HN user

Scramblejams

3,420 karma

Former aerospace engineer, now game dev.

Favoriting does not imply endorsement.

Posts45
Comments902
View on HN
medium.com 6mo ago

Local Agent Safety Framework

Scramblejams
1pts0
github.com 6mo ago

Nanolang: A tiny experimental language designed to be targeted by coding LLMs

Scramblejams
232pts202
www.tomshardware.com 1y ago

Intel: New products must deliver 50% gross profit to get the green light

Scramblejams
8pts6
calmatters.org 1y ago

How the state sent Californians' personal health data to LinkedIn

Scramblejams
6pts0
frame.work 2y ago

Framework Laptop 13 with Intel Core Ultra Series 1 CPU

Scramblejams
7pts1
zenoh.io 2y ago

Performance Evaluation of Rust Asynchronous Frameworks (2022)

Scramblejams
44pts3
news.ycombinator.com 3y ago

HP Dev One has sold out. Support is still available

Scramblejams
3pts6
xeiaso.net 3y ago

Push notification two-factor auth considered harmful

Scramblejams
4pts0
www.freecodecamp.org 3y ago

I Stopped a Credit Card Thief and Saved Our Nonprofit

Scramblejams
40pts2
www.theatlantic.com 4y ago

Russia and the Curse of Geography (2015)

Scramblejams
4pts0
www.washingtonpost.com 4y ago

Despite the hype, iPhone security no match for NSO spyware (2021)

Scramblejams
289pts268
blog.crunchydata.com 4y ago

Devious SQL: Message Queuing Using Native PostgreSQL

Scramblejams
141pts38
www.washingtonpost.com 5y ago

Despite the hype, iPhone security no match for NSO spyware

Scramblejams
2pts1
www.bloomberg.com 5y ago

Supersonic Jet Dream Dies as Aerion Folds

Scramblejams
2pts0
m.nautil.us 7y ago

Is the Modern Mass Extinction Overrated?

Scramblejams
1pts0
www.ibm.com 8y ago

How an Accidental Discovery Led to a New, Highly Recyclable Plastic

Scramblejams
2pts0
www.cnbc.com 8y ago

1976 letter from Silicon Valley exec calls Steve Jobs 'flaky' and a 'joker'

Scramblejams
71pts63
www.howtogeek.com 8y ago

Hey Microsoft, Stop Installing Apps on My PC Without Asking

Scramblejams
393pts331
jtfmumm.com 10y ago

Safely Sharing Data: Reference Capabilities in Pony

Scramblejams
2pts0
www.washingtonpost.com 10y ago

Meet Dream Chaser: the spunky little space plane that could

Scramblejams
1pts0
prog21.dadgum.com 10y ago

The Same User Interface Mistakes Over and Over

Scramblejams
20pts2
prog21.dadgum.com 10y ago

The Right Thing?

Scramblejams
80pts18
prog21.dadgum.com 10y ago

Computer science courses that don't exist, but should

Scramblejams
415pts247
icube-icps.unistra.fr 11y ago

Modern C [pdf]

Scramblejams
28pts2
blog.oozou.com 11y ago

An intro to OTP in Elixir

Scramblejams
2pts0
gradha.github.io 11y ago

Goodbye Nim, and Good Luck

Scramblejams
51pts29
hackaday.com 11y ago

3D Printing RC Airplanes That Fly: An Engineer's Chronicle

Scramblejams
1pts0
medium.com 11y ago

ProgLang Design with Evidence

Scramblejams
1pts0
users.cecs.anu.edu.au 11y ago

Down for the Count? Getting Reference Counting Back in the Ring [pdf]

Scramblejams
3pts0
www.businessweek.com 11y ago

Has Oculus Finally Conquered the Virtual-Reality Vomit Problem?

Scramblejams
2pts3

I doubt that very much. 20ish years ago I read about the Indians being very upset that the engines in the Sukhoi fighters they bought weren't even making it to the promised (very modest) 300 operating hours between overhauls. That's far less than Western engines routinely achieve. And with the hollowing out of the Russian industrial base that's occurred since then, I'd be surprised if it's gotten any better in the intervening years.

