HNHacker News
TopNewBestAskShowJobs

tomkwok

3,146 karma · joined March 16, 2014

.
submissionscomments
tomkwok··on Ask HN: Who is hiring? (April 2022)
Read the whitepaper and sent some comments to the email. Please check.
tomkwok··on The origin of Covid: Did people or nature open Pandora’s box?
Previous submission (3 days ago): https://news.ycombinator.com/item?id=27026039
tomkwok··on Show HN: Svgasm – SVG animation from single GIF using tracer
Do you mean recompiling primitive or svgasm to JavaScript? No, it is not currently possible.

But yea it would be cool to have a web version of svgasm that uses some Javascript raster image tracers out there. I will be working on it and posting to HN later to anyone who's interested.

tomkwok··on Show HN: Svgasm – SVG animation from single GIF using tracer
Thank you for your interest. What browser do you use? It seems to work better on Safari on my MBA.

Also, as stated on my GitHub page I used primitive [1] for the lions example. What svgasm adds to primitive and other tracer tools is the ability to process a GIF (or a sequence of images) and make an SVG animation out of the sequence.

[1]: https://news.ycombinator.com/item?id=12539109

tomkwok··on Show HN: Svgasm – SVG animation from single GIF using tracer
Hi HN readers. I created this command-line tool called svgasm to automate the generation of an SVG animation from a lot of SVG files. Originally I made this tool to create a dumb SVG animation from a bunch of matplotlib SVG exports. Then, I had the idea of using this method to sequence traced/vectorized versions of raster frames extracted from a GIF to create a time-discretized SVG animation, which is found to be generally aesthetically pleasing and smaller in file size. I created a bunch of GIF vs SVG side-by-side comparison examples with some interesting GIFs that I found online. The examples can be viewed on https://github.com/tomkwok/svgasm. Please tell me if the SVG animations work on your laptop/PC, especially the more complex SVGs like the infinity spiral example.
tomkwok··on Freenom World – A fast and anonymous Public DNS resolver
> DotTK and now Freenom have been great enablers for many smaller hobby sites. Get free webspace from bplaced, domain from freenom and CDN from CloudFlare and you have a pretty decent, ad-free infrastructure for a quick-and-dirty web project. A scratchpad solution basically.

Agreed. But never use free .tk domains for anything serious. DotTK is notoriously for deleting domains registered for free from a user's account without any notification to the user as soon as the domain gets some amount of traffic according to many reports online.

tomkwok··on Freenom World – A fast and anonymous Public DNS resolver
Freenom appears to be the company managing the (in)famous "free" ccTLD .tk

No, thanks.

http://www.freenom.com/en/aboutfreenom.html

tomkwok··on Windows 10: Microsoft launches intrusive full-screen upgrade reminder
Well at least they now give a "Do not notify me again" option, which they previously didn't even include in popups according to earlier reports.
tomkwok··on Spotify is down for many users
Can confirm. Currently it says I'm offline.

Edit: It seems to be back online (at least for me).

tomkwok··on [XKCD Flowchart] How to tell the year of a map, from it's features
http://explainxkcd.com/1688/
tomkwok··on Free VPN integrated in Opera for better online privacy
It has been... See https://news.ycombinator.com/item?id=11177438
tomkwok··on Yes, I’m a nine-year-old girl. But I’m still a serious reporter
https://news.ycombinator.com/item?id=11434910
tomkwok··on How Google’s Web Crawler Bypasses Paywalls
> Google's Web Crawlers are not "bypassing" paywall. It's the paywall that let's crawlers through. I.e. exactly the reverse of what the author implies with their headline.

Don't nitpick. It's just a shortened version of How To "Be" a Google’s Web Crawler to Bypass Paywalls. You get it. I get it. Everyone gets it.

tomkwok··on Who are the Chinese tech companies that just bought Opera?
Isn't Opera closed source?
tomkwok··on Britney Spear's Guide to Semiconductor Physics (2000)
> *Spears'

No. Spears's

tomkwok··on The Word “Million” Didn’t Exist Until We Needed It
> There is no actual "word" for million in Chinese.

> 百 is a hundred, 萬 is ten-thousand. A million is 百萬. But also I'm guessing 400萬 could be understood as the same as 4百萬/四百萬.

But there is 億 in Chinese which means a hundred million.

     十                     10 ten
     百                    100 hundred
     千                  1,000 thousand
     萬                 10,000 ten-thousand
    十萬                100,000 hundred-thousand
    百萬              1,000,000 million
    千萬             10,000,000 ten-million
     億            100,000,000 hundred-million
    十億          1,000,000,000 billion
    百億         10,000,000,000 ten-billion
    千億        100,000,000,000 hundred-billion
    萬億 or 兆 1,000,000,000,000 trillion
萬 and 億 are traditional Chinese characters. The simplified characters are 万 and 亿 respectively.

兆 is usually avoided because it does not only mean trillion but also 百萬 (million) in mainland China's translation of "mega-byte" or "mega-pixel" for example.

tomkwok··on Signs of Liquid Water Found on Surface of Mars, Study Says
NASA's 'Mars Mystery Solved' Press Conference starts at 11:30 a.m. EDT.

