Hacker Newsnew | past | comments | ask | show | jobs | submit | noAnswer's commentslogin

It makes me sad that shells, operating systems and languages have basically made zero progress / had zero innovation in the last 60 years.

"Escaping" should be something some graybeard is mumbling about.

Yet here we are in 2026, still having to be on the lookout for a wild /../

Even PowerShell is boilerplate, boilerplate galore.


It's just a fundamental problem of encoding the boundary between different (meta-)languages in-band. It will always be a problem, until it's possible to implement the separation out-band, which makes the respective language no longer self-contained, as it needs to be implemented in the layer above.

This occurs now with LLMs too. It's a fundamental problem, of the problem description, not the implementation.


Yeah, the innovation would be to not make everything in-band. Which implies proper file formats for source code for example. I know, that is blasphemy against 7bit ASCII.

It's like the telephone networks of old. They eventually realized that that is not so good. The computer world is still in its analog telephone phase. ;-)


Yes I want to scream everytime a tool gives me crap for "no newline at end of file" or other similar BS

I don't care. I never cared. And every sane tool knows how to deal with it

Shut up and stop thinking we're still in the 70s


They also pull this off in the other direction too. You having earned money by showing ads? They claim there was click-farming ...and it's gone!

www.uceprotect.net does that for email. It's a DNS blacklist that puts hole networks on it, even if "only" a individual hosts SPAMs.

It's a double-edged sword. That is how you end up with most ISPs blocking port 25 completely. If your hosting provider is on the list you are collateral damage. You yourself can do very little to remedy the situation except to beg your provider "to look into it".

What do you expect the ISPs to do in this story? We are talking about TSL connections. Block port 80 and 443 and expect the costumers to use your HTTPS-Proxy. Than they could inspect and block individual actions.


> If your hosting provider is on the list you are collateral damage.

Yes, and this sucks. I moved ISPs because the original one had burned IP addresses that you can't send email from. Every ISP that gets the ranges burned like that will eventually either goes out of business or gets their act together. Not by tomorrow, but eventually

Like, the only other alternative outcome I see is that everyone has to pass through a central surveillance point that decides who's benign and who's naughty, and since nobody wants that... what else are we to do but report abuse?

> What do you expect the ISPs to do in this story? We are talking about TLS connections.

What they've done to me when I abused a service as a teenager, the ISP got an abuse notification: cut off the connection, ask the subscriber wtf this traffic is and how they're going to make sure it doesn't happen again (at which point my dad, the subscriber, came to me and asked if I knew something about this.... yeah ^^')

TLS doesn't matter because the ones receiving the abusive traffic can say what it was. Their access logs will contain the decrypted information and that should be put in an abuse report. If the customer denies everything, turn on netflow logging for a month and see if a future abuse report comes in that can be correlated against the netflow logs. Or have netflow logs stored for 1h by default and retain the entries for which an abuse notification came in (grep for IP addresses in incoming notifications). Lots of reasonable options there; this isn't the difficulty. It's getting people to send that abuse notification so the ISP can identify the problematic subscribers


The ratio between people who lost their "free big provider" account do to arbitrary algo decisions and people who lost their domain because they ignored provider's invoice for over a month must be 1.000.000 to 1. :-)

I use a prepaid provider. If at the day of the renewal there is no money "in the bank" they immediately release the domain. So yeah, I treat their reminders with priority. I really should change providers...


It's ignoring the reminder for however long name cheap sends them (*) PLUS ignoring that the domain is down for over a month. At that point I can only assume that the person must not have cared about that domain very much.

* Providers I have used send them multiple months ahead of expiry but I also don't use automated renewal and buy as far ahead as I can and still extend that yearly.


It still works with regular mail servers:

Quote from https://providers.delta.chat:

"Usually, it just works, but for some providers, you need to adjust the settings. In this case, click on “prepare” for details.

Please note that push notifications do not work with classic providers and esp. large classic providers often have sending limits and overzealous spam rejections. This can worsen the chat experience, as messages are delayed or missing messages may even disrupt groups."


> I was unaware German Impressum applied to a natural person who is not running a business.

It doesn't.


> teachers somehow understood that I was one of these

Are you sure your parents weren't involved in the background?

> Extra time for someone who struggles to complete on time isn’t cheating - it’s allowing people to demonstrate what they can do.

For me it becomes cheating when its no longer allowed to be mentioned on the certificate that extra time was given.


I don't care about the internal format. What I'm missing is an active component. Instead of re-downloading the same thing over and over it should work like POP3.


Atom kinda does. Atom is a paged format, so a publisher can publish their entire history in their Atom feed and only the most recent page gets redownloaded to see new entries as they are added.


> But surely, latency is all about "placebo" and "vibes" and "feel" is it not?

Not sure if I can follow but...no?! My first TFT-TV had 2 seconds input lag. Impossible to play video games on it. That has nothing to do with feelings.

Already 10ms delay has a measurable effect: https://www.youtube.com/watch?v=5qjSGEOEaXo


I know it's "just" AI but one could think there is a forkable project out there. I have seen like tenths of projects like this. OPs explanation is different though. Usually the line is "inspired by movie".


There might be, but that would be missing out on half of the fun. Plus the real development challenge wasn't the frontend, but the database strategy, caching strategy, and edge availability. As with all my projects they serve as a way for me to learn.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: