<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: harshreality</title><link>https://news.ycombinator.com/user?id=harshreality</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 28 Jul 2026 21:57:20 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=harshreality" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by harshreality in "GrapheneOS duress PIN could land a man in prison"]]></title><description><![CDATA[
<p>No, <i>not</i> things in your brain.  That's covered under the 5th amendment.  Refusing to provide information is not the same as interfering.  The portable brain scanner issue is an issue, but the legal system will get around to addressing that if and when it becomes practical enough for police to attempt using it.<p>The exceptions I know of are things like:<p>- In some situations you have to ID yourself (not just when you're driving, but that's the usual case, where they have legal authority to ID you, and if you don't have ID you have to provide the equivalent from memory so they can check your identity.)<p>- Face and Fingerprint unlocks are not things in your mind, they're not testimony, therefore you can be compelled to provide them, though usually by court order.  If a cop in the field is forcing you to face- or fingerprint-unlock your phone, that might not be allowed.<p>- In a few jurisdictions, if it's a "foregone conclusion" what's on your phone, i.e. they know from other threads of the investigation what's on it, but it's just encrypted, they <i>might</i> be able to force you to unlock it in that case, but that's through a court order not during a field investigation.</p>
]]></description><pubDate>Mon, 27 Jul 2026 08:18:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49066575</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=49066575</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49066575</guid></item><item><title><![CDATA[New comment by harshreality in "GrapheneOS duress PIN could land a man in prison"]]></title><description><![CDATA[
<p>Providing a duress PIN to wipe your phone when they ask for the passcode?  Any realistic person can predict that could have major legal repercussions.  Cypherpunks have pondered the legal consequences of blatantly doing things like that for decades.<p>Props to the defendant for volunteering as a test case.  He should've powered off his phone before he went through customs, or better yet traveled with a burner phone.<p>It doesn't matter if the feds are doing something wrong... if you <i>interfere</i> or <i>destroy</i> potential evidence, rather than simply recite your 5th and 6th amendment rights, you've put yourself in a whole new ball game.<p>He probably would've been fine if he'd maintained his refusal contingent on talking to a lawyer first.  They might not have even attempted to crack the phone, and if they had, he'd have a better chance of getting the contents thrown out than he has now of fighting the destruction of evidence charge.  The two issues are largely separate, unless a court decides the detention and attempted search were so egregious that they negate his separate, intentional act of wiping his phone when he was being detained.<p>We might wish for a mobile device to be a mobile castle immune from any [request for] search or seizure without a warrant, but that hasn't been established in case law, and everything else crossing the border (except what's diplomatically immune) is subject to some warrantless scrutiny.</p>
]]></description><pubDate>Sun, 26 Jul 2026 11:28:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=49057002</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=49057002</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49057002</guid></item><item><title><![CDATA[New comment by harshreality in "Passkeys were invented by engineers with zero understanding of consumer brain"]]></title><description><![CDATA[
<p>That's also how any good password manager works.  You'd have to manually copy-paste the password to get around the same-site fill restriction (whether it's autofill or manual fill).</p>
]]></description><pubDate>Wed, 22 Jul 2026 18:08:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=49010975</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=49010975</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49010975</guid></item><item><title><![CDATA[New comment by harshreality in "How to Abandon Your Climate Commitments and Get Away with It"]]></title><description><![CDATA[
<p>Can't happen.  Western (and most other developed/developing) economies are addicted to number-never-go-down.</p>
]]></description><pubDate>Mon, 20 Jul 2026 01:51:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48973560</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48973560</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48973560</guid></item><item><title><![CDATA[New comment by harshreality in "Qwen 3.8"]]></title><description><![CDATA[
<p>> Is it because linux and debian hate windows and iOS and want to see american [closed-source duopoly] fail?<p>maybe a little?</p>
]]></description><pubDate>Sun, 19 Jul 2026 23:16:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=48972594</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48972594</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48972594</guid></item><item><title><![CDATA[New comment by harshreality in "LG monitors silently install software through Windows Update without consent"]]></title><description><![CDATA[
<p>It's not the computer that did it.  Microsoft did it.  Microsoft enabled random hardware with random strings in their connection protocol metadata to point to software on the internet that Windows happily downloads and installs.<p>Strangely, nobody who runs linux has this problem.<p>Perhaps because windows "drivers" are so bloated with helper apps and other stuff that they can't possibly all be shipped to end users with the core OS.</p>
]]></description><pubDate>Sun, 19 Jul 2026 01:49:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48964293</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48964293</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48964293</guid></item><item><title><![CDATA[New comment by harshreality in "Texas wins court order to suspend domain name for violating age-verification law"]]></title><description><![CDATA[
<p>try adding -issuer after -dates<p>the real one is
