HNHacker News
TopNewBestAskShowJobs

vetrom

476 karma · joined February 15, 2013

I do stuff with Linux and distributed systems. Embedded hardware too, nowadays.
submissionscomments
vetrom··on Sudo – A dedicated music player designed around listening to music
If it's the same people ("New Matter") that made https://www.indiegogo.com/en/projects/steveschell/new-matter... , then it basically is?
vetrom··on Ask HN: Just saw a YC25 job posting front page that looks like a 7-day work week
The being expected to fly around the country weekly in conjunction with 'this is not a remote position' is pretty wild.
vetrom··on Spaghettifying DRAM
Why does this whole set of paragraphs sound vaguely like a Claudeism?
vetrom··on Deletes all instances of Microsoft's GDID and prevents minting of new ones
I'm imagining a situation where you need to run windows on the host, but you do not want windows itself arbitrating network access -- so you pass through the real NIC to the vm, and route through the vm with a virtio (I think TAP is actually the only option host-side though but still) NIC.
vetrom··on Deletes all instances of Microsoft's GDID and prevents minting of new ones
Run say a linux firewall vm with PCI nic passthrough and give the host windows machine a virtio-pci/TAP interface as its network access is one countermeasure off the top of my head I can think of.
vetrom··on I'm switching my phone from Android to Linux
Linux cameras can be made to work well, it's a matter of software. Case in point, newer Ricoh/Pentax cameras actually run an a Linux firmware. (See: GR IV and K-3 Mark II/III). Parts of the software stack are already there, but noones had the will to glue it together correctly for a mobile device usecase, yet.
vetrom··on Show HN: SIEMatic, a fair-sourced observability and security platform
What makes this compelling over actual OSS stacks plus say Bro or some other IDS?
vetrom··on A 10 year old Xeon is all you need
IDK about OPs setup, but I run a pile of E5-2683v4 Xeon recycled servers for Ceph and self hosted business SaaS usage.

One node's ipmitool sensor report (and self-monitoring PSU, so grain of salt, but my UPS side monitoring tracks closely), reports 250-300w average power use. This though, mind you is for running 22 spinning disks, 2 SAS/SATA SSDs, and 4 NVME ssds, and 768GB of DDR4.

Mid-gen 2015ish Xeons were not great at power reduction, but if you are pegging the cores, they were never particularly slow, and they did have lots of PCIe lanes. This boils down to the CPU/mobo itself not being that big a cost floor, especially if you have high utilization rates.

As a comparison, my main desktop development machine, running a Threadripper 9970X, 128GB of DDR5, a RDNA4 GPU, and a small pile of NVME drives has a power floor of roughly 250W. Some CPU centric workloads you'll definitely lose out on on the older gens of machines, but they are by no means impractical.

Maybe for a desktop usecase they are absolutely suboptimal nowadays, but for a lot of realworld usecases I would say they're still relevant.

---

Like the author posts for the LLM usecase, I think optimizing the hardware choice to the application and not leaving levers unpulled is a big key, especially considering how wide a variety of bandwidth/power draw/peak frequency/corecount SKUs exist in the Xeon lines. Without knowing what you intend to run and fitting the correct processor to it, you will end up with a disappointingly poor environment fit.

vetrom··on California moves to exempt Linux from its age-verification law after backlash
Take the volume and mass of lobbying by all of data broker companies, data collection companies, and executive agencies.

Combine that with the character of practically every law written involving data privacy, use, IP, and associated regulation of activity around these since the 1990s. It becomes painfully clear that the interests of private citizens have not had a seat at the table, and the Constitution has been taken as an inconvenience to bypass, not a guiding document.

vetrom··on Ninth Circuit Panel Goes Out of Its Way to Question Section 230–DOE vs. Meta
The core sticking point is, I think, is that Section 230 was envisioned as a 'common carrier' exception. Common carriers do not apply editorial control to the content they transmit.

In the modern landscape, where practically every mainstream (and most of the non mainstream even) platform has extensive policies and applies them in a manner that's equivalent to editorial control, they are no longer a common carrier, they are a publisher.

Should that exemption and safe harbor be expanded to all publishers? If no, do you really want the Government picking and choosing favorites? Either way you choose, I believe there will be many first and further order implications.

You can either get Congress to modify the definition, or you could try to get a case through the courts to clarify its interpretation. As one of those indirect implications, I am actually not sure which one would be more of a footgun.

vetrom··on Show HN: Write your BPF programs in Go, not C
Well tinygo takes some go bindings they implemented for llvm, https://github.com/tinygo-org/go-llvm, uses the Go standard library for parsing, and wires it up to a LLVM IR generator, with a set of flexible backend/machine definition machinery.

You could likely improve gobee to use tinygo's packages directly, instead of transpiling to C and calling into clang, and the licenses of the two projects look compatible. You'll still need to deal with defining a subset to pass the verifier, of course.

---

From the README:

> Replace clang. clang's BPF backend gives us CO-RE, BTF, and verifier-friendly codegen for free. Reimplementing that costs years and gains nothing.

