Hacker Newsnew | past | comments | ask | show | jobs | submit | empthought's commentslogin

I read your book when I was ten years old! I was later stoked to find our computer system at school was a Unix machine, so I could try some of the commands you explained in the story, like ps and sendmail.


“That’s real, and it’s interesting.”

Stop with the slop.


Dang, my bad. Thought I cleaned that up. To be clear, I use AI to help clean up scattered thoughts, and then I edit it further but sometimes I miss the AI-isms that it inserts.


Use AI to condense, not extend.


Slop with the stop!


Unfortunately I think that we need to be much more judgmental than is tolerated on this forum if we want to get people to stop writing with AI assistance.

People are not going to stop spamming you with slop text unless the narrative is "Using AI for writing is a mark of poor literacy/low intelligence".


Yeah, NeXTSTEP is notoriously a locked-down, untweakable OS. It's not like anyone was able to use it to program anything of consequence.


I had an argument with Steve Jobs about pie menus at the Educom conference in Washington DC, October 26 1988 -- right after he finally shipped NeXTSTEP (people had been teasing it as vaporware with "NeVRSTEP" t-shirts).

I was demonstrating the work I'd done at the UMD Human Computer Interaction Lab on a color Sun 3/60 that Sun lent me to use at their booth, which happened to be right across from the NeXT booth.

Ben Shneiderman dragged Steve Jobs over to the Sun booth, and I gave him a NeWS demo for about half an hour: HyperTIES, UniPress Emacs, pie menus, PostScript windows in arbitrary shapes — the Hubble Space Telescope in orbit, Bill Joy's head popping up when you pointed at it, that kind of thing. Jobs has RELIGION about UI, and he argued wonderfully. He also has volume. On the show floor, in a suit and tie, he was jumping up and down yelling:

"That sucks! That sucks! Wow, that's neat! That sucks!"

Not discouraged, I figured one neat to three sucks was a good score from Steve Jobs. When I explained how flexible NeWS was -- programmable PostScript in the window system, malleable windows, extensible UI, transforming all menus of all apps into pie menus, etc -- he told me:

"I don't need flexibility -- I got my window system right the first time!"

Okay, agree to disagree. Then I gave him a free NeWS "NeRD" button, which he gracefully accepted, then he departed leaving my reality intact and undistorted.

So empthought's joke isn't far from the design philosophy. NeXT was world-class software, but malleability for the user was exactly what Jobs was proud of not offering. That's a big part of why the Emacs / NeWS / PostScript / Smalltalk / Self / Oberon / JavaScript / AJAX branch of computing and the Mac / NeXT / Display PostScript / Objective C / Cocoa branch diverged.

More context from that week:

https://news.ycombinator.com/item?id=17098824

Also, during the conference I was giving essentially the same rolling demos to anyone who walked by, and some scruffy looking dude was hanging out and watched the whole series until it looped back to Emacs, then he finally remarked "I used to use EMACS on ITS." (i.e. the original TECO version)

...I said "Wow, what was your user name? Mine was A2DEH@AI!" and he replied "WNJ".

Only then did I realize I had been giving demos to Bill Joy, the author of VI, of UniPress Emacs for NeWS, and of HyperTIES embedded graphical pop-up links demo with his own inflatable pop-up head. I didn't recognize him because he'd shaved his beard!

HyperTIES founders storyboard: https://donhopkins.com/home/ties/emacs/founders.st0

Bill Joy's Head Target: https://donhopkins.com/home/ties/emacs/obj/founder.curly.tn0

NeWS PostScript pop-up target class: https://donhopkins.com/home/ties/target.ps

At least it wasn't RMS, who would have immediately objected strongly to the "Evil Software Hoarder" version of Emacs I was using.

