HN user

gotodengo

186 karma
Posts0
Comments38
View on HN
No posts found.

While I agree with you, that disagreement with the author (and not in a my side vs. your side talking point kinda way) is one of the things I liked. I don't think anyone other than geohot himself would agree with the full thing, but that's his point.

I’ve been scraping dating sites and feeding them to ChatGPT, and it’s amazing how few of the profiles still say anything about the person. There are no rough edges, it’s basically marketing copy. Reflected back and forth in their heads with this “society” mirror so many times that there’s no identity or coherence left, just a mush of diffuse monochrome light.

I rode the TAT through from Ripley, WV to Port Orford, OR last year over 10 weeks on a Kawasaki KLX 250 I can't speak enough to how awesome the experience was. A solid half the time I stopped for gas or to eat, I'd come out to my bike to someone sitting there waiting to chat about trips and adventures or just ask what I was doing. It was an eye opening experience to just how many awesome conversations I could have had, had I just stopped and waited when I saw some interesting car or bike at a gas station.

It was both incredibly physically demanding while being relatively safe. I know most probably do it on ADV bikes, but I felt my dual-sport was perfect.

Cheaper, sturdier, and more easily swappable than NVME while still being far faster than spinning discs. I use them basically as independent cartridges, this one's work, that one's a couple TB of raw video files plus the associated editor project, that one has games and movies. I can confidently travel with 3-4 unprotected in my bag.

There's probably a similar cost usb-c solution these days, and I use a usb adapter if I'm not at my desktop, but in general I like the format.

Phishers are working completely blind, thus any amount of info going back to the phishers is a benefit to them.

Just getting server logs from an opened link lets them know their messages aren't being quarantined and their server is reachable through the target's firewall.

The user agent and how the links are accessed give info about who is opening them (A few every couple minutes == all good, 10 links sent to 10 different employees all opened within seconds with a non-standard user agent == you're being investigated and should burn the domain)

It's been a few years since I've done phishing engagements so details may vary with how things are done today. But the goal is to limit any information going to the bad guys. Let them think their messages are being blocked until they go elsewhere.

*edit: That being said, phishing at least one person at a large company is not particularly hard. There's too many companies using domains indistinguishable from shady links for one thing. Limiting engagement is good, but companies also need to be prepared for the eventuality that somebody will get fooled.

I'm on year 10 of learning my second language and passed through a variety of teaching/learning methods. Intensive FSI courses, immersion including output as early as possible, self guided based heavily on reading and vocabulary, etc. While I get by mostly fine and now live in my second language, my listening is definitely my weakest skill.

Anki is probably my most beneficial single tool. Though if I were to do it over again I'd follow more or less the poster's strategy. Maybe 80% comprehensible input for listening and 20% Anki for vocab building. At least until I could watch native TV without much effort. I've played around a bit with LLMs, but still haven't found a really great use case for my study.

On the otherhand I think consistent practice (with growing difficulty) trumps technique. Whatever process keeps you motivated to practice month after month is most important.

Their site will break consistently in any case. Running a site in 2024 comes with a responsibility to update regularly for a good reason.

There are more than enough forgotten kebab shop restaurant pages that are now serving malware because they never updated WordPress that an out of date certificate warning is a very good "heads up, this site hasn't been maintained in 6 years"

If we're talking hosting even a static HTML file without using a site hosting company, that already requires so much technical knowledge (Domain purchasing, DNS, purchasing a static IP from your ISP, server software which again requires vuln updates) that said person will be able to update a TLS cert without any issue.

Oura Ring 4 2 years ago

Looks like those generic rings are supported by gadgetbridge[1] so barely any hacking needed for 100% on device processing and storage.

I have a miband I use with gadgetbridge. I'm reasonably happy with the app, and it has visibly improved over the last year (it also wins by default being opensource + the only option for keeping data private) but the watch is a bit bulky when sleeping or typing so I stopped wearing it.

I can't imagine $10 hardware will be particularly accurate, but cheap price + data control is enough to give me an excuse to play with one.

[1] specifically rings intended to be used by the QRing app - https://gadgetbridge.org/gadgets/wearables/colmi/

For various reasons I started to open a bank account with Mercury, before deciding to use another provider.

When I said I'd no longer be finishing the application and to please delete my passport info, first they ignored the second part. When I replied again asking them to delete my data they replied about KYC laws and assured me the data was securely stored of course.

At that point I gave up. Maybe they could delete the data if I fought, maybe their hands were tied, maybe me fighting would end up flagging my info as a money laundering risk. But I immediately imagined exactly this leak happening.

