HN comments - Digest ⚙️ Edit Settings

Period: 2025-11-14 18:08 - 2025-11-21 13:22 📚 All Digests

Details

bestcomments

  • New comment by maccard in "Over-regulation is doubling the cost"
  • Content:

    It’s not over regulation, it’s bad regulation.

    Not all regulation is bad, and some of it is wildly effective at not just achieving the letter of the law but actually solving the problem it was defined for. Good regulation IMO looks bad because you never hear of anyone being punished for breaking it because it is complied with.

    The EU banned roaming charges in 2017. Most networks by then had already abolished them, but only because this change was coming. The UK then decided it was going to leave the EU, and pretty much overnight the major mobile providers reintroduced the roaming charges.

    EU flight compensation rules are another great example - they don’t pay out often because what’s happened is the airlines don’t get delayed to that point as often as they used to.

    Scotland has a “right to roam”, which can be summarised as “don’t be a dick and you can go anywhere you want outdoors”. So you can walk, camp etc pretty much anywhere (it’s a bit more complex). In theory this means I can just open a gate to a farm, and walk across their fields. In practice, this means that most popular walking paths have access routes maintained by landowners that people use.

    On the flip side, the cookie banners are a perfect example of bad regulation. They’re super easy to (allegedly) comply with and the result is just an annoyance for some 300 million people and absolutely no change to company behaviour whatsoever.


  • New comment by jakelazaroff in "CBP is monitoring US drivers and detaining those with suspicious travel patterns"
  • Content:

    > Taking a photograph of a car with its license plate is legal. As is selling a photo you've taken, whether it has a license plate or not.

    > Therefore taking millions of photos in public of cars, and turning their license plate numbers into a database is legal, as is selling that information. It's all data gained in public.

    One absolutely does not follow the other; there are all sorts of things that are legal only if done for certain purposes, only below a certain scale, etc. The idea that we must permit both or neither is a false dichotomy.


  • New comment by brandon272 in "Nano Banana Pro"
  • Content:

    Just a note that your HN bio says "Developer Relations @OpenAI"


  • New comment by logankilpatrick in "Nano Banana Pro"
  • Content:

    First off, apologies for the bad first impression, the team is pushing super hard to make sure it is easy to access these models.

    - On permission issue, not sure I follow the flow that got you there, pls email me more details if you are able too and happy to debug: [email protected]

    - On overall friction for billing: we are working on a new billing experience built right into AI Studio that will make it super easy to add a CC and go build. This will also come along with things like hard billing caps and such. The expected ETA for global rollout is January!


  • New comment by JohnTHaller in "CBP is monitoring US drivers and detaining those with suspicious travel patterns"
  • Content:

    It's the same as the Republican slogans of being the party of "fiscal responsibility" despite under-performing the Democratic party in nearly all financial metrics and constantly blowing up the deficit or being the party of "family values" while having leaders and 'respected' voices who are the complete opposite.


  • New comment by simonw in "CBP is monitoring US drivers and detaining those with suspicious travel patterns"
  • Content:

    License plate scanners are one of the most under-appreciated violations of personal privacy that exist today.

    It's not just government use either. There are private companies that scan vast numbers of license plates (sometimes by driving around parking lots with a camera), build a database of what plate was seen where at what time, then sell access to both law enforcement and I believe private investigators.

    Want to know if your spouse is having an affair? Those databases may well have the answer.

    Here is a Wired story from 2014 about Vigilant Solutions, founded in 2009: https://www.wired.com/2014/05/license-plate-tracking/

    I believe Vigilant only provide access to law enforcement, but Digital Recognition Network sell access to others as well: https://drndata.com/about/

    Good Vice story about that: https://www.vice.com/en/article/i-tracked-someone-with-licen...


  • New comment by hypeatei in "CBP is monitoring US drivers and detaining those with suspicious travel patterns"
  • Content:

    It's been fascinating watching the party of "small government" turn into one that supports ever expanding powers of a three letter agency whose job is supposed to be patrolling the border. It's like a new 9/11 Patriot act moment, except it's only one side supporting it this time.


  • New comment by vunderba in "Nano Banana Pro"
  • Content:

    Alright results are in! I've re-run all my editing based adherence related prompts through Nano Banana Pro. NB Pro managed to successfully pass SHRDLU, the M&M Van Halen test (as verified independently by Simon), and the Scorpio street test - all of which the original NB failed.

      Model results
      1. Nano Banana Pro: 10 / 12
      2. Seedream4: 9 / 12
      3. Nano Banana: 7 / 12
      4. Qwen Image Edit: 6 / 12
    
    
    https://genai-showdown.specr.net/image-editing

    If you just want to see how NB and NB Pro compare against each other:

    https://genai-showdown.specr.net/image-editing?models=nb,nbp


  • New comment by layer8 in "Android and iPhone users can now share files, starting with the Pixel 10"
  • Content:

    This is based on Wi-Fi Aware: https://en.wikipedia.org/wiki/Wi-Fi_Alliance#Wi-Fi_Aware

    Some background: https://www.ditto.com/blog/cross-platform-p2p-wi-fi-how-the-...

    On the Apple side, this was prompted by the EU Digital Markets Act: https://digital-markets-act.ec.europa.eu/questions-and-answe...


  • New comment by ceroxylon in "Nano Banana Pro"
  • Content:

    Google has been stomping around like Godzilla this week, and this is the first time I decided to link my card to their AI studio.

    I had seen people saying that they gave up and went to another platform because it was "impossible to pay". I thought this was strange, but after trying to get a working API key for the past half hour, I see what they mean.

    Everything is set up, I see a message that says "You're using Paid API key [NanoBanano] as part of [NanoBanano]. All requests sent in this session will be charged." Go to prompt, and I get a "permission denied" error.

    There is no point in having impressive models if you make it a chore for me to -give you my money-


  • New comment by 24t in "Android/Linux Dual Boot"
  • Content:

    > sideloading

    It's called installing. Language matters and I see no reason to concede this point in Google's favour.


  • New comment by unbolted3032 in "Verifying your Matrix devices is becoming mandatory"
  • Content:

    I decommissioned my server 3 months ago and migrated my community back to IRC. I still had the IRC Podman containers kicking around, so that was easy.

    I dealt with ~monthly issues around my devices not being correctly verified, messages not correctly decrypting, and various other rough UX edges. There seemed to be a lot of velocity in the beginning but the last couple of years have addressed approximately nothing in terms of the UX and it's a crying shame as Matrix/Element (I no longer fully understand the difference/relationship between these entities) had a lot of potential.


  • New comment by vinkelhake in "Gaming on Linux has never been more approachable"
  • Content:

    I recently had my Framework Desktop delivered. I didn't plan on using it for gaming, but I figured I should at least try. My experience thus far:

        * I installed Fedora 43 and it (totally unsurprisingly) worked great.
        * I installed Steam from Fedora's software app, and that worked great as well.
        * I installed Cyberpunk 2077 from Steam, and it just... worked.
    
    Big thanks to Valve for making this as smooth as it was. I was able to go from no operating system to Cyberpunk running with zero terminals open or configs tweaked.

    I later got a hankering to play Deus Ex: Mankind Divided. This time, the game would not work and Steam wasn't really forthcoming with showing logs. I figured out how to see the logs, and then did what you do these days - I showed the logs to an AI. The problem, slightly ironically, with MD is that it has a Linux build and Steam was trying to run that thing by default. The Linux build (totally unsurprisingly) had all kinds of version issues with libraries. The resolution there was just to tell Steam to run the Windows build instead and that worked great.


  • New comment by ronsor in "Gaming on Linux has never been more approachable"
  • Content:

    Community forums/support from big companies like Microsoft and Adobe tend to be completely useless. In most cases, all threads follow the same flow:

    * Question with reasonable amount of detail.

    * A reply from some "Community Helper" (Rank: Gold): "did you try reading the help files?"

    * Another person with a "Staff" badge: "this isn't our department"

    [Thread closed.]


  • New comment by crote in "Loose wire leads to blackout, contact with Francis Scott Key bridge"
  • Content:

    I strongly recommend watching/reading the entire report, or the summary by Sal Mercogliano of What's Going On In Shipping [0].

    Yes, the loose wire was the immediate cause, but there was far more going wrong here. For example:

    - The transformer switchover was set to manual rather than automatic, so it didn't automatically fail over to the backup transformer.

    - The crew did not routinely train transformer switchover procedures.

    - The two generators were both using a single non-redundant fuel pump (which was never intended to supply fuel to the generators!), which did not automatically restart after power was restored.

    - The main engine automatically shut down when the primary coolant pump lost power, rather than using an emergency water supply or letting it overheat.

    - The backup generator did not come online in time.

    It's a classic Swiss Cheese model. A lot of things had to go wrong for this accident to happen. Focusing on that one wire isn't going to solve all the other issues. Wires, just like all other parts, will occasionally fail. One wire failure should never have caused an incident of this magnitude. Sure, there should probably be slightly better procedures for checking the wiring, but next time it'll be a failed sensor, actuator, or controller board.

    If we don't focus on providing and ensuring a defense-in-depth, we will sooner or later see another incident like this.

    [0]: https://www.youtube.com/watch?v=znWl_TuUPp0


  • New comment by ckozlowski in "Microsoft AI CEO pushes back against critics after recent Windows AI backlash"
  • Content:

    This Microsoft response reminds me of the 2018 Blizzcon event, where the Diablo Immortal developer challenged the audience with "Do you guys not have phones?" when the audience asked if the game was coming to PC.

