HN user

pertique

85 karma
Posts0
Comments35
View on HN
No posts found.

This article is borderline malicious in how it skirts the facts.

This wasn't a case where KeePass was compromised in any way, as far as I can tell. This appears to be a basic case of a threat actor distributing a trojanized version via malicious ads. If users made sure they are getting the correct version, they were never in danger. That's not to say that a supply chain attack couldn't affect KeePass, but this article doesn't say that it has.

Principles and Gear 4 months ago

I'm of two minds on this. On one hand, I appreciate a good piece of gear and the feeling of having things just work. I think anyone who's been on a hunt and one day found a perfect something knows that spark of satisfaction every time you use it.

On the other hand, and this is probably isn't right, the brandification and fetishization of gear doesn't sit right with me. I ackownledge it's unfair - there should not be any difference between being proud of some thrifted hat and some fancy running shorts. Yet it still tripped me up.

Regardless, I can 100% corroborate the meat of the post. Running is, by far, one of the best ways to explore a new or old place. There's something about the pace of it that helps you notice details that you miss on a bike or when walking. At least, despite biking, walking, and driving through my last neighborhood for years, I'd regularly pick up on new things during runs.

Ghidra by NSA 5 months ago

What resources would you recommend now? Even if they're a year behind the meta, it's a lot easier to start a year behind than 6+

Can anyone speak to the reliability of using metropolitan statistical areas for something like this? Having lived across on both sides of the tracks in a few, grouping them for something like this seems like an interesting choice. One that I probably wouldn't agree with, but I'm out of my depth

Gmail to SQLite 1 year ago

I had the same problem when I switched off Google. I didn't have a ton of data, and I just wanted content for past search purposes, so I didn't dig into how the data would be transformed but I can at least offer my scuffed solution.

I installed a third-party client (Thunderbird, but I imagine any would work) on a local box, signed in with both emails, and just copied the mail over from one to the other. Low-tech, but it worked quite well. I may have forced some local cache/download for the original email, but I can't recall. I'll check later if it preserves headers and the like. I assume it would, but it wasn't that important to me.

I actually thought about writing at some point about the process of getting off gmail and all the funny things I ran across.

I can't personally vouch for it as I'm still stuck in Google Photos and would prefer to self-host it, but Ente may interest you. Open source, end-to-end encrypted, self-host or cloud.

That's very true, and I'd love to see some actual documentation on how they get to pace numbers.

I'm in the same boat with regard to 5K/10K pace, but I reckon it's probably not a huge issue in the long run. While plans specify those times, I think it's more about shorthand for effort zone where 5K is "this hard" and 10K is "a little bit less hard".

VO2 max improvement is a good point, though, and I'd probably agree. If I had a hazard a guess, Garmin would say that their training productivity tracker/race estimated are the preferred way of presenting that data. as an aside, I think VO2max has sorta been coopted as a "fitness number" when it actually represents a very specific thing that may or may not be emblematic of actual performance in the majority of cases. It is nice to have a a single value to look at that can sum up whether what you've been doing lately is productive, though.

That could just be me coming from the world of cycling where watts are king and there's far less variability. In my mind, all these running stats are mushy, but that might not actually be the case.

I'm hardly a serious runner, but I'd say the pros you laid out for Garmin are quite nice, and the cons are inconsequential to your average fitness tracker user. I'd probably argue they're inconsequential to everyone but the absolute elite and, for them, are pointless.

Sleep tracking is hard to action on for the average user outside "you slept this long" and none of the writst-based devices are that good anyway.

Pace to sub 5 is a little more annoying, but probably not useful for the majority considering most people are just running, not craning over their watch the whole time.

VO2 max is also a wild estimate, and I'd hazard it's not particularly accurate for the average person. It's off by close to 20% for me, and I should be a pretty good candidate.

On the flipside, you can get tons of data out of a Garmin that costs significantly less than an Apple watch. Plus, the majority of Garmins sold are fitness devices with some smart features, with Apple watches being primarily a smart watch. While maybe not justified (I think the Apple watch features are quite nice) I'd expect that's a major part of the reason Garmin has the rep it does.

If someone is buying a device to run, most would recommend the cheaper, light, simple, specialized, long battery life watch over the opposite. If you already have an Apple watch, it's probably a no brainer. For the high-end Garmin devices, it's a little more complex, but not many people are considering a US$800+ device without knowing the nuances of the discussion, or having enough money to not care.

Why GitHub won 2 years ago

I agree with a lot of the other options, but I'd be remiss if I didn't mention one that isn't always obvious.

With all the Big Corp asterisks, Microsoft Business Basic can be a pretty great deal at 6 USD/month. Solid reliability, aliases, (too many) config options, 1TB of OneDrive storage, cloud MS apps, etc.

It is. From my understanding, CPUs execute machine code. Assembly has to be passed through an assembler to get machine code, and that assembler can make other changes as well, so they are not always one to one. Written assembly will usually translate veryclosely to machine code, though.

