HN comments - Digest ⚙️ Edit Settings

Period: 2025-09-22 03:19 - 2025-09-29 04:31 📚 All Digests

AI Digest

美国城市在公交车采购上的花费过高

英国将为工人引入强制性数字身份

不存在超过218步的可达棋局

埃文斯顿市要求Flock移除重新安装的摄像头

聊天控制:欧盟想要扫描所有私人消息,甚至在加密应用中

ChatGPT Pulse(聊天GPT脉冲)

聊天控制:欧盟想要扫描所有私人信息,甚至在加密应用中

Cloudflare电子邮件服务:私有测试版

Helium 浏览器

一张图就能看清谷歌搜索的所有问题

一张图就能看清谷歌搜索的所有问题

就让我能选择文本

Terence Tao:社会中小型组织的作用显著缩小

就让我能选择文本

Yt-dlp:即将对 YouTube 下载的新要求

在西班牙,踢球比赛期间我的游戏服务器被封锁

Libghostty 即将来临

Mesh:我尝试了 Htmx,然后放弃了它

Delete FROM users WHERE location = 'Iran';

你用AI做了这个,但你并不理解你在这里在做什么

你用AI做了这个,你并不理解你在这里在做什么

misnome 在“你用 AI 做了这个,你并不理解你在这里在做什么”中的评论

韩国总统:美国的投资要求将引发金融危机

nomilk:通过让极少专业的人测试文档来改进文档



Details

bestcomments

  • New comment by RobKohr in "US cities pay too much for buses"
  • Content:

    "Federal funding typically covers 80% of bus purchases, with agencies responsible for the remainder."

    Well, there is your answer. The one making the purchase isn't the one primarily paying for the purchase. This makes them less sensitive to pricing.

    Kinda like how expensive healthcare is since it is paid for by insurance.

    Or how you don't care how much you put on your plate or what you choose to eat at an all you can eat buffet.

    The second you detach the consumer from the price of something, even through an intermediary such as health insurance, that is when they stop caring about how much something costs, and so the price jumps.


  • New comment by aftergibson in "Britain to introduce compulsory digital ID for workers"
  • Content:

    A secure, optional digital ID could be useful. But not in today’s UK. Why? Because the state has already shown it can’t be trusted with our data.

    - Snoopers’ Charter (Investigatory Powers Act 2016): ISPs must keep a year’s worth of records of which websites you visit. More than 40 agencies—from MI5 to the Welsh Ambulance Service—can request it. MI5 has already broken the rules and kept data it shouldn’t have.

    - Encryption backdoors: Ministers can issue “Technical Capability Notices” to force tech firms to weaken or bypass end-to-end encryption.

    - Online Safety Act: Expands content-scanning powers that experts warn could undermine privacy for everyone.

    - Palantir deals: The government has given £1.5 billion+ in contracts to a US surveillance firm that builds predictive-policing tools and runs the NHS’s new Federated Data Platform. Many of those deals are secret.

    - Wall-to-wall cameras: Millions of CCTV cameras already make the UK one of the most surveilled countries in the world.

    A universal digital ID would plug straight into this ecosystem, creating an always-on, uniquely identified record of where you go and what you do. Even if paper or card options exist on paper, smartphone-based systems will dominate in practice, leaving those without phones excluded or coerced.

    I’m not against digital identity in principle. But until the UK government proves it can protect basic privacy—by rolling back mass data retention, ending encryption backdoor demands, and enforcing genuine oversight—any national digital ID is a surveillance power-grab waiting to happen.

    I'm certain it's worked well in other countries, but I have zero trust in the UK government to handle this responsibility.


  • New comment by codeulike in "No reachable chess position with more than 218 moves"
  • Content:

    They dont really spell it out but they mean "from this position the player has 218 possible legal moves to choose from"


  • New comment by donmcronald in "Evanston orders Flock to remove reinstalled cameras"
  • Content:

    Even though it's become commonplace in the last 20 years, I'm still shocked to see how companies can pretty much ignore the law, do whatever they want, and have everyone involved shielded from any kind of significant consequences.

    In situations like this, I think the person at the top of the chain that told employees to perform the illegal installations should be arrested and charged. On top of that, the company should be fined into bankruptcy. If the directors knew about it any companies they're involved with shouldn't be allowed to conduct future business in the municipality (or state).


  • New comment by txrx0000 in "ChatControl: EU wants to scan all private messages, even in encrypted apps"
  • Content:

    Dear citizens of the EU:

    If this gets pushed through, you will gradually lose control of your government much like how the people of the UK already lost control of theirs.

