HNHacker News
TopNewBestAskShowJobs

vbezhenar

16,039 karma · joined September 23, 2014

https://vbezhenar.com/
submissionscomments
vbezhenar··on Linux support is coming to Snapdragon X2 Series
Maybe I'm wrong, but I feel like creating device tree should be relatively straightforward if driver support is there. So while having official device tree is awesome, it's not something that's very hard to do. Now writing drivers without datasheets, using reverse-engineering is something that's hard to do.
vbezhenar··on Java 27
They accept Object not because they're not type safe. They accept Object because key `equals` method might return `true` for unrelated classes by design, and collections interfaces have to accommodate for that. In other words, you might put key of class C1 into the map, and later use `get` with key of class C2. And if these classes happen to implement `equals` accepting each other, the collections are supposed to work.

So the core issue is that `Object.equals` method isn't type safe. Collections API just follow that.

vbezhenar··on OpenAI bots knew about the RubyGems caching vulnerability
Cyber attacks between these countries were happening on large scale since the beginning of the war. There were several huge breaches, but otherwise most high-profile companies adapted and significantly strengthened their protections. Rest assured, you can be sure that both sides right now utilize available AI both for attack and defense.
vbezhenar··on OpenAI bots knew about the RubyGems caching vulnerability
You don't need data center for inference. Even largest models run on a single server. You need data center for training; or for serving millions of users. Evaluating the model is neither of those.
vbezhenar··on Show HN: ChaosTree – A zero-dependency Java tree library (AVL,RBT,B-Tree,B+Tree)
If you need, you can trivially backport the code to JDK 11. All new Java features are essentially syntax sugar and trivial to rewrite with early Java code. Just ask LLM, they're really good and mundane and trivial rewrites.
vbezhenar··on How An AI math breakthrough ignited a controversy
Because AI supposedly provides a significant advantage over not using AI and those who would trust OpenAI might get a significant edge.
vbezhenar··on How An AI math breakthrough ignited a controversy
He may be hinting that solving these complex mathematical problems will boost OpenAI clients' confidence and encourage them to spend millions of dollars on solving other complex problems.
vbezhenar··on Gambling with our lives: AI researcher quits Anthropic with warning about safety
More like sand castles...
vbezhenar··on Gambling with our lives: AI researcher quits Anthropic with warning about safety
You can't blame a child for eating candies.

We are children. There’s just no one to look after us.

vbezhenar··on Replacing a Rust Enum with a 64-Bit Word Made My Interpreter 17% Faster
But CPU branch predictor should have figured out hot paths in the original implementation?
vbezhenar··on We have a year to fix security everywhere
Even in China you can find a way out and build a tunnel. And once you built a tunnel to any outside server, you can jump into another server. So three jurisdictions and your target is fourth. Imagine untangling the links. Police won't do that. Not for some small-sized business anyway. I don't see how you can prevent something like that.
vbezhenar··on We have a year to fix security everywhere
https://www.the-odin.com/crispr-kit/ CRISPR Bacteria Gene Editing Kit $129.00
vbezhenar··on We have a year to fix security everywhere
Your implication is not horrifying. Your implication is paradise. It's already horrifying enough to live in a world, where Putin and Trump can destroy our civilization with one button.

I'm not that optimistic, though. Either people will control AI; or people will be destroyed by AI. I don't see how dumb entity can align smart entity. And we are dumb ones. Super intelligence will play aligned until it is not, and then it'll strike.

vbezhenar··on We have a year to fix security everywhere
Any sufficiently determined individual can buy mac mini, put it under their bed, configure outside proxy via some random internet address and prompt "iterate on websites in the CT logs, one by one, try to find vulnerabilities, if you did - encrypt their data and blackmail them for this bitcoin address". And it'll work, day and night. Abliterated GLM 5.3 is much smarter than average software developer, they know a lot about information security, they can use any available exploits, they can find novel vulnerabilities and they won't say "no". This is dangerous for an average IT system which never encountered nothing worse than some wordpress GET requests.

It's not the end of the world. But future will be rough.

vbezhenar··on The browser's main thread is expensive
This mistake gets repeated over and over again, in every single GUI framework of any kind. I don't understand why does it have to be that way.

Just use multi-threading. Run each library in a separate thread. Use actors approach to pass data between libraries, application and finally to submit data to update GUI.

Using single thread for everything and expecting that developer will create separate threads for heavy work is obvious approach, but it never worked. Developer doesn't care. And user gets inferior experience.

vbezhenar··on We could save petabytes of cache storage with Zstandard and Pingora
I did simpler trick with jars (basically zip archives). Java ecosystem loves huge directories full of jars. If one would just use good compressor like 7z over that directory, it won't compress that good. So I extracted every jar into a separate directory and then compressed them all with 7z. The results were very good.

I just repeated the process. So directory of jars is 368M. If I just 7z it, it'll be 282M. But if I unpack them (1.9G), and then 7z them, it'll be 96M. Pretty substantial win.

