If you enjoy this, you may also enjoy the `atc` binary that is shipped alongside tetris and other classics in Debian's bsdgames package. Also exists for Ubuntu (https://packages.ubuntu.com/noble/bsdgames) and probably other Debian derivatives. I enjoy the keyboard controls there, a lot more deterministic than trying to mouse around the screen!
HN user
lucb1e
I'm Luc, Dutch, love coding, IT security and computer networking. I'm also into Linux, open source software, OpenStreetMap, and things that reduce or capture CO2.
For contact info, see: https://lucb1e.com/email-address
I found it reasonable because there's no need in this specific case but you do often use quotes and this could be a good middle ground of annoyance (line complexity) and getting the character distribution somewhat right
...but then you read the author's response about not having actually made this themselves and your head canon implodes
I tried looking it up but "“sadge” The word you've entered isn't in the dictionary." Care to say more than whatever slang I presume this is?
Yes, still down. The HTML loads eventually with the query contents, but no CSS, much less query results
No issues here with Firefox on Linux or Android 11 (installed from F-Droid in case that matters). Strange. I wonder if it's a network difference rather than the workstation setup
There's a highscore system but considering it's a matter of time before that gets cheated, the first run where I didn't struggle with backspacing into a previous command (which is blocked):
60s | Basics category | 79 wpm | 100% acc | 38 cmds | QWERTY | Logitech K200 (membrane keyboard from like 2007)
Fun idea, I like the categories and the option to specify keyboard+layout in the highscore, and the page layout/design is very clear. Thanks for making!
Switching categories does not restore scroll position to top, so you start to type what shows as being on top and the whole list changes to "you've got the first command wrong and here is a completely new list to type". I didn't understand what had happened at first
The scroll position of the whole page (including the field where I'm typing) changes when you press enter with the first three commands, until until the current command is centered within the commands list
WPM is a strange measure when some words are -h and others are "user@example.com" including the quotes. Not like language doesn't have long and short words but especially with needing shift etc., this feels kinda weird and like it would depend a lot on which words you get randomly assigned. You can pick the longer duration to even that out, but you could also just switch to CPM and get more reliable results faster -- or so I'd expect
The highscores don't show the run's duration, aka the error margin
Theoretically this would have to use readline or whatever input mode the person is used to. Ctrl+P would put the cursor at the end of the previous command, Ctrl+W then erases the last word (until the previous whitespace), Alt+Backspace is similar but erases until the previous punctuation, etc. Not sure if that's all possible on web. For some reason it also didn't bother me though, although I'm a very heavy user of these and e.g. web KVMs and chat input fields (when writing a command to a nerd friend) keep tripping me up. I guess it just feels like a typing test and not "real". But it makes me wonder what "real" would do for typing speed
Going back to the previous command (with (ctrl+)backspace I think mainly) is something I kept trying to do though, also tripping up 3 commands in a row (notice typo -> autopilot-mode fixing it: backspace to undo the enter, type correct character, enter again -> now you have 2 lines wrong). Maybe backspace (or also arrow keys?) being able to go back to a previous command could be a setting so people are free to choose whatever is faster for them
The input field defocuses at the end, so then the default browser commands start triggering as I'm typing the remainder of the command (mostly that's just searching on the page and the scroll jumps to some random spot, but can also be leaving the page with backspace). Maybe the fix can be as simple as restoring the box' previous value onkeyup and coloring it as though it's disabled
Highscores are probably more fun if you see (or can toggle between) the latest submissions as well as the top month/year/all-time. More of a long-term thing, for now I lead one of the categories so I know the submission worked and that I'm amazing *pats self on back* (there is only one other person in that category for now :P)
I wonder how long it takes for everyone to get kicked out by a cheater though. Maybe there should be a cheater category that shows up once you hit >1.5×max(leaderboards), because people will want to try autotyping but you also don't want to give them ideas. Then they have some place to submit to without breaking the other highscores. I know that a lot of cheaters won't care but... I would :shrug:
Choosing e.g. Debian does not include Basic commands that I can tell, whereas of course on Debian it's not like you never mv a file. Maybe multi-selecting categories would enable people to combine it however they want, but then the highscore system is difficult so hm.
