<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ploxiln</title><link>https://news.ycombinator.com/user?id=ploxiln</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 11 Oct 2026 20:09:43 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ploxiln" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ploxiln in "The last time my family was replaced by technology"]]></title><description><![CDATA[
<p>Mining is not limited by human labor, we already use huge machines (and some robots) controlled by a few humans. The limitations are investment in huge machines and processing plants, and regulations on where/how you can mine/process.<p>You can't just have a robot start mining/processing rare earths, anywhere in the country. You need permits, and a lot of money. I guess that didn't stop AI companies ... but there isn't an "infinite" novelty/hype premium for rare-earths, like there is for LLMs.</p>
]]></description><pubDate>Wed, 30 Sep 2026 20:44:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=49914151</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=49914151</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49914151</guid></item><item><title><![CDATA[New comment by ploxiln in "Spain orders blocks on Archive.today and its mirrors"]]></title><description><![CDATA[
<p>archive.today (etc) does not properly serve dns results to cloudflare dns servers, because they do not include EDNS subnet information in the query<p><a href="https://jarv.is/notes/cloudflare-dns-archive-is-blocked" rel="nofollow">https://jarv.is/notes/cloudflare-dns-archive-is-blocked</a></p>
]]></description><pubDate>Mon, 21 Sep 2026 01:58:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=49782198</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=49782198</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49782198</guid></item><item><title><![CDATA[New comment by ploxiln in "Ubuntu 26.10 completes transition to Rust-based coreutils"]]></title><description><![CDATA[
<p>8MB is the default per-thread stack size from glibc, also seems to be the default "ulimit" from pam or the kernel, I'm not sure. So for the main/default thread (or if not using threads) the process can use setrlimit() and for threads it can use pthread_attr_setstacksize() to get bigger stacks if it knows it may need them.<p>8MB is pretty huge though; musl libc is famous for defaulting to much smaller per-thread stack size of 128KB (to avoid over-committing lots of memory when there are many threads - the main dev is really principled/opinionated on this topic, but again there are a few ways for applications to explicitly size their stacks as large as they need). Linux kernel threads get a bit less than 16KB!</p>
]]></description><pubDate>Tue, 15 Sep 2026 04:10:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=49707597</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=49707597</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49707597</guid></item><item><title><![CDATA[New comment by ploxiln in "ReactOS 0.4.16"]]></title><description><![CDATA[
<p>You can forward USB devices into a VM. About 15 years ago I was using a Windows VM on Linux to program PIC18F??? devices with the custom (JTAG based?) programmer provided by Microchip. The upside is that you can preserve and share this windows environment for other coworkers, and have separate VMs for different projects (perhaps one you can update, and one you can't ...)</p>
]]></description><pubDate>Mon, 31 Aug 2026 15:54:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49511253</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=49511253</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49511253</guid></item><item><title><![CDATA[New comment by ploxiln in "A third world engineer responds to “RISC-V: They should have known better”"]]></title><description><![CDATA[
<p>This blog post is very defensive and argumentative, which I guess is fair considering Dmitry's post is similarly inflammatory, but most of it was really not convincing:<p>> Simply put, the things a high-end CPU needs are diametrically opposed to the things a small cost-saving microcontroller core needs.<p>> The conclusion he draws is that no single ISA can serve both ends, and that RISC-V fans are fooling themselves, in theory the premise is true. The conclusion does not follow, and I can show you why from three parts sitting on my desk as we speak.<p>> CH32V003. This is the cheap "RV32EC" with sixteen registers, no multiplier, no divider, machine mode only,<p>> CH32H417. A dual core MCU that is unmatched in performance to price point and is at the higher end of the MCU line<p>> Baochip. A VexRISC-V with an MMU built around a stack thats open from silicon to os Baochip-1x: A Mostly-Open, 22nm SoC for High Assurance Applications<p>Uh, which one of these is a datacenter server cpu? Or a workstation cpu? Or at least a developer laptop cpu? How about a Raspberry Pi 4 level SBC (supporting latest ubuntu and fedora releases, driving a display that runs a browser and plays video ...)<p>There's a lot of angry indignation but it seems obvious that Dmitry is quite right about this.<p>But I found this is where this blog post starts making a lot of sense:<p>> Has anyone tried adding an MMU to a Cortex-M? The physical tradeoffs are real, the difference is that with RISC-V, the ISA owner does not decide for you where that boundary must be drawn. If you want virtual memory on ARM you license a Cortex-A instead, which is a different core family, a different profile, a different negotiation, and a different royalty.