HN user

kstrauser

32,853 karma

I make things. I’ve learned a lot from messing up along the way. It always works out OK in the end.

I don't speak for my employer, obviously. I barely speak for myself half the time.

I blog at https://honeypot.net/

Write me at kirk@strauser.com

Posts38
Comments8,165
View on HN
honeypot.net 4d ago

Synology back to requiring first-party drives

kstrauser
3pts3
factory.ai 21d ago

Droid Shield 2.0: learned secret detection

kstrauser
2pts1
www.wsj.com 3mo ago

An Investor Dared Him to Quit School. Now He's Building a $1.5B AI Startup

kstrauser
7pts0
github.com 10mo ago

Show HN: Little Fluffy Clouds: Combine a bunch of small adjacent networks

kstrauser
2pts0
clay.earth 1y ago

Clay Is Joining Automattic

kstrauser
6pts8
honeypot.net 1y ago

Trying (and failing) to hack the Wall of Sheep (2022)

kstrauser
30pts11
gist.github.com 1y ago

A journey though Elixir's syntax

kstrauser
4pts0
honeypot.net 2y ago

One Pill Can Kill

kstrauser
2pts2
innovation.consumerreports.org 2y ago

Permission Slip: Enabling consumers to meaningfully exercise their data rights

kstrauser
4pts1
www.washingtonpost.com 2y ago

Hacking group plans system to encrypt social media and other apps

kstrauser
5pts1
honeypot.net 3y ago

Language Server Protocol Launched a Golden Age of Editors

kstrauser
3pts1
honeypot.net 3y ago

Accidentally Hacking the Planet

kstrauser
2pts0
honeypot.net 3y ago

Pianos

kstrauser
3pts1
retr0.id 3y ago

The image in this post displays its own MD5 hash

kstrauser
766pts130
honeypot.net 3y ago

Surprise Eero Hardware End-of-Life

kstrauser
3pts0
honeypot.net 3y ago

Trying (and failing) to hack the Wall of Sheep (2022)

kstrauser
2pts0
honeypot.net 3y ago

Slack was broadcasting hashed passwords for 5 years

kstrauser
6pts2
www.epicgames.com 4y ago

Support-a-Creator Program

kstrauser
1pts2
sflive.schedulefly.com 4y ago

Updates (“We got hit by a ransomware attack.”)

kstrauser
2pts1
privacystudy.cs.princeton.edu 4y ago

Princeton-Radboud Study on Privacy Law Implementation

kstrauser
32pts11
github.com 4y ago

Wonk is a tool for combining a set of AWS policy files into smaller sets

kstrauser
41pts14
honeypot.net 4y ago

The Itanic Has Sunk

kstrauser
203pts244
news.ycombinator.com 5y ago

Cdw.com is offline with missing nameservers

kstrauser
6pts0
www.wired.com 5y ago

Netheads vs. Bellheads (1996)

kstrauser
4pts3
doesipadhaveweatherappyet.com 5y ago

Does iPadOS Have a Weather App Yet?

kstrauser
4pts0
jellycuts.com 5y ago

Jellycuts

kstrauser
2pts1
nvd.nist.gov 5y ago

CVE-2021-27135: xterm flaw may allow remote code execution, CVSS 9.6

kstrauser
43pts61
livestream.com 5y ago

Saving Hacking from the Zaibatsus: A Memoir

kstrauser
1pts1
www.cisecurity.org 6y ago

Multiple Vulnerabilities in [Android] Could Allow for Arbitrary Code Execution

kstrauser
1pts0
honeypot.net 7y ago

Commodore declared bankruptcy 25 years ago today

kstrauser
6pts0

It did for me. I put it in my jeans pocket when I head out the door in the morning: grab backpack, phone in one pocket, reader in other. Then I actually read books in my queue to and from work. It’s the similar routine as grabbing my keys as I head out.

Their software suuuuucks. They market it as a paper notebook replacement, and it’s alright for that. Anything other than that is out of scope. Good reading experience? No: it’s a notebook, not an e-reader. Organization with tables of contents and links between documents? No: Paper notebooks don’t have tappable links, so neither should this. Dictionary? LOL no: That’s not how books work.

If you can live with its many, many, many weird limitations, the hardware is delightful. I returned mine after I had it for a month, though, and bought a Nomad. Remarkable makes good devices but I couldn’t abide the shoddy software.

