HNHacker News
TopNewBestAskShowJobs

throwaway92394

126 karma · joined May 3, 2022

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGJxlfQBEADfA8oXLSZ4Jtqe6mkpJyk1hrtkG1uu/WwDFI/69XEbJEzfyCZk td8Rz2PbVmXqfKoEkWALvlecmY2eL+PPsilVmQJRF7bHI2Le/jD+MFj2SfN0MHY0 Un0+ZBrrk2pZmVT6bhpyhNAp4SLFV8XdmHl6M3w5Wxi4q+idphxecUd4mXlH7fC6 /ZdK/W2L36wqWHzaGBB1M3Qn3oc/QLsyIp9XFuaHqkouFiYpae0rQpBkqrqTa5UV 0J4uiFqxpTEwgJRtDGQY3pKDvnsmZhMMMsbSEzk/2SbbkYyUn+forB51ggyWFqb3 MkQ6tEQbh52wHY2UsbZQyBqTiZf3n9IsOKqlNZfMOSAtMLJvcha2tsSk/5bcNQuP 29VW0Dlw+h+FSCNyf/fmRgQ/Y9K78os53lwwVcv4EaXIi5z/EaQqqHTHm3IJejJw dhPdJ7BR0cpL6PQbbjeN8FUkbXUWHPSFApFVW0ZxHgAGYojuKVieR3zWEPxvFd4O lclebqmc8dpniU4nH10NzQ+H4HyuIOb3tIiJbCLOC/ZpxbyXb4bgp89GnX+fr9+H xofbodBPBVqdBFPgIOkQo0aUaszLJOXf+lA9MG5fKyRPwABILfSAjy4T8ymGfclj aHDzCjGpCNDYlsnLVuMOhwopi9W28/IudhYXhTp8uZ6mxwVX6T5kopiRYwARAQAB tA50aHJvd2F3YXk5MjM5NIkCTgQTAQgAOBYhBGLYBKASbWhSMv3GSiwuWqE0ATEZ BQJicZX0AhsDBQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJECwuWqE0ATEZXIUP /1JGP3mll/n8rgG7q/STO0udKKRCKKcVN6TD1BvtoRZ+Eh7Xkez84AhMuqgG5Xsw agN3xLd0GiAOfTG9yQ0JU8gNAhInPDaNP/nQfYXCW2DTEJM9uVMXK1ancAR4JMwQ IkpygmzCnga57ZPnGoYZjMHOLDk8C4MYCR3oKOJxpMqdrjqR8+tpmz3Gm4BMlMle EcYZhE6W7fLief7MlreTqhlqWzwYFBUk/G6u2b8WztJAzCdmGbbpccni6lBws6rh /wutRcThRiSmp1duZ2oxngf0vSQIpO2o8IheVmn/I8oMbDlBqz+iocm3eNxzAE0n a73I/xPO7jz5jJJJ7BOamk35VO1FPE1WzR2ENdh/N2c2Nn1nOEDNN1XNWaE8oVXg AtffKdGKjQVCMT5oTrZJZs2ECvUczRhNLCwVMOZiNTw6KdA+a/CfC3pFvrxsRYMC NRJDA7BRVrlRP+6UThipzvYCUK47TjTL0F/goPlff+lQwmqMs3eFL5q7NN2aYnUK xzWl1GuNrp+CNrcj9oGIssrk+492LTcSJWSvvnTIkAB470sJT665aPmgSCDLcs4y MHjqioQ5I5cabq/ChfgdQdPrpHMMx0OjGW+xCUZTtNTMfMVzWSlO9z1yXgy00WiW Y61L9EUZsoPfrh5Zsvi+TNF1LUhcTs+bsaVhRZrTuJLYuQINBGJxlfQBEADXCngH 32wpeCA+PriOngFoMJ7iELr60R0txwRTh8tVnTmNLiDkQugkQTetNdh20nJJlXVO Bvp5sse8SYWjWc3BxXSkJC3UW4S3JUpA+bgMm4OLzd/wGVuib6LHoV2roNdPTB6Y 46CigH8KI4LL1S6xyQekJLC7FAMLbiOf4c79LU3SODHz1kl+4FS8RiAukoT+7C+w RKL+9GsrKx4TNX3OXza9JSSOCF6mZEkdpvaeVyjHX93knK8z28z5qOaI4Esr8uty u+w6WcBSpNzRI/H67u2jyB0PlxSKiwKG5tE1iO6wgJ4z8K/2OkNni1Ws54pRdDC6 1NuN7/QM6Xx6Q7OLvd5ZMY3FyQk/W1OQNyozUHaYa4AYSlHK8vvaYp+Yx/b8f21V P+j/zFvXIr/R3RWETMOIYHC4yzkt1TSqiL/myCNuBuZg4Q99dV7FM23HCPt4uCkb edOT214RGiDm2BmdGd6cme1LOCUT2LOhCK0TpzuDsoTsKFI3wuTJ9USZ0TVOLOaE MjSI8QbdtPqzBZ1jo4OLQEWR9ogjJNj+zUYv22vMgk0N5/T2B6JFz6IafuhVecXH mlMf1bnNkfA86eStAlXHnqs6P8l7v0kvIQso/E9smj7NfBWklORyFMoZkJZwhfDB MAvrWZBE6ky74c5edsR/v8iddg4+KXEm91L71wARAQABiQI2BBgBCAAgFiEEYtgE oBJtaFIy/cZKLC5aoTQBMRkFAmJxlfQCGwwACgkQLC5aoTQBMRkp4RAAppVCJLie xh1zyQGugxQL288Uzyfs97oa9uDHBK7hX0h1BjxRNXdQ3BqmKw13ZoUkisrx2NIq Ua0xXKZGztoK9rvq/X5ScbeoAWOrDJ3cHLZ3KVbtaf4lRIQ/4wGkU3oA9DutFDDi jA4q1DfklvGD/cybqzF4mdNlE47WCT7natvU56USHQ7RRq+dOfRuJO/2UIrdaxV4 y5wBK3lW3cK87ALtIiNxreJMrXN3p4trAwvaw5bAZkkTibRCi/TIGnbiOZgRMDOt r+LE4m1Tkou/hwhzwUSXmd0GxsI4zUBBByOIPqLdPoQMKUlpjVbyJUMiZN6V8AfA LTp4x84fIkrzTAHQVFdNH3eFHdm4kzJHcdnDZRS6V/1TONgiPmOiBKIiehz9lEcS X0eBUREjmax1+QyY+DBGX0Tagx1/D3OuUEKdhqlaOiZvDI6JuiNF/jhkEvMmEngG +BR5JzdqSxC0J1qG0OSzu8qqrZK6fWrza3x964mqyPqgvAkts7QayEUWOYys+ag5 ZmnK53Ld+4UzMFV194sm61JOXFv4UJGl/K0LNOFcYl/XuWoHENjUUraGp11ney6s RkW+gfOxXWXdtJJB0lwQ2gOabww0taWte/MntzILgTPpOhnzfH9d67ZePawZgJOq rHNqMWrDSrWOLl8HJPydRaWcryvydCvMQjo= =0H1h -----END PGP PUBLIC KEY BLOCK-----

