HN comments - Digest ⚙️ Edit Settings

Period: 2025-02-08 00:00 - 2025-02-17 23:55 📚 All Digests

AI Digest



Details

bestcomments

  • New comment by decimalenough in "X blocks links to Signal"
  • Content:

    Remember the Arab Spring and how Twitter was hailed as a tool for the masses to fight against their oppressors? And remember how Elon bought Twitter, loudly proclaiming he was doing so to defend free speech?

    I'm mildly curious to see how X tries to justify this, but I suspect they've reached the stage where they don't even need to pretend to pay lip service to their notional values.


  • New comment by fvrther in "All Kindles can now be jailbroken"
  • Content:

    Kobo are giving you root access with telnet from the start. You can flash modded firmwares, change the backend servers to phone your own calibre-web instance, install ssh, koreader and even a tailscale vpn on it. They even have UART pins labelled on their board. These are amazing devices to play with. And they read pretty much everything you throw on their storage: epub, cbz, cbr, pdf..


  • New comment by atomicfiredoll in "YouTube asks channel owner to verify phone, permanently overwrites personal info"
  • Content:

    > A few days ago, I was prompted to verify my phone number by Google. Immediately after completing the verification, I received an email notifying me that Google had overwritten all my personal information. It turns out that because my mom is the one paying the phone bill, they automatically "verified" the name on my account to be hers and updated everything on my account without my consent.

    It sounds like someone at Google (not necessarily a programmer) needs to read "Falsehoods Programmers Believe About Phone Numbers:"

    > 4. A phone number uniquely identifies an individual

    What a bureaucratic nightmare.


  • New comment by padenot in "Watt The Fox?"
  • Content:

    This is planned, and important, and we'll fix it hopefully soon, it's long overdue. I'm sorry this hasn't happened yet, it's always a game of priorities that can never satisfy everybody on time. It however ranks fairly high on my personal list.

    As one could imagine it's a bit (read: a lot) more complicated than just pausing the AudioContext after some time of silence, but we'll get it fixed regardless, it's possible because others did it. There are tradeoffs we're willing to do.

    Source: Firefox implementer of a lot of things around this, editor of the Web Audio API standard.


  • New comment by aDyslecticCrow in "Carbon capture more costly than switching to renewables, researchers find"
  • Content:

    Anyone who isn't aware of this is either - Lying. - Paid by the oil industry. - Tricked by the oil industry.

    All you need is napkin maths. We gain energy by turning carbon into carbon dioxide. Now, we need the same energy to reverse it, but with a loss factor.

    We continue to see companies and politicians claiming it's feasible and will help us become "green". We should call them out on their shit. If we had the renewable power budget to use proper carbon capture on a large scale, we would already have a fully green grid.

    ---

    Well... There are other methods than reversing c02 back into carbon chains.

    Capture of CO2 and storage as CO2, mostly in compressed gas form in underground, has been proposed by a lot of companies. This is a logistical nightmare that has to be kept up for forever. Better keep that pressure chamber leakproof for 1000 years with likely upkeep. (setting aside how inefficiently that actually stores the carbon even if grabbing it from the air was free)

    Ideas to shove c02 air bubbles in concrete are promising but barely enough to offset the c02 generated from creating the concrete itself.

    One promising approach is to grow plants and turn them into charcoal. Charcoal is great for keeping fertilizer in the soil so that we can spread it over crop fields for a small increase in yield. Napkin maths on that makes it just require about Australia of farmland (if I remember) to offset the world's CO2 emissions. Almost feasible. (bamboo, algae, and sunflowers seem to be the highest biomass generators, but perhaps a slower crop that can handle worse climate is preferable)

    But these are still worse plans than just building a green grid.


  • New comment by nicoburns in "We were wrong about GPUs"
  • Content:

    > There's an (increasingly small) group of software developers who don't like "magic" and want to understand where their code is running and what it's doing. These developers gravitate toward open source solutions like Kubernetes

    Kubernetes is not the first thing that comes to mind when I think of "understanding where their code is running and what it's doing"...


  • New comment by freedomben in "We were wrong about GPUs"
  • Content:

    > The biggest problem: developers don’t want GPUs. They don’t even want AI/ML models. They want LLMs. System engineers may have smart, fussy opinions on how to get their models loaded with CUDA, and what the best GPU is. But software developers don’t care about any of that. When a software developer shipping an app comes looking for a way for their app to deliver prompts to an LLM, you can’t just give them a GPU.