Here are some examples of not-locked-down NeWS user interfaces:

HCIL Demo - HyperTIES Browsing:

https://www.youtube.com/watch?v=fZi4gUjaGAM

HCIL Demo - HyperTIES Authoring with UniPress Emacs on NeWS:

https://www.youtube.com/watch?v=hhmU2B79EDU

Just the Pie Menus from All the Widgets:

https://www.youtube.com/watch?v=mOLS9I_tdKE

Ben Shneiderman, Don Hopkins, and pie menus in Spring 1989 on a Sun Workstation, running NeWS:

https://www.youtube.com/watch?v=8Fne3j7cWzg

Nelson Spins Pip While Emacs Watches:

https://www.youtube.com/watch?v=aRaD5zH3Qdg

(Oops that was a different Emacs, my cat.)


Thanks for sharing this! You are a legend!


We don’t need aggregators like HN pitching AI-authored content, no matter how pedagogically sound. We can direct our own AIs to generate our own AI-authored content.


Almost nobody has DNSSEC enabled.

Against DNSSEC: https://sockpuppet.org/blog/2015/01/15/against-dnssec/


That article kicks off with a politically motivated "issue" which seems pointed at the US Govt (USG) before dealing with perceived architectural issues.

The thing about trust anchors is that they are trust anchors and not a back door. DNSSEC goes well out of its way too, to not screw up things as far as possible if something is missing. OK, client implementations do that (I haven't gone into the RFCs in too much detail).

The architectural issues alluded to seem pretty handwavy too. I deployed a slack handful of PowerDNS boxes and adding DNSSEC is basically two CLI invocations per domain and passing on the DS records to upstream. The second invocation is to add an adjustment to deal with NXDOMAIN better (can't remember the exact thing at the moment)

If it doesn't work for you then fine - don't use it!

I find it useful and thanks to a decent implementation (so far) it is trivial to implement. However, I'm going to need to get my thinking cap on for some split-horizon domains.


It doesn't work for most sites, which is why so few organizations use it. It's awfully hard to make an argument about how straightforward DNSSEC is to use after DNSSEC had to be disabled by Cloudflare and Quad9 for all of Germany because of a misconfiguration. And it's more or less impossible to take seriously as a security boundary after that. Real security protocols fail closed.


A fuck up or two doesn't invalidate DNSSEC. IT related security is hard, really hard as you well know, but not impossible nor likely perfect and always a moving target.

Putting security on top of DNS is really, really hard because DNS was invented rather a long time ago when information wanted to be free and not fettered and I wore short trousers at school and in the distant future would run an IBM System /36!

When you confidently insist on "most sites" you appear to want to rudely trample on my experience of "it works for me and my 20 at the moment DNS domains and increasing as I migrate them over". I'm taking my time - I have quite a few more to do and each one needs adding to monitoring etc.

I don't run .de and I do feel for the lads n lasses that do that buggered up a KSK roll over or whatever it was that was screwed. I think that holding up a screw up is an extremely crass and facile argument against ... anything, let alone a rather esoteric engineering function.

I don't agree with your assertion about "Real security protocols fail closed." That sounds like striving for perfection and you know as well as I do that perfect is the enemy of good.

DNSSEC for better or worse is what we have and I don't think it is too bad. It does give some guarantees within certain parameters. Any decent engineer will look at the risks/rewards and decide on effectiveness and design their solutions to a requirement ... accordingly.


I came to this thread with data. Your 20-at-the-moment DNS domains versus the current signing statistics of the Tranco Top 1000.

At the point where we're arguing about fail-open versus fail-closed, our premises are too far apart to get anywhere. We can part company here: I'm speaking, in part, for the people who believe that any viable security protocol must fail closed.

Plenty of security protocols have ultimately failed in the marketplace and been abandoned. DNSSEC is simply another one of them.


You have deployed proof by assertion - I am powerless.

I am only describing my own experience and not pontificating on behalf of the world.


tptacek is HN's resident DNSSEC hater. I think he also hates IPv6.


I built the IPv6 private network system at Fly.io.


