HNHacker News
TopNewBestAskShowJobs

thyristan

859 karma · joined August 7, 2024

submissionscomments
thyristan··on I beg you to follow Crocker's Rules, even if you will be rude to me
> The Gladwellian direct/indirect dichotomy (or continuum) is a misapprehension of how language works. All communication is indirect in some sense because we don't have mind control powers over our fellow humans. Even saying ‘I want to buy this bread’ is indirect in a sense

If you take 'direct' vs. 'indirect' literally, you are right. Everything is somehow indirect, because language tries to represent reality, but isn't identical to reality.

But you are missing the point. The real issue is information density. Indirect communication generally has lower information density: You give examples of various possible interpretations of one phrase, and the more possible interpretations there are, the lower the information density is. The longer the phrase is, the lower the information density. One can come up with a few counter-examples, where for example a very long and very indirect phrase might just have one very unique and direct interpretation, but those are rare. In general, direct communication conveys more information with less words.

thyristan··on I beg you to follow Crocker's Rules, even if you will be rude to me
There are better and worse societies in this matter.

I'm glad I live in a society where it is acceptable for a bartender to just bluntly ask "what do you want?" without all the pointless chitchat. Or for me to go to my boss and tell him "there is a problem with X, we should do Y, even if you earlier said Y is bad.".

thyristan··on I beg you to follow Crocker's Rules, even if you will be rude to me
> The better a person is at communication the more they will fit their message to the audience to get the action intended. If 'direct' really works then over time it will be used but the fact that direct isn't used often implies strongly that it doesn't work for most people or it has secondary effects that are too negative. Demanding the exception is a pretty big ask especially if your aren't willing to meet half way.

'Direct' can work and does work, depending on culture. There are direct cultures, where communication is primarily intended to convey information. There are indirect cultures, where communication is primarily intended to convey social status, manipulate social bonds, or perform culturally necessary rituals. With the actual information being secondary. In a direct culture you will tell say "I want to buy this bread". In an indirect culture, it might be more like "Hello, be greeted, o nicest and finest of all shop clerks, nice weather, $deity be praised for her mercy of having me walk this earth for one more day. All your wares look magnificent, but might I inquire if it would be possible, if it isn't inconvenient, reserved or forbidden, to maybe ask about how that very fine loaf of bread came into your possession? ...". All the while tourist me, back in the queue rolls his eyes in total annoyance, having suffered through innumerable minutes of waiting for people to get on with their useless diatribe.

Since HN is primarily engineers, time is precious on this earth, and secondary considerations should be secondary really: There is only one desirable mode of communications. The direct one. Everything else is a waste of time. Being indirect and long-winded isn't "bad at speaking and listening". It is being inconsiderate and rude. It is putting secondary things before the main issue. I think cultures need to be changed to be more direct.

Your last points are valid, sometimes you need some time and collect your thoughts. But in this case, you should just ask the other person to help you think, and directly tell them that you haven't fully formulated your issue and need help with that. That is a far more productive way to deal with the issue of half-formed thoughts and questions. Beating around the bush and using another person as a involuntary rubber-ducky is also rude, and only excusable in rare circumstances.

thyristan··on Iran-backed hackers claim wiper attack on medtech firm Stryker
Which in itself wouldn't be too bad, if mobile platforms had proper backup facilities that allowed individuals and enterprises to easily get all their devices to the exact backed up state they were before being wiped. But that seems to be unwanted by Apple and Google...
thyristan··on Iran-backed hackers claim wiper attack on medtech firm Stryker
Yes, but Germany isn't the US. We do believe in the "rules-based international order", meaning that there will be a strongly worded letter, some discussion in the UN security council, ending in a veto by China or Russia. Followed by years of nothing at all, a memorial and yearly speeches at some day of rememberance.