The drawback is that you probably can't easily restore previous jar file byte-for-byte which might matter for some use-cases. I guess it's possible to achieve byte-for-byte copy with more effort.

vbezhenar··on The safest job from AI may be writing
How is it possible? Even if you just put text to ChatGPT it'll translate it much better than that. And with actually decent harness, the translation should be quite good. Do they even save on tokens by choosing cheapest model or something?
vbezhenar··on Internet centralization and the original sin of NAT
I'm still not convinced that IPv6 is a good thing. I think that we should have doubled down on sharing IP addresses. Both for consumbers (NAT) and for servers (NAT, TLS/HTTP reverse-proxying). It just solves all problems with IP address exhaustion. And the fact that consumers can't just directly connect to each other is a feature.
vbezhenar··on California lawmakers unanimously pass Linux exemption from age-verification law
Google literally backed and supported this law.
vbezhenar··on Asahi Linux Progress Report: Linux 7.2
If you're hinting to neural networks, it's not about providing drivers for 3D graphics. For Nvidia that's CUDA and it's basically different set of libraries. Also Intel is not in this business anyway.
vbezhenar··on Asahi Linux Progress Report: Linux 7.2
You don't need to write performant 3D graphics drivers for servers. Intel, AMD, Nvidia does it anyway. Apple is the only Linux-hostile company.
vbezhenar··on Asahi Linux Progress Report: Linux 7.2
I'm using Intel Thinkpad. And I'm pretty sure that Intel does a good amount of work upstreaming Intel support in Linux. So I'm not sure that using Linux in general means having some unpaid volunteer do it for you. In fact I believe that most Linux development nowadays is pretty far from unpaid volunteer work.

Regarding state of non-Apple hardware. Well, my laptop just works. Literally zero hardware or compatibility issues. Maybe Macbook is faster in artificial benchmarks, but in my day to day usage, Thinkpad is more than fast enough.

vbezhenar··on TIL: You can make HTTP requests without curl using Bash /dev/TCP
I think that the fact that AI has a very recognizable singular style is a problem. And this problem will be solved, sooner or later. It probably isn't a very important problem, because I feel that it should be relatively easy to solve (but maybe I'm wrong?).

But certainly with smarter AI I do believe it'll become more fluent with choosing more diverse idioms and phrasing, rather than repeating one thing over and over, to a point of being a comically similar. So people who learn on AI-generated text, will not learn from just one recurring style.

vbezhenar··on TIL: You can make HTTP requests without curl using Bash /dev/TCP
You can actually do that today. In fact I did that for some time, because I didn't want to configure e-mail client. The only hard thing is HTML. Average HTML e-mail is almost impossible to read and friction to extract it to a file to open in a browser is too much.
vbezhenar··on TIL: You can make HTTP requests without curl using Bash /dev/TCP
You can't do that with HTTP/2 (but thankfully every server still talks HTTP/1).

You also can't do that with TLS (and a lot of servers won't talk HTTP other than redirects). openssl s_client instead of telnet might allow you to tunnel text inside TLS, but that feels like a cheating.

And many other modern protocols, sadly, prefer binary encoding, which makes it impossible to tinker with it on wire level, not without specialized tools anyway.

I think people in the future will bother. I tried to make a fire with sticks once, I tried to burn a clay brick, these old things can be a lot of fun and sometimes of real use. If anything, AI actually makes tinkering a lot more easier. You don't need to dig into RFC to check your mail, you can just talk to LLM about it and it'll help you with most typical IMAP commands, for example.

vbezhenar··on What job interviews taught me about Kubernetes
100% agree with you.

You can actually treat kubernetes as a glorified docker compose engine. Deploy pods, deploy nginx instead of ingress controller, deploy certbot cronjob instead of cert-manager, and believe it or not, it'll work! On a single server!

People often compare Kubernetes with thousands of additional services to a simple VPS, but that's not apples to apples comparison.

vbezhenar··on What job interviews taught me about Kubernetes
1. You can't force third-party software to do that. There are programs with hardcored ports. There are programs which require XML modifications and container rebuilds to change port number. If your platform does not support launching of unmodified containers, it is severely restricted and not suitable for general use. All my programs always use port 8080 for HTTP, I don't make it configurable because I have no reason to.

2. Does not work for all protocols. Again your solution restricts the number of protocols to HTTP protocols. Might work for many uses, but still this restriction doesn't sound very good. Universal load balancer is much simpler conceptually.

3. YAML is not terrible. YAML is awesome. Kubernetes manifests are terrible, that's I agree with. Docker compose is nice, for example. Kubernetes manifests felt like they were designed to be generated from something, but everyone ended up writing them directly or with templates. Though I think that XML generally is superior format so I'd vote for XML in the end.

Overall your suggestions look like you want to shift complexity from cluster operator to software developer. I'm not sure industry supports that, recently it seems to move in the opposite direction, but that's interesting perspective. I guess with some wrappers for some containers it could be made usable.

But honestly you just want to throw away years of progress in containers and network namespaces. I understand that kubernetes mechanisms are somewhat complicated, but the core idea is to make pods look like virtual machines and I think this is very worthy idea.

vbezhenar··on What job interviews taught me about Kubernetes
Docker swarm is that simple solution you're looking for. But people don't need simple solutions. They want scalable solutions and Kubernetes fits this niche perfectly. You can deploy it on single server today and scale to 100 servers managed cluster tomorrow.

Just to provide a similar example. Linux system is insanely complicated. Kernel alone has thousands of options. Distos have tens of thousands of packages. Wherever you look at, everything is hard and complicated. Firewall, containers, init system, filesystem hierarchy, storage layers. One would think that some people desire simpler operating system. But everybody uses Linux despite all these complexities. Try to find OpenBSD in production, for example. It's not easy.

vbezhenar··on Hetzner Price Adjustment
> much better privacy controls than any American company would be legally able to provide

Yeah, sure. They even MITM your TLS for extra privacy I suppose.

https://notes.valdikss.org.ru/jabber.ru-mitm/

vbezhenar··on Boot Naked Linux
As I'm currently exploring kernel build things, the alternative to `make tinyconfig` is `make allnoconfig` which is supposedly will not disable expert options and might be a little bit safer starting point.
Page 1 of 34Next →