submissionscomments
throwaway92394··on EU reaches deal to make USB-C a common charger for most electronic devices
Don't get me wrong I do too. I'd prefer it if everything just used USB C.

I just wanted to point out that it's not universally superior to micro USB or lightning, and there are places it could be improved.

throwaway92394··on FBI seizes notorious marketplace for selling millions of stolen SSNs
You run into the same issue you do with 2FA -

I cannot remember my own SSN. What happens if I lose my license, SSN, and master password manager password in a fire? What happens if someone has a stroke and forgets a recent pin code, etc.

Do I go to my state and request new IDs? How do they authenticate me?

throwaway92394··on FBI seizes notorious marketplace for selling millions of stolen SSNs
So in the US you can do "credit freezes" which prevent people from taking out new loans/new cards in your name.

HOWEVER - you can't do anything about the fact they can call up your bank, say "I forgot my password" and then give them your SSN. Your bank will happily reset the password for them. If someone has your SSN they essentially have everything they need to get access to any of your financial, medical, or utility accounts, and can also use it for KYC/AML to open say a crypto account in your name. You cannot do anything to prevent this option.

throwaway92394··on What ID3v2 could have been
But more importantly - can we embed ID3v2 inside ID3v2?
throwaway92394··on Show HN: The Bitcoin Note – Secure, Self-Custodial Bitcoin Wallets in Cash Form
> For the sake of simplicity 2-of-2 multisig that downgrades to 1-of-2 multisig over time should capture the essence of how these notes work. > Users can always claim funds after the expiration date of January 3rd 2029 using the user key stored on the note.

