HNHacker News
TopNewBestAskShowJobs

witrak

45 karma · joined September 11, 2019

submissionscomments
witrak··on Gorhill pulls uBlock Origin Lite from Firefox store
>uBOL is not an important extension on Firefox.

Perhaps you should read some earlier comments then you wouldn't say such things?

Hints: Firefox mobile; range of privileges required.

witrak··on Gorhill pulls uBlock Origin Lite from Firefox store
It may be true, but your point of view isn't the sole possible. Many people have to use more than one browser and for them, the Google decision (effectively forcing the creation of uBOL) was really painful so Hill's new product is of big value. Also, there are people who don't know anything about uBO since they never used Firefox but they probably will start to use uBOL as other blockers for Chromium-based browsers are incomparable to it. Thus 5k downloads of uBOL are no measure of its importance.
witrak··on The "email is authentication" pattern
>Self-hosting inbound email is trivial. Anybody will send email to any random domain, they're just not willing to accept it from random sources.

That is simply not true. I have self-hosted email service and starting about 1.5 yr ago some big email services don't deliver emails to my server anymore. And there are many similar cases reported...

So one can say that even if an independent email service is willing to accept email traffic from any sender it does not guarantee that customers of all other services can have delivered their emails to addresses at the service.

witrak··on Zen, a Arc-like open-source browser based on the Firefox engine
>76 ideas which were submitted are currently in development and 84 have been delivered.

So what? Does it invalidate the critics of glacial speed of making other improvements?

witrak··on The Harmless Pi-Hole Bug
>I look forward to your explanation of how the temperature of Bob's Raspberry Pi poses a threat to his employer.

Hmm, anything like this can be used as part of side channel if an attacker is able to influence the temperature of Bob's RPi.

witrak··on Alcohol Researcher Says Alcohol-Industry Lobbyists Are Attacking His Work
Would you admit - just for the sake of more balanced arguments - that there's another possible reason for the exclusion of the majority of studies? Like visible bias towards "alcohol in reasonable amounts {is | may be} {good | not making harm} for health" opinion?
witrak··on Tests for consciousness in humans and beyond
Relation between consciousness and intelligence seems to be a problem for everyone including the authors of the article.

Hmm... Peter Watts, Blindsight.

The novel explores themes of identity, consciousness, free will, artificial intelligence, neurology, and game theory as well as evolution and biology. [Wikipedia]

Especially interesting, and contains a long list of literature.

witrak··on First new VAX in 30 years? (2021)
>They were all the size of washing machines.

More like a cube - all dimensions equal. And it was because they should fit into an American submarine hatch. After all, they were used there...

witrak··on Text editing on mobile: the invisible problem
Seems to be quite an improvement. Thank you for the tip! But it would be even better if it had "stylus mode" because, with a precision stylus, it's easier to tap directly alternate characters than to drag from the center of the button toward the needed variant.
witrak··on Chrome extensions can steal passwords from websites
The problem is that far too often extensions' authors require unnecessary privileges under excuses of need for improvements (usually of doubtful value). And users are used to accepting it...
witrak··on Regex Isn't Hard
Unfortunately, the suggestions related to characters representing elements of regular expressions are completely wrong when you consider the non-ASCII text. Thus except for program text containing string literals and comments in pure English the use of regex isn't so simple, especially without a dot symbol.

So in general I would classify the article into the "marketing text" category: not completely false but not telling the truth ;-)

witrak··on CWE Top Most Dangerous Software Weaknesses
>Those things are stopped by other tools, such as query builders and web frameworks.

No. All tools can be used with an improper attitude which leads to the creation of weak points.

The proper way is to have a deep understanding of the role of design rules.

A programmer who does not pay attention to design (very basic principles of the design process) can create a good game, and even if this game contains weaknesses the risk related isn't a reason to not use it. The same programmer when creating critical infrastructure software is a source of potential nightmare.