    I'm increasingly coming to the view that there is a big split among "software developers" and AI is exacerbating it. There's an (increasingly small) group of software developers who don't like "magic" and want to understand where their code is running and what it's doing. These developers gravitate toward open source solutions like Kubernetes, and often just want to rent a VPS or at most a managed K8s solution. The other group (increasingly large) just wants to `git push` and be done with it, and they're willing to spend a lot of (usually their employer's) money to have that experience. They don't want to have to understand DNS, linux, or anything else beyond whatever framework they are using.

    A company like fly.io absolutely appeals to the latter. GPU instances at this point are very much appealing to the former. I think you have to treat these two markets very differently from a marketing and product perspective. Even though they both write code, they are otherwise radically different. You can sell the latter group a lot of abstractions and automations without them needing to know any details, but the former group will care very much about the details.


  • New comment by muglug in "Anyone can push updates to the doge.gov website"
  • Content:

    On top of that, Musk said he "deleted"[1] 18F, which built out the IRS direct file system (online tax filing is an area where the US lags far behind other countries).

    This is a moral crusade carried out under the auspices of a tech overhaul of government operations.

    [1] https://archive.is/3vdPN


  • New comment by danso in "Anyone can push updates to the doge.gov website"
  • Content:

    Worth noting that the U.S. Digital Service (USDS, i.e the org that DOGE has now subsumed) has for a long while been experts at building and deploying static websites for the federal government. And doing it completely in the open. Within minutes you can literally clone and re-deploy all of httsp://usds.gov — 150MB of 2,700 assets and documents, built on Jekyll — locally or on S3. They've even written out the complete deployment instructions:

    https://github.com/usds/website


  • New comment by fabian2k in "Anyone can push updates to the doge.gov website"
  • Content:

    For some reason quite a number of people seem to believe the purpoted goals of DOGE, removing waste and increasing efficiency of the government.

    I can't really understand that as it seems obvious to me that they're just destroying parts of the government they don't like. And while there is certainly room for improvement in many areas, whatever they're doing is not going to improve anything, it's only destruction.


  • New comment by arrosenberg in "Larry Ellison wants to put all America's data in AI, including DNA"
  • Content:

    All I know, is if I was worth $200B and owned the island of Lanai, you would never hear from me again. Ellison, Musk, Zuckerberg and the rest of these weirdos are deeply damaged human beings.


  • New comment by bayindirh in "Resigning as Asahi Linux project lead"
  • Content:

    [Putting my dusty Linux Distro Maintainer Hat on]

    First of all, I wholeheartedly applaud Marcan for carrying the project this far. They, both as individuals and as a team proper, did great things. What I can say is a rest is well deserved at this point, because he really poured his soul into this and worn himself down.

    On the other hand, I'll need to say something, however not in bad faith. He needs to stop fighting with the winds he can't control. Users gonna be users, and people gonna be people. Everyone won't be happy, never ever. Even you integrate from applications to silicon level, not everyone is happy what Apple has accomplished technically. Even though Linux is making the world go on, we have seen friction now and then (tipping my hat to another thing he just went through), so he need to improve his soft skills.

    Make no mistake, I'm not making this comment from high above. I was extremely bad at it, and I was bullied online and offline for a decade, and it didn't help to be on the right side of the argument, either. So, I understand how it feels and how he's heartbroken and fuming right now, and rightly so. However, humans are not an exact science, and learning to work together with people with strong technical chops is a literal superpower.

    I wish Hector a speedy recovery, a good rest and a bright future. I want to finish with the opening page of Joel Spolsky's "Joel on Software":

    Technical problems are easy, people are hard.

    Godspeed Hector. I'm waiting for your return.


  • New comment by nindalf in "Resigning as Asahi Linux project lead"
  • Content:

    Marcan links to an email by Ted Tso'o (https://lore.kernel.org/lkml/[email protected]...) that is interesting to read. Although it starts on a polarising note ("thin blue line"), it does a good job of explaining the difficulties that Linux maintainers face and why they make the choices they do.

