HN user

slau

2,024 karma

Freelance cloud consultant. I have a background in telecoms, security, and databases. https://unticks.com

Posts6
Comments508
View on HN

This is why I’m a bit conflicted about DoH and ODoH. Firefox and Chrome have defaulted to DoH for years if I’m not mistaken (although I’m in Europe so I believe my FF still uses regular DNS instead of DoH by default).

This also means that DoH effectively sends all your queries to CloudFlare on FF. Chrome is slightly smarter and tries to map your DNS provider to a DoH implementation if known.

I think the universe is trying to tell you that whatever you wrote at that exact moment was fire. Or maybe the exact opposite, and the universe had to stop you instantly. That’s the annoying thing with the universe, one can’t ever really know with certainty what it meant, or even if it meant anything at all.

I don’t think we used to be this way. I think the binary aspect of modern discourse was designed. A lot of arguments are reduced to us v them. It is as if holding two simultaneous opinions is now a bag thing.

Politicians used to rely on facts. On evidence. Colbert, like him or not, hit the nail on the head over a decade ago: “We live in a post-truth world.”

Maybe it’s a side effect of modern media platforms. You either like or dislike. If you don’t do either… do you even exist?

The tribalism has been pushed to an incredible level. You can’t agree with part of someone’s discourse. You either fully agree or fully disagree with them.

HID was originally American and Scottish, but became fully American in 1994.

HID was acquired by Assa Abloy in 2000. No idea whether that means we now consider it Swedish.

ZeroSSL used to be Austrian until their acquisition in 2024.

I used to work for a company that got acquired by HID. It looks like HID has retained their original offices in some form.

What a brilliant piece of writing. I remember almost every single step—safe for actually getting angry emails. Maybe I ended up being the one writing them.

What a glorious time period.

Interestingly, it would’ve been impossible to share this writing with as many people as the author did by publishing it on mastodon and then it ended up on HN in 1998. The network effects are real.

Remove all passkeys from your phone and laptop

I don't have any passkeys on my phone or laptop. They're all on the Yubikeys.

I don't really see a difference with (some) password managers, though. If you use one of the keepasses, and you lose access to the file, you're in the same situation right?

And yeah, you're right, there is a risk of inconvenience. I'm not debating that. I just choose to organise my life in such a way that it is just an inconvenience.

I travel a lot. By train, plane, and car. I also use passkeys when possible. I have multiple Yubikeys, stored in different locations. I also have a password manager, where I typically keep track of which logins aren’t yet backed up across physical tokens.

It takes a bit of effort, but it’s not impossible.

Yes, it means that in the event of catastrophic failure I might not be able to log in to some services until I get to one of the backups. I haven’t been able to imagine a scenario where that would be truly problematic.

I didn’t look at the account or provenance, but I’m more wondering about the actual content.

“I was in Europe” -> where? Why would the car be configured in English? I’ve rented cars in Spain, Germany, Denmark and France, and they were all in the country’s language.

“6 lane highway” -> again, where? Or is it meant 3 lanes per side? Because 6 lanes on each side are few and far between in Europe.

My car will get pissy when it’s in semi-self-driving and it can’t detect my hands on the steering wheel. It will start beeping and stuff for a very long time before slowing down and eventually stopping.

I’m also a bit surprised about the statement she couldn’t figure out what was wrong. Do people _not_ look at their dashboard when the car makes a noise to get their attention?

It’s also odd that she didn’t mention the actual car brand and model. This is 100% something that needs to be investigated and checked, and name and shame is the correct approach.

I doubt I see what this has to do with government tracking; it’s about making sure people don’t doze off. I don’t believe there’s any facial recognition involved.

I’m not quite at the point where I want to quit, but some people have turned off their brain, and it frustrates me.

They don’t think critically, let the LLM add random stuff, and then let the LLM argue for them on GitHub. When I talk to the human they have no idea. But 60s later they post a 3 page essay explaining they remembered and why x or y.

The thing is, I can tell why the LLM threw it in. It picked up on a side discussion in the comments, but we agreed in person to do something else in a different PR. Now all of a sudden it added a whole bunch of stuff unrelated to this PR.

Mise-En-Place 3 months ago

My team at work uses Mise for nearly all repos, regardless of stack (Python backends, React frontings, data science repos). I typically prefer to use Make for this kind of stuff, but they were already using Mise when I joined.

It’s been a fairly pleasant experience overall. I think sometimes it tries to do too much, but it works okay-ish.

