HNHacker News
TopNewBestAskShowJobs

throwaway2016a

5,903 karma · joined February 16, 2016

submissionscomments
throwaway2016a··on Certificate will expire on 14 March – update Firefox to prevent add-on breakage
The fact you not once in your reply acknowledge that certificate pinning and bundling trusted root CA public keys is actually common knowledge in desktop and mobile app community makes me thing you didn't even consider my reply.

I was simply explaining why for a desktop app pulling down the new certificate doesn't make sense because updating an app to update the pinned certificates is SOP for apps that use pinning.

> A strawman argument is where you attack a lesser flawed argument than what was said with the implication or claim that it is the same as the first. This wasn't a strawman argument, it was about exactly what was said despite the gymnastics needed to parse your statements.

No it literally was not. It was so much not what I said I wonder if you are replying to a completely different post. And rather than acknowledge you may have misinterpreted me, you are doubling down.

Also, that definition of straw man is wrong. It can also be -- as it is in this case -- attacking an argument the person never even made in the hopes it will bring the debate onto your terms.

But, I'm not attacking the straw man back, once again, at no point did I advocate for certificate pinning in open source apps nor make any comment on GPL or Mozilla.

My post was simply a statement on how to update apps that use certificate pinning. Reading any more into it than that is you injecting context that is not there.

Have a good day. My post is net positive votes now. I will not be replying to this conversation further.

throwaway2016a··on Certificate will expire on 14 March – update Firefox to prevent add-on breakage
While I appreciate your detailed answer it reads more like a inditement of Mozilla and doesn't actually address why my answer is wrong. I never said pinning coding the certificate is a good idea, you are attacking a straw man. I was simply answering the original commenters question which was:

> Why can't they release a new certificate?

And nothing in your reply indicates why my answer to the question that is actually asked is incorrect.

Also, Certificate Pinning, which is the technique used here is not exclusive to Mozilla. I agree it's brittle but it's not an unusual practice. They also appear to be using certificate chaining (which is often considered best practice for pinning) since they say it is the Root certificate that expired so it doesn't appear to be a naive implementation. And again, even if it was: that's a straw man, I was not arguing for the technical merits of what they did, only answering the question asked.

Do you not remember when Let's Encrypt had a similar issue when a CA Root certificate expired and the certificates stopped working on old devices?

> the sentiment and statement you made is misplaced and false

What "sentiment", I was not making a political statement, I was answering question. And your entire post is attacking the use of certificate pinning and an open source project, which is something I was not arguing for (hence, a straw man) and does not actually refute my answer to the question asked. Furthermore:

> common knowledge at a professional level, which you may not be aware of

ROTFL, this is an anonymous account but I've been in this industry for over 25 years. You are almost definitely running code on your computer that I wrote. Never make assumptions on who you're talking to and use it for a personal attack. It's not a good idea. Also, never make assumptions that something is "common knowledge" -- you must have never managed anyone and if you have a feel sorry for your reports. But regardless, not a single thing you said in your post was new information to me, except maybe that down stream projects may be using Mozilla code for certificate pinning to run Mozilla add-ons and DRM... and if they are, that's on them because a browser is an app not a library.

throwaway2016a··on Certificate will expire on 14 March – update Firefox to prevent add-on breakage
This is a certificate used to sign and verify add-ons and (I think based on the reading) some DRM features. They did, in fact, release a new one. This is a warning to the people who haven't run their browser updates and don't have the new one.

There is no point in pulling down the certificate, it's only used by Firefox and there shouldn't be any valid use case to patch an old version to use the new certificate, you would just update your whole browser (it would be easier and safer).

Edit: to whoever downvoted me. I was trying to be helpful with an actual interpretation of the article that this story linked to. I was also answering what was a question in good faith, respectfully. So if my reply is factually inaccurate I would love to know how I misinterpreted it as a matter of curiosity.

throwaway2016a··on DOGE's Misplaced War on Software Licenses
> they should not be charged for those licenses until they actually use them

Unfortunately that's not the way bulk licenses has ever worked. For Government or enterprise. What you just described is no different than buying individual licenses.

The reason it's not "pissing money down the drain" is a few reasons:

- Managing licenses is not a free thing. The time it takes to actually go and purchase / negotiate / maintain those licenses can become significant if you are doing it many times per year.

- Vendors negotiate discounts for bulk purchases of licenses and the whole reason they do that is because it is guaranteed payment. If you stop guaranteeing the payment (by only paying for what you actually use) there is no incentive for the vendor to provide discounts. They will just charge you retail price.

Likely, though I don't know the specific in this case, you are seeing 2x to 3x extra licensing because someone actually did the math and found it was cheaper than constantly renegotiating deals and/or paying retail (and the associated bookeeping that goes with that).

