HNHacker News
TopNewBestAskShowJobs

traceroute66

5,810 karma · joined September 24, 2019

submissionscomments
traceroute66··on Eating Fruit Skins
I very much doubt the problem magically disappears with "newer" pesticides.

Afterall, if a pesticide washed off in the rain, it wouldn't be much good as a pesticide .... it would be a very expensive proposition for the farmer to re-apply after each rainfall.

traceroute66··on How Trail of Bits helps verify the integrity of Signal chats
> You don't have to give out your phone number. You can mint an arbitrary "username" and give the username out to people.

You are deliberately missing the point.

Signal are gatekeeping these new advanced security features behind a phone number wall (soon to become paywall if some posts here are to be believed).

traceroute66··on How Trail of Bits helps verify the integrity of Signal chats
> you can buy Mullvad credits on Amazon

That is not the same thing.

You buy a Mullvad scratch card on Amazon and you redeem the token string.

Mullvad also offer the option to put your card number into the Mullvad website, and I'm sure many privacy conscious people would be very reluctant to do that.

Card payments these days leave far too big a trail. The bank knows, the intermediary (e.g. Stripe) knows, and the merchant (e.g. Mullvad) has to keep records for accounting/tax requirements.

traceroute66··on Real-SWE: Benchmarking AI models on private, real-world, enterprise codebases
> How does that work?

My gut feeling is that any serious real-world company with a proprietary codebase worth looking at would not be handing out the crown jewels to a third party. License or not.

I don't doubt somebody licensed their codebase to them, I just have my doubts about who the "who" could be.

traceroute66··on Real-SWE: Benchmarking AI models on private, real-world, enterprise codebases
> You're giving up transparency for it being harder to game

But then if we take that argument to its natural extreme, surely it means people should take the marketing bullshit published in the 100-page system cards published by Anthropic & co as "valuable" too ?

traceroute66··on Eating Fruit Skins
Yeah, erm.

You should only ever eat fruit skins if the fruit is organic and the skin is clean.

At this point I think its safe to say there are hundreds of scientific studies out there telling you why. This is one example[1].

I quote from their abstract:

    Notably, the distribution of pesticides in the apple peel and pulp layers is visualized through Raman imaging, confirming that the pesticides penetrate the peel layer into the pulp layer (∼30 μm depth). Thus, the risk of pesticide ingestion from fruits cannot be avoided by simple washing other than peeling.

[1] https://doi.org/10.1021/acs.nanolett.4c01513
traceroute66··on Real-SWE: Benchmarking AI models on private, real-world, enterprise codebases
So TL;DR benchmarking in a completely non-reproducible manner ?

"Model X performed great, but we can't possibly tell you anything about the code it was looking at apart from it was a large code base from an unknown company".

So basically pinky-promise benchmarking ?

I'm not sure I follow the value here ?

traceroute66··on How Trail of Bits helps verify the integrity of Signal chats
> What is a more private, usable solution for filtering them out than using a phone number?

Since when is giving out your phone number a "more private" option ?

traceroute66··on How Trail of Bits helps verify the integrity of Signal chats
> registering without phone number as a paid option soon

Replacing the need to register with a phone number with a requirement to pay is a better option how, exactly ?

traceroute66··on deSEC – Free Secure DNS
Super, thanks. zonemaster added to my bookmarks !
traceroute66··on deSEC – Free Secure DNS
> Netnod.se uses a DNSKEY that is too small on their main domain.

Interesting, could you expand on that ?

I ran netnod.se through the Verisign[1] and internet.nl[2] and it passes DNSSEC tests ?

[1] https://dnssec-analyzer.verisignlabs.com/netnod.se [2] https://internet.nl/site/netnod.se

traceroute66··on deSEC – Free Secure DNS
> We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC.

I mean, if your definition of "affordable" is free, then sure.

