<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Veserv</title><link>https://news.ycombinator.com/user?id=Veserv</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 26 Jul 2026 16:15:03 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Veserv" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by Veserv in "RISC-V Is Inevitable: State of the Union Keynote Argues"]]></title><description><![CDATA[
<p>Have they figured out how to implement free() yet?<p>Last I looked you need a garbage collector to deallocate at which point you might as well use Java which is actually designed for that use case.</p>
]]></description><pubDate>Wed, 15 Jul 2026 18:52:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48925432</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48925432</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48925432</guid></item><item><title><![CDATA[New comment by Veserv in "Theo de Raadt: "You've been smoking something mind altering" (2007)"]]></title><description><![CDATA[
<p>Sure, this is why virtualization is a valuable feature, it is just not the basis of security/isolation.<p>One of the points I am making is that when deploying on a modern multi-tenant VM-based platform, VM orchestration is analogous to process orchestration. However, you orchestrate the units, VMs, in a very different way to how you would orchestrate processes on say Linux. If your platform orchestrates, configures, and operates processes the same way a VM-based platform orchestrates, configures, and operates VMs and your implementation is solid then you would see similar security benefits. Virtualization is not the key. It just kind of looks that way because virtualization is usually paired with a fundamental re-architecture.<p>In greenfield application development or cases where you would do single-application VMs, you would target processes/platform directly. Only in situations where you are literally lifting code from a different OS environment that you can not or will not port to the native model would you need to go through a VM. If you orchestrate them the same way and your operational models for them are similar, then you will usually see similar outcomes. This is how it works in high security microkernels/separation kernels which simultaneously allow native processes alongside VMs. Virtualization is a feature to allow non-porting, it is not security/isolation; that is already provided underneath.</p>
]]></description><pubDate>Mon, 13 Jul 2026 01:00:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48886591</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48886591</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48886591</guid></item><item><title><![CDATA[New comment by Veserv in "Theo de Raadt: "You've been smoking something mind altering" (2007)"]]></title><description><![CDATA[
<p>Yes, you do enjoy evading the argument. You continuously point at implementation and operational model differences as proof that virtualization is the key factor. Theo's argument is literally that virtualization versus non-virtualization is irrelevant compared to implementation and operational model deficiencys. If you make garbage implementations and operational models, then you get garbage virtualization. If you have a good implementation and operational model then you do not need virtualization for "security".<p>As independent evidence for this point, virtualization is not the basis of security/isolation in seL4. You have isolation without any virtual machines. Virtual machines are just a feature on top that can leverage the existing isolation functionality to also provide isolated virtual machines. Of course, a secure deployment then requires you to leverage this foundation with a good operational model and system design since you can always make a insecure system even atop a good foundation. This demonstrates that virtualization is not necessary for a secure base, nor sufficient to achieve highly secure systems.<p>Just to hammer in the point that you are heavily misinterpreting Theo's response, this is the full sentence at the start of the post that Theo was responding to:<p>"Virtualization seems to have a lot of security benefits. Rootkits can lie to DomU but not Dom0, and of course snapshotting, migration etc is <i>really</i> nice."<p>Wow, amazing, rootkits can <i>never</i> be in Dom0 because Xen has "virtualization" magic pixie dust. Theo is pointing out how this is nonsense and virtualization will only provide security if you can create implementations without glaring security holes. Furthermore, you should not just listen to the people who brought you insecure system 1 when they tell you that this time for sure they are going to give you secure system 2; maybe have just a little bit of cynicism and ask for some evidence first.</p>
]]></description><pubDate>Mon, 13 Jul 2026 00:01:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48886187</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48886187</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48886187</guid></item><item><title><![CDATA[New comment by Veserv in "Theo de Raadt: "You've been smoking something mind altering" (2007)"]]></title><description><![CDATA[
<p>Cool, show me a LPE in a seL4 deployment. Do you believe that is easier or harder than finding a KVM escape?<p>Since you are varying the security basis, implementation, and operational model simultaneously when you are comparing KVM to Linux to argue that the security basis is the important factor, I get to as well. Except mine is actually more fair because the design of a seL4-based system is actually much more similar to the design of a multi-tenant KVM-based system than the design of the KVM-based system is to the design of a Linux user environment.</p>
]]></description><pubDate>Sun, 12 Jul 2026 23:11:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48885819</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48885819</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48885819</guid></item><item><title><![CDATA[New comment by Veserv in "Theo de Raadt: "You've been smoking something mind altering" (2007)"]]></title><description><![CDATA[