Maybe more than a headwind. From my time in AAA here are two things I learned that were true in that environment:

1. Artists hate Perforce.

2. You will never get them to try anything else.

I'm exaggerating, but not by that much. I lost count of the number of artists who are deeply uncomfortable with technology and just manage to learn the bare minimum to do their job, and then will take no more.

So besides everything else Lore needs to nail to be acceptable, they need to make it easy for artists to switch. Maybe when UnrealGameSync grows enough knobs and switches to make it unnecessary for an artist to ever touch P4V, Epic can roll Lore into UGS as an unobtrusive option. And if by then there's good support in Unity, in JetBrains, in Maya, etc., then maybe they'll have something.

I'd love to see this in the bootloader, along with a selection of binaries useful for recovery. Might sound silly but over the years I have had many a remote system get to the bootloader and then no further after an upgrade. Nowadays we've usually got a nicely sized EFI partition, why not stuff it all in there? Gimme a full Linux userspace from the bootloader, it would feel luxurious when I'm up at 3 am trying to recover a broken system halfway across the country.

Or is there already a solution to this that I've been missing? (Yeah, KVM/IPMI/etc, I know, but not all hosters make it easy to get to that.)

You're right, packaging would definitely be a challenge. The cylinder head would need to be low profile, conformal exhaust headers, dry sumped, and put all the plumbing you can (including the turbo and wastegate) behind the block. Maybe it’s not feasible, but it sure would be an interesting puzzle to try!

The peeps I've talked to who've done LS swaps seemed more interested in the economic, technological, and fuel economy leaps made versus the certified air-cooled default choices rather than the power, but YMMV...

Upsides are that they're both first- and second-order naturally balanced, requiring no balance shafts, which reduces weight and makes them very low vibration. I keep waiting for someone to come up with a lightweight, turbonormalized straight six that runs on Jet A to replace old turboprop engines on aircraft, but I digress...

Hand on sales: Don't expect customers to sign up for a free plan and convert. Your conversion rate will be close to 0. Mostly scammers.

Brutal! Is that true even for Japanese companies with a traditional sales force?

In other disciplines, yes. Very common to hear it in mechanical or aerospace engineering, for example. They'll say "codes" to refer to multiple programs or "a code" to refer to a single program. It's amusing, when I was in the field I just went with it.

Wayland Nvidia 8 months ago

That’s awesome! But not everyone’s library is the same, so YMMV. I regularly see problems with flight sims that are Nvidia-specific, for example.

Wayland Nvidia 8 months ago

Many of the replies completely missed the part about Nvidia, sigh.

I unfortunately still see a lot of Proton bug reports that don’t repro on AMD cards. Hoping that improves soon, I’m sure Valve would love to tell hardware makers that Nvidia GPUs are supported.

It can be helpful to look at it less in terms of what it costs Valve to run their service and more in terms of what value developers get from Valve for the money.

I'm in the business and I've asked two different heads of large, very well-known AAA studios how they felt about Valve's percentage, and they basically told me the same thing: They had their teams do rigorous analyses of what it would cost them to 'replace' Valve for their games, and concluded it would cost roughly what they were already paying Valve. So they had no incentive to move off the platform. Look at how many publishers have come slinking back to Steam after trying to go solo -- there are good business reasons for that, and it isn't just about the stubborn fact of their huge social graph.

If it costs that much to replace Valve for your game, it's hard to argue that what they're charging isn't fair.

As others have pointed out, Valve does far more than just host. Shipping a multiplayer game and want comprehensive protection from DDoS attacks? Use Valve's datagram network for no additional fee. Don't want to host your own lobby servers? Use Valve's for no additional fee, they'll accommodate hundreds of thousands of players with no complaints. Want to sell your game in a zillion countries? Valve's got you, easy peasy. And discovery is a thing -- Valve sells a whooole lot of games just by putting them in the carousel in front of players. This is huge, huge value.