    It makes sense to be extremely adversarial about accepting code because they're on the hook for maintaining it after that. They have maximum leverage at review time, and 0 leverage after. It also makes sense to relax that attitude for someone in the old boys' network because you know they'll help maintain it in the future. So far so good. A really good look into his perspective.

    And then he can't help himself. After being so reasonable, he throws shade on Rust. Shade that is just unfortunately, just false?

    - "an upstream language community which refuses to make any kind of backwards compatibility guarantees" -> Rust has a stability guarantee since 1.0 in 2015. Any backwards incompatibilities are explicitly opt-in through the edition system, or fixing a compiler bug.

    - "which is actively hostile to a second Rust compiler implementation" - except that isn't true? Here's the maintainer on the gccrs project (a second Rust compiler implementation), posting on the official Rust Blog -> "The amount of help we have received from Rust folks is great, and we think gccrs can be an interesting project for a wide range of users." (https://blog.rust-lang.org/2024/11/07/gccrs-an-alternative-c...)

    This is par for the course I guess, and what exhausts folks like marcan. I wouldn't want to work with someone like Ted Tso'o, who clearly has a penchant for flame wars and isn't interested in being truthful.


  • New comment by galoisscobi in "Resigning as Asahi Linux project lead"
  • Content:

    > But then also came the entitled users. This time, it wasn’t about stealing games, it was about features. “When is Thunderbolt coming?” “Asahi is useless to me until I can use monitors over USB-C” “The battery life sucks compared to macOS” (nobody ever complained when compared to x86 laptops…) “I can’t even check my CPU temperature” (yes, I seriously got that one).

    This sounds so rough. I can't imagine pouring your heart out into this labor of love and continue to have to face something like this. Back in the early days of Quora, when it used to be good, there used to be a be nice be respectful policy (they might still have it), I wonder if something like that would be helpful for open source community engagement.

    Regardless, major props to Marcan for doing the great work that he did, our community is lucky to have people like him!


  • New comment by rkagerer in "Leaking the email of any YouTube user for $10k"
  • Content:

    I found this title confusing. For those who didn't make it toward the end of the article: the leaked emails didn't cost them anything (except their time and ingenuity), and they received 10k as the bug bounty.


  • New comment by doright in "US and UK refuse to sign AI safety declaration at summit"
  • Content:

    Something tells me aspects of living in the next few decades driven by technology acceleration will feel like being lobotomized while conscious and watching oneself the whole time. Like yes, we are able to think of thousands of hypothetical ways technology (even those inferior to full AGI) could go off the rails in a catastrophic way and post and discuss these scenarios endlessly... and yet it doesn't result in a slowing or stopping of the progress leading there. All it takes is a single group with enough collective intelligence and breakthroughs and the next AI will be delivered to our doorstop whether or not we asked for it.

    It reminds me of the time I read books in my youth and only 20 years later realized the authors of some of those books were trying to deliver a important life messages to a teenager undergoing crucial changes, all of which would be painfully relevant to the current adult me... and yet the whole time they fell on deaf ears. Like the message was right there but I did not have the emotional/perceptive intelligence to pick up on and internalize it for too long.


  • New comment by tptacek in "Leaking the email of any YouTube user for $10,000"
  • Content:

    Since every 3rd message on this thread (at the time I wrote this) is about how Google underpaid for this bug, some quick basic things about vulnerability valuations:

    * Valuations for server-side vulnerabilities are low, because vendors don't compete for them. There is effectively no grey market for a server-side vulnerability. It is difficult for a third party to put a price on a bug that Google can kill instantaneously, that has effectively no half-life once discovered, and whose exploitation will generate reliable telemetry from the target.

    * Similarly, bugs like full-chain Android/Chrome go for hundreds of thousands of dollars because Google competes with a well-established grey market; a firm can take that bug and sell it to potentially 6 different agencies at a single European country.

    * Even then, bounty vs. grey market is an apples-oranges comparison. Google will pay substantially less than the grey market, because Google doesn't need a reliable exploit (just proof that one can be written) and doesn't need to pay maintenance. The rest of the market will pay a total amount that is heavily tranched and subject to risk; Google can offer a lump-sum payment which is attractive even if discounted.

    * Threat actors buy vulnerabilities that fit into existing business processes. They do not, as a general rule, speculate on all the cool things they might do with some new kind of vulnerability and all the ways they might make money with it. Collecting payment information? Racking up thousands of machines for a botnet? Existing business processes. Unmasking Google accounts? Could there be a business there? Sure, maybe. Is there one already? Presumably no.