    What are you going to do when the government's interests inevitably drift out of alignment with yours? Start a political movement? You will have the police knocking on your door for criticizing the establishment.

    Start a revolution? You have no weapons. You can't even organize a resistance because all channels of communication are monitored.

    You have neither the pen nor the sword. There is no longer an incentive for the government to serve you, and so it eventually won't.

    No amount of protest will recover the freedom you once had. You're heading towards a society where everyone feels oppressed but no one can do anything about it.


  • New comment by SirensOfTitan in "ChatGPT Pulse"
  • Content:

    My pulse today is just a mediocre rehash of prior conversations I’ve had on the platform.

    I tried to ask GPT-5 pro the other day to just pick an ambitious project it wanted to work on, and I’d carry out whatever physical world tasks it needed me to, and all it did was just come up with project plans which were rehashes of my prior projects framed as its own.

    I’m rapidly losing interest in all of these tools. It feels like blockchain again in a lot of weird ways. Both will stick around, but fall well short of the tulip mania VCs and tech leaders have pushed.

    I’ve long contended that tech has lost any soulful vision of the future, it’s just tactical money making all the way down.


  • New comment by haolez in "ChatControl: EU wants to scan all private messages, even in encrypted apps"
  • Content:

    I think the challenge for society here is not to simply reject attempts like this, but how to prevent them from being pushed over and over until a specific context allows it to be approved.


  • New comment by mosura in "Cloudflare Email Service: private beta"
  • Content:

    Eventually all Internet protocols will be MITMed by cloudflare. Your single point of interception!


  • New comment by godelski in "Helium Browser"
  • Content:

      > Helium is based on Chromium
      > Best privacy by default
    
    Sorry, pass...

    Even with un-googled Chromium I do not think these statements are self-consistent. We need browsers that do not allow Google to control the ecosystem. We need legitimate competition. So what, our choices are Firefox (Gecko), Safari (WebKit), and Ladybird?

    Personally I go with Firefox on most devices and Orion (WebKit) on my iPhone and iPad.

      > Helium anonymizes all internal requests to the Chrome Web Store via Helium services.
    
    This seems like something pretty easy to mess up. Maybe it is good now, but it sure is going to be a cat and mouse game.

    I really would be curious to have some breakdown comparison with something like the Mullvad browser (Gecko). I have a lot of trust for both the Mullvad and Tor teams. They have a much longer history working with this kind of stuff and have been consistently updating it since release. Launched in early 2023[0] and last update was last week[1].

    [0] The Mullvad Browser (mullvad.net) https://news.ycombinator.com/item?id=35421034

    [0.5] Mullvad Browser (torproject.org) https://news.ycombinator.com/item?id=37159744

    [1] https://github.com/mullvad/mullvad-browser


  • New comment by CSMastermind in "Everything that's wrong with Google Search in one image"
  • Content:

    I'm old enough to remember when a big selling point of Google was that it didn't do this.


  • New comment by jsheard in "Everything that's wrong with Google Search in one image"
  • Content:

    They do the same thing on the Play Store, for example I just searched for Firefox and the first result is a sponsored spot for Opera. Does Apple do that on the App Store?

    A funnier example: searching for Amazon gives Temu as the first result. Searching for Temu gives Shein as the first result. Searching for Shein gives Shein as the first result! ...but only because they outbid everyone else for the ad spot on their own name, resulting in Double Shein: https://i.imgur.com/0buR8Hq.png


  • New comment by zelphirkalt in "Just let me select text"
  • Content:

    I have a habit of selecting and highlighting text on computer screens, while reading. I have no issues tracking lines usually, but somehow I still select and highlight. Maybe it is just easier to track lines this way. When I see some web page, that prevents this, then that website gets a -50 reputation score out of 100 in my book. So if the site is perfect in every other way (almost no site is) then -50 still makes it pretty terrible. If additionally it would actually be useful in other ways to highlight and copy text on a site, then I get really annoyed by web non-sense like that. Similarly I get annoyed, if every pixel is some clickable action trigger.

    This is not what hypertext has been created for. Stop making the web into a cesspit of bad accessibility.


  • New comment by cs702 in "Terence Tao: The role of small organizations in society has shrunk significantly"
  • Content:

    Great post, thought-provoking. Highly recommended.

    Interestingly, in the past, the US federal government actively made efforts to keep private organizations from becoming too dominant. Here are just a few examples, from memory:

    * The Bell system was broken up, resulting in a geographically distributed telecom network: https://en.wikipedia.org/wiki/Breakup_of_the_Bell_System : Your phone company was local.