The primary gotcha you may hit if you try this is how much of the BPF features are implemented by clang, and how much is instead implemented in core LLVM. Even with a LLVM sitting next door you could pull out, the harnesses may not exist independent of clang, but I have not looked THAT deep.

vetrom··on sp.h: Fixing C by giving it a high quality, ultra portable standard library
Has anyone gone and implemented a 'real' (production not necessary) piece of software this this yet?
vetrom··on sp.h: Fixing C by giving it a high quality, ultra portable standard library
The title says 'standard library'. Are you saying that, in the context of C, that it is an error to take that to mean an implementation of libc?

Yes, I know the author's writeup then goes on to say that it is not a libc with a pile of questionable justfication. This is a custom runtime, in a single header no less, which is admittedly impressive, especially considering it provides runtime and thread safety primitives. This does not rise to the level of claiming the idea of a 'standard libarary' though, IMO. In that, I think the author misses the point.

vetrom··on How to Write to SSDs [pdf]
can be both, psql has pluggable storage engines. See any of the numerous columnar or sharding extensions for postgres for examples of prior art.
vetrom··on MPEG-2 Transport Stream Packaging for Media over QUIC Transport
I became aware of RFC4259: https://www.rfc-editor.org/rfc/rfc4259, but is there literature about its use in the wild? Searching on [rfc4259, nanog] comes up snake eyes for me.
vetrom··on K3sup – bootstrap K3s over SSH in < 60s
The dual clusters which run each others' control plane is also a perennial classic.
vetrom··on GoDaddy gave a domain to a stranger without any documentation
The point isnt the apologists that pop up whereever CF gets mentioned, the point is that they more or less have a built reputation for deceptive loss leader marketing.

Maybe early/MVP product engineers should know better, but CFs own education materials do not teach you to expect that.

vetrom··on GoDaddy gave a domain to a stranger without any documentation
https://robindev.substack.com/p/cloudflare-took-down-our-web... - one of a number of citations. To find more insert the terms [Cloudflare, hostage] into your favorite search engine.
vetrom··on NIST gives up enriching most CVEs
I think you have to look at the history of disclosure from the 90s to get a good grip here --

The CVE system arose as something of a mediating factor to enable coordinated disclosure of discovered issues and make something of a standard that vendors could point to and they they were being responsive, vs wondering if a random exposure on Bugtraq in the 90s would ruin your week.

If it no longer aids in that, then it has ceased to be a system useful for its original purpose, and it would be foolish to continue to feed it resources. It probably doesn't help that all sides viciously game the CVE system these days.

vetrom··on The Pentagon Threatened Pope Leo XIV's Ambassador with the Avignon Papacy
Papal visits to the United States have fairly long intervals to begin with. Wikipedia reports 10 trips between 1965 and 2015 (https://en.wikipedia.org/wiki/Papal_visits_to_the_United_Sta...). Given the relative rarity of visits, not having planned a trip during any given presidency would even be normal. It doesn't surprise me at all.

That's still a good question, though. Do any of them have anything more substantial than 'anonymous' sources, or even their own anonymous sources not linked to the breaking article's?

I am generally suspicious when anonymous sources quoted these days, but I am rather more suspicious of reports that only come from a single source and get repeated in multiple outlets more or less immediately.

I know there is some amount of synchronicity induced by syndicated news feed outlets like AP, but like many single source/anonymous stories, this reads to me like some 'suggested copy' was sent out to some reporters or outlets ahead of time.

Anonymous sources are important for the integrity of reporting, but it must also be recognized that they are essentially non-authenticatable information.

The author of the secondary source I see most mainstream sources quoting (Mattia Ferraresi) has also come out and said people are stretching and misrepresenting what he wrote: https://xcancel.com/mattiaferraresi/status/20424925662396866...

There is at least one outlet that appears to have asked the both Pentagon and the Church what was up and both parties told them the meeting was overstated as well: https://www.pillarcatholic.com/p/nuncios-pentagon-meeting-wa...

vetrom··on The Pentagon Threatened Pope Leo XIV's Ambassador with the Avignon Papacy
The U.S. Ambassador to the Holy See is on record saying this is a fabrication?

https://xcancel.com/BrianBurchUSA/status/2042307511504519366

I'm going to put this in the "Extraordinary claims require extraordinary proof" bin.

vetrom··on EFF is leaving X
My impression is that as EFF's executive leadership has evolved over time, the driving motivations and attitudes of that leadership has changed EFFs style of execution.

It has probably helped increase their raw numbers, but it has also induced "mission drift".

vetrom··on EFF is leaving X
What does it say? EFF has not bothered to engage with basically anyone that replies to them on X the platform at least since Dec 1, 2025. Searching for EFF replies from older posts also shows that they basically never engage with X users, apart from using it as an advertising firehose.

If they spent any appreciable amount of time replying to people and not just themselves, their X impressions would be considerably larger. X themselves has been clear that engagement weights impressions/recommendations/algorithmic display, and EFF has done none of that.

It looks to me like a people at EFF problem, not an X problem.

vetrom··on After 20 years I turned off Google Adsense for my websites
It seems to me at its root, that it's a question of available ad attention, and the value thereof.