Unfortunately, software business accepts such specialists for projects both of kinds. Why? Who knows? Perhaps because of legal regulations? Why when an engineer designs a car they don't try to "Move fast and break things"?

witrak··on Alien Artefacts
No, it was at my university computer center. I wanted to improve the Executive program, the simplest operating system for the computer they had. So we took a binary dump of it... :)
witrak··on Alien Artefacts
I remember such a piece of code, perhaps the shortest ever created! It was 4 instructions in the machine language of ancient British ICL1900 computers. I - together with my colleague - spent some hours to understand it - firstly, what it does and then how and why it works! The problem was that ICL1900 had a rather obscure method of storing 6-bit characters in its 24-bit words (yes, bytes were unknown in ICL computers). To copy character strings indexing was used but character position was stored on the first two bites of the index word while the word address offset on the right part of the index. Since memory was extremely valuable, the rest part of the index word was used for the counter. Thus fetch and store instructions were working such that after a character was accessed counter was decremented and 1 was added to the 2-bit character position subregister with overflow used to increment address offset every 4th character. Very clever solution because the string copying loop was very tight! The 4 instruction sequence we tried to interpret turned out to be a macro modifying character index register backward allowing to use of an almost identical loop for copying a string starting from its end... It was using arithmetic overflow in a way we had trouble understanding and we hadn't access to hardware :-)
witrak··on Alien Artefacts
I remember such a piece of code, perhaps the shortest ever created! It was 4 instructions in the machine language of ancient British ICL1900 computers. I - together with my colleague - spent some hours to understand it - firstly, what it does and then how and why it works! The problem was that ICL1900 had a rather obscure method of storing 6-bit characters in its 24-bit words (yes, bytes were unknown in ICL computers). To copy character strings indexing was used but character position was stored on the first two bites of the index word while the word address offset on the right part of the index. Since memory was extremely valuable, the rest part of the index was used for the counter. Thus fetch and store instructions were working such that after a character was accessed counter was decremented and 1 was added to the 2-bit character position subregister with overflow used to increment address offset every 4th character. Very clever solution because the string copying loop was very tight! The 4 instruction sequence we tried to interpret was a macro modifying character index register backward allowing to use of an almost identical loop for copying a string starting from its end... It was using arithmetic overflow in a way we weren't able to understand, and we hadn't access to hardware :-)
witrak··on A number system invented by Inuit schoolchildren
Sorry, but I don't understand the basis for the opinion presented by a couple of people that the Kaktovik numeral system is similar to the Roman one. Is that because both of them use short lines as the sole element to build digits/numbers?!

But Kaktovik is a positional system while Roman is not!

witrak··on A Number System Invented by Inuit Schoolchildren
Earlier thread https://news.ycombinator.com/item?id=35523948
witrak··on Who invented vector clocks?
> [...] for most topics I think many would rather see no article than a crap one.

I'm sure that many people would support just the opposite. And in the case of Wikipedia, it is even more probable: the first person who finds the weak points in an article can (and often does) add comments (or - nowadays - opinions on the discussion page), which usually instigate discussion and corrections.

Of course, in the case of scientific articles, the practices are different, and your statement holds. However, IMO Wikipedia only struggles to get as close as possible to the role of a real encyclopedia, and definitely isn't (and won't be) Asimov's Encyclopedia Galactica.

witrak··on Ask HN: Science Fiction books that predict where ChatGPT might lead us?
Perhaps not exactly what OP expects but AFAIK the oldest book directly dealing with the subject. https://en.m.wikipedia.org/wiki/Golem_XIV
witrak··on Rosenpass – formally verified post-quantum WireGuard
So any claim such as your previous one is rather of no value.

>It does help make it much less likely.

