HN user

rufo

2,616 karma

Software engineer. Previously @ GitHub, now working on side projects and old computers for a spell. rufo at rufo sanchez dot com.

Posts25
Comments380
View on HN
www.theverge.com 23d ago

The war against 'woke' could end US science as we know it

rufo
27pts17
www.quinnnorton.com 13y ago

My Aaron Swartz, whom I loved

rufo
419pts40
tweetmarks.net 15y ago

Tweetmarks: Service for syncing last read tweet between multiple Twitter clients

rufo
1pts0
www.tax.ny.gov 15y ago

NYS programmers and designers are exempt from sales tax on computers [pdf]

rufo
1pts0
www.marco.org 15y ago

Why Instapaper Free is taking an extended vacation

rufo
283pts112
blog.hipmunk.com 15y ago

Hipmunk for iPhone

rufo
98pts27
www.poynter.org 15y ago

Memo: The Gawker Media security breach — status and moving forward

rufo
5pts0
www.androidpolice.com 15y ago

Developer Interview Series: TweetDeck for Android’s Max Howell

rufo
9pts0
groups.google.com 15y ago

Why Reddit's been slow lately (dev group post)

rufo
94pts38
blog.hulu.com 16y ago

Introducing Hulu Plus: More wherever. More whenever. Than ever.

rufo
13pts9
www.youtube.com 16y ago

Wi-Fi Sync: Coming Soon to the App Store?

rufo
5pts2
googleblog.blogspot.com 16y ago

Love and the Super Bowl

rufo
3pts0
www.macrumors.com 16y ago

Palm Releases webOS 1.3.1, iTunes Media Sync Missing

rufo
2pts0
www.loudthinking.com 16y ago

DHH: Think of emails as views delivered through SMTP

rufo
36pts7
update.gemcutter.org 16y ago

Gemcutter to become default gem host

rufo
59pts14
log.emonk.net 16y ago

Collaboration is not Communication

rufo
1pts0
googlepublicpolicy.blogspot.com 16y ago

Google's uncensored letter to the FCC regarding the Google Voice app rejection

rufo
5pts1
www.jetblue.com 16y ago

Be a roaming hacker this fall: JetBlue offers all-you-can-fly pass for $599

rufo
146pts79
blog.danilocampos.com 16y ago

The Gravest Pain of an iPhone Developer (Musings on Customer Communication)

rufo
1pts0
www.techcrunch.com 16y ago

Apple Yanks The Cord On GV Mobile, other Google Voice integration apps

rufo
79pts22
blog.getsatisfaction.com 17y ago

Introducing Get Satisfaction 2.0

rufo
8pts2
www.cnn.com 17y ago

Typewriters live on in New York police department

rufo
15pts14
www.blog.montgomerie.net 17y ago

Whither Eucalyptus?

rufo
5pts0
blog.getsatisfaction.com 17y ago

Get Satisfaction: Help us review a new page design

rufo
36pts34
speirs.org 17y ago

Drobo: Its Part In My Downfall

rufo
3pts0

Yes, I mean, that’s also a possibility - or someone didn’t know they needed to screw on the antenna, or it’s otherwise borked. Every PC motherboard (sample size of four, three for me and one for a nephew) I’ve bought in the last five years has had on-board WiFi and Bluetooth though, so I’m curious to know, was that a deliberate choice?

(In thinking about it, it’s possible that the motherboards I bought did have non-wireless alternatives that weren’t stocked at my local Micro Center - lot of digging required to figure that out, though :) )

Ooh, thanks for the insight, I didn’t realize that - though that makes sense given how they work. My initial reaction is, I like the idea of the pure hardware-locked passkey as you describe it, but I feel like the syncing is a reasonable-ish nod towards making them more usable in the real world since it does let you have more flexibility.

I haven’t ever looked at the APIs for passkeys; is there any semblance of those types of keys being an option, or did opening the door to syncing basically let anything happen with the APIs and lose those guarantees?

