HNHacker News
TopNewBestAskShowJobs

tgsovlerkhgsel

17,079 karma · joined December 26, 2015

all opinions are my own
submissionscomments
tgsovlerkhgsel··on Steam Frame starts at $1059
Quest 1, the built in native streaming, with a wired connection from the beefy desktop to a WiFi 5 AP on 5 GHz in a low noise environment worked sufficiently. I'd get at least a Quest 2 if you're getting something new (not sure if the 3 is better than the 2).
tgsovlerkhgsel··on Steam Frame starts at $1059
36 FPS makes running it on the device a rather theoretical possibility for a VR game.
tgsovlerkhgsel··on Why is Google still serving dodgy ads?
Google gets paid to show the ads.

Adding friction to the process (on the advertiser side) means less money for Google: 1) due to the cost of implementing the checking, 2) because some legitimate advertisers will be falsely denied, 3) because the scam ads were still paying money.

Not adding the friction doesn't seem to come with any serious downside. One would expect that it would, e.g. due to publishers removing the most profitable properties from the ad network or governments legislating this out of existence, but that doesn't seem to happen.

So, given these incentives, the outcome is inevitable.

If Google had to pay a massive fine for every scam ad that gets through, or was liable for the damages the ads cause, etc. - or otherwise had a strong incentive - suddenly there would be enough resources to make sure every ad is reviewed, advertisers that push scam ads get fully banned on the first offense rather than being given second, third, and fourth chances, etc.

tgsovlerkhgsel··on google.com/goto: Google's anti-scraping update
The biggest problem with this is if the target URL doesn't load but also doesn't quickly error out, like e.g. many .gov sites in Europe (seems like they are just dropping traffic from non-US IPs).

Now you can't load the page and can't easily (using only the browser UI) get a link to paste into archive.org or archive.is to read the page.

tgsovlerkhgsel··on google.com/goto: Google's anti-scraping update
"Figuring it out" doesn't help if it's encrypted with a key only Google holds or a reference to some database record that you don't have. In either case, the only way to resolve this is to ask Google, which means they can track it as a click (and rate limit etc.).
tgsovlerkhgsel··on NTSB issues investigative update on B-767 runway excursion accident in Miami
> But they made the wrong choices at all of those points.

This tends to be something we see in most incidents, because the cases where someone makes the right choice at one of the points tend to not become incidents.

An interesting thought is that the more obviously bad/incompetent/terrible decisions or (in)actions were involved in an incident, the better it is, because it means more things had to go wrong for a disaster to occur (more slices of cheese in the Swiss Cheese model).

tgsovlerkhgsel··on Growing proof that autonomous cars save lives
The giant spot of land could be in a much less convenient (= valuable) location if the car can take itself to and from there.
tgsovlerkhgsel··on Copyright does more harm than good and should be abolished
> free

That's the key difference.

The fact that it's illegal limits large scale commercial exploitation, leaving enough room for legitimate distribution that pays the author.

With no copyright whatsoever, there would be a well-organized company with a better marketing department selling their version of your work, taking all the profit, and making it impossible to actually sell it yourself.

tgsovlerkhgsel··on I've factored the RSA keys of a Certificate Authority from the 90s
> which governments around the world are just waiting to crack anonymous political speech by recording and saving for later

Probably not too many, because anonymous political speech from 10+ years ago isn't that interesting. Punishing people a decade after the fact isn't very effective for anything.

tgsovlerkhgsel··on GrapheneOS Overhauled Default Apps and Secure Clipboard
Which of my banking apps are running on any of these?
tgsovlerkhgsel··on GrapheneOS Overhauled Default Apps and Secure Clipboard
IE was a web browser. Breaking it was a matter of making a web browser good and compatible enough.

It's a completely different situation here.

tgsovlerkhgsel··on GrapheneOS Overhauled Default Apps and Secure Clipboard
There is no alternative.

Apple isn't going to let them build on top of iOS, and anything except those two is dead in the water because it'll never have users because it is missing a bunch of critical apps, and will never have those apps because it doesn't have users.

tgsovlerkhgsel··on Statichost.eu – European static site hosting
In this case, it's less "proudly made in USA" and more "will likely remain available and legal to use for EU companies, even if the conflict between Trump and the rest of the world escalates"
tgsovlerkhgsel··on Cloud in a Bottle: making self-hosting accessible to everyone
Ruby/RoR doesn't really solve the e.g. monitoring problem, does it?

My goal is something that would work for startups that plan to grow beyond a single person/single server project. If you build the architecture for a too small size, you start running into walls as soon as you exceed that size.

But even if you are small, you probably want some kind of Grafana/Prometheus monitoring to tell you what's breaking. You want your framework pre-wired so it automatically reports data (e.g. requests/failures per service) without you having to set it up, because it it isn't automatic, you probably won't get around to setting it up until it's too late. You also want some kind of build system, CI/CD to handle deployment. An easy way to set up staging environments would be nice. If you don't want to use a hosted forge, then a self-hosted forge connected into all this.

My idea is to have one somewhat commonly adopted stack, where most of the stack "self-deploys" so you don't have to set up, connect, and coddle all of these services. If you want to deploy something within the stack, you're somewhat limited because you have to do it "the stack's way", but in exchange, once you've set it up, adding a staging environment consists of not actively disabling the default staging environment that the stack would set up for you otherwise, and once you've deployed your service, it's already pre-wired into your monitoring.

