HNHacker News
TopNewBestAskShowJobs

tripflag

272 karma · joined September 3, 2021

submissionscomments
tripflag··on Recent Performance Improvements in Function Calls in CPython
I've tested a particular python webserver in PyPy and saw roughly the same performance as CPython on average. My guess at the time was that PyPy has a bigger overhead for network sockets than CPython. You would likely see a gain from using PyPy if the webserver did heavier processing in pure python than what mine does.
tripflag··on I turned an old phone into a NAS
That's curious; maybe this is device/distro-specific? I've had good experience using this approach to transfer files to both my tablet (Samsung s2, lineage) and phone (pixel7, grapheneos).

Or maybe Termux is pulling some additional tricks to avoid this issue?

tripflag··on I turned an old phone into a NAS
if you use Termux to host your service, then you can "Acquire wakelock" to keep it available with the screen off. That's an action-button attached to the Termux notification, and I believe also the main reason Termux has a notification (to trick android into not background-killing it).

I have some quickstart notes here: https://ocv.me/termux/

tripflag··on Secure Boot is broken on 200 models from 5 big device makers
The case you're outlining (an uefi rootkit) is pretty much the worst case; assuming you get infected by some malware which decides to install a malicious firmware (BIOS update), then pretty much nothing is getting in the way of that.

What secureboot is designed to prevent is malicious changes to the OS bootloader (a conventional rootkit), which is usually shimx64.efi or grubx64.efi on linux/dualboot machines, or bootmgfw.efi on windows. Secureboot checks the signature of .efi files before they're allowed to run during boot, ensuring they were signed by one of the trusted keys. And unless you've made changes to your secureboot config, that means microsoft and/or the hardware vendor.

tripflag··on What did the Ignore button do in Windows 3.1 when an app encountered a fault?
> ON ERROR RESUME NEXT

Ah yes, the load-bearing magic words that somehow made my programs work... I kinda miss vb6 :-)

tripflag··on Bash-Oneliners: A collection of terminal tricks for Linux
Please be extremely careful blindly trusting oneliners from GPT's! Plenty of horror stories, but I'll name a recent one as example:

Someone wanted to use FFmpeg to (losslessly) convert video files from one container to another and then delete the original. ChatGPT made a script which created a list of filenames and passed them into a loop which executed ffmpeg on each file. Thus it ran headfirst into several edgecases, for example how FFmpeg by default (unless you -nostdin) consumes stdin byte-by-byte, which messed up the list of filenames. Of course it appeared to work fine, as it clearly was processing a bunch of files.

Secondly, it forgot to map the input streams correctly, so several files came out with subtly missing tracks.

But more crucially, it failed to check the returncode for each file, assuming everything went fine... And deleting the lone copy of several files which failed to convert. Of course there were no backups.

So if you must rely on GPT's, then do so with extreme caution. Don't get fooled by their "self-confidence".

tripflag··on Bash-Oneliners: A collection of terminal tricks for Linux
Atuin should help with large histories; https://atuin.sh/

Graduating specific oneliners into functions/scripts is also a good chance to clean them up a bit, but it's a balance that's hard to strike - too many aliases and scripts, and you quickly forget they exist :-)

tripflag··on Bash-Oneliners: A collection of terminal tricks for Linux
I can warmly recommend making your own oneliners.txt over time, especially if you hop between boxes a lot. Some of the more hyper-specific entries in my own list has saved my bacon more times than I'd like to admit... https://ocv.me/doc/unix/oneliners/
tripflag··on What scripting languages come out of the box on Debian 12?
Replacing glibc with musl is usually unproblematic. That's what I did for my own portable toolbox which builds to a single self-extracting binary; https://github.com/9001/lxc
tripflag··on Windows 11 is now enabling OneDrive folder backup without asking permission
it worked for me on win11pro 24h2 just a few days ago; maybe you had a lan cable connected?
tripflag··on PeaZip: Open-source file compression and encryption software
I've found zstd --long=31 to be an excellent replacement for lrzip. Mentioned it in the github issue as well, cross posting for context. I'm not associated with either zstd or lrzip, but would still be curious to hear if you find any remaining usecases in favor of lrzip.
tripflag··on Garbage Collectors Are Scary
> NullPointerException became a meme

quite literally; https://danbooru.donmai.us/posts/947012?q=parent%3A947012

tripflag··on A proof-of-concept Python executable built on Cosmopolitan Libc (2021)
I built a Win10 binary with Nuitka just the other day, and was surprised to find the pyinstaller binary had higher performance at runtime. Pyinstaller also had several other advantages, such as producing smaller binaries, and building faster, and Win7 support.

For reference, I kept notes on the exact commands I used: https://github.com/9001/copyparty/blob/hovudstraum/docs/nuit...

tripflag··on TSAC: Low Bitrate Audio Compression
Like jasomill mentions, the browser playback issues statement has not been true on desktops for a long time. The most recent (or only) example I know of is iPhones, which finally added passable support for non-44.1kHz audio somewhere between iOS 15.7 (late 2022) and last august. Until then they'd sound like a broken vinyl deck when playing 48 kHz audio, oscillating in playback rate and crackling like crazy -- especially when passing through an AudioContext.
tripflag··on Reflections on Distrusting xz
I always use "zstd --long=31 -T0 -19" to compress disk images, since that is a usecase where it generally offers vastly superior compression to xz, deduplicating across bigger distances.