I use it for my daily commute, spending my ride reading instead of doomscrolling. I just finished “A Confederacy of Dunces” and now I’m on “Lonesome Dove”.

I didn’t imagine how much I’d use a tiny, pocketable reader. I love it.

Back to Kagi 9 hours ago

Yes, for me.

Work: “foo corp privacy policy”, “foo okta integration”, “foo corp trust center”

Here I want specific links to exact documents because the details matter.

Home: “3d print boston terrier”, “cyberpunk fight chimera”, “!w georgia country”

Here I want to look at lots of similar things quickly, or read long-form content.

And with Kagi, “cyberpunk fight chimera?” gives me a consistently decent AI summary of the search results, with references. It’s a single UI that gives me exact results or broad summaries as requested, and that’s pretty handy.

IANAL, but the notion of "strict liability" horrified me when I first head of it, and I thought it had to be some kind of a misunderstanding. So we're tossing that "innocent until proven guilty" idea out the window, huh?

I'm sure smarter people than me have sussed this out and can explain why it's a good thing, but it sits wrong with me. We can put the subject matter aside for a second: I don't think I could convict someone for having something happen to them, regardless of what the law says. Let's say drug possession was a strict liability law (and maybe it is for all I know). Finding a baggy of meth on the corner of a farmer's lot would mean that, technically, he was guilty of possession and had to prove that it wasn't really is. That's nuts. And looping back to the subject at hand, if the only evidence that someone possessed CSAM was their email inbox, without proof that it was solicited? They want me on their jury.

There should never be a circumstance where someone can't report something that happened to them to the police without a legitimate fear of being arrested. That's bad for the person, and it's bad for society.

But if their hard drive has folders grouped by age or something, prepare the solar catapult.

I think you’re right, but from another angle. In the state where I lived way back when, a state representative put forth a bill to explicitly make e-CSAM illegal. I guess it was already illegal for print media and this covered a gap in the law about cell phone pics, etc. Thing is, it had no allowance for the age of the picture taker, or even whether the picture taker was the photo subject. If a 16 year old girl took a nude selfie and sent it to her boyfriend, she was a felon.

I wrote to the rep and explained my concerns. I wholeheartedly agreed with the intent of the law, but the code was buggy. To my surprise, he wrote back in horror to say he hadn’t considered that and pulled the bill immediately. I’m proud of having done that.

I’m 100% pro yeeting child pornographers into the sun. I still don’t want to throw kids in prison or remove all traces of a right to privacy in our haste to sun-yeet them.

Just throwing this out there: the post you're replying to had a litany of things like "we had no control over the fact that the site's owners and maintainers implemented a completely different UX than our interpretation of the policies would allow for".

The site's builders put one set of UX patterns in place. The site's visitors who created things like that linked mini-faq tried to put another in place. When the two are in obvious conflict, as they clearly frequently are, the people who wrote the mini-faq etc. claim it's because the people who built the site are wrong, as is every other non-personally-invested user of the site.

You're not going crazy, or if you are, at least you're not going alone.

You've mentioned Intel's compilers a few times but they're not a magic thing that could make Itanic not-suck. Suppose they make general purpose code that's twice as fast as GCC when the whole computer is dedicated to running one specific process. They don't, but let's pretend. Even in that ideal scenario, it falls apart as soon as you're processing unpredictable input. VLIW sucks hard at chewing through data that's not precisely what it's expecting. You could probably make a video codec that performed really well, but it would be impossible to make a database that performed consistently not-badly. It's not that the existing compilers weren't good enough, not even the magic Intel ones. It's that it's not possible to pre-generate VLIW opcodes that do well when the input value isn't a homogeneous stream. Even if Intel's code was 2x better than GCC's — and again, it wasn't — twice abominable was still abominable.

I wasted more time SSHed into an Itanic than most people had to, so I'm speaking from first-hand experience. Some very, very specific Itanium code was a bit faster than the equivalent x86 or similar. That was always some very tightly scoped thing that did the exact same tight loop a gazillion times, like en-/decrypting a data stream. Anything more heterogenous ran poorly, as in multiple times the wall-clock time of the same workload on the x86 server next to it that cost a tenth as much. And that's even when using the magic Intel compilers.