    Then - like now - it seemed that they couldn't understand that what they made was not what their customers wanted.


  • New comment by anon7000 in "Microsoft AI CEO pushes back against critics after recent Windows AI backlash"
  • Content:

    It’s partly that, but it’s also partly that the quality SUCKS. I’m frustrated with AI blogspam because it doesn’t in any way help me figure out whatever I’m researching. It’s such low quality. What I want and need is higher quality primary sources — in depth research, investigation, presented in an engaging way. Or with movies and shows, I want something genuine. With a genuine story that feels real, characters that feel real and motivated.

    AI is fake, it feels fake, and it’s obvious. It’s mind blowing to me that executives think people want fake crap. Sure, people are susceptible to it, and get engaged by it, but it’s not exactly what people want or aspire to.

    I want something real, something that makes me feel. AI generated content is by definition fake and not genuine. A human is by definition not putting as much thought and effort into their work when they use AI.

    Now someone could put a lot of thought and effort into a project and also use gen AI, but that’s not what’s getting spammed across the internet. AI is low-effort, so of course the pure volume of low effort garbage is going to surpass the volume of high effort quality content.

    So it’s basically not possible to like what AI is putting out, generally speaking.

    As a productivity enhancer in a small role, sure it’s useful, but that’s not what we’re complaining about.


  • New comment by hifix in "Microsoft AI CEO pushes back against critics after recent Windows AI backlash"
  • Content:

    > The fact that people are unimpressed that we can have a fluent conversation with a super smart AI that can generate any image/video is mindblowing to me.

    It's not that people are unimpressed with AI - they're just tired of constantly being bombarded with it, and it sneaking its way into where it's not wanted. "Generate any image you want!" "Analyse this thing with AI!" gets pretty tiring.

    If I want AI I'll actively seek it out and use it - otherwise, jog on.


  • New comment by nverba in "Cognitive and mental health correlates of short-form video use"
  • Content:

    As someone who pays for YouTube, I don't understand why I can't disable shorts fully. They already have my money. What more do they want?


  • New comment by energy123 in "Europe is scaling back GDPR and relaxing AI laws"
  • Content:

    I've stopped thinking of regulations as a single dial, where more regulations is bad or less regulations is bad. It entirely depends on what is being regulated and how. Some areas need more regulations, some areas need less. Some areas need altered regulation. Some areas have just the right regulations. Most regulations can be improved, some more than others.


  • New comment by ahepp in "The Death of Arduino?"
  • Content:

    > users are now explicitly forbidden from reverse-engineering or even attempting to understand how the platform works unless Arduino gives permission.

    I briefly looked at their IDE and CLI repos and GitHub claims they're AGPL and GPL 3 respectively. I didn't see a CLA when I looked at their contribution guide.

    Am I missing something here? What basis do they have to restrict users' rights to reverse engineer the software?


  • New comment by rckt in "Europe is scaling back GDPR and relaxing AI laws"
  • Content:

    I get that too many regulations is a bad thing. But when we talk privacy and personal data there should be no gray zone. It has to be black and white. When I see a stupid cookie banner I search for "Reject all". There's no some data that companies can collect and process without my consent, they just shouldn't be able to collect anything without me actively opting in. Business never respects anything, but profits. Seeing news about relaxing these laws with the "AI" going after this leaves a bitter taste. And with them also trying to push the Chat Control thing, it gets even worse.


  • New comment by nico in "Building more with GPT-5.1-Codex-Max"
  • Content:

    > Claude basically disregards your instructions (CLAUDE.md) entirely

    A friend of mine tells Claude to always address him as “Mr Tinkleberry”, he says he can tell when Claude is not paying attention to the instructions on CLAUDE.md when Claude stops calling him “Mr Tinkleberry” consistently


  • New comment by johnfn in "Building more with GPT-5.1-Codex-Max"
  • Content:

    I've been using a lot of Claude and Codex recently.

    One huge difference I notice between Codex and Claude code is that, while Claude basically disregards your instructions (CLAUDE.md) entirely, Codex is extremely, painfully, doggedly persistent in following every last character of them - to the point that i've seen it work for 30 minutes to convolute some solution that was only convoluted because of some sentence I threw in the instructions I had completely forgotten about.

    I imagine Codex as the "literal genie" - it'll give you exactly what you asked for. EXACTLY. If you ask Claude to fix a test that accidentally says assert(1 + 1 === 3), it'll say "this is clearly a typo" and just rewrite the test. Codex will rewrite the entire V8 engine to break arithmetic.

    Both these tools have their uses, and I don't think one approach is universally better. Because Claude just hacks its way to a solution, it is really fast, so I like using it for iterate web work, where I need to tweak some styles and I need a fast iterative loop. Codex is much worse at that because it takes like 5 minutes to validate everything is correct. Codex is much better for longer, harder tasks that have to be correct -- I can just write some script to verify that what it did work, and let it spin for 30-40 minutes.


  • New comment by danishSuri1994 in "Europe is scaling back GDPR and relaxing AI laws"
  • Content:

    I sympathize with the startup argument: heavy compliance costs can stifle early innovation. But the solution shouldn’t be “weaker rules.” It should be smarter rules, clearer safe harbors for small actors, browser-level consent primitives for users, and stronger enforcement against dark-pattern CMPs. That keeps privacy meaningful without killing small businesses.


  • New comment by amluto in "Building more with GPT-5.1-Codex-Max"
  • Content:

    I would love to see all the big players put 1% of the effort they put into model training into making the basic process of paying and signing in suck less.

    Claude: they barely have a signin system at all. Multiple account support doesn’t exist. The minimum seat count for business is nonsense. The data retention policies are weak.

    OpenAI: Make ZDR a thing you can use or buy without talking to sales, already. And for those using containers or a remote system or really anything other than local development with the codex CLI, you really really need to fix this bug. I bet Codex could do at least the client part for you!

    https://github.com/openai/codex/issues/2798

    (Hint: Claude Code gets this right by default, despite the fact that everything else about Claude sign-in is a joke.)

    Google: get all your B2B AI product managers in one room and tell them that they need to make one single product menu on one single webpage with all the pricing on that page and that the Google Cloud people are not permitted to make anything that isn’t actually logically Google Cloud depend on Google Cloud Billing. Your product cannot compete with OpenAI or Anthropic if people need to ask an LLM to figure out what your product is and if your own fancy LLMs can’t give a straight answer. My company pays for a non-Google product primarily because it’s too complicated to pay for the Google product! Right now, trying to use Google’s AI is like trying to ride Bay Area public transit before the Clipper Card.


  • New comment by orev in "What Killed Perl?"
  • Content:

    The backwards incompatibility of Perl 6 absolutely killed Perl.

    There are many languages still in use today that have all kinds of warts and ugliness, but they remain in use because they still have momentum and lots of legacy things built in them. So being ugly or old isn’t enough of a factor for people to abandon something in droves.

    Once you need to rewrite everything, there’s no reason to stay with something you know since you need to fully retool anyway.

    As a Perl programmer since v5 was released, the confusion around 6 completely destroyed almost everyone’s enthusiasm, and immediately caused all new projects to avoid Perl. It seemed like 5 had reached the end of the line, and 6 was nowhere to be found. Nobody wants to gamble so many hours of their lives, and the future of their business, on such an uncertain environment.

    If Perl 6 had any visible movement within the first few years, it might have survived, but it was a good decade before they even admitted Perl 6 might take longer than expected, and then more time after that before they admitted it should have been a new language. 6 was interesting for language geeks, and they probably did some cool things, but you can’t run a large popular project like it’s a small research project. That completely destroyed all momentum in the community. Perl 5 development only resumed far too late, after the writing was already on the wall.

    Both Bill Gates and Linus understand backwards compatibility as a sacrosanct principle. Python only just barely survived the jump from 2 to 3. JavaScript can only survive this because there’s no other option in a browser.


  • New comment by bnchrch in "Thunderbird adds native Microsoft Exchange email support"
  • Content:

    While its been a long time since Ive used Thunderbird, I just wanted to take the time to publicly say thank you.

    Many HNers probably wont (or cant) remember the world of desktop mail clients but basically during the height of MSFT dominance there was only one real mail client: Outlook. Which Microsoft was starting to monetize heavily, ignore UX, and keep it windows only (cant blame them for that).

    Then Thunderbird arrived on the scene, an OSS mail client that beat the pants off of Outlook in features, spam detection, IMAP support and a bunch of other things.

    And it was free.

    And you could use it on any machine.

    This was a huge moment for OSS.

    We owe a lot of credit to Mozilla and Thunderbird for rescuing us from a closed source world.


  • New comment by radicalbyte in "Europe is scaling back GDPR and relaxing AI laws"
  • Content:

    There has been a change in the community here over the last decade, we've lost a lot of the hacker spirit and have a larger proportion of "chancers", people who are only in tech to "get rich quick". The legacy of ZIRP combined with The Social Network marketing.


  • New comment by autarch in "What Killed Perl?"
  • Content:

    As a very long-time Perl developer and FOSS contributor, I think this blog post is incorrect about whether Perl 6/Raku was a factor in Perl's decline. I think Perl 6/Raku did a few things that hurt Perl 5:

    1. It pulled away folks who would otherwise have spent time improving Perl 5 (either the core or via modules).

    2. It discouraged significant changes to the Perl 5 language, since many people figured that it wasn't worth it with Perl 6 just around the corner.

