HNHacker News
TopNewBestAskShowJobs

throwaway2016a

5,903 karma · joined February 16, 2016

submissionscomments
throwaway2016a··on Knoppix
Fun to see this on the front page. I'm curious if ops intent was to share something cool is trigger a bunch of nostalgia because they definitely did the latter.

I remember using this when it first came out. It was a game changer for doing forensics back before full disk encryption was a common thing.

throwaway2016a··on Show HN: We built an 8-bit CPU as 2nd year EE students
Every generation in history has said the younger generation is lazy. Didn't make it true when I was a young xenial / millennial and I suspect it's not true for Gen Z and Gen Alpha either.
throwaway2016a··on Show HN: We built an 8-bit CPU as 2nd year EE students
I hd to do a 4-bit version of this back in 2006 for my Computer Science undergrad. Interesting to see EE students doing it as well. Like many people here, we had to build it on actual breadboards. Which I think adds a ton to the experience.
throwaway2016a··on My Students Can't Read
My undergrad was in computer science and my master's is a MBA. Both from good schools (think top 50 not top 5).

I was thinking more like text books. Text books authors are generally much more wordy than they need to be because the publishing industry and academia awards length. But with that said, I kind of disagree with you a bit on biz school work. I'd say a quarter of most HBR case studies are fluff. I don't mean throw 12 on the floor and 3 are fluff, I mean, take a 12 page case study and 3 of the pages are not adding value.

Articles are even worse because the pay is often by the word and there are min lengths to get into the print edition.

Speaking from experience. I actually wrote a book for a major publisher and the main metric that determined how much I got paid was page count. We had a page count decided before the first word outside of the proposal was written.

throwaway2016a··on My Students Can't Read
Is it? I thought the point was to learn. Most reading is just busy work that doesn't actually advance the learning objectives.
throwaway2016a··on My Students Can't Read
> Looking at the other half of this complaint: cannot or will not?

This. I'm 40 and getting my MBA part time while working and being a parent and I can tell you even as an adult: when you hand me a 20 page case study I will read it but I'm going to be swearing under my breath the whole time.

In today's day and age reading anything long is asking a lot.

My daughter (10) routinely reads 400+ page books meant for kids older than her, but give her a 200 page book in class and she struggles with it even though it's a lower reading level because it is a chore.

throwaway2016a··on My Students Can't Read
First, colleges don't generally give loans. The lenders are not affiliated with the college.

Second, as with anything it is more complex than you are making it. For example, I've known people who have:

- Had a variable interest go up with little to no notice and no adjustment to the payments so if you're not paying attention month to month you end up underpaying.

- Been put in deferment without notice (so their payments stopped) and without requesting it, but continued to accumulate interest.

- Interest is sometimes compounding while in deferment or paying less than interest.

- Were mislead about how interest accumulated while they were still in school (i.e. lead to believe there was no interest when in reality there was just "no payments")

And in that last one in particular, the person I know in that situation (happened to be married to her now), it was her boomer parents that signed the loan paperwork and they didn't even give her access until after she graduated when she found out interest compounding that whole time.

I think the whole debate is putting too much on 17 kids and not enough on their parents who need to co-sign these documents. When I was that age the school didn't tell me how interest worked, my parents did.

throwaway2016a··on The tyranny of single page apps
You can also use SCSS with CSS modules, which is what I do.
throwaway2016a··on Workspace Agents in ChatGPT
What am I missing? I don't see it in either the MacOS app or the web app. I have a "Plus" plan. Do I need "Business" or "Pro"?

Edit: To answer my own question "Workspace agents are available in research preview in ChatGPT Business, Enterprise, Edu, and Teachers plans."

throwaway2016a··on Delve – Fake Compliance as a Service
100%, accepting pre-generated board meeting notes is egregious. This whole thing is awful and I am in no way defending it. The opposite, I think other compliance as a service companies also need to be scrutinized as well.
throwaway2016a··on Delve – Fake Compliance as a Service
There is a lot of serious allegations in here. But some of these complaints apply to most SOC 2 compliance services. For example: it points out that Delve provides pre-filled documents and encourages you to accept them as is. In my experience that is typical. I have seen companies just rubber stamp pre-created documents that describe IT processes that do not accurately reflect actual policy because the MBA[1] running the project didn't want to pull in IT and had no idea what any of it meant.

