HNHacker News
TopNewBestAskShowJobs

thequux

569 karma · joined March 24, 2009

submissionscomments
thequux··on Needed 1+1, built a functional programming language
In my experience, it depends. 99% of the time, malloc/free is your best bet: fast enough, battle-tested, everything already uses it, etc.

In the 1%, though, you'll have needs that malloc/free don't fit. Complex object graphs don't really have a single point of ownership or requiring that you free something in all the places that it might be released is too much to handle. In this case you can reach for a garbage collector (including, for example, implementing reference counting). Other times, you may need to make a lot of allocations in a short time where they can all be freed at once. Request processing in a network server is a common example of this: once the request is complete, everything allocated can be dropped, and you generally want minimal latency.

All of this comes with tradeoffs, though. With a GC, you lose predictability and performance changes; sometimes for the better and sometimes for the worse. Depending on the GC, you may not be able to have stable pointers, and you may lose the ability to finalize objects. With an arena, you can't free or reallocate, so you need to scope the arena to a small region of execution (this is where the author went wrong, for example).

Finally, regardless of which approach you use, you're going to need to thread the allocator through the application; probably implement your own datastructures, etc. Depending on how complex your memory management model is, you may need more than one allocator at any given point (e.g., a GC for the persistent data and an arena per connection and per request). If you're implementing your own allocator, you'll also likely have bugs, and allocator bugs tend to be insidious and obnoxious to debug.

If you can avoid going down that route, I recommend it. Sometimes, though, you have enough constraints that you need to brave the jungle.

thequux··on The Alpha 21264 CPU: NT's Greatest RISC (1998)
Itanium has well over a kilobyte of general-purpose registers. That's lovely for single-process performance, but it absolutely slaughtered context switch time given the available memory bandwidth at the time. On top of that, it was fiendishly difficult to actually find instructions that could fill the instruction stream, and thus i-cache utilization was a disaster. On top of all of that, it exposed far too much microarchitecture to userspace: it would forever be pinned to having three execution ports with very specific capabilities, and any changes to the µarch would have resulted in all of the complicated register rename and instruction scheduling hardware that VLIW was supposed to avoid.

I'll grant that it seemed like a decent idea at the time, but there was enough risk there that I can only describe Intel's all-in stance on Itanium to have been a blunder.

(There's a worthwhile distinction to be made between a blunder and a mistake. Mistakes are calculated risks that don't pan out, whereas a blunders is something that should have been obvious that it would go poorly when the decision was made. Losing your savings in the stock market from a surprise dip is a mistake. Losing your savings by betting it all on 14 in Vegas is a blunder. Similarly, the design of Itanium was a mistake. Betting the company on it was a blunder.)

thequux··on Writing by hand is good for your brain
Don't underestimate the importance of a pen, ink, and paper you like. I found my pen a decade ago: Lamy Studio, in British Racing Green, with a medium nib. I found my ink not long after, from J Herbin's collection.

It wasn't until I got a nice notebook from Leuchtturm 1917, though, that the ensemble came together and I started looking for excuses to get my kit out and write things down. Since then, I've moved onto notebooks from de Kempen, but the point stands

thequux··on Chopped, Stored, Secured – The Story of the Hash Function
I can't judge the veracity of the history of hash functions, but the moment it starts talking about cryptography it goes completely off the rails: it seems to indicate that finite field exponentiation o'r high degree polynomials are used in cryptographic hash functions; they are emphatically not. It presents password hashing as just applying a suggest function to the password; in practice a KDF is used, which is a completely different design space (for a start, KDFs have a tweak parameter, usually called a salt in this context). Finally, there's a haven't reference to quantum computers breaking hash functions and needing post-quantum algorithms as a result. This does brush with reality in that Grover's algorithm does theoretically eat half the first preimage resistance security level of your hash function, but even SHA256 will require 2^128 iterations on a quantum computer, which will likely never be feasible. Worse, it doesn't help at all in attacks against second perimeter resistance or collision resistance.

Considering that everything I have personal knowledge of here is obviously bunk, best ignore the rest of it too

thequux··on Linux gaming is faster because Windows APIs are becoming Linux kernel features
It's been a long time since I've touched any of this, so the details have slipped my mind. However, the general idea was that there were two different exit calls in DOS: terminate and terminate and stay resident. The difference between the two is that the stay resident option wouldn't release the memory used by your application. Further, the interrupt table, which told the processor how to handle each interrupt, was in RAM and therefore writable.

So, what TSRs would do is overwrite one or more interrupts to point to a routine that would check if the system call in question was one it wanted to handle (eg, to add a hotkey it would grab the keyboard handler and check for a special set of keys before passing control back to the normal handler). Once that was fine, it would call the TSR system call and control would be passed back to the OS with the hook still in place

thequux··on dBase: 1979-2026
How do you feel about ADD 5 TO X GIVING X?