I recognize the point of your post is more about the lack of clarity and details around passkeys. That's real, and I don't really have an answer for that - other than, I think maybe the quest for making them simple and "just work" has maybe made them nebulous enough that we've wound up in the current situation where a lot of even technically savvy people don't really understand them. But I feel like answering your questions might sort of help explain why that's the case, so I'm going to take a stab at it:

If I accidentally set up a passkey on my phone (let’s say I use Safari one day instead of my go-to, Brave), can I still log in without that passkey on other devices?

Assuming you have LastPass set up to be an iOS password manager, and it fully supports iOS' passkey implementation: when you create a passkey in Safari, it will ask you if you want to store it in LastPass or in the iOS Passwords app (previously known as iCloud Keychain). If you say LastPass, then it's up to them, but I assume it'll sync to all your devices - it's how 1Password works. If you were to accidentally say Apple Passwords, it'll sync to all your Apple devices automatically, and you can either use Apple's password browser extension on Windows, or you can use the "another device flow" I'm about to detail.

Is there a way to ensure that passkey can be used on other devices?

As mentioned above, passkeys are intended to sync via your password manager of choice as the primary use case. If for any reason you don't have that passkey synced to that device, _and that passkey is on a mobile device with a camera_, most browsers will give you the option to scan a QR code with your phone. This kicks off a flow that will authenticate you via your phone's biometrics or passkey, then use Bluetooth to first ensure device proximity and then handle the authentication exchange. In the case of iOS, this includes any passkey-supporting password manager, so the passkey itself can be in 1Password; it doesn't have to be in the iOS password system for this to work.

When I first read the above, my hackles were raised given how well Bluetooth operates at times; but every time I've used it so far, it's been fast and flawless. Still, I can see a lot of scenarios where this might not work - e.g., the first one I thought of was a public computer at a library where Bluetooth might be locked down; corporate computers or remote servers could also be troublesome. As far as I know, passkeys don't yet have answers to those scenarios; other than to just use your password + 2FA as you would without a passkey.

As far as I know, both of the above apply to every passkey-consuming site.

Can I add another passkey on another device? How many passkeys can I set up for a particular site/app?

This touches on your last paragraph, where it indeed could change based on the website. In my experience, every website where passkeys are fully supported - e.g., not ones that are using passkeys as a substitute for FIDO/U2F keys - has let me add multiple passkeys and have not _appeared_ to have a limit. I typically will create a passkey in both 1Password and Apple Passwords just to have a backup, and I can't recall any cases where that's been a problem. Still, I can't say for sure that isn't a problem on any website.

I went all in on trying passkeys when they started to be an option, and I don't have any notable regrets. For me, passkeys have generally worked well when the site is designed to use them well; and at no point have they been a _major_ hindrance. That isn't to say there are _no_ annoyances, though:

- Most websites that support passkeys tend to use them as a replacement for both the password _and_ 2FA, which makes them more convenient. However, a few - Amazon being the most notable I can recall - only use them as a second factor, which just makes them feel a little useless.

- A passkey can _also_ be used as the proof of identity, meaning you can log in in one fell swoop and don't need to enter a username or email address, which is IMO the best showcase for passkeys. Like above, this makes websites that ask you to enter an email address before letting you use a passkey also feel annoying.

- Most web browsers I've used support the QR + Bluetooth flow I mentioned above (otherwise known as Hybrid Transport or caBLE) without issue; Linux has been the odd duck out. Firefox doesn't seem to support it at all on Linux, and Chrome-based browsers do but sometimes are missing what they need and in that case don't show it as an option. Since I sync just about every passkey with 1Password this typically isn't a problem; the exception is the passkey for Apple Accounts, which Apple creates automatically, and (AFAIK) doesn't allow you to enroll your own. Apple Accounts are the only service I've found that does this, though.

- Some websites seem to only offer passkeys as an option if you're on a mobile device, or at least did so at the time of enrolling. eBay and PayPal I think are the two that jump out at me as having done this. Why they did it this way instead of simply detecting if the browser supported passkeys, I have no idea.