[1] No offense to MBA, just using it as a placeholder for: business stakeholder with no IT background.

throwaway2016a··on Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
I was literally just attending a course on "innovation" and the topic of Apple vs Android was covered. Interestingly enough, a majority of students commenting cited iOS "security" as a core value proposition. As an Android user, however, I know there are a lot of CVEs in volume but in terms of severity, when an iOS issue happens it appears to generally be much more severe.
throwaway2016a··on Skip the Tips: A game to select "No Tip" but dark patterns try to stop you
First I will say, I am very much against dark patterns and I believe servers should be paid a fair wage and not have to rely on tips.

But until that I do tip for dine-in service. But I found the "buy me a coffee" link on the button of this to be much funnier / ironic than it probably should have been.

It's also missing what I think is the worst dark pattern:

Having no option not to tip at all. Instead requiring that the customer press "Custom" and manually entering "0.00"

throwaway2016a··on Using AI Generated Code Will Make You a Bad Programmer
First, I'm using frontier models with Cursor agenic mode.

> Also, if you use an LLM haphazardly and it introduces a security flaw, you as the user are responsible. The LLM is a power tool, not a person.

I 100% agree. That was my point. A lot of people (not saying you, I don't know you) are not qualified to take on that level of responsibility yet they do it anyway and ship it to the user.

And on the human side, that is precisely why procedures like code review have been standard for a while.

But my main objection to the parent post was not that LLMs can't be powerful tools but that specifically the examples used of maintainability and security are (IMO) possibly the worst examples you can use. Since 70k line un-reviewable pull requests are not maintainable and probably also not secure (how would you know?).

throwaway2016a··on Using AI Generated Code Will Make You a Bad Programmer
> If the programmers goal is to produce valuable software that works and is secure and easy to maintain then they will gravitate to LLM assisted programming.

Just this week alone I had the LLMs:

- Introduce a serious security flaw.

- Decided it was better to duplicate the same 5 lines of code 20 times instead of making a function and calling that.

And that is actually just this week. And to be clear, I am not making that up to prove a point, I use AI day in and day out and it happens consistently. Which is fine, humans can do that too, the issue is when there is a whole new generation of "programmers" that have absolutely zero clue how to spot those issues when (not if) they come up.

And as AI gets better (which it will) it actually makes it more dangerous because people start blindly trusting the code it produces.

throwaway2016a··on TikTok 'directs child accounts to pornographic content within a few clicks'
I'm not convinced that will fix the problem. Even in situations where identity is well known such as work or school, we commonly have bad actors.

It's also pretty unpopular for a good reason.

There is a chilling effect that would go along with it. Like it or not, a lot of people use these social platforms to be their true selves when they can't in their real life for safety reasons. Unfortunately for some people their "true self" is pretty trashy. But it's a slippery slope to put restrictions (like ID verification) on everyone just because of a few bad actors.

Granted I'm sure there's some way we could do that while maintaining moderate privacy but it's technologically challenging and I'm not alone in wanting tech companies to have less of my personal information not more.

throwaway2016a··on TikTok 'directs child accounts to pornographic content within a few clicks'
If you consider "skimpy outfits" pornographic that both Facebook and X are worse than TikTok for me. I've seen a few pieces of content I had to report before but not many.

X, on the other hand, has literal advertisements for adult products on my feed and I get followed by "adult" bot accounts several times a week that when I click through to block them often shows me literal porn. Same with spam facebook friend requests.

I think it boils down to a simple fact that trying to police user-generated content is always going to be an up-hill battle and it doesn't necessarily reflect on the company itself.

> Global Witness claimed TikTok was in breach of the OSA, which requires tech companies to prevent children from encountering harmful content...

Ok, that is noble goal but I feel that the gap between "reasonable measures" and "prevent" is vast.

throwaway2016a··on Why America still needs public schools
Thank you on presenting the research. I appreciate that.