They're not the only vendor affected that had my data, nor is this breach the first, but that's the one that stings the most.

Anecdotally I'm being swarmed by text message spam for the first time in months. I have to assume people are running through new breach data to find live numbers.

I have to admit, I'm a bit concerned about Blender's future development.

I've been a Blender user for 15 years, I jumped on somewhere before the 2.4 redesign.

There have been some really awesome advances in Blender over the past two years. Things that really changed my typical workflow in an absolutely good way, Eevee and all of the node work for a couple amazing new additions.

They've also changed a lot of things, namely keybindings, UI, certain modifiers, that had been done in a certain way, and that I'd committed to muscle memory, for over a decade. Those changes also had the effect of breaking years worth of accumulated tutorials and bookmarks as the workflows they mentioned are not longer relevant.

It's intensely aggravating to spend 10 minutes figuring out how to do something that you used to know how to do with the flick of a wrist. Especially when you fall back to searching how to perform the action and only find 4 year old stackoverflow posts which state the old way to do it.

I've even recently taken a weekend reimplementing the old full color icons, which required a full custom compilation, due to the lack of contrast in the new uneditable monochrome replacements.

I fully admit this may just be my initial steps into the grumbly guy who doesn't like change in my software. But I can't help but compare Blender to Firefox.

Awesome tech and a great mission, sometimes aggravating UI and workflow changes, important relationships with would be rivals.

As someone who is also still on Firefox, my opinion is that loads of cash didn't necessarily turn out great for them either.

For me at least I consider my custom hacked up, modified keybindings as best they can be, Blender to be nearly feature complete for the work I do. It's awesome that it being opensource has allowed me to nudge it in the direction that works for me. Like I said though, as a long time user I am a bit concerned.

I was mostly treading water in my Portuguese practice for the past few years, before getting remotivated this year and making some decent progress.

I agree with many of TFA's points > To learn a lot from reading, you need to read a lot, and for that you have to understand at least the gist of what you are looking at.

Reading was huge for me. After "speaking" the language for 5 years I finally read a full novel. I immediately noticed improvements in my writing and understanding. A few weeks later I finished reading a second novel and am now on to the third.

(I really recommend The Martian by the way, it seems like it's been translated a ton, and it's written in a mostly first person diary style so the tenses are fairly simple while being more engaging than kid's books)

Blender 2.92 5 years ago

My issue is that the last year or two has seen a huge amount of technical improvements that I genuinely love.

Those improvements are combined with UI and workflow changes which are big enough changes that you can't fully copy over your old defaults.

I'm still using the new versions, and some of the workflow changes are genuine improvements as well. But I can mirror the GP comment of spending an hour googling something that I knew how to do by muscle memory in an older version. With the majority of results being older than a few months and not showing the current way to do it.

*Edit: in the time I wrote this comment the GP comment appears to have been flagged (I don't recall if it said anything overly mean or anything, that may have something to do with it if so). The concern about the UI and workflow changes is real and has been brought up for a couple of years now however ([1], among others)

[1] https://devtalk.blender.org/t/huge-issue-community-split-bet...

"we're gonna turn it back on in four weeks"

This is my recurring issue when I see most "changes we're making for the election" posts. Sure this seems like a good step for this election.

Fake news and the destabilization it can bring isn't just an American phenomenon though. Are they going to apply these precautions to elections in Brazil, or Myanmar?

Godot 3.2 6 years ago

I'm making RoomWithAView [1] in Godot. Not quite a productivity app, more an apartment builder/computer interface. Although on a bit of a hiatus (and a bit buggy) for the time being.

I'm pulling in desktop screens to VR which can be moved and placed as wanted. Working on pulling in individual applications and doing application launching. Aside from that it exposes a good bit of file system access in game. So a decent amount of stuff a productivity app may want to do.

I'm not a Unity guy but I briefly tried VR in Unity and the support seemed quite fractured. SteamVR has multiple versions across stores/github and I wasn't sure which to use, ditto for various tool kits. Godot I just downloaded a sample project and striped it down then worked off that.

The hardest part is doing anything non-gamey. Occasionally I'll make a help post and people will just reply "why would anyone want to do that?" but the C# support means you can use just about any libraries out there, so pretty much anything is possible with enough fiddling. I dropped the idea but even had OpenCV working with the Index's webcams at one point.

[1] https://ark1ve.itch.io/roomwithaview

This review seems oddly combative.