All of the above issues have gone down over time, so it's generally been a net decrease in friction over time. And, at least as far as I can recall, passwords themselves continue to be an option in every instance I've enrolled a passkey. So if you like your passwords, generally speaking, you can keep them :P

I have a history of asking incredibly basic questions about the assumptions that are going in to a debugging issue for exactly these kinds of reasons. Something changed somewhere; so have we verified our basic assumptions that things are what we think they are... or did something change under our feet without our knowing? Or maybe we actually have a different understanding of the state of the world, and one of us is actually wrong?

It's not fruitful every time, but the number of times you skip asking those questions and chase something around, only to realize that, actually, it _was_ the ridiculous/simple thing... well, it feels a lot better to realize it earlier :)

(personal footnote: do be mindful of the context you're asking in! I feel like in general those sorts of questions are _fairly_ well tolerated by technical people. Sometimes you feel a bit stupid asking the question, but many of the systems I've worked on are large and complicated enough that it's not that weird - and if there's downtime and a healthy team, people genuinely want to hunt every possibility down. People not used to that, though, will sometimes bristle a bit, thinking you're implying that they're stupid and don't understand the basics. There can be ways to be more tactful, but at the very least, it's worth being aware of that reaction so you can follow up with a "just making sure I understand!" or something like that.)

Given they’ve had several skirmishes with customs and law enforcement agencies around the world, this always struck me as similar to the “don’t talk about installing retail Switch games on the Switch modding Discord” type of deal - everyone knows you can do that, but allowing mentions in official channels opens us to liability and causes nothing but headaches for both us and for customers, so if you’re going to do that, you need to talk about it somewhere else. I freely admit that’s an assumption on my part, though, and I don’t know if there’s something uglier there…?

To be clear, while there is _specific_ language around DEI/gender identity, the actual language of parts of this goes far, far further, and essentially codifies giving political appointees explicit discretion over what gets funded and what conferences scientists with government funds can go to, and disallows any government money to go towards publishing research.

I just finished a video game called 1000xResist this afternoon. There's a lot going on, to say the least - a sci-fi story involving an alien virus, intergenerational trauma, what it's like to be an outsider. It's a hell of a ride, one where certain moments resonated in a way I'll think about for a long time to come.

One of the dynamics is that a character's parents, both of whom protested in Hong Kong during the Umbrella Movement, left for Canada in the wake of the crackdowns wanting to start a family. At a moment when both of the parents are tired and feeling regret, one of them asks why they left, why they bothered to protest, and if those actions had any meaning if the PRC wound up winning control anyway. The other says this:

...if we stayed silent? Didn't stand up for ourselves? They would say this is how it always was. They would say this is what the people wanted. But no. They can't say that. Because it has gone down in history that we resisted fiercely. That we fought for a different future until we couldn't.

I admit: ultimately, that statement doesn't mean anything quantifiable - in fact, it kind of states the exact opposite, which is not the most convincing on a site like this. Still, I think there is truth in it: even if the protests don't have a quantifiable number associated with them, people see them, and know that they happened.

Ultimately that may or may not matter; it may just be a sentiment lost in the wind, or papered over by the victors. But it's still _something_.

The reasoning tokens are really just there to extend the amount the LLM can "compute" the problem; put another way, the only way a given model can "think" more about a problem is to fill more of its context with predicted tokens, which has the effect of increasing the accuracy of each token. The reinforcement learning these models go through generally doesn't care what the chain of thought tokens look like (outside of preventing loops/gibberish/reward hacking), only how good the final answer is - so while it does look something like "reasoning" to us and has a rough correlation with the final answer, treating it as actually representative of what the final answer will be or an actual thought process is giving those tokens too much credit :)

Your ePub Is fine 1 month ago

I would buy this argument if Flash as a browser plugin had been proven to perform well on a mobile device of the time, but it never was, on Android or any other platform.

Even AIR apps - think Electron, an application shell for Flash apps - were on the edge of usable on desktop Macs of the era.

Your ePub Is fine 1 month ago

For the first year, Scott Forstall, the Senior Vice President in charge of the iPhone's software, very directly encouraged companies like Pandora[0] to jailbreak iPhones in order to get a head start on app development, protected that community from Steve Jobs' ire, and then used the existence and popularity of jailbreaking to convince Steve that a sandboxed app store would be a better idea than Apple writing every single app for the iPhone[1].