But for the record there are other affordable EU suppliers who do DNSSEC:

    - Bunny DNS[0] is "free" – i.e. only subject to their minimum $1/month account spend fee.
    - RcodeZero is very affordable[1] plus added bonus it is run by the `.at` registry so the infrastructure is solid – business customers only, no private individuals
    - Netnod (only via resellers[2] unless you are a big company or government) – Netnod host the I Root Servers and their public hosting DNSSEC service will soon feature HSM-bound DNSSEC keys
[0] https://bunny.net/dns/ [1] https://www.rcodezero.at/solutions/enterprise [2] https://www.netnod.se/dns/find-a-partner
traceroute66··on My practical approach to surfing the web safely
> Main browser: A restricted Firefox

Mullvad Browser[1] is an example of just that, ready to go for people in the real world who don't have the time or inclination to mess around with random extensions and `about:config` hacking.

Also surprised the blog author made zero mention of the importance of keeping your OS up to date. Its all very well having a patched and hardened browser but not if you're running it on a vulnerable OS.

[1] https://mullvad.net/en/browser

traceroute66··on .name Termination
> given they've been a bit of a hot mess since the early 2010's-ish

No.

Oversimplified summary:

There was a period around 2010 when the management at the time wanted to follow a more commercial route with various unrelated "investments".

Nominet members made it impeccably clear in a very loud manner to management that it would not be tolerated.

Management insisted on a vote which they inevitably lost.

Management departed.

TL;DR Don't piss off Nominet members

traceroute66··on .name Termination
> My point is both that it's hard to tell,

Its not hard to tell for things like ".uk" or other serious suffixes.

It only (maybe) becomes hard(er) to tell for all the vanity ccTLDs that came along in the 2000s. But even then 10 seconds on WHOIS and Google should fix any doubt.

> about the reverence of `co.uk`

What are you on about ? Lots of other countries do it too. Japan is one example given already here, but there are dozens. It is very common practice for country tlds.

traceroute66··on .name Termination
> but you have to admit that the existence of these SLDs (like co.uk)

I'm sorry, what ? Admit ? Confusion ?

In the case of .co.uk it has been around since 1996. HN is a technical forum, most people here should be well aware it is a serious SLD. I honestly can't believe it even needs clarifying.

Hell, if you use AWS Route 53 you'll see they use co.uk as one of their nameserver suffixes[1].

[1] https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/SO...

traceroute66··on .name Termination
> What's so dangerous about it?

Implying lack of trust in `co.uk`

Implying `co.uk` may suffer the same fate at `.name`

Complete FUD.

traceroute66··on .name Termination
> Nobody owns the .co part of .co.uk. If you buy foo.co.uk, that is registered with Nominet, who are the registry for .uk.

Yup. The original statement was dangerous FUD which should be urgently corrected.

traceroute66··on .name Termination
> geez, dude, someone woke up on the wrong side of the bed this morning...

5 seconds on wikipedia or google would have stopped them spreading completely dangerous FUD about .co.uk.

traceroute66··on .name Termination
> disagree on .co.uk being a problem

Nominet and therefore .co.uk has been around since 1996.

.co.uk is not going anywhere, and neither is Nominet.

The only "problem" is the original poster did not do their homework. I suspect they were inferring `uk.co` which is a completely different kettle of fish. The original poster should urgently correct their post.

traceroute66··on My local model setup on an M4 Pro Mac Mini
> I'm able to load a bunch of different models on my little mini-PC with 16GB RAM, but the performance is terrible

With all due respect, I'm not clear why you are so surprised ?

By your own admission its a little mini-PC with 16GB RAM, I'm not sure what miracles you were expecting ?

Its a bit like complaining Rasperry Pi performance is terrible when trying to compile the Linux kernel.

traceroute66··on James Dyson Sold Us on a $400 Hair Dryer. Now He's Trying a $499 Toothbrush
Not a fan of Mr Dyson politically or "inventor" wise.

Politically he was a loud backer of Brexit and then disappeared off to Singapore when it actually happened – he moved back two years later, perhaps having seen the bad PR but that's irrelevant.