Itanium was bad. The compiler tech didn't exist to make it not-bad, and in retrospect I think it become obvious that it couldn't exist. It wasn't a matter of the compiler authors needing to be clever. It was more like making Itanium live up to the hype required making P=NP.

That's ridiculous and you're wrong. I grant them a CC license to my content to fold, spindle and mutilate it for their own purposes, but not to leave my name attached to the folded, spindled, mutilated version.

My answer has my name on it. It's right there saying "kstrauser said these words". If I didn't say them, I don't want the site lying and saying that I did. I don't mind if someone fixes an obvious typo, or updates a URL that had bitrotted. That's fine. They're what I obvious intended to say. But I've had people add extra sentences or paragraphs, and oh hell no.

That was never a core principle of the site, at least not when I joined it before you. If it'd been an expressed core principle that people could edit my words, attributed to me, so that my user account ends up saying things I never said, I never would have signed up and not many other people would have, either.

I reverted nearly every single edit to my answers other than obvious typos. If I’d have meant something other than what I said, I’d have said it. You want to see your own words on the page? Write an answer of your own.

Lordy, that use to piss me off most fiercely. I don’t want someone else’s words attributed to me.

If you figure that out, please let me know. I've been using their gear since my first DS412+ way back when. For the most part, it's been rock solid and works as advertised. Without these shenanigans I'd have little desire to switch to anything else.

But now? Since their first attempt to lock users into buying their insane first-party drives[0] I've started migrating all my workload off the NAS and onto separate servers. It's very close to being just "dumb storage" now. I refuse to use any of their cool proprietary products because I want to avoid this lock-in.

[0] https://www.amazon.com/Synology-HAT5320-Enterprise-Internal-... is $1300 (but only 12 in stock), vs a Seagate https://www.amazon.com/Seagate-IronWolf-Enterprise-Internal-... for $860. And what happens when you have to replace a drive? I can drive over to Central Computers right now and have a new WD installed an hour later. I have no idea where I'd source a Synology drive on short notice in an emergency.

GitRoot 4 days ago

Oh, nifty. While It’s maybe not the tool I’d pick, I can see the appeal of it and why others might choose it.

Synology's latest headline features are only available to people using solely Synology's own hard drives.

A year ago, they tried to make it so that you couldn't create a new RAID volume unless it used only first-person drives.[0] Then they walked that back to allow you to use normal Seagate and WD, etc., drvies.[1] It seems they've reverted locking new features to their own hardware.

After that first move, I swore I was done buying Synology hardware. After they relaxed, I was willing to consider that they'd learned from customer feedback and abandoned this scheme. Now? This is the future they're racing toward and I want no part of it.

[0] https://news.ycombinator.com/item?id=43734706

[1] https://news.ycombinator.com/item?id=45513485

GitRoot 4 days ago

What’s the cool thing about this that make me choose it over Forgejo?

My college notes were OCD-grade tidy and organized, and I did alright. I get what you mean, though. I've seen plenty of examples of people who obsess over making pretty notes that don't convey much information.

Whenever I get a new notebook, I immediately scribble on the front page before I have a chance to stop myself. There. It's tainted and imperfect. And then I've given myself permission to make messy notes, and jot down just whatever, rather than treating it like some museum-grade archive.

I wonder how true that is, vs customers using AI to port projects off big iron, or to many work that they’d previously outsourced to Big Blue. I suspect it’s only going to get easier to migrate to cheap servers running modern languages, which can’t be great news for companies that highly depend on lock-in.

I just tailed the web logs for a bit and saw that it was wild. For fun, I fed 10 minutes of logs into an AI and it picked up a lot of signal I didn't catch at first glance, like clients claiming to be MSIE 7 on Android 3 and such. I added some reject rules to the webserver in front of Forgejo but that only made a dent in the traffic, alas.

You’re so right. I have a public-facing Forgejo server. Before configuring Anubis, scrapers were sending it about 600K requests per day. Copying and pasting from my blog post about it:

* For every Git commit, fetch the version of every file in the repository at that commit.

* See git blame for every file at every commit.

* Attempt to download the archive of each repo at every commit.

* Run every possible pull request search filter combination.

* Run every possible issue search filter combination.

* Fetch each of those URLs at random from some residential IP in Brazil that had not ever accessed my server before.

Afterward, it dropped to several hundred. Expect anti-attack features to keep getting stranger and more visible as scraper get still more aggressive.