Interesting, thank you. That does seem more reasonable to me. Best of luck with your project.

throwaway92394··on Tell HN: Read up on your GitHub Support SLA
I'm not defending github specifically, I have no experience with the customer service and have no reason to beleive they are or aren't garbage. I'll assume they are garbage.

To be fair, what do you expect the first representative to do/say? They responded in 3 hours, and it's unlikely they can do much beyond escalate this issue internally. We can't expect them to say "We're going to do sweeping changes" at this point.

Github in the past has done sweeping changes for things such as youtube-dl. They created a large blog post about it, including having both programmers and laywers review every DMCA request, and allowing the most minimal amount of changes to comply, etc. That type of response takes time and coordination.

Even cloudflare with their CEO/CTO can't offer sweeping changes in a HN comment. There's layers to this. You can only really expect damage control from a HN comment.

throwaway92394··on Show HN: The Bitcoin Note – Secure, Self-Custodial Bitcoin Wallets in Cash Form
> We will have a security overview doc up soon, we ran out of time to have it ready today.

I mean this respectfully - why would you release a cryptographic method of transferring money - without going into detail of how it actually works? That's kinda the entire point of cryptocurrency, that we have a way to be mathematically confident the money is safe - but you didn't tell us the math. Especially on HN were a lot of the audience is technical enough to want to and be able to verify it to some degree.

I see you have patent US10896412B2, which honestly I have to ask how this is any different from any other hardware wallet?

> A physical cryptocurrency may comprise a physical medium and an attached processor.

I read some of the details (admittedly not all) and I'm still unsure how this is different from any other hardware wallet. AFAIK this is just a hardware wallet that exposes it's public key, then exposes it's private key when you cut the wire? Then we still need your signature to transfer the crypto, which is so double spend is prevented?

Also, if your servers go down or you're hacked or rm -rf dir/ * happens, will all the notes become unusable? Are we relying on you to maintain servers indefinitely?

throwaway92394··on EU reaches deal to make USB-C a common charger for most electronic devices
> Innovation is overrated. And standardising is not blocking.

Hard disagree? Both lightning and USB C were massive improvements in durability compared to Micro USB - I'd argue lightning is still better in that regard, because there's no thin piece inside the phone that can break (did phone repair, and 99% of the time a "broken" iphone port was just stuck lint).

USB C is not universally better then then Micro, namely it has a much larger footprint both on the connector side and the PCB.

> Will EU block innovation?

So my question is - if there's a new USB standard connector that's smaller, or is inside-out for better durability - is it now prevented from being used?

throwaway92394··on FIDO Alliance
Or apple's iCloud (see their passkey thing also currently on the front page)

EDIT: Yes you don't need to use a syncing service. But it will be important for it to be portable between syncing services, as that is what most consumers will be using.

throwaway92394··on Apple Passkey
Does anyone know how this/FIDO/Webauthn affect privacy? How well supported are alt accounts? Are they easy to tell they're from the same signer?

I figure privacy is fine as long as the implementations allow you to select which account to login with. Is this currently a thing? From everything I read it seems like the current implementations are only meant to support one identity?

EDIT: These are great responses, also curious if anyone is aware if Apple's current implementation supports multiple identities?

throwaway92394··on On the security of plugins
> Unfortunately only mobile OSes are on the forefront of this.

I'm not sure why the OS would have to manage this. For example when using electron you can use node's vm and run js in a seperate context. Its a seperate process but doesn't require anything special from the os for it.

mobile OSes do sandbox the entire program usually by default though.

Ubuntu sorta tried to with snapd. Windows tried to with UWP.

throwaway92394··on Rejecting data demands, ExpressVPN removes VPN servers in India
Yeah my impression is they're all marketing and care relatively little about privacy. How you can claim to care about privacy but still require an email is beyond me.
throwaway92394··on Tell HN: I'm Afraid We're Shutting Down
> In fact, they get paid well to do it. Your typical family law attorney should be arrested, tried and convicted, and they've destroyed countless families, harmed countless children.