I'm not sure if this is any better.

thyristan··on Are the Mysteries of Quantum Mechanics Beginning to Dissolve?
Energy.
thyristan··on Hetzner Prices increase 30-40%
Maybe that could help a little, but on the other hand, there are just no more IPv4 addresses at RIPE. And European businesses seem to be very hesitant at adopting IPv6.
thyristan··on So many trees planted in Taklamakan Desert that it's turned into a carbon sink
Yes. But nobody cares about a few unimportant bugs and mice.
thyristan··on Using an engineering notebook
You can't OCR handwriting. There are some AIs that do claim handwriting recognition, but I've yet to find a single one that can read my notes.
thyristan··on TÜV Report 2026: Tesla Model Y has the worst reliability of all 2022–2023 cars (2025)
> I assume the denominator is cars registered with ADAC, rather than all cars in germany? Presumably that means those with lease contracts requiring another breakdown service wouldn't affect the stats?

Not quite, the denominator is the number of road-side assistance calls they get.

ADAC has a driver membership system, where you get that assistance for free as part of your membership as a driver. You can still call them as a non-member, and I suppose those calls will factor in the statistics as well, but that is expensive, so it's rare. And you don't register your car with them, so they don't know what their members are driving, you just tell them your membership number and can get assistance for whatever car you are currently driving in.

thyristan··on TÜV Report 2026: Tesla Model Y has the worst reliability of all 2022–2023 cars (2025)
Car insurance in Germany exists in 3 categories.

The mandatory one, liability insurance, which pays out others' damages in case your car is in an accident and the driver of your car is found to be at fault. Base rates for those are by law based on the rate of payouts per car model and per owner's county at that insurance company. A multiplier makes the base rate more expensive or cheaper respectively for new drivers, accident-prone drivers or long-time accident-free drivers. No other external statistics are allowed to play a role.

The two non-mandatory ones are "Vollkasko" and "Teilkasko", which pay for damages your own car suffered from various factors like animals, weather, accidents, road conditions and stuff like that. Vollkasko even pays for accidents you caused yourself, Teilkasko only for some of the aforementioned things. In both, insurers are still required to do some classification by county, but they are allowed to factor in statistics about your car's repair cost.

But none of those will pay for your car just randomly breaking down and needing repairs, that is something you get a manufacturer's warranty for. And none of those is directly related to the mandatory inspections. I think I've read some statistics that driver behaviour and skill is also a large factor in why there are less accidents in Germany, at least compared to some regions of the world... But make of those what you will, that might as well be jingoism and often also comparing apples and oranges...

thyristan··on TÜV Report 2026: Tesla Model Y has the worst reliability of all 2022–2023 cars (2025)
There is an ADAC report, that reports the number of road-side defects per car type that the ADAC was called to fix: https://www.adac.de/rund-ums-fahrzeug/unfall-schaden-panne/a...

And they do provide some statistics about running cost: https://www.adac.de/rund-ums-fahrzeug/auto-kaufen-verkaufen/...

However, both aren't that trustworthy, just better than nothing, because:

The first one about road-side breakdowns is frequently gamed by car manufacturers, because in leasing and warranty contracts they often require the use of their own road-side assistance orgs, thereby bypassing ADAC. So the more expensive German manufacturers are definitely underrepresented there.

And generally, ADAC has been known to produce unreliable tests and statistics: https://www.focus.de/auto/ratgeber/sicherheit/neue-vorwuerfe... https://www.sueddeutsche.de/auto/neue-enthuellungen-sind-auc...

thyristan··on TÜV Report 2026: Tesla Model Y has the worst reliability of all 2022–2023 cars (2025)
I do drive to work almost every day, and I don't drive an electric car. So there is sufficient use.

And quite a few decades ago, people noticed that when you mix chromium, nickel, vanadium or things like that into your steel, it doesn't rust. Car manufacturers are just very slow in noticing.

thyristan··on TÜV Report 2026: Tesla Model Y has the worst reliability of all 2022–2023 cars (2025)
Worn brake disks are a manufacturing problem. Nominally my VW needs new brake disks every 100Mm. Practically it needs new ones every 40Mm, because VW makes them from shitty steel that rusts and wears like hell, especially when there is salt on the roads in winter.