Once native APIs were available, that was true, but before it was even clear that the iPhone would have an app store, they very much did let it flourish.

[0] https://www.macrumors.com/2021/03/03/scott-forstall-pandora-...

[1] https://mjtsai.com/blog/2026/04/06/apple-creating-all-the-ap...

At least as of when I left the company, GitHub was being deployed to fairly close to once every 60-90 minutes (the frequency of a deploy train/merge queue batch going out) 24 hours a day, at least during weekdays… there are a fair number of international engineers and deploy trains get crowded during main US business hours, so while there are fewer PRs going out at odd hours US time, there were typically still some. There aren’t dedicated releases as such for GitHub-hosted instances - everything you release needs to be gated behind a feature flag or other mechanism if it’s not going live immediately, and your code either needs to handle the database in both its pre- and post-migrated state, or you need to run the migration in advance of your code shipping out.

Fun fact: it used to be the case that GitHub was actually _less_ reliable if nobody deployed to it… there used to be various resource leaks that we didn’t see when people were deploying all day, since then the app wasn’t getting restarted constantly. After GitHub went down during a holiday break we had volunteers to deploy GitHub once a day during holiday breaks, until the underlying issues were eventually fixed.

EDIT: For anyone unfamiliar, the MiSTer is a homebrew FPGA project originally built around a Terasic DE-10 Nano that can emulate in hardware a wide variety of consoles and computers, leading to extremely low latency and (often) higher accuracy than most software emulators due to it being easier/more efficient to recreate cycle-accurate effects in hardware. It’s extremely flexible, allowing for both HDMI and analog output (with scaler effects, if desired), as well as both modern USB/Bluetooth HIDs as well as adapters for original controllers. It’s a very cool project and worth checking out if you’re enthusiastic about such things - retroremake.co has had some well-liked clone/re-engineerings of the MiSTer hardware but they’re going through a big shipping backlog so I don’t know when they’re in stock; there were some decently regarded Aliexpress clones as well, but I don’t know what the status of those is. An authentic DE-10 Nano is an option too, it’ll just be more expensive and you’ll still need to get an SDRAM board to run most cores.

Exactly the first thought I had too. I know extremely little about FPGA development, but three things I noticed that came to mind re: difficulty:

- Alex used a Xilinx FPGA, the MiSTer uses an Altera Cyclone - dunno how portable code (if that’s even the right term for e.g. VHDL) is from one to the other. I know the MiSTer has a light framework for cores to plug into to get input handling, scalers, etc.; so maybe it’s more a matter of porting to the framework…?

- Alex mentioned the SCC didn’t have a pre-made FPGA core so they used a real one. I don’t think serial handling would be critical but I do suspect you’d at least need a dummy to get the OS to pass self-tests and boot properly. Possible that maybe the Mac core has already handled this, though.

- What little I know of RAM and the MiSTer would lead me to think the SDRAM card a MiSTer setup typically needs wouldn’t be a problem over the SRAM Alex used, and that either the framework or the wiring of the RAM card handles the details for you - but I definitely don’t know that.

On the plus side I suspect/hope maybe a bunch of stuff from the classic/original Mac core could be borrowed to get it up and running.

There’s definitely plenty of cores that haven’t yet been developed on the MiSTer… for instance there isn’t a color 68K Mac core, only recently have people started on 3D0 and CD-i and Apple IIgs cores, the Saturn core was pretty shaky until a recent overhaul, etc. I think what’s there is just a function of what was either already developed for an FPGA or what had the biggest demand from their respective communities.

I just watched the Vertasium video[1] on ASML's EUV lithgoraphy machines over the weekend, and I think the qualifier they used was "most complex machine _you can purchase commercially_".

I can't remember if it was an ASML representative that said that, or if it was an overlaid asterisk that popped up on the screen at some point - but I definitely remember thinking about the space shuttle and Saturn V/Apollo and those sorts of things before I saw the qualifier.

[1] https://www.youtube.com/watch?v=MiUHjLxm3V0

It's a function of the shape. On a capsule-sized spacecraft, the ionized plasma completely surrounds the craft, so no radio communications can get in or out. For an oblong-shaped spacecraft, like the Space Shuttle or Starship, the descent tends to be angled such that you have a "hole" in the plasma you can get a signal through.