I kid, of course, but "X is x + 5" brings Prolog to mind with all the unification and bidirectionality that implies.

thequux··on Anna's Archive loses $322M Spotify piracy case without a fight
> So I think the following is IMO by far the biggest problem, no matter one's personal opinion: > > "Rakoff entered a permanent worldwide injunction covering ten Anna’s Archive domains: annas-archive.org, .li, .se, .in, .pm, .gl, .ch, .pk, .gd, and .vg."

Legally speaking, the Southern District of New York can say whatever it likes, and Libera, Sweden, India, St-Pierre-et-Miquelon, Greenland, Switzerland, Pakistan, Grenada, and the British Virgin Islands are free to ignore what the US says. They all have national sovereignty over their respective ccTLDs, and of them, most are not going to simply accept the US telling them what to do considering recent geopolitical missteps.

thequux··on How to turn anything into a router
NixOS using https://github.com/thequux/nix-zone-firewall/ worked well for me for many years. I only stopped using it because my poor embedded Linux machine started having issues and it made more sense to go with a Mikrotik than to buy a new device to run as a soft router.
thequux··on Microsoft mishandling example.com
$227k just to apply, and another few hundred thousand in legal, compliance, and contracting to reach delegation.

Source: I'm on the board of dotMeow and wrote the financial plan

thequux··on DotMeow – A fun domain with a serious mission
Hi! I'm one of the founders of dotMeow, and it's been a long road to get to the point that we're willing to stake our reputations on a crowdfunding campaign. From applying to the applicant support program (we believe we were one of the first, if not the first organization accepted) to working out financial plans and overall strategy to achieve NIS2 compliance on a shoestring budget, it's been a year and a half of effort to reach where we are now.

It's quite late here in Belgium, so I'm about to go to sleep, but in the morning, I'll happily answer any questions people have about the project.

thequux··on DotMeow – A fun domain with a serious mission
Do catgirls count? We've got one or two on staff. We'd have a cat, too, if it weren't for the fact that I'm allergic.
thequux··on DotMeow – A fun domain with a serious mission
The sad thing is, this is one of the rhetorical flourishes that gets drilled into you in debate and comms education. ChatGPT picked it up because it's extremely common.
thequux··on DotMeow – A fun domain with a serious mission
A few people have called us on this, but it's simply not true. The copy was all written by hand; the only machine assistance here is XCompose (you, too, can type an em-dash!).

It turns out that when everybody involved is some level of techie and you're targeting a sort of "corporate bland" tone so that you look professional and trustworthy by modeling your communications on other successful kickstarters, it comes out looking similar to what other marketing copy looks like, which is precisely what all of the LLMs were trained on.

thequux··on The Connectivity Standards Alliance Announces Zigbee 4.0 and Suzi
As much as I dislike mandatory certification, I can understand the need for it in wireless battery powered devices: a malfunctioning decide can talk the battery life if everything within range, and most consumers aren't equipped to realize that this is happening much less identify the device that's causing the problem

Perhaps the solution is to make the spec open but make using the trademark contingent on certification (much like USB, for example)

thequux··on JMAP for Calendars, Contacts and Files Now in Stalwart
Ehh, not really. OSI layer 5 was responsible for managing multiple non-overlapping sessions within a single transport stream, and routing those sessions to specific applications. This is precisely what HTTP/1.1 did (though the accept, content-type, accept-encoding, and transfer-encoding headers are really an implementation of layer 6); QUIC, on the other hand, covers the same layers that TCP does (3-5) plus the aforementioned layer 6.

I recommend actually reading X.200 (the specification of the OSI model) at some point: it's quite approachable (especially for an ITU spec, which are notoriously dense reading), and will quickly make you realize how silly it is that we still use it as a reference for modern stacks.

thequux··on Replacing a $3000/mo Heroku bill with a $55/mo server
In that case, you don't want cloud; you want an MSP, whose core competence is running those IT services. They, in turn, have the skills to colo a rack at a DC or to manage rented servers, amortized across a number of clients.

In practice, there are two situations where cloud makes sense:

1. You infrequently need to handle traffic that unpredictably bursts to a large multiple of your baseline. (Consider: you can over provision your baseline infrastructure by an order of magnitude before you reach cloud costs) 2. Your organization is dysfunctional in a way that makes provisioning resources extremely difficult but cloud can provide an end run around that dysfunction.

Note that both situations are quite rare. most industries that handle that sort of large burst are very predictable: event management know when a client will be large and provision ticket sales infra accordingly, e-commerce knows when the big sale days will be, and so on. In the second case, whatever organizational dysfunction caused the cloud to be appealing will likely wrap itself around the cloud initiative as well.

thequux··on IDEs we had 30 years ago and lost (2023)
I recall reading somewhere that the entire point of solitaire (at least the original implementation that came with windows 3) was to teach users how to click and drag, so I'm not surprised that it was good for teaching your colleague how to use a mouse
thequux··on Ask HN: Abandoned/dead projects you think died before their time and why?
OSI's session layer did very little more than TCP/UDP port numbers; in the OSI model you would open a connection to a machine, then use that connection to open a session to a particular application.

