<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: DownrightNifty</title><link>https://news.ycombinator.com/user?id=DownrightNifty</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 05 Apr 2026 22:13:43 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=DownrightNifty" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by DownrightNifty in "Things Linux Can Do That Windows Still Can't"]]></title><description><![CDATA[
<p>> Many of those points reveal lack of knowledge about Windows administration capabilities.<p>Do those capabilities require a more expensive edition of Windows?</p>
]]></description><pubDate>Mon, 16 Mar 2026 21:42:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=47405340</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=47405340</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47405340</guid></item><item><title><![CDATA[New comment by DownrightNifty in "GrapheneOS – Break Free from Google and Apple"]]></title><description><![CDATA[
<p>In what ways does LineageOS trail behind AOSP in terms of security? I looked at the comparison chart you linked elsewhere and the privacy/security sections only seem to list advantages over OEM Android (not AOSP), with the exception of secure boot [1], but AOSP (not OEM Android) doesn't have that out-of-the-box either. Unless you are comparing Lineage with OEM Android?<p>[1] <a href="https://eylenburg.github.io/android_comparison.htm" rel="nofollow">https://eylenburg.github.io/android_comparison.htm</a></p>
]]></description><pubDate>Wed, 18 Feb 2026 00:15:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=47055353</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=47055353</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47055353</guid></item><item><title><![CDATA[New comment by DownrightNifty in "The browser catches homograph attacks, the terminal doesn't"]]></title><description><![CDATA[
<p>They do provide installation commands for every platform that aren't vulnerable to homograph attacks due to GitHub not allowing Unicode characters in user/repo names :)</p>
]]></description><pubDate>Sat, 07 Feb 2026 17:12:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=46925485</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=46925485</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46925485</guid></item><item><title><![CDATA[New comment by DownrightNifty in "The browser catches homograph attacks, the terminal doesn't"]]></title><description><![CDATA[
<p>But as the title of the post says, browsers already solved this problem.<p><a href="https://www.xudongz.com/blog/2017/idn-phishing/" rel="nofollow">https://www.xudongz.com/blog/2017/idn-phishing/</a><p>It does make running commands from an untrusted website a little safer, which is nice. I imagine it's not uncommon to copy installation scripts from random StackOverflow comments or blog posts, for example. But that's still not safe even with this tool. Homograph attacks aside, how can you tell if a URL you're pasting into your terminal is the official source for something? It's trivial to create fake GitHub accounts or organizations.</p>
]]></description><pubDate>Sat, 07 Feb 2026 16:10:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=46924923</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=46924923</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46924923</guid></item><item><title><![CDATA[New comment by DownrightNifty in "The browser catches homograph attacks, the terminal doesn't"]]></title><description><![CDATA[
<p>A simpler solution: examine the URL displayed in the browser window before copying terminal commands from the page. E.g. "starts with github.com" -> "trusted GitHub UI indicates the repo is the official one for this project" -> "URL points to the official project README" -> "terminal commands are most likely not malicious, and if they are, there's a bigger problem here".<p>Of course, more secure installation methods should be preferred, but those are not always available. I am simply comparing the provided solution to homograph attacks with another solution to the same problem.</p>
]]></description><pubDate>Fri, 06 Feb 2026 15:21:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=46913914</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=46913914</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46913914</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Android’s desktop interface leaks"]]></title><description><![CDATA[
<p>The linked article seems to imply that this remains a good design choice even today:<p>> The use of this rule can be seen for example in MacOS, which always places the menu bar on the top left edge of the screen instead of the current program's windowframe.<p>I guess now that the browser is the one app you probably spend the most amount of time in, it might make a little less sense? Android's lack of a menu bar system makes it make very little sense there.</p>
]]></description><pubDate>Thu, 29 Jan 2026 04:59:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=46805978</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=46805978</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46805978</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Launch HN: Bitrig (YC S25) – Build Swift apps on your iPhone"]]></title><description><![CDATA[