"Inventor" wise its always the old story of over-engineered stuff of questionable practical quality. For example his "strawberries" are grown by some hyped-up heavily roboticised methodology, but they taste like crap compared to properly grown strawberries, and they are not much better than your average supermarket strawberry either – I did a comprehensive double-blind taste test with some friends. Meanwhile Dyson sells them at a vast markup.

He should have stopped at the vacuum cleaner, really. Preferably before then.

traceroute66··on Physically Immutable Optical Archive Libraries
> Tape drives are much simpler

Maybe back in the 90's :)

LTO-9 increased track density, increased the total number of tracks by reducing their width and increased linear density.

The "how" certainly does not sound "much simpler" to me ?[1]

    The new, narrower track width was achieved through a combination of improvements in tracking
    performance, new, narrower tunneling magnetoresistive (TMR) readers within the head assembly
    (now <1000nm in width) and optimized writers. The narrower tracks also necessitated
    improvements to the media magnetic layer. Magnetic particles are Barium Ferrite (BaFe) as in LTO-8, but with
    improved characteristics to support the higher linear densities.

    Changes were also made to the tape substrate, with the thickness reduced by 7% from 5.6µm to
    5.2 µm. This in turn enables more tape to fit on the reel – tape length per cartridge has
    increased from 960m to 1035m. The new substrate also features optimized stability
    characteristics to mitigate tape dimensional variations that occur due to fluctuations in
    environmental conditions.
In addition the LTO Program's own technical paper describes how LTO-9 manages dimensional changes in the new substrate with a one-time-per-tape calibration algorithm to control 32-channel recording via closed-loop servo algorithms, plus a longer-block Reed-Solomon C2 code — together getting LTO-9's uncorrectable bit error rate to 10⁻²⁰, a 10× improvement over LTO-8[2]

[1] https://at.ingrammicro.eu/api/cfs/Icecat/PDF.ashx?l=en&s=957... [2] https://www.lto.org/wp-content/uploads/2022/08/LTO-UBER-Tech...

traceroute66··on European Commission Revives Push for Encryption Backdoors in ProtectEU Strategy
This is from 2025. I don't know why someone has seen fit to repost it again in 2026.... I'm guessing they didn't look at the date.

And lots of people here are spouting FUD.

In the ensuing period, the EU took expert advice later in 2025, and as they say in an update a few months later in June 2025[1]:

    The High-Level Group recommended taking a cautious approach to designing solutions for lawful access to systems, whereby industry should not be asked to integrate systems that are likely to weaken encryption in a generalised or systemic way for all users of a service. Lawful access to data must remain targeted and limited to specific communications on a case-by-case basis.

   As a general rule, any solutions should be implemented based on clear standards that are developed with input from all stakeholders, including industry representatives, data protection, privacy and cybersecurity experts, and law enforcement practitioners. However, caution is warranted when dealing with encryption, as underlined by the High-Level Group.
So there is ZERO EVIDENCE that the EU are "pushing for encryption backdoor".

It is instead quite clear from the above that the experts are on "our" side AND the EU are listening to them.

Instead, all these publications are just a reflection of a democratic process of discussing modern threats. The documents clearly mention "terrorism, organised crime, online fraud, drug trafficking, child sexual abuse, online sexual extortion, ransomware".

So it is only fair and reasonable that politicians should be discussing ways to counter these threats. And quite honestly they would not be doing their job if someone did not MENTION "encryption" and ask "the question" to the experts and other stakeholders.

The fact they are DISCUSSING "encryption" does not automatically mean they want to backdoor it.

I know it is alien to people in the US under the present administration, but this is how proper politics works. You openly discuss issues of the day, you seek opinions from stakeholders and experts, rinse and repeat until you make a decision (or not). The present US administration could do with learning a thing or two. ;)

People here need to rein in the FUD.

