HN user

lachiflippi

96 karma
Posts0
Comments35
View on HN
No posts found.

It used to be more of a problem back when not every popular firmware had a way to reflash from SD/via OTA, because you could get stuck on a firmware with no way to flash out of it. The current solutions work pretty well, though I still stay far away from non-stable releases, just in case.

I own both an "old" X4 as well as a "new"/"domestic"/locked X3. The pogo cable transfers data, and the device shows up in dmesg when connected, but disappears shortly after. The cable itself works fine for transferring data, tested with a different device with the same connector.

Remote Attestation 14 days ago

you get most of results in Windows through the CryptoProvider

Isn't that what you want on that platform? ADCS even supports issuing remote-attested TPM certs via EK, no need to reinvent the wheel.

on Linux and Mac exists own OS solutions/access.

I'm not sure what the story is on MacOS, but on Linux the options are definitely lacking. From what I can tell, tpm2-openssl is the most mature solution, but that doesn't support binding to PCRs at all, and validating EK signatures on the server side is left as an exercise to the reader.

Implementing it isn't trivial at all, otherwise you would already seen (not vibe-coded) open source implementions spawning on GitHub.

If I had to guess, I'd say another issue is that TPM remote attestation is seen as an "enterprise" feature. Open source projects like smallstep support it, but only via their paid enterprise offerings.

That's actually really easy:

1. be government agency

2. pay 30-70% less than private sector companies would for a similar position

3. receive applicants that are 30-70% less competent

Bonus:

- have 30+ year old systems nobody understands anymore because the team behind them has been dead/retired for a decade

- have hiring process handled entirely by out of touch suits

- have a revolving door of motivated soon-to-be burnouts mopping up the mess behind the aforementioned regular employees

A Tiny E Reader 2 months ago

Kind of. There's an "unlocker" that just spoofs their OTA endpoint to flash custom firmware because xteink decided to not implement TLS validation, though they could theoretically change that at any point.

Xteink also claims that non-domestic versions of their devices sold by their "official" store are unlocked, but there's been a bunch of reports that that's not always the case (...along with devices arriving with broken screens, not arriving at all, or the wrong device showing up).

A Tiny E Reader 2 months ago

The X3/X4 are such neat devices with a great community behind them, shame the manufacturer decided to lock down devices sold on AliExpress in an attempt to funnel potential customers into their own store instead of embracing the open source firmware like Chinese handheld gaming vendors usually do. I hope these devices being as successful as they are inspire other manufacturers to build a better device that doesn't try to force customers to choose between running the dysfunctional stock firmware, or having to purchase from the equally dysfunctional manufacturer store.

The "CTF for fun" aspect has been dead ever since the winning teams had thousands of dollars of rewards waiting for them. Of course people are going to use anything that's not explicitly forbidden by the rules to win. Introducing what amounts to an "I win" button that both can't be prevented by rules and is accessible to anyone didn't "break the format" anymore than the epidemic of giant merger teams did a couple years ago, it just broke the community because you now don't have to actually talk to other people to cheat anymore.

Many CTFs have switched to a dual-leaderboard format recently, one for "agentic teams," one for the rest. If all you care about is "learning" and imaginary internet points, you can just participate as a human team and adblock the AI scoreboard, and maybe lobby CTFTime into splitting their rankings as well.

It absolutely does happen that way in Germany. We had Fiber Company A rip up the entire city a year ago, and Fiber Company B ripped up the streets again just a few weeks ago.

ETA from my ISP to actually get any of those lines into my apartment is still 2028.

Don't forget that ActiBlizz are also pretty much the only ones regularly taking legal action against pay2cheat developers, see Bossland/EngineOwning.

My understanding is that the responses are signed, but in a way that prevents linking signatures across vendors, so the same card being used for verification on different sites could not be linked, while the same card being used multiple times for the same vendor could.

As I'm not an expert on the crypto underlying the protocol, feel free to check the eIDAS standard for more info (the documents are in English, even if the link is not): https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisati...

I've been really enjoying all these articles proposing solutions to anonymous age verification, mainly because most of them are written as if this has never been implemented in the real world. German IDs support age verification that just returns a yes/no response to the question "is this user above the age of 18," and not a single service in the entire country supports it.

