HN user

logic

1,768 karma

Home: <https://esm.logic.net/>

Twitter: <https://twitter.com/esm>

Mastodon: <https://mastodon.social/@esm>

[ my public key: https://keybase.io/logic; my proof: https://keybase.io/logic/sigs/5jZpQq4CuBQ3sBc487AHcaRbhNfkHi5ItoN6HBwsXOk ]

Posts55
Comments295
View on HN
discussion.fedoraproject.org 21d ago

Fedora: Future of Community Initiatives and AI Deveoper Desktop

logic
3pts0
github.com 2y ago

Corrosion: Gossip-based service discovery for large distributed systems

logic
32pts1
www.issquareup.com 2y ago

Square Is Down

logic
9pts3
mastodon.world 3y ago

Board Changes at Signal

logic
77pts70
craigmod.com 3y ago

Walking Tokio Tōkyō Tokyo² – Winter Edition

logic
5pts1
twitter.com 4y ago

Lofi Girl radio streams taken down due to copyright claim

logic
99pts16
gantry.io 4y ago

Gantry: The tool to iterate on machine learning-powered products

logic
14pts2
blogs.gnome.org 4y ago

Towards Gnome Shell on Mobile

logic
4pts1
sfconservancy.org 4y ago

SF Conservancy now accepting copyright assignment for any GPL software

logic
86pts158
kdspaul.github.io 4y ago

How Does Git-Push Work

logic
2pts0
wp.puri.sm 5y ago

Purism Convertable Note Offering

logic
31pts4
en.wikipedia.org 5y ago

Vala Programming Langauge

logic
6pts1
writing.kemitchell.com 6y ago

/Dev/Lawyer on Luis Villa’s Licensing Year in Review

logic
1pts0
thehowlandcompany.com 6y ago

Advanced Systems Integration Lab

logic
1pts0
www.bizjournals.com 6y ago

Lyft sued by more than 20 women for ongoing sexual assaults

logic
3pts0
techcrunch.com 6y ago

GitHub faces more resignations in light of ICE contract

logic
13pts1
twitter.com 8y ago

Twitter's Smyte acquisition/shutdown took down NPM

logic
6pts0
www.chicagotribune.com 8y ago

Lyft-branded beer aims to give ride share company a lift in bars

logic
1pts0
bugzilla.gnome.org 8y ago

Gnome-keyring does not have a maintainer

logic
2pts0
medium.com 8y ago

The Universal Data Plane API

logic
3pts0
medium.com 8y ago

The art of exploiting heap overflow, part 2

logic
2pts0
twitter.com 9y ago

“Emoji composer is now at 100% on Twitter”

logic
59pts19
blog.opsee.com 9y ago

OpSee shutting down

logic
2pts0
www.djangoproject.com 10y ago

DSF Code of Conduct committee releases transparent documentation

logic
1pts0
dangerousprototypes.com 10y ago

Trolling venture capital and the death of Hacker Camp Shenzhen

logic
1pts0
blog.twitter.com 10y ago

When seconds really do matter

logic
3pts0
mjg59.dreamwidth.org 10y ago

Linux Foundation quietly drops community representation

logic
778pts185
unethicalblogger.com 10y ago

Choose Happiness

logic
1pts0
www.gigamonkeys.com 10y ago

Let a thousand flowers bloom, then rip 999 of them out

logic
231pts122
www.jwz.org 11y ago

Jwz: YouTube has finally destroyed their RSS feeds

logic
4pts0

I'm about to receive a librem5, and Signal is going to be one of the biggest stumbling blocks for me to switch over. The electron desktop app can't serve as a replacement even if it could run properly (it needs to be tethered to a phone that can run the Android or iOS mobile client, with the SIM for your number installed), and open source reimplementations are few and far between (and then there's the issue where they don't want third-party implementations or forks talking to their servers, and they don't federate, so it's not like you can actually run your own server and continue to talk to anyone).

I'm sure the librem5 community will eventually scaffold something to make this work, and it might even be somewhat user-friendly, but I can't imagine a scenario where Signal themselves are positive about it.

So, it's back to SMS for me. And convincing my more technical friends to give Matrix a try again, in the hopes that the UX issues aren't as bad for them in late 2019.

I wish Signal the best of luck, I really do; their goal is laudable, most of their source is open, and they're smart folks. But a very limited developer community (and open hostility to the kind of community that might result in broader platform options) means I've stopped suggesting it to folks, because I won't even be able to use it myself very shortly.

This has happened to me several times as well. I use them with the temporary container tabs add-on (so, short-lived containers by default, plus a selection of specific sites that I retain information for, with strict cross-domain isolation), and let me tell you, losing that configuration is painful after setting it up.

The fact that you can't sync container configuration between devices is also a huge pain point, when you have a nontrivial setup.

I still use them, but I accept that I'm going to endure some pain now and then; I can't recommend Firefox containers to people who just want to get work done right now.

The hoops a password manager has to jump through to get halfway decent integration into a browser is basically begging for security vulnerabilities. Seriously, just look at how much JavaScript is riding behind webextensions like LastPass, KeePassRPC, Bitwarden, etc. It's staggering.