    A bounty payout is not generally a referendum on how clever or exciting a bug is. Here, it kind of is, though, because $10,000 feels extraordinarily high for a server-side web bug.

    For people who make their nut finding these kinds of bugs, the business strategy is to get good at finding lots of them. It's not like iOS exploit development, where you might sink months into a single reliable exploit.

    This is closer to the kind of vulnerability research I've done recently in my career than a lot of other vuln work, so I'm reasonably confident. But there are people on HN who actually full-time do this kind of bounty work, and I'd be thrilled to be corrected by any of them.


  • New comment by CobaltFire in "The year I didn't survive"
  • Content:

    My son had cancer during COVID, though he was fortunate enough to beat it into remission (with the help of a huge care team).

    I was active duty military, and he is also non-verbal and autistic.

    The things she talks about, how focused she was and how hard it is to do any of that now, I've been experiencing exactly the same things. I find it hard to do anything, put anything together, etc. after 3 years of managing his care closely, being at his bedside all hours, having to scream at nurses to call away a code because he couldn't breathe (anaphylaxis), and a ton of other things. All of this while working 50+ hours a week, including remotely from his bedside.

    It's like I burnt out that part of me. Maybe I'm slowly healing? But I don't feel like it. I get minutes or hours when I can hit that stride again and it's absolutely terrifying to realize that I can no longer keep it up.

    I don't know that this comment adds anything to her story. I just felt like I understood her on a level that's hard to communicate and had the urge to share that.


  • New comment by not2b in "WASM will replace containers"
  • Content:

    "The main thing holding back wider adoption is a lack of system interfaces. File access, networking, etc. But it's just a matter of time before these features get integrated."

    But then you've got to figure out and prevent all the security holes that can be introduced by adding file access, networking, etc. That's what killed the Java write-once, run-anywhere promise. Maybe put the whole thing into a container? Oops, looks like the container wasn't replaced after all (though perhaps it could be simplified).


  • New comment by kersplody in "Nvidia's RTX 5090 power connectors are melting"
  • Content:

    12vhpwr has almost no safety margin. Any minor problem with it rapidly becomes major. 600W is scary, with reports of 800W spikes.

    12V2x6 is particularly problematic because any imbalance, such as a bad connection of a single pin, will quickly push things over spec. For example, at 600W, 8.3A are carried on each pin in the connector. Molex Micro-Fit 3.0 connectors are typically rated to 8.5A -- That's almost no margin. If a single connection is bad, current per connector goes to 10A and we are over spec. And this if things are mated correctly. 8.5A-10A over a partially mated pin will rapidly heat up to the point of melting solder. Hell, the 16 gauge wire typically used is pushing it for 12V/8.5A/100W -- that's rated to 10A. Really would like to see more safety margin with 14 gauge wire.

    In short, 12V2x6 has very little safety margin. Treat it with respect if you care for your hardware.


  • New comment by giarc in "I tasted Honda’s spicy rodent-repelling tape and I will do it again (2021)"
  • Content:

    That's one of the best blog posts I've read in a while. It nails the idea of "write one line that makes the reader want to read the next". It's humorous but also serious. There's no fluff. Instant subscribe.


  • New comment by hombre_fatal in "Firing programmers for AI is a mistake"
  • Content:

    I think we who are already in tech have this gleeful fantasy that new tools impair newcomers in a way that will somehow serve us, the incumbents, in some way.

    But in reality pretty much anyone who enters software starts off cutting corners just to build things instead of working their way up from nand gates. And then they backfill their knowledge over time.

    My first serious foray into software wasn't even Ruby. It was Ruby on Rails. I built some popular services without knowing how anything worked. There was always a gem (lib) for it. And Rails especially insulated the workings of anything.

    An S3 avatar upload system was `gem install carrierwave` and then `mount_uploader :avatar, AvatarUploader`. It added an avatar control to the User form.

    But it's not satisfying to stay at that level of ignorance very long, especially once you've built a few things, and you keep learning new things. And you keep wanting to build different things.

    Why wouldn't this be the case for people using LLM like it was for everyone else?

