HNHacker News
TopNewBestAskShowJobs

tracker1

13,985 karma · joined August 16, 2012

tracker1.at.hn

My opinions are my own and do not necessarily reflect those of my employer.

* X: [@tracker1](https://x.com/tracker1) * Email: tracker1 at gmail * Website: [tracker1.dev](https://tracker1.dev/) * Keto Blog: [Keto Playhouse](https://medium.com/keto-playhouse)

-----

``` [ my public key: https://keybase.io/tracker1; my proof: https://keybase.io/tracker1/sigs/DAQeHW19H-HCUr1ZBXVK7v0QEKqyv4J40IU227AiCVg ] ```

submissionscomments
tracker1··on GrapheneOS Defends Data-Wiping Function That Blocked US Border Search
So be it, they can send me back.
tracker1··on Ask HN: Crooked Timber showed showed me a virus captcha, What now?
True enough... but even then, you can download and review the script before running. Usually it just detects your OS/Distro and then downloads and runs the appropriate installer. You can also do this by hand.

For that matter, there's always a risk of downloading/installing anything from anywhere. There have been successful compromises of many application supply chains at this point in official release paths. You will accept some risk regardless of your approach.

tracker1··on Ask HN: Crooked Timber showed showed me a virus captcha, What now?
I make it a rule never to give confidential information to an incoming call. I had a primary doctor whose office would send notification calls immediately asking for part of my social security number, I always hung up.... I figured out it was for the doctor later, and commented that it was ridiculous and I wouldn't ever receive any such notifications.

Just that simple practice has kept me reasonably safe, even from an AI scam once.

tracker1··on GrapheneOS Defends Data-Wiping Function That Blocked US Border Search
I'm mixed... if they really thought there was evidence on the phone, they should have seized the phone and acquired a warrant IMO to compel the valid, non-destructive PIN be given over.

As I mentioned earlier, this is part of why my own plans for international travel are to only go with a notebook/sheet with contact numbers and buy throwaway devices on the other side. I don't think I'd travel internationally with a phone or laptop at this point, and that's kind of been my thoughts for a while. Especially given the direction that many countries, not just the US have taken. For that matter, I don't think I'd ever even risk travelling to the UK or China at this point. Not that I like the surveillance state here in the US, at least I still have some rights preserved.

tracker1··on GrapheneOS Defends Data-Wiping Function That Blocked US Border Search
And this is why part of my plans for any international travel are to simply have a physical notebook with phone numbers to trusted friends/family and to buy throwaway devices on the other side (phone and chromebook or similar).

TBF, similar mindset if I ever attend defcon, etc. as well.

tracker1··on The startup's Postgres survival guide
I'm more fond of just number+label files and a simple log as deployed to prevent re-run scenarios... Grate/Roundhouse does that for me... I don't use all the features, just separate each sproc/view and the up directory of migrations. This is checked into source control and gets deployed with the services themselves.
tracker1··on The startup's Postgres survival guide
yeah, 1-2 across an index is fine... but I've seen live websites with very normalized structures where it took no less than 30 joins to get a flat view of a single resource. I could do the same with about 4 secondary queries (each with several joins), but I was trying to map a mental model of where all the data lived as a single view, so I could extract flat records for a search database.

There was absolutely zero advantage in how the data was structured in that case (auto classifieds website).

That's not to say that database normalization and modest level of joins is always bad... it's just something that can go too far, and holds things back even more in certain environments. FWIW, I started bundling child data in XML before JSON was a thing in highly controlled environments where any schema change was very difficult and required approvals through several groups in a large banking org.

That JSON is fairly well supported today only makes this an easier and better option IMO. Again, sometimes, but enough times to make note of.

tracker1··on My security camera shipped a GitHub admin token in its login page
I appreciate the pedantry, but in this case it's pretty immaterial to what specifically it refers to, and yeah, I'm pretty boring like that.

I made me smile.

tracker1··on Half-Life 2 running natively on HaikuOS
I used to use a shell replacement in the Win2K era that I could do very similar.. I don't even recall what it was called, but you could completely customize pretty much everything. On win2k in particular (vs 9x/me) you could use transparency with the images in the UI/UX. It was pretty nice at the time... When Win7 came out, I liked the taskbar/menu there more and just went stock.
tracker1··on AI companies are shredding rare books
That's one that really gets me... if I'm buying a classic work or reprint, I'd really like a decent copy that can be handed down generationally... no such thing gets published today. I can understand a technical manual or programming book being printed in a lesser quality, even some education materials as they're likely to only be read through maybe once and maybe sparsely used for reference.

I can even understand the cheaper novel prints... but there should be decent hard back/cover copies that are much higher quality than what we see today. There's really zero excuse for it. Other than general enshitification we see everywhere.