XZ offers slightly better compression on average, but decompression is far slower than Zstd.

tripflag··on Backdoor in upstream xz/liblzma leading to SSH server compromise
indeed; it should be trivial in any language. Here's python: https://github.com/9001/copyparty/blob/a080759a03ef5c0a6b06c...
tripflag··on Nanofont3x4: Smallest readable 3x4 font with lowercase (2015)
if you're in the market for something slightly bigger, I've found this font to be useful on lowish-res (640x480) displays: https://github.com/josuah/miniwi
tripflag··on Ask HN: Non-duopoly smart phone in Sweden?
> Yes, not officially supported, but if it's just Android it will most likely work just fine.

I have had zero issues with Norwegian banking apps on my Pixel running GrapheneOS, so I'm inclined to believe OP would be fine with such a setup, if that is sufficiently de-googled in their opinion.

A question to OP: Does Sweden not give the option to use BankID-based services with a separate OTP device, instead of having it provided by your SIM? This was the default in Norway until recently, and is still an option over here.

EDIT: Oh I see the neighboring comment from OP mostly answered this already.

tripflag··on Cloning a Laptop over NVMe TCP
Thank you for the correction -- it is likely that I did use count= when I ran into this some 10 years ago (and been paranoid about ever since). I thought a chunk of data was missing in the middle of the output file, causing everything after that to be shifted over, but I'm probably misremembering.
tripflag··on Cloning a Laptop over NVMe TCP
This use of dd may cause corruption! You need iflag=fullblock to ensure it doesn't truncate any blocks, and (at the risk of cargo-culting) conv=sync doesn't hurt as well. I prefer to just nc -l -p 1234 > /dev/nvme0nX.
tripflag··on Unlocking NetWare 2.0a
I've been having similar issues with Windows 3.11; trying to boot a qemu image I made a few years back and it looks like networking has died in the meantime, and another image crashes when it exceeds some small amount of RAM usage. But at least there's nothing stopping us from running an older linux in qemu to easily use an older qemu version that way, avoiding the hassle of having to patch the source to work with recent versions of its dependencies.
tripflag··on Protein biomarkers predict dementia 15 years before diagnosis in new study
Fwiw, at least one recent study indicates there is little benefit from exercising your brain: https://www.cell.com/trends/cognitive-sciences/fulltext/S136...

related news article (in Norwegian): https://www.nrk.no/trondelag/forskning-viser-at-hjernetrim-o...

tripflag··on Keeping a long shell history
We have a lot in common :-P except I'm still on bash, and do rely on PROMPT_COMMAND like you mentioned -- https://github.com/9001/asm/blob/hovudstraum/etc/profile.d/e...

Lines 11-21 can be ignored, they detect if the folder you were in got moved/deleted from another shell, to avoid the confusing behavior you get in that case.

tripflag··on Ventoy
In that case we probably have the answer already :) The next question then would have been whether secureboot-signing it yourself and replacing the PK/DB in the BIOS would have made it work, but it's really unfortunate that we've gotten to this point.
tripflag··on Ventoy
iPXE makes the client-side part of it manageable; the only drawback is having to walk through the open pull-requests on github for the patches you need to get it working, and possibly having to fight some buggy uefi drivers (usually solved with snponly). Also has the advantage of making it possible to do everything secureboot + over TLS with your own certificates, rather than classical PXE which is all plaintext.

For the serverside, there are several python projects on github which provide everything you need in one package, for example pybootd.

tripflag··on Ventoy
while I don't have any of those machines readily available, i am curious if this USB image [1] would work. It's a lightly customized Alpine which can be written to a flashdrive using either Rufus, usbimager, or this command: xz -dkc <asm.usb.xz >/dev/sdi

the image was built using this repo [2] and this command: ./build.sh -i dl/alpine-standard-3.19.0-x86_64.iso -p min -s 0.3

[1] https://ocv.me/asm.usb.xz [2] https://github.com/9001/asm

tripflag··on datetime.utcnow() is now deprecated
The warning is also opt-in; you'll have to run python with PYTHONWARNINGS=always or similar to see it.

Which is scary, because you will be taking the performance hit from generating the warning regardless, which can easily amount to 30% of your total CPU time if you use utcnow/utcfromtimestamp a lot.

tripflag··on A simple web server written in Awk
neat! i was aware of bash's built-in tcp client at /dev/tcp, but gawk being able to function as a tcp server is way cooler. Thanks for that bit of knowledge :>
tripflag··on Textual Paint – MS Paint in your terminal
it's not intentionally obfuscated, it just happened like that :-) The only place I've posted it until now is on my oneliners collection, https://ocv.me/doc/unix/oneliners/#c58b5be6
tripflag··on Textual Paint – MS Paint in your terminal
How about bash? :p

r() { read -n1 -r c; [ "$c" = "$1" ]; }; b=2; stty -echo -icanon; printf '\033[H\033[0m\033[J\033[?1003h'; while true; do r $'\033' || { printf '%s\n' "$c" | grep -qE '[0-7]' && b=$c; continue; }; r \[ || continue; r "M" || continue; r "@" && d=y || d=; read z x y z < <(head -c 2 | hexdump -C); [ $d ] || continue; printf '\033[%d;%dH\033[1;4%dm \033[0m\033[D' $((0x${y}-32)) $((0x${x}-32)) $b; done

(you can change colour with digits 1..7 btw!)

← PreviousPage 2 of 3Next →