To address you points though:

> A handful of very bad students can easily derail the education of an entire class

Private school had plenty of bad apples too. In fact, some kids I went to school with were explicitly there because they were trouble makers and their parents though the nuns would break them (they didn't). In contrast, I've found my daughter's public school to be pretty zero tolerance when it comes to disruptors.

But even if you are right, that is also the strength of public schools. The same thing that makes them unable to turn down the bad apple is also what makes sure kids with special needs or low family means don't get left behind.

> math is racist, or the contemporary 'reimaginings' of history that mix critical theory and contemporary values, and retrofit them into the past in an antagonistic fashion.

Except every time one of those stories come out and you dig deeper it is almost never actually what the media says. It's usually either extremely isolated or taken entirely out of context for sensationalism.

For example, there have been several documented cases of public school teachers teaching creationism, and also that the Civil war wasn't about slavery (despite slavery being specifically mentioned by multiple states when they joined the Confederacy), but I would never represent that as wide spread and try to tear down the whole system over it.

throwaway2016a··on Why America still needs public schools
I didn't get a sense the article singled out charter schools specifically rather it just lists it as a alternative place that funds get funneled instead of to neighborhood public schools.

Which brings me to:

> The main reason "private" (in their sense of the word) schools are gaining in popularity is precisely because they are seen as delivering a better education by an ever wider chunk of society.

If you accept that the article is talking about charter schools, then yes, perhaps the narrow focus of the charter could allow for a stronger education in a specialized area could allow for better education in that area.

But, if you accept it as private schools as a whole, then I don't buy that argument fully. The administration has been very clear that the motivation is "anti-woke" and "traditional family values" and nothing to do with education quality. In fact, as someone who went to a religious school in a small town (granted 30+ years ago) I can vouch that my education (especially in science and math) was FAR worse than the public schools at the time and homeschooling quality varies wildly.

Edit: As far as

> More specifically the US currently spends more than the vast majority of the world per pupil

I also find this focus on spending per pupil very odd because it doesn't account for cost of living.

And if you dive into the fine print it says:

> Includes both government and private expenditures.

So what if (and this is a completely untested hypothesis) the reason we spend so much per pupil in that chart is being exasperated by the private school system.

Edit 2: after diving into it, that source provided is greatly inflated by private school spending including private colleges (which are insanely expensive). So that same data can also be used to argue the US is really spending too much on private schools not public ones.

throwaway2016a··on Vibe Coding Is the Worst Idea of 2025 [video]
This whole thread is giving blockchain in 2015 vibes. People were using all sorts of quotes and anecdotes to tell skeptics why they were wrong and in 10 years the entire financial system will be running on blockchain. A certain amount of skepticism and cautious optimism is healthy.

Also, people seem to be missing that "AI Assisted" coding and "Vibe Coding" are not the same thing.

Personally I think the issue with vibe coding is two fold:

1. It is not good at solving problems that are uncommon.

2. It is not deterministic.

Yes, AI can do quality control and testing now. But anyone who has done TDD can tell you that just the mere presence of tests does not itself mean the code is effective or solving the right problem.

Is it getting better? Yes. Do I trust any vibe coded apps built by people who don't know actual code and are treating it like a black box? Absolutely not.

And I say that as someone who has tried pretty much every IDE out there and uses AI assisted coding (on "agent" mode) heavily every single day.

throwaway2016a··on Vibe Coding Is the Worst Idea of 2025 [video]
Not OP, but there are many things that I know don't work without trying them. That's not a contradiction. It may or may not be true but it's not a contradiction by itself. You can know reasonable well that something doesn't work by looking at other people who have tried it (sometimes even better if those people are experts and you are not).
throwaway2016a··on Lab-grown salmon hits the menu
When was the last time you actually priced them out?

When they first came up they were pricy but unless you're talking about fancy smart-bulbs with Wifi and color changing, they are not 10x the price. And they empirically last 5-20+ times longer.

So even before you consider that a huge portion of the energy put into incandescence is lost to heat (thereby making it cost MUCH more in electricity), they are still roughly the same price after accounting for lifespan.

throwaway2016a··on Link Out for In-App Purchases
Stripe supports Apple Pay, though. You can easily enable both Apple Pay and Google Wallet.