Some manufacturers use better steel and therefore have a longer disk lifetime.

thyristan··on TÜV Report 2026: Tesla Model Y has the worst reliability of all 2022–2023 cars (2025)
TÜV is the largest such organisation in Germany and almost has a monopoly. The inspections themselves are colloquially even called "TÜV", even if you do it at some other org.

However, as others have written, there is still some huge bias in those numbers. Especially German brand car shops provide an inspection service, where they pre-check and repair the car before the official inspection. Many of those German brands are also very big on company leasing, to the point where almost nobody buys a new BMW, Mercedes or Audi privately, they either get a new one as a company car via company leasing, or they get a used leasing return car. All those leasing cars always have the aforementioned inspection service as part of the leasing package. So those numbers are to be taken with a huge huge grain of salt.

thyristan··on TÜV Report 2026: Tesla Model Y has the worst reliability of all 2022–2023 cars (2025)
The report from the original article is not a general problem rate but more specific: TÜV does mandatory technical inspections every two years. In those inspections, only safety- and environment-critical problems are checked for, so e.g. brakes, rust on structural parts, high emissions, non-working lights. But there is a whole bunch of stuff that they don't check for, e.g. heating/cooling, GPS not working, doesn't charge/start sometimes, ...

So it's quite possible that both are true: Maybe ID4 has lots of non-safety and non-environment problems, so it is in the shop very often, but still rarely fails an official inspection.

thyristan··on IPv6 just turned 30 and still hasn't taken over the world
Usually there is no official justification given, just a list (in excel...) of security requirements that have to be ticked off. One of them is "Disable IPv6".

I've heard some ex-post justifications, make of them what you will: Existing infrastructure like firewalls, VPNs and routers might not be able to handle IPv6 properly. Address distribution in IPv6 is unpredictable. No inhouse knowledge of IPv6. Everything has an address in IPv6, so the whole internet can access it. No NAT in IPv6, so it is insecure. IPv6 makes things slow.

thyristan··on IPv6 just turned 30 and still hasn't taken over the world
Ink on paper, where I work. There have been court decisions that have seen Fax as "remote copying". And said that those remote copies only had any legal value if there was an actual paper original. Thus the workflow always has to involve paper that is then archived as paper in a folder...
thyristan··on IPv6 just turned 30 and still hasn't taken over the world
German situation is mostly/rarely/never. Small businesses have their DSL line where their cheapo router will announce an IPv6 prefix which almost all ISPs over here provide. Medium to large businesses usually have some braindead security policies that include switching off all IPv6 functionality in devices.
thyristan··on Finland detains ship and its crew after critical undersea cable damaged
Yes, and the three western allies agreed to let their occupation zones form a German state. Which the Soviets opposed and had their occupation zone form an East German state, thus dividing Germany at their zone boundary. The Soviets did the dividing, the other allies did no such thing.
thyristan··on Finland detains ship and its crew after critical undersea cable damaged
> But even accepting that argument, at the very least you'd have to agree that if the people decided to change the constitution through means other than those the constitution propose, then that could still be perfectly democratic.

Yes, of course. If the voters, or at least their democratically elected representatives, decide that a new and different constitution is necessary, that's totally fine and expected. Some more modern constitutions even point this out explicitly.

thyristan··on Finland detains ship and its crew after critical undersea cable damaged
There is ample precendent for impounding the assets of hostile nations. The Soviets did it to Germany in WW2, so they cannot really claim that they are opposed to that practice.

The only reason why this seizure of russian money in Belgium might be a bad idea is reciprocity. Russia would of course then try to seize European assets in Russia.

And regarding ships, prize law is still internationally accepted and in effect. Ukraine can offer prize letters to privateers or foreign navies, allowing the seizure of Russian ships. Or they can seize ships themselves. When those ships are then in a Ukrainian or allied harbor, a Ukrainian admirality court then assigns ownership of the vessel and all goods to the ones who brought it up. https://en.wikipedia.org/wiki/Prize_(law)

thyristan··on Finland detains ship and its crew after critical undersea cable damaged
> We the People of the United States [, in Order to ...,] do ordain and establish this Constitution for the United States of America.

