<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: franga2000</title><link>https://news.ycombinator.com/user?id=franga2000</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 22 Jul 2026 09:29:42 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=franga2000" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by franga2000 in "TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years"]]></title><description><![CDATA[
<p>A large part is also how much you read back what the model writes. The good models generally write quite secure code, but they also often implement temporary solutions that they tell you to fix later.<p>For example, if secret storage methods aren't specified in the prompts, a model might decide to be clever and implement a generic secret access interface, with a default implementation that hardcodes everything. It will probably tell you that this is not production ready and you should write or specify your preferred secret storage implementation, but if you don't read or understand that, you'll just leave it as is and push to prod.</p>
]]></description><pubDate>Sat, 18 Jul 2026 11:28:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48957043</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48957043</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48957043</guid></item><item><title><![CDATA[New comment by franga2000 in "GhostLock, a stack-UAF that has existed in all Linux distributions for 15 years"]]></title><description><![CDATA[
<p>Realistically, if you have a browser sandbox, the system LPE exploit gives you very little more. Everything interesting on a desktop system is accessible by the user account directly.</p>
]]></description><pubDate>Mon, 13 Jul 2026 12:22:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48891625</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48891625</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48891625</guid></item><item><title><![CDATA[New comment by franga2000 in "CoMaps – FOSS Offline Maps"]]></title><description><![CDATA[
<p>Given the nature of the problems with OM, this makes sense. The dispute is about governance and money, which is something that only the people involved in development will deeply care about. It makes sense they're the main people talking about it.</p>
]]></description><pubDate>Tue, 07 Jul 2026 06:44:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48814411</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48814411</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48814411</guid></item><item><title><![CDATA[New comment by franga2000 in "It's not about physical vs. digital games, it's about ownership"]]></title><description><![CDATA[
<p>It's a completely different license. A normal software license gives you the right to use version X of the software on Y computers/seats/users/... You have the original installer on the disc, you can download installers for patch releases online and save them for later, you have the activation key. At any point, you can uninstall the software and give or sell the installer and key to someone else.<p>What games and some software do these days is much worrse. You have a license to use their "software installation service" and their "let me run the game" service until they decide to turn them off. At any point, at their discretion, they can remove your ability to install a new copy or even run it all together.<p>Very different and quite recent.</p>
]]></description><pubDate>Sun, 05 Jul 2026 19:38:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48797270</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48797270</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48797270</guid></item><item><title><![CDATA[New comment by franga2000 in "The 'papers, please' era of the internet will decimate your privacy"]]></title><description><![CDATA[
<p>That's just it - if remote attestation becomes commonplace, you can't make your own devices. No apps you need to live your life will work, no mainstream websites will let you visit them... Not to mention that once you get to hardware, "just build your own" login simply stops working.<p>The internet has plent, of security elements. Devices use TLS to communicate, are encrypted by disk encryption, users' messages/calls/data are encrypted with various protocols... This is already in place.<p>Building codes and such are laws, the government didn't go and change the laws of physics to make it impossible to build something not up to code. They also don't limit the same of materials and tools to only certified builders who they know will respect the code. You can still break the rules to some extent, or even follow them, just without external certification.<p>Remote attestation and related technologies change the laws of physics - not complying is simply not possible. You can't just make one little change and hope nobody bothers you about it, the system makes the change impossible, or it detects it and "burns the whole house down".<p>If your house isn't certified because you repaired a light fixture on your own, you can still invite friends over, you can receive mail and packages to it, you can get phone, internet and other utilities. If you want to change the color of the icons on your phone, or if you want to disable the pre-installed spyware, you're cut off from talking to your firends and family, from social networks, reading the news, you can't pay your taxes, can't get a bank account, can't get paid for your work or even apply for a job. That is the reality we're going towards.<p>The thing that changes isn't that your every action will be followed. That already happens. It's that you are powerless to avoid it. It's a technological lock to keep you obedient. There is no security element to it. We as an industry need to stop pretending like these are security technologies and start talking to more social sciences experts. Before it's too late...</p>
]]></description><pubDate>Sat, 27 Jun 2026 08:15:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48696225</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48696225</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48696225</guid></item><item><title><![CDATA[New comment by franga2000 in "The 'papers, please' era of the internet will decimate your privacy"]]></title><description><![CDATA[
