HN user

pimterry

10,297 karma

Building httptoolkit.com - HTTP debugging, testing & development tools

More about me: tim.fyi

Posts380
Comments573
View on HN
www.iroh.computer 12d ago

The Road to Iroh 1.0

pimterry
2pts0
www.theguardian.com 26d ago

OpenAI staggers AI model release after Trump administration request

pimterry
1pts1
dare-riscv.eu 1mo ago

Digital Autonomy with RISC-V in Europe

pimterry
3pts0
docs.npmjs.com 2mo ago

Staged Publishing for NPM Packages

pimterry
4pts0
hackerone.com 3mo ago

The Internet Bug Bounty paused indefinitely

pimterry
2pts0
bunny.net 4mo ago

Migrating from Heroku to Magic Containers

pimterry
36pts12
react.dev 4mo ago

A New Home for React Hosted by the Linux Foundation

pimterry
2pts0
paultendo.github.io 4mo ago

Confusables.txt and NFKC disagree on 31 characters

pimterry
60pts40
httptoolkit.com 4mo ago

Dictionary Compression is finally here, and it's ridiculously good

pimterry
39pts18
nlnet.nl 7mo ago

NLnet announces funding for 45 more open-source digital infrastructure projects

pimterry
34pts0
meshtastic.org 11mo ago

Meshtastic: Open-source off-grid decentralized mesh networking

pimterry
2pts0
github.blog 12mo ago

We Need a European Sovereign Tech Fund

pimterry
16pts0
patriksvensson.se 1y ago

Introducing OpenCLI

pimterry
6pts0
robertheaton.com 1y ago

MinorMiner: We turn your kid's maths homework into Bitcoin

pimterry
56pts11
httptoolkit.com 1y ago

HTTP/3 is everywhere but nowhere

pimterry
8pts0
www.economist.com 1y ago

What Spain can teach the rest of Europe

pimterry
6pts2
www.macrumors.com 1y ago

Apple Faces Epic Games-Style China Lawsuit over App Store Practices

pimterry
4pts0
httptoolkit.com 1y ago

HTTP Toolkit Is Joining the Open Source Pledge

pimterry
2pts0
9to5mac.com 1y ago

New macOS Sequoia permission prompts: a subscription you can't cancel

pimterry
10pts1
appleinsider.com 2y ago

Apple will restore Epic Games' developer account in the EU

pimterry
2pts0
digital-strategy.ec.europa.eu 2y ago

European Data Act enters into force

pimterry
3pts0
httptoolkit.com 2y ago

22 years later, YAML now has a media type

pimterry
4pts1
emilymstark.com 2y ago

E2EE on the web: is the web that bad?

pimterry
1pts0
appleinsider.com 2y ago

Don't read too much into early Apple Vision Pro app sales

pimterry
1pts0
pyfound.blogspot.com 2y ago

EU's Cyber Resilience Act Passes with Wins for Open Source

pimterry
3pts0
httptoolkit.com 2y ago

What is X-Forwarded-For, and when can you trust it?

pimterry
2pts0
github.com 2y ago

Haier's attempted-then-withdrawn HomeAssistant integration cease and desist

pimterry
2pts0
papereditor.app 2y ago

9 years of Apple text editor solo dev

pimterry
740pts378
graphite.dev 2y ago

Empirically supported code review best practices

pimterry
3pts0
www.bsc.es 2y ago

Marenostrum 5 starts up, combining #8 and #19 of top supercomputers worldwide

pimterry
1pts0

It's an anti-competitive concern all the time.

If we gatekeep service access to specific implementation attestations, it becomes much harder for new implementations to emerge. It doesn't really matter who controls the process.

In that sense, it's always bad. In this specific scenario for example it directly blocks emergence of alternative Android ROMs and Android-mostly-compatible devices like the various Linux phones.

There may be times where that downside is worthwhile, but it's always a downside, and we should very strongly discourage attestation wherever possible on that basis for the health of both the tech ecosystem and the business market around it.

There's a compatibility list at https://privsec.dev/posts/android/banking-applications-compa....

I think the challenges here exist but the reality is overblown to be honest, the vast majority of banking apps (everything that isn't struck through in that list) work just fine.

Fully agree the concern is discouraging adoption though. I would love to see more of a solution here, it seems like purely anti-competitive behaviour by Android that will block competitors emerging.

I mean sure, I'm not intending this to be quoted in a court, honestly I would say all my online comments are irrelevant phrases!

That said - it is their business, they're broadly well reviewed, and they're clearly incentivised to give scrubbing your data out a good go.

More generally, if you're in a jurisdiction with GDPR-like rules (which is a lot of the world nowadays) the brokers themselves have formal policies & tools for removing your data and chasing people manually myself occasionally I've found it quite effective.