issuer=C=US, O=Google Trust Services, CN=WE1<p>I hope you meant 1.0.2 or 3.2.  There was never an openssl v2 release, so if that's what it's reporting, you have problems.<p>The program (unitary gigantic bash script) testssl.sh (github) can give you a thorough rundown on the ssl properties of whatever's MITMing you.  The other possibility is that cloudflare is unusually serving you an alternate certificate and your ancient openssl <i>and</i> browser are both unable to handle whatever the presented cert algos/extensions are.</p>
]]></description><pubDate>Sun, 19 Jul 2026 00:40:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48963894</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48963894</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48963894</guid></item><item><title><![CDATA[New comment by harshreality in "Texas wins court order to suspend domain name for violating age-verification law"]]></title><description><![CDATA[
<p>It's being served by cloudflare and gets A+ from ssllabs.  Maybe there's something going on with your network or your browser's TLS support.</p>
]]></description><pubDate>Sat, 18 Jul 2026 07:13:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=48955903</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48955903</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48955903</guid></item><item><title><![CDATA[New comment by harshreality in "The infinite scroll may become endangered if controversial Calif. law passes"]]></title><description><![CDATA[
<p>They can randomize (with bias for hot/recent content) entries on each page, but paginate them.  FOMO will keep people clicking next even once they recognize some entries.</p>
]]></description><pubDate>Tue, 14 Jul 2026 05:56:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48902785</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48902785</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48902785</guid></item><item><title><![CDATA[New comment by harshreality in "An update on residential proxies and the scraper situation"]]></title><description><![CDATA[
<p>Putting aside the question of whether it will continue to work, even somewhat, against botnets, I find your first paragraph confusing.<p>Reload loops, or being able to "bypass" anubis (unless you merely mean bypassing it for the token validity period <i>by solving a challenge</i>), sound like misconfigurations.  There's no reason for anubis itself to cause reload loops; it's tricky to configure a webserver to use it in some scenarios.<p>Any ability to <i>bypass</i> anubis probably means the site is using it in auth/challenge mode only, and then misconfigured their webserver's auth checking.  Or it's a bug.  If you mean the double-spend tavis mentioned in his blog post which previously made the HN frontpage, that was patched right after it was reported to the maintainer almost a year ago.</p>
]]></description><pubDate>Sat, 11 Jul 2026 08:36:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48870071</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48870071</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48870071</guid></item><item><title><![CDATA[New comment by harshreality in "An update on residential proxies and the scraper situation"]]></title><description><![CDATA[
<p>Anubis's default 1-week token lifetime may not be nearly enough to dissuade enough scraper networks to make a difference, particularly with the default weight->difficulty level hierarchy, but that's for individual site admins to determine.<p>We can all argue based on how we envision "ideal" scraper networks being run and whether the web-PoW concept would stand up to that.  However, what matters at present is that anubis helps many sites cope with misbehaving bot scrapers written by the script kiddies you mention, who don't care if the internet burns as long as they finish their scrape 1 hour faster.  If anubis motivates them to devote a few brain cells to make their scrapers smarter, they may also fix the scrapers to not take down the sites they're scraping.</p>
]]></description><pubDate>Sat, 11 Jul 2026 06:41:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48869406</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48869406</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48869406</guid></item><item><title><![CDATA[New comment by harshreality in "An update on residential proxies and the scraper situation"]]></title><description><![CDATA[
<p>> ...we have tried to minimize the impact on real readers as much as possible. We have not gone with tools like Anubis, partly because it causes annoying delays for those trying to get to the site, but also partly because it seems inevitable that the scrapers will eventually find their way around it. Indeed, there are some indications that is already happening. A proof-of-work requirement is not a huge obstacle when you have millions of other people's machines to do the work on.<p>It's massively less annoying than a captcha, which is both a longer delay (typically, at present) and a massive cognitive distraction/roadblock.<p>The anubis author has stated they recognize it's an arms race, but PoW scales.  Captchas and other signals are already at the end of the road; any additional difficulty increases false bot-positives, which are already unacceptably high.<p>For websites running dynamic languages, a binary (anubis is in go) sentry that operates <i>before</i>[1] the website is forced to expend any resources, is usually a large improvement over a site-hosted captcha.  I would rather, and I think most humans would agree, have to wait a few seconds, maybe even closer to a minute in the future, to get a website access token good for a day or a week, than be forced to solve a captcha.<p>The dilemma for bots: when tokens are bound to the connecting ip, scrapers must limit the connecting IP pool for each site they want to scrape, becoming <i>much more obvious and easy to block</i>, or they have to use <i>massive</i> amounts of compute.<p>[1] this is true regardless of whether anubis is in reverse proxy mode or auth mode.</p>
]]></description><pubDate>Sat, 11 Jul 2026 00:01:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48866932</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48866932</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48866932</guid></item><item><title><![CDATA[New comment by harshreality in "A road to Lisp: Why Lisp"]]></title><description><![CDATA[
<p>MacOS Chrome?  The code blocks look fine to me in linux {firefox, chromium, brave}.  I think they're all using Qt.</p>
]]></description><pubDate>Fri, 10 Jul 2026 01:01:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=48854503</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48854503</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48854503</guid></item><item><title><![CDATA[New comment by harshreality in "Grok 4.5"]]></title><description><![CDATA[
