<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ocdtrekkie</title><link>https://news.ycombinator.com/user?id=ocdtrekkie</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 27 Sep 2026 07:19:58 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ocdtrekkie" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ocdtrekkie in "Fixing the Portobello Police Station Clock"]]></title><description><![CDATA[
<p>Pro tip for sump pumps: Get a <i>float switch</i> instead of a liquid sensor. That tells you if the water level is too high or not, not if the sensor is wet.<p>- You want to know this before water is on the floor.<p>- Sump pits tend to be splashy in heavy water flow.<p>- The float switch will correctly return to "it's fine" status when the problem is no longer occurring.<p>Liquid sensors are great for "my basement is flooding", float switches are great for "I need to fix my pumps before my basement floods.</p>
]]></description><pubDate>Sat, 26 Sep 2026 02:22:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49852587</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49852587</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49852587</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Sourcehut account takeover via build logs (XSS in ansi2html)"]]></title><description><![CDATA[
<p>Quality placement, no notes. I saw this comment before reading the article, still clicked it and felt got.</p>
]]></description><pubDate>Fri, 25 Sep 2026 07:39:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49841367</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49841367</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49841367</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Disney+ and Hulu raise prices by up to 13 percent after doubling profits"]]></title><description><![CDATA[
<p>The unfortunate reality is this is why we have residential botnets. Your friend is probably paying for his free TV by attacking things over the Internet.</p>
]]></description><pubDate>Thu, 24 Sep 2026 16:17:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49832866</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49832866</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49832866</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "SAML: A fractal of bad design"]]></title><description><![CDATA[
<p>Everything can stack onto everything else, sure. Most people's SAML IdPs are... synced from their LDAP. =) But in particular SAML provides an SSO experience where signing in once in the browser will allow you to go to various integrated sites and apps without signing in again. That flow is not <i>dissimilar</i> from OIDC but it is <i>separate</i>. So I can have 10 apps with SAML and 1 with OIDC, and the OIDC one is gonna be an odd duck.<p>And a key aspect that modern setups often forget: Every single different UI your users see makes them easier to phish. One of the reasons Entra is so easily phishable is Microsoft uses like 500 different domains for their cloud platform, so the one in the mix they don't actually own isn't obvious to the average user.</p>
]]></description><pubDate>Wed, 23 Sep 2026 00:52:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=49810274</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49810274</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49810274</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "SAML: A fractal of bad design"]]></title><description><![CDATA[
<p>It's outdated in the way that the author doesn't like it, but SAML will probably outlive OIDC.</p>
]]></description><pubDate>Wed, 23 Sep 2026 00:41:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=49810194</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49810194</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49810194</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "SAML: A fractal of bad design"]]></title><description><![CDATA[
<p>As a SaaS customer, interacting with SaaS vendors tends to entail:<p>1. Finding out a company wants several grand to flip the "allow SAML" switch on the tenant config, and a few thousand a year in additional licensing to leave it on. (I had a vendor both tell me it "takes five minutes" to get it set up, and then quote me $4,800 to "implement" it.)<p>2. Having to yell at the SaaS vendor for routing the identity connection between two or three other identity providers in different various clouds because, you know "modern stuff". (A vendor I am working with has not less than five different accounts to access various parts of their infrastructure, none of which are connected at all. I assume people there listened to "switch to OIDC" nonsense, completed half the job, and now have OIDC sites and SAML sites forever.)<p>3. Discovering the SaaS vendor knows how Entra works, how Okta works, and how Google auth works, and having no idea how SAML works. Or OIDC or anything else for that matter.<p>4. Eventually finding an engineer far enough from the sales and implementation teams who can answer how the product actually works. :D This point is reached after a lot of yelling.</p>
]]></description><pubDate>Tue, 22 Sep 2026 20:08:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=49807373</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49807373</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49807373</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "SAML: A fractal of bad design"]]></title><description><![CDATA[
<p>Entra is just allowing the Chinese government in your environment. Why bother with authentication at all?<p><a href="https://www.war.gov/News/News-Stories/Article/Article/4288992/pentagon-halts-chinese-coders-affecting-dod-cloud-systems/" rel="nofollow">https://www.war.gov/News/News-Stories/Article/Article/428899...</a> (Microsoft has solely discontinued this practice for the DoD tier. Commercial, GCC, and GCC High are still impacted because foreign labor is cheaper than the risk to your security.)</p>
