HN comments - Digest ⚙️ Edit Settings

Period: 2025-12-17 21:46 - 2025-12-24 10:19 📚 All Digests

Details

bestcomments

  • New comment by kburman in "I didn't realize my LG TV was spying on me until I turned off Live Plus"
  • Content:

    My rule for modern TVs: 1. Never connect the TV panel itself to the internet. Keep it air-gapped. Treat it solely as a dumb monitor.

    2. Use an Apple TV for the "smart" features.

    3. Avoid Fire TV, Chromecast, or Roku.

    The logic is simple, Google (Chromecast) and Amazon (Fire TV) operate on the same business model as the TV manufacturers subsidized hardware in exchange for user data and ad inventory. Apple is the only mainstream option where the hardware cost covers the experience, rather than your viewing habits subsidizing the device.

    [Copied my comment from here: https://news.ycombinator.com/item?id=46268844#46271740]


  • New comment by mikepavone in "We replaced H.264 streaming with JPEG screenshots (and it worked better)"
  • Content:

    > When the network is bad, you get... fewer JPEGs. That’s it. The ones that arrive are perfect.

    This would make sense... if they were using UDP, but they are using TCP. All the JPEGs they send will get there eventually (unless the connection drops). JPEG does not fix your buffering and congestion control problems. What presumably happened here is the way they implemented their JPEG screenshots, they have some mechanism that minimizes the number of frames that are in-flight. This is not some inherent property of JPEG though.

    > And the size! A 70% quality JPEG of a 1080p desktop is like 100-150KB. A single H.264 keyframe is 200-500KB. We’re sending LESS data per frame AND getting better reliability.

    h.264 has better coding efficiency than JPEG. For a given target size, you should be able to get better quality from an h.264 IDR frame than a JPEG. There is no fixed size to an IDR frame.

    Ultimately, the problem here is a lack of bandwidth estimation (apart from the sort of binary "good network"/"cafe mode" thing they ultimately implemented). To be fair, this is difficult to do and being stuck with TCP makes it a bit more difficult. Still, you can do an initial bandwidth probe and then look for increasing transmission latency as a sign that the network is congested. Back off your bitrate (and if needed reduce frame rate to maintain sufficient quality) until transmission latency starts to decrease again.

    WebRTC will do this for you if you can use it, which actually suggests a different solution to this problem: use websockets for dumb corporate network firewall rules and just use WebRTC everything else


  • New comment by antirez in "Fabrice Bellard Releases MicroQuickJS"
  • Content:

    If this had been available in 2010, Redis scripting would have been JavaScript and not Lua. Lua was chosen based on the implementation requirements, not on the language ones... (small, fast, ANSI-C). I appreciate certain ideas in Lua, and people love it, but I was never able to like Lua, because it departs from a more Algol-like syntax and semantics without good reasons, for my taste. This creates friction for newcomers. I love friction when it opens new useful ideas and abstractions that are worth it, if you learn SmallTalk or FORTH and for some time you are lost, it's part of how the languages are different. But I think for Lua this is not true enough: it feels like it departs from what people know without good reasons.


  • New comment by groundzeros2015 in "Fabrice Bellard Releases MicroQuickJS"
  • Content:

    For all the praise he gets here, few seem interested in his methods: writing complete programs, based on robust computer science, with minimal dependencies and tooling.


  • New comment by ddtaylor in "Fabrice Bellard Releases MicroQuickJS"
  • Content:

    Fabrice Bellard is widely considered one of the most productive and versatile programmers alive:

    - FFmpeg: https://bellard.org

    - QEMU: https://bellard.org/qemu/

    - JSLinux: https://bellard.org/jslinux/

    - TCC: https://bellard.org/tcc/

    - QuickJS: https://bellard.org/quickjs/

    Legendary.


  • New comment by pizlonator in "Fabrice Bellard Releases MicroQuickJS"
  • Content:

    This engine restricts JS in all of the ways I wished I could restrict the language back when I was working on JSC.

    You can’t restrict JS that way on the web because of compatibility. But I totally buy that restricting it this way for embedded systems will result in something that sparks joy


  • New comment by InsideOutSanta in "How Did Doge Disrupt So Much While Saving So Little?"
  • Content:

    Perhaps because disrupting things was the actual goal, rather than saving money. DOGE was highly effective in harming the entities meant to oversee Musk's companies, stealing information about union organizing and labor complaints, reducing the government's ability to collect taxes, and destroying its regulatory capacity.


  • New comment by Fiveplus in "Meta is using the Linux scheduler designed for Valve's Steam Deck on its servers"
  • Content:

    Valve is practically singlehandedly dragging the Linux ecosystem forward in areas that nobody else wanted to touch.

    They needed Windows games to run on Linux so we got massive Proton/Wine advancements. They needed better display output for the deck and we got HDR and VRR support in wayland. They also needed smoother frame pacing and we got a scheduler that Zuck is now using to run data centers.

    Its funny to think that Meta's server efficiency is being improved because Valve paid Igalia to make Elden Ring stutter less on a portable Linux PC. This is the best kind of open source trickledown.


  • New comment by ZeroCool2u in "Meta is using the Linux scheduler designed for Valve's Steam Deck on its servers"
  • Content:

    Igalia is a bit unique as it serves as a single corporate entity for organizing a lot of sponsored work on the Linux kernel and open source projects. You'll notice in their blog posts they have collaborations with a number of other large companies seeking to sponsor very specific development work. For example, Google works with them a lot. I think it really just simplifies a lot of logistics for paying folks to do this kind of work, plus the Igalia employees can get shared efficiency's and savings for things like benefits etc.


  • New comment by gmd63 in "Inside CECOT – 60 Minutes [video]"
  • Content:

    Larry Ellison is using his bags to purchase lies and silence.

    No economy can be in true equilibrium when the consumers send profits to be spent in unforeseen and unrelated ways like this. Every purchase carries potentially immense future costs that are almost completely opaque.

    Free market maximalists need to confront this fact before praying at the altar of complete deregulation, and every consumer should pay more attention to who they are buying from.


  • New comment by evan_ in "Inside CECOT – 60 Minutes [video]"
  • Content:

    The whole thing is poorly-conceived and obviously false but I just have to call this out-

    > Of the 252 Venezuelans sent to CECOT, we say nearly half have no criminal histories. In other words, more than half do have criminal histories. We should spend a beat explaining this.

    The story isn't that people found guilty of crimes went to jail, the story is that half weren't even charged with crimes! That's the whole point of the story! We should not be aiming for a balanced diet of criminals and not-criminals in our government-sponsored foreign death camps!

    The fact that they exist at all is an affront to humanity, but to say "it's OK because a slim majority deserve it"- I just don't know what to say.

    > We then say that only 8 of the 252 have been sentenced in America for violent offenses. But what about charged?

    What about charged? What does charged with a crime have to do with anything? Why bring that up at all? Do we send people to prison because they were charged with a crime? Is Bari Weiss a newborn baby who has never heard about the presumption of innocence?

    I feel sick.


  • New comment by dcminter in "Ryanair fined €256M over ‘abusive strategy’ to limit ticket sales by OTAs"
  • Content:

    "O’Leary accused the travel agent industry of scamming and ripping off unsuspecting consumers by charging extra fees and markups on ticket prices."

    That is ... pretty rich.

    A couple of years ago I was going to go see my brother in the UK who lived near Stansted. As such Ryanair would have been the most convenient airline. The shere number of dark patterns I encountered trying to book the ticket was such that when I got to the payment page and they tried to coax me into using my local currency instead of GBP and hid a £20 spread in the exchange rate I rage quit. I should have known better even then, but now I will only use them if I have literally no other choice. With luck that means "never."

    I'm always happy to see the various EU competition authorities pushing back on this kind of thing.


  • New comment by Doches in "10 years bootstrapped: €6.5M revenue with a team of 13"
  • Content:

    > We're not bragging (okay, we're bragging a little) but it turns out that not burning through VC cash on ping-pong tables and "growth at all costs" actually works.

    Have an internet fist-bump from a fellow successful bootstrapper; this is the way, and you're calling it out!


  • New comment by isodev in "iOS 26.3 brings AirPods-like pairing to third-party devices in EU under DMA"
  • Content:

    It’s fascinating the kind of cool features we can have when products are made to be useful, with their target user in mind. Go EU!


  • New comment by UncleMeat in "Inside CECOT – 60 Minutes [video]"
  • Content:

    Weiss got her start screaming about how various college professors should be fired. There has never once been a moment in her career where she seriously cared about open debate.


  • New comment by cdrnsf in "Inside CECOT – 60 Minutes [video]"
  • Content:

    She was hired following the acquisition of Paramount to do things exactly like this. She's not a journalist.


  • New comment by slg in "Cecot – 60 Minutes"
  • Content:

    I'm reminded of the Letter on Justice and Open Debate[1] that Bari Weiss signed only a few years ago, now she's spiking stories like this one on CECOT for showing the current administration in a negative light.

    I also wonder if this story will get the type of leeway to stay on HN to collect the 200+ upvotes and 300+ comments of that previous example or if it will be flagged off the front page within minutes like so many other similar stories.