I dont have any interest in using Lockbox; I already have a self-hosted open-source password management solution (Bitwarden, in my case, but that's just an implementation detail) that works for much more than just my web browser, which means I'm way more interested in hearing how Mozilla plans to make this kind of integration smoother and less error-prone.

I need to sync passwords for apps on my phone, for desktop apps that aren't web browsers (and for multiple browsers on several platforms), and Mozilla's one-off reinvention of existing software and protocols for their singular use cases is just xkcd'ing the problem, sadly.

If your local transit agencies are supported (or you're able to add them to the upstream library they use to collect this data), Transportr seems like a good choice: https://transportr.grobox.de/

Sadly, it doesn't cover any of the agencies in the Bay area, so I've had to rely on Transit (transitapp.com) from the Play Store.

I just finished most of this transition for my own purposes, with the main difference that I decided to self-host most of the services I was previously using Google for. Some highlights:

* Android: if you really want to divest yourself from Google, Android is going to be a showstopper for any but the most committed people. I'm running LineageOS (nee CyanogenMod) without gapps, using microG as a collection of play services API replacements. While that keeps me from adding a google account to the phone (which is the main thing I'm trying to avoid), I still end up needing something like Yalp Store (available from F-Droid) to download and update Play Store apps, because there are a few I actually can't get by without a huge level of inconvenience. I did all this because I enjoyed the challenge of it; for normal people who aren't intrinsically motivated by this stuff, I suggest buying an iPhone and saving yourself the headache. Seriously.

* Email was the easiest thing to move, and the hardest to get right. I remember when I originally moved my email to Gmail, and noted a marked increase in spam; the same thing happened when I moved off of Gmail last month. A combination of postfix, dovecot, spamassassin, and a lot of tweaking has me mostly back to the point where I was when I was with Google. I've been using Rainloop for a use-anywhere web UI, although I've used Roundcube in the past and was pretty happy with it. On mobile, I'm actually using k9mail, despite how dated it is, because it actually gets IMAP right; both the stock "Email" app and Gmail had sporadic issues with IMAP that I got tired of dealing with.

* Meanwhile, calendaring was the messiest part of the move, mostly because CalDAV is a bit of a mess, and both client and server implementations leave a lot to be desired. I ended up using sabre/dav on the backend because I could tweak and extend it quite a but to do what I need, and because it had baked-in support for CalDAV scheduling, which is something I can't really live without. I'm using DAVdroid on Android for both calendar and contact sync, which is great except for scheduling, which I can't really use. (A combination of what looks to be some misbehavior in davdroid, and android limitations in the calendar API.)

* More calendaring: are you used to having your calendar invites just magically show up in your calendar? Yeah, that's probably not going to work anymore. I'm been writing an itip milter that scans for text/calendar mime parts in incoming email and shoves them in an appropriate caldav store, but it's going to be pretty hacky even if I finish it. ;) If you're looking for better integration here, look at something like Zimbra; it's a huge pain in the ass to run, and it's resource-heavy, but when it's running well it's amazingly polished from the end user's perspective. Or give FastMail some money, because they've been doing this for a long time, and do it really well.

* Docs, photos, file syncing in general: There's a bunch of options here. I almost ended running an instance of NextCloud (nee OwnCloud) for this, because it would cover a few different use cases (document storage, photos, calendaring, contacts, etc), but settled on Syncthing as a general file synchronization tool. I'm hosting a cloud instance that my laptop, mobile devices, etc. can all talk to, as well as an instance on a machine at home, giving me pretty good coverage for on-demand backups. I try to avoid working in heavyweight document formats for personal stuff (markdown and a text editor works for my use case most of the time); for things I have to share or where I need more powerful tools, LibreOffice. I don't have a good photo management solution right now beyond "directory full of photos synced from my phone and camera".

* Books: I had bought a bunch of books on the Play Store. This was a painful lesson in how bad the state of DRM in ebooks is, especially if you don't have a Windows machine lying around. I ended up having to install Adobe Digital Editions under Wine, then used a Calibre plugin to automatically convert DRM'd ebooks via ADE when I have it import them. I share the Calibre collection to my tablet via syncthing, so changes, read positions, etc. sync nicely. (I don't mean to pick on Google on this one; the DRM issue seems to be a mess with every bookseller right now.)

* Music: Exported my music using Music Manager, sync with Syncthing, and access streaming music with Spotify. Done, easy.

* Maps: I use Google Maps, logged out (it's one of the few Google apps that continues to function properly even without a Google account on the device). OsmAnd~ is a great idea, and I use it as a fallback when I'm outside of cell coverage, but I find it almost impossible to use in a day-to-day context (if you have it open gmaps links/intents, it almost never figures out the address I'm looking for, and I've had terrible luck relying on it for navigation). Note that without logging in, you cannot save Google Maps data offline, because apparently gmaps engineers are a little bit spiteful.

* Search: I've defaulted to DuckDuckGo for years. Yes, sometimes I hit "!g" to search Google, but I don't default to them, and haven't for a long time. Also, shock of shocks, bing is getting pretty good.

