HNHacker News
TopNewBestAskShowJobs

_flux

1,473 karma · joined October 6, 2020

submissionscomments
_flux··on OpenBSD has a use-after-free allowing local privilege escalation to root
I wonder how many of the Linux the LPEs are related to drivers, which I understand there are more of..
_flux··on Decoding the obfuscated bash script on a Uniqlo t-shirt
On one hand it's nice how it's clean and commented, but on the other hand some golfing could have made the encoded block a lot more reasonable to actually manually enter.
_flux··on Car touchscreens are cheap, not good
It could use array microphone to detect that the sound originates from the driver's seat (in addition to using it for filtering out not-from-driver's-seat sounds).
_flux··on Does code cleanliness affect coding agents? A controlled minimal-pair study
Paraphrasing: if I don't write the codebase [but someone else does], I don't write the tests, and other team members are modifying it, what even is considered a messy codebase?

I actually don't see a connection between the mechanism used to create the code and the code messiness. Things like code repetition, incorrect level of abstractions, tests testing only tests themselves, using too smart optimizations for things that don't matter, .. These all can happen in both person- and machine -authored code.

I would be surprised if a professional software developer has never seen at least some aspects of messy codebase in most any large project. The difference can be whether this messiness ever managed, or just piled on.

_flux··on Alibaba to ban Claude Code in workplace over alleged backdoor risks, source says
Does Alibaba only have developers in the China?
_flux··on Immich 3.0
Wouldn't it then be reasonable to focus on those many features, instead of storage? I would enjoy using with S3, as expanding S3 storage is easier than expanding the storage of a virtual machine: usually it happens automatically.

Of course this topic has been discussed: https://github.com/immich-app/immich/discussions/1683

_flux··on AI can't be listed as inventor on patent applications, Japan's top court rules
You can't assign the copyright to Emacs either, yet it can be used to produce software.
_flux··on Tidal AI Policy
Works for me (TM). Maybe you lost CDN-lottery?
_flux··on Replacing Systemd with OpenRC in Debian
Yes, but one only needs to write it once, and then everyone could use it. It could probably even be packaged as an official Debian package.
_flux··on Replacing Systemd with OpenRC in Debian
Hmm, I perhaps didn't quite catch this. I thought having a generator would let you be less committed to it, as you wouldn't need to manually write all the init scripts you need.. ?
_flux··on Replacing Systemd with OpenRC in Debian
My /usr/lib/systemd takes 6.4 megabytes, so I think I could live with that overhead. Or I suppose just delete them manually.

What would actually be useful would be a generic OpenRC wrapper that would ingest those service files and provide traditional start/stop interface for them.

_flux··on Replacing Systemd with OpenRC in Debian
Devuan us a separate Debian with its own repositories (and presumably many packages patched to improve systemd-less life), while this is just replacing Systemd with OpenRC on a Debian system, while keeping Debian repos etc.
_flux··on Why current LLM costs are not sustainable
So I let ChatGPT do the legwork for me, but it does seem the price difference between inference for GPT-5.5 and open-weight frontier models like DeepSeek V4 Pro and Kimi K2.6, which both are smaller models and thus cheaper to run inference on, is only 8x or so.

Sources https://openai.com/business/pricing/#api says for GPT-5.5:

  Input:$5.00 / 1M tokens Cached input:$0.50 / 1M tokens Output:$30.00 / 1M tokens
and for https://docs.fireworks.ai/serverless/pricing DeepSeek V4 Pro:

  Input: $1.74 / 1M tokens Cached input: $0.145 / 1M tokens Output: $3.48 / 
Ratios are: 2.8, 3.4, 8.6

So as these numbers seem reasonably comparable to SOTA, and the SOTA vendors have additional overhead, then I think it is fair to deem that the alternative explanation offered here is not the explanation:

> Why do you think that subscriptions are subsidized and not that enterprise tokens are sold at 3000% margin?

As it does seem like the GPT-5.5 API tokens do not have significant margin based on the overhead-free companies selling inference for smaller models at prices of the same scale, I think we can believe that the subscriptions must be heavily subsidized.

It should be noted though that DeepSeek itself sells this even cheaper, but they may also be in it for the getting market share.

_flux··on Why current LLM costs are not sustainable
So they do not train models, and in addition their models are expected to be smaller than SOTA models, although we cannot know for sure by how much.

So what's the price difference, 3000x?

_flux··on Why current LLM costs are not sustainable
I think this comes from the idea that serving these tokens without paying for training is already expensive, e.g. https://news.ycombinator.com/item?id=46613887 self-hosted solution might give you only 10-100x more affordable solution at cost.