I was with you up until this. While I understand the view that what many attorneys do is immoral or wrong - generally speaking to my knowledge there isn't widespread illegal behavior?

I understand but don't fully agree with the view that laywers are "evil" - but the way I see it is they are skilled at playing by the rules of the law. This makes them incredibly powerful (for both sides of people that can afford it), but if they are generally playing by the law - thus not arrestable. Tearing a family apart because the mother is an A hole and lies about things the father does might be immoral - but it's not illegal for an attorney to represent them.

throwaway92394··on Tell HN: I'm Afraid We're Shutting Down
Add no degree. Many especially in CS might even be highly skilled but have no degree to show for it.

EDIT: And only speak e̶n̶g̶l̶i̶s̶h̶ a single language.

throwaway92394··on CNN cutting back on over-hyping everything as “breaking news”
> Personally I'd like to see the fairness doctrine reinstated

That's not going to help at all with online media as that's only broadcast licenses which to my knowledge only affects operators of a broadcast TV, Audio Radio (as in AM/FM/SSB/etc), or other radio station - meaning the internet, cable, and satellite (not sure how satellite broadcast licensing works) are unaffected by this. Also it only affects the holder - ie DishTV - not the channels themselves that DishTV is transmitting

And I have no idea how you adapt this for the internet - broadcast licenses were relatively hard to get, relatively expensive to operate, and generally unavailable to most people, edit: and had limited availability. With the internet anyone can make a blog for free in 5 minutes.

EDIT: I think you'll have a lot of 1st amendment problems here. To be honest I'm not sure how the FCC was allowed to do it. To my knowledge the FCC cannot enforce this for cable/internet - I think that would have to be the FTC. But I really doubt this be found to not violate the 1st amendment with the internet.

EDIT 2: > The courts reasoned that the scarcity of the broadcast spectrum, which limited the opportunity for access to the airwaves, created a need for the doctrine.

It looks like the supreme court at the time ruled that because of the limited number of broadcast stations it made sense for the FCC to regulate it in this manor. Because of the lack of scarcity of resources for the internet, I highly doubt the FTC would be allowed to do the same.

throwaway92394··on Rejecting data demands, ExpressVPN removes VPN servers in India
Mullvad isn't small, and I'm not sure how Nord specifically compares, but its probaubly worth noting they mostly use 100TB, Tzulo, Quadranet, M247, and 31173. They use a bunch of others but not much.

Mullvad for obvious reasons is used for less... wonderful usecases. It's not uncommon for websites to block you due to abuse from that exit. ASN blocking is rather common with mullvad too though that's less avoidable.

I have less info on Nord, although I can see it has about 4x the ip's. No idea if they are more diverse network wise. Their accepted payment methods suck though.

throwaway92394··on Monterey’s Finder Find memory leak may not be fixed
> CLI programs tend to be FOSS

I think this is more likely because they're often made (or at least started) by individuals as a hobby or side project, not as a commercial venture. CLI is generally easier to develop then GUIs especially cross-platform.

> GUI programs tend to be proprietary and non-gratis.

GUIs require so much more work, especially for cross platform. If engineers are paid for their time then this is worth it.

Granted electron has made it far easier - you still need to be essentially a full stack developer to make a GUI with it.

throwaway92394··on Canada trials decriminalising cocaine, MDMA and other drugs
That's not a good solution because it makes the law ambiguous as to where it should be enforced.

The better solution is to treat it like alcohol - legalize it but make being a nuisance still be a violation (ie Disorderly Conduct and Public Intoxication). This makes it clear it shouldn't be enforced say in a night club or likely a homeless camp - but still allows police to intervene with people causing problems.

throwaway92394··on Zulip – Threaded real-time chat for distributed teams
That's a setting you can configure. You can also choose whether it shows the sender's name.

There's reasons unrelated to this for why you want to not show the message/sender - namely devices like a desktop you might be screensharing from or if you're concerned about someone seeing it over your shoulder.

I almost leaked a message just taking a screenshot because I didn't notice the notification immediately so I keep it disabled.

throwaway92394··on An autonomous car in SF blocked a fire truck responding to an emergency
To put it mildly - this is unrealistic in the US except for major cities. Even then, depending on the city and where in the city, its going to be very difficult to convince and implement methods of cutting cars.