Popular packages would then over time likely get packaged for this stack, with service-specific monitoring exports (e.g. the postgres container could export query details rather than just the default-collected values like CPU usage and requests-through-the-standardized-RPC-framework).

tgsovlerkhgsel··on Site Is Closed on Sundays
Nothing compared to the crowds on Sunday in the few stores that are allowed to open because they're e.g. inside a train station or otherwise exempt.
tgsovlerkhgsel··on Cloud in a Bottle: making self-hosting accessible to everyone
This is a great idea and I wish it success. Self-hosting shouldn't be a nightmare of researching and setting up 20 different applications.

Is there something similar in progress for a "tech company tech stack"? As in, rather than trying to assemble your own custom infrastructure by finding an RPC system, permissions/group manager, credential management, storage, database, service discovery, job management, monitoring etc. one "opinionated" stack that you can easily deploy, as long as you're OK accepting their choices, with all these parts already bundled and wired up.

tgsovlerkhgsel··on You Don't Have a Right to Safe Drinking Water, US Court Rules
Generally, I've seen courts derive this kind of right from general rights like "the state cannot just arbitrarily kill or maim you", which (hopefully) are explicitly written down. So it doesn't feel that unreasonable to ask the court to specify that "the state cannot just arbitrarily kill or maim you" extends to "the state cannot arbitrarily lie to you in ways that will endanger your life/health".
tgsovlerkhgsel··on Site Is Closed on Sundays
You should interact with government sites more. I'm sure you'll love it when you finally found the time and motivation to do something about the bureaucratic task you've been procrastinating for weeks and then get told that the web site is currently closed.

https://dafyddvaughan.uk/blog/2025/why-some-dvla-digital-ser...

tgsovlerkhgsel··on Play GTA Vice City in the Browser
Unless they've gotten a license to do it, it's a crystal clear copyright violation, generally done under the assumption/hope that an entity that has abandoned selling the game has also abandoned caring about enforcing its copyrights against such projects.
tgsovlerkhgsel··on Statichost.eu – European static site hosting
I would be in the market for Europe-based static hosting and am glad that more European services are popping up, but this has one massive drawback: Unpredictable cost (unless you manually set a limit with support, then it presumably changes into unpredictable availability). With everyone moaning about AI crawlers I have no idea how far 10 or 500 GB bandwidth go nowadays, and I don't want to need to know.

At all-inkl.com (no affiliation except being a happy customer) I pay something like 8 EUR to get "unlimited" bandwidth (I'm sure if my site caused a problem I'd hear about it, but I can be sure that there won't be surprise bills, and I know I don't have to worry about "background noise"), static hosting, dynamic and database (which I don't use) hosting, and 5 domains included which makes the net cost of the hosting nearly free.

tgsovlerkhgsel··on FBI Probes Service Selling 153M+ Drivers Licenses
The fine doesn't have to be higher than the company's profit to matter. If it's bigger than the profit from keeping the data and significant enough to warrant allocating resources to care about it (tens of millions might be enough here), they'll have a small team work on data minimization not because it's the right thing to do, but because it's the cheap thing to do.
tgsovlerkhgsel··on FBI Probes Service Selling 153M+ Drivers Licenses
If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold.

Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.

tgsovlerkhgsel··on FBI Probes Service Selling 153M+ Drivers Licenses
Hertz or the company Hertz uses
tgsovlerkhgsel··on Google Has Removed MV2 Extensions from the Chrome Web Store, Including UBO
No one will invest even after Android is closed.

The Android/iPhone duopoly is nearly impossible to break because very few people want to carry two personal phones, and it takes only one app that they can't do without being only available on Android/iPhone to make it impossible to choose anything else. The app providers likewise have no incentive to support anything else because everyone has one of these two.

Bank apps are the prime example here that's unlikely to start supporting other systems. Public transit (and in some places parking) is another potential problem where even the unhinged "well just change banks to the one that does support your favorite phone" argument fails. ID apps (either governmental or de facto standards like the Swedish BankID) are coming too.

tgsovlerkhgsel··on I think the military commissary's freezers were hacked
Even if it isn't an attack, you demonstrated how it could be one. The vulnerability is likely there and worth mitigating. Excellent investigation and write-up!
tgsovlerkhgsel··on I think the military commissary's freezers were hacked
Or someone somehow got into one web interface (e.g. by popping a random workstation used to monitor all these sites) and clicked buttons.
tgsovlerkhgsel··on I think the military commissary's freezers were hacked
Running certbot on your web server is easy.

Running certbot on a random PLC isn't happening.

tgsovlerkhgsel··on I think the military commissary's freezers were hacked
My guess would be something like the CA using some feature that was newer than what the equipment would support (e.g. ECC signatures but the equipment only supporting RSA), not an intentional "no real CAs" decision.
tgsovlerkhgsel··on I think the military commissary's freezers were hacked
The Osprey is air refuelable though, isn't it? Each flight is roughly one pound per person on board.

It's also roughly 2800 nautical miles from Kuwait to Diego Garcia, so regardless of where the carrier group is, it should be at most a ~6 day round trip at 20 knots for a supply ship from the closest of the two.

That assumes there is no way to airdrop watertight pallets of food (e.g. steel drums loaded with cans and MREs) into the water, then retrieve it with RHIBs or helicopters.

tgsovlerkhgsel··on Google Has Removed MV2 Extensions from the Chrome Web Store, Including UBO
If a scam ad is found, at the very least, require them to disclose business records to show how much money the scam ad made (revenue, not profit), and make them repay it. Leave it up to the platform whether to recoup the paid-out share from the publisher or not.

If they are caught doing it repeatedly without taking adequate measures to stop it, treat them as an accessory to the crime.

← PreviousPage 2 of 34Next →