HNHacker News
TopNewBestAskShowJobs

usr1106

4,860 karma · joined August 1, 2017

submissionscomments
usr1106··on I don't like passkeys
A bank that cannot be used in the browser has no decent service.
usr1106··on An update on Wayback Machine access
No. What happened to their remote library scheme? They did not make if for profit, but still...
usr1106··on An update on Wayback Machine access
Interesting, in all the years I have never noticed that IP has 2 meanings (well probably more...) Yeah, I am an engineer and usually try to avoid the legal BS. Although I hate that AI has made stealing legal if you are big enough.
usr1106··on An update on Wayback Machine access
Sorry, not following. I thought the user agent is a string that the caller can set to anything. There is no immediate, reliable way to tell whether the string is correct.

Yeah, a real browser would produce certain patterns and never certain others. So in some cases one could clearly say it's not a human using a browser. But a scraper could also make efforts to mimic human browsing. Mostly the frequency of requests can tell with high probability tell it's not human. But such algorithms might occasionally give false positives for real users, exactly like it has obviously happened for the archive.

What google service are you referring to? Not sure whether the archove uses any of Google's tracking. I have pretty strong blocking of trackers and ads. But the archive works for me.

usr1106··on The revolt of the reader
> but they simply don’t allow signing up with my custom email domain.

Tried 4 different domains. 3 of email services of various kind. 4th one my private domain which has absolutely no email reputation because I use it only for internal emails and sending is not even possible.

In the end I dug out some old gmail address and tried to use that.

The error was always the same, there had been suspicious activity from that domain. So the message is definitely incorrect. Well, there could have been suspicious activity from some gmail address, but if they don't allow gmail I guess they don't want many customers.

Yeah, did not cover my tracks. The could easily notice that I was the same one trying to sign up repeatedly with different emails.

usr1106··on Chrome again exempts Google from user site data settings
It seems to be very popular on this site to condemn surveillance capitalism and billionaires. But who built and still maintains the basis for their power, misusing it and the billions. So-called smart engineers like many of HN readers. If they rated morale higher than their personal 100Ks we would not need to wait for a government to stop the misery (in vain).

Yes, I have worked for 400,000 employees corp, then for a 70,000. For the last 15 years I have staid under 100. The pay is less, but it's easier to look into the mirror each morning.

usr1106··on Git hosting that never leaves Europe
I don't want to host in a country where a wannabe king breaks the law continously, who treats former allies like enemies etc etc

Which country do you recommend? Offshore on my own boat?

usr1106··on Shutting down our public encrypted DNS
I use Clouldflare DoT and enabled validation in systemd-resolved some time ago. Not because I would be particularly paranoid, but more out of curiosity how it works. I noticed no problems, except for with Atlassian. They use 2 second level domains (at least), one under .com signed and one under .net (unsigned) (IIRC). Most things worked like normal, but some Jira extension stopped working. Turned out that systemd did reject their signed subdomains. Could not figure out whether the rejection was justified or not. When I asked Claude 7 times about it, I also got 7 contradicting answers... Reported to Atlassian support that their signing is incorrect (some delegation missing). To my surprise they replied: Are you using systemd? And gave a bug number that systemd handles validation wrong in their case.

Haven't had time to study the bug and really understand the whole issue myself. Just left it there with the takeaway that local validation is currently not for non-experts.

(Sorry not at my computer. Details rather vague from memory.)

usr1106··on What's within a 10-minute walk in 50 European cities
I looked at some other cities I know a bit. Those "facts" are typical AI slop. Not always completely wrong, but stereotypes you will easily find on the internet.
usr1106··on Linux 7.2
It was the default on SUSE / OpenSUSE for years. Haven't used them for a while, not sure whether it still is. No problems with basic functionality including snapshots. I believe some RAID configurations were experimental for long time.
usr1106··on Debian weighs eight options in vote on LLM usage
There you can see true democracy. Some of the same people are backing competing proposals. Not claiming that there were a single truth and give voters true choice.

Remains to be seen whether their complicated voting system [1] comes up with a result. I don't dare to make complete predictions, although I am sure that many voters see AI very critical.

[1] https://www.seehuhn.de/pages/vote.html

usr1106··on Linux 7.2
Exactly. My immediate reaction was: A violation of HN submission guidelines. Linux is project of many contributors / companies. For sure Igalia is a valuable contributor and I would not doubt to recommend them for serious Linux work, but this "article" is pure marketing.

https://lwn.net/Articles/1088991/ has all the relevant links. Probably somewhwere there is also a more detailed "neutral" article.

usr1106··on India has paved the way for charging merchants a fee on UPI transactions
> But Apple, Visa, Mastercard and Google Pay aren't very "competent" either.

