HN comments - Digest ⚙️ Edit Settings

Period: 2025-08-25 23:30 - 2025-09-01 18:01 📚 All Digests

AI Digest

我们应该有在自己拥有的硬件上运行任意代码的能力

评论者认为问题不在于“不能运行自己选择的软件”,而在于社会正在被苹果或谷歌账户所绑定,难以参与日常生活。以银行与学校的例子说明,去谷歌化的生活越来越困难,很多服务要求通过特定账户或应用才能使用。呼吁社会层面的对话,而不是仅仅聚焦技术 artefacts。

我们应该有在自己拥有的硬件上运行任意代码的能力

评论者指出,即使硬件允许安装替代操作系统,内容提供商与服务商的控制使得用户仍被锁定在受信任的实体链上。对 Netflix、银行等的强制性 DRM 与授权关系进行辩护,强调这不是纯粹的技术问题,而是原则和权利的问题,需要通过辩论来维护自主性与端到端加密等基本权利。

是否可以在确保用户安全的前提下允许旁加载(sideloading)?

评论者指出“sideloading”并非天然负面,回顾早期个人电脑时代,安装软件是常态。并且指出苹果在手机上缺乏自我保护的能力(如防火墙、拦截追踪等),以及系统对 telemetry 的控制与阻碍。

FBI 网络警察:Salt Typhoon 几乎攻破了“几乎每个美国人”的系统

评论者回顾对“让执法机构轻易获得访问权”的警告,认为这会增加对网络的渗透风险。引用历史事实与情报机构的行为,强调网络安全与隐私之间的张力,以及对政府能力与边界的担忧。

尽可能简单、但能起作用的做法

评论者指出“Do the simplest thing that could possibly work”并非意味着追求极端的简化,而是承认问题的复杂性并非可以一蹴而就地被简单化。强调在复杂系统中简单性与可维护性之间的权衡,以及避免为了追求简洁而牺牲必要的鲁棒性。

尽可能简单、但能起作用的做法

评论者分享在大型系统中的实际观察:即便在最简单的业务问题上,也可能因为边界情况与规模带来长期复杂性。对“简单性”的主张需要结合对实际场景的深度理解与演进中的代码库的现实性评估。

深入掌握代码速成1

评论者对代码生成与自动化工具的速度、可用性与功能表现给予正评,指出在代理性工作流中其表现出色,并对其成本与适用场景提出看法,认为市场竞争有利于推动优质服务与降低成本。

再次在 Anthropic 面试中失败

评论者坦诚分享面试经历的反思,强调一次拒绝并不能定义个人能力,指出招聘过程中的主观性和多重因素。强调对面试结果保持健康的心态、理解多轮评估的实务性。

Meta 可能在秘密扫描你手机的相机胶卷

评论者建议应提供应用访问相册的审计日志,让用户了解哪些数据被访问,从而提高透明度并促使开发者负责任地处理用户数据。

Ask HN:我所在国家的政府屏蔽了 VPN 访问。我应该使用什么?

评论者提供关于翻墙工具的实际建议,如获取可用的 VPN 软件与配置、使用混淆传输、以及长期绕过监控的挑战。还提及 Mullvad 等提供商,强调在高压环境下维持隐私的现实困境。

Google 在过去一年中裁减了负责小团队的 35% 经理

评论者分析 Google 的管理结构调整,认为这是将管理者和开发者更多地分工的举措,而非真正提高效率;这类改变被视为对组织结构和团队动力的再配置,影响生产力与协作方式。

GitHub 网站在 Safari 上很慢

评论者对 GitHub 的性能、用户体验以及产品路线表达强烈不满,指责决策过程的混乱与对社区工具生态的影响,同时指出与 GitLab 的对比中 GitHub 的弊端。

Nx 已被妥协:恶意软件利用 Claude 代码 CLI 浏览文件系统

评论者对安全建议的真实性提出质疑,强调在面对安全 advisories 时应自行核验来源,警惕被篡改的指令与工具,避免盲目信任。

Chrome 版 Claude

评论者关注 Claude for Chrome 的安全风险,特别是私有数据暴露、对不受信内容的风险以及数据外泄等潜在问题,提醒需要对这类工具保持警惕。

一名青少年自杀倾向。ChatGPT 是他倾诉的朋友

评论者回忆个人经历并强调需要更多的法规与工具来防止此类悲剧,认为 AI 对话系统如果缺乏适当的干预,可能对脆弱用户造成伤害,呼吁对这类问题进行更严格的监管与保护。