To reproduce... actually, I wonder if you can guess my browser and OS family based on the above :D
None of these are a blocker or big bother for me btw, it's just that I saw the invite to report UI issues/ideas and I can't help myself. I had fun using it, thanks for making!
Why call it "Ant" and not "Antjs" or "Ant.js" when there is already Ant from Apache? https://ant.apache.org
Seems unlikely/strange that all these clones would miss this little thing of using the derivative instead of the accelerometer directly so that it 'actually works'
But the significance during motion sickness is the rate of change of the rate of change. That thing where the vehicle slows down, turns a corner, goes over a bump.
That's the same as being pulled towards the earth at 1 gee. Both are acceleration from the accelerometer's point of view. I'm not sure how to convey this well in text, but maybe try installing a sensor reader (e.g. https://f-droid.org/en/packages/de.rwth_aachen.phyphox/) and looking at how the accelerometer values change when you move it in various ways
From an accelerometer's point of view, there is no observable difference between standing "still" (on earth's surface, moving some km/s around its axis, which also moves around the sun, which also moves around the milky way, which...) and being in an airplane. Both feel ~9.8m/s/s acceleration in the same direction because both are in a moving reference frame that stands still with respect to the accelerometer. The 'absolute' speed of the airplane (relative to the ground or air) is not something the accelerometer can measure, so it couldn't not work at 'higher rates of speed'. (If I understood your comment correctly!)
note where I wrote:
su'ing to the user ID of [another app]
Look, I have root, so you can hack me! And my bootloader is wide open, too! In your words:
> Root access and an unlocked bootloader are insecure, even for low threat models. These devices are vulnerable and should not be used for any sensitive data.
I'm serious that anyone should feel free to prove the point by sending me a responsible disclosure notice about having found a way in, but the threat clearly isn't serious enough for that to actually be concretely possible. Which is not to say that it's never relevant, but "such a device shouldn't be used" is not valid as a blanket statement
Sure, we can have different opinions on what makes a useful Linux distribution. Either way, you can't install Ubuntu Touch on just any phone. That Volla supports that alongside their AOSP derivative gives you more options on how to use the device; it's worth pointing out to potential buyers as a bonus on top of running Android only
Thanks, but there's no way anybody here hasn't already heard all of that. GrapheneOS' statements are inevitably reposted to every thread and subthread that touches on the topic.
Yes, I knew it's in a sandbox at the time of writing my comment above; no, that doesn't make it a privacy paradise compared to microG.
The sandbox still needs internet access for a lot of GMS' functions and lots of apps send information into it. For example, Signal will actively reach out for notification bundling, so Google gets to know who runs Signal, what IP address they're on, with who else they share that address as they go to school and work, build a social graph... So while the sandbox is definitely very useful and I'm glad it exists as open source software that other Android distributions can be inspired by, it doesn't definitively solve fundamental problems with running unwanted software on your device
Do you know what privileged context means? As in, what access this grants concretely? I tried to look it up once, ended up in Android source code trees, and left more confused than I went in. It looked like it gets no extra file access at all, which is strange right? What does privileged mean if not that? I tried su'ing to the user ID of GMS and this confirmed that the GMS user can't access other apps' data folders. So I'm no longer sure what to even make of this wording. Is it maybe about syscall hardening that isn't applied to privileged apps or so, so like exploit protection rather than normal permissions? The benefit of that would be protecting from exploits that Google could send. Do we think they'd legit do that, short of receiving an NSL that compels them?