That goes double in a situation like Government where you need to get purchase orders, approval, etc. Buying bulk significantly reduces the cost even without the discount just in hours managing the approval process.

throwaway2016a··on Meta apologises over flood of gore, violence and dead bodies on Instagram
I have no doubt that is your experience and it's good to hear some people are having good experiences with it.

My main account is fine but I have an account that follows very few other accounts (it's for a product I was building that never really took off) and I just signed in and scrolled until I hit 8 ads. The ads were in this order (completely unedited list... I'm not editorializing here):

- Robinhood

- A very explicit "male enhancement" ad

- A movie ad for a movie I've never heard of until now

- A "bedroom aid" (blue pill)

- A marijuana dispensary

- A scammy looking mobile app

- Another ad for a pill for men who are having trouble in the bedroom

- An affiliate marketing scam

... I stopped scrolling at that point because it felt like enough.

throwaway2016a··on Meta apologises over flood of gore, violence and dead bodies on Instagram
X is similar now for new accounts now. Except it's not just the timeline content, it is the advertisers too. My active account gets regular advertisers but my inactive one has all X rated and scam advertisements. And tons of "18+" bots that will go around auto-liking people's posts.
throwaway2016a··on The U.S. Cannot Be Run Like a Business (2017)
This comment was at least +5. It is 100% factual based on my actual experiences. Yet now it is at 0 with no replies overnight.

How about we do what HN was made for and actually have intelligent debate on the topic? If you downvoted it you must have an opinion. Unless of course you're a bot or a voting ring.

The only thing I can see a legitimate downvote for is the right vs liberal promoted tweets. But that's not actually a political statement. My Twitter account is 100% tech no politics AT ALL yet somehow 90% of my recommended tweets it shows me notifications for are FAR right (not even center right). That should be concerning no matter what party you're in. That is beyond coincidence. It is definitely not showing me them based on my interests as I have shown no interest in tweets like that. So what is it using to show them to me?

throwaway2016a··on The U.S. Cannot Be Run Like a Business (2017)
I've been using Twitter since the early days and while it hasn't crashed and burned it definitely performs worse than it used to. The only bots now are the ones willing to play dirty so every one of my tweets typically gets liked by at least one "adult" account with 18+ material on it. I go to my lesser used accounts (that I have for my business) and 90% of the ads are for scams, NFTs, outright porn, and sleezy mobile games.

Let alone the technology itself. Someone liked one of my tweets the other day and it showed up in my notifications but it took hours to show up on my page as a like. Sometimes I tweet and it doesn't show up for a long time and I don't even know if it successfully posted. And every single one of my notifications is right wing, not a single liberal notification on most days.

Not even mentioning that Musk has been pretty eager to ban people he disagrees with. Which is the opposite of what he said he would do. And "tweet" was a "verb"... you know how hard it is to get your own verb as a product? But he just threw that brand equity out.

So yeah, it may not have crashed and burned but from a technology and a culture perspective it is not what it used to be.

throwaway2016a··on What do you think about using a game engine for UI?
Using a game engine for UI and making the style of the interactions the game-like are two different things.

Game engines are generally capable of creating hardware accelerated 2D UIs which could be great in some cases where highly dynamic UIs are desirable. But making a business app 3D for no reason is a different story.

The later is largely what "The Metaverse" as Zuckerberg sees it is trying to accomplish. Check out Horizon Workrooms and the like.

I've worked at a number of agencies over the years and at one point years back a client insisted on Unity for their mobile app because it worked cross platform out of the box. It was an unmitigated disaster because we were trying to fit a square peg in a round hole. Tens of thousands of dollars wasted.

throwaway2016a··on "We Will Pass Those Tariff Costs Back to the Consumer," Says CEO of AutoZone
While tariffs may make people consider where they source their products, corporate income/profits tax has incentives too.

Things like hiring more people, research, development, capital improvements, etc all impact the companies tax bottom line. So in that sense, corporate taxes incentives companies to spend their money instead of hoarding it, using it for executive bonuses, or giving it back to the shareholders.

A vast majority of manufacturers don't source their materials from the US for good reason. Either the US is more expensive or the US supply is completely non-existant. Tariffs aren't going to fix that because domestic suppliers when given a monopoly are not going to magically lower costs and moving production here will take years and cost far more than just continuing to pay the tarrifs.

throwaway2016a··on Tell HN: Robots.txt pitfalls – what I learned the hard way
/favicon.ico is the default and it will be loaded if your page does not specify a different path in the metadata but in my experience most clients respect the metadata and won't try to fetch the default path until after the <head> section of the page loads for HTML content.