    EDIT: No idea how long this post actually lasted, but checking in an hour later to see this has been flagged completely off the first 10 pages of HN despite getting close to that 200 point total.

    [1] - https://news.ycombinator.com/item?id=23759283


  • New comment by scratchyone in "Inside CECOT – 60 Minutes [video]"
  • Content:

    I have a feeling this will get DMCA-ed off of Internet Archive in an attempt to suppress it. Here's the infohash of the archive.org torrent download for future reference, this should allow the file to be retrieved in any torrent client as long as someone in the world is seeding it still.

    8105370ed7dba50dc7ec659fd67550569b4dd8a0


  • New comment by dogman144 in "Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves"
  • Content:

    Was fortunate to talk to a security lead who built the data-driven policing network for a major American city that was an early adopter. ALPR vendors like Flock either heavily augment and/or anchor the tech setups.

    What was notable to me is the following, and it’s why I think a career spent on either security researching, or going to law school and suing, these vendors into the ground over 20 years would be the ultimate act of civil service:

    1. It’s not just Flock cams. It’s the data eng into these networks - 18 wheeler feed cams, flock cams, retail user nest cams, traffic cams, ISP data sales

    2. All in one hub, all searchable by your local PD and also the local PD across state lines who doesn’t like your abortion/marijuana/gun/whatever laws, and relying on:

    3. The PD to setup and maintain proper RBAC in a nationwide surveillance network that is 100%, for sure, no doubt about it (wait how did that Texas cop track the abortion into Indiana/Illinois…?), configured for least privilege.

    4. Or if the PD doesn’t want flock in town, they reinstall cameras against the ruling (Illinois iirc?) or just say “we have the feeds for the DoT cameras in/out of town and the truckers through town so might as well have control over it, PD!”

    Layer the above with the current trend in the US, and 2025 model Nissan uploading stop-by-stop geolocation and telematics to cloud (then, sold into flock? Does even knowing for sure if it does or doesn’t even matter?)

    Very bad line of companies. Again all is from primary sources who helped implement it over the years. If you spend enough time at cybersecurity conferences you’ll meet people with these jobs.


  • New comment by gardncl in "US blocks all offshore wind construction, says reason is classified"
  • Content:

    US deploys nuclear energy at over $10/watt meanwhile solar and wind are deployed around $2/watt (for levelized cost of electricity) including battery storage which means they are deployed for roughly the same cost as natural gas (so, direct competitors).

    Don't let comments like this fool you, nuclear is far from being competitive with natural gas. Even in countries like south korea that can deploy nuclear the cheapest it's still $3/watt roughly.

    Good news? Net new solar and wind plants can come "online" in less than two years. Net new natural gas takes four years. Part of why 95% of new energy deployed last year were renewables in the US, not just the subsidies.


  • New comment by beembeem in "US blocks all offshore wind construction, says reason is classified"
  • Content:

    Result first (kill anything not carbon-based), find rationale later.

    Same applies to how this admin forced layoffs at the green energy (hydro + nuclear) behemoth BPA [1] (which was funded entirely by ratepayers, not the federal government) then claimed an energy emergency to keep open coal plants serving the same geographies, coal plants that were already uneconomical and planned for shut down (or re-tooling to gas in the case of TransAlta's plant in WA). [2] Oh and they already re-hired some of the laid off staff at BPA because they overcut.

    There is no point in taking these arguments at face value. It's an excuse generated after-the-fact, and in service of one outcome - kill renewable energy.

    [1] https://www.columbian.com/news/2025/mar/12/letter-cuts-at-bp...

    [2] https://www.seattletimes.com/seattle-news/climate-lab/doe-or...


  • New comment by JohnTHaller in "US blocks all offshore wind construction, says reason is classified"
  • Content:

    We've been in the realm of intentionally doing damage for a while now. But we got these cool red hats.


  • New comment by linuxhansl in "US blocks all offshore wind construction, says reason is classified"
  • Content:

    What the... It seems we crossed into the realm of intentionally doing damage. I'm reminded of threatening tariffs to successfully derail global carbon levy on ship emissions.

    Meanwhile China runs away with all the clean energy tech (solar, wind, batteries, etc, etc.) while we hold to fossil fuels to save less than 200,000 jobs.


  • New comment by tony_cannistra in "US blocks all offshore wind construction, says reason is classified"
  • Content:

    I looked into this a little because I was curious. I guess the ostensible "national security" rationale (which clearly is not the only reason!) for this is that turbines severely degrade the utility of radar surveillance along the coastlines.

    This is particularly relevant for low-altitude incursions and drones.

    Now, other large governments (UK) have resolved this in several ways, including the deployment of additional radars on and within the turbine farms themselves.

    So clearly this is politically motivated, and they're using what seems to be a real but solveable concern as a scapegoat.


  • New comment by jjwiseman in "Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves"
  • Content:

    The CEO of Flock, Garrett Langley, called Deflock a terrorist group. It's unhinged. https://www.youtube.com/watch?v=l-kZGrDz7PU


  • New comment by spullara in "Claude Code gets native LSP support"
  • Content:

    I really can't understand why JetBrains hasn't integrated its refactoring tools into the AI system. Really missed the boat on making their platform transformational for AI coding. Imagine how much smaller the context would be for a tool that renames a function than editing hundreds of files. This LSP support is a good start but without the mutation functions it is still pretty lackluster. Plus LSPs aren't as good as JetBrains generally.


  • New comment by kklisura in "Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves"
  • Content:

    For more context here Flock Safety is a YC-backed company [1][2]

    [1] https://www.ycombinator.com/companies/flock-safety

    [2] https://x.com/garrytan/status/1856016868580151615


  • New comment by bane in "The U.S. Is Funding Fewer Grants in Every Area of Science and Medicine"
  • Content:

    The people I know who work in life sciences R&D (basically anything bio) have had their funding absolutely annihilated. PhDs with 20 years of experience working second jobs as substitute high school teachers, lab workers taking up tech support positions paying a fraction of what was already terrible pay.

    What's worse is that in most of these fields, you don't really even start working until after your PhD.

    4 years is going to be a long time to underfund what's basically 4 entire classes of researchers coming out of Doctorate programs. It might take decades to recover our research programs.


  • New comment by edot in "Flock Exposed Its AI-Powered Cameras to the Internet. We Tracked Ourselves"
  • Content:

    Flock or their defenders will lock in on the excuse that “oh these are misconfigured” or “yeah hacking is illegal, only cops should have this data”. The issue is neither of the above. The issue is the collection and collation of this footage in the first place! I don’t want hackers watching me all the time, sure, but I DEFINITELY don’t trust the state or megacorps to watch me all the time. Hackers concern me less, actually. I’m glad that Benn Jordan and others are giving this the airtime it needs, but they’re focusing the messaging on security vulnerabilities and not state surveillance. Thus Flock can go “ok we will do better about security” and the bureaucrats, average suburbanites, and law enforcement agencies will go “ok good they fixed the vulnerabilities I’m happy now”


  • New comment by jsheard in "The biggest CRT ever made: Sony's PVM-4300"
  • Content:

    Don't sleep on that Shank Mods video linked at the end, it's insane that he managed to pull that off.

    He also made a second video (not linked) which shows off more of the actual hardware.

    https://www.youtube.com/watch?v=Dgkw3uu19V8


  • New comment by sandebert in "Programming languages used for music"
  • Content:

    Switch Angel live-code using Strudel. Really impressive and interesting stuff.

    https://youtu.be/aPsq5nqvhxg


  • New comment by Swizec in "If you don't design your career, someone else will (2014)"
  • Content:

    My favorite lens on this comes from Hamming:

    > It is well known the drunken sailor whos taggers to the left or right n independent random steps will, on the average, end up about sqrt(n) steps from the origin. But if there is a pretty girl in one direction, then his steps will tend to go in that direction and he will go a distance proportional to n. In a lifetime of many, many independent choices, small and large, a career with a vision will get you a distance proportional to n, while no vision will get you only the distance sqrt(n). In a sense, the main difference between those who go far and those who do not is some people have a vision and others do not and therefore can only react to the current events as they happen.

    Just a tiny bit of bias towards a direction will get you very far very fast.

    I once modeled+visualised this with a bit of javascript[1] and it's quite surprising to see the huge difference from even a tiny multiplication factor on each random/probabilistic decision.

    [1] https://swizec.com/blog/your-career-needs-a-vision/


  • New comment by zarzavat in "I wish people were more public"
  • Content:

    It's all very well being more public, until a government decides to make 5 years of social media history an entry condition[0], and moreover imprisons those people who are denied entry instead of simply sending them home on the next flight[1].

    I have no problem with this per se, as I have no plans to go to the US this decade, but I do worry about contagion. Perhaps being a public person on the internet is an idea whose time has come and gone.

    [0] https://www.bbc.com/news/articles/c1dz0g2ykpeo.amp

    [1] https://amp.dw.com/en/german-nationals-us-immigration-detain...


  • New comment by yoan9224 in "You’re not burnt out, you’re existentially starving"
  • Content:

    The premise is interesting but feels incomplete. The "Monday morning excitement test" doesn't account for the hedonic treadmill - even meaningful work becomes mundane once your brain adjusts to it.

