HN user

anewguy9000

229 karma

astrobiologist

Posts4
Comments194
View on HN

this. the uis for different apps have different needs - ex. keeping a video editor wide and narrow. and its not uncommon to want more apps open than would fit into their own tiles or having to move to another desktop workspace. i just wish there was a compositor or window manager for wayland that supported working this way, none really do. without a tiling wm, apps in gnome want to open right in the center of the screen, and don't remember their positions, its comically bad

mozilla used to have this smart guy, brendan something, as their cto. but he was chased out of mozilla and created a new browser called brave. it actually does what this current cto claims to be trying to do

got it, thanks. indeed looking again at the whois record, the registrant info is redacted, and the make offer link takes me to domain agents.

so i may have jumped to a conclusion here, but ultimately though my question remains: i searched a domain on namecheap, it was available, and then suddenly it is taken a couple days later. the domain itself appears unused and for auction, and the registrar is also, conveniently, namecheap. so if namecheap isn't the actual registrant holding it for ransom, are searches shared or sold to third parties looking for potentially valuable domains? whatever happened it's hugely suspect - so the net effect is that im hesitant to search with or use namecheap again for my next domain without some insight here

maybe i wasnt clear - its listed for sale by name cheap. i am open to other explanations, but im just sharing my experience of what happened. the whois record shows name cheap as the owner. thats the "basis" for my point here. why would they do it? well read about what happened with icann, lots has been written about the incentives and state of affairs today. if you could link to some policy that states this practise is not done (like how some companies privacy policy calls out if they sell your data or not), that would be great, but otherwise baseless comments like this are not helpful

thanks, will dm you. do you explicitly state its a practice you do not engage in anywhere other than the comments here? if so it would greatly help folks like myself if it was an error of some kind. the whois record showed it registered after my search, so i dont think a misreporting makes sense. if its a mistake that would be cool, obviously incredibly suspect which led me to read up on it and i found similar stories from others

apoligies for the lack if clarity

how does a rainbow table crack "dog" with the salt "109231oijoasdfnaisdfabatteryhorse123"?

rainbow tables are as old as time and indeed still work on passwords with poor salting. for more complex (but not complex enough) passwords there are more modern approaches, like probabilistic candidate generation

i meant others commonly assume horseloverwhatever is more secure.

to be more clear,

1. dog is weak 2. horseloverwhatever is weak 3. 8randoms! is weak 4. therefore, dog is as good as horseloverwhatever or 8randoms! 5. most account compromises do not even require a brute force (shoddy practices on the backend) making the complexity requirements pointlessly burdensome on the user 6. in cases where you want a password to resist a legitimate brute force, we need to talk about passphrases (ie > 50 chars) or passwordless

what u think?

i agree. but most sites that enforce a policy (8 chars, symbols, etc) are bruted just as easily. we need to take a step, away from passwords, to secure against brute force in 2022

im sorry, what point are you making?

if its that "dog" is a weak password, i thought that was evident. but many people seem confused that "horseloverwhatever" is more secure, similarly that "dog23!Wog" is more secure. my point is they are equally trash so leave the user alone

yep, most of the discussion about passwords completely miss the point. a random word, like "dog" or "pingpong" is fine if the pqsswords are salted and hashed appropriately. how often have your accounts been hacked this way? if an adversary is really banging on the hash, and they want it, any password under around 50 characters is as good as "dog", and no "complexity" meter is gona cut it. that xkcd comic that says 550 years? no, that password its owned a lot a faster than that. all this talk of entropy and security but so obviously clueless about modern brute force techniques

but this doesnt really explain what makes gpl superior to mit. in my experience, gpl is expensive, and i have seen plenty of fair contribution, ownership, and community making things better with mit. what i was trying to say was that code published in the open will inevitably be abused by humans and machines alike. the difference between gpl and mit, in my view, is that more permissive licenses are less at odds with this reality. with copyleft there will always be lawsuits

ive come to think that if you open source your code, u should only use MIT. ie. make it a gift. because once your code is just out there in the open, you cant pretend you still control it. suddenly you're dependent upon lawyers. thats icky. i mean anyone could be using this guy's code to do something against the license, and dude would never know. well, if you give a shit, maybe don't leave your code sitting in the open on a microsoft server? either set it free, or don't.

its legally dubious but not morally ;)

pirated sports are even a better product. they dont have ads. so if i pay for sports on tv, im actually paying to watch ads?? it should be the other way around, and if it were, i would probably sign up. also give me all your money

ontario still conflates anyone hospitalized for anything testing positive for covid, with anyone hospitalized from covid; this alone could explain the discrepancy between a hospital bed and icu. lies damned lies and statistics...

because 75% of them are probably dead links now ;-)

but all the major browsers have sync. you can export them from chrome and import them into brave

and btw if you use a lot of bookmarks (i do too) you might love this graphical bookmark manager YASD - you can browse bookmarks as thumbnail images of the site -- much easier to browse them for the link you want):

https://github.com/conceptualspace/yet-another-speed-dial

coderpad interviews test performance anxiety. there is a set of programmers without performance anxiety and there is a set of programmers with performance anxiety. whats interesting is that the cargo culting of coderpad interviews from google on down means google takes the best programmers with acting skills (thanks to infinite money) and everyone else takes the second tier of programmer with acting skills. the best programmers without acting skills (like kevin here) are left out. the plus side, for them, is they may find the set of companies who arent cargo culting and might really have a clue.

You realize Firefox only exists because it serves Google's interests right?

And while Brave might be based on Chromium, it is distinct; in addition to not crippling nativewebrequest as chrome will, it's native adblocker is compatible with the same lists as ublock origin. So I would go with Brave :)

on the other hand, while driving with a passenger my android auto wont let them interact with the system without a "safety pause" every 2 seconds, making it virtually impossible to, for example, change the music or update the navigation. i thought google was famous for hiring people with IQs above 100? or did a lawyer add this feature? or is it pure safetyism? sadly all 3 options seem credible

i seem to meet more and more people who have experienced acute anxiety / panic attacks than ever. it leads me to wonder if it's just more understood and easier to talk about now, or is there some phenomenon where the incidence is actually increasing?