But non-HTML content has no choice but to use the default so it's generally a good idea to make sure the default path resolves.

throwaway2016a··on xAI Grok API Beta
I know this is a late reply, but gRPS is exactly the kind of RPC computer scientists talk about.

I'm not sure what you think RPC is but RPC is just the paradigm of calling functions on a remote machine, passing arguments in a structured way, and getting a response back. Which is exactly what gRPC, JsonRPC and others all do. As opposed to resource-centric paradigms like REST, query languages, and non-realtime paradigms.

The main gripes against RPC is tight coupling, lack of a discovery mechanism and caching out of the box, and difficult in error handling and session management. All of which are also issues with gRPC.

gRPC offers no real benefits or drawbacks compared to other RPC implementations except that it is built onto of Protobuf.

throwaway2016a··on H2tunnel – ngrok alternative for Node.js in 600 LOC and no dependencies
I understand multiplexing is necessary. My point is SSH tunnels already multiplex. If two people connect to the same port on the tunnel machine then that will be two seperate sockets on the destination machine. Since they are already two separate sockets what is the point of adding HTTP/2 protocol awareness at the tunnel level? Just let the endpoints handle it.
throwaway2016a··on H2tunnel – ngrok alternative for Node.js in 600 LOC and no dependencies
Clearly a lot of work went into this so kudos for that.

I do think it missing the point a tiny bit though. For me the primary use of Ngrok is to automatically get sub a domain with TLS and this seems to be outsourcing that to Caddy. And also I need to run a server. If I was going to run a server and run caddy I'd probably just use SSH -L directly.

Also SSH -L is a TCP/IP level tunnel so I'm missing something regarding why the HTTP/2 multiplexing is necessary vs just using the tunnel as is.

throwaway2016a··on Show HN: Last CLI tool you will need
Ironically the thing that makes this even remotely secure is that it doesn't look like it runs the command immediately, it copies it to clipboard. Ironic because that makes it not really any different than asking ChatGPT or similar to give you a command to use.

With that said, if it did run automatically that would be a compliance and security nightmare.

Overall, these days most of my terminal usage is inside my IDE which has a shortcut to use AI to write a commands and I imagine that will become a standard feature in all terminals soon enough so I don't see too much use in this.

Good work, it's just not for me.

throwaway2016a··on Omni SenseVoice: High-Speed Speech Recognition with Words Timestamps
This looks really nice. What I find interesting is that it seems to advertise itself for the transcription use case but if it is "lightning fast" I wonder if there are better uses cases for it.

I use AWS Transcribe[1] primarily. It costs me $0.024 per minute of video and also provides timestamps. It's unclear to me without running the numbers if using this model I could do any better than that seeing as it needs a GPU to run.

With that said, I always love to see these things in the Open Source domain. Competition drives innovation.

Edit: Doing some math, with spot instances on EC2 or serverless GPU on some other platforms it could be relatively price competitive with AWS Transcribe if the performance is even slightly fast (2 hours of transcription per hour to break even). Of course the devops work for running your own model is higher.

[1] https://aws.amazon.com/transcribe/

throwaway2016a··on Linux from Scratch
This brings back memories. I tried to do his (by using this exact site!) in college. Which, for reference, was 20ish years ago.

I wasn't able to get very far, mostly because I kept running into obscure compiler and linker errors and 18 year old me wasn't clear how to fix them. Would be fun to see how much is changed since then because it does appear to be at least partially maintained.

throwaway2016a··on I got everything off the cloud and am paying less
Reading through these comments I'm not sure everyone is on the same page as to what "Cloud" actually is.

In both the Twitter thread and the HN comments people seem to think VPS in no longer "cloud". IMO you are not "off the cloud" unless you own the hardware. A VPS is not that much different than an EC2 instance.

So in reality you just converted from cattle to pets[1] while just being on a different type of cloud.

And once you get into actual colocation you have to buy the hardware, have redundancy, and the colocation facility is probably charging you quite a bit (and perhaps even extra for bandwidth and power consumption).

[1] "cattle" refers to a disposable and easily replaceable resource, like virtual machines or containers, while "pets" are unique, carefully tended servers that are individually managed and not easily replaceable.

throwaway2016a··on An easier way to get your logo in the inbox: Google's latest BIMI changes
Perhaps I'm missing it but where do you actually buy and/or generate a CMC? I can't find any information on it.

Personally VCM is far too expensive for me at this time which is the only reason I haven't gotten one. But I certainly realize that putting a cost barrier to entry makes it less accessible to bad actors.

throwaway2016a··on Tesla Full Self Driving requires human intervention every 13 miles
Like other here I think 13 miles may be generous for city driving but pretty reasonable for highway.

