HNHacker News
TopNewBestAskShowJobs

SerCe

5,231 karma · joined December 12, 2014

https://serce.me/
submissionscomments
SerCe··on Write some software, give it away for free
Or don't. I've done both, published OSS projects and sold some software. The level of entitlement in some comments I received on the OSS side was pretty crazy at times. While with the paid software, all of the interactions I had were so much more constructive. YMMV, but willingness to pay is a great filter.
SerCe··on Many SWE-bench-Passing PRs would not be merged
While I somewhat understand the impact on the craft, the agents have allowed me to work on the projects that I would never have had enough time to work on otherwise.
SerCe··on Many SWE-bench-Passing PRs would not be merged
> Do you have any examples or resources that worked well for you?

Using this particular example, if you simply paste the exact code into the prompt, the model should able to reproduce it. Now, you can start removing the bits and see how much you can remove from the prompt, e.g. simplify it to pseudocode, etc. Then you can push it further and try to switch from the pseudocode to the architecture, etc.

That way, you'll start from something that's working and work backwards rather than trying to get there in the absence of a clear path.

SerCe··on Many SWE-bench-Passing PRs would not be merged
If you've got some time, I highly recommend going through the exercise of trying to change the prompt in a way that would produce code similar to what you've achieved manually. Doing a similar exercise really helps to improve agent prompting skills, as it shows how changing parts of the prompt influences the result.
SerCe··on Making frontier cybersecurity capabilities available to defenders
What's incredibly ironic is that research labs are releasing the most advanced hacking toolkit ever known, and cybersecurity defence stocks are going down as a result somehow. There’s no logic in the stock markets.
SerCe··on Evaluating AGENTS.md: are they helpful for coding agents?
In Theory There Is No Difference Between Theory and Practice, While In Practice There Is.

In large projects, having a specific AGENTS.md makes the difference between the agent spending half of its context window searching for the right commands, navigating the repo, understanding what is what, etc., and being extremely useful. The larger the repository, the more things it needs to be aware of and the more important the AGENTS.md is. At least that's what I have observed in practice.

SerCe··on A kernel bug froze my machine: Debugging an async-profiler deadlock
Great article! Just yesterday I watched a Devoxx talk by Andrei Pangin [1], the creator of async-profiler where I learned about the new heatmap support. To many folks it might not sound that exciting, until you realise that these heatmaps make it much easier to see patterns over time. If you’re interested there’s a solid blog post [2] from Netflix that walks through the format and why it can be incredibly useful.

[1]: https://www.youtube.com/watch?v=u7-S-Hn-7Do

[2]: https://netflixtechblog.com/netflix-flamescope-a57ca19d47bb

SerCe··on AI generated font using Nano Banana
Definitely not the first AI generated font. One can find an enormous amount of research in AI font generation on https://scholar.google.com/ going back many years. This could possibly be the first one that used Nano Banana though, and the result is impressive for sure!
SerCe··on Pocketbase – open-source realtime back end in 1 file
I believe there is no contradiction with the definition from the linked article?

> A system is said to be real-time if the total correctness of an operation depends not only upon its logical correctness, but also upon the time in which it is performed. Real-time systems, as well as their deadlines, are classified by the consequence of missing a deadline:

> Hard – missing a deadline is a total system failure.

> Firm – infrequent deadline misses are tolerable, but may degrade the system's quality of service. The usefulness of a result is zero after its deadline.

> Soft – the usefulness of a result degrades after its deadline, thereby degrading the system's quality of service.

From what I can tell, https://pocketbase.io/ attempts to be a soft-realtime system.

SerCe··on LinkedIn is loud, and corporate is hell
The highest level of cringe you can feel is when you see people you know well in real life post on LinkedIn. The contrast between the way they speak in real life and on LinkedIn is often immense, you don't feel that level of contrast with random internet strangers.
SerCe··on Cloudflare outage on November 18, 2025 post mortem
As always, kudos for releasing a post mortem in less than 24 hours after the outage, very few tech organisations are capable of doing this.
SerCe··on Can we know whether a profiler is accurate?
> Isn’t not that they’re “not perfectly accurate”, it’s that you can find half an order of magnitude of performance after the profiler tells you everything is fine. > That’s perfectly inaccurate.