It's $35, it boots off the shelf Ubuntu, it has a real graphics chip, it does what it says it does. It doesn't have RF shields, and was probably designed cheaply, but it's $35.

Aside from the RasbperryPI (which obviously isn't x86) the review compares it to items which are 3x in price.

Admittedly, I assume that 3x price is probably closer to what the actual retail would be for this without the surplus angle. I think it being surplus is cool in a hacker kinda way, but I do see an issue there if you're concerned about longterm support.

Pen testing is a pretty big industry. I've used a handful of RATs for different purposes including at least one which was professionally developed and purchased (through my employer anyway)

I'll add however I've seen more than one sketchy dev hide behind the "It's just server admin software" angle. I'm not familiar with the software from TFA so I can't comment where that one stands.

I've been working on a game project over the past year. Everyone I had shown videos to was supportive. I felt like I got a lot done in a short few months. But no one other than myself had gotten their hands on the game proper.

I had planned on doing a single point of release when it was finished. I'd done that with a game release before however. After months of work release day came, the game flopped, and by a week later it was more or less lost to the void. Not wanting the same to happen on this project I changed my mind and released it as it was one random weekend.

It had very little documentation, and even worse known bugs and crashes. But a couple people downloaded it and one guy liked the concept enough to kick me $5. By the next week I had some more info on what those people liked and what they could live without. I had motivation to fix some bugs that I had learned to work around in my using of the game. My development rate on the game has gone up significantly since releasing it in an unfinished state, and the community is very small but two months later the game hasn't dropped into the internet void.

I can sympathize with the mindset of "I've been working on this in a vacuum and just want someone else to see it, warts (or lack of content) and all". In my case it's worked out for the benefit of the project as well.

This has interesting ramifications in areas which do have the ability to support power supply, but haven't implemented our style of loans tied to collateral (Edit: Or rather haven't implemented automated billing, pre or post paid, tied to an identity.).

I saw this in play in Mozambique. Few people had bank accounts, even fewer had mailing addresses, but many still had power.

Once a month or so you went down to the market and bought a little scratch off ticket worth X amount of power, I assume with the same one time use keys used on gift cards. When a house wanted hooked up to the grid they'd be supplied with a power meter which had a keypad. Type the numbers from your scratch off into the box, and it'd update it's counter with how much electric you had left.

A lot of things worked on this scratch off system, and it's one of the things I really liked. It enabled the power company to trust in their hardware instead of having to place trust in an individual. So the individual didn't have to provide any collateral. There was no credit check to get a new phone plan, because you either bought a scratch off that month or you didn't. No one came around to check your power meter unless there was something wrong with it, and they company didn't much care what it was supplying power to. I watched my neighbor build a new house and transfer his live box (quite dangerously) from his old to the new. The power company trusted the hardware, not a person or house it was tied to, so it didn't matter and there was never any record of what he was powering with it in the first place.

For me it's less the duration of a holiday and much more about the content.

I've had 2 week vacations that consisted of some small important event like a family get together, but otherwise were largely spent on the computer. These usually fly by and suddenly I'm right back at work feeling exactly as I left.

Most long weekends of the year wind up more or less the same. With the extra day off barely even being noticed.

One time though, I saw and bought a cheap day of ticket to Puerto Rico over labor day. Left the laptop behind, found the first cheap place to stay once I landed, met some cool people while hiking and spent the whole weekend with them. It was by far the best vacation I've ever had, and the relaxation stuck with me for months.

I suppose I agree with the article, that length largely doesn't change your perception of the experience. So if taking shorter vacations means more experiences then it may be better. I think the important thing to note though is, at least for me to get anything out of it, it has to be an experience outside the norm and off the computer.

I have a particular interest in the languages of Mozambique. Many of these languages are heavily used in their local areas, but endangered by lack of acceptance in schools, lack of media in the language, and lack of resources (Possibly one of the reasons Moz is blank in the linked map).

I've found most of the best resources for actual text in smaller languages comes from religious translations, which can be a bit outdated but usually offer a fair amount of text. And beyond that I've gotten lucky with a few google drives and other repos mostly containing educational packets put together by various volunteer and missionary groups.

Unfortunately I'm not sure the copyright on many of those. I think that's why most of the language projects[1] I've seen wind up being mainly repos of titles of papers published on various languages. Which can be hit or miss for educational purposes.

[1] From the linked site I mainly poked at a couple African languages and didn't see much beyond the paper titles. There may be others with much more info.

