HN user

avallach

132 karma
Posts0
Comments36
View on HN
No posts found.

Doesn't this mean we just need to make the webgl fingerprint resistance implementation smarter? Instead of explicitly rejecting webgl access or responding with dummy data, respond with data that is random within space of N common and reproducible patterns. E.g. emulate webgl implementation of some low spec but actually popular devices.

The whistleblower claim against them that I've seen:

"Delve allegedly took an open source tool and passed it off as its own work without proper license attribution. The Delve folks said they built it themselves, the whistleblower contends. DeepDelver then presented alleged evidence that this tool was actually a fork — a modified copy — of SimStudio, changed just enough to be passed off as Delve’s own. If that proves true, it would be a violation of the Apache software license, which requires the original developer be credited."

https://techcrunch.com/2026/04/01/the-reputation-of-troubled...

Their defense in this article:

"falsely claims we “stole” from another YC company when in reality we built on an Apache 2.0 open-source repository"

I'm really confused. Unlikely that they misunderstood the accusation. This looks a bit like admitting to half of the accusation, while completely misrepresenting what the accusation was, so that they could say that the whistleblower is a liar.

Isn't this actually improving safety by openly admitting how things always were in practice?

Any e2e encryption provided by the same entity who fully controls both the blackbox clients, and the server in between, is just a security theatre that they can selectively bypass anytime with very little risk of detection. Not really much better than simple client to server encryption.

Truly safe e2e requires open source client provided by a trusted entity who is as much as possible independent from the one who provides the untrusted transport layer. Eg how pgp email works.

If I wanted to make ad blocking hard, I'd first keep serving an easily blockable ad system while getting everyone used to extension API which only can block such simple systems. Only once it is fully adopted, I could switch to hard to block system.

Doing that in the opposite order would obviously harm adoption of my crippled extension API and push users to competing browsers which kept supporting the advanced API.

how do we get large text to scale at a lower rate than body text

Express the header text size with CSS calc function with a sum of em (relative) and px (absolute) values. Depending on their ratio, element will be more or less scalable. 100% em -> scales like body text, 100% px -> no scaling.

Maybe I'm misunderstanding, but after reading it sounds to me not like "io_uring is faster than mmap" but "raid0 with 8 SSDs has more throughput than 3 channel DRAM".

WebOS – Part One 11 months ago

It's even weirder than that: mention of the shell GUI is just the intro, later they proceed with implementing a facsimile of the Windows NT kernel in... TypeScript. Even for purely self-educational purposes, this pairing seems to be very counterproductive.

I agree that the title is misleading and should be changed. I also expected LG webOS.

I can totally see your point. It's a bit like that fight of news agencies against the free snippets and aggregations on 3rd party websites. The Internet is supposed to be open after all.

But it also feels like essentially "pirating" the webpages while erasing their brand. Maybe it's even a tolerable transitive situation, but you can't even argue it's beneficial in the same way as game piracy could be according to some. In the long term, we need an incentive for the content creators to willingly allow such processing. Otherwise, a lot of high quality content will eventually become members-only with DRM-like anti agent protections.

The incentive doesn't have to be monetary. I could for example imagine some website owners allow AI agents that commit to upfront verbatim repeating some sort of mandatory headers/messages/acknowledgements from the content authors, before copying or summarizing, and are known to stick to this commitment.

You can also bypass the problem already now by accessing and copying the content manually, and then putting it in the context of a tool like NotebookLM. Nobody's hurt, because you have actually seen the source by yourself, and that's all the website owners can reasonably demand.

TL;DR: why even post quality content in open if the audience won't see your ads, your donation button, or even your name. What do you think?

And then once they see that the website operator blocked the perplexity-user, apparently instead of respecting that, they not only ignore robots.txt, but actively try to bypass the security measures established with the explicit purpose of limiting their access. If this was about bypassing DRM rather than AI-WAF, it would be plainly illegal.

To me this invalidates their whole claim that Cloudflare fails to tell the difference between scraper and user-driven agent. Instead, distinguishing them is trivial, and the block is intentional.

Cloudflare did explain a proper solution: "Separate bots for separate activities". E.g. here: one bot for scraping/indexing, and one for non-persistent user-driven retrieval.

Website owners have a right to block both if they wish. Isn't it obvious that bypassing a bot block is a violation of the owners right to decide whom to admit?

Perplexity's almost seems to believe that "robots.txt was only made for scraping bots, so if our bot is not scraping, it's fair for us to ignore it and bypass the enforcement". And their core business is a bot, so they really should have known better.