[1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...

traceroute66··on Woman stranded in Spain after UK's eVisa system mistakes her for twin sister
> If a person off on holiday just had their face burned off

I suggest you actually read my post, because its clear you did not.

If you had read it, you would have seen the phrase "Of course, if you have a temporary mismatch due to being injured on holiday that's different.".

I quite clearly excluded holiday injury.

traceroute66··on Woman stranded in Spain after UK's eVisa system mistakes her for twin sister
I don't follow.

You cite three meaningful changes in biometrics: disfigured, loss of fingerprint and retinal issues.

In all three cases surely the right and proper thing do to is to get your details updated on the system ? It may even be a legal requirement for you to do so in the case of official ID documents.

Of course, if you have a temporary mismatch due to being injured on holiday that's different.

But for a permanent thing I just don't see why you would not just get stuff re-issued or updated.

traceroute66··on I dream of quieter computing
Please do not attempt to move goalposts.

My original comment was quite clearly about businesses, I wrote company/companies three times.

I was unaware German Impressum applied to a natural person who is not running a business. If that is true, then I agree that is unfair. But I was never seeking to comment on that anyway.

traceroute66··on I Dream of Quieter Computing
> I live in the Czech Republic ....build a website without identifying yourself

I am not familiar with Czech Republic law but out of curiosity I asked an LLM:

     § 435 of the Civil Code (Act no. 89/2012 Coll.)
     The law explicitly says every podnikatel (entrepreneur/business) must include on all business documents and on information made publicly available through remote access (i.e. their website):
     - the company's name (firma),
     - its registered seat (sídlo) or place of business,
     - its identification number (IČO) — the Czech equivalent of a company registration number,
     - and if registered in the Commercial Register (obchodní rejstřík), the registration details including the file reference and section/insert (spisová značka, oddíl, vložka).
    This is the summary provisions that was previously found in § 13a of the old Commercial Code (obchodní zákoník) and is now codified in the Civil Code.
    Consumer Protection Act (Act no. 634/1992 Coll.) — adds requirements when you sell to consumers online: business's name and address, ADR (out-of-court dispute resolution) body information, delivery/payment terms, and — for online marketplaces — how offers are ranked, etc.

I then did a quick Google to attempt to validate the LLM and it seems this is indeed true, I found https://www.zakonyprolidi.cz/cs/2012-89 and putting it through Google Translate, §435 is pretty clear that publication of name and address is required.
traceroute66··on I dream of quieter computing
> it's a very naive thing to think that it's just "customers/suppliers" looking at who they're dealing with

Its still no excuse.

Nobody forces anybody to start a business.

If somebody chooses to start a business then they should do grown-up things like having insurance and complying with the law – which includes publishing their business's contact details.

The legal and good manners reasons for publishing a business's contact details far out-weigh any negative ones.

I am sure I am not the only person on this planet who associates alarm bells with small/medium businesses that try to hide their contact details on their website. As a customer it rings alarm bells that they are going to be a pain the neck to deal with if something goes wrong – if a business is trying to bypass such fundamental requirements, then it makes you think about how they feel about e.g. consumer rights law in relation to handling returns.

traceroute66··on I Dream of Quieter Computing
> Some countries like Germany also require legal contact information (an Impressum). Technically it even applies to sites outside Germany that Germans can visit

I don't understand people bitching about Impressum like its some sort of German-only thing.

I am sure if you looked at the legislation of many countries, you would find similar requirements for companies to identify themselves. Off the top of my head you have Austria, France, Italy, Spain, Switzerland, UK ... and probably the rest of the EU/EEA states as well. IIRC it is also a requirement in a number of Asian countries.

In reality requiring an Impressum (or equivalent in other countries) is no different to having to put identification information on a company's old-school letterhead. Its just good manners so that your customers/suppliers can know who they are dealing with.

Personally I dislike the US attitude of trying your damnest to hide any trace of your company's identifying or contact information from your website. ;)

← PreviousPage 2 of 34Next →