<p>> Compare what happened with Baochip. The RISC-V privileged specification defines supervisor mode and Sv32 paging as optional things an implementation may provide. VexRISC-V is an open core, somebody added an MMU to it. bunnie built a chip around it and runs a microkernel with real process isolation on it<p>Yeah, that is a good point. We're still in the low-end specialty realm, but that is real interesting advantage for RISC-V, a good reason for it to exist.<p>As for shipping to Trinidad and Tobago ... this post is trying too hard to turn this into moral issue, but it seems a bit random (OrangePi cost $30 and shipped free? you can also get arm-based and stuff from the same places), and the vast majority of people don't live on semi-remote islands, it doesn't make sense to consider this kind of accessibility above all else, and it's strange to blame Dmitry for not thinking of you here.</p>
]]></description><pubDate>Sun, 16 Aug 2026 19:42:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=49322991</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=49322991</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49322991</guid></item><item><title><![CDATA[New comment by ploxiln in "How Our Rust-to-Zig Rewrite Is Going"]]></title><description><![CDATA[
<p>I think it's a reaction to many simpler advocates of Rust saying "it's unsafe and irresponsible of you to not use Rust, you can't write software in C or C++ or Zig (or Go?) and have memory unsafety and put your users at risk, it's not safe, you have to use Rust to be safe".<p>Freakin' safety. I like doing lots of unsafe things in life: rock climbing without gear (short bouldering sections on hiking trails), bicycling and skateboarding without a helmet, etc. I developed pretty good skills in all these things, and programming C too. What kind of life would be worth living with enforced perfect safety? Without developing skill in life's many un-safe activities?<p>So people want to emphasize that, if they shouldn't use non-Rust languages because their safety can't be guaranteed, well your safety using Rust isn't absolute, either. So you can't tell me I must use Rust, or the Rust rewrite of my favorite tools, to "be safe".<p>Do you recall the early rust web framework, that used a lot of "unsafe" "inappropriately" and had some vulnerabilities ... actix web? ... reminds me of the bun-in-zig situation, kinda makes the language's PR situation more complicated and tricky.</p>
]]></description><pubDate>Fri, 17 Jul 2026 01:35:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48942447</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=48942447</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48942447</guid></item><item><title><![CDATA[New comment by ploxiln in "I'm a USB-C Maximalist"]]></title><description><![CDATA[
<p>The high data rate cables all need to be stiffer. You can find good 100w or 240w charging cables with good flexibility, so that's a good reason to keep usb-2 data-speed but high-power charging cables.<p>The measure of a good high-power cable is the resistance. You can gauge it with a usb test load, typical usb power meter, and a usb-pd trigger (all can be pretty cheap, often you can find the trigger functionality combined with one of the other two). Calculate voltage drop for a given current by measuring both sides of the cable, or at least compare different cables with similar load.<p>But I found a "USB Cable Checker 2" by BitTradeOne which will directly measure and show the resistance in milli-ohms, very convenient! A very good cable measures 150 to 250 mOhm, the worse ones are 3 or 4 times that (at which point this device over-ranges around 1000 mOhm). You can really tell the difference with how some phones and laptops will slow their current draw after voltage droops.</p>
]]></description><pubDate>Wed, 15 Jul 2026 01:21:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=48915092</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=48915092</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48915092</guid></item><item><title><![CDATA[New comment by ploxiln in "OpenBSD has a use-after-free allowing local privilege escalation to root"]]></title><description><![CDATA[
<p>If they can provide only 20% of the functionality and only 1% of the bugs, that's a compelling trade-off for many use-cases! (and a bit closer to the reality IMHO)</p>
]]></description><pubDate>Wed, 08 Jul 2026 20:15:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=48836883</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=48836883</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48836883</guid></item><item><title><![CDATA[New comment by ploxiln in "Box3D, an open source 3D physics engine"]]></title><description><![CDATA[
<p>But you probably depend on over 500 open source libraries and tools, mostly ones you're not aware of. (Do you ever use a linux VM to run or just develop your stuff? Ever use git or curl etc? Did you know that tools and components in turn use other open-source libraries that you didn't pay for?) The main reason you use such things is so that you don't have to worry about this question.</p>
]]></description><pubDate>Thu, 02 Jul 2026 00:28:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=48754890</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=48754890</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48754890</guid></item><item><title><![CDATA[New comment by ploxiln in "CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq"]]></title><description><![CDATA[
