HNHacker News
TopNewBestAskShowJobs

x0x0

9,803 karma · joined May 29, 2013

submissionscomments
x0x0··on Photopea creator weighs in on Photosuite project
Also, he started by lying. He/she went from

> That's a bold accusation. Would you care proving which bits of the code are "stolen"?

https://github.com/eolix/photosuite/issues/77#issuecomment-5...

to banning photopea, to when photopea responds with a 2nd account re: some duplicate code which is very hard to explain w/o being, well, duplicated to what you pasted above.

x0x0··on Apple and a hacker's future
> Way to go, application developers.

I really dislike this point of view.

1 - we're all going to suffer because meta are scum. It's not "all application developers", it's "exactly who you assumed it would be", and also too, "exactly the same scum who've spent the last 10 years working around privacy controls any possible way they can and deliberately obfuscating the choices people make around their privacy." The people who made pervert glasses and did covert web-to-app tracking by opening local ports [1] and bought sketchy spyware to track everything you did and scurried away from the light the second someone asked about it [2], [3]. And on and on and on.

Spotify has long asked for it and... they use it to copy my local mp3s onto my phone so I can listen to them away from my computer. It's awesome.

This doesn't mean that Apple isn't champing at the bit to use Meta as an excuse to screw all software developers. If Apple cared about their users, they'd do something like revoke Meta's software keys and leave responsible developers alone. Alas, Apple will obviously exploit this too :(

[1] https://localmess.github.io/

[2] https://en.wikipedia.org/wiki/Onavo

[3] https://uk.practicallaw.thomsonreuters.com/w-040-4130?transi...

x0x0··on Reddit is putting more limits on old.reddit.com
this is some smarmy shit:

> we'll stop supporting RSS feeds on November 13, 2026

3 sentences later:

> RSS has been a beloved part of the open web for a long time, and we’re grateful to everyone who used it to stay connected to Reddit.

https://old.reddit.com/r/modnews/comments/1wubgvt/

x0x0··on Seattle Bans Rental Junk Fees
Well, there are plenty of lies. Because tenants are liable for the supposed damages regardless of whether landlords can grab $100/mo or whatever.

That's not to say that pets can cause tons of damage: if someone let's a cat spray inside and doesn't immediately clean it, that can cost tens of thousands if it seeps down to the underlayment. But (1) that ain't getting covered by the $50 - $100 they want to gouge people for; and (2) tenants are liable for that either way.

x0x0··on Mullenweg has returned as CEO after attempted board ouster
Holy shit. You are, if anything, underselling the article.

> When TechCrunch asked Mullenweg if his comments about being back as CEO were legitimate, he promised a blog post was coming. When it arrived, however, it was about him buying a houseboat. When we asked if his comments about being back were also him trolling, he replied, “I’m not a troll I’m a pirate, obviously.” Mullenweg never provided any official comment about his return, but noted on X that this was likely the fifth time he’s faced a “coup.”

And like all well-run companies, it's not clear who the ceo is.

x0x0··on I've operated petabyte-scale ClickHouse clusters for 5 years
It's multiple records per user over time. See something like posthog. One interaction with a form can generate 10-15 events. eg enter page, click link with text "settings", change input, clicked input, etc. So active users can generate 15-150 events per session, each ~1kb to 2kb in size.

The reason to store that data is to be able to build analytics and funnels you didn't anticipate and construct them retrospectively. You can of course save massive amounts of storage by building rollups and aggregating, but that prevents you from being able to eg change the funnels and see the funnel in the past.

10M users × 100 events/day × 1KB ≈ 1TB/day. A couple years gets you into PB range.

The other obvious thing is logs. Being able to have a vulnerability then go back in time and see if you were exploited is super valuable. See eg log4shell: if you kept records, you probably could go back and see if you'd been exploited.

x0x0··on I spent $220 on Google app ads and 60% of the installs were robots
That's it. The scammers display ads. Two scams: one is mostly or entirely artificial traffic; a second is eg low quality ad slots disguised as higher quality. For the latter, think ads in videos shown off screen with programmatic interaction to make it appear as if the legit traffic saw and interacted with the ads.
x0x0··on I haven't lost a customer service fight in seven months
An American who interacts with health insurance can easily do that. Insurers will literally try not to pay just because some percentage of people give up.

