HN user

earlz

1,017 karma

I do programming and electronics stuff. My blog is at http://earlz.net My email address is earlz -at- my-blog's-domain-name

Posts39
Comments220
View on HN
earlz.net 8y ago

The Faults and Shortcomings of the Ethereum Virtual Machine

earlz
5pts0
auth0.com 8y ago

A Brief History of JavaScript

earlz
7pts1
www.youtube.com 9y ago

Didn't pay $1000 and our channel got terminated by copyright strikes [video]

earlz
8pts0
earlz.net 10y ago

Analyzing the $5.6M Exploit and Cryptsy's Security Failings

earlz
39pts10
forums.aws.amazon.com 10y ago

Life of our patients is at stake(2011)

earlz
1pts0
www.google.com 10y ago

All locations your Google account has been

earlz
2pts1
www.gamespot.com 11y ago

Wolfenstein 3D pulled from App Store due to swastikas (2011)

earlz
8pts0
tech.slashdot.org 11y ago

SourceForge and GIMP (Slashdot)

earlz
6pts0
twitter.com 11y ago

Law enforcement teams used EMP device for Garland Shooting

earlz
2pts0
bitcointalk.org 12y ago

Kraken Passes Cryptographically Verifiable Proof of Reserves Audit

earlz
5pts0
dogecoin.org 12y ago

Dogecoin.org taken down

earlz
39pts20
blog.xamarin.com 12y ago

Develop for Google Glass with Xamarin.Android

earlz
1pts0
github.com 12y ago

Github search: exec sudo $_GET

earlz
3pts0
marc.info 12y ago

OpenBSD now supports booting from keydisk-based crypto volumes

earlz
1pts0
www.noulakaz.net 12y ago

A regular expression to check for prime numbers

earlz
8pts0
www.netc.com 12y ago

Is this website real? -- Nuclear Emergency Tracking Center

earlz
1pts2
earlz.net 12y ago

My zero-investment application makes money

earlz
2pts0
hackaday.com 12y ago

Cracking GSM with RTL-SDR for Thirty Dollars

earlz
2pts0
earlz.net 12y ago

I'm learning Rust so I can move away from C#

earlz
5pts2
www.theregister.co.uk 12y ago

Down with Unicode

earlz
3pts0
earlz.net 12y ago

Why I won't be using Microsoft.Bcl.Immutable (despite much anticipation)

earlz
2pts0
www.nuget.org 12y ago

The license of Microsoft's Portable Class Libraries

earlz
1pts1
answers.onstartups.com 12y ago

I have an app that's making money. How do I protect myself from patent trolls?

earlz
3pts0
earlz.net 12y ago

Show HN: My new simplistic/flat website design

earlz
1pts0
www.youtube.com 12y ago

How to pronounce 49

earlz
1pts0
variety.com 12y ago

CBS Blocks Time Warner Cable Internet Users from Full Episodes Online

earlz
1pts0
news.ycombinator.com 12y ago

Ask HN: Best ways to accept donations?

earlz
26pts18
netbounce.earlz.net 13y ago

Show HN: NetBounce -- A tool to viewing a HTTP client's requests

earlz
1pts0
gist.github.com 13y ago

Take a moment to reflect on how bad your code once was

earlz
26pts26
news.ycombinator.com 13y ago

Ask HN: What web framework/language should I learn this weekend?

earlz
7pts6

There's a few different actions. First, since it isn't developed the paper effectively acts extremely slowly. Whereas normal photographic paper would be around 6 or up to 20 ISO, doing it this way is almost immeasurably slow. Getting similar results without a pinhole and just something layed on top (photogenic drawing), it would take several hours in direct sun to get a decent image. The next contributing factor is that some papers "print out" easier than others. The hard ones will take hours in direct sunlight, while the easier ones might take "only" 30 minutes or so. The final factor is that pinhole is a very slow and low contrast method of exposure. Silver halide paper suffers from "repricocity failure" where basically during a very long exposure, the material becomes massively less sensitive. This is why film is so hard for astrophotography. A 100 ISO film over several hours can become something more like 1 ISO. Either way, the end result is that the paper gets very slow and gains a very wide exposure latitude, nearly impossible to over expose.