<p>Wow, this is great. Would you mind if I reached out over email?</p>
]]></description><pubDate>Thu, 28 Aug 2025 19:53:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=45056324</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=45056324</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45056324</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Build iOS Apps on Linux and Windows"]]></title><description><![CDATA[
<p>True, it's far from ideal, and not entirely without Apple's approval. You need an Apple ID, to accept Apple's EULA (which probably forbids such activities), to accept the risk of your Apple ID being banned [1], to accept the risk of Apple breaking things (intentionally or not), and to continue asking Apple's server for new signatures every week into the foreseeable future.<p>Still better than nothing, for those already fully immersed in the Apple ecosystem, with no hope of escape? (I still use and recommend Android, but I have a spare iPad to play around with, so I enjoy seeing stuff like this come out.)<p>[1] They recommend using a secondary Apple ID, which eliminates most of the risk: <a href="https://swiftpackageindex.com/xtool-org/xtool/1.10.1/documentation/xtool/installation-linux#2-Configure-xtool-log-in" rel="nofollow">https://swiftpackageindex.com/xtool-org/xtool/1.10.1/documen...</a></p>
]]></description><pubDate>Mon, 12 May 2025 21:17:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=43967543</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43967543</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43967543</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Build iOS Apps on Linux and Windows"]]></title><description><![CDATA[
<p>Mega cool!<p>We should all be taking full advantage of the amazing capabilities of the pocket supercomputers we all carry around with us at all times (even if the companies who make them don't want us to or don't care about us). Anything less would be silly! Now Linux and Windows users (the majority of iPhone users) can do easily do so, and that's great.<p>To install your own personal homebrew apps without Apple's approval, use AltStore (Windows) or SideStore (Linux):<p><a href="https://faq.altstore.io/altstore-classic/how-to-install-altstore-windows" rel="nofollow">https://faq.altstore.io/altstore-classic/how-to-install-alts...</a><p><a href="https://docs.sidestore.io/docs/installation/linux" rel="nofollow">https://docs.sidestore.io/docs/installation/linux</a></p>
]]></description><pubDate>Sun, 11 May 2025 22:34:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=43957775</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43957775</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43957775</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Lenovo May Be Avoiding 'Windows Tax' via Cheaper Laptops with Preinstalled Linux"]]></title><description><![CDATA[
<p>Most laptops run Linux, but few provide official support for it. The Gen 12 and 11 did, and you could get Linux pre-installed. But there's no "Linux" option on the Gen 13 store page.<p><a href="https://www.lenovo.com/us/en/p/laptops/thinkpad/thinkpadx1/thinkpad-x1-carbon-gen-13-aura-edition-14-inch-intel/len101t0108" rel="nofollow">https://www.lenovo.com/us/en/p/laptops/thinkpad/thinkpadx1/t...</a></p>
]]></description><pubDate>Mon, 28 Apr 2025 15:29:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=43822564</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43822564</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43822564</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Lenovo May Be Avoiding 'Windows Tax' via Cheaper Laptops with Preinstalled Linux"]]></title><description><![CDATA[
<p>The latest model X1 Carbon (Gen 13) doesn't appear to officially support Linux at this time, unfortunately.</p>
]]></description><pubDate>Mon, 28 Apr 2025 01:05:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=43816555</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43816555</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43816555</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Apple will soon support encrypted RCS messaging with Android users"]]></title><description><![CDATA[
<p>Extra context I forgot to provide:<p>> RCS may require access to certain SIM card information, which only pre-installed apps can do<p>> because they don't want to implement RCS themselves.<p>Sounds like they <i>can't</i> implement RCS themselves even if they wanted to, not simply that Google doesn't provide an open source implementation? (Referring to app developers here, not custom ROM devs.)</p>
]]></description><pubDate>Sat, 15 Mar 2025 03:31:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=43369754</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43369754</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43369754</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Apple will soon support encrypted RCS messaging with Android users"]]></title><description><![CDATA[