Live TV: http://www.nasa.gov/multimedia/nasatv/

tomkwok··on Perceptual Image Compression at Flickr
imgmin: https://github.com/rflynn/imgmin
tomkwok··on Popular Chinese iOS apps compromised in malware attack
Tencent security team just posted a write-up on this issue on its blog. http://security.tencent.com/index.php/blog/msg/96

Here's the English translation:

---

Sep 12 - When we were tracking down a bug, we discovered that there was suspicious encrypted traffic sent from one/some app(s) to one/some particular domain(s) when the app(s) was/were launched or closed. Front-end security team immediately followed the issue.

Sep 13 - Tencent product team released an updated version of the app(s). We notified CNCERT of the issue.

Sep 14 - CNCERT issued a pre-warning on its website. [1]

Sep 16 - We discovered that 76 of the top 5000 apps on App Store were infected. We notified Apple and most of the app vendors of the infected apps of the issue.

Sep 17 - Palo Alto Networks also discovered the issue and published a report of their preliminary findings[2], and so did Ali mobile security team[3].

Analysis

1. Infected apps send the following information to attackers' servers: app name, app version, iOS version, locale, device type, country code, IDFV. The domain used is icloud-analysis.com. We also discovered three other domains that are not used.

2. Attackers can identify every infected iOS device and issue commands to be executed via the openURL API.

3. Attackers can invoke a customized alert box on infected iOS devices, showing whatever they want.

4. The malicious remote control module itself is vulnerable to MiTM attack.

It should be noted that multiple versions of the remote control module are discovered, some of which do not have the capability described in (2) and (3).

[1] http://www.cert.org.cn/publish/main/12/2015/2015091415282115...

[2] http://researchcenter.paloaltonetworks.com/2015/09/novel-mal...

[3] http://drops.wooyun.org/news/8864 (Chinese)

tomkwok··on Popular Chinese iOS apps compromised in malware attack
@XcodeGhostSource on GitHub claims to be the author of the malware and open-sourced it and apologizes.

"XcodeGhost" Source: https://github.com/XcodeGhostSource/XcodeGhost

tomkwok··on Hit Charade
The previous story about Max Martin (Martin Karl Sandberg):

https://news.ycombinator.com/item?id=7127488 [600 days ago] One Man Has Written Virtually Every Major Pop Song Of The Last 20 Years

tomkwok··on Most interesting datasets/APIs?
The first 10M items (comments and stories) on HN: https://news.ycombinator.com/item?id=10002791
tomkwok··on Ask HN: How easy/hard is it to offer HTTPS to your users?
The major downside I know is that in case your private key is compromised and you want to revoke the certificate, you have to pay $24.90.

> Even though StartSSL™ provides certificates generally free of charge, revocations thereof may carry a handling fee. Take great care of your private keys, save and backup all files all the time!

See more on https://www.startssl.com/?app=37

tomkwok··on Ask HN: How easy/hard is it to offer HTTPS to your users?
Use StartSSL[1], or self-signed certificates if you just use HTTPS for admin access to some of your sites. You can easily find many online tutorials on how to setup TLS/SSL on your web server after a bit of googling, such as this one[2] on the DigitalOcean community site.

P.S. Judging from your username, it seems like you have played agar.io too much. :)

[1] http://www.startssl.com

[2] https://www.digitalocean.com/community/tutorials/how-to-set-...

Edit: If you can wait until November this year, use Let's Encrypt[3] when it is generally available to the public. At this moment you can also use CloudFlare, which provides free SSL branded as "Universal SSL" if you use their CDN.

[3] https://letsencrypt.org/2015/08/07/updated-lets-encrypt-laun...

tomkwok··on WordSafety – Check a name for unwanted meanings in foreign languages
Coincidentally cha1 ("1" here means the first tone in pinyin) is a sexual innuendo alluding to sexual intercourse. The character itself, which means "to insert", has nothing to do with sex in normal usage though. And most importantly, there is virtually zero resemblance between the pronunciation of "change" and that of "cha1".

> to have sex (lit. insert).

> Source: a long list of Chinese profanity on Wikipedia.[0]

[0] https://en.wikipedia.org/wiki/Mandarin_Chinese_profanity

tomkwok··on Poll: Do you regularly visit these HN sections?
Reference / clickable links at https://news.ycombinator.com/lists
tomkwok··on Show HN: Find your competitors that Google can't
And Google's competitors are ... Googles.

> google.com.my, google.com.tj, google.com.sl, google.ac ...

https://rivalseek.com/search/index.php?searchterm=google

tomkwok··on Firefox exploit found in the wild
Docker containers can sandbox GUI apps[0], but I don't know if it's secure enough. Maybe not.

[0]: https://news.ycombinator.com/item?id=8426764

tomkwok··on 142857
There is a detailed explanation on Quora [0] that I stumbled upon some time ago.

[0]: http://www.quora.com/Why-does-the-number-142857-have-such-in...

tomkwok··on Twitter Contest Winning as a Service
A list of the most frequently occurring words:

    322 ticket
    56  show
    51  concert
    48  another
    48  free
    45  london
    44  code
    44  game
    38  beta
    38  book
    37  copy
    37  logo
    33  club
    33  destiny
    27  festival
    25  pokeman
    24  fifa
    23  Dublin
    23  shirt
    21  UK
    21  city
    20  pass
    20  vip
    19  coin
    19  england
    19  some
    18  card
    17  LA
    17  thing
    16  2x
    16  list
    15  see
    15  signed
    14  manchester
Page 1 of 3Next →