That is the literal first paragraph of the US constitution. I cannot imagine a valid legalistic argument that ignores that. When first establishing the constitution, it also didn't appear in a vacuum, the pre-existing states and confederation were already democratic for some time. So all authority/validity/legitimacy the US constitution has comes from the population, back then. And through continuing use, participation and broad acceptance until present.

And of course, as a practical matter in a representative democracy, between elections, the people do have far less of an influence. They can basically only voice their opinions, threaten to vote differently in the next election, or start a revolution. But that doesn't absolve them of their responsibility on election day.

thyristan··on Finland detains ship and its crew after critical undersea cable damaged
Oil tankers are basically "weapons of mass environment destruction" (slight hyperbole, sorry ;). When you shoot at them, or their captains have the valves opened, their oil will devastate a sizable chunk of sea and coastline.

So you really need to tread lightly around enemy oil tankers.

thyristan··on Finland detains ship and its crew after critical undersea cable damaged
I can see a few advantages:

Internal Propaganda. You show to your own people, that you can cut off the enemies' communication lines easily.

External Propaganda. You show to the enemies that they are vulnerable, spreading fear and doubt in their own strength.

Exercises for larger operations. You train ships' crews for those kinds of maneuvers, in case you need to to it a large number of times, e.g. to cut off all baltic cables at once, cut all transatlantic cables, cut all cables to some important island like Iceland, etc.

Internal Normalisation. You get the ships' crews, your population and your governance structures used to a more aggressive mode of operations.

External Normalisation. You get the enemies' population and governance structures used to those kinds of pinpricks. So when the large-scale operation starts, they will ignore the first signs as "just the usual irrelevant pinpricks".

Testing and mapping connectivity. When the cable goes down, you can have your spies look at which relevant infrastructure goes down at the same time.

thyristan··on Finland detains ship and its crew after critical undersea cable damaged
In a democracy, "We The People" is the sovereign. It is in the hands of the voters, and it is their responsibility to choose leaders wisely and shape their overall legal system. In democracies, the population doesn't get to use the "but its just our evil leaders" excuse. Only in other less democratic forms of government.

And yes, this means that in a democracy, the opposition's voters are screwed because they share in the responsibility, even if they were right. Why? Because they were unable to convince the majority of the wrongness of the majority vote.

thyristan··on Finland detains ship and its crew after critical undersea cable damaged
"Benevolent" more in the sense of "currently unable to order the next massacre". The German unification only went ahead because soviet troops didn't intervene like they did in many prior instances:

> https://en.wikipedia.org/wiki/East_German_uprising_of_1953

> https://en.wikipedia.org/wiki/Prague_Spring

> https://en.wikipedia.org/wiki/1956_Georgian_demonstrations

Glasnost and Perestroika under Gorbachev were not benevolence but necessary because the centralized power of the Soviet Union was dwindling. The SU became more and more occupied with fixing its own problems and could no longer hold together the Eastern Bloc by influence or force. Which is why the Eastern Bloc then slowly dissolved. This didn't start with the German unification, but earlier, and encompassed Poland, Hungary, Romania, Yugoslavia:

> https://en.wikipedia.org/wiki/Revolutions_of_1989

The SU (who are actually dominated by, but different from "the Russians") certainly would have liked to hold it together. And while under Yeltsin, there was a period of acceptance of the dissolution of the SU, currently Putin seems to want to revive it, at least in terms of territory.

thyristan··on The architecture of “not bad”: Decoding the Chinese source code of the void
Same for a German.

Scales of goodness of expressions are shifted relative to English: "good" (gut) to a German means "it totally fulfills all my needs and expectations, so it is perfect for my purpose". "very good" (sehr gut) means "it exceeds all my expectations" and to a German already sounds like total hyperbole. Anything like "delightful" or "excellent" to a German sounds either totally sleazy or sarcastic.

When something is not perfect but adequate and we are happy with it, we would say something like "not bad", "it's fine" or "you can leave it like that". Which to the english speaking world has totally different connotations and can lead to rather interesting misunderstandings.

