HNHacker News
TopNewBestAskShowJobs

timmattison

73 karma · joined October 27, 2014

submissionscomments
timmattison··on Trellis – 3D mesh generative model
Agree with this on many levels. Some people idolize movie directors but in the most simplistic view everyone else is doing the “real work”.

Not everyone needs to do everything. And if someone’s amazing idea can get out of their head and onto paper/film/video or into a game I’m all for it.

There will be a lot of AI shovelware junk. But it doesn’t all have to be that way. Now more people compete on larger landscape of ideas.

timmattison··on Llama-OCR: Document to Markdown
I love this. Can you share the source?
timmattison··on Apple's requirements are about to hit creators and fans on Patreon
Apple Pay and Google Pay work with an existing card for normal (non-IAP) purchases. I don’t like rent seeking either but in this case it’s the standard CC payment flow. Nothing additional, just better security.

What makes a normal CC better?

timmattison··on Unix forking the universe by running IBM's free online quantum computer
Where is the best place a layman can dig into this statement “You do this by taking advantage of the fact that the superposition is a periodic function and the amplitude repeats.”? I’ve seen articles hinting at this in an obtuse way but I’d love to see something more approachable to help wrap my head around it.
timmattison··on IceCube observes seven potential tau neutrinos
I was hoping to hear he went from rapper to physicist. Guess not.
timmattison··on Interesting ideas in Observable Framework
You can. But then the only time it realizes that the code has been updated is when you update the script or touch it. It’s a minor annoyance but it adds up when making lots of changes. Periodically deleting the cache works too but also annoying.
timmattison··on Go(lang): Robust generic functions on slices
I haven’t used strtok in a long time but my recollection is that it mutates the original string by placing a NULL value at the next delimiter so “hello world” would become “hello<0x00>world” if splitting on spaces. This lets you loop with the same string passed to strtok until it is done.

It’s ugly. Would not recommend. 0/10

timmattison··on FCC: Telcos must now tell you when your personal info is stolen
Wow, they have to do what other companies have to do. Brutal. /s
timmattison··on P2pcf: P2P WebRTC via Cloudflare Workers
I use WebRTC in non-browser applications primarily. For those systems you can use mDNS.

I have been working on WebRTC a lot lately. If you have ideas on how you’d solve this issue I’d take a stab at implementing them.

I’ve built a demo that lets you get two systems connected by copying and pasting the session description information. No third party systems required. But you still need to get your clipboard data to someone else. Which usually means SMS, Apple Messages, etc.

timmattison··on P2pcf: P2P WebRTC via Cloudflare Workers
You knowing your subnet is not the issue. The other party needs to know it.

WebRTC needs info about where to try to connect. It doesn’t specify the signaling method which is how you get that information and share it.

If you’re already on the same subnet, use mDNS.

If you’re on different subnets it requires some kind of way to share the subnet info.

If you’re on different networks behind NAT then scanning isn’t very helpful. You’d need to scan IPs and ports because NAT randomizes the outbound ports. That’s what STUN helps you figure out. Once you’ve got that info and you build the session description structure you can send that to the other party however you want.

Public, free STUN servers exist. And people use them for all kinds of WebRTC stuff.

Neither WebRTC nor WebSockets prevent pure P2P. It sounds like your bigger issue is with NAT. IPv6 isn’t going to fix it though since the IP space will be too large to scan for peers.

timmattison··on Twitter Traffic Tanking
Because in the beginning SMS support was important and the 140 character limit worked well with the SMS 160 character limit.
timmattison··on Credit Suisse sheds nearly 25%, key backer says no more money
Not anymore - https://www.moneyland.ch/en/numbered-bank-account-switzerlan...
timmattison··on Judge rules Charter must pay $1.1B after murder of cable customer
This comment is legendary
timmattison··on 2022 NSA Codebreaker Challenge
Ah, other comments say that domain names are restricted. Missed that!
timmattison··on 2022 NSA Codebreaker Challenge
The registration page just asks for an email address and a password. How are these people blocked from participating?
timmattison··on New MacBook Air with M2
They’ve been doing this with a lot of products for a long time. “Today we announce iPhone … with iPhone you can do anything!”

I think it is very strange.

timmattison··on Trivago fined $45M for misleading customers on hotel pricing claims
“Trivago earned approximately $92 million in revenue from those non-cheapest top position click-outs”

$92M - $45M = $47M

Average pay out to customers who were ripped off = $0

Incentive to not do this again = 0

timmattison··on No patches for digital audio releases
I used to report broken tracks to Google when I had Google Music. I gave up. I’d get a form letter that said to reset my cookies, uninstall and reinstall the app, etc. every time.