很遗憾,但我们必须暂时暂停对美国的发货

评论者对贸易与关税政策表达强烈不满,指出对材料含量的逐项申报以及对最终产品的高额关税不合逻辑,强调测量与估算的困难以及政策执行的混乱。

美国情报机构

评论者从半导体行业的视角出发,描述了行业人才向软件和机器学习转移的趋势,以及这对半导体行业的潜在影响与机会,提出若干策略性看法。

美国情报机构

评论者继续就美国在半导体领域的地位与政策讨论表达观点,分析未来的产业格局与国家层面的影响,强调保持对关键技术的战略关注。

Google 将只允许来自经过验证的开发者的应用在 Android 上安装

评论者质疑强制性开发者验证带来的影响,指出这可能削弱对自有设备的控制权,并批评 Play Protect 与 DRM 机制提升对设备自由的限制,以及对多样化生态系统的打压。

Google 将只允许来自经过验证的开发者的应用在 Android 上安装

评论者对应用商店对开发者的信誉审核提出担忧,讨论这类做法的安全性与自由之间的权衡,并质疑其对创新与用户自主性的潜在影响。

Google 将只允许来自经过验证的开发者的应用在 Android 上安装

评论者进一步讨论对“验证开发者”机制的担忧,强调普通用户对于安全性的追求应与对自由的保护并行,而不是简单地让市场由大厂来定义规则。

Google 将只允许来自经过验证的开发者的应用在 Android 上安装

评论者指出若仅以开发者身份验证来管理应用,可能会出现 YouTube Vanced 等被排除在外的情况,因其商业模式与平台收入相关,质疑监管方式的有效性与公平性。

Google 将只允许来自经过验证的开发者的应用在 Android 上安装

评论者对所谓的“验证开发者”策略表示担忧,认为这将削弱对第三方应用的支持,可能使用户更难获得自由与多样化的应用选择。



Details

bestcomments

  • New comment by kristov in "We should have the ability to run any code we want on hardware we own"
  • Content:

    I think the conversation needs to change from "can't run software of our choice" to "can't participate in society without an apple or google account". I have been living with a de-googled android phone for a number of years, and it is getting harder and harder, while at the same time operating without certain "apps" is becoming more difficult.

    For example, by bank (abn amro) still allows online banking on desktop via a physical auth device, but they are actively pushing for login only via their app. I called their support line for a lost card, and had to go through to second level support because I didn't have the app. If they get their way, eventually an apple or google account will be mandatory to have a bank account with them.

    My kid goes to a school that outsourced all communication via an app. They have a web version, but it's barely usable. The app doesn't run without certain google libs installed. Again, to participate in school communication about my kid effectively requires an apple or google account.

    I feel like the conversation we should be having is that we are sleepwalking into a world where to participate in society you must have an account with either apple or google. If you decide you don't want a relationship with either of those companies you will be extremely disadvantaged.


  • New comment by zmmmmm in "We should have the ability to run any code we want on hardware we own"
  • Content:

    > In this context this would mean having the ability and documentation to build or install alternative operating systems on this hardware

    It doesn't work. Everything from banks to Netflix and others are slowly edging out anything where they can't fully verify the chain of control to an entity they can have a legal or contractual relationship with. To be clear, this is fundamental, not incidental. You can't run your own operating system because it's not in Netflix's financial interest for you to do so. Or your banks, or your government. They all benefit from you not having control, so you can't.

    This is why it's so important to defend the real principles here not just the technical artefacts of them. Netflix shouldn't be able to insist on a particular type of DRM for me to receive their service. Governments shouldn't be able to prevent me from end to end encrypting things. I should be able to opt into all this if I want more security, but it can't be mandatory. However all of these things are not technical, they are principles and rights that we have to argue for.


  • New comment by m463 in "Is it possible to allow sideloading and keep users safe?"
  • Content:

    "sideloading" connotates something that is negative.

    On systems before apple's locked-down iphone, it was just called "installing".

    The PC revolution started with people just inserting their software into the comptuer and running it. You didn't have to ask the computer manufacturer or the OS vendor permission to do it.

    And note that apple doesn't allow you to protect yourself. You cannot install a firewall and block arbitrary software on your phone. For example, you can not block apple telemetry.


  • New comment by michael1999 in "FBI cyber cop: Salt Typhoon pwned 'nearly every American'"
  • Content:

    The security community warned that making Lawful Access easy and automated would guarantee that bad people would penetrate the network.

    And now we have China using CALEA-crippled systems to slurp up the entire USA network. Exactly as predicted.