I have a friend who did that for a few months and it took her iirc 2 years to get over the gum fixation.. even without nicotine, she always had to have some gum for cravings

I think she was chewing the nicotine gum a few times a day, but I'd still be careful about it.. iirc the reason she did it was she wanted gum and the only gum her parents had regularly was nicotine gum and she was like 14 at the time

I think the key with vaping (not necessarily with Juul though due to market availability) is that it's very easy to decrease the dosage of nicotine without reducing the fixation amount. For traditional cigarette smoking you want a high amount of nicotine to fill that void (and also to get through the other side of other addictive substances in tobacco beyond nicotine) and to effectively "get hooked" on vaping instead, to the point that normal cigarettes are completely unattractive to you.. Afterwards, decreasing dosage with a vape is super easy, especially if done in a blind way, ie, buying two identical flavors at different dosages (your "normal" and the lower dose) and put them into two carts. Pick a random one each day to use. I've heard of people doing this all the way down to 3mg to get over the lowest dosage hump even. One has no nicotine, the other only has 3mg. Eventually the non-social fixation (ie, at your house alone) stops, and the social fixation (ie, outside of a bar, etc) is controllable with no nicotine... Then that's not even getting into the different ohm ratings etc that further control dosage without affecting the fixation of using the vape.

edit: note I say "easy", but its not a short process.. If you try to go immediately from 48mg to 3mg you won't have a good time. It takes months for each step down

Honestly, they go to bed at the time the parent sets a routine after probably 3 or 4yo. My kids consistently go to bed at 9pm for school, 10pm on weekends/summer, and typically no problems going to sleep or waking up in the morning. It's been like that for years now. The time they did have trouble going to sleep at the right time is when they visited grandma for 2 weeks and had a wild and inconsistent sleep schedule the entire time. It took them about 2 weeks to adjust back to the normal routine. One hour adjustment from weekends etc is easy, but 2-3 hour adjustment is a huge stumbling block

It blows my mind some of the comments here of people who do this. I can literally not recall a time that mornings were not miserable.. and that includes when I am jet lagged (either going to a country, or coming back) and naturally fall asleep by 9pm and awake by 5am. Mornings are boring and I can never really get into enjoying them. The most fun I've had was one time in China I woke up at 4am and went to photograph things at 430am.. But that's not something I'd do every day, and even at the time I felt kinda cranky about it.

I have 2 kids, so have to have some structure to my sleep schedule. Left to my own devices, my natural bed time is 3-4am and I'm awake at 11am-12pm. With kids during school (in summer they sleep in too) it's a bit more reasonable though probably less healthy. Asleep by 1 or 2am and wake up at 8am. They're 9yo and 6yo and the oldest is responsible for getting the younger up if she doesn't wake up with the alarm. They're both 90% ready by the time I wake up (they prefer to wake up at 7am or even 6:30am to have some play and tv time before school). This includes getting themselves dressed, hair and teeth, and the picky youngest packing her own lunch. Their school starts at 8:45am and I'm typically out the door at 8:30am and back by 9am.

I don't really start working until 10am most days, but I'll do some passive stuff like read emails and industry news type stuff while having coffee. At 10am I'm getting started, at 11am on a good day I'm hitting a stride. Typically not doing my best coding work until at least 2pm though after lunch. Depending on how in the zone I am and what I'm doing, I work until 5:30pm to 7pm. I have the benefit of being remote and setting my own hours though, so it's definitely a blessing I know many people aren't fortunate to have. Have dinner with the family after I stop working, and then just relax with dumb activities (TV, social media) and of course bonding stuff with family, until the kids go to bed at 9pm. When they go to sleep I sometimes work for a couple more hours (coordinating with 12 hour different timezone is fun), but more usually relax with peace and quiet playing games, messing around with interesting research (both hobbies and work), or just dumbly watching TV, or do some hobbies (analog photography/darkroom printing)

I sacrifice sleep more than I should, and typically will have a 10 minute power nap after I'm done working.. But honestly, as long as I'm getting 6-7 hours of sleep, I feel just as well as when I'm getting 8 or 9. When I get less than 6 though I definitely regret it the next day. And I don't mean just sleeping in on weekends. I had about 2 weeks this summer where I had no kids, no wife, and basically nothing guiding my sleep schedule. I'd tried naturally sleeping for a week with no alarm and realized I felt more tired and it was consuming a lot of time. I was waking up at 11 or 12. So I started setting my alarm to a more reasonable 10am and was in bed by 3 or 4am, and always felt well rested after I got out of bed.

