HNHacker News
TopNewBestAskShowJobs

twicetwice

815 karma · joined April 21, 2020

submissionscomments
twicetwice··on One year with Next.js App Router and why we're moving on
what's the moderation policy/etiquette for calling out obviously LLM-generated comments? doing so feels like more heat than light, but letting them pass by without saying anything feels like another step towards a dead internet.
twicetwice··on Using FIDO keys
My "solution" to this problem is: hardware keys with backups for the really important services—Bitwarden, Google, domain registrar, etc. And then for stuff that isn't absolutely critical, I just use an OTP stored in Bitwarden. As for having both the password and OTP stored in the same place, the way I see it, the OTP is mainly protecting against keyloggers, data breaches, etc. And then I figure, if someone gets into my Bitwarden account, I'm already fucked anyway, so it's whatever.

I currently have four Yubikeys: one on my keychain, one in my apartment, one to take with me while traveling, and one at my parents' house. I figure this should be adequate to ensure I never get locked out of Bitwarden or Google, which would be an utter disaster.

twicetwice··on Apple cuts off Beeper Mini's access
Does Matrix not qualify?
twicetwice··on $20k bounty was claimed
Isn't this a natural consequence of having line length limits? This seems like a general problem, not a problem with Prettier.
twicetwice··on Ask HN: As a first-time solopreneur how would you go about hiring the first team
Yes, but I think that's a poor choice of words; those are not the same thing. There are lots of smart people who are not independent, self-directed, or hard working! My manager was just saying to me yesterday, "we need smart people who know how to get shit done—just hiring smart people isn't enough."
twicetwice··on Home Assistant blocked from integrating with Garage Door opener API
Good suggestion, but where and how does HA receive callbacks? I would guess that almost all HA instances are behind residential LANs and most aren't accessible on the public internet. You could use dynamic DNS and forward ports, but that's flaky, you might run into CGNAT, etc. And anyway, it's best if your HA instance isn't publicly addressable; mine is only accessible over my personal WireGuard VPN and I intend to keep it that way.

I'm sure this is a solvable and solved problem, but I do believe it is non-trivial, and potentially a major headache for a company to implement just to support a tiny niche of users. I'd be delighted to find out I'm wrong though!

And, unfortunately, the business case isn't there, since this weakens lock-in effects. I don't endorse this reason—that's why I run my own HA instance and don't buy or use any products that require the cloud or otherwise can't be operated entirely locally (including flashing Valetudo to my robot vacuum!).

twicetwice··on A new home and license (AGPL) for Synapse and friends
Oh wow, this is laudably frank in my opinion. They are quite up front about the motivation behind this change. Two relevant excerpts:

> Over the last year or two Matrix has evolved from ‘explosive growth’ to being a ‘category’ in its own right. In other words, ‘Matrix-based’ is now specified as a requirement in massive public and private sector tenders - in which multinationals compete to provide Matrix-based products and services.

and

> Today we have arrived at a crossroads. We have succeeded in making Matrix wildly successful, but Element is losing its ability to compete in the very ecosystem it has created. It is hard for Element to innovate and adapt as quickly as companies whose business model is developing proprietary Matrix-based products and services without the responsibility and costs of maintaining the bulk of Matrix. In order to be fair to our customers, we need to be able to put more focus on them and their specific requirements.

So basically, Element can't compete with other companies for the contracts that only exists because of Element's work, because the other companies can focus just on making proprietary extensions for code that Element has more or less the sole burden of maintaining. So Element is saying to those companies, hey, either AGPL your modifications and extensions (AGPL is relevant since if you're running eg sidecar services with Synapse or Dendrite, this will still hit those sidecar services), or pay for a license for our code. This seems fair to me, to be honest.

And yeah, I understand people's moral objections to the CLA, but it's necessary for Element's strategy to work. And maybe I'm naive but I do believe Element and the team have Matrix's best interests at heart, they're just also grappling with making money and being self-sustaining, and so I hope that they succeed in that for the sake of the broader Matrix project and ecosystem.

This change also does not seem likely to me to affect open-source work or the broader Matrix community for the most part. If you want to self-host a Matrix server this shouldn't change anything for you. All the code you're running is already open-source, you don't need to do anything. Matrix as a protocol and an ecosystem of servers and clients and users won't be affected by this, just companies selling services that are based on Element's open-source code.

And protocol governance hasn't changed, it's still in the hands of the Matrix Foundation, and this won't change that. And you can say, hey, Matrix protocol development has always been driven by Element and its priorities and interests—yes, that's absolutely true. But this change won't affect that either! And in fact, if the CLA pushes pushes community development efforts away from Synapse/Dendrite and toward other projects like Conduit[0], then this might even be good for the ecosystem and community governance by decreasing Element/Synapse's influence over the direction protocol, which I'd be happy to see.

