HNHacker News
TopNewBestAskShowJobs

vgalin

148 karma · joined February 16, 2021

submissionscomments
vgalin··on Mistral X Mozilla: Private, Multilingual AI Browsing
> These are two companies that seem to be slipping in ethics recently

What makes you say that?

vgalin··on ChatGPT Images 2.5
The introductory video is a bit... daring. Generating tattoos that clearly look AI-generated is not one of the use-cases I'd try to sell.
vgalin··on Google says criminal hackers used AI to find a major software flaw
The company doing the actual ID verification (KYC) is probably the last company I'd trust with this kind of data.

To circumvent conversations being flagged as "cybersecurity bad!!!" I often have to use previous models (5.3 for example, and sometimes using them through subagents is enough). And when this method no longer works, local models will be good enough for it to not be a problem (for my use case, at least).

vgalin··on Google releases Gemma 4 open models
I ran gemma4:26b without any tooling access and it gave me the correct answer in a few minutes only (definitely less than 8 minutes, but I didn't timed it).

Specs : RX 9070 XT (24GB VRAM) + 16 GB RAM

gist : https://gist.github.com/vgalin/a9c852605f39ab503f167c9708a46...

(I gave it another go and it found the correct result in about a minute, see the comment on the gist)

vgalin··on Switch to Claude without starting over
> And that is shared with chat too.

Huh, I didn't know about that. I'm trying Claude Pro for the first time while comparing it against ChatGPT and I'm (sadly) not impressed at the moment.

When I asked both Codex and Claude Code to "look into" an issue of medium-to-high-complexity in a code base, Codex went with the fix I had in mind and directly and made code changes without being asked or at least asking for permission. It only used a few percents of its 5-hour limits to do it, on `High`.

Claude in the meanwhile misdiagnosed the core of the issue on its first pass (even on Opus 4.6 + Thinking). I had to guide it in the right direction and despite being given the 'answer', it was quite a long process compared to Codex' one-shot. And it hit the 5h limit before being able to finish solving the issue.

vgalin··on Pyxel: A retro game engine for Python
Python library with Rust backend*
vgalin··on I am sick of LeetCode-style interviews
But the older you are, the more likely it is that you have built a family and have children and responsibilities outside of work. You cannot necessarily afford to spend time studying (problems untied to the real world) as much as someone younger I guess.
vgalin··on Making USB devices – end to end guide to your first gadget
I didn't used a kit, but bought the components separately (microcontroller, key caps, switches, wires). It runs custom code as it was sufficient to fit my use case, though QMK may be possible? The keys are mapped from F13 to F22 and can be use in some software that allow custom keybinds.
vgalin··on Making USB devices – end to end guide to your first gadget
I recently built a small hand-wired macro pad using an Arduino Pro Micro equipped with ATmega32U4, it's apparently quite popular amongst hobbyists building custom keyboards. Quick and fun project for a beginner, the most tedious part of this project was to carve the wooden case.
vgalin··on Colab notebook to create Magic cards from image with Claude
(Disclaimer, I'm the maintainer of this package, but this kind of use is exactly why I created it at the beginning)

If you know how to use HTML+CSS and would like to generate full-fledged cards, you could use a package such as html2image [0] to combine the text, the image and a card-template image into one final image. Chrome/Chromium has to be available on Colab Notebooks though, that's the only requirement. Using basic SVG without this package could also do the trick.

[0] https://github.com/vgalin/html2image

vgalin··on Algorithms for Modern Hardware
People are now boycotting knowledge?
vgalin··on Thanks FedEx, this is why we keep getting phished
(translation provided by ChatGPT)

> Terms and Conditions, Price and Service List, Conditions.

> Dear customer,

> our price and service list, our terms and conditions, as well as further conditions which will come into effect on May 1, 2024, can be found on the USB stick.

> With kind regards,

> The Sparkasse Bremen AG

vgalin··on Ask HN: What's your "it's not stupid if it works" story?
I wrote a Python package [1] that does something similar! It allows the generation of images from HTML+CSS strings or files (or even other files like SVGs) and could probably handle PDF generation too. It uses the headless version of Chrome/Chromium or Edge behind the scenes.

Writing this package made me realize that even big projects (such as Chromium) sometimes have features that just don't work. Edge headless wouldn't let you take screenshots up until recently, and I still encountered issues with Firefox last time I tried to add support for it in the package. I also stumbled upon weird behaviors of Chrome CDP when trying to implement an alternative to using the headless mode, and these issues eventually fixed themselves after some Chrome updates.

[1] https://github.com/vgalin/html2image

vgalin··on How would you say “She said goodbye too many times before.” in Latin?
For further nitpicking: "etc." shall also end with '.' as it is the abbreviated form of "et cetera/caetera". Also, when used in an enumeration, it shall be preceded by a comma.

https://en.wikipedia.org/wiki/Et_cetera

vgalin··on Harvard ethics professor allegedly fabricated multiple studies
If this is an established fact, where could one learn more about this?
vgalin··on Bark: A transformer based text to audio system
The french example sounds off in my opinion, it seems to mix up its consonants/ vowels.