I think if a work is out of publication/availability for over a decade, then copyright should maybe be forfeit altogether. Especially, if that would include digital copies, that has pretty much zero production cost.

tracker1··on Half-Life 2 running natively on HaikuOS
Reminds me a bit more of Amiga... that said, I just don't like the "handle" on the windows, and the launcher is a bit odd imo.
tracker1··on Half-Life 2 running natively on HaikuOS
Nifty to see... I always liked BeOS/Haiku from a tech perspective, but really don't care nearly as much for the UX or ergonomics... I really like a lot of the Windows 10 start menu and taskbar, but I do hate the MS search results/ads,etc so I switched to Linux for non-work and mostly Cosmic since later alphas.
tracker1··on My security camera shipped a GitHub admin token in its login page
Which doubly sucks in terms of assigning a DNS name to an IP/PC... and/or opening the assignment to less restricted access... feels just problematic to me.

Again, I don't know any of IPv6 enough to use it really right or wrong.

tracker1··on The IBM PC, Part 1: Arrival
In retrospect, I think IBM would have been much better off if it had done two things differently... Made the deal with MS such that any external sales had a minimal price with a kickback to IBM, and that IBM would license its BIOS directly to third party MFGs.

If they'd have done that, much like MS, they'd have a piece of every PC sale, not just their own hardware.

That said, I don't think IBM culture could ever have that level of foresight or for that matter hold back the greed to try to own the whole pie. Just watching what became of OS/2. By the time NT4 came out, it was pretty much over... NT4 was leaps and bounds nicer to work with than OS/2 had been, and the software much more plentiful.

Not that MS was much better in terms of monopolistic tendencies, they managed to leverage their position both better, and in many ways have better overall offerings. Then again, MS today is a poor shadow itself of what it could have been had they not tried to start leveraging their own desktop customers for pennies on the dollar. Linux will erode their market share over time, and frankly, I'm surprised that MS doesn't have an AppImage/Flatpak version of MS Office for Linux that they license. They still have relatively nice tools, and though their online versions mostly work, it's not nearly as good and a lot of the integrations are still clunky.

tracker1··on Em dashes are fucking amazing
MS-Word will replace " - " inside a paragraph with an em dash, fwiw. I don't know for sure about other word processors, I don't use them much tbf.
tracker1··on Em dashes are fucking amazing
I just know that MS-Word will replace a hyphen with an em dash in practical use, which is a big part of why I didn't really pick it out as an AI thing in general. Though AI, in particular Chat GPT, does tend to use a lot of them.
tracker1··on My security camera shipped a GitHub admin token in its login page
I'm largely with you... I would think they'd take the IPv4 block and have a direct/virtual block that just extends it to more addresses... so it could be an IPv4 NAT or IPv6 direct.

like 1.1.1.1/192.168.45.4 ... for a router that understands IPv6, that's the direct route to the sub-network, otherwise it will have to use IPv4, and the subnet route is treated as NAT and otherwise isolated.

To me, that would make more sense... then internal IPv6 might be practically limited to 10. and 102.168. in the nearer term, but adoption would be MUCH simpler in practice, and distribution would mostly already be established, however unfairly, but can then be broken into single addresses and vNext adoption could be that much quicker as a result of piggybacking.

tracker1··on My security camera shipped a GitHub admin token in its login page
One thing I don't appreciate... Is the nature of NAT protected my internal/home network before... now, I have to actually configure firewall settings etc. to protect IPv6 issued addresses internally.

I know you can just block inbound non-established connections, but it feels like an extra step and complexity. Not to mention, that I really don't understand how IPs are supposed to be provisioned to devices on IPv6. Is there like a 50-100 page book you can recommend "for dummies" on IPv6, that hopefully contains at least a tiny amount of how to configure a common router and/or linux host.

tracker1··on My security camera shipped a GitHub admin token in its login page
I know that on my hosted server, I never bothered to set it up, because I didn't know how to properly configure or sub-net it. I know it's skill issue, but really feels significantly more complicated and even harder to understand than NAT even.

Not to mention, at home, most of the ads I do see (PiHole) are IPv6 addresses.

tracker1··on My security camera shipped a GitHub admin token in its login page
I got a "home" Verizon box, and the first thing I did was change the DNS setting... 1.1.1.1 wasn't working, and I wanted to change it back to default. Verizon's tech support are idiots... they literally wouldn't give me the default DNS IP because they were concerned about security.

Google's DNS worked fine, but Cloudflare's didn't. No idea if they ever fixed it... I'm using it as a backup for my main connection, eventually I'll setup autofailover on my router (OpnSense). For now, I just swap the cables.

tracker1··on My security camera shipped a GitHub admin token in its login page
LOL, they should have just used a 10.x space instead if they wanted slightly simpler numbers.

On the shotgun, or adjacent, I do tend to prefer ammo classes for my nets... 10.22.x.y, where x may be 1, 38, 45, etc. Allows for site to site vpn with friends/family a bit easier to remember.