The article doesn't say and I know nothing about India. I could guess consumers are oaying using their smartphones. So Google/Apple duopoly are still the gatekeepers to use UPI making huge profits. Of course using one of the American backends would make their control and profits orders of magnitudes bigger.

usr1106··on Stop sending me huge PRs; a rant
Has it ever been a thing in most companies? I have seen definitely more bad code and negligance than serious, skillful attempts to write clean code.

Which rules do you think are particularly outdated?

usr1106··on My Homelab Got Hacked – A Postmortem
Haven't you noticed that LLM are a vastly unethical technology? Stolen content processed using amongst others slave labor from Africa and huge environmental impact. Paid by the average computer buyer today.

Yes, my employer strongly encourages me to act unethically. And in cases like in TFA I do.

usr1106··on Fastmail offers EU data region
No. Did you read the OVH story linked by user kvemkom? https://www.heise.de/en/news/Canadian-Court-OVHcloud-from-Fr...

A difference could be that Germany might not have such blocking law as France. At least I have never heard of it.

usr1106··on Python string literals are kinda funny
Interesting read. I had no ides that they switched the parser https://peps.python.org/pep-0617/
usr1106··on Harvesting SSH Credentials: Insights from My Honeypot Network
This was submitted 2 weeks ago https://news.ycombinator.com/item?id=48947548

Seems more entertaining than suitable for real analysis. At least I did not see any collected data. You can just watch what happens at this moment.

From watching it a while I came to the conclusion that adding a new authorized ssh key is a common first step.

usr1106··on DMARC has been public since 2012 but most company domains still don't enforce it
Interesting thread. However, for over a year, the "secure email provider" did not reply more than that the consultants are too overloaded to reply...

The message you obviously refer to as just an educated guess by a forum user who seems to be experienced in email topics. It could be that the guess is correct. It could be hat the consumtants are too overloaded to configure things differently. Another user has that guess. We don't know as long as the provider does not answer.

usr1106··on git's –end-of-options Flag
Copilot CLI (we get that at work) often uses slightly low-level and cryptic git commands. Never noticed that it would use --end-of-options though.

Should check what it does with branch names starting with a dash.

Of course that wouldn't be a security vulnerability, but a user error. It asks user approvals to execute those things and has disclaimers to check results. Which of course every user does all the time... /s

usr1106··on git's –end-of-options Flag
Like the von Neumann architecture. Your data can be misused as code.

Don't see that we get rid of either command lines in text or von Neumann any time soon.

usr1106··on The EU is about to sell our most sensitive data to the US for visa-free travel
Unless it has changed recently Germany has no general database of biometric data. Of course law enforcement has for the cases they work on, but for the average passport holder the data gets destroyed once the passport has been accepted by the citizen. So it remains only decentralized in passport chips.

It's probably an exception in EU.

usr1106··on OnePlus halts operations in USA and Europe
Land of the free oligarchs.
usr1106··on OnePlus halts operations in USA and Europe
I was figthing a bit recently to make my 9210 Communicator charge again after well over 20 years in the drawer. But it eventually worked. The first phone with a color screen and a keyboard!
usr1106··on No leap second will be introduced at the end of December 2026
Isn't this anti-news? I vaguely remember they have stopped introducing leap seconds until further notice because they cause too much trouble with today's computing systems. On my phone now and did not research it, as I say vaguely remember. Now we are 37 seconds off. Nobody of us will have to worry that Christmas is around Easter time. We can leave that problem to future generations much more responsibly than many other problems.

That the notice comes every 6 months is just to meet the letter of the original international treaty.

usr1106··on Android Developer Verification: Threat masquerading as protection
Recent headlines in Finland say that about 10% of the population are basically excluded from society with no access to important services.
usr1106··on Android Developer Verification: Threat masquerading as protection
I have a German bank sccount that can be used with a standalone code generator, that uses the chip on your bank card.

I have a Finnish bank account that use a completely standalone, purely time-based code generator.

Alternatives exist. But with current know your customer requirements it's increasingly difficult to open new ones if you are a foreigner and/or non-resident.

usr1106··on Finland's last analogue landline phones go silent after 150 years
In Finland many news outlets had the same headline, but needed to correct it. It's the last big operator who closed their network. There are still a couple of smaller local operators that have not yet stopped. Finland traditionally had many local phone companies and a few have obviosly survived.
usr1106··on Order a burned CD of your own public GitHub repo
A terball does not contain git history.
usr1106··on Order a burned CD of your own public GitHub repo
It won't backfire because there is no relevant competition. A couple of complains on social media, but no drop in sales.
Page 1 of 34Next →