Let's keep the discussion civil please


That is civil. It's relevant and important to know that tptacek is present in every thread about DNSSEC and he always posts many comments opposing it, usually with little actual substance beyond "most people don't use it therefore it must suck"


Anyone can trivially use the search bar to see that your "little actual substance" claim is comically false. One of us built an actual app for this thread.


Your reasoning why DNSSEC is bad has been "most websites don't use it". Does that mean TLS was bad back when most websites didn't use it?


People have been trying to make DNSSEC a thing since 1995. Even when "most websites" didn't use TLS, basically all of ecommerce did: TLS has been load-bearing since the 1990s. Meanwhile, here in 2026, it is literally true that if the root keys landed on Pastebin tonight, almost nobody would need to be paged.


I have it enabled for an ssh interface for managing linux vms: https://shellbox.dev

Even supports post quantum encryption :)


In the FAQ of this article it says:

> What’s the alternative to DNSSEC? > Do nothing. The DNS does not urgently need to be secured.

> All effective security on the Internet assumes that DNS lookups are unsafe.

This is not true, our entire infrastructure of ACME certificate authorities like let's encrypt are fundamentally dependent on DNS: https://letsencrypt.org/how-it-works/#domain-validation

Then TLS verifies the domain with the private key the certificate authority issues...

How can you trust the s (secure) in https then??

Can anyone provide an example of "effective security on the Internet"?


Virtually none of the most important sites on the Internet are signed. When's the last time one was maliciously misissued?


Fair point.

I'm just looking for a way to cryptographically prove that my website is from me in a way that browsers will accept.

This means the whole chain from ICANN -> Verisign -> registrar -> dns -> IP -> my server.


1. Browsers briefly tried adopting DANE and gave up on it.

2. DNS is the wrong level of networking abstraction to do this kind of policy enforcement at, because DNS isn't plumbed for warnings and error reporting; when DNSSEC fails, whole zones simply fall of the Internet (for people who validate) as if they weren't there at all. It's the worst possible failure mode.

3. The thing you say you want can't be had with DNSSEC. You don't get "the whole chain from ICANN to your server". Any of the parent zone operators above you can decide to defect, for your zone specifically, and (particularly for state-level adversaries) for particular targets resolving your zones, without you ever knowing about it.


If any of the parent zones defects, they can trivially misissue a certificate. Having separate CAs that ddo whatever DNS says doesn't improve anything.


Stop posting slop.


How about

  for wmv in Path(sys.argv[1]).rglob("\*.wmv"):
        print(wmv, end=" ")
        r = subprocess.run(
            ["ffmpeg", "-i", wmv, wmv.with_suffix(".mpg")],
            stdout=subprocess.PIPE, stderr=subprocess.STDOUT,
        )
        lines = [l for l in r.stdout.decode().splitlines() if "kb/s:" in l]
        print("\n".join(lines) if lines else f"ERROR {r.returncode}")
?

If you go outside stdlib you can use the sh library instead of subprocess.run.


Not bad, but the subprocess invocation is too verbose given this is a staple of shell script type work, and the string mangling is a bit painful.


“No one is required to follow The Rule, to know The Rule, or even to think that The Rule is a good idea. The Founder of SQLite believes that anyone who follows The Rule will live a happier and more productive life, but individuals are free to dispute or ignore that advice if they wish.”


As the first section notes, the only reason they posted this is to fulfill a checklist requirement for certain commercial users. The external requirement for a code of conduct, which requesters never read and don’t actually care about, is the actual nonsense here.


Hardly. It may be annoying for commercial users to require a checkboxy code of conduct from the software they choose to use, but taking that opportunity to shove religion down people's throats is very strange behaviour. It also makes me suspicious of SQLite: if they're that brazen, do I need to look out for potential implementations of these rules within the code? Will certain words, like "gay", cause queries to fail? I don't think so and I hope it never will. But this is a SQL database engine and they chose to publicly affiliate it with religion. That's concerning.

