HNHacker News
TopNewBestAskShowJobs

tuetuopay

1,762 karma · joined December 23, 2021

submissionscomments
tuetuopay··on Show HN: Make cursed fonts like Times New Bastard
Thanks, I always wondered why this was the case with latin text from CJK countries, as they use the same computers and software than the west, they should be able to do kerning right. I guess the original designers of those fonts are to blame for not making the latin characters "properly" monospace so that it still works.
tuetuopay··on There's a new "Google Jail" for independent wikis
That's ignoring how video game wikis are used. People will google "<game> <place where I'm stuck>" and completely miss the wiki. Or "<game> <mechanic>". Etc. So reachability and proper indexing by search engines is a must.

I've hit this on a few wikis where, for some (at the time inexplicable) reason, I'd get only the crappy Fandom wiki with above queries, and a good wiki when searching only for "<game> wiki" after seeing a link to it on reddit.

When the reason is to move away from Fandom, get people what they are looking for, and perhaps attract contributors, this is an issue. Your average gamer won't route through the Wiki's main page, rather rely on the top Google search result for their issue.

tuetuopay··on Qwen 3.8 27B is excellent, but it defaults to overthinking things
Quite the opposite, RAM is always the issue. More specifically, high bandwidth RAM.
tuetuopay··on France to ban unsolicited telemarketing calls
It's worth quite a bit: the numbers on that list are live, with people smart enough to care, etc. Random numbers are worthless.
tuetuopay··on France to ban unsolicited telemarketing calls
All calls at least appear with a Caller ID from France (+33). Are they really from france or just spoofing them is anyone's guess (not really, former French colonies in the Magrheb like Morocco make good money running call centers for French numbers).
tuetuopay··on France to ban unsolicited telemarketing calls
Yup, having a French number is unbearable without automatic blacklist apps. I definitely notice it when it breaks after an iOS update, is start getting multiple calls a day. For any french here with an iPhone: Begone works great and has community lists for spam numbers.

The SMS are getting out of hand too, they send you a pre-recorded MP3 in addition to the picture too. At least they don't have enough information to know I don't have a letterbox.

> Related, there has been dozens of private data leaks in the last years in France

Yeah, more and more French people are getting annoyed at it, esp. when companies always say "no worries no payment info leaked". I don't care, I can change my credit card but I can't change my personal informations.

And literally last week it's Bloctel that leaked! It's the government managed list of phone numbers that don't want to receive telemearketing calls, where anyone can add its own number to be excluded. Great idea on paper, goldmine of a data leak.

tuetuopay··on France to ban unsolicited telemarketing calls
As if we don't already have enough advertisement channels in our lives.
tuetuopay··on Exploiting System Management Mode with a very long interrupt
It's an instruction in the sense that timing boundaries are x86 instruction boundaries, which is what the security model bases itself on. So yeah, not an instruction in the strict CPU sense (microcode + micro-ops), but in the useful sense.
tuetuopay··on Discovery of a multicomponent alloy forged by the Hiroshima atomic blast
You can probably skip the town in the ingredient list.
tuetuopay··on Germany Records Historic 12B KWh Solar Feed-In in July 2026
European utilities also bill by the kWh, the markets bill by the MW or MWh (depending on the market product), yet we’d still use TWh to write this number.

The American way of handling units is always surprising.

tuetuopay··on Harvesting SSH Credentials: Insights from My Honeypot Network
SSH bastions would like a word I guess. You can authenticate, but you definitely can’t login (which is also the case for git over SSH).
tuetuopay··on Increasing the lifespan of a bulb makes it worse in every other way
Seeing how many people buy 6000k LEDs for sunset/night lighting (e.g. a bedroom), no, people don’t give a shit about lighting. The most caring of average consumers would notice their bedroom looks like a hospital, but refuse to buy 2700k or 3000k because "they look like piss" when they go to the store at midday.

And with the stupid habit of talking about lights in input watts (skimmed over in the article), we’d get what’s described in the article, albeit less dramatic: people would buy the bulb that lasts 50% longer and not notice the lower lumen output.