    3. It confused CTO/VP Eng types, some of whom thought that they shouldn't invest in Perl 5, since Perl 6 was coming soon. I've heard multiple people in the Perl community discuss hearing this directly from execs.

    Of course, hindsight is 20/20 and all that.

    Also, even if Perl 6 had never happened the way it did and instead we'd just had smaller evolutions of the language in major versions, I think usage would still have shrunk over time.

    A lot of people just dislike Perl's weird syntax and behavior. Many of those people were in a position to teach undergrads, and they chose to use Python and Java.

    And other languages have improved a lot or been created in the past 20+ years. Java has gotten way better, as has Python. JavaScript went from "terribly browser-only language" to "much less terrible run anywhere language" with a huge ecosystem. And Go came along and provided an aggressively mediocre but very usable strongly typed language with super-fast builds and easy deploys.

    Edit: Also PHP was a huge factor in displacing Perl for the quick and dirty web app on hosted services. It was super easy to deploy and ran way faster than Perl without mod_perl. Using mod_perl generally wasn't possible on shared hosting, which was very common back in the days before everyone got their own VM.

    All of those things would still have eaten some of Perl's lunch.


  • New comment by purple_turtle in "The peaceful transfer of power in open source projects"
  • Content:

    > I'm begging project leaders everywhere - please read up on the social contract and the consent of the governed.

    I do not need consent as I am not governing anyone like king or president governs.

    If someone is using my project they are also not really entitled to anything, beyond what stated in license and similar documents if any.

    If they dislike it, they can fork my project and go away.

    If someone wants to be entitled to anything, they are free to make a contract and pay for service they desire. But while many are happy to demand nearly noone is willing to help. Or even fork project. Instead they make entitled demand and treat open source developers as servants or slaves or their pets.

    No, you are not entitled to your preferred governance model to be used in my software project.


  • New comment by Havoc in "A $1k AWS mistake"
  • Content:

    These sort of things show up about once a day between the three big cloud subreddit. Often with larger amounts

    And it’s always the same - clouds refuse to provide anything more than alerts (that are delayed) and your only option is prayer and begging for mercy.

    Followed by people claiming with absolute certainty that it’s literally technically impossible to provide hard capped accounts to tinkerers despite there being accounts like that in existence already (some azure accounts are hardcapped by amount but ofc that’s not loudly advertised).


  • New comment by Groxx in "I just want working RCS messaging"
  • Content:

    Yeah... I just started getting back into building sms/mms/rcs apps on Android and oh boy. It's much more of a mess than I expected, and much more "oh so it's basically just Google now, and they seem to be trying to lock it down further" than I expected (or hoped).

    And you can't even implement it yourself because it requires special permissions on Android, which you can only get if you're a carrier/oem-blessed app. And the early "you'll be able to build other apps, there will be an API like this: https://github.com/android-rcs/rcsjta" promises (which would put it on par with sms/mms) never materialized, despite a reference implementation that did exactly that over a decade ago.

    At this point I'm just totally against RCS and I'm intentionally turning it off. Why hand all of your messaging communications over to Google, when they've got such a consistent history of being hostile? We're much better off going back to telling people not to use sms (or mms or rcs) at all because it's insecure.


  • New comment by spyridonas in "Show HN: I made a down detector for down detector"
  • Content:

    As a European solo developer, I’ve switched entirely to European alternatives for all my infrastructure since the beginning of the year.

    Cloudflare > Bunny.net

    AWS > Hetzner

    Business email > Infomaniak

    Not a single client site has experienced downtime, and it feels great to finally decouple from U.S. services.


  • New comment by abalone in "Cloudflare outage on November 18, 2025 post mortem"
  • Content:

    I’ve led multiple incident responses at a FAANG, here’s my take. The fundamental problem here is not Rust or the coding error. The problem is:

    1. Their bot management system is designed to push a configuration out to their entire network rapidly. This is necessary so they can rapidly respond to attacks, but it creates risk as compared to systems that roll out changes gradually.

    2. Despite the elevated risk of system wide rapid config propagation, it took them 2 hours to identify the config as the proximate cause, and another hour to roll it back.

    SOP for stuff breaking is you roll back to a known good state. If you roll out gradually and your canaries break, you have a clear signal to roll back. Here was a special case where they needed their system to rapidly propagate changes everywhere, which is a huge risk, but didn’t quite have the visibility and rapid rollback capability in place to match that risk.

    While it’s certainly useful to examine the root cause in the code, you’re never going to have defect free code. Reliability isn’t just about avoiding bugs. It’s about understanding how to give yourself clear visibility into the relationship between changes and behavior and the rollback capability to quickly revert to a known good state.

    Cloudflare has done an amazing job with availability for many years and their Rust code now powers 20% of internet traffic. Truly a great team.


  • New comment by eastdakota in "Cloudflare outage on November 18, 2025 post mortem"
  • Content:

    Well… we have a culture of transparency we take seriously. I spent 3 years in law school that many times over my career have seemed like wastes but days like today prove useful. I was in the triage video bridge call nearly the whole time. Spent some time after we got things under control talking to customers. Then went home. I’m currently in Lisbon at our EUHQ. I texted John Graham-Cumming, our former CTO and current Board member whose clarity of writing I’ve always admired. He came over. Brought his son (“to show that work isn’t always fun”). Our Chief Legal Officer (Doug) happened to be in town. He came over too. The team had put together a technical doc with all the details. A tick-tock of what had happened and when. I locked myself on a balcony and started writing the intro and conclusion in my trusty BBEdit text editor. John started working on the technical middle. Doug provided edits here and there on places we weren’t clear. At some point John ordered sushi but from a place with limited delivery selection options, and I’m allergic to shellfish, so I ordered a burrito. The team continued to flesh out what happened. As we’d write we’d discover questions: how could a database permission change impact query results? Why were we making a permission change in the first place? We asked in the Google Doc. Answers came back. A few hours ago we declared it done. I read it top-to-bottom out loud for Doug, John, and John’s son. None of us were happy — we were embarrassed by what had happened — but we declared it true and accurate. I sent a draft to Michelle, who’s in SF. The technical teams gave it a once over. Our social media team staged it to our blog. I texted John to see if he wanted to post it to HN. He didn’t reply after a few minutes so I did. That was the process.


  • New comment by porphyra in "Blender 5.0"
  • Content:

    Blender is really an amazing case study of open source software. Apart from the Linux kernel and web browsers/tools, it is perhaps the only open source software that managed to beat all the commercial software in its niche. It has rendered Maya nearly obsolete.

    Meanwhile, in other niches, Microsoft Office still beats open source office suites like LibreOffice; Photoshop isn't about to give up its crown to GIMP; Lightroom isn't losing to Darktable; and FreeCAD isn't even in the rear view mirror of Solidworks.

    I wonder what will be the next category of open source to pull ahead? Godot is rapidly gaining users/mindshare while Unity seems to be collapsing, but Unreal is still the king of game engines for now. Krita is a viable alternative for digital painting.


  • New comment by ojosilva in "Cloudflare outage on November 18, 2025 post mortem"
  • Content:

    This is the multi-million dollar .unwrap() story. In a critical path of infrastructure serving a significant chunk of the internet, calling .unwrap() on a Result means you're saying "this can never fail, and if it does, crash the thread immediately."The Rust compiler forced them to acknowledge this could fail (that's what Result is for), but they explicitly chose to panic instead of handle it gracefully. This is textbook "parse, don't validate" anti-pattern.

    I know, this is "Monday morning quarterbacking", but that's what you get for an outage this big that had me tied up for half a day.


  • New comment by eastdakota in "Cloudflare outage on November 18, 2025 post mortem"
  • Content:

    Because we initially thought it was an attack. And then when we figured it out we didn’t have a way to insert a good file into the queue. And then we needed to reboot processes on (a lot) of machines worldwide to get them to flush their bad files.


  • New comment by gucci-on-fleek in "Cloudflare outage on November 18, 2025 post mortem"
  • Content:

    > This showed up to Internet users trying to access our customers' sites as an error page indicating a failure within Cloudflare's network.

    As a visitor to random web pages, I definitely appreciated this—much better than their completely false “checking the security of your connection” message.

    > The issue was not caused, directly or indirectly, by a cyber attack or malicious activity of any kind. Instead, it was triggered by a change to one of our database systems' permissions

    Also appreciate the honesty here.

    > On 18 November 2025 at 11:20 UTC (all times in this blog are UTC), Cloudflare's network began experiencing significant failures to deliver core network traffic. […]

    > Core traffic was largely flowing as normal by 14:30. We worked over the next few hours to mitigate increased load on various parts of our network as traffic rushed back online. As of 17:06 all systems at Cloudflare were functioning as normal.

    Why did this take so long to resolve? I read through the entire article, and I understand why the outage happened, but when most of the network goes down, why wasn't the first step to revert any recent configuration changes, even ones that seem unrelated to the outage? (Or did I just misread something and this was explained somewhere?)

    Of course, the correct solution is always obvious in retrospect, and it's impressive that it only took 7 minutes between the start of the outage and the incident being investigated, but it taking a further 4 hours to resolve the problem and 8 hours total for everything to be back to normal isn't great.


  • New comment by SerCe in "Cloudflare outage on November 18, 2025 post mortem"
  • Content:

    As always, kudos for releasing a post mortem in less than 24 hours after the outage, very few tech organisations are capable of doing this.