I've been considering switching to H2 for a while now to avoid depending on a fat-jar full of binaries. This nonsense has persuaded me to make that switch.


The source code is in the public domain. You can inspect it, fork it, and redistribute it as you like.

Nothing is being shoved down anyone’s throat.


I'd rather just not use the thing than maintain a fork just to monitor for the influence of its official religion in its code.


Good luck! It’s the most widely-deployed database software by far. I’m sure you have hundreds or thousands of SQLite files among devices you own.

https://sqlite.org/mostdeployed.html


I think you have vastly mistaken what I'm saying. You seem to have leapt from me merely switching away using SQLite in my own projects, to me attempting to purge SQLite from every machine and piece of software I own or something? How odd.

Even with their strange choice to give a SQL database engine an official religion, I'm under no illusion that they'd turn it into actual malware. The example concern I gave was about queries failing, not it rm-rfing my computer. Sheesh.


I don’t know, wouldn’t you be pissed if you tried to search your browser history for “gay” and nothing was found? After all, that’s the threat model you’re proposing that you’re worried about — the thinnest of excuses for your clear and deep bigotry.


When I wrote my example, I was more thinking of database and table names, the schema itself, rather than cell content. There are already various limitations on such things, usually in the form of reserved prefixes. It doesn't seem out of the realm of possibility that a piece of software that officially affiliates itself with a particular religion might infuse that religion within itself. In fact, I find it suspicious that you seem to disregard this possibility entirely. Most explicitly religious software does this.

Instead, you attempt this weird switcheroo where I'm a bigot? Let's recap: a piece of software has officially affiliated itself with a religion that has made no secret of thinking we're evil and persecuting us for it for multiple millennia. I state that this is off putting and wish to switch to alternative software in my own projects. And you call me a bigot for it. Great job, Sherlock.


1. There is no religious affiliation for this project, official or otherwise. It is not “religious software.” The project founder is a Christian, that’s all.

2. You clearly are bigoted against Christians and likely all religious people. Every comment is infused with bigotry. You likely don’t even notice it because you’re swimming in it like a fish.

3. You are free to ignore the code of ethics and the software as much as you like. The code of ethics is not intended to apply to you. This is all clearly spelled out in the document, but you saw the word “Christ” and let your prejudice guide you instead of exercising basic reading comprehension.


If you say so. You seem desperate to cast me as a bigot to explain away my objections. Since we're assuming things about each other's character now, I'm just going to assume you follow this religion and feel attacked by my objection to it being officially adopted by a database library. God forbid, right? Oh well, I've endured a lot worse from you people. Goodbye.


I am an atheist.

There's no desperation and no casting here. I am just pointing out objective facts.

https://www.dictionary.com/browse/bigotry

> stubborn and complete intolerance of any creed, belief, or opinion that differs from one's own.

You:

> But this is a SQL database engine and they chose to publicly affiliate it with religion. That's concerning. I've been considering switching to H2 for a while now to avoid depending on a fat-jar full of binaries. This nonsense has persuaded me to make that switch.

It's textbook. Your decision is not based on any actual technical consideration, but rather "stubborn and complete intolerance." You can't conceive of a publicly Christian person who wouldn't use the software they wrote to somehow attack you, even though Dr. Hipp would never dream of doing anything like that.

Why can't you conceive of this? Because of your bigotry.


> stubborn and complete intolerance of any creed, belief, or opinion that differs from one's own.

What an odd definition, where did you get it from? Bigotry is being unreasonably intolerant. Your definition would cast intolerance of naziism as bigotry (Godwin's Law, yes, I know). But this doesn't surprise me since you don't seem to understand what "goodbye" means either. It's a shame this site has no equivalent to a block feature.


We're not talking about Nazis though, are we? We're talking about well over two billion people (possibly more than six billion if it extends beyond Christianity). Your prejudice against them is almost prima facie unreasonable.


Hetzner astroturf?


Are we getting paid for that?

I need to collect my paycheck.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: