HNHacker News
TopNewBestAskShowJobs

RVuRnvbM2e

831 karma · joined April 24, 2014

submissionscomments
RVuRnvbM2e··on Building a certificate authority for the whole Internet
This is BS. One quick google and selecting a result from the first page: https://zeusstress.com/

Surprise! It's on crimeflare.

RVuRnvbM2e··on On caring for user data: NeoVim caused Vim undo files to be deleted
It's the part where you upgraded and apparently failed to read the release notes.

Or in the OPs case, installed a totally different application and was surprised by an incompatibility.

RVuRnvbM2e··on On caring for user data: NeoVim caused Vim undo files to be deleted
Undo files and persistent undo are not meant to work that way. They are just persistent across process restarts. That's all.

They live in ~/.cache which is defined as "user-specific non-essential (cached) data".

Despite this user's impressive résumé, they simply misunderstood the feature.

RVuRnvbM2e··on Why does Opus 5 feel worse to work with?
It also refuses to use tools, instead preferring sed and grep to view files. So frustrating.
RVuRnvbM2e··on Cloudflare launched self-managed OAuth for all
It's the worst delegated authorisation system except for all the others that have been tried from time to time.
RVuRnvbM2e··on From Australia to Europe, countries move to curb children's social media access
Where's the regulation of addictive dark patterns that hook kids and adults alike? Most jurisdictions regulate gambling to reduce societal harm. Social media is little different; it just has an advertising middle man.
RVuRnvbM2e··on The Token Compression Illusion: Why I'm Skeptical of RTK
Agree. I've watched agents go around in circles or use ridiculous workarounds after being confused by rtk output.
RVuRnvbM2e··on Zero-Touch OAuth for MCP
I don't quite understand the advantage of this over regular oauth. I think I need an example comparison of the authz flows.
RVuRnvbM2e··on Conventional Commits encourages focus on the wrong things
Yeah the article is wrong
RVuRnvbM2e··on Conventional Commits encourages focus on the wrong things
The thing conventional commits are really helpful for is continuous delivery. Every merge to main can be automatically tagged with semver and shipped because the thought that goes into tagging and versioning has already been done by the developers when they wrote the commit message.

I fully recognise that it doesn't make sense for huge projects like the Linux kernel to do this. But for 99% of projects conventional commits combined with semver vastly improves the release process status quo and makes it easy to automate.

RVuRnvbM2e··on When Dawkins met Claude – Could this AI be conscious?
It is terribly sad when someone undeniably brilliant in a particular field fails to recognize their own incompetence in other areas - in this case mistaking advanced technology for magic.
RVuRnvbM2e··on Glassworm is back: A new wave of invisible Unicode attacks hits repositories
Vigilant mode exists, and would have flagged the malicious commit as unverified in this case. Maybe it should be the default.

https://docs.github.com/en/authentication/managing-commit-si...

RVuRnvbM2e··on Glassworm is back: A new wave of invisible Unicode attacks hits repositories
Someone has maintainer/admin access to the repository and has force-pushed to master overwriting the git history.

Notice that the original commit is verified: https://github.com/pedronauck/reworm/commit/df8c1803c519f599...

While the malicious one is not: https://github.com/pedronauck/reworm/commit/d50cd8c8966893c6...

RVuRnvbM2e··on How I use Claude Code: Separation of planning and execution
This is just Waterfall for LLMs. What happens when you explore the problem space and need to change up the plan?
RVuRnvbM2e··on I started programming when I was 7. I'm 50 now and the thing I loved has changed
Another victim of the LLM-induced malaise many are calling "Deep Blue".
RVuRnvbM2e··on Thoughts on Go vs. Rust vs. Zig
> There's also no way to shrink the memory underlying a slice.

Sorry, that is incorrect: https://pkg.go.dev/slices#Clip

> It's a common newbie mistake to think they do work like that, and write "append(s, ...)" instead of "s = append(s, ...)". It might even randomly work a lot of the time.