If you use a password manager (which they say they do) it's much quicker to just save that info and automatically populate it. Doubly so considering the MFA hell they went through.

It'd definitely be possible although, if you're not already using a VPN, I doubt it'd be easier. You could do it a few ways, but the gist would be running the VPN endpoint and the web app in the "same place" (same machine, same network, etc.) and restrict access to the web app from anywhere else.

Do you have other info on languages that do? In my mind, if a library is compromised and incorporated in software that touches sensitive data then there's no way to meaningfully sandbox it. Sure, the library lives in the sandbox, but so does the stuff you're trying to protect. I'm not sure that's a Rust-specific problem.

The author actually brings this up in the article, and it seems that they are not likely to be deleted (baring vandalism due to their unique status being surfaced, I guess).

Spoiler for the interested, and it could be an artifact of the dataset the author used, but one of the commonalities between the least viewed articles is that their subject matter falls into a category that isn't usually eligible for deletion under Wikipedia content guidelines.

This is what I got on a basically brand new OpenAI account: https://chat.openai.com/share/5199c972-478d-406f-9092-061a6b...

All told, I'd say it's a decent answer.

Edit: I took it to completion:https://chat.openai.com/c/6cdd92f1-487a-4e1c-ab94-f2bdbf282d...

These were the first responses each time, with no massaging/retires/leading answers. I will say it's not entirely there. I re-ran the initial question a few times afterwards and one was basically giberish.

This is what I do, and I'm surprised that more people don't. It's trivial to clear text or email notifications when you make the purchase as they usually appear very quickly. Plus it makes it very easy to identify fraud.

Get a notification that your card was used at a gas station when you're in bed at 11pm and last filled up 5 days ago? Probably not legitimate. Plus, if you trust your CC company, it saves you from having to review your charges at statement close.

I'd probably take the more charitable view that usage of the phrase in the negative is a willingness to embrace the spirit of the saying rather than attribute it to a misunderstanding.

If it is a misunderstanding, that is. While all sources I've seen sdo agree the phrase is of military origin, the Ngram shows usage as early as 1908 [1], with usage between 1930 and 1955 in English fiction [2]. Maybe the origin of the phrase predates the pointless numbered hills of the Vietnam War, and perhaps those hills had value and were worth dying on.

Not that this is a hill I'm willing to die on, though. All I wanted to point out is that the opposite phrase is used often per past experience, and Google Trends [3]. I can't actually find any trend data for the "original," but it is used.

[1] https://books.google.com/ngrams/graph?content=hill+to+die+on...

[2] https://books.google.com/ngrams/graph?content=hill+to+die+on...

[3] https://trends.google.com/trends/explore?date=all&geo=US&q=w...

If there was no corollary hill worth dying on then there'd be no reason to specify that the hill in question wasn't worth dying on. Thus, we can assume there are hills worth dying on.

Anecdotally, I think I hear the "I will die on this hill" variant more than the converse.

While I've never used Google's toilets, cleaning your asshole using a water spray is usually accomplished by a bidet. They're somewhat common in toilets in parts of Europe, and quite common in Japan. It's preference, but people usually like them.

That being said, if the toilet component sucked then the whole experience will suck. I just wouldn't discount ass-spraying toilets from one bad toilet.

EDIT: Almost all the toilets with bidets I've used have also had manual flush options, although the UX is hit or miss.

The E-Ink Badge 3 years ago

Not the commenter you asked, but in the United States pumps with one hose are common. All the grades of petrol are dispensed through the same hose, and you just select which one you want.

Some pumps do have two (or more) hoses, especially those that have multiple types of fuel (one for regular petrol, and one for diesel). Some pumps for also have separate hoses for each grade, although they seem less common to me.

It'd depend on the field (and region), I imagine, but after the first job or two I feel like all that matters with respect to schooling is that you went. Five or ten years into a career I'd be surprised if coursework that hadn't been used on the job was relevant, and GPA wouldn't even be considered.

Hobbies are probably not that useful either, but I could see them catching a hiring manager's eye. Coursework probably won't have the same effect, although I suppose it could help you get through ATS.

I won't speak for the parent comment, and this isn't a critique on you, but I think it's more of a reflection on the reader than an ironic take.

Many would read "I should be worth more than..." as "I should have more money than...", but that's exactly what the parent comment is railing against. In the corporate world, and especially in the startup space, money is often the metric that defines worth. In the parent comment's world, I imagine they would rather that not be the case, and by <some other metric> they would be worth more than these startups/"money is god programmers" that are "only" worth money.

It could've been put a bit more nicely by not implying the reader is a 'money is god programmer,' but otherwise it's a valid opinion, I think.

It's very common in the US, at least the parts I've been. It depends on the restaurant, of course, but most places will provide a takeout box to take home uneaten food if you ask.

In fact, it's not uncommon for the waiter to offer a box unprompted if you have a fair amount of leftover food.