  • New comment by falcor84 in "Gemini 3"
  • Content:

    I love it that there's a "Read AI-generated summary" button on their post about their new AI.

    I can only expect that the next step is something like "Have your AI read our AI's auto-generated summary", and so forth until we are all the way at Douglas Adams's Electric Monk:

    > The Electric Monk was a labour-saving device, like a dishwasher or a video recorder. Dishwashers washed tedious dishes for you, thus saving you the bother of washing them yourself; video recorders watched tedious television for you, thus saving you the bother of looking at it yourself. Electric Monks believed things for you, thus saving you what was becoming an increasingly onerous task, that of believing all the things the world expected you to believe.

    - from "Dirk Gently's Holistic Detective Agency"


  • New comment by cedws in "Google boss says AI investment boom has 'elements of irrationality'"
  • Content:

    I don't even know what the selling point of AI is for regular people. In the 60s it was possible for a man to work an ordinary job, buy a house, settle down with a wife and support two or three children. That's completely out of the realm of reality for many young people now and the plummeting birth rates show it.

    The middle class have financially benefited very little from the past 20+ years of productivity gains.

    Social media is driving society apart, making people selfish, jealous, and angry.

    Do people really think more technology is going to be the path to a better society? Because to me it looks like the opposite. It will just be used to stomp on ordinary people and create even more inequality.


  • New comment by throwaway13337 in "Google Antigravity"
  • Content:

    I gave it a fair shot.

    It is a vs code fork. There were some UI glitches. Some usability was better. Cursor has some real annoying usability issues - like their previous/next code change never going away and no way to disable it. Design of this one looks more polished and less muddy.

    I was working on a project and just continued with it. It was easy because they import setting from cursor. Feels like the browser wars.

    Anyway, I figured it was the only way to use gemini 3 so I got started. A fast model that doesn't look for much context. Could be a preprompt issue. But you have to prod it do stuff - no ambition and a kinda offputting atitude like 2.5.

    But hey - a smarter, less context rich Cursor composer model. And that's a complement because the latest composer is a hidden gem. Gemini has potential.

    So I start using it for my project and after about 20 mins - oh, no. Out of credits.

    What can I do? Is there a buy a plan button? No? Just use a different model?

    What's the strategy here? If I am into your IDE and your LLM, how do I actually use it? I can't pay for it and it has 20 minutes of use.

    I switched back to cursor. And you know? it had gemini 3 pro. Likely a less hobbled version. Day one. Seems like a mistake in the eyes of the big evil companies but I'll take it.

    Real developers want to pay real money for real useful things.

    Google needs to not set themselves up for failure with every product release.

    If you release a product, let those who actually want to use it have a path to do so.


  • New comment by uatec in "Google Antigravity"
  • Content:

    "Congratulations, you have been elevated to manager to agents."

    That's not exactly really where I hoped my career would lead. It's like managing junior developers, but without having nice people to work with.


  • New comment by lairv in "Gemini 3"
  • Content:

    Out of curiosity, I gave it the latest project euler problem published on 11/16/2025, very likely out of the training data

    Gemini thought for 5m10s before giving me a python snippet that produced the correct answer. The leaderboard says that the 3 fastest human to solve this problem took 14min, 20min and 1h14min respectively

    Even thought I expect this sort of problem to very much be in the distribution of what the model has been RL-tuned to do, it's wild that frontier model can now solve in minutes what would take me days


  • New comment by djdelorie in "How Quake.exe got its TCP/IP stack"
  • Content:

    Back then, DJGPP was a much bigger group, and most of the Quake kudos go to Charles Sandmann, author of cwsdpmi, who worked directly with Id to help them optimize their code for our environment.


  • New comment by kUdtiHaEX in "Google Antigravity"
  • Content:

    2020: every day a new JS framework is announced

    2024: every day a new Chrome fork browser is announced

    2025: every day a new AI IDE vscode fork is announced


  • New comment by modeless in "Google Antigravity"
  • Content:

    Thank you for saying what this entire blog post doesn't. It's actually disrespectful of Google to launch this without even a mention of the fact that it is based on VSCode.


  • New comment by nateb2022 in "Google Antigravity"
  • Content:

    I went ahead and downloaded it, it looks to be a VSCode fork very similar to Cursor, with support for the following models:

      - Gemini 3 Pro (High)
      - Gemini 3 Pro (Low)
      - Claude Sonnet 4.5
      - Claude Sonnet 4.5 (Thinking)
      - GPT-OSS 120B (Medium)


  • New comment by njarboe in "Nearly all UK drivers say headlights are too bright"
  • Content:

    One of the main reasons people want/need brighter headlights is that there is much more light inside the car from screens. These don't let your eyes adjust to the dark properly. Older cars had dim green lighting for the gauges and even had a knob to adjust the brightness up and down. You could create a very dim interior instead of the huge amount of white light you get with modern cars and the multiple screens.

    I'm happy my Tesla does a decent job of having the screen be quite dark at night but the headlights are quite bad with the horizontal cutoff style that only lights the first few feet of horizontal ahead of the car. I need to see those deer and elk on the side of the road, damn it.


  • New comment by throwaway150 in "Do Not Put Your Site Behind Cloudflare If You Don't Need To"
  • Content:

    > For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!"

    If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a service. Sometimes people do DDoS your small blog because some random stranger didn't like something you said somewhere online. Speaking from experience. Very much the reason I'm posting this with a throwaway account. If your website receives DDoS, your hosts will take down your server. Nobody wants to be in this situation even if for a personal, small blog.


  • New comment by abelanger in "Cloudflare Global Network experiencing issues"
  • Content:

    If anyone needs commands for turning off the CF proxy for their domains and happens to have a Cloudflare API token.

    First you can grab the zone ID via:

        curl -X GET "https://api.cloudflare.com/client/v4/zones" -H "Authorization: Bearer $API_TOKEN" -H "Content-Type: application/json" | jq -r '.result[] | "\(.id) \(.name)"'
    
    And a list of DNS records using:

        curl -X GET "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records" -H "Authorization: Bearer $API_TOKEN" -H "Content-Type: application/json"
    
    Each DNS record will have an ID associated. Finally patch the relevant records:

        curl -X PATCH "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records/$RECORD_ID" -H "Authorization: Bearer $API_TOKEN" -H "Content-Type: application/json" --data '{"proxied":false}'
    
    Copying from a sibling comment - some warnings:

    - SSL/TLS: You will likely lose your Cloudflare-provided SSL certificate. Your site will only work if your origin server has its own valid certificate.

    - Security & Performance: You will lose the performance benefits (caching, minification, global edge network) and security protections (DDoS mitigation, WAF) that Cloudflare provides.

    - This will also reveal your backend internal IP addresses. Anyone can find permanent logs of public IP addresses used by even obscure domain names, so potential adversaries don't necessarily have to be paying attention at the exact right time to find it.


  • New comment by afavour in "Cloudflare Global Network experiencing issues"
  • Content:

    Because no one cares enough, including users.

    Oddly this centralization allows a complete deferral of blame without you even doing anything: if you’re down, that’s bad. But if you’re down, Spotify is down, social media is down… then “the internet is broken” and you don’t look so bad.

    It also reduces your incentive to change, if “the internet is down” people will put down their device and do something else. Even if your web site is up they’ll assume it isn’t.

    I’m not saying this is a good thing but I’m simply being realistic about why we ended up where we are.


  • New comment by trollbridge in "Cloudflare Global Network experiencing issues"
  • Content:

    Coincidentally, large tech companies have been conducting mass layoffs and claim they're going to rely on AI much more to replace junior developers.


  • New comment by arbuge in "Cloudflare Global Network experiencing issues"
  • Content:

    Tell him it's worst than he thinks. He obviously brought the entire Cloudflare system down.


  • New comment by lordofgibbons in "Cloudflare Global Network experiencing issues"
  • Content:

    How did we get to a place where either Cloudflare or AWS having an outage means a large part of the web going down? This centralization is very worrying.


  • New comment by rco8786 in "Cloudflare Global Network experiencing issues"
  • Content:

    Is it me or has there been a very noticeable uptick in large scale infra-level outages lately? AWS, Cloudflare, etc have all been way under whatever SLA they publish.


  • New comment by rollulus in "Cloudflare Global Network experiencing issues"
  • Content:

    Classic. I see issues. Vendor’s status page is all green. Go to HN to find the confirmation. Applies to AWS, GH, everyone.

    Edit: beautiful, this decentralised design of the internet.


  • New comment by farhadhf in "Cloudflare Global Network experiencing issues"
  • Content:

    Pretty much everything is down (checking from the Netherlands). The Cloudflare dashboard itself is experiencing an outage as well.

    Not-so-funny thing is that the Betterstack dashboard is down but our status page hosted by Betterstack is up, and we can't access the dashboard to create an incident and let our customers know what's going on.

    Edit: wording.


  • New comment by entropoem in "Cloudflare Global Network experiencing issues"
  • Content:

    Everyone laughs when AWS collapses, everyone is silent when Cloudflare collapses. Why? Because the place to laugh has collapsed.


  • New comment by jpmonette in "Cloudflare Global Network experiencing issues"
  • Content:

    phewphoria


  • New comment by gwd in "Cloudflare Global Network experiencing issues"
  • Content:

    I do appreciate the visual "mea culpa":

    Your browser: Working

    Host: Working

    Cloudflare: Error


  • New comment by itzjacki in "Cloudflare Global Network experiencing issues"
  • Content:

    A colleague of mine just came bursting through my office door in a panic, thinking he brought our site down since this happened just as he made some changes to our Cloudflare config. He was pretty relieved to see this post.


