HNHacker News
TopNewBestAskShowJobs

Too

4,749 karma · joined October 7, 2011

submissionscomments
Too··on GitHub Actions and Pages are experiencing degraded availability
Mods, I think there is something wrong with the front page algorithm. This post has been stuck there for more than a year now.

Among with assorted thoughts on AI or new model point release announcements.

Too··on Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
> 36 billion ads needing review annually

This would mean every single user gets 10 uniquely personalized ads per year.

Even if that wasn't hilariously unreasonable by several orders of magnitude, if the moderation cost was was included in the cost of serving ads, this would all self regulate and only serious actors would participate. Treating it as a public bulletin board while still raking in a percentage of the impressions for sure is a nice business model, but not what's best for the rest of the society. Maybe ads just shouldn't be such a lucrative business.

Too··on Stacked PRs are now live on GitHub
Gerrit manages stacked changes with standard git tooling, except for the tiny change-id hook. Similar stable change identifier is also what enables Jujutsu to do its magic. Standardizing around something like this would be greatly beneficial, instead a ”gh” CLI is now needed to push a commit.
Too··on Stacked PRs are now live on GitHub
This emphasizes the problem even more. Only one out of ten people use the force push approach, most others add commits to the PR.

Allowing two different workflows – even within the same project – just shows the lack of strategy for how this should work.

Re-educating when and when not force-push is a holy sin is also a barrier to alignment.

Too··on Superlogical
On iOS the whole page jumps up and down when you try to grab it.
Too··on Superlogical
> We're also addressing the most common papercuts of existing tools, such as making scrollback, selection, and scrolling all work natively.

Goes ahead and butchers the browser scrollbar.

Too··on Firefox 153 available with support for Vulkan video decoding, JPEG-XL
Does this mean that AV1 on Youtube will finally not melt my CPU, while my nvidia GPU is asleep, or is this just an enabler that will require more work to build upon?
Too··on You only need the frontier model for one single edit
> The mistake is upstream of the architecture diagram. People price agents the way they price people: senior time is expensive, so minimize senior involvement.

> But the expensive part of an agent's day is not the fixing, building, or even the thinking. Opus fixing things does not cost money. Opus reading things costs money.

Heh, another rediscovery that agents and humans are alike. By the time I've researched a Jira ticket and made it unambiguous enough to outsource, I might as well have written the code myself instead.

Too··on What AI did to stackoverflow in a graph
Even without AI, a large part is also that everything easy and relevant has already been asked and answered. 10 years ago, there was still demand for low hanging ”how do I reverse a string in programming language X”. On top of that, languages and libraries today tend to have a lot better documentation.

What’s left to ask now is ”plx fix my homework” - [pastes error log unique to the posters environment]. Something that Claude is very good and very tolerant at.

Too··on Moving beyond fork() + exec()
Fill with what stuff exactly?

The only thing I want to inherit from the parent process is its cwd and environment variables, even those are often overridden. The rest can easily be passed explicitly through other channels like pipes or command line arguments.

Back to the example from the article. It makes no sense that a git-subprocess forked from a web server need to have any process state inherited from the web server.

Too··on Infrastructure decisions I endorse or regret after 4 years at a startup (2024)
This does not match my experience. Terraform validate will check for types and you have great IDE support with refactor, find usages, resource documentation and everything else you might expect. You can of course build a monster of untyped dictionaries but that’s true for almost any language. Do you have examples of something else that the validation step does not find?
Too··on Linux is good now
Sure you can secure boot the kernel and the game binary itself but then you have all the surrounding support from the OS that also need to interop without being tamperable. Screenshots, network and input devices for example are routed through user space before reaching the game, and they can be used to make cheats. Now some of those layers are getting more isolated, for example with Wayland. Even so, that means your secure boot chain must go all the way up to include a non tampered window manager too, taking you closer and closer into reinventing a Android like console OS.
Too··on Linux is good now
> The best Valve could do is offer a special locked down kernel with perhaps some anticheat capabilities and lock down the hardware with attestation.

That would require essentially turning it into a console or Android.

Too··on Why users cannot create Issues directly
GitHub desperately needs a feature to pin comments in issues or sort by reactions.

Very often in those infamous bugs that has been open for years, having hundreds of ”me too” comments, there are gems with workarounds or reproductions, unfortunately hidden somewhere under 4 iterations of ”click to load 8 more comments”, making it difficult to find. This generates even more ”anyone know how to solve this” spam, further contributing to the difficulty to find the good post.