]]></description><pubDate>Tue, 22 Sep 2026 20:01:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49807291</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49807291</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49807291</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "SAML: A fractal of bad design"]]></title><description><![CDATA[
<p>Eh, if you don't have SAML support, I can find a product that does. Not a problem. \o/<p>(Or to be more clear, it is mostly unacceptable for an enterprise product to have opinionated decisions about what authentication it works with. You either work with what we use or you are not viable as a product for our need. It's kinda simple. I would expect someone whose authentication was OIDC-based to be similarly dismissive if you told them you only would do SAML.)</p>
]]></description><pubDate>Tue, 22 Sep 2026 19:33:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=49806910</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49806910</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49806910</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Data Protection Commission fines Google €403M over processing of location data"]]></title><description><![CDATA[
<p>They just need to ban these companies from operating in their countries. They are fundamentally burdens on society run by bad people.<p>Your best case scenario with fines is getting them into the narrow definition of compliance just until a new "innovation" gives them a different way to conduct the same abuse while evading the letter of previous judgments.</p>
]]></description><pubDate>Mon, 21 Sep 2026 23:39:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=49794911</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49794911</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49794911</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Seattle Bans Rental Junk Fees"]]></title><description><![CDATA[
<p>I mean obviously fees should either be included in the original price, or there <i>should</i> be a reason it might apply in some cases but not others. But I can also see someone just wanting to break out the costs as separate line items to highlight where their costs come from. (Here's what I pay for the property taxes, here's what I pay for the included utilities, here's what I pay for these maintenance services, so tada, there's your rent.)<p>But again, if the <i>advertised price must be the total price</i>, it doesn't matter if there's a mailbox access fee or not. It's no different than if they eliminate the fee but raise the price the same amount. Make the advertised price be the highest price, and say "hey, you can advertise discounts off of that".<p>Nobody's going to advertise you can save $5 a month by eliminating your mailbox.<p>A similar effect, would be no longer advertising a plan's price if you enable paperless billing and autopay. You'd have to advertise the price without, and then can offer discounts for those things.<p>Or movie ticket prices being required to be listed with the convenience fee included, and if a theater wants, it can advertise a discount for buying a ticket some other way. More than likely that would just kill convenience fees.</p>
]]></description><pubDate>Mon, 21 Sep 2026 18:28:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49791301</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49791301</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49791301</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Seattle Bans Rental Junk Fees"]]></title><description><![CDATA[
<p>I think in general my preference is the other part of this story: Rather than choosing what fees can and can't be offered, require both brutal price transparency and prohibit advertising the unrealistic/lesser cost.<p>A friend of mine has recently lamented the idea gas stations can advertise "with car wash" pricing on top with what is "fine print" on the sign, which looks good but isn't when you factor in the cost of the car wash.<p>Another favorite is the personal loan ad, saying you're preapproved for a loan as low as 6% APR but actually you can be denied and the loan could be up to 36% APR even if you get approved. Nonsense.<p>I don't have a huge problem with a discount for car washes but the advertisement should be an out the door price or rate. Similarly I don't mind capped or content-restricted data plans, but the advertised price should be the unlimited one.<p>I don't think we should decide what businesses can sell, but we should make it very hard to mislead on the ad. Force advertisements to be the highest price instead of the lowest price, and you'll find companies finding ways to remove fees from the table themselves.</p>
]]></description><pubDate>Mon, 21 Sep 2026 18:06:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=49790969</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49790969</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49790969</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Android 17 is the first since 3.x to add new APIs without releasing to the AOSP"]]></title><description><![CDATA[
<p>The MADA has been illegal for a long time, but you'll still find nobody willing to cross it. Samsung is indeed the only company with the power to actually escape Google and survive its penalties intact, which is why they are paid so lavishly to stay in.</p>
