HN user

notpushkin

7,041 karma

[Verifying my OpenPGP key: https://keyoxide.org/dbed7086f4662ac59eaa343536271a1d783b07c4]

alexander@notpushk.in

Posts121
Comments2,385
View on HN
hackaday.com 2mo ago

Your browser probably lies to the big sites (blame Chrome)

notpushkin
1pts0
github.com 5mo ago

Nix isOdd

notpushkin
1pts0
www.osnews.com 6mo ago

HP-UX hits end-of-life today, and I'm sad

notpushkin
8pts3
github.com 10mo ago

tailscale-initramfs

notpushkin
5pts0
matrix.org 1y ago

Upcoming coordinated security fix for all Matrix server implementations

notpushkin
172pts95
tuta.com 1y ago

Open letter against ProtectEU (a.k.a. Chat Control)

notpushkin
2pts0
soundcloud.com 1y ago

Windows 7 x64 MS Paint EXE Interpereted as PCM Data

notpushkin
2pts1
osmocom.org 1y ago

Make VoWiFi calls using Asterisk and strongSwan

notpushkin
2pts0
mozillapetition.com 1y ago

Tell Mozilla: it's time to ditch Google

notpushkin
424pts443
github.com 1y ago

AbsurdSQL – IndexedDB as a persistent back end for SQLite

notpushkin
3pts2
www.home-assistant.io 1y ago

Home Assistant Voice

notpushkin
4pts1
buckwheat.app 1y ago

Buckwheat: An Android app that helps you spend money wisely

notpushkin
2pts0
basecamp.com 1y ago

Decisions are temporary, so make the call and move on

notpushkin
3pts0
hackaday.com 1y ago

Mac OS on an unmodified Wii (2022)

notpushkin
21pts3
github.com 1y ago

Better Than Nothing – a Pi Pico-based hardware wallet

notpushkin
4pts3
github.com 1y ago

Google Play Integrity support lands in microG

notpushkin
1pts0
cardgames.io 1y ago

CardGames.io Bridge

notpushkin
1pts1
news.ycombinator.com 1y ago

Ask HN: How is your job search going?

notpushkin
50pts51
github.com 1y ago

git-credential-oauth

notpushkin
2pts0
github.com 1y ago

Offline UX Patterns

notpushkin
124pts24
www.theverge.com 1y ago

Snapchat's AI selfie feature puts your face in personalized ads

notpushkin
1pts0
nuitka.net 1y ago

Nuitka: Optimizing Python compiler compatible with CPython

notpushkin
3pts2
xon.sh 1y ago

Xonsh is a Python-powered shell

notpushkin
3pts0
github.com 1y ago

Audile: Open-source Android music recognition app

notpushkin
3pts0
ergaster.org 1y ago

Why are open source nonprofits so weird?

notpushkin
3pts0
mystmd.org 1y ago

MyST: rST Roles and Directives in Markdown

notpushkin
2pts0
www.rrweb.io 2y ago

Rrweb – record and replay debugger for the web

notpushkin
177pts33
simonwillison.net 2y ago

Chrome makes CPU info available to code running on *.google.com

notpushkin
2pts1
en.wikipedia.org 2y ago

Backslash History

notpushkin
2pts0
github.com 2y ago

libSQL, a fork of SQLite accepting third-party contributions

notpushkin
2pts0

1. I’ve added the ⌘V remark on the first slide (it was the only way I could add anything in the previous epoch at all!). Hope it helps others have fun in the meanwhile.

2. Absolutely fair point, and it’s okay – the demo speaks for itself :-) Although if you wrote that submission text yourself, you do write pretty well! But obviously no pressure here.

Go to https://bento.page/guestbook/ to try out the live guestbook to experience share editing / collab.

My M1 Mac froze in the end (had to hard-reboot), but that was so much fun! I guess there’s a reason Figma uses WASM and a custom renderer, though I guess your implementation should work fine for most cases (i.e. not when all of HN are trying to edit everything simultaneously :^)

Two notes:

1. It would be nice if another person changing something unrelated to what I’m doing didn’t reset the focus for me.

2. WAY too llm-y copy both on the landing page and the example deck. Your HN submission text is way easier and more pleasant to read.

And huge kudos for releasing this as FOSS!

I don’t really care. I’m just... disappointed a bit? It seems like a cool project, but those “concise sentences” don’t make it easier to learn about it.

  no passwords. no OAuth. no accounts.
  your ssh key is your identity.

  chats, scores, and streaks are tied to your public key fingerprint. same key, same data.
No accounts? How is that possible? You literally store my data! Is that not an account?