    It's like presuming that StackOverflow will keep you as a question-asker your whole life when nobody here would relate to that. You get better, you learn more, and you become the question-answerer. And one day you sheepishly look at your question history in amazement at how far you've come.


  • New comment by theandrewbailey in "Backblaze Drive Stats for 2024"
  • Content:

    > I have been authoring the various Drive Stats reports for the past ten years and this will be my last one. I am retiring, or perhaps in Drive Stats vernacular, it would be “migrating.”

    Thank you for all these reports over the years.


  • New comment by tofof in "I tasted Honda’s spicy rodent-repelling tape and I will do it again (2021)"
  • Content:

    Liquid capsaicin treatments for bird seed are an effective squirrel repellent.

    They also illustrate the evolution of this protein: birds have no receptors for capsaicin, while mammals do. Birds eat seeds mostly intactly. Their digestive systems are capable of breaking them down - but it's stochastic and some seeds make it through the bird undigested, being redistributed elsewhere. Obviously, having an agent sow your seeds widely is a fitness advantage, and so seedy plants are ultimately served well even if 90+% of their caloric investment into seeds goes into the birds.

    Mammals, on the other hand, have teeth - particularly molars. Mammals that eat seeds grind them apart orally before even swallowing. As a result, any seeds ingested by mammals are very likely to be completely destroyed. Plants - peppers, anyway - found a chemical irritant that repels the mammals without even being sensed by birds.

    I've used one such treatment (with an amusing logo illustrataion - https://i.imgur.com/JAl8vyW.png) to good effect to discourage squirrels at my feeder, so that they stick to my dedicated squirrel bungee with a log of compressed corn instead.


  • New comment by csmpltn in "Firing programmers for AI is a mistake"
  • Content:

    I think that LLMs are only going to make people with real tech/programming skills much more in demand, as younger programmers skip straight into prompt engineering and never develop themselves technically beyond the bare minimum needed to glue things together.

    The gap between people with deep, hands-on experience that understand how a computer works and prompt engineers will become so insanely deep.

    Somebody needs to write that operating system the LLM runs on. Or your bank's backend system that securely stores your money. Or the mission critical systems powering this airplane you're flying next week... to pretend like this will all be handled by LLMs is so insanely out of touch with reality.


  • New comment by dham in "Firing programmers for AI is a mistake"
  • Content:

    There's such a huge disconnect between people reading headlines and developers who are actually trying to use AI day to day in good faith. We know what it is good at and what it's not.

    It's incredibly far away from doing any significant change in a mature codebase. In fact I've become so bearish on the technology trying to use it for this, I'm thinking there's going to have to be some other breakthrough or something other than LLM's. It just doesn't feel right around the corner. Now completing small chunks of mundane code, explaining code, doing very small mundane changes. Very good at.


  • New comment by pyrale in "Firing programmers for AI is a mistake"
  • Content:

    We have fired all our programmers.

    However, the AI is hard to work with, it expects specific wording in order to program our code as expected.

    We have hired people with expertise in the specific language needed to transmit our specifications to the AI with more precision.


  • New comment by alpha_squared in "Musk-led group makes $97B bid for control of OpenAI"
  • Content:

    It feels like Musk is single-handedly making a great case for why unlimited accumulation of wealth is a bad idea.

    It's pretty colorful language, but my mind immediately jumps to "financial terrorist". He's using his enormous amount of wealth and influence as a weapon to bludgeon anyone and anything in his way.


  • New comment by aidenn0 in "Undergraduate shows that searches within hash tables can be much faster"
  • Content:

    > I'm beginning to think that the best way to approach a problem is by either not being aware of or disregarding most of the similar efforts that came before. This makes me kind of sad, because the current world is so interconnected, that we rarely see such novelty with their tendency to "fall in the rut of thought" of those that came before. The internet is great, but it also homogenizes the world of thought, and that kind of sucks.

    I think this is true only if there is a novel solution that is in a drastically different direction than similar efforts that came before. Most of the time when you ignore previous successful efforts, you end up resowing non-fertile ground.


  • New comment by irs in "Musk-led group makes $97B bid for control of OpenAI"
  • Content:

    Sam’s reply on twitter[0]

    no thank you but we will buy twitter for $9.74 billion if you want

    [0]https://x.com/sama/status/1889059531625464090?