<p>> many developers are waiting for Google to add RCS to the same API that SMS/MMS already exposes because they don't want to implement RCS themselves.<p>Is that a planned feature? It's frustrating that third party messaging apps don't work with RCS. I hope we don't have to get the EU involved here...</p>
]]></description><pubDate>Sat, 15 Mar 2025 01:09:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=43369014</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43369014</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43369014</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Y Combinator urges the White House to support Europe's Digital Markets Act"]]></title><description><![CDATA[
<p>Thanks for the suggestion. Feel free to contribute this change yourself if you want: <a href="https://github.com/DownrightNifty/dihsy/blob/main/dihsy.md" rel="nofollow">https://github.com/DownrightNifty/dihsy/blob/main/dihsy.md</a><p>I'll probably end up adding it myself if you don't want to, because it's actually something I wanted to include originally but forgot to.<p>This is definitely a huge issue with the current implementation of DMA compliance. Apple's mandatory DRM encryption scheme as part of the notarization process doesn't just block reproducible builds and the improved security that those offer, but also means that third party app stores aren't capable of auditing the apps they offer in any way. If Apple lets something slip through their notarization review (which is not an impossibility, since it's happened on the App Store before), then the third party store carrying that app will be unfairly blamed for the incident.</p>
]]></description><pubDate>Fri, 14 Mar 2025 22:09:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=43367801</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43367801</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43367801</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Y Combinator urges the White House to support Europe's Digital Markets Act"]]></title><description><![CDATA[
<p>Some good points overall, and I think I agree in a lot of ways, actually.<p>> (or have the capability to jailbreak their iPhone and know what they’re getting themselves into)<p>It is a common misconception that people can "just" jailbreak their iPhone if they're not happy with the walled garden. This requires someone finding a critical-impact zero day vulnerability in iOS, quite literally worth around half a million dollars [1]. Apple is hard at work as we speak trying their hardest to prevent those from slipping in -- and that is a good thing, in general. It's not currently possible to jailbreak any up-to-date iOS device.<p>I'm all for sandboxing and other iOS security features; I'm not proposing that we get rid of any of that. Sideloaded apps would presumably still be fully sandboxed, and would still only be able to access sensitive data with explicit user consent. This is very different than the situation on Windows, where in 2025 you can still double click an .exe and instantly have all of your passwords and credit cards stolen (not an exaggeration; this literally happens).<p>I'm also not against the idea of making it difficult enough to enable sideloading so as to make social engineering attacks against grandma effectively impossible. This is what Chromebooks are doing; nerds get root, but grandma doesn't.<p>However, the DMA is more concerned with delivering alternative apps to everyone than it is concerned with empowering techies. So I can see why you might not support it even if you want to have a little more control over your phone, as a techie.<p>[1] <a href="https://archive.is/9jdW7" rel="nofollow">https://archive.is/9jdW7</a></p>
]]></description><pubDate>Fri, 14 Mar 2025 22:00:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=43367734</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43367734</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43367734</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Y Combinator urges the White House to support Europe's Digital Markets Act"]]></title><description><![CDATA[
<p>> Delta seems to be allowed (at least partially) because of the DMA and the EU.<p>Yeah, that's an important point. Delta on the App Store is most likely a direct result of the Digital Markets Act: <a href="https://www.theverge.com/2024/4/5/24122341/apple-app-store-game-emulators-super-apps" rel="nofollow">https://www.theverge.com/2024/4/5/24122341/apple-app-store-g...</a></p>
]]></description><pubDate>Fri, 14 Mar 2025 21:28:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=43367491</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43367491</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43367491</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Y Combinator urges the White House to support Europe's Digital Markets Act"]]></title><description><![CDATA[
