HN user

looperhacks

1,872 karma

Personal: https://jeschke.dev

New project: https://supplywarden.com

Posts22
Comments267
View on HN
www.heise.de 1y ago

More than repairable: Teufel presents an unusual speaker

looperhacks
1pts1
pwnagotchi.ai 2y ago

Pwnagotchi: Deep Reinforcement Learning for WiFi Hacking

looperhacks
1pts0
www.youtube.com 2y ago

I Ran a Chess Tournament

looperhacks
1pts0
www.home-assistant.io 2y ago

Home Assistant 2023.11

looperhacks
288pts190
arxiv.org 2y ago

Is Saturn a failed gas giant?

looperhacks
59pts58
www.debigare.com 3y ago

After 8 Years, Double Fine's Hack 'N' Slash Secret Room Has Finally Been Cracked

looperhacks
2pts0
www.heise.de 4y ago

EHealth: Connector replacement is a €300M grave without valid reason

looperhacks
3pts1
dave.autonoma.ca 4y ago

Logging Is a Code Smell

looperhacks
2pts0
github.com 4y ago

A circuit-level redesign of the Game Boy Advance

looperhacks
241pts52
tonsky.me 4y ago

Python as a Build Tool

looperhacks
5pts0
interestingengineering.com 4y ago

Scientists Are Creating Vaccines for Type 1 Diabetes

looperhacks
2pts0
earthly.dev 4y ago

Idiots and Maniacs

looperhacks
6pts0
engineering.fb.com 4y ago

WhatsApp enables multi-device capability

looperhacks
3pts0
news.virginia.edu 5y ago

Doing something is better than doing nothing for most people: study (2014)

looperhacks
267pts194
sebastianfast.github.io 5y ago

Bark Beetle Infestation

looperhacks
2pts0
www.mozilla.org 5y ago

Firefox Release 89.0

looperhacks
487pts474
hitsave.org 5y ago

The Nintendo e-Reader – Fundraiser for a forgotten treasure for the GBA

looperhacks
3pts0
githubwrapped.tech 5y ago

GitHub Wrapped

looperhacks
2pts0
bugs.chromium.org 5y ago

GitHub: Widespread Injection Vulnerabilities in Actions

looperhacks
624pts145
netzpolitik.org 5y ago

German Made State Malware Company FinFisher Raided

looperhacks
135pts52
netzpolitik.org 6y ago

EU diplomats to use mystery app for secure messaging

looperhacks
1pts1
engineering.shopify.com 6y ago

Pagination with Relative Cursors

looperhacks
2pts0

But if these tasks are too minor, too finicky, too open-ended or too reliant on manual dexterity for a purpose-built robot, how can a general purpose robot perform them better? If anything, they should be doing worse.

The only thing I can think of are tasks that are so rarely done, it's not economical to build a robot for. But I then I also don't see how another robot solves this problem.

Before I respond, I want to point out that I'm against age verification as well.

"Think of the children!" - Say the 40-year-old millennials who were exposed to the Wild West of internet content as children and are still fine.

While I'm not 40 yet: I was exposed to "the Wild West" and I was certainly not fine. And even then, I'd argue that today's social media is even more damaging for the psyche than everything I was exposed to.

"Our child will become a pariah without the internet!" - In what way, exactly? They still go to school, still play sports, still go to chess club/band/theater/etc, still ride bikes around the neighborhood, still hang out at friends' houses, etc. All the kids will not hate them because their parents refused to give them a smartphone. (How do I know? I know a kid who grew up without one. Has plenty of friends.)

Not all communities are like this, but I have certainly seen it:

- They still go to school: Sure, but they will miss out on class group chats that, depending on the school, might be important. Or, even worse, will miss information from teachers. - still play sports/go to chess clubs/etc: Sure, unless all club communication happens over chat apps/social media and is required to join. - All the kids will not hate them because their parents refused to give them a smartphone: Maybe not. Maybe they will be because they are the odd one out (How do I know? I was the kid who grew up without the back-then equivalent)

StarFighter 16-Inch 3 months ago

They sell to the EU, so they have to follow their regulations. If they don't, the devices can be seized by customs.

Tbh there are more issues if they wanted to be compliant with EU regulations. I'm fine that they aren't compliant (they aren't in the EU, after all), but it's something to be aware of when ordering from them.

Now, I'm pretty confident to say that this is obviously just a red herring to distract from the fact that Frau Klöckner simply fell for a phishing attack. The usage of Signal wasn't the real problem (besides that it isn't formally approved for comms).

But since this whole ordeal started, I'm divided where to place the blame (besides the attacker, of course):

- Can we really victim-blame someone for falling for an attack? Sure, people in positions this important should know better, but I don't think we should put the blame on the victim. - Should we blame Signal for even providing the functionality that allowed the phishing in the first place? Signal announced changes that supposedly makes phishing harder, so apparently, something could've been improved before? - Should we blame the software-world entirely that having credentials that can be shared is even a thing? (Looking at passkeys) - Should we blame society that the knowledge about phishing attacks isn't ingrained into every person? (being a bit hyperbolic here) - Should we blame the administrative staff that allowed exposed politicians to even have apps that make phishing possible? It would be possible to make a super-secure messenger that needs much more verification than just "having the credentials". It's just super annoying and impractical for most people. Should we prevent exposed politicians from even having access to not super-secure messengers?

I feel like things could be improved to prevent phishing attacks in the future. I just don't know what is the most sensible point to start.

The earliest doc I can find quickly shows that the BSI already recommended Wire in 2021 (at least; couldn't find anything earlier). The actual authorization seemed to have happened some time in 2024, but it's possible that just nobody asked for the formal approval before that.

What I'm saying is - just because the BSI authorizes something, doesn't mean that it has to reach the Bundestag ;)

Why I forked httpx 4 months ago

but it requires knowing what class and value to pass

Unless you use a text editor without any coding capabilities, your IDE should show you which values you can pass. The alternative is to have more methods, I guess?

why can't I just pass 20 or 20_000 or something

20 what? Milliseconds? Seconds? Minutes? While I wouldn't write the full Duration.ofSeconds(20) (you can save the "Duration."), I don't understand how one could prefer a version that makes you guess the unit.

proxy(ProxySelector.of(new InetSocketAddress("proxy.example.com", 80))), geez that's complex

Yes it is, can't add anything here. There's a tradeoff between "do the simple thing" and "make all things possible", and Java chooses the second here.

.authenticator(Authenticator.getDefault()), why not just pass bearer token or something?

Because this Authenticator is meant for prompting a user interactively. I concur that this is very confusing, but if you want a Bearer token, just set the header.

Migrating to the EU 4 months ago

This is already a crazy take on its own, why would a fork have to describe their relation to the parent project front and center? Both the Readme and the comparison page link to the origin blog post [1] that describes the lineage clearly.

But even if there were some "ethical reason" to do this, I don't think Gitea is the right project to play up as a victim. Their homepage [2] doesn't mention that Gitea itself is a fork either. Their Readme does, but is this so much better?

[1] https://forgejo.org/2022-12-15-hello-forgejo/ [2]: https://about.gitea.com/

You "need a plugin" in the sense that every component of maven is a "plugin". The core plugins give you everything you need to build a self-contained jar - if you wanted to, you don't even have to configure the plugins, if you want to write a long cli command instead.