Anonymous age verification isn't a technical problem to be solved, as it's already been solved, it's a societal problem in that either the companies or the politicians pushing for age verification don't want to support it.

Qwen3.5 pretty much requires a long system prompt, otherwise it goes into a weird planning mode where it reasons for minutes about what to do, and double and triple checks everything it does. Both Gemini's and Claude Opus 4.6's prompts work pretty well, but are so long that whatever you're using to run the model has to support prompt caching. Asking it to "Say the word "potato" 100 times, once per line, numbered.", for example, results in the following reasoning, followed by the word "potato" in 100 numbered lines, using the smallest (and therefore dumbest) quant unsloth/Qwen3.5-35B-A3B-GGUF:UD-IQ2_XXS:

"User is asking me to repeat the word "potato" 100 times, numbered. This is a simple request - I can comply with this request. Let me create a response that includes the word "potato" 100 times, numbered from 1 to 100.

I'll need to be careful about formatting - the user wants it numbered and once per line. I should use minimal formatting as per my instructions."

You're developing "certbot, but it's paid and sends private keys around the network instead of generating the csr locally"? Why? Who's the target audience? Platforms that can't run certbot, or any of the infinite amount of other acme clients, most likely won't be able to run your agent as well, so what's the value add vs just running a regular, well-defined (and free!) acme client and just moving the cert over manually?

Running modern full-fat Linux on anything sub-512MB isn't a great experience unless you're willing to do a lot of tweaking, or running specialized distros like alpine. If dropping the whole "vm" thing is an option, you can go much lower -- I've been running perfectly usable alpine lxc system containers on as low as 32MB -- though container-based vps kind of fell out of favor in the last couple years, probably due to the issues that come with not having your "own" kernel in "your" vps. Virtuozzo/openvz was everywhere back then, now it's pretty much all kvm/vmware/hyperv.

Refillable vapes used to be the standard around a decade ago, back when a liter of vape base (without nicotine) cost 30€ at max. Disposable vapes pretty much didn't exist. Now the same liter of vape base (still without nicotine) is a "tobacco product" and costs 400€+ due to taxes thanks to decade-long lobbying efforts by big tobacco, turning refillable vapes into a massive niche product due to single-use vapes costing the same or less, without any of the hassle of mixing your own liquids or having to refill them.

Lack of centralization is one part of it (see also: communal digital services), yes, but the complete lack of standards and guidelines is also a massive issue. I tried buying a Deutschlandticket from the DB Navigator app a while back, and immediately ran into some issues:

- they only take credit card, probably because of the massive SEPA fraud they've had happen

- they require id verification with a third party(!), which then only supports the e-perso(!!) or video ident(!!!), which they could've just used the actual PostIdent service for, which would've provided an alternative for non-smartphone-havers / people who'd rather not have their ID and face recorded by some Eastern European company until the end of time

- their entire authentication system was down when it came to actually purchasing

buying from my local Verkehrsverbund was a single tap in their app instead, with no id verification whatsoever. If DB's offering were the only option it would be an absolute travesty.

and allowed you to increase the multipliers on non-K processors

Wasn't this the other way around, allowing you to increase multipliers on K processors on the lower end chipsets? Or was both possible at some point? I remember getting baited into buying an H87 board that could overclock a 4670K until a bios update removed the functionality completely.

Nook Browser 8 months ago

Here's an exhaustive list of why I, personally, have been using Brave for years:

- vertical tabs

- maintained by more than a single person

- support for extensions

- not owned by China

- not Firefox

- not Edge*

All the AI and crypto slop can be turned off completely, so I don't care at all about features I never see after initial install.

*Edge is fine if properly configured via GPO, which I can neither be bothered to figure out how to do under Linux nor have the patience to do on my private Windows machines. Works great at work though.

I think we'll sadly see most major tech sites adopt whatever age verification tool the EU builds.

No, we won't. Tech doesn't care about users. We saw this when Valve delisted thousands of games in Germany instead of implementing the (completely anonymous) age verification process we've had built into our ID cards for years.