The post title is misleading. The algorithm did not leak, only the documentation listing all the signals that can possibly be used as inputs for that algorithm. It doesn't reveal which ones are actually used and how.

The magic lies in tessellation. Tessellation is an efficient GPU process of heavily subdividing your mesh, so that displacement maps can add visible geometric details afterwards. And because it's dynamic you can selectively apply it only to the meshes that are close to the camera. These are reasons why it's better than subdividing the mesh at preprocessing stage and "baking in " the displacement into vertex positions.

No, at least not in the "automatic" way the Nvidia RTX Remix does. You would not only need to generate the displacement maps for textures, but the most importantly port the game to this new rendering engine. It's an extremely complicated task if done by reverse engineering and hacking the executable, without ability to read and recompile the source code.

In various trains, over 20 versions of the compiled firmware with unique variants of the locking algorithm were found. And to make matters worse, the trains were found to have something that appears to be a GSM-to-CAN bridge. It isn't reverse engineered yet but AFAIK shouldn't be there and in the worst case may be a remote control backdoor.

This looks great!

But with all these mentions of democratizing and opposing centralization, the licensing model seems unclear to me. The Croquet Microverse is Apache-licensed but "built on top of Croquet OS" which seems to be proprietary with paid and centralized server. Does anyone understand whether at least the client side component of the Croquet OS, which interfaces with the Microverse, is open source so that alternative server implementation could be developed without legally dubious reverse engineering of the protocol?

I'd qualify the most popular chains here (like Albert Hein) as super markets. You can buy not only food, but also all the basic home supplies (cleaning products etc), large choice of drinks and sweets and so on. Basically all you need on daily basis as long as you're not too picky about the brands. But not home _equipment_. In years of living here in few places I've been only going to the store by feet. Indeed it's every few days as apartments are mostly small and you have no space for storing/freezing a lot of food. And there are mice everywhere.

Digital Euro 3 years ago

How can they prevent double spending of digital currency in offline transactions? Or is it not about preventing, but inevitability of detection and legal consequences, as they will somehow identify the wallet holder who did it?

Unless you mean particular artwork called "Eiffel Tower At Night", Eiffel Tower is 3d object. Making photo of it gives you opportunity to involve your own creative invention. But photocopy of 2d artwork seems to me to be clearly just a copy, not a derivative that deserves own protection distinct from protection of the source art. Even more so than transcribed text of audio recording.

I'm curious if the ruling could be any different if the scraped website only served the content once the visitor clicks "accept" button next to the T&C link, rather than referring to it in the footer.

Also: is the situation any different when art galleries display online photos of public domain paintings and similarly attempt to put restrictions on use of these photos? After all, faithful photographic reproduction of 2D artwork seems even less derivative than transcription of song lyrics.

Traditional way of expressing it is "following the spirit of the law vs the letter of the law". But in case of U.S. Constitution opinions are always divided, which of these interpretation is the right one.

WebContainer API 3 years ago

It's very reassuring to see that this is going to be open standard with working group behind it!

I was a bit confused when writing my previous comment. I kind of meant client-side vs server-side part, but I see it may be (or should be) both. I'm impressed you answered in person, please let me elaborate.

webcontainers.io/api describes client-side ECMAScript interface (e.g. `WebContainer.boot().spawn('ls', ['src', '-l'])`). The "StackBlitz WebContainers client" is not the only existing in-browser implementation capable of providing such interface. For example, there is "WebVM" from Leaning Technologies, that "runs unmodified Debian binaries in the browser" using "x86-to-WebAssembly JIT compiler" and "Linux syscall emulator". It can run everything from WebContainers examples, like `ls src -l` or `npm run dev`. One could easily make adapter that uses WebVM to implement WebContainer API. This is what I thought "WebContainers API" should encompass.

But as I learned today, WebVM just like WebContainer also requires a web service (Tailscale) for proxying network traffic. Even JSLinux (bellard.org) uses proxy server. That's necessary because there is no "WebNetworking API" exposing local native networking trough the browser. Usage of such service is implementation detail, but including it in the "WebContainers API" standard is right now the only way to make provider-agnostic clients and I did not consider that before. It may become redundant one day if we get "WebNetworking API" for the browser but there's no such ongoing initiative.

Did I get that right now?

Is StackBlitz WebContainers web service going to proxy arbitrary network traffic, or is it about git, package management and other dev-specific protocols?

Is "WebContainers server API" going to also reflect client API methods to give optional support for thin clients and hybrids? (running all or selected commands in remote container rather than only proxying the network)