That's a very strong claim, and it's not true in my experience as I've showed above.

SerCe··on Can we know whether a profiler is accurate?
> Let me save you fifteen minutes, or the rest of your life: They aren’t.

Knowing that all profilers aren't perfectly accurate isn't a very useful piece of information. However, knowing which types of profilers are inaccurate and in which cases is indeed very useful information, and this is exactly what this article is about. Well worth 15 minutes.

> And that often involves ignoring the fancy visualization and staring at the numbers.

Visualisations are incredibly important. I've debugged a large number [1] of performance issues and production incidents highlighted by the async profiler producing Brendan Gregg's flame graphs [2]. Sure, things could be presented as numbers, but what I really care about most of the time when I take a CPU profile from a production instance is – what part of the system was taking most of the CPU cycles.

[1]: https://x.com/SerCeMan/status/1305783089608548354

[2]: https://www.brendangregg.com/flamegraphs.html

SerCe··on Rating 26 years of Java changes
> So yeah, why expose it to those who are not the "main customer"?

How did modules affect you as a user? I'd guess that you had to add `--add-opens`/`--add-exports` during one of the JDK migrations at some point. And the reason you had to do it was that various libraries on your classpath used JDK internal APIs. So modules provided encapsulation and gave you an escape hatch for when you still have to use those libraries. How else would you do it while still achieving the desired goal?

SerCe··on Rating 26 years of Java changes
My read is that it's easy to be quite negative on Java features when you're not the person they were designed for. For example, the main "customer" of the module system is the JDK itself. The main customer of NIO/2 is the low-level libraries like Netty.

I highly recommend the Growing the Java Language talk by Brian Goetz to anyone who's interested in the philosophy behind evolving the modern Java language [1]. And Don’t be misled by the title, it’s not just about Java, it’s about software design.

[1]: https://www.youtube.com/watch?v=Gz7Or9C0TpM

SerCe··on Google Safe Browsing incident
What this post might be missing is that it’s not just Google that can block your website. A whole variety of actors can, and any service that can host user-generated content, not just html (a single image is enough), is at risk, but really, any service is at risk. I’ve had to deal with many such cases: ISPs mistakenly blocking large IP prefixes, DPI software killing the traffic, random antivirus software blocking your JS chunk because of a hash collision, even small single-town ISPs sinkholing your domain because of auto-reports, and many more.

In the author’s case, he was at least able to reproduce the issues. In many cases, though, the problem is scoped to a small geographic region, but for large internet services, even small towns still mean thousands of people reaching out to support while the issue can’t be seen on the overall traffic graph.

The easiest set of steps you can do to be able to react to those issues are: 1. Set up NEL logging [1] that goes to completely separate infrastructure, 2. Use RIPE Atlas and similar services in the hope of reproducing the issue and grabbing a traceroute.

I’ve even attempted to create a hosted service for collecting NEL logs, but it seemed to be far too niche.

[1]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Net...

SerCe··on iPhone Air
I own a 12 mini, and I'm planning to upgrade my phone this year, it's time. If there were an iPhone 17 mini, I'd buy it, but because there isn't one, I'll probably go for the Pro to get a bigger battery. Apple knows that many folks like me would buy a cheaper mini if there were one, and not spend as much on Pro.
SerCe··on Claude Opus 4 and 4.1 can now end a rare subset of conversations
This reminds me of users getting blocked for asking an LLM how to kill a BSD daemon. I do hope that there'll be more and more model providers out there with state-of-the-art capabilities. Let capitalism work and let the user make a choice, I'd hate my hammer telling me that it's unethical to hit this nail. In many cases, getting a "this chat was ended" isn't any different.
SerCe··on GPT-5: Overdue, overhyped and underwhelming. And that's not the worst of it
To provide an update, both – custom GPTs and Deep Research seem to have been fixed.
SerCe··on GPT-5: Overdue, overhyped and underwhelming. And that's not the worst of it
Here are my reasons why this "upgrade" is, in experience, a huge downgrade for Plus users:

* The quality of responses from GPT-5 compared to O3 is lacking. It does very few rounds of thinking and doesn't use web search as O3 used to. I've tried selecting "thinking", instructing explicitly, nothing helps. For now, I have to use Gemini to get similar quality of outputs.