Consumers are not educated at all in lighting, especially when the industry does not help (re: watts, but also temperature, color rendering, flicker, etc)

tuetuopay··on Elevators
Meanwhile, the elevator at my apartment building: hey only one floor at a time can call me! And no queueing, you must wait for me to be idle for someone to call me. (And yes, often someone beats me and presses the butter faster than I can).
tuetuopay··on Designing an Ethernet Switch ASIC
The two scenarios I can think of that definitely make use of cut-through are timekeeping systems, and HFT. The latter goes even further, where the switches at the exchange do cut-through, but also ensure the packet is broadcast to multiple ports at the exact same time. This is done so that no specific HFT firm get an advantage from being on port 10 rather than port 20. They even measure out the outgoing fibers to be the same length.
tuetuopay··on Mysteries of Telegram Data Centers (2022)
It’s quite easy to anycast an IP to multiple physical datacenters. Their DC nomenclature is probably a relic from when they really had a single datacenter for each region.

On the other hand, it wouldn’t shock me if they had no site redundancy. It’s a free service, it’s not like there’s SLA agreements you paid for on signup.

tuetuopay··on We Put an L7 Firewall in the Kernel
I’ve followed yeet from the inception phase (the creator luks in the Aya Discord, a library to write eBPF using Rust). They’re very skilled, and the project started a few years ago well before LLM coding was up to par for such code.

Nowadays I’d expect them to do AI assisted coding, but the underlying skill set is sound. A shame such good projects delegate blogposts to Claude.

One thing that would be interesting is whether they explored running their automaton in multiple steps, sharing the state across XDP probe invocations, instead of offloading the work to a JS userspace app.

tuetuopay··on Every new car sold in the European Union must include a driver monitoring camera
I agree, and I don't remember whether I had the blinker. I, however, also respectfully disagree as in all fairness we should drive 100% perfectly 100% of the time, but we're humans. Expecting 100% driving all the times is the worst as it puts strain on the driver (I say that as someone that's pretty strict on blinkers).

What is special is one time it was a one way lane next to the tram with a concrete stub down. I wouldn't be surprised if the anti-collision kicked in and applied lane assist even with the blinker.

At any rate, the principle of least surprise still applies: heavy machinery must not jerk unexpectedly to the side. Never ever ever.

tuetuopay··on Every new car sold in the European Union must include a driver monitoring camera
I almost slammed bicycles in Paris on a few occasions because of that crap. Shift a bit to the left to overtake them, get lane assist slam me back right. Thankfully those were close calls, but only thanks to the cyclist being used to traffic in Paris and having good reflexes.

Any dangerous machine (like a car) must not do anything unexpected out of the driver's control. A lane assist that resists the wheel when trying to get out? Why not, but dangerous. A lane assist that slam you back in the lane? Criminal. (same with anti-collision braking that triggers too strong too early and surprises drivers behind you)

I'm definitely of the opinion that all those features reduce security. The alarm fatigue is real, because the car always finds something to beep at you. Heck, even your hands not being a perfect 10-2 o'clock on the wheel is reason enough on some cars. You quickly ignore the beeps because there are so many reasons for the car to beep it's hard to even understand why.

tuetuopay··on I found 10k GitHub repositories distributing Trojan malware
Definitely. If bitwarden does not shows a little "1" icon I'm basically lolnope'ing out.

Still, it pains me to see that practices from the early keylogger era are still "good practices".

tuetuopay··on I found 10k GitHub repositories distributing Trojan malware
It's a bank, and a rather old at that. I fully expect them to store the password in cleartext. (hence the security theatre qualification)

Banks are notorious for taking security as a strict cost/savings measure. I would not be surprised if they enforce weak passwords stored in cleartext on purpose to save on support agents for the people that forget/lose their password. Imagine the customer service reviews: "they were able to find my password back, 5/5". Probably enough savings to offset the cost of refunding people that got their account pwnd. Cost of doing business.

tuetuopay··on I found 10k GitHub repositories distributing Trojan malware
That's without considering a lot of banks have non-textual inputs for their passwords. Man they love their scrambled virtual keyboard!

I think the worst I ever had was HSBC that asked me for fragments of my password, like characters 4, 6, 7, 11, and 12. Absolute bonkers of a security theatre.

tuetuopay··on 10Gb/s Ethernet: switching to a Broadcom SFP+ module
So much this. The rule of thumb is: avoid SFP-RJ45 converters at all costs, you'll be burned by them (literally and figuratively).