<p>That is listed under "unofficial sideloading methods". A more accurate title would've been "Does iOS <i>support</i> sideloading yet?" but I wanted to keep the domain name as short as possible :)<p>The Apple Developer program is not intended as an option for end users to enable sideloading on their device, even if that is a side effect of joining it. It is only intended to allow developers to briefly test new builds of their own apps in a limited capacity before uploading them to the App Store (or third party stores in the EU). Apps "installed" this way expire after a certain length of time and you must ask Apple's cloud service for a new certificate each time that happens in order to keep using them. You're still tied to Apple indefinitely this way. If your developer account is terminated for whatever reason, or Apple decides to increase the price such that you can no longer afford your account, then suddenly you no longer have sideloading, and you no longer have access to any of the apps you previously sideloaded.<p>Therefore, I lump it into the same category as jailbreaking -- yes, you can argue that the existence of that means iOS already has sideloading, but it's not officially supported.<p>Sidenote: You don't need to spend $100/yr if you want to go the "unofficial sideloading" route; AltStore (Classic) is available for free: <a href="https://altstore.io/" rel="nofollow">https://altstore.io/</a></p>
]]></description><pubDate>Fri, 14 Mar 2025 13:54:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=43362679</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43362679</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43362679</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Y Combinator urges the White House to support Europe's Digital Markets Act"]]></title><description><![CDATA[
<p>The DMA allows Apple to take "strictly necessary and proportionate" measures to ensure that alternative apps do not "endanger the integrity of the hardware or operating system". IMO iOS notarization (which is a different and more involved process with many more rules than notarization on macOS) goes well beyond that, but it's up to the EU to decide.</p>
]]></description><pubDate>Fri, 14 Mar 2025 12:06:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=43361812</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43361812</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43361812</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Y Combinator urges the White House to support Europe's Digital Markets Act"]]></title><description><![CDATA[
<p>> Since DMA came into effect almost two years ago, can anyone comment on its effectiveness?<p>I'm so glad you asked, because I wrote an entire website about it: <a href="https://doesioshavesideloadingyet.com/" rel="nofollow">https://doesioshavesideloadingyet.com/</a><p>Executive summary: Epic Games benefits greatly from the DMA, but powerusers and smaller developers don't get much benefit. This is due to Apple's lackluster compliance measures that are currently being investigated and may be deemed illegal.<p>We might hear another update from the EU rather soon though: <a href="https://9to5mac.com/2025/03/10/report-apple-will-be-fined-by-eu-for-alleged-violation-of-dma/" rel="nofollow">https://9to5mac.com/2025/03/10/report-apple-will-be-fined-by...</a><p>I really hope that the DMA does not go down in history as a failed experiment, because that will be a huge loss for open platforms as a whole.</p>
]]></description><pubDate>Fri, 14 Mar 2025 11:19:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=43361506</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43361506</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43361506</guid></item><item><title><![CDATA[New comment by DownrightNifty in "Y Combinator urges the White House to support Europe's Digital Markets Act"]]></title><description><![CDATA[
<p>> I personally don’t care about alternative app stores<p>I've seen this sentiment a couple of times here and I think it's the wrong framing on what the EU is trying to do. Third party app stores aren't the point; they're just a vehicle enabling users to choose which software they want to use without interference from Apple. The indie devs using AltStore PAL don't all necessarily <i>want</i> to use it, but they're forced to because of the way Apple chose to implement DMA compliance.<p>In fact, the DMA doesn't even explicitly require that gatekeepers allow third party app stores; they can only allow direct distribution (e.g. via web sites) instead, if they want (this is to the best of my understanding of the text, but IANAL).<p>When you say you don't care about alternative app stores, what you're really saying is that you don't care about the end user's ability to use apps that aren't approved by Apple. That is certainly an opinion that many folks have, but I'd prefer that they refrain from hiding behind the shield of "third party app stores are weird and who even cares", whether deliberately or not.</p>
]]></description><pubDate>Fri, 14 Mar 2025 11:16:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=43361479</link><dc:creator>DownrightNifty</dc:creator><comments>https://news.ycombinator.com/item?id=43361479</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43361479</guid></item></channel></rss>