Yeah... To the same extent as the infamous proof of formal correctness of an example program published in a book, until the program was tested negatively by a student some months later.

witrak··on By way of introduction – EWD 1041 (1989)
Interesting that in these all comments, nobody referred to the (un)reality of the creation of proofs. The fact that the proof has to be longer than a program - ignored completely 40 years ago - undermines the generality of the "purely scientific" approach marketed by Dijkstra. While his critics of software business are fundamentally sound - today even more than in the '80s - his idealistic view of programming as scientific activity and negation of the importance of (to not say contempt to) software engineering weakens his message even if we keep in mind the creation date of his philippic.
witrak··on Tech only has one strategy: Embrace, Extend, Extinguish
>Google has more of a history of this, but even there it’s not core to their strategy—they might be harming SMTP but they’re not going to kill it[...]

Well, did you have an email server for your family, friends, and your small business? And someday your friend or customer using it reported that there's no incoming mail from Google nor their email to Gmail addresses aren't delivered. You check the reason and see that for Google - "because they fight spam" - your IP address seems to have a reputation not good enough for accepting email from your server. No discussion, no reason revealed, no way to appeal, no human on the other side, and nothing can be done. Of course, you can outsource mail delivery to one of the big email operators - big enough that Google doesn't try to block them even if they allow for spamming.

This way the very idea of email as a common, freely available service is strangled step by step for years.

witrak··on NRC Certifies First U.S. Small Modular Reactor Design
https://caseyhandmer.wordpress.com/2022/07/22/we're-going-to...
witrak··on Firefox Translations: Translate websites in your browser without using the cloud
>It just don't understand how they stared from "Protect your privacy from sites like translate.google.com by using this add-on to translate webpages locally!" and ended up at "Let's make firefox users connect to Google's servers every time they use this feature!" If you're creating a product designed for people concerned about their privacy, it should beyond obvious that making your users send data to Google is a problem.

Don't you think that except for the PII data which shouldn't be used for training at all those (training) datasets can be stored at any place and it does not make a difference from the privacy point of view? Or I wrongly interpret their purpose...

witrak··on No Privacy in the Electronics Repair Industry
>[...] keep in mind that these computers did have malware on them: the spyware the researchers planted there! As a former repair tech, if I’d seen some thing writing screenshots and activity logs to disk (we would use, among other things, sysinternals tools like procmon to look for malware) I would definitely be deleting that.

I don't think that you as repair tech are entitled to manipulate any software installed by the owner. Even if your order covers malware removal and you see such activity and you suspect that it isn't installed by the customer you should contact them first, simply because such software isn't malware by definition (only in case it is installed against owner's/user's will).

witrak··on Open Source and Saying “No”
Perhaps other people may have another opinion but I'm afraid that most people seeing 200 issues think that the product is in the phase of intensive development so is not mature (what can be true) or that its development is stale (what also can be true). Their first thought isn't "it's a mature but still well-maintained product"...
witrak··on PayPal Allows Bypassing Two-Factor Authentication with a Button Click
Strangely, half of the discussion concentrates on the arguments for and against the alleged (in)security of the PayPal solution in general cases while obviously the solution quality can be decided in a specific context. At the same time nearly nobody addressed the real source of PayPal's stupidity: the fact the "feature" can't be permanently disabled.
witrak··on Show HN: Google hijacking search from GitHub, Twitter, others
>I use Firefox. However I can't help but chuckle at how they introduced it. Some people at Mozilla live on a different planet.

Exactly. Next example: 2 weeks ago they introduced a new version of the internal pdf viewer and set it as default (that I accept - it's their application). However, when you set FF as the default browser in Windows they make the browser a default pdf application too (see Release Notes 106.0).

witrak··on Privacy respecting weather app for Android
Would you be so kind as to say what you mean by "foreign" in this context? I'm asking because I was sure that .com, .org, and .edu are international domains...
witrak··on What it means to see a 'bad' certificate in TLS Certificate Transparency logs
"The net result is that CT gives us visibility into all web certificates [...]" including not always the desirable effect of publishing information on hosts in the non-public part of the institution network...
← PreviousPage 2 of 4Next →