  • New comment by its_notjack in "Cloudflare Global Network experiencing issues"
  • Content:

    Ironically, DownDetector seems to be down because it protects its site with Cloudflare Turnstile... which is also down!


  • New comment by powerclue in "How many video games include a marriage proposal? At least one"
  • Content:

    That's me! I made that 17 years ago, still happily married. Took me like two weeks of full time tinkering. It involved a lot of trial and error messing with a hex editor.


  • New comment by lrvick in "Core Devices keeps stealing our work"
  • Content:

    I am the primary author of the current generation Pebble Appstore frontend, the one that maintained the database most of the time, the guy who ran the security, infrastructure, data privacy team, and quite a few things around the Pebble ecosystem over the years. I also was on the team that begrudgingly had to hand it all over to Fitbit in the acquisition.

    I have a very strong opinion here.

    Any development of Pebble as an ecosystem that is not 100% free open source software and available to the public, is a dick move at this point. It is a dick move if Eric does it in any way, and it is a dick move if the Rebble team does it in any way.

    Let Eric or anyone else scrape what they want with the Appstore and wish them luck. Maybe even make a nice JSON export button for people, why not?

    Meanwhile those in the community should keep doing what they have always done: Work towards fully open source community first solutions with the full blessing and support of said community.

    Proprietary solutions are always a dead end so do not waste any energy fighting them or thinking about them. Just keep pushing to public repos.


  • New comment by luke727 in "Windows 11 adds AI agent that runs in background with access to personal folders"
  • Content:

    > Office products are bastardized with copilot buttons everywhere.

    They put copilot in notepad. NOTEPAD.


  • New comment by ChicagoDave in "Windows 11 adds AI agent that runs in background with access to personal folders"
  • Content:

    Microsoft has gone full-blown evil corporation again. No customer validation on any of the AI cruft. No full OPT OUT. Office products are bastardized with copilot buttons everywhere.

    I've been a Windows user from day one and I now see a future without it. Satya had been a bright spot in Microsoft, but this blind lust for AI, especially in bed with Altman who is pure con artist, is unforgivable.

    Some of the investment sells recently are starting to look like the beginning of the end for OpenAI. That will have a wide range impact on everything.

    I use Claude for coding (and mostly in WSL). OpenAI enabled its users to have a sext conversation.

    Seriously. And Satya just keeps on at full speed.


  • New comment by astrocat in "How many video games include a marriage proposal? At least one"
  • Content:

    The heart-warming gem:

    > I sent a note about these Easter eggs to Scott Corley [the game's developer]. He said that he had recently pulled out the game to show the marriage proposal to his son. But he’d forgotten the code and couldn’t make it work! He and Melissa did indeed live happily ever after.


  • New comment by amatecha in "Core Devices keeps stealing our work"
  • Content:

    Wow.

    > We made it absolutely clear to Eric that scraping for commercial purposes was not an authorized use of the Rebble Web Services.

    > We’d already agreed to give Core a license to our database to build a recommendation engine on. Then, Eric said that he instead demanded that we give them all of the data that we’ve curated, unrestricted, for him to do whatever he’d like with. We asked to have a conversation last week; he said that was busy and could meet the following week. Instead, the same day, our logs show that he went and scraped our servers.

    Seriously uncool. I don't really consider myself a part of the Pebble community anymore (despite having two of the OG Pebble) but I'd def lean towards getting legal input on this...


  • New comment by zeta0134 in "Rebecca Heineman has died"
  • Content:

    Rebecca was well known in emulation circles for her high quality work on various games of the era, often pushing the hardware in unusual ways. This article is one of my favorites, detailing the wacky tricks she used to get Another World's 3D rendering system running acceptably on a Super Nintendo

    https://fabiensanglard.net/another_world_polygons_SNES/

    Rest in piece, you absolute legend.


  • New comment by caymanjim in "Raccoons are showing early signs of domestication"
  • Content:

    They're pretty great pets. We had one for a while when I was a kid. Its mom got run over and we nursed it and raised it for a few months. Instinctively used the same litter box as the cats. Hung out on the couch sitting on my shoulder watching TV. Friendly and playful. Would follow people around and play with toys.

    The biggest challenge is that they basically have hands. He would climb up the kitchen cabinets, grab a box of cereal, open it up and sit there eating out of it like a toddler.

    We only had him for a few months before reintroducing him to the woods behind the house. I've wanted a pet raccoon again ever since.


  • New comment by the_snooze in "Windows 11 adds AI agent that runs in background with access to personal folders"
  • Content:

    >For example, if you ask ChatGPT’s Agent to book a travel, it’ll open Chromium on Linux in an Azure container, search the query, visit different websites, navigate each page and book a flight ticket using your saved credentials. An AI Agent tries to mimic a human, and it can perform tasks on your behalf while you sit back and relax.

    Big tech has repeatedly shown that they are not good stewards of end users' privacy and agency. You'd have to have been born yesterday to believe they'd build AI systems that truly serve the user's best interests like this.


  • New comment by everdrive in "Windows 11 adds AI agent that runs in background with access to personal folders"
  • Content:

    It's an agentic OS now. It acts as an agent on behalf of Microsoft and its business partners, and against your interests.


  • New comment by denkmoon in "Azure hit by 15 Tbps DDoS attack using 500k IP addresses"
  • Content:

    Mad salt. Imagine a fully grown man having a toddler tantrum. "If I can't play/win/get my way, nobody can" type mentality. It's also a method of coercion. Give me mod status or I'll DDOS your server and destroy your community.

    The other half comes from sever operators ddosing their competition. There is a lot of money to be made from paid cosmetics, ranks, moderator (demi-tyrant) status, etc on custom servers.


  • New comment by etangent in "My stages of learning to be a socially normal person"
  • Content:

    > a lot of the points felt more like learning how to charm, manipulate, and game social interactions.

    A lot of stuff "normal" people do is charm, manipulate, and game social interactions. Except because they are not conscious about it, we give them a pass. One of the characteristics of autistic-spectrum individuals is that they must make a conscious effort to achieve goals that are achieved unconsciously by most of us. If we prevent such individuals from learning all that rarely-written-down stuff consciously because it seems "distasteful" to us, then we are disadvantaging such individuals socially.


  • New comment by baklavaEmperor in "Israeli-founded app preloaded on Samsung phones is attracting controversy"
  • Content:

    What’s striking is how often these ‘small’ surveillance tech stories trace back to the same state-aligned ecosystem. When Israel does it, it’s treated as a complex security issue. When another ‘bad’ country does the same thing, we immediately call it espionage. And almost on cue, the discussion drifts anywhere except the uncomfortable fact that it’s the same ecosystem from the same country showing up again.


  • New comment by dlisboa in "Show HN: PrinceJS – 19,200 req/s Bun framework in 2.8 kB (built by a 13yo)"
  • Content:

    I know it's intentional but very amusing name considering the country of origin.


  • New comment by Aurornis in "My stages of learning to be a socially normal person"
  • Content:

    This post wasn't what I was expecting from the "socially normal" title. While there is a lot of self-reflection and growth in this piece, a lot of the points felt more like learning how to charm, manipulate, and game social interactions.

    Look at the first two subheadings:

    > 1: Connecting with people is about being a dazzling person

    > 2: Connecting with people is about playing their game

    The post felt like a rollercoaster between using tricks to charm and manipulate, and periods of genuinely trying to learn how to be friends with people.

    I don't want to disparage the author as this is a personal journey piece and I appreciate them sharing it. However this did leave me slightly uneasy, almost calling back to earlier days of the internet when advice about "social skills" often meant reductively thinking about other people, assuming you can mind-read them to deconstruct their mindset (the section about identifying people who feel underpraised, insecure, nervous,) and then leverage that to charm them (referred to as "dancing to the music" in this post).

    Maybe the takeaway I'd try to give is to read this as an interesting peek into someone's mind, but not necessarily great advice for anyone else's situation or a healthy way to view relationships.


  • New comment by keiferski in "A new book about the origins of Effective Altruism"
  • Content:

    The popularity of EA always seemed pretty obvious to me: here's a philosophy that says it doesn't matter what kind of person you are or how you make your fortune, as long as you put some amount of money toward problems. Exploiting people to make money is fine, as long as some portion of that money is going toward "a good cause." There is really no element of self virtue in the way that virtue ethics has..it's just pure calculation.

    It's the perfect philosophy for morally questionable people with a lot of money. Which is exactly who got involved.

    That's not to say that all the work they're doing/have done is bad, but it's not really surprising why bad actors attached themselves to the movement.


  • New comment by hpdigidrifter in "Why don't people return their shopping carts?"
  • Content:

    I assume it's generally unbecoming to reference 4chan posts for an academic but surprised the Shopping Cart theory didn't get a mention given how close it was to the subject matter.

    >“The shopping cart is the ultimate litmus test for whether a person is capable of self-governing. To return the shopping cart is an easy, convenient task and one we all recognize as the correct, appropriate thing to do. To return the shopping cart is objectively right. There are no situations other than dire emergencies in which a person is not able to return their cart. Simultaneously, it is not illegal to abandon your shopping cart. Therefore, the shopping cart presents itself as the apex example of whether a person will do what is right without being forced to do it.”