So, given the SOTA providers with even larger models also need to continously be using considerable resources for training their next models, to fund future data centers, and make profit, the token costs are more likely reflecting the real costs, rather than the subscription costs.

_flux··on Zig's new bitCast semantics and LLVM back end improvements
You too could have it easily accessible on your keyboard by using EurKEY: https://eurkey.steffen.bruentjen.eu/
_flux··on LuaJIT 3.0 proposed syntax extensions
Surely the most likely explanation is familiary from C?

But e.g. ml-family languages (like OCaml, F#, Haskell) and Rust just have the *if* expression that has a non-void value. If your language accepts expressions as statements (most do?), then I think that should just be compatible out of the box.

_flux··on The new HTTP QUERY method explained
There is the Accept-Query header https://www.rfc-editor.org/info/rfc10008/#appendix-A.3 that tells you can use QUERY. That's a bit different.
_flux··on Steam Machine launches today
I believe that's exactly what the Steam Machine reservation does: limits to one per household, so I take that to mean the address without the name.

Although I think the language in the response dialog will be nicer than accusing of fraud.

_flux··on Writing Postcards with a 3D Printer
I've also used 3d printer to straight up print on top of a greeting card (the print was 1 layer).

The print might not fare that well though the post system, though, so maybe it wouldn't be suitable for postcards. But it can be a nice touch.

_flux··on Gribouille 0.3.0: A Grammar of Graphics for Typst
Perhaps you would enjoy the rest of the tooling, that may be useful in scientific contexts or in books discussing programming languages. Or perhaps you would also want to publish in PDF, like for an actual print book.

What kind of issues did you expect to encounter in translating Typst documents to other languages?

_flux··on Gribouille 0.3.0: A Grammar of Graphics for Typst
Typst html support is already available as an experimental feature, so e.g. EPUB probably isn't too much work in addition to that (as I understand it, it's basically zipped HTML with some metadata). It's also in the roadmap: https://typst.app/docs/roadmap/#:~:text=EPUB%20export .

If the translator has access to a service like typst.app, then I don't see too many obstacles for translating. But I don't have any experience on doing translations.

_flux··on Google Chrome update will close the door on ad blockers
I was under the impression MV3 is stricly less capable in terms of blocking ability than MV2?
_flux··on TinyWind: A pixel pirate sailing game with real wind physics (380k+ kms sailed)
Should there be sound? I think sounds would be essential for this.

Running on Linux Firefox.

_flux··on Malicious npm packages detected across Red Hat Cloud Services
I think if they did it, then attackers would be able to iterate their attack against their own project, and once it passes the filters they could deploy for real.

I guess it could work better if it was enabled for only actual attack vectors projects.

_flux··on Malicious npm packages detected across Red Hat Cloud Services
> Maybe NPM should run scanners before distributing malware?

I suspect there's always a human checking these results. If NPM straight out rejects an update due to suspected malware, they might end up rejecting correct updates as well. If they grant some "safe" patterns a special pass, they might get exploited.

So I think this only works if you have security scanners that are well-maintained and kept in secret. NPM folks could of course co-operate with some security companies to have a first stab with the releases before they are put to public access. At some point some parties might start want to have monetary compensation for such an arragnement, though.

_flux··on Rift: Better Alternative to Git Worktrees
I don't have a reflink-able filesystem in this host, but I just tested that

    echo 2 | sudo tee /proc/sys/vm/drop_caches
    time cp -rl foo bar
took 2.6 seconds for 273000 files, so I think it's highly manageable. Reflinking might be a bit slower than hardlinking, though.
_flux··on Rift: Better Alternative to Git Worktrees
How about cp --reflink? Supported by btrfs, bcachefs and zfs. It's quite not as fast as subvolumes in btrfs, but it should be plenty fast.

This should actually be a feature for git itself, if it's not already.

_flux··on MCP is dead?
So are you using MCP to do this?

I'm not saying MCP or the ways we use it cannot be extended to cover this use case, but my understanding is that nobody does it. But shell/code does, and more.

_flux··on MCP is dead?
Let's say you have a jq MCP. How do you pass data in and out to/from it without the data also being processed as tokens?

That's really my only issue with MCPs.

With shell you can pass data from one component to another directly, not only being cheaper, faster, but also preserving complete integrity. While models nowadays seem to do data echoing well, there's always the chance they might not do it exactly.

There's no reason why a shell would not be able to limit abilities of a party using it as well, by virtue of just implementing only the desired functionality. What makes it more advanced in this context is the (standard) ability to express how to connect multiple components to each other, or to/from local storage. MCP does not have this.

Providing that does not have any inherent danger any more than jq's functions have an inherent danger. Actual execution of processes or real files does not need to be involved.

← PreviousPage 3 of 32Next →