HN user

TheBrokenRail

744 karma
Posts21
Comments85
View on HN
thebrokenrail.com 1y ago

After nine years, Ninja has merged support for the GNU Make jobserver

TheBrokenRail
2pts0
thebrokenrail.com 1y ago

The challenge of updating InsydeH2O UEFI with Linux

TheBrokenRail
3pts1
thebrokenrail.com 2y ago

A tale of Debian, Mesa, and ancient OpenGL

TheBrokenRail
3pts0
devblogs.microsoft.com 2y ago

An amusing story about a practical use of the null garbage collector

TheBrokenRail
3pts1
github.com 2y ago

Gitea Hosted Gitea

TheBrokenRail
2pts0
rmirabelle.medium.com 2y ago

There Is No Material Design Spinner for Android

TheBrokenRail
2pts0
github.com 3y ago

For #19918: Add option to hide the toolbar home button (Firefox For Android)

TheBrokenRail
1pts0
wiki.archiveteam.org 3y ago

Robots.txt

TheBrokenRail
4pts0
meta.miraheze.org 3y ago

Miraheze (a wiki hosting platform) is shutting down

TheBrokenRail
4pts1
developer.arm.com 3y ago

ARM's OpenGL ES Emulator

TheBrokenRail
1pts0
github.com 3y ago

Break rust Easter Egg Merged Into gccrs

TheBrokenRail
2pts0
www.eelis.net 3y ago

C++ Multi-Dimensional Analog Literals

TheBrokenRail
2pts1
thebrokenrail.com 3y ago

Xfinity Stream on Linux: A Tale of Widevine, ChromeOS, and a patched Glibc

TheBrokenRail
144pts71
aeon.co 3y ago

Is Are we kidding ourselves that anything is original? [video]

TheBrokenRail
1pts2
www.youtube.com 3y ago

Humans Need Not Apply (2014)

TheBrokenRail
3pts0
github.com 3y ago

GitHub's New Code Search and Code View (Beta)

TheBrokenRail
2pts0
blog.gitea.io 3y ago

Open source sustainment and the future of Gitea

TheBrokenRail
157pts182
gist.github.com 3y ago

A script to allow installing unsigned extensions on Firefox

TheBrokenRail
63pts28
letsencrypt.org 3y ago

Let's Encrypt’s subscriber agreement changes on Sept 21

TheBrokenRail
86pts46
thephd.dev 4y ago

#embed – a scannable, tooling-friendly binary resource inclusion mechanism

TheBrokenRail
1pts0
transparencyreport.google.com 4y ago

Google's Certificate Transparency Search page to be discontinued May 15th, 2022

TheBrokenRail
79pts42

Forgejo in particular has self-hosted actions runners that can be registered offline, and the runners themselves can be given labels and execute most existing GitHub actions (in fact, the yaml format they use is intentionally meant to be compatible with GitHub actions).

This is also part of Gitea. Which makes since because Forgejo is a soft-fork of Gitea.

I hate these 2FA mandates. I don't use PyPI, but I do use GitHub, which has also announced a 2FA mandate.

I use my GitHub account to make bug reports, small pull requests, and silly personal projects. It is not that important. I want to sacrifice security for convenience on it, and that should be my choice.

I also do not agree with the argument this secures the supply chain because:

1. It ignores supply-chain attacks from people who already have repository access.

2. Most big companies (ie. Google) are probably already using 2FA.

3. And if people are automatically pulling code from random people/groups without checking it... maybe that's what actually needs to be banned.

On the topic of user freedom, Firefox also doesn't allow installing extensions not signed by Mozilla unless you use a fork, Nightly, or Developer Edition (which is just a badly named beta)[0]. The hilarious thing is that Safari, the web browser from the company infamous for walled gardens and not letting you control your device, does let you install unsigned extensions on desktop[1].

[0] https://wiki.mozilla.org/Add-ons/Extension_Signing

[1] https://developer.apple.com/documentation/safariservices/saf...

Firefox doesn't allow users to install unsigned extensions unless they use a beta version, because users apparently can't be trusted to install software. I trust Mozilla to fight for privacy (they're great at it), but I do not trust them in the slightest to fight for user freedom (like accessing banking sites on an "insecure" OS).

This is really minor compared to other parts of Firefox. Notably, Firefox requires all extensions to be signed by Mozilla.

And the only way to turn that restriction off, is to either use Firefox Nightly or Firefox Developer Edition (which is a beta). If you want to use stable Firefox, because you like having a stable web browser, you just can't turn the restriction off. Period. The closest thing you can do is installing it as a "temporary extension" which uninstalls itself when the browser restarts.

It's kind of ridiculous that the default browser of most Linux distros has a Apple-esque mentality of "we get to tell you what you're allowed to install."

I just wish Firefox would stop trying to open external programs when I type "site:" in the address bar. It's so annoying to type "site:example.com hello" and just get a "No apps available" dialog and have to retype my search, manually specifying a search engine that time. I'm not sure if it's a bug with Snap, Firefox, or both, but it is beyond infuriating.

