<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: naturalmovement</title><link>https://news.ycombinator.com/user?id=naturalmovement</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 14 Jun 2026 21:56:51 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=naturalmovement" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by naturalmovement in "Caddy compatibility for zeroserve: 3x throughput and 70% lower latency"]]></title><description><![CDATA[
<p>That's literally how client certificates work.<p>It's not attempting to "read" anything, nor is it the least bit suspicious or malicious.<p>Your browser was asked if it would like to present a certificate to authenticate, and you were prompted to choose one if you please. You can also hit cancel as client auth can be optional and the server will either serve you the page or a 401/403.<p>It's like being asked to show ID to enter a pub, you can either show one or decline, and they may or may not let you enter based on that transaction.</p>
]]></description><pubDate>Sun, 14 Jun 2026 19:08:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=48531350</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48531350</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48531350</guid></item><item><title><![CDATA[New comment by naturalmovement in "Linux 7.1"]]></title><description><![CDATA[
<p>Is it safe to assume we can see this in Debian Stable around 2036?</p>
]]></description><pubDate>Sun, 14 Jun 2026 17:34:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=48530114</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48530114</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48530114</guid></item><item><title><![CDATA[New comment by naturalmovement in "Honda Civics and the Evil Valet"]]></title><description><![CDATA[
<p>Having rented a car and seeing 80 variations of "Ben's iPhone" in the Bluetooth pairing list leads me to believe 99.99% of society isn't worried about this.<p>Another thing to consider is Honda may have signed these packages with a wink and a nudge, because it may be required, regulatory or Android or otherwise, but they're also not interested in building closed devices. Instead of thanking them we're complaining.</p>
]]></description><pubDate>Sun, 14 Jun 2026 05:43:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48524518</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48524518</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48524518</guid></item><item><title><![CDATA[Tribblix: The retro Illumos distribution]]></title><description><![CDATA[
<p>Article URL: <a href="http://tribblix.org/">http://tribblix.org/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48524434">https://news.ycombinator.com/item?id=48524434</a></p>
<p>Points: 76</p>
<p># Comments: 28</p>
]]></description><pubDate>Sun, 14 Jun 2026 05:23:12 +0000</pubDate><link>http://tribblix.org/</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48524434</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48524434</guid></item><item><title><![CDATA[New comment by naturalmovement in "Honda Civics and the Evil Valet"]]></title><description><![CDATA[
<p>If I'm reading the room, the sentiment is Honda is incompetent and their cars are security holes on wheels. But if the opposite happened, they would be technofascists locking us out of our own cars, a 30 post sub-thread "this is why I drive a 1999 Ford Ranger" would ensue, and someone would be investigating it as a possible GPL violation. Do I have this right?<p>It's also a good assumption most people airing such complaints have never eaten in a restaurant fancy enough to have valet parking, let alone <i>evil</i> valets.<p>That said, are evil valets known to tote around USB drives, or would they more likely use your navigation system to drive back to your empty house and clean it out while you're eating?</p>
]]></description><pubDate>Sun, 14 Jun 2026 04:55:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48524306</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48524306</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48524306</guid></item><item><title><![CDATA[New comment by naturalmovement in "ReactOS (FOSS "Windows") achieves 3D-accelerated Half-Life on real hardware"]]></title><description><![CDATA[
<p>Maybe worry about Linux malware which is a major problem right now everyone is in huge denial about, instead of throwing shade at a hobby OS emulating a 25 year old version of Windows.<p>ReactOS isn't the one that just had one of its package repos owned (again).</p>
]]></description><pubDate>Sun, 14 Jun 2026 02:03:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48523473</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48523473</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48523473</guid></item><item><title><![CDATA[New comment by naturalmovement in "Running DOS on Behringers DDX3216 with a DIY x86-Bios from Scratch"]]></title><description><![CDATA[
<p>Using x86 in embedded products is not new, especially older ones from the 90s, it was extremely common actually to run DOS or VXworks or QNX. It's all over industrial products. In fact Intel still shipped 386 CPUs until a few years ago.* It's cool and all but if we wrote blog posts about all of them you'd be set for the next 10 years.<p>* Supposedly 2007 but that does not sound right for embedded customers unless Intel built a lifetime supply.</p>
]]></description><pubDate>Sat, 13 Jun 2026 20:33:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48521156</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48521156</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48521156</guid></item><item><title><![CDATA[New comment by naturalmovement in "Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages"]]></title><description><![CDATA[
<p>> AUR isn't a package repo.<p>What does the 'R' in AUR stand for? Rutabaga?</p>
]]></description><pubDate>Sat, 13 Jun 2026 19:07:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48520391</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48520391</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48520391</guid></item><item><title><![CDATA[New comment by naturalmovement in "Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages"]]></title><description><![CDATA[
<p>The BSDs prevent this by never having allowed random jamokes to upload Makefiles into the ports system.</p>
]]></description><pubDate>Sat, 13 Jun 2026 16:55:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48519075</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48519075</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48519075</guid></item><item><title><![CDATA[New comment by naturalmovement in "Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages"]]></title><description><![CDATA[
