<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: thefr0g</title><link>https://news.ycombinator.com/user?id=thefr0g</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 18 Jun 2026 07:52:10 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=thefr0g" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by thefr0g in "Hackerrank DMCA Notice"]]></title><description><![CDATA[
<p>He probably meant <a href="https://gitea.io" rel="nofollow">https://gitea.io</a> ;)</p>
]]></description><pubDate>Tue, 16 Nov 2021 14:35:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=29240973</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=29240973</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29240973</guid></item><item><title><![CDATA[New comment by thefr0g in "Hackerrank DMCA Notice"]]></title><description><![CDATA[
<p>> GH should really be considered a potential single point of failure now.<p>now…</p>
]]></description><pubDate>Tue, 16 Nov 2021 14:27:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=29240894</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=29240894</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29240894</guid></item><item><title><![CDATA[New comment by thefr0g in "Despite having just 5.8% sales, over 38% of bug reports come from Linux"]]></title><description><![CDATA[
<p>> Yes, it is a VST plugin<p>Shouldn't that be the easiest way to distribute audio software for linux? It's just a static shared library and maybe some data.<p>> This is the first time I'm reading of Pipewire, and it sounds promising, but will need to have host support before it becomes a reasonable VST / LADSPA replacement.<p>I'm pretty sure they didn't mention pipewire as a replacement for vst or lv2 (or ladspa lol). It's benefit would be for your standalone since it supports alsa, jack and pulseaudio clients and can get decent latency.</p>
]]></description><pubDate>Mon, 25 Oct 2021 11:24:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=28986545</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28986545</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28986545</guid></item><item><title><![CDATA[New comment by thefr0g in "Harden and secure browsers in containers, with GUI"]]></title><description><![CDATA[
<p>> The only part that "only works on Windows" is the RDP client.<p>Ah ok, I thought they have an X server running under windows, but apparently not. (Was that in some previous version? I remember reading that.)<p>> so presumably the FreeRDP client would be just fine on Linux.<p>Memory sharing would need support by the hypervisor I guess, that probably means hacking FreeRDP, rdp-wayland-backend and the hypervisor :\</p>
]]></description><pubDate>Mon, 11 Oct 2021 14:50:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=28828952</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28828952</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28828952</guid></item><item><title><![CDATA[New comment by thefr0g in "Harden and secure browsers in containers, with GUI"]]></title><description><![CDATA[
<p>I didn't know virtio_wl, it looks pretty neat. WSLg doesn't seem to have too much focus on sandboxing and only works on windows :(</p>
]]></description><pubDate>Mon, 11 Oct 2021 13:45:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=28828225</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28828225</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28828225</guid></item><item><title><![CDATA[New comment by thefr0g in "Harden and secure browsers in containers, with GUI"]]></title><description><![CDATA[
<p>> x11docker is just a (very convenient) security layer for containers which need to expose graphics (and possibly webcam, audio, networking, clipboard, printers...). Kata Containers are just "micro VMs" where you spin up a separate kernel to drop the container into.<p>Yeah, thats what I meant, you can just use kvm and your gui/audio/etc. stuff directly instead of having all the unnessecary complexity and dependency those layers bring along.<p>> Bubblewrap is okay if you trust your kernel<p>Thats why I proposed it for when you don't need virtualisation. You can ofc also use it in a VM to further restrict processes.</p>
]]></description><pubDate>Mon, 11 Oct 2021 13:42:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=28828195</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28828195</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28828195</guid></item><item><title><![CDATA[New comment by thefr0g in "Harden and secure browsers in containers, with GUI"]]></title><description><![CDATA[
<p>> Another approach might be x11docker [5] with Kata Containers [6].<p>Why all the complexity? Just qemu/kvm and xpra, waypipe, whatever would be way simpler and in turn have way smaller of an attack surface. Same if you don't need virtualisation, just use bubblewrap instead of docker etc. It will even give you more fine grained control and you can just use your distributions package manager to keep everything up to date.</p>
]]></description><pubDate>Mon, 11 Oct 2021 13:09:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=28827904</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28827904</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28827904</guid></item><item><title><![CDATA[New comment by thefr0g in "Harden and secure browsers in containers, with GUI"]]></title><description><![CDATA[
<p>> Only over X11 network protocol?<p>If you read the examples you'll see that they mount /tmp/.X11-unix in the container, thats where the X-Sessions Unix domain socket is. You can do the same for pulseaudio. But you shouldn't. Use Wayland and Pipewire if you are actually interested in using this as a security measure, since they are built for sandboxing.<p>> I thought modern browsers would need /dev/dri/?<p>They only need it for hw-acceleration. You can also give the container access to it if you need that.</p>
]]></description><pubDate>Mon, 11 Oct 2021 09:30:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=28826434</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28826434</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28826434</guid></item><item><title><![CDATA[New comment by thefr0g in "World food prices hit 10-year peak – FAO"]]></title><description><![CDATA[
<p>So you got what he meant to say?</p>
]]></description><pubDate>Mon, 11 Oct 2021 09:02:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=28826268</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28826268</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28826268</guid></item><item><title><![CDATA[New comment by thefr0g in "Always-on Processor magic: How Find My works while iPhone is powered off"]]></title><description><![CDATA[
<p>> I wonder what the next Crypto AG (CIA front) will be<p>NSA: VPN and "secure" webmail providers<p>CIA: They don't need fronts anymore, they have CISCO, Juniper, Netgear, etc.</p>
]]></description><pubDate>Fri, 01 Oct 2021 09:45:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=28716405</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28716405</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28716405</guid></item><item><title><![CDATA[New comment by thefr0g in "CNLabelContactRelationYoungerCousinMothersSiblingsDaughterOrFathersSistersDaught"]]></title><description><![CDATA[