I went to the dentist recently. They wanted to do a "deep cleaning". cost: somewhere between $0 (covered) and $5k (fully out of pocket). I asked the obvious: that's one hell of a range. "Depends on how much the insurer will pay." They weren't happy when I demanded to know that number before committing, as it takes them hours on the phone.

x0x0··on South African diamond mines are closing due to weak sales and lab-grown stones
there goes their veblen goods...
x0x0··on Google Antigravity TOS: 3rd party usage can get Google account suspended
I'm aware. Like I said, you're foolish to trust google. That said, the claim in the reddit post: that the ban spread across the entire gsuite account and also any account that used that device, is far more aggressive.
x0x0··on Google Antigravity TOS: 3rd party usage can get Google account suspended
fwiw, google said that didn't happen.

https://www.androidauthority.com/google-account-bans-3654171...

Not taking a side, but I remember that too and had looked later.

That said, I deliberately don't trust any google services. Fastmail is great; you all should try it. Google capriciously bans accounts, so keep your email elsewhere.

x0x0··on Saving money on Google Photos with Immich: Your own personal photo storage
Google sells 100 gi for $2/mo. So it's a lot more than 2g.
x0x0··on Trade (and Tariffs)
And for aluminum in particular, the US is essentially importing dirt-cheap hydro energy.
x0x0··on How Europe is killing makers and micro-entrepreneurs
Yeah, a $800k property paying 0.2% or $1600/year is... seems low for the provision of roads, schools, firefighters, etc.
x0x0··on How Europe is killing makers and micro-entrepreneurs
You won't get any disagreement from me.
x0x0··on How Europe is killing makers and micro-entrepreneurs
Spain charges you tax if you rent the property out. If you don't rent the property out, it imputes a rent and you are charged tax on the imputed rent.

The cadastral value is (finger in the air) 40% of the value of the property; you pay (non-eu resident) 24% of between 1.1% and 2% of the cadastral value.

So 0.1%-0.2% of property value annually.

x0x0··on Where did all the public bathrooms go?
A friend owns pizza restaurants. They leapt at the opportunity during covid to shut their bathrooms to the public, and have continued to (illegally) keep the bathrooms closed as much as possible.

People made horrific messes in them. Employees and/or owners had to clean them. They don't wish to do so. Public messes; private employees and/or owners being made to clean them is pretty much the story.

x0x0··on Harvest hikes bills by 1500% after purchased by Bending Spoons
Airtable and Harvest weren't failing. They just weren't as profitable as hoped, and appear to have eaten most of their TAM and were wasting the engineering dollars being spent building features to increase the TAM.

Bending Spoons business model is less buying failing businesses and more buying runouts; ending ongoing investment in them / shifting to maintenance; and and hiking prices to grab as much cash as possible. It's Broadcom's business model (see vmware) just pointed at b2c or software in the smb not enterprise category.

x0x0··on I requested a copy of my data from McDonald’s loyalty program
Or not just sell. Random state governments may be able to rifle through it.
x0x0··on I requested a copy of my data from McDonald’s loyalty program
> What is the actual concern with McDonalds having this data about you? That they will charge you more if they know you will come back anyway?

While McDonalds is somewhat benign, most people simply don't understand that this data can be (technically at least, legally is a different question) permanently stored. See the surprise in the article that it is now easy to store every app open. Almost certainly with associated location data. So McDonalds selling/sharing that is a concern, particularly with the extraordinarily lax US approach to data privacy. Data like that cleanly bound to true identity is very unhealthy. McDonalds is highly likely syncing that into facebook as well, which is generally done both via email and phone.

And if McDonalds is doing this, imagine what more natively sensitive apps/websites are storing about you. Medical sites, period / pregnancy trackers (particularly in light of the US bans on medical treatment of pregnant or possibly pregnant women), a whole host of health-related information; political opinions, etc.

x0x0··on HTML over WebSockets: real-time SPAs with barely any JavaScript
Yeah, there definitely is a library here. It is a small library: ~5 klocs. In part because it just does (a lot less) than React and leans more on working with the browser instead of a shadow dom, etc.

The downside is it does less than react. You will mostly have to keep the reactivity dependency tree in your head. Huge win for most b2b apps; A+ for internal admin pages; solid A for config pages in almost all apps; not a great fit for (parts of) highly reactive b2c apps.

x0x0··on HTML over WebSockets: real-time SPAs with barely any JavaScript
no api. The way it works is thus (rails, because it's what I regularly use):

The system is called Turbo. A turbo_frame is just a custom html element. You can largely use it instead of a div.