    Also, many people are genuinely burnt out from overwork, not just existential malaise. When you're juggling demanding work, family responsibilities, and barely have time for basic self-care, the problem isn't finding your "highest purpose" - it's structural.

    That said, I agree that meaning matters. But meaning doesn't always come from work. Sometimes the healthiest thing is treating work as necessary fuel for a meaningful life outside of it - relationships, hobbies, community involvement.

    The "go into politics" solution is fascinating though. Zero-sum games as existential fulfillment feels counterintuitive.


  • New comment by nanolith in "I'm just having fun"
  • Content:

    We need more people in this world willing to do their own thing, even if others might find it intimidating or silly. The important thing is to have fun and learn things. Compiler hacking is just as good as any other hobby, even if it's done in good jest.

    Sometimes, these things become real businesses. Not that this should be the intent of this, but it shows that what some consider silly, others will pay good money for.

    Example: Cards Against Humanity started as a bit of a gag game between a small group of friends and eventually became something that has pop culture relevance.

    Example: The founder of FedEx actually wrote a business pitch paper for an overnight shipping company. This paper was given a low grade by his professor. He went on to form this company, which become a success, despite this low grade. I like to think that he did this out of spite, and that Christmas letters to his old professor must've been fun.


  • New comment by gkoberger in "Disney Imagineering Debuts Next-Generation Robotic Character, Olaf"
  • Content:

    This is cool, but it will almost definitely never end up in a park, outside of some promotional situations.

    Disney's been doing awesome work with "Living Characters", like a Mickey that moves his mouth or a BB-8 that can roll around. But for various reasons, they never tend to make it into regular usage.

    If you have a few hours over Christmas break and want to watch a 4 hour YouTube video (I promise if you're on HN on a Sunday, you'll be delighted by it), I highly highly recommend this video:

    "Disney's Living Characters: A Broken Promise" by Defunctland https://www.youtube.com/watch?v=NyIgV84fudM


  • New comment by isolatedsystem in "I can't upgrade to Windows 11, now leave me alone"
  • Content:

    Easy answer to your last point: Work machine and Non-work machine. If I'm working for a company and the company needs MS Office, they will give me a machine with MS Office. I will treat that machine like a radioactive zone. Full Hazmat suit. Not a shred of personal interaction with that machine. It exists only to do work on and that's that. The company can take care of keeping it up to date, and the company's IT department can do the bending over the table on my behest as MS approaches with dildos marked "Copilot" or "Recall" or "Cortana" or "React Native Start Menu" or "OneDrive" or whatever.

    Meanwhile, my personal machine continues to be Linux.

    This is what I'm doing at my work now. I'm lucky enough to have two computers, a desktop PC that runs Linux, and a laptop with Windows 11. I do not use that laptop unless I have to deal with xlsx, pptx or docx files. Life is so much better.


  • New comment by linguae in "I can't upgrade to Windows 11, now leave me alone"
  • Content:

    I miss the days when personal computers were simply tools, akin to pencils and handheld calculators. I remember the days of Macintosh System 7 and Windows 95. No upselling services. No automatic updates. No nagging. You turned your computer on, executed programs, and that was it.

    On the Windows side, things started going downhill starting with the Windows XP era, and on the Mac the annoyances began sometime in the mid-2010s.

    It seems Microsoft, Apple, and other companies realized that they’re leaving money on the table by not exploiting their platforms. Thus, they’re no longer selling simple tools, but rather they are selling us services.

    Yes, there are good Linux distributions that don’t annoy me, and the BSDs never nag me, but the problem with switching to these platforms is that I still need Microsoft Office and other proprietary software tools that are not available outside “Big Tech.” There are other matters that make switching away from Windows and macOS challenging, such as hardware support and laptop battery life.


  • New comment by simonw in "A guide to local coding models"
  • Content:

    > I realized I looked at this more from the angle of a hobbiest paying for these coding tools. Someone doing little side projects—not someone in a production setting. I did this because I see a lot of people signing up for $100/mo or $200/mo coding subscriptions for personal projects when they likely don’t need to.

    Are people really doing that?

    If that's you, know that you can get a LONG way on the $20/month plans from OpenAI and Anthropic. The OpenAI one in particular is a great deal, because Codex is charged a whole lot lower than Claude.

    The time to cough up $100 or $200/month is when you've exhausted your $20/month quota and you are frustrated at getting cut off. At that point you should be able to make a responsible decision by yourself.


  • New comment by yboris in "Show HN: Books mentioned on Hacker News in 2025"
  • Content:

    I once commented on HN how my favorite Sci Fi novel is Accelerando and the author, Charles Stross, replied to it suggesting I try his The Rapture of the Nerds he co-wrote with Cory Doctorow; I loved it when I read it too.

    I love HN - it's basically the only website I visit these days (aside checking mail, watching YouTube, and gardening my GitHub repositories).


  • New comment by Animats in "I can't upgrade to Windows 11, now leave me alone"
  • Content:

    Why would anyone want to buy a new computer now unless the old one is worn out? There is no price/performance improvement. Nor will there be for the next five years or so. NVidia says to expect 10% price increases each year. DRAM prices have doubled, and Samsung says not to expect price cuts. Micron just exited the retail RAM business.

    Microsoft is trying to escape this trap by pivoting to Windows as a subscription service. It will get worse, not better.


  • New comment by ori_b in "The Going Dark initiative or ProtectEU is a Chat Control 3.0 attempt"
  • Content:

    Until people lobby for these privacy rights to be enshrined in law, this will continue to be a problem.

    Defeating one bad law isn't enough.


  • New comment by unstyledcontent in "You’re not burnt out, you’re existentially starving"
  • Content:

    I'm burned out because I have to raise two young children, work a full time job in a demanding career, and then in the hour or two a day of time that isn't accounted for in those two tasks, I need to maintain a household and try to care for myself. I feel a strong sense of purpose caring for my family, but don't have enough time to meet life's demands. Maybe other people relate more to this post because they more money and no kids.


  • New comment by heinrichhartman in "Logging sucks"
  • Content:

    A post on this topic feels incomplete without a shout-out to Charity Majors - she has been preaching this for a decade, branded the term "wide events" and "observability", and built honeycomb.io around this concept.

    Also worth pointing out that you can implement this method with a lot of tools these days. Both structured Logs or Traces lend itself to capture wide events. Just make sure to use a tool that supports general query patterns and has rich visualizations (time-series, histograms).


  • New comment by MBCook in "Waymo halts service during S.F. blackout after causing traffic jams"
  • Content:

    From John Ripley on Mastodon:

    “Thought of the day, and I wish there were a way to get this to legislators:

    Come the next Big One earthquake, all of San Francisco’s emergency services will be blocked by Waymos.”

    I’m AMAZED they’re not designed to handle this better. This does indeed seem like a massive problem. “Oops we give up” right when things get the worst? How is this OK?

    I’ve been very impressed by Waymo’s more cautious approach. Perhaps they haven’t fully thought through the ramifications of it though.

    https://mastodon.social/@jripley/115758725115731454


  • New comment by GenerocUsername in "Show HN: Books mentioned on Hacker News in 2025"
  • Content:

    Hitchhikers guide to the universe having 42 mentions is a cosmic level coincidence


  • New comment by ziofill in "I program on the subway"
  • Content:

    When I was living in Paris I had a 20 min ride from home to work each day. I picked up the habit to read during those 40 total minutes and I was going through books like I had never been able to, because while 40 min is not a lot, it’s about 150h per year. One easily underestimates the power of consistency.


  • New comment by Aurornis in "Reasons not to become famous (2020)"
  • Content:

    If you’re not familiar with Tim Ferriss, you should know that there is always more to the story than the narrative he shares. He’s one of the most charismatic and charming writers and podcasters out there and has a strong ability to build trust through his writing. However, he also has a long history of stretching the truth and spinning history in his favor, often by omitting important facts.

    One example: His 4 Hour Work Week book really was on the New York Times Best Seller list for a long time like he brags about in this post, but he has also bragged in other contexts about all of the manipulation and engineering (including mass purchasing books to artificially inflate sales numbers) that goes into gaming the New York Times Best Seller List.

    On the topic of being famous, he’s not typically famous like a celebrity. He built his career around being a self-help guru who will bring you the secrets to success in business, life, relationships, and even cooking. He’s talked about how he selects his writing topics based on how to present solutions for people’s inner desires, like financial freedom or impressing people for dating success. He puts himself at the center of these writings, presenting himself as the conduit for these revelations. He was even early in social media and blogging and experimented with social media engagements and paid events where you get to come hang out with Tim Ferriss and learn his secrets, encouraging his fans to idolize him and his wisdom dispensing abilities.

    So his relationship with his fans isn’t typical fame in the style of a celebrity or actor. He’s more of an early self-help guru who embraced social media and blogging early on. His experience with uncomfortable fan obsessions is therefore probably on the next level, but not exactly typical fame.

