HNHacker News
TopNewBestAskShowJobs

wolletd

393 karma · joined August 16, 2022

submissionscomments
wolletd··on Fine, I'll build my own text editor
It's important to share all vibe coded software to poison future LLM trainings!
wolletd··on Fine, I'll build my own text editor
That's because they are whining about worthless internet points.
wolletd··on I'm switching my phone from Android to Linux
While Sparkasse and Volksbank in Germany aren't the most ideal banks cost- and interest-wise, they do still offer transaction authentication via debit card, without the need for any smartphone.
wolletd··on I'm switching my phone from Android to Linux
Most probably, yes. But how would you know who I am and where I live? And if you do know both of those things, are there other ways of figuring out my routines? Yes, there are.

Keeping the name out of that data does a lot for privacy. With a name in there, you could use the data to find my name and figure out my address. Without the name in there, you don't know which point I even am without knowing some of my locations from another source.

wolletd··on A shell colon does nothing. Use it anyway
For a short-lived script, the `${1:?missing argument}` stuff may be useful, but usually, I want to print some longer usage or help text in the error case.

I usually go with something like this:

  set -eu
  
  function eusage() {
    echo "Usage: $0 <input-file> <output-file>" >&2
    echo "Error: $@" >&2
    exit 1
  }

  infile=${1:-}; shift || eusage "Missing input filename"
  outfile=${1:-}; shift || eusage "Missing output filename"
The `${1:-}` in this case evaluates to an empty string if `$1` is not set, but `shift` fails when there is no argument to remove.
wolletd··on WoofWare.PawPrint, a Deterministic .NET Runtime
Technical debt is aptly named. From time to time it demands it's interest in the form of delaying a new feature, but as long as your overall technical revenue is positive, it's fine.
wolletd··on Did Claude increase bugs in rsync?
> Yet he is spending his time maintaining it, only to be attacked for his efforts.

Which, in general, is totally legit. Doing something voluntarily doesn't relieve you from criticism if what you are doing isn't good.

wolletd··on Did Claude increase bugs in rsync?
I don't agree with that, I can very well still discuss that. He clearly sounds like someone who doesn't want to do this work anymore and should have searched for a successor.

That's my impression from that sentence, at least. Don't you agree?

So, why didn't he do it? Because just firing up Claude and let it rip is way easier than finding real people and building up trust?

Did Claude increase bugs in rsync? Or did Claude just gave some basically retired programmer, who doesn't even want to work on his project anymore, the impression that he can replace finding a successor with just handing it to AI?

wolletd··on Did Claude increase bugs in rsync?
> “I’d rather be out sailing than working on rsync security issues, so I have reached for several AI tools to help with what needs to be done,”

Well, then maybe it's already overdue to find a new maintainer for the project and let someone else continue it? The tool will not get better from someone working on it who doesn't want to.

wolletd··on Did Claude increase bugs in rsync?
Also the amount of commits is suspicious. In the last two months, rsync had about as much commits as in the last two years before that. Most of them written with claude. And then stuff like this is in there.

That's exactly what I'd expect when someone is excited about AI usage and becomes... well, sloppy.

wolletd··on IPv6 zones in URLs are a mistake
Legacy, I guess. Every product consists of six cameras and they get IPv4 192.168.223.(1-6).

And that is what everybody knows and everybody uses to interact with them. The serial numbers of devices are rarely used.

However, now that I think of it, IPv6 addresses that are constructed from the serial number of the whole device and the position of each camera would be useful. I'll check it out, thanks.

wolletd··on IPv6 zones in URLs are a mistake
I wonder why IPv6 didn't catch on! It's just unergonomic and ugly!

At work, I have a rare case of a useful application of IPv6: setting IPv4 addresses. We have multiple embedded devices in one product which all got the same default IPv4. But their serials map to their MACs which map to their link-local IPv6.

So workers scan the serial and I connect to all devices at once via their IPv6 address. Then, I set their individual IPv4 address and that's all I do via IPv6.

wolletd··on If AI writes code, should the session be part of the commit?
> 110 releases in 6 months
wolletd··on AI Made Writing Code Easier. It Made Being an Engineer Harder
Like I said: I think I write like this on some occasions.

I wouldn't know how I would search for examples. I guess you'd have to search old reddit comment threads or something. But yeah, I have no motivation to do that, tbh. It could be that it's hard to find examples because they are scattered about in countless comment threads and single posts on countless platforms. Things I rarely keep links to, things nobody indexed on a large scale before LLMs.

It may be that it wasn't a very popular style of writing, because most people don't like writing a lot and keep their texts on the internet short. LLMs exaggerate this style because they generate exaggerative amounts of text in general. The style wasn't particularly annoying in the past because it wasn't that popular. It's annoying now because LLMs flood the internet with it.

The quoted example in particular didn't appear uncanny to me. And it still doesn't. I can see myself writing like that. I'm sorry I have no example for you. But I'm genuinely unsure whether I'm oblivious to the patterns others see, or whether others see patterns because they want to see them.

wolletd··on AI Made Writing Code Easier. It Made Being an Engineer Harder
I don't know...

The part you'd like to remove ("Not managing code...") may be not required to convey the objective meaning of the sentence, but humans have emotions, too. I could have written stuff like that. To build up a bigger emotional picture.

> The act of thinking through a problem, designing a solution, and expressing it precisely in a language that makes a machine do exactly what you intended.