* Android Pay: I opted out. I have credit and debit cards, and I have cash. Some people might find this to be a deal breaker, I find it hasn't changed my life in any significant way.

* Browsing: Firefox. Not really a change for me.

There's a bunch of smaller one-off services that I've used over time, but those are the big ones from a personal perspective. For some folks, a large chunk of these can be handled by running an instance of NextCloud, and you'll get a polished, fairly integrated experience for the parts they can cover.

At some point, I should probably write this up with more details about the tradeoffs I made with each piece.

In a life long ago, I was responsible for an office full of Thinkpads, not long after Lenovo spun off from IBM. These were machines that "just worked", and if there was a problem, their on-site service was legendary. I never had to worry about them.

I now own a 3rd-gen X1 Carbon for personal use. After my experience with it, I'll never buy or recommend Lenovo again. Months of waiting on backordered parts (for their flagship laptop), repeat visits from their service center, and the end result is finally a laptop that mostly works, but is starting a slow death very early because of cheap plastic construction and tight tolerances that aren't so tight after a few months of use. I've had it a year and a half (I bought it the week it came out); I'll be lucky if it makes it to two years without another significant problem.

Terrible experience all the way around. It looks pretty on the website, but it's not built to last like their older products were, and their service is a shadow of its former self.

epeus is right; I'm not at Twitter anymore either, but the last time I looked at this, per-country takedowns were clearly labeled as such (ie. you hit the tweet from the blocked country, you get clear "this isn't visible to you" messaging).

My honest guess? Cache coherency is hard, man.

His position, I'm guessing, is that when a good has no natural scarcity (pictures and music in digital form, for example, or compiled code), society should not be creating an artificial scarcity in its stead (ie. compelling others not to reproduce it through force of law). He views the idea of this compelled scarcity to be, basically, rent-seeking behavior codified into law.

I'm not entirely sure, but I suspect the "you can't own" portion of his statement was a point of possession and direct control, not necessarily law.

exratione, please let me know if I'm misrepresenting your position here at all, and I'll correct my post. (I'm intentionally leaving out my opinion, just trying to clarify yours. :))

Just a quick note about the disassembly challenge he faced (indirect references), having gone through this before: you can get amazingly good results by cheating a bit. That is to say, rather than assuming you actually have to properly execute through the code path, you can get very close by roughly tracking register assignments when making your initial pass through a block of code. (Even better, if you can track potential ranges of values with later calls into a given block. Some of this depends on how you've implemented your disassembler, though.)

I ended up doing this with a SuperH disassembler (with SH2, due to its two-byte opcode layout, indirect addressing is the order of the day), and by doing basic register assignment tracking and adding a few crude heuristics, I was able to get very usable results. No, the end result won't be "pretty"; you'll be moderately embarrassed to show it off., but it will work. :)

(Heuristics: one structure that I had to manually handle were compiler-generated jump tables; thankfully, for my project, I'd had a bit of help from the compiler that was used, and there were distinct signatures I could key off of.)

If you're even remotely interested in the disassembly aspect of this, I'd recommend learning a bit about a piece of software called IDA Pro: https://www.hex-rays.com/products/ida&#x2F; As horrible as the UI of it is, there is simply nothing better on the market for reverse engineering analysis.

Donating my Xbox 13 years ago

A black screen that says nothing but "Unity Web Player Install Now!" might as well be a facebook login screen to me, I'm afraid.

Your life's work 14 years ago

I suspect the 37signals employment contracts still say "at will" somewhere in them. In fact, Jason Fried talked about exactly that at one point: http://37signals.com/svn/posts/2239-employment-contracts-wha...

If you want me to treat a position like it's the last one I'll take, then show me the same: treat me like a member of the team that you'll fight to keep around. Offer equity, take that at-will clause out of the contract, treat me like a partner in your success.

Anything else is just blowing smoke, I'm afraid. At the end of the day, you can be let go without notice (and, to be fair, you can also walk away at any time); that's the agreement you sign during your first professional interaction with most US-based companies. And it sets the tone for the rest of the relationship: this is a transient arrangement, and can be discarded as situations change on either side.

You just described the level of integration G+/Picasa has with my Android phone: every photo I take is automatically uploaded to a (private) folder on there.

For many of us, Flickr's appeal is that it's (self-)curated: you've picked your best stuff to upload. Features like "explore" reward this; popular content is highlighted, while those who just upload every photo they take tend to not get any attention at all. They've effectively trained the userbase to share good content (insofar as the userbase is capable of producing, anyway).

It's the reason a lot of Flickr users, particularly the ones who produce good content, are interested in 500px: quality counts.

That dynamic would change quickly if everyone were encouraged to dump everything they take onto Flickr. It would devalue the service for many of us: nobody wants to see fifteen different perspectives of the same "moss on a rock", taken in rapid succession, but that's what your contact stream would end up filled with. You can only remove people as contacts for so long, before you decide it's no longer worth the trouble and jump ship.

Flickr isn't Photobucket or Picasa, and that's a good thing.