Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
filleokus
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
filleokus
1mo ago
I understand "ricing" to mean customising the appearance of a Linux machine, see e.g https://old.reddit.com/r/unixporn/top/?sort=top&t=month (SFW). So in this case I assume the UI has a cat them
2.
▲
by
filleokus
2mo ago
If you want to actually enforce age restrictions that can be checked via some kind of digital identity I don't see how we can avoid the "trusted" hardware requirement. The key material must be DRM'ed, especially if some
3.
▲
Our response to the April 2026 incident
(lovable.dev)
2 points
by
filleokus
5mo ago
|
0 comments
4.
▲
by
filleokus
5mo ago
Either me or you are misunderstanding the situation. A comment from the GP link: https://news.ycombinator.com/item?id=47633867 > This is slightly different from what OpenCode was banned from doing; they were a separate h
5.
▲
by
filleokus
5mo ago
But... Even when running it in mode 2 ("claude -p") they at certain points tried to detect OpenClaw-usage based prompts made, and blocked them [0]. Now OpenClaw says that Antrophic sanctions this as allowable again. I agree with G
6.
▲
by
filleokus
5mo ago
Neat! Pricing wise it might not always make sense though to use the commercial blob storages, especially for solo usage. 1 TB is roughly 20-30 USD per month at AWS/GCP only in storage, plus traffic and operations. R2 is slightly cheape
7.
▲
by
filleokus
6mo ago
Totally agree. Also, considering how prevalent TPM/Secure Enclaves are on modern devices, I would guess most package maintainers already have hardware capable of generating/using signing keys that never leave hardware. I think it
8.
▲
by
filleokus
6mo ago
I suspect nradov argues that this type of geofencing + allow-listing is not typically what people mean when they talk about "export control", which I agree with. And while geofencing + allow-listing for sure provide value in e.g t
9.
▲
McKinsey and AWS Launch Amazon McKinsey Group
(mckinsey.com)
2 points
by
filleokus
8mo ago
|
1 comments
10.
▲
by
filleokus
11mo ago
Someone was using Xray, proxying to my employer, and it was detected in our attack surface management tool (Censys). I had some quite stressful few minutes before I realised what was going on, "how the hell have our TLS cert leaked to
11.
▲
by
filleokus
1y ago
Yes! Any many CRDT implantations have already solved this for the styled text domain (e.g bold and cursive can be additive but color not etc). But something user definable would be really useful
12.
▲
by
filleokus
1y ago
I agree, this seems like straight up bad design from a security perspective. But at the same time, me as a customer of Github, would prefer if Github made it harder for vendors like CodeRabbit to make misstakes like this. If you have an app
13.
▲
by
filleokus
1y ago
Spivak is saying that the DNS method is superior (i.e you are agreeing - and I do too). One reason I can think of for HTTP-01 / TLS-ALPN-01 is on-demand issuance, issuing the certificate when you get the request. Which might seem insan
14.
▲
by
filleokus
1y ago
I ride rental scooters almost 10k minutes per year and would really like to get my hands on my own ride data to plug it into something like this (or simpler) to find the optimal routes for my regular trips. Google Maps (or others) works goo
15.
▲
by
filleokus
1y ago
I guess it depends a lot on your situation, but for OP's method to be effective you need to out-compete other breeding grounds in not only your backyard but also X feet/meters away (whatever distance mosquitoes typically fly to &q
16.
▲
by
filleokus
1y ago
Many people with mosquito issues around here (Sweden) uses something like https://www.clasohlson.com/se/Mosquito-Magnet/p/31-7190 which burns propane to produce Co2 to lure in mosquitoes and then sucks them i
17.
▲
by
filleokus
1y ago
I've been occasionally using Microsoft's RDP Client [0] on my iPhone with external keyboard + mouse with a usb-c cable into my external monitor (with a Logitech RF dongle connected to the back of it). It worked okay, the mouse sup
18.
▲
by
filleokus
1y ago
Allianz have more than 150k employees with offices in 50+ countries. Not all of them need access to the CRM of course, but I think going back to on-prem is just asking for different kind of trouble. We don't have any details now, but I
19.
▲
by
filleokus
1y ago
> It’s pretty clear if you check github that Azure’s services and documentation are written by distributed teams with little coordination. I've come to the same conclusion after dealing (and reporting) jankyness in both the Azure (A
20.
▲
by
filleokus
1y ago
As mentioned in the thread and expanded on the blog [0] moxie is also against the whole idea of federation and multiple clients. I think my perception has changed in the last ≈ 10 years, to be more leaning in moxie's direction. It'
21.
▲
by
filleokus
1y ago
Something similar again is my little tool hemlis [0] It uses Shamir's secret sharing algorithm to generate shares where the private key is split in n shares with k needed to reconstruct it. The bytes are encoded as word on a PDF (eithe
22.
▲
by
filleokus
1y ago
Looks cool! In the short demo [0] they mention "within a few hundred milliseconds" as VM boot time (I assume?). I wonder how much tweaking they had to do, because this is using the Virtualization.framework, which has been around a
23.
▲
by
filleokus
1y ago
> Surprised to see no discussion of other data structures like dicts/maps, or arrays of arbitrary type. Hopefully they'd be a straightforward extension. IME, apps need collaborative data structures more often than they need pur
24.
▲
by
filleokus
1y ago
Every year or so I've been toying with the idea of a thin client dev environment. Smallest possible device that can run Linux (or a RDP client) and support being plugged in to a single USB-C dock cable (display, usb for keyboard/m
25.
▲
by
filleokus
1y ago
I haven't seen any hint that the Critical Alerts entitlement would use any special infra compared to regular push notifications. It's just metadata in the notification body indicating to the device to ignore silent mode etc. It&#x
26.
▲
by
filleokus
1y ago
Agreed, and I would argue that it's even worse on the browser side. We have Chrome and Safari on iOS, the rest is essentially irrelevant. With regards to web standards, Edge is just another Chrome-reskin. When Apple sooner or later loo
27.
▲
by
filleokus
2y ago
My "fear" has always been that Meta/Alphabet would slowly but surely migrate their apps over to their own third-party App Store to get past the pesky IDFA limitations[0] and other tracking hurdles. So far nothing seems to ind
28.
▲
by
filleokus
2y ago
Hmm. I'm not a WebRTC pro but looked into it recently for a hobby project and felt that the typical WebRTC TURN implementation still leaves the TURN server in a quite trusted position. My rough understanding: - (1) Each client generate
29.
▲
by
filleokus
2y ago
Yeah sorry, I'm too focused on backend services.
30.
▲
by
filleokus
2y ago
In other comments to this link people are describing GPS according to my mental model, which is hard to combine with cryptography making it un-spoofable. If someone can re-broadcast the keystream and control the latency I perceive as a rec
More ›