Turbo's js watches for navigation events (link clicks, form submits) that originate inside one of these elements, and instead of letting the browser do a full navigation, it:

1 - makes the request itself, against the usual rails routes. It uses your normal routing, sessions, cookies, etc.

2 - Intercepts the html response and looks for a <turbo-frame id="..."> that matches the id of the frame that triggered the request

3 - Swaps just that element's contents into the page.

more concretely: suppose I have a list of people in a flex table. I wrap the people table in a turbo_frame so I can prepend to it, and wrap each person in a turbo_frame so I can update it. My page can look as so:

    turbo_frame "people", class: "person-table flex flex-row" <-- the overall list
      turbo_frame person_1, class: "person-row flex flex-col"
        the row for person 1
      turbo_frame person_17, class: "person-row flex flex-col"
        the row for person 17
      turbo_frame person_12345, class: "person-row flex flex-col"
        the row for person 12345
etc.

If the user edits a form for person 12345, that is wrapped in turbo_frame person_12345.

The browser makes the request itself, grabs the response, pulls out the contents of turbo_frame person_12345 (and NB: the response can be a whole page or just this fragment), then swaps that in for the existing person_12345.

It's designed so you can make your normal MPA with page navigations and reloads for editing a table row or whatever, make a small set of updates to the html, and have this work almost entirely for free. It sounds too good to be true but I've been using it for years and it often really is that easy.

edit: for server-initiated updates, I can broadcast to select listeners:

1 - replace a turbo_frame (person_12345 was updated externally, and I want to just swap out) 2 - prepend (eg for a css table, put my new person_12345 row in front of other rows; 3 - append (same, but at bottom)

x0x0··on HTML over WebSockets: real-time SPAs with barely any JavaScript
Responsive site built via server-side render, with a particular benefit for partial page updates. 90% of the benefit of an SPA but 10% of the code: no api, no moving of system of record for state back and forth between database and browser (it's always db), etc. And you can avoid react.

A common use case: eg in Rails, a user has a table open. you can stream new records to the top of that table as they are created in ~5 lines of ruby (a broadcast on the model, and put the table rows in a turbo_frame with a turbo_stream_from somewhere on the page).

There are real limits to this -- you have to hold the update dependency graph in your head -- but the benefits are huge for small to medium amounts of responsiveness.

My experience has been great with Rails/Turbo and htmx.

x0x0··on Tracking down the 16-year-old WAL-reset SQLite bug
It's common for databases.

This is Percona's business model. They employ core pg/mysql developers and you can buy a support package from them. Same for enterprisedb. Pretty reasonably priced packages (like maybe $10k-ish/core IIRC) get you 24x7 support. I've only had to escalate issues once but inside 10 hours we got a pg core committer to debug some very strange vacuum behavior.

x0x0··on Microsoft raises Xbox prices by up to 43%
I don't think it's played; it's that idiots brought low-margin businesses into a high-margin enterprise b2b saas company (that exploits a monopoly too) and are shocked that gaming is not going to give you 30% or higher margins. Nintendo is super disciplined and a bad year for Microsoft margin-wise is one of Nintendo's best. If Nintendo can't regularly hit 30% margins, nobody can, and certainly (as you say) people who don't game and don't know a single thing about gaming except speedrunning a tutorial aren't going to do that.
x0x0··on Turn And Face The Strange
Well, I do interpret this is step one towards a forthcoming post titled "Our Incredible Journey [with Fly Machines]"...

Whether that comes to pass depends on sprite uptake and so forth, but I believe it to be a lot more likely than I did a month ago. So, like I said, bummed, because fly is genuinely nice and I dislike using aws.

x0x0··on Turn And Face The Strange
sucks: fly backburnering the app platform to build sprites.

> [...] Sprites, and focusing the company on [Sprites] and the problem they solve.

Then later

> first path [the thing I like/advocate/use] and [Sprites] ... We do one thing or the other. We don’t limp in on both. And if we fail, we fail with our full asses.

Hard to interpret that as anything but the thing I like being backburnered. Which is how it goes, but sucks.

x0x0··on Turn And Face The Strange
This really sucks. I not only like fly a lot, I have two production apps; thousands in annual creds up for renewal soon; and some mildly embarrassing discussions about migrations to have.
x0x0··on The Sunscreen Result No One Wants to Talk About
Randomized Control Trial
x0x0··on Identity verification on Claude
I had immense trouble buying api quota as a startup with a brex card and a C corp.
Page 1 of 34Next →