<p>What you also get is mobile devices that can't run unblessed code, make it impossible to remove legally-mandated spyware or backdoors, as well as websites that you can't use anonymously, even when you have very valid reasons to do so.</p>
]]></description><pubDate>Fri, 26 Jun 2026 17:18:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48689173</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48689173</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48689173</guid></item><item><title><![CDATA[New comment by franga2000 in "The 'papers, please' era of the internet will decimate your privacy"]]></title><description><![CDATA[
<p>Trusted computing is the biggest threat to privacy and liberty of them all!</p>
]]></description><pubDate>Fri, 26 Jun 2026 06:43:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48683157</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48683157</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48683157</guid></item><item><title><![CDATA[New comment by franga2000 in "Anthropic says Alibaba illicitly extracted Claude AI model capabilities"]]></title><description><![CDATA[
<p>Cool, then they can train their proprietary models on their proprietary data only.<p>Even if the other models were trained on the same data, which is unlikely, since they had less time and money to scrape it and fewer lawyers to be able to do something like pirate, the proprietary models are still largely built on the public data and wouldn't exist without it. At the very least, they should release the intermediate model, before training on their proprietary data. Not that that's how that works...</p>
]]></description><pubDate>Thu, 25 Jun 2026 14:58:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=48674441</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48674441</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48674441</guid></item><item><title><![CDATA[New comment by franga2000 in "I built an offline tool to stabilize TV audio because nothing else worked"]]></title><description><![CDATA[
<p>So much LLM marketing/hype speak in the readme, so many moving parts, failure points, wasted CPU cycles, added latency, not to mention the externalities of the tokens that were burned on this...all to do what even the cheapest audio processors are able to do.<p>Back in the day you could dismiss all of that as "it's part of the learning path" and yes, I made over-engineered non-solutions to long-solved problems when I started programming too. But this isn't learning. It's pure LLM slop.<p>LLMs are doing the thing that greedy/unethical programmers used to. They'd quote a client a dozen microservices and four months of work for something that could be solved by writing a slightly longer Excel formula. Not that the quote was crazy or the work was poorly done, it just wasn't anywhere near necessary to solve the problem. But they got paid and the client was happy because they didn't know any better...until I showed up to ruin the fun.</p>
]]></description><pubDate>Tue, 23 Jun 2026 06:10:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48641013</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48641013</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48641013</guid></item><item><title><![CDATA[New comment by franga2000 in "There are no instances in ATProto"]]></title><description><![CDATA[
<p>TL;DR: people complaining why there aren't bluesky instances are misunderstanding atproto. There are no "instances" like in Mastodon, atproto is different, it uses many "hostings". Except those hostings are just instances of the hosting software. And there in fact aren't that many.<p>But you're just Mastodon-brained, you don't get it!</p>
]]></description><pubDate>Sat, 20 Jun 2026 11:37:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48608474</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48608474</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48608474</guid></item><item><title><![CDATA[New comment by franga2000 in "Leaving Mozilla"]]></title><description><![CDATA[
<p>You're missing the point. If someone doesn't want to use AI features, they can just NOT. USE. THEM. That's it. Just don't press the AI button. Is it that hard? Would you say Mozilla is deleting all your data because there's a "Delete cookies and history" button in the menu? You can just NOT. PRESS. THE. BUTTON.<p>The master AI switch doesn't actually change whether the browser uses AI features - it never does unless you specifically run them. What it does is hides them from the user, pretending they don't exist.<p>Browsers that don't respect their users' choices about using AI do things like automatically download large models in the background, integrate cloud-based speech recognition and synthesis as an API available to any website and make the default search engine which they also own show LLM slop above actual results.</p>
]]></description><pubDate>Sat, 13 Jun 2026 12:16:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48516544</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48516544</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48516544</guid></item><item><title><![CDATA[New comment by franga2000 in "Twenty One Zero-Days in FFmpeg"]]></title><description><![CDATA[
<p>The user is not free to use whatever codec they want. Many niche codecs can't be put into the usual containers, so if you only accept QuickTime/MP4 and AVI, sometimes even just by limiting the file extension, those codecs can't be used.<p>If your service works by taking whatever file the user gives you and shoving it into unsandboxed ffmpeg, you've already fucked up. It would be nice if you could do that, but that's not a guarantee ffmpeg has ever provided, nor would it make sense for them to spend their limited resources on it.</p>
]]></description><pubDate>Sat, 13 Jun 2026 09:50:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48515424</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48515424</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48515424</guid></item><item><title><![CDATA[New comment by franga2000 in "Leaving Mozilla"]]></title><description><![CDATA[