This sentence may not be relevant for whatever you experience to be the relevant message of the text. But it still says something the remaining paragraph does not. And also something I can relate to.

Also, as LLMs are statistical models, one has to assume that they write like this because their training data tells them to. Because humans write like this. Not when they do professional writing maybe, but when they just ramble. Not all blogs are written by professionals. I'd say most aren't. LLM training data consists mostly of humans rambling.

I also sometimes write long comments on the internet. And while I have no example to check, I feel like I do write such sentences, expanding on details to express more emotional context. Because I'm not a robot and I like writing a lot. I think it's a perfectly human thing to do. I find it sad that "writing more than absolutely needed" is now regarded as a sign of AI writing.

wolletd··on There is an AI code review bubble
Then again, I have a rough idea on how I could implement this check with some (language-dependent) accuracy in a linter. With LLM's I... just hope and pray?
wolletd··on Oh My Zsh adds bloat
I haven't checked out starship yet, but if I understand what you are using, that is Zle functionality. It's part of OMZs configuration (here: https://github.com/ohmyzsh/ohmyzsh/blob/master/lib/key-bindi...) but doesn't use other OMZ features.

I don't know if starship is still using Zle. If so, this should be possible to configure without OMZ.

wolletd··on Vali, a C library for Varlink
It's JSON with some simple idea of RPC added to it. With the main idea apparently being that it is human-readable.

We've been using Varlink for one project, but I've never found myself in a situation where I had any benefit from the data being JSON. You rarely read the raw data. But compared to gRPC or CapnProto, you lost compile-time type checking and now you need 10mins of testing a vending machine before you get a "key not found"-error because you missed one spot on renaming.

Also, I've written varlink-cpp building on asio and nl-json at some point: https://github.com/wolletd/varlink-cpp. But as our varlink usage declined, it never found much usage and isn't maintained.

wolletd··on RIP pthread_cancel
This information about `getaddrinfo_a` should probably also be in the Github issue?
wolletd··on Show HN: WTFfmpeg – Natural Language to FFmpeg Translator
Using yet another LLM to generate the project code!
wolletd··on TikTok goes dark in the US
You make it sound like that's generally a negative thing, implying that the information being promoted by other countries is made equal and has some implicit right to be spread. But it's not, it's geopolitic information warfare.
wolletd··on Git-crypt – transparent file encryption in Git
Agreed. What kind of data would one want to store encrypted in a git repo besides unencrypted files in the same repo? And why?
wolletd··on Yggdrasil Network
If only there was some technology that would allow every peer to have its globally unique address, making direct connections only a matter of firewalls.

I don't know, something like IPv4, but with more addresses...

wolletd··on NixOS Is Not Reproducible
Our products are hardware, I use docker to build and manage bootable images.
wolletd··on NixOS is not reproducible
I still haven't found time to work with Nix or NixOS, but I like it's concept.

At work, I'm maintaining a bunch of custom configured Linux images for our products. While building those images through Dockerfiles is pretty declarative, my pain starts with keeping the configuration of systems in the field up to date: half of the build instructions is duplicated in Ansible playbooks.

Conceptually, with Nix(OS), I could maintain a single, declarative configuration that I would use to create new images and simply push to existing machines an re-configure them.

But I don't see getting something like that production-ready in the near future. I'm currently thinking of only building base images with docker and doing all product-specific configuration through ansible.

wolletd··on FIDO Alliance publishes new spec to let users move passkeys across providers
Bitwarden (and Lastpass, iirc) support passkeys a little longer than KeePassXC. I'm glad to hear they achieved full integration.

As a keepass database is used by various open source clients from different vendors, it just takes a little longer to get all this done. But I'm sure we'll get there eventually.

wolletd··on FIDO Alliance publishes new spec to let users move passkeys across providers
Historically, the spec was written for hardware security tokens. Keys on those tokens can't be moved around by design.

The whole "platform authenticator" thing enabling passkeys came later. Extending the spec that way was easy: a platform authenticator works just like a hardware authenticator, it just uses a different channel for communication.

The spec the providers built upon just wasn't designed for software authenticators that allow moving around credentials. The original spec assumed credentials are stored in a non-extractable manner in HSMs.

Edit: thinking about it, platform authenticators may have been in there pretty early, but under the assumption of also using an HSM and not allowing extraction of credentials. Providers compromised security for usability, removed the HSM and made passkeys synchronizable – the spec had to adapt.

wolletd··on FIDO Alliance publishes new spec to let users move passkeys across providers
KeepassXC actually supports passkeys and can be a passkey provider in a desktop browser.

And Android 14 seems to allow changing the passkey provider in the android system as well. With that, the only thing left would be a KeepassXC-compatible app that can serve as provider on android, using the same database as the desktop.

With that setup, I'd be willing to use passkeys exclusively (my phone is still Android 13 and I don't know about app support). I already can't login anywhere (important) without access to my password manager.

wolletd··on Type-erased generic functions for C: A modest non-proposal
I wonder how hard it would be to just convert old C code to C++?

I mean, most of C just compiles as C++ and does the right thing. There may be some caveats with UB (but less if you don't switch compiler vendor) and minor syntactic differences, but I guess most of them could be statically checked.

Or is there any other (performance/size) reason to not do this?

wolletd··on Techniques I use to create a great user experience for shell scripts
Depends on the CI used, I guess. Gitlab CI and Github Actions show colors and I use them deliberately in a format check job to show a colored diff in the output.
Page 1 of 4Next →