Category Archives: News

Shared items and notes from my feeds and browsing. Subscribe as feed.

Lisp Badge LE

Source: Hacker News

Article note: I love goofy little standalone computers. I'm always a bit puzzled why so many people who build them choose Lisp.
Comments
Posted in News | Leave a comment

GPUs from all major suppliers are vulnerable to new pixel-stealing attack

Source: Ars Technica

Article note: This is some insane shit. The fact that "GPU-accelerated CSS filters on a cross-origin iframe" are a thing is psychotic and and indictment against the state of the Web on multiple levels. The fact that someone figured out they can use the mechanism to launch side-channel attacks by building filters with different execution times based on pixel properties is super nifty in a horrifying way.
GPUs from all major suppliers are vulnerable to new pixel-stealing attack

Enlarge

GPUs from all six of the major suppliers are vulnerable to a newly discovered attack that allows malicious websites to read the usernames, passwords, and other sensitive visual data displayed by other websites, researchers have demonstrated in a paper published Tuesday.

The cross-origin attack allows a malicious website from one domain—say, example.com—to effectively read the pixels displayed by a website from example.org, or another different domain. Attackers can then reconstruct them in a way that allows them to view the words or images displayed by the latter site. This leakage violates a critical security principle that forms one of the most fundamental security boundaries safeguarding the Internet. Known as the same origin policy, it mandates that content hosted on one website domain be isolated from all other website domains.

Optimizing bandwidth at a cost

GPU.zip, as the proof-of-concept attack has been named, starts with a malicious website that places a link to the webpage it wants to read inside of an iframe, a common HTML element that allows sites to embed ads, images, or other content hosted on other websites. Normally, the same origin policy prevents either site from inspecting the source code, content, or final visual product of the other. The researchers found that data compression that both internal and discrete GPUs use to improve performance acts as a side channel that they can abuse to bypass the restriction and steal pixels one by one.

Read 15 remaining paragraphs | Comments

Posted in News | Leave a comment

PiWrite – Kindle Paperwhite to Write

Source: Hacker News

Article note: ...This is a webserver running on a Pi Zero serving a page to the feeble internal browser on the Kindle over Wifi, and talking to a Bluetooth keyboard. There's that SolarWriter app that does the same trick with a phone as the intermediary. Either way, there are two relatively powerful computers (as in... bigger than minicomputer that would have served a whole department in the late 70s) running Linux and a complete web stack at each end, to attach a keyboard and display for simple text editing. It's shocking how the "little eink terminal" market has failed and always spirals into this kind of weird complexity and/or goofy proprietary closed devices freewriter type things.
Comments
Posted in News | Leave a comment

Google is killing Gmail’s Basic HTML View in early 2024

Source: Hacker News

Article note: This caused me to think. Remember when a little bit of judicious JS to do small updates on the client made pages seems super fast compared to doing a bunch of network roundtrips in the early 2000s? Notice how now connections are only slightly faster (only slightly lower latency, typical bandwidth has improved more) and most JS pages are so bloated they consume enough resources to be the limiting factor on otherwise-usable computers, which has made static HTML pages seem startlingly fast while typical JS-heavy pages are sluggish? It's quite an indictment of where the web has gone. Plus, we lost local presentation control/structure (for theming and alternative displays and screen readers and such) in the process.
Comments
Posted in News | Leave a comment

The invisible problem: text editing on Android and iOS sucks

Source: OSNews

Article note: I don't immediately love the demo, but I absolutely agree that the consensus approach for text editing on fondleslabs is absolutely awful, and much of the problem is occlusion. The "swipe space bar to move cursor" trick some keyboards do is the biggest improvement to happen in some time, but I think touchscreens are just not very good fine input devices.

Android and iOS share a common problem: they copied desktop text editing conventions, but without a menu bar or mouse. This forced them to overload the tap gesture with a wide range of actions: placing the cursor, moving it, selecting text, and invoking a pop-up menu. This results in an overly complicated and ambiguous mess-o-taps, leading to a variety of user errors.

It’s less of a problem if you only do short bursts of text in social media or messaging apps. But doing anything more complicated like an email gets tedious. However, in my user study on text editing, I was surprised to find that everyone had significant problems and rather severe workaround for editing text.

With the extremely talented Olivier Bau, together we created a prototype called Eloquent, which offers a much simpler solution. We presented this work at UIST 2021.

This is now one of my favourite articles I’ve ever read. I despise text input and text editing on mobile devices, whether they be Android or iOS. I hate it with the passion of a thousand burning suns, but it seems like nobody else cares. Luckily, the author of this article, Scott Jenson, a man with an impressive career doing UI work at Apple, Google, and others, agrees with me, and together with his colleagues, during his time at Google, he came up with an entirely different, touch-first way of editing text.

The end result – be sure to watch the video to see it in action – immediately clicks for me. I want this. Now. This would be a massive usability improvement, and the fact it isn’t in Android yet, despite being developed at Google, is further evidence Google has no clue how to make good ideas float to the top. Jenson explains why Eloquent, as they called their new input/editing system, won’t ship with Android, while he expresses a bit more optimism Apple might be more open to rethinking mobile text editing:

Unfortunately, shipping something like Eloquent would be challenging. First, as too many people mistakenly see text editing as “done”, there is little appetite to fix it. Second, users have been trained to cope with this error-prone approach for well over a decade. Asking people to change at this point would be hard.