    * Banks could not cross state lines, resulting in a geographically distributed financial system: https://en.wikipedia.org/wiki/McFadden_Act : Your bank was always local.

    * Banks were prohibited from entering riskier businesses, resulting in a compartmentalized system: https://en.wikipedia.org/wiki/Glass%E2%80%93Steagall_legisla... : Your bank did not try to sell you investments.

    * Monopolies and oligopolies were routinely busted, resulting in less concentration in many industries: https://en.wikipedia.org/wiki/Competition_law#United_States_... .

    The companies you dealt with every day were typically smaller, more local, more subject to competition, and less able to yield economic and political power, particularly at the national level.

    Nowadays, power and resources seem to be far more concentrated.


  • New comment by gaoshan in "That Secret Service SIM farm story is bogus"
  • Content:

    There is so much to address in this post but I want to look at just this part: "One of the reasons we know this story is bogus is because of the New York Times story which cites anonymous officials, “speaking on the condition of anonymity to discuss an ongoing investigation”. That’s not a thing, that’s not a valid reason to grant anonymity under normal journalistic principles. It’s the “Washington Game” of “official leaks”, disseminating propaganda without being held accountable."

    It is not accurate to claim "that's not a thing". Citing anonymous sources is a long established practice (in particular when it comes to law enforcement activities or potentially sensitive political reporting). The NYT has formal editorial standards around the identity of anonymous sources that require editors to assess the justification for applying it. It doesn't mean the information is reliable, that's where an editorial eye comes into play, but it does fall under the category of normal journalistic practice.

    Next the "Washington Game": there’s a grain of truth here, but it is overstated. Yes, leaks can be part of a strategic move by politicians and it can be a source of exploitation by political operators but to equate all anonymous sourcing with propaganda is misleading. Plenty of such reporting has resulted in significant truths being revealed and powerful people being held accountable (Watergate, the Pentagon Papers, Abu Ghraib). Responsible reporting involves weighing a source's motivations as well as corroborating and contextualizing that information as accurately and truthfully as possible.

    The author's dismissiveness oversimplifies (or mischaracterizes, if I am being less generous) the reason and function of anonymity here. They overstate the issue with propaganda and anonymous sources. Accurate in the sense that anonymity can enable propaganda (it has happened), it is inaccurate in its absolutism.

    I feel like this sort of tone, with the absolutism, the attempt to reduce the complexity and nuance of reporting to the point where it can be dismissed is pretty typical of what passes for commentary in today's blog/tweet/commentary culture but it really plays more into the hands of those that would sow confusion and mistrust than it does into that of the truth and accuracy.


  • New comment by NoraCodes in "Just let me select text"
  • Content:

    Given that this page has the following styles which aren't applied anywhere else on the blog:

       body {
           -webkit-user-select: none;
           -webkit-touch-callout: none;
           -moz-user-select: none;
           -ms-user-select: none;
           user-select: none;
        }
    
    I think it's safe to assume that being unable to select text on this page is not unintentional, as several comments here assume, nor "ironic", but an intentional effort to demonstrate how annoying this behavior is.


  • New comment by piyuv in "Yt-dlp: Upcoming new requirements for YouTube downloads"
  • Content:

    I’m a paying YouTube premium subscriber. Last weekend, I wanted to download something so I can watch it on my way in the train. The app got stuck at “waiting for download..” on my iPad. Same on iPhone. Restart did not work. I gave up after an hour (30 mins hands on trying stuff, 30 mins waiting for it to fix itself). Downloaded the video using yt-dlp, transferred it to my USB c flash drive, and watched it from that.

    Awaiting their “premium cannot be shared with people outside household” policy so I can finally cancel. Family members make good use of ad-free.


  • New comment by dabeeeenster in "My game's server is blocked in Spain whenever there's a football match on"
  • Content:

    Related (7 years ago):

    https://www.reddit.com/r/soccer/comments/8q1j0o/la_liga_uses...

    - Bars, pubs and other public establishments have to pay around 200€/month in order to show football on their TVs while the household package goes between 10 and 30€/month.

    - The official app, with over 10 million downloads, asks you for microphone and GPS permissions.

    - La Liga remotely activates the microphone and tries to detect if the sound matches with that of a football match. In addition, it uses the geolocation of the phone to locate exactly where the establishment is located. That way they can locate bars and other establishments where football is being pirated or showed without paying for the bar package.