From the post:

"The ad is attempting to use the Audio API as one of literally hundreds of pieces of data it is collecting about your browser in an attempt to "fingerprint" it... Your browser may be blocking this particular API, but it's not blocking most of the data."

Seems like killing the audio is the metaphorical putting a finger in the dyke of serving arbitrary JavaScript to your users.

Your link is in reference to the state of the air reports. Which seem to collect data in 3 year periods. Looking at the most current report vs. the previous one Pittsburgh is (slightly) worse for particulates, going from 12.6 ug/m^3 to 12.8. The city also fell from 17th worst to 10th worst for fine particles[1].

Between the reports, it was the only county in PA to see an increase in unhealthy days for fine particle pollution[1]

25% of days in 2019 have been unsafe for people with asthma in the city[2]. Obviously the coke fire is a large part of that. Which by the accounts I've read at the least took their sweet time warning the public about the scale and type of pollutants that were released.

Obviously the city is not yet at 1970's level. I've spent some time on the rivers, and indicator species once lost have returned and are still there.

Your own link however contains the quote(from before the coke plant fire)

"Of all counties in the state, only Allegheny experienced an increase in the frequency of unhealthy days for particulate pollution, 6 to 8.5 — the highest in any county east of Utah."

--

For context with the neighbor, this is while the well ~200 yards from his house was spraying mist. From the last time I was at my parents' house it seemed to do that for about 10 minutes every 4 hours or so. It makes the air smell like old cabbage and is hard to schedule around. The whole street has shared their concerns with one another.

I love the place, and farms certainly add their own pollutants to the air and water, but the status of the air in Pittsburgh is pretty canonically "not good".

--

https://www.nextpittsburgh.com/latest-news/american-lung-ass...

https://www.ehn.org/pittsburgh-warned-stay-indoors-pollution...

Western PA in general seems to be slipping back into (as I've been told it was like) the pollution of the 70's.

Even without the recent coke plant fire, Pittsburgh had a record worst year (since they've cleaned up in the past few decades at least) for days of high airborne particulates, warnings for those with asthma, etc.

The gas wells in the south west of the state used to pool their run off/waste water (which contains at least benzene IIRC) and wait for it to evaporate off. Those pools occasionally leaked though, and the pictures of dead fish in nearby ponds/streams looked bad. So now they mist the water and spray it into the air to be dispersed over a larger area. Last time I was home I saw my neighbor mowing his yard with a white surgical mask on.

Tap water has turned cloudy at best and isn't trusted by anyone, so everybody buys bottled water, which just increases pollution again.

Last I read though, Bayer was getting out of Pittsburgh, and BNYM was doing a bunch of layoffs. As much as they should, I can't imagine the local govts bringing down the hammer anytime soon. In leiu of tax breaks, Appalachia has a long history of selling the environment and locals health in exchange for business.

Sorry, but you're making a lot of assumptions as to why this person, or anyone would have a large amount of video or photos.

They could be the guy taking photos of their kid's ball game, that parent's know they can reach out to for pictures of their own kid's goals as well. They might have to record regular meetings at a work or club for posterity/legal sake. Based on what they posted it possible they're a pro photog/videographer who is just looking for a better system than what they're using currently.

Take less video isn't applicable to the question at all.

As for my experience I do agree with the keep them on an HDD part though. Nothing beats raw storage capacity for me, and multi-terabyte drives are only getting cheaper. I've got one set for bulk items, and another for backups of anything worth keeping.

The only annoying part for me is remembering to get data off a group of SD cards and onto the harddrives in a timely manner.

At this point it's a backwards compatibility issue. Like you say for Ohm they now recommend using the omega symbol[1] but there's still code out there using the Ohm symbol.

Solving that wouldn't have helped in the Spotify case though since there's a ton of other edge cases like combining characters 'e' + ' ́' vs precomposed characters 'é' which still cause the need for an idempotent canonicalization of usernames.

Not to get too far from the topic at hand, but I came across the Spotify article earlier this week while looking to support Unicode usernames in an application. After consideration I've decided to just lock things down to ASCII for now. It's just too big a case to consider and there are bigger fish to fry.

[1] https://en.wikipedia.org/wiki/Ohm#Ohm_symbol

The Portuguese have exported certain other aspects of Asian culture to various parts of the world as well.

"chá" is the word for tea in (all?) the Portuguese speaking world, an early borrowing from Cantonese. Whereas most other European languages use a variation of tea or chai, which have somewhat longer etymological routes.

Cross-pollination from their colonial days has also lead to curries being part of the regular diet of many Mozambicans.