HN user

pferde

3,547 karma
Posts71
Comments1,203
View on HN
brr.fyi 2y ago

Pressure Altitude – Day-to-Day Variability at the South Pole

pferde
2pts0
fediversereport.com 3y ago

Dutch government officially launches Mastodon server

pferde
3pts2
www.w3.org 3y ago

First Public Working Draft: Compute Pressure Level 1

pferde
2pts0
www.gamingonlinux.com 3y ago

Beware of Scam Steam Deck and Steam Account Stores

pferde
2pts1
blog.codeberg.org 3y ago

Codeberg is moving and what this means to you

pferde
119pts51
www.hughrundle.net 3y ago

Home Invasion – Mastodon's Eternal September Begins

pferde
9pts4
blog.mollywhite.net 3y ago

Is Web3 Bullshit? (Transcript)

pferde
124pts176
www.securityweek.com 4y ago

Log4j Software Flaw 'Endemic,' New Cyber Safety Panel Says

pferde
1pts0
www.reuters.com 4y ago

Global automakers face electric shock in China

pferde
2pts1
www.theguardian.com 4y ago

‘No hope for science in Russia’: the academics trying to flee to the west

pferde
9pts0
eev.ee 4y ago

Old CSS, New CSS (2020)

pferde
284pts97
www.rockpapershotgun.com 4y ago

Union survey alleges culture of mistreatment at Paradox Interactive

pferde
2pts0
www.reuters.com 5y ago

China makes desalination push to ease water scarcity

pferde
1pts0
www.universetoday.com 5y ago

Move over Artemis Accords Behold Lunar Governance Report and Eagle Manifesto

pferde
1pts0
www.wired.com 5y ago

Russia May Have Found a New Way to Censor the Internet

pferde
5pts0
www.gamingonlinux.com 5y ago

Is opening up your source code worth it? Terry Cavanagh thinks it was for VVVVVV

pferde
65pts16
eev.ee 5y ago

Gamedev from Scratch 0: Groundwork

pferde
2pts0
blog.davidedmundson.co.uk 6y ago

Running Kwin Wayland on Nvidia

pferde
2pts0
www.wired.com 6y ago

The 5G Coronavirus Conspiracy Theory Has Taken a Dark Turn

pferde
6pts0
www.wired.com 6y ago

Signal Threatens to Leave the US If Earn IT Act Passes

pferde
82pts3
lists.gnu.org 6y ago

Automake-1.16.2 Released [Stable]

pferde
5pts0
thenewstack.io 6y ago

Why Bruce Perens Is Proposing ‘Coherent Open Source’

pferde
1pts0
www.wired.com 6y ago

Identity Activist Wants to Make Facebook Obsolete

pferde
1pts0
www.gamingonlinux.com 6y ago

Valve continue working behind the scenes for Linux gaming with 'Gamescope'

pferde
2pts0
www.wired.com 6y ago

Facebook Says Encrypting Messenger by Default Will Take Years

pferde
2pts0
www.wired.com 6y ago

A Facebook Bug Exposed Anonymous Admins of Pages

pferde
50pts14
www.wired.com 6y ago

Creditors Seek to Exhume the Body of a Dead Crypto[Currency] Executive

pferde
3pts0
davidalfonso.es 6y ago

FOSS Zombies

pferde
42pts17
coconuts.co 6y ago

Three Bangkok roads to become regular ‘walking streets’

pferde
2pts0
www.wired.com 6y ago

The Debate over How to Encrypt the Internet of Things

pferde
2pts0

If it used one of the standard system APIs for looking up user accounts (e.g. getpwnam(3)), there's no way it can happen.

This is incredibly bad engineering, on level of a SQL injection, in 21st century. Something a highschool student experimenting with scripting could come up with, but not a supposedly professional software company.

The proper fix would be to not use getent CLI tool in their logic, but instead use proper system APIs for looking up user account entries, like one of earlier comments here already mentions. This is shocking amateur hour!

My guess is they hastily threw together something hacky in early development, and forgot to replace it with a real, safe solution later.

I guess my (badly conveyed) point was that Anki is already so efficient for me that I don't feel the need anything more.

Well, not for vocabulary, anyway. There is more to learning a language than vocabulary. :)

I have the exact opposite experience with Anki. I use it to memorize vocabulary of a language I'm learning, a language completely different to other languages I know, and my retention before and after I started using Anki is night and day. Frankly, I was floored once I realized how much faster I was learning, and how easily I can recall even words I last practiced or used months ago.

I make and maintain my own cards/notes, which I think is part of why it works so well - it's tailored to my learning, not to someone else's.

That's because Unified Attestation is unsalvageable. It's basically the same scam as Google's, with different owners doing (or wanting to do) the extortion.

I'd like to point out that it only "gets pulled in" if the data is actually made available by the government, and there are dedicated volunteers who work on getting the data, massaging it into the right format and importing it into OSM, and that is not the case in many countries.

The seemingly duplicate data on crossing is because there are different "parts" of the crossing, intended for different users.

There is the path across the road, usually from one sidewalk to the opposite, which is meant for pedestrians, and there is the node where this path touches the road, which is meant for car drivers.

Yes, the system could be improved by grouping these somehow, maybe using relations (https://wiki.openstreetmap.org/wiki/Relation ), but that would add complexity to any navigation or rendering application using OSM data that wants to process information about crossings.

Can you give examples of what you consider "nasty attitude" on their part? All criticism of other project I've seen was either cold, clinical technical criticism, or defense against slander propagated in the media against GrapheneOS.

I haven't seen GrapheneOS folks going out of their way to attack anyone.

That, not being sure if the submitter is willing to meet you part way, is exactly the miserable part I am talking about. Basically, you go in risking it's just a waste of your time. After some trust is established, or when the PR is from someone you already have some trust relationship, the dynamics are very different.

Yes, it can still be a slog to review someone else's code, but you usually have the feeling of "hey, this is probably something good".

No, reviewing PRs in general is a delightful process. The tedious part is in the initial triage when the PR comes from a previously unknown submitter, and you cannot be sure what is the intention of the submitter, what is their technical level, whether they are talking out of their ass or not.

It's basically the same issue as spam in emails. It was bad before, and automation made it a zillion times worse.

For a model that claims to focus on many languages, it's quite unreliable when it comes to simple questions like "how to say X in language Y" or "how to conjugate verb X in language Y". It keeps hallucinating words that do not exist, and when corrected, it only hallucinates a new lie.

If you actually take the time to look for posts and communities about things you care about, you'll find more than enough of interesting people. It's just that there is no algorithm to feed you content, you have to be active in looking for it, at least initially.

I'm not necessarily saying you made this mistake, but plenty of other people who dip their toe in the fediverse do this - they get in, find nothing in their feed, they shrug and forget about it. A good start is to search for a few hashtags that match your interests, even add a follow for those if you see they're active, and soon you'll start seeing interesting people. I've been on there for years, and I'm always amazed at the small niche discussion threads I find.