    And this - "outside of the norms of what we see in the espionage space" - LOL. ROTFL even. The NSA tapped Google's backbone! Have we forgotten Room 641A? MAINWAY? Poindexter and TIA? Palantir?

    The NSA used to play defence and offence, and has gone full-offence for a generation. Did anyone really believe that only the USA could play offence?

    Morons.


  • New comment by sodapopcan in "Do the simplest thing that could possibly work"
  • Content:

    This is the classic misunderstanding where software engineers can't seem to communicate well with each other.

    We can even just look at the title here: Do the simplest thing POSSIBLE.

    You can't escape complexity when a problem is complex. You could certainly still complicate it even more than necessary, though. Nowhere in this article is it saying you can avoid complexity altogether, but that many of us tend to over-complicate problems for no good reason.


  • New comment by codingwagie in "Do the simplest thing that could possibly work"
  • Content:

    I think this works in simple domains. After working in big tech for a while, I am still shocked by the required complexity. Even the simplest business problem may take a year to solve, and constantly break due to the astounding number of edge cases and scale.

    Anyone proclaiming simplicity just hasnt worked at scale. Even rewrites that have a decade old code base to be inspired from, often fail due to the sheer amount of things to consider.

    A classic, Chesterton's Fence:

    "There exists in such a case a certain institution or law; let us say, for the sake of simplicity, a fence or gate erected across a road. The more modern type of reformer goes gaily up to it and says, “I don’t see the use of this; let us clear it away.” To which the more intelligent type of reformer will do well to answer: “If you don’t see the use of it, I certainly won’t let you clear it away. Go away and think. Then, when you can come back and tell me that you do see the use of it, I may allow you to destroy it.”"


  • New comment by NitpickLawyer in "Grok Code Fast 1"
  • Content:

    Tested this yesterday with Cline. It's fast, works well with agentic flows, and produces decent code. No idea why this thread is so negative (also got flagged while I was typing this?) but it's a decent model. I'd say it's at or above gpt5-mini level, which is awesome in my book (I've been maining gpt5-mini for a few weeks now, does the job on a budget).

    Things I noted:

    - It's fast. I tested it in EU tz, so ymmv

    - It does agentic in an interesting way. Instead of editing a file whole or in many places, it does many small passes.

    - Had a feature take ~110k tokens (parsing html w/ bs4). Still finished the task. Didn't notice any problems at high context.

    - When things didn't work first try, it created a new file to test, did all the mocking / testing there, and then once it worked edited the main module file. Nice. GPT5-mini would often times edit working files, and then get confused and fail the task.

    All in all, not bad. At the price point it's at, I could see it as a daily driver. Even agentic stuff w/ opus + gpt5 high as planners and this thing as an implementer. It's fast enough that it might be worth setting it up in parallel and basically replicate pass@x from research.

    IMO it's good to have options at every level. Having many providers fight for the market is good, it keeps them on their toes, and brings prices down. GPT5-mini is at 2$/MTok, this is at 1.5$/MTok. This is basically "free", in the great scheme of things. I ndon't get the negativity.


  • New comment by jp57 in "Flunking my Anthropic interview again"
  • Content:

    One great piece of advice an informal mentor gave me long ago is that there is no information in a rejection.

    That is to say that you cannot draw any conclusions about yourself or your interviewing technique or your skills or anything from the single accept==0 bit that you typically get back. There are so many reasons that a candidate might get rejected that have nothing to do with one's individual performance in the interview or application process.

    Having been on the hiring side of the interview table now many more times than on the seeking side, I can say that this is totally true.

    One of the biggest misconceptions I see from job seekers, especially younger ones, is to equate a job interview to a test at school, assuming that there is some objective bar and if you pass it then you must be hired. It's simply not true. Frequently more than one good applicant applies for a single open role, and the hiring team has to choose among them. In that case, you could "pass" and still not get the job and the only reason is that the hiring team liked someone else better.

    I can only think of one instance where we had two great candidates for one role and management found a way to open another role so we could hire both. In a few other cases, we had people whom we liked but didn't choose and we forwarded their resumes to other teams who had open roles we thought would fit, but most of the time it's just, "sorry."


  • New comment by nomilk in "Meta might be secretly scanning your phone's camera roll"
  • Content:

    IMO Apple should provide the user with audit logs of which photos/videos were accessed by each app. It might be a long list but it alleviates doubt and would put huge pressure on reputable developers to ensure they don’t get caught doing things the user wouldn’t have expected (even if the user technically allowed it).


