HNHacker News
TopNewBestAskShowJobs

WatchDog

3,291 karma · joined September 30, 2012

dev
submissionscomments
WatchDog··on AWS won't discuss my bill, suspended my account, took $1,600, still no human
I feel like this isn't the whole story. What line items were they billing you for? You couldn't get it resolved for a year? Why not move platforms after a couple of months of this treatment? If you have near zero usage, it shouldn't be that much work to replatform right?
WatchDog··on I fixed Windows native development
The license doesn't actually permit OSS development. Only compilation of near-unmodified third party OSS libraries.

You may not compile OSS software developed by your own organisation.

The OSS software must be unmodified, "except, and only to the extent, minor modifications are necessary so that the Open Source Dependencies can be compiled and built with the software."

https://visualstudio.microsoft.com/license-terms/vs2026-ga-d...

WatchDog··on Show HN: Microgpt is a GPT you can visualize in the browser
I trained 12,000 steps at 4 layers, and the output is kind of name-like, but it didn't reproduce any actual name from it's training data after 20 or so generations.
WatchDog··on ICE, CBP Knew Facial Recognition App Couldn't Do What DHS Says It Could
That is concerning, if this kind of technology is going to be used, there needs to be clear policies about it's use, and they must be followed.
WatchDog··on ICE, CBP Knew Facial Recognition App Couldn't Do What DHS Says It Could
That quote from the source wired article, does not allege that the DHS makes any claim that the app can itself verify anyone's identity.

Where has the DHS made any statement that the app does something that it does not do?

The closest thing I can find is from the 2025 DHS AI use case inventory, where the entry for Mobile fortify states it's benefits are:

"Utilizing facial comparison or fingerprint matching services, agents/officers in the field are able to quickly verify identity utilizing trusted source photos."

The claim is not that the app verifies someone's identity, but that it can potentially find trusted source photos that look similar to the person in question.

The officer could then evaluate the match, and make a determination to their own satisfaction that their subject is one and the same as the person in the database.

WatchDog··on ICE, CBP Knew Facial Recognition App Couldn't Do What DHS Says It Could
Privacy issues and politics aside, the title doesn't really seem to describe the content of the article.

The app seems to be doing what they say it can do. Is there any actual data as to it's effectiveness, match and false positive rate?

WatchDog··on Apple's latest attempt to launch the new Siri runs into snags
Grok runs on a cloud server, I think Apple are trying to do as much as possible on-device, which makes it a lot harder.
WatchDog··on Show HN: Double blind entropy using Drand for verifiably fair randomness
This happened on the first click opening the page, no other commit request in progress from myself, although maybe it's conflicting with other users.
WatchDog··on Show HN: Double blind entropy using Drand for verifiably fair randomness
Clicking the button sometimes displays an error:

    Error: JSON.parse: unexpected character at line 1 column 1 of the JSON data

Looking at the network tab, the POST request to the commit API returns a 409 error with the message:

    Commitment already pending for Round 26020619. Please wait for settlement before starting a new round.
WatchDog··on Vouch
> Ah, we have converted a technical problem into a social problem.

Surely you mean this the other way around?

Mitchell is trying to address a social problem with a technical solution.

WatchDog··on GitHub Actions is slowly killing engineering teams
I agree with all the points made about GH actions.

I haven't used as many CI systems as the author, but I've used, GH actions, Gitlab CI, CodeBuild, and spent a lot of time with Jenkins.

I've only touched Buildkite briefly 6 years ago, at the time it seemed a little underwhelming.

The CI system I enjoyed the most was TeamCity, sadly I've only used it at one job for about a year, but it felt like something built by a competent team.

I'm curious what people who have used it over a longer time period think of it.

I feel like it should be more popular.

WatchDog··on Deno Sandbox
If you achieve arbitrary code execution in the sandbox, I think you could pretty easily exfiltrate the openai key by using the openai code interpreter, and asking it to send the key to a url of your choice.
WatchDog··on Court orders restart of all US offshore wind power construction
> ...the Department of the Interior settled on a single justification for blocking turbine installation: a classified national security risk.

To speculate on what this risk is, the two obvious risk I can think of would be:

- Susceptibility to seabed warfare[0]. A rival nation can sabotage the infrastructure and maintain deniability, like we have seen with the Nord Stream sabotage[1].

- Potential interference with passive sonar systems, the turbines are likely to generate a fair bit of noise, which could potentially make it harder for SOSUS[2] to detect rival submarines.

[0]: https://en.wikipedia.org/wiki/Seabed_warfare

[1]: https://en.wikipedia.org/wiki/Nord_Stream_pipelines_sabotage

[2]: https://en.wikipedia.org/wiki/SOSUS

WatchDog··on xAI joins SpaceX
I think you mean "California High-Speed Rail", not light rail.

Light rail, generally refers to urban rail, "trams".

WatchDog··on Denial of service and source code exposure in React Server Components
When I looked into RSC last week, I was struck by how complex it was, and how little documentation there seems to be on it.

In fairness react present it as an "experimental" library, although that didn't stop nextjs from widely deploying it.

I suspect there will be many more security issues found in it over the next few weeks.

Nextjs ups the complexity orders of magnitude, I couldn't even figure out how to set any breakpoints on the RSC code within next.

Next vendors most of their dependencies, and they have an enormously complex build system.

The benefits that next and RSC offer, really don't seem to be worth the cost.

WatchDog··on Programmers and software developers lost the plot on naming their tools
There are many different tools that attempt to solve the same problem, with varying levels of competency.

They can't all use the same name. If you want to build a better alternative to an existing solution, you need to choose a different name, this leads to names being arbitrary.

WatchDog··on Apple's slow AI pace becomes a strength as market grows weary of spending
For the occasional local LLM query, running locally probably won't make much of a dent in the battery life, smaller models like mistral-7b can run at 258 tokens/s on an iPhone 17[0].

The reason why local LLMs are unlikely to displace cloud LLMs is memory footprint, and search. The most capable models require hundreds of GB of memory, impractical for consumer devices.

I run Qwen 3 2507 locally using llama-cpp, it's not a bad model, but I still use cloud models more, mainly due to them having good search RAG. There are local tools for this, but they don't work as well, this might continue to improve, but I don't think it's going to get better than the API integrations with google/bing that cloud models use.

[0]: https://github.com/ggml-org/llama.cpp/discussions/4508

WatchDog··on RCE Vulnerability in React and Next.js
I ran your exploit-rce-v4.js with and without the patched react-server-dom-webpack, and both of them executed the RCE.

So I don't think this mechanism is exactly correct, can you demo it with an actual nextjs project, instead of your mock server?

WatchDog··on RCE Vulnerability in React and Next.js
A CVSS score of 10.0 may be warranted in this case, but so many other CVSS scores are wildly inflated, that the scores don't mean a lot.
WatchDog··on Kohler Can Access Pictures from "End-to-End Encrypted" Toilet Camera
Any new term you come up with, will end up being misused by marketers.
WatchDog··on Why Strong Consistency?
A soft-realtime multiplayer game is always incorrect(unless no one is moving).

There are various decisions the netcode can make about how to reconcile with this incorrectness, and different games make different tradeoffs.

For example in hitscan FPS games, when two players fatally shoot one another at the same time, some games will only process the first packet received, and award the kill to that player, while other games will allow kill trading within some time window.

A tolerance is just an amount of incorrectness that the designer of the system can accept.

When it comes to CRUD apps using read-replicas, so long as the designer of the system is aware of and accepts the consistency errors that will sometimes occur, does that make that system correct?

WatchDog··on $96M AUD revamp of Bom website bombs out on launch
Another way to think about the price, is that it's slightly less than we spend per day on the NDIS(~126 million)
WatchDog··on The Bitter Lesson of LLM Extensions
The most useful LLM "extension" isn't even mentioned in this article, and that is shell use.

An LLM with a shell integration can do anything you need it to.

WatchDog··on A time-travelling door bug in Half Life 2
The impulse console command originates from Quake, the Half-Life 1 engine (GoldSrc[0]), was based on the Quake engine, and the Half-Life 2 engine (Source), was based on GoldSrc.

In quake, the impulse commands were used mostly to switch weapons[1]. I'm not really sure about the naming though, why choose the word "impulse".

[0]: https://en.wikipedia.org/wiki/GoldSrc.

[1]: https://github.com/id-Software/Quake/blob/0023db327bc1db0006...

WatchDog··on Measuring the impact of AI scams on the elderly
TLDR: They generated some phishing emails using LLMs, they sent the emails to 108 elderly people who agreed to be in a study, 11% of the recipients clicked a link.

Generating a phishing email isn't very difficult to do, with or without an LLM, and claiming that because someone clicked on a link, they were "compromised" seems disingenuous.

More interesting to me, is using LLMs in multi-turn phishing correspondence with victims, the paper mentions this in the discussion, but it isn't something that they appear to have actually tested.

WatchDog··on A file format uncracked for 20 years
Have you done any analysis of what proportion of the lin file is being read in total?

You stated in the blog post, that your goal is to try and find unused content, however if as described, the file is just a record of how the game loads the data, then it won't contain any hidden unused assets, since unused assets would never have been read from the original unoptimised file, and thus never written to this optimized file.

WatchDog··on I have recordings proving Coinbase knew about breach months before disclosure
So the emails had proper DKIM signatures.

Did the support agents have the ability to send arbitrary emails from commerce@coinbase.com? If not, how did the scammers send a properly signed email?

WatchDog··on FBI tries to unmask owner of archive.is
I’m not certain either way, but part of the document tries to make a big deal about some GitHub profiles having the “arctic code vault archive” badge, and implying that has something to do with running an archive website.

Pretty much anyone who has made any kind of commit to an open source project has that badge.

WatchDog··on FBI tries to unmask owner of archive.is
Probably works against a fair few sites, but not if they are using RDNS.
WatchDog··on An eBPF loophole: Using XDP for egress traffic
Presumably you don’t need to handle traffic at line speed, you just need to process it faster than userspace applications can produce and consume it.

What I don’t really understand is why iptables and tv is so slow.

If the kernel can’t route packets at line speed, how are userspace applications saturating it?

← PreviousPage 4 of 31Next →