They all are little snowflakes. Compatibility is hit-or-miss. They run hot. They eat more power. They're finnicky. Heck, they plain out lie about what they are (I've got some that pretend to be fibre with 3m of copper, sure).

So yeah, DAC it is for patch, fibre for anything more.

tuetuopay··on Statement on US government directive to suspend access to Fable 5 and Mythos 5
Yeah a bit like I’ll be impressed by a humanoid robot that can fold a shirt from a freeform state (i.e. thrown as a ball on the laundry chair, or straight out of the dryer). Just like repeatable movements an balance are the easy(er) parts of robotics, text processing is the easy part of AI.
tuetuopay··on How much do amd64 microarchitecture levels help in Go?
Yes, it's in the platform options. You can specify --platform linux/amd64/v3 for a v3 image.
tuetuopay··on GitHub and the crime against software
They've made a lot of progress in the recent years, and the last two major releases downright feel snappy compared to GitHub (really, browsing a repo tree is literally snappy). Oh, and their SPA implementation actually works, the back button is not broken 90% of the time like it is on GH.

And mind you, that's on a small 4 core VM on 2019 mid-range Xeons, which I would not consider to be a huge amount of compute (granted, not Raspberry Pi level, but I'd expect the SD card to be much more of an issue).

So yeah, along with the sane(r) way to do CI pipelines, and usable review tools, it's a net improvement over GitHub.

tuetuopay··on Show HN: Write your BPF programs in Go, not C
Nitpick: you definitely can do loops as long as the verifier can prove they're bounded.

At my previous job, I've written production eBPF exclusively in Rust using Aya (mentioned by a sibling comment), and it's been a blast. Being able to share the type definitions between the kernel-space and the user-space code is a blessing to avoid subtle issues when going through the maps. And, at least in Rust, you can re-use crates and types that make you gain time. As a (simple) example, being able to use the standard library's IpAddr types or the ipnet crate to not have to roll your own IP and network manipulation libraries is a (small) timesave. It's main value is not needing to onboard new developers.

The Rust type system is a good helper in keeping the verifier happy. Slices, iterators, match statements, etc are very good in my experience (e.g. Option is a godsend to ensure you stay withing the bounds of the input packet, esp. slice::split_at when parsing headers).

But you're right that reading C is non-negotiatable, especially since pretty much all example code on the internet is in C.

tuetuopay··on Migrating from Go to Rust
The difference is, unwrap will stick out like a sore thumb, and it’s opt-in. You explicitly tell "this may panic".

As for error handling, this kind of enrichment is usually left to the caller (that is, the end application), with error libraries like anyhow where you can add arbitrary string contexts to an error. You would end up writing `Config::load(path).with_context(|| format!("Failed to load configuration file {path}"))?`.

tuetuopay··on Bun Rust rewrite: "codebase fails basic miri checks, allows for UB in safe rust"
As for the specific issue: it does not exist in Zig, because Zig does not have ownership.

In a nutshell, the LLM created abstractions that allow you to write unsound code in safe rust, which is squarely against the language.

To be specific: the abstraction takes a (shared) reference and uses unsafe to wrap it in an owned object, completely erasing le lifetime. In practice, this means users of the abstraction think they own the underlying memory: they choose when to free it. However, it just wraps a pointer that’s owned by someone else (it was a shared reference, remember?), thus it will be freed when you don’t expect it.

So why does it not exist in Zig: it’s a false contract about what it is. The Zig pointer is a pointer with no added lifetime information. You can hold a Zig pointer wrong, but you will hold a lying abstraction wrong. You will misuse it because it doesn’t do what’s written on the tin. You will write bugs with it.

And, LLMs will too. If they do not have the abstraction definition in their context, they also have no way to know the contract is lying.

tuetuopay··on CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
Well, it is a good thing to get control of your own hardware, when the vendor decides that no you won't do what you want with it.
tuetuopay··on I hate soldering
Give a shot to the SAC305 mix. It’s a low temperature lead-free alloy, and it’s the one that made me ditch leaded solder definitively. Use more flux and a bit more iron temperature and you’ll never touch leaded solder again. Oh, and it’s available both as a hand-soldering wire reel and solder paste.
Page 1 of 20Next →