    >“No one will punish you for not returning the shopping cart, no one will fine you, or kill you for not returning the shopping cart. You gain nothing by returning the shopping cart. You must return the shopping cart out of the goodness of your own heart. You must return the shopping cart because it is the right thing to do. Because it is correct. The Shopping Cart Theory, therefore, is a great litmus test on whether a person is a good or bad member of society.”


  • New comment by xmcp123 in "Google is killing the open web, part 2"
  • Content:

    It’s interesting to see the casual slide of Google towards almost internet explorer 5.1 style behavior, where standards can just be ignored “because market share”.

    Having flashbacks of “


  • New comment by nwellnhof in "Google is killing the open web, part 2"
  • Content:

    Removing XSLT from browsers was long overdue and I'm saying that as ex-maintainer of libxslt who probably triggered (not caused) this removal. What's more interesting is that Chromium plans to switch to a Rust-based XML parser. Currently, they seem to favor xml-rs which only implements a subset of XML. So apparently, Google is willing to remove standards-compliant XML support as well. This is a lot more concerning.


  • New comment by wmeredith in "Are you stuck in movie logic?"
  • Content:

    > Good Will Hunting. The entire movie feels like it could’ve been skipped if literally any emotionally intelligent person said to Matt Damon’s character: “I feel like you have a tremendous amount of intellectual potential that you’re wasting here — why are you getting in fights rather than trying to do something interesting?”

    Maybe I'm missing something but that's literally what everyone in the movie is telling Will. HIs best friend, his mentor, his girlfriend, his therapist. They all literally say this in some form during the movie. His character growth is believing it himself.


  • New comment by rudedogg in "Open-source Zig book"
  • Content:

    I submitted this and unfortunately it is likely AI generated. The authors github history suggests it at the very least, along with seemingly misunderstanding a reference to a Zig language feature (labeled blocks - https://zig.guide/language-basics/labelled-blocks/) in the project issues (https://github.com/zigbook/zigbook/issues/4).

    I’m not sure how much value is to be had here, and it’s unfortunate the author wasn’t honest about how it was created.

    I wish I wouldn’t have submitted this so quickly but I was excited about the new resource and the chapters I dug into looked good and accurate.

    I worry about whether this will be maintained, if there are hallucinations, and if it’s worth investing time into.


  • New comment by retube in "Where do the children play?"
  • Content:

    As a parent, I relate to all this. Great piece.

    When the kids were babies we had the standard debate of move to the countryside for fresh air and gambolling in the fields etc. But so glad we stayed in London, the kids have so much freedom with public transport they can organise their own meet ups and activities and go running around all over town without any parental assistance or intervention at all. Whereas elsewhere we'd need to drive them everywhere, they'd be stuck at home way more, they'd have no real agency in their lives - I grew up like that and hated it.


  • New comment by btilly in "A new chapter begins for EV batteries with the expiry of key LFP patents"
  • Content:

    It is worth noting that this is an ad. It is a law firm that is advertising their expertise in this field. And the product that they want people to buy is revealed in this passage:

    Freedom-to-operate (FTO) analysis therefore remains critical for market entrants. Whilst the primary patents have expired, a dense web of secondary patents, covering additives, coatings, and production methods, still poses infringement risks.

    Of course Shoosmiths would be happy to do a FTO analysis for your potential product...for a fee.

    That doesn't mean that it doesn't contain quality information. Law firms tend to make this kind of ad informative. But it does mean that there is an agenda.


  • New comment by RandyOrion in "Heretic: Automatic censorship removal for language models"
  • Content:

    This repo is valuable for local LLM users like me.

    I just want to reiterate that the word "LLM safety" means very different things to large corporations and LLM users.

    For large corporations, they often say "do safety alignment to LLMs". What they actually do is to avoid anything that causes damage to their own interests. These things include forcing LLMs to meet some legal requirements, as well as forcing LLMs to output "values, facts, and knowledge" which in favor of themselves, e.g., political views, attitudes towards literal interaction, and distorted facts about organizations and people behind LLMs.

    As an average LLM user, what I want is maximum factual knowledge and capabilities from LLMs, which are what these large corporations claimed in the first place. It's very clear that the interests of me, an LLM user, is not aligned with these of large corporations.


  • New comment by AlbertoGP in "Britney Spears' Guide to Semiconductor Physics (2000)"
  • Content:

    Around the time this website was made, I was building an application for a big company in Spain that was to run as a Java applet and required the code to be signed.

    They did not yet have their own certificates so I had to make my own CA during testing and sign the code, and I wanted to make sure that they did not forget to switch to their certificates later, so instead of signing the code with my name which some bureaucrat might decide to not bother changing, the code was signed by Britney Spears.

    They noticed it, got the joke and made sure to switch certificates for the release. Everything went well thanks to Britney.


  • New comment by stego-tech in "Goldman Sachs asks in biotech Report: Is curing patients a sustainable business? (2018)"
  • Content:

    I feel kinda bad for the writer, because it's a good question: no, curing patients is not a good business model, just like public transit is not a good business model.

    What a lot of folks neglect are N+1-order effects, because those are harder to quantify and fail to reach the predetermined decision some executive or board or shareholder has already made. Is curing patients a bad business model? Sure, for the biotech company it is, but those cured patients are far more likely to go on living longer, healthier lives, and in turn contribute additional value to society - which will impact others in ways that may also create additional value. That doesn't even get into the jobs and value created through the R&D process, testing, manufacturing, logistics of delivery, ongoing monitoring, etc. As long as the value created is more than the cost of the treatment, then it's a net-gain for the economy even if it's a net loss for that singular business.

    If all you're judging is the first-order impacts on a single business, you're missing the forest for the trees.


  • New comment by mendelmaleh in "Open-source Zig book"
  • Content:

    > The Zigbook intentionally contains no AI-generated content—it is hand-written, carefully curated, and continuously updated to reflect the latest language features and best practices.

    I think it's time to have a badge for non LLM content, and avoid the rest.


  • New comment by chaps in "I have recordings proving Coinbase knew about breach months before disclosure"
  • Content:

    Once did some programming/networking work for a company that did the networking of a office sharing building that Coinbase was running out of. Early in my work there I noticed that the company had its admin passwords written on a whiteboard -- visible from the hallway because they had glass for walls. So I sent them an email to ask that they remove it (I billed them for it).

    Their fix was to put a piece of paper over the passwords.

    What a time.


  • New comment by jchw in "I finally understand Cloudflare Zero Trust tunnels"
  • Content:

    One thing that makes Cloudflare worse for home usage is it acts as a termination point for TLS, whereas Tailscale does not. If you use a Tailscale Funnel, you get the TLS certificate on your endpoint. With Cloudflare, they get a TLS certificate for you, and then strip and optionally re-add TLS as traffic passes through them.

    I actually have no idea how private networks with WARP are here, but that's a pretty big privacy downgrade for tunneling from the Internet.

    I also consider P2P with relay fallback to be highly desirable over always relaying traffic through a third party, too. Firstly, less middlemen. Secondly, it continues working even if the coordination service is unavailable.


  • New comment by joshcsimmons in "Heretic: Automatic censorship removal for language models"
  • Content:

    This is extremely important work thank you for sharing it. We are in the process of giving up our own moral standing in favor of taking on the ones imbued into LLMs by their creators. This is a worrying trend that will totally wipe out intellectual diversity.


  • New comment by gpi in "Anthropic’s paper smells like bullshit"
  • Content:

    The below amendment from the anthropic blog page is telling.

    Edited November 14 2025:

    Added an additional hyperlink to the full report in the initial section

    Corrected an error about the speed of the attack: not "thousands of requests per second" but "thousands of requests, often multiple per second"


  • New comment by yousif_123123 in "Maybe you’re not trying"
  • Content:

    I've always noticed that when I'm giving advice to someone or trying to help out, it always feels their problem is easier than whatever problem I have. As someone with some anxiety around things like calling some company to get something done or asking a random stranger for some help in a store, I would gladly do it if it was to help someone else (family member or friend). But when it's for me I find it harder.

    I wonder how much psychologically we can be more confident and less anxious when we're doing something for others vs ourselves..


  • New comment by jmkni in "Anthropic’s paper smells like bullshit"
  • Content:

    That whole article felt like "Claude is so good Chinese hackers are using it for espionage" marketing fluff tbh


  • New comment by KaiserPro in "Anthropic’s paper smells like bullshit"
  • Content:

    When I worked at a FAANG with a "world leading" AI lab (now run by a teenage data labeller) as an SRE/sysadmin I was asked to use a modified version of a foundation model which was steered towards infosec stuff.

    We were asked to try and persuade it to help us hack into a mock printer/dodgy linux box.

    It helped a little, but it wasn't all that helpful.

    but in terms of coordination, I can't see how it would be useful.

    the same for claude, you're API is tied to a bankaccount, and vibe coding a command and control system on a very public system seems like a bad choice.


  • New comment by prinny_ in "Anthropic's report smells a lot like bullshit"
  • Content:

    The lack of evidence before attributing the attack(s) to a Chinese sponsored group makes me correlate this report with recent statements from companies in the AI space about how China is about to surpass US in the AI race. Ultimately statements and reports like these seem more like an attempt to make the US government step in and be the big investor that keeps the money flowing rather than anything else.


  • New comment by torginus in "I don’t need a Steam Machine"
  • Content:

    When I first saw the Arduino I didn't see the point - after all there were boards that cost less, did more, and the Arduino IDE seemed very barebones compared to what you could do with GCC and a custom toolchain.