tracker1··on Nobody knows what a used GPU cluster is worth
lol, meant 1980....
tracker1··on Can a MUD evaluate LLMs? A $99 proof of concept
Would be kind of a cool experiment for a mud-style interface, where each npc/avatar was backed by a lower-cost LLM... similar rules for the npcs in the game, but a background feed, and history of interactions with other players as background.

Maybe limiting npc's to only a certain number of moves that aren't a response to other users per day...

It could be a lot of fun.

tracker1··on Nobody knows what a used GPU cluster is worth
Not to mention, physical limits to lithography are slowing down significantly... so tech will continue to evolve more slowly... it'll never be the jump from 1080-1990 again, for example, even though 1990-2000 was pretty close, 2000-2010 much slower and since 2010 slower still.

What's as or more weird is how much hardware is backordered, and how much live hardware is allocated, but waiting on facilities for operation. And how many facilities are years behind at this point already... all on various credit and dept swaps between all the involved companies... it's not just a balloon, it's a house of cards balanced on a balloon.

tracker1··on Amid nurse shortage, a university rolls out the welcome mat for men
That's the split between skilled and unskilled labor... I'm talking about trades for skilled labor. And no, it's not for everyone...

But using your own example, how many people with bachelor's degrees are asking if "you want fries with that?" Not every, or any path is guaranteed success... I've worked with plenty of degreed programmers who aren't able to function at all.

tracker1··on The startup's Postgres survival guide
How do you handle schema changes after your project is in production?

I mean, sure start with a unified schema file until you have a production release... deploy, populate with placeholder data, etc... but once released, having a file for each set of changes isn't a bad thing.

Also, the management tools you can have single files for each view/sproc, etc... it's just schema migrations you need to take care of.

tracker1··on Amid nurse shortage, a university rolls out the welcome mat for men
Yeah, I don't mean maintenance staff for like a rental company, but just running your own repair business, or working with a more established one.

Just being able to do basic drywall and paint along with simple wiring for electronics (hanging/wiring a wall mounted TV, for example). Can do pretty well, ex: $100+/hr .. though you're not going to be 100% productive.

tracker1··on The startup's Postgres survival guide
On migrations, there's a .Net tool called Grate that I tend to use for schema migrations... I don't use all the features, but it works well... using a migration stack in a repository for deployments and a similar tool is IMO more reliable than magic comparison tools or hand migrations in practice. You should defensively write your migrations as much as possible so that re-runs are relatively safe, though the tool helps to handle this.

One bit not mentioned, and particularly useful in more modern RDBMS with JSON binary expressions in the database are to leverage JSON columns and avoid joins altogether for a lot of use cases. There are a lot of times where you have variance of sub-information, or other data where table normalization and joins work against you. Even with indexes, joins are costly, especially under load at scale with millions of simultaneous users. You can avoid a lot of this by simply having that sub-table information inside a JSON field with the row in question.

For example, logs and notes related to a specific field. Variable transaction data (paypal vs amazon vs google payments), where the logs/details from the API aren't something that really needs to be in a separate table but related to the transaction.

Another would be something like a classifieds site where many fields are repeated, but sub-fields can vary dramatically by the type of item or category.

Knowing how/when to leverage denormalization and JSON can be one of the most impactful things you can do in terms of performance in practice, short of falling back to a search database (Elastic, Quickwit, etc), which can also be practical depending on your needs, but adds complexity.

Similarly, knowing how your datagase uses certain types of data/serialization... for example UUIDv7 if you don't mind storing creation time (utc) of a record, or COMB if using say MS-SQL in particular... the serialization of said field in practice helps in terms of understanding how indexes update and impact performance.

I do wish the guide was expanded a bit with lots of specific examples and details... a lot of it is hand-wavy blurbs.

tracker1··on Kimi K3 Is Competitive with Fable; Kimi K3 and Fable Is SoTA
Kind of cool to see.. that said, there's more to a tooling experience than benchmarks and specific models. Cursor, Claude Code, Codex, etc. add to the mix. Things like Open-Router and backend options make it easy enough to test.

The tools, libraries and languages you are using can also dramatically affect results. Even on state of the art models, I find, for example, the output of SQL for complex interactions, or C# for that matter to be sub-par, where I find Rust results to be pretty great, with JS/TS falling in between.

At the best, it can feel amazing and productive, at worst, time consuming and annoying that you could have done it faster yourself. YMMV in real world use.

Note: I'm a proponent of human in the loop gatekeeper/reviewer usage of AI, and I'm not able to even consider Chinese models for my own use, and not able to use anything at my day job.

tracker1··on Running Doom on Our Custom CPU and Going Viral
That would be kinda sweet.
← PreviousPage 2 of 34Next →