HNHacker News
TopNewBestAskShowJobs

vbezhenar

16,044 karma · joined September 23, 2014

https://vbezhenar.com/
submissionscomments
vbezhenar··on Asahi Linux Progress Report: Linux 7.2
I'm using Intel Thinkpad. And I'm pretty sure that Intel does a good amount of work upstreaming Intel support in Linux. So I'm not sure that using Linux in general means having some unpaid volunteer do it for you. In fact I believe that most Linux development nowadays is pretty far from unpaid volunteer work.

Regarding state of non-Apple hardware. Well, my laptop just works. Literally zero hardware or compatibility issues. Maybe Macbook is faster in artificial benchmarks, but in my day to day usage, Thinkpad is more than fast enough.

vbezhenar··on TIL: You can make HTTP requests without curl using Bash /dev/TCP
I think that the fact that AI has a very recognizable singular style is a problem. And this problem will be solved, sooner or later. It probably isn't a very important problem, because I feel that it should be relatively easy to solve (but maybe I'm wrong?).

But certainly with smarter AI I do believe it'll become more fluent with choosing more diverse idioms and phrasing, rather than repeating one thing over and over, to a point of being a comically similar. So people who learn on AI-generated text, will not learn from just one recurring style.

vbezhenar··on TIL: You can make HTTP requests without curl using Bash /dev/TCP
You can actually do that today. In fact I did that for some time, because I didn't want to configure e-mail client. The only hard thing is HTML. Average HTML e-mail is almost impossible to read and friction to extract it to a file to open in a browser is too much.
vbezhenar··on TIL: You can make HTTP requests without curl using Bash /dev/TCP
You can't do that with HTTP/2 (but thankfully every server still talks HTTP/1).

You also can't do that with TLS (and a lot of servers won't talk HTTP other than redirects). openssl s_client instead of telnet might allow you to tunnel text inside TLS, but that feels like a cheating.

And many other modern protocols, sadly, prefer binary encoding, which makes it impossible to tinker with it on wire level, not without specialized tools anyway.

I think people in the future will bother. I tried to make a fire with sticks once, I tried to burn a clay brick, these old things can be a lot of fun and sometimes of real use. If anything, AI actually makes tinkering a lot more easier. You don't need to dig into RFC to check your mail, you can just talk to LLM about it and it'll help you with most typical IMAP commands, for example.

vbezhenar··on What job interviews taught me about Kubernetes
100% agree with you.

You can actually treat kubernetes as a glorified docker compose engine. Deploy pods, deploy nginx instead of ingress controller, deploy certbot cronjob instead of cert-manager, and believe it or not, it'll work! On a single server!

People often compare Kubernetes with thousands of additional services to a simple VPS, but that's not apples to apples comparison.

vbezhenar··on What job interviews taught me about Kubernetes
1. You can't force third-party software to do that. There are programs with hardcored ports. There are programs which require XML modifications and container rebuilds to change port number. If your platform does not support launching of unmodified containers, it is severely restricted and not suitable for general use. All my programs always use port 8080 for HTTP, I don't make it configurable because I have no reason to.

2. Does not work for all protocols. Again your solution restricts the number of protocols to HTTP protocols. Might work for many uses, but still this restriction doesn't sound very good. Universal load balancer is much simpler conceptually.

3. YAML is not terrible. YAML is awesome. Kubernetes manifests are terrible, that's I agree with. Docker compose is nice, for example. Kubernetes manifests felt like they were designed to be generated from something, but everyone ended up writing them directly or with templates. Though I think that XML generally is superior format so I'd vote for XML in the end.

Overall your suggestions look like you want to shift complexity from cluster operator to software developer. I'm not sure industry supports that, recently it seems to move in the opposite direction, but that's interesting perspective. I guess with some wrappers for some containers it could be made usable.

But honestly you just want to throw away years of progress in containers and network namespaces. I understand that kubernetes mechanisms are somewhat complicated, but the core idea is to make pods look like virtual machines and I think this is very worthy idea.

vbezhenar··on What job interviews taught me about Kubernetes
Docker swarm is that simple solution you're looking for. But people don't need simple solutions. They want scalable solutions and Kubernetes fits this niche perfectly. You can deploy it on single server today and scale to 100 servers managed cluster tomorrow.