You're certainly not going to get anything removed from any three-letter agencies or purely malicious people. Most of the discussion here though is around data brokers, who are generally large serious businesses who will at least follow the letter of the law. You've got pretty good odds of getting your data removed from any non-trivial businesses, if you follow their carefully hidden data collection policy links and then quote your local legislation and their privacy team in a polite but firm (and repetitive) way.

Some scepticism here I see, but personally I think this is spot-on. I've been keen on a dumber phone for a while, but losing whatsapp & maps makes it a non-starter for any real use. This is an excellent middle ground. The aesthetic is cool, and building this on Sailfish but with Android compatibility is awesome. Big fan of the concept.

Today, in 2026, as a Spanish resident, I still can't access https://www.womenonweb.org/. Why? Who knows anymore. Fucking money + religion owns our digital spaces now, been for a long time, no one seemingly noticed.

I didn't know about this, so I looked it up: it's because they sell prescription-only abortion medication and ship directly to consumers, where it's legally only available via prescription and medical oversight. Fundamentally they're blocked for ignoring medical regulations. There were some appeals, but the argument is that access to abortion medication is already a well-protected right, so that this is dangerous and unnecessary, and it's not possible to block that while unblocking the rest of their educational resources.

Let's not pretend that Spain of all places is caring about horribly destructive psuedo-gambling.

Is this intended to imply that Spain has particularly high levels of sports betting, or issues with gambling? All the stats I can see suggest the opposite, and there's already plenty of tight restrictions on local gambling businesses (sports sponsorship ban, welcome bonus ban, almost no public advertising, etc). At a quick google, it looks like the 'Spanish gambling racket' for sports is tiny, gambling problem stats far lower than UK/France/Italy, and most gambling that does happen is the lotteries etc instead, which has its sins, but is a very different beast.

Is there something specific you're getting at?

Given EuroPA has done a token amount of transactions to date, I’m not sure anyone should hold their breaths.

The Spanish equivalent (Bizum) is merging into Wero is not a token use case, it's absolutely massive here. The absolute standard for peer-to-peer payments, more than 30 million users (>65% of the population), and they already launched contactless terminals for in-person commercial payments this month (https://euroweeklynews.com/2026/04/03/bizum-goes-contactless...).

This is begging for anti-competitive investigations, surely? It's explicit collusion between the largest mobile makers and key app-based services (e.g. gov services, communication tools, banking) to directly block any competing OS.

They're publicly agreeing that only users using their approved mobile devices are allowed to do banking, and competitors cannot. I'm not sure how much more clearly anti-competitive this could be.

Because (like every IoT product) Bambu want to sell a product with an easy app-powered workflow, and LAN device discovery and remote-access for home devices from mobile apps is flaky and terrible.

I wouldn't be surprised if they're slurping telemetry en route, and it's convenient for them that using their app helps nudge you towards Makerworld (their ecosystem for 3d prints, which is presumably good marketing) but I very strongly suspect "make it effortless for non-technical users to use the device with just a phone" was the original & primary driver.

As far as I can tell, they're just objecting to use of their cloud service. You can fork their software and use it with your own printer just fine, they just don't want you to use it with their cloud service, which its own terms of service for access.

I think it's an odd hill for them to die on, but it's not a totally unreasonable position - the cloud is other people's computers, other people can have rules about what you can do with their computers. Just because a client is open-source, doesn't mean you're allowed to use the server.

If you're using developer mode running everything locally (or remotely over your own VPN, like the author here) then I think this makes zero difference.

This has been widely discussed, and initial implementations exist: the EU digital wallets are doing exactly this. https://ec.europa.eu/digital-building-blocks/sites/spaces/EU....

In theory, every EU state will have to support this soon so users can use it to verify age privately online. Still work to do to roll this out for real, but the technological part is very much already happening and I think the rollout plan is committed.

StarFighter 16-Inch 3 months ago

Clearly! I see how this is a bit unusual for GDPR etc in a services digital world, but for physical products it's extremely standard everywhere that local laws apply to foreign companies.

If you sell medical devices (apparently even down to toothbrushes) in the USA, you have to follow FDA rules. If you sell children's toys in the EU, you've had to follow EU consumer regulations (e.g. CE mark) at least since the 90s. Going back to the 70s, if you sold a physical product in the US as a foreign company you had to follow local rules about maximum delivery times and minimum warranties. If you don't follow the rules, your shipments get blocked at customs, and any marketplaces (Amazon) selling your products get fines as well for not verifying you appropriately, so marketplaces will verify and ban your business too if you blatantly violate local rules (e.g. selling devices containing radios without FCC approval). If you're selling laptops at any scale, you need to follow the local rules for every country you ship to.