<p>Keep in mind that while Firefox offered 20 extensions on mobile, Chrome offered zero and continues to lack any support for extensions whatsoever. Nobody ditched Firefox for Chrome because of the extensions thing.<p>The move to WebExtensions was painful, but it also made it possible to easily port Chrome extensions to Firefox, which was a great boost for the extension ecosystem, as well as being the thing that actually made mobile extensions possible.<p>I do agree they should've made the transition period longer though. There were like two years in between where some of the big Chrome extensions hadn't been ported yet, but their original Firefox counterparts were already killed. That probably made a few users move ti Chrome, but that was already during the great Chrome migration, so I can't imagine this made a huge difference.</p>
]]></description><pubDate>Sat, 13 Jun 2026 09:31:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48515288</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48515288</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48515288</guid></item><item><title><![CDATA[New comment by franga2000 in "Leaving Mozilla"]]></title><description><![CDATA[
<p>You're complaning that the browser that "puts you back in control"
... put you back in control of which AI features you want to enable/disable? How horrible!<p>What? They didn't make these 10 distinct features one single all-or-nothing button? They let you switch them on or off individually?? How dare they?!?<p>What? They shipped new features to the browser...turned on?!? Instead of spending all those development hours and then...hiding them behind a setting by default?<p>I need "AI" in my browser, so I don't use the AI features. No data was sent anywhere. No 4 GB model was downloaded. Nothing happened, except for a popup saying "hey, by the way, if you want to do X, just press this button here". It's just UI elements. No AI-related code runs, no data is sent to AI companies unless you directly tell the browser to do that.<p>Imagine if Firefox shipped a brand new GPU-accelerated compositor, improved hardware video decoding and WebGL/WebGPU. You people cry about why they didn't add a big "disable GPU features" button? And that they dared to enable this by default?</p>
]]></description><pubDate>Sat, 13 Jun 2026 09:17:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48515198</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48515198</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48515198</guid></item><item><title><![CDATA[New comment by franga2000 in "Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]"]]></title><description><![CDATA[
<p>Any DNS-based solution needs something like DNSSEC to work. I believe DNSSEC didn't exist yet when HTTPS was being developed and even if it did, it wasn't anywhere near ubiquitous enough. Is it even these days?</p>
]]></description><pubDate>Wed, 10 Jun 2026 07:40:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48472850</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48472850</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48472850</guid></item><item><title><![CDATA[New comment by franga2000 in "Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]"]]></title><description><![CDATA[
<p>Not back when SSL and the PKI ecosystem was developed.</p>
]]></description><pubDate>Tue, 09 Jun 2026 16:01:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48462848</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48462848</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48462848</guid></item><item><title><![CDATA[New comment by franga2000 in "Surveillance is not safety: A statement on the UK's latest threat to privacy [pdf]"]]></title><description><![CDATA[
<p>This assumes surveillance prevents crime, or even that crime is worth preventing if surveillance is the cost.<p>In terms of everyday threats to my life, billionaires are a bigger one than criminals.</p>
]]></description><pubDate>Mon, 08 Jun 2026 22:07:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48452970</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48452970</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48452970</guid></item><item><title><![CDATA[New comment by franga2000 in "SQLite is all you need for durable workflows"]]></title><description><![CDATA[
<p>It's complexity you already have. You need some sort of HA for your app server and some sort of resilient storage for your database server. Using sqlite just means the storage is used by the app server directly, nothing more.</p>
]]></description><pubDate>Sun, 31 May 2026 08:07:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48343909</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48343909</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48343909</guid></item><item><title><![CDATA[New comment by franga2000 in "SQLite is all you need for durable workflows"]]></title><description><![CDATA[
<p>1. Proxmox live migration or HA, Ceph storage<p>2. K8S DaemonSet, PVC backed by probably Ceph<p>3. Just..don't care? Do maintenance outside of working hours, fix issues quickly and explain things nicely to your customers. Not everything is google-scale. Most people can deal with some downtime.<p>And it's not like you won't have downtime in let's say a postgres-backed app. But now you have two "servers" to deal with.</p>
]]></description><pubDate>Sat, 30 May 2026 20:40:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=48340401</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48340401</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48340401</guid></item><item><title><![CDATA[New comment by franga2000 in "SQLite is all you need for durable workflows"]]></title><description><![CDATA[
<p>Yes? Well, every "app", as I quite explicity wrote. Look up the docker compose file or helm chart for basically any app. I'm running dozens of apps, each with their own postgres, redis and nginx containers alongside the main application server. That's what the stack is designed for.</p>
]]></description><pubDate>Sat, 30 May 2026 09:52:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48334485</link><dc:creator>franga2000</dc:creator><comments>https://news.ycombinator.com/item?id=48334485</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48334485</guid></item></channel></rss>