With that said, it works MUCH better for me than it did a couple years ago and I find most of the time I disengage it is not because it actually needed human intervention but because it wasn't aware of the social norms at certain intersections.

For example, I have an intersection near my house that requires you to inch out and essentially floor it first chance you get if you want any hope whatsoever of taking a left hand turn, but FSD will (understandably, I think) not do that.

throwaway2016a··on How much energy does desalinisation use? Is it "absurdly cheap"?
You are right, I cannot generalize. In fact our main flush function in newer toilets is the same flow as almost all countries (Australia and Japan being the exceptions) but we also have far fewer "Duel Flush" toilets (apparently, I'm just learning this myself) and the low flow on duel flush toilets uses much less water.
throwaway2016a··on How much energy does desalinisation use? Is it "absurdly cheap"?
> as long as you actually fill the machine

That's more or less what I suspected. Though... and I'm not sure if this is an American thing, an international thing, or just a weird quirk of the specific people I know... I know several people who run their machines every day even if they aren't even close to full.

throwaway2016a··on How much energy does desalinisation use? Is it "absurdly cheap"?
Fair enough, that was the one that seemed most questionable even as I wrote it.
throwaway2016a··on Ephemeral IDs: a new tool for fraud detection
Exactly, the "how it works" section ironically does not actually explain much.

I would love to know how this differs from fingerprinting. And if it is just fingerprinting it seems like it'd probably be trivial to bypass. Especially since it appears that you have a way to check your ID so you could potentially experiment with different ways to affect it.

throwaway2016a··on How much energy does desalinisation use? Is it “absurdly cheap”?
My guess is that the average is very different than the median here. In general there are a few considerations:

- Green lawns are considered a status symbol in the US and in many higher end neighborhoods houses run irrigation multiple times a day.

- Same goes for pools.

- Baths are common (especially for kids) and use a fair amount of water.

- Our toilets and showers are not efficient.

- We tend to do laundry and dishes with machines (though I'm not sure if that would really use more or less water).

I also suspect that number may include industrial and commercial. Since even considering the above it still seems high.

throwaway2016a··on pgroll: PostgreSQL zero-downtime migrations made easy
This is really great. Managing migrations without locking the table can be a real huge pain-point. And having a dedicated project likely covers more edge cases than an internal tool would (as is evident looking at the issues list).

With that said, it looks like it could be used not just as a stand alone tool but also embedded within a Go application since it does export its API. In my case I'd love to use it from my existing tooling. I couldn't find any documentation on how to do that, though.

I'll probably dig more into that later.

throwaway2016a··on Show HN: I built a tool to roast landing pages using AI agents
I'm not sure it's something I would use but it looks like some good work.

At first glance the pricing seems a little high for a single-use tool. It is still cheaper than using humans but also, as it sounds like you are aware you are aware, there are some issues demo page that the AI agents didn't call out that a human would have.

I like that you included developer tool results in your summary. Consider possibly including Accessibility results in there as well. A11y is something a lot of developer and product people don't think about. It could be you already have it and I just didn't notice.

throwaway2016a··on If AI is helping people code better, why aren't products getting better?
This was my first reaction. It hasn't been that long and giant ships can't change course quickly.

And for much of that year there were a lot of questions around the ownership of AI generated code as well as information security. In fact, most of those questions are still not satisfactorily solved. So I'm not so surprised that we haven't seen massive results "yet"

throwaway2016a··on Analyzing the OpenAPI Tooling Ecosystem
Working means you give it input and it produces the expected output for all your defined used cases. Don't confuse working with good.

Let's keep your analogy: AI isn't producing software that is the equivalent of a AAA movie title by any stretch but it is producing far better than a bunch of kids in a garage with their cell phones can make. Which is orders of magnitude better than 20 minutes of blank video. Which means that people will use it whether you like it or not.

Reality doesn't care if you think it is a bad idea... in fact I think you and I are on the same page, I do think it is a bad idea... but reality will continue to exist whether you and I like it or not.

You're not helping anyone by arguing how crappy and harmful it is to someone who already knows how crappy and harmful it is.

throwaway2016a··on Analyzing the OpenAPI Tooling Ecosystem
> I think it's a fair attitude if your only goal is to make money

Short term, yes. But it's a bit short sighted as most of the AI code I have seen has security and scalability issues that long term have potential to blow up in your face costing even more money.

Granted that can usually be fixed by better prompts. But to right those prompts requires the person doing the "prompt engineering" (rolls eyes) to actually have a working knowledge of a lot of areas such as architecture, security, software engineering best practices, etc. And a lot of the influencers out there pushing AI openly admit to "not knowing how to code" let alone knowing the right way to build a technology product so that it scales and is safe.

← PreviousPage 2 of 34Next →