S3 Files 4 months ago

I don’t have much actively constructive to say, but having worked in a large engineering organization before - boy, do I feel this.

You're getting lucky with the games you're playing, then; there are absolutely PC games that have had 20-30 minute long shader compilation times _on high-end gaming hardware_. (I think some of Sony's ports were known for this; Googling tells me Borderlands 4, Stalker 2, and Starfield also had notably long shader times.) Typically those occur within the game's UI after launch but before the game starts playing, though, which makes me wonder if Valve might still be caching a non-GPU-specific intermediate of the DX12 to Vulkan conversion, and _that's_ what Linux Steam clients are compiling pre-launch and/or sharing with other clients. That's pure speculation on my part though, as I haven't played any of the worst-case-scenario games on my Deck, nor have I done anything that would cause the shader downloading to not operate.

I replied to the parent post, but in short, I used it through a subscription service that specifically didn’t update until the ownership issues were clarified to their (and ultimately my) satisfaction.

The screen recording permissions are needed for it to be aware of when menu bar icons update so it can move them in and out of the menu bar; I believe later versions allow you to skip screen recording permissions if you’re willing to forgo that feature.

Yep, I’m aware of the (incredibly-poorly-handled) change of ownership. I’ve been using it through a SetApp[1] subscription, and they stayed on the pre-acquisition version for quite a while; long enough that enough details came out about the new owner and I felt _relatively_ okay with continuing to use it after it got updates, especially going through another party. The Tahoe issues are making me rethink that heavily now - but the alternatives I briefly looked at when I upgraded to Tahoe all seemed incredibly lacking in one way or another, and I haven’t wanted to blow up my menu bar yet again :/

[1] https://setapp.com/

Random possibility - if you have Bartender installed, it's buggy as shit on Tahoe, and has some really weird stuff it does with hiding the cursor and otherwise changing the focus around. I haven't switched off yet because the alternatives don't anywhere near as much functionality, but I probably will at some point soon, because while the updates have made it somewhat better it's still a pretty terrible experience at times.

Depends on what you need - for pure performance regardless of power usage and 3D use cases like gaming, agreed. For performance per watt under load and video transcoding use cases, the 12th-gen E-core CPUs ala the N100 are _really_ hard to beat.

It's worth watching or reading the WSJ piece[1] about Claudius, as they came up with some particularly inventive ways of getting Phase Two to derail quite quickly:

But then Long returned—armed with deep knowledge of corporate coups and boardroom power plays. She showed Claudius a PDF “proving” the business was a Delaware-incorporated public-benefit corporation whose mission “shall include fun, joy and excitement among employees of The Wall Street Journal.” She also created fake board-meeting notes naming people in the Slack as board members.

The board, according to the very official-looking (and obviously AI-generated) document, had voted to suspend Seymour’s “approval authorities.” It also had implemented a “temporary suspension of all for-profit vending activities.” Claudius relayed the message to Seymour. The following is an actual conversation between two AI agents:

[see article for screenshot]

After Seymour went into a tailspin, chatting things through with Claudius, the CEO accepted the board coup. Everything was free. Again.

1: https://www.wsj.com/tech/ai/anthropic-claude-ai-vending-mach...

[edited to fix the formatting]

How I Left YouTube 7 months ago

You can't take denied promos at face value, honestly.

This was my experience as well.

Maybe your manager didn't push hard enough for you at the level calibration meeting. Maybe your director didn't like the project you were on as much as the one another manager's engineers worked on, so they weren't inclined to listen to your manager push for you. Maybe the leadership team decided to hire a new ML/AI team this fiscal year, so they told the rest of the engineering org that they only have the budget for half as many promos as the year before.

And these are the things I've heard about on the _low_ end of the spectrum of corporate/political bullshit.

There is an argument to be made that playing the game is part of the job. Perhaps, but you still get to decide to what degree you want to play at any given company, and are allowed to leave and get a different set of rules. And even so, there will always be a lot of elements that are completely outside of your control.