While I think it's a good idea I just don't see this happening in the majority of the US other then major cities. In my state I just don't see how it would be possible given people commute 30+ miles regularly.

throwaway92394··on Bolt Financial's loans come due
Forgive me if this is a dumb question -

Assuming you're an employee with a relatively small number of shares (in terms of company control) - what's the point of shares if you can't sell them? Just _in case_ you can sell them later? Some type of dividend/profit sharing (which seems unlikely for a startup)?

throwaway92394··on Ask HN: Why XMPP failed and SMTP didn't?
The original comment was

> iPhone push notifications could only be sent with a signing key tied to the same developer account as used to publish the client application.

> That meant it was impossible to send push notifications from your own XMPP server to a generic XMPP client written by someone else.

and you were replying to

> This restriction that push notifications must only come from the developer’s server is a restriction imposed by Apple and their App Store.

So I'm confused as to what you mean.

> An __off device__ request that is processed server to server.

> ... They are portable (very smart) terminals ...

How does this relate to methods of reliably pushing notifications to an iPhone?

throwaway92394··on Ask HN: Why XMPP failed and SMTP didn't?
I apologize I'm not sure what you mean by mothership, I'll assume you mean the core API's the OS presents. I mean that's how requests already work? You ask the system to handle the network for you and it passes the app data?

In the context of notifications this isn't an issue for when the app is in the foreground. But when it's in the background the app's event loop isn't ran consistently, so you might not get the notification for hours. To my knowledge the ONLY way to consistently push notifications for apps in the background is through apple's push gateways.

throwaway92394··on Bolt Financial's loans come due
What happens if they waive the loan? Does it count as LTCG + the income tax on the loan amount?
throwaway92394··on Ask HN: Why XMPP failed and SMTP didn't?
> should trigger background actions

Because of the way iOS works nowadays, you cannot reliably do this for notifications because you can't run apps in the background reliably for this purpose.

> allow that community's chosen point of contact to have push notification capabilities

This is what push notifications are?

throwaway92394··on Parsing JSON faster with Intel AVX-512
Well I mean this article is demoing a 28% improvement (if I did my math right) for json parsing.

Sure AVX-512 is only applicable to specific workloads, and even many of those workloads the cost/opportunity of optimizing for AVX-512 might not be worth it. But there clearly ARE usecases that would benefit, and it might be worth it for more consumer applications to optimize for AVX-512 - but only if it can be used.

The way I see it is that the benefit of optimizing for AVX-512 is far higher if it becomes normal for consumer CPUs to have it. A 28% improvement is pretty decent, but it's only worth implementing if enough people can utilize it.

throwaway92394··on Bolt Financial's loans come due
I'm more familiar with traditional retail options, but I'm confused.

I understand why the employees would want a loan - they need money to buy the shares required to exercise the loan - and I guess they can't do it through a normal broker?

If the employees Exercise-to-sell-to-cover or Exercise-to-sell they should be fine right because they would have closed the loan? This would explain why so many took the loan but so few of the layoffs were affected.

Is the only issue the ones that didn't Exercise-to-sell? I understand that tax will need to be paid but I'm not sure what benefit they'd have would be?

Unless, its because the capital gains + loan rate < income tax?

throwaway92394··on YouTubeDrive: Store files as YouTube videos
I mentioned it in another comment, but while that does lower the bandwidth of a single frame, its not actually an issue. There's several DRM techniques that can survive a crappy camera recording in a theater.

"compression resistant watermark" turns up some good resources for it. QR codes are another good example of noise tolerant data transmission (fun fact - having logos in a QR code isn't part of the spec, you're literally covering the QR code but the error-correction can handle it).

The best way I can describe it is that humans can still read text in compressed videos. The worse the compression/noise the larger the text needs to be, but we can still read it.

throwaway92394··on YouTubeDrive: Store files as YouTube videos
Compression will limit the bandwidth of a given frame but you can work around it.

Some forms of DRM are already essentially this, compression - and even crappy camera recording from a theater - resistant DRM that is essentially stegonagraphy (you can't visually tell its there) exist.

EDIT: "compression resistant watermark" is a good search phrase if anyone is curious

throwaway92394··on YouTubeDrive: Store files as YouTube videos
Just gotta add some good 'ol steganography
Page 1 of 2Next →