ordinary people's lives by knowing their identity. Which is interesting because we live in a new culture of "share everything online" vs old the hacker ethos of "don't use your real name online". The attackers have become stronger and the defenders weaker.

tarpitt··on Pseudpocalypse
I wonder if this could be used to unmask satoshi. I remember a piece about applying stylometry to satoshi's writing, but they just compared him to the usual list of suspects (finney, back, etc.)
tarpitt··on Pseudpocalypse
I remember this! it got me pretty good. I have a bad habit of generating alts because I forget the password.

It makes me wonder if we could use non-instruct LLMs to slightly alter the wording of text while keeping the meaning the same meaning. Perhaps by using perplexity or some other metric. I don't know, maybe you compare the distance of the "meaning" vectors.

You might also want to have some "style" vector associated with each pseudonym. For example, I might want it to produce british english under a certain pseudonym, and simulate an ESL speaker under another.

Essentially, you would want some way of re-styling text. The basic way to do this would be to run the same sylometry tools the hunter uses and manually make synonym word/phrase subsitutions to lower your similarity.

It's a cat and mouse game, but I think the mouse eventually wins. Consider a program that translates your english writing programmaticially into a low-entropy symbolic form and then translates them back to english in a procedural manner. Basicially you design an intermediary language that cannot contain style. It would be boring to read but it would remove all the style.

tarpitt··on SpaceX wants to launch 100k more Starlink satellites for 100x the bandwidth
Eh, I've got 200mb/s fiber for cheap. It's pretty good and definitely bottlenecked by crowded wifi and upstream sources moreso than the ISP. Ethernet helps somewhat.

At the same time, I do kind of want more bandwidth just so I can download massive files like model weights quickly, host a web service out of my own house, seed torrents, etc. What might cryptocurrency look like if typical residential internet speeds were measured in gb/s? Perhaps bitcoin might be capable of more than 7 tps!

But to be fair, I am a nobody.

Page 1 of 3Next →