But since it is just the regular version of Apple Pay and not an in-app purchase it has different (lower) fees.

throwaway2016a··on Minimal CSS-only blurry image placeholders
I could tell and I really appreciate it. It's really helpful to see both the good and the bad.

Great work!

throwaway2016a··on Minimal CSS-only blurry image placeholders
Very nice solution!

Definitely very low resolution, but compared to sites that use a solid color this seems much better. And only requiring one variable is really nice.

The article seems very well thought through. Though for both the algorithm and the benchmark algorithm the half blue / half green image with the lake shows the limitations of this technique. Still pretty good considering how light weight it is.

throwaway2016a··on Certificate will expire on 14 March – update Firefox to prevent add-on breakage
It is a conversation that started with a simple post that was just pointing out that you had to download a new version the way Mozilla implemented the pinning.

I never said it was a good idea, I never made a political statement, I never said there wasn't a better way to do it with current PKI technology. I simply explained the way it had to be done the way Mozilla implemented it and I have to deal with rants talking about Hitler. And you call me unprofessional?

This conversation is over.

throwaway2016a··on A powerful free and open source WAF – UUSEC WAF
When I saw that link I thought maybe it was one of those: "add X to the recommended libraries list" PRs or something like that. But this is wild... it's literally an advertisement.
throwaway2016a··on Certificate will expire on 14 March – update Firefox to prevent add-on breakage
You contradict your part here. I'm not sure if you meant to because the rest of your post sounds like it is saying Mozilla needs to pin if it's using a custom signing mechanism.

> Firefox uses (and ships with) the Mozilla Root Program

> can not not pin certificates

Shipping with a certificate store is by definition, pinning. So not only can it but your own post states it is when it says "and ships with".

throwaway2016a··on Certificate will expire on 14 March – update Firefox to prevent add-on breakage
1. Most of those articles refer to Public Key Pinning (HPKP), which is not the type Mozilla used. There is more than one type of pinning.

2. Once again... and I'm tired of repeating this... that's a straw man because never once in my original comment did I say pinning as a good idea or advocate for it.

3. With #2 in mind, seeing as my position was not for or against pinning, sending me articles about how bad it is just proves it is common enough use to warrant mainstream articles. Though again, moot, because I wasn't arguing it is common so another straw man.

From your source:

> Certificate pinning, the practice of restricting the certificates that are considered valid for your app to those you have previously authorized, is not recommended for Android apps.

At no point did I say this is not the case. I am aware of the limitations of pinning. Doesn't change the fact of my original post -- which is correct and has not been refuted in a single one of these replies -- Mozilla distributes the root public keys with their app (as does Google as proven by my citation) and the way to upgrade it is to install the newest version.

That last sentence is ALL my original post said and one of your replies or the other persons once addressed that statement, you're all addressing these ridiculous straw men that I never actually said.

throwaway2016a··on Certificate will expire on 14 March – update Firefox to prevent add-on breakage
rolls eyes sure bud

Tell me, how exactly else are you supposed to update an app with a pinned certificate without defeating the whole purpose of pinning?

How about Google?

https://chromium.googlesource.com/chromium/src/+/main/net/da...

> The Chrome Root Store contains the set of certificates Chrome trusts by default.

Google also bundles some certificate fingerprints with their browser.

You can see right here where they are in their source code:

https://chromium.googlesource.com/chromium/src/+/main/net/da...

But according to trod1234 it is "common knowledge" you shouldn't do that... so Google and Mozilla must both be idiots.

In fact, Google's Android network article has a section specifically on how to add it to their mobile apps[1].

Any app that follows that article and has a root key expire will need to push an update if they don't have backup pins. And the only way to do that is... as I said in my original reply up top... update the entire app the cert is pinned too.

There are literally hundreds of sources I can find. Including the other reply to the post I replied to... which says the same thing as me but for some reason isn't being trolled.

[1] https://developer.android.com/privacy-and-security/security-...

Page 1 of 34Next →