<p>Question to all software architects: At which point do you decide to implement a DSL?<p>Also I see nothing wrong with this except for the hungarian PascalCase…</p>
]]></description><pubDate>Fri, 01 Oct 2021 09:00:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=28716154</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28716154</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28716154</guid></item><item><title><![CDATA[New comment by thefr0g in "NFT projects are just MLMs for tech elites"]]></title><description><![CDATA[
<p>> What is to stop someone who MITM's the artist's webpage from selling NFTs on their behalf?<p>I guess anti-fraud laws… Also, to my disappointment, someone already got banksy.io :D</p>
]]></description><pubDate>Fri, 01 Oct 2021 08:50:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=28716102</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28716102</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28716102</guid></item><item><title><![CDATA[New comment by thefr0g in "JSXGraph: Dynamic Mathematics with JavaScript"]]></title><description><![CDATA[
<p>You can easily double the price. I'd limit the amount of support/feature requests that includes so heavy users will have to pay more :D</p>
]]></description><pubDate>Fri, 01 Oct 2021 08:43:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=28716062</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28716062</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28716062</guid></item><item><title><![CDATA[New comment by thefr0g in "JSXGraph: Dynamic Mathematics with JavaScript"]]></title><description><![CDATA[
<p>> What do you HN think about the licensing?<p>My immediate thought when I read your post was GPL or GTFO, so I guess it's fine ;)</p>
]]></description><pubDate>Fri, 01 Oct 2021 08:41:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=28716052</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28716052</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28716052</guid></item><item><title><![CDATA[New comment by thefr0g in "Offline First"]]></title><description><![CDATA[
<p>> On a rooted phone the local database copy could be fiddled with I guess<p>If you depend on users (attackers) not being able to modify their software or environment and poke around at each and every bit of your (publicly accessible) interfaces you are doing something awfully wrong!<p>> but the user needs to be authenticated to upload a database<p>Is registration for your service limited to a fixed amount of trustworthy people? Otherwise this isn't an obstacle.<p>> the lambda that extracts the data is sandboxed to access only what it needs<p>Using a simple serialisation format would be orders of magnitudes safer (and simpler)<p>> Unless there is some way to introduce a malicious side effect to a select statement in sqlite?<p>See all the links posted here already</p>
]]></description><pubDate>Wed, 29 Sep 2021 12:22:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=28692690</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28692690</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28692690</guid></item><item><title><![CDATA[New comment by thefr0g in "Secret military aircraft possibly exposed on TikTok"]]></title><description><![CDATA[
<p>> By contrast, the U.S. killed Taiwan's nuclear program the moment it was discovered<p>Why don't they start with their own?</p>
]]></description><pubDate>Wed, 29 Sep 2021 10:53:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=28692144</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28692144</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28692144</guid></item><item><title><![CDATA[New comment by thefr0g in "Tools to measure software energy consumption from your computer"]]></title><description><![CDATA[
<p>> Worse, focusing on the computer consumption may push web developers to just move computations to the server side, where the energy consumption is not measured.<p>Server side energy consumption is directly measured by how much money it costs to run the servers. The only reason web devs waste client processing power like there is no tomorrow is that it doesn't cost anything.</p>
]]></description><pubDate>Wed, 29 Sep 2021 10:31:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=28692029</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28692029</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28692029</guid></item><item><title><![CDATA[New comment by thefr0g in "Elk: A low footprint JavaScript engine for embedded systems"]]></title><description><![CDATA[
<p>Has anyone here used scripting languages on a microcontroller? And if so why? For user-scripting? I can't really think of another practical use case but there are multiple implementations of pretty high-level languages out there so someone must be using them.<p>You'd have to build some hardware abstraction to use with the scripting language anyways at which point you could just use the language you wrote the abstraction in imo. Is it so you can have inexperienced (cheaper?) devs do the maintainence? For all the embedded projects I worked on the high level program logic wasn't the thing that took the most effort.</p>
]]></description><pubDate>Fri, 24 Sep 2021 12:57:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=28641682</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28641682</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28641682</guid></item><item><title><![CDATA[New comment by thefr0g in "Bespoke Synth 1.0 – open-source software modular synthesizer"]]></title><description><![CDATA[
<p>Ardour is really great for recording and mixing. For a more "contemporary" workflow you might want to try zrythm¹, it's getting better and better. (I still use Bitwig though…) If you exclusively make electronic music you could also look into LMMS², it's more of an electronic-music-toy than an actual DAW but thats not necessarily a bad thing.<p>¹ <a href="https://www.zrythm.org/en/explore.html" rel="nofollow">https://www.zrythm.org/en/explore.html</a>
² <a href="https://lmms.io/" rel="nofollow">https://lmms.io/</a></p>
]]></description><pubDate>Thu, 16 Sep 2021 11:07:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=28550230</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28550230</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28550230</guid></item><item><title><![CDATA[New comment by thefr0g in "Why Firefox has been in decline for 12 years"]]></title><description><![CDATA[
<p>> we still don't have form and CB auto completion<p>Yes please save all of your personal and payment information in your browser, I don't see how that could be a bad idea.</p>
]]></description><pubDate>Sat, 11 Sep 2021 17:56:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=28494130</link><dc:creator>thefr0g</dc:creator><comments>https://news.ycombinator.com/item?id=28494130</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28494130</guid></item></channel></rss>