<p>Great, then falsify it. Point at a system with the same operational model as KVM-based multi-tenant systems with large numbers of platform vulnerabilitys.<p>Let us review a standard operational model:<p>Virtual machines are usually pre-allocated their total RAM. Virtual machines are usually pre-allocated a number of cores and pinned to them. Virtual machines are usually only allocated a small number of devices such as a virtual block storage device and virtual network device upon which they implement a in-VM filesystem and network stack. Virtual machines usually have no access to shared services provided by the hypervisor.<p>So we have a operational model where you have to pre-allocate RAM to a process. You have to pre-allocate a whole core and pin the process to it. The process has no access to a global filesystem, network stack, or devices. The process has access to exactly one file, which is logically similar to a virtual block storage device, and a single raw network socket, which is logically similar to a virtual network device. The process has no ability to form a socket to another process, form a new file, or even have any way of interacting with other processes at all. The process has no access to shared services of any kind.<p>The chasm between that operational model and any commercial IT operating system is immense, being basically the polar opposite in every dimension in the direction of security. Default-deny instead of default-allow. Shared-nothing instead of shared-everything. What you have there is a system even more static and simple than what runs on most microkernels. That is the comparable class of platforms with a similar operational model.<p>To demonstrate that virtualization is the key factor, you need to demonstrate that actually comparable systems with similar operational models like microkernels have more platform vulnerabilitys than comparable KVM-based, or even just hypervisor-based, systems. Which, again, flies against the face of evidence as the systems that are actually used in high security applications designed to protect against state actors are separation kernels instead of hypervisors.</p>
]]></description><pubDate>Sun, 12 Jul 2026 22:58:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=48885740</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48885740</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48885740</guid></item><item><title><![CDATA[New comment by Veserv in "Theo de Raadt: "You've been smoking something mind altering" (2007)"]]></title><description><![CDATA[
<p>Virtualization is responsible for effectively none of those security benefits.<p>It is the reduction to a smaller “kernel” that is responsible. If you applied the same design and operational model to running regular old processes instead of virtual machines you would also get a system with less security holes than the grossly insecure rat’s nest that is Linux, Windows, or whatever other commercial IT OS you have in mind.<p>Virtualization is almost entirely orthogonal, if not harmful, to security of the platform and operations. It is not magic pixie dust that makes your operational model more robust. You need a robust operational model, then you can have a robust operational model with virtual machines.<p>There is a reason why the most secure systems in the world are separation kernel architectures instead of hypervisors even though most of those systems do support virtualization as a feature, just not as the basis of their security propertys.</p>
]]></description><pubDate>Sun, 12 Jul 2026 21:49:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48885162</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48885162</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48885162</guid></item><item><title><![CDATA[New comment by Veserv in "Common prefix skipping, adaptive sort"]]></title><description><![CDATA[
<p>Claims do not support themselves. The claim is unsupported by evidence and thus the burden of proof is on them or you to produce that evidence.<p>As the author and implementer of the algorithm allegedly prepared, ran, and analyzed benchmarks they obviously, by far, have the easiest time producing the evidence for their claim. Your argument that the poster needs to go read, implement, integrate, and benchmark the algorithm to to generate evidence to counter the absence of evidence for the claim is ridiculous. It would be as easy as 1-2-3 for the author to present their evidence to meet their burden of proof, yet you are demanding a extraordinary level of effort by the poster to present evidence against when they do not even have the burden of proof.<p>This is further ridiculous because the author or you would merely need to support the positive claim, where as you are demanding the poster demonstrate the negative, and all this before there is any evidence.<p>You should really stop with the unnecessarily combative tone when your entire model of argumentation is completely backwards in every respect.</p>
]]></description><pubDate>Fri, 10 Jul 2026 20:04:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48864556</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48864556</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48864556</guid></item><item><title><![CDATA[New comment by Veserv in "Neoengineers"]]></title><description><![CDATA[