Some people can not "relax" and enjoy mornings. My goal with mornings is to get that phase of day over with so I can work and then get to a free evening. When I'm jetlagged it's pretty interesting becoming a forced morning person, but it's always proven to me that having 3 hours of free time in the evening is so much more valuable to me than 3 hours of free time in the morning.

Really cool, see a few missing film types (Superia 800 and 1600, Cinestill 800T/Vision3 500T) would also be really interesting if there was listings for cross-processing, especially of slide film in C-41. Each stock has its own set of casts and color crossing and it can be pretty difficult to figure out what that is for each film stock.

Also completely unknown how you'd do it, but giving any kind of data for pushing the B/W films would be really interesting too

One would think, for example, that it would make sense to do the "instruction decode" pass ahead of time, to end up with an array of pointers-to-instructions plus literal-values... but the resulting representation of the code is usually much larger in memory, and so less of it will fit in cache (and it'll also fight the VM interpreter itself for cache-lines.) You might gain from your instruction impls not having to trampoline back to the interpreter (https://en.wikipedia.org/wiki/Threaded_code, basically), but you'll lose in cache coherence.

As someone currently writing a (subset of an) x86 VM, I feel this pain entirely too much. My subset greatly simplifies things by not using segment registers and getting to (mostly) not have to implement the 16bit version of ModR/M.

The biggest problem with x86 is the sheer number of ways to do addressing within a single opcode using a Mod R/M operand. For instance, all of these lines of assembly can use the same primary opcode:

    push eax 
    push [eax] 
    push [1000] 
    push [1000 + eax] 
    push [0x11 + (eax * 2 + ecx)]
    push [0x11223344 + (eax * 8 + ecx)]
    push [(eax * 8 + ecx) - 10]

If not for the Mod R/M and SIB operands, x86 would be a static-width instruction set

I'm building an interpreter that goes the way of decoding to build a pipeline (really a "basic block") and then to execute the entire pipeline with minimal branching across execution. I'm less afraid of excessive cache use than the unpredictable indirect branch problem. The hope is that building a pipeline and executing it with a branchless unrolled loop will allow me to avoid that problem, while also greatly simplifying the implementation of each opcode where the actual logic just receives a set of operands it can get or set.

There was no disclosure that they were hemorrhaging money nor that their product was significantly unprofitable though. I imagine interest would've been a lot less had that fact been public at the time. They were literally selling it as "invest now and we all make a lot of money later"

I think the SEC is interested in the conditions around their ICO, the misleading tactics, and the aftermath of it, more than the fact that they did an ICO

I think writing an OS from scratch is discouraging and not very accessible because... writing an OS is discouraging and not very accessible

I actually learned C by writing an OS from ages 16 to 18. I don't know if I'd recommend it to everyone, but it is surprisingly accessible if you limit scope. The real hard parts are dealing with complicated hardware. If you care about the basics like keyboard, mouse, display, flat memory, no threads, then its incredibly easy in 16bit C for x86. 32bit C (i386) is also easy, but does require a bit more setup etc.

It is incredibly educational learning how to write your own libc and having to manage toolchains etc. You very quickly learn the exact boundaries of what is computer controlled and what is toolchain controlled, and of course what is controlled by your own code.

And yes, I had a similar experience to you re: emulators. Tried making a simple 8086 computer emulator. CPU instructions are really easy and really the part I enjoyed. Emulating the hardware and all the machine protocols gets very difficult and complicated very quickly. I ended up, after a few months of that, rescoping the project to only be an 8086 CPU emulator, which was one of the few projects of my youth I actually completed.

I remember my first digital camera. I think it was a somewhat pricey ($200) point and shoot. It was around 2002 or 2003. It was so awesome to get "scans" off the camera with just an SD card... but, it had it's drawbacks. It was 3.1MP which was fine for most stuff at the time, but it had this awful way of rendering colors and a few months after I got it some kind of hardware broke in it making video and preview mode "broken" in some way. Basically what you saw was NOT what you got in preview mode, typically with way less exposure on preview.. and movie mode always looked weird, as if it had lost half of the bits of color info or something.