    EDIT to add why I know this: Tim Ferriss literally wrote the book on how to abuse remote work. His Four Hour Work Week book encourages readers to talk their boss into working remote then to outsource their work to low paid overseas assistants so they have more time to travel the world. It encourages things like setting up an e-mail auto responder and only responding to your coworkers once a week whine you’re “working remote” and setting up your own side job while traveling the world. If you’ve ever had a remote work job get ruined by people abusing it, chances are good that those people had read a Tim Ferriss book somewhere along the way.


  • New comment by kshahkshah in "Ruby website redesigned"
  • Content:

    I used cursor over the past three weeks to update a 12 year-old Ruby on rails project. While it has been slightly updated throughout the years, this was my first proper modernization of the code base.

    It’s been a real pleasure getting back into Ruby after so many years in typescript, python, and rust.

    Happy to see the update. Real shame about the haters here, the Ruby community is a supportive and positive bunch that has shipped real products while others seem to worship at the altar of computer science alone… that’s about as counter snarky as I want to be here


  • New comment by Kwpolska in "Ruby website redesigned"
  • Content:

    So many Web designers put zero thought into how their page looks when it is not loaded or not scrolled exactly past the trigger. So many sites say "0 happy customers", because someone thought showing incrementing numbers is cool. On this page, it opens up with a "100%" loading indicator, for a site that appears to have no interactivity that would require JS, just to show a pointless animation.


  • New comment by thiht in "Clair Obscur having its Indie Game Game Of The Year award stripped due to AI use"
  • Content:

    That’s incredibly harsh. A blanket ban on AI generated assets is dumb as hell. Generating placeholder assets is completely acceptable.


  • New comment by skibidithink in "Clair Obscur having its Indie Game Game Of The Year award stripped due to AI use"
  • Content:

    The AI witch hunt claims its first victim, apparently over some placeholder textures.

    https://english.elpais.com/culture/2025-07-19/the-low-cost-c...

    > Sandfall Interactive further clarifies that there are no generative AI-created assets in the game. When the first AI tools became available in 2022, some members of the team briefly experimented with them to generate temporary placeholder textures. Upon release, instances of a placeholder texture were removed within 5 days to be replaced with the correct textures that had always been intended for release, but were missed during the Quality Assurance process.


  • New comment by yellow_lead in "Claude in Chrome"
  • Content:

    So Claude seems to have access to a tool to evaluate JS on the webpage, using the Chrome debugger.

    However, don't worry about the security of this! There is a comprehensive set of regexes to prevent secrets from being exfiltrated.

    const r = [/password/i, /token/i, /secret/i, /api[_-]?key/i, /auth/i, /credential/i, /private[_-]?key/i, /access[_-]?key/i, /bearer/i, /oauth/i, /session/i];


  • New comment by ethmarks in "Show HN: HN Wrapped 2025 - an LLM reviews your year on HN"
  • Content:

    https://hn-wrapped.kadoa.com/ethmarks

    Mine seems to think that I'm some kind of detail-obsessed super-pedant. Personally, I think this is ridiculous. "super" is a Latin stem meaning "beyond", which implies that I've transcended the qualities of pedantry. A better term would be 'pluri-pedant', which denotes someone who is exceptionally punctilious while still remaining within the bounds of being pedantic.


  • New comment by greyface- in "Flock and Cyble Inc. Weaponize "Cybercrime" Takedowns to Silence Critics"
  • Content:

    If Flock truly believed that the domain name infringes on their trademark, they would file an ICANN UDRP complaint instead of Cloudflare and Hetzner abuse reports.

    But they don't, because the former would require them to perjure themselves, and the latter just requires them to lie to a hosting company.


  • New comment by CAP_NET_ADMIN in "Claude in Chrome"
  • Content:

    Let's spend years plugging holes in V8, splitting browser components to separate processes and improving sandboxing and then just plug in LLM with debugging enabled into Chrome. Great idea. Last time we had such a great idea it was lead in gasoline.


  • New comment by muzani in "Show HN: Jmail – Google Suite for Epstein files"
  • Content:

    I'm impressed. You guys cloned a whole suite of products in a short period of time that cost millions of dollars. Even the little bits of humor look costly.

    On the other hand, it's way more information than I expected. I can see why someone would hesitate to release them - there's a lot to sift through and it's likely even the government couldn't sift through all of them to make sure their friends weren't mentioned somewhere.


  • New comment by jsheard in "Backing up Spotify"
  • Content:

    > The Anna’s archive group is ideologically motivated. They’re definitely not doing this for AI companies.

    They have a page directly addressed to AI companies, offering them "enterprise-level" access to their complete archives in exchange for tens of thousands of dollars. AI may not be their original/primary motivation but they are evidently on board with facilitating AI labs piracy-maxxing.


  • New comment by flxy in "Backing up Spotify"
  • Content:

    I think what earned what.cd that title wasn't necessarily just the amount but the quality, as you mentioned, as well as the obscurity of a lot of the offered material. I remember finding an early EP of an unknown local band on there, and I live in the middle of nowhere in Europe. There were also quite a few really old and niche records on there which possibly couldn't be put on streaming services due to the ownership of rights being unknown. It was the equivalent of vinyl crate digging without physical restrictions.

    Additionally there was a lot of discourse about music and a lot of curated discovery mechanisms I sorely miss to this day. An algorithm is no replacement for the amount of time and care people put into the web of similar artists, playlists of recommendations and reviews. Despite it being piracy, music consumption through it felt more purposeful. It's introduced me to some of my all time favourite artists, which I've seen live and own records and merchandise of.


  • New comment by Etheryte in "Backing Up Spotify"
  • Content:

    To put this into perspective, What.CD [0] was widely considered to be the music library of Alexandria, unparalleled in both its high quality standard and it's depth. What had in the ballpark of a few million torrents when it got raided and shut down. Anna's rip of Spotify includes roughly 186 million unique records. Granted, the tail end is a mixed bag of bot music and whatnot, but the scale is staggering.

    [0] https://en.wikipedia.org/wiki/What.CD


  • New comment by Aurornis in "Backing up Spotify"
  • Content:

    > The thing is, this doesn't even seem particularly useful for average consumers/listeners, since Spotify itself is so convenient, and trying to locate individual tracks in massive torrent files of presumably 10,000's of tracks each sounds horrible.

    I wouldn’t be so sure. There are already tools to automatically locate and stream pirated TV and movie content automatic and on demand. They’re so common that I had non-technical family members bragging at Thanksgiving about how they bought at box at their local Best Buy that has an app which plays any movie or TV show they want on demand without paying anything. They didn’t understand what was happening, but they said it worked great.

    > Definitely wondering if this was in response to desire from AI researchers/companies who wanted this stuff.

    The Anna’s archive group is ideologically motivated. They’re definitely not doing this for AI companies.


  • New comment by crazygringo in "Backing Up Spotify"
  • Content:

    This is insane.

    I definitely was not aware Spotify DRM had been cracked to enable downloading at scale like this.

    The thing is, this doesn't even seem particularly useful for average consumers/listeners, since Spotify itself is so convenient, and trying to locate individual tracks in massive torrent files of presumably 10,000's of tracks each sounds horrible.

    But this does seem like it will be a godsend for researchers working on things like music classification and generation. The only thing is, you can't really publicly admit exactly what dataset you trained/tested on...?

    Definitely wondering if this was in response to desire from AI researchers/companies who wanted this stuff. Or if the major record labels already license their entire catalogs for training purposes cheaply enough, so this really is just solely intended as a preservation effort?


  • New comment by Too in "Log level 'error' should mean that something needs to be fixed"
  • Content:

    This is why it’s almost always wrong for library functions to log anything, even on ”errors”. Pass the status up through return values or exceptions. As a library author you have no clue as how an application might use it. Multi threading, retry loops and expected failures will turn what’s a significant event in one context into what’s not even worthy of a debug log in another. No rule without exceptions of course, one valid case could be for example truly slow operations where progress reports are expected. Modern tracing telemetry with sampling can be another solution for the paranoid.


  • New comment by layer8 in "Log level 'error' should mean that something needs to be fixed"
  • Content:

    > When implementing logging, it's important to distinguish between an error from the perspective of an individual operation and an error from the perspective of the overall program or system. Individual operations may well experience errors that are not error level log events for the overall program. You could say that an operation error is anything that prevents an operation from completing successfully, while a program level error is something that prevents the program as a whole from working right.

    This is a nontrivial problem when using properly modularized code and libraries that perform logging. They can’t tell whether their operational error is also a program-level error, which can depend on usage context, but they still want to log the operational error themselves, in order to provide the details that aren’t accessible to higher-level code. This lower-level logging has to choose some status.

    Should only “top-level” code ever log an error? That can make it difficult to identify the low-level root causes of a top-level failure. It also can hamper modularization, because it means you can’t repackage one program’s high-level code as a library for use by other programs, without somehow factoring out the logging code again.


  • New comment by Youden in "Over 40% of deceased drivers in vehicle crashes test positive for THC: Study"
  • Content:

    There was a larger discussion in a previous thread on this topic: https://news.ycombinator.com/item?id=45494730

    Since then, [0] has been published and I think it's worth at least a skim. Since it's quite recent the introduction summarizes some of the most recent research.