So yeah, as someone who is self-hosting Synapse and really rooting for an open, free, community-centric Matrix protocol to succeed, I'm not heartbroken over this change. I'm actually even a bit hopeful about what it means for Element and Matrix going forward.

[0] https://conduit.rs/

twicetwice··on KDE desktop cube effect returns
I have settled on exactly the same setup! It's pretty great. My right-hand monitor is a terminal 24/7. My center monitor is code—I used to think I'd want vertical for code, and it is nice sometimes, but at my current job I benefit from having several files open side-by-side more than I benefit from seeing more of one file. It's a 4k monitor and I have it fractionally scaled so that I can read comfortably, but I can also fit up to four files side-by-side on the screen at once. It is very useful. And then the laptop screen is for Slack, docs, AWS dashboard, whatever is useful at the time.
twicetwice··on HubSpot Acquires Clearbit
Be that as it may, their object-level behavior is still far less shady. And in fact this is an argument that it is good that they exist, because in the counterfactual world where they don't, their niche would be filled by these non-vertically-integrated data brokers and advertisers who ARE financially incentivized to leak and sell and share far more information.

I used to be all gung-ho about being anti-FAANG, those evil privacy violators, but having now talked to friends who have worked at places like FB and Google, their internal data security practices are far more stringent than I had imagined (my friends complain about how difficult these rules make their jobs!). And yeah, sure, they are scooping up as much information about you as they can, and I'm not a big fan of that fact. But I have been convinced that they are actually somewhat decent stewards of that information, and the alternative is far worse.

All that being said, this is a pretty loosely-held belief, and all the surveillance and so on is quite icky to me. I'm still trying to slowly de-google my life and all that, just with a bit less paranoia and urgency.

twicetwice··on The death of a public intellectual
Yes, this is a textbook parasocial relationship. No judgment—me too. I've been listening to the "New Heights" podcast a lot recently, so my most recent parasocial relationship is feeling like Jason and Travis Kelce are my friends. Of course I know they're not, it's just how these things work. Parasocial relationships are ubiquitous in the modern day.

My favorite analogy is that parasocial relationships are the Doritos of socialization: appealing. delicious, addictive, can temporarily keep hunger at bay—but fundamentally not satiating, lacking in essential nutrients, and unhealthy when they displace their original natural & more nutritious alternatives.

twicetwice··on The slow death of authenticity in an attention economy
Which social media app was that?
twicetwice··on The Cloud Computer
Perhaps if you don't understand what the copy means, then that is a sign that you are not the target audience, rather than that the copy is bad? From what I've gathered from reading other comments in this thread, that copy will make perfect sense to Oxide's target audience, as it uses words in a way that will be very familiar and make perfect sense to the kind of person who might make a purchasing decision for a system like this.

And for what it's worth, I don't think you need to explain what's happening to Steve, it seems to me that he understands perfectly well. To me you come across as being rather condescending and in my opinion Steve is being commendably polite in response.

twicetwice··on The Cloud Computer
Do they raise those sorts of numbers in series A, though? Other comments in this thread seem to suggest they've raised a surprisingly large amount of money for such an early stage of the typical fundraising process. If it is atypically high it would make sense to me—it's hardware which requires more up-front capital, and it's a rockstar team so I understand why investors would have confidence in them—but from what little I know about fundraising it does seem remarkable to me.
twicetwice··on Piped – An alternative privacy-friendly YouTube front end
Yup, I've written about this a couple times[0], I cancelled my YouTube Premium subscription—I was otherwise a happy customer!—and switched to NewPipe on Android because I couldn't turn off YouTube Shorts.

[0] https://news.ycombinator.com/item?id=36593028

twicetwice··on iPhone 15 and iPhone 15 Plus
My home is currently all ZigBee/Z-Wave, but Thread/Matter is an open protocol that can be used entirely locally. I'm cautiously excited about the industry standardizing on it; hopefully this will mean that over time more and more mainstream smart-home devices will be compatible with my local-only HomeAssistant setup.
twicetwice··on Why yewtu.be was down: Data loss after being shut down by Oracle Cloud
Yup, for me I cancelled my YouTube Premium subscription—which I had been happy to pay—because of YouTube shorts. They were constantly pushing them in the mobile app, and sometimes I would succumb and click on one, and then often lose several hours to scrolling. Skill issue, I know, but when I went looking for a way to disable them in the UI I found there isn't one. I ended up feeling like it was a adversarial relationship—they're using dark patterns to hijack my attention to increase their engagement metrics, to my loss—so why would I pay them? I installed NewPipe and subscribed to the creators I watch regularly on Patreon and I'm very happy with this setup.
twicetwice··on Twitter now requires an account to view tweets
That's never going to work for the average person, sadly. And it misses a lot of social features that a lot of people (myself included) want from social media. Simply put, the UX is way too far off what people want and need.
twicetwice··on Twitter now requires an account to view tweets
Yes, at the end of the day a malicious client is always a risk with this sort of thing. But the AT Proto does have some mitigation in place—users have a signing key which their PDS needs to act on their behalf (sign posts, etc) and a separate recovery key which users can hold fully self-sovereign and use to transfer their identity in case they detect malicious behavior. It's not foolproof of course, nothing is, but it is thoughtfully designed.

But yes, the protocol does have a fair bit of trust of your PDS built in. But that's inevitable for decent UX—imo the crypto craze proved that basically no one wants to (or can) hold their own keys day-to-day. If you want to have a cryptographic protocol that the average person can use, some amount of trust is necessary. The AT Protocol artfully threads the needle and finds a good compromise that is a (large) improvement over the status quo, in my opinion.

twicetwice··on Twitter now requires an account to view tweets
fwiw, Bluesky is fully federated (well, will be, it's in development, but it's well on the way, they just launched the federation sandbox the other day), and identities are portable, so it shouldn't be susceptible to the same dynamics as twitter. Plus, the dev team has stated a number of times that "the company is a potential future adversary" is one of the principles they keep in mind when designing the protocol. Plus, it's a Public Benefit LLC, for however much that's worth. And I really do trust the good intentions of the current devs and leadership (mostly the same people), based on my somewhat extensive interactions with them—I think their hearts are in the right place.

So of course it definitely could go badly fo a variety of reasons—but I think there's good reason to be optimistic that it will go well.

twicetwice··on Twitter now requires an account to view tweets
This is basically the entire point of the Authenticated Transfer Protocol (AT Protocol), which powers Bluesky. I think it does a ton of stuff right, including portable identity backed by solid cryptography (no blockchain or "crypto"!) and has a lot of promise. It's still in development, but I am hopeful that it will live up to its promise.
twicetwice··on The FAA has granted SpaceX permission to launch its Starship rocket
I hadn't heard that Raptor 2 was a complete redesign as a results of flaws discovered (I hadn't heard anything at all about why they made Raptor 2). Do you have a link where I can read more about this?
twicetwice··on Bing: “I will not harm you unless you harm me first”
Yes, I firmly agree with your first paragraph and roughly agree with your second paragraph.
twicetwice··on Bing: “I will not harm you unless you harm me first”
I think Searle's Chinese Room argument is sophistry, for similar reasons to the ones you suggest—the proposition is that the SYSTEM understands Chinese, not any component of the system, and in the latter half of the argument the human is just a component of the system—but Searle does believe that quantum indeterminism is a requirement for consciousness, which I think is a valid response to the argument you've presented here.
twicetwice··on I spent two years trying to do what Backstage does for free
I've been pronouncing it as "zeesh" in my head, which works well for me. I think I got that from a coworker? Not sure. Works fairly well with "oh my zeesh" as well, which I like.
twicetwice··on Lichess gets a big upgrade. It doesn't go as planned
Yes, I believe rust-analyzer language server + vscode extension is the setup I have that does this for me.
twicetwice··on Yale’s 367-year-old water bond still pays interest (2015)
You can definitely get pretty creative and interesting—for example, transmuting a pile of primed hand grenades into a handful of confetti and then tossing it over your enemy right before the spell wears off. That said, you're right, it's highly likely that boring strategies would dominate. However, the Harry Potter magic system is so fast and loose that you can always make up some new spell to cancel out whatever OP strategy; the author has almost unlimited leeway.
twicetwice··on Sam Bankman-Fried tries to explain himself
Yup, he founded Alameda Research in 2017 at age 25 and FTX in 2019 at 27.
twicetwice··on Google is shutting down Stadia
It's probably just different. I don't know what the Steam Link is like. GFN streams the games from a datacenter, so the quality will depend on the quality of your internet connection. Also, GFN can't play all Steam games; publishers have to agree to allow their games to be played on GFN, and several major publishers don't agree (eg Bethesda, Rockstar). All that said, I'm happy with it. Usually I can't tell at all that it's being streamed, and it's cool to be able to max out every single graphics setting without thinking about it.
twicetwice··on Google is shutting down Stadia
I use GeForce now for singleplayer games and I'm super happy with it as long as I'm on an ethernet connection.
twicetwice··on Google is shutting down Stadia
Yeah, if I had known this would be how they would have handled a hypothetical shutdown, I would have very happily used the service. Instead I signed up for GeForce Now since I can buy games through Steam and play them there. The main thing that stopped me from going with Stadia instead was that I was pretty confident that at some point it would shut down and I'd lose access to $xxx worth of games. If they had promised up front to do this in case of failure, maybe it wouldn't have failed.
Page 1 of 6Next →