<p>Writers make conscious trade offs between time, cost, feasibility. Are writers language engineers? Literally everybody makes trade offs, that is not a distinguishing aspect.<p>I am confused how you got to “make the minimal thing that ticks of [sic] all of the must requirements”. I said engineering was about <i>objective guarantees</i>. Requirements are a derivative and means of that.<p>Making things better, more efficient, cheaper, etc. is not at odds with that. If you guarantee that level of performance and achieve it, then you have produced a acceptable instance meeting your guarantees. If you fail to meet your guarantees, then you have something unacceptable.<p>Despite the tolerances of a rocket-quality screw being far better than  a car-quality screw being far better than a toy-quality screw, a car-quality screw does not get a pass in rockets because it is “better” than a toy-quality screw. It needs to meet the guarantees.<p>When you would rather have nothing over something that pretends to meet its guarantees, then you are probably in the vicinity of engineering.</p>
]]></description><pubDate>Sun, 05 Jul 2026 22:25:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48798498</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48798498</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48798498</guid></item><item><title><![CDATA[New comment by Veserv in "Neoengineers"]]></title><description><![CDATA[
<p>To add on, engineering is about <i>objective guarantees</i> to meet objective responsibility.<p>This bridge is rated for 10 tons. This chemical process produces 1 mg 99% purity crystals. This biological process produces 90% pure insulin. This circuit handles 1 kA.<p>Engineering is not about <i>better or worse</i> it is about <i>acceptable or unacceptable</i>.<p>This naturally results in a desire for <i>requirements</i> so you can meet your guarantees. Specifications so you know what guarantees you need or what you are provided and how those map back to the real responsibility. Standards so you can consistently solve common problems.</p>
]]></description><pubDate>Sun, 05 Jul 2026 20:16:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48797585</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48797585</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48797585</guid></item><item><title><![CDATA[New comment by Veserv in "Africans Are Turning to Starlink"]]></title><description><![CDATA[
<p>Why do we judge an organization by their leader and head executive who has complete control over direction and operations? Who individually has a controlling interest which can and has been used to elect himself the leader? Who regularly, openly, and publicly talks about how he needs to have control over the operation of the organization to be willing to run it?<p>You would be hard pressed to find a person who is more responsible or more representative of their organization than that.</p>
]]></description><pubDate>Sat, 04 Jul 2026 04:51:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48782717</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48782717</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48782717</guid></item><item><title><![CDATA[New comment by Veserv in "AI Data Centers Use More Water Than Most Tech Giants Report"]]></title><description><![CDATA[
<p>To add on, that is just ~40 million m^3 of water.<p>Desalination, turning unlimited sea water into fresh water which is one of the most expensive sources of fresh water, is ~0.50 $/m^3. They can literally manufacture the water they use with zero impact on the water table for ~20 million dollars.</p>
]]></description><pubDate>Fri, 03 Jul 2026 18:17:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48778085</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48778085</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48778085</guid></item><item><title><![CDATA[New comment by Veserv in "Zig – SPIR-V Backend Progress"]]></title><description><![CDATA[
<p>Capability passing and dependency injection are just convoluted ways to describe passing parameters instead of using globals.<p>Capability passing is just extending that to the level of imports. Your files do not import the global I/O library and then use io.print(). They are passed a I/O library as the parameter {io} which  defines a print() function and then call io.print().</p>
]]></description><pubDate>Tue, 30 Jun 2026 19:47:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48738259</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48738259</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48738259</guid></item><item><title><![CDATA[New comment by Veserv in "British Columbia, Time Zones, and Postgres"]]></title><description><![CDATA[
<p>No tzdata. When a time becomes the past you canonicalize it to the UTC, or better yet TAI, second it occurred at. As in, this occurred N cesium atom vibrations after the zero timestamp.<p>That is permanently fixed and can be losslessly and perfectly converted to the corresponding date in the past if you care about what local time was at that instant at some location.</p>
]]></description><pubDate>Tue, 23 Jun 2026 19:07:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=48649824</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48649824</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48649824</guid></item><item><title><![CDATA[New comment by Veserv in "Iroh 1.0"]]></title><description><![CDATA[
<p>Just to clarify are you saying a 1 gigabyte/s link or a 1 gigabit/s link? And you are seeking to saturate a 10 gigabyte/s link or a 10 gigabit/s link?</p>
]]></description><pubDate>Wed, 17 Jun 2026 02:07:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48564897</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48564897</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48564897</guid></item><item><title><![CDATA[New comment by Veserv in "When Did White-Collar Work Start to Look So Bleak?"]]></title><description><![CDATA[
<p>Obviously. The cubicle was invented as a more humane and private alternative to the standard open plan office of the 1960s, let alone hotdesking which is somehow even more of a fungible human cog than the open plan office.</p>
]]></description><pubDate>Tue, 16 Jun 2026 18:24:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48559723</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48559723</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48559723</guid></item><item><title><![CDATA[New comment by Veserv in "Formal methods and the future of programming"]]></title><description><![CDATA[
<p>> One can make the argument that the requirements is a much smaller surface to verify than that of the entire program.<p>This argument is unfortunately empirically false for any program of any meaningful complexity (>1000 lines, probably even as low as >100 lines ignoring well-defined algorithms and data structures) using current formal methods.<p>Complete formal specifications are usually multiple times larger than the corresponding source code and encode esoteric propertys necessary for the proof, but which are largely even more impenetrable than a undocumented codebase.<p>So, it is both harder to figure out if you encoded the desired requirements and it is more complex. Your only advantage is confidence that what you wrote down is proven.</p>
]]></description><pubDate>Sun, 14 Jun 2026 17:01:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48529638</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48529638</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48529638</guid></item><item><title><![CDATA[New comment by Veserv in "The Birth and Death of JavaScript (2014)"]]></title><description><![CDATA[
<p>Not at all. WASM is a repudiation of the thesis, not a confirmation.<p>The thesis is that javascript-compatible source will be the substrate of the future. A javascript engine, though one highly optimized to efficiently interpret a compatible subset, is a potential universal platform of the future despite generic javascript being a terrible substrate.<p>WASM fundamentally rejects this by creating a new javascript-incompatible substrate that is actually designed to be a low level target. Claiming WASM is confirmation of the thesis makes as much sense as claiming that a future where everybody has a Rust interpreter in the browser is confirmation of the thesis.<p>If you are arguing that, then you are just arguing that web browsers will run code in some form in some language as they already do. As the video is clearly discussing a “surprising” possible future, it makes little sense for it to be consistent with literally business as usual and literally every possible future.</p>
]]></description><pubDate>Sun, 14 Jun 2026 16:49:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48529496</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48529496</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48529496</guid></item><item><title><![CDATA[New comment by Veserv in "France's Own Hack Is the Best Argument Against Its War on Encryption"]]></title><description><![CDATA[
<p>Huh? It is a argument against government backdoor access to messages.<p>The government demonstrated that they are unqualified to keep data securely under their control. As such, any argument that a backdoor <i>only</i> allows the duly elected government access is empirically false. Any such backdoor empirically allows nefarious criminals access to your messages whereas the absence of a backdoor keeps your messages safely between you and the other party.<p>So, your options are:<p>1. Encryption with no backdoors so all messages are safe.<p>2. Criminals can freely read your messages so the government can more easily investigate potential criminals.</p>
]]></description><pubDate>Sat, 13 Jun 2026 22:10:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48521993</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48521993</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48521993</guid></item><item><title><![CDATA[New comment by Veserv in "Tesla Full Self Driving uses bicycle lane in official Denmark approval video"]]></title><description><![CDATA[
<p>Nope. Those accusations were proven false and the people who made them have lost all their credibility. It was just a smear campaign by Tesla promoters so effective that here you are parroting it against reality to protect a trillion dollar company that actively lies and promotes illegal and dangerous behavior. They really outdid themselves with that smear campaign.<p>If you disagree, I presented the criteria for evidence needed to support your case. Remember, no shaky cam.</p>
]]></description><pubDate>Fri, 12 Jun 2026 23:43:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48510705</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48510705</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48510705</guid></item><item><title><![CDATA[New comment by Veserv in "Tesla Full Self Driving uses bicycle lane in official Denmark approval video"]]></title><description><![CDATA[
<p>Ah yes, consistently, correctly, and truthfully highlighting serious safety defects and unacceptable design oversights for years in the products of a trillion dollar company with a rabid fanbase well known for running smear campaigns is "not interested in pedestrian safety".<p>I imagine everybody relishes the opportunity to get smeared by entirely false accusations by Tesla promoters with a conflict of interest. You can tell the Tesla promoters running the smear campaigns are worth listening to because their smears keep getting disproved by video evidence.<p>Please point at any clearly visible video evidence that their whistleblowing is inaccurate. No "shaky cam" "Bigfoot" evidence where you point at something blurry and falsify a claim to fit your desired narrative.<p>Your job would have been a lot easier if any of those Tesla Promoters accepted the Dawn Project's offer to attempt the tests themselves with their own Tesla's and their own cameras giving them the perfect platform to debunk the Dawn Project's claims. Weird how they all chickened out on that slam dunk.</p>
]]></description><pubDate>Fri, 12 Jun 2026 22:28:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48510155</link><dc:creator>Veserv</dc:creator><comments>https://news.ycombinator.com/item?id=48510155</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48510155</guid></item></channel></rss>