Too··on Show HN: Use Claude Code to Query 600 GB Indexes over Hacker News, ArXiv, etc.
What’s the benefit of manually pasting a massive prompt and enable egress to make queries over http vs just using MCP?
Too··on I can't upgrade to Windows 11, now leave me alone
That’s if you run a OS version older than 5 years. You can still update to a newer Ubuntu version for free and get another 5 years if you pick an LTS version.
Too··on I can't upgrade to Windows 11, now leave me alone
To be honest Linux desktop has been ready for the past 4-5 years or so. Long gone are the days where Bluetooth suddenly stopped, external monitors crashing and when closing the lid only put the laptop to sleep every fifth time. Heck, even Wayland, wireless printers and usb-c docking stations work these days, even with nvidia. You might even find some games.

It’s become a boring appliance that just works every time. Just they way I want it. I even forgot how to use grub.

Too··on Log level 'error' should mean that something needs to be fixed
Beyond LiteralString there is now also t-strings, introduced in Python 3.14, that eases how one writes templated strings without loosing out on security. Java has something similar with Template class in Java 21 as preview.
Too··on Yep, Passkeys Still Have Problems
When was the last time you used a library computer, let alone logged onto a private service with it? This was a bad idea even 20 years ago. In today’s security climate, aw hell no.
Too··on Log level 'error' should mean that something needs to be fixed
Simple: include those relevant details in the exceptions instead of hiding them.
Too··on Log level 'error' should mean that something needs to be fixed
Agree with the post. The job of blackbox is to turn probes into metrics. If a probe fails, that should just become a probe_success=0 metric. Blackbox did its job and should not log an error.
Too··on Log level 'error' should mean that something needs to be fixed
This is why it’s almost always wrong for library functions to log anything, even on ”errors”. Pass the status up through return values or exceptions. As a library author you have no clue as how an application might use it. Multi threading, retry loops and expected failures will turn what’s a significant event in one context into what’s not even worthy of a debug log in another. No rule without exceptions of course, one valid case could be for example truly slow operations where progress reports are expected. Modern tracing telemetry with sampling can be another solution for the paranoid.
Too··on Germany: Amazon is not allowed to force customers to watch ads on Prime Video
Is anyone paying for Prime just for streaming? I always saw it as a nice bonus included with free shipping and all the other discounts you get on Amazon, it breaks even very quickly. It cost half of a Netflix subscription. The content is also half the quality, so it’s not like I would like to pay anything for it anyway. I hate ads as much as anyone, after the ad introductions I just stopped slop watching.
Too··on Dagger: Define software delivery workflows and dev environments
If I understand correctly, this is essentially a more composable way to write Dockerfiles? That alone is a very welcome improvement. They would do themselves a big favor if they were more clear on that in their marketing, instead of boasting around the bush with all kinds of other terminology and claims of redefining foundations.

If I already have a Dockerfile that doesn’t need composition, how does this help me vs being a small cosmetic improvement over ”docker build” command line?

Too··on Dagger: Define software delivery workflows and dev environments
But that dependency order is usually just one big blob of ”COPY src/ . + RUN make”, within that block you have none of the benefits. Bazel/Buck has much finer awareness down to every individual file.

Out of curiosity, would it be feasible to take a big cmake project and generate thousands of compile rules into dagger and use it as a substitute for make with sandboxing? I’ve never seen builkit used with such many nodes, how would it fare?

Too··on Linux Sandboxes and Fil-C
From a definition point of view that might be right and it’s no doubt a good step up, compared to continuing with tainted data. In practice though, that is still not enough, these days we should expect higher degree of confidence from our code before it’s run. Especially with the mountains of code that LLMs will pour over us.
Too··on Linux Sandboxes and Fil-C
Can someone give a tldr of what makes fil-c different from just compiling with clang’s address sanitizer?

Calling it memory safe is a bit of a stretch when all it does is convert memory errors to runtime panics, or am I missing something? I mean, that’s still good, just less than I’d expect given the recent hype of fil-c being the savior for making C a competitive language again.

Too··on Reddit Migrates Comment Back End from Python to Go
To optimize that code snippet, use temporary variables instead of member lookups to avoid slow getattr and setattr calls. It still won’t beat a compiled language, number crunching is the worst sport for Python.
Too··on We should all be using dependency cooldowns
You should also factor in that a zero-day often isn’t surfaced to be exploitable if you are using the onion model with other layers that need to be penetrated together. In contrast to a supply chain vulnerability that is designed to actively make outbound connections through any means possible.
Too··on Experiment: Making TypeScript immutable-by-default
Rust compiles to wasm right?
Page 1 of 34Next →