X.400 was a nice idea, but the ideal of having a single global directory predates security. I can understand why it never happened

On X.509, the spec spends two chapters on attribute certificates, which I've never seen used in the wild. It's a shame; identity certificates do a terrible job at authentication

thequux··on The Buchstabenmuseum Berlin is closing
Alas, the market can remain irrational longer than I can remain solvent.
thequux··on Athlon 64: How AMD turned the tables on Intel
Years ago, I had a CD marked "Windows 2000 for Alpha RC1", which suggests that it was cancelled quite late in the release cycle.
thequux··on From Rust to reality: The hidden journey of fetch_max
I think that this can change the semantics though; with the preceding check you can miss the shared variable being decremented from another thread. In some cases, such as if the shared value is monotonic, this is done, but not in the general case.
thequux··on Reverse proxy deep dive
If you actually read ITU T-REC X.200, which specifies the OSI model, you'll find that it doesn't match the modern internet at all. E.g., we don't have an OSI-style transport protocol at all (connections themselves aren't addressable independent of the SSAPs), TCP and UDP are actually layer 5, the presentation layer is protocol-specific, and pretty much the entire stack falls to bits if the network layer isn't packet switched.

There's a separate term for the bits of the OSI model that are actually relevant; it's called the IETF model.

thequux··on Infinite Mac OS X
There was an ISA I saw a while back that featured an "enhanced multiply and accumulate signed" instruction, which of course got the mnemonic "EMACS"
thequux··on How the BIC Cristal ballpoint pen became ubiquitous
I second your recommendation for trying fountain pens. I suffer from some form of arthritis, and fountain pens let me write again.

There are a variety of cheap ones available; I'm fond of the Platinum Preppy. They're cheap as chips, write nicely, and have a fine version that actually lives up to its name. The Lamy Safari is also popular, but I found it too chunky to be comfortable.

thequux··on Show HN: Qrkey – Offline private key backup on paper
Many barcode scanners these days can scan QR codes. I have a NetumScan NSL5 that I got for €30 or so that can handle QR, DataMatrix, and even Aztec codes.
thequux··on A manager is not your best friend
What this misses is that, in a properly-functioning organization, a team that reliably delivers gets a bigger pie to divvy up. If your organization isn't like this, then perhaps you should consider finding a new one.
thequux··on Ditching Obsidian and building my own
Set the AllowedIPs wireguard setting (and/or the route, if you can set that separately) to one larger than your home network (i.e., if your home network is 192.168.1.0/24, use 192.168.0.0/23). Then, block wireguard packets from the internal network on your router. Then the tunnel will always be running; it just won't be used when you're at home because there's a more specific route
thequux··on Dotless Domains
I know that Len Sassaman had r@ai for quite some time, so your friend didn't have the absolute shortest address. Still a cool one though
thequux··on Ghost students are creating problems for California colleges
The US does identity verification by asking for a driver's license (which has no chip or biometric data) and possibly a series of questions about your past drawn from public data. All of these credentials are laughably easy to spoof. Compare this to Europe, where every resident has an eID containing a keypair and X.509 certificate signed by the government containing their personal details. It is trivial to check the validity of these cards and nearly impossible to forge without subverting either the national PKI or printing apparatus
thequux··on Espressif's ESP32-C5 Is Now in Mass Production
The USB HID protocol is designed to support basically any device that regularly reports a set of values; those values can represent which keys are pressed, how a mouse has moved, how a joystick is positioned, etc. Now, different devices have different things that they support: joysticks have varying numbers of axes, mice have different sets of buttons, some keyboards have dials on them, etc. So, there's no single format for a report that simultaneously efficiently uses bandwidth and supports all the things a human interface device might do. To solve this, the HID protocol specifies that the host can request a "report descriptor" that specifies the format and meaning of the status reports. This is great for complex devices running a full OS; there's plenty of memory and processing power to handle those varying formats. However, these HID devices needed to also work in very limited environments: a real mode BIOS, microcontroller, etc. So, for certain classes of device such as keyboards and mice, there is a standard but limited report format called the "boot protocol". IIRC, the keyboard version has space to list 6 keys that are pressed simultaneously (plus modifiers), all of which must be from the same table of keys in the spec, and the mouse has an dX and dY field plus a bitfield for up to 8 buttons (four of which are the various ways you can scroll). To implement a more complex device, you'd want to be able to specify your own report format, which the ESP driver doesn't seem to allow you to do.
Page 1 of 7Next →