There'll certainly be cases everywhere where enforcement isn't perfect (if you contact a tiny vendor in China and they ship to you directly and you sign for & pay the customs yourself, in practice you'll get away with it, or you can always travel to a country to buy a product and carry it back personally) but in the general case local regs on physical product sales are not unusual or optional at all.

Most of the facts exposed are likely inferable anyway, or certainly were in a non-GDPR tracking world. I think it'd be clear from my browsing patterns that I'm over 18, and broad tracking + IP checks could quite easily infer where I actually live at least to a national level, I'd be confident that e.g. Meta already know this without being told. Given that, I'm not too worried about exposing residency + over-18 status, the fingerprinting bits are redundant.

Whether it's actually anonymous in practice, and/or whether it starts to go further than that (websites asking for verified gender? First name? City? Full DOB?) will be a real concern but I think there'd be plenty of push back and tech will end up setting norms here through the browser APIs & permissions prompts. In theory in this is all covered under GDPR anyway so requesting or storing information that's not necessary is illegal anyway, and at least explicit requests are less secret than invisible tracking of the same thing - much easier to reject individually, and to litigate abuse collectively.

The upcoming EU digital wallets in theory could do this kind of thing. They're focused on anonymity preserving age verification right now, but exposing any other government-verified attribute anonymously should be equally possible, including residency and/or citizenship if that's your bag.

EV no longer skips smartscreen either nowadays. I understand that was abused, so it's treated as the same as OV. Having a certificate allows the cert itself to accumulate trust (rather than each binary independently doing so) and provides better UX and I suspect an initial small boost to trust signal, but doesn't bypass the initial distrust. There's no way to avoid that AFAICT and even if you're an established business you hit it at intervals because all these certificates expire and so the whole process resets every few years anyway. What a mess.

no Gov agency would ever mandate secure firmware

Interestingly, Europe is about to try this: the Cyber Resilience Act is going to become obligatory for all sold digital products (hardware & software) by the end of 2027, with a bunch of strict minimum requirements: no hardcoded default passwords, must check for known vulnerabilities in components/dependencies, encryption for data at rest, automatic security updates by default (which must be separate from functionality updates), etc.

Remains to be seen whether this'll help, but good to see somebody have a go at fixing this.

Europe is less industrial than in the past, but by every measure I can find many countries (especially Germany, Poland, Slovakia, Italy) are significantly more industrialized than the US - around 1.5x to 3x as much industrial activity and employment per capita, depending on the measure. Even the very least industrialized of the major EU nations (e.g. Spain, Greece) only just drop down to match the US numbers per-capita.

Keep Android Open 5 months ago

Done! I wrote up both my concerns about this and how it affects app/app-store market competition, and how limitations like Play Integrity encourage apps to block usage on non-Google approved devices as well, since that's anti-competitive within the mobile device & OS market (blocking GrapheneOS, Waydroid, etc).

Supporting free competition with and within the Android market is in theory what these teams are all about so hopefully with enough voices they'll push harder on it. I'd love to see a shift here that makes non-Google/Apple-controlled mobile a possible option (even if it's a Linux-on-desktop-style niche for the foreseeable future)

Sizing chaos 5 months ago

This exists, https://www.sonofatailor.com/ for example. You put in a full set of your measurements, pick a type of garment, and they make it to fit and ship it, takes a couple of weeks or so.

It is more expensive, but not impossibly so, and they fairly aggressively discount for larger orders which presumably amortizes some of the overheads.

for the Android case, as you use it from your bank's app, it would typically require some Google security assurances - so no Huawei phones allowed, for example

I don't know about Huawei, but actually most (all?) of the banking apps in Spain should work on a non-Google-certified Android builds. There's an community list tracking GrapheneOS compatibility at https://privsec.dev/posts/android/banking-applications-compa... and all of them currently appear supported just fine.

“Breakup” seems a bit exaggerated considering the % of payment volume which might switch to the new system.

Brazil introduced Pix in 2019, it's now the most used payment method for all transactions nationwide, ahead of both cards & cash.

India introduced UPI in 2016, it now handles >80% of digital payments there, and handles more transactions a day than Visa does worldwide.

It's totally plausible to me that a similar replacement could overtake cards completely within a decade. The lack of cross-border support means "Pay with Bizum" is a niche feature that's only useful in Spain, but if "Pay with Wero" becomes an instant & ~free payment method that works for hundreds of millions of users then it's a very different ballgame.

Bunny Database 6 months ago

I've been using their DNS (and CDN) for a good while. Only positive experiences - fast & rock solid. I would start a new project with them again in future.

I've also tried some of their new more experimental stuff (magic containers, edge scripting) and it's much rougher, but the core product is very good imo.

I wish they'd focus more instead there tbh, there's plenty more that could be done in terms of core content delivery, without trying to enter other (very competitive & I think much more complicated) markets like serverless hosting.