    The things that jump out at me are:

    - [0]: Habitual users with baseline concentrations above legal limits perform just as well as habitual users with baseline concentrations below the legal limit, indicating that for habitual users, the legal limit doesn't have any relation to impairement.

    - [1]: A study in Canada analyzed crash reports and blood tests to look at the state of drivers responsible for accidents. While alcohol had a very clear and statistically-significant influence on the risk of a driver causing an accident, THC did not.

    To steelman the idea that THC causes accidents, [0] only looks at habitual users with baseline levels of THC and [1] only looks at non-fatal injuries.

    My conclusion right now is that the number of drivers in accidents with THC in their blood is going up because the number of people with THC in their blood is going up, not because drivers who use THC cause accidents.

    The law's assumption that this level of THC is evidence of impairment seems to be invalid.

    The law would be better off measuring impairment in some way and perhaps intensifying penalties when an impairment test fails and the user has THC concentration above some threshold.

    [0]: https://academic.oup.com/clinchem/article/71/12/1225/8299832...

    [1]: https://pubmed.ncbi.nlm.nih.gov/31106494/


  • New comment by mittermayr in "Go ahead, self-host Postgres"
  • Content:

    Self-hosting is more a question of responsibility I'd say. I am running a couple of SaaS products and self-host at much better performance at a fraction of the cost of running this on AWS. It's amazing and it works perfectly fine.

    For client projects, however, I always try and sell them on paying the AWS fees, simply because it shifts the responsibility of the hardware being "up" to someone else. It does not inherently solve the downtime problem, but it allows me to say, "we'll have to wait until they've sorted this out, Ikea and Disney are down, too."

    Doesn't always work like that and isn't always a tried-and-true excuse, but generally lets me sleep much better at night.

    With limited budgets, however, it's hard to accept the cost of RDS (and we're talking with at least one staging environment) when comparing it to a very tight 3-node Galera cluster running on Hetzner at barely a couple of bucks a month.

    Or Cloudflare, titan at the front, being down again today and the past two days (intermittently) after also being down a few weeks ago and earlier this year as well. Also had SQS queues time out several times this week, they picked up again shortly, but it's not like those things ...never happen on managed environments. They happen quite a bit.


  • New comment by tokai in "Over 40% of deceased drivers in vehicle crashes test positive for THC: Study"
  • Content:

    An issue with having the legal limit at ~2-5ng/ml is that it makes habitual users be over the limit if they have smoked recently or not.[0] Making the prohibition seem unserious to some, not about safety but about punitive control, and in turn making it matter less if you smoke and drive as you are taking the risk of getting into trouble in any case.

    The impairments of driving under the influence of alcohol have been extensively studied, but unless I have overlooked the literature it seems that the same investigations have not been carried out with THC.

    [0] «Blood THC >2 ng/mL, and possibly even THC >5 ng/mL, does not necessarily represent recent use of cannabis in frequent cannabis users.»; https://www.sciencedirect.com/science/article/abs/pii/S03768...


  • New comment by Nextgrid in "Go ahead, self-host Postgres"
  • Content:

    > employing engineers to manage self-hosted databases is more cost effective than outsourcing

    Every company out there is using the cloud and yet still employs infrastructure engineers to deal with its complexity. The "cloud" reducing staff costs is and was always a lie.

    PaaS platforms (Heroku, Render, Railway) can legitimately be operated by your average dev and not have to hire a dedicated person; those cost even more though.

    Another limitation of both the cloud and PaaS is that they are only responsible for the infrastructure/services you use; they will not touch your application at all. Can your application automatically recover from a slow/intermittent network, a DB failover (that you can't even test because your cloud providers' failover and failure modes are a black box), and so on? Otherwise you're waking up at 3am no matter what.


  • New comment by etra0 in "Reflections on AI at the End of 2025"
  • Content:

    LLMs have certainly become extremely useful for Software Engineers, they're very convincing (and pleasers, too) and I'm still unsure about the future of our day-to-day job.

    But one thing that has scared me the most, is the trust of LLMs output to the general society. I believe that for software engineers it's really easy to see if it's being useful or not -- We can just run the code and see if the output is what we expected, if not, iterate it, and continue. There's still a professional looking to what it produces.

    On the contrary, for more day-to-day usage of the general pubic, is getting really scary. I've had multiple members of my family using AI to ask for medical advice, life advice, and stuff were I still see hallucinations daily, but at the same time they're so convincing that it's hard for them not to trust them.

    I still have seen fake quotes, fake investigations, fake news being spreaded by LLMs that have affected decisions (maybe, not as crucials yet but time will tell) and that's a danger that most software engineers just gross over.

    Accountability is a big asterisk that everyone seems to ignore


  • New comment by jrronimo in "NTP at NIST Boulder Has Lost Power"
  • Content:

    I'm the Manager of the Computing group at JILA at CU, where utcnist*.colorado.edu used to be housed. Those machines were, for years, consistently the highest bandwidth usage computers on campus.

    Unfortunately, the HP cesium clock that backed the utcnist systems failed a few weeks ago, so they're offline. I believe the plan is to decommission those servers anyway - NIST doesn't even list them on the NTP status page anymore, and Judah Levine has retired (though he still comes in frequently). Judah told me in the past that the typical plan in this situation is that you reference a spare HP clock with the clock at NIST, then drive it over to JILA backed by some sort of battery and put it in the rack, then send in the broken one for refurb (~$20k-$40k; new box is closer to $75k). The same is true for the WWVB station, should its clocks fail.

    There is fiber that connects NIST to CU (it's part of the BRAN - Boulder Research and Administration Network). Typically that's used when comparing some of the new clocks at JILA (like Jun Ye's strontium clock) to NIST's reference. Fun fact: Some years back the group was noticing loss due to the fiber couplers in various closets between JILA & NIST... so they went to the closets and directly spliced the fibers to each other. It's now one single strand of fiber between JILA & NIST Boulder.

    That fiber wasn't connected to the clock that backed utcnist though. utcnist's clock was a commercial cesium clock box from HP that was also fed by GPS. This setup was not particularly sensitive to people being in the room or anything.

    Another fun fact: utcnist3 was an FPGA developed in-house to respond to NTP traffic. Super cool project, though I didn't have anything to do with it, haha.


  • New comment by cornholio in "NTP at NIST Boulder Has Lost Power"
  • Content:

    The disater plan is to have a few dozens stratum 1 servers spread around the world, each connected to a distinct primary atomic clock, so that a catastrophic disaster needs to take down the global internet itself for all servers to become unreachable.

    The failure of a single such server is far from a disaster.


  • New comment by jimnotgym in "Airbus to migrate critical apps to a sovereign Euro cloud"
  • Content:

    Freeloading?

    My country spends less on defence as a percentage of GDP than the US. But it spends much of that with US companies. This is not Freeloading. It was a deal. Cancel TSR-2, and buy American and we will lend you some money. Cancel your nuclear program and buy US submarine launched missiles and we will help you look after yourself. Now let Visa and Mastercard skim off all your transactions and we will keep you secure to keep the money flowing. Sweetheart tax deals for US companies to operate, and we will keep you safe to keep the money flowing. It is not Freeloading, it is colonialism


  • New comment by arn3n in "NTP at NIST Boulder Has Lost Power"
  • Content:

    Wind gusts were reaching 125 MPH in Boulder county, if anyone’s curious. A lot of power was shut off preemptively to prevent downed power lines from starting wildfires. Energy providers gave warning to locals in advance. Shame that NIST’s backup generator failed, though.


  • New comment by breve in "Airbus to migrate critical apps to a sovereign Euro cloud"
  • Content:

    A necessary step to reduce risk to infrastructure given that the US government has become erratic and has decided it is now anti-Europe.

    The US means to undermine the EU: https://www.dw.com/en/will-trump-pull-italy-austria-poland-h...

    The US means to annex European territory: https://www.bbc.com/news/articles/c0j9l08902eo

    It's the same reason you don't want Chinese equipment in your telecommunications infrastructure. You can't trust what the Chinese government will do to it or with it.


  • New comment by autarch in "NTP at NIST Boulder Has Lost Power"
  • Content:

    Time travel is extremely dangerous right now. I highly recommend deferring time travel plans except for extreme temporal emergencies.


  • New comment by flumpcakes in "Airbus to migrate critical apps to a sovereign Euro cloud"
  • Content:

    Some people in the US deride it's close allies as "freeloaders" because they choose to use and buy US tech, reinforcing the US's position as a global powerhouse. (Meanwhile US tech is built on the shoulders of their allies.) Now we see these same allies are starting to look inward and invest in technology they own completely because the US is acting decisively not like an ally. Something unthinkable since WW2.

    I don't see this news as anything but a good thing. For every technology out there, the EU needs a native alternative. It's clear the current US administration wants to make the EU worse based on a politics of grievance.


  • New comment by mk89 in "Privacy doesn't mean anything anymore, anonymity does"
  • Content:

    At first I thought it was a blog. No, this is a company. So, their privacy page (https://servury.com/privacy/):

    > Server Logs > Like all web services, our servers may log: > IP addresses of visitors > Request timestamps > User agent strings > These logs are used for security and debugging purposes and are not linked to your account.