The classic value prop for ads has been so badly destroyed by bad curation and content invasiveness that the basis value of that attention has dropped trough the floor. The growing prevalence of ad blocking is only a symptom of that.

This has become bad enough it even invades special interest nonprofit rags like the AAA, American Legion, and USPSA newsletters, for example.

vetrom··on EmDash – a spiritual successor to WordPress that solves plugin security
It looks like they rolled it so you can plug in local components of your choice, though? The security model does assume you have MAC containerized environments available at your fingertips though, so having something like DHH's once is probably a soft minimal dependency if you want to do-it-yourself.
vetrom··on EmDash – a spiritual successor to WordPress that solves plugin security
Functional April Fools, the best kind. A couple years ago Eleiko, a weightlifting equipment company did one, the 'Heavy Mug', a 19 poundish steel coffee cup with a handle in the style of a knurled bar, and actually did a limited run of them.
vetrom··on Sony V. Cox Decision Reversed
There is a very important consideration here that this opinion doesn't really touch on, but I think is invited down the road for future cases and legislation: Can you compel the speech of a third party to aid in exploratory evidence gathering (aka fishing expeditions) without a clear, well defined, and particular, cause of action at court to issue a subpoena?

In most classic U.S. jurisdiction, no, you cannot. Compelled activity or speech is generally frowned upon. The most important part of this case, IMO, was the Supreme Court constraining the Fourth Circuit's interpretation of contributory liability and attempting to turn the DMCA system into one for enabling those fishing expeditions.

vetrom··on Supreme Court Sides with Cox in Copyright Fight over Pirated Music
So, merely selling 'with intent' for the van to be used in a robbery I don't think meets the bar as the opinion is written. In particular, I read "...which can be shown only if the party induced the infringement or the provided service is tailored to that infringement;"

In that vein, merely selling a tool even if a predominant use or intention of that tool is infringement, the infringement must be actively induced or invited by the seller. This is also affirmed in detail in the USSC opinion: "The Court has repeatedly made clear—see Kalem Co. v. Harper Brothers, 222 U. S. 55, Sony, and Grokster—that mere knowledge that a service will be used to infringe is insufficient to establish the required intent to infringe."

This is the primary part of the opinion, the first 7 of 27 pages. I'm still reading the rest and will update when finished. (Concurring Opinion and Dissents I believe)

===

The meat of the opinion has some interesting elements as well:

* "Internet service providers, such as Cox, have limited knowledge about how their Internet services are used and who uses them. They do know which IP address corresponds to which subscriber’s account, but they cannot distinguish one individual user from another...However, because online infringement is so widespread, pursuing each individual infringer does little to stem the tide.": mere IP logs are not enough to establish liability, perhaps. More importantly, it is opined that individual fishing expeditions dont actually serve the end of eliminating infringement. This does not absolve individual liability, but it becomes important later.

* "Holding Cox liable merely for failing to terminate Internet service to infringing accounts would expand secondary copyright liability beyond our precedents ... The Fourth Circuit’s holding thus went beyond the two forms of liability recognized in Grokster and Sony. It also conflicted with this Court’s repeated admonition that contributory liability cannot rest only on a provider’s knowledge of infringement and insufficient action to prevent it.": This points to another case where Circuit and District courts have been ignoring the instruction of higher courts, in this case, inventing new liabilities where none existed. This doesn't go so far as to repudiate entirely the idea of fishing expeditions having teeth, but it places a clear guardrail around expanding liability without laws establishing such.

===

The Sotomayor concurrence on judgment states that the Justice does not believe the methods used by the majority opinion are correct, but still agrees with the judgement because of insufficient information presented by Sony. I think the analysis gone into in this section is flawed, but it is also not precedential since it is not the Order part of the opinion. I am also out of time to poke at that part for the moment. It does relate this case to the closest recent big case on secondary liability though, that of Smith & Wesson Brands, Inc. v. Estados Unidos Mexicanos, so its worth reading even if the justifying analysis I think does not fit.

The big difference I guess is whether you think negative jurisdiction (limiting what the government can do) vs positive jurisdiction (further enabling the government) is more important, but considering HN and the exhortations against divisive commentary, I'd rather not dive into the weeds arguing that part here.

vetrom··on Supreme Court Sides with Cox in Copyright Fight over Pirated Music
There already is a specific law shielding gun manufacturers from liability from simple sales, which Democrat heavy states and locales do a lot of work to test the edges of and chip away at: the PLCAA, https://en.wikipedia.org/wiki/Protection_of_Lawful_Commerce_... which was passed in 2005 in light of mendacious lawsuits taking up a notable amount of courts' time.
vetrom··on Sony V. Cox Decision Reversed
> where overwhelming amount of USED guns are used to accompany crime

I do not think this holds up to a factual analysis if you look at any cross section of defensive gun use reports. I don't think that parts actually relevant here though. If you were to use a similar standard as the USSC court applies here: Impressions don't matter to qualify for inducement. The action must be actively invited.

Page 1 of 9Next →