But most importantly, fixing text editing isn’t seen as important enough in the war between Android and iOS. It’s not the flashy feature that shifts your Net Promoter Scores. What I find ironic is that a fundamental change, like fixing text editing, could make people feel much more at ease using their phones and could be an enormous reason to switch. But it would be a slow burn and take years of steady effort. Android just can’t think this way. Apple just might.

Android needs this.

Posted in News | Leave a comment

Amazon adding ads to Prime Video in 2024 unless you pay $2.99 extra

Source: Ars Technica

Article note: Just like the descent of Cable from "Paid so ad free" to "You pay more and ALSO we advertise to you and bundle and rentseek in every other way that is possible and legal." the same bullshit is going down in the Streaming market. Everyone who can will just go back to piracy as the service gets worse.
Screenshot from The Boys S2 teaser

Enlarge (credit: YouTube/Amazon Prime)

Next year, watching TV shows and movies on Amazon Prime Video without ads will cost more than it does now. In early 2024, Amazon will show ads with Prime Video content unless you pay $2.99 extra.

Amazon announced today that Prime Video users in the US, Canada, Germany, and the UK will automatically start seeing advertisements "in early 2024." Subscribers will receive a notification email "several weeks" in advance, at which point they can opt to pay $2.99 extra for ad-free Prime Video, Amazon said.

That takes the price of ad-free Prime Video from $8.99/month alone to $11.98/month and from $14.99/month with Prime to $17.98/month.

Read 7 remaining paragraphs | Comments

Posted in News | Leave a comment

Working remotely can more than halve an office employee’s carbon footprint

Source: Hacker News

Article note: ...No shit. Make employers pay for their exernalities. Tax carbon footprints. Refuse to discuss your compensation without including commute time and cost. Zone to discourage car-required lifestyles. There _is_ a lot of work that needs to be done on location, but the vast majority of office work is not that.
Comments
Posted in News | Leave a comment

Running PalmOS on a Raspberry Pi RP2040 #RaspberryPi #RP2040 @dmitrygr @Raspberry_Pi

Source: adafruit industries blog

Article note: Motherfucker wrote a bare-metal kernel for Cortex-M3/M4 (and now M0) class parts, an ARM-on-Thumb JIT, and all the support infrastructure to host PalmOS5 on modern Cortex-M micocontrollers. Holy shit.

Dmitry Grinberg had demonstrated a Raspberry Pi RP2040 microcontroller running unmodified PalmOS 5.2.8 (showing off world’s only ARM-to-thumb1 just in time (JIT) compiler).

How little RAM/CPU does PalmOS 5 really require? Since rePalm had support (at least in theory) for Cortex-M0, I wanted to try on real hardware, as previously the support was tested on CortexEmu only. There does happen to be one Cortex-M0 chip out there with enough ram – the RP2040 – the chip in the $4 Raspberry Pi Pico. I then sought out a display with a touchscreen that could be easily bought. There were actually not that many options, but this one seemed like a good fit. It turned out, after some investigation, that driving it properly and quickly will not be at all easy. RP2040’s special sauce – the PIO – to the rescue!

Dmitry documents the extensive history and architecture of Palm devices and their operating system, from Motorola 68000 versions to the switch to Arm devices. A masterclass in both Palm and reverse engineering.

See this post for all the details. Via X (formerly Twitter).

Posted in News | Leave a comment

Snowden leak: Cavium networking hardware may contain NSA backdoor

Source: Hacker News

Article note: Interesting. Also weird that it went unreported for so long. I can't quite tell what the exploit is from the provided context. Was it algorithm substitution with a backdoored version that will interoperate with the real one? Was it a bad RNG (see: Dual_EC_DRBG)? As someone in the HN pointed out, one of the big markets for this stuff is HSMs (Hardware Security Modules: think co-processors that do the "security stuff" for a larger system) in hosted environments like clouds. Last I looked Cavium->Marvell's CloudHSM product was pretty big in the "It's totally secure to do your work on our computer" market.
Comments
Posted in News | Leave a comment

Unity promises “changes” to install fee plans as developer fallout continues

Source: Ars Technica

Article note: It's such a "We got caught intentionally doing something wildly unacceptable to our captive customer base, please put down the torches and pitchforks and keep investing in our ecosystem, so we can go back to abusing you later." It's also _the_ classic fast route to tech companies turning awful: they merged with an adtech company.
Unity says it will be announcing changes to its recently revealed fee structure in the coming days.

Enlarge / Unity says it will be announcing changes to its recently revealed fee structure in the coming days. (credit: Unity)

After nearly a week of protracted developer anger over a newly announced runtime fee of up to $0.20 per game install, Unity says it will be "making changes" to that policy and will share a further update "in a couple of days."

In a late Sunday social media post, Unity offered apologies for the "confusion and angst" caused by the sudden announcement of the policy last Tuesday. "We are listening, talking to our team members, community, customers, and partners, and will be making changes to the policy," the post reads. "Thank you for your honest and critical feedback."

It's currently unclear whether those changes will amount to tinkering around the edges of the fee structure as currently planned or represent a more complete rollback of the idea of charging install fees in the first place. But even a full about-face might not be enough to satisfy some longtime Unity developers at this point.

Read 8 remaining paragraphs | Comments

Posted in News | Leave a comment