Just to provide a similar example. Linux system is insanely complicated. Kernel alone has thousands of options. Distos have tens of thousands of packages. Wherever you look at, everything is hard and complicated. Firewall, containers, init system, filesystem hierarchy, storage layers. One would think that some people desire simpler operating system. But everybody uses Linux despite all these complexities. Try to find OpenBSD in production, for example. It's not easy.

vbezhenar··on Hetzner Price Adjustment
> much better privacy controls than any American company would be legally able to provide

Yeah, sure. They even MITM your TLS for extra privacy I suppose.

https://notes.valdikss.org.ru/jabber.ru-mitm/

vbezhenar··on Boot Naked Linux
As I'm currently exploring kernel build things, the alternative to `make tinyconfig` is `make allnoconfig` which is supposedly will not disable expert options and might be a little bit safer starting point.
vbezhenar··on Anthropic's Safety Superpower
But he already got it, no? Claude Fable can only be made available to US citizens, which implies that every user who wants to use Claude Fable must provide proof of citizenship in some way, basically KYC.
vbezhenar··on Anthropic's Safety Superpower
> does the users who use Anthropic switch over to those even if they're available even as hosted models?

I'm currently spending $200 for Claude. That's around my maximum that I can afford. I could stretch that to $500 I guess. But I saw reports of people spending tens of thousands of dollars with Claude API. That's certainly outside of my budget.

So if/when Anthropic decides to stop subsidizing subscription (if they ever do that thing, I still not sure about that), I'll certainly look at the other options. And available "open weights" LLMs hosted by someone will be my first pick. Right now Claude 4.8 feels very advanced, but things move very fast...

vbezhenar··on An Interview with Intel's Kira Boyko: Xeon 6's Product Director
TLDR:

- What is a product director?

- Xeon naming is very confusing

- AET is Application Energy Telemetry

- A lot of discussions about cheese

vbezhenar··on AUR packages compromised with Infostealer and Rootkit
I think that AUR is a not a very good idea.

It's essentially uncensored platform. I think they can moderate it, but obviously only for high-visibility cases.

Anyone can create package with any name, potentially impersonating any other project.

And that's all on archlinux.org domain, which inherently adds some trust to the whole concept. Trust that is unfounded.

If someone wants to distribute PKGBUILD, they should put it to Github or any other git hosting.

vbezhenar··on The Future of Email
> If it were that easy, everyone would be doing it.

E2E encryption is one click away in Telegram. I've yet to find anyone turn it on. Most people just do not care about encryption. The whole encryption story is pulled into mainstream by crypto-enthusiasts IMO.

vbezhenar··on The Future of Email
Of course it is possible to have E2E encryption on emails. You can have E2E encryption on everything. Just use `age` and encrypt your message with sender public key. Easy.
vbezhenar··on Software is made between commits
> I've been saved so many times by a git bisect that landed pointing at a tiny commit to a single line that looks completely innocuous, yet broke something in a subtle way that only got discovered way later.

I did git bisect exactly zero times in my life.

vbezhenar··on Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable
Their detection is too aggressive. Just today I'm trying to build a kernel for some SBC and I hit that downgrade. I just asked some things about `make menuconfig` items. I suppose it just flags everything related to linux kernel as cyber attacks.
vbezhenar··on Upcoming breaking changes for npm v12
You can build application outside of container, but run it in container. I think that it is simpler workflow, than everything in container (when you actually need to develop it with IDE).

I didn't try devcontainers stuff, TBH. But that's how I often develop my apps.

That said, there are other attack surfaces for that approach. For example I'm not sure if I can trust LSP server not to execute application code. So keeping everything in a container or in a VM seems to be the only sane approach to work with code you don't trust.

vbezhenar··on Claude Fable 5
I'm on $200 plan which is supposedly 20x usage of $20 plan. With few Fable prompts (I'm working on u-boot port) I got 10% of my 5h usage, so that's already 2x of $20 plan usage and that would be 40% of $100 plan.

So Fable is just not usable for $20 plan and barely usable for $100 plan.

vbezhenar··on Claude Fable 5
I don't live in USA. I'm getting paid around $2500/month and that's good salary for developers here, plenty of folks are getting below that number.

So this pricing is just completely outside of our economics and nobody I know would pay that, no company will justify spending $20k/month when they can hire 10 more developers instead.

It is very interesting unfolding of events. Can't wrap my head around it completely.

vbezhenar··on A discovery about GCC's unidirectional rotation algorithm
Sometimes I want to design a simpler C-like language and build toolchain for it from the scratch, with no historical baggage. Obviously optimization story will be very poor, gcc carries hundreds of super-qualified man-years of optimization work. But I wonder if it'll be that bad. Modern computers are fast.
vbezhenar··on Moving beyond fork() + exec()
As I understand it, the whole purpose of vfork is to avoid that problem. So vfork does not copy memory in any way and you're not allowed to do anything but exec after vfork. But at this point question arises: why not call it `vfork_and_exec` and get rid of undefined behaviour. Or choose better name like `CreateProcessW` hehe
vbezhenar··on Moving beyond fork() + exec()
Let's say you have 1GB RAM. You're running program that occupies 600 MB. Now this program wants to launch second small program that occupies 1 MB.

You're doing fork + exec.

If you're overcommiting, fork will not reserve another 600 MB, and exec immediately after fork will cause total system usage to be 601 MB.

If you're not overcommiting, that fork will fail, because total memory consumption will be 1200 MB which is more than 1GB. That somewhat restricts program design.

vbezhenar··on Ask HN: Why is the HN crowd so anti-AI?
Because I enjoy writing code. I enjoy being paid for writing code. And I don't enjoy writing prompts for AI.

Code is not just a means to an end. Code is a means to my happiness. Users might not care, but I do care. I love good code. I feel great when I can write good code.

I won't say that I don't care about users. I do. But I care about me, first and foremost. And AI threatens to remove my lifestyle and workstyle. That's why I'm bullish against it. And at the same time I use it, because I feel forced to use it. This is rat race.

At the same time I can say that I don't care about delivering product 10x faster. Actually I'd prefer to deliver product 0.1x faster.

Yes, I understand that contradicts to the business side of view. Well, I don't care. I'm not getting paid percentage of product sales. I'm getting paid flat salary and I care about keeping it and live good life in the process.

I'm being completely honest about it. Maybe it'll help someone to understand that point of view.

vbezhenar··on Entanglement Builds Space-Time. Now "Magic" Gives It Gravity
That's how science always worked. The stupid people throw money at smart people and sometimes they pay back with good things. Any attempts to optimize that is futile, so the best we can do is to continue throwing money.
vbezhenar··on Learn SQL Once, Use It for 30 Years
It is not obsolete. In fact, I've yet to encounter IPv6 anywhere, so my IPv6 knowledge so far stays mostly theoretical. And I work with servers.

Probably depends a lot on a particular location.

vbezhenar··on The ways we contain Claude across products
I'm using qemu VM. This VM has Internet access (that's the biggest risk, I guess, that claude can just upload things somewhere). If I want it to work with github, I create token restricted to repository with read or read/write access. But I prefer for it to not push, but just commit, then I can fetch these commits via ssh from VM, check log and push it myself.

I thought about just running claude in container, but it feels a bit weak. Too many Linux vulnerabilities around. Probably these fears are unfounded, but I feel safer running untrusted stuff in qemu VM.

vbezhenar··on Learn SQL Once, Use It for 30 Years
That's true. SQL knowledge is one of the few skills that didn't age.

1. C language.

2. *nix tools (shell and friends).

3. SQL.

4. Basic IPv4 networking.

These things I learned around 20 years ago, they didn't change much and they are useful for me to this day.

vbezhenar··on Microsoft builds MacBook Pro rival with NVIDIA-powered Surface Laptop Ultra
Recent Surface ARM laptops do not seem to be locked in any way.
vbezhenar··on Claude Opus 4.8
Finally I can make it think hard. This is feature I loved in ChatGPT (Pro Mode) and I missed in Claude for so long. Can cancel ChatGPT now, I guess.

Still feels like even with Max mode it doesn't think reasonably long, at least ChatGPT Pro thinks longer.

← PreviousPage 2 of 34Next →