* Somehow, custom GPTs [1] are now broken as well. My custom grammar-checking GPT is ignoring all instructions, regardless of the selected model.

* Deep research (I'm well within the limit still) is broken. Selecting it as an option doesn't help, the model just keeps responding as usual, even if it's explicitly instructed to use deep research.

[1]: https://openai.com/index/introducing-gpts/

SerCe··on Cursor 1.0
I use it pretty much daily and am pretty happy with it, especially its ability to do very targeted edits rather than leaving random changes everywhere.

I believe it’ll get much better as LLMs start editing code by invoking refactoring tools (rename, change signature, etc.) rather than rewriting the code line by line, as this will let them perform large-scale changes reliably in a way that's similar to how software engineers do them now using IDE tools

SerCe··on JEP 519: Compact Object Headers
The previous JEP 450 [1] has a lot more implementation details for those who are interested.

> They have been tested at Oracle by running the full JDK test suite. They have also been tested at Amazon by hundreds of services in production, most of them using backports of the feature to JDK 21 and JDK 17.

One of the underappreciated perks of working on platform teams in large (and very large in the case of Amazon) companies is that you've got a playground to see and quantify the impact of your performance work that few others have.

[1]: https://openjdk.org/jeps/450

SerCe··on There is no Vibe Engineering
> Why is that quote in the piece? I don't get the analogy.

I liked the quote because what it conveys is that you can't control everything. You can't control the way people freak out about things on Twitter. You can't control an influx of new tools. But what you can control is the way you react to them – not giving in to the chaos, but instead approaching the changes with a cool head. And the Netflix show it's from, Midnight Gospel, is pretty good. I do agree that the house analogy could be better though.

SerCe··on TL;DR of Deep Dive into LLMs Like ChatGPT by Andrej Karpathy
I believe Andrej Karpathy runs a discord, which is linked on his website [1]. I haven't participated personally, but from what I've seen, it's very active.

[1]: https://karpathy.ai/zero-to-hero.html

SerCe··on The LLM Curve of Impact on Software Engineers
The author here. Yes, what you're saying is 100% on point. Putting a company's code into a random chatbot online would be a horrendous violation of any company's policy out there. I'm in a fortunate position where we've had a clearly defined policy for a long time now, outlining which tools can be used and which categories of data we are allowed to use with them.
SerCe··on You could have invented Fenwick trees
I remember trying to memorise the implementation by following the e-maxx guides [1] (back then it was http://e-maxx.ru/) for use in competitive programming contests. They're so simple once you understand them, yet it's pretty easy to forget the details of the simple implementation if you haven't done it for a while.

[1]: https://cp-algorithms.com/data_structures/fenwick.html

SerCe··on The hidden complexity of scaling WebSockets
I wrote about the way we handle WebSocket connections at Canva a while ago [1]. Even though some small things have changed here and there since the post was published, the overall approach has held up pretty well handling many millions of concurrent connections.

That said, even with great framework-level support, it's much, much harder to build a streaming functionality compared to plain request/response if you've got some notion of a "session".

[1]: https://www.canva.dev/blog/engineering/enabling-real-time-co...

SerCe··on Why we built Vade Studio in Clojure
They most likely refer to homoiconicity [1], as Clojure is a dialect of Lisp. However, it's hard to say for sure, and maybe they were simply referring to the built-in syntax for maps, lists, etc.

[1]: https://en.wikipedia.org/wiki/Homoiconicity

SerCe··on Six Sins of Platform Teams
That's the point I was trying to highlight in the "Treating product engineers as customers" sin section – the duality goes both ways. Sometimes the best thing for the company is to make the lives of product engineers better, sometimes it's to make them worse. You do whatever is best for the company, not for the product engineers.
SerCe··on Six Sins of Platform Teams
I see, thank you for clarifying. That's an interesting observation, I feel like there is a story behind it. :)

I definitely agree that as any small start-up grows, the security controls become very painful, especially for those folks who felt "the freedom" before the controls were established. That said, would the picture look better without platform teams? The security controls would need to be there anyway, and I'd personally prefer to use some self-serve, platform-ish solution built by a team of software engineers that would do call auditing, verification, etc., rather than raising a JIRA ticket with some ops folks who'd do the security-sensitive thing for you.

Page 1 of 3Next →