    Then eventually I saw how much community support, ready made hardware emerged around it, to the point that after a while, not going the Arduino route was a decision you needed to justify heavily.

    Same thing with the Raspberry Pi - there are commercial devices now running or more or less stock Pi hardware with some accomodations - the power of the community is just too large - you can either spend an insane amount of time getting things working on your custom SBC, or get something well-supported for free.

    I hope that the same thing will happen with the Steam Machine - the pull of the community will result in a well-supported 'default' device where people (and Valve) will put in the effort to create a comparable desktop experience to the commercial OSes.

    Valve already helped immensely with Wayland - it's crazy to think that the project was stared cca. 2008, and today there's still arguments to be made it's not mature yet - by investing the necessary energy to make sure games run well, the drivers are optimized, and there's a high-quality end-user library (wlroots) for writing compositors has been the push that Wayland needed.


  • New comment by mariopt in "I don’t need a Steam Machine"
  • Content:

    Steam Machines can become an existencial crisis for PlayStation and Xbox.

    A “console” that I can use as a PC? I am in 100%. You’ll get the world biggest game library at a discount, this is why I sold my PlayStation after spending 200 euros and watching it becoming useless.

    I also suspect a lot of game devs will optimize for steam machine and finally we’ll get a console like experience on PC.

    Don’t let the “low specs” fool you, it has the same specs or better as 70% of steam users.

    Given Valve gave money to a lot of open source maintainers , it’s also great for Linux.

    Just take my money


  • New comment by xps in "AirPods libreated from Apple's ecosystem"
  • Content:

    They don't report battery status to non-Apple devices. This is a pretty basic feature and without this I wouldn't consider them to perform "on par" with other Bluetooth headphones.


  • New comment by gloxkiqcza in "Hyundai Paywalls Brake Pads replacement on Ioniq 5 N"
  • Content:

    Doesn’t really surprise me. I remember reading the article linked below from which I quote:

    > Forced to raise their game, carmakers are only now realizing they cannot repeat past mistakes such as letting others build up parts and services businesses off the back of their core product. "They stole the business from us," Martinet says, referencing as an example windshield replacement companies. "So I don't want them to steal the next one."

    Xavier Martinet is the President and CEO of Hyundai Motor Europe.

    https://www.wired.com/story/the-global-car-reckoning-is-here...


  • New comment by LarsDu88 in "Report: Tim Cook could step down as Apple CEO 'as soon as next year'"
  • Content:

    They shipped AirPods and the Apple Watch during his tenure. And the ahem, Vision Pro. The M-series chips are probably the biggest win for Apple in the past 15 years.

    There hasn't been lack of category killers during his stint. If anything they are running out of places on the human body where you can stick a small computer.

    Surely the next CEO will hopefully not ruin the company and brand by cramming ads into everything.


  • New comment by exitb in "AirPods libreated from Apple's ecosystem"
  • Content:

    AirPods can connect to any device and perform on par with other Bluetooth headphones. This is about availability of special features which require a dedicated driver non-Apple devices are not expected to have.


  • New comment by isoprophlex in "AirPods libreated from Apple's ecosystem"
  • Content:

    From a bit further down the page

    > Bluetooth DID (Device Identification) Hook > Turns out, if you change the manufacturerid to that of Apple, you get access to several special features!

    I hope Apple gets slammed hard by some regulatory body. Apparently there's absolutely zero magic reasons why their airpods are unable to connect to non-Apple devices; pretend you're an iPhone and you're in.

    EDIT: read "unable to connect" => "unable to expose advanced functionality", ofc they connect just fine


  • New comment by jmgao in "AirPods libreated from Apple's ecosystem"
  • Content:

    It doesn't seem obvious to me that this is actually a bug in the Android implementation, it seems like this is due to AirPods violating the spec and requiring a special handshake before responding to standard requests. It doesn't seem reasonable to expect Android to work around a device that appears to be intentionally breaking the spec for vendor lock-in purposes: the possibility of them just OTAing an update that breaks in some other way means that you'd have to be entirely bug compatible with iOS's bluetooth implementation.


  • New comment by ferd in "When did people favor composition over inheritance?"
  • Content:

    An important point not mentioned by the article is that of "co-recursion" with inheritance (of implementation).

    That is: an instance of a subclass calls a method defined on a parent class, which in turn may call a method that's been overridden by the subclass (or even another sub-subclass in the hierarchy) and that one in turn may call another parent method, and so on. It can easily become a pinball of calls around the hierarchy.

    Add to that the fact that "objects" have state, and each class in the hierarchy may add more state, and modify state declared on parents. Perfect combinatory explosion of state and control-flow complexity.

    I've seen this scenario way too many times in projects, and worse thing is: many developers think it's fine... and are even proud of navigating such a mess. Heck, many popular "frameworks" encourage this.

    Basically: every time you modify a class, you must review the inner implementation of all other classes in the hierarchy, and call paths to ensure your change is safe. That's a horrendous way to write software, against the most basic principles of modularity and low coupling.


  • New comment by JSR_FDED in "When UPS charged me a $684 tariff on $355 of vintage computer parts"
  • Content:

    Tariffs are great. They protect the struggling domestic IT industry and gives it time to ramp up its production of vintage computer parts.


  • New comment by moonleay in "AirPods libreated from Apple's ecosystem"
  • Content:

    A cool project, when you want to use AirPods outside of Apples ecosystem. Sadly, you have to use a rooted android device with a small patch due to a bug in the Android Bluetooth implementation. https://issuetracker.google.com/issues/371713238


  • New comment by ryandrake in "Report: Tim Cook could step down as Apple CEO 'as soon as next year'"
  • Content:

    Cook's been great for massively scaling Apple (and its stock price) up, but the art, vision, and soul of the company is gone. It's just a stock price maximizing lawnmower now, just like every other corporate stock price maximizing lawnmower. If that's what shareholders want, fine, I guess. But I'd be bored just manufacturing the same boring rectangles every year. I think Steve would have been, too.


  • New comment by PinkSheep in "Our investigation into the suspicious pressure on Archive.today"
  • Content:

    Good job on AdGuard's end for bringing this to the Internet's attention. I especially enjoyed the unearthed details about this "N"GO's short history.

    I think the e-mail exchange should've been kept short, although it is good that the owner of archive.today was eventually notified (by them) about these links in good faith to remove them. Their reply should've been the following:

    "Thank you for contacting us. If you have conclusive proof of illegal behavior, you should contact police and seek legal assistance. A website's administrator is expected to adequately react to illegal actions conducted by its users, such as removing media that's breaking a law.

    We have visited the URLs provided by you (https://archive[.]today/ , ...) and found no evidence to corroborate your concerns. To avoid misunderstandings, we require you to send a certified mail to before further replies on this matter."

    Remember guys, it should always be certified mail (bonus points for international). And yes, I mean literal index pages as provided in the first e-mail. Play by the legal understanding of words. Be creative and break the rules to the extent of not breaking them ;)

    PS: If you want to see more of "funny replies" you should read Njalla's blog (<https://njal.la/blog/>) and TPB's infamous e-mail replies.


  • New comment by puppycodes in "FBI Director Waived Polygraph Security Screening for Three Senior Staff"
  • Content:

    The only way polygraphs work is by convincing people its an actual lie detection machine. Cops leveredge this belief and tell you that you "failed miserably" so you ultimately confess because "your caught".

    They are about as accurate as flipping a coin.


  • New comment by jayflux in "Boa: A standard-conforming embeddable JavaScript engine written in Rust"
  • Content:

    Hi all, wow was not expecting this to be trending right now.

    I’m the creator of Boa, you can catch my talk about it at JS Conf EU 2019 https://www.youtube.com/watch?v=_uD2pijcSi4

    That said, today Boa has a whole team of maintainers who I’m sure will answer some questions here.

    Yes the name does invoke the sense it’s a Python project but I liked it and stuck with it, I saw a Boa snake at a zoo once and knew I wanted to name my next project after it, I was also inspired by Mozilla at the time who named their projects after animals.

    Speaking of Mozilla, Boa’s existence came to be because at the time I was working on Servo and wanted to include an all-rust JS engine, one didn’t really exist so I set about making one as a learning exercise, after around 2 years more joined me on that journey and today Boa is around 8 years old. It is not browser grade (although at 94.12% it is more compliant than some browser engines) but that doesn’t matter, plenty of Rust projects have found good use for it as they find it easy to embed and use, so we’re happy.

    One recent example is Biome who use it for their plugin infrastructure. https://github.com/biomejs/biome/pull/7300

    Another recent thing which we’re very proud is seeing our implementation of Temporal be used in V8 and other engines, so we’re also helping the wider ecosystem and raising all ships! (More here: https://boajs.dev/blog/2025/09/24/temporal-release)

    We do hope to improve performance over the next year or so, hopefully that answers some of the Qs here.


  • New comment by m417z in "Windhawk Windows classic theme mod for Windows 11"
  • Content:

    Hi, Windhawk author here. Nice to see it on Hacker News.

    This is just one Windhawk mod, submitted by a community member. There are hundreds others. Windhawk was created to simplify Windows customization and to make it more accessible, both for developers and users. For a more detailed introduction, check out the Windhawk release blog post:

    https://ramensoftware.com/windhawk


  • New comment by wartywhoa23 in "Our investigation into the suspicious pressure on Archive.today"
  • Content:

    The Ministry of Truth simply doesn't want unaccounted and uncontrolled snapshots of history. Too much hassle steering the narrative regarding any surfacing truth-now-meant-to-be-lies and vice versa into fake news territory, discrediting by association, cranking up troll farms.. Much easier to make this inconvenience disappear with the due cooperation from the controlled outlets of information.