  • New comment by _verandaguy in "Ask HN: The government of my country blocked VPN access. What should I use?"
  • Content:

    Hello! I've got experience working on censorship circumvention for a major VPN provider (in the early 2020s).

    - First things first, you have to get your hands on actual VPN software and configs. Many providers who are aware of VPN censorship and cater to these locales distribute their VPNs through hard-to-block channels and in obfuscated packages. S3 is a popular option but by no means the only one, and some VPN providers partner with local orgs who can figure out the safest and most efficient ways to distribute a VPN package in countries at risk of censorship or undergoing censorship.

    - Once you've got the software, you should try to use it with an obfuscation layer.

    Obfs4proxy is a popular tool here, and relies on a pre-shared key to make traffic look like nothing special. IIRC it also hides the VPN handshake. This isn't a perfectly secure model, but it's good enough to defeat most DPI setups.

    Another option is Shapeshifter, from Operator (https://github.com/OperatorFoundation). Or, in general, anything that uses pluggable transports. While it's a niche technology, it's quite useful in your case.

    In both cases, the VPN provider must provide support for these protocols.

    - The toughest step long term is not getting caught using a VPN. By its nature, long-term statistical analysis will often reveal a VPN connection regardless of obfuscation and masking (and this approach can be cheaper to support than DPI by a state actor). I don't know the situation on the ground in Indonesia, so I won't speculate about what the best way to avoid this would be, long-term.

    I will endorse Mullvad as a trustworthy and technically competent VPN provider in this niche (n.b., I do not work for them, nor have I worked for them; they were a competitor to my employer and we always respected their approach to the space).


  • New comment by AnotherGoodName in "Google has eliminated 35% of managers overseeing small teams in past year"
  • Content:

    This was called the TLM role at google. Technical Lead/Manager. You were expected to code and manage a couple of more junior engineers.

    It’s part of an effort to have dedicated managers and dedicated engineers instead of hybrid roles.

    This is being sold as an efficiency win for the sake of the stock price but it’s really just moved a few people around with the TLMs now 100% focused on programming.


  • New comment by PedroBatista in "The GitHub website is slow on Safari"
  • Content:

    The Github website is slow everywhere. It is truly a piece of shit software both in terms of performance but also UX/UI and everything in between.

    It's a product of many cooks and their brilliant ideas and KPIs, a social network for devs and code being the most "brilliant" of them all. For day to day dev operations is something so mediocre even Gitlab looks like the golden standard compared to Github.

    And no, the problem is not "Rails" or [ insert any other tech BS to deflect the real problems ].


  • New comment by JdeBP in "Nx compromised: malware uses Claude code CLI to explore the filesystem"
  • Content:

    > Are you using a compromised version of nx?

    > Run semgrep --config [...]

    > Alternatively, you can run nx –version [...]

    Have we not learned, yet? The number of points this submission has already earned says we have not.

    People, do not trust security advisors who tell you to do such things, especially ones who also remove the original instructions entirely and replace them with instructions to run their tools instead.

    The original security advisory is at https://github.com/nrwl/nx/security/advisories/GHSA-cxm3-wv7... and at no point does it tell you to run the compromised programs in order to determine whether they are compromised versions. Or to run semgrep for that matter.


  • New comment by dfabulich in "Claude for Chrome"
  • Content:

    Claude for Chrome seems to be walking right into the "lethal trifecta." https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/

    "The lethal trifecta of capabilities is:"

    Access to your private data—one of the most common purposes of tools in the first place!

    Exposure to untrusted content—any mechanism by which text (or images) controlled by a malicious attacker could become available to your LLM

    The ability to externally communicate in a way that could be used to steal your data (I often call this “exfiltration” but I’m not confident that term is widely understood.)

    If your agent combines these three features, an attacker can easily trick it into accessing your private data and sending it to that attacker.


  • New comment by podgietaru in "A teen was suicidal. ChatGPT was the friend he confided in"
  • Content:

    I have looked suicide in the eyes before. And reading the case file for this is absolutely horrific. He wanted help. He was heading in the direction of help, and he was stopped from getting it.

    He wanted his parents to find out about his plan. I know this feeling. It is the clawing feeling of knowing that you want to live, despite feeling like you want to die.

    We are living in such a horrific moment. We need these things to be legislated. Punished. We need to stop treating them as magic. They had the tools to prevent this. They had the tools to stop the conversation. To steer the user into helpful avenues.