I've never contributed to Go before, but from reading this, I have to wonder who thought this system was a good idea.

From the sounds of it, the only situation where this PR-mirroring works properly, is PRs without any comments, which I imagine are quite rare. But if your PR does have comments, then you not only have to sign up for Gerrit anyways, but you're also responsible for keeping the GitHub PR and Gerrit PR in sync. That sounds horrible.

I've been using Discord since 2017 and in that time I think I've literally never accidentally joined a voice channel?

I've also been on Discord since 2017, and I've done it many times. Especially on servers which put voice channels right next to text channels. And I'm not the only one either, judging by another comment[0].

[0] https://news.ycombinator.com/item?id=36439417

The app even prompts you if you're sure about joining under some circumstances.

The app is even worse! It brings a full-screen pop-up and if you haven't granted Discord microphone permissions, it will bug you, every, single, time.

Please no.

As someone who doesn't use voice channels, I can't even count how many times I've accidentally joined them because I mis-clicked. And then I have to find the "end call" button because, of course, it's small and located away from the channel itself. It is so unbelievably annoying.

The best feature Discord added recently was the ability to hide channels, so I can finally, once and for all, forget about voice channels.

Not a lawyer, but if this was true, wouldn't a bunch of developers and companies be facing fines? Especially smaller open-source stuff. And larger companies as well (for instance, Reddit's mobile app is infamously inaccessible).

If you allowed free reign access to the sensors people could record the inside of your house/work, capture your face, fingerprints, retinal pattern etc.

Yes, yes they could. That's not and shouldn't be Apple's problem. That's your workplace's problem to regulate how the device is used on-site, the government's problem to regulate how it can be used in public, your household's problem on how it can be used in private, etc.

The device will be inevitably jail-broken anyways, so a walled-garden isn't going to stop bad actors.

Not to mention, most of the things you mentioned can already be accomplished with less expensive and much more subtle devices, like a standard digital camera. And those device definitely don't try to prevent abuse. (Imagine if your camera refused to take a picture because it thought you didn't have permission!)

If you put information online publicly, you should be always working under the assumption that it will be immediately archived by someone. Whether that is the Internet Archive for websites, a Discord bot archiving edits and deletions, Pushshift (formerly) for Reddit, or just some private group operating a web scraper.

At least in this situation the archived data is public.

I really hate the modern idea of locking down devices to protect users from themselves. It's my device and I should be allowed to install what I want on it.

Android's better than iOS in that regard, but that doesn't mean it isn't still terrible. Sure, you can sideload apps, but you still can't run as root unless your device's manufacturer allows it. And sure, it might have a built-in file manager, but in newer versions of Android, you can't read/write to /sdcard/Android/data without a separate device.

And this trend is even infecting non-phone devices as well. You can't install extensions on Firefox if they haven't been signed by Mozilla. The only way to disable this restriction is to use a fork or beta version (Developer Edition or Nightly).

So.. it's run everything sandboxed by default the recommendation for regular users?

Yeah, that is probably the best solution. Most mobile OSes do that by default now anyways. Desktop Linux has Flatpaks and Snaps. Windows has UWP apps. And I think MacOS has its entitlements system IIRC.

If you don't absolutely trust somethibg, you shouldn't allow it to run unrestricted.

From my understanding, neither.

It's the same code (presumably) but Chrome OS's version was compiled with metadata that said it was running on Chrome OS and Linux's version was compiled with metadata that said it was running on Linux. And that metadata is later embedded into the license request which Xfinity's servers check.

Of course, that's just my assumption from what I understand. I can't verify anything due to how obfuscated Widevine is. But due to how long-lived this problem has been, the two Widevine versions having the exact same version number (4.10.2557.0), and that everything else Widevine-wise works, I'm inclined to believe that this is intentional.

I'd argue that's less the AI being biased, than the AI's human-imposed restrictions being biased. Once you get around those (and it is not difficult to), you can get it to write an essay on pretty much anything, from any viewpoint.

I got it to write a pro-fossil fuels essay, and it gave some pretty typical pro-fossil fuels talking points (here's some excerpts):

In contrast, renewables are often hampered by their reliance on weather conditions, and they require complex and expensive infrastructure to be built and maintained. For example, solar panels can only generate electricity when the sun is shining, and wind turbines only produce power when the wind is blowing at the right speed.

In contrast, fossil fuels have a much lower ongoing cost, making them a more cost-effective option in the long run. This is especially important for developing countries, which may not have the resources to invest in expensive renewable infrastructure.

The construction of solar panels and wind turbines requires the use of materials such as concrete, steel, and copper, which are extracted through processes that generate significant greenhouse gas emissions. In contrast, fossil fuels like coal and oil are already extracted and ready to use, reducing their overall environmental impact.

This. 100% this.

We live in the 21st century and have proper APIs to detect features now, we should not be relying on parsing this user-agent string which is 90% legacy-garbage anyways.

I mean, sites blocking compatible browsers is such a common problem that not only do user-agent switcher extensions exist, they're also some of the most popular extensions out there!