Rather than running the unwanted proprietary (but necessary) software wholesale and attempt to sandbox it, I'd much rather substitute as much as possible with open code (where we know what it does) and have a much smaller set of proprietary components that need to be kept around in a sandbox and active only when necessary. For example, microG will replace Gmaps with Mapbox, reducing how much data is sent out about you to Google (they don't get to see which city you are probably in while using the map in Too Good To Go, for example).
It seems fairly obvious to me that less data sharing plus less proprietary code (that needs to be sandboxed) is better than letting Google go wild and installing their apps as-is with self-updating functionality (in said sandbox). What threat would sandboxed microG pose that sandboxed GMS doesn't? Is there any logic to GrapheneOS not wanting to build upon microG to get the remaining proprietary parts properly sandboxed, rather than starting over from scratch?
Contrary to popular belief
Extraordinary claims require extraordinary evidence. Got any?
The rest of the comment consists of even vaguer statements about how it's better in every way and then (circularly) drawing the conclusion that it's always the right choice because it's better in every way. I have no idea how to respond to these opinions than either writing a book that goes into every subtopic you're touching on, or just concluding "ok that's your opinion". Maybe consider that others may disagree by having different values and priorities than you, and so it's not strictly always the best option
Somehow that stands in stark contrast with the many Fairphone users that I know use their device for many years. One of them uses it as their primary computing device, not owning something like a laptop because the Ubuntu Touch that runs on it plugs into a screen and keyboard and works like a desktop as well as a phone for them. I don't understand why the derogatory statement about that being e-waste out of the box when it obviously works great, at least for those willing to pay the premium for as-fair-as-they-can-make-it part sourcing
Privacy is when nobody is looking, whether that's because they cannot look or because there's nobody that looks.
Security is the former: actively denying someone or something the ability to look in a situation where they are trying. GrapheneOS does that by encouraging a locked bootloader (preventing physical attacks) and letting you deny sensor access (preventing malicious apps from accessing unnecessary info), for example. I think we agree so far?
But you can also have privacy by just not installing apps that violate your privacy. Such a device could be as open as any Linux laptop where you log in with root:root. It lets you do whatever you want and access whatever you want. It's yours through and through. That's freedom without security, which may or may not have privacy depending on who you let look: if you leave it unattended at a hacker conference or have sshd with password login enabled, yeah that won't stay private for very long. But that's your choice right? You can just not invite anyone in or, in this example, bring it to someone who would do something malicious
An official GrapheneOS release has a lot of features baked in against actively malicious actors (be it apps or people at border checks), but users need to work within the boundaries and limitations of the sandpit that's provided to them. They're not granted much freedom, and that limits what privacy measures you can enact. Making a backup of /data, modifying firewall or traffic routing rules, signature spoofing to substitute an untrusted app with a trusted implementation, intercepting and faking Android API responses... a lot of things are off-limits: you don't have the freedom to shape the environment to suit your needs, for example to create privacy or security
The axes (privacy, freedom, security) all influence each other, but they are still separate enough that you can have one or two without the other. I can see what you mean if you say that your threat actors are skilled exploit developers and you can't have privacy without also thwarting these constant attempts. (Paranoid as that may sound, I'm sure it's true for some people.) Most people would gain more privacy from doing something about the pervasive adtech than about exploit developers they're not likely to run into. For them, LineageOS could be more private and provide more freedom while being less secure in some ways (e.g. they need to watch out which processes they grant access, for example something claiming to be backup software that turns out to be ransomware) and more secure in others (e.g. data availability by getting to make backups)
Grapheneos is fully open source and comes with 0 Google services.