And especially "not bad" ("nicht schlecht") can be confusing in that it is sometimes something rather positive. It, in German and said in the right tone of voice" can mean "this is suprisingly good".

thyristan··on Linux CVEs, more than you ever wanted to know
Maybe.

But you cannot PoC most hardware and driver related bugs without lots of time and money. Race conditions are very hard to PoC, especially if you need the PoC to actually work on more than one machine.

So while a PoC exploit does mean that a bug is worthy of a CVE, the opposite isn't true. One would overlook tons of security problems just because the discoverer of them wasn't able to get a PoC working. But it could be worth it, to maybe also keep the slop out.

thyristan··on Linux CVEs, more than you ever wanted to know
All the issues basically boil down to "nobody wants to do the busywork of CVE filtering, triage, rejections, changes".

As a developer, kernel or otherwise, you get pestered by CVE hunters who create tons of CVE slop, wanting a CVE on their resume for any old crash, null pointer deref, out of bounds read or imaginary problem some automated scanner found. If you don't have your own CNA, the CVE will get assigned without any meaningful checking. Then, as a developer, you are fucked: Usually getting an invalid CVE withdrawn is an arduous process, taking up valuable time. Getting stuff like vulnerability assessments changed is even more annoying, basically you can't, because somebody looked into their magic 8ball and decided that some random crash must certainly be indicative of some preauth RCE. Users will then make things worse by pestering you about all those bogus CVEs.

So then you will first try to do the good and responsible thing: Try to establish your own criteria as to what a CVE is. You define your desired security properties, e.g. by saying "availability isn't a goal, so DoS is out of scope", "physical attacker access is not assumed". Then you have criteria by which to classify bugs as security-relevant or not. Then you do the classification work. But all that only helps if you are your own CNA, otherwise you will still get CVE slop you cannot get rid of.

Now imagine you are an operating system developer, things get even worse here: Since commonly an operating system is multi-purpose, you can't easily define an operating environment and desired security properties. E.g. many kiosk systems will have physical attackers present, plugging in malicious hardware. Linux will run on those. E.g. many systems will have availability requirements, so DoS can no longer be out of scope. Linux will run on those. Hardware configurations can be broken, weird, stupid and old. Linux will run on those. So now there are two choices: Either you severely restrict the "supported" configurations of your operating system, making it no longer multi-purpose. This is the choice of many commercial vendors, with ridiculous restrictions like "we are EAL4+ secure, but only if you unplug the network" or "yeah, but only opensshd may run as a network service, nothing else". Or you accept that there are things people will do with Linux that you couldn't even conceive of when writing your part of the code and introducing or triaging the bug. The Linux devs went with the latter, accept that all things that are possible will be done at some point. But this means that any kind of bug will almost always have security implications in some configuration you haven't even thought of.

That weird USB device bug that reads some register wrong? Well, that might be physically exploitable. That harmless-looking logspam bug? Will fill up the disk and slow down other logging, so denial of service. That privilege escalation from root to kernel? No, this isn't "essentially the same privilege level so not an attack" if you are using SElinux and signed modules like RedHat derivatives do. Since enforcing privileges and security barriers is the most essential job of an operating system, bugs without a possible security impact are rare.

Now seen from the perspective of some corporate security officer, blue team or dev ops sysadmin guy, that's of course inconvenient: There is always only a small number of configurations they care about. Building webserver has different requirements and necessary security properties than building a car. Or a heart-lung-machine. Or a rocket. For their own specific environment, they would actually have to read all the CVEs with those requirements in mind, and evaluate each and every CVE for the specific impact on their environment. Now in those circles, there is the illusion that this should be done by the software vendors, because otherwise it would be a whole lot of work. But guess what? Vendors either restrict their scope so severely that their assessment is useless except for very few users. Or vendors are powerless because they cannot know your environment, and there are too many to assess them all.

So IMHO: All the whining about the kernel people doing CVE wrong is actually the admission that the whiners are doing CVE wrong. They don't want to do the legwork of proper triage. But actually, they are the only ones who realistically can triage, because nobody else knows their environment.

← PreviousPage 3 of 12Next →