<p>You don't have to use Debian stable, if you'd prefer Ubuntu every 6 months, or Fedora (6 months? 9 months?), or even Arch Linux updated daily ...<p>I use Arch on my laptop, when I got it 2 years ago the amd gpu was a bit new so it was prudent to get the latest kernel, mesa, everything. Since I use it daily it's not bad to update weekly and keep on top of occasional config migrations.<p>I use Debian stable on my home server, it's been in-place upgraded 4-ish times over 10 years. I can install weekly updates without worrying about config updates and such. I set up most stuff I wanted many years ago, and haven't really wanted new features since, though I have installed tailscale and jellyfin from their separate debian package repos so they are very current. It does the same jobs I wanted it to do 8 years ago, with super low maintenance.<p>But if you don't want Debian stable, that's fine. Just let others enjoy it.</p>
]]></description><pubDate>Tue, 12 May 2026 22:37:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48115522</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=48115522</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48115522</guid></item><item><title><![CDATA[New comment by ploxiln in "Mad Bugs: Vim vs. Emacs vs. Claude"]]></title><description><![CDATA[
<p>Yup, I've had "nomodeline" in my vimrc for years. I used to add the "securemodelines" plugin <a href="https://www.vim.org/scripts/script.php?script_id=1876" rel="nofollow">https://www.vim.org/scripts/script.php?script_id=1876</a> but just recently removed that too (I think I may have ran into an annoyance after a vim update, and decided I never really use automatic modeline support anyway)</p>
]]></description><pubDate>Wed, 01 Apr 2026 07:03:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=47597779</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=47597779</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47597779</guid></item><item><title><![CDATA[New comment by ploxiln in "Wayland set the Linux Desktop back by 10 years?"]]></title><description><![CDATA[
<p>I'm still using Xorg after all these years, on a laptop with 150% scaling, which I occasionally plug into an external monitor with 100% scaling. Somewhat surprisingly, it works great. (Cinnamon desktop, Ryzen 7840u integrated graphics. And also a desktop machine with Radeon RX 6800XT, but it's not surprising that still works great.)</p>
]]></description><pubDate>Fri, 20 Mar 2026 06:20:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=47451138</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=47451138</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47451138</guid></item><item><title><![CDATA[New comment by ploxiln in "Despite doubts, federal cyber experts approved Microsoft cloud service"]]></title><description><![CDATA[
<p>it's "Enterprise" grade software! need to check the boxes for the procurement process (actually working is a separate department)</p>
]]></description><pubDate>Wed, 18 Mar 2026 17:18:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=47428498</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=47428498</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47428498</guid></item><item><title><![CDATA[New comment by ploxiln in "SSH Secret Menu"]]></title><description><![CDATA[
<p>Just type <enter> <i>without</i> cat, your shell will show you another prompt, and the ssh escape command will also work.</p>
]]></description><pubDate>Wed, 11 Mar 2026 06:28:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=47332276</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=47332276</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47332276</guid></item><item><title><![CDATA[New comment by ploxiln in "NRC issues first commercial reactor construction approval in 10 years [pdf]"]]></title><description><![CDATA[
<p>This is how it works in NYC, but the wires are almost twice as expensive as the power. (If you add taxes and the numerous weird fees, the total bill is a solid 3x the cost of the power.) It's really all about the grid maintenance and management these days.</p>
]]></description><pubDate>Thu, 05 Mar 2026 02:31:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=47256752</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=47256752</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47256752</guid></item><item><title><![CDATA[New comment by ploxiln in "Turn Dependabot off"]]></title><description><![CDATA[
<p>The previous company I was working at (6 months ago) had a bunch of microservices, most in python using fastapi and pydantic. At one point the security team tuned on CodeQL for a bunch of them, and we just got a bunch of false positives for not validating a UUID url path param to a request handler. In fact the parameter was typed in the handler function signature, and fastapi does validate that type. But in this strange case, CodeQL knew that these were external inputs, but didn't know that fastapi would validate that path param type, so it suggested adding redundant type check and bail-out code, in 100s of places.<p>The patterns we had established were as simple, basic, and "safe" as practical, and we advised and code-reviewed the mechanics of services/apps for the other teams, like using database connections/pools correctly, using async correctly, validating input correctly, etc (while the other teams were more focused on features and business logic). Low-level performance was not really a concern, mostly just high-level db-queries or sub-requests that were too expensive or numerous. The point is, there really wasn't much of anything for CodeQL to find, all the basic blunders were mostly prevented. So, it was pretty much all false-positives.<p>Of course, the experience would be far different if we were more careless or working with more tricky components/patterns. Compare to the base-rate fallacy from medicine ... if there's a 99% accurate test across a population with nothing for it to find, the "1%" false positive case will dominate.<p>I also want to mention a tendency for some security teams to decide that their role is to set these things up, turn them on, cover their eyes, and point the hose at the devs. Using these tools makes sense, but these security teams think it's not practical for them to look at the output and judge the quality with their own brains, first. And it's all about the numbers: 80 criticals, 2000 highs! (except they're all the same CVE and they're all not valid for the same reason)</p>
]]></description><pubDate>Sat, 21 Feb 2026 15:36:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=47101731</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=47101731</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47101731</guid></item><item><title><![CDATA[New comment by ploxiln in "How did Windows 95 get permission to put Weezer video 'Buddy Holly' on the CD?"]]></title><description><![CDATA[
<p>High school ... 20+ years ago probably</p>
]]></description><pubDate>Tue, 10 Feb 2026 22:50:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=46968115</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=46968115</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46968115</guid></item><item><title><![CDATA[New comment by ploxiln in "Lessons learned shipping 500 units of my first hardware product"]]></title><description><![CDATA[
<p>In addition to the all the other stuff, including light spectrum differences, you can't just trust that a "37000 lumen" light (cheap from China ...) is such a thing. Some examples of "100,000 lumen" flashlights that ended providing more like 2000 to 3000 lumens: <a href="https://www.youtube.com/watch?v=6q_0wxzClkg" rel="nofollow">https://www.youtube.com/watch?v=6q_0wxzClkg</a><p>It's possible, they exist, many such LEDs are probably manufactured in China ... but the legit ones are probably more expensive, and you may need a more recognizable brand to do some QA, and keep pressure on the factory to not slip quality or inputs.<p>Consider the cheap screwdriver included with the lamp in this story: unexpectedly, many were more faulty than the cheapest $4 screwdriver you'd find in any hardware store. The more stories you read about manufacturing stuff in China, the more you'll see very strange things. It's not about nationality or anything, it's an extreme kind of optimization. If you didn't catch it already, maybe you didn't really need what you thought you asked for ... they're just checking/optimizing</p>
]]></description><pubDate>Tue, 03 Feb 2026 23:31:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=46878952</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=46878952</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46878952</guid></item><item><title><![CDATA[New comment by ploxiln in "Ode to the AA Battery"]]></title><description><![CDATA[
<p>I just worry that the voltage of these is a bit too high, if the device takes 3 or 4 in series. They tend to be around 1.8 volts per cell, significantly higher than a fresh alkaline AA at around 1.6 volts, and even after half the energy is discharged, if the device is off for a long while, the initial voltage for next turn-on creeps all the way back up.<p>(The price doesn't bother me ... it's worth the much lower chance of leaking than alkaline, if you leave it in a remote or gadget for years. But I've come to think that rechargeable NiMH like eneloops are a better idea due to the voltage.)</p>
]]></description><pubDate>Fri, 30 Jan 2026 20:04:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=46829127</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=46829127</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46829127</guid></item><item><title><![CDATA[New comment by ploxiln in "Microsoft forced me to switch to Linux"]]></title><description><![CDATA[
<p>Windows 11 officially requires TPM 2.0, secure-boot enabled, <i>and</i> an AMD Zen+ (Ryzen 2xxx) or later <i>or</i> an Intel Core Gen 8 or later.<p><a href="https://arstechnica.com/gadgets/2021/10/windows-11-the-ars-technica-review/#page-2" rel="nofollow">https://arstechnica.com/gadgets/2021/10/windows-11-the-ars-t...</a><p>> ... the best rationale for the processor requirement is that these chips (mostly) support something called “mode-based execution control,” or MBEC. MBEC provides hardware acceleration for an optional memory integrity feature in Windows (also known as hypervisor-protected code integrity, or HVCI) that can be enabled on any Windows 10 or Windows 11 PC but can come with hefty performance penalties for older processors without MBEC support.<p>> Another theory: older processors are more likely to be running in old systems that haven’t had their firmware updated to mitigate major hardware-level vulnerabilities that have been discovered in the last few years, like Spectre and Meltdown</p>
]]></description><pubDate>Wed, 28 Jan 2026 19:04:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=46800051</link><dc:creator>ploxiln</dc:creator><comments>https://news.ycombinator.com/item?id=46800051</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46800051</guid></item></channel></rss>