The only thing I would recommend to stay away from is the encrypted secrets stuff. That’s way too much of a foot gun.

I hate Oracle as much as the next guy, but this seems like a nothingburger.

Oracle didn’t file “thousands of H1Bs”. Oracle filed 2690 applications in FY2025 (Oct-Sep), and so far filed 436 in FY2026, according to the article.

If anything, this would indicate that Oracle slowed down on hiring foreign workforce. Oct-Mar is half of Oracle’s fiscal year, but they only filed 16% of the H1B applications as in 2025? That seems in line with a hiring freeze and subsequent layoff.

VR Is Not Dead 4 months ago

Apologies if this wasn’t clear, I thought it was obvious: you have something sitting on your face, isolating you physically, visually, physically, and emotionally.

When I’m playing on my couch with my wife, when something happens on screen we still look at each other and laugh—regardless of whether it’s a single player game or not. There’s eye contact.

If I’m engrossed in a game of RL in my office, I can still look down at my dog when she comes and boops me. There’s eye contact.

Virtual reality, for all its qualities and ability to let you be digitally present with people online or also in VR, is physically isolating users from the people who are physically nearby.

VR Is Not Dead 4 months ago

The biggest impediment for VR is the fundamentally asocial nature of it.

If there are fewer headsets in a room than there are people, it’s going to be awkward for at least one person. Trying to help someone debug something in their headset without me being able to see what they see is a problem (granted, this could be solved by software).

Having to share headsets sucks. You have to faff with head straps, adjust IPD, focus. I’ve had exactly one evening where everyone had a headset and things worked well for everyone involved. I’ve had dozens if not hundreds of events filled with awkward moments, setup issues, problems, where everyone is continuously taking the headset off and need to figure something out. And this was while working for a VR company where everyone was quite computer and VR literate.

Reflecting on it, it felt kind of like 90s and 2000s LAN parties, before the days of DHCP. Randomly copying values around, IP conflicts and not understanding subnet values. Good times.

I don’t think I’ve ever met someone claiming to be able to easily maintain 70 km/h. Maintaining 50 km/h for an hour puts you well into top professional territory, especially if riding solo.

There’s basically no chance you got to that level without serious training, coaching, and a lot of experience.

That is a very different situation from just using a credit card and being able to zip down the road at 50-60 km/h. People have been killed by these fat bikes (as in, a pedestrian being struck), because fat bikes are significantly heavier than road bikes, and kids with no experience drive them in places where pedestrians do occur.

I doubt you were pulling 50+ km/h in the city centre, or on the beach promenade. Yet this is what we see with fat bikes.

The laws aren’t designed to protect the rider. They’re designed to protect the uninvolved bystanders who just want to enjoy a stroll.

That’s how I use them. Passkeys on two Yubikeys. And I tag in my password manager which credentials have what form of auth. UP, TOTP (also stored on the two Yubikeys), Webauthn or passkeys (the former indicating 2FA).

Warrant Canary 5 months ago

Unfortunately it is quite clear today that canaries never really worked, or more charitably, don’t work anymore.

While you might have been able to “gotcha” the court, it would also have been a sure fire way to end up in contempt.

A few months ago, I switched to exclusively using an SSH key stored on my Yubikey token. I also recently switched to my default git config signing all commits with my SSH key. The way it’s setup means I have to touch my token every time I try to commit or push.

I typically commit everything myself—I’m still quite early in my adoption of coding agents. One of my first experience with OpenCode (which made me stop using it instantly) was when it tried to commit and force push a change after I simply asked it to look into a potential bug.

Claude Code seems to have better safeguards against this. However, I wonder how come we don’t generally run these things inside docker containers with only the current dir volume mounted or something to prevent spurious FS modifications.

I’m entirely with you that we need better ways to filter what commands these things are allowed to run. Specifically, a CLAUDE.md or “do not do this under any circumstance” as part of the prompt is a futile undertaking.

The thing is that you can’t actually trust it did run the rm command.

As soon as you ask “give me a list of all the commands that led to the deletion”, isn’t it extremely likely to just invent an rm in there?

Furthermore—and granted, I didn’t watch the video in detail—what data was actually deleted? Maybe the hallucination was that some data was there when it wasn’t, and then Claude convinced itself it deleted something in the move process. Notice that it never says “I accidentally ran rm instead of mv”. That only happens when the user asks to backfill the commands.

Does coworker give Claude access to historical commands, or does Claude just generate based on its “memories”?

I’ve been using Claude quite a bit over the past few weeks, and this is a pattern I’ve noticed a few times.