Anyway, I kept it and ended up digging it up in 2010 from a box of old stuff to crack it open and make it an IR camera. Something went wrong, so now it's fixed focus at ~3ft, and with a few bits of dust permanently on the sensor... but, it worked! The focus issue prevents it from being very useful, but it's really cool as it is VERY sensitive to both IR and UV light. Using a very deep 920nm IR filter with it, I have to decrease exposure on a bright day or it's blown out... and it can very easily see UV patterns on things inside when the sun is out. I have a faded shirt that looks just black, but with the camera it can see the original lettering etc as if it were new... but also it looks magenta rather than black. Even with tungsten lights, the IR sensitivity is stronger than normal light and can end up with some crazy pictures that have "color" but not true color.

Here's some example pictures:

* https://i.imgur.com/5ZKmgFm.jpg reading text on a letter through an opaque black shirt (UV/IR illuminated through windows) * https://i.imgur.com/IYzdhXP.jpg an out of focus look out of my house on a summer day (notice red leaves, brown grass) * https://i.imgur.com/STSPbq5.jpg IR "enhanced" portrait in a car. Her hair is deep red and the coat she's wearing is black and white only. * https://i.imgur.com/7gSzCTT.jpg looking partially through a deep IR filter

The only good UV-only photos I have tend to be flash pictures. The built in xenon flash appears to output enough UV that it will burn through IR filters. It definitely appears to be UV though because of different colors used and the way certain things will fluoresce

I've done some film B/W IR photography but with film it's so temperamental and I've never gotten good IR-only (though a deep red filter can be nice) pictures. There is Aerochrome, which is getting harder and harder to find for color IR pictures on film, but even it is hard to predict (though requires less filtration) and very expensive these days.

I would think the real test is to do some pulling on the cable to make sure it's reasonably sound structurally, and also maintaining 10 GBit at the spec maximum for cat-6... but really if it works for however long you run it, what does it matter

The credit is currently wrong, it should belong to one of the developers on my team, David Jaenson.

My comment was an early disclosure before I fully understood how sensitive the details were. Even without going into detail or providing any code it was very irresponsible of me to off hand just mention that possibility. It didn't click how sensitive things were until a bitcoin core dev confirmed it. Sorry anyone who sees this. I merely reported the exploit, David Jaenson is our genius security researcher that definitely should deserve all credit.

This has happened with other, much smaller, cryptocurrencies. The choice usually agreed upon by exchanges, developers, and community is to pick a known good block before the attack and fork the chain backwards from that point. It requires significant downtime and is of course very complicated, but several different cryptocurrencies have used this method and recovered to a functioning blockchain

As a hater of the EVM and person directly trying to replace this shit, here is my rebuttal:

First, smart contracts don't have a private key, at least not in the meaning of the word. They do the equivalent of signing by sending a message from their address to another address, or expose a function to indicate that a particular message is authorized by the contract code... but it's impossible to send some packet of data to a contract and (without external communication) have it verify "this data was provably sent by this contract"

Every other system I know of puts contract addresses in some other different namespace. Even looking at Bitcoin, they use the "3" address version for pay-to-scripthash, while "1" is for pay-to-pubkey. Internally Ethereum actually DOES namespace these two different address types implicitly. A normal address has no code and has a public key. A contract address has code and no public key. There are many many if-statements with this logic to handle the multitude of edge cases that come up from using the same address namespace for person-addresses and contracts... and beyond that, this has been the direct cause of several smart contract bugs because checking if a sender is person or contract is not trivial. Even for your purported benefit of being able to send coins to contracts in the same way as a person doesn't really work. You must attach some data when sending to a contract, whereas sending to a person should never contain data.

And for your idea of a contract having multiple addresses, what would be the purpose of this? Technically this is possible but not exposed today by making it so that an address contains both the location of a contract in the blockchain as well as encoding some data. Could be done simply by allowing an ethereum address to have more than 160 bits. The first 160 bits is contract address, the remaining is data to send to the contract.

I can understand Ethereum's design being not great. It was the first one to exist and the designers were not fully aware how it would be used.. but I will never understand the people that defend the design as "oh you just don't understand why this is a good thing"

There appears to be a workaround to bypass the assert check in Bitcoin Core 0.16 that allows one to mint new coins by using an input multiple times and it be accepted by the network without crashing. Probably will be waiting until the dust settles on this before publishing that test case though, since it's clearly much more severe than a DoS

I've heard Europe is more reasonable, but at least as of a few years back before Square got so popular, there was a ton of fees to having a bank-owned card reader. Typically required >$1000 deposit just to get the machine, and then a subscription in excess of $200/month, and if I remember correctly, card present transactions were around a 2.5% fee... oh, and that was typically just for Visa and Mastercard. The people I knew with these machines never sprung for the other networks because the price was so expensive. My parents run some small businesses, and credit card machine fees were one of the major line items in their monthly expenses before getting one of those cheap square phone devices back in 2012 or so. Maybe the banks have made things more competitive though now that Square has taken at least some of their business.