    That's already a huge breach in comparison to mullvad privacy page. (https://mullvad.net/en/help/no-logging-data-policy)


  • New comment by BrenBarn in "Android introduces $2-4 install fee and 10–20% cut for US external content links"
  • Content:

    The fact that this is being introduced after the whole Epic/Apple thing clearly shows that the penalties in that case were not nearly severe enough and the standards set were not nearly stringent enough. The mere attempt to engage in policies like this should result in fines in the hundreds of billions.


  • New comment by hirsin in "Android introduces $2-4 install fee and 10–20% cut for US external content links"
  • Content:

    The apparent information gathering and brutal review process is unbelievable here. If I'm understanding this correctly, the requirement is that eg Epic Game Store must register and upload every single APK for every app they offer, and cannot offer it in their store until Google approves it, which may take a week or more - including every time the app updates.

    Meanwhile they get full competitive insight into which apps are being added to Epics store, their download rates apparently, and they even get the APKs to boot, potentially making it easier for those app devs to onboard if they like, and can pressure them to do so by dragging their feet on that review process.

    > Provide direct, publicly accessible customer support to end users through readily accessible communication channels.

    This is an interesting requirement. I want to see someone provide the same level of support that Google does to see if it draws a ban.


  • New comment by culi in "CSS Grid Lanes"
  • Content:

    Props to the Safari team. They surprised us all when they suddenly shot to the top of interop-2025 this October

    https://wpt.fyi/interop-2025


  • New comment by noname123 in "Brown/MIT shooting suspect found dead, officials say"
  • Content:

    I work on campus (very very close to the engineering building) and I previously lived near Brookline. So all of this hits home.

    But what got me was the tipster who blew wide open the case is reportedly a homeless Brown graduate who lived in the basement of the engineering building (a la South Korean film Parasite). It made me so sad but also not surprised, that building does have a single occupancy bathroom with showers; and no keycard access was needed in the evening until 7pm.

    So it made sense to me that he or she would've used that building for shelter and comfort. Also it didn't boggle my mind at all that a Brown grad (from the picture, the tipster looked like a artistic Brown student vs. the careerist type) would be homeless - given that I known many of my classmates who have a certain personality, brilliant but also idealistic/uncompromising that made them brittle unfortunately in a society that rewards conformity, settling and stability.

    I can't get over the fact that two Brown student whom presumably have fallen on the wayside of society have chosen two different paths, (1) the homeless guy who still perseveres even in the basement of Barrus & Holley for 15 years a la Parasite after 2010 graduation but still has the situational awareness and rises to the occasion to give the biggest tip to the Providence Police, (2) the other guy who harbors so much resentment over a course of 25 years to plan a trip from Florida to gun down innocent kids who are 18 and 19 and his classmate when they were 18 and 19 year old.


  • New comment by Aliabid94 in "Brown/MIT shooting suspect found dead, officials say"
  • Content:

    Worth noting that a partner at Sequoia (Shaun Maguire) publicly accused the wrong guy of being the shooter.

    https://www.fastcompany.com/91463942/sequoia-shaun-maguire-b...


  • New comment by koakuma-chan in "Rust's Block Pattern"
  • Content:

    I have one better: the try block pattern.

    https://doc.rust-lang.org/beta/unstable-book/language-featur...


  • New comment by rao-v in "TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy"
  • Content:

    I'm a little frustrated with articles like this that scattershot their critique by conflating genuine failures with problems that even FAANGs struggle with.

    In particular, I don't love it when an article attacks a best practice as a cheap gotcha:

    "and this time it was super easy! After some basic reversing of the Tapo Android app, I found out that TP-Link have their entire firmware repository in an open S3 bucket. No authentication required. So, you can list and download every version of every firmware they’ve ever released for any device they ever produced"

    That is a good thing - don't encourage security through obscurity! The impact of an article like this is as likely to get management to prescribe a ham-handed mandate to lock down firmware as it is to get them to properly upgrade their security practices.


  • New comment by jonathannorris in "Graphite is joining Cursor"
  • Content:

    Yeah, hard disagree on that one, based on recent surveys, 80-90% of developers globally use IDEs over CLIs for their day-to-day work.

    I was pretty worried about Cursor's business until they launched their Composer 1 model, which is fine-tuned to work amazingly well in their IDE. It's significantly faster than using any other model, and it's clearly fine-tuned for the type of work people use Cursor for. They are also clearly charging a premium for it and making a healthy margin on it, but for how fast + good it's totally worth it.

    Composer 1 + now eventually creating an AI native version of GitHub with Graphite, that's a serious business, with a much clearer picture to me how Cursor gets to serious profitability vs the AI labs.


  • New comment by laser9 in "Hacker News front page now, but the titles are honest"
  • Content:

    A good Friday morning laugh! I think the tiles are not just honest, they are brutally honest. Some of my fav ones:

    - Amazon finally adds a feature that has been standard since 2005

    - Texas accidentally does something good for privacy

    Would it possible to add a feature where hovering over a title displays the original title?


  • New comment by zeroonetwothree in "Graphite is joining Cursor"
  • Content:

    We’ve heard this many times before with other acquisitions so don’t be upset if people are a bit skeptical.


  • New comment by jvanderbot in "Hacker News front page now, but the titles are honest"
  • Content:

    OK, so the "Storing data in the network ... " title made me remember something.

    If you transmit a message to Mars, say a rover command sequence, and the outgoing buffer is deleted on the sending side (the original code is preserved, but the transmission-encoded sequence doesn't stick around), then that data, for 20-90 minutes, exists nowhere _except_ space. It's just random-looking electrical fluctuations that are propagating through whatever is out there until it hits a conducting piece of metal millions of miles away and energizes a cap bank enough to be measured by a digital circuit and reconstructed into data.

    So, if you calculate the data rate (9600 baud, even), and set up a loopback/echo transmitter on Mars, you could store ~4 MB "in space". If you're using lasers, it's >100x as much.


  • New comment by BeaverGoose in "Hacker News front page now, but the titles are honest"
  • Content:

    "Please star my repo so I can get a job" is brutal


  • New comment by egeozcan in "Amazon will allow ePub and PDF downloads for DRM-free eBooks"
  • Content:

    A friend of mine received a double shipment for a $300 order. Being honest, he contacted customer service to arrange a return. Everything seemed fine until a few days later when he noticed they had also refunded his original payment. He reached out again to let them know, and they said they’d just recharge his card. Apparently, that transaction failed (no clear reason why), and without any warning, they banned his account, wiping out his entire Kindle library in the process. Amazon works wonderfully right up until it fails spectacularly.


  • New comment by icqFDR in "Amazon will allow ePub and PDF downloads for DRM-free eBooks"
  • Content:

    I’d advise anyone buying e-books on Amazon to think it through carefully. My account was banned recently because, years ago, I ordered two paper books that Amazon said would be split into two shipments. Both books arrived without any issues, but later Amazon refunded me for one of them, claiming that one package never arrived. This happened 4–5 years ago.

    Apparently, during a recent review, they decided this counted as fraud and banned my account. As a result, I can no longer log in and lost access to all my Kindle e-books. They also remotely wiped my Kindle, so my entire library is gone. I appealed the decision, but I’ve been waiting for over six months with no resolution.


  • New comment by thomasahle in "Texas is suing all of the big TV makers for spying on what you watch"
  • Content:

    ACR — Automatic Content Recognition: tech in some smart TVs/apps that identifies what’s on-screen (often via audio/video “fingerprints”) and can report viewing data back to vendors/partners.

    VPPA — Video Privacy Protection Act: a U.S. law aimed at limiting disclosure of people’s video-viewing/rental history.

    HDCP — High-bandwidth Digital Content Protection: an anti-copy protocol used on HDMI/DisplayPort links to prevent interception/recording of protected video.

    DRM — Digital Rights Management: a broad term for technical restrictions controlling how digital media can be accessed, copied, or shared.

    MPAA — Motion Picture Association of America: the former name of the main U.S. film-industry trade group (now typically called the MPA, Motion Picture Association).

    TV / TVs — Television(s).


  • New comment by tliltocatl in "Firefox will have an option to disable all AI features"
  • Content:

    I think people screaming "but AI is the future" doesn't recognize what the problem is. The problem is not AI. The problem is that Mozilla keeps jumping on fads instead of focusing on their browser core. There are a tons of "we bundled all the latest crap" Chrome forks out there. Nobody needs more those. Stop pushing bells and whistles. Give us more extensibility instead. Keep supporting v2 manifest and add more. There were genuine technical reasons for why XUL and NPAPI had to die, but we need an equally powerful alternative.

    And yea, having a faint through about removing adblock support, yet alone speaking it aloud is a really bad sign for Mozilla's future.


  • New comment by bjackman in "Getting bitten by Intel's poor naming schemes"
  • Content:

    I work in CPU security and it's the same with microarchitecture. You wanna know if a machine is vulnerable to a certain issue?

    - The technical experts (including Intel engineers) will say something like "it affects Blizzard Creek and Windy Bluff models'

    - Intel's technical docs will say "if CPUID leaf 0x3aa asserts bit 63 then the CPU is affected". (There is no database for this you can only find it out by actually booting one up).