"append(s, ...)" without the assignment doesn't even compile. So your entire post seems like a strawman?

https://go.dev/play/p/icdOMl8A9ja

> So (generalizing) Go won't implement a feature that makes mistakes harder, if it makes the language more complicated

No, I think it is more that the compromise of complicating the language that is always made when adding features is carefully weighed in Go. Less so in other languages.

RVuRnvbM2e··on Americans no longer see four-year college degrees as worth the cost
The reason for US economic domination starting in the 50s is the fact that society and infrastructure in the rest of the developed world had been utterly devastated by the second World War. The rate of college education is utterly irrelevant.
RVuRnvbM2e··on Exploring the Fragmentation of Wayland, an xdotool adventure
This is analogous to calling unix account separation "fragmentation". Why can't I just run all my services as root? It has worked for years!?

The answer is that it is a fragile, unmaintainable security nightmare.

Wayland has separation of concerns to fix that problem, with the tradeoffs described in the blog post.

RVuRnvbM2e··on State of Terminal Emulators in 2025: The Errant Champions
I'm quite confused why this article tests foot v1.16.2, which is two years old at this point. The latest version is 1.25.0.

By contrast, the tested version of ghostty v1.2.3 is two weeks old.

RVuRnvbM2e··on We all dodged a bullet
Fucking this.

I have seen so many takes lamenting how this kind of supply chain attack is such a difficult problem to fix.

No it really isn't. It's an ecosystem and cultural problem that npm encourages huge dependency trees that make it impractical to review dependency updates so developers just don't.

RVuRnvbM2e··on XZ Utils Backdoor Still Lurking in Docker Images
I don't understand the point of this article. Container images are literally immutable packaged filesystems so old versions of affected packages are in old Docker images for every CVE ever patched in Debian.

How is this news?

RVuRnvbM2e··on XZ Utils Backdoor Still Lurking in Docker Images
This is hyperbolic.

Unpatched long-lived VMs are much more cumbersome to fix than an outdated Docker image. And good luck reproducing your long-lived VM with years of mutation-via-patch.

RVuRnvbM2e··on Show HN: unsafehttp – tiny web server from scratch in C, running on an orange pi
Obviously you aren't one of them with an attitude like that.
RVuRnvbM2e··on Debian 13 “Trixie”
Why would you want to do this?
RVuRnvbM2e··on What to expect from Debian/Trixie
I've been using this combination successfully for a long time with no issues. In fact it is the only way to handle complex DNS setup on Linux.

If you have specific issues, please file them over at systemds GitHub issue tracker.

RVuRnvbM2e··on Stop Hiding My Controls: Hidden Interface Controls Are Affecting Usability
Notion is horrendous for this. Hiding every control behind an invisible hover target. No, I don't want my company documentation to have a minimalist aesthetic. I just want to use it.
RVuRnvbM2e··on Cloudflare to introduce pay-per-crawl for AI bots
By Cloudflare inserting themselves as a "HTTP market maker", is this step one in the enshittification of the web?
RVuRnvbM2e··on I Dropped the Production Database on a Friday Night
This is a good story and something everyone should experience in their career even just for the lesson in humility. That said:

> Here's the technical takeaway: Never use CASCADE deletes on critical foreign keys. Set them to NULL or use soft deletes instead. It's fine for UPDATE operations, but it's too dangerous for DELETE ones. The convenience of automatic cleanup isn't worth the existential risk of chain reactions.

What? The point of cascading foreign keys is referential integrity. If you just leave dangling references everywhere your data will either be horribly dirty or require inconsistent manual cleanup.

As I'm sure others have said: just use a test/staging environment. It isn't hard to set up even if you are in startup mode.

RVuRnvbM2e··on (On | No) Syntactic Support for Error Handling
Reduces the vertical space by vastly increasing the horizontal space and inserting line noise into the syntax. I don't even understand what that code would do.
RVuRnvbM2e··on CVE program faces swift end after DHS fails to renew contract
NVD != CVE
Page 1 of 6Next →