There is a way around it, but it's complicated, expensive (in terms of gas), and thus I have never seen anything similar deployed yet.

Basically, use a proxy contract with some form of governance built in to it. The governance is comprised of all Dapp users/token holders/parties/whatever. Using this system, an upgrade can be proposed. The upgrade is a hash of the new contract's EVM bytecode. Then, there are X days for all parties to vote, until Y% approve it (of course, deny or not getting enough votes means nothing happens). Once approved, someone must deploy the new contract code to the blockchain. After the new contract has an address, the proxy contract gets a "finalization" command with the new address. The proxy contract then reads the bytecode of the new contract, hashes it, and compares the hash to the voted on hash. If it matches, then it points to this new contract. Depending on the details, there might be a migration command sent to the old contract, telling it to send coins, state, etc to the new contract and to self destruct. If there are no coins held by the contract, then the state and old code can remain on the blockchain for people who disagreed... Of course, this is stupidly difficult to fully realize in Solidity, but Ethereum has all the features necessary in the EVM. I personally think the faster we can move away from EVM and Solidity, the better off the smart contract world will be.

I do a lot of traveling for business and staying in a city like Dallas, St. Louis, or some suburbia part of the bay area is absolutely my least ideal place to stay almost always. I love that uber exists, but my favorite part about traveling is walking around and doing photography so that I'm not just sitting in a depressing hotel. If everything interesting is at least 2 miles apart, it's hard to enjoy a city. And especially in Texas cities, many times there are no sidewalks so that walking even short distances is a big pain

A rubberized case wouldn't protect as much. ie, the phone feels more impact from a similar fall except for maybe multi-story drops where most cases don't do anything anyway. Also, this protects the screen from falling onto an uneven surface (think gravel) whereas a rubber case won't help at all, even if it includes one of those annoying plastic screen covers

I don't know about "easily", but that's pretty much exactly what Qtum did. It's a UTXO blockchain with EVM and other smart contracts on top. It required about 6 solid months to figure out how to make it work and the output of that is something called "The Account Abstraction Layer" to basically decouple smart contracts from the underlying blockchain protocol

Disclaimer: co-founder of Qtum

Qtum sounds like the thing you could be looking for. To TL;DR; it, Qtum is a smart contract platform on an independent blockchain that supports PoS (not DPoS, true PoS) and designed to support multiple smart contract VMs. Right now it only supports the EVM and thus can only run Solidity smart contracts, but later this year we'll release a new VM based on the x86 architecture so that it will be possible to use mainstream languages like C++, Rust, Go, etc...

Anyway, ending the whole description bit, we built it because of similar thoughts as you. Tired of seeing the only suitable smart contract platform (Ethereum) be treated like some philosophical research project, rather than a platform that businesses and people stake hundreds of millions of dollars on. Everything we design is intended to be practical to not just use, but also implement. We pride ourselves in never missing any deadlines we set for ourselves, and in never having some pipe dream project that won't be ready to use for 5 years.

I can't recommend developing your own color film, but black and white is fun to play with if you want to get a better understanding of the process. If you're just doing a few rolls occasionally though then development is probably the best option.

Yea B&W only, from my research that was what I gathered too. I wasn't aware the chemicals expired though, I assumed you bought some and just processed whenever and you were good to go

The better question I think is why wear a suit, ever. There are some people who genuinely enjoy wearing a suit (I know at least one), but in general it seems the only reason to wear a suit is to impress someone. (either because you want to, or the company who hired you wants to)

Who would Zuckerberg have to impress? And I honestly doubt Zuckerberg is impressed by someone wearing a suit. And especially with the latest generation where billionaire attire has went from traditional extravagance to show the world how well off you are, to comfortable attire where you tend to blend in.

And then there's also the social norms of suits, most of these have decayed outside of government and and fortune 500 C-level norms though. In our society right now, it would be not just "unimpressive", but also insulting if you went to a meeting with say, a president (trump or whoever) in shorts and a tshirt. And in the same way, it'd be insulting to most people if who you were meeting (the president) came to meet with you in a tshirt.