    - The spec sheet for the hardware calls it a "Xeon Osmiridium X36667-IA"

    Absolutely none of these forms of naming have any way to correlate between them. They also have different names for the same shit depending on whether it's a consumer or server chip.

    Meanwhile, AMD's part numbers contain a digit that increments with each year but is off-by-one with regard to the "Zen" brand version.

    Usually I just ask the LLM and accept that it's wrong 20% of the time.


  • New comment by hhoorzad in "2026 Apple introducing more ads to increase opportunity in search results"
  • Content:

    > I’d rather pay an extra $100 for the phone than have ads all over it.

    In all likelihood, we will pay an extra $100 AND have ads.


  • New comment by yanhangyhy in "How China built its ‘Manhattan Project’ to rival the West in AI chips"
  • Content:

    Domestically, we often put it this way: since it wasn’t made by God, we can definitely make it ourselves. It’s only a matter of time — if not this year, then next year; if we can’t do it next year, we’ll just keep going. This is how we approach everything.

    There is a small caveat, though. China was not actually that far behind in the semiconductor field in the past. The problem was that corruption and fraudulent projects were quite serious, which undermined the Chinese government’s confidence in these efforts. A few years ago, there was even a so-called “transparent computing” scam project that was awarded a national-level prize.

    Corruption and fraud can slow China’s progress, but they will not affect the final outcome. This is because it is not only a government policy, but also a Chinese way of thinking. Nothing can interrupt this process.

    In fact, aside from high-end chips, China already dominates the mid- and low-end chip segments.


  • New comment by al_borland in "2026 Apple introducing more ads to increase opportunity in search results"
  • Content:

    I’m really not a fan of this direction for Apple. One of the differentiators between iOS and Google was a lack of ads, which make the experience feel more premium. Increasing ads, or having them at all, really erodes the user experience.

    Apple managed to become the most valuable company in the world without ads. Adding them after hitting that milestone feels either greedy or desperate, maybe a little of both. I know the ads themselves aren’t new, but the steady increase is a worrying trend.

    I’d rather pay an extra $100 for the phone than have ads all over it.


  • New comment by seizethecheese in "History LLMs: Models trained exclusively on pre-1913 texts"
  • Content:

    > Imagine you could interview thousands of educated individuals from 1913—readers of newspapers, novels, and political treatises—about their views on peace, progress, gender roles, or empire. Not just survey them with preset questions, but engage in open-ended dialogue, probe their assumptions, and explore the boundaries of thought in that moment.

    Hell yeah, sold, let’s go…

    > We're developing a responsible access framework that makes models available to researchers for scholarly purposes while preventing misuse.

    Oh. By “imagine you could interview…” they didn’t mean me.


  • New comment by jimmy76615 in "History LLMs: trained exclusively on pre-1913 texts"
  • Content:

    > We're developing a responsible access framework that makes models available to researchers for scholarly purposes while preventing misuse.

    The idea of training such a model is really a great one, but not releasing it because someone might be offended by the output is just stupid beyond believe.


  • New comment by nneonneo in "Texas is suing all of the big TV makers for spying on what you watch"
  • Content:

    ACR needs to die. It’s an absurd abuse of the privileged position that a TV has - a gross violation of privacy just to make a few bucks. It should be absolutely nobody’s business to know what you watch except your own; the motivation behind the VPPA was to kill exactly this type of abuse.

    The greatest irony is that HDCP goes to great lengths to try and prevent people from screenshotting copyrighted content, and here we have the smart TVs at the end just scraping the content willy-nilly. If someone manages to figure out how to use ACR to break DRM, maybe the MPAA will be motivated to kill ACR :)


  • New comment by saaaaaam in "History LLMs: Models trained exclusively on pre-1913 texts"
  • Content:

    “Time-locked models don't roleplay; they embody their training data. Ranke-4B-1913 doesn't know about WWI because WWI hasn't happened in its textual universe. It can be surprised by your questions in ways modern LLMs cannot.”

    “Modern LLMs suffer from hindsight contamination. GPT-5 knows how the story ends—WWI, the League's failure, the Spanish flu.”

    This is really fascinating. As someone who reads a lot of history and historical fiction I think this is really intriguing. Imagine having a conversation with someone genuinely from the period, where they don’t know the “end of the story”.


  • New comment by superasn in "We pwned X, Vercel, Cursor, and Discord through a supply-chain attack"
  • Content:

    This is a pretty scary exploit, considering how easily it could be abused.

    Imagine just one link in a tweet, support ticket, or email: https://discord.com/_mintlify/static/evil/exploit.svg. If you click it, JavaScript runs on the discord.com origin.

    Here's what could happen:

    - Your Discord session cookies and token could be stolen, leading to a complete account takeover.

    - read/write your developer applications & webhooks, allowing them to add or modify bots, reset secrets, and push malicious updates to millions.

    - access any Discord API endpoint as you, meaning they could join or delete servers, DM friends, or even buy Nitro with your saved payment info.

    - maybe even harvest OAuth tokens from sites that use "Login with Disord."

    Given the potential damage, the $4,000 bounty feels like a slap in the face.

    edit: just noticed how HN just turned this into a clickable link - this makes it even scarier!


  • New comment by autoexec in "Texas is suing all of the big TV makers for spying on what you watch"
  • Content:

    I'm happy to see it. They should have included Roku in that too!

    > Roughly twice per second, a Roku TV captures video “snapshots” in 4K resolution. These snapshots are scanned through a database of content and ads, which allows the exposure to be matched to what is airing. For example, if a streamer is watching an NFL football game and sees an ad for a hard seltzer, Roku’s ACR will know that the ad has appeared on the TV being watched at that time. In this way, the content on screen is automatically recognized, as the technology’s name indicates. The data then is paired with user profile data to link the account watching with the content they’re watching.

    https://advertising.roku.com/learn/resources/acr-the-future-...

    I wouldn't be surprised if my PS5 was doing the same thing when I'm playing a game or watching a streaming service through it.


  • New comment by pton_xd in "Texas is suing all of the big TV makers for spying on what you watch"
  • Content:

    This is what seemingly every app does. They add 15 different categories for notifications / emails / whatever, and then make you turn off each one individually. Then they periodically remove / add new categories, enabled by default. Completely abusive behavior.


  • New comment by kstrauser in "Show HN: Stop AI scrapers from hammering your self-hosted blog (using porn)"
  • Content:

    I love the insanity of this idea. Not saying it's a good idea, but it's a very highly entertaining one, and I like that!

    I've also had enormous luck with Anubis. AI scrapers found my personal Forgejo server and were hitting it on the order of 600K requests per day. After setting up Anubis, that dropped to about 100. Yes, some people are going to see an anime catgirl from time to time. Bummer. Reducing my fake traffic by a factor of 6,000 is worth it.


  • New comment by spike021 in "Texas is suing all of the big TV makers for spying on what you watch"
  • Content:

    I've had the advertising settings disabled on my LG C2 for a while and yesterday I decided to browse the settings menu again and found that a couple new ones had been added and turned on by default.

    Good times.


  • New comment by vslira in "How China built its ‘Manhattan Project’ to rival the West in AI chips"
  • Content:

    It’s a good thing that Chinese companies have zero expertise in leveraging consumer demand for lower-end tech to develop know-how and catch up with the state of the art from Western-aligned companies and then economies of scale to surpass them in distribution.


  • New comment by llmslave2 in "We pwned X, Vercel, Cursor, and Discord through a supply-chain attack"
  • Content:

    This feels so emblematic of our current era. VC funded vibe coded AI documentation startup somehow gets big name customers who don't properly vet the security of the platform, ship a massive vulnerability that could pwn millions of users and the person who reports the vulnerability gets...$5k.

    If I recall last week Mintlify wrote a blog post showcasing their impressive(ly complicated) caching architecture. Pretending like they were doing real engineering, when it turns out nobody there seems to know what they're doing, but they've managed to convince some big names to use them.

    Man, it's like everything I hate about modern tech. Good job Eva for finding this one. Starting to think that every AI startup or company that is heavily using gen-ai for coding is probably extremely vulnerable to the simplest of attacks. Might be a way to make some extra spending money lol.


  • New comment by dllu in "We pwned X, Vercel, Cursor, and Discord through a supply-chain attack"
  • Content:

    The fact that SVG files can contain scripts was a bit of a mistake. On one hand, the animations and entire interactive demos and even games in a single SVG are cool. But on the other hand, it opens up a serious can of worms of security vulnerabilities. As a result, SVG files are often banned from various image upload tools, they do not unfurl previews, and so on. If you upload an SVG to discord, it just shows the raw code; and don't even think about sharing an SVG image via Facebook Messenger, Wechat, Google Hangouts, or whatever. In 2025, raster formats remain way more accessible and easily shared than SVGs.

    This is very sad because SVGs often have way smaller file size, and obviously look much better at various scales. If only there was a widely used vector format that does not have any script support and can be easily shared.


  • New comment by mccoyb in "GPT-5.2-Codex"
  • Content:

    If anyone from OpenAI is reading this -- a plea to not screw with the reasoning capabilities!