And what the fuck is OAuth? (Okay, this clearly is oriented at developers, but on its own the sentence just doesn’t make sense. For me as a user, what pain is removed by not having a “Sign in with GitHub” button? Why should I care?)

How about you tell me why you decided to do it that way:

  all your data – chats, scores, streaks – is tied to your ssh public key.
  no need to come up with a password or verify your email – just ssh in.
It took me a couple of minutes to write this, sure, but at least it now makes sense. And it’s more concise, no? (It still sounds llm-y to me, but whatever.)

Now, for bonus points, there’s two obvious questions to answer:

• what do I do if I lose my SSH key?

• what do I do if I use more than one device?

(The obvious answers are “you can add other SSH keys in your account settings” and “you can add other SSH keys in your account settings”.)

---

Okay, one more, and then I need to go grab a beer.

  a read-only peek at the TUI in your browser.
  tab around, see what's inside.
  
  no typing, no chat, no games — just a window
  into a shared demo session.

  for the real thing, `ssh late.sh`.
Concise?
  a read-only preview of late.sh in your browser.
  poke around and see what's inside. `ssh late.sh` when you’re ready to chat and play.

No X. No Y. A is your B.

We do G, not H. C, D, E — plus an optional F.

No I, no J, no K — just an L into a W.

I would say the design is the most human thing about this page. (It has its charm somehow, even if it’s obviously “flavour of the week LLM design”. Also, I don’t think an LLM would choose colours so poorly unless nudged in that direction – accidentally, I suppose.)

HMD Touch 4G 3 days ago

They could do Telegram at least, which has a non-zero user base (not sure about India, though, which seems to be their target market), and supports third party clients. Rolling their own chat app is... well, good luck with that.

The thing with ATProto is, there is little incentive in creating apps that speak the app.bsky vocabulary. If I understand correctly, there is one other full-fledged app that does that, Blacksky [0]. By full-fledged, I mean they host a PDS, a relay, an app view, a moderation service, and a bunch of feeds and other doodads. If Bluesky goes down, Blacksky will probably be fine. They are, however, yet another US company [1], which is not ideal.

[0] https://docs.blacksky.community/

[1] https://blackskyweb.xyz/about/support/tos/#:~:text=Blacksky%...

I guess that’s fair, too. I’m not really into podcasts either, and the ecosystem seems healthy enough. Many FOSS podcast clients use Apple for discovery, which I guess make sense; but there’s probably other databases, and the contents themselves aren’t usually hosted by Apple, just the metadata.

So yeah, podcasts are in good shape. In fact, they are probably the most used decentralized media right now (apart from torrents, maybe). I hope Bluesky gets to that point, and I do wish them luck, but we’ve got to see the incentives are not that well aligned. As for the trademark... it’s surely weird, it’s not the end of the world if they continue to hold it, but setting up a non-profit (not in US, perhaps) for the protocol itself would probably be more appropriate down the road.

It makes sense to talk about “RSS aggregators”. Especially it makes sense to talk about “RSS aggregators that speak a specific vocabulary on top of RSS, host 99% of content using that vocabulary, and if you host your own RSS feed with said vocabulary they’ll show it in their aggregator but can ban it any minute”.

Did I just describe Apple Podcasts? Huh. Regardless, yeah, there’s no “ATProto instances” technically, but there are ATProto apps and the single biggest one now owns the trademark to the protocol name.

This is very cool and thanks for sharing the workflow, buuuuuut... Could you please rewrite the README in your own words? If not for this comment, I would have just flagged this submission without looking into it further, because no matter how useful the premise is, it feels like one of the millions “I’ve burnt a bunch of tokens and thrown the result on GitHub” kinda projects you see nowadays. Clearly that’s not the case here, but an LLM-generated README really does your project a disservice.

It is true, yeah. But it allows you to own the brand identity, which is kinda useful if you have a brand.

I think we’ve found the holy grail with one of my clients recently. Our UI kit follows https://mui.com/ wherever makes sense, but we implement the components ourselves. This means (1) we don’t have to make too many architecture decisions – we just do whatever MUI does, and (2) it’s fairly easy to push back against adding features that don’t add a lot of value and deviate too much from, well, whatever MUI does.

Honestly that’s about the only thing I like in shadcn. It makes scaffolding your UI kit extremely easy, but then you own it and can extend it in whatever way makes sense for you. Unfortunately I’m allergic to Tailwind, and React-only makes it a no-go for me, too :(

There are alternatives, of course, but what I’d like to see is a kinda unified component API spec that you can implement however you like, which both humans and AI can pick up without having to learn whatever idiosyncratic props you might have chosen. So I guess, I’d like to see other libraries use shadcn props with “sane”¹ implementation under the hood?