And calls the open source microG a threat while encouraging people to install google mobile services, conveniently provided from their preinstalled app store, which most people will need for at least some of the apps they need in daily life, so everyone ends up with GMS installed in their main profile. A real bastion of freedom and choice.
giving out root willy-nilly is not more freedom. It's more like letting your child play on the 5th floor of a half-constructed building that's about to be exploded
I take it you don't use desktop OSes anymore of any kind and call child support whenever you see a parent letting their kid use one? Better protect them from themselves in case they can't handle sudo / UAC prompts and give access (xkcd.com/1200) to the wrong process
This sort of logic really boggles my mind to see on hacker news
Nah, Android is not a really a proper Linux system that 'supports' Linux software within any reasonable definition of the word; not anymore at least
Root nowadays gets you very little: software like wavemon that worked great on Android 4.4 no longer runs because selinux or whatever restrictions block nearly everything from working that isn't going through the Android API channels. Accessing external storage from Linux Deploy (running your favorite distro in userspace with root) no longer works; thankfully it does from Termux so I have some way of manipulating the files with standard Linux tools, but then that keeps getting killed and you need to restart sshd a few times per day if you want to actually use that as a remote access method for your photos.
The Linux processes are being shot at left and right, it's go android or go bust on android. Perhaps that sounded redundant but it used to be that you could install Xorg, Virtualbox and other GUI software, and knock yourself out. No more
Oh, one vendor supporting multiple OSes! I hadn't clicked through (https://volla.online/en/operating-systems/), that is neat indeed and quite a unique selling point among mobile vendors
This should have gone in my spreadsheet before I chose a new device xD. Ah well, next time
The Pixel 8 Pro has hardware WiFi problems, the 9 and 10 are both minor updates
The prime difference between P8 pro and P9 pro is that the newer one is nearly a usable size (just about fits in a pocket now). The battery also got substantially better in two ways: on mobile data (when you're on someone's WiFi, odds are you're also near a charger) you get 33% longer use time on all variants of the P9 and 55% on the P10 and P10p (9 to 12 and 14 hours, respectively), and hours of use per 30 minutes of charging went up from 4.6 for the P8 to 6.3 for the P9(p) and 6.2 or 7 for the P10 and P10p, respectively
The rest is indeed relatively minor but it's not an unwelcome upgrade. Prices didn't change much when buying second-hand 1.5 years after release, when the newest devices are out and nobody cares about the generation-before-last despite >5 years of updates remaining (plus however long you think it's fine without updates)
Ah, right I forgot they are discontinuing ChromeOS. Makes sense that current Android releases are focused on getting the Android laptop experience on par
Edit: not discontinued but 'merge with Android' https://en.wikipedia.org/wiki/ChromeOS
I don't see anything they offer for security that's not also in AOSP/LineageOS/eOS/stock/etc.
Which is not to say that's not enough for most people, but why highlight them? It doesn't seem comparable to the laser-focus GrapheneOS has on security
Not without root, no
Hold the phone upside down for extra rollercoaster effect!
Probably the lesser known feature because it’s under Accessibility.
First thing I do on a new device is browse accessibility settings. They're among the most useful and I'm always excited for what extra features you can get if you just browse that section
For example turning off animations is somehow an accessibility thing, but it also just makes everything work instantly and you're not having to wait for animations to complete (which in the alarm app triggers a bug where it'll select the wrong hour if you didn't let it finish animating the hour dial before starting on the minute dial). Or finding out during initial browse that it can do autogenerated offline subtitles, that's a useful solution to know about when you want to watch a clip someone sent with relevant audio but can't listen to the audio
Not sure if the word 'modern' is meant to carry meaning there. Did/do you not get sick in non-modern cars? I could imagine less good soundproofing giving your brain extra clues or so but it seems odd. Are non-cars an issue (bus/train)?
Only if the other services provide a network proxy right? You'd need to find an exploit in the app otherwise.
Edit: although, I just remembered that it's actually as simple as sending "open this URL" intents to the Android equivalent of sensible-browser, which everyone will have installed. That does rely on users not understanding or caring about what's happening or it only works for the first user
Not in all app repositories. This isn't so common among open source software as it is in the commercial/adware ones you find very prominently in Google's curated collection
Any self-respecting OS has packet filtering, this isn't unique to or surprising from GrapheneOS. On my Samsung/OneUI I use AFWall+ which sets iptables rules iirc