    Codex is so so good at finding bugs and little inconsistencies, it's astounding to me. Where Claude Code is good at "raw coding", Codex/GPT5.x are unbeatable in terms of careful, methodical finding of "problems" (be it in code, or in math).

    Yes, it takes longer (quality, not speed please!) -- but the things that it finds consistently astound me.


  • New comment by endorphine in "Your job is to deliver code you have proven to work"
  • Content:

    > there’s one depressing anecdote that I keep on seeing: the junior engineer, empowered by some class of LLM tool, who deposits giant, untested PRs on their coworkers—or open source maintainers—and expects the “code review” process to handle the rest.

    It's even worse than that: non-junior devs are doing it as well.


  • New comment by zipy124 in "Beginning January 2026, all ACM publications will be made open access"
  • Content:

    The main problem is the incentives are off. Publishers are now rewarded for publishing more papers, as opposed to having more readers. When it was more readers, you were rewarded for the quality of the publication thus more people wanted to read it. By switching the profit incentive to number of publications, we have chosen quantity over quality.

    Needless to say I prefer open access since those outside institutions can then read science, but the incentive model is heavily broken, and I'm not sure it's a good price to pay for the reward.


  • New comment by trainyperson in "Beginning January 2026, all ACM publications will be made open access"
  • Content:

    The financials of open access are interesting.

    Instead of journals getting revenue from subscribers, they charge authors an “Article Processing Charge” (APC) which for ACM is $1450 in 2026 and expected to go up. Authors from lower-middle income countries get a discount. [1]

    Authors are often associated with institutions (e.g. universities) who can cover the APC on behalf of the author through a deal with the journal. For the institution, now instead of paying the subscriber fee and publishing for free, they pay a publishing fee and everyone reads for free.

    1. https://authors.acm.org/open-access


  • New comment by recursivedoubts in "Please Just Try Htmx"
  • Content:

    Hey, I created htmx and while I appreciate the publicity, I’m not a huge fan of these types of hyperbolic articles. There are lots of different ways to build web apps with their own strengths and weaknesses. I try to assess htmx’s strengths and weaknesses here:

    https://htmx.org/essays/when-to-use-hypermedia/

    Also, please try unpoly:

    https://unpoly.com/

    It’s another excellent hypermedia oriented library

    Edit: the article is actually not nearly as unreasonable as I thought based on the just-f*king-use template. Still prefer a chill vibe for htmx though.


  • New comment by oidar in "Are Apple gift cards safe to redeem?"
  • Content:

    I'm glad that got resolved for Paris, but what the hell is a normal person supposed to do. Not every one has that kind of public reach to get a satisfactory resolution. First he had understand what happened technically, then he needed a public platform to tell people about it, then that writing needed to get reposted by others, than PR needed to get involved. Not something that's going to happen for a normal user.

    Apple, Google, and the big players are not a trustworthy place to entrust precious data. Increasingly, Apple and Google aren't very much different as they are both in the advertisement business: the great misaligner of incentives.


  • New comment by Geonode in "Classical statues were not painted horribly"
  • Content:

    I will die on this hill, because I'm right. Painters put on the first layer in saturated colors like this, then add detail, highlight and shadow. The base layer stuck to the statues, and the rest was washed away.

    This whole thing just won't go away because many people are operating outside their area of expertise on this subject.

    Painters layer paint, starting with a saturated base color. These archaeologists are simply looking at the paint that was left in the crevices.


  • New comment by flowerthoughts in "Creating apps like Signal could be 'hostile activity' claims UK watchdog"
  • Content:

    > He warns that developers of apps like Signal and WhatsApp could technically fall within the legal definition of "hostile activity" simply because their technology "make[s] it more difficult for UK security and intelligence agencies to monitor communications.

    Sounds like Let's Encrypt would also fall under that.

    This has got to stop. If you want to stop criminals, then focus on their illegal activites, not the streets they walk on. I walk on them too. And don't use CP as a catch-all argument to insert backdoors.

    Their big problem here is that previously, it was hard to find people with the same opinion as you. If you couldn't find someone in the same village who wanted to start a rebellion, it probably wouldn't happen. Today, someone can post a Telegram group message and make thousands of people rally to a town square. I see the dangers, and I see why governments think they are doing this to protect the people. No one wants civil war. That is still not a strong enough reason to call road construction a hostile activity.

    I'm back in Sweden after 12 years abroad. Time to read up on which parties are sane and which aren't when it comes to technical infrastructure.


  • New comment by skwee357 in "Ask HN: Those making $500/month on side projects in 2025 – Show and tell"
  • Content:

    I run a dead-simple, one-time, online fax service called JustFax Online[0]. While I don't have a recurring revenue as I operate one one-time payment, for the past months I have been consistently grossing over €500/mo.

    This also brings tears to my eyes, as I remember[1] browsing these threads and being amazed (still am) by all the people who make side projects and make money from them, and at the same time thinking that I will never reach this milestone, and yet, here I am.

    [0]: https://justfaxonline.com [1]: https://news.ycombinator.com/item?id=39110194#39141819


  • New comment by MathiasPius in "Ask HN: Does anyone understand how Hacker News works?"
  • Content:

    It sometimes blows my mind how questions which essentially boil down to "How do I best manipulate you for personal gain?" can be asked in such an unabashed fashion.


  • New comment by jacquesm in "Ask HN: Does anyone understand how Hacker News works?"
  • Content:

    HN is hard to game on purpose. So stop looking for the levers and participate, that's all there is to it. I've made friends here, have been helped by people on projects that I was busy with, did the reverse, found friends and business partners and spend way too much time. HN is a very interesting slice of the online world, a place that is unlike the rest, sometimes a bit dry but always interesting and extremely useful. If you're looking at it to try to understand it then you might as well try to understand a rat or a mouse. You won't understand it because it isn't there to be understood, it just is, like any other organism.

    The root of HN is a thing called 'startup news', that was changed very quickly and since then HN has been a focal point for techies of all sorts but also lots of other people from all walks of life and from a large variety of countries. It isn't 'one thing' to everybody that participates, just like a hammer is a different thing for a carpenter than it is for a masoner or a farmer.

    The fact that after being a member for a couple of years you have this question indicates a lack of participation, not a lack of understanding.


  • New comment by dang in "Ask HN: Does anyone understand how Hacker News works?"
  • Content:

    (I'm a mod here)

    It's true that this place can be cryptic, and that has downsides—specifically, it can be confusing to newcomers, even to some newcomers who would make ideal HN users. That sucks.

    But there's a key that unlocks most of the puzzles. That is to understand that we're optimizing for exactly one thing: curiosity. (Specifically, intellectual curiosity, since there are other kinds of curiosity too.) Here are links to past explanations about that: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...

    We try to elevate things that gratify curiosity: creative work, surprising discoveries, deep dives, technical achievements, unusual personal experience, whimsical unpredictability, good conversation, etc. And we try to demote things that run against curiosity, especially repetition, indignation, sensationalism, and promotion.

    It gets complicated because you'll also see plenty of repetition, indignation, sensationalism, and promotion on HN—alas! This is the internet after all. But the site survives because the balance of these things stays within tolerable ranges, thanks to two factors: an active community which cares greatly about preserving this place for intended purpose (https://news.ycombinator.com/newsguidelines.html); and an owner (Y Combinator) which pays us to work on the site full time and mainly just wants us to keep it good, to the extent possible.

    If you really want to figure this place out, the way to do it is as a reader. Hang out on the site, look at the mix of articles that make the frontpage, spend time in the discussion threads (hopefully the interesting sectors and not the flamey ones!), and over time your eyes will adjust.

    What doesn't work—and this is good because we want it not to work—is approaching HN as a platform for promoting content. If you (<-- I don't mean you personally, but anyone) mainly care about "how can I use this thing to get attention for my startup/blog/project/newsletter", then you're operating in 'push' mode rather than 'pull' mode (or, even better, 'idle' mode). In that case you won't be curious because you're too focused on what you're wanting for extraneous reasons—and if you aren't in a state of curiosity, this place won't make sense. At least we hope it won't!


  • New comment by 3np in "I got hacked: My Hetzner server started mining Monero"
  • Content:

    > I also enabled UFW (which I should have done ages ago)

    I disrecommend UFW.

    firewalld is a much better pick in current year and will not grow unmaintainable the way UFW rules can.

        firewall-cmd --persistent --set-default-zone=block
        firewall-cmd --persistent --zone=block --add-service=ssh
        firewall-cmd --persistent --zone=block --add-service=https
        firewall-cmd --persistent --zone=block --add-port=80/tcp
        firewall-cmd --reload
    
    Configuration is backed by xml files in /etc/firewalld and /usr/lib/firewalld instead of the brittle pile of sticks that is the ufw rules files. Use the nftables backend unless you have your own reasons for needing legacy iptables.

    Specifically for docker it is a very common gotcha that the container runtime can and will bypass firewall rules and open ports anyway. Depending on your configuration, those firewall rules in OP may not actually do anything to prevent docker from opening incoming ports.

    Newer versions of firewalld gives an easy way to configure this via StrictForwardPorts=yes in /etc/firewalld/firewalld.conf.