]]></description><pubDate>Sat, 19 Sep 2026 20:50:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=49770017</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49770017</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49770017</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Android 17 is the first since 3.x to add new APIs without releasing to the AOSP"]]></title><description><![CDATA[
<p>Google will destroy any OEM which ships an Android fork out of the box. Google only permits alternative ROMs as long as they are niche and keep developers distracted from creating real competition.</p>
]]></description><pubDate>Sat, 19 Sep 2026 15:31:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=49767378</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49767378</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49767378</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Android 17 is the first since 3.x to add new APIs without releasing to the AOSP"]]></title><description><![CDATA[
<p>If you are not working to destroy Android, you are supporting it. You might feel happy about your custom ROM nonsense and how it protects <i>your</i> privacy, but that just means you're selfish, because nearly everyone will still be trapped on Google's version.<p>Technologists need to <i>aggressively reject</i> solutions which don't spread freedom to ordinary users as well.</p>
]]></description><pubDate>Sat, 19 Sep 2026 01:26:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=49762430</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49762430</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49762430</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Android 17 is the first since 3.x to add new APIs without releasing to the AOSP"]]></title><description><![CDATA[
<p>Neither Wine nor Proton run on Windows. Building Android emulators for Linux: Worth your time. Building Android knockoffs which claim to remove the Google from Google's operating system? Foolishness.</p>
]]></description><pubDate>Sat, 19 Sep 2026 01:24:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49762427</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49762427</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49762427</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Android 17 is the first since 3.x to add new APIs without releasing to the AOSP"]]></title><description><![CDATA[
<p>The bigger problem is wasting developer effort contributing to Google's platform. The real secret behind Android being "open" (sorta) is that while almost nobody runs AOSP, Google has tricked a bunch of fools into working on Android forks instead of building a real competitor.<p>Playing at their table is a losing game, the house always wins.</p>
]]></description><pubDate>Sat, 19 Sep 2026 00:40:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49762167</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49762167</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49762167</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Salesforce Global Outage"]]></title><description><![CDATA[
<p>Rebooting is the first step: If it fixes it you don't have a problem. If it doesn't, you know more about the problem.<p>It's a joke, but like, after nearly two decades of engineering I have something break on me, due to updates. I figure the updates broke it, call the vendor, and they go... did you try rebooting it <i>again</i>?<p>Rebooting it a second time fixed it.</p>
]]></description><pubDate>Wed, 16 Sep 2026 20:49:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=49732804</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49732804</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49732804</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Salesforce Global Outage"]]></title><description><![CDATA[
<p>I've dealt with a fiber cut, it wasn't nearly that bad. Fiber cuts impacting my SaaS providers were worse because there was nothing I could do about it.</p>
]]></description><pubDate>Wed, 16 Sep 2026 16:14:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=49729238</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49729238</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49729238</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "Salesforce Global Outage"]]></title><description><![CDATA[
<p>> which belies deep misunderstanding<p>I think you are missing the point. When I state my Exchange server is more reliable than Exchange Online, I don't think I'm a better engineer. I recognize Microsoft has harder problems to solve than I do. I think building overengineered, oversized SaaS environments is introducing extreme risk. It's an inherent flaw of the current approach.<p>Smaller is, in fact, better, because it's easier to operate reliably.</p>
]]></description><pubDate>Wed, 16 Sep 2026 15:29:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=49728555</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49728555</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49728555</guid></item><item><title><![CDATA[New comment by ocdtrekkie in "The Google Play app review process now regularly takes longer than a week"]]></title><description><![CDATA[
<p>Open Web Advocacy's goal is Chrome on all platforms, which just means the Play Store problem gets even worse. The moment OWA wins, the open web dies. These are people with a truly bad astroturfy goal, clothed in charitable nonprofit status.<p>Paradoxically, as long as WebKit is mandatory on iOS, the open web is safe: Websites have to build for a lowest common denominator standard instead of building for Chrome proprietary APIs.</p>
]]></description><pubDate>Wed, 16 Sep 2026 13:24:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=49726676</link><dc:creator>ocdtrekkie</dc:creator><comments>https://news.ycombinator.com/item?id=49726676</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49726676</guid></item></channel></rss>