<p>Uh but this isn't random git repos these are packages available through the OS's repos. Why does the AUR even exist if not for malware distribution?<p>It's an uncontrolled free-for-all disguised as a watering hole. If they can't do the most basic of housekeeping it should not exist full stop.</p>
]]></description><pubDate>Sat, 13 Jun 2026 16:54:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48519064</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48519064</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48519064</guid></item><item><title><![CDATA[New comment by naturalmovement in "Introduction to UEFI HTTP(s) Boot with QEMU/OVMF"]]></title><description><![CDATA[
<p>They have a hard enough time managing the relatively few certificates for secure boot.<p>You want me to believe all the various BIOS manufacturers are going to competently manage a WebPKI root certificate program?</p>
]]></description><pubDate>Sat, 13 Jun 2026 08:05:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48514709</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48514709</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48514709</guid></item><item><title><![CDATA[New comment by naturalmovement in "There is a shadow hanging over this Fable thing"]]></title><description><![CDATA[
<p>> where companies that bribe government officials get preferred treatment<p>Do you think lobbying did not exist prior to two years ago?</p>
]]></description><pubDate>Sat, 13 Jun 2026 07:58:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=48514650</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48514650</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48514650</guid></item><item><title><![CDATA[New comment by naturalmovement in "Twenty One Zero-Days in FFmpeg"]]></title><description><![CDATA[
<p>Security is a bit different.<p>Today it's an industry driven by unscrupulous clout-chasers and a commitment to quantity over quality.<p>There is a difference between going through patches and pull requests vs. the endless stream of LLM-assisted bullshit that has started cluttering security inboxes in the last few years.</p>
]]></description><pubDate>Sat, 13 Jun 2026 02:45:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=48512241</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48512241</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48512241</guid></item><item><title><![CDATA[New comment by naturalmovement in "US Government directive to suspend access to Fable 5 and Mythos 5"]]></title><description><![CDATA[
<p>Are you saying everyone is failing to recognize the AI revolution is entirely built atop the Terry Davises of the world?</p>
]]></description><pubDate>Sat, 13 Jun 2026 02:35:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=48512121</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48512121</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48512121</guid></item><item><title><![CDATA[New comment by naturalmovement in "Twenty One Zero-Days in FFmpeg"]]></title><description><![CDATA[
<p>I have numerous examples of security researchers being hostile and impossible to work with (but cannot share them unfortunately).</p>
]]></description><pubDate>Sat, 13 Jun 2026 01:53:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48511673</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48511673</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48511673</guid></item><item><title><![CDATA[New comment by naturalmovement in "Statement on US government directive to suspend access to Fable 5 and Mythos 5"]]></title><description><![CDATA[
<p>Brilliant analogy<p><a href="https://www.youtube.com/watch?v=DAuG7_acmdA" rel="nofollow">https://www.youtube.com/watch?v=DAuG7_acmdA</a></p>
]]></description><pubDate>Sat, 13 Jun 2026 01:30:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=48511436</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48511436</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48511436</guid></item><item><title><![CDATA[New comment by naturalmovement in "Twenty One Zero-Days in FFmpeg"]]></title><description><![CDATA[
<p>> AI slop is a real problem and annoying. Just because it exists does not mean every vulnerability report is AI slop.<p>Ok but who is going to sift through it all to triage the good bits when you're working on something for free?<p>> Ffmpeg devs are free not to care, but then they cant complain when they start to get a bad reputation<p>Who gives a shit about reputation when you're the only game in town?<p>There is nothing out there that even attempts to approximate an ffmpeg clone. They are the Swiss army knife of media encoding and all complainers have produced are plastic sporks.</p>
]]></description><pubDate>Sat, 13 Jun 2026 00:52:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48511077</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48511077</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48511077</guid></item><item><title><![CDATA[New comment by naturalmovement in "Twenty One Zero-Days in FFmpeg"]]></title><description><![CDATA[
<p>If there was a nearly inexhaustible supply of Indian security researchers emailing you a nearly inexhaustible supply of LLM slop daily, there is a point where you or I would stop caring too.<p>ffmpeg is Free Software. You are also free not to use it.<p>Oddly enough, despite all these endless grievances, no one has come up with a better or more capable tool, certainly not one that is freely available.<p>Evidently no one cares either, because most implementations of ffmpeg I've seen typically run it as root "because we have to". <i>Don't worry we use Docker bro.</i></p>
]]></description><pubDate>Sat, 13 Jun 2026 00:41:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=48511032</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48511032</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48511032</guid></item><item><title><![CDATA[New comment by naturalmovement in "Introduction to UEFI HTTP(s) Boot with QEMU/OVMF"]]></title><description><![CDATA[
<p>Ok, but so what?<p>You guys are out here protecting against ghosts but at the same time making the really important stuff 10x harder and more vulnerable to bugs.</p>
]]></description><pubDate>Fri, 12 Jun 2026 22:41:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=48510226</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48510226</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48510226</guid></item><item><title><![CDATA[New comment by naturalmovement in "Introduction to UEFI HTTP(s) Boot with QEMU/OVMF"]]></title><description><![CDATA[
<p>I can guarantee you with nearly 100% certainty that UEFI TLS clients are bound to be buggy garbage broken in not-insignificant ways.</p>
]]></description><pubDate>Fri, 12 Jun 2026 22:39:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=48510217</link><dc:creator>naturalmovement</dc:creator><comments>https://news.ycombinator.com/item?id=48510217</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48510217</guid></item></channel></rss>