(¹ – in my case, just plain old Svelte components with inline CSS and/or CSS modules :-)

My main gripe with Shadcn and, well, most UI libraries nowadays, is that they are reinventing the wheel for like a thousandth time.

I’m trying out Ark UI on a side project. They do have some genuinely useful components, like tags input: https://ark-ui.com/docs/components/tags-input

They have a tabs/“segment group” component with a nice animated active element indicator which would probably be tricky to implement: https://ark-ui.com/docs/components/segment-group

And then they also have stuff like overcomplicated “click to copy” button and a <details> reimplementation: https://ark-ui.com/docs/components/clipboard, https://ark-ui.com/docs/components/collapsible

All with a verbose markup that renders as a div soup.

I’m leaning towards vendoring for all my new projects.

Grabbing an off-the-shelf UI library is easy in the short term, but it’s usually overcomplicated, implements things I won’t ever need, is hard to tweak if/when you want to distinguish your app from the thousand others using the same library, and when you do decide to upgrade it, all your tweaks break in subtle ways.

What I think would be the best approach is building your own UI library. You own it, you get to reuse it across different projects and maintain the same visual style (if desired), and you add features when you need them.

Russians will just share it back (I’m saying that as a Russian). And if not Russians, then somebody else will.

What you can do is make sure people can pay you easily, and not put (a lot of) hurdles in your readers way. And when people can’t afford to pay... maybe let them enjoy your work still, and you’ll get a couple more loyal fans who would pay you when they’re able to.

At least this was my world view before AI has arrived and ruined^W disrupted everything. Now I’m not so sure.

Okay, that one is on me indeed. I’ve re-watched it at 0.5× and he does make 8 taps indeed. Apparently, only the first and the last are registered then. Sorry for the confusion!

Then I definitely need to get some caffeine I guess *yawns*

And it would be so much more predictable and pleasant if you could just tap the button three times at any pace you wanted without thinking, without paying attention, without getting your UI blocked by an animation that no longer helps you.

Am I misreading this?

The author says: “Now, I’m going to exaggerate the problem a bit and tap 90-degree rotation quickly eight times.” I was wondering why the Nothing one stuck upside down after that, and expected a rant about Android not registering all taps or something. But the article got ahead with explaining how the Nothing’s solution was better. Huh?

The iPhone was eight taps. The Nothing was six. (Yeah, I could have noticed it while watching, but I was situationally incapacitated; namely, I’ve just waken up.)

---

Edit: I’ve rewatched it at 0.5× and the Nothing was eight taps after all, too. Author’s point was, indeed, that all taps should register regardless of what animation state is, and Nothing doesn’t do that. Sorry for the confusion!

---

Regardless! I still find the iPhone one more pleasant to look at, because the animation doesn’t stop. But if you press quickly enough, I guess what they could do is animate until the taps stop, then:

• if the image will arrive to the desired state: finish up the current 90°;

• if it’ll still be 90° away: finish up then show one more 90°;

• if it’ll be 180° away: flip it upside down, then finish up the current 90°;

• if it’ll be 270° away: flip it upside down, finish up, and show one more 90°.

But that’s not a very practical thing to implement I suppose.

This is an RFC with "recommended to implement = N" marked about how to do PQ TLS 1.3 in environemnts where hybrids are too expensive

I think the argument boils down to this, yeah.

I am not a cryptographer, nor I’m participating in IETF (yet :), but he does make a good argument on why sticking with a hybrid for the time being makes sense (in between of all the NSA tinfoil hat stuff). And from an outsider point of view, publishing this as an RFC would somewhat legitimize using ML-KEM alone even though it’s marked as Recommended: N. (I would rather prefer waiting until we can publish it as Recommended: Y instead!)

If there are environments where ECDHE-MLKEM is really that much more expensive than ML-KEM alone, could we figure out another hybrid construction instead? E.g. one that only uses SHA3, if that’s the problem.

It provides no security, so why would anyone ever accept it a proof of identity?

Because there is no other universal method that works online, and because companies don’t really care about identity verification – they just need something “good enough” so that they can say “hey, we’ve followed industry standard protocols, how could we have known this passport scan was photoshopped?”

And to be honest I think it’s for the best. I really don’t want to be scrutinized even more online (and give even more personal data so it gets leaked a couple years later).