And as a player, I'm actually really happy, super happy, did I mention how incredibly happy I am with what they're doing with some of their cut: They saved gaming on Linux -- it's often better than Windows -- and I love my SteamDeck. So that cut is benefiting me directly as a consumer because they're spending it on initiatives I'm really passionate about.

Valve delivers a ton of value for the cost. If someone wants to try to do better, Valve's not stopping them, but I can tell you that as a player and a gamedev, none of the other options are remotely enticing to me. In my view, that's not Valve's problem to solve by cratering their own revenue.

ML on Apple ][+ 10 months ago

Same. What flavor of ML would be the most appropriate for that challenge, do you think?

Long-time Navy jet jock finds it "cringe" when people try to get a little break from the stresses of their life by attempting in a very small way to emulate what he achieved.

I get your point but come on man, ease up. At least remember that some of those DCS-playing wage slaves helped fund your adventures.

I did apologize, didn't I? :-)

Perspective is everything, I guess. You look at that three year old comment and think it's not particularly informative. I look at that comment and see an experienced infosec pro at Fly.io, who runs billions of container workloads and doesn't trust the cgroups+namespaces security boundary enough so goes to the trouble of running Firecracker instead. (There are other reasons they landed there, but the security angle's part of it.)

Anyway if you want some links, here are a few. If you want more, I'm sure you can find 'em.

CVE-2022-0492: https://unit42.paloaltonetworks.com/cve-2022-0492-cgroups

CVE-2022-0847: https://www.datadoghq.com/blog/engineering/dirty-pipe-contai...

CVE-2023-2640: https://www.crowdstrike.com/en-us/blog/crowdstrike-discovers...

CVE-2024-21626: https://nvd.nist.gov/vuln/detail/cve-2024-21626

Some are covered off by good container deployment hygiene and reducing privilege, but from my POV it looks like the container devs are plugging their fingers in a barrel that keeps springing new leaks.

(To be fair, modern Docker's a lot better than it used to be. If you run your container unprivileged and don't give it extra capabilities and don't change syscall filters or MAC policies, you've closed off quite a bit of the attack surface, though far from all of it.)

But keep in mind that shared-kernel containers are only as secure as the kernel, and today's secure kernel syscall can turn insecure tomorrow as the kernel evolves. There are other solutions to that (look into gVisor and ask yourself why Google went to the trouble to make it -- and the answer is not "because Docker's security mechanisms are good enough"), but if you want peace of mind I believe it's better to sidestep the whole issue by using a hypervisor that's smaller and much more auditable than a whole Linux kernel shared across many containers.

Apologies for repeating myself all over this part of the thread, but the vulnerabilities here are something that Podman and Docker can't really do anything about as long as they're sharing a kernel between containers.

The vulnerability is in kernel syscalls. More info here: https://news.ycombinator.com/item?id=32319067

If you're going to make containers hard to escape, you have to host them under a hypervisor that keeps them apart. Firecracker was invented for this. If Docker could be made unescapable on its own, AWS wouldn't need to run their container workloads under Firecracker.

Raspberry Pi 500+ 10 months ago

I did not!* Through many Pis serving many years and experiencing many power outages.

But I'm using CanaKit power supplies (which supply 5.1 volts, Rpis are notoriously flaky if the voltage dips just a little below 5v) and ATP industrial automotive-grade flash cards (not a big premium in absolute terms, I think 32 gig cards are $13 on Digikey).

* Okay okay, before I switched to those accessories I did have problems.

Better not rely on unprivileged containers to save you. The problem is:

Breaking out of a VM requires a hypervisor vulnerability, which are rare.

Breaking out of a shared-kernel container requires a kernel syscall vulnerability, which are common. The syscall attack surface is huge, and much of it is exploitable even by unprivileged processes.

I posted this thread elsewhere here, but for more info: https://news.ycombinator.com/item?id=32319067