  • New comment by brink in "Undergraduate shows that searches within hash tables can be much faster"
  • Content:

    Krapivin made this breakthrough by being unaware of Yao's conjecture.

    The developer of Balatro made an award winning deck builder game by not being aware of existing deck builders.

    I'm beginning to think that the best way to approach a problem is by either not being aware of or disregarding most of the similar efforts that came before. This makes me kind of sad, because the current world is so interconnected, that we rarely see such novelty with their tendency to "fall in the rut of thought" of those that came before. The internet is great, but it also homogenizes the world of thought, and that kind of sucks.


  • New comment by exmadscientist in "Some terminal frustrations"
  • Content:

    > inconsistent command line arguments: is it -h or help or –help?

    I've said it before and I'll say it again: the error "Option `--help` not understood, did you mean `-help`? Use `-help` to display program options." is one of the most insulting things a program can say to me. `--help` is the lowest common denominator. You have to support it. I don't care what your program has to special case in its parsing, just do it. If I knew your program's preferred syntax, I wouldn't be asking it for help.


  • New comment by fabian2k in "Teen on Musk's DOGE team graduated from 'The Com'"
  • Content:

    Ignoring the horrifying political parts, I think one aspect here about data access that is inherently worrying is that it seems like all usual controls were bypassed and the DOGE people had very low level access to systems. So there are probably copies of sensitive data now in their possession, and nobody knows exactly what was copied and where it is stored.

    This kind of access would be dangerous even in the hands of principled and well-meaning people. Giving it to people with glaring red flags like here is just entirely irresponsible.


  • New comment by dang in "Teen on Musk's DOGE team graduated from 'The Com'"
  • Content:

    All: if you're going to comment here, please make sure you're up on the guidelines at https://news.ycombinator.com/newsguidelines.html, and don't post low-information / high-indignation comments that could just as easily appear in any related thread. Such generic comments make discussion less interesting and more activating. That's not what we're trying for here.

    Rather, we want curious conversation. I know that's not so easy when a situation is intense, infuriating, frightening, distressing, and so on. But we need to protect this site for its specific mandate—which is fragile at the best of times—so please make the effort.

    As some of you know, this article was posted a dozen times and immediately flagkilled by users. I turned the flags off on this one because there's interesting new information in the story. But now it's up to the commenters to prove that was a good decision by co-creating a discussion that is interesting, curious, and has to do with the specifics of the article.

    If we end up with yet-another interchangeable flamewar about $BigTopic, that will only confirm that the flaggers were right, so those of you who want fewer of these threads to be flagged have a particular interest in sticking to the intended spirit of the site and proving that a substantively different discusson is possible.

    Edit: if you want to reply to this, please uncollapse the child comment below and reply there. Your views are welcome! I just also want to conserve space at the top of the thread.


  • New comment by simonw in "Why blog if nobody reads it?"
  • Content:

    Writing on a blog is a very inexpensive way to establish your credibility about different subjects. This pays off later down the line when you can link people to things you've written in the past.

    Credibility is a very valuable commodity. It's worth investing in ways to build more of it.

    Don't assume people will stumble across your content (though they will eventually via Google). Actively send links to people who you are already engaged in conversation with.

    It's not the number of readers you have that matters: it's their quality. I'll take a dozen people reading my stuff who might engage with me usefully or lead to future opportunities over a thousand readers who don't match that criteria.


  • New comment by rmason in "Cities can cost effectively start their own utilities"
  • Content:

    I used to live in a small town in Michigan which had city provided power using a dam. It was inexpensive and highly reliable. But every couple of years the big power company in the state would try and get the city to sell them the utility.

    After I moved a city council for whatever reason ended up selling. As a result the cost of electricity immediately doubled and power outages occurred regularly due to reduced maintenance. I don't know what they spent the money on that they received but it was a very poor decision that I have to believe they regret.


  • New comment by tptacek in "VSCode’s SSH agent is bananas"
  • Content:

    I have been for like a month now noodling on a long-form post about a piece of software we've been noodling with for 3-4 years now. Kurt is freaking out, because we haven't written anything on the blog since, like August. Finally I'm like, look, I will write the simplest thing I can come up with. We'll do the opposite of what we've been doing. We'll do anti- effortposts. I bet I can do one in 30 minutes.

    I promise, I thought about this less than you have. It's a thing we were tinkering with, and I wrote about it. That's all.