<p>We're killing a lot more people than that; if we'd just tax the rich at 80% and send all that money abroad, we'd save millions more.  Failure to do that is mass murder, the same as decreasing foreign aid funding; that is your thesis, right, that it's mass murder?<p>Doing less to save people in other countries that have no legal demand on our treasury is not "being responsible for [their] deaths."  It's tragic, and it may even be a <i>bad policy decision</i>, but there's no responsibility (in the "duty to prevent harm" sense) or evil there.</p>
]]></description><pubDate>Thu, 09 Jul 2026 00:44:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48839480</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48839480</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48839480</guid></item><item><title><![CDATA[New comment by harshreality in "Google Books (or similar) all book scans – $200k bounty (2025)"]]></title><description><![CDATA[
<p>I'm not here to defend publishers or the insane current copyright terms.  However, in the traditional model of publishing, publishers subsidize production of new books from unproven authors--through book advances, copyediting services, and printing and distribution costs--via the money they make on the few successful and very few ultra-successful books.<p>If you take away copyright, you reduce the revenue of publishers, which reduces the number of unproven authors they can take chances on.  (They're not very good at picking winners from the pool of new author manuscripts, not nearly as good as "agents" like to think they are, but that doesn't matter; they still wouldn't be able to take as many chances.)</p>
]]></description><pubDate>Sun, 05 Jul 2026 09:08:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=48792532</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48792532</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48792532</guid></item><item><title><![CDATA[New comment by harshreality in "Google Books (or similar) all book scans – $200k bounty (2025)"]]></title><description><![CDATA[
<p>If knowledge is to be free, then any corporate/commercial interest that locks up modified knowledge (code) to run their own services should have that locked-up knowledge freed from their commercial silo as well.</p>
]]></description><pubDate>Sun, 05 Jul 2026 03:24:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=48791003</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48791003</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48791003</guid></item><item><title><![CDATA[New comment by harshreality in "Age verification is just a precursor to automated attribution of speech"]]></title><description><![CDATA[
<p>A generation of kids have grown up with just such assigned adults, who overwhelmingly did not apply sufficient oversight to the kids' use of social media.<p>In large part that's because, if they'd done so, the kids would've been socially isolated from their peers, at least the most normal ones with the most normal parents, which are the kinds of friends most other normal parents want their kids to have.<p>It's a collective action problem, except instead of "I can be better off if I ignore what I know is best for society", it's "if I ignore what I know is best for my kids psychologically, they will still have friends, and social media brainrot is a lesser evil than socially isolating my kid from all the normal kids at school."<p>And also, giving kids social media interaction devices is a convenient form of babysitting.  It reduces up-front effort of parenting.</p>
]]></description><pubDate>Mon, 29 Jun 2026 10:41:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48717435</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48717435</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48717435</guid></item><item><title><![CDATA[New comment by harshreality in "Choosing a Public DNS Resolver"]]></title><description><![CDATA[
<p>Why pre-cache?  For speed... what is it, 30-50ms at most?  If the authoritative server's TTL is <60minutes, do you force it to 3600?  Do you audit all the connections that occur for every website you visit, collect all the domains hosting assets, and pre-cache those as well, or is the main site's domain the only critical one because that affects perceived latency the most?</p>
]]></description><pubDate>Sun, 28 Jun 2026 00:43:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48703236</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48703236</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48703236</guid></item><item><title><![CDATA[New comment by harshreality in "California AB 2047 makes 3D printers off-limits to students, educators, business"]]></title><description><![CDATA[
<p>A law like this just passed in New York State.<p>If this fails it'll be because the tech industry expresses disapproval too loudly to ignore.<p>The legislators don't care about the underlying criticism.  Almost no legislators have ever used a 3d printer or written any software, beyond <i>maybe</i> simple assigned programs if they had a required intro-to-programming course.  Few are "tech" people.  The rest don't understand this technology, or any technology really, beyond it being a black box for specific purposes.  They see 3d printing and plastic guns and think something must be done, because the 3d printing black boxes are producing dangerous weapons.</p>
]]></description><pubDate>Tue, 23 Jun 2026 23:36:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48653166</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48653166</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48653166</guid></item><item><title><![CDATA[New comment by harshreality in "Show HN: Oak – Git alternative designed for agents"]]></title><description><![CDATA[
<p>From the github repo readme:<p>> This repo was written almost entirely using AI with human oversight. If you see anything that needs fixed or would like to contribute, please email ... or reach out on Discord<p>Why not just provide an email address that's delivered directly to the agents you have developing Oak?<p>I didn't delve into the benchmark repo to understand what your loop is measuring.  Why would an agent (without fine tuning or oak-specific context) be faster with oak than it is with git or jj?</p>
]]></description><pubDate>Mon, 22 Jun 2026 21:34:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48636535</link><dc:creator>harshreality</dc:creator><comments>https://news.ycombinator.com/item?id=48636535</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48636535</guid></item></channel></rss>