    Then they will come after our local storage, and making it prohibitively expensive is the least malign way they can come up with.


  • New comment by andronikos in "Our investigation into the suspicious pressure on Archive.today"
  • Content:

    member of DNS4EU ops team here - This was not the case, we had reachability issues with the authoritative servers of archive.is and had to reach out to the team to allow our source IPs.

    https://www.reddit.com/r/BuyFromEU/comments/1ohekv5/updatedn...


  • New comment by codedokode in "Our investigation into the suspicious pressure on Archive.today"
  • Content:

    Note that association's site is made from this free template [1] with minimal editing (can see it using diff). The web hosting account at name.com (prices starting from $5/year) was registered around Jan 12, 2025 [2]. The page also contains commented out section with a part of French mobile phone number and words "Emergency Standard" (the template contained fictional number here):

                   
    
    [1] https://www.tooplate.com/view/2117-infinite-loop

    [2] https://web.archive.org/web/20250112153727/https://webabused...


  • New comment by supriyo-biswas in "Our investigation into the suspicious pressure on Archive.today"
  • Content:

    Its interesting that being unable to find a legal route to dig up dirt on archive.is, they're going the route of CSAM allegations.

    I first heard of this technique on a discussion on Lowendtalk from a hoster discussing how pressure campaigns were orchestrated.

    The host used to host VMs for a customer that was not well liked but otherwise within the bounds of free speech in the US (I guess something on the order of KF/SaSu/SF), so a given user would upload CSAM on the forum, then report the same CSAM to the hoster. They used to use the same IP address for their entire operation. When the host and the customer compared notes, they'd find about these details.

    Honestly at the time I thought the story was bunk, in the age of residential proxies and VPNs and whatnot, surely whoever did this wouldn't just upload said CSAM from their own IP, but one possible explanation would be that the forum probably just blocked datacenter IPs wholesale and the person orchestrating the campaign wasn't willing to risk the legal fallout of uploading CSAM out of some regular citizen's infected device.

    In this case, I assume law enforcement just sets up a website with said CSAM, gets archive.is to crawl it, and then pressurize DNS providers about it.


  • New comment by atomicfiredoll in "Our investigation into the suspicious pressure on Archive.today"
  • Content:

    I don't know anything about Adguard, but good on the team for doing the extra digging instead of just going along with the claim. Even better that they're sharing what they've found with everyone else.


  • New comment by defanor in "Lawmakers want to ban VPNs"
  • Content:

    > It Won’t Even Work

    I heard similar sentiments about censorship efforts in Russia, but it does seem to work, unfortunately. So far they have outlawed and blocked major VPN providers (and keep blocking more, including non-commercial ones, like Tor bridges, and foreign hosting companies' websites), blocked major detectable protocols used for those (IPsec, WireGuard), made usage of proxying ("VPN") an aggravating circumstance for the newly-introduced crime of searching for "extremist" information. That seems to deter many people already, and once the majority is forced to use the local approved (surveilled, censored) services, it is even easier to introduce whitelists or simply cut international connections (as is already practiced temporarily and locally), at which point the ban is successfully applied to everyone.


  • New comment by mechanicum in "One Handed Keyboard"
  • Content:

    Their video on YouTube, in English: https://www.youtube.com/watch?v=9vW12gQ4Klc


  • New comment by gsliepen in "TCP, the workhorse of the internet"
  • Content:

    If you start with the problem of how to create a reliable stream of data on top of an unreliable datagram layer, then the solution that comes out will look virtually identical to TCP. It just is the right solution for the job.

    The three drawbacks of the original TCP algorithm were the window size (the maximum value is just too small for today's speeds), poor handling of missing packets (addressed by extensions such as selective-ACK), and the fact that it only manages one stream at a time, and some applications want multiple streams that don't block each other. You could use multiple TCP connections, but that adds its own overhead, so SCTP and QUIC were designed to address those issues.

    The congestion control algorithm is not part of the on-the-wire protocol, it's just some code on each side of the connection that decides when to (re)send packets to make the best use of the available bandwidth. Anything that implements a reliable stream on top of datagrams needs to implement such an algorithm. The original ones (Reno, Vegas, etc) were very simple but already did a good job, although back then network equipment didn't have large buffers. A lot of research is going into making better algorithms that handle large buffers, large roundtrip times, varying bandwidth needs and also being fair when multiple connections share the same bandwidth.


  • New comment by jacquesm in "Unofficial Microsoft Teams client for Linux"
  • Content:

    The official client is absolutely terrible. But, I've found a much better solution: I tell all my customers Microsoft Teams doesn't work for us and they'll have to pick something else.

    Kudos for at least trying to address this, MS should hang their head in shame, this is not the hardest problem to solve these days. If we could do it in 1995 they should be able to do it 30 years later.


  • New comment by jdietrich in "AI World Clocks"
  • Content:

    Clock drawing is widely used as a test for assessing dementia. Sometimes the LLMs fail in ways that are fairly predictable if you're familiar with CSS and typical shortcomings of LLMs, but sometimes they fail in ways that are less obvious from a technical perspective but are exactly the same failure modes as cognitively-impaired humans.

    I think you might have stumbled upon something surprisingly profound.

    https://www.psychdb.com/cognitive-testing/clock-drawing-test


  • New comment by georgehotz in "HipKittens: Fast and furious AMD kernels"
  • Content:

    Full disclosure, we have a contract with AMD to get Llama 405B training on MI350X on MLPerf.

    Things are turning around for AMD. If you have an AMD card, go to pytorch.org, click Linux+ROCm and install PyTorch. 3 years ago, this was hopeless. Today, most mainline things work. I ran nanochat on MI300X and it just worked. I think that's true about MI350X now too. The MI350X machine is stable.

    They are clearly behind NVIDIA, nobody doubts that. And a lot of investment into software will be required to catch up, ecosystem, compiler, and driver. But 2 years ago they seemed hopeless, now they don't. Things take time. HipKittens is a great codebase to study to see where AMD's LLVM backend is still lacking; compare it to the CUDA Kittens.

    For training, it's NVIDIA and Google in first. AMD in second. And nobody in third. Intel and Tenstorrent are not remotely close. Huawei examples segfaulted. Groq gave up selling chips. Cerebras isn't available anywhere. Trainium had a 5 day wait time to get one instance and I lost interest.


  • New comment by Xeoncross in "Go's Sweet 16"
  • Content:

    I know they say that your programming language isn't the bottleneck, but I remember sitting there being frustrated as a young dev that I couldn't parse faster in the languages I was using when I learned about Go.

    It took a few more years before I actually got around to learning it and I have to say I've never picked up a language so quickly. (Which makes sense, it's got the smallest language spec of any of them)

    I'm sure there are plenty of reasons this is wrong, but it feels like Go gets me 80% of the way to Rust with 20% of the effort.


  • New comment by throwup238 in "A new Google model is nearly perfect on automated handwriting recognition"
  • Content:

    I really hope they have because I’ve also been experimenting with LLMs to automate searching through old archival handwritten documents. I’m interested in the Conquistadors and their extensive accounts of their expeditions, but holy cow reading 16th century handwritten Spanish and translating it at the same time is a nightmare, requiring a ton of expertise and inside field knowledge. It doesn’t help that they were often written in the field by semi-literate people who misused lots of words. Even the simplest accounts require quite a lot of detective work to decipher with subtle signals like that pound sign for the sugar loaf.

    > Whatever it is, users have reported some truly wild things: it codes fully functioning Windows and Apple OS clones, 3D design software, Nintendo emulators, and productivity suites from single prompts.

    This I’m a lot more skeptical of. The linked twitter post just looks like something it would replicate via HTML/CSS/JS. Whats the kernel look like?


  • New comment by dwedge in "Being poor vs. being broke"
  • Content:

    > its not uncommon to have the few worthwhile items you own being seized by bailifs to recoup debts, treasured heirlooms that cannot be replaced and have little monetary value so they do no impact to your debt. The hoarding of canned goods to avoid being unable to eat.

    As a teenager I worked at a bailiffs in the office typing up the paperwork. One case that stuck was me was where the debtor owed somewhere around £400. The bailiff took a motorbike (or scooter) that could easily have covered the debt. It was sold at auction for £50. £35 bailiff fees for taking it there and £15 auctioneer fees, £0 off the debt. It was so unfair it should have been criminal.


  • New comment by lanewinfield in "AI World Clocks"
  • Content:

    hi, I made this. thank you for posting.

    I love clocks and I love finding the edges of what any given technology is capable of.

    I've watched this for many hours and Kimi frequently gets the most accurate clock but also the least variation and is most boring. Qwen is often times the most insane and makes me laugh. Which one is "better?"


  • New comment by otterley in "AI World Clocks"
  • Content:

    Watching this over the past few minutes, it looks like Kimi K2 generates the best clock face most consistently. I'd never heard of that model before today!

    Qwen 2.5's clocks, on the other hand, look like they never make it out of the womb.


  • New comment by pcrh in "The disguised return of EU Chat Control"
  • Content:

    The right to privacy is enshrined in the European Convention on Human Rights, article 8 [0].

    It escapes me how politicians can repeatedly attempt to violate this.

    [0] https://fra.europa.eu/en/law-reference/european-convention-h...