    Still amazes me this just sort of went by and no one really seemed bothered. Absolutely insane.


  • New comment by hackitup7 in "Libghostty is coming"
  • Content:

    I love how this guy founds + takes public + sells a multibillion company and then just goes right back to hacking. Legend.


  • New comment by recursivedoubts in "Mesh: I tried Htmx, then ditched it"
  • Content:

    Sounds like this app wasn't a good fit for htmx. I have added it to the "On The Other Hand" section on the htmx website:

    https://htmx.org/essays/#on-the-other-hand

    Regarding the default swap behavior of "innerHTML":

    https://htmx.org/quirks/#the-default-swap-strategy-is-innerh...

    Our proposal to merge htmx functionality into the HTML spec uses outerHTML:

    https://alexanderpetros.com/triptych/

    Also consider datastar, it was written from an SSE-first perspective by a go engineer:

    https://data-star.dev/


  • New comment by adastra22 in "Delete FROM users WHERE location = 'Iran';"
  • Content:

    OP, some context from the other side might be helpful.

    Yes, there are fines for American companies if they do business with Iranians. That's how sanctions work as I'm sure you're aware. But the story doesn't stop there.

    If an American finds out they are transacting with a sanctioned individual, or citizens of a sanctioned country like Iran or North Korea, the stakes go up: $1M USD fine and up to 20 years in federal prison. Oh and that's a personal risk -- you, the manager or executive in charge, and anyone else who is in the know on the transaction is now facing 20 years in federal pounding-in-the-ass prison if they don't immediately cease all communication and break off contact. Hence why they ghost you and remove your data from prod. It sucks, but I would do the same thing in that situation. Nobody should be expected to take that risk.

    That's why you have these experiences :(


  • New comment by rpigab in "You did this with an AI and you do not understand what you're doing here"
  • Content:

    "I heard you were extremely quick at math"

    Me: "yes, as a matter of fact I am"

    Interviewer: "Whats 14x27"

    Me: "49"

    Interviewer: "that's not even close"

    me: "yeah, but it was fast"


  • New comment by dansmith1919 in "You did this with an AI and you do not understand what you're doing here"
  • Content:

    Crazy how he doubled down by just pasting badger's answer into Chat and submitting the (hilariously obvious AI) reply:

    > Thanks for the quick review. You’re right — my attached PoC does not exercise libcurl and therefore does not demonstrate a cURL bug. I retract the cookie overflow claim and apologize for the noise. Please close this report as invalid. If helpful, I can follow up separately with a minimal C reproducer that actually drives libcurl’s cookie parser (e.g., via an HTTP response with oversized Set-Cookie or using CURLOPT_COOKIELIST) and reference the exact function/line in lib/cookie.c should I find an issue.


  • New comment by misnome in "You did this with an AI and you do not understand what you're doing here"
  • Content:

    I wonder where the balance of “Actual time saved for me” vs “Everyone else's time wasted” lies in this technological “revolution”.


  • New comment by arunabha in "South Korea's President says US investment demands would spark financial crisis"
  • Content:

    It's mind blowing to witness the speed and rapidity with which we have

    * Completely alienated key allies via an erratic and unpredictable tariff policy

    * Significantly undermined faith in US economic data and fiscal policy via overt politicization of key economic institutions

    * Increased the deficit by almost $3 trillion after vowing to reduce the deficit

    * Signaled far and wide that pay for play is the new norm, whether for pardons or favourable policy. Preferably paid in crypto, but with in kind payments being acceptable.

    Is there any wonder that other countries are unwilling to trust the US? The only hope we have is that the current bout of madness in Washington DC is a one time aberration, but who knows!


  • New comment by nomilk in "How I, a beginner developer, read the tutorial you, a developer, wrote for me"
  • Content:

    Can't recommend this approach highly enough: have someone with minimal expertise go through your docs with the goal of achieving the goal of the docs. Sit next to them or screenshare. Do not speak to them, certainly do not help, just watch. Watch them fumble. Watch them not know what to do. Watch them experience things you (the author) didn't, because you already had xyz configured on your machine and you forgot users won't have it. (even watch them pretend to know what they're supposed to do when they don't really).

    If the user achieves what they need with minimal stress/guesswork/ambiguity, the docs pass. If not, note every single place they fail, address each one, and repeat with a new user.

    I've used FAANG docs that don't come close to passing the above criteria.

    I've been incredibly grateful my org set this high bar. Especially when using docs for critical tech I only use from time to time (where I forget lots of it). Saves meetings, support inquiries, and video calls, because the user can self-serve.