HNHacker News
TopNewBestAskShowJobs

txrx0000

787 karma · joined August 26, 2025

hello
submissionscomments
txrx0000··on RISC-V Router
More open-source forks of OpenWRT and open-schematic router board designs are exactly what we need. It would further raise the cost of planting backdoors in routers at meaningful scale. We're currently too dependent on the OpenWRT project for router firmware. It's a high-payoff target for XZ Utils [0] type of multiyear infiltration by malicious actors.

[0] https://en.wikipedia.org/wiki/XZ_Utils_backdoor

The StartWrt port supposely adds some nice features, of which VPN chaining looks especially useful. And a better UI will make it more accessible. There are plenty of people out there who are willing to switch out their routers and chain VPNs to escape gov/ISP/big tech surveillance but don't have the technical means to do so. These are welcome improvements to reduce friction if they manage to pull it off.

The specs are not too bad for the price considering this is a startup project. It has 8 cores with per-core performance similar to Cortex-A55 + 4GB LPDDR4 + 16GB eMMC, which is better than most off-the-shelf routers. I wish they released the WIP schematics and code though, because there seems to be nothing at the moment.

txrx0000··on The hypocrisy of cyberlibertarianism
The world I'm describing is one where anyone, rich and poor, can say whatever they want without being silenced or persecuted, without fear. People with more resources will have the means to make themselves louder in public as they do now, but unlike the situation we have right now, they will not be able to monitor other people's private conversations, nor can they censor and compell other people's speech. That's a world of more freedom and opportunity.

The loudest ones are not aligned with eachother. Their efforts to influence public opinion will neutralize eachother, and none of them can gain moderating power over the platform because the platform is just protocols. Ideas will clash, leaving only what people think is good in common. And that is the definition of the common good.

Do you have any better ideas? Or do you think that you possess the superior definition of "good" such that public discourse to search for it is unnecessary?

txrx0000··on The hypocrisy of cyberlibertarianism
> How has this worked out with email, text messages, or the phone system, or even postal mail.

Those are centrally controlled systems where propangandists have home field advantage (email is debatable, it's halfway, it wasn't designed with the existence of companies like Google in mind). But even if that wasn't the case, it's not the same phenomenon as bots on social media. The important difference is that on social media, if there is no central moderation, the bots will cancel out eachother's influence. If I make an anti-propaganda email bot, it doesn't lower the ranking of the propaganda that's already in your inbox. But if I have an upvoting bot for their downvoting bot, they neutralize eachother.

Also, ensuring that nobody except the participants of group chats and DMs can figure out eachother's real identity is already a massive win. That alone makes it a lot harder to beat a population into submission.

txrx0000··on The hypocrisy of cyberlibertarianism
It's Barlow's goal as I understood it. The article criticizes corporate opportunists, which is fair. But there are also plenty of other people willing to put short-term profit aside to fix problems and build the future we want to live in. The free and anonymous Internet is not a dream and will be built. It may have been half dead at one point post-911, but it was revived by Snowden and will strike at the panopticon until it shatters.
txrx0000··on The hypocrisy of cyberlibertarianism
"Entities with more resources" are not necessarily bad, as you seem to assume. In reality, they're not aligned with eachother. This is just as true for nation states as it is for individuals.

When everyone can talk without censorship and fear of persecution, the best ideas might not always win, but the good ones usually will, and the worst ones will always lose. This is why every authoritarian regime needs censorship to survive.

txrx0000··on The hypocrisy of cyberlibertarianism
Bots are only an issue for public posts, not chat groups and DMs where the most valuable interactions happen. Ideally chats would be encrypted, untraceable, and anonymous, except to the people you're talking to. Anonymity is an overwhelmingly positive feature there.

For public feeds, you seem to assume that only the propagandists can leverage bots effectively, which is the right assumption for the centrally-controlled social media platforms of today. But if we make a platform that is just some protocols that can't be controlled by anyone, you and I would be able to spin up anti-propaganda bots to pwn the propaganda bots without fear of repercussion. Anyone can try to push public opinion in a specific direction, but someone else will simply go the opposite way. There would be no moderator or algorithm to artificially boost one type of noise over another, so we would actually get a less corrupted feed that accurately represents what people are thinking because the noise cancels eachother out. And if you want to customize the feed, we could make client-side filters and algorithms. There could be an open-source algorithm called "Hacker News" that you can just download and install into your open-source social media client.

As for keeping the powerful in check, don't forget that we've kind of lost equality before the law at this point, as shown by the Epstein saga. If we try to remove anonymity from the Internet right now, it will only be used to surveil regular citizens but not the people we need to keep in check. I would happily support a law that selectively enforces the other way around, though: let's mandate real identity for all government personnel online and expose their Polymarket accounts.

txrx0000··on The hypocrisy of cyberlibertarianism
I will add, for those that lost the plot: the goal was, and still is, to build a world where anyone can communicate with anyone else without exposing their physical identity and location, and therefore people cannot be physically persecuted for what they think and say.

We're far from achieving this goal, and we underestimated our opponents by a lot. But it would be foolish to blame the Barlows of the world instead of blaming the tyrants and corporate opportunists that go to great lengths [0] to sabotage and interfere.

[0] https://en.wikipedia.org/wiki/Edward_Snowden#Revelations

txrx0000··on EFF is leaving X
> Telegram less of an "encrypted messaging app" than Instagram was

Instagram is not comparable to Telegram. It is closed source, so there's no way to verify that it's doing E2EE.

> DOGE strengthened the surveillance state. It does not matter whether or not it's tied to a singular intentional plot.

That's not what you originally implied, but no matter. DOGE probably strengthened surveillance capacity within the government as a side effect of its auditing work, but I don't think it added any new capability to surveil citizens that the NSA did not already have.

As for Musk being a proponent of surveillance and censorship, there's a difference between an individual surveiling and censoring users on a platform he bought vs the government using mass surveillance and censorship against its citizens.

After Elon bought Twitter, he is like the Discord mod of his giant server, and doesn't want people to go to other servers. I don't think there's much more to it than that behind the ban of Signal links on X. He had previously banned other platforms' links on a whim as well [0]. He enforces his own rules on his own platform, but he's outspoken against government surveillance and censorship. He's somewhat hypocritical value-wise in this regard, which is one of his flaws, but he's also not the government. And even so, Twitter still manages to have looser speech restrictions nowadays than it did in 2021.

[0] https://www.theverge.com/2022/12/18/23515221/twitter-bans-li...

txrx0000··on EFF is leaving X
Which part of what I said is the opposite of reality?

I'm aware that Telegram is not E2EE by default, and you have to turn it on manually. But it's not true that Elon has long been rallying against Signal. In fact, he endorsed Signal a while back along with Edward Snowden. He also later criticized Signal, as well as other encrypted messaging apps. I remember seeing a podcast clip of him saying something along the lines of "none of them can really protect against the government spying on him", which is true. If you're a high profile individual like Musk, nation states will expend lots of resources to spy on you, and no messaging app will protect you from that. The point of encrypted messaging apps like Signal and Telegram is to raise the per capita cost of doing surveillance so that surveiling the entire population becomes prohibitively expensive, but it doesn't prevent targeted operations on an individual by determined state actors. Having multiple options for those apps is a good thing, even if the apps are individually imperfect, because the government will have to deal with multiple apps instead of one, and that takes more resources.

As for the rest of your comment, those claims aren't true, at least not in the way you stated. DOGE has been accused of mishandling sensitive records, and that part might be true, but I've not seen any evidence pointing towards the mishandling being a part of a evil plot to strengthen the surveillance state and promote fascism. Mass surveillance was already a problem back in 2013 when Snowden leaked it. In fact, it was already a problem before Obama's first term, and Snowden held off on leaking it because he thought Obama would introduce reforms, which didn't happen. The surveillance state is not a recent fascist movement spearheaded by Musk or DOGE. And I think a lot of the vitriol towards Musk is manufactured. He occasionally lies and is prone to manipulation like everyone else, but he's not the supervillain you think he is.

txrx0000··on LittleSnitch for Linux
As articulated in the author's own blog post:

https://obdev.at/blog/little-snitch-for-linux/

The core issue is simple and uncomfortable: through automatic updates, a vendor can run any code, with any privileges, on your machine, at any time.

-----

If the author is serious about this, then they should make their own program completely open source, and make builds bit-for-bit reproducible.

For all I know, the proprietary Little Snitch daemon, or even the binaries they're distributing for the open source components, contain backdoors that can be remotely activated to run any code, with any privileges, on your machine, at any time.

txrx0000··on German implementation of eIDAS will require an Apple/Google account to function
It will matter a lot in the long run. I will outline one concrete way it will matter, which I think is the most critical, but there are other ways it will do damage besides this:

Right now, physical ID is only required for government services, for the most part. But digital signatures can be extended later to gate all services and purchases, both online and physical, including non-government ones. For example, you can't host a website without a gov approved signature for each website.

Under a system like that, you would rarely find out when the gov refuses to issue a signature, or when any kind of injustice happens, really. Websites where people can talk about bad things happening to them will simply be denied a signature to legally operate, so they're given the ultimatum to "voluntarily" censor posts, or be shut down. It becomes impossible to have this very conversation on a public platform with any kind of meaningful reach. And they already have this kind of system in China, since you brought it up. In fact, they have domestic surveillance systems that make the Snowden disclosures look cute.

txrx0000··on German implementation of eIDAS will require an Apple/Google account to function
This is about mass surveillance and control.

https://en.wikipedia.org/wiki/Edward_Snowden#Revelations

The existence of eIDAS itself is already a big problem. They're going to try to gradually push laws to make it so that you'll need a government issued signature to do anything. That's when they'll have total power over you because they can simply refuse to issue.

Modern computing and communications technologies can be leveraged to build infinitely stable authoritarian regimes. It's even possible for democracies to stumble into it on their own as they attempt to regulate these new technologies. In hindsight, the Internet was built wrong. It has a top-down structure which all of human civilization is beginning to mirror.

txrx0000··on The threat is comfortable drift toward not understanding what you're doing
The threat is if you replace your cognitive capabilities with AI, but you don't control entire the system your AI runs on (hardware, firmware, drivers, OS, weights, frontend), then that's equivalent to someone else owning a part of your brain.
txrx0000··on Show HN: Mtproto.zig – High-performance Telegram proxy with DPI evasion
What I meant was that you could combine ideas from those 4 projects to build a new VPN protocol, not that you need to tweak your existing tunneling setup to allow those applications through.
txrx0000··on Age verification on Systemd and Flatpak
Apple is indeed better than most other companies on #2. But that's because it's the worst offender on #1. Its strategy is to appear to be the model company that cares about user rights and privacy, in hopes of capturing everyone in their closed-source walled garden that's already surveiling you at the OS level.

They're a part of the corp-gov surveillance complex [0]. This is the real threat behind the age verification push. The feds already have mass surveillance capabilities in iOS and macOS, and even Windows and most Android distros, but not on most open-source Linux distros, so they're starting to force it legally in the open. They're desperate because Linux is about to outcompete the enshittified Windows on desktops.

[0] https://en.wikipedia.org/wiki/Edward_Snowden#Revelations

txrx0000··on Show HN: Mtproto.zig – High-performance Telegram proxy with DPI evasion
Cool project. But why tunnel Telegram specifically? This could be a yet another VPN protocol.

There are some useful ideas from SoftEtherVPN, BitTorrent, Yggdrasil Network, and Tor you could borrow, if you're looking to improve this. The ideal tunneling solution, which doesn't exist yet, is one that not only evades DPI, but also onion bounces you through nodes in a decentralized ad hoc network, and does automatic node discovery.

txrx0000··on Age verification on Systemd and Flatpak
The user can voluntarily give the platform their age by typing it into their account profile in that streaming app. You can already do this right now. No laws required.

The problem at hand is we have a new law that forces everyone to give their age to every app. It's mandatory personal info collection.

txrx0000··on Age verification on Systemd and Flatpak
1. The current norm of social siloing apps was created by these tech companies in the first place. What regulators can do is discourage anti-competitive practices that lock users into specific software and hardware platforms. If there's plenty of competition for every kind of social app, and competition for OSes, and users could freely choose and move between them, then not having a particular app would not result in social isolation. This affects adults as well.

2. The OS has a firewall. But it's currently not user-controllable on your phone. Phone companies have decided you don't need that feature. But actually, they can easily implement a nice UI in the settings for the firewall and lock it behind a password, then parents would be able to use it to block individual websites. We can even make it possible to import/export site lists as a txt file so that you can download/share a curated block list that you or other parents made, to block many things at once. You could also do this for your entire home WiFi network in your WiFi router's settings, if your router's firmware has that feature.

And yeah, I agree that we should make the platforms less evil in general. But I think the way to do that is to give people the ability to easily ditch bad platforms and build new ones. Let the platforms actually compete, then the best will prevail. Right now, they don't prevail because of layers and layers of anti-competitive barriers. It would take great technical effort to regulate all the tricks these tech companies use, that's why I propose dealing with it at the root: make it so that all computer/phone hardware manufacturers must open-source their device drivers and firmware, and let the user lock/unlock the bootloader and install alternative OSes. If we do this, then the entire software ecosystem will fix itself over time along with all the downstream problems.

txrx0000··on Age verification on Systemd and Flatpak
1. Depends on how it's implemented. It won't identify you to individual platforms if the OS filters on a per-app or per-website basis. And yeah, there would be no dynamic behavior based on age, as that would enable tracking based on age. I don't think any kind of API is the ideal solution though, it's just better than the malicious one being mandated in the Cali bill. Instead of an API, it's simpler and more effective to just have an app installation lock (like sudo on Linux) and a firewall for website blocking with a nice UI in the phone's settings, locked behind a password/pin.

2. Other data points like User-Agent are not required by law, and browsers already spoof user agent by default. I agree that there are other data points we need to address, but the problem in this specific case is the slippery slope of legally-mandated data points. And I don't think winning high profile lawsuits is a real "win", it just exposes problem which we already know in this case. Keep in mind those people can get away with the Epstein files.

txrx0000··on Age verification on Systemd and Flatpak
Thanks for the clarification.

Regarding what to do with algorithmic feeds, instead of forcing platforms like Facebook to be less evil, we should give parents the ability to simply uninstall Facebook, and prevent it from being installed by the child. We could implement a password lock for app installation/updates at the OS-level that can be enabled in the phone's settings, that works like Linux's sudo. Every time you install/uninstall/update an app, it asks for a password. Then parents would be able to choose which apps can run on their child's device.

Notice their strategy: these companies make it hard/impossible for you to uninstall preloaded apps, and they make it hard to develop competing apps and OSes, and they degrade the non-preloaded software UX on purpose, which creates the artificial need to filter the feeds in existing platforms that these companies control. They also monopolize the app store and gatekeep which apps can be listed on it, and which OS APIs non-affliated apps can use. Instead of accepting that and settling with just filtering those existing platforms' feeds, we should have the option to abandon them entirely.

We need the phone hardware companies to open-source their device firmware, drivers, and let the device owner lock/unlock the bootloader with a password, so that we could never have a situation like the current one where OSes come preinstalled with bloat like TikTok or Facebook, and the bootloader is locked so you can't even install a different OS and your phone becomes a brick when they stop providing updates. If we allow software competition, then child protection would have never been a problem in the first place because people would be able to make child-friendly toy apps and toy OSes, and control what apps and OS can run on the hardware they purchased. Parents would have lots of child-friendly choices. This digital parenting problem was manufactured by the same companies trying to sell us a "solution" like this Cali bill or in other cases ID verification, which coincidentally makes it easier for them to track people online.

txrx0000··on Age verification on Systemd and Flatpak
Assume they're 18+ then.

But even that's still not a great solution. I outline a better solution that doesn't require any legal enforcement at all, in the link at the bottom of my original comment.

txrx0000··on Age verification on Systemd and Flatpak
There are two things very very wrong with the California law, which you call "age indication".

1) The parental responsibility is given to the wrong people. You're basically being forced by law to give all apps and websites your child's age on request, and then trusting those online platforms to serve the right content (lol). It should be the other way around. The apps and websites should broadcast the age rating of their content, and the OS fetches that age rating, and decides whether the content is appropriate by comparing the age rating to the user's age. The user's age, or age bracket, or any information about the user at all, should not leave the user's computer.