The "OU" sound from "nous" sounds like "EU", or like if the sound was skipped. The "OH" sound from "sommes" sounds like "EU" (again, but less pronounced). The "T" sound from "trop" becames "P" ("pro").

vgalin··on Ask HN: Where to Feature Startup on Spanish, Portuguese, German, French?
It appears to be invite-only (even though you can request an invite). I'm not sure about what drove them to do so, but that may be why there is not much activity on the website.
vgalin··on On Having Enough Socks (2019)
Interestingly, they have a "barcode" system that allow them (and allow us) to know the age of a given sock.

"Blacksocks knows the age of all socks" https://www.blacksocks.com/en/ageofthesocksen

vgalin··on Show HN: GPT-4-powered web searches for developers
This peculiar tool seems to be aimed at developers, so I don't find it surprising.
vgalin··on Attacker with access to XML config can trigger keepass.exe to obtain passwords
If 'someone' (an attacker), introduced themselves physically in your house or workplace (thus obtaining a high level of access) to place hidden cameras and to record you typing your master passwords. And if that someone later retrieved the footage and a copy of your password manager database... Would you blame your password manager for being insecure?
vgalin··on Attacker with access to XML config can trigger keepass.exe to obtain passwords
Then it would be an attack vector of course, but whether it is a vulnerability of the password manager itself would be debatable.
vgalin··on Attacker with access to XML config can trigger keepass.exe to obtain passwords
The XML config file is by default stored locally, as KeePass doesn't support cloud-backup or sync out of the box. If the XML config file is on DropBox, that is because you allowed it (either by uploading it manually or because you enabled sync on a whole directory / directory tree).
vgalin··on Attacker with access to XML config can trigger keepass.exe to obtain passwords
About data stored in-memory, see KeePass.info > Security > Process Memory Protection [0]

> While KeePass is running, sensitive data is stored encryptedly in the process memory. This means that even if you would dump the KeePass process memory to disk, you could not find any sensitive data. For performance reasons, the process memory protection only applies to sensitive data; sensitive data here includes for instance the master key and entry passwords, but not user names, notes and file attachments. Note that this has nothing to do with the encryption of database files; in database files, all data (including user names, etc.) is encrypted. [...]

[0] https://keepass.info/help/base/security.html#secmemprot

vgalin··on Attacker with access to XML config can trigger keepass.exe to obtain passwords
This 'someone' could also, on most computers, install a keylogger to get your master password, or passwords that aren't registered in a password manager. Would you consider this a vulnerability coming from the password manager?
vgalin··on Attacker with access to XML config can trigger keepass.exe to obtain passwords
To perform an export of a KeePass database, the database needs to be opened using (at least) a master password. A database file without its master password is still worthless on its own.
vgalin··on Attacker with access to XML config can trigger keepass.exe to obtain passwords
The export would only be triggered when a database is opened, so the master password is required.
vgalin··on The Minecraft End Poem was released under a public domain license by its writer
TL;DR from Julian Gough blog post[0]:

"I wrote the End Poem for Minecraft, the most popular video game of all time. I never signed a contract giving Mojang the rights to the End Poem, and so Microsoft (who bought Minecraft from Mojang) also don't own it. I do. Rather than sue the company or fight with my old friend, who founded the company and has since gone off in the deep end, I am dedicating the poem to the public domain. You'll find it at the bottom of this post, along with a Creative Commons Public Domain dedication.

Anyone can now play with it. Have fun."

[0] https://theeggandtherock.substack.com/p/i-wrote-a-story-for-... (this link was found on the Reddit post)

vgalin··on Why do we hack?
Whether Frankenstein is human or not is the question directly asked by Mary Shelley's book. As in our "making or not" problem, ironically, the answer is neither black nor white, as the monster is alive, yet made of dead flesh, and can be cruel, yet display human-like sensibility.

My point is that the line is blurry. "Configuring" a system with a large amount of parameters can be considered "creating something". A good example is how the knobs on a synthesizer can be tweaked to achieve a peculiar sound.

vgalin··on Why do we hack?
Then, where does being a "maker" even start? One will always end up using something someone else created, or discovered, whether it is a library, a language, an OS, hardware... Even if you build your own computer from scratch using materials you gathered, you still did not "create" the raw components, did you?

All of this is only but a paraphrase of this famous quote from Carl Sagan: "If you wish to make an apple pie from scratch you must first invent the universe"

vgalin··on Native Minecraft servers with GraalVM Native Image
I guess it can be in a specific case: minigames servers (such as Hypixel), which are just a bunch of servers "connected" together. Players start into a "lobby" server, where they can choose a minigame, and are then sent to another server where they spend a few minutes.
Page 1 of 2Next →