I’d write and explain the problem was with the same song, on different machines (Windows, Linux, and Max) and both Android and iOS. Still got the same form letter back.

I’ll almost guarantee that if I search my email for the broken tracks they’d still be broken. One was Saddam-a-Go-Go by GWAR. A few seconds in it just skips ahead a few seconds from one lyric to another.

timmattison··on Running GUI apps within Docker containers
I love the idea of this. I’ve struggled to get a setup like this to work on MacOS though. Which X server is the “right” one to use? Which is the easiest? Is there some way to make it work seamlessly with built in tools?

As an aside, instead of talking about growth hacking, and OSINT I think this whole thing could be a lot more relatable if the author chose a simple motivation like privacy. Another comment here mentioned subtools (?) which clearly highlights that not everything should be trusted with full access to your system.

timmattison··on Discord is a black hole for information
Sure. But when you first join there is no history which means that anyone new to the channel would ask the same questions because there was nothing they could search.
timmattison··on Rich: A Python library for rich text and formatting in the terminal
Take a look at TermKit - https://github.com/unconed/TermKit

Long abandoned but I’d love something like this. Someone I know tried to revive it but Node has changed so much that they gave up.

I would donate to an effort to revive it.

timmattison··on Show HN: Slim 2: Create VM from Dockerfile, boots in seconds (+macOS M1/Hyper-V)
I think you should add the steps (or some links) on how to start this image on a Mac. With that missing “glue” I would definitely try it. Right now I’m anticipating that after setting up cloud-init I’m on my own to figure out how to run it.
timmattison··on Privacy Is a Human Right
I just get a page that says I’m not authorized to access this page. Privacy to the max!
timmattison··on AWS SIGv4 and SIGv4A – How AWS signs and verifies API requests
Wow, I tried this (or another similar project) a few years back and loved it. Nice work! Sorry it is still pending though. I don’t work on the SDKs unfortunately.

On the auth side, the major change since then is that you can use the IoT credentials provider to provide certificate based auth to all services (https://docs.aws.amazon.com/iot/latest/developerguide/author...). You don’t need to be using any of the other IoT services. It was created to make it easier for devices to use AWS services but can be used by anyone/anything.

What we did was combine the AWS CLI feature to source credentials from an external process (https://docs.aws.amazon.com/cli/latest/userguide/cli-configu...) with a script to do the certificate based auth. This allows you to obtain STS credentials using a certificate and pass them to the CLI (access key, secret key, session token). Your secure hardware just needs to do the normal work of assisting in the mutual TLS auth which in our case was done with curl and Zymbit’s OpenSSL engine. We are releasing that code along with a SoftHSM2 setup so people can see how it works in a test environment.

timmattison··on AWS SIGv4 and SIGv4A – How AWS signs and verifies API requests
You can email me at tim at mattison dot org if that works for you
timmattison··on AWS SIGv4 and SIGv4A – How AWS signs and verifies API requests
In this case it was a Zymbit Zymkey 4i which contains a secure element with a bunch of additional functionality (tamper detection, etc) and works with a Raspberry Pi. Now I’m wondering how easily it could be adapted for use on a laptop with a TPM…
timmattison··on AWS SIGv4 and SIGv4A – How AWS signs and verifies API requests
We actually just did a livestream today at AWS about how to store a credential in an HSM to avoid having IAM credentials in clear text. You can see it here - https://www.twitch.tv/aws/video/1156973272

We haven’t released the code yet but are in the process. If you think this could work for you or you’d just like to see how we did it DM me on Twitter @timmattison and I’ll give you the code ASAP.

timmattison··on Gift card gang extracts cash from 100k inboxes daily
A previous comment mentioned the hackers setting up rules to automatically delete messages that would inform the user they were hacked.
timmattison··on Use of artificial intelligence for image analysis in breast cancer screening
Well, just like all technology that wasn’t perfect from the start we should probably just give up. /s
timmattison··on Charter charges more money for slower Internet on streets with no competition
I’ve always suspected this. Same with TV. Internet+phone+TV = $X. Remove any single component or just choose one and the price is > $X. Makes no sense. I was told at some point if I remove TV and phone my price would go from $90 month to $500 month for just Internet. Their answer is always “it’s a bundle discount!”
Page 1 of 2Next →