2) The age API is not "completely private". It's a legally-mandated data point that can be used to track a user across apps and websites. We must reject all legally-mandated tracking data points because it sets the precedent for even more mandatory tracking to be added in the future. We should not be providing an API that makes it easier for web platforms to get their hands on user data!

For many years, certain tech companies, SIGs, and governments have fought against technologies that could enable real digital parenting, all while claiming to do the opposite and "protecting children". They craft a narrative to convince you that top-down digital surveillance and access-control is for your own good, but it's time we reject that and flip their narrative upside down: https://news.ycombinator.com/item?id=47472805

txrx0000··on Proton Meet isn't what they told you it was
Counter-surveillance is not a binary switch. We can win by forcing the government to use increasingly expensive backdoors and exploits (>$10k per capita per year, beyond which mass surveillance is impractical even with a $1T budget). Hardware backdoor capabilities are costlier to maintain and use than something at the app level. Encrypting content and leaving metadata exposed is still better than encrypting nothing because they'll have less info to work with which means more effort. The point of all this is not to make it impossible for the gov and corps to surveil a targeted individual (of course they'd be able to if they expend enough resources). The point is to ensure that they only have enough resources to do targeted operations rather than blanket mass surveillance. The former is fine for a democracy, but the latter destroys it.
txrx0000··on Show HN: 1-Bit Bonsai, the First Commercially Viable 1-Bit LLMs
I always remind myself and everyone else that human DNA is "only" 1.6 GB of data, and yet it encodes all of the complex systems of the human body including the brain, and can replicate itself. Our intuitive feel of how much stuff can be packed into how many bits are probably way off from the true limits of physics.
txrx0000··on Olympic Committee bars transgender athletes from women’s events
The male-to-female ratio at 1500 elo is not 90:1, but more like 9:1. 10% is a visible minority.

But I see where our disagreement is. You think there ought to be more women in chess. I think different people can do different things, so women don't need to match men in every statistic and vice versa. If we open it up to universal participation and it turns out to be a male-dominated game, then let it be. I don't think there's anything wrong with that.

txrx0000··on Olympic Committee bars transgender athletes from women’s events
I don't deny that there are very few women in top chess, but that wasn't your point. You said it would end up being all men at all the skill rating levels, which is not true. Take chess as an example: there are a lot more women at around 1500 elo than at 2500 elo. So if you host an intermediate-level tournament just for players around 1500 elo, plenty of women will participate.
txrx0000··on Olympic Committee bars transgender athletes from women’s events
That's a possible compromise, but a high maintenance one. It would set a precedent for other groups, and then we'd have to add a new category every time people complain.

I think we should just make the Olympics universal and let anyone compete for the title of absolute best in the world, no qualifiers. Detach the existing categories too, like men-only or women-only. Make all category-gated games a separate deal, like Paralympics. Each group can organize their own variant if they want.

txrx0000··on Olympic Committee bars transgender athletes from women’s events
No it would not. Look at chess ratings.
txrx0000··on Olympic Committee bars transgender athletes from women’s events
> So you're just suggesting making everything mixed-sex, and having very few women at the Olympics?

Yeah. It would work like video game rankings. Top-ranked players are top-ranked because of skill, and if they happen to be mostly men for most games, so be it.

But I get your point. The crux of the problem is most people don't want to see skill-based matchmaking. They want to see the best man, the best woman, or the best disabled person, etc. The categories are already defined in people's minds as cultural constants. The trans people don't like this because they feel excluded by both male and female categories, so they argue in bad faith that there's no physical difference between females and trans-females or males and trans-males. Our long-term options as a society are to either 1) change culture so that people get used to skill-based matchmaking like in video games, or 2) ignore trans people and wait for this issue to disappear when future tech allows a man to transfer his consciousness into a female body and vice versa.

Since 2) is quite far out technologically, I propose 1).

txrx0000··on Olympic Committee bars transgender athletes from women’s events
Grouping based on skill would achieve what you describe and then some. It would eliminate every kind of advantage, not just sex-based advantage.
← PreviousPage 4 of 10Next →