HNHacker News
TopNewBestAskShowJobs

ComputerGuru

32,238 karma · joined January 3, 2008

mqudsi on most sites.
submissionscomments
ComputerGuru··on A Rust-Python thing I am working on. Apache 2 licence
How is this an OS? I thought it might be a kernel developed in rust with a python ffi api, but it's nothing to do with any of that.
ComputerGuru··on Google Chrome silently installs a 4 GB AI model on your device without consent
> I suppose this means that ALL the browser vendors are likely to implement something

Mozilla has taken a strong stand against the prompt api.

ComputerGuru··on Google Chrome silently installs a 4 GB AI model on your device without consent
This might be worth it if Gemma4 E2B were a good model, but honestly it's absolutely useless in all our testing without further training and finetuning, and those aren't usecases that are fit for normal web browser use such that one would care to support it by adding such overly broad and expensive infrastructure to make it happen.

Gemma 4 E4B is a much better model, but it's too large to simply download and run everywhere.

IMHO, this is jumping the gun. Google's going through a lot of effort to release a model that will give everyone a very poor first impression of what on-device models are capable of, souring it for everyone for a long time afterwards. It would be better to wait until a smaller, better model ships before doing this.

ComputerGuru··on Opus 4.7 knows the real Kelsey
Just tried this via the api; it seems to work best if reasoning is set to low, otherwise (especially GPT-5.5) like to “delve” into the matters discussed in the quoted text in order to logic out the author rather than just going off of stylistic measures.

But, yeah, I’m a nobody that has been blogging (very sporadically) publicly (and writing at length on forums like this one, with various handles loosely tied to my real identity) for twenty or more years (and by virtue of not trusting 3rd parties to host my content, most of it is actually still up) and Opus 4.6 (didn’t try 4.7) got me on the first try with just two paragraphs of an unpublished draft post (though it couldn’t come up with a convincing reason as to why it thought it was me).

Gemini and ChatGPT both clearly go off the subject matter rather than the stylistic clues; for the specific blog post I fed it which included mentions of “decoding” and “deciphering” and spoke of a tranche of legal documents (ok, it was the Epstein files, which I have been working on decoding), Gemini and ChatGPT both guessed “Molly White”, who seems to be a crypto-adjacent (currency not the real thing?) technical writer, and gave explanations that actually did explain why they arrived at that (wrong) answer.

So it seems Opus is indeed a bit special in this regard (and not limited to the latest 4.7 release)!

—-

What I would be more curious about is how well they can identify (open source) developers from their code. I’ve possibly publicly published more tokens in the form of OSS code than prose over the same period of time, in multiple languages and for completely different applications and environments. I’m sure there are style stylometric quirks associated with my coding style that persist across codebases, (though possibly somewhat stunted when contributing to others’ codebases to comply with the respective projects’ standards and styles) that should make it possible for an LLM that’s ingested code (and commits) to guess who’s who.

Edit:

Reading this self-same comment: I am apparently obsessed with parentheticals. Maybe my writing is more distinctive than I realized!

ComputerGuru··on Where the goblins came from
The explanation is very concerning. Lexical tidbits shouldn’t be learnt and reinforced across cross sections. Here, gremlin and goblin went from being selected for in the nerdy profile to being selected for in all profiles. The solution was easy: don’t mention goblins.

But what about when the playful profile reinforces usage of emoji and their usage creeps up in all other profiles accordingly? Ban emoji everywhere? Now do the same thing for other words, concepts, approaches? It doesn’t scale!

It seems like models can be permanently poisoned.

ComputerGuru··on OpenAI releases GPT-5.5 and GPT-5.5 Pro in the API
Yes? The same reason you would use it via the tooling.
ComputerGuru··on ChatGPT Images 2.0
It can generate 3840x2160
ComputerGuru··on A Periodic Map of Cheese
Isn’t that kind of an “implementation detail” of the cheese? Like you can’t categorically say one way or the other for some without knowing the process used? Obviously some forego that altogether, but for the majority it would simply depend, no?

(I have many close friends that are similarly pedantic though for other reasons.)

Anyway, the site lets you categorize by processing method. All the acid cure options should meet your requirements, no?

ComputerGuru··on Edit store price tags using Flipper Zero
Police know which side their bread is buttered on. Target is famous for being to get local cops to do exactly what they need post-facto (now prosecutor is another story).

I.E. just because police don’t “waste” time investigating a crime with $1000 of damage to your personal property does not mean they won’t dedicate the time to pursue $200 in losses for the local mega mart.

ComputerGuru··on Tim Cook's Impeccable Timing
> but recovered nicely afterwards

After Ives was fired/forced out/decided to leave to pursue his creative vision.

ComputerGuru··on Gemini Robotics-ER 1.6
So should we be using this until Google deigns to release Gemini Flash 3.1? (Not flash lite or live)
ComputerGuru··on Anna's Archive loses $322M Spotify piracy case without a fight
Not sure how I feel. Anna’s Archive turned into a profit-seeking beast a long time ago. They’re also rolling in it thanks to he massive deals to “license” the content to AI companies.

Libgen was a much better option.

ComputerGuru··on CPUs Aren't Dead. Gemma2B Out Scored GPT-3.5 Turbo on Test That Made It Famous
Grading by hand was done fully blinded?

(Also this comment is ai generated so I’m not sure who I’m even asking.)

ComputerGuru··on CPUs Aren't Dead. Gemma2B Out Scored GPT-3.5 Turbo on Test That Made It Famous
Seems to be llm written article and the tooling around the model is undeniably influenced by knowledge of the tests.

In all cases, GPT 3.5 isn’t a good benchmark for most serious uses and was considered to be pretty stupid, though I understand that isn’t the point of the article.

ComputerGuru··on Show HN: Keeper – embedded secret store for Go (help me break it)
SecureStore is an open spec/protocol for managing secrets in a secure and portable manner, while it defines the decryption key formats (currently: key-based, password-based, or a mix of both interchangeably) it doesn't get into the mechanics of key management, which are "trivial and left as an exercise for the reader."

More seriously though, you're supposed to use separate vaults (with the same keys, where "keys" is the name of the secrets, not the decryption keys) for testing/staging/production, e.g. perhaps secrets.{testing,production,staging}.json and the same secrets.{testing,production,staging}.key for the decryption keys, and store both the username and password in them (after all, it's just an encrypted, glorified KV store) so that you don't have to hard-code any usernames and conditionally load them based on the environment in your code (so db:username is one "secret" and db:password is another (actual) secret).

The secrets vaults (the secrets.json files) are non-sensitive and can be versioned and pushed to your server the same way you push the binaries. Now how you move the secrets to the server is up to you. You could do it the old-fashioned way and just have it as an environment variable, in which case even when your env vars leak at least you haven't leaked your api keys, only the key to decrypt them (which you'd then rotate), but that's not a recommended option. Ideally you'd instead use whatever secure channel you use to init/stage the servers to begin with to transfer the secure key files - the key files are generally immutable, even as the secrets change, so you only have to do this once (ideally via a high-friction, high-auth mechanism, for most people not at FAANG scale, probably manually).

You can also use whatever additional layer of abstraction on top of the symmetric SecureStore decryption key you like. For example, you could asymmetrically encrypt the keyfiles and then each host would decrypt it with its own private key, or have a secrets side channel that's just used to obtain the static decryption key over the local network, or use your operating system's encryption facilities to transmit it, whatever works for you at whatever point on the complexity/security curve you desire.

(These are all just options, none are official recommendations.)

ComputerGuru··on Show HN: Keeper – embedded secret store for Go (help me break it)
We actually just ported SecureStore to go, it’s sort of like this but with cross platform clis and intended to also allow sharing secrets across services and languages, in a secure and embedded fashion! It’s available in rust, php, .net, JS/TS, Python, and golang and easy to port to others.

I didn’t get a chance to do a write up but the golang port is here: https://github.com/neosmart/securestore-go

The approach to crypto is very different, we went with what’s very well understood and very well supported on all platforms with little or no dependencies (eg we can use web crypto in JS frontend or backend with no external libs or crypto JS library nonsense).

The original .NET and Rust code is from over a decade ago and carefully architected (well before vibecoding was a thing), the secrets are stored in a human readable (json) vault that can be embedded in your binaries or distributed alongside them and be decrypted with either password-based or key-based decryption (or both).

The rust repo has the most info: https://github.com/neosmart/securestore-rs

ComputerGuru··on Microsoft terminated the account VeraCrypt used to sign Windows drivers
For comparison, my code signing cert via Azure (no Microsoft store account required, can be used to self-publish binaries/installers the old fashion way) is $10/month, or about a third of the price Sectigo is charging you. I figured it was worth trying this route first, though I had to write my own basic tooling around it.
ComputerGuru··on Veracrypt project update
Thanks for sharing your experience. I have been code signing releases for over a decade as an indie publisher myself, until I found myself effectively iced out by the HSM requirement, the increased cost, and the shortened cert lifetimes, which, as someone with certain executive order dysfunctions, I already had a hard time being on top of with the old (multi-year) lifetimes.

I just migrated to MS artifact signing and, thank the lord, had an actually easier time getting verified than I did with the Sectigo and Comodo in the past. I’m sure I’m not representative of anyone else’s experience but having already had a developer account (with a different email and without an Azure account!) that I had already been using for the Microsoft Store might have helped, as well as the fact that I had a well-established business history (I’ve heard businesses younger than 3 years can’t get verified??), but reading all the comments here makes me very uneasy about the future.

It’s good to know the HSM route isn’t a complete non-starter. The main reason I panned it is that when I started looking into this I found that a number of companies that had previously offered the HSM route had done a bait and switch and were now keeping custody unless you were big enterprise (meaning willing to put up with 10k/yr fees). I did find a few that would allow OSS devs to sign their work, but read horror stories on Reddit and elsewhere about their freezing the account and issuing no refunds if you ask them to issue the cert in the name of your LLC or corporation instead of with your personal name (which I expressly did not want). Also, they actually were more expensive than Azure artifact signing even after the HSM cost was taken out.

ComputerGuru··on Muse Spark: Scaling Towards Personal Superintelligence
So does this confirm the end of llama?
ComputerGuru··on Veracrypt project update
It’s become neigh impossible to get your own code signing cert these days. The 2025 update from the CA forum required code signing certs to be short lived (no more three or five year certs) and stored exclusively on an HSM. As a result, most companies cross-signing these certs have moved to a subscription PaaS model where you are issued a cert but never receive custody of it, and perform signing via their APIs, and are at their mercy should they decide to block your account.

Anyway, even if you could get your own cert it would be same thing: MS could revoke or blacklist your indicate cert (though usually the grounds for doing so are much less shaky than your account being suspended for vague “tos violations”)

ComputerGuru··on Veracrypt project update
That’s not how any of this works. There are separate teams within (each division of) Microsoft that could easily pull the plug on your account (or if not the entire account then your account’s access to the specific service or family of services) for any of a myriad purported reasons or alleged ToS violations.

No one is calling an executive meeting to discuss banning an OSS dev’s account.

ComputerGuru··on AI helps add 10k more photos to OldNYC
Thanks for the clarification!
ComputerGuru··on AI helps add 10k more photos to OldNYC
I have mixed feelings about this. It's absolutely phenomenal that such a treasure trove was unlocked thanks to AI, but presenting the AI results are "definitive" (even with an "edit" or "report" feature that's applied equally to human-located and AI-located results) isn't really a win. The old dataset might have been incomplete, but where locations were determined, they were a result of a (probably neural/autistic/ocd) human contributor that had some measure of true confidence in the results. AI contributions are great, but imho they should never be allowed to freely mix with and dilute human contributions: the resulting dataset is permanently polluted.

Ideally they'd always carry an "AI-generated" flag (in the db and in the frontend) until manually reviewed (or never) by a human. If anything, this is actually in AI proponent's favor as it would let you periodically regenerate or cross-validate (a subset of) the AI contributions some years down the line when newer and better models are released!

ComputerGuru··on 12k Tons of Dumped Orange Peel Grew into a Landscape Nobody Expected (2017)
There's actually no guarantee that if the "experiment" were allowed to continue that the results would have been as great. If the biomass accumulated faster than it could be broken down, we might not have seen the same result.
ComputerGuru··on Show HN: I successfully failed at one-shot-ing a video codec like h.264
Nothing on @bushido (props for humbly admitting what happened) but AI has completely destroyed people’s ability to appreciate the effort and domain knowledge that goes into the design of just about any properly successful undertaking.
ComputerGuru··on Neovim TreeSitter plugin has been archived on GitHub
I’m not sure what this means for the future of the project; I can’t find any information about its deprecation anywhere.
ComputerGuru··on ICAO issued new power bank restriction on flight
You’re both saying the same thing.
ComputerGuru··on Antimatter has been transported for the first time
A very different problem then the one I proposed an answer to, no?
ComputerGuru··on Apple randomly closes bug reports unless you "verify" the bug remains unfixed
Every other month I get an email from a legacy pre-GH bug tracker that's either a "me too" or "bug fixed in latest release" a decade after I filed these one-offs you would be so quick to throw away. Bugs with no activity for years on end.
ComputerGuru··on Antimatter has been transported for the first time
You can carry exactly (or roughly) as much energy in the form of antimatter as you would energy in the form of fuel.
← PreviousPage 6 of 34Next →