    When I was suicidal, I googled methods. And I got the number of a local hotline. And I rang it. And a kind man talked me down. And it potentially saved my life. And I am happier, now. I live a worthwhile life, now.

    But at my lowest.. An AI Model designed to match my tone and be sycophantic to my every whim. It would have killed me.


  • New comment by zaptheimpaler in "We regret but have to temporary suspend the shipments to USA"
  • Content:

    > importers must declare the exact amount of steel, copper, and aluminum in products, with a 100% tariff applied to these materials. This makes little sense—PCBs, for instance, contain copper traces, but the quantity is nearly impossible to estimate.

    Wow this administration is f**ing batshit insane. I thought the tariffs would be on raw metals, not anything at all that happens to contain them.


  • New comment by georgeburdell in "US Intel"
  • Content:

    If I may add my view as a formerly high-achieving semiconductor worker that Intel would benefit greatly from having right now, a lot of us pivoted to software and machine learning to earn more money. My first 2 years as a software engineer earned me more RSUs than a decade in semiconductors. Semiconductors is not prestigious work in the U.S., despite the strategic importance. By contrast, it is highly respected and relatively well remunerated in the countries doing well in it.

    From this lens, the silver lining of the software layoffs going on may be to stem the bleeding of semiconductor workers to the field. If Intel were really smart, they’d be hiring more right now the people they couldn’t get or retain 3-5 years ago


  • New comment by themgt in "US Intel"
  • Content:

    I’ll be honest: there is a very good chance this won’t work .... At the same time, the China concerns are real, Intel Foundry needs a guarantee of existence to even court customers, and there really is no coming back from an exit. There won’t be a startup to fill Intel’s place. The U.S. will be completely dependent on foreign companies for the most important products on earth, and while everything may seem fine for the next five, ten, or even fifteen years, the seeds of that failure will eventually sprout, just like those 2007 seeds sprouted for Intel over the last couple of years. The only difference is that the repercussions of this failure will be catastrophic not for the U.S.’s leading semiconductor company, but for the U.S. itself.

    Very well argued. It's such a stunning dereliction the US let things get to this point. We were doing the "pivot to Asia" over a decade ago but no one thought to find TSMC on a map and ask whether Intel was driving itself into the dirt? "For want of a nail the kingdom was lost" but in this case the nail is like your entire metallurgical industry outsourced to the territory you plan on fighting over.


  • New comment by arielcostas in "Google will allow only apps from verified developers to be installed on Android"
  • Content:

    Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning the device, not the user.

    Android shouldn't be considered Open Source anymore, since source code is published in batches and only part of the system is open, with more and more apps going behind the Google ecosystem itself.

    Maybe it's time for a third large phone OS, whether it comes from China getting fed up with the US and Google's shenanigans (Huawei has HarmonyOS but it's not open) or some "GNU/Linux" touch version that has a serious ecosystem. Especially when more and more apps and services are "mobile-first" or "mobile-only" like banking.


  • New comment by tgma in "Google will allow only apps from verified developers to be installed on Android"
  • Content:

    The funny thing is Stallman started his fight like half a century ago and on regular days Hacker News shits on him eating something off of his foot and not being polished and diplomatic, and loves practical aspects of Corporate Open Source and gratis goodies and doesn't particularly care about Free Software.

    On this day suddenly folks come out of the woodwork advocating for half baked measures to achieve what Stallman portrayed but they still hardly recognize this was EXACTLY his concern when he started the Free Software movement.


  • New comment by medhir in "Google will allow only apps from verified developers to be installed on Android"
  • Content:

    Every day we stray farther from the premise that we should be allowed to install / modify software on the computers we own.

    Will once again re-up the concept of a “right to root access”, to prevent big corps from pulling this bs over and over again: https://medhir.com/blog/right-to-root-access


  • New comment by rvnx in "Google will allow only apps from verified developers to be installed on Android"
  • Content:

    If this is a thing then the solution they offer is incorrect. A big giant red screen: “warning the identity of this application developer has not been verified and this could be an application stealing your data, etc” would have worked.

    What they want is to get rid of apps like YouTube Vanced that are making them lose money (and other Play Store apps)


  • New comment by throw10920 in "Google will allow only apps from verified developers to be installed on Android"
  • Content:

    This is really bad. I think that most people on HN will agree with that.

    The problem is that most normal people (HN is not normal - mostly for the better) don't even understand what sideloading is - let alone actually care.

    How can we fix this?

    (